MalScore
100/100
MalFamily
Androm

HDLO.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 31/67 Related 2707
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 464.00 KB (475136 bytes)
Compile time: 2017-12-17 22:53:01
MD5: 2a8c99a5d050cf0cb3d988d9d82dfea5
SHA1: ac876322ab8e2f109ba63712c271d76c1ebc4644
SHA256: b061bb11b2de75af258f516c93e7cbea1477b7d1123ddf9e181431127c3c143b
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2017-12-18 13:15:09
Last submission: 2017-12-18 13:15:09
Filename detected: - HDLO.exe (1)
URL file hosting
hXXp://ecommesaa.org/pepe/HDLO.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2017-12-18 10:22:25 [31/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x6ea94 454656 ec633ae130061d407a8154d0562b1d29 efca45718140b4653f72e5554721817194331f27
.rsrc 0x72000 0x2628 12288 dc3b532e0959f9af471f13c15bd49ce0 d7286bc482bb1b8da2a582622d411ceef9865c00
.reloc 0x76000 0xc 4096 a62aa7568fb88ab9e4c5df428f167951 6e95e8b4e24e91ddca2b5da63214c326d33b35a9
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x72398 8824 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x74610 20 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x720e8 684 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: BIJOYEX
Assembly Version: 0.0.0.9
InternalName: HDLO.exe
FileVersion: 0.0.0.9
FileDescription: BIJOYEX
OriginalFilename: HDLO.exe
ProductVersion: 0.0.0.9
Translation: 0x0000 0x04b0
Comments: BIJOYEX
ProductName: BIJOYEX
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
ogakpee.dll
grgxzcpcguz.dll
mscoree.dll
npfll.dll
KERNEL32.dll
IP Found
0.0.0.9
8.0.0.2
URL(s)
http://swhuoeq.microsoft.qk
String too long
BREEZTBVOOBZXNZUROIZVIXZXBVTZOTNCCIUIOOTUBOONEUCMZXROXUETIOMZOEOORCNECEXCMBONCOOUEEOMIZRTTREVIUOZTZMTMTIX
[MSGONC
Str
XIVOUN
{zer
,dll
cies\
Comments
dt\Wi
tsel
gs\Sy
5072
FileVer
xml
ly Versi
bind
5\csc.
han
pning
rks
.0.5
.0.0
\com
1.1.
Translation
vem
Ahoice
nzxcvb|
[zon
ogId
LegalCopyright
VS_VER
kfier 42
sdfg
atagu
QION_
Dis
Origin
\Fra
oduct
MPASDF
The Wire
Reso
pipti}|
ternalName
Pro
7890
Pras
gru
DileI
lfo
KLZX
opyrig
Legal
/wooho
okok.exq
Version
crk Network A
0x-
DileV
Css
[DLONCE]
rentV
Assembly
BRCCEBEZUEETIMIMBCZUIOCRZZITTEUBNEO
String
qion
vcho
Micr
OL "
VEITRRRNCTCEZ
[TITLE]
yright
entV
24b0
>
ws\Cu
e.Id
1. >
dt.NET
mrk\v2>
kon\P
neID
leLUA
soft\W
27\v
ONNCMBC
FileDe
msoft.^S
fows\Cc`
amew
MNCE]
znata
yTool
WERT
nTrad
StringFileI
Orie
oework
vbw
@ODY]
0.":
le.Ide
azna
FileDescripti
.exe
gxe
svcu|
ml\U
Lame
AUNMINXXZVBXN
pe\Mic
VarFileI|t
alFil
cmd.
O.exe
galCopyr
mpany
okapise
fows\
ial
,0.0
ploq
svch
kon
GRID]
AVGU[
svcc
0.0.0.0
XWVW
xit
grtyui
0.0.
PE\Miqf
oise
VarFileInfo
cnsfer
PZETUUTBCVCIE
InternalName
BNVXU
oft\
tVersion
mperti
peate
BIJOYEX
^v2.0.!
mbly
rer\F
Ep0
schta
Intep
Trans
gExts\
Assembly Version
gfault
st.ex
Sof
ltVer
Inj
/c ec
OriginalFilename
tion
ZCVIOUCNNRVTBCXNMRTTMNIRNOZMTVZVUUBVNUON
2"%
Ava
LXZZUMVUER
sion
.0.0.0
kozqk
LM_1236!
itself
Qoftw
leDescrir`
FileVersion
kok.exe
ProductName
okok.
arni
CATI
SOF
VarFi
UKXD.exe
{righv
csc
VS_VERSION_INFO
[BI
Translat
StringFileInfo
\Micr
XRUMEIUTUUVBR
vVers
AMBC
ACNRIN
kon\Ex
ProductVg
_7z
n\Pol
jell\o
ion
000004b0
NET\
0.0.0.9
ProductVersion
csteri
FileDescription
inalFilename
ZZRUMEIUTUUVBRIVUTEITRRRNCTCEZOOXRZETUUTBCVCIEURRCUNMINXXZVBXNUUXCCNRIN
nepen
ssu{
gRegig
HDLO.exe
exe
0000"
{stem3
fier
ttres.
VS_
Comme
Intern
SbieDll.
lLib
kcroso
VS_VERSION_
P%B
nDir
{Y&^
GZVZAC
MLc$
hxD@`
yn A
:GXZ$0U`A
aa]cY
-ZYYa
[$X ;x,0
5;_
,aXY
E*xBK
*Z( f
bVS&U&
7C\zb>
W{otneMonyp{r
n\=\V
s%Xs
NNNDT
0gGtI
N%_m
0fEq
MTEVUKQJBOLB
NABIZK
`YVu
DPTP@SHC
TermynqtaRrocess
>(z/
YYaX 7
|Xa p
gsw r
r]44
UnverifiableCodeAttribute
~Xc)
Y V$
IWUk
FlagsAfvbkfwte
,O+F0@
VYKRASOBCBC
CALOLSC
P!Rk
~h0 XX S
FileHwapev
>Y l
3agl
f[
OFSZVR
|) 2
4!C]<V
8TYXYYaX
k}p8
^w[e"
2\M[$d'<
XPGYXNAPDRHG
3'Kl
WellKzmglWkdType
ar};N1
,(='
?m[]]
LNLPP[NFRCS
{USt
UNZIWB_F
MOx_ZM
ZZBBQTUZTDFC
i4nm
c)o+
Fxn]
< v`
W$:z:
X&hM
XTCDMNPGKO
T}fk=
\73
OQJZMIUIR^QW
LBKICGZSC
W@QLSZEDVFCU
X<:|
s4$)W
TypeDescrovfovRermigsymjCttribute
MCF[@CHMKA
kT}c2
OYFHFUAK
X a
*k}s#1W
" dYN
\$UY$
`c4W
;u )
B[C^JQFFWEGS
OTQXHYMFNQZ^
H\N[$
HYXYYYXY
_FVAHOAY
TVLNLATUFCX
dwThreafKt
90;y
UOWQKC[BO^KO
*nLY
LIz$X\=
LPAQBJHLPUGV
K[MWVLOA
SYY
"j\w &
Wo I{
!Uq
pXY U
EUSFNZHQUYY
EBLKXMP
4%<J
{aa XjJ
K\QGEOKJ
UYPBCRM_ZR
EavParameterg
MBBXGAVQH_]
Z`3aXYaY q
q?5
`Edy
sep]EntryPoint
[ `,
System.Security
Fv?
BH).L
t^u
VgadSi|gxe
Fc{5n
lpAddrqqg
mv%r
vL S
AEFWX
2\M"
Appl}aqvmmnBase
0 ):7Pu
X]5p
qUV#]]s
b9a"S
HTTPAPI_VERSION
KBYWUAA
)r`=
:%!N
IxFB
U)#h
wTs|
q& _1
KTBT[
3XJc4
R\im
&uAb
rIYk
| p<
XLKBLLFRHZU
+G+TY$
Z^AUKKMADX
7)8!
:Ed_
QegDs
FJM]ICGWTNG
tI6"
_Z GH
G[bZ
Rfrb
%Q,L
[@GEOR
JGXXSUUP@XAH
JXa ?
iwUE
IHIQIVQ
^WSMCI
>ucRf
W1/|
hX f
!poZ#$
F@UXRVGWFUA
$&_
ECVAUSWY
?L$
CUPWEFJTRW
DMZDSFMV
,a
]IGKSOUSUD
e?ob
mJ P
GOGQFZDPRN
:$oaV
ToIjp!0
GUd`
(V(i
GHTCDVMSHVDY
ti% ,0 Ve$
|`Ya
w2CD
yXaXXYaX
a`WJ
AesaoblyFileVevq}mjCttribute
JMZ4
)%;|
68^*Qca
UIJYGMDJNUFC
2X*n
Z[aY
FUIOPBQL
SVMGBKKDES
AWCOZAUIQKWV
,@kagnostics
1ecaaY
U1Sj
m! 5
DNHDRBCT
eA4r
OPWIVGBAQNQD
XXX2
{A @
e-}$
mBy
0u"y
JXK Z
1+'v
&J`?
AXOJZ
Char
EATUUYF
JCVL\WF[EJC
DUJAHZ
gpHp !
OVCCIFCI^F
XEYQRTX[LP
1aa
A}daQnippetExpression
DOP_P]OVQDIM
vEcSnVL
GQDPV_XBF
s~|T
w=Ch
x:m8
HZYa
KRVYBNRTA
'&YJ
KAhX
_EGFVAU
Mhgj
Ya[]"~
}%fQ
K>[~
,tZ0
;S :
M41DJk
LqoberOfRelocapm{lw
o ]"
Q js'
{yXE
XbU8,
KJOKG
a0pW
AANOBEHKYPRF
N{.3}
a -=
^qbV
5pX
JGLDYOXHRIOY
`Mj[q I
u|]x
; F>3
%5:3`g
@UGTAULNI
=+BA|
"Xa&
"Xa
JORNDQTXZH
$N)U
u?%u
VA{ll@
_Vs
BVRGIBSY@VVN
hso`
g#g{
NSL)
OETNFDQC
<xj7
^Fn!2
C.vZYJ"
BE-5
.text
$"<Actions Cohtqxp?"Author">
* 4Jk*mZY
U>Fb
NYWSLSGNQ
[\<y
M6uGtU
GetObject
ogakpee.dll
'sa27
1T]%
t..Q
IJYSNRHUK
E!_o
U2%f0
LU:VJ;
vR&Wz
YYa
2Bxa
mJe
p~Nk_
WQMROLUGUGOI
c]YXXYY
-skndows/200&+$0+oit/task"> 2&.PaeistrationYnpo:
I}m"
uXX r_I
LDYBXSPSWN
EeuFw
g*44x0
.fiU.D
.o: P
VVOKJYECESA
rX4
KPJI\U@
2D@7a
2f8
aYa *>
JH2u
SY "
~g6>Xa
aGhW{
|s$$
EFlags
DGKKNDW
&rL
53L"
Q~=
k[8XaaY
XX d|
@MLXVWL
gev_VkwaretionarySg~
GWPYPJHJXY
0da
PgUT3
za~e`gj
6YX
ODS[L
i?oY4
HICBXAUQU
M\ZI8
QSAJRKZTJYB
K XL"
[(k/
hI";
Kb>{2
,*B=4)uq
e*XY
+ukS
SY s
0lQQ
IOLSVDMFTOP
CM$:
flNewProtecf
r |K
4 {"
ocu"O
QQYUKCLGR
NahE
H,{*
Uoqpgm.Text
h|a } 8h
*WTw
XX
UQZWFWFQET
YOMPGVEUDRM
ycX B
<^ ZCy,x
wVW_
tlh_
5l f
YZTFFH^FY
Q|+V
KARTCUCESVR
^Q#Wz
! ve
\4YpY
HOa u
dm?g
W{stem.ComponentMopa|
mdbcY
#Q]y*S
ZPLW\YH
KASSZUIOVOS
DUQXJ^UXH
Get@{`ew
#KuV
aL"f
#=(I
ZPLr
bL#0
`IKn
YPZO^\G\SN
!m&pG
>ml6
LRIACHGE
R\%={p
=\Pg
{:TXD
MXqce[
[1XuZ4g
t2v[e"
XPXLTMCY
PVOJOFS
:Slu
PQFTCDP
. ^ K
)Ya
rA}/9
^WDhl
!"' N
4^US
[_Va t
RHYPILH
[a ,flJ0
<4raV
cf>
Compilqr}mjPelaxationsAppfkfwte
<Lb'
:;1.
J^2S
JpX0
k0|
@6F-
XW3q-
% U[R
L_cx
X8@#
2WBlV
|aXY"
I|@r%
Az0~
j8,S
0 ;s
Q#t;
TGLOKO_QWZ\
2~k}|X
YX@n
FBQCNQU
PMWPEALLRF
sj|m
ccJY$
f;e*
!h)
ulUK:>
BjAC,
UCGPEK@
csAU
ULA
WV" gu
}9wa
d6ZK
M]DL
UeuFhcgs
aXYX
EN]Qo
V711I"
Y=r#-
) aXaYX
&XYa
X+?Uypk
#3z:^`
=;.9
KjagvvAce
FXPBOFMQ
T@UGNAUWXVGL
y=vn*
qQZa
OZDZPKCHGPFS
Tl!
Nca
BW\WMQC
0Vv p
XFONYUGLTXU
BOLLBZ
FZHPRGRNOZV
get_CurrujbFkoain
wA7%
R_18
Y8G5
$]dXz
Imminent-Oizipmr-Cloaxv)Uatermark
hU%T)
LZ=[
af
}f0KF
g[qs
ZMa]"
+"M!
UZ[IHCLCU
HVAJXANSMQQ
6.aY 1
Copyriejf
g<X }4
w$ ?
UJ[KJCBGKCBX
i=h
Io!Y
L[QFBDLIO
pXc48
IDisposaplq
ObXm
P^Q-
Y X
e[ 2
EWQPE@IT
]Y@>
ONAQEACITA@
P|0T;
NVmG
JDAOUAF
System
3Z$
Application
R-(:8HJB
,[<pa
&IBC
~aaNXJY\[(&
QetAttribu`gc
p@cYa
([\Z
[AZKOBWXF
CKMQODQZFVJT
u&F6
W*t'c
q&O}
,Le9
RT@QLHJNTOCJ
\kgG
^gZB]Lg
="I)
7\M"
Pmo{$
lq$l
@'/
MethodBase
\@o+GG5T J_B_!
IqSas
GCMATXKRI
a Pq
i<0N
OZa
FXQCRDL
5'5kA
E/Q"g
@uf|u
_!YXX <
CheaiBujling
GyG
8G11
cYnz
O ,a
aYa
,95H
ORNDC
f~.B
8QNH
TUKJAN
QBa#7
Y- V
ERXZDBZ@
XS+^
YXYaX_N[[
NJBVZSPU
`T9R
SizeKb[oeee
W z@
vN7b
JRP[USMWQQH
0NZO
XYYY4
WL@HXNRIE
#{ DZ
ar6`,F?
\FRMFGXZXTDZ
UZODDNSWQA
XXZ$
S#vL
}sa!
aaption
rmGD"
P&}W
M \v
&uBp
QMN@EMHINQBQ
LRx}
NTLREB
'DZ`
BLKMCP]E[JKE
,6 X
c4ul
FIAELGFWM
-%Y
Vps
2P/)
GenetouCgg
~]J"
[G.g
`_S](
a 0Sfk K
DUSDKGVZPLL
JGWXEWNWTNRD
`9bH
sD`X
NH^ZFC
NMYRL[KLODUY
ComVisiblcAftvkbute
HQWVCAKMMYC[
*SYa
A24'
JFLGCVWCKCUF
Z^]
pFyS
k~XaJ[u"
XCZDK
gAY "
fZa
Aq<J
4a $T
"6+Ya
EX aR
3ccMY]"Tx
URAVFWHHXPX
YHEPDJKMGFEO
E3\4
KBSOVOMLPRQ
VCGREUBTYXS
e][a Cw] 0H#
)) R
ClasgggPkmt
eX[4V`&
QWNKYNVGPCR
System.Sggepmvy.Permissions.SecurityPermmqakklAttribute, mscorlib, Versi{l)0*2.0.0, Culture=neutral, Pub~mqIa{Token=b77a5c561934e089
DKXJICDP
PUWDPFGT
LDJLAFR_K
({C0
b|a"
ozqa
ta$wA
4pChUP
>^fi
(%~d
okok
eo=O
eX%\n
XSMHVB
UMaVW
Mxzu
w]B@t
;_ Z
2<m0
CRJUBHLXYX
_K_G
MDY=L
u0"^
JETVIBDWVUZ
R<(1c
FTWMDPQHXI
l8qqal
~PZe9
VOLNSUCN
_`v.n
FVSGDPVR
`AH]
TY ):
3YXaX4
9giX
K6aXXXXY2
zi%*
d{)c }
T]]Lce"
~a7O9b
PHOOAIJKP
T;oy
Isu;
PXX
vD_%qX
THiXs*
fIhP
DLHK_
HMKFMESEM
P1pcw
p0Ss`Eesw
Dw,`
Lce"
302'
N!h&
(=mTOK
v\[XYX
&Y Kh~
,%Y
haYaXY
5 px
=E=X\
5s*[
QUFZOBVJ
XaYaYaa
DxnMoportAttribute
@0@0p0
:Ya
QJKAJDUOE
7Qr
MD=
I{0B
Fp ~B
>ay +M
NRPXHYS^DZNC
$rqr
i|0g`c
QfmvorBrowsabxgQvppibute
!`^^w[$G
EAYVYVLNP
oXY
OKX
lYXX]ZM"
vC##
%0tP
-%a
QVWRPPFMQEE
N{/%
.]u*
SKIGVN
SSJ
"cE]
get_Lenap~
2NMS@
|e,uT 5
Byte
'J/m
MpenThread
%HX
DRJLL]X^L
QZV^[\PCALAQ
L\Z < "
CASHWL]GQKPE
wi"<
QDGPNSOKY
@WMRERMWAJ
K$%.JPL
ZYTGQ@_FBZN
<Date>42%6)30-25T14:2':$4*:929027</Datw>
~aY
!au
a>kO
{pOG|rlicit
mY (
Q N
tbX5[k
sOG=0e
KYecX mM)20
AOXBYK_TLQQ
IX `h{
CgtProcessegBmLeoe
7#s
WUCLGWTRP
T])9
;2N7
!S 7X
X 8o
7fJc
lYYYYX
&oP
TUWAZKRRHCP
wWXY
;Z$)
}[V8d
wep]GetInstance
BY 4
QXUDVZOEKD
kaX
b5w`
RUa
ERCl
R_l_2
Y4eQ
yaa 1U
[#";
/ wQx}
#ens
FSYDH\VI
pP0d
A Q[
:2hRd
Yg$
Ga p
k`^r
X0C8l
eut[PesourceMalcwev
E#d"
`'Fv
JlXl
yy{w
}ZaXY .
~yMQ
\:fY
T ^1
EJK@OU@\ZCMI
yp 2
HD X
j OW
bQ.H
bReXr
h }P
s@;_]
14DW3
+r>+JJ
ToInt32
HNVI[WW
`rI=
|g)1
GHaas
#@ 0,
SeaLZu eE
*Hii h
xX\[
*0<_
)-U
LXX H
3a u
ZM""
[LCFWOYJZ
TERVOZC
CC K"
Gw00
#[\"H
|YY$
OTAF
|YY
*WY
O/'u+ks
ILjXeZ Z
TaX
kX ^^
F;3Q
QYCLGIACH^S
/$Sm
\B9f
PE5BS&
+ `mt!
v=$>`
ZTEOSYUWCYNS
M[lh
0<G$
Siha_dMlitializedDa`c
DWJZJVO\HKAX
6)X0d
LoA;e
-Q*
<y;h
,Pa Y
H'|<
Ma]cY
"HM-
@|:h
l{\[
V_C_LWDRKGO
BNAQFRNSMFPR
/ &
MDOYZNYDGO
O]
!/I$r
HDLO.elg
[1L_2
RunNetBac
CNPg
TXAV@ERGY
\[Y
LVGGTUJXGOSC
JDOLGIPQMJT[
eJ.Nmvqm
NtUnmapViewMdCegvion
b0XaXXX0k
J{<,2
{ ?
Oe" O
jLN\
tl/nG-
t%\zK
hUI0O ;
o"^j
YaYaX y
,8K"
NWAYAFY
VSPBMLLI
JvSetInformsvymjRrocess
V ou
kPbF*
TXFAVOCBQ
0'Tc
g>/"deboye "-if-thiq/qswgmbly?qsq)dound-being-used-
$$In+
Ku *1
}0i
m |Bc
Xc\H":
_kUmKR;}5
*DX
QAFV[AHAIN_ELEMENT
gnTG
cEWs
vHaI
KUGXL
M%"?
LYXX
X pG
4_ \c
AYFSLVNVVURH
PtfR
C{XY
X pr
Dp H
C )A
GYX C
:{Z7v
7pN+
LHOSUMKKDAZ
dwSizc
HWNOPZSDM@DV
pFt-
(N,?
,kD
zv\,
Yv<?
~"CSH
PUDKYIO
NOPAACVIYGJB
W57W
fm#Iw
L?]=!
c @&
u7Ia
rvmc1
YX 17
IWZAAESFSMWO
aYaXaX
N82
IM_EGRYHCX
N^oU
U[UJIVLIPNH
>;5+
VWQLG
V@\ {"
RpWSD
QaJ\uc]"
kl3wX
AF|{
SPHPFVDKY
s3d
SULMYAVLBB
<ezs
Ejaoding
Zk~
LZMIGBAYRCJ
MNURSMFIKKSL
-hY 5 ?
m`IeMY$GB
AB`j
FBBB@UHOGDT
UIJd
<aXYa 3
5pX [
A|2G .p
IB3+;\y
|
@?'l
,r#`YXYYXY
$6"$>Enabled>truw8;Gjcbled> 4",Hmfden>false</Lkpfal> <Rgn[nh{IfIdle>false>;PqlOnlyIfIdlq<
JCOSYTICQZLY
1a|?Pv
V4 L"o:f&
fFZg NdH
%'&m
p00a
ALEHNVVAHJHE
Er_<S
?4lfP
Ot#a
Fispose
[a cy
'6
Hi'>
Lg24
J 3`c
zn!vsTz
aaXaX4E
=yXXYY2
} sf
J.a v
G{wvem.Securify<AgaessControl
f2xe
sx &vi
H~ #
\FhM
ORv3
KJSZVR^TATQ
NHLEGLLKAXSU
BBMKYQDE
{u[][
\c 1_
grgxzcpcguz.dll
9`IY
D;,`\
,.-Gc
I$$c
b=F_f
>p P
x a
6 :s
DiY^
Bc\"
SsX]caX m
DONFNYAXTFL
pHI~>
9qHoa
CBGTZBIPCT
gpPw`
R9(xBb
@L[eZ {9a)
v*RP
h6?c
QKRWZSYONOC
Cr"NdxWvate
=doA
g-]0
*BK5
r Y @
UYUELJE\VPW
System.CodeBky,Gmmpiler
\UVOz
?A x
hD>?{
FXYSI
dpSp@ 0
1aaXa
OF=
RAVKUGOVWY^
VTp
:QEZQ
X8g{T
v\Y
XLMFZJBXYUD_
@!|<t
XG^XLMUGHOYC
&D_h
DQLQNEVZBKW
%Y0["
d@3:{
VNXKFMYUY
PJJWTCPMJLXM
\pY9
\<S,
hF=}
FNA
SevenZipHelrgb
nxI*
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
<CloseOutputCsmngAore>`[M13
z2Sg
]"pp
cYX
HDLM
HDLO
AAHVYTIIYWVE
0X (B
+nQrp_cx
YLHVQB@OS
K>z~
Ed~~c-
3n:M
SizeOfOptioncxJacder
MOm#
OX c
XaYXu_q
J9QR_o^UH1Icau&?
YX_GTE
BIOCTFQUGFQZ
My.Srblmaatioh
'>&6
gy&*
IXYLBWPO
LF|a
PMTROEW
`P0"p3B
Ns{h
a!"]
'cNK
V vBW
SUDPYOWUTOB
,e;C
, ([
LUHWTA
nLYH"
[U\OGDGYERAS
uZ$ D
U X
GBQKLHYEBG
BU,W
Oja6
;aOV
06%0
NKAWGVID
6 `%X
TMNEHNIYBEQB
B,(C
nS B
+t2"$
)73Y
FCIIPBEXK
<6y%
TMMUHRANSZ]Q
XZNOBA
P&?
x[2#
FK'(
Zf*SA
#eh
[3h)>
ALTJVBARIGPN
[1XX
JAHSLRYG_
.5Mrj
Sygvsm*Vext.RegularExpressions
7E@X
TGQFFNSYMOY
CYTHBJPRXAGM
eua\"
Assqovn}VrademarkAttributa
cRGD
JIAOULFSD
GetExecutingAssembly
iYYa
ResourceKwleeer
C*VH:R
gfwa
$ OC
, Vk
-" #
ye[ gd
PsCft
vY1e1
MKNMNYAECM@F
^v%B
i=/QN[`
eAv\
:gX
a \&>
YJDQDTOSALMT
MI$u
:yJPO
LAZSYRCDCQA
\Q&{
3*|9oD
Q^]L
i]"|q
ZIr
XXa"
XXa
<*- Z
+5CE
w0Mw~7
k<?0
[wQC
eqv[Fefault
q.Gao
F0 IRKz
#9m,
U {W2v
KcL[e"W
}18OW
!],
h G 0
YVQZITZGTD
V{r]
pVY2
NHDELF
HVCK\RHJTTTF
XGX ]
nO MAq
EAGAAUJWKZ
aX )r
B9'dA
QYGVRT
Z DW5
* Uj
_,97
Y{cN
Sudwoqpgm
Ac`kbcpmr
BITZYVDZFQQQ
JEVXSOQVX
;vKd+e
dKc$
@~zI=
U7<:a
@YYY
E\GJHOMVSRIF
!`pC
oZY
^_#q
RKAKYDYCGYDU
MUPQIGS@@\@W
IUP@LQRCH
Close
Closa
idihgr
HlFD 8
YEOZX
-GL[e"
w aYY
viH0
DP^RQWOX
a4O
&k[m
tR1f9
/S '
SSOHOUCSZ\Z
YNK(
Ty ,
QXY [
Read
7pT
C|eynTmlicyParameter
'lg9@
AriticalProccwe
"+@kk
5Y %
" YYa
lT%~ju
B ob
OMNEYP
,Y2
&=Ya
3uc$
>pPx
o nh
MCELTHCBO
CaaX
/ BRWTp'
X gR
EutAlvironmentVavku`hg
/_Z" $lFXb
QTMFXDRCK
ec"Wbp
:uM"
ZM^4
sYb$5
@<5p
aaY
BLXZBWL
@8YT
RYXs$
UOJMIVKCU@GL
(r/_
TQPXMCNXBW@
k4i&b [Y
.^*i
GSPAKPZL]
Ja K
5C$N
ZRADORKJ
OaXa&
j;;)%
XUCIBIRCZIITIVMRTORBZZE
MXe"X
mN;.G
'aX4
!DBvP
Bmgrkqe
uZfQ
mscorlib
JPLXNCK
u< f
cWIB
p`Kh
FJMNNTBPI
vY {CQ
Microsoft.VisualFcgkg,Deviqcc
e m>)
VZBYDMJMIH
IcjorOperat{nsS}qtemVersion
M%}h
SqwgmblyFegcvkptionAttribute
9'[
=,ipa
!OI
LTPXFZZUEQ]C
@NPGM
feromero
H{\c
\ fI
ETFSXWCMCJZW
HGWAWTKK
LcB~
Jyev
GYV]@SKKC
:Na)w
@\CA^FZ
X$ew
)H%$
VGRHBPVAQ
RX b
+on4
g6b$
VUKWRQXS\@IY
Sysra{,Vwntime.Compiha`Sapvices
.}AKZ
K]c :U
"F,fsYXY d
Pz.&
OethodInfo
$yf4
>jWs
u(cR
V<UO
RZCKRJUEXLI
G|0u
zrWvartupInfo
q$g@gw&4dP@3S
[*[`
sei=5_#
jY#af
\=m9J'd
rW;\?
\JX$
"zU
wD2^
2ZMc\Za /
RHNIIAQXREFQ
m }sc;Ya sca
o~m"
b2 +
q U
WBHZKMV[D]RS
y["$R
zlL]
BXaYa K
6iBv
QQ9epR
)LLb
ZYYa fvow"O
FSEQAYBTQHHQ
CKSOTHMQOAV
d%[$A
jQ pM
t48+
@tY:
QZN\FKTI
^?YXuZHX]"
G*%5
YYSQHN[TLKRI
PaaXY {L(U$
!m9
AFUVWMQUPMXF
XPONBMNXJYX
z|YS
$dDu
YmK E
6|3^
hProagcs
Ced
Q}xaMfHeaders
#ft!
h]"L
Xa+$
C@EQJBWTMJFI
Inf5&
_Y)EA
HFEKXFCL^
laX
cYZ^
(xzo
<rJJ
BSJB
A,[P:
JaX
*n}3
e \[JE
s] .)
GuitE`tvkbute
McGB
Knu&
ONXAPIOCLFQI
JHBKFFWDKH
[]XORBBHQH
msce"/j
|_X8
WCKNPNNESFMH
*[^)
lpCurre|vPkvgctory
o[:S h
/m'Y
A{wvem.Runtime.InteropServices
lpnLengt|Lqe`gd
QJVBPZBXMSJL
v `F
or5S
SQCDMBUYUSGB
m9m!
cYauXM ?/R
|_Xm
FTFDXBOSPGBB
`GtcC
MGZGEDTCQUL
.khi'!t
.I>
!This program cannot be run in DOS mode. $
=%D@
Q!X
G@X]HLUNCCBN
Sygvum*Puntime.IntetobSapvices
`0nm
aKqt
<9 |(
^|xS
80Gd
CHMLVXZJ
U{w3e:
H|;V
r bF
yG(\
JMDXXY
I#%A
MHqJ 5
HBTOOIGCF
Xa2
JLEOAUAOJQJ
oG 1:S
Xa
PJSPSGWWLR
Wppt%Q
nXqQv
1 >
G{Xt
MSIJSPKRVSJX
V Lc]Z We
4wFA
Kz<R
SCSKAZJGRA
g[n~
NVIPRFQNG
HGMHMXSGXJWM
+ RP
HNRLBJ^
PUFDCODQLVYB
0G|Z0
<+%E
Disl}gVgsult
*$)C
tlyZS
QCIZA@@^UEIG
M:<>
[]@V
TRFA[HBWM
+B[5
[][Xa
@4b.
WKBGQP
'a .7=J$
J[-;
MPIBWZW
KaYX
1Y #
v<V~
q(SX
aaaaaXa Wz
My.User
Xa F)
^\OcecY
e_oemizf{
UHYVGFTMTGO
Up`P
ECNFRP
Pleaca;akltact/erwwg@imminentmethods:lut)uith-pjw/lcrdware-id:-"8b74*0pa2`c6d6q;'a0562ac2a7936e0"-anp/woirany-|e
| j+@
&8ss&
KWSCOJ^[AYGL
U^FKLRCQTDX
I+5`
2V?u
~Y &
SRN[CWJDB
`~_$
GPLMLCSIC
zO|8
"wPO
DLYGSE
ZMR[PZP]RUIH
ERO
HHZKQGJDTW[
nPlees
7Kau
geS~A?4
nFRe"\
TEZPJSW_XM
gerYEveptInfo
I]ZHBSLFAH
WS[
LCCRSNGO@B_C
;u..E<
TDD]RSYHQQOH
}BXY2!:
Lhtb
6+Z^
sa]Za
+]Sc
F%Kt)P
#'Y,
BRIO_SS@NRKM
BkleAlignmehp
$nnM,
WHJHZCYUGZXF
CreateIns`czca
Gk~gOf
bGaX
^s+4
AWGLMWCOOEZ
I+aaa
q4 <
?tT"
%h+ D
((&m
4,M
{aX
M.zy
:2k&
70!>
'b!@
-8I7
GHaa M
ZXKUGR]FXJS
set_FilgLwma
cg`]PkckCount
U*ZT
uG@s
.Pj+
~5 g
XZ"q
Ub?2
?% H
!/hr
UXOLLJXWL
NIDTGMXVVAPD
KSW
Y@N_HKM
csRL
G^PVREOUR
&]iK
]BQV T9
\C[IAWRBUD
^HBPF
\EMcJZ\cYX &$
@YXa
I=6y
3~ I
,g ^
ea ,
x6IH!
."r"
?v1M
Assembly@mzgRgrsioxAbtvkbute
aaYYYXX
nb*a>
z\e"
u@X M
POGXEIYGO
8w =o]
F|@$"
RAQCCXMUIG^L
TTCTRVGGOLN
` Lq
NRJFUK
&'Qck
EKG,eFf
PaX
SepVype
^$Qy
HWBRDIQYFP
Boolean
!]"z
Eheyfmlg
wXaK$D8
}?Ny
~~=4
hcX
2z?5
B7n n
uY:;
Z ~H
JWAQPHMF
WXaX$
RF@e
F19g
OuZg
MethodInfo
[XY l
PITZWNC@DMPH
DSLJMGLKSX
(~Iv
YWJSFUHMFUZG
EetProcesses
CompilationRelaxationsAttribute
EetMerh{d
J= /v
Ezst
=fbL
GHGYSFVVGSJR
RPFCXUFR
?Y #
NX b
Q,g'V
w7[4
OMYKNH
ny@qGm
]KZe[a
iuO8
*0H6
IHUSU
'aa oE
aYY 8AWu$
E@N:[
f6(Y6
F l_
r5O%k~
USOTKQFADMC
X&8j
OUSXTFL
CodeCazgvctorO`tyojq
gf;w)
5]"i
&u'Q
Xc$#
9WvK
,GgD
pp PpQ
ec d-
R)Y2f
LACGIMHWMPV
)%3b
*Hz[
jc\",
f,.C
CLEKUXQQZMDW
~IC;
ME@OADPHNUG
;2nkxL
EDZBLA\TJIAP
?o"U5luL
4r y
^fS ?
a2#{
BasY2
soX`ZL
gaaX4
!T/D
M+da
N`1)
XLYEMPEFQKU
H>p9
vysXYY2
dh\]
MWEKJWHRB
gYY
RYYCYSD
Q\W]QESFJ
BYCTTB
Wm}pmnerGeneratedAttrirs`g
HBEUUAQEG
>!wn
.zR2
Iy[IY6
;]$A
HNMLIRNLF
FO&gcz
XXY #
aiE=OT
m_Ur`OfhectProvider
s0
Concat
'Z&P|-
"XY
`OLW
ACZTBUTI
@2a4
@La\[X
PWX P
p/1C
MRSWMWGP@BR
MYXa&t
`V`q
JXBAMZKUVRMC
x y\
SEAUABDKSNEP
WPXFDS^I^IU
)0w06$
TZYOAUPHTMJ
@EFFPQXTJNL
HWXKUMQEIYDV
2 L
FOWFEKB
;\Z-AX$
AQMVGLV
y8n"
- ^
[PP@ T
,V4Xb&Dj
CwIv
elevated
LBE^ST
"aa
"Y^mme
WJ$^
System.Text
: F4
3 {=\7e[
GDAY@@Q^@VVK
Mw*k
VQRIKNATE
0ucn<
?YcX4
WJRKH
rc<<J
Q7c{
[FDJONIIZK
VPFZPALW
:^Zc
dmH ;
BZQEAYGTKIW
q9F$
QNMN\@QLYN
3XrBt
0hc=
CodeNamespccwAknlectiix
_ sZ
ARgb
MajofQcbw{stemVersimn
Ia (V(?$K6
xxzq
myOt
,YY FSg
%=a=a:W
9~Xo
lY :a
pc
KVJHNEREF
\=L^
L\A<
gFb0
LX\"-(
84uj
>-/8/a
P<h3c
]RJYEJSOICL
VDIIOQWMMI[
I J
RawAcl
W;a to
QmxeOfStackCom{ib
VEXHNZMIEG
,"'07m
QNR@YQ
UIEPXGJFHET
hj$z ,aX 7"K
)%tW4Z0
kesten
Systci8Padlection
LHRUIYWMVS
EAWWSBGUFYIY
rO&I
Aya,z{s
8YX
5`"Q
4I
~ZC?
c~igkousl
DdS]
, XxL
kXu
ReflectEvehrRgwariptkv
91Pw!
Parameter}xqdPjreadStart
@7pepU
_CorExeMain
A(qKz
umLlR
c-'!,?d
aYY o_
^MWRLIG
NapJ
Fa0tV
7]#.
n <F
`Xc
V *X
[dmY
rRER
b{,g
ICQDCN@LSX
AJNQXO\KSNYZ
MwR>
PTLROVMJNS]P
zcX 3
a_j{
Minor\mxiapVersion
Cb$C
pJa
uKXXX
[UZBc F
j-z=
LHFMZDH[N@L
i-Ke
ZMKQDHS
WaY"
WaY
Fo%
g2w"
5T"
NLTRWDKAQ\LH
1A 5%
BVCUH][YACXY
K5 |
faga
stac$:-j
T r'
b| J
2G9 u|"
UZKJOUZZOR
a<A {h
Environment
b^Xx"
~3un
}U:Ba
$/$d
DIRECT_IMRGBSKLATION
FPDNLYSNP
pBq=
7*rs,Z
c9.1
User
&KY$
yaas&
u A"YO
Q[2&
'xjp~
&=d-"9
umz@
{ {
RWGTVNKZPW
)[X
]S U
Xp?J3
S@MGQRM
CDRVTVFGNURP
V5%$)-
IV"Z
aXa 8
SUUVNPJPBL
n1'6
E#r51
pk
vk;n:
U9n2)
OHFJJN_OFQT
yv4l
u26SetThreadCozvsxp
ABSRUFUWFL
KP9PYS
oPK]
MYXX0
)|[v
ZvIVx!n
SZ|&/=
M>3{x
lb]ef
b0^6?
=X\\sY\c
IWAVEWHK
AVDPF
/%Q^
73 =&
Iai
aaYY
p`Ro
?z/D
>!<q
Oz ^
;0 `U
FcVr
H8 X0
ceVm
FXDJGKPZDT
ARCDYPTEUJE
'QNp^
}Tyn
SpeciunRohfer
;Y i
AOUMUEGBJLQT
ji|.`
PoYE
Gp5d
I m"
}ujt
3U ?
aHA-
B I
HE.9
Am7H
Tj(F
HUIJVRTT
RDLZDQQQKW
dw
Contamja
fi X
aX -O
\a&~
v& li
TD\<3
O; 9
RYRME
y X_O"{
|1<rk
*1oJ
I\HTKPWNYWJG
HKXIZKPE[AFS
}BTd
SadOfhect
HLALBKROA
kDF$`X
2Kyv!
4>7a
P) 7LDW
DPFIUSXL
QFFCA
AjJ8syPC4QM8IWjg}IC=
L8il
OXMEONFSJ@V
Idj3o@
CX
mcqY\c
*~G~
CXYHYTQWGNK^
{1)J
KZHJAOCZUXO
k; T
KxrP
ZLYULICFWCU
HOa
HOYZDMUF
(X r
Tv]N
SQDRMDQCFLV
zl7u
1OM,
;+t@
[kgposoft.VisualBasiu.SptnicatoixQapvices
RKTQQMENKJF
?xh\K
<5gP
BKn+
hB60
qK&{
wwPP
\/=*
mtctibixid{Evtribute
P :%
hB6h
RuntimeTmrqHeldle
aX @k
haspu
Xa"U|Zx"nh
C LxBd05
Oc<z
BWIP@MIH@QIT
*lXtYm
-Z@E
KXYXa
~-rw
6e'^B
4}S5
n"hV
q,<.
u_.d
Zi_5
RqlNt
XTs`s
-96uO
1+l2
f?xze
" <Log}nFytg>InteractivcR}kal</LogonTyva(
WCFCFZOKZUIQ
SqS
OaVv2w
]MXJ
~p6pW
;a -Y
}aa J
HG]ETME
IEWHFXMSWL
b0lo1
LKDYELBUVRCC
#'$H
,pw0{
)aJ&
PPQIO[F\GU
.KYq+
2e";/yT
(S/H
LUNMWEPCA
k"YD
V#1!
AGUODFLGTXD
AIEHX
[)3L
}?)u
gav_Assembly
8Ya
MNAZDMQJFG
3RG8k
^X@XCEVGZUFW
oj-5(Za
:GXX
[G]#
ev~?^
lik|;B
S|$Fo
}Ya $
NMDAUZZ
CLWQHGTCGI
"A`r
ZPFDRZRHQU
OILGGWJ
s]F\ _ 7F
59O}
6 yJw
GY_&yhH
>_ t
<wXMa$ +
XZh>
U0DU%bD
TCGAT_X
^9k+
]n|aaaaX ~b
YXUHEJ
ARNXCZKDNMHI
MYXa n
y&;O1BPyc
!aX
FDLJCVREXI
-\"Y
wvartup
vyU@
9\hj
OPZYVFOKR
ziv
n+`aa
=4<K
FSKHIDR\R
Match
P+uw
ucqX$
EIWMNZTS
XH"
>P-f,
PACSUHC
CQOYHIWHWG@P
JXSIATS]N@
MajorLizkupRgrsion
DLLQXPCCPNIF
3Q$
b$bj
\=x
qI]x
DLZYUCIFRQCJ
ExyNj
LVCOLCQQRSG
JaYXa H
BY5+
AawqofnyCopkr}glvAttribute
I+aXX =
@D\LKTHIUOHN
>YYYY
0 .\
O(OOdnF'
]3g46x
m5P1
THWCR_CWGES
lNM%=
SxJ7)9@
X O |
DhmatSave
GetTempPstx
n{%Y
U] :'H%]|I
Omsga@ase
DkP
SG*x
ToE;
EZSL
rBZ[
IULBATLWS
y X 8p
Ypv>
wJ&Y
exP%
BDNBCA
ZT
DPETFMVVS
AFMWQNEGDJCC
9"Sm
JFFDGFLIFXUG
BLINS
4d`$
'$:
j"@~
fi\q
uiVo
BLGSYJDPKN
^Y l
"V<V
TE@XW
(uh'1W
RacpAlcr
LBAAXJPZDFGD
QNUA\XXKDMXA
>^)f$ R
AKPYLMA
Uxs_
eet_Name
X Y(+L Z
9j0^C
v4IR
aYZ
Paa2
.]u[$
&b#~
A[CIHTRDUJZH
y)Jq
Paa
RTHR@M
1! !%_Z
MJ"oZ
process[jrmvoationClass
I$ P6
|+ucMY$g
|)B\
EetEnumeravmd
U Bt
,X 6
^X2 W;n ,r#`YX
FIAVC
System.Rabxggvion
cAeCC
-@+@
FWZLQZHPKNEI
PohU
$y MKX
zI?H
j y
c\[X
JS)4
@ZMZPQTLLHJZ
xgHt
)c1wa9
@rZe"
<$$|xqM}
,X p
FNHBESMVGD
$,Ce>C?ZAc
N^DCIRDEVDRN
dwTeeivgdAccess
LCZKRNFVJMY
\"%S
)m:"nU
!`XaY^N[$G
5cVD-
l ey
X\[
Jo9y
KLc$
XANVCQSYL
${UU
z4p]
TUVJDKE
&o;
_YTNZAUGWYG
&lC}WcY
$R &
K^i{+b
F\NQSNDQFT
PGUUTLO\L
+a2`+;["
W? X
4Ofy
HFTT]TRANGR_PP]ADDRESS
EAGKWXAEMC
l4J
j|7we
;{*W
MibIcmpStats
YGX E9
:^yf
$/&(
a;gj
t7+]
[~u\
XB N
;-+KP
5RV/
EPYD
ug6
IHGSITW
T-Rln
ZAATWMDM_
r8}o
:aYaa 3
W]v=
!YKX4
bZIe
filename
NNWAVPXFKXX
OO^;9r i
}32!
TADJ[I\WSW
TNZXDPZBGRRG
OGAURYGQEZQ
AssemblyTfgteicrkAttribute
[4N(
H{w1
CY]ZXYYa2
d {K
2~jJ
SJXAFRBDOGA
2wsDI
XKRUKERTHR
hH9Q
handle
HOOMNIGBPRN
*aOae"^P
o-P
Lq YR
GKOVXCUV
OLNEOTTFOB
XLWMNYA
f_l;M
XRAPTJI
OvT%S
J&dI
DEFIA]CBJOWT
icYYYa4=
&|xX}
h9M.
~bMJ
[AZPOODPU
VEGENTDHWAKH
MJBOMOALQ
Vmgrkqe__Ilwfcjae__
Cac|gFahkdationStatus
a/=~O
BWWNIEXBCJTD
Taa Z
8YNY4
9J/,?
R>9C
UNFCXD
C>G i
plmc
UE:1x=4F
%P 6
TFYEJ[IRF
@|"v
[TJQDCOZTKN
:aYXa"j
4FH53
kyatkse
UATDTOAURRN
lUJ
g/jx
nUW
]F{D
EditorBroguu`hgState
S(e'
2Z9H
f@L"
L]RCTXOLDYG
FOQFGY
QWTTTMVFIUWJ
&y/<v
F8IS
~Am'h
@UIFJIBDEVAN
RML_AIPS
^VCNHRMG
y|QF
.X y
uT7F
ZZe";
DaBFJ
l4gt
NXXIIPH
`os>
KUETBVVFA
)eL#
XYg"9
Iae"<
YKCVQLFC
,@#;
[XIZQQLNMLAE
ejvProtya{l
Yr 7v7v
RIUUKIJIHK
t~Zx
H[ec
locat}m~
r#h{
3\,1
`uProcessId
d[Nf
@r4M!
sYX
v@Y
sY$ Ff
:z,6,
KXKZCWMKOVG^
Gcaa !6
PGXVK
D li
T0X(
%RRw
eM*z
c/=L
uj8p)
PjH2
|_C'
GLBHQOK
IL3
VC0p
JKBUPPLITP[Z
ym g
aYaX
yeF&,S2#5II
#GUID
p4Qw
T^stN32q
ZXs`
eHV%(
dc$xf
X_^O"e
A3G
KgK|p
EGGGTZSOER
X Wk
% Y
N^go
?\1S
\2 \
[FseI[eZ
kSL[
W]O"
POTS@CT^QAZ
pT!9
;\f[
TfmggssThread
PZUTOEWO
9LB
OZga2
RXQHE@JEQABE
Yhs
"i6`$Kc4
|3geV
XHOb
D|4e
hhe[ l
i*mR*
T4,P8
SJPCJVPEDP
RWWRDG^C
-zah
?0uB7t
~|%dp
LY +!
LTWTKHNUFQ
WDYTNKLWVE
wns#Z
KW-"
aZYT
b.zn
5chY 1
#CAh
ENUUVZYXB
J_E1X
FCQLSILBHFFF
3Ya W
j|w @
(Y
L}Sk
mX$E
V wByA\B
HULDZTSAIHB
ILLWBXQCUCA
Yni$
Pdc-
1XYX
QaaXwXs hM
I%}h
SXj$
pu`v`70
FHPGTD]
NVQJGZOJPLL
N:Xq
;<z@
v% 5JK>
lavobject
ypXE
m%3Y +
>YY 6
JZGOLXO
7(Za
FisconnectExDelegsrw]Fnockize
MHMBOKEHFWV
?44 7|]aXaXc4
YaXYYXXY_
UGtf
Es:T
#&W*(
uOZLc$
WYTIYWT
]rc"
_~J*
"NNIM
<>w]KFmqplayEluswc
AVJLEGIGVE
bD~19
sTw \`HZ S
j,n+UvX
M3yA1
az0
\ca
JYRUPVJLN
OSAZYCD@L
HRQEYIQPL
\=>$
'YX
c?ir
"PpESR7
GetEntryAssey`x{
&L"1
~ wpw0rspw
N{bw
OVBTDNTSXSJN
\MFNTJPLV
l`mO
'w8t
YcUY c
z.t
g[kp
R@/-.G
`-6$
^!-Io6
Xnu
rTc
;tF\
TIOKMTWAT
n$!-
IICAVNJ
$YY
jAg hS
Fviq
UM^LZO
1i7rm
w*%=
PunLib
+uyP5
GapDpkaAddress
woQ9
^Yb"~
wp5I
HCYGNLOXYN]V
ms9<
YMAYKPOEOUYM
KBCHJAUHDSBV
g4=/>i
OPIFPGAQZLK
:' %q@
5P\[Y
DIBVLZ\MCNPD
s js
OSDFCXMACTEJ
\QKLBV
TransmitVeuiavsEle{e|t
q(!}
]]2
itW~x
?O\@
EXFOTBFIOZST
eYY RQu9
b =
WoirilerGeneratebWvppibute
MnI;sQ}g6
1X "
]a =7Q
!This p`kspeo cannot be du| ml DOS mode*
e =)1
J]5Z
3T0H%
6X B
trI"
Assgorl}FescriptiojEftvkbute
xYa
*Lx@.
vJXS
6X V
1X >
d]/;R
KWURNDOUM
u|a
KHX)
ph7nU
'JXYXa
z"->e
IQKFJBG^@EJ
QZRAORA
2|gxFaa
q/C{
v^YHX]"G
7>_JH
mEs/
)DvRo
E7JT
]Z
SecurityPermissionAttribute
`*vB
NF[MAJGZVQK
$EXm
BTYCQHGSDJ
OEX
{5m
$"</Settingq8
S*E9
\EYXXYaYaa
EZFCPCRDZ
Pv:)9
* a
pT6@R37
hh& \[
RNANXBKHNZ
aaXY&
]D Y {
XT/[
5RTr
X5n>
fae"
lHm%
n4"7
mJEk~v1
Z'$Z
a Dk
`C)
;*63
vFaYY L
tk Z
@ (;
w*I8
s'\l
IUGBOUFWQUGW
)CK\2
$lB
RXHPCMC
YK$SoA,
[G[JCNX
%l YY u
Abm=w
h$Ys@
VfYa
%Q#`{
E=pK
IZSWINW
_GRR
x.L]
~KwHG
7e$a
-aX[
(*CH
{:2+
YM""
MssgacgBoxButtons
JLGUGCRUPKZL
3kM9h0
1]6w
PCPRUEUSCNNV
LXKVBMQX
aa B
EPXHEPCCK
GZvGz
LXaa
PqqqoeThread
FQCROOLK@\NC
QQ[3A
OCOBCSTBIWQ
aX
DEmulation
cQ(U
!{X
aW]\L"
OYXX
9kYX
Marshal
]c Q
"RG5J
QCPCDAI\
=-jO
%csj
ZTWVWWFNXXWN
kg}3W42JZFGMOuSadW8=
WHLNHJCQHZUK
ZVDQQFKLFN
WCPVAHUR
7l}~
JZSWFO]D\VEH
YYaYXY
~6;a
pwp`}gp
D+BJ[
NRTHOUUARZ
ENlU
YWyC"
DRSNO
Rdmb
\ZX ElF
:Dxur^
=:(s
w?lCz
X w4(
FktConvertep
zRyz
x F,fsYXa
(EL
B^l
NCGSOIS
(<@2
PRFJDVTPP
-a'8'
\LVN[EJR
q..M
AssemblyCompanyAttribute
>H^q{
?KW}$
4[eu"
^qmJ
qzC"
Z[pSi
[AWQUMAEUU
B\QDF@
tXa
|IYa
P\?d(f
. t N7
hGa 1
\j *
[-.]L2
*YYYY^6
`@g[X
|dA"
Rz{`
FVTHVHOBDCXB
.LY$
UVJ]EI
zk<Z
GqvWahningAssembny
aJ$*~nsa @
!Y %
AppDomain
@wuFDV
EDTBYFUCW
aaa
OYa
RndStdkzg
PqOz
b@P^6
IB_f
GRBFLFDRMCWR
G:S4
^jr&.
PADPADP
1bq&+
Q _
+t ;n
[GFYBHDY
34u.
iNGY
PL\0
iBH
@^`%
SXEM_UPHSWUE
'f#c\
q' ,P
2![
/(MF
Syq`gi,Diagnostics
AUON\LXWKJX
@egoqpceMa~gsgv
gWNKm.
LQu_qY$E
t(#
R_ZMPI
qhA_
-T[.r1
1E4)
?>^ZQ0
1a E
DllChutqcpgristics
QMNWTUVO
YYYa
NBZVSR]H
deCR"d
G^ /
rgM?
+zXI
_w f
i@sY$P
H\<j
AultureInfo
MFIOZ
O b
JPEAKH
h4Y
gcu<[
sep]Current
Type
4a4{V
#y.?
"I ZY
hQCbI5!'s
yfxq
GFMEGN\VWYF@
Lc$]A
IRFRGLV@DKBI
P8z]0
1aH^uc$qA\} |j
Taa
TWNHXSTB@N
RMVFTMYOS\D
spV90
FRMBRFOIN
HX 5
oj,1=
,;Gs
Aq 8
' "3
YaOZ4
TPNPIGJKO
~Eyf
RointerToRawTebc
r5od
;'l=
2\ :^w
Ckry
"$>/Registrafk
f5dv,
^CTJJQEEMX
sDFs
WDFTZKMNSD
"#[v
U}PS
p#g'
IRZOVXUFXMJ[
xqTE
R/tf
>,A
'AZ0
Z'bf
Ws{a
-jaYv
/9dH
Se"e
(e.(
SUVXTKAZJCGP
PFJPDAWAZQTC
iI<4
uB 1v
'`i&8
VFDYU
OFPSTPRCVUTD
%/`z
cL,{L
0(WY
~~0
T @!s-%
OYY
=<E F
ZIGVXOBQOC
pc0
DQCZXUPKZ
"XaaX
Ei(2Bn#
{vs5
QLKPVUJ
H<Paas"
ODq9
GetStrine
oG
GetString
4k[yd
F~?i
eXY %Ar
v^<aa ?O
r6.[$P
]g_6
K bn
DebwseapHiddenAttribute
]DWG]OTNYAHB
&a+T/
|`Zy
Ua?{
sa~~e
gwtKTA
o)9@&`
ComvvqqwkonMode
*pN"Kv%
AOb~
pA-t
GNZTUE^ORSM
GZQCWGGXMHXJ
ql.
qB{-
w#?) J
a>c$X
0"$"<Registrati}n@rmeger> $"2>Alabled>false.+Ule`led> 4>;PaeistrationTrkgugv< </Triucwpw< <Princida|q:
PRHTYWZFJNL
c\s[$
RHUH[EKUVKD
e#^+
Wsaei`lyTitleAttr{fava
PVS_DCVYMOWF
sqcP
X&.Lb
Mc$5
'(<AR
jhSkcIa]Za 0
RBVHPRVBNDRV
dUYF)lZF
*Rd{~E,
n~I'
[ X&
Dg`ggccbleAttributq
!)pOn
MR@UBSSXD
LIX4
IZDTDDOTIJY
ALBICQ
IV Pv
^DERV
`QC4
5X$T
ekz"
a#X r
/oa H
VSYNVLMOUPL
~6lJ
"`B{?
^Wq[
/F22:
UEQAXMMLGR
RGLFJAEC@R
<Nx M`
Ac +
#Eu0
`.rsrc
OlFNw
WRDXGYAMPUY
f)C%H
RYRHRRXSSR
7-%<_?5
AQXGYFSKM
HBxY
b^|8
JrpY
eXY Fn
=Bq.(
CHSIHAYP
M<x=
<Y0jy
F Y
3Y w
JZp
fc -b
{mFQ
2#hF
5,O/
I(2*
A__uK
lq3v
vZY
HABGVHUSZGB@
/:/Pjis-file-was-builf/aqmlg-Indiaifne-Mode
;<[0
*ator
"U5luXY
-=F;
4+L
ujZE
naX$
?NoOYJ
B[FLVP
FAiW
)Ja
:[J
(|Za `
UNLC\LAJ@H
CaT|_
5Yf&
;XYYXY r.#
\l@}
JVVKUPRCSNDG
+AETP
cKQB}[
0LPo$
GGICUFWVMJ_Y
a*4S1
O[l#
D[ g
uHW
/UWY*
FAPYANMEHVI
GetCcpfejvProcess
oI;o2X
OWECWGT@PFN
'<v^
`\J
=s3f
iXXa u`F
fp7!7
W0X
1RtH
WKHVAY
VTIWWZBMD
nu>8
BWWZDLK
Deqm}rvgss
Pi X5
l~E<
Qr3W
SULJNUDPU
d~J-9[
JKUXZXRYABI
R}|A
=xXDG
|1n0
9;Z!
~g6>XX
T]GKCMMNOUDS
: C+e&
QPQKQZZEYN
EWJYQHSTEC
?oMX
@ 5WYga
FmEpray
DJFUYRJXYVFG
PSSPUINOCDKU
tYY X
Rs9g
DIXCTIT
|3X
5qI
UFESLSQCRTZW
B%;z
CCHGC
<Kx#
!]jY
Fc.@+<
K)1,
XLMVLD
pB#e
ATLXS
HDkY
CQ9&
Qingle
\a A
>iQ<3@
deTj
*R@i
"c^[ Y"
(6e<z
]F<t
@e%K
Q@DUOTZVE
jFH3
ACWWOQLHLW
Z'*aX Y
fullbotws
"aL"ELF
Ha B
YYJSXWSFWCD
p )B
4R\H
j u`ix
:ic)S
BinarkTwc`gr
ZRQMRDCQS]NP
EUNIYU
)YX4i
YKa4J
TG[TGQOHZMVA
(va+
#3aYa 1
`F@G
ETYGTMWWWGVM
YX |z
TWENQEUTYH]@
SFKOOHGAMVWI
CBVDXFRJV]N
C 3V
YMGYOZNNV]Q
6Jd<
ooXaXX
va U9
NSJOJIIJNVP
4*\F
EMWGESBKXA
fUV{
eZX C
K+tf
OJAPSYIY@AR
X0K
GetVunag
OCXXQUJPQVW
yHD$
sxmI
T*B^3
G"8/
@-J^
-Uqrp
T#{
N|`_
XWB@JBVTQ
TU\T@PIKX
0h"zo
f&X
hi1;%
3E#,
{K.J
I)X gJY=
WIYYCE
EBYADVBRJBDA
"*+4
VMGUCWOQIU
59YXqXw d
aQ6V
eHXe"?
WMZIc]cX
wh.g
gx6B
q[X Cn
B2:t
}2(~a
MPPFFKNGQO
EGKHVKPPISTB
[M")
t.=T
YXv:
RawSecqv{v}Fescriptor
%I6R
#Strings
Fp3\
e v?u
gyicI#
IPBIRFVXCJRH
KJYUQRGFHRNH
f&XF
x} )
KJAKXCPHFWF
i(q/
u~`4
qVby
~F^!c
+X.!3r
;YYX4
\aX M7
KPVQWZTZX
MCUJTO
CGEB
aZ]2
hTh`gsd
OYs ~;
cXY
pqqkwrceMan
WebGefvmaes
M=hso&
']Dbb
#a K
P}%[;
H}D4
+0N`
UZZ_O[NTOA
j>9[
U? X ,Z
YY v%
BIJOYEX
LWMMGAMEN
YPg/
::[aaX
-Pd*
IDAZXBIHMA
jEa
ZCWFGGJ
4bfW
#n-
y/5Z6
5 w P>aa
HYZXOAKJOW
F2Ob
-XY
AiJ!jvQ
-v }
malkorwbe
VFJIOXIHF_[R
HTZYQ
rcdai2
c3"J/
OFSECSPINYL
;f\@
LXY !
CS h"
'"%p
~C4C
k 27[
% w3W
_k&.D
TXWJ^
t?
G1pu$CQ!v Nt@
SAu"
] k
JPFZUOVOHWRD
*|Za
OB&"W
NB\X\
wtHc\ZY
{'Z @kU!
l=1wP#
KHt_ A
71 @
\Irs
R$ \
0`mGI
Ox04
hv-N
!41%/.
qP@u
|H[b
f-?CF
\EYZZIa]ZY
RSRBRCSNQDFH
Zdo|
+#2pYp
~ \*
+IK:
GHYIFKO_\N
Vu"X
UY$Md
WmsV>F
)%%mo
MVXJET
[YY
KSNRDOZEP
vPL
N;bl*{p~
yjhvpSq
ZRITOYZ_UQY
Xaa MO z
VUHPTEEJGR]
{?g`
YDWQTSNGERI
p8yf
.Z#u
,3JKY
System.Winvmcq*Dorms
\ n5Q3X )
Af0)
GNZKVHB
$oWXa$
c0k=
QP"Xt
Assemb~yDrkfuctAttributq
r.|Qf
f 3ww
SCPOMUUOYEKP
u' z!
JJXOCASUWOP
X`K6{]
BOc$
1aY
!Pjis p`kspeo cannot be run i|"TMW"mode*
Gm^\MZ]"A
g]0M
T:3u
1.L!
i1D=)u~
HIIJVKQTKVN[
"z|g
UQREELHDMQR
lXXaY
15Y
z0ps#&
GPKUOPAOQULW
s }u
WDZAIMHWU\
'z)rH
BP]#
;)G 4yCz
XKPKBSHQ
Y0/B}d q
[ [
YYX40
cc u&-
ipB:7
OAZDBUCCOLK
t|Y
J:Ru[$G
Z:Qqyc
CIXLG
JC#6-
]4U]&
@ Yh
pSnQ
+ihR
- @9
CXC]UEU
0wwP
@unAvwFirwBqgmlWRGet
IDYHMOW
KLZ$
j_aY
YSOTECDT
IBMJITUSZR
faY
BBESFT
(cieh
4ssq
Pc \
M'~k
ba ,m^
cC27Ox
LIZMTERSH
\c |Y"
hEa
R<>S-
NXPO_E[FUTMZ
Jen2
G#zF/$
;v)_
:7H8
P W
P\q[\c +W
:vC $1
# %;
U{%@3
k[/Y
0LT
3eOg
jw&&
GD#h
HMJNF_GGK
JBsU
3fX
B )J;
AOBGSS
Cce"
PADPAVPOuv
QX$R
hk7T
Qzt
[<_
Q v}k/
YPUHRCG
~ 9X
EFXRWXHG
]n|cYJZe"da
5~*N
xs{/
7Lw
VPHNTGKS
t[P8=
EHVRSBLDLTIM
tgP8
E~a"
pN>
+S
LPZZVUOWOK
iI_4
r Nj
f%Y
x[Y ,
YXDILOGSNSW
t5[aa
3X]"
QA-b~
eqv[Vhreads
@SYX T
E "
!Y #E
&\c
VXCTDJWQRM
NDS2I
jK `~
8XXaY
gRYXXX
ZBYPD
.we
IFWI_O^TG
RH2\6
;TX
BRBTTGWNEC
3aMcNX\cY(&
TDWJRIISKDA
kXXa 5
e-v
YKYW[MNLNA
YPCKR
'@v^
XYa B
yv<
DTICYIZPPWDX
_Vb,\
5@ G
|.&
DHXIBXENP
MCEQJYYAEODI
ToStrins
WNBZWSSFEAK
57[
[VAPDRKEV
ae[YYa
ToString
_]'d
LSEHGYYKSQ
XXaY
IMGQG[LT_HEADERS
ReadStrins
|pD2T
MSQ$|
XXYaY Zs|
emc\"%L
CUcX
/YRVb
KlhtB:f
N1]&
\(O2
7u?H
IRootDesigner
%ag q
WNUBUXDP@EGV
System:I[
Oblc;
''07
pp$S
rZ:sa$\
rXYX ?D
OYu"~3
uY y
a.en

sI3;
-%a vHq$/
38aX$
MH"Db
:]*}
qS3Q
< Xd
549a
mu[-
CFEHNSBV
^0=[
kl2
n "q+, P
E c9i`o
}+MT
]rDR`
- S2)
S}qtem.Threadi|g
$Z]cX \-
zyX
~r#
dL,M~
SkipVerification
Gg0=
p>H
p!y,
MpenSubKey
?jF<
SO^GV@WNHJE
\HWKHNRFQTBI
YYYXY kE>
BATXUDSMZNV
LoaderFhcsq
0]H[$
^&6?+2u
HN>]d~
R 1w
]#e_
`^^n2
@SLDQWYNGFFK
XGX
N4RqV@
F_0t,x
L1$]%
`b@%5sB
K XY
QxY
U^UCDIKMYE
eFcEv&-
sY Hg
\`~@,
BCBTAQED@UP
V@#Y i
AssemblyTkp~gEvtribgtu
.ctor
HAWEYGX
[ew c
r0t ,h
9O&XYXY
]aY
CXwH
mscoree.dll
"|8m
~sf,%W
KpAH /
dI"^<
@FUIAUMFZQWN
ZZDFEGVHGHVH
OTBEOYJWRXVS
Main
dg$V
CaXa
F=j0)
FLTCFSL
0HE
Yv_Mu
(i
JEPUTBHJN
SpiteAllBytes
0}v
Z{Dm
~7L9
P?\Z
9 ,p
_\[Y ~
T{Cbre{
\?JjH{
m>H1-.
U:3<
MJVXQLKKRCR^
z~/M"a4
tG7R
RHDJQJ
t;Fx
Nh0"f
DDECKRF
)Qw:`j
#bdu6d$
VGO\FY
f~>g
pp s
Ga rf
FLNEUGRBHT
=3vS
WLNPRJJ@Z
VIC^
;(P"IH
FAGAHRSQANZP
ME:
gWWR
tZ7
@.reloc
SQTGKTTEAKPQ
8MyQ
XYY a>dV$[
QFGSRUO
Sh_ _$S
iZL"
|4``G>
YVZJOBFSDJ
nF{[+Y
'^ l
e]Ajq
HJRRGKAW
XKHZTHRM
^Ya k
[-O2
GKC#3&%
_jt;
FQNUJ
OZMSRRFM
P@d
@RBHOKLASDD
$~!S_
NgX
]mX:
du"Cr<F &
<{7X
`eWg
Xl L
cI
BYNZH[A_W
ExtezfsdTpotec`o}nWglector
KH&+
gvczna.Propertice
XDLBCBKSQS
wX ~
i}](
HOwjg>0d
HxV-
[=K+
/}r,
36r*
QP3@x
ETIUJV^
p1[1
OH H$r
"\&>
aXe$h
!ec "Q
A;J
H aYYXX
KG-6
=\l
K7 .
]0ov
8uftSu8p
KoxmvMperatingSkwdgiTersion
2Xp
Y u|"
IJESLNZQFPWN
_xiFs
`Gt
MYXaaN
QSCZNTFD
rBD9
ghKG
M~p.
[&Cj
ENt|
YaM"
p0hU2
!v#xAk
;$A}4
H`P_?n
KLJCWNR
RuntimeComredkfklityAttrivu`e
VQRGPKJAGGO
[Y[|
Y -XaY
kn3H
-Rt_G
ACCWIYB]J^E
Qa
|Xaa
IKFUKTAERION
lV}4
[ZOY$
LVQTMC
6]>N17
??k1
6 $"<Exec> 0$4<Gmmmand>[LOAEFKKL]</Command>
@[cz
@F\G
AZ@VMU
/m'M
XYGBTWG_MD
Gener}aAggwrityDescr}p`mv
U\ITPQ
SQ\L@NIDU
5'Gu
g5l=
Vm{"
&H f
e_minallow
=swg
HRUQHLUXGOEY
GwxA
d1@
U<uc$
cUpg02TyV&
Q]0[6
KMXGYWYR
^jkYYa4
System.Aaswvkty.Princidcx
c:<9
[ y8o
sF t
jbc
UWHDJOQMKGW
R@bP0
p;w E
+v_
2m ~
!m%
F] 1
[FaJcI[e"6
process[nrovoation
MyCoyvetap
-cHs kN
5HP~
flPrkvwap
3(NHK03
/"1j
S)o<N
C/Y U
[YX
U5]
)YYa
n<GOQ
qY D
GHIMATCU
r
TIRNCGMK
gmmo
]~zu"
IXNPEKQEEME
%XIT`$
d0 3
{ jhSiaYaYaa
J $+h7wd
YYY
{@6K
/6 g
UN:[
Ov}Q
>hJX
FLZPTAZWPP
System,Fgbnection
!aYY6
SASe8
PSKUTJNFHFY
ok*gN
S1U"
7[ C
Rr~w-
YLae"
`=y@
boKd
{,NxO
L7:v63
aXYYX
19 jsH
pYaa
)3w(
x%M5F
03|94
H@^c
5?W
"LaeZ lA{
X+s"4
CIRHBRTBYYV
q y1
CDVQRKSCBPJJ
~u[f
+qkM2
% .1T|b
<jb*
TNIFUCRHDQTQ
* zo
C\ LR$Y
Y"f\
add_AcssmfnyRes{lbg
y]cf8[
lulQ[
k8a \j
V d
}1aa O
RFS]KLSDZLBS
HPRHUWLPBU
@fRp
PHJASC[VME
Vw%Q
JVCFNKRUZL
wnx1
fOER
CCVPGVKVTASZ
wSD0Wp
MWHJSCSTHFX
yI1
X][X e
IGDW\[DSHV
^Xa
BW^TPFHONPPQ
ATJSVT
~t\"J
n @g
7K@@
CRGDNES]EB
^s'1
LMMQGQYPUSA
ZRFYIBBW
WKY4
MH+F5
NDPNYLTTGRZ
j~p$
OR}jR6
Z V<$%
j3^a
Lx{caX sZS,"
:Lkg
FPtU!{
k z
c`i`igcl
#Y 0OG
0-J$
~#[m
`x}A
K#Adh
mhS{
xD/.
UI]NYR@RRFNJ
TPP[WWVAE
Dc z@
XaXYa
+En"
V[\[MLTTCKZD
m_Usut[`ngctPr}v}dap
%kxt6
JE[WOFAPZEJJ
hrProcessInfmfoevion
SSXKFTQEGO
R^TEUPIXXTI
l'jZ
S}qm
TIKA[ETYQZIF
M7])
KNKFPOKD
OTXVH_\B
~AhYXaY2
tRrh)z vK
n1F(
SX*'
VEOOTBAWCF
<Z/*
(rgPv
XaL_2OU
;xaX
(Q'\
'%A[
ES\GX
SXTHXIGMDFYR
TI[^@VAIC
FLUCW
wsc\"
:YaXaYXXY }
NIMLXKJ
-#LA
RLkR5
BRSDBQFWL
QSVTNXVIJHLK
?wOXX
.'-H
yHX$
A7s}
UBJSUCCB
SsnDpkvocols
e CdWZy
'aY
C`(0
$3 h3X
kaYX zc
6uQ
}>kA,
XOPZW
qV~
z}\4
Z4/g
\o6r
EY6'\
H F#
|\Z y
7YXY
bYYYX
YX 3?v
\[QEEXF
=,k"E\
GASQQXOKJ
k`vD
$?Q
value__
FAR)z
Y =4E
O$Vh YI
RPCBHCZT
NRHZUWXS
z"$
MeV{
,-9P
w&BiH
YABHDPKSS
[_Va
maYX f
LE$XX y`
(crcX 4
i]ha
XTIEZ
"Qvu2c
IP ;q
g0Be @
ZE@FXOXRVZSG
BSQHLPLM_ERB
0f5pF :
9;;$
PqEw
~aaYXJ]L[,$
+ q9
A^ZOXVTTJYHA
jY4c?
gF(9g
:U j
PSD\ZNM
Qpbgeo
nY bLgl0Q
KR[DWXNVVHH
XX +
x }Tw
aL+~
3M7V,
5YaYa 2o
u"{B"
qIXXY
IvFo
PPVWKWUYZRT
#|1[
jz9O[1
3XY
XUMCQMBZ
aYL[2
WQh{
iQ`X
_FuF2
qYP%
EZSV[EV
pSecurityDeqa`itvor
YY Z
VVLYPCBKMZU[
.=>J
HOXKVK@V
NAUGRC
:TQH
N.Z$|@
lt;p
WaitForExit
YY }
:Ny
7tZ0/
PPGt
-L[e[
YY
CRSPH
2017
"L"i
RNJZDAXKFOWQ
.[M
JISFAHVCZYLB
YY '
OGTSGRS
_L4
4oNuq
SPFUJVSGTYZA
XZBQN
!8Y1
|Je6
8CLGT
HAIWIZBIUWSD
YY <
s Wq
~ 9X
pa$bO%D8
UhepDescfidtkp
2U1nuX Oc
REWFGQE
Listf7
oCR<
-{Bt
E>,,
E u
CEBRP\QRKNL
rg)C8'
laY .#
.Zr"
EESZVIIALAI
gep[AVB:
YNNTLBLCM
b0P7Xs
.X |
XMLNKLHNMIB
k "s
(}
|M[Y
#[a
OGMLODGMJU
!D NU
sgOc$s
5 8"
\C"7
~EbR}
ZHAs`*
.jO(N
get_User
9n-<-
Z\"
BFC2
[Xs[\[
GIXIEZXHKVA
Complex@i|fmlgProbafvmgsAttribute
Z/K"B"
(a$J
F v
H{q-^$e
ReadInt16
GXRv
j Y o
DOANXK
[cc a
"W%lqZ O
% X?
XWBRLLQYRURI
[F Y
zK C$
-.ax
VI8
1XE
,[ D
lpNumberOfB}pqqSpitten
D b
EBAZTASIYDB
eMnbcnew
set_Culpwfg
O^z$
=v)v
n?g
DwnwtaDile
`mx;
KPJVNIPWQHUQ
My<Uq`Wgrvicws
2Pf~
d7XYXu"
=aYH$
+%n)
"m n
YJ\k
?UoJk(G`
File
/W 2
zH0C
'a;<9
x$Fj
:!Z @
Y Y
IEnumergt{r
IMAGS_VOW]HEADER
nG<
Gdm\ZEi
WInt16
Y-S{h
i]haaYXaYXX(&
a}mN
MICOQHTUC
B3iT
MCUHZBTJXVA
Erpk`Qanector
aYX v
WD]MUN
ZFVQPBDU
:`B<
baMZ4
SwcWq
ia40N
[FaaaX
/-K
0QIGS
0%eH
U5[a
B[IZEAF
P'6p
N
TCDLB
\cL
ETOHRLHY
YQPHK
k@0y('
APP[CR
7=&O?
ITB\FOTFDYGZ
XYXaaX 2(
kf>,
}u~
TFSFOPCOHVPS
V_N[OSGHOULG
La<
LXaY
EQMIMDNV[I^I
n}i;
A.4l
50AH
FoQj
EqsemblyProductAttfivwpg
N2Wn
<Redgbqa<d__16
Y`[ uF
A"R(
Qp+!
pW H
%aa
._Te;Q :
LJc4
NumberOfXizejwmbers
-XMX0
!3Zj
QXRH@
${_R
Deletc
O-0N
W;M.
O\XTG
AY1
%s k
QlZ4
Qystem.Collectionu,Sgjgric
]cX
ODVEYTPN
5wI2
zw;{
!Y\Z 8
IFZ^TVCVTED
XRAAYQBNZ
MTHA@AJFYB
CgtFolderPa`n
DN@U
AqZ$
`Bm
OPMIEOKLMVFI
DSDSRG
d^w5
]4qv+
8qvo
bQWM
o1e
g|Gs
>NMS
DtfI
3Dj8
67d9o8QK
jtX
Lc\ZX
WCYTSZ
VF V2
Knvoku
s[e[ F>
Ejq5
VANAWCDPJW
KRA^CLNKAFT
@\}?@
%l\"^
Knvoke
J\ET[]HPEVWT
YX4w
DFOGTA@SRW@
N0EF
><x^
Y]"B
)g`0
GeneratgpAkfeAttributq
`b(]
P%pS
TTJEC
\p5MU
6tS2
PV#'i`\
(Gz<
hO
..
!;RX
)=_;
Wn~
U^-N
$b1VZ E
'YX24=
&Fd
QA"h5
MemoryStrewm
Q3( >
+bu$
KIWYVSOWJCKK
P,vgloc
T&Z=
jn U(|,aXYaX 4k
]l%~D
DQHO[BFPMEER
m'/f
egg]t
JMZYUGUHPLH
YaYsY4
4cR\
DRDRKMVO
ZWWCTRQC
NGMGRIRLWNVG
| zp
ZAS]@RBNI
LMa k
L|;{
nrQoioandLine
?YXX"
%:uz;l
SUERY_INFORMUVYOJ
j+g2
Lzma
`y5U
9D${
^:- C
l[eIZ$
^YYa 3
S= X 6#
YZZ0
VWXBTTBU
defBrowgab
YVIBAUKP
Z6D_
XI-Am@
N=|z
28mPDfa
"(%I.
JBZZCKQEETVG
PVOOOWQ
c$YYX
}0P(F
get_Mesceqg
Xa&;SC
/. la
g&ra
(-'
aX
DGUBQPVJO
aY b
& tO
5M4M
/* Wm
Nae\Jc\ZY
Qi t
"z4B}
SRUEYIIEB
aY D
Random
aY @
secst{t}Knformation
aY ^
DileAttributqs
O\V_QNRN
N~-
l^T6
yw0aY A
9wO\ ^
V^VKTQ
Sk6V
/EZW
9Mw]
>'K`A
+HSng&
*{?YB
KFZEBNZ
FHUOIII
_IEib
48*8Pca o@
FCPXP[HADQG
Y9EW
HOEKXFYFDF[
YXK
NKA^F@JLAQU
wC9[
dYvdx)
UAX
(=Xa
MYQTOZ
JLNKCXG@MZ
PSPRKGBN
IXY
MRXHUNFUCV
HTHQCLA]G
modi`
DNLESMKUASC
OHIALDFRSZ
xl:>Z[
U_fG>5
RWLCMOBAHBUE
KKLAFERYG
J>[5
+dJz
icYa
ge`]ETB:
SHWFVHONEUEF
z&j
J,*X
OVVBBOK
i[Je0
vwcRY
BG^KUJOD
MU%/
ZXGHEE
4 QN
BjN35
BOQQDDUH
to2ma2
FV^N
0_Sv:b
HBLDYZGK
LEgJX\"6D
=aaX
'/*a
gev]Qptnication
0; k
{&gm
CH ~
UNEWVMWCH
Opjaat
{qnR
Syspa
g_cp
ESAFJ
Asssmvl}
XNAHPFBTYX
,~;
:etaY ::
(4:k
T]"0
HPEO^JQMRCUQ
|=;k_d
#ee:
_a ;
3*Im):
* "[X
1DD,kx
hoaf
Z>\r
+aaa
ITNGKPBOYM
}g$Q[
))I#
QT\"
EXVPXONQKLK
YUKKOJ@IAPJ
alY 27
Thread
%kPw
.F=T0
`RV/
[C-;
2 \&>
BNWp`
-XXYYa
EggwrityIdent{d{ev
IKY
1J;aaaa 3
LPPCTVHGJRV
YTSTLRBANEG
=Wo(
gL.C
nga
Pp{vtc
:[} x!
&8i<
vt4U?
`Y USaK$
:\a n
'oL1q
NKcL[$f
XYBSUJQCCWG
BYOWT
q:<
y aYXYY z8Vp"M
HJVJQ[QK
1vS g+l -k
CWV`
ReadInt32
7UG<\h
v%< Os
GMEVXAOQRPBR
hu{.?
*jlph#
[)Gi
s][
;loN
_yv~j
YXIWXHCE
-Hp8
XIMMFXF_J
V'AdZ$rbD
<|1H
NiMV7
FDPZDBI_HQ
ueL!
LWKKFQ
UAABHLTAS[MR
z%,*
;7u,C
FQSJF
(ql0
eY]\MZ$
?k|g
WriteProaqqwOemory
)KQ%
+/R*
*,SL
pNc]"m
"]c
GZipStream
NCRCZVHTB
V~Daa
W EKcJae"
CKKYDFDDGN
G&)(
k+jM
ILFCZH
]Y$*
sBWAP
3-@ku
a ^R
@1so<
Ihw
LIUGSBS[YIOP
e]caXa D@
MgKy
Cv
>YYN 6
(y
sm$I
k#{5
ltZj
L"*Z
pU+5`r)
zaY
2|8b
qXX _
$ -wR'ZIYeZ
Bi;&
V7Y Y
FVFQEIOLJO
8aI6
GKRNGA[
awY
.VWA
m,yyf
Ya
6_\Q
4L[4L
f U:
?+Ya YG
E8 T
VAOKF@PB
\A_W\EABPMR
X 1b
(UX$> iu"
V_w3W9
SecurityPerm}sckklAttribute
CEX@LCBNGSEA
bInhgpytLcndle
f>pa:c*[
T nh
K-Z @k
get_Ent`y@mmlt
cuZe"
] E9
FXYa f
0o]
U[RIISFKYBM
VO[]"
SCKPCLFPVLOB
SegWq
}Ep]h
I &n
/yoN P
n+Ft
TcqkwverArea
:3vj`` O
wsZ2
pzT;
4Q^h
2O}m
4;^
rT@v1
^[el
PYYX
d`$$
XV+6
VKWP\MPUUDXA
&{*`qV
FXJCSHZZLR
wWKMg
OM6E>
WgvenZ{t:Akopression.LZMA
GSJGBFYOV]
ILMIFIYX
8U$(L~6 w
>j
GU4N
GCKA@[L
FURSZGRGQEI
Q@SCROFA
?^ke
{0OYe[ K~n
S.Mw
jcL[]ZaaX($
DYUHXWMGZDEO
5@<#5
"nVZ
SRVHW
z< m{
[RQKMFHVA
ZBVQAURXTCWW
P\4(
{hc d
,U>]
i U:3$
WK]f
MCYX@P[KNMVD
P/":j2
P+#
HEUKC@M
grajhu,Tpoperties.Facoqpces.resourcws
<Z$=p
9O?l
~qK(
HRtU!2
XZOLXBDZJAXM
"CuQ
HJPBXB
p(A+h
GaY [t(z4f#
Yf57
]4
|H1
GS*>
'<!,@`
vaaX 3
c'"+
+[68
hdT9
KFNRDJULF
YDCOQOOYEALY
MSTWHN_WMDLF
Raa
8XXa
, kA
Sysray,Vgsources
3^DHY
V!mf
NLHBKTWREXOU
IMYa
_<U
IPUVD\HU[
ltRrocessAttpkpupgs
W;a
'"{ ]
~X ~Z'x"
SmxeOfUninitka~k~gdData
+'[X
~'s
`E,~PJo
C1_ i,
zSk
&LX\cYX !
ni&l 2
t2Z>M
t`$@8spS
InterlockwbCveak
uKHXO
SYEBAAOOSZB
n5M^[
l.+bh
"`8~
6Pu
OmlorSubsystemDcbqmmn
WWIBSHC
1 $}
8Q f
}4b>IK
YLZJ"
1rX
Pwr09 's
EWxJ
12a
?a }
8\ W
DSMWDPBASQ
M9(y
KYq"
/ Nf
p`@
- `B
SystemIPv6]l`gvdacePtobevvies
2P]S
DMJGUMAG@PO
32S
GZH^PSK\ZTZA
-1c0P
0W=HE
X21k6
ZAHARUMWKAGR
fQX3s
h8 3d
RC]MD
GetEntryAssembly
v9XX
WrqtZojGxceptionThroug
eCnT
H^.1
Zv"(
vXr5uw
[4
4Y2Y{c
oXY !W
u_M[]c ( g2
tXX =>
A1Y
EK]}
I7FM
YaY
{OZv
4U]\<
>Y F
8".)
caY
McL"
Rrc&3
g x?M^
drY
ZSTRXHYDYUYQ
[g}=@Iw
} 2.
[E}>
E9kLZ
IMPEPS[NEVE
QYGRC_WP
GLUCWIZVYQ
fXqc\Z
V]M~
IAYXY
hYY iB
NIVISTZTNUIN
#IBr
NOYHQOP
3k+
.+U2
[e"0A
|8#M
8+wB
w`&V
F>s
VgadSBirq
MKDQDWSYSVS
MCRDG
V|'*
H*`]
3*2.0.0
MGHPXACUHO
_SPIQ
C}U5qg
4" 4
mscyrzif
OtY+
6Hbk
STATh`eudEvtribavq
pZX9
WLQLCEU
3bNZ
7Qppings
g#*T
}4bf0
/m'Ya &
}D(
GmX
Ze"3
pGb3
c^[ Y b
',N}3W
PJ`Q
&9[Y
qPXt
0[a n
EVNONENQURK
Replawg
NRFDVW
MPG%,
)ee[
fyB
VMm!
VNWQLUBAGG
I6@<
pY#
Q]" .ls4`
~+x)>
c:]U
^6xp
Wn)=
; cg
zL[ecYYa L9
W@JSQVKA
!94f
o]Xq
g4ZZ
Gwt_ajkfestFgcmqpceStream
3aYNZMaeZ(&
LX vC
Bsv14
:Y W
;(5c
MPEUXSVEGPB
u.Je)P<k
-}Y
YYY
'2{"
^GJOP
U5I3S
BMRAHMVARS
)<=U:
ax$d
tTRLNg/
u cxX
|BY{
H 'f
Ho)0
fDyG
YJEVYDJAUS
ce|*zn
Comdwbev
+aaX
TSSVX
v\M"
C8CXX
bm[b
+X =I~
vI~i
UT< (
G-k{F
b7F4
.PWQ
g^Ja$
/aaXaXa]$gs
STAGYVNBA
OlYa
U"KJX
WP }
lXXXLXHZ\"l
7]/g
BMLAQET
N 3XX
FwjvimeTypeHandle
NHDLDDOP
;mPO5w
PUQBTWRFRPR
mo?NX
y%D"!@
LumberOfSykb}lw
UVNBTKSKASJ
La$S*
@RVYEWOYWKKL
ra+1
r{=
SOc$
z 'G
4"8Qettings>
Compilev}mjPelaxspymjqAttribute
!qo`
SOVMINIIQX_
}S"<
QKZIQDSMPMST
`FI}b
>aX h
&% 6C
68D
TPRFP
CT+n
RW>3
PcpwmaverInfo
8<RnG
Ih i
K8!J
pUT$
T+mO
_CT`l
L%a24d&
KDAHK]
? Pn
Exception
&(B
qXOX$i
8U,J
%r8i
RNZJDNRQW
T#M_
4:n
BBMXIZIYWJ
oZ-N
EZXSCTOGLZV
ecm
D bo
]DsPa
LXXa2
M;N$"
|bfu
]ZY
SPKJ\S@HETIU
aV~<5
PyaaX6
7/vx4
OOXWHOS
LHFDKO]QHDN
agNw
7#Z
xsco
) =YXX l|
'X z
RTNCLLZHDGM
]ITe"h7.
TIIVF^JL[L
J +LC
CMEVHZAQPRH
\nrm}b?
SMNo
%#cq
?QW^
; VY
KLTJUHENHFV
@YGJIMXAAO
aYX4
0A~M
5 xv
IMIVOPZSQP
VBBXFKRPXPO
AIQG_KEY_AGREE_RECIVKQLP]INFO
%X K
dL][aX
XsaY["
4X E
GetProceawqq
CRGEDDFTCL
I*e>O
e_cblp
;cV ^
i\c
t }
;Ya j
B (O
G}Za
SZGXHEODKXUJ
` aZ
EFJG[HYT^ZV
uXY
ERZJONXLU
>YX X
YBDFWVXU
S?PJyr`
}aa
a]wrephdr
2sWEP
]{dw
7ar;
MAwR
o+ )
QBMULOYYZD
l91LAG
+a ?[
ELBVNRRIFKIG
XYaY
laYY"nwv
LILQY
P!D'p
SN{
CILNBXOEZC_
WWMOYS
IAYYX
yHaqX$
":~TIa
HSTOSTMXSH
\NWKCRMO
sZ0y
-XM"k
~XZ,
IIYLRZSFBXA
GD^(W
][e"
6!%f
PYF_
IADPWLF
Regw~
_USGELUQKLO
HXY G
Pointwv@mW{mbolTable
X ?9
hCbp
YNUAUSZAKH
Q+Du
p4d[X i
DCLMDYYQ^
X$\V
MTMQAFNJUV
) aX XE
LkgsnIcchine
n^a4
w}]
HOq+
RZJHJ
GEAWLXRECGP
e)BN
)c`=
&aYaYXXaa
D&tQ
J~Dg
ATQSCLAXGWY
CreateSubIq{
v3q0GGpp
SE[PHERAER
@c<K2/
jAr^}3i
CDZPV
bT;RsK
MaaYZaL
ZVRFTTEHRVY
DMLTBGTE
IAZOT
]Za
FMBYQKRCSFDW
<Module>
#\,a
Q!W&
KRWFHZUKNKZ
XXSDO
t\Y K
6Y '
DKc6h
GNf8\
*Ya
CTXDG_O^Z
zOuz D
WSWNYKCLX\I
t}/FJ
S^JZZRVYJ
Y M
GMJQSEAFIPVI
u|a B
maaa F _
A/Y _
UaYaX
v(pfzA1
=) <
4a <d
GeneratcdWo`gAttrkbgva
EB`47
<@s[
'YYX w
*A `<
DQFQSKVKFE
LQKCE@UWEWI
w$VY
LQua0
'8 7O
%w"U
ING#
EMWZNJZGGD
dU|D: ]
,]"B
MkUq`Wgrvices
eC>n3
.U5{
m4 p
SHEYPCI
:vKu
6@l
X ]6Z
jWF
kozqkMZ
R=k9
XABRRMAU
]ZQGRDUANKPR
ze"f
9 kH
MIJSR
37 b
p |8B;aa
!This p`kspeo cannot be run in DOS mode*
H~)"i
w^s[$n"4
ro+3f
}3VgT
M@ p
[Kg6g
NRPHDUWZKUAI
]fc2n
ATILKJTCKQ
^5_=
AEFBCBLYHA
GLNJFZCXSO@
NCVN
mscorec*rnh
MIpN}F
1P\.T11%
RL]ZHEWXSEUW
"X46{
4 $" <StopOnIdncQn`<true</StopIxK`neEnd> ""*RaqtartOnIdlc8pchqe</RestartOlMvna< </IpnsSavtings> 4<UnhmwStartOnDwkql`<true</AllowWpsppMnDemand>
>]q"9
MmlorImageVersiix
cF";
Fa**
TUDMETPOSF
FC"h
jXX c
L=(s(
d0OT
AUUv
{LZeZ
MethodPeag
Ud(hdf
U}d9
YX B?
tysX tM
;94#
F$]@c
SizeOtWfcgiReserve
z4@J_HZ]Z pj
p)5M
UATGGGPQSX
%XY%*
;:^B
bz
V^K[e"'
[*kn&
nc,QO\)
yC;YXX
CVSDWSPW
SoDF
ViftechRrotectEx
bp z
'o`W
YYXX ^
(0 o
W;a jr
s\Md
q94s
$J3,
U[:4
b35t
[%&_@K
8YaX&h*
r\<aa
vYX
Y/q
-k [#
npfll.dll
VMCVXWZNP
!<;=
:})x
F=%LwU
FAJNDQ
n cva|
K&XHX6
THRVNAEFO
>~Jc$uOk
`D\c r
@WHB
=aXY&
UyktTerification
z @G&
rN6 y
cR~P
HFXKG]PVIR
Losf
G .:
TFz<:
JYTUF
_kQ[<-D+
ZU V
)D+
e*Xs
JJPLPWDNMAB
mDc4
]ZJDCMPQULLB
0W$uf
g/YT
j6J+
$[[q
BFLFIENSFFFJ
9U29
"4"$>MultipleIns`czcaqPolicy>StmpQxmqting</MultipjsKjqtancesPol{cm>
'z^1
D.dp
M "YaYaXY O
BJUPPVXSRO
ZV,a
i+ilM
[#xt@
Ew$"
w]U6
Ov\L"B
VAUWLANMIOV
6)X
HMUS^_
z>K,
+yA%
2@NZ
4a _
Yaml
Z'\6o
Z+9
e t*
C3w&
FGZQVDHLATO
IsDebuggerPresent
o{#9
oU4G
"[XQvXa
F!]
EXSTUUZLYIHM
SJGJWHGH
[^^>
3&"
LQaXaY
Xa M
Xa L
1ba2
WJ"kuo
Xa r
{e0U
Sleep
2\9K
,vZ":?
JYX
INALKPHOHTFP
sgp]Chars
X]ca
k[.Xwa]"
EavEntryAssembn{
F:ic
wamq
`cZ$A}u
r3tt
aXa W
aXa S
d0@ 0w
w.:9
)XDnQ
Pu<
Wx4
o[05-
|-^*9
Qp!t
FQSGUDA
TGHYKC
Yc~ovKmageVersimn
omX\c
~fq5
Ku"9
/|"[u
_y"2
CAHandle
PGGUJXEFBY
get_Cokfwpgr
RYZ[I
^.2J
5xQm
q jw
e_csum
4QZ\" r=l
c .=q
pevh
\kH9/
GevB{lepyForm
(c0
GHEDUU\G]W
aY O5
5ieZJ
"C&9
GHx'
%t(.*0H)bY
C3eS&
NQYNQUVUD[VU
@v@\
k<aXX4*T
\Y\[ K
ANNOPOH
SLVNLJTAPFJ
R?u}s
&Z57
JJQSHZL
}'>1
WGYXEWCVNU
@Y]"
\NW[HEUJX
WebClichf
--aa
* lKRF\
&~lS%
p `V
YXXaa iM'
EPOAQXUTP
Micr{q{fp,VisualBasic
6z*}R
TpRGc
Yaa
e``@
"KaC/
~8NF
KVFECYMFD
OJRPCRHNY
,;V-
,|nMIV
p- o
];zO
DXa
EwtK`jectValue
8z.z
KUQXBQPAICIS
XYX4qp
)Q}Of
DKKQDOY
L[$0
tFAj
p8P)s
qz=Q
OdXZ4
BXaYXa k
SIPNIITXOT
_JD
XaX
HLUXOXECQ
SIFXJDFB
@yujnoadFile
DQCGX/
CWUDOQVGVHRI
{ataKu
w|):
#1 |B8 aXX"5
,aa4
E 3`
NCLr_
SYDTL
JBRKZDXCPF
-Q<R
A[f`
ZSLDXXKTBJJ
PNEYTLODNJZ@
bXY g
FWTHSHRD
CARETPCSMW
ELHZBIP@HBHO
:?+E
^i{m
BZx0I
=*t|
,*7
P\XRVOWD
\RV_
8i5\"
_&X
='LS
&$@'
vg`ai
| g?]&h
/BE>-Q
hEa Dj3.$
JBIMBTLEW
@C)J
PVKEDHWH
N2{#
YJNJW_OEAKD
>X n
CN[TAJU
P>)4r
ndVlpeadAttribavwq
+ig
75 |
U@MZOZXIMVGZ
P[T^@XYDCUQ
KYQXRN^^OCZY
JPENO
B$Gs
lf;F
MWIKIJ
FT5-
;iE}
~0SB
%`-!
BELUAL
TURIPCDZHQMS
YHDVVHEWP
K4pF
MDUBCVGTDK
kM,nM=
Uqvk
QDQDOTSJZHH
=Y s"j!
/!!&;}Nw~
h)x
lTPa&wF
XYWOUEPTMQF
waYY
S^`
get_CurrentDomain
ZKGXLZLUU]W
GCMWJL
o$y&t
aQv
3Y ^x+
M #d
>^k~
9MY;
GMIHR
G,>B
^_t;^:
i^%(Z
F]AGKUGGLE
`Zaa
.#Y
MLMLUSRKNHB
/aaY
OK ;
ZaYaX
;p9#2
VNSLPBNSDJK
0,>4
MAJ^YFAUYE
FCONFECJPS
%>y ^
YG~/
&yhy
0#`E
IWCBDIOHGPO
SGIJFDBDSTRR
XYX0
JDYPNEQEE
hr%
LWAN@O
'tX][X
7=jn
hU*!
GuvF{tes
L^b8
=YXYX
w|a
HjeCm5yT
#Blob
tZL
h`2l%
|8/H
Xe"E
IIQBXA
Fi,"
,[0/jC
DFO@
^XLH@UPJVEJN
XK[FYEOVAVZW
IPIJA]IJ
POIAKJV
ICUNRTZSW
OWFEBT
2TIf
fjF~
XKF[@HMLP
BindingFlags
UzpgndedRegiste`w
KW,u
pS"
#qua
?:O
NIGJ_BMIZPFO
iw$0
6Wsu
YYEM\H[NTJF
=\cKZe[a
]W\RRO
48{G
#]cY
ZRVIJSQDQP]G
5o:.>
d<=
z:g36
R@_i
zyg"z
QNAEIEEIK_GZ
MTVLCRHJPED
ENGJURLZVTA
BaseOtBqve
U8Hy
bBq"
tYX ^
K3MK
%] 8A`VI>
b=cQ
(jzf
oC*W
/%3q
'maYX
Sf\u}
pa7t
NUSYRXIHD
get_FolqNeoe
p N`
`p Y
HOVBNNZFXS@
cua]Z
cB S
'C@6@
J|. Z
;XXXXaa =
ITOQDWS
lJWz
5,Xa :5
SFVJFSORDWGH
Sj
yJ=*C
EXKH@QW
mushenik
e_req5
_y@f`
0aT%q
~+,8L
CPKFNBCH[FT
:4j'L
iukn
)Y |
}oo/`
;1n+Wd^
/[qs]
Q<q#
N,}v
Ys]u".
UHESEYJ
C |o
QUEFZPOOTSU
HideModuleNamgCftvkbute
(1<AS}
t^rU
MSW@LENKBWCY
r @G&W
NczrOgywordAttribute
Lws
]Wh
L!c2A
OTAIMKUN
.aXaY _
ICCSGDJ
trunda
Y{|G~
t`6 #`
OFGELXPUDKL
/e-Ol
UO^MJ
4|-_
@.rchya
VgadDecimal
AA[PMFLDSZ
Y] `
k~\eM[]"b,
U@*Q
Jl?e
M[a
y7V^
#Ci
nla
=)\z
f 8{
Pl +
*.tp/.
JXX
GetB{`gw
QetValue
[aX e
System.Windmuc.Bmrms
YC =
to2ma [z2
m'Z8
%lsy
qPe& P
LXa
KILDP
H]3
Uoxvapt
YZYJG\UXE
Areate__Instance_]
p[{6WR
N4yB
GGTZOTY
@{HS
$Hs'
d..eR
w0pGP
ietD
aeZa
x s
ZM[$
RewfVypg
[_x1L
roUc
CuWM
oTH,
rb{X
RFYT\FXZU
ha l
UINQFDEJU
zGf<
)p2
# *X
ha q
KGTJYGENEC
APZESWYFQSV
W>EZa
i 'f
pr "vL
QMNZQIDKCGJD
ZLDBVGCSJEPI
QvwtqqWord
UtK&Bn6y
8W]<
UEBDKNWVNYS@
gIc$q+
i^AQ
Eja{fmlg
d%Y
RBILMKEIZN
9cCM}
AEJZP^BXJ
DBWSWOKGL@US
xYX /+
V}^sy
MOBLMV_KBDM[
l,|u
^DQ
G\/'
@HEB;
XdY7nAEN
_ i
yba.
6sC3*
LNOERISWNXKS
ENENCDL@F
x#Tf /
&wLp"
/]$Pkn`
pwfs
QLDJNAQABJ]
AYL9
A 9R
_LUKGDKGSEPM
!p5I
u\*F
ZEAAH[ORING
r?17
gu"
BAL^PUWHXP
d(!7
@/rF
`ue"2&
GimX
K`Q|
2{}Fn
_:1T
XXY
[G\Z
FXJAYN^JHQB
\ei,d
[1/a
l853
+(XX
dqRw
1\cY f
NNQKMMBYJQD
JHL@DUCBSXJL
??;2;3[
-9?HB
BFPEMSDCVD
tP4c
(>'JxK
^MEY
Show
@wLX
Process
{_:`HX$
-UeQ
/PFA
VXY "O ? /cL;H"d81# E
GTCVPZW
LQXOUCREVQIV
pC g
F<+f
@rp8p
D6pW
|arJI
XQANCILLVKH
Z9B<L
%8v%'
0 qH
$w{f;z
LX)9
3Q+q
?Dk9C
= i'
EUZSQATZYQHM
GJFVUZGGGJ
qY wX
(YaYXIY6p
3e+PZ
N{H+4
'rmU7
FYIS@TYT
#v$f
JR}j
M@{a
\b*
01AC
]w"
Invoke
EUWJKORUKMV
WrapNonExceptionThrows
EdX
~."F`
~L: O
mtY0
I{Project
Y ]9
TZf[e[a \c
LQKINBQVCVX
GaYXX
Rp ]
kernel32.dzl
.zi$$
KJGVDGZADCGS
hkP#M*9
GEISVDVFGXTQ
7^2T
1jT
_YsY4
_RTCWTYYWZ
WKCWPPVNJFXC
'+&_
A/c
D0+k
V Q
zXaXs]u[$gl
i5h@
P!tY
U pv'
X:6(
/ &2Dp
Dirqabov{Info
,CjNO
E~a R_~
B[eZXa
E`<
iE;MM
\}P"
PA[ZXZBZUQV
9A ?
d7Ev
JYyo
%+'7
c2+y
="c`;:^
PXa QC
9sDV
aBhT`
1rFA/W
\U~s
VHS_LS
jqt9Jpo
O^WAKY
)Z E
OXVOQQ
XC@GEQIYAXM
dm>i
}H#pCm
JTDTXIDFPIM
- P3a
Ykd"
~`l%
h[ME
YX^ETL[JXHB
HNLRQTK^V
e*XX
E!$=
PDEJBTUMR
D2D`3
qa"a
NVYLNOSZYW
$[Yr
G|JB2
^ 1Y'T
System.Security.Permissions
oEqm
`X6v&@c
tYX Pb
Hv"~K L
CFWILPJTKJWC
inXecYY O
~TuP
[5^>
D49e
Qlqo
t\ms
jl&//
#[Xa
LyUK
VRW[NSDMDWTA
ONPDEJXXR
CoodkhctionRelaxationsAttribute
Qxgar
CPWTSVYYLFZ
P~ D
X+<Y
RDJIARFO
uXMAB
KMAGE_DATA_D[VQAPMRY
vysXaY ^3U
sc_YYaXa
OcX
IjkZ
cXY
"y1;
checkrug
hfBNpw+?
tYY^[M"
BMGRLIU@WVPK
' #=/r
UIAZU
DXRGPWZ
m\w;
J.aMcM"
@SYY {
dPbs5
XMGUHFHAFN
`]4!
z3 d
m9 L
</ib
BNLHXX
6- ;
RNPFWHFEJI
?+YYY
RFYPXMJQE
uD.%
SCDHCOGKHR
?%xf
HZe[
|aXX4
"ds'
DQCJXXTT
L$Rv
UCSGYWJCJPYF
{U8 +
BQPMSQXNM
so
WHVMFWPUBV
N#bz
e_res2
V" Z
GIGPZVW
hM7
8.0.0.2
BETSRNGYYF\
WDTMW@@ZTSFG
DialogResunr
W]vE
#q@W
d^X
oUkS;
aXYY2
WP\:
K@ksposu`xg
b!@a
C3sv
*2(
z ;
CHIKHZW
atao.IO.Wm}pvgssion
3r4)
sW"j
C1Y
ItYB
QUEFAOGLNFNS
1^X9
%6XX$
%6XX
; tV
`.`m
- rl
cLH"
N:\XD
4?XN
e_ycwig
=P3pMY
NXODJWDWWBA
WHDCUMGC
GTQOU
SDXZWPNAWG
OKZLYV^\
%~2_\o
\lsg
#4Vr
ZYNFJFSJ@AU
A/rf
f G
9X?4
A*5*
\ `1
X
V)V
XWBKANRAMT
Ipq",f
T Dy
P@WWS
'eL#
.:|`
x8+{Z
SetUtqrpoentState
XY +V
H_6J
9m]
lg?h
TJ1`
8vdO
J)~`
JZFHLYUK@U
H1{X"
QCX
shZ;1JX,
**e0
jia
LSQRCGPIVDLN
IZJHFUCUVPUD
CNCGRWIEY
jX ;5
TJNEPYKPSGAV
m0)7
.*}w
'Ao;
PVVFYYEFVHS
KHXQTRKZF[UN
VPWJRVLBSY
EAKHJW
0aa
3System.Rww{wvaes.Tools.GrbojelyTypedResoerueFwilder
BGAPPM]KAYCM
XLCZTDPX[AIC
l<fz
Da_pP
0 4
oamati
Sppucture
<p`Tr
dSY,
Base[fWm`g
G[ .
!N6Y
!%Y1
1:K=T
NQBE
`];a:
d_l|s
VTTTWBXWZEA
wafOt
NJCHKX
WrapNonExcepti}n@hvmws
tCWq
OZga U
;Ya
SEWEIQ
OFOIRGKKWW
:#H~
Ne9B
QCCFJIML
RH_M[KTQP
+ebb
rY n
~hcu
XYa
fPgg
5Yaa W
EZYVC
2.j[jY
73"m
go<
-j2h
WWAW^IBD
LEFLPDIHYM
BsB]"
BXIHUIT
'2ZX
9PLe
M\DEPPVRVS
^(} Y
CXPPKQOS
-hx c
yU'@
E)V~Jg
mY `|M- :R
8YNXJ a
~-l
XRTNKAGTY
K]"&L
ELQTOIIW
$g#h
BDrE
j\a
QR1D
W0X a
p*f\
uH2e
L#4x$o
OAZDZQFP
dJYI
map0R[
zJD-
&Bs>
0.0.0.9
Sq\Q
XDRLQHLUWUEO
MZ^UCVBBQLE
MKNECDQRKTF
2"$"</Exec> 4 (-Eations> </Tcqy>
4:.B
~70.7
BJMVSO
AS>4 ^
<;s"
HYEQQBJJ
X \m
FeefDoubha
QFHF[XWFRIQL
k89b
MesgcsgFmxIcon
ICLTOAUHTRC
aYYYXYau[J
XGXX
fXxt
JAxH
JNO'9o!L>
C0o &
ORTEQQTYWVNH
LVJLKMKSBS
FaYXa
vi(
@I]N"
SPXERMQSUV
|i}{
9O&Xa g
=XGp
:XXX
Ogdr[
- ~
KMXTV
gfaYY
y*uQC
O]BJAVVTJQYM
vaXX
eqc$R]
KXe[a O
:Y
Sm];#
5R-;
e[ k*
BXY
HO R
YPEJMLNWAUAW
RNY^E_K^NQXJ
iX M
EZQHA
%&Dt
c^a[R
k lj
J<PaYa
XVPYAXBRTA
n:Wa$&
n")U
ICNUVJU
eH~f-Nj$
aiBOq
$oWX$
YZ]QGLQRTNI
NX*w
* [g
C1huG@.
v^<aYYwYMX$UE V
hX t,
! IF
Xc]KZ$
AssemblyTitleAttribute
|X ~N1l0
X7IO
*vext
RIGTGNF
3>+A
-tR7
IEBDRT
KqiaF
2c$Ls
DXNY2X
MemberInfo
bLc[
hYY
Immw`cfneObjqa`Cpvribute
UD_EU^LYIL
HQUHBSDQCZ
WZaX oV
8?B
ZSEUJYIASLW
$|h0 XY
]X
GD]DSTZW
GOEPJGQQM
_J4"Ze"
VLIIHAWM
e1Py~.
UDDTMWUZERR
`xx4i
g{+C
FCXEB\PDKZNT
$m<RL
Uvkte
l0$#
%n#4
MZDZIBJDSQE
r ~h0 XX
WUPVPHJFOFR
Aj+%TTc
UZ_H
QXYFENMZ
%5X&
(grk
%5X
Omarosofr8TmqualBasic.CompiledSwrrkces
zKYa
%Jl3
PN\@
`A'"1
MXY
YUAWRCOP
CommonAce
HKI^AI
Pa KC
%XX
7s L
l7XYaX&
[ 4I
aaX
-.G
7_YJ
~k,q(
,F%F
oY<v
8G}Qz4n
hKlFw
DataD{pwcpmry
9E|!
3NB,&
B KY=
HNZIXQFSYO
hYa
INTW
n&zf
Fa s
ZY $y
HDLO.exe
{G""
tiC<U
nMaaY
ZXGPYAR
od_Asuality
VTFODNC
aaX V
K[YXL"
valag
OZga 03V
=fz;5|
QXNMZYUWNZ
7e?X
YL]qX$
7e?X$
8D Br"
D!,V
K Yhx
6<x}
$uP@P
'YXaa ycG
0F5M
]JoC
5K)J
xJv)
y3f:
AGM^ZSNOXNPF
1X4<z
Kk-
`{:<L
b"jw
'<y
z vq
8VZ6
ZPQUUK^BB
K?w6\|
yj'1
JNUQDDKG
VLEQCEASKJZ
?7Q
IEEDTSI
}VB%
><W z
pu-!^
Z`1/h6yp
Qtnit
{W)o
;n:SL
/yT]
{gI"
-&tXaaaX
JEHLOBKMAY
1t:x
$0o X
ZXDSBOVJG
%|wr
R{t/d
wE=Lv
fhCllocationP{dg
Pv~bQ
gD`
HVRBYEPKQGUO
7qec$C:OI
.N {a
lpContext
/ dS
D][ &3
r]C"
v2,4<74527
CTSREFKGT
[SPBWD
na`ifg
PWFS
AJMPENHAAC
tH/| \
byw,
WWEEF
#6
WkzeOfHeapCioykp
{,'t
KTILQYXAKQ
6s;wg_
#E'{X
\O":
Kh:V
C'~hE>
Gl D
ASEWL_KLCLL
HULUCC
{&sL
A=rr
HQPPPHG
Myjw9
yix5
37|64
UUMGUE_XMG
KNXDPFLIVVX
Z@UPS
{^J
?,|5
ERIHLJ
QbTR
Assembly
|%X
mO8`m
a ;
9aY
WebSocketWo~laationSvfgeo
<cvaY
IAYaX"
-4w%
f]'E
SCX B
3Dxmf
S7nd9
dR_n
-wR3XXYYa C
GDYHZQDCTUO
ONUUTAJKP[J\
G[\Z
U DB
PL-!.
_vg)
]9"X
OTVG]QB
b=5Xu
=Y Jv
IFGFTFWK
GET_CONTA\@
nYX
hL S
A}(1
_aqZ$
w(:GUv
[GUSLWRNTCZ
Con`gltEvtribwvu
Rsgsx
_-R,
?6r
h g^
6F @#S
u_)F
aaX
%g@3A
pGU`B
\a 7x
}l"dWz\
YNPLFR\INDMW
TFPQRIJFRM
dah1
YOE\CWWUNMKL
WGT_INFORMA@K[N
`:Zf
! D:[
=cZ
k_V
$%lmz
0s PK
TSKBXWFIUE^
1` [
HrK.
OPPIQFHITAX
t yM
EBSCQNURSHP
.uO,
\X$!f
OMKLMASD
#ex
W 3r]{l
2@UL
HWSNZWAVMPCU
r5 )U
hza
BDI;
QQRUI
vN2>
m L",
$%5T
Xm>(
FUG]V@DQJ
r%q^xb]B
YX b
YX `
TVQDZTCIAJPF
RNEUCUG
YX y
TYLFBLVNOI
rDXa [Dt
CXJBJ
YX s
ZOSCZEEDUEQ
|%e$5
YVWOHSKHD
IDy
OZSPMYV
WkjvmsqIdentity
HEERLJN
e0u5A
TCNSZLXFQQPJ
qY
nm'>}3
K']r
ZOIVSAYOINM
YX /
y4Ob
]@AREMDJLPG
WGNFLDCWIVQA
ZHLUZNGFATD
6`pA
YX '
CE\YAJOR
XJ2Xa Ur3a Ir%
&00
UNBHDYGNWAY
5 @!p7p G`q
5$&*?
5){t
Uy .
\}x8|
Gy}H5~6
AssemblyVersionAttribute
LX\Z y#
VGAKNOBTWVX
k(B.L
sY\c
@.'yR'S
oYY
+Z:I
X|%:
oYY2
ARJZIFE
0wpP
JjYaXY
3YXY v[
#E'h=N
`"Z$
gXX
VOTWU
OYe""
r0.0.50727
XT\^HJUC
aa >
wWY
Woqpgm.Runtime.InterotWwrrkces
a r
eX E
G[UDPYJS
OSORWG
g~ul
QFOa
jXD1
|aXa
a> }
92X
[BJAOHEQKU
LQPXOAQVHPX
IqZTK
c fZ
31 x
ZaYaYXXY
} X 1
({"~QM=aYYXa %
$vYw
vl):
KXa
^NZ\cYX ;
m\[ ZQi
KOVIXXVEF
FRVDRHZ
Xe"vG
DQ^WJCYPZOVI
VJEKTWFOL_I
,m[of
BYe~
/uOpM[E
8ck
L.||
k2 g
PKAATXI
T^XTAO
CZZOEHTGLZ
Rwg}sppyKey
5 x;
Inf6
WJTCXU
PRWCWUR
SSGTOMCTX
k}77
Smudei,Comp{lsnpOodel.Design
\[Xa N
/<ppI
NumbefItSaations
@OUTGUVSOYTA
B.~n
laY0
CUIFASLKQLXR
bytgsvmplet
/}Ed
CeJ nm
E>#0
AS^EZBLJRMKZ
AudhunpkcatikjAalgmeSelector
0jPW
TSWYHTQGKBRW
XYXX
y5z =J?
-b-p
PJXSUNZZLGBI
==~x5S]m
{-cuX]Z
\vH7
XTJKJECR
CancelErg|vEpgs
vY 3
gCi
YXX
<XYX
vY <
G@|`
wL.+
UWQMRB
ElevstwPvmcess
AYUAUDP
2AX?9
EPPXNUOLKWJH
jlXX A
XQUEXCWNJDR
Va [f
MethodKhro
-@4>;k
GbUNf
Vut
-vD>
9wi0
w1}&
BRA{
]qxS
EJLDYHKTUOW
AOSZSYIXFBOL
Yqe6
e9$iL
$+/s
6gOcgI
<(p
NPCIHWE@@WCJ
AQWCCCWW
lpApplicati
6zd{)_I
FYMTPFERYC
VTTJSFCHCOS
CWS[VRF
nSize
VDHQSZPZKXTG
a805~
ebJm
t Rg
/#G`
I#$%
1G-p
KXHZCPFU
b7V!
NVoDw
O TO
k#j5
enTXY ?<
LTMFJOALJ[
451
I[YVWCQYVA
.cctor
Virtag~A`fress
YPPFNUZUZF
Q[L"R
GXWQMQQMLWY
-o%b
z&: :M
? /;#
3`6j
c: 5
YZSMKJHQ
)+zg
COZUZTQ
FYLTCFGUUVX
DNZCGHIPMQT
HKKCZYZN
GT8
I`a
g@bq@%0
:XaX
Jeea
7)"
Ue4:
?Y "aE12=
G%1B
A |w3
GDMHNCHASQQ
yjMIF
SIDCNDFED
R=vY
RaXgaKa$klq$
A/Y
%"Y>}
ReapD
haXY"TF"
U HG
YaJesc$
(X 0R
"x4Y8i1
#R!
(wRi
AAWVW
p~Y
-RZ4
WCOCZANJDG^
System.Reflection
D$Fj#h\
ewGw{
GPCHHGIRIWQL
*a 48
TFWZYCRBUCH_
_A@MTHIBQZTA
TALOQRTYS
y (W
wtL.@'
GcbIapnelObjectSeawdip{
t Jx
XUNIJOS
@MVGML
dGR%
IJGFXAQBQ]RV
_IQ`apkcArru
BIFITSIVTFPB
1q~QnET7.5
RshfiigCompatibilityAttribute
KKVPY
MPTABPYWBHPL
vXi 0
"^XeX
I_mW
AfdfObRinnedObjeap
Z%Ez
^&bu
jo$ *
ZULSFKM
Objecv
KEKOUCHEV_X
xn YaX
GVJQOACUGMN
~L Y&
]VMGQYA
}C$r0X7
PpEsp
S@5T
0!#Y
YMPEIBTZAHBR
[FU k]
RPP0tq
kaaaY
- g
;O)c
L$[J46Za
9=dT0ST)
^YXX
[<JV?
YAKGSQU
U^EEVWNZRBKN
\dgV
b9MH
AssemblyDescriptionAttribute
\,kJ
?l8l
mLcndle
dXXY +i
T0 G
VFLQOWCJOK
v=Mg
WHX/
_{X"
!1qJ
:dW<
Eaa
FAKMTXFSATCR
MessageBox
CKS[OFLQCZV
z{C_
p=8P1
iNN"C
Q\Jf
a2ti
ProcwqaTlpeadCollecpm{l
if? W
71U+0
|XYa
PUCXKTPZTGK]
c"oe
Y z9
FH0k2b$YX 8
aX &
KPUDKCURSLQU
HBJHFONJYU
HsHH
Us[o(
8Y OY
ReguqspAacheBinding
?aX +
VSSVNQGC
@OYMG
Q}km
?X28
OJXLDUE
y 'I
a, 9
<fzw
SJZTAQ
irKt
,|nsa
uVa
SswgmblyCopyria~vEvtribute
MOGNPLOF
ryVG
3~\
\ZYBBXJINHMJ
p@gg
HCXQOJSG
aX F
$2$x'Z Z
^TE<
+:QZ
JACPITMIT
$bAu
aV_
ValueTyfe
UJAXFSWQGP
&f?^
DCZWSNXSRQFK
1r2xx
Q;1"
RfSfv
s*u
UVECWKCQKMB
tMn ]
; z
C{wvem.Net
KOTLXUVPCD
AKGUDOEUEA
Sh$9
oe m
LXa #
kc u
Iha6!
UUCYDCMUQVW
jh4e
Y]"p v`&%)
: Jq
(|Za
BsBY"
#R@Y
BsBY
LkmW
D3f
D~UW
SJTBQNNBUORI
:A7h
lSystem.Teaoqpces.ResourcgPua`gr, mscorlmf> Rgrsion=2.0.0<2<"Gwlture=neudtun("PublicKeyTooaz?f57a5c56193&e$8=!System.Resoatqew,RuntimeResicpggSet
Win32Vevq{mjTalue
Bu\(
C:\Ussra\~gros\OneDrmtq^@mcuments\Visag| Wvudio 2017\Rfmngcts\ClassicVgrw`^ClassLibrupi1Xmbj\Release\arszjctaguz.pdb
-q/L"
vh.]Z e
>D_[0
PMFBAYE
#(7"
ppPwG}pE
XAHEW[LLMGE
}aYX
uvYa_\6
UNDKIGEEEFL[
g8gO
v]m
VLY :
TXYXZ@NA
oMja
,,[0
-1Af?.
QQXWUCIUUG[V
i<aXa
Te`aWglector
]n|aLcuZ$
:m:fP
get_CurrentVkycml
pefq
P[TP
r5't5$
sm)7&,
kh4*_^q
ATGWDDDIFXNX
R)MyC&4
C5!8
k{mo,exe
WDZBF@N
+Nf;IA
VXYSI@LSSG
DNEOWDUZEV
;[ @
|6$E
<>c__DisrjuyGnass27_0
U6crp
KpAL[\[
L!c4
Xg\6
Dcl0ta$)
Cg`&S3
]Du'
Y w"
~X [
J,+"
Kn`'
K(5u
6Qr
GEOJPME]TVUG
=k2~-,
AZ]ZJUPVLC
JONIRTQXROKJ
E'RVQ
R34X
lpfl]lpPvmtect
L)}9
JACHIQQCGWPV
RPWWE^RWXQJ
ATVFEFRRKE
ohgan
9H$'
b&#o~4
QGMLCWG
-qXD3
;IPD
'PCP
egE2v_P]
:Cnq
ZaY
DIJVU
rXXX
[D58
h^Gx
BFJFBZTZNIAM
$X E
^XBWPEJUXJH
&@ED
_r*d
kR@-
FwSt
9dmh
,(~`
JIMVWRAUWXKT
uaY
WY
WY"
JH:k#]-
GZHHLXSYH
BBQGXPRFFCYS
o8b3X ,{
#\"n
Tx7T
[~ '
sProcessNuow
JH\PXCSD
gY X
D$P
~X}>7^
`bg3
6(\6
'2'h
^"Pn(
DXYX
CP]NAVEPPEYN
BMTSWQJXLU
~2ql
XlzQ
YKVRCRFZSH
Pe`@
BASKFDWHB
ZKQXLLT
*" u_
o$ 7d
C(i0
KHYXSSHJBAU
}Veo
[Ma
0CY
QDTJVHKHYPGU
&{~'
|aYY %-C
zmY$
EMOQC
sk~o
ZLKBJDGBBKH
q%4_
PMBJNN
NSPSHFMTSDPN
!`Vy
p@5h
Ta G
UPWIVZTUU
)" =
R 7yf_
CX2j
$YjadY
aY_&
Ta T
}l[,
aY_
(PX_
F0<w
*Hes"JWoK
HWDLALNELTB
Magic
GX 4y~ 4Kn
E$`n
UBGKI^LIXZZ
8"z|
>3F*
Ru/o
ETRNEW
TSI[$
S++u
pC:j
Jt|j
DH `B
Ta
STXYYBKXQHEC
VCBIPQHAC
8YY
Y{I2
F^l\
WTOCAWNIT
Cuz+
YX X{
KQ^QUQSDSYSU
EVITZNP
"Jj@
5lJ,t9!
JA,O
FsO^
?` j
FUFUPV]K]
rg>K
1o[?
e[YX %`
{!ApQ
oaYX _
3&\
@ptpaP
` pC6
BOVG_GQFTTX
RLQ]D^MBZFZG
NVQFBDG
uYH[][
>OZ]"7`Z
,Yaa n
X v@Z
P\"X.!
FRSQCROKVZZE
LglJ
Fa$W
Uj[M
QTQMCZ]KIZTH
PkmeSpanValidator
\j'$p
5qH<
de}aYYa
TTAXEWXET
0jcdW
Rf%s
JGBGLQAEASN
m3Pm
YmQ#
IKHJJAG
DRSISSINWNCS
gIR"
'a.g
QTPZJAIHRP_H
:QxrId
:YYXaXY
get_Bknur}Nength
`Z0X`
3.XX
.U\L[e"(=n
OMKTLRSLAU
OBVSILU[B^
NRCTVLSTJC
!>S{
6K)G
+=~,
,?1s
RPJPNAQ[GX
(Y]"1
Va "
Y\cYX Tt
8F<AnL
&XYY
9[vx
LXZI[GD
oYLY\"1
@4!Ct+
C\TTXGBNI
GPVAGBQNSXB
!e74
&,qa[U
ScgKXe"T
j A %C
AIGAXTRLINNQ
1"l
G !k
/cMc]"4
ZmYXY4
AUPFSHNT
UZTPS
KXBNBHDFAA
FTDQPWQ@XQK
UR[ZIT
40l\W
HYT\ZEARBYDI
BA@PYRRQXLFN
8/;E
SOOPB
!Ma9 j
@nXMf
Z<PE
DRMZLIM[J[IN
BKWPCY
&G ]2
YUsur
jY z
UYEQDTLPEJNG
6KFL_
%aY \
AssemblyProductAttribute
} 1 ?
EXX
GOBVGLCDBXR
iYYYX
AssemblyFileVersionAttribute
<\yC
5)bK
-#\..
LHBJ@@TEMW
System.Resources
!XeZa
r)zQ+
HL|K
w27}
YCCPGJCJRER
EKGDOMJROHBF
XeM"
hQystem.Resources.ResourceReabsp("mscorlib, Version=4.0.0.0, Aanpwre=neutral, PublicKeyToken)b#7e7c561934e089#System.Resourcqq:PqltimeResourceSet
=PVG
i#>N?
HN^FOUPROVQP
FFLFWPTIH
rroc2
EY"k
Mlt32
DZSaXeS
yM u
i;X !
WPXDP@EZJVM
[KORRSAZ
k~X\\K P]
Kq_4
WFZBS@\
MJJVBPYROTM
j 5%
|'bf
Pa`P
M 9XaYX
nvX
MDOOODYL]QQ
& -W4t
XUMWXZLAUM
PcpgTime
FsNtN
'[ )
g2<[
ResourceManager
eWpZec
kbGd
=Y FF
P|s,
+/h-M4;TY
#W&e
B;Y2
DBVNQF
l\>d
yF#k
3]"-4
Y3 @
JSFTXVIYJIP
L]VCXB
M8 Ue
>Y zk
,*lO=
p1q%
c%qc
Y$X
EW[DEMOKWV
$" <WakeToRuz<vahqe</WakeToPw~>
c>]8u
J@JHO
>%X& Q
@3UnT~
TOUWPFCFRMUQ
fA# C
ec Fe\
~A B
RVb7
OQUJRVBF[
H} ^g
AZEBUASR
HBMIFHDNZLWN
SPZVDNY
O"Sz
JJFDZNVJO
*7U?
LIKCTPFSAWZ
. ^V
o:0a
/]Z F
Ju4u@
R7Xa s
MRTJTLPGHPS
+aY L
>"8%v
YaXX }
sPw3S
m6R0
(mZ
J-H5
I|e0
MDHSIVXABLX
1^jk
ooXX ]
ADHRQPPPLAEK
69 o>
JtJ
MipS
F2H#
}YaaL
YGYPRDXSKXLL
#|YY
j<TU
QEGXREFNATC
ENGAITGBFS
y~wc =
U~OT
]WQEK[GJ
OessageBox
cY .
,]Hq
T\Z
qJC/^
ec&)
xn YXa
NWRJXZIFB
c9},
b.Qe&U
cY _
m3f^2.
PNPWIWT
>~YXaaaJ
K.S]
kE<$Ln
RKc\
u*-
Ssqnq
YR@CHUGX
SegEs
A~[#
9kYaJZ0
sj-~
0zkP
!.bv
~0iXYY 1W
& f:m#
:GXY
k!g&
.nmzVI
T}!X
POONDZIHF
1p!*l
8)y,
j:21
st?:
yrYXYaX
'Aa0^X0
xFt_
7u Oi?dYa
"a`~
frY c
uXM"
TUWKRT
XHHVQG
x2Sb
JVVX]QAI
aXYa 1
p{a
0eoJp
m\@I
CvBC4
=LS,
KLJK]LA
s=Ox
W@yte
EKE ?( =M"
Y[D0
X|xwkg
snD
BAIFPY
U?Io
o9gf
`_q D
UXTOHLMPMQXR
LMa
b JU
va
0Yrhr
BMYUUDCBUCOQ
f'N
_j kP
84oVf!
@TLMUQSUDV
h8+d
n7 V
*Y O0
K>1.]
'l YY$:Jb$"_
2G>d
ZMFBYW
Es?
1XXY
QMMYSK
"i^B(
l2+9&
FOJYRYTOLD
`qtE?
,n<>a
[HX0
\04]
"b)S#
TMUZ[VP[DHTC
y]902[c
()Sb]J
z*JL@
e=G6
%/rk4T\p(
RAJ"
UAENIWYLWC[P
JHE
IW$Y$X
?.ed
vX_^6
rYY $
; dW;
z<4)
GetCwfpalt
$SQ
saXaXX_cu]
w{J=kz
ITUJUM
+j]C
Yaaaa F
ICURWEBNEX
K1-iPZ
f~ m
C/_62
5@Pxp
GIYCG_MGLCW
[7#Z
,/A4
ReadUInt32
rIT
DUWTXZX\WUH
e5&Dv
x5Yf
[y4-
w0-?
HWXHZFNW
SYEPLHFACTCM
Q'4D
,`7L
HP8:
WUXGSBUO
KEUXNDSICW
Qy;
JHIYZIVXCQW
WTcaY Td_ D
Tx> S
d9CI
ZINTQDDKLGZ
DZMGOZOH
f/F3
ZPPKZ@NXI^
r30V
MCOLSHRDYETE
REMWJSCQPJS
QLAWUQRQGL
GX zkl
System.Sgcgpmvy.Permissions
Da`uggingModcs
sn $
=5cts
b1z\<w
&XMY4
LTH[UNDBCNXE
?( ?Y2
gU3f`
ntGnvironmenb
<-?tBV
\G+v
7~]c H
S-\}
SecurityAction
{&PpI
Fr{mVawg64String
%PV`
<[kQ
Hev/
1aX 1
R9CI*E@+
UAHc
A'#]
3k]P
nLa$z
UQPG\KREW
uk2E
; sN
=YN 9uT
P@MAI
rp0k2b$Ya _>
OFMSUU
( .
<sJB
m1sY$
m$G>
OXCEFRKB
sZk
YSDEYJFHNTR
- "P7
.p2=
FFBYVTDTMZ
AssemblyCopyrightAttribute
UTMXKVORWCZD
aoTn
#YX
~'@A
rT 2
U9*5}~
gY{eikd
D_rmh
Agyj
aSw"
'LZ
f^DS
tmsu"
i<aXX
&L+
pvmcName
NCHNPJMOD
RLMEWRVWX
aa
aaYX
VDm
VWSEKWQU^
QT 8^
)<=CC
P6N(
&t[
=l[Y
WaY r#
-"=YYX
#]iU
Fnb
$\[=
a'(1
DFOONWLXKVC
tue>
_)Dm
{KaYY i
|XXa0
W nh
9#e@
VVT"
f{!bW
OAP1
LYXY k
xt|@
siV(
YaY ?
GH$[
W9e0
]aX
RAC^QKRENRLU
gstILkaation
:</[
lXYX
P.n<
P\|6
P/53
YBBR
2 2t
ZBAZMIUERGS
LvYa
RUAEMAELVUMM
:<X
JQKRAUAK_UFH
P&it
:<X4
aaX0\R`
ZMLMSVZZLUV
5hZ ,
tysXX]$*
RJRMS
%ZL[$
WCKSVK
_I][
a9`
Y ~/
\k^w
OaYu"
8 eo
]Y4w
,voB
VoString
g$gO
o Y$q
W*/] p
MCZNK
7:kX
({gGn
6]Z
h%Psc
,7nN
,g7X>
`!]=
VgfwggerNonUserWopeEvtribute
O^MUFKLJQDUH
Za N
oum&
SBGTGYUX
ROOEUKEPKTWP
oyl,'xY1
v2.0.50727
{;MB
[+49S$
BFRSNQDEWPEM
a/p=
;YY
n/ ,
dJa]"
[eO1
FQJB
iQ31
-"sD
VM@RQUWWH
"F>dw[Ya
Q#Z%
m(Z&
6Tae
dataToRun
wAzitCode
cW\c E
IYJR^VZG
FPRPDKJONSAD
RTLMTWWFBKZ
y'8&{!Y#
VoUInt32
m;gu
z =OH%
3~X[
get_ASCII
u\I
!V>G
AHTXEPIW
@0e
a^6i
#@V4CV%8
Hp7Q
p< R
^.&W
SYRGJTNDUOS
j,O*
yL$\
{a8U
E~ujelgeAlumbkpjmType
[Ma U
rXa
'@5k
JZLUMRPE]B@
i$^Y
gY30!
OCt
m Ya ^X
,9>D{
b:]x
I71r
GBzW
NLMZAHSUXBIL
BRtIdp
gc P
&Zo+4
H9"-lm/Y
VQzE
dqX
e/Z @
/XXY["6
CregvqRvmcess
.I-L+
SJ$
IK[XWLU
YT W(
;T0Ru
Zq:Cb
Dkwble
YX&=
* *
"~ff
&ZLc\"K:
SegGs
+V\"
Fn`gefAccess
K&XXa&
OIYY
set_Position
QYGKGXOOUVB
zaa
P`d:U
GW6W
_@CGZYJIYR
$:-
GqW?
UYRJGDKSG
S}qtem.OK
B,#TL
> a^$g
KFDVS
TOFIGXQLFQNW
-aa K
da"}P8d"
BSBSUH
QJLNBDRTNG@N
KMJFXWEJVELC
`[5&
aX[L"
| jqM
GY s
^0z5
A@R@KFIJKO
COyQ|
S'CD
MRDJWPONTTV
( {dw%
MPCCHRRXM^
JEABJYVL
PointapFmHknenumbers
0>` U1
qlR X
WTKTYSBLLJU
=aY
R@N b(8
DATKZVETFDLN
HOSCBQTOCRUD
@yte
AAYLRYBTVF
aXaYXa
@@.
GetAttribavqq
z#\-
MZe"e
7{oq.
-Euc09
)"X3<
UKYUFPBMEUCV
'f +`
AH^SCZK@ZMO
$)[O
RRFVE
FKBAABZR
ISOPILCVPVKE
oCE
I>6
.YX
:- %I
Xs[p
ASYXQGJGYUUP
GQXRFTA^\W
ZU6
RyaXa
E`6/
OGNEWPYFJSZ]
MVLROBEVS
GTLMRUSDI
]Z]"sxP0&
q;Xc
ZRGFWI
BQVPAHJI
advapi!4<fhn
i.OFF
s^a[
F!io/u
bZZQR
&ZY
XX y
{OZ\[ Q
S\O]@GIDXRNC
$CDG
dXXY
Crgg`eMlstance
NGUBIBKBMBF
@` e
LBMMI@KUFXCB
3aa4
AUWREND_RESUME
Equals
TBCodeGenerator
GrrorOffset
JgXGg
MTLLCHGN
[iv
LI[k
3aa
|;Gy
stsaY
^LUBUFITXRXW
Virtua|S
<Pri|e{ren id="Author4>
R+>%
[u8w
{yp!
{4v0
&ZYF
FF\AS[E
i3"-h
IDYNQSI@UN
ou75W
set_WindoeQ`{hg
VCEPNDKRV
ESfZH1
jZ/:
PQNC1
XX
H j'"
{]Ae
TRUFNZOUGOUZ
file
PRFXITFDOT
jZaig
ZFCEXPZK
+Pwmq
d\@ a
yrrv
TAB@BOJPGP
?Yas$
L%s,ll
YLK]AYOBK
p7?|
J"i;
TYXXX
DJBYKLKCIUWY
F[PBQSJW
?MF7
ELDCQZVPR
nEY+
Z`3u[Mc]"
SEKBPBMNIB
I;aaX
%B<5mn
d=+a0I4a
ZdH(
[2iK
GE]KMYHLJWE
CaYX 9n
<EG!
{aY K
DCivgshark
MSUKQNWBMRZV
PH/g,N
`Y QUs["
JPU\IULRHIXP
%/%B
fw H&
0* a+
LPRTZTAGYL
9TdH_
BOR\OHTSPEJ
`g4 :
]p'Il
Aa0=
f5?d
r (~nsa
tXe]LZ$
_EgE
E-Y
_GLWNMHPQNQ
\ m
QDRM[ATTUCCD
Slhmc
s"W-
l~V
BSBSPR\LK[HV
-3\~p6
TKULKBIE
ESSGA
:K@|
&=Y G
+aYY$
gptM
(~Q1
}FeX
M}v(
SUHUZLOFWELF
_.L|
O6 AO
"fgl*l
$XL[LX\"q+
QFMNFHRVAZDS
)Ver
UGP~
ZHY$@y-
6eMa
_%yx
ZQ&T
Z^qt
M}-H
SG@QLINELEJC
LWYMXWIRA
2.K1c
JJWPY
AddressOfAj`p}Roint
=D]{
QKRQBNHOAMKL
,JR e
?G9
keN6z"
p|i~
FCAQEEEUOFQN
hfZ*?
-yLn
/(6E
HYaYs"
mzqa %=
RRKZDCFYGZWQ
bQLm
\PEH
S{~qMbJeapReserve
18,g
@UUN]VANMB
zA(B
]'r->+
FJYNGWGYIN
'lx
,2?
SF\GVGAVAZMO
ZOCGRFD
Cqrr.
Xa]\2
@GGGYOCAWMV
YY +>
NFs`
XIK0x
MJTKTSGKH\OP
Exv'
4t6Y
P/^nI.
="'=D
']-oW
q% Gc
^1Q]
NVCZN
tJ?1
{]x5
H.Yr
CeecaX ,
RuntimqA
rs~e
i 5YX 46
lPRa 3x
XNEWSDZB
elyK
Z|-*
wX}}
2Qm6
=$yt
pemove
rb0
BUIGMGLC
eKlbcrlc
DXYKBTLBWK
KTHPCYG
OF;c
TK>MQ~
rg^,
MyApplicatiml
#5-|
5V<~
Qg$m
`9{Ic
IOhV
vc+??
a>5S
7Fa/
?+Y a
c>H
~] lRsz
, tH
LMGKSJH
DJCSEHYRX
j&?7
GFPg
EEW]UGAM
I7u;+>U
|_B`
Ikcrosoft.W{h#0
&2}D
CULNKJVCYUH
GISTLFCNFPTY
3\+o
)v,,
CF^A@WYHKERV
%q[$
CEAXTNZXOD
W44I(
E6(o
x]$Q
}Ya
UBHYUJTLSXFX
rUWNCJ
AK4_ e
ARIRESVTFYJ
A'M#fN
y0g_i'
-}3Kn
(l]g
RaYY
J=2V
G n.
as";
XC*o
MaQ[ O
GetTypqFfoiJandlw
I]$sg
1XX_a2
oXL[I[]"
hN)<
^+ft
lTPa&
t*"g
PWGERDYOK
j=^%b
BRWRSETEJUIW
&YX
Gzu]
CEKWFSVUOHI\
cX6w>P"
MK_RYHNCTKO
Ba M$
SBKNCJVUK
8Y a
_#q[
Fy@|:
_x5&~
e-q@f
}\C
B\O[UN@LPAUT
)"gy
[8My
vNYsXK
DNRXNSKJHILR
OPa &
UUBLQQAOHOVO
ARNOHUTDVSOT
3"C<
x[]ca fm
m[I(J
fCJh
Asda
UYMNPEXAAL
*dcre[a YU
Sosbei,Runtime.CompilerServices
oa !
^N}5i
z&q0
` wN
M _F^ y
f"a
\|JN
LgG3
T'Wwt
CheuiGui
(B<]$
NCZNMFXWNR^H
t' PN
hide
8vJR
Da V
JXa4
Zzsc
JyM6?F
<ZlD
E__ 1
HXt`
m(yBL=
WWEBAMTJROO
9]"L[\[ n
k\K[]ca
grannuveeuz
*mD1
oa k
XYTKOYHIRFOX
8 FB+
cgt_ASUI[
- s
AceQualifiet
4J`r
)X I
aaq]OZ$d
QIETDMQGHWQ
@KNJPPVMQOE
C062
{Hk/
Q+T<
L%g$
qYY
BHYMELA
M.^Pn
T{sD_
ZYaY
][ TW
UIYEMWXHJ
0a "sC
}$[h
9@x87
WGT_CONTEXT
MQ Q
.Z b
U[lp12
LXY CE
60y
C gLH
XJGAXF^CBAV
4\ RXXagX4
]1H8-
Vae$.
c)a
D'-.
kernel32
Vlub.
ZLHK\CFOXEF
PQKFCLOBURQ
RFSVSXWP^VCN
T@ZBHH
0uM
\j|R
` aJX$
FXFPYCDETZEO
%ljT
wgt_Argumenbs
)4 h2/
1*f2
GVSXMUOT
TDu"
Zj 0{r
`v,u3X
iXYa
WUZXSEJZ
ET:~
ESV_GMRQMOSS
'o4y #
`XM[KZ$
KUFJBVMDVRW
G\LLCN
aYY
0&'L
6U[$}RF/
TLDNMMOGDSF
SBCLXP
!xAa
"7[%
Khxp
PtsI
]IWFOAZJSRJ
JYY /
vF%7
!`XYc]2
3Rl c
Q[SEYYNNU
?Eb g
G{avao.Diacj{qpkcs
M :p
63\jr.
IXX 8:
AontextFlags
$dg Q
ppPP
PV&({%
{ooR
QBYQQMDQV
XQ[CCKMJBFZP
CZHKXBUDTOX
!qua \
WZEROVSEXO
ZLSRJUJ[ALF
i)M"
\=38
R W`
CRAUFWSMBVFD
!XQzh
O*"M
EU`#
JW"\
lX7iJ-
HKSFTZTMNACY
STIHPDIGKO
trN7
gyD%
H _4
AJRUGIJQYD
MNJKYUTIBB
}(|u
f 3_
p=uD
AfitorDt}wwcbleState
VKJHC[@
LR\SU@PIJA
E X5=
b^{X
vdP
,/h80
6daw
Li3I
Lch@
.zgT
tl /
JSCGRIHA
|>.f?D}
nVW :
kkl{'
JSEHUIRLS
rvj_O
MzYt
YaXX
j*1e]
B4Q0
>eC<
R.^Y7
GJBH[FB@AAVU
I&IX
v)wwr
s&[ @N
]ZPNt)
dj!n
&YaaYYaaY_
Iw_4
YOKGCQV
m'K9
y =sa4v
n]M"
Zj 5
fL\HY$
I\)8
)4FO
z].,
#x'(
f9@n1
zw"*
TKYRIDTIUMMW
,8Y
NQDLURUDIRD
[(>]
OJQBFDWO_
NQVGHIUWAH
M)aaY
w0NY4
P0ec
vXa MK
MU@R@RAGLRG
Kill
FuX$C
5Ya
g@q)o
PTOFF
EpBv
IEETSGVIOUJR
BA6
kiok.Resources.resosdaaq
8Z<a
YOUWXATV
-p]J
swT6
3|OY
)rvr
AQKVG\DGL
Cw/C
DSandboxie
u:+dG
9pY
BR5RP2
3W `
~jA6O'W
WYaMaq[\"m
get_Name
SY_6
AOTVAXNJUTDX
!|O!
h m Y
avue"
|LIBLTn G%
w V1>li
@FUKBTVR
TITX@UIXQ
EditorBrowsgfxgEvtribuvq
DADZP]@HEVIO
BZV]D]
ProceqwAveptInfo
LKWKCVOYNHZK
UNZSSEA
4: CLQ
C*-9
lYXXX
?KZ$W
]U T
D[Ya
ile7`r\zg
QY ,s Q
&Bv:
K?%
PDxd
.[{;!
QaationAlignmelt
Z!t>
bY 9\
aXaXY Z
H@[4z
DC_^EMQPFROC
HHN
[LLCIGGHFUL
W_EIGWTUUVCY
75hP
ONJD]BOXGDGR
LDCTHVLB
`2X
aXLa4
_D Y 2M
MDKEERHWDVBM
Bdg /
OMZHDW
\9|cF
a]ovno
F=dj
i cP}
WNP\M^CFTJFP
TQWYDECXSM
QMUNB
2aX
&W$)?k
Xm#Sz
uaYY v
l
q*y%4
aXu"
oe95
S@YM]AQSTVME
gA
,U7:
OVUSIHPXNZT@
m_ThreadS`adkgTalue
HN9Z R oT$%
TaM7
VhreavS`apkcAttribute
H1 V+2o"
D^.)OQ
Dg!p
WS^FQWITZ
6g, (Jd
Nfi^r
Dtsp
>X Ur
cYYY
02N"o
AFFUPB
<24;o
?t7
j$[ /
]Ya 8
4System,Qqb*Qervieae,Tpotocols.SoapHttpAn
;o 6
HERAXGCMSB
g9D "U
f5)y
*7Oi
zH*zm"-
"XXa M
<aaXXYY
OOJ(X7p
ABDAZ^H@F
RXa
BLNKLWTQEGK
UXVPUR
DWDPNG\K@
TpGP
)v*#
ResolveEta~vEpgs
N[E
TWKBLAEWFQ
zXLcu"
DVAJXFY
DUWTVBY
TCDPADPTtY
Vi`rechCllocEx
maYX 5x
/KE!
DataOftwwv
g#,a H
p~)_
#T'L
':(q
AK}R'
OFBOACMIGYMW
ZLEZKEU
get_Default
?g}-!7
kernel32.dll
LhPL
XaX&}
u L?\X
S' +j.2
V\6mc
#$|7
sdTI
UH n
DZLBFDJC\
s'H
LumberOfRvaA|`Gk~gs
NcTX
wjduuN
RKLCD^I
HOWVBLNYOL
|7e
/JW%j
hBD X
6Y7Z
9 `
YJSDBHNGIR
eq h
GetModuleZe~fhg
+ n=
etp7
GCHsjpnaVype
P\GFIDLRL
1XFF
NBJFLM
AJFPTNNO
t_$vo2ma
}P |?
ma 3
+Uq:Et
Wow64GcrBjvgadContext
"yoU
P_ZX }+zN
VDKFOVPV
1Y4o
IX@
&, 2
6dJV
ma /
6*0c
m$
U4!15
P}[M E?0z
,&Ic
CTNHSWKU
%2vfCp
,BtA
K& FR !XXa
Y%H ZIl
Pj]_H
UInt64
PTGAHZEDEVP
pP #
pnu0%X
Fmolean
IMAGE_SECT]O^]LGADER
CUWDWHKOSLFX
EQMHKCKQMTAE
tI_?
GetBytes
XZUs
ComVigirnaCttribute
%=+t
}]Mc$2
.{T
FFCO^FCXKEC
OGTYADCB@X
2 w
>e^6
BS`yT
bM:u
sSR"
^G+u
(41/>
b6%w
EMEPT@AWMEHZ
)dfd
^A\VC
1 [
M^|a
& ,a
+\6
z}DB
U0X x k
okoo*qza
CTRXQASONZX
GT!$
EP'zp
;t^3}`H
m e:
KPIWRMJBELH
fI ,
>;zml versioz=61*2" encoding=&WFD)36"?> <Tagi4tapsion="1.2" loxlw?"http://swhuoeq.microsoft.qk
ZY?
5{+SXXY
P!fR
`K2
WGOXNJJSEA[T
1 [U
Bd t
5 uSqZG
}YucJ"B
xj YYX
QHYPC
v&&C
USSESMFZPVUZ
lSkufgi,Resoapqgw,ResourceReader, kqwmvnib, Tg`smmn=4.0.0.0, Cultu`e/nawtral8"@wfnicKeyToken=b77a5e1 3=14e08/#Aywvem.Resources.RunbkyeVgsourwcCep
ZSACN
y8au >
+-a
" <RunLete~<HgastPrivilseq<+PunLevel> "4>+Rrincipal>
~ bR
{\MO
PHMKIQQXMPT
URAP]ENULCPT
Wr{tqAhnText
1. *N
D`ZU6
* "Z
=Ya
instance
jZ+y
$ cnDa YP
-p)'!
%frP
qNx&6
1YXY
BDICAPTFF
;M ~
ZLJ\SB[C
)ZD`
YX eIl
FCRGHSLGWUMK
OyTemplate
BRINOKM\EL
mMc\[ v
YZUMDWW
xkdOx
TIHFOBHEBCH
8" i
f~{s
XXYXs$
X[+C
c\"A
+"D*{
ERRKNTKMPJ
[c FU
G1S07
OXQNWCQ
ezs#
[s[\c ^
+ZC~
;u[$L !5 i
QGi=+q
MPL/XX
qYxc
6kSJ
`\X ~
m&bC
;ku=X;FR
X {?K;$
2 o4~Fa i
6/}{
9]H
,~u`
2Vsg
VG x
%b+`
lNSh
OEBVAPUQCHOA
_@J>;
PJ#%
NTSOX\OLS
~?yUQ@K
1mY4
JYNPZTSOVKU
'GFfc
!(XXXY
~YeZ &
SNYLB
=wUp[
Systc{,Gmllections
KAAYSWR
FCGKNNIUBO@
9##M
I>TDa
6)X [
[ ~p[
AZWYBGNFBFKE
3qc$/P
[B9H7L
Oa gL
(W%6
\WAP
YXFPRVBERA@
`"b][ z%
WnEs%
G)td
RrQw
get_ProcgwaLeoe
b\on
1LZqa$b
Gfv&
sY@6
15.4,$,4
=9pXXXY
get_EntryPoint
YSPJFZYL
EWD&
Deciman
=cY
BHPDMRJHCRZS
yp/(
6vEf8
Nhm
EYESCXIAIR
ZQVHLB
/\ZL[$~
ZCVIOUCNNRVTBCXNMRTTMNIRNOZMTVZVUUBVNUON.resources
LCGEOQFNZTLZ
NSXQYMAVNA
RrQ8
%[$gc_
~_ou"
CUGRCCLAUP
VZACFRPUMDJ
veZa
qBa,og
8e_i
DXaYa L
LXXXCNXUKK^Y
c5[&
{iQX-)(
%JyW
v!<H
]Y _h
Activator
VKGDTXV[TVND
s6DE
7b7R
SSPIHandleCache
{4Jc
s rc
IJOGRFCUG
LQCJRXPR@
WN<d
AEER_UWQ\FX
UAYMQDQGQT
Yn]Z 6
mXQa
lpBuffer
Sg`JeqhCodg
LONGSCDFXO^
zY4e
3y."@n,
@e$?
CKBRGVAJABFQ
Y&@
XaX
MUTXPMYCI
$" <Author<YESAPID]</Author8
|uZ$=
ZYZIQIEYY]
$g_N"
HW4K
GdX
p9\0
^iNQ
+A}k
THBDBJU
0 8i
9Gcu
%ag]6
QREJBCJTCT
q[Z&
"SqLX{
O)T$
Q%U-
WUCFVKCRHP
P0@pr
oiOY
mKM
cM"Y
k=5z
+aXY
hcCx
Y 1X
~O4H
~q"dS
0da2X
v %5
i8UI
#{FK
J So$
,ZX
/ 5WYga
System.Palpkme.CmmbkhgrServices
#BI
e_cs
SMh/
_puM$
BUFRSLHX@_CV
>ZYY
$axb
_@
sO'_YX
!cr!i
kv-
] /
hxc ;=
\h
QCFOSSTNF
:.u8B-L V{u
"w:7
ON)O'i
LYYY4ZFc
:1 aX
IfTR
JZHVQZOVQ[A\
[GCJBUZRODJQ
ocZsa]"
EVL&
ZBWA[QPJP
dXYa6b
CYHRZNVGA^MU
BHOHVL
AUKRPHKDLHVX
RIWGBPHEPCKN
t 49
/003
aYY n2KH i
XXXa H
70`0g
j Y lk
V^Lg
la?F
dqX Q51
wY @#w
sY2%
X`XYa
RNWUD
SeaM_qX$W
i; ~b
0 mL
OIKOUMPQWOD
aaY 6
7lX i1
W?&V
id_Mlequality
laYY 78dI$
)<72
L Yh
aYaY g
RGPMOJLODDJ
EUUMV@[PNRFF
$k2s,f
XJaL \C7
QW]OTZIEQIS
Enum
zs7H
CLRPX@IIP
^'5q
qJ 1
2@_;
_YXaXX
o4"]
bY W
-EaX >
[ +uQ
(2t Q
bY G
ojae
>!@W
get_Length
get_Lengtj
RECOMWNAJ
WCISMK
?=$Z
<p#|
`@*f\l
QaNU
_ hG
lMlfo> <Triqeqrw< <LockzVvkgger> 2 ,Gjcbled>true()Wne`led> 4>AqapId>[USERIR](/QqerId> >/XocmnTrigger>
K`a
< a
!wJ/
0<i
Spacte__Kletelce__
SSEDYHUHM
3k 7
?YY\"
Cu`pqlpWser
LRYTUFBXOEV
XHCVOCG
@J1a
X[1yD
SY
ce"HfA+
PAMLMVY
b `h
nk t
\C>x!
rjJ?
*o&y
HGZCN
q`WR
U92:
QSer
d0Fk
LTAAMMSCHAM
E*C\[
#v`pE
>eX
@PSYIHKSYX
WPEy
-|cu B
hCZ
IOI%
&a
va y
S{\[ \
JUCJSZW\
FMTP\ZH@KBT
EC8, 2h
Proceqw@gvq
<DisalliqEveptIfOnBattwvygw<false</DisaxnywWvartIfOnBavtwpmgs> <St}vYdCmingOnBattqrygw<true</StopIvCykjeOnBatteriss(
aa Xl
XBYIUNQTTWZY
ZJYPT
ANBARQCSDE
8tN-N
Rwll
wX\"
A]OPPYYNRAOB
m\H
PsQ}
FKFNVCMKJUKX
r)P7
7YYY
TY >~
NFCMIA
D^Yh
?/K;
jhW/HM#Z #
!b+7
DWCOABVWU
_1y[Y
va "
)03:?
VNWXDQXHGK
aaaX
BT_}K)
dpkaessInformwt}ojNength
%X #
VXURPFZL
*O;mL
I\6T
?aa
1Y2|
a4wl
':] j
q~-PF"
-8_
sGvV
IUGOXOQKIALN
CN"u
1^1@V
^,.Z ZE{
RWZYSGCR
E^s:Y
(~5 Y
tJSP
w*'[W
]MLSVZVGUZT
wOyNjsPa[
[?Ky
!_\ U
`5"
'YXY 7$
O[VIQBNUBPMA
]a2y
cxJ{d
RCMYSSMTZP
M+St
HaYXZ$>8
,b=>
PAWVS
d]x<W
aXs]4
8W| H
w\p:
Asqg{bh{CompwlmApvribute
oaXaaY %@
X{j6 3
[ldoogMember
SCOFNREC]]XV
b Qs
GyZ{a)
AEMTEGV
RuntioqJanpers
MBF]YELFZHAM
PON_HRXXGDAX
KX5F
7ZY |
Ib07
PTMATSKECXVZ
YXaXY [1
;e3B
ZGX
g'`D8
ZYRDMLIWK
CodeEzrbewqion
ELWRZKCVM
xNYQj
bsx/
q4DTP
Xnsg
Ds9
faX
@9ZX
]9NA
RYUKIANTNEA
d!;\
sKe0
x"lX
WIRVVW[XEXNG
JYCJIJP\WWDE
5HgX$
JVOKIMIO
SSRLIQK
v=`2?}
sqfp
v+ZN
XaYa
R{vlk
Ua`SocketError
<atX
SizeOfRawPadc
Am{R
NoQY
[Pa$Sr
b[!I
u| k h
LAGRPIV
, M#
T WQ
tO@e1
MUAXELNEW
#nQa
Z"ee<
YCTCL@TCSIS
WXV@TOWFDDK
EENMQG
GWMAPHPHQF
0"8-Principals>
S=ON
aLa\[X
4S]rB
oVh$
DWIWGYWGF
^,3"
{Xv
\l$JT
0>j_e
icon
5xn5
X 7H
} xU
,YWc
~ B\/ >
;Na
0x92
JKIWNIKQDGE
IYXYaXX
7.t8
b}1
Ligvr3
f}|>
JKJOKOERH
9q4g
dwCreati
#|YX )H*
og_u
C1 YYY
*E\W
6oeZX7
EUPONJJBS
QCXJUBXWVV
NQ|[']
QJXUISCJFR
IvW{aogtAddress
TSW}
Dwq'0pvQ
k2u:
Nvz2
^F[C
MoveNext
g\w[\c b
'ue[XX O
CXZKEIWNCKLC
``Uvg0P
8|G)
LAVHGR
7euce[
X\ZY
~8Pz
OaaY
QETOGTQ
Y Wij
ECRQVRJG[
STOLIRKWLPJN
BZ_B@UGIFV
2O Xa zO
XXYY
]P7
,>c$
E s pY$
QGAKKJWXDZGG
4t/dw
>0!l
%XY F?
TCRUP
J,A
Conpe{lw
RUGJTKBFAXS
7pX P
" X~
U5,U<
gnEM
X]"%
FDABS
MRFBQE
GetTypeRp
-|0n<
g/eA
sYe"(
XQUSAQABX
guPx "
Eu">
OXv
.np?G
RHAAZZZDCYAR
ACQWO
X]"u
SAPWV
IVNBF
CT\LFCOV
`XY
4 nz^a
KGLCBNDQYIJB
NLKITJVEG
muX$
@XY
get_Naoc
|T( 2
SX9,p
RUBXNKXMYICG
-jw
uq +SD
JG7a !q!P
C'*U
;oZ6
Q5[*
AFEMTMZ
9B$lR
de`9X
ResmhdgAtentHandler
'aX
C^MYPXSVHLXF
*9jtK
MFL;X\"
YVD
g\3Hg\
>d9=
C8CXY h
3XX 1
F!LS
3rI
8c 2
1i~
CodeVap}cfneDec|adapkonStatement
q 5:=
{T(VExU(w
P)0;hJ_<
WF@UJNI
IZbo
JQUFARYJ
@KGJPYXTXCX
ZHZ'>Ev
6xu"
AKHp]
Y."&
DSCDGM
&Y5E
uY$
jYY
@#sk
F x-
i;SX
l0J`
n^a
=aY
O4Mn
mhwS
y #n;@Lw
PNc
|+aaaX *
u-!@d
^6C$
maYa P
F&F(
QSJWRGFSLR
R1nb4^K
8bq$
y6Op
I$ns
Upp*
NJXYDDGYFEMC
|+a_cL"~
a >B
MOAGE_FILE_\GQFAP
EGZEHFGKY
DDHUQUMUGRVI
6> u|"
Qz$r
h>#l
GW>+
clo/
aWxf
SXNINJKDW
CBIGALKCNOBD
x3r U*0N-D
RNPEYCW
K)H (Q
R@=z
NGDIOWME
~aX[Y2HH
DBLACLUFVWVZ
TPGZOZXD^
B6 !
SCTJGCTJSL
XDWZMOEUHBD
XLDKZVEJQGD
EgPg!
0aY
3;bH
UY 1
^ X;
HWLRMXK
w ty
<v -
JHHUANDPDM]
Excebv}mj
W(I$p
LZJt
yAYY
vA@pPsD
I!vUv
\ V
23
=A 9
SECUGTSZPM
&A}W
u dW1c
Y@)1T
EE$a
}k)9
KJXE[^Q]EGSZ
,B-w
VDPPTQUZQYYO
2xp{
FdaX[^L
}k)
kQmM
&h%(_
eqv[UebSe`t{caq
tvPQd8
@ i
k5$J
[2%AC
VIMVA
JtM
OPNEGJDBUUHK
j YLO
RTMPTUWZM
<c4h
@TCBZTUAEN
PointerTo@exogctions
r~Y
\[i@
mYa
JZTEVOVCSJXS
.Ut$
\Gc\H"S
bZ]"
RJXMXCKUJH
RAGSFECZCK
)lG
M^$0\[
x&/,
C86+a
G1)
B)Q>
jc")
BNOHSFB_
Rp"
I.)el
UAMDBJG[NFX
bypgxB&
vZYa
fvuz\<^
+a HV
juEd
ZTFNNN@WLODW
fKnheritHanthqs
3Xa4
UGUFFGHXWFCB
e`pe3
+ 4n9*#
(`*,x
m~sa k
f*O;
g7XY
CZIBXLYFQNGX
rV7u
HaX
i:$ X(
rz;3/
GXJQXWG
ZLZ\"&
a ]w
JGIZMXULRPXH
Reg}q`r}
+Xa
!YXY j
RY t=
Sgp0P
9[YJc\cY
\Dyk
HFIZIUQ
f?kc
gUnj
XXXX
AtentLog
wHWp'0Pp|w
"Aw)$X
U]$M
LZOXN]CFCQGR
FZX q
p!*O+F
sM":3
^:5a
SHUWBUJ
XELFQPJSRCQW
Lb0Hk
G;Ik
IGWAASRP@COD
TBENQMJLAU
fukam
3N0X
XR0^{G
Y) 9_T#c$
HNiJ
ArUF
0+1g"
AYRRC
X ;&y
$" <UserOf*YQQERID]</UserIf*
O[q^
=ig[
pesourceCuxvera
aX Dj7
"TC3.3
AMBBCAMSQQHE
hMn$
UDOa
pm(l
(WZ7
,=%5T
Asssmvl}AompanyAttrkvwpg
?l(u+
y+Mq1
~qK5b
iY4>
~oF
Ij[a
MENs
3zM[T1&rZSC.
D>3<
7;Ft
Hx4"
IBVNXJHCLA
$"=S'
0X4p 0
JmCkDc
UFNJWIB
{U7
Qu 6
P.G'
BYQRUKDTWLKM
c 6Y"
'au
QZLXGMZ
o;
CPY
w\Qy
-U F+
*t8a
XY"rs4."-P
L+"`~
Pu7M
drbH
5$:@
MTECAHLANIFT
!cAS
Wgze
@oHmwer
7gD?'WAA
j3^a0qt
Z[GCMIEAHJNA
BMOI@BRQJQTI
WritwHuc`grsCahnvcgiState
YWUCRMUNAR[K
$Y h
/,{P`-
XHHHTXK@RI
s @,
GGLJDTHIX
haa
Ax^R
QGd
6FYV
i +W
ne5
a3fi#
AF" M
\c %2
JFR'
uaYa
FromBsqu40Qtring
SMCVQMQFGWJ
VTQ[D\DZRMT
QBFXIK@YFLOV
BOPTPYZ_DEM
N m]
gX y
$a^[ Y"El7
op_Equality
PHUFGTOR_QSQ
qX$
RuzLqv
WNMXQWBI
GNvL
Eu B
D_PKPSCDZSX
&$9D
zram
m[u!{
YXXa
6![r
q@tt}
e|p
?LdH8
FBPCNPIZEBIC
oFVRp
VOLFBPA@HY\J
DPKOBUTII@T_
% 'G
jnRi
|a2K
>qe"
{nUp
BGP_PAIRQKG
a@{t
get_Locatkm~
DUQTPQIPTZFI
XxWC
f\Yn
P.`q
jg^Oc\"Q
WQAMLNWZGS
3\X#
3aYXXYaYa(&
!YYa
"(~nsa
Z/xe
rTg=-
0h-8
liJ,Sd
MDVCKFBPJ
EN^o
CIJKXRIB
n##L
QSEIFBKEK
G:7(
e,+$
C=*.f
<G$G_
{3sW
6v 2
TWWAICKPJ]
FCYGNUDLORUF
s0t
MNFVSTRCIUTS
NLMON
F\ZaXaY$
+/)YaXa
Jxix
jpn~
IVEFV^FHTOL
aZX de<'2H
IcmpV4Stat}ufigq
fzhk
L]KPGPSACHLU
,Ih+
V Ze
Slmw
~xDJ
5*_r7
!L2h/#4
SNECLZDV
B05Q
XWIQJARVMD
BYKINQPJTYPH
*cl-
:A(P
VTHNNDHE
LZ$F
GED]PJREAD_TOKEN
lpBssuC`fress
G`m}c
PHABQJJCLP
dz@!|r
s@XRu
Binder
FERPE_YZLUUA
YVNF
CZEZAMI
Qignature
Rl\w
GBEOHIRNR
F[VX@F
4("\
DN -
k2Th6
CIEOWGLTH
ZBXNUO\
o#ILh
#}"%
i a
6\34Kx
~}UMY$w
%o2
q"@
Uw6=r7
vm}A
u~>%
%o%
AVCXQE
9Ot1
D"8R
nr`rCp
15Ya
r; m
bJz4
lXs]Jc]ZY
jnP W
,CF.
eaYs"
\EY
rtWQp$ p
tV^&)
)P(C(
1ba {l
C{nrgrt
IFEA_B
RZV5
[:UW
P1 H7
kw0dpil&k
ieP)
d"@@G
|dpy
e3g"
!*x &
%Bd%)
SWBRQCVGMDUP
GetExecutingAgqqmfny
Xb^s
*2o>
KONVDCL
\I]_Y
IntPtr
RLJWLOASPG@_
HHUKTOR@LQT
0PYc
j!Zs"[
NU``
Q`ajfardModuleAttribu`g
.HDw
TTRQYBA]IEDU
MRAJBSK\
/h:{
YcZ6
HARJNXHMGOTI
Q\ZLY
OVURGZKCSZEW
]0][
abLf
K{l2
MOGXVS]JMJSN
0^c'
$!aL
ETMCWQ
.Ye>_
ZnFa`
oe?~
>i+
-DNg
MKASF@JBOWRQ
T2\y
ZYny
ffq]
/Ls}U=e
)~ k&
LMVJZVMK
Ors 1
9MPB%
1Js/^
3Z-!7
YaL]q
ukTD
ZENJSQJQXMDO
e7k6
7Y]"
BJMCVCSLWXEW
x-Ji
VSDISUBHUGS
!y8)
1.1.&."
YTmdw
4NN
|`$=
XKa@E=
VM]KBREGOFQZ
LFMLHSGKSLNL
]ca
JMURINEF
<: @'6G
rf%@
1?Xw/:a
I-xO
NIKALDOFMJTV
QpRr
=_3
L P
6rx9o(
h+t,
RndSdv
> U.U|e=
rP/V
*YY
XLX]"i\j< V#EpX
HV% Y
Ba,,QaF
MyGrkwdAknlect{i~Cpvribute
-X ]>-
$KL0ID;9
Spl{r
De1n
5@Gr
BRKFVMCJ
qae"
~p@c4ow;?+
BNUKJEHIUY
PFOGGSS_INFORMATIMZ
;kYa
o]
Jec T
(sCw
GEOZCLWB
EF1X
0:6aD
MC58w
9M'|u^
%6Xa
T^QIZJD
#cob
APIYMSHLG
XPU\AQWXZDQV
Btq6K
BHPTQHTOMUC
FMGHG
HDEOWINSVL
b~VH
wYaY
~
D Y
y4C$
\aa
VWHIGIQY
B%UU
"fH:
CUU][LG
|xOX
|pXn\
TagWidf
# mUe
W.Za CJ
eolemiq
HMJHPYWVQUNO
[wA oJ
SUBQX]L
\\{)
]qXuhnOrEmpty
@Z<;^Z
t<dY
:6i4
SGIRGEUAANU
{K\s"l>
'ZX$
\y9
5a m
uT%%
7VaY
E: t
fWV"7
GA$s
SG&tf
&a yK
W{stem.ComponqndOkfel
2!O/
>$";
EFFARHSGWL
8Naw
tkj}h
J<iVba
XAX\Z
Z]6h+
m;v
&z.E
e_crle
$c$v
TAHEVZUOS
\UaI
O.&f
CSVAM
5a <
E.=
eQg.
7Ieg
&sPx
@TNZCQCNJ
KJIGJGBT
ULEE@XL]FXT
>ez#U
f'lh
2dgA
RGJVDNILNCND
ACALLXDZRKBP
v ! #<X
RuntimeCompatibilityAttribute
(L0|L
uoEY
=#;5
V@OCH^RMYQ
]cY
$QRJF
/Ckp-
e2K~Qy
SrBW
S<Cb
; 5S
<ExecutokxVmoeLimit>PT"Q./AzecutionTimeJmykp< <Pr{mfkp{>7</Prioritm:
>@ $
dRx5
o o4~Fa $
Xu[eZ
@@IRGKYU
WXls
=XYXaYXY
DGANIMKIILBL
Hx6\
xs~U
Cfp@mmain
KADURJTXWYLX
YFYFTHULXZ
FIREKUDH
}1aY
HLZSXKWD
l\t"
%r#
_CorDllMain
3aX
BSLVFUIJSTL
jjvs|N
IBOOYLH
s ru;
BSMEGLUWI]@M
U5}e
IO[X >
System.Colnqapkons.Generic
TNLWDCWWCJKS
">pu
,h8
x<Tb
-EaY
NYRABCEVMNOZ
$-G<p
l0g
@mGjarArtak
B/Qg
SizeOfCovc
CERT_BASIC_C_NETVCINTSKIZDK
WZKCYOSXD
_IBH
Pc$*fA
MJZOQHOXU
Ya ]
ORLKEWCRBOUW
WHKDAPUUNE
MDQHA\]Z]QXB
/8dsrL
/\[
QDJZTFHWJEE
)d 6
OTCCHJHDAPRZ
CUMCZNZBZNXVUTZOOUXVUBXRU
<PtyaaqsPers>b__0
*; =
f(\E
nE6.
seSM
WRH"
Rw[I
Swz%v
" h>&
HLQHOPHOFRB
TDbJ
Cscu"
'o@|
Enj
voAb
LXYa
vAlv*
M!3\cYX 5y8
Fbv#7@$pW
;>aYY
WpAp
Y5!/G
!u64F
YCep
ksDotNet
vSzaOain
IOJRRZBD
MKX e"
PCNMIMHGB
RyaaX
EgfE|gcutingAssembly
YXUFAYKDKYPX
VZHAACNXJG
Jm?
FZZAAMJ
TvaY
0vA* t=
QLBDKNGS
Encoding
$2|k
KWMDXZC
E1.
NVELTACJYC
BLJAHICJN^ZG
LR85
@ut ^
5KxC
P*YE
FromBinary
X509ExtensionEnqiqpevor
JDDWK
G{gtao.Globalizct{mj
Zp;i
String
n3vwb'
HH~D
TpO)
pR dD
H}64I
VEKPWCGH
',Z 8
}J?Q
&\cX
:41l
\ A?}{
dX^g2i
we>#
M2r<
x&Fa
m_MyWebSerdiwewMbjec`Rforkder
>V#"
|uY$
@k>K
]YNE[ZLZ
%U3%
[x__
FUPPA\WRG\
LIW[A@[T@UUB
i@i0
DRBIQM
E9v&r
HZCYVQ
LOHRWOETE
{|1L
ivb1t
KaB/
t4)g
g@1[
IXX
EJJ[NMK[
aXX
?PXsW0
^<h"
TDQGJZD[
k{yC
-er
ZmYMZ4
]raaYaY GK^>0
[-'
w~@I
,>7K
tv2,
EMJEJPRS
^YSL@ZFZY
3v3+
System.Sewwbip{
1EQKD
/)p R
Load
SRUDVZCZJP
:t>r
(sf8
s<w`
\cXY
kernex3&
EIXTNCHHI_FW
fV]!
) +^
eav_Id
.02+
ELTHVBMHHJ[K
]de0\)/H;
QPOZXOGVOKED
TG@ZCUVXDRK
NoHY
XZTXS
lYYsX4
QJCTZSR
gsC'
dW'U
CXWUUDWMBJ
FVWB]ILXC
MXTWRXOO
tYLQ
YXY [
X ~a>
DD0_
+[M"
[XIqsHv!4
Ng-9Y
Y Q
=]%3{`
J\WXQQCZXUBK
Ye"I
(tP2x
s1Z
APOXUJFGMLRW
WnSz
`1b;
sFef
.(\g
iLa2o
get]Wwhvure
KQ/w
Rwat@}ves
%dbM0
ZQ7g
N 1Xa a
.IT|( 7
Wo*k_8G
\\2C A0
CIFXCHCBIZSM
YYX
GXZVSZEBGGIY
Gq zo
OBICLWSRAPU
u` //
IHZJQBATJ
>]Zc
td e
jB:.
uqD"
J\S\DYP
LsZ\Z
2tpmCu
#Bx<
rl%q
EX |
PbpI
UYY
PVKSAIM@DO\
Object
:>YaYaYa *
roshav
1U0V
?8>o
Create@mfggvory
DOSES
exgj
=5]Y
ProcessWinpkgSp{le
OAUNURAAF
zeC_<
X rUp
WNQC[M]D
b45
"JJc+
hMi`ana
E|mY
8fBx
J^[_WSQCOVC
yE^>
X 7V<
".;|s
Rum;Nl
GDQQFUOPVBQS
State
!YXY
"] U
BREEZTBVOOBZXNZUROIZVIXZXBVTZOTNCCIUIOOTUBOONEUCMZXROXUETIOMZOEOORCNECEXCMBONCOOUEEOMIZRTTREVIUOZTZMTMTIX
futevorun
w)##
n0-u@
#H0wF0
Q H
FLETIVP
|=r-;
get_Lengt|
!zH
/jB($
\nnC
VMQ@S
a||+
} Y
YYa {h
h3Fd
gn,*
T.^"
KODAGPBPSJI
yLa 1
oib
SWR
DVVCMQCMCAA
2@ X4
cUD,
IL@UVCAGUYPD
AN>T%
`{2m
+@f+
zd~!
y w
#sQZ
Exit
|]=
#C-x
QKNAAANF
P_Wc
BHANFRJS[WJ
aXX2f
+!(@
NZEWIIV
v\Ya
RriT
ZF/a
xyo$
rJ!)Z%
#ga)
#ga4
JBGIOZKJAJ
M[X ?
k}pOl
SetKernejIthaatSecurity
XYQ_MWH\@TG
SZMSLRSHOOOK
gXa v`
J3ZB
ReabCKjv64
$>L[
NUV[\UG[YAUF
%#b%
jxc
@(
de0z
Z`5eOc]Z #c
+l,x
v1b@
$'%'PaeZ20
g 9i_ [$4yuG =
{Bz>K
TLRXWUFAJ
ReadUIzt!4
IsProceuwDwjling
`Qo
ARFY@HC@S
KELNDFOH
HNSKNLX
VY ?
Zero
]9!M
F _@
u_~dL"R
+-bwM4)
;i x
{0XWl
.+&u
4b@a
Yau
zhB2
Yau"
[gWY
System.Threading
X tp6
xWT F
TEDQHUFDBMCR
\:&T
9Zh#
s!Ufn
`'}
12B\
B'y,
?ZN
*V=@/(
SSCINEULBY
J.a
IZI"
E 8B`
m$90
etFD
D^TISNPHRVVW
F>tr/
HGULYSFS
bigdick
-kI[$lG
v0F@#0F
^BNNHPCYK
2 i
Da\"
VBZAE
0a l
?W'}
C@NOOMJWHOA
]qlSj
SCEYZJPTBWLW
9?})}
XR[PHYIUGANW
0:qc24b40-4dd1- 4s1)c0e7-8706a1f%6&;f
Dm{g@cteStamp
p0?S=
gEn-
VcM[][
OdXY
_Z][ o-
XMBIIHELHTBY
F]CAMBQY
2a /
@5~:t
PLDRYK@S]CCT
!RD
G[MQO
\_TKWNMTZNXZZUMVUER.resources
CbP^
gX3P
" <AllowHaffDevoinate>falsg(-EnlowHardTerm{nuta< <StgtfWlgnAvailable>`pae8-StartWhenCvskhcble> <Pw~OjnyIfNetworkCbcmnable>false<=PgnKllyIfNetwovoUteklable> 2>]fhgSettings>
WJA[_SP
0a (
FKXEVEGBTUM
H[VX@*
ZX z9
XY t
Xi[
k8 (
,aaa &~
USWZJNDIN^SO
esZ$sT
55Jd37o
85+.
SKISN
XY ^
0ds$Z
XY W
BBOBEVMQSV
E(\[J
XY L
aXXXY %
FDJWRJYQRPM
YXX[[HYe]Z
XY G
Yuae"
)X+5 R&b;
dyRF
[FaXaYYa w<x
x#jB'
ka H
get_Hczfhg
'w"8w
}xO
685b
tDmH 2GC3`Qbz1ofzUVM3OtQH1v[cc/EXU2hyX[6q{AbSHl9uf7t6L $VfpJ#DGWz7CqMcsD]L8m0j76rqNpfdSLegq?
G56[
Y&~q
rDXa
^(J|
~jOI
} |
GapGvvkng
TKiep
B<U>)
GXEVPFUCKBW
:A^H!~eO
pa$
]aa"P
NGPAXLMHL
'P&y8
KTOBEOXJYMCO
sX\c
?auZ67
UTFPZCEPTCY
GSGSAXLTHKPW
QLFZJUVQTHRL
5]3i
[>e
tUNL
SALAPDJIGTZX
:xX1
4r 0
UBJBCITZKZ
t?;tD
~L@j
qy3 n~
HLBDWYNZEGRG
{C7?
Vi4a
S-FX7
gXaY
4&$v
CNg7
$Tvl
d%W ?
3 xg">\[ l
1 'C
P0u
oh.R7
=UP%
\[$3
qI\4I
vWp
a #G/
OvZb\
gK>.q
;J^Q
SVBZSRXYZVG
le+<
cdi
&U ^
CNUPXBXGN
nn$uhg
EIBQCSAT@
4]Ii
R,Bzi
UANSYQZLUQ
&Xse4agu
Z,$
h4Y D
F):
6 *:
:[-eP
YFUCHACJ
W~H:
DVGVXQX
e ./t
YgWY Y}J
QWWT
@M)
5<#3
D@][FNDLHD
f"m8
FXDZESYYNMA
m'z:
fs76u\
s> @
W{stem.Text.RweenepExpressio~u
2[ /
p'c
TRSNYFJX
o7uum
GSVDXBEG
WrapNynQxggptionThrows
o_ComputerObjectPvkdi`gr
+d;=P
d1\%P
YnmvTypeSize=16
R!EpX
RWWYOXGHD
A=[4h
xY]"7
@YY[&AP
9TyH
MV7+
$SKGr'
System.Runtime.CompilerServices
rf20V
D\W#
YT_CJIMWNXJ
SJAORJZCCEC
JL>IK
p<~w
}hq^
x||Oio
3nXa I
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
L9N`
K7cW,
9f\oXy
R'LQ
MHQZNINLWD
XJITLGJOSH
fW
%D1A<
A(;}
LY8'
X*X1
Rzh:Jg
VUEWEWLRXQ
7>'f22Z
u cI
WjZME
KICGE_OPTIONUNIHACDER32
a)fC
`\X
I*fz
ReadOhhoAknlectionBase
X=naeZ
4pX
(l
IMYe"@$zw
/qJ>
_967$*
HEVRNODRN
_0oY
rwEq
Yu[eZ
x6A;p!
R9d{v
Y1r)
e Ad
NaX x
EODGUQURNR
CAGYIXMFXKYS
_aX
q_icxalloc
fv8tZ
/ +
HDUNIEGWTALG
&cla
$VI
zXq\w[][ x
-'YX l
1w&^
dI63Rx|w
XXMNNUADMN
sR$C
20hE
0a z<
cE5YYaa Q
XXJAINHWLY
fojW
JOGXFWJPG
;Ne?|
UJ\FWQEETYEN
ucf]Wkze
m C
FGTSHJ
%HXYX J
}J4~\
{%&
ivX,4UF
"aX
ItBl
+k{
Dz")w
nG1M
ESXPLDZPC
OTISVQ@RY
MPL/Xa
96m
j3^gO"=n
2 K!
XVFDRXFWHKNQ
6\ZM"
h)[ob
F%&
oNe(
TPYXKI
BJHTA
WZKYTZXG
pederungel
WY]"
kK9
CIZESMERU
?+77
A{eh
fkO
-$J
BPQ&I
a<th'O
Lw-:C
I_yN
WJY\VDRGD
laaa2&
daM
E(Mq
uj49 E
<yL&
a G
Vm-&`
52bP
u.{
[\cXaa
r3%kBX
PVPUSNZJXDX
"-wR3LcOYe"^1
k d,
YVPYORTQAGA
Qzc
eu$R
hH[e[aYXa2l
<K4Q'
zXct
+K(?d
?I H
:<X @
JRIEWBPDIAKM
FOPNMMWVN
!n*g
wLJR
52R+E*
J,*X !+
)_$g+
Z9]zd
b)xa
@pup
u/-n
z(:|k
m`kcknal
w9:g
RGXN
h fA
'_" d{
5tzG
t(MbE
IGKCLDICLUQY
VLJZMV
Wu *
TLY
4^jB
VV@JZWWSWAU
2FHM"
fAI=
^m3<-!
RJ2X
WXH[R]UDGX
V >U
JgNZe"g)s
) =YaX2
YPA^IRBJUNW
lpModunqLeoe
OBTIVD_OJNAR
ReadInt64
>)cR=
OOIX&c
B ?`!X}
0PQY~
U]\d
A8Fp
aXa
Ra K1
/OIeWv
O>\Ut
VDXQCECRQWGD
zkdo
D[2&
E~a 5n
],TD
System.CodeDom.C
}q8
QLVSRR
iF7x
n%"t
x I,3
K/W
XaY
Hs
XaY$
mojeci
/; %D
F d7
[XTCLURAZSOG
%5X z
([ q
1'a.
LN8o-
`r g
eet_MainWindowTitle
ZCG@JOJBIVBN
.Y\"G
LOHQXMRH
>g;O
?q&dR
LicenseExceptiox
Te3K
Hsqk
FLOATINA[ECRG_AREA
JS9K
[ N
kI:L[\c
SBICC
!(Y
) 1UYga M
IY 9
]TzL
Vuc2^#T
5&'*qpX
@]IEB
QSOOQNQEY
3wau[I K
]62
7z-Rg
_`Nc;
-29^
&Ya l
D?XY
j^>q
8#9<
LZ<#
A<r_
JABRJKQUBEN
A@@%
. #
Sycpso
PNV_R^IKC
Y !Ry
RNY
JCNVEJ^M]
O! sv
YWZZIWQQSCS
3YXX
.Qmg
Yb^5
k%EW
$gS'=
HN]$
LMZWTHOVEQHB
j^>'
Vkwrose_MI~qpcnce__
[1Xa
*YXe$
e;n:
Asce}bh{Configurari}nEvtribute
PQsqW
k RHi
Z'^E$I}
N[$<
Oys96F
#NSi
AontrolWord
AFNOGJE
kce"
+ ;a
Ka jm
cQW}
ENFWLQIUR
qRF
TYasaH"
XIG_WCXH
L 7\M"
YYZ"{
#M|H|
]{z,
k7# c
WDSYZSFPUI^[
l-r o4~FaYYY CiZ["
o#fS^
u>of&9
B[ m>
{xY
VLVHWCNSEMZI
5H^=
/{c
Ka\ZX
NXEFM
Qa44
63jx
_{*Aomputer
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2017-12-18 13:07:55 2017-12-18 13:10:52 177

16 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2017-12-18 13:07:55 2017-12-18 13:10:52 177

11 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\HDLO.exe.config
C:\Users\Seven01\AppData\Local\Temp\HDLO.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\HDLO.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\HDLO.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Users\Seven01\AppData\Local\Temp\it-IT\HDLO.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\HDLO.resources\HDLO.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\HDLO.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\HDLO.resources\HDLO.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\HDLO.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\HDLO.resources\HDLO.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\HDLO.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\HDLO.resources\HDLO.resources.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Users\Seven01\AppData\Roaming\XWVWKXD
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Local\Temp\it-IT\graznataguz.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\graznataguz.resources\graznataguz.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\graznataguz.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\graznataguz.resources\graznataguz.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\graznataguz.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\graznataguz.resources\graznataguz.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\graznataguz.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\graznataguz.resources\graznataguz.resources.exe
C:\Users\Seven01\AppData\Roaming\XWVWKXD\XWVWKXD.exe
C:\Users\Seven01\AppData\Roaming\XWVWKXD\alllll.xml
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll
\??\MountPointManager
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2424.21672843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2424.21672843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2424.21672875
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\sysnative\Tasks
C:\Windows\sysnative\Tasks\*
C:\Windows\sysnative\Tasks\Adobe Flash Player Updater
C:\Windows\sysnative\Tasks\XWVWKXD\XWVWKXD
C:\Windows\sysnative\Tasks\XWVWKXD
C:\Windows\sysnative\Tasks\XWVWKXD\
C:\Windows\SysWOW64\net.exe
C:\Windows\SysWOW64
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\*.*
C:\Windows\SysWOW64\net1.exe
C:\Windows\SysWOW64\ui\SwDRM.dll
C:\Windows\sysnative\WerFault.exe
C:\Windows\sysnative
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\AppPatch\AppPatch64\sysmain.sdb
C:\Windows\sysnative\
C:\Windows\sysnative\kernel32.dll
C:\Windows\sysnative\ntdll.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\okok.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\okok.resources\okok.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\okok.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\okok.resources\okok.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\okok.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\okok.resources\okok.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\okok.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\okok.resources\okok.resources.exe
C:\Users\Seven01\AppData\Local\Temp\Lzma.dll
C:\Users\Seven01\AppData\Local\Temp\Lzma\Lzma.dll
C:\Users\Seven01\AppData\Local\Temp\Lzma.exe
C:\Users\Seven01\AppData\Local\Temp\Lzma\Lzma.exe
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Users\Seven01\AppData\Local\Temp\LZLoader.dll
C:\Users\Seven01\AppData\Local\Temp\LZLoader\LZLoader.dll
C:\Users\Seven01\AppData\Local\Temp\LZLoader.exe
C:\Users\Seven01\AppData\Local\Temp\LZLoader\LZLoader.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Users\Seven01\AppData\Roaming\Imminent\s.dat
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\Globalization\en.nlp
C:\Windows\System32\tzres.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL
C:\Windows\SysWOW64\stdole2.tlb
C:\Users\Seven01\AppData\Local\Temp\HDLO.exe:Zone.Identifier
C:\Users\Seven01\AppData\Roaming\
C:\Users\Seven01\AppData\Roaming\.exe
C:\Users\Seven01\AppData\Roaming\Imminent\Path.dat
C:\Windows\assembly\GAC_32\AForge.Video.DirectShow\2.2.5.0__61ea4348d43881b7
C:\Windows\assembly\GAC_MSIL\AForge.Video.DirectShow\2.2.5.0__61ea4348d43881b7
C:\Windows\assembly\GAC\AForge.Video.DirectShow\2.2.5.0__61ea4348d43881b7
C:\Users\Seven01\AppData\Local\Temp\AForge.Video.DirectShow.dll
C:\Users\Seven01\AppData\Local\Temp\AForge.Video.DirectShow\AForge.Video.DirectShow.dll
C:\Users\Seven01\AppData\Local\Temp\AForge.Video.DirectShow.exe
C:\Users\Seven01\AppData\Local\Temp\AForge.Video.DirectShow\AForge.Video.DirectShow.exe
C:\Users\Seven01\AppData\Local\Temp\nkEgbdbbMdrHLHmLNXeZGRqslxSt.dll
C:\Users\Seven01\AppData\Local\Temp\nkEgbdbbMdrHLHmLNXeZGRqslxSt\nkEgbdbbMdrHLHmLNXeZGRqslxSt.dll
C:\Users\Seven01\AppData\Local\Temp\nkEgbdbbMdrHLHmLNXeZGRqslxSt.exe
C:\Users\Seven01\AppData\Local\Temp\nkEgbdbbMdrHLHmLNXeZGRqslxSt\nkEgbdbbMdrHLHmLNXeZGRqslxSt.exe
C:\Windows\assembly
C:\Windows\assembly\Desktop.ini
C:\Users\Seven01\AppData\Roaming\Imminent\Logs\
C:\Users\Seven01\AppData\Roaming\Imminent\Logs
C:\Users\Seven01\AppData\Roaming\Imminent
C:\Users\Seven01\AppData\Roaming\Imminent\Logs\18-12-2017
C:\Users\Seven01\AppData\Roaming\Imminent\Monitoring\network.dat
C:\Users\Seven01\AppData\Roaming\Imminent\Monitoring\system.dat
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb
C:\Windows\symbols\dll\System.pdb
C:\Windows\dll\System.pdb
C:\Windows\System.pdb
C:\Users\Seven01\AppData\Roaming\Imminent\Monitoring\
C:\Users\Seven01\AppData\Roaming\Imminent\Monitoring
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\display.inf
C:\Windows\sysnative\DriverStore\it-IT\display.inf_loc
C:\Windows\inf\display.PNF
C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
C:\Windows\inf\hdaudio.inf
C:\Windows\sysnative\DriverStore\it-IT\hdaudio.inf_loc
C:\Windows\inf\hdaudio.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\sysnative\Branding\basebrd\basebrd.dll
C:\Windows\Branding\Basebrd\basebrd.dll
C:
C:\Windows\sysnative\tzres.dll
\??\PIPE\wkssvc
C:\DosDevices\pipe\
\??\PIPE\srvsvc
\??\WMIDataDevice
C:\
\Device\PcwDrv
C:\Windows\SysWOW64\taskmgr.exe
C:\Windows\System32\ntoskrnl.exe
C:\Windows\System32\smss.exe
C:\Windows\System32\csrss.exe
C:\Windows\System32\winlogon.exe
C:\Windows\System32\services.exe
C:\Windows\System32\lsm.exe
C:\Windows\System32\lsass.exe
C:\Windows\System32\wininit.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Windows\System32\taskhost.exe
C:\Windows\System32\SearchIndexer.exe
C:\Windows\System32\SearchProtocolHost.exe
C:\Windows\System32\wbem\WmiPrvSE.exe
C:\Windows\System32\SearchFilterHost.exe
C:\Windows\System32\wbem\WmiApSrv.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\System32\sppsvc.exe
C:\Windows\Fonts\staticcache.dat
C:\Windows\System32\UxTheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\SysWOW64\taskmgr.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
C:\Windows\System32\taskeng.exe
C:\Windows\sysnative\advapi32.dll
C:\Windows\sysnative\it-IT\advapi32.dll.mui
C:\Windows\sysnative\drivers\acpi.sys
C:\Windows\sysnative\drivers\it-IT\ACPI.sys.mui
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\it-IT\ndis.sys.mui
C:\Windows\sysnative\drivers\mssmbios.sys
C:\Windows\sysnative\drivers\it-IT\mssmbios.sys.mui
C:\Windows\sysnative\drivers\hdaudbus.sys
C:\Windows\sysnative\drivers\it-IT\HDAudBus.sys.mui
C:\Windows\sysnative\drivers\intelppm.sys
C:\Windows\sysnative\drivers\it-IT\intelppm.sys.mui
C:\Windows\sysnative\drivers\portcls.sys
C:\Windows\sysnative\drivers\it-IT\portcls.SYS.mui
C:\Windows\sysnative\drivers\monitor.sys
C:\Windows\sysnative\drivers\it-IT\monitor.sys
C:\Windows\sysnative\drivers\it\monitor.sys

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\HDLO.exe.config
C:\Users\Seven01\AppData\Local\Temp\HDLO.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\pubpol23.dat
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Roaming\XWVWKXD\alllll.xml
C:\Windows\sysnative\Tasks\XWVWKXD\XWVWKXD
C:\Windows\SysWOW64\net.exe
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\net1.exe
C:\Windows\sysnative\WerFault.exe
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\AppPatch\AppPatch64\sysmain.sdb
C:\Windows\sysnative\
C:\Windows\sysnative\kernel32.dll
C:\Windows\sysnative\ntdll.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\System32\tzres.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb
C:\Windows\symbols\dll\System.pdb
C:\Windows\dll\System.pdb
C:\Windows\System.pdb
C:\Users\Seven01\AppData\Roaming\Imminent\Logs\18-12-2017
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\display.PNF
C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
C:\Windows\inf\hdaudio.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\Branding\Basebrd\basebrd.dll
C:
C:\Windows\sysnative\tzres.dll
\??\PIPE\wkssvc
\??\PIPE\srvsvc
\??\WMIDataDevice
\Device\PcwDrv
C:\Windows\Fonts\staticcache.dat
C:\Windows\System32\UxTheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\sysnative\advapi32.dll
C:\Windows\sysnative\drivers\acpi.sys
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\mssmbios.sys
C:\Windows\sysnative\drivers\hdaudbus.sys
C:\Windows\sysnative\drivers\intelppm.sys
C:\Windows\sysnative\drivers\portcls.sys
C:\Windows\sysnative\drivers\monitor.sys

Write Files

C:\Users\Seven01\AppData\Roaming\XWVWKXD\XWVWKXD.exe
C:\Users\Seven01\AppData\Roaming\XWVWKXD\alllll.xml
C:\Windows\sysnative\Tasks\XWVWKXD\XWVWKXD
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Users\Seven01\AppData\Roaming\.exe
C:\Users\Seven01\AppData\Roaming\Imminent\Path.dat
C:\Users\Seven01\AppData\Roaming\Imminent\Logs\18-12-2017
C:\Users\Seven01\AppData\Roaming\Imminent\Monitoring\network.dat
C:\Users\Seven01\AppData\Roaming\Imminent\Monitoring\system.dat
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\PIPE\wkssvc
\??\PIPE\srvsvc
\??\WMIDataDevice

Delete Files

C:\Users\Seven01\AppData\Roaming\XWVWKXD\alllll.xml
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2424.21672843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2424.21672843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2424.21672875
C:\Users\Seven01\AppData\Local\Temp\HDLO.exe:Zone.Identifier

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HDLO.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\186ef6ff\3fb03b37
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\68e21496\5e915760
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|HDLO.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|HDLO.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|HDLO.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\68e21496\49eee99
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\14c57cbf\44e41c71
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\14c57cbf\1ca25d88
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\schtasks.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\XWVWKXD\XWVWKXD
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\XWVWKXD\XWVWKXD\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\XWVWKXD\XWVWKXD\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\DynamicInfo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net1.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WerFault.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61941978\5444db37
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\2f0b5890\6a89d71f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\2f0b5890\b49ff9a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d608f43\663c74a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7cdb1e21\64824de1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Classes\AppID\HDLO.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6AA2B39F
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\winmgmts
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\410
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.2.AForge.Video.DirectShow__61ea4348d43881b7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7454be22\631aafc0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f97a8e2\430164e3
HKEY_CLASSES_ROOT\CLSID\{62BE5D10-60EB-11D0-BD3B-00A0C911CE86}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{62BE5D10-60EB-11D0-BD3B-00A0C911CE86}\InprocServer32\Class
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum\Version
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum\{860BB310-5D01-11D0-BD3B-00A0C911CE86}
HKEY_CLASSES_ROOT\CLSID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{860BB310-5D01-11D0-BD3B-00A0C911CE86}\Instance
HKEY_CLASSES_ROOT\DirectShow\MediaObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\DirectShow\MediaObjects\Categories\860bb310-5d01-11d0-bd3b-00a0c911ce86
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\control.exe
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{65e8773d-8f56-11d0-a3b9-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{65E8773D-8F56-11D0-A3B9-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{65e8773d-8f56-11d0-a3b9-00a0c9223196}\#eCDInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{65E8773D-8F56-11D0-A3B9-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{65e8773d-8f56-11d0-a3b9-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{65E8773D-8F56-11D0-A3B9-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{65e8773d-8f56-11d0-a3b9-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{65E8773D-8F56-11D0-A3B9-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{65e8773d-8f56-11d0-a3b9-00a0c9223196}\#eMicInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{65E8773D-8F56-11D0-A3B9-00A0C9223196}\Properties
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Elevation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{E43D242B-9EAB-4626-A952-46649FBB939A}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANBH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIPV6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}\00000006
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Pnp\{71d10298-bdb9-4dcd-a87a-eec6137ab254}\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{8c7ed206-3f8a-4827-b3ab-ae9e1faefc6c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{afd97640-86a3-4210-b67c-289c41aabe55}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\BTH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Properties\{afd97640-86a3-4210-b67c-289c41aabe55}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CdRomVBOX_CD-ROM_____________________________1.0_____\5&106af171&0&1.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDEChannel\4&2f42c713&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267a616a&0&09\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ACPI_HAL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\Device Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\IDE#CdRomVBOX_CD-ROM_____________________________1.0_____
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\IDE#VBOX_CD-ROM_____________________________1.0_____
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\IDE#CdRomVBOX_CD-ROM_____________________________
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\VBOX_CD-ROM_____________________________1.0_____
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\GenCdRom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\Device Parameters\Icons
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Device Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Device Parameters\NoSoftEject
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\Intel-PIIX4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\Internal_IDE_Channel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\CompatibleIDs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\*PNP0600
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Device Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Device Parameters\NoSoftEject
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\HardwareID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\IDE#DiskVBOX_HARDDISK___________________________1.0_____
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\IDE#VBOX_HARDDISK___________________________1.0_____
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\IDE#DiskVBOX_HARDDISK___________________________
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\VBOX_HARDDISK___________________________1.0_____
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\GenDisk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\ActivePowerScheme
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\User\PowerSchemes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\ActivePowerScheme
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\381b4222-f694-41f0-9685-ff5bb260df2e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\94ac6d29-73ce-41a6-809f-6363ba21b47e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e\238c9fa8-0aad-41ed-83f4-97be242c8f20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238c9fa8-0aad-41ed-83f4-97be242c8f20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94ac6d29-73ce-41a6-809f-6363ba21b47e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\DefaultPowerSchemeValues
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\ACSettingIndex
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\ValueMin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\1\SettingValue
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\a7066653-8d6c-40a8-910e-a1f54b84c7e5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\381b4222-f694-41f0-9685-ff5bb260df2e\4f971e89-eebd-4455-a8de-9e59040e7347
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\a7066653-8d6c-40a8-910e-a1f54b84c7e5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\DefaultPowerSchemeValues
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\ACSettingIndex
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\ValueMin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\0\SettingValue
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eheadphonewave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonetopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonewave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&40
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&40\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStopMissed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wmi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wmi
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PauseResumeTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A359DEC5-E813-4834-8A2A-BA7F1D777D76}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A359DEC5-E813-4834-8A2A-BA7F1D777D76}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A359DEC5-E813-4834-8A2A-BA7F1D777D76}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\HomeNet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\HomeNet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sList
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sDecimal
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sThousand
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNativeDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonDecimalSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonThousandSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sPositiveSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNegativeSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sTimeFormat
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortTime
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s1159
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s2359
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sYearMonth
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sLongDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iMeasure
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iPaperSize
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iLZero
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegNumber
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\NumShape
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegCurr
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCalendarType
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseInfo\FilePrint
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\SYSTEM
HKEY_LOCAL_MACHINE\SOFTWARE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager\UsrColumnSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\taskmgr.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager\Preferences
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FileAssociation\CutList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\DFE4A99D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\MS Shell Dlg 2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\WDM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\IDE\DiskVBOX_HARDDISK___________________________1.0_____\5&33d1638a&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ACPI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDIS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mssmbios
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HDAudBus
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\intelppm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\ImagePath
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\portcls
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\monitor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\ImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\WMIBinaryMofResource.HighDateTime=30016564,LowDateTime=3292279056,Name="C:\Windows\system32\advapi32.dll[MofResourceName]"
HKEY_USERS\.DEFAULT\Control Panel\International
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\C:\Windows\system32\advapi32.dll[MofResourceName]

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\DynamicInfo
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6AA2B39F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{62BE5D10-60EB-11D0-BD3B-00A0C911CE86}\InprocServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{65E8773D-8F56-11D0-A3B9-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{65e8773d-8f56-11d0-a3b9-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\AppID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CdRomVBOX_CD-ROM_____________________________1.0_____\5&106af171&0&1.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDEChannel\4&2f42c713&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267a616a&0&09\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ACPI_HAL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\Device Parameters\Icons
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Device Parameters\NoSoftEject
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Device Parameters\NoSoftEject
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\ActivePowerScheme
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\ActivePowerScheme
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\381b4222-f694-41f0-9685-ff5bb260df2e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\94ac6d29-73ce-41a6-809f-6363ba21b47e
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\ACSettingIndex
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\ValueMin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\238C9FA8-0AAD-41ED-83F4-97BE242C8F20\94AC6D29-73CE-41A6-809F-6363BA21B47E\1\SettingValue
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\SecurityDescriptors\a7066653-8d6c-40a8-910e-a1f54b84c7e5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\DefaultPowerSchemeValues\381b4222-f694-41f0-9685-ff5bb260df2e\ACSettingIndex
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\ValueMin
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerSettings\4f971e89-eebd-4455-a8de-9e59040e7347\A7066653-8D6C-40A8-910E-A1F54B84C7E5\0\SettingValue
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&40\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wmi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wmi
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PauseResumeTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A359DEC5-E813-4834-8A2A-BA7F1D777D76}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\HomeNet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\HomeNet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sList
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sDecimal
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sThousand
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNativeDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonDecimalSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonThousandSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sPositiveSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNegativeSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sTimeFormat
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortTime
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s1159
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s2359
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sYearMonth
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sLongDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iMeasure
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iPaperSize
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iLZero
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegNumber
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\NumShape
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegCurr
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCalendarType
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager\UsrColumnSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager\Preferences
HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FileAssociation\CutList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\DFE4A99D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\MofImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor\ImagePath
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear

Write Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\XWVWKXD\XWVWKXD\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\XWVWKXD\XWVWKXD\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F1E73D-F4AA-4997-903D-3FC6DC092766}\DynamicInfo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\(Default)
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum\Version
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStopMissed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\IDE\DiskVBOX_HARDDISK___________________________1.0_____\5&33d1638a&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\C:\Windows\system32\advapi32.dll[MofResourceName]

Delete Keys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\WDM\WMIBinaryMofResource.HighDateTime=30016564,LowDateTime=3292279056,Name="C:\Windows\system32\advapi32.dll[MofResourceName]"

Mutexes

Global\CLR_CASOFF_MUTEX
3af86008-b72e-4037-ad67-c3b786ecfeaa
Global\.net clr networking
eed3bd3a-a1ad-4e99-987b-d7cb3fcfa7f0 - S-1-5-21-1822907384-1282624486-319450072-1000
Local\TASKMGR.879e4d63-6c0e-4544-97f2-1244bd3f6de0
Local\MSCTF.Asm.MutexDefault1

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.CloseHandle
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
ntdll.dll.NtQuerySystemInformation
user32.dll.EnumWindows
user32.dll.GetWindowThreadProcessId
user32.dll.GetWindow
user32.dll.IsWindowVisible
user32.dll.GetWindowTextLengthW
user32.dll.GetWindowTextW
kernel32.dll.IsDebuggerPresent
kernel32.dll.GetModuleHandleA
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.SwitchToThread
shfolder.dll.SHGetFolderPathW
kernel32.dll.CreateDirectoryW
kernel32.dll.LocalFree
kernel32.dll.LocalAlloc
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
advapi32.dll.LsaClose
advapi32.dll.LsaFreeMemory
advapi32.dll.LsaOpenPolicy
advapi32.dll.LsaLookupSids
kernel32.dll.CopyFileW
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.WriteFile
kernel32.dll.RtlMoveMemory
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
shell32.dll.ShellExecuteEx
shell32.dll.ShellExecuteExW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
comctl32.dll.#332
comctl32.dll.#386
ole32.dll.CoUninitialize
ole32.dll.CoRevokeInitializeSpy
comctl32.dll.#388
oleaut32.dll.#500
kernel32.dll.DuplicateHandle
kernel32.dll.DeleteFileW
kernel32.dll.GetTempPathW
kernel32.dll.CreateProcessA
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.VirtualAllocEx
kernel32.dll.TerminateProcess
kernel32.dll.GetThreadContext
kernel32.dll.WriteProcessMemory
kernel32.dll.VirtualProtectEx
kernel32.dll.SetThreadContext
kernel32.dll.ResumeThread
comctl32.dll.#321
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
sspicli.dll.GetUserNameExW
advapi32.dll.WmiNotificationRegistrationW
ole32.dll.CoTaskMemAlloc
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
rasapi32.dll.RasEnumConnectionsW
rasapi32.dll.RasConnectionNotificationW
iphlpapi.dll.GetIfTable2
iphlpapi.dll.FreeMibTable
kernel32.dll.VirtualProtect
kernel32.dll.GetEnvironmentVariableW
user32.dll.SetProcessDPIAware
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
kernel32.dll.ReleaseMutex
kernel32.dll.CreateMutexW
ole32.dll.CoWaitForMultipleHandles
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
kernel32.dll.GetCurrentProcessId
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
advapi32.dll.CreateWellKnownSid
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.OpenProcess
kernel32.dll.GetProcessTimes
ws2_32.dll.inet_addr
kernel32.dll.CreateEventW
kernel32.dll.SetEvent
ole32.dll.IIDFromString
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CoGetObjectContext
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.LoadLibraryA
kernel32.dll.GetProcAddress
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
oleaut32.dll.#283
oleaut32.dll.#284
oleaut32.dll.#9
oleaut32.dll.#7
advapi32.dll.GetUserNameW
user32.dll.GetSystemMetrics
user32.dll.GetDC
user32.dll.EnumDisplayMonitors
user32.dll.GetMonitorInfoW
gdi32.dll.GetDeviceCaps
user32.dll.ReleaseDC
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
kernel32.dll.GetModuleHandleW
user32.dll.GetClassInfoW
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.DefWindowProcW
ws2_32.dll.gethostname
ws2_32.dll.gethostbyname
kernel32.dll.lstrlenA
iphlpapi.dll.GetAdaptersInfo
iphlpapi.dll.GetIfEntry
iphlpapi.dll.GetPerAdapterInfo
ole32.dll.CreateBindCtx
ole32.dll.MkParseDisplayName
ole32.dll.BindMoniker
sxs.dll.SxsOleAut32RedirectTypeLibrary
advapi32.dll.RegOpenKeyW
advapi32.dll.RegEnumKeyW
advapi32.dll.RegQueryValueW
sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid
sxs.dll.SxsLookupClrGuid
oleaut32.dll.#4
mscoreei.dll._CorDllMain
mscoree.dll.GetTokenForVTableEntry
mscoree.dll.SetTargetForVTableEntry
mscoree.dll.GetTargetForVTableEntry
mscoreei.dll.GetTokenForVTableEntry
mscoreei.dll.SetTargetForVTableEntry
mscoreei.dll.GetTargetForVTableEntry
kernel32.dll.GetLastError
oleaut32.dll.VariantInit
oleaut32.dll.VariantClear
oleaut32.dll.#204
oleaut32.dll.#203
kernel32.dll.GetLocaleInfoA
advapi32.dll.DuplicateTokenEx
advapi32.dll.CheckTokenMembership
kernel32.dll.GetSystemPowerStatus
kernel32.dll.DeleteFileA
advapi32.dll.RegSetValueExW
kernel32.dll.QueryPerformanceFrequency
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptExportKey
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptDestroyKey
setupapi.dll.SetupDiGetClassDevsW
setupapi.dll.SetupDiDestroyDeviceInfoList
setupapi.dll.SetupDiEnumDeviceInterfaces
setupapi.dll.SetupDiOpenDeviceInterfaceRegKey
setupapi.dll.SetupDiCreateDeviceInterfaceRegKeyW
setupapi.dll.SetupDiGetDeviceInterfaceDetailW
setupapi.dll.SetupDiCreateDeviceInfoList
setupapi.dll.SetupDiOpenDeviceInterfaceW
setupapi.dll.SetupDiGetDeviceInterfaceAlias
wintrust.dll.WinVerifyTrust
msdmo.dll.DMOEnum
msdmo.dll.DMOGetTypes
msdmo.dll.DMOGetName
avicap32.dll.capGetDriverDescriptionW
user32.dll.RegisterWindowMessageW
user32.dll.AdjustWindowRectEx
gdi32.dll.GetStockObject
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
user32.dll.SetWindowsHookExA
oleaut32.dll.#179
oleaut32.dll.#220
kernel32.dll.GetExitCodeProcess
kernel32.dll.SetProcessWorkingSetSize
kernel32.dll.GetSystemInfo
kernel32.dll.CreateIoCompletionPort
kernel32.dll.PostQueuedCompletionStatus
ntdll.dll.NtQueryInformationThread
ntdll.dll.NtGetCurrentProcessorNumber
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.bind
user32.dll.GetForegroundWindow
user32.dll.GetWindowTextA
ws2_32.dll.WSAIoctl
ws2_32.dll.WSAGetOverlappedResult
kernel32.dll.FormatMessageW
mscoree.dll.DllGetClassObject
mscoreei.dll.DllGetClassObject
diasymreader.dll.DllGetClassObjectInternal
kernel32.dll.lstrcpy
kernel32.dll.lstrcpyW
user32.dll.PostMessageW
ws2_32.dll.WSAConnect
ws2_32.dll.WSAEnumNetworkEvents
kernel32.dll.ResetEvent
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CreateStreamOnHGlobal
advapi32.dll.RegCreateKeyExW
cryptsp.dll.CryptReleaseContext
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernel32.dll.SetThreadToken
kernelbase.dll.CheckTokenMembership
kernelbase.dll.AllocateAndInitializeSid
oleaut32.dll.#285
oleaut32.dll.#12
oleaut32.dll.#286
ole32.dll.CLSIDFromString
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#290
winbrand.dll.BrandingLoadString
security.dll.InitSecurityInterfaceW
cryptsp.dll.SystemFunction035
schannel.dll.SpUserModeInitialize
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlFreeUnicodeString
ntdll.dll.NtSetSystemEnvironmentValue
ntdll.dll.NtQuerySystemEnvironmentValue
ntdll.dll.NtCreateFile
ntdll.dll.NtQueryDirectoryObject
ntdll.dll.NtQueryObject
ntdll.dll.NtOpenDirectoryObject
ntdll.dll.NtQueryInformationProcess
ntdll.dll.NtQueryInformationToken
ntdll.dll.NtOpenFile
ntdll.dll.NtClose
ntdll.dll.NtFsControlFile
ntdll.dll.NtQueryVolumeInformationFile
netapi32.dll.NetGroupEnum
netapi32.dll.NetGroupGetInfo
netapi32.dll.NetGroupSetInfo
netapi32.dll.NetLocalGroupGetInfo
netapi32.dll.NetLocalGroupSetInfo
netapi32.dll.NetGroupGetUsers
netapi32.dll.NetLocalGroupGetMembers
netapi32.dll.NetLocalGroupEnum
netapi32.dll.NetShareEnum
netapi32.dll.NetShareGetInfo
netapi32.dll.NetShareAdd
netapi32.dll.NetShareEnumSticky
netapi32.dll.NetShareSetInfo
netapi32.dll.NetShareDel
netapi32.dll.NetShareDelSticky
netapi32.dll.NetShareCheck
netapi32.dll.NetUserEnum
netapi32.dll.NetUserGetInfo
netapi32.dll.NetUserSetInfo
netapi32.dll.NetApiBufferFree
netapi32.dll.NetQueryDisplayInformation
netapi32.dll.NetServerSetInfo
netapi32.dll.NetServerGetInfo
netapi32.dll.NetGetDCName
netapi32.dll.NetWkstaGetInfo
netapi32.dll.NetGetAnyDCName
netapi32.dll.NetServerEnum
netapi32.dll.NetUserModalsGet
netapi32.dll.NetScheduleJobAdd
netapi32.dll.NetScheduleJobDel
netapi32.dll.NetScheduleJobEnum
netapi32.dll.NetScheduleJobGetInfo
netapi32.dll.NetUseGetInfo
netapi32.dll.NetEnumerateTrustedDomains
netapi32.dll.DsGetDcNameW
netapi32.dll.DsRoleGetPrimaryDomainInformation
netapi32.dll.DsRoleFreeMemory
netapi32.dll.NetRenameMachineInDomain
netapi32.dll.NetJoinDomain
netapi32.dll.NetUnjoinDomain
wkscli.dll.NetWkstaGetInfo
cscapi.dll.CscNetApiGetInterface
kernel32.dll.GetDiskFreeSpaceExW
kernel32.dll.GetVolumePathNameW
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Thread32First
kernel32.dll.Thread32Next
kernel32.dll.Process32First
kernel32.dll.Process32Next
kernel32.dll.Module32First
kernel32.dll.Module32Next
kernel32.dll.Heap32ListFirst
kernel32.dll.GetSystemDefaultUILanguage
oleaut32.dll.#15
oleaut32.dll.#26
wmi.dll.WmiQueryAllDataW
wmi.dll.WmiQuerySingleInstanceW
wmi.dll.WmiSetSingleItemW
wmi.dll.WmiSetSingleInstanceW
wmi.dll.WmiExecuteMethodW
wmi.dll.WmiNotificationRegistrationW
wmi.dll.WmiMofEnumerateResourcesW
wmi.dll.WmiFileHandleToInstanceNameW
wmi.dll.WmiDevInstToInstanceNameW
wmi.dll.WmiQueryGuidInformation
wmi.dll.WmiOpenBlock
wmi.dll.WmiCloseBlock
wmi.dll.WmiFreeBuffer
wmi.dll.WmiEnumerateGuids
devobj.dll.DevObjCreateDeviceInfoList
devobj.dll.DevObjGetClassDevs
devobj.dll.DevObjEnumDeviceInfo
devobj.dll.DevObjDestroyDeviceInfoList
setupapi.dll.CM_Open_DevNode_Key_Ex
devobj.dll.DevObjGetDeviceProperty
cfgmgr32.dll.CM_Connect_MachineA
cfgmgr32.dll.CM_Disconnect_Machine
cfgmgr32.dll.CM_Locate_DevNodeW
cfgmgr32.dll.CM_Get_DevNode_Registry_PropertyW
cfgmgr32.dll.CM_Get_Child
cfgmgr32.dll.CM_Get_Sibling
cfgmgr32.dll.CM_Get_DevNode_Status
cfgmgr32.dll.CM_Get_First_Log_Conf
cfgmgr32.dll.CM_Get_Next_Res_Des
cfgmgr32.dll.CM_Get_Res_Des_Data
cfgmgr32.dll.CM_Get_Res_Des_Data_Size
cfgmgr32.dll.CM_Free_Log_Conf_Handle
cfgmgr32.dll.CM_Free_Res_Des_Handle
cfgmgr32.dll.CM_Get_Device_IDA
cfgmgr32.dll.CM_Get_Device_ID_Size
cfgmgr32.dll.CM_Get_Parent
user32.dll.MonitorFromWindow
user32.dll.MonitorFromRect
user32.dll.MonitorFromPoint
user32.dll.EnumDisplayDevicesW
dxgi.dll.DXGIReportAdapterConfiguration
gdi32.dll.D3DKMTOpenAdapterFromDeviceName
gdi32.dll.D3DKMTQueryAdapterInfo
gdi32.dll.D3DKMTGetDisplayModeList
gdi32.dll.D3DKMTCloseAdapter
slc.dll.SLGetWindowsInformationDWORD
comctl32.dll.RegisterClassNameW
uxtheme.dll.OpenThemeData
imm32.dll.ImmAssociateContext
shell32.dll.#66
imm32.dll.ImmIsIME
uxtheme.dll.EnableThemeDialogTexture
rpcrt4.dll.RpcAsyncInitializeHandle
rpcrt4.dll.NdrClientCall2
rpcrt4.dll.NdrAsyncClientCall
imm32.dll.ImmGetContext
imm32.dll.ImmReleaseContext
ole32.dll.CoRegisterInitializeSpy
winsta.dll.WinStationGetProcessSid
utildll.dll.CachedGetUserFromSid
propsys.dll.#421
rpcrt4.dll.RpcAsyncCompleteCall
uxtheme.dll.GetThemeColor
uxtheme.dll.GetThemeMargins
uxtheme.dll.GetThemeFont
dwmapi.dll.DwmIsCompositionEnabled
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
uxtheme.dll.GetThemeBool
uxtheme.dll.IsThemePartDefined
uxtheme.dll.GetThemePartSize
comctl32.dll.HIMAGELIST_QueryInterface
comctl32.dll.DrawShadowText
comctl32.dll.DrawSizeBox
comctl32.dll.DrawScrollBar
comctl32.dll.SizeBoxHwnd
comctl32.dll.ScrollBar_MouseMove
comctl32.dll.ScrollBar_Menu
comctl32.dll.HandleScrollCmd
comctl32.dll.DetachScrollBars
comctl32.dll.AttachScrollBars
comctl32.dll.CCSetScrollInfo
comctl32.dll.CCGetScrollInfo
comctl32.dll.CCEnableScrollBar
comctl32.dll.QuerySystemGestureStatus
uxtheme.dll.#49
uxtheme.dll.DrawThemeBackground
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.GetThemeTextMetrics
uxtheme.dll.GetThemeTextExtent
uxtheme.dll.GetThemeBackgroundExtent

Execute Commands

schtasks.exe /Create /TN "XWVWKXD\XWVWKXD" /XML "C:\Users\Seven01\AppData\Roaming\XWVWKXD\alllll.xml"
taskmgr.exe 
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe -Embedding

Started Services

Nothing to display

Created Services

Nothing to display