MalScore
100/100
MalFamily
Ispy

Quotation Sheet_#RFQ180724,doc.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 14/68 Related 2367
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 1318.00 KB (1349632 bytes)
Compile time: 1984-12-20 18:22:25
MD5: 30837905381a7fd152baed405f2737a7
SHA1: bf7eb13e93696fc8463001ee4037fc3fdffe6e29
SHA256: 0b6b0f5a98e4674d3a8b50234f79cf282dfedcea9b4a8e8f2be88e794ccd68e7
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 $B.yZ! .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-07-24 16:29:37
Last submission: 2018-07-24 16:29:37
Filename detected: - Quotation Sheet_#RFQ180724,doc.exe (1)
URL file hosting
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-07-24 11:11:03 [14/68] VirusTotal
PE Sections 3 suspicious
Name VAddress VSize Size MD5 SHA1
$B.yZ! 0x2000 0x1c34 7680 0aea792c2eb33b317411d01c1e78d1f6 5878c6a128a32f3b778dd9b851a4acd7a2ef798b
.text 0x4000 0x1469b8 1337856 a4551e563d89f5dd5fb53a23b2c2c8ea 37bc7a42c11f6b44be6f8595c1cd307799a891c8
.rsrc 0x14c000 0x690 2048 9a32c93d9854e46c9d65561abe6b5300 8eaf44d86b32c19f31c2c3ea76f07e77db470a38
.reloc 0x14e000 0xc 512 ec90e706458e5d8142dda35a68402970 67f24bb5ad8ab1c3b8408eb33f592cedc2b30dcf
0x150000 0x10 512 9758262ddeb84a7d7fdaf4fe9f9ffecc a407a9de2e32ddc3f51e19fa5089f77fa4703013
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x14c0a0 1028 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x14c4a4 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2018 Hercules Inc.
Assembly Version: 0.0.0.0
InternalName: stan crrr.exe
FileVersion: 6.7.14.1
CompanyName: Hercules Inc.
Comments: awosalaqumodumojoduc
ProductName: Recovery Manager for Active Directory Forest Edition
ProductVersion: 6.7.14.1
FileDescription: Recovery Manager for Active Directory Forest Edition
Translation: 0x0000 0x04b0
OriginalFilename: stan crrr.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Binary
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.Resources.tst.dll.bin
FIle type: Library
tst.dll
mscoree.dll
KERNEL32.dll
dwhdm22.dll
SHELL32.dll
IP Found
6.7.14.1
URL(s)
No URL found
String too long
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.Properties
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.Properties.Resources.resources
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.Resources.tst.dll.bin
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.exe
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.fm.resources
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=
96ba171b-776c-d1336
96ba171b-776c-d1337
96ba171b-776c-d1334
96ba171b-776c-d1335
96ba171b-776c-d1332
96ba171b-776c-d1333
96ba171b-776c-d1330
96ba171b-776c-d1331
96ba171b-776c-d1338
96ba171b-776c-d1339
96ba171b-776c-d178
96ba171b-776c-d179
b;M
96ba171b-776c-d172
96ba171b-776c-d173
96ba171b-776c-d170
96ba171b-776c-d171
96ba171b-776c-d176
96ba171b-776c-d177
96ba171b-776c-d174
96ba171b-776c-d175
InternalName
dIK
.0.0
96ba171b-776c-d1239
96ba171b-776c-d1238
96ba171b-776c-d1237
96ba171b-776c-d1236
96ba171b-776c-d1235
96ba171b-776c-d1234
96ba171b-776c-d1233
96ba171b-776c-d1232
96ba171b-776c-d1231
96ba171b-776c-d1230
/.0.1.43
96ba171b-776c-d1459
96ba171b-776c-d1458
96ba171b-776c-d1457
96ba171b-776c-d1456
96ba171b-776c-d1401n
id??
96ba171b-776c-d1451
LegalCopyright
tst.dll
$p'
96ba171b-776c-d1342
96ba171b-776c-d1341
96ba171b-776c-d1340
96ba171b-776c-d1347
96ba171b-776c-d1346
96ba171b-776c-d1345
96ba171b-776c-d1344
96ba171b-776c-d1422
96ba171b-776c-d1423
96ba171b-776c-d1349
96ba171b-776c-d1348
96ba171b-776c-d1426
96ba171b-776c-d1427
96ba171b-776c-d1424
96ba171b-776c-d1425
ProductVer
HTc
ZD~
b=:
1.0.0.0
aKM
IMaU
96ba171b-776c-d1309
OriginalFi
96ba171b-776c-d1308
v>G
b=C
96ba171b-776c-d1165
96ba171b-776c-d1164
96ba171b-776c-d1163
96ba171b-776c-d1162
96ba171b-776c-d1161
96ba171b-776c-d1160
96ba171b-776c-d1286
96ba171b-776c-d1287
96ba171b-776c-d1284
96ba171b-776c-d1285
96ba171b-776c-d1282
96ba171b-776c-d1283
96ba171b-776c-d1280
96ba171b-776c-d1281
96ba171b-776c-d1307
lTrademarks
FileDescript
96ba171b-776c-d1306
St$
#s$
96ba171b-776c-d1466
96ba171b-776c-d1467
96ba171b-776c-d1464
96ba171b-776c-d1465
96ba171b-776c-d1462
96ba171b-776c-d1463
96ba171b-776c-d1460
96ba171b-776c-d1461
96ba171b-776c-d1468
96ba171b-776c-d1469
96ba171b-776c-d136
96ba171b-776c-d137
96ba171b-776c-d134
96ba171b-776c-d135
96ba171b-776c-d132
96ba171b-776c-d133
96ba171b-776c-d130
96ba171b-776c-d131
n`HM
96ba171b-776c-d138
96ba171b-776c-d139
96ba171b-776c-d1260
96ba171b-776c-d1261
96ba171b-776c-d1262
96ba171b-776c-d1263
96ba171b-776c-d1264
96ba171b-776c-d1265
96ba171b-776c-d1266
96ba171b-776c-d1267
96ba171b-776c-d1268
96ba171b-776c-d1269
96ba171b-776c-d1305
96ba171b-776c-d1304
96ba171b-776c-d1303
96ba171b-776c-d1302
96ba171b-776c-d1301
96ba171b-776c-d1300
96ba171b-776c-d1429
UyX
ProductName
ig5K
96ba171b-776c-d1413
96ba171b-776c-d1412
96ba171b-776c-d1411
96ba171b-776c-d1410
96ba171b-776c-d1417
# $ % & ' (
96ba171b-776c-d1415
96ba171b-776c-d1414
96ba171b-776c-d1419
96ba171b-776c-d1418
FileVersion
dNn
ProductVersion
0.0.0.0
OriginalFilename
D@}-
NX#2
+wP
File
`_>
96ba171b-776c-d1139
j@~
96ba171b-776c-d1130
96ba171b-776c-d1131
96ba171b-776c-d1132
96ba171b-776c-d1133
96ba171b-776c-d1134
96ba171b-776c-d1135
96ba171b-776c-d1136
96ba171b-776c-d1137
Pr"
tst
96ba171b-776c-d1416
e9O
96ba171b-776c-d169
96ba171b-776c-d168
96ba171b-776c-d161
96ba171b-776c-d160
96ba171b-776c-d163
96ba171b-776c-d162
96ba171b-776c-d165
96ba171b-776c-d164
96ba171b-776c-d167
96ba171b-776c-d166
N~U
`<:
96ba171b-776c-d1185
96ba171b-776c-d1184
96ba171b-776c-d1187
96ba171b-776c-d1186
Ss)
96ba171b-776c-d1180
96ba171b-776c-d1183
96ba171b-776c-d1182
96ba171b-776c-d1224
96ba171b-776c-d1225
96ba171b-776c-d1226
96ba171b-776c-d1227
96ba171b-776c-d1220
96ba171b-776c-d1188
96ba171b-776c-d1222
96ba171b-776c-d1223
96ba171b-776c-d1488
96ba171b-776c-d1489
AUh-
96ba171b-776c-d1343
awosalaqumodumojoduc
FO~U
-1J
96ba171b-776c-d1428
96ba171b-776c-d1350
96ba171b-776c-d1351
96ba171b-776c-d1352
96ba171b-776c-d1353
96ba171b-776c-d1354
96ba171b-776c-d1355
96ba171b-776c-d1356
96ba171b-776c-d1357
96ba171b-776c-d1358
96ba171b-776c-d1359
96ba171b-776c-d1455
96ba171b-776c-d1454
96ba171b-776c-d1453
96ba171b-776c-d1452
\T}
96ba171b-776c-d1450
vTc
Copyright
4c7ba141-effa-f0
96ba171b-776c-d1420
g:M
96ba171b-776c-d186
96ba171b-776c-d185
96ba171b-776c-d184
6.7.14.1
stan crrr.exe
MU]
FileDescription
96ba171b-776c-d1174
96ba171b-776c-d1175
96ba171b-776c-d1176
96ba171b-776c-d1177
96ba171b-776c-d1170
96ba171b-776c-d1171
96ba171b-776c-d1172
96ba171b-776c-d1173
96ba171b-776c-d1178
96ba171b-776c-d1179
be*
96ba171b-776c-d1378
96ba171b-776c-d1379
96ba171b-776c-d1218
SwS
VS_VERSION_INFO
MM>I
96ba171b-776c-d1387
96ba171b-776c-d1386
96ba171b-776c-d1385
96ba171b-776c-d1384
96ba171b-776c-d1383
96ba171b-776c-d1382
96ba171b-776c-d1381
96ba171b-776c-d1380
96ba171b-776c-d1370
96ba171b-776c-d1389
96ba171b-776c-d1388
96ba171b-776c-d1371
96ba171b-776c-d1377
GQt[
mpanyName
96ba171b-776c-d1493
96ba171b-776c-d1492
96ba171b-776c-d1491
96ba171b-776c-d1490
96ba171b-776c-d190
96ba171b-776c-d191
96ba171b-776c-d192
96ba171b-776c-d193
96ba171b-776c-d194
96ba171b-776c-d195
96ba171b-776c-d196
96ba171b-776c-d197
96ba171b-776c-d198
96ba171b-776c-d199
u.K
96ba171b-776c-d125
96ba171b-776c-d124
96ba171b-776c-d127
96ba171b-776c-d126
96ba171b-776c-d121
96ba171b-776c-d120
96ba171b-776c-d123
96ba171b-776c-d122
96ba171b-776c-d129
96ba171b-776c-d128
96ba171b-776c-d1255
96ba171b-776c-d1254
96ba171b-776c-d1257
96ba171b-776c-d1256
96ba171b-776c-d1251
96ba171b-776c-d1250
96ba171b-776c-d1253
96ba171b-776c-d1252
96ba171b-776c-d1314
96ba171b-776c-d1315
96ba171b-776c-d1316
96ba171b-776c-d1317
96ba171b-776c-d1259
96ba171b-776c-d1258
96ba171b-776c-d1312
96ba171b-776c-d1313
Hercules Inc.
I!I
nbNH
96ba171b-776c-d1400
96ba171b-776c-d1402
GO~
96ba171b-776c-d1404
96ba171b-776c-d1405
96ba171b-776c-d1406
96ba171b-776c-d1407
96ba171b-776c-d1408
96ba171b-776c-d1409
23qo`
96ba171b-776c-d1138
e8L
Comments
Aa:
yright
Translation
96ba171b-776c-d1109
96ba171b-776c-d1108
96ba171b-776c-d1105
96ba171b-776c-d1104
96ba171b-776c-d1107
96ba171b-776c-d1106
96ba171b-776c-d1101
96ba171b-776c-d1100
96ba171b-776c-d1103
96ba171b-776c-d1102
96ba171b-776c-d1318
Ps)
CompanyName
a8?
e8>
96ba171b-776c-d1473
e8:
96ba171b-776c-d1211
96ba171b-776c-d1210
96ba171b-776c-d1213
96ba171b-776c-d1212
96ba171b-776c-d1215
96ba171b-776c-d1214
96ba171b-776c-d1217
96ba171b-776c-d1216
96ba171b-776c-d1219
Lega
96ba171b-776c-d158
96ba171b-776c-d159
96ba171b-776c-d154
96ba171b-776c-d155
96ba171b-776c-d156
96ba171b-776c-d157
96ba171b-776c-d150
96ba171b-776c-d151
96ba171b-776c-d152
96ba171b-776c-d153
96ba171b-776c-d1198
96ba171b-776c-d1199
DD-
96ba171b-776c-d1192
96ba171b-776c-d1193
96ba171b-776c-d1190
96ba171b-776c-d1191
96ba171b-776c-d1196
96ba171b-776c-d1197
96ba171b-776c-d1194
96ba171b-776c-d1195
jgOC
96ba171b-776c-d1167
96ba171b-776c-d15
96ba171b-776c-d1166
96ba171b-776c-d1365
96ba171b-776c-d1364
96ba171b-776c-d1367
96ba171b-776c-d1366
96ba171b-776c-d1361
96ba171b-776c-d1360
96ba171b-776c-d1363
96ba171b-776c-d1362
96ba171b-776c-d1444
96ba171b-776c-d1445
96ba171b-776c-d1446
.v/
96ba171b-776c-d1369
96ba171b-776c-d1368
96ba171b-776c-d1442
96ba171b-776c-d1443
PwU
96ba171b-776c-d1288
96ba171b-776c-d1289
jg9K
k`=9
%w!
StringFile
VS_VERSION
96ba171b-776c-d1169
96ba171b-776c-d1168
+u"
96ba171b-776c-d1149
96ba171b-776c-d1148
96ba171b-776c-d1141
96ba171b-776c-d1140
96ba171b-776c-d1143
96ba171b-776c-d1142
96ba171b-776c-d1145
96ba171b-776c-d1144
96ba171b-776c-d1147
96ba171b-776c-d1146
dLH
ZT`
2018
VrW
*r!
96ba171b-776c-d1394
jcL
96ba171b-776c-d1396
96ba171b-776c-d1397
96ba171b-776c-d1390
GRyU
96ba171b-776c-d1392
96ba171b-776c-d1393
Recovery Manager for Active Directory Forest Edition
96ba171b-776c-d1398
96ba171b-776c-d1399
96ba171b-776c-d1153
96ba171b-776c-d1440
96ba171b-776c-d1113
96ba171b-776c-d1448
#u)
96ba171b-776c-d1449
96ba171b-776c-d1321
96ba171b-776c-d1320
96ba171b-776c-d1323
96ba171b-776c-d1322
96ba171b-776c-d1325
96ba171b-776c-d1324
96ba171b-776c-d1327
96ba171b-776c-d1326
96ba171b-776c-d1329
96ba171b-776c-d1328
96ba171b-776c-d1482
96ba171b-776c-d1483
96ba171b-776c-d1484
96ba171b-776c-d1485
96ba171b-776c-d1486
96ba171b-776c-d1487
96ba171b-776c-d187
ion
000004b0
oductName
96ba171b-776c-d183
96ba171b-776c-d182
96ba171b-776c-d181
96ba171b-776c-d180
96ba171b-776c-d189
96ba171b-776c-d188
96ba171b-776c-d118
96ba171b-776c-d119
96ba171b-776c-d1447
96ba171b-776c-d1480
96ba171b-776c-d110
96ba171b-776c-d111
96ba171b-776c-d112
96ba171b-776c-d113
96ba171b-776c-d114
96ba171b-776c-d115
96ba171b-776c-d116
96ba171b-776c-d117
96ba171b-776c-d1248
96ba171b-776c-d1249
96ba171b-776c-d1242
96ba171b-776c-d1243
96ba171b-776c-d1240
96ba171b-776c-d1241
96ba171b-776c-d1246
96ba171b-776c-d1247
96ba171b-776c-d1244
96ba171b-776c-d1245
96ba171b-776c-d1481
`H>
MYh
lc<L
.dll
96ba171b-776c-d1435
96ba171b-776c-d1434
96ba171b-776c-d1437
96ba171b-776c-d1436
96ba171b-776c-d1431
96ba171b-776c-d1430
96ba171b-776c-d1433
96ba171b-776c-d1432
GSh
96ba171b-776c-d1439
96ba171b-776c-d1438
96ba171b-776c-d1319
$wR
`OM
`OJ
$wW
&pW
96ba171b-776c-d1421
96ba171b-776c-d1310
dHC
96ba171b-776c-d1311
96ba171b-776c-d1395
b<8
`HB
VarFileInfo
96ba171b-776c-d1112
96ba171b-776c-d1298
96ba171b-776c-d1110
96ba171b-776c-d1111
96ba171b-776c-d1116
96ba171b-776c-d1117
96ba171b-776c-d1114
96ba171b-776c-d1115
#pP
96ba171b-776c-d1290
96ba171b-776c-d1293
96ba171b-776c-d1292
96ba171b-776c-d1295
96ba171b-776c-d1294
96ba171b-776c-d1297
96ba171b-776c-d1296
\D^
d?L
[L#
96ba171b-776c-d1181
96ba171b-776c-d1229
96ba171b-776c-d1206
96ba171b-776c-d1207
96ba171b-776c-d1204
96ba171b-776c-d1205
96ba171b-776c-d1202
96ba171b-776c-d1203
96ba171b-776c-d1200
96ba171b-776c-d1201
kcKN
96ba171b-776c-d1208
96ba171b-776c-d1209
96ba171b-776c-d1441
96ba171b-776c-d1391
96ba171b-776c-d1189
96ba171b-776c-d1221
96ba171b-776c-d1471
96ba171b-776c-d1470
OX#2
96ba171b-776c-d1472
96ba171b-776c-d1475
96ba171b-776c-d1474
96ba171b-776c-d1477
96ba171b-776c-d1476
96ba171b-776c-d1479
96ba171b-776c-d1478
NX#9
'uU
96ba171b-776c-d143
96ba171b-776c-d142
96ba171b-776c-d1228
96ba171b-776c-d140
96ba171b-776c-d147
96ba171b-776c-d146
96ba171b-776c-d145
96ba171b-776c-d144
96ba171b-776c-d149
96ba171b-776c-d148
96ba171b-776c-d1273
96ba171b-776c-d1272
96ba171b-776c-d1271
96ba171b-776c-d1270
96ba171b-776c-d1277
96ba171b-776c-d1276
96ba171b-776c-d1275
96ba171b-776c-d1274
96ba171b-776c-d1372
96ba171b-776c-d1373
96ba171b-776c-d1279
96ba171b-776c-d1278
96ba171b-776c-d1376
Copyr
96ba171b-776c-d1374
96ba171b-776c-d1375
mbly Version
$sP
2018 Hercules Inc.
u
Assembly Version
96ba171b-776c-d1299
tst_dll
GM~
96ba171b-776c-d18
96ba171b-776c-d19
96ba171b-776c-d16
96ba171b-776c-d17
96ba171b-776c-d14
96ba171b-776c-d141
96ba171b-776c-d12
96ba171b-776c-d13
96ba171b-776c-d10
96ba171b-776c-d11
GO~U
96ba171b-776c-d1291
96ba171b-776c-d1158
96ba171b-776c-d1159
96ba171b-776c-d1156
96ba171b-776c-d1157
96ba171b-776c-d1154
96ba171b-776c-d1155
96ba171b-776c-d1152
96ba171b-776c-d1118
96ba171b-776c-d1150
96ba171b-776c-d1151
96ba171b-776c-d1119
"sR
96ba171b-776c-d1403
StringFileInfo
96ba171b-776c-d1129
96ba171b-776c-d1128
96ba171b-776c-d1123
96ba171b-776c-d1122
96ba171b-776c-d1121
96ba171b-776c-d1120
96ba171b-776c-d1127
96ba171b-776c-d1126
96ba171b-776c-d1125
96ba171b-776c-d1124
$this.Icon
W&[MQ
Zd*0
q8q>3a
U1V
#Y>J
4&16
PNG
Q$2=fGC
zRC
;J@z
t;deO
q @f
5#gf
iW@/S
s<sR
IS'z
iX&/
whqg
Q94D9D5878CE343F3DE3626769AD500
CswE
ResolveEventHandler
f+2V>
dsV(
FG8E$
:=r1
Z5S>
T :
UnverifiableCodeAttribute
(qDx
]NM0
#hnh
P5C
| 6p
zh6 ]UU
XX3x
oU}m
JbH^
G8mr w
o/D
cq(Z
c4![("F
K 7b
ll[ww
8CD
vK 37I
a :9S
+QvD
Q>D
[e7Z
UV#-
F=::{
\v n
gZl
uptd<oeutral, PublicKeyToken=b
Li"$
l|G:
&")(Y
m}u"
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.Properties
zg{_
O}k+
?uZ}
r)Jc
kKzlC
Int32
gBy91m
Nr @
y%*R
O{C^
S@C*%%
3`=Z
eKOp
Jc90
4-if?
g\#P)
:5c7
(J|\
b5sw
]$\y
k&1{
L7r:
rP?DVvx
/+xt+6MTNV
3
U(6p?
bKVps
CommonStartup
\[ah
BX=}
L}$D
YrYv+
| .G
\H'K
f jtJ
?7n'~
;@0 }
U9)D
^dm+
@#VV
Recent
Z,9Sl
cg~?
iT4f
Ooq.
9 I+
l+ 4
bq'2
Bhk
ka}44<
qz5J
K(0u
bT "
Bw89Z
YL"[
vs$H 8k
.!h@<
@X%z9
w^[
ZJe[*
get_Proce
8>z?
G{m(
D?r3
RhW~
?.U&=p".
HP P[[
Format
lCQ
+>!
EAog
@qrshcutes
QRQ=
X,@1
fbss
B(y(
tNj:y\
*bAcXS}D
ly{m
-4I,_
;MAK
7 @
J5&KcfoZ@a
:.f
5NOh {
q 5Q
<^GI
LpGI
Zdq`8q
tE* <y
Ma^N
7C @
5hP(
6vw2)=~7ZKGtZ'OApq0\X`9)!
Gm8
xwuh
]5B>O
PXK
|Bg^
:4Bn]O
OpenSubKey
J(SU
zl!5
hOT.u
OrVl
SOFCryptoServiceProvider
EW @
HCHz
`!Rv_
qjR7
z]i
UXHC
;qq:
6N*
1{bVCQ
D'Vy
set_Text
uCf
yTx
}1y
Utnfsams
XO32
=c.E9ft
x@0dy
z Qh
FK.QxZVkoG
s3){
r'q51
S8yd
ihKA
fNe}x
/D%$
o}7*
$}H)
n)j- 9
7x(&
^Iib`mPath
~wG_%4Q
2wxza
;*,!!
< MxS5>%Wa6
+cyr
ld5W
Tn`lingTiles
)LOOE
y f,ye
4V;mx
Z@WO1s
%Q87
FtxquoStream
dKoHU
]05K
dr1Q
RQ x
w(lA] (
j.K8/
P*g4
fpY3
,*Hi
TC43
]f 7}
o'b"5 eT
P%>t
nabd
'\U~Y5
xyW7"&
A! GYj
DefineType
V`-X
eYY
wG;,
{ 2sr
WNup
v#@\4-
\Xe
?WlMz
O`hx
m|@hmdVersionAttribute
*E:L<#'
IU |
L;+
LfG~'}M
e j%
,W{j yE
i fn
D_N`
&&mE!
?Yo *
r`kcmxTrademarkAttribute
H78V
GetValue
Slhfunnes
D%_
y}P4N:A
IDATx^
TK[O8
M/!I
K.!G
O~l{{
System.Resources
CeqR
Rf @
get_FullyQualifiedName
uQ@m;
MaQ '6
WW#FoC
, "y
'8DPy,
?14IW>G
PtrToStringUni
V`FK
UBrD]'O
System.Runtime.In
,+ "0:>
&'._x
TMCI
:y..zEr
RegistryKey
`46qCd
tAoe
RJF3
TuRQ
gBRe(
QcsY
4 k[
C\2JY
.text
08#dz
K6[?
LUi
5{vi
x\A"
GetObject
Mn
]W$&h
K PE
B9Su
Thes
GetExecut
S[Y(Z
$Mq6
Zj~:
6rBX
object
yacQ
qj D,
F:71
FdtCurrentProcess
'_Gp
B-9A
M8T~
9tT~
fP ~
Fz&w
d8R$
/S0K
?IG'
+;!Z
_duaIeV
v9G>
Yb F:
D EI
c}l_
Rp`X
e Q-
c($>Q
``%/W
( 5y
t,b]\f+
~\e#
7tkrhldResourceSet
a&Y0 u
v}zY
#b}c
.0c
UvSp
>-h+Tj}
k}^s
>dVY
=Ee\
`f2g
GJ-b
lm2f4
hDestinatio
y6?K
\<_~
12?C
czw{
D.C=
#S;_
Y{B(
+gff
`vML
Conversions
Z-j l
Yj\P
W5'2k
xGwG
k`}/
JPREXl
fI3x
!,
m!h6
eM_l
h2Xv.D
m-{43
*:
=$!@
StackFrame
Cf2 ;o
{O_?
PublicLibraries
NGS
_W=7
Fcnh
t7,6+
.ctor
K Nr
get_CodeBase
{&Vc'
X&R c
A^6V
auE
*klLg
!RkS
5'uP
Settings
t)d
%{[ik
9"2q
N&&ySX
GZD*
dqv~
}=lCB>
w yB
wj/`
JC)[
[9uZZ
:?RN
fY3x
k2.CXV
7<c
Z 6}J
e6#H
!jG9
macs 05.0.0.0
RI3
`&^d
~f_l
,WI[
97*,
C$(^(
&/!x
b>CE
Lv^@D
T/(;Nh
Q228
?@ x,:y>pE
1|;*c
l_tT
X /Ml!
O~ ]
e}"r
>'z4
0 ##G
).(eOJj
~"14
MCM
z]J
BzSy
TargetFrameworkAttribute
S2)<
zR-C<
_xe`,&
+Yp(f
SearchHistory
Fb(G
S4>}I
!z[
u]sY
%G"F
T(T]%
'EUZ
'_ z
G0 <kM;
!Uwb
g]s^$m
;z%i
Xrn
J[0m8q~"
get_Assembly
` +c
[x >
;bU-
@ Uk
;H#P#
;+7W
3:z8
_/ue
~xT>
?7?+
v!/'
U*
XF"/x
IKA
.gF\
#01>5@078ECE6EBC6B9CBABC
Y|ndR
Di#c ;/
lYFU
FivKTK
vK8<
YJk
:]eij
BnlputeHash
vY{p1
q }o
N3.e
DRDwP
7Z_t
^9[E
{{xm
="TA^3a
&5>Q5<>
59L]
('IqwB
1$ (p2
!fnK
?s;mLi
4^wX;&
(B8
sW-#
VH=Y
j<(5
7&U-
hkW *
xh:h
FP.HS
8,%v
(9a4y
=6n4
+!U1B
.$ui
IHDR
_wdnq'
s%]wr
zI(G
DFqU
2 @3
cLIW
'De%r
iw#P[
HJ>t
]O2+`
@+RS
oo<c0
uX!k
C!RDm{
U)[8
eJ;N
\?}[TL
(+!O
(j>7L
]:@r
T#76
System
i2 y
%tWt'
Application
[u<n
`dRB
5 jWc
vO<\3
"4w
.lA!
k;d~Z
AQXD
t7F\
w0M]
ghJ[p
~_DL`
J> 3z
hgsud
@teq
6g(+?
I%LS4
-mL2
Y$` G
{4C$l
Nr*O
_*3
[9 H^Fj
;93ZN
XB8M
|S@d
l= wv
4z0 gk
1=75
[Q5Z
|A)r
C*Pv
PxhP5@
@k+
U$s?
6gIt
SaZ\
Publ
width
Gjjeds
d"}u
rR*C
U@@31
)iPCo
>[ 3
zv/J
Xcue
1?N 5*
jl:$
3 tZ
Qoa`p
x)/qQ
:#IC
i&Y`
@.NG
Yq%4
?-$Z$
z7!o
dQM=
bytesRead
;G(jt
0oO2
SI6&
B,Di {
d Fy`
uE:|
>#]`
sC:Df
~X!sY
vX^>?
'DZk
)llH
y#Q\E(7cF:?
zc @
~SL3F
ufMy
<3`]
]g-z
bsOF
Module
e"IM=1Z
r #g
>s
fZal
7&p
cFO04hT
[2Ff
4zD >
f I
KV~l
c;uDx[
)aA0jz
#&"m
;t_r
Tn`lingAppData
/a~
.+k2>H
IILe
(4.
Kg:IE
RtE8/
IPXw
m]KR
g:Q*
['@{og#y/
I X0
sc-d
_?V;
PYB\
}&$?
` QFA>z
^EzC
jPa9{
_CorExeMain
8IAc
f#xl
Jo Wr=] @
Desktop
AI=u
;xfS
O"9Y
\\k
'G@mz
qeR'
QhQ=
x{[ 2
{{`UHlQ
Ok|O
%-4*.-Ku3
@v)Lt
@t]A
c=o:
.N|^
kC?=@&
lpBaseAddress
z_| O
W2_>,
7=/zr
@Gn)
ck (
Y7 l
Z=xB
zCog
?gtC
oHvA
{q/f
`!qb
W,93
Rt^v
n]pm
_:xa
XUS-
V97G6D9CCDAA40F30CEB9ADD9A77
/g}5&z
;*1IS<F
|d9=&
s@7k
Q{*N
1p0.
Lc!(E
$ S?
S(a$
oz9c
BGc>)
pB iz
},oD
/..*
FNG?
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
fx%}
p>.a
x&hv&
'd0YD
h-HB
address
Z9+7
D#C3
CN="
fW+=r
fx\.
7 n N
^G8d
rnw+
?18Iwjo
#TbJd
t quX
P 5~vY
Vtqv.8]
<86Jz
n/^+}
,H3!\h>
df8&C8
f"Sx
ilV"
-7kE
v8~p
8c~_
"Bn%
B<WD
Y v1kPj
HDB{
']:C
set_Name
q>aHh
Default
2`SS%yfk
f /
HFj%c
sdDG
|S+Q
u`Uusdam
'GC }
:7>1
Pn[Cl-
Obwx
>$oM" @
_tI'
@+9Z
X7jVV
K;]AL$9*+
`#rv
tdrIzG_
1q>c
TWW#
YJeq^
+ yJ+
{ Jj
QV)M
Oj#<
[AXV F*
HTbu
epOW
=Y,^
MI_ea
WxFQ.
(34M
6zkT
$8mK
o&2"
Cdgb
2B_e
k)%8E
QOq$V
mlW%
EpI
`qonoGlags
)PlY
1};
;bVrH
/o4XAM
]V+S
?{Hz
0vi$
LPON
rudm.Drawing.Imaging
4
v2#b
kTB1
QxZN
"RKUg%*
MFwJi
v!!i
k5QrTI{6+ x4c*ut-v{8NBYn#
p[!A
SL\,
XIUo
b`mlback
i\ut
u~Lz
^g`Z]s
8c6}w,
'twhhof
o4t#
.v5<
sV6U
=I}
&M$R|j
U1e\Y
_:_*
+Izp
~IDF
ku)C
'!MN
#A!n
+&CL
'> p#F
84l_
I|qw@
Or o
2SQ;X
u lsd
XH<NwL
c
W9Up*
7HTz
6:m"
`'=6
dY[_
#x0M<8 J0
8LW'
dBwj
V@ne
g&N,H9Uh
"YAg4@
2 B}
M]B,
f{]x
m4,*
SetImp
uZ:>Z
,s]F1
'nil
JRw=K
UhV4
YP\h
d^-$6
r"HO9
v!tb
>`?}Lxeyd
c>%:45
c_GN
=gx>
% &F,
PCr.d
Cgt-Z7W
xC%cP
<PrivateImpleme
7 \:
lVnq
J5Fo
m$>l}
V@n"
U3I k
]<(4
SettingsBase
dsq
c*jc
mzx>
-=\W
bWw2
)$*~
o\-{
hyIoz
!p6E
pUo[G
;] '
*ePX
Av )
SgJ5
QFE
e=L'
HK|x0
N a=]
bJS3}vL6
9Ju]
yA8
History
BX>,$
J>A="HD
^n1oZ
d+La
T<e9tX
83&
P Dd
!`6y
,r=\
Rystem.Linq
`KkW
w~go
Jv3+
11.0.0.0
,8 w
GiXy
"<Fx}
ChtConverter
BAv7
Ztd5+
$K%*I<:
Invoke
g"Q+*
;UHM<fUY<fY^<fY^<fY^<fY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jYb<jYb<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<jY^<fYQ<jw+</3
XT-
wlx~2:j
JCF>S
w<aI
>/ah
6`sc
jtOL
Q]u~q
&DBb
1d>B{!
buffer
~<.,D
SA[`"
O:;'C
=;:#
[dN-
ZhH7
io~|u
q0 8&
a+5$p/
Ii 1
$zmsQo
*C; 7}
$`NT
oUw9!
X
pi'?"
R0g"
MeF~
?WBv{mI]
[v9
V] 5
''#x
$GH^
61Uy`K
F] 9
HE`0
cyU'
Wbdw2f
h9`
u7En-
+{ J
0{K
r63W
\XP
7eJJ7F
d::bW
VYJ[e
rnoE!
:uGM
UlaJ
faiZ<
.c"hd
H&M-
$rvclcmy
^Lv
Akaa
&v<J
b.BU
](r_'t
v7ie
?t&U
Dg\x
Dr4/&
(JLe5k
BP P
*{ZY
Q(h<~
qxpou
G\Or
??6k$5
t L&L[
nYD|
DV<PbN
bH$o
WRRc
fP,9
X^Z0o5B
9\bw
+ z}
V`itForExit
ZGXE)
U0$6G4
}w4k
gvbq
$bhb_
`#OMo
5kWwJqKc
C/; Lo4pNCYUACYA$j3g3Vw1%
i7
bQC4>0xd.#
SkWC_o
?T4>
Directory
>& C
I.9g7@
?X9
*eW5
g?qV2
6d0D
O0sB
.6~1
y 4M%.x
OF \0
!YZ;2
[oFCc
gZO\9e
JM=O
V~Q&
p{6/
RuntimeCompatibilityAttribute
/80^
8
rp )
1_D9
P7yL
0C18
System.Securit
-*Co
o`Mq
dT->
d R+
&S'6
LQr~-
XkbS
j1Jx
kL]!
tn,O*
s\$GE
[Ev
$Di/E
"HAM#
K^?]n}c
CKm"
H=l"
?'L3
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
Size
FnKG
:o1#X
tsc
F$v>
`ip4]
E5h^
lpCurrentDirectory
h\+<
v qgV0
$4`
Le]MML
U)Nc
T!G#
Lw^.Z>
H[8
8[*C
hvio
wR?Is
pt8^
aWny
Q}fi
6Q)
[5 4b
4w<,:1
gr 7
m^G>k
E7rH
p/G)
IContainer
EQ'8
b$eO
lpEnvironment
;D~
%r
6eDm
i}ovFW
xBo&Z
6_n.
JPEk
p"` sa
_`k;
\;[*
p[9a
8lZ;
{pLf)o
}-Jz
V4wDzO4
tqyA
bytearr
C]=pPc
\ar
|PhvxT
>,hk
gGz #9
Nil6
w@+i
!p3!\
TBW$
,p_e
?b Tp
Az_s
-q1',
yH2a
[1E)
{{<a
dBs+
p 8@
V'.
\uW%9
v,:.
FsC=r
$8! 7
ResourceManager
wNR<+;
p6KH
GetExecutingAssembly
rNcx
\?2~^t)
7n#4
ld^E
kpo1v
1*!e
TlF"F
Jd8C
ContainerControl
{$ T
m@)Z_
35?
L=Z`
7.iD
5MI
BY 1*8
]l;E
ToInt16
k @H
v^ne%L
+FhY
LQEa
khN],
X_7o^
m+eS
EX_}
99c+6b9;$#
F.Yy
MGB
Z5-
>\2L
"8y'
KMYy0Xu
0=P"
;kTJS
=uOD
TH_ uln
:HMrS
pp$,
I>RZ
r9Ua
V~63
x[!3&
VN~nMF:
hThread
h53
/aeb
K^B>
/$Qr
2I`y
BlSL
E5Mv
^^IV
Empty
3h l
{\[5
To@;S
$11675e66-8c06-4767-8687-980f0a9f6d0e
m'_U
Mh[|q
Z*Yt
h-z{
*+|>
YHQx
`XL_
?|9P
>N]|
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.Properties.Resources.resources
0|ef
%E4X
Mo.Gi
t+9Q|
FileShare
) p
o"a
A1cR
<"=aZ
/J#k
fHt"X
n~th
xUp
&vfa
*>_F
/2EY4
Jqb$H
;"o`
h
MessageBoxIc
l :N
Close
# 6u
}X:.$
P wJ
n 8{
{A]i
Bb]F
[\nMR
vx<
NAU{ E
A!O)X*
GStl
\y#K,
3[<Im
dm]>pr
4:et4
EshvePictures
tN'S
J_b"`
Read
z;~-
{I"w
2Cs
3;XEf
UALug<0
K j7]
1-+
S!P6C
+> !
Ac(\S]
EjtR
&!d P
38H2N
Q5.c
5 C
&TlZ
mHd T9
joY5
4,rmu
:)j|5
"dF3
z [K
;0Nc 9
zYk/
5sn8
&rZ
Nx\3
C}@/8
}O%9
T3d=
jIKj
3iDjb
m22S5RTQ]):8-W[Jl5*Ptyr(
nRi
Cr:O
bwgxZ
mscorlib
)Eo%8
SkyDriveDocument
6[M~
{R8rc57
^k;-
w}G{
!: UQ
dcsC
)x9J
|}4l
newpath
'xqcr
qk0e
Y*'#
"-*HP
SdXUB
+jqef\P
Y4*
VDPw
sN2W
7G51C5B2ED023216838FACD165AA2F
-?|W|
Guid
e,aB
s{}t
dmyj
.ZB6u}
R@07
$d\~gH^
t=Sg=X^h-"c^~"N?JAHjg5o,+
>_gN/!;
1"}
f /k
^47 G$
MNG3-q
`[eX
Q+]Z
/pd_
AesManaged
g6CVU
b)p&
RuntimeTypeHandle
DH3C
Ut<.
Yyj1
a]u>>
X MA
}_E{
Q[EF_
jQI
77 x
?"%1
2s9U
U~JJ
X3{M
2U)=
oUh~
"}Nk
i a)(C
a`M@VP7
' rp
SfL&
8RlPjq1YDe
$j y
9LDy
q}iu4
AHe:
pJ^A
#,0N
/.'bN|
o$"s
tW"
6bSv
0(_-
<?pl
="0|Uh
,y
,jS}F
%S j<NP^
d`wQ
w8LL!
5rUS)`
daRWMhbrary
Y hF
/Fioghguration
6/Hnm
JE$4<}~"
hqs{
&I%7
x[nY
C[$
Mw(T
4|xo)
K ;
* j19
ZCo<
y[wR
i,.`
t#X
s-sn
]L5k8
J9Yl
7Rsw
Gk,;
Y<1k0
6d6[
x~1![
!m:
oIM=
c"l6
%> u,Y
K t
"($l
m/$Vc*
n6es
z?}i
H$as
{+MB
$nf1
bZ]D{
dI`u
#
w6Y>i/
wS|OrS
x{uE32 Z
<Gj'
b%J 6
^6nx
)hG|S
,Dab
Q$AUcx
}|\1_
v+{n
"zCv
threadHandle
+\k{+w
C09
kB~vO?;uMUnCMMUS$+,>12'`!
F5;
fJ">
^OKuUq
!This program cannot be run in DOS mode. $
L1Ll
R1nF
7u8Z=E.
$`W&]g
<f[G
gp39_k
Dispose
I| +
EWa
?l4,y%
6$Bc
_LLb
7ZvF
^jNt
ulT: w @
!
9FQ
e_(^]
t3"i)
c0 A
_1!-
}XX@Br
rkCB4C
fSJFX
EwP~
set_ClientSize
$@F s
dj>"
ZSniI
r{/U
}>paY
eO3O
CJxr
= =C
fhL(t=
---
ds56
)r}=
n3LQe
4fteT
<Z}/tm
ZQ|?
Bryq
c;>G
1oD^5
;& ~
9hs#g(
w1('%
9r 7
I%6ZCT
QPWjO
.|+'IutTq
E(X:.
8f}C
GeneratedCode
.MW"o
[Wz{
2SEE%]FO
3QMr
La_`
Qm.@
44 R
TA%5o
fj]^
[m/s
pLMg
4^ ?
Nt1,I5d^$I#0]vvV-!wX^#mW
rIcd/
%lmY
-#~[8
:S;^
28]}c
z{][MfU
O-w*
Cmy5
|vl(
%<26
, |@H
,2H/
ng8$
bu!S
%_X9
l)*e
PBGIC
5H.o
>/z{
L5Lx
Qhctures
NYjd
Xz! 6_
b[Wf
y\
+bwHF
!;3 1
uDrushbute
bM=8o
mp(e}:
*hs:9cx
r![A,
/&$p
^m{A
v4fM
B} S
:x.g
z*?Y
s%`
qm+w;
yce
;O.8
BlockCopy
#,oy TW
QRY)
V3@td
grC*E=
QZ-v
*>a6
81X.
Mutex
i.V
@of\
>fh5
@&h9
1w%Sj
7l{\
###I%!
nWY&Z
BinaryReader
S}5"Ip
2%R,
0d<n
set_Key
VuJG
AfxW
z?XY
&, &
?2KP
F 2W#
?pUyg
Z^f6
2'')
}HO&
[z8Y
cjEW
c eWe
lU_2
\W/Bca
k4=]
HttpStatus
:!v
0:0{
e&SH#
?7~ Q[g
l8`m-
jj4N[
;qy1
2\E
e$XQ,
Reco
cejmRt
CompilationRelaxationsAttribute
UZhY
x tV
]L%'O
b^l+ s
MemoryStream
{P_z
jyqd
r(Z)
JBnz
|f4S
V/OH
n3nS
k_BU
d[yP
!'~NvbX2@
aS+<
f=eC
W[wi_Z
5O8z
:+5
4 a4
*SyR
-CU6
T??]
Sg8H<
J@!>
GHo<
J-5geo7
4mn%
9%9%
*Dwl*
04>i
?Y:w
d-ah_
CV.?
?HZ>0
@vI"
}.SmB
< Lo%
:K(:
>c?zE+
E9w
itGN
FF OD7
Ng 8
'&oy
q#QC
#zI-S
\+Q
Un(\
k2gt
%xF4a
IIos>R
r3y5L~1
1QuG
szkM
^l6&
roV9
x6v'
sjP0,
qiu`mFileSize
-J<8
yT v
[.~n
EventWaitHand
*DkpK
yPm
lBvR
OuW
, >I
newPath
bcu^QarameterType
| ]=
Iw'e
Nnhu
=93@

hvUh
#klB y
X?*
Rectangle
zrPTC8
<A;A\~
j96v
W2$`
v^5;F
$y(&@
s<f2
t^E>
YwfJ
>5KK
Concat
*%[W
XI %
>OXW
b,/0$
>\12d
OGFb
*MdJUQ?
)m1h7
c[f2
{,rk`
n6?O
4> /
w$@?
^7.
MW)Z
qlKr
`'ac
56b W
bQQTv
k~dJ
?,Oi
`qcEhsectory
< FE
m o{a
1euQ
?@p hd
n;is
fRW<
4QiN
]&zZ~t
currentDirectory
Gp `
ejNg_
?T(G
/$2!
w@Dz
y*EV
/\Ed
< < < < < < < < < < < < < < < < < < <
<='8
System.Text
q$ NXb
<"Lb
74TD
Y?f1W
n[sV
gqZU
sF#)
vjtjEhsplayName
L4QE
qQ\)
gVgh$
;t$i
j3X
;<~7
|($]u$
Q u*
J_ Tv
6]\
jKs]bY@V
8\nP3[$
* `*
!+A@
T\A6
$qU~uC
y`o
4tru
S\BM:
+w4d
_-zWKu
O<5s
npe
b6SD
+42s4
Q<e2
109@
AR"v[
!C7:
fxr=
Q=y6
hbp4
5}r4b$
\p$S
5![w
w/Tw4pt:
Tdq0
B3E#])
rb,/
Weho
BZ<J
tSpd
p Q?
E1`s
-@UmUKr
defaultUser
bRj!
x *(
>d|Y<}
d>db
Lya:7
w0Ud_
\rb$Db7
zc]3
9Uq>
u4 @
XI>:=
t]xCVg
+jEtN
v4ut#\_
0&i+0
DebuggerNonUserCodeAttribute
COUa
H:8o
k1 '
_<@9
\#2w
/B F
zq=_
dRw\
tsBCO
7VA-
|_sK
%eF,V/
%fyn
a2COup
E,Bf
DebuggingModes
2 7
A5 Ot:
0ErN
B6$kkC
BE'Ob
mchWc
o,3g;
U6<q
ov~,
O-$o
WGRr
rD|V
B$5hMF
v9jz
\UV-
, ]N
$_jC
Eed<uN
4061
.ZiAR$"
+SeBf
2|)#MJ
qbmJ
Jw=/
c'j'
p`! '
a)T%
pr>\Hz
dwSize
;$aL
d0/f
Lvx8
;<Q1
A#x ;C
Ou?=
F<zI
] C>a
c6f@2
I|?k9Q
)z98%n~
.j-
pnAG
V^Wu6U 0;{
$85540@DC7
t+'AJ:
get_FullName
V\<zx$
AD]_
v3f-
\<4j
[~x
:I<~d
G1;N
* $%6
=.W&=
xTrA
!Xp&0
J8|q
UyWk
ewcrr
dB[P%
CallingConvention
])GF
1cN#X
#::
L.C
^uuS
QuickLaunch
x6Ks
@pD0
6 n4V
]f)$
DirectoryInfo
$rvclcmyProductAttribute
'RwG\
Co`E
#|?eu(]
c&L
ICredentials
g?~y`
:!h9
+m[*
#9<U
C*-=!
c\dB
+Xws
y"st
v_"KS
0EU6
Mb}=
-TLe%
S$De
ea&2
<a`L
bSj"
2V]EQ
A:Q
,Z!P
9;n]7R}
vbLP*4o
Afv!
'q4 V
wu~Z,
S/QJ
QPAD
tf2j
:6`v
UXK~
!/
gz]E
Q FB
ElG8\
`7mo
N8 "
P5(
/i?d
P2M9
t,4>SS
d1}d
x5(^
u)p+"i
dLy?
:Y0 ~
$*a*
5,HD[
}!W{
z,Kk
R[xv
=*1&
G:WY
:lpIE4z
-|pgizyN%
HwqZQ
"+Ww
^#e
n#6
D*P
cs=0
\Uq}
1.0.0.0
Y O[
hw#_}b~
<)QI
&2$0x?
'}^(
[Z=/
kov 5s>
ci%m
#OV<]I
Q?Ql
{&vbNi
&^"9
4-*x
1G
CTcE
oha<]z
Stream
=[Y:
System.Reflec
{!&*Un
[Cqo
+{&kj
L1:<
*kv#
lRT T)
7MJMR
;]]pdU
wVK3
b aks
0[(E
nK)%
3qIw
; 2hCB
`Kj"
2$sC
EJ:'Ga
RO:bGu0kfR*aZwbOq ,JWLj %
'x>S"
M)V:[
jw6!
w-e
"g1i
-="z/%
&r^
|bsh
05416AA105229A9
#C%
L;K;l
+\/'
Au4@_H
SESa
)-27
^}[X
e
*N+
jxLO!
9R`Sb
r[8*F
_(D=
tSol
) G%p
G.(]E
RxrtemX86
:lT^;
process
-E1h
|3q#
%K4Uh4
|a J
[*_X
f f
j-D[
FUTOF5
+Bm ^
totalBytesTrans
`luC
dDf'
('iB#
t/M8
{Eb|
6k=5
<sJI|
eR|uudl.Collections
g[Ao
fDurdlbly
CreateType
vp[L
]U#{
#\ @
EV7#
0r?Z
Z?dQC
XXBL
_?^
threadAttributes
8#yO4
"A5l
VBJv
Q*Du}
$ ]!
)0%?O
nvN\e
dzOZ
>q <
qEyI
O@GB
6EF'
VBhnTk4w
`AVu
Z69;
#'(L^>
mY`H
FduProcessById
ModuleBuilder
AM=Dl
Hpni
e'Qn
^PTIfS[
<Ie
PM/S
w8~>
j Q_
z,l3
uJ! J
JX_$19d
p%}r@
Qem
CbjnT
vtGS3
} V
';)a
fML}
set_IV
2CH3
za K
(ue<
y 5C
f f f f f f f f f f f f f f f
W76Jm
`:x$
<N>t
}f e
3hvs`mCasic.CompilerServices
LocalAppData
Q^Z= E
q#2]n
~)j8g
g\/
A& Z
Qrgh
]Ko7
C[ L
7Qj-
HRc1
q`V}
eYov
oHx/]Y
8+r>H2
F]IkP3
[=JL
1`j{
N CM
T8V&
{Q)1
R34Q3%<
{0#T
length
U$#g
Bu|S
bz?ot
D3FI
k4yUN
-lad
YS2m
&5WO
0PkK
SMB~AP
\NQE_
Program
0-oU
`?<l5
{.FK
RieM
`aoof
)5$
} ;o
IbBR
x7kh
JAe_T
-Nz`;
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.Resources.tst.dll.bin
5/oF
a|I8
N:zp`9
U?%v
[y5g
FZkT
daMhM
`6d8
gC/41
}I8F>
NqdnRead
oame
-(2C
1a_@
\\tQY
7A-)82
k@M|-
]yi
-3<Q
gk48
(4~=
|zLM
sJ
0! r
[G~O
{9_
6jDR
8 Z4
qmOfk
8Qt Q2
(G5.6r
x Aq
3UB<>
x|E=
A"1$
l eq
J:#u
@hwm
miZj}~S
]DU#
|&ll
cg$b (%
?tmp]
z.F"
PublicPictures
`lJ7
Rxstem.Resources
xkPE
Compiler
7>u
Qdub
=pq/
7fB5
l(/H
HHh2
G{!Q
QP t
?^uq=
w}_SnHDL
PR;rp
_v>{TO
S}T-
VNXW
so%t
6-l+
&`b
fgy%
?n9
;SrLP
sN%"
{0>9
(U$}hg V
v22Q
^mG6
hl^t
F}x1X
d4PU
pQ^2}l
:X=\X
UW_n
}h_I)@C
=CLI Jb
Q$<K
<W,#
*&TRO8
*?kT12
9IZk
v{fd]
To {
I%\|S
:E`em`singType
5h$n
|95`C
V |?
J?2y
x,x
;vb NP
ys3,
[C(t3z
v) @
yuLM0PER@'
95.z
)mTH?
23!H
?XA?d^
w?=p
:HS$RJ*
(u?}
B 7G
_ly
d(|#
S<N?
{.4}+
4fY u IF
u'>8
?di#
~>O @
=EM\
nq^E
+ >g
}Czb
wV9r
} $D
W_!m:
IVuR
j> !"
~!S1$w~
G@olw
h+f(
A |8Gf xC
Xwc(
?v5B
{Sm1
sKioTrerCodeAttribute
SampleMusic
R0.9a
*Tzk4
-A_#@
0jaNf
g!Bu
dSns
TEWb
0+FBHMM<V
$X8=
lAE9f
#!cl
IDisposable
) )
k O @
P^N*Y
SsVf
[X)'
=@N \
Rj2 k
<M(0
xs0r
~Nu|
C?KT ;;
hprq
%5C#D
e{, `
G7SN
+qw(
NE1h
5:Qc8?
vEsP
)fxn
Q8S
2SEh
;h/[
v>85
I+V`
SsTE
Tt\Ec
fLUv
\Dg.H
I^ep
WtX=@$V4"?
ca|f
_ucZ
|)eB
(uY1@w
1!E![
j[V5
k7Z|_\wxvUy:AgPZ>##jE$*r,
cG9.A
2V F
^s_y
LP?E
Rf\|
>HLmF
MRT7
%o2"
e+9W,
ou3
+Jzo
g^Kq<.
})5U7$I
E[V}
<7.y
myf[
ComVi
h},n
]6=W T
eH++
GGPwh.
/ Z7
gL5`K
hf1LC
)V2c/
X:uZ
:]B]_1=
#GUID
wfOAnUUf
[.s.
d~Fxy
q0tu$
E d
X>-ZuOBX
D C~i
dRON<e
'$]^
kk
#m I
,oq53
mm!D
kSLH
HC @
M *W\
y:]9[4y
C>$d
9m,T
0Yo*
Cpn~
Rw![
SUf"N
=P%;qg@
]`>
iTG""P
/>;A.
CommonAdminTools
JDTn
RlriT
(&bP
=Dd?h
Pbxj3
^e9?ePj`
ytD1
W}~Wz
S&\D
bD*d
fOU >
*$k,
FW B
LS{"&
= xe
B]C"
N(:!
~$mB
&! !c 1N
>lQg
y`PL
o Af
SXj>
Xem^
2nuu%ggh
&6XQ
)(dx
+F5I
P%]M
UG)q
W^~{
?| /
1vhd
^)v|!
ysPw
_/C/`
WEO+
u^5]
C}R)
6 J c i
C+ zOj
iCQ$
n c$
oqo`mr
L4 {
$p @
az6h
BY7g
l ]|
*kWL
TZt:I
k3S7
h:z|8X
|cK-A
ztQb3o
M C<R
J3_C
get_Size
zG A
dZnv
CommonTemp
ln,.
&EXRDZ
iN9i
f-e
`vzFl
Replace
2eT"Rb
B#mv
<d=dt
;X]I
JV P/
>^tL
C'[6L
-grUnD,X
p\vYX
b Q
A7z$uu
XY6p`
(d1I
\tDDW/
+& ^
#1dFnF
k"<
hC M
*l0>=
NkEx{
X.bU
Dn N
xB9A
t@\M
</wa
6@_t
8Gn1
qa|'
s4r9R
9eij
zNAM
hg_m
a3'Om
]>H&30i{MPg
l@-nMz
j!F;5
Qd 9
e| @
ReadAllBy
/]>QaKn
o 5Fcp
-&J?c/
Z| |
tte4
|3;#
cT:P
X6zr
n-=e
4*6y6
GeneratedCodeAttribute
oU&J
N _u
+`hc
A#R:
cO8v,
M8*D
W0>
5];#!5
lU\Kp
{Ned
. c ;
s]6
"-7>
-[($
~$} C
\ij-
\_KZ+
@ I
mo F
9)a:
Kcyu
&a QA
Rk`~W
"/@Z.%
i',:
,8X[
v+ho{
=^ J
_}xS
*"zn
Wv8C
ejvF
+;*
P"J
bNcxUnken=b77a5c561934e089
Xg~.
yC5W
!Y_a
Pyw7
G0`1!,
Qf{zF
C GP
UQ/&
`Pc{
5QpZ
yONLo
PyPHy y
YoPQ
_L6i
u$p
pB}I
e?_&<y@
Substring
nEMw
>5AV@P
EO7H
@qpend
:q T
)'>'Hi%F
v :xy
exqR
W\c7
l9,aY
w/Nz
ae0u
`sIM
<.IJ
^ sJDcK+
x,~2
Ik 6
V'q6
Gr"^V[B
X2x|/
nogh
tMYL
4z$q
e'%
`sIk
,I"~
lk#
o9H0
IySV
k#`
%/R5_
|jZR
)O%v
Marshal
6Ky\
`q8#$
dO/:
6~\* ;<
@qrshcute
<)x
+r +
K=p`
?$ T
+E @
t C,
+]6k7
{Ey<
='{jGl
*0T9S
$*eD
<Sj2
}<BGb
wC [
gy+5dtt,;
(nsc
cF `
g;eo9
{wC *
*>gs
7qJ-
Vsnfram
##w0
:Fe @
sGWq
,~J
f %{7
U{*'
*_E X
4.YD
N h+C_
znay8
(7
{d5vK
Qr>s
j3E/d
2!]6#
9z%_=h4
AssemblyCompanyAttribute
PiH
%MY?
-i:@<k
CcJV
bi#?
n(sdG
x-cxB-rUbGHmp2]! W~L(o't$
d2iTt
Ug"}n/
"w5H
#$#fZ
eQwibdrsWindowStyle
Y)
X}U3
\*Y^
PnJ b
8W%w
J7}mDk{
B#S
? tC
m8E_`
ru(g
Z([|
[,vC
!fFk.
Y=Do
&hH_
AppDomain
T?5b
<.|
(bG
n+ (
u{l`
a<l
8+*0
}>Rzh/s
H_9eF
A5"a
[! `
rag
:Fw3
rae
"j8"
@qNf
@pdouResetMode
Q;eSq
ty58Dv
&m])y
20/oc
gx&
q]rC
Mspyu|[
uKf^
) s"
Ase@
~-~k
FvSY
@gD
'>xr
HY1u
h6p)7
=+9A%
A{rjZ
+S>%
>d'I
A3It
<zX/
PBc`~
9{$|
,oq77
T`s'{
(Foq
WImT
eCdh
n G
GHip
Vt<&
ku @
vdNI
CameraRoll
Cn+O
%y:I
Control
\,8{F
LEa$
uO 0Ozb
pN'^
zxpc
FT z
o]!X1FjY
@6? h
qae
ToUInt32
PO;4
V;!.h
|3}6
2slrd
zW odS
f1_P
ME$M# r04T5
Type
(42d
CpXX
OWod
amC/\
$vk$L
H+*Aa
*J+
$T x
zX 4FC
x:&G
``@<
{?r`
)(f%
mX&q
@^c{s
RO3D
A'[(
8$d3
Lb)W
+g(Z
@+&`
%T5 W
1)rUMl,
rAF _
AwQ<
9wn=,
|*9O
/Hh]
Iqbpv
&aA\
X] *
Xj:"
|' 92O
}fFn
1tDqHj=V6
dLC8I
@U{
Q. @
N 0
oTfP
l5n%
awosalaqumodumojoduc
d J2
y9M.8
r4KX
3EiW
?fIoU
f.3W
SamplePlaylists
h&)z(.
eSphuhleCompatibilityAttribute
eHKM
[8::R[
dF+>|d
1gmT
1kei<@
=KfO+
A2 [
Rt`qOonExceptionThrows
> zg
`$]d
i4c$
Quo%
~D 3a
p'Zg
v)U#g
D',#
.8=$
@gST
pz[P_
;4-
*43m
292*$gX[
uAU
`z~)\
K+.`
Mr`!
-roi
c{4|
p2}*
4akQ
b:*OR
,S|~
re
fdu_DefaultNetworkCredentia
Og|G
mi6|a=X
rxV>Xj
]OA|/
L WG{
\D5CC7@C3404D00D3F7
GetString
9eo,
HashAlgor
#rp
&S@A
rc\c
streamBytesTra
*u75
2< n
#h+F
e7ShS
f;tw
WaitHandle
Fi&T4
wBhX
tgsN
X%i@
9gNg6
I91%v
J?[x
IDB!4QWWm
63Zi
O ,\2
#2Tl
~NPVx
\? 2
SkipVerification
JU53_
em3!
9=1&
CI c
Monitor
1q5;
lF$e
)234
8 S,C
lpProcessInfo
Md5HashData
Q2kGWk
u{o4
`qcRtcKey
)(E,
7od
t]|S
wQ)O;
YrfR
Wb{X
ohM=
y)VH
~(oY(
Ovze
mRPO
\B(3
(m f=K
5[?
CRU3Aj
J ^2f)
b~no
y<q=
htE@
X1!]&""
0Mz`Y
`.rsrc
O*d_S
LL c
-w=t"
O1[k
{82|
a F/
6 hc
~_R;
jA6\*]
FPzPg
l_&=)5
zPI
J9$!
lQ[pa|6
E+8r
]P9a
Fx^L
IA{1
svKz
! :
sy HA:
GetTypeFro
.@pI
set_Length
M}K#@
g1LG
9)ox
|k4q
5ZEt% ]
yE*v
MHZE&
^MOuQ
Y&Tk
smo
Kv 3
u.|+
k;"${]
7a:O
>LM%
k ;e
pXa]
I7F[ &
cNv{
-E^t
X$'xI
bC^V
K !]
3;uCe
MonitorPackageH
zo N
#2s7
)va@
PE{> |]l8)&-3zzG]WvKMJr$
^) P
f,*q
XmO
VZ"J
;z3C
WebRequest
NetHood
kg=a~=
tvK&\
{:4p
(
'[mc
5)e
x1;^J
SLPK
e\_u
#D.Y
dR0rf
.;%
:09"GE
ciWWA
/z:" @
4Sp-
tS-;
J<NG8
]DLlrB
kernel32
sJmw
set_AutoScaleDimensions
~_I^Y
5r[I
#rZS3
6emN
(f*w
g]v
l{TN
p@NV
d)vF
w.uI6
ok=qa
jgyJ$
\wm?
K+S[M
r:>!
WgIh
o=+Ig
W( W
Hk l ?
Q0yXA.
]U[5w
E#un
|*G
O]7+


Bos
p;Jo
0i9\
`I :
StackTrac
!`'{
gwSM
QJRQ
Mas'
J* >
Dufe
.VL
+ 0
Rl'V/1
6%x<7
4KHw
ts1e
@R7 u\
!^==1
I(q4 ur
J~T[_ iR
Lx21
Tvf@
InternetCache
ovCa
/iTjt
5 eI
C<PUVi
/53B/?
Jm_Md
&hJt-
-kZH6
7HXQ
U$F4
GXAlU
Zl"C
^8JS
?c;/
b2bM
System.Runtime.Versioning
UoString
Y>{5]L I
fUVJ
uJhd
9SZ;
i+sd)
M}j;
A} !
d k'
*J-W
q9](
vTSaZ
GTX[
Np3+
I[!
LocalizedResourcesDir
d@`r
2~&@
#F`?2
s 6_
?Cmg'&
mgo
*v,HQ
Downloads
UDR
D 4JY
SrdsProfiles
,NiT
4[(E
B(_@
iv!j
oq
0x#U
FwZ=
{WqI
FO^CF
pwV"W
*0Miu+
}!7 :
sdrns 11.0.0.0
( r6
Q4^8
PxV0
#Strings
/.QH
T .M
7#"<
Image
VjT0
r% "#
RJ[_
)PtO
'2(
slcr
-V @
sn6q
ea&[7
9lR@
\1UR
#T hJ
4&%/O
&oJ
~YqvZ
gV(`
^)43
bK*w$
Yhw,
!/T9:3
sl*R
e5*Vv,P
S-vf
@brz
3A/2
0wG)0
)qWy;2g G
Oo"d
~S\_6
]Z\m-b
BJ _
n\~&f
v =B
ZESHn0T
SLNN RQ-
E[a%
Wa >Xc
IlCR
Creat
"=&M
:rFO
Ubo\
u|-9
add_AssemblyResolve
Hl"F
>F@ iO)8
&ZB-1
!#\o
@UX
vR
(U'#
t0jFm
AM(*Qh
e)*x
EXZmSZ
[]6 u
+dpE
%O*%i
ZI*n"G]mz
H 5xH
@f7M
WH\"w
L X
.P!:
/+$uU
F/uDaO
T;C
Windows
%>z
^Ama
D& WM5V/]
9?t l
cR <
: fK
@mMa
o4Jc:
TtouimeTypeHandle
GD{1
q:@E
U`kqm`tes
E w^
VC!Z
tI^^
}kl3T3
I&{w
q|z q
E`jdf`te
3I"k
%UpB
k/3q
I=i
nPE
O*p
RX86>
"D',`
*kS-
%'k\;
HAx/
U/ @
rtg|L
OTpl
dKgld
cic@uuribute
v\
aea]
Vo4
[caMk
"v#%
).(;$
TypeBuil
q #&m
6%W]
eoKA
9yghgB
u+Qho22
w3c5*
H Q}7~p
pAC xQ
W z1
vMPBe
gDQq
f$Z:
h !c1
"63W`
A(Z.s
Sm'N=
Ovyn
(RhY A
`(7'
uRn'
=17uS
~2nV
Form
hb;*
\)/
uFill`ndLineArgs
uNhnvoFolderPath
-`kbmd
System.Runtime
s/6,(sF
;U= 3n9
gFK1/3c
I|A,
JU|[V
R%|3
bD$ :
+Ju!.
9s*XxJ
l w
Mjqds
_<bj|dS
s=!nP
ResourceMa
Delegate
Oa1l
U+)'
.} (7qU64bK
sWPI
;7lV
TEUd~A
<r%O
$?<$
}/1^
S :!J
p lE
IF7_
G6l
*e @
=<g:@9c
CmockCopy
m0[*
[~.[{!HUy
)#8{
u-hp*P5"Z
6\P[
get_Bmp
=R^Y|
Calli
.Wt
V7m<
D'Y9b
B]b&
JT3O]
G'\r
16^Mi
Yz/:
,oci
q5Ek{
>s78>~
NG>G
8@|!
%V]
~$_e
uWzZp{
spGD$
FK3T
ocQl
g~]K
y.5DDU
(G~
X
:QA=\
ResumeLayout
|*s5(P
I9:=/
.6G
Ke/"
b MA
handle
_/e@
8h}S
[w! -
H(,U
xn;
6t\w%
pItYqx
ValueType
System.CodeDom.Compiler
!dftxquor
emH&
qMS
#']y@D
618<J#
#KgL
5xoM
:=QC?
LocalA
@L4e
ou"O"
l~CV
9c +
5n}Q
BGg;zz(n
qpJI
y(^g
,Lh|
\?SY
,tb!
D\K[
`a ]
S\mw
bInheritHandles
@=dQG
_ ?t;T
I Yp
\EyQ
-LL3wK
x=uW
,H9]
b*^cp
zZuj
Kwh-
> @6
kox1
?FG2;"
S> v
(f f f f
g|Cg
7V+~
i..3i8..i
X@mo
m1c0
+3Hkl
M !a^ot
D*';
a"=t 6J
ZZXlB
+O*
bK/ a4
jeH8
[7.h
7e*
z9 {uA
-X3o
>aHQTe
dJ|FAy
c2xM
&Z-FZnK
_0Yb
ReadString
mqData
6~?/J
)'ZuRl
m`'Q=
o BH
) RU
$o6BN
(#hv
Eb>u
*;p$
UD)n
"]7q
<~2l
`5%1V

I&)-
O}:c
b^[g
}(1>
e`irMhbrary
ND+n`
Conta
J5js
:b1|
^LuC`bkground
,~
ed7H
06PTmx
s2Gl&h!
sY^
+G^9
~^L>
WySD
}y6X?
Mf! Nt
GB=/+]iY
b1vy
u-|EQ
Videos
QE-x
n#{l
h 1D
4RiVe
*JQ>|
[<o\Q
!"Ek
"7) s
bJ'N\~
<s;
?=P1
`<Yj
SavedSearche
H{46
] ~2
AYt
81Q
ujayW%)
Combine
B=C
u BV
N+Z
d5mJN
8cB!mO1
+sP 8
F*TBO
\^"\
Oxv0
:Ku?&
D)$ ew
e Jt
@VCr
(t-M
~{t>
*99
O2\F
/gU!b
EWbs
rFillnnX64
cIF84t
mTSt
?'JFH
ik6L
* uq
@}AF
g[J-4oF
?^b
Q"_KN
yLr6
~m @
2ZSZ%tin
029B050B225FA2AECCA589EECFF42
W`thghcation
WIiT
j]WA
d?EL
T(<Q
=w$;A
R}UwQu
$LN- k
VPU$
,.dZ
g[Y)
Main
s &R
[*GC
Weh/sc
Mi].
!`D
;c1a
"0=1
[H|M
DzY
k$ P
6|DT
`J39?\
v4.0.30319
PbOk
$B3 +D
MJ6+Vr
K``"
XI?e
bWZbz&.
X=&c
4ojD
tmFAa
#Mg{T
*Ue
'*E*
?n&2
~>}b~79
7AN^_
& xl
b9>T
${>w
5q_>E
){ N%f4q^
aV{V.
g!uq}
-gkrt
/c|j
@.reloc
!5H
&Jbs9f
yw"=
cIa;s
,5VT
ZFX%
R$ d
7<V#
$*G1]
WriteAllText
/e(L
f:gc&
b+"uQ
luA]?
creationFlags
P/`:>,p
,84A
!03Y
LG
#M`{V
*16Z
l@F
W)T`
SR 9
OYU<
b yH
p' e
&fm1n
KbFG
k5G%wz
a^)
"HB%
-& @
>kL0c;
}=;U
~pZN
"Kf,
s8nQ?\
o4y=
VR$n
Crea
0U.H
0tX=
mLS"
"2*$
\!jWUzK
Bnntacts
_:5Y
'N{u
JB}H/
': %
offHE
Hashtabl
E%^Qj
59de0
\9F'o/
Ls?l
f ##c"/2Y7
*>+
RLen
Bb6G
<"9DU
ehca^
H7CB
Nw4
W rx
2axA
}lqSQII
J/%X
)Fy8
4ae]H
- Y
4uK[MG_
dRF ]
lt&!Y!
I"j~
I6c[y
T4ce"
8;^;Y1lZ&
j>*+$
LtsicLibrary
eJo]V&
h:s2
P%|@5
`j ]Z?
8I8`
7Q]p*
K6aNj|w
"vZ/J
FileSt
}K:/
eHkp`mhdOperationException
Khsx
`]y
S$8E
`rDH
ReadToEnd
yR!y
Exists
5xQ>' cz
q:Q7)]('P&NcFb%8$L,U>0YC%
!GZt
?MM<
Oi<&c1
e2-%Tn
)Qb9Cq4
]jS?:
TR @
W167
HD2%#
>bj;
%i9MA
Rxstem
[8
9x||w
ot/b/E
@;H M
>6+U
iQ)
S~8OR
Z&:g
ktH(
@fy
/[E<
I~!
YawSe@
SJ @
N"L0U
#~3o vX
{NGKwu
mo&#
6B&i
7y[i
y_t}
6io!
j}98
jdkx
Vth7
./5fOs
BJ!8Lo
+IjD
E! H
twvN_
7$.c
6`n]
~B'Nv6%
M.vp
zzjG>
}J K
1*mT.
j)|"c
/;?+5;
"(H*
Hx3s
@B8q
P-|}`
lpApplicationName
T5AMBp
s8C~
r?>"'
installFolder
E`R8
{}8r
Qp]Pf
=} g9q
n| Gbf
?= /
e'vt
r L9
P.Fn
System.Secu
?M5-
MT TE
KFtK
6LQ&n
6KSZl
*=4P!
/ #@
^:|E
"*|u6
n~,7hO
g?> !
nG n
`og
4$O;Y
XU b
u H 7
hU}#W3T
lh<s
/T{z>
Ehctionary`2
1^7=
2ea?OQ2_
MtVJD
YjTZ
Edr`Mnw
g!:1
'#/m
]v)h
z#w$
M7(:
2*OL
commandLine
'%,/
R9yp
S/0@
O7 \
-H,^
Y`PmG
y "^
mt"b?<n
C-O
rWA>;X
`YbA1S
HttpWebResponse
MlMr
[L[N
e) h
'?EGu
|)e!
EjF
mRl6S
U_|''@
#xyH h
q.}^
:v'e4
7H?>
KJr7\
SAlQ
6`'U
CompilationRelaxatio
_fm)9H
FSkbO
am; S
;2})
pD[>W
tO> '
o70'
Pq$
WbZr
^^$C
&'/K4
%1NT?
o1k_
.NETFramework,Version=v4.0
vlBgW
0Sc
/Ps"<
g<n
'aY<
eFh'
07)N
^AjBdS
y;Gz)
Chun
/uext
ug(oe
[pIG$V
ha %
e+'L
T0,IO
OJ),
CGPLex+
v@!Q
value__
r`mtBytes
D`P<
d5oo
JfiM
lE2]
set_Arguments
^G3{
!&z
~m`3
yb#J
>Hn_L
120V
GF"e
EU >
?@:+
=dp(
-[2"
lOCa+
Et 5
h7fv
F=KE
&5:\
W:wE
OEjb8
%l>
]F^m
9vA5
wg!D
e3fd
TEs3o64
~s y
) fLD
N\c
2NZM
Ss+/V
Qv)m5
|uTF
_t\:
Hd[=G:io`vr
StartMenu
)j
r~"V
&nhvsdrsionMode
p^tA
Zp}/
6Z%F
`jyNR
*&$i
tst.dll
p5X7a
Pex9
5&wXw
/v8.-
QGt~n
A Q5{X
Uxruem.Reflection.Emit
sbs
x[l$
w+m=p
\Gl"
Z>Qh
XXH
==>niR
S3hz x
_us+s
O8"
N1zn
Yg=A
zD (W&
#_%$
NpfJ
Xe-d=H
WnN(
="o6
sjTCm
d)Q 6x>
~yO_
h~QFJ
'dfR>#
,M.vh
R N0u
ORf
L)Q@2
Hy)s
Y7N@
SeadBytes
`yIq
b,&-3
R\EZ:
v1{B
V'x()
h4hk`e
xn7j@CJ
T[c@
/#&
0$<|
|6q|
\T]
w;?T]
dQc_
h sU
~$ gMx Tm
z!]d
4x,A=~z
M wVV
3 ~
StreamReader
y1-S
'x @
}29%
Ow.nm
6bac
9@#v3
}_?l)
&k<sa#
JlnKx
p3h4[M
E9\"
(
T8h
ydKE
L0y%
,hJ^
#tD
P}9X60T
3M:a
;xiySg
] QY
$^3/
:[DS
VH[B
xw44
*Ne4H
Z*Dq
P\(pV
D4es
h8xa
Ir_}
vC_
Wp[ P
'{tj4
{,]J-7P
o?)%)
+|6
.?Dd
KJ~~
V^R'R
(wa>
}g>8**
3?@l
DF#~a
,zFF
I b0
.yZ!4
g8Mp
|!`[ F
VD`8jw
{xC_
hIAg#
>*F0
\i'm
[Pa9
~[uY
RhzeOf
idPA
DsV>
E5/!
VBq?
mscoree.dll
r\!
F%nK
WFAl
gL!m
&@>
File
e0s/Q
eL6e
X$*$
k3|8
!QDBQ
yr O
Metho
'/1%
@RW2+
,ua/0
SidebarDefaul
[7C6
U@4F(Y
| W_z
EO:qse
AYVg#
b68
egLV
Odkd
K2i0
{&qk
85 l
vR*n
t,8w
8)!n
&i|S
?D 6
k +2
}2 X
ATa1
TU?S
@sYKx
p>($78X
3~n
JJ.}9.
Vy H
+l/U
(Rg`
i7"&
L]GyC
TR 5
}k :
AZ[2
'aaR
eqga
HOLs~
0"G"
o9`i
c2+
get_Scan0
8` Z^W*
Rk\U
![|
#x 8{
ch3&
8We"
,Ll/
in \fV
R5+8
cG>'
f"p.5{
yhDI
'8b]
:!|0
0o)q
V 5r
#CC(I
_@ 2
DV(x
BroK
@4E?@
ckSa
_w7C
Delete
- %H
pZum
KxIi
.s>
Tr9bb
;}[N
S"G~
lVB]
}h f*
/${rW
phL2K
Bc<e
mq7Rj 4
~RL1
?0u=
-!D;a
F:sT
X #wi
N(/G
8qvO
y$j&2z
G68I
f{=\tm
yL6E
8]w
~g>
W?^D
I6`!j
)~k|
80vXv
|(cv
;ER6
^;fR
`n'8C
+K*
AssemblyConfigurationAt
:qao
&>Z^
HPP>
hXmyf%
Q1r3
}B3t9
uUyJJ
P%Rzio
PbVR
Te[HQ
vN 3s
Iv|J
'`vc@eeress
=epT
SX(&
v.X<
d8.<
[Y2u
''iJ
VM 1
XldK
\fd
bP{oVp@
Oo D`
Quz\
EdfineDynamicAssembly
@fXR
9rF
)hCO
`}AkI~
j!)F?
.V0{
;.[S
-fP[
oiDq
ZP(_
Dhz%8z
zpx?
c"|
[TR4L
,%N#
Y!0M
?KH$"
u5'
;Sc=FZ
782
K7G e
<w?y$
H)[
K`O
FC4d
AH v
^Wg"]
(&=N
'L,<Fr
*yg8}*
QTy,
jo,o^
&f (f
NbI$
P!h0s
PAkv
e 6L
PTUu
@H^y
zF-wjq
:E'v1S
@p\z|
LHA!
#gD=
{p;r
^<Gy\:
t 11
67[7
;:,g9
BsikfyR
1f)$
CB01E0B0B93
cQR#
L<|!x
wM$g
fF&W@2U@(
t-HQJ
%vh|
O2X]
~5NP6
)"M4h
m pe
ii MNJ
T{>l
]ecq
Random
( /]
h?+E
c#h[
,%?.
nt 2[1o
t$15#O
o ]U
:_wi
{#8'
[YW"
R$q_
GON^FC
e3`@
#>5[8
)?rc
{1wg
Kwmal
jhUW.
o2lW!
)!rZ|
!RXb;
DDSg#
_U(/
`2-Wj
2%c"F
2JMgJ
pe|2X
*BS
7o_K
T=OTI
0OOl
ThreadStart
n*T>
oNE
JX k:9d
|{*9l
MT\{
Qaa
o!yobfKu
_*vH
B7=x
3###32223
"{/T
QBQ=
fb3k&
=}8p
B 2z
\_;B
a9iN#
P!4]
TOK!
YLN
fap
9nJXY//
}z?P
TkK`;
zfN%
ap bBy
Sd`dDecimal
9|~
$jc,ad7>Ck
^Tj*U
8hYte
GbbnuntPictures
75q K-+
sjas`l cannot be run in DOS mo
OH0p`
acg`tltInstance
i 50J78Hz
(?!Z
System.Th
JL e
UPty
?R@,RG
# B;
/xd.
n/pC~
/J*D
[ 0
fpIaH
m$VW
\N(3t
]h#+E
q N
ReadDouble
wo_dn_HQ
H VME[
{TPs
4^J0
7`td
y]K|
]]! uh
5?~?
nkkdou
.mn*R
e,Io
CL_Y
=;{3=
;ilS
y{3G`'
p1y H
nQp!
=HBD>~
dvudr
ta1(Gt
GetName
Y~b8
k9;1
c w
MK3w
Vu(:
_-`O
*:+
+T}P
9v+>}
R;C
&+nQ/67
~ &8tz
Mh;=
( WiU
K1+6/1- Culture=neutral, Public
4>$@
4 Qo
(z}H(
?%. 3
7r$/
xrb
Yi
D.]!
M7dm
4J1A
_n\U
#EyQ
z ^a4
,H"|
FRBl
N>#n
hV~
=o4L
ag_e/
c26N
1vA
]O !3=
3Xg_
0 5
k^ 1G
wrEV
EzK(.
t,E#
7&\a
uCEh
=3Jr
ZF3c
d96x
|t<VJ
/t*`
Y;S>M
%]jA
Cws\
.b;K
*g?
i92C
C|rdr
roS3
VFGG
<tV]^
ImageLockMode
`Y2~
I`PL
0|/<
:Tge
vP&
ft-y
LX{h
r3xC
?`>|
UnmanagedFunctionPoint
z]r
l*O.0
3+bO
9xF!
2/wwu
#Gce
|z9Fg
gBD{
1 0q
xEj#+
-w;&
[_JA
Xa&MtN
D 3~H
1>[{
^]wN
cX')
)SV8
AssemblyDescriptionA
/!vn
c|~Y5
0Q%u
u3f&
O2b?
:flV<-a
52e+
Hb :
{0w
)lgv
=]?d!W^
>BK6
_F\=
Sbe:
FLt
ProgramData
|e @
9^kTcbS
oUJ5Hh
a\`#
#kFgB
p1:x
x6Ea
mt!s
RidebarParts
C4q\
A] ;
_D5QYfgv
^sp7
k:h[
yQoI
-2D
I4JDb+
.ajd
m('D
;do[o =2xy&
M1Z&
VEfv
n H?
/=Zw
fArl?
s_'<\
| 5.@
?\"4
,7KF
y>8`l
6dfsshuy
i?,]
YLoP
/u7%.T`b
e|@z
|04T*^
+b \
THJnF
T`_'
ZU$N&
;es3K
.?9E\
u] >
z8'6
H q{
D-rl
9k1s
u/J;s
o_m,:
PW]#&
93L{
_RFq
)]xl
SS1
Zfek
yb '
~4k_Xnd
:vu
9=Z3
kA-C
GM^G
99{eA
QUea-
- @
lGj!P
i& @
rRx
8*Uk
bG!YA
{{U*
vn)
m&\.'q
(iO_
2(bH4
;+Z g
.9Tm]
Zx+J
?V5s
" @{U@
:E)y
1B V8
TC^\R(
:HLu
WYGmN]
RN`S
#d 4%
9bNx
rNnMm
d /4
rya&
]Q(#6sPxTM
'rlu6
tQCD
#Z@Qh"Z
@ 9!
q0DsIG
q5!
-n}T#
Registry
csb6
++Ba b
5&W4z
ComVisibleAttribute
lpThre
1$he
/J8
4,7\3
A mJ
Z*+^
q2 k
hJ((
x<Uh
xFz
{GyL
'055
~H"x
^x1lk6a6y?C
%,c5/O
Playlists
Tu NZ
eua#
Vl:8
#t`
=^8?
GnJC
d3txY
4d,
E(*o
z^OZ
|@yk
qV|
rMjau Sybd
A]G$pj
vS
R6mjM
Implic
(\P$
8J0P
eI6_
(Ip0
4r0t
"^r,
P3~
Q^3!
s)DE
Q^3&
=8|
3'UfFA}
z#LM
g;"
lk%IX
RV{|
jm K
Kxj~
+x,K
9T1/
mg"^
\8XM
/d6e]
KRjb
?"SJ
0Y0
5P+0
"" @
ch V[
TM{_
twcHogo
rDCo
RunPe1
Kn`[
#a3|H
F2[J
l'5n
SgI+f
#|-3
X 46
`a0
xTn"=
S$'d
8TrcLU
ey6W
XPZc
z4/$
{S%N =nM
S()
W71i
;UrD
nfMN$
2 |c
9=w1
`u5Vo
9y<#
{6@G
0-~b
heh]Z
%U1 ZC
VBX
Il<H
:WU6
qxYF
7Jzl
^PTI{in
{ l_
rj@ m
#hic
ztZb
"vcf
4kHqyVN
2VHSI`
d''?]
P:@=
"}lkw
^ \ @
hRr x a"
'QCxN[
OIG~W
69&;?Y
C0v(
jP ^
,X1Q
Ppn2
KAjq6
}\Z%YH
GjENt
gv8}J
fIo
9}f[_/
pZLx
9l1#
a WO#\
GetFol
A}:^
m}vQ
.NET Framework 4
}0Ma
l4B/
dbMFx$"
y~7|{7
"<#x
DsSD
I4F*o
Sy Co
X|4%\
/8i
M=,v
Y+$_
z YX
3]F!
tv3O
u!9"
4D {
\|a9'
/4xE
>Bh!~+
(mN+
I|6?Y
X4?e
'Q[[
bVI
^QVt3
o 1%
v\M6u
>p2?
KdGq
K(j\{
N@+J0^
#%7&Ni
+p/k
GetHINSTANCE
<"18
u`k/Ehagnostics
Buffer
?(hj
O9UR
sc3;u
ht k(R
x4L4
.YWt
(%H"
-g 9
Ho)_
Jf f
a/Z{
zSxLa
't]BE
:fK6
2j=lm
jwfb
G(~e
G<"%yG
Enum
P *0
?g 1H
2YS
lb_h/
ft'j
UBvb
X/>T1
QQ')
H#V)r5=
ICryp
Z:?E
OnR&
y{j>
"fc#.
XXkZR
D>>'.6
+5J?
*+|q-|t
|t,;|
ReadUIn
6m`)
Q-DR
n I
Su="X
U%W%
2Y `
ew`R
9N-P(
^G'?:
-D@7w
8)RN
>gj0
7 { X
/Aa
Copyright
j.0[G
.?d:
4'/_KXo
$a!vPg
9c,l
fuFd
n v
xzp4
gZ%C60
Zu,Ac
h: {x
~)OL~T|M
[j,
RO^N_
6.7.14.1
1g "
Assembl
S!.m^
CLX/2(
3g A
l`vX
cR;K
2gg`%
cXr0
>~F
=e.&m
jD M
%1Yk
[4!D
P@Rn
"s]P
ft~.
q2@]
czMuO
A5f{
&wiB
'/%j9wo
{T w
Exception
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.exe
sldtud
&4,.
=H>A
Ao"R|
! Za
M@7!
+LO]_1
G"/2
|( '=
yO8
cl 4
\i:"mNH
qYq7
=wL6ARc
5ix][&
|_ W
Sdup
w@&Tk
VTJD
xQijdo=b77a5c561934e089
|ZYF'
ME$r
o|L2C, h
x:e
}YQ,
=V#>
iJyG
w<>.
W3>S
W&M.
R/-~
B 3$f
fqJ@
":2
SavedGames
rtreamSize
\ G^
b3PL9Z>,
Enter
swce
xRgR>r
Q2:F]
M +pzv
\2ip
#7.=
:<n
e`ta
GetDelegateFo
[oT0
zR}wE
dw;?
PAg YL0
*bh?
d{;7KV
uwoctue
84&:,$
/ec:
Public
Math
^PTIxfk
UgXV
n'Oyi{
a>Ml
BV*W=
-+ D
FF5s
usi)mK=2
XwQr
" @yx
@zDW
uQgY
v 7\
passB
cmdCopy
PbRj
C9[c
u?"
+*_`+
490V
vPv$}E
0fGdv
scwC
I "]]
R~&c
CL`V
mG22
Ma
!&<x
H'?k
So`'>
~j.4
0qY+
|B)f
}]^.
8tt}dT
KYQ.F
PicturesLi
( V9
b-X+
{^Q
lL1qF
*M 6cQ
Uv{AnB
4e E
N>"]9
fc:
X.D<z
Ig8BM
NONY
poX:
nw^}
QNWj&
x l
BE(*
E{VY
hW/-
%=Vx
'2F
Z `o
@(!DO
qXRTz;
`f19'*a
I81
$3BK
6Ix^
:] @
$]Lj
x|s^
` KY
p,}U
F:Yf
5yqI
%iulF
AVIX"
I8=j
?>"I
~GS}
l;%Z
fwCw
b@M"
e{ F
/Ar$
AssemblyProductAttribute
bj6sl
tS`2f
^PTI|jo
bhX f
Cpx
bw5%
<7++<
<Module>
jUl>
+KSn_
p&H
vjL>
iV(A
IkMOG
B2GE
`UPx
vjL*
@W5G
ID:3+{
4 +%
G 'i
vPQr
|vB
'{+HM
U\WS
UInt32
SizeF
{:FE
XD9G
X!d!
>,j
nvigu/VisualBasic
!_Ff
8FgG
" z2
I._b*
3X"k
N&A
S.[1K
W&TwK7
;c9}
1|d*
N`U
$\g:
=) )
|uPVh
o;K\
Syst
:: }
jj,_
X}(
T^1o
'PK):
Yn{K
' rf!
V^)VHs
~N]SO
eE``
6H'63
;oe_!
'w)J
X:gR
#O8+M`
/|]V
k<UqR
o w7
"As[
1)n_
=b/)
T!Oi
q1#m
eA%kkj
juAb0C
(r[f
"+V#e
kp,6V
$wBE
#.=h
5@ .1
ERXh
4\do
<5!
#HJ,
CT[7
}I_2
NC1<=J
mY/D
xskZ:
[e6]
c\O7z
a?LYwJ|l
eUC;
I3r#
:^Lj
R!O&
eO>
^5PE0
% \N9 @
:%C)
F U9
#jQ]
gp~vI
Zl#PM
Wjy!
Debug
|ZW'
W2Mf
N]_v
~6>q
Cookies
SetValue
2LJ,
F3]V
lqY}
gZ%K@?
Vfa_fU
[D"(
(q(a
TG"C
}C)Qo
vyxHg8
1 lA
?m5/#
<Ry-
Uxco
0bC{08
tui~
BATW
_Sg1
=oa27Q
(%v0
c!3
15.0.0.0
PQaB
gy0'
?6H a
R8:A
? Lzp
odjDybeption
V<tUA
dkrrMhbrary
NL. )
l9~S
'5oG
F(Te
X:byzk
o^847e
B+py
9[LI
fileNameA
kx1+
Enouains
A}W;cg
sW\w
e'Af
HS.Be
%h#\9`
!%mI
t<oK
System.ComponentModel
Gi+/
^0G{M
jvS&@QxB
kzi
zD.FV.resources
~ FT<
Mi"T
GetDirectoryNam
pWh]
ZN<6Z
Aj}
&@s_
Kx> w
F'^|g
A,Y:y}T
=oco
b C
$% C
DVk"
5tgjhbFameTasks
- uT
w+X%
-G#i
Yk}]
d01iiO'
{-h(
xgQyjC
S]2k 3P
h\;;V
U]/5
xE,P!C
Ay\f
System.Windows.Forms
gQk x
DA1084F6CDFC10797D568BBD9
GetDefaultP
hx{ ?
q#ZO}
~w5|
J O}
Sut"
fE)9
L)Ed
;LNH
8?i 'j
;$$>
set_WindowStyl
+bl>
6F18s
JQ'g
GetPr
;Cg*(
O5 @
B+N<\2
o`t`uddAttribute
:7F{
&g2z
aL vL
LKZ_
R4E,
VOTt
ATp$K
L>@j
Z;Ke<&
*f.>
#/XS
'iXGLOm
Qx1$
s3[`9
!<L4
>v,I
}Y8E
YN L
8\?L
r*ubM<@
2yw^8
q<\G
\B#yo ?
e^IM:-
9>S
qVS.
N&|U-
5/5{z
=B <
O &V
=OO;
9s gs
v}mZI
3U232v
f+++f--0fDDDf???f
A~:5
(c0
KT:$
zvG5
W<Gq?
i`Rl
hfcLduadataStore
@5FGN
"VI=
-IS[
Y3L;&
KD:bcr6
QfK[.
^;ZaZ
7^ @
D^w
OKxT
> V]
1Hw#
RY8;
eH 'C
W_uP
HOMl?
Ujit
DSE>
_890
4%m_
FduFileNameWithoutExtension
djAo3/
4A\7<
D jZM
E5 +
Nm=w
$g_r
jtRo
Tap%
xm1(
8FXo
)\][s
e|1<
7n.k>
:!I
~#S'
H*K}
QH-*
X-@u
%e_G
b ;h
op_Explicit
dfgo
t?&#
System.Security
0tc&
3>p]
W!9`
MP~I
^D&&QP3px
g4l}J
w\H%A
?9DQ;
9J:(
(fe)R
\\F4Ic
AoRk
(1$!%
EndInvoke
~A >
3zhY3
w^\9
i7 C
APV4
;fu
dwStreamNumber
''&q
Vt>V
WlX$
=IF@oU(
hDu
t.t3
Od%h
}U\5
#m>r
r$"=
\/x9
]%u$
u%NN@K"
`7"vXR
+:Dv
BI z~
1VYU
I83?
%+klx
w'KJ
^w"aI,
shHP
I5 hA
k/"n
b~8'#
.>AG
iX0rmM
L4YS&
W4B+
B)EB
(dhisxRtream
-5?[
l *5
E`X^L
:F!$
md`NV
.B]d
Hh7
5C6kv+
bV J}
okh5
u+ W
,EBE
#/u2
3>/N
{/EI<
g4]!U
U !3
k$0d{
`L?
`wrtqHnfo
i^IqWG
get_CurrentDomain
C"W#
'Y N
U;`(
& FZ
Z5;Vm
D (4
(M@g
}OfW
|kh Fx
VX1|
"6U@p6
T^?F
T`u:{
7_?`7b
OO,$;
T^ .e2
jHj
mD[S#:
JgIx
wZR4u
"U0
J]1mE;
][/C
% @
FO C{q
$g:g
Path
.( e%t
*asr
o>Z
-;Zo
2Pq$G,
u \f
ub{_
khKpq
5tgjhbLusic
#@h*
r(|4,
2HLZ
:vAB
5*'T/
#Blob
./u4K
Sk07
&\`
iR7G
X4iPU.d
&=2s
KDU^
>_cY
G_i,-Y
JXDK`
:J'cF|uC?hUw*>R-G:_Al|NG"
`yf
%zQK
8R*@
V"jv
3V:.
#* ;\
HZg2[
EK&*
BindingFlags
YY(K
[IU
BN2g
}tCr
\fV.
"qGl
%Tp.s
rv:N l
)8A'
P^&5i
PGZ:
(Hop
hG_5T
pJ5{
NEz
p`d}ePW
@$.g
/REV
jFl
2 mJ
n@MZ
?Ak3
Uk|#
G*db
<%PC
startu
$a g
6X/p
(adq
ProcessModule
d@ '
USv
11l%
^)/?W
NQe6
]>M}W
0>nOa'k
c\jI
fCYO
MdU
o3mq
a`,G^
:5b;
[vp'
^dba
BXlnQ
NM"0
</ G2
xfXj
1{%i
[h=:
z/VIR
d4E!
>[2t
qbf^
c+7 A
HnzX?
qhwI%
&!X 0
L@:I
x.C$
][bp;
=[ ~s
65 G
-F4@
3&a, |
nSpQ
0jnc
ngdD
;QlG
J^w
px_A
>TrU
e:h:
{o_hd#
,c6Gn
K3!
#VF1
jQ9$+
x>b.
kn !{k
qvUh
DialogResult
'd?4
:j
W{:I%x
M&q
[RZ^j{
UWmfo
J{ma
DboO
Mp*3z
_OJ\
wY+116
`8Y&r
n*bp
N==P
nc(=
&iX?
]b8
WU|$
XI h
qalb
eWcl
dataA
rF{PX
System.Configuration
g^Sb
bv#l
lm+g
F<O2
|\ N
X$;"
K>7'
kk}v
ICJ&
W?Z'E<
{ Y(!
(MC:
wLlm
!0PM
zmO
nxaN
E[)<:
&O!q
f qq
Hh #o
9cO=
grY8/
T'mO
<*&t
:azF
BK{X
_=Qpk@$c
9|z3
6]`X
!8 A
Gyr"
A S"
!0"w
/aX3
7j .
lhvU
o8>J
L 4s
&CZp
uhWH
E<4
vZWp
E |Bx
ReadIn
oLhwnje
2? @
BS{]
V2y)
QHgQ
EQOf
elAC
EgJRj
*6d#ZF{
H?)~
_m=N
!0"
skSx
IconData
8ZY =p
t@aP
o)yv
`+;A&
Sk CN}:q3
B}L
,kKw
a,_w
#tkeuhnnPointer
.Z Z
f5L
ZO al
+}w9
W-D T1@
ybaP
m;}\
Mhst`1
V[Baf
t[D9
aJm*,
]mp=
b2j4j
1=6%
W>;L
lIoojr
zD\9
_M3+
lBO?
e:_f9
Gp@a
rDhl
/D4Z
flAllocationType
H>m"
\ SJ(
%G^@y
3System.Resour
i`thuIandles
`wUdu
Ta~y
O^*U
!JB
height
P\26
Cxjf7
eu`!
i/|{.b'
x[9-+gm
]>Vf
{DC6
Bjhwdotions
<do4
vJnieX
*_l?
>d*W
a&3k @
w oM
psD+J
Qau|
;jK[
[l<v
Floo
/eq
5Sb4
Process
!Yl>
`qonoEetails>
qen9f
pih4
#Hs4
v)OqI<eR
=h(^
y I{
Utnghle
O#-f7^
ImageFormat
?|BW/
Eo)H
r~87WI
set_Cre
H!`
System.Collec
f`dUA\M
Rfc2898DeriveByte
GetMethodImplementationF
,. 4
VPqH9
$cEw7'
UInt16
lSt#
/lTh
r[r#)
@ey0(
~FW(
A @
HI!5
a@w03
&dmX+7
5YX
%ux[<
bn8k|.!+]
Z%=,T
eTLhu75
AQ<;
`X}GN
|j5Ln
System.IO
WrapNonExceptionThrows
#E$Q
UTI+
l>5V)
ZWHL
E;d:
;Pgi-
| IS
b%ih
dDFX2
z)5u
?e0';
zPt@fZ
b Ky
B9R(
(zKX
0T~5
J G)
EZ\A
la2>
]Zm4
W?|?V
3^4Q
gdt }}g
E;d
.LIR
Mj>gd[=
h_AU
:F#E
|bj>o
ip /R
T;B$
Vr~e46
",/H
D}`7
dUobutres
c<IW/
#Yh[
xzdH
79]$t^
4BT
9#]FW
hzY"Dg
]FDl
0B^>Y
e mU
=1 fs
FN3e
qCd$
O Uh_
O3;!
J%c2n
H['d
_]'@)
0w"u
s @
`{:L
,@ 5g
""9[
SNCu
lX7
jChg~
cryptBytes
#(~1p8
1aC1
VhXP
{!OQ
e/-i
othfd
System.CodeDom.Compile
CN VP
~pG<
c" F
eTvcsQsogramFilesCommon
P:'(
,qcx
D$Vb
Dt+h*
:%Gx
0RH!
oDrushbute, mscorlib, Version=
VirtualProtect
2`SS%{in
"{2Y}
k#m
+IHD
M(ue
+HRk-5
Q2^?
/ xE
=c]w
()VR
Rb{=
] @J
'n>7
r[#w
kd+bL
c4i{
RdE^V
,JwY
o4![\*r
94 ~
SQR-/
GetFileNa
|^<r\"
arN/
j8zY;
A3@Hs
A^5@
lojZp
QVqlB
System.Diagnostics
Z`ya
bLQeR
tWgd
`)4'`/
]o<
6IDr
tXKz
OpenWrite
e=0_
&nke`u
xUib!
ehOG
Uf}6
<1(1/1.0, Culture=neutral, Pub
hCs$;
_5hU
mcc 6o
;Dg
E|h`lhcModule
X-.m
E]na
?x}
+I /4
c+Xh
Hp8zzG
WDn,e_
T(/|
g<\R
C^,:
IT'wyf<O
Q,;
|1[5
Q y
6}O|
8Ac
!_7GK"#'"v
q,FlBe
CL&C0
rudm.Resources.ResourceRead
DIS1
8m`6
SvW=Z
Uc]q
]T|R
TCR8
~3MU
u\T&
iaM:
gHo~j%H
n5J
-(GS
0?#
z `
0E~7
get_UTF8
JU@4
J/`3
K15
/E ,
@x\(F
E =r-
M \uZ
z'eU
m P7j+
VsnframFilesCommon
uP0<
ab.6
,r#=
PW8*lB1Hr
rf"
/'p/
b!~i8
8R#
7T$j
Bhnd
6SxA&
Xfrq>6h
_aEB
P"o}^
QxGz0Q%
[8jx
<XW#
sq@hmd
_)9
(MA4
I=Uh>
1!3k!1
/-W p
`m?
|Ng^~
rM 2
I fz
c}\dI
h ">
E-O9
TsUm
eRMAduGolderPath
'w!Udrt
EJyN
vB*U
Dh'
>VRT
o}Eo
*1i^
+,>9j
nku/Fdneric
EditorBrowsable
%8a2b9547-5549-4d03-9d35-8
/S i
c?G'
x(W,
Sezv,
;8Ew5
GoQA
$-T{
H(JU
NaF
v'>w
aE=jE2
pJ M
1 H
W(<:
sZ+3
$8/K
mTd}
F6^
]jx9
r[kC
aE[W
k;I
;yDg
RAcbsxptBytes
Y%eDPFIvDPLj`~#Bz@8)b2o
,Lf>
nzE:
JJHZQ
B:]Do
xZJ:+
[CvT
kU=CF
L {+{i
kzTFfK
M O
+z"MF
!qUM&yS
fNKLs
](GB
*=HG.&.
a753
!r5P
!;Z;
"##8
LGxl
* %H*
9 O24
q>nn
23 1
k2`:
w6R z
3qR#
${au
8`u*\
y9)
~}P(
Y&v,
fTrU
-F
kQ5z
WrgUN
Qwiudbt
zM'X
} 4t
kQ5p
LH6m
kXVS
n-+m6
[@N_z
t-rw
%_%
21;7
!g9H
*+aO]?
8kW:
k`g/
fdu_StatusCode
>< 3
9 E,Hhv
O\Z0
GuidAttribute
G[/C
z/'lxZ
)Eoe
;Czv
EC
`*N
6?A$K
}3- @
P>M9bu
@6I7"
^( 7#GD
kH&N%OrAZ-.
%D$ `
$b*W
, #
Np=
"y +
6 ,H}
<}{E
~E3
8T Ue?w
7`/B
}b%BK
Td$,
^z3l
Y/PiA
W^u6>
E
#9GX
~=u$
!Ixw
z94Ec.<i7
,a @
BN |
<aJ
rb/N
#7"z
"V#g!
x2 &
!>J%t
V{X6
p|Lr
EU|EM
1h B
led$
;_ h
\BU{
VS9%+
f&miCL;
M(?2
etO_
u8VF`
f7526ac8-c648-1a.Resources.resources
1w>{6
<xZ {
) y
eVD)
Z '&WKsE
dm K
N >/
JCn^
z.-B f
b6voY9*
;Bh!
]9OuS
!E^<I\
./SO
Z4#c
A<&Ie@
,rDu
7M)Z{
XsS*
z ]MoY)
4gXq
U}&+
y @
prD[
U}&8
0RAK
CqsaR"
rj(!
6aqE
%!!Yj
<_2q
IY-(
;+'
<Kl
dk.@
353 E
y=Xb/
Z`4B
+S,
[zN8~
Y!SE
AssemblyTitleAttribute
# m;)
=(5l
GN5y
L$ 3
$tyAw
/AxM
4cr 2B
XoVnQ*
_gDX
cT.+
Hh1A
NeuPDE
ZFe`
"bJ;
y|u}s
b.V V
%N O
RdcuritySafeCriticalAttrib
8Be"
TQD5
J][*U"g&"
VB`g
u}K#m
Y#z(G
UserPin
(2y=
Uyj<
Iytf
u< ;
B*bPt
d\L
`IH|
RtringBuilder
rWr|
S&H
eDaounsBrowsableAttribute
X~0OZ
}@0N
@ s8
instalFolder
<1]r
nst[
8Uo bz;
BsU\
%aXZ
y>R?a
IoD6Fx/
pTMI
Z: &
Int64
k w0%
VN A
.-s
asS:+"Y
a@_c"
SxcM
mO%\
Njsl
'S^4
KxI#Q
?Z,
2AZc"6 N7
]ye
S`X7j
O~ W
mdy8
Lgh*
PADPADP
_sxA
7mji5G
R< c
]'g~
DZzbbBD
?"z,*
*M6Ti
=, &
$/!Q
+"6v
ai9S
*z^3
G}+?
:p 4
ue o
m)-rZ
AVEvader
_ 2h
Cpomedr
}w{-
#Xm'
Wlbdnr
>]$V
}Y~43A
-&z-_)
7Vh
FrameworkDisplayName
Z+a d?
&_*u
MXY_
@]?7U
u<ZCu
l.Ek^
/#S
=\iSF
QR@rS
h=#O
JG:E
YCwjd
xeI~E
_6dv
PW+A
rk%X
j\>"
\hJ@6
s2;Y
WGap
|NAaH
SpecialFolder
get_Chars
d}T@f
CryptoStreamMode
E+wv3
K2 F
|ln+E. \t
ODotmerable`1
'ORgu
4C*k
psJ
(_*V
Rusing
v9gw
^J!e
HV( GH
MethodB
;5A4
53l%
q[pp
; L
f9ASgc
M6(6
=28
c6ql
WS#
\7C!,
$">Fd[
i.^c
mtJXw
Nh!$
ESC#FL
{\j&ox
nZ@H
f MG2 i
MessageBox
5Nq!
Ygg2H)
J cc*
=+S:
j~@2 j:X
v}/!
e;H
<+OK
lpContext
q4RN
\<?Q
N3X9
8P%
^;&i
r.lF
0 {SI.;
MethodAttributes
F'6F
{gI}
{^ 8%
D y>P
%.jq0
r+4!
t3Wg
T k?T
48 gDL|
$D*?L
Q4m[
KcuvnrkCredential
F6
HRfi
;y/
kLKE
ehiFa~iO6
?3K](
k..b
.DUi
&
qujhb`tionName
Ardkr
eH6R
h @]
kO1t
rqcl/Suntime.CompilerServices
@2A"
Assembly
!kV.zi
.Im/
"Rs%
_m6Y
RnsR~
v< @
Subtract
8qgI
System.Drawing.Size
d|*E
V$n0*w
l+fQ
tC724
<xS&
SuspendLayout
wtP1
[G,9[#
dSvz1
=U<m
d} *`
^%'a
7uWHOte
X~*%
zBb
Fq@>w
"GnyHr
qhE
OB4x
9e~D
ProgramFi
qh[*
set_AutoScaleMode
d5^.
e yO
MCM}
y ]&
Nzfu<
xKT?hKC_
t@-#4
</Sn
CVF8
]gR>\4
m4jhg
tkXbe
Fe|N
/&>:
l+Qhoeows.Forms
u X
'W_b
BIan
7/m~
Q@~&
Gqc^}
fFF$Y
:BQ[J6+ S
e:G
4q{f[
Hd:oc
C SP
0A3i
@p^s;
@Wu&
M%#^
]<~O
Z.2| 8KAu
k_F
?zh
upV/
X"4'
Q?py
{3vS
[pI4
tYWK
+t{{
q7pD
NCB6
Y.+;;
#o&+j
w_e!nkF
Yduw
nLBRE
dts`mhty
KF$4sle
F T s
|OBpO&S
G4lQL
AS}#
(2?&
:Eb]Z
) 98
MW&#
_%f/t&
IwO.
!&/A*
S`grno
*,eK
1aj)
oCoG
`wB
Jlc|
k`eu
#!$W
y]@
t"n$e(
d.=grJf
n6<.
oMh
5Bgk
KZ\]t
p9h{
y T(
PwGv
o+d*~rz
bl&s
{ (s
URJ3oXH
/p]Uj
3008
_Tb]
$swgx
h.|w
+_*
U-`=
TXB2
oY?X
QHFa
IL1x
z/e(
$.'kBN
oM=t
$5 oceT
x_+
DMM
7(]Rc
_W~r
/mur]p
~G'*/
U4=5|
# q+
gB4r~P
vv\Kl
mao:
;]v=
a]X
AssemblyCopyrightAttribute
:z1[
j, w
2,-s}
{|e%|
s$ `=
get_Ret
'9>j
;D@<
eayd)T
#rIe
~6 D[
` (*
-Z e
jc0E
ow3d
ifEK
5axx
DeleteFile
h!)W
Of<3#bk
JcKlN
C AL~
>%H
k4yP,
^BwQQZb|
2018 Hercules Inc.
];Siu
CA%h
e+a5%>l
(a9[G
dc 8t
8KOf
1Wo6>
iYAY
2>07%T?E
z!L
q=ed
$B4P
FHd
Fr "
e"Gjnc
a@#l
'g1h
esqU
h4Y%
<Jqc
0D|Lt1
?B3f
Xt]5
gU{v|
z p !
h+G'
l'mm~
_hostPath
PomJ
&XyN
Templates
Kz=a
,$ad
*T\5Gw
!Jmc
f|kl
u]4}
"3G;;vf
AssemblyBuilderAcces
G.)&n
ga||
z.&{B4
zV#'j
hPIb
K,<#
]3,A u-
E$^W
J~0O(
KHr
_ yi
v~PV
ChX5l
M|K(
%(4
A!9=
yc-[
q-=;
mle`uhonShortcuts
nSize
{ } 8
S=bLM,
Y !%
Wg ,
Rb8aH)
FPtT
l&H *
j66Tit-
|IUquF
DU.E
K_F$
PY :
k Zj
y6fUL
]wn3
t&C]
ResourceDir
4-W+
A=#+
.cctor
CY]j
LqK2
d F6
V%8{c
= d+u!
?h$z
BS=r
Sv c}
G$kM
W*>f
&C*@?
s*V.
PB]>\(4H2<vyF$UW9$CC~GN{"
w?8Q
GetMethod
ILAG
-$f;
AM*I
6sHm
3TNf
KnownFolder
qKw[
?lbO[
3VU*ux
fet_Assembly
]3UA
Kill
#`?l
z a&
( \r
=B`r
)O.^
dp=-
~nV@Ad
7D`yA
v4az
7/Nv!
?KKd
6p6X
G|VpUz|
]kFp
System.Reflection
b G<
6)Oz`
} {)2
z[Y,
{T?
.Z`
UC:XW
ToGenericPar
`0J#
ni)H
^m-R
3&i00
Npx~
)'^r
GetMethods
jn8)
+L]]
0, T
?xqj
fWxE
3:qL
fkM2uI$
Object
v*/t0
[ rr_
E::d
k/A0
! *I|E
5`Yq
[kr?
P\pF
ah$*
B/blS
BGNE
2/0r
|vRS
V#x
F#ZN2
-Ge1
Ub0G
}`VVp
r 0
Ah=
C$=U
AssemblyDescriptionAttribute
xRst4Dz
}XCr{
^ 4T@
G!u_>se1
^kr,
g#O
]XzP
/xJL rYk
uZBt
6 p&3
z,cJ6
"0~/
9url
zX*<7a
m!NX
bC V^
.9]d
GetTypeFromCLSID
dh a
8"W%M
eF`rGs`mes
.c\h$
H$E)
@;LL
zuM^P
R|
"[iP
vbbXn
vW-D
50m6]
H4H?
>)O5
![B
?n!\Q
S`wtdrt
M8.s
4(((
Y4EU
[9|wJ
2g7)
=@ `0
dUy7
Vaf!
1e|?EAp
Y9H|
tkQ''
K_~]
j_?F
Kva3
+Jw$
dYC6
cj)M
[ 9e>9F
lS_{
System.IO.Compression
L 6`(
=mQl
OXB%
hM42
phlH
{?Ue
FGo6
dn>i
"E "
QZJ cl
:K)E
jn`!
}GAn
ZKKS
d[Nn(
Yu<
~t .L
_>t6
o X|
&s|vunRerviceProvider
PyKpj
dbFIy!
UDSf
j$n$.e
tz}!
J7*{
RYe2
2Td-q
t.4z
HqLJR
;S+
(wj
er^Sr
d8di
ArF]
wledr/CharSet, mscorlib, Versi
?b<K
t@5E
ie x'n
!WFrE
G:Zt
q~[E
*lDR
-;|Hv
`aUu`st
bD!]
!G {
hSourceFile
pPKR')
mEUk
jO I
m<Bi }ZE
}upaPo}e
jNsQM
r0UW
?@hh
$o@r
XL#:
zjc=
!qYx
uA @
j oc
msGa
nWa]
~bMJ$\/i2"(B*
.9xg
|3t#
7 Qh
l`hu`uionFlags
}9(u
A'_
j#BE9
/q{z
,90D
hm9[@
^#Dl
f@9k@
d?I}t
\g ^
RZ;
GetBuffer
n>|w^W
p7 |
E'd 1q&f*
,W<M
x K 6k
HLMTr~
I-OI(O
X'OOF
$hDlhI
GetTickCount
z.{`
aRj
dm8^w2
$- 2
FB)7[;
Z:SW'>
Ai 5
ToChar
V"${
~Cjp
ftmG@p
Tw'H&^
P7/$HA
|AT
ssF
3 \&
p0Hl
9B8:N
j`!
t K7
ProcessStartI
`g,4
g+N&
jy>%
} E
YfFVn.5
62m5
d $9
cd6E
M`~(YW
*3^W
u{)![
7F!8d
e0KB
yY?x
/LOvd
&*>+
OM(_
p(Ue
E`:v
OAL-G
hDdq
D` @
=q"
$r`7
.}{vq
VsnframFilesX64
-=7x
wQ:CnRIB
5FF"t
!(+E+
]_#6
"^]^B
*C SC}
G:yQ
HHQ
q Fl
h)`,
Common
TQz
OeG}
nNN$
m 6V\`
Gu2^
b> >>
/t/5Fo
CkkP
p[9r
o4l,
:W(!=
Ayi
8 n&M'
M$@R
n{h{
W:J*P`
2H 8[
e{Px)
?U8^
[6 "%
][7T
h{d)
iETF
C3h`
^Nl
Y_c,n
#V[
QZ j
Favorite
^`\p
ResolveEventArgs
+?TX
8`iVs
H(e )
0JEd3i
5S0e
:su8~
sldtuds
W5A1C908509B34
;6I}
,XPlyiQ
<.t\
AoT"Z
X'%D
26}
A~_A/kOX
>{+k|
Create
-gBo
'VB(
7IX}^;
xbS7
"CV H
/l%d~
i7^(
-w N
1z D
]9]-AK
aaJ<%
T&$V
Q+{r
%FBk0
{c@wqT
/z9Xo[
q eF
N$+ [
Z|mU
Ca?b&
31i~
AN{*s
qXdD
([bu
u f[
YQ@x
`By ,
W28M
Ep"
2+o(
%OE hn
)0,N
;k .H
7*v:
Rihk
bnT|%
a'P$gT"
-G}u4
tisbJ
) {{
k=>_
HmdQk
<>;}
eR|uudl.Security.Cryptography
d57>
h+kv#dp
+jV'w
MYS sZ<
} Cx
k?'
,}.W
F%_r'E
VyH49
eL`ur`feBoxButtons
4_H.
Q DEL
}8
StringComp
v 5[
b^ f
$ 1?
f%Vl
<Hb'9
Boolea
0lR2FM
95+
@.DT#
AInJ
`bTT
UDvw
7/&r,
/r`z
n\ rp
7Gfv
N'*b>
`Q]`n
[aR=Dn
A)o
Cz0;
2nSL%aI>
?R0p
lj}
x-Ne^v
,s
yZ!56
rM1z
]EXp
>X-wf
'qah
h6yo+
<T"
_H(\
R`0e470934e089#System.Resources
KBjkqnoentModel
2o Tbp
p/BKP
m&JF
X|W_
Copy
)54QY
j!\8
AssemblyFileVersionAttribute
X Ar_5>4
Z@A
b4
.# _
vzXhB
0v"M
R80W
rvGuusibutes
U2Y\
495Fc&k
E7 @
-.r
=3XM
%l)``P
! 7
ckMS(
eqjj
$5!E
gt?p
|5xo4
UMtN
32:v@
at4E
l%o:
\ MP
IibjCits
7SKqr`
9%?4V
]j"
x2Nr
qzHj
eXI9
cU`r
Icon
4/V)
7D{M
SU!g
H3MF1&f)
Lzlwu
WH&R
_~ }/
mzc'
9U q!x
? l !
ius]
HO @
s}zGq
PublicDownloads
8]k3
*6T
j^,&
v tQ"
4.U<
P =0
h{( k
/=HU
.]6[_
wzN`
Ickdct
)iGw
M1dU
h^K}#
=_$a=
*7UF
`IYb"
7.2Q
mdRs
MgY;
), m7K
colsY^5
*Uke
87q;N6
Cb/,4
$Tf#
$.d,
7O9 !.
)9Yxt
*d*m,ZD
YAE6
g &|
TOp(fr
y EC
/Aaz
7$<
3unC
Bxm;
K L5d&
VDW5
p5f,M?
E=pc4
1D X|
CredentialC
N(bd
z?n)p
OR5#
?H>u
i0x\
,]HZ
#0C*K
'rHH
!Lur
a;xzZ
i(x#
q -]5
1Bd
Q*4U
`$A~}
RdXyg
sG v
[n)PN
U-x
q/6[
_L1xe
YllnJ
E[[P
,]`GzKz
OR?_@
q%G+.
System.Drawing
}A:zZX
+Eu^H'?yZ
Fc]Pa
:9YG7
+[*
q.k]
izOd#`
kZ_8
{ X[_
Mq?kM
Tsc1
)!"\o
eA.m)~
d&PF
!]Y`4
DebuggableAttribute
#l<s
\B 3
,|]b@
5`wrr
U%2IF
XZD@?
H_di
|^sC
`
[G1Z
`ZNm(
tcT,R
-1L]
PublicUserTiles
u}|$,
,W-`b>
D4p4-
Jj&w
?$<Z[
ItzG
\,`|~X
<+ns
_WzG
G258!/
U8_n
si!bh
8XXf
7jQ}c
ubWZ
F9o=
}pc|2
K8/4C5
"S #
-2.N
oho+
':1
]e&0
>,%Y
*awf
8]C
ckW
XSG~w/%z
?p=3
6wri0
(cb p
\CX%Y
tC)L$M
#r[
GH&]T>#|
'`*8p
m\7]
o2b#ybw
GetDomain
2l+
n =J
dDBb
9_?$
SkyDrive
EditorBrowsableState
AssemblyConfigurationAttribute
61i'
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
'a*'ct
.YKQG
5VXU
wr @
80
evKd
kbl;
CultureInfo
g>R:
Heyhj
;V W
LX6y
"0a^
ReadUInt32
,|pt
(b2dQ^
-;3/
;E:I
,AI YJ
KptX
Ui:g
*a>`
vsnuect
*. bH
.m)M
wo_dnzhm
C6T}3
g6?@
bC @
tst.Propert
$G^=B
T%u
p~3c37
%7xf
EZ`6
8-r
kDM>
dK&9
(Q{7)
:Hfh
*:_%
bNv9
z2!t
'"l^6
&Yj"s
kG$5Qa
=A7S
c9/u
L9Oj[
+Flh^9
&]FA'
+~h^b
Rj0m
udu^CreateNoWindow
tINYV
4Ik*
ProgramFiles
C" Df
+aL4$
SbO+r
c\V&o
5?[&_
ai1(
p'g*
5"aP]_cN&IS
LFyl
=8!I
mt J
rH lN7
5SnMNa
Qzs9
H3V$
MK(T?
a!2Y*b
Cn4
u4H
jS/Nd
!5\@t=
_q2jd]e
XKy;
/}19
`a=ZU8
~{yr2
;~|
fr6M
"GV7
kqx{FF
-Z,E
>J8;
tf-(T
#g8H
UDx!
`F~/b
y]{p7\
hOvm
]%(/
9YB,
~F*:
- A}zj
4F]T
8]fC
J hV
:{T22,y@
l mxrg
fU#~
M8rp
$35@
fm30
I[U{
sq&[
;+-oQ
@[ _
fO^s
SUPeL
Y@dZ
BitmapDa
qUB,
4MwT
E% P+;,
hkgmQ`th
KON1P
}}K3#H
[)W_
!! ^
a,6u;)
Ha-}
2vHe~
P;::
W;w
~z9x
!4Oc
>Z)c
|jP\
cB*D
get_UtcNow
B'eLZ
)rwrk
Vu8\
6.<W@
po<]
`}*Ah
:Z X
' @
JZdZ
~OO_ b
J%Bj
^_>(
u-xD
xj)[
ldkr
k{.Y
(:$<
bhBA3dp
X+5.\4
h*zMbh
##84q
Hk!$kC
d,_j
set_F
&nwBmmLain
L]'
rY&Pi"
|].0
E-#[Ji
qKC|
t<7$
(RU%
/u+nW
o YIj
AoA"
SWm[
0&-*;qN
B}Qq F
Tnm.
<a_X
yHce4
q#TM
wO.2
OZLO*&
$McT
Q?-\
6 ln
9zD}Q
h8eJ
0KZ;
S2!Al
C?"0
X8fP
xzh-T
hW>a
!+':
:M7Z
+EXO
Y,Y~%
f5v|
>3K`
u?ek
&`-O
((R7~~
|BsW
_AKXo
tAVi(%t,
Y2w&/
BwN~
r\53
Flush
uiread
Tp{'
8z^P{NS
SosutalProtect
ye@QO
}4zU
:P<_
O45.
$bwA
_pwW
D]r_
)F@N
,<^y
/PLt
JYh4/
V1}O
3AEK
1!_s
[S~B
cQG&
/I%U|
)?&g]~G
'X'-
fNcl
@Mjfz
\C8G}
Bu]@
$ >V
3Jm{Z
?SdbM
FcD3s
VufSV
}/J\
w4\l
i@)k-*
v81R
6v1G
BRSD
n51O
+wsD
{,DG
KAWXI
I]|r
%Gx;
fy G
Py8l
Ki*W
`Y_XwV')
gv8rw
g`tsde
#E.,
t 'Tj
1NI<
xGr"
;fQP
xF!h
Ot$&
Fn|T
1ws,
_' W?4
1DPV=c
h5X;
U ;<. r
1SR7
=X)b
<0 'Y70
Dv(_ ZBN
{2Q\i
j;Nf'L
~PnW
jX\
cM|i
O`]1-F~c
tGS&
kg,$+
HFR=oW
HfXL
/^ 0
K@fedrrControl
a91
,CqUMB
JJP @
F( l1
@u
_sW.
#__mF$3
EWd2tF
W$z
UQ.{
Kg$}A9f!
])J3M<'
$yo"'
i UX
$xJE
C(mH
96aZp
1Gwgldvork,Version=v4.0
QV]%
%V>g
v[}{
0j*v
bDKQr
(Eo |
HxO
K[1jgI
);c&
[Tfr
\3XS
ChS @
m%+u
jBdh
9QX;
Synchronized
Sd`dInt16
=:-n
0h0z
3O~J[R
3RN+KquJQQ
@2 _
n{lq
WPo=
=@q4
Q~i
HpJ
#bo~
Q_Arf
[Tn/L&
^4C ;}
6Z y
x.nk
|}9$
/?.D
rKC
Equals
~ f
;|yb
(E?a
Z25y
}MhU
YAvrW
amkU
.t~\/
$D @
|[&PLJ
"L@BKM
m9fs
NE^H3
^,ak
TbLW
eym!
"/-y:
Bitmap
g5eZ
Wj5b
\!8!{)
a0,m&
xq/h
CTMI
H9,[
3huz
<>pC
y{E/eI
ldheMhne
@5u"
+2x}
Y4\|
T$J^
/Sgl
dN `
SByt
#zh4z
pB|j
?Rbx
u H3
FgGt
/eiM
n4-|
x|F+
0$i@
$a4y
fM{^W
GE<2@
X~{[8
:7N
>;ox
\ v1
8@8
w--(-wfhiyhmi|hmi|hmi|hmi|hpi|hpi|hmi|hmi|hpi~kpi~hpi|hmi~kpi|hpi~hpi|hmi~kpi|hpi~kpi|hmidUUiBI"i
S>I<
;bd}j
}[T
PT)"5"
3 n(
[,]{E
&TAgS
l`@hdmdHandle
egS%
:Qov
0cxKz
6M*!
Bc5Ib>E
ApplicationSettingsBase
=LJ<5
of,Z
F/lH
i,s$lD#
9hFK
V!X4
z) Iv
Acnd{
ID9 Ni
DL2FI
4q @
~_#+
Thread
orO7,
Te
RWJZk
.YG1
#wT>
PixelForm
! $^
? G
eJYb!v`
jn>4
WhH5
x~$k
CSM i
m@~e3(
>v]
Hu!>{~E
N| 7
ek SKH\
9,0Y
xEfR
'6YGV
*|c
kHA
Documents
2~k4
\YJ
PhotoAlbums
wsF($
el(VT
c&I'
Z$F>
XmS%
?+"}
Y("Z/
s H}
l`rshbAlgorithm
}y.i
!(TO@{
>@j/
EN8UB
"w0A=D
,/5v
(&ub8
e%6
wh-26
N*4a
rAcrhfner.SettingsSingleFileGe
,K;}
Q4c|HM
0/0
)0uO^
XuDX
f+HB
?: l
[*e.
@/Sg
.Rui
K;@
_G>1
sC1Mz
bytesWr
NmQz
MvZ
G|84[
S2I!5
Q*p4
TP/C
sOf:
&8"
acU}_)
UVVf
rbg
ZH,EQ
_<TM
p<kj
2I?>
[~D@awp
06 v
LNNJaN
NP k
DBx5
%3(=
?Z:9
$:2E
'7p@6
]S@6
VX<+
S9_=
I[>p;&
ke8YlF
c"hZO<
dEr=
JzKR
qXGP
pa 3
DNXLv
/"Z2
An){
f/g#
<Y0 XQ
wsh?
T3}|
]iSA;
FG oZwl
avv7N
$z+HAY
'jd2W
"dqRdlqPath
FQLP
1Y~:
g42v
, K*T
Zgn1F
wY @
Array
!D`H
z: S
,EIBf
"?w*b
6)i`.k
f f f f f f f f f f
PLS4
^Gyus
LhwnjeMember
ReadSingle
FR'J J
qa>Ni;
j^E4
_8`
@ !
A$ yfZ
Duas
;e:oX
n;qI
L/
Sleep
q&Dc
,%K]P *Cy
qB! U
y#j,h
G91i#
Z[Z 2
qsocessInformation
C +9
x"7(
DateTime
pr2i
vpFB
Jpz
G<#*?
; T5
?' '
R@2
:Z(t
ProgramFilesCommonX
+=<(`
V _| &
h_Z|
z w6N:
,)S"\
v?8?
fC`Z
UaF]
1^v&
g9>ULF
x.hr
W`mueKind
1(^V
i>jq>
HUV?
n"kH
rR=
9B J,
qFhE
}?AI
lSx8
e%Cu#E
U5hh
aUhN
Q}Nq
?.2E
hS$
GJT0O#j
hfe,U
ZJLe=@Jb!
<yoR5
8lK~v
3<BM-
=pTOa
+%_\
`j#v
~E^qC
#l&fb>3QZyFS
)b}
Oo
CPE-d3
sM9Yl
NA,q
gq m
w`thghableCodeAttribute
2i|
vp_T
|ol$y
RuntimeFieldHandle
VF(D
?w>~
aY @
KTtB)B
_ TJ
arD"=T
aA|dW
!@3'
* m[
(j C
I|g"tk
A$ b$
} <m"
;Qcv
X m[
3g}.
sf~3k
/n_$
WnI[
TH< 0
zSY]
R ?vdf
& )+k!
(# @
&R>
GhNK
x5%:
C~RZ
:;AB
BH'Eyf
_?mg
L
56,C
bcS
]cjY
MS=
D|F8Y3
Ta*b
lm:Q
c> 18]
.P@w
Tb<^[
U a
T3*
?B|t
DefinePInvokeMethod
1L8c
hGQyL
;
&A*Z
N|S<
v(1[R&
<z6A
W&8b
G9Ua
8j "1
m<:~
ncr/WhsualStudio.Editors.Setti
us)c
)we+
7#4d
hIs8;
M]T XT
n^xH-]pd*>
*n+
M?{'
w#6h
i!C'
Q@F_
ovc
e+Vf
0kINy
' R!V
Y!Y/]_'
6Dp{f
+aE0
hk2{
AssemblyTrademarkAttribute
tIDQ
bWAZ
4Zb>
|8,[
+18Vc
LnnhR
zr3A
<P6x
m|RhumeAttribute
~>S
jqJ5x
S@u\
eF`rBtsrentMethod
MOr.
+9P`
W2]"
1'^ '
uxg#)
-%krbnrlib, Version=4.0.0.0, C
]N^m
1^IW
baseAdd
|BJ%z_
xV3O
OT ^:}
px!tmF
ulgmh{eArray
$?;q
.rwl
&2Q>Z
0U78
!L>H
Ng0D
:BH4o&0
~)~
hpH*
\"(;
x-1
GetRes
get_TotalSeconds
+v>Kx
?qYF"
>;L_
$Ir(q
&-Gr
HYBz
)p%I
p~ S
* U
aMuq
eGljd@bcess
gD9uo
.NET Framework
>hk)m
d7 :x%>
>P)Uh
QeEz:WH
P Ro
x/pn9.%
ov}+L
e@frhw`tor
AQAS=s
QsX[ s
.{4c
0^E9
9|<;
9!@
]\&m
oxZ
WX i)
4 iO
}!w 1
get_Name
3!,X
,rHN/i
"mkk!(
dY2U
CozD
UserProgramFile
] .G
#h?!d2
CopyFileEx
h@|jJt
^DR5
o^t
IDATX!
wY]R#>
" F >
10|r 2[
6%$+
3(=0
os+z/r%@"7
Jj}35
,h=i
_?-.
A~7K
wr,/
hkKnetle
&cYnf
G{`s
biO{\
C\3r
sUgui
)y7hHOr
]#ES
ZTZZ*
E3579
z$<>,
i)u+
4AcvG
1[-;W%
/vb
m.9q
#PhR
h4n%A
@8u!]
vxXn}
La1
h3[(
^AOX
uC{_]Nb
&o G
I0 @
4XJ(5
6Iom
Nq<d
-H0
YS $
[,us
[{f@/
aG&)
Urmm
$E-q,"
At!5
lcMVW?
$7 P
J,JNH4
Convert
,6w#
oz*&$z06&z$**z&*(z$$$z
=t%
N%DQ9A
"6 :}y
[W%;
i7c0
V b;
;*QVn
FlagsAttribute
g7vd
8]y'&,sk
dL~k
u=ybA
_^c~
nQ,u
#pQK
(wbb
*w?2N
x'Qt
F4X,
z{a*L
`~} "
4lk%d
!Ea8
1rQr
P,!TU
(>m~
ka)T`L
D1I1
<odo6aN
R-^X
<s>q
|smi
YI"P
<G4Bw
ttX @
"#7g
{hME
L_Mg
+1Svl-
System.Net
5*/{
FTUW;|y
qm?\Z
%`e5
y3Hn
cu0D
bAE)
$A G\
Bx2n
@@jI
#eVh
wLv8`gkM\kz>E"aW`ITG$L?'!
L_"|u
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
get_Default
ev"8
1%ZZZ
KrQ~
kernel32.dll
,]KG
@k65
I'~
nvBD
iA]@k
&|9
IZ 5
U) b
;zx
Obgj
&|%\
93 u
p t42
3nlb
0i>
.aBt
g<= (
v$[^G<-
Xmi[
P"$=
~x:b
cUeSk
c.S
dwCallba
}b4$k
,]KU
e*R9
*K*
pzdTH0
u\=*Y
=t)qM
&^-:>
_dAc
bZ).
:KN
'~>2
*^Fs
O?<$,
heA /
z6vv-
vf5~
u|(Qdsmissions.SecurityPermiss
c{5U
rjHi
z~~Iqrs
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=.fm.resources
@kr:Ix
J`S^
bq,\
(S29
2"""%&"
qP,(
M5*w
Al4F
xS0,
yDf)
4*\L
Q PM
sv'L
5[`w
nMfe
+* \
pXEi
M?}n
0}0
Ringto
mwO.
Q=c,-
GetPath
;X/m
{Oh@bQ
GP=J
`w#m
r,yb
5xU a
AD9E75AA3F5EC98E04FF
O? []l
?gey
wr9]-+
" -
A !
'(g.
gw}AZe
^UVK
_QNe+
f-f3
d:V?
9T2#
bvMSd
Write
I; p
^p]y
F:/$.!B
aS@m
;Qs&E
m Z
kf \
w ;rH
\T
7`kbnl
_M['_
733|
V@CV
R y[3
mO.Z:q&
cD=}E
d dx
-jE %
m{$0
u}g
=C-Ij
l`qnsjAttribute
=7gz
PublicDesktop
JG+6
bvA7z
{[*L38
\\ b
UsbT
P^]t
$,DV
ZaQO
k?2y
8%UMlI0
Va]j
} `y
#ywAC
1UZ @
m|Dthmder
a8 W
3!A7
~sA_
%<t
`Fo,qU]
e^I\E8
%Us?
e+IO
Uwgorgorm
u#9MC
ZP
G :
8A;z
(zey
(PP>
*U '-u
?]k
I0+
1!\ g 1
HVbe
System.Globalization
jc&w
jfK*O
'i[N
M1 w
/7 B
Igvn
p(-d
IconSize
6b1e
re4w
*iH4)
c=Du*
K1&
G2{@x
uWc`edr
Oj wu
BP1
y 8K
O5p;
QP=<
iqg3
7P(qg
System.Drawing.Icon
%S*=
0z{U
!5#@
I$Hk2
/NMz
HRv
ChangeExtension
;{KH
Rm8-[9
E`
V[cK
:PhF
Ew)<
32m}
-fr
euE#
`BYJi
CreateInstance
16Pi
w0[?
Q>H%NM7 x
]M]ZN
Q*iF
.Cyz
.L/Y(H
gaq
I`4&
26bP
i Vi
lni3U
_Ig#
z8T{
e~"E|"
x]nOS
# X*
\HP"|#
&9UR
Ip4P
L$`i
!3Ue
Environment
26t,
`JAqy
;;4!
Bmgs
N#)2
"Z08
]rCb
pSPLK
^zwi
mZwN
jm\F
}&s5
,0UUUH
PtV?
Qoint
Tp9\{
@xj
r>1Y@
!N%'
b@6O
\x-7
Decimal
\F*^z$
6#(.p
c_5U
*.+
Bi"P
p6r%5
3j^rP
@5(
0&%V+B
~D@
? nl_>
+)RC
Hercules Inc.
^>EC
%} )A
'r][
wheJ
Micros
cKEHC
'>{W
RRvT
ll@MK
mT^r!
R{m6
[@,v
3`isdUxpe
Double
M R
ReadBoolean
@ $
];w
q >1f4
d^J7
2w~k,d
Intern
N -y
ComponentResourceManager
P&A w
. 89;
#B#
_Lc=
UVJX
j3j
T:/'
0Q8[
pUWv)
IDAT
Z fjD
GetN
V"o5
H-;Jhb
c{ @
c>L B
{7v4
xE>y4
gnC:
/B[j
l"!2
eJW;
t`;1
M Tg0
J R|=
`tDw
_uX9
f@"8
XZ~~
RE#Q
[`tnCxtes
It_^
-b zT
znL
xm<l
f4vZ
t [
V5{3
KKXM
Y/!e
O5,Z`
xJx H
.# x
| Ts
<j'c
j0u
mVsnbess
bwah
@hmdInfo
sCLIt
u `
KmWy
f-"
xt<s%#
@5@2#
iz kz
AssemblyCopyri
U-%0)
System.Core
B+&8
p(0d
}rJ8?
YF$0*F
P2 '@
(w}z
> 02
"dzXY
AssemblyName
Isi+
n1 K
ParameterInfo
y.>' ::
>"(#&
%%q|
T^(k
Ga ?
%\TiC
CLI=P6n
vNFR
Sm*kf
Uq|5=
+(7A
3}6r[
JiNn
$Vlv
/qeVW
m]Z9
Hz?
}'W
[+Ywt
8 ":|
Y DN
b~ D10 Y
KV0,
,]@=
@uvRinrtcuts
kCK
get_Length
AE!
zWn!
jWm(
lZS\
[+;i:<h*c
Bdbnmpress
8Q4b
(XKXT~n
5e_^$
s"Jr
B>5YC
FUc+
S_?s
/&!SM
VA7"&s'n:[o!K|yqYE:Bi~5a"
N;gQ
oWYj
{q>S
PrintHo
~6';
V=BC
}%W[
Q&r\
,oux
GetFullPath
wg"f
#LzV D
r3%
X4696}
FreeCoTaskMem
_si1
p]u!]
n>0
Gd ea
vq@
.8yBM
h{tE;
pLS8
f CwP
%?i (R
3 w
^Lrdl
B<
Z +r5=
ZkO{^nw
]+Iq
`%bYY
Q)/n
b^'"
-o+[.
^uR*5
8BWh
t>)r
PpV
,T!(
&wM#
Mb2Q
5:G
f7Vo.
^T<*
hxOD
7\9@
: D#H
J W
3k/C=
\ ?O QyVQ"
GIKWW
AC J
1~vz`[8`](UDTi=4=A5jhH?I
a7cA
fKW,
.Fc l
lNl&7
2*u?R
-F/'
xBT?n
NoN)
@\M}
=ZAu
7LC%T
J PkaA7
Z1;iu
eyw^
UiBC
hnmA,V
u7#\
]ce%
S3!r
.rsrc
Lx}'
cG9*rbVf
xri'
-GQ.
AdminTools
bL(_
rE)n
ilvX
UD1zl\^[
mLk`fds
;j\.x
i|FW
T P(
:h'4
;T)&
tzR\"y
pV
6V $
#&KK
/3K(A{x
gw^zs
3Di
RTsSystem.Runtime.InteropS
(MN;
7G'Lz
o-{t?
NB^
fWpo+j
aJTs
?7 d
V#jow|cT
9;`U
%a.F+<
`%!(
8F2K
+
PY<cI
L'dl
Q4WGs
0V|w
S iXl
qay5
lg [
dBZ]
Start
]1.B
[{>P
hB*P
P P(
HD.u
v_>>
F'&1:>
2"i0
a|Fy
ParameterizedTh
F3=JCn
g.BN
QZ0 UxY
SendTo
cteh
Data
@oT0
D?M3P
O X5
>gah
{^5c
9$>'
uZRhldout
At&VS1
A|@Q
MX]uap
5Q j
Nqx
D3/S@?
!w/K
YzUxB
'/iK
j'9o
B'@[S
CommonPrograms
g6RE7h
$n5M
zQFc
N3#
S"V=b
U[m%
WTu0
XGtg
FHh6x
iy& 4
8wWu3
:4uiw
x_+$
h @
TQKV-A
H+"9
;bWN
HTxvX9A+TQ4G3VrM/cCjQmIjiX9Kre625ZnEupnJ28dCkns/HagFwVk+rF+wKOJ6rVpkyuwe5NclRpvuLsfTCrkpnfFK1+o+MYiHiJL8CO6igA3QLLhuxQVKMNvZizYLRWU0URcrQ+uR8sauqwo=
V !$
X Gm
BY
9-n J
h$a-
sjvRdsvices
7p\W
+<@\8"-
8H(a
#;pwT
%Sj:_D
&8Ue
Q9GK
Zf1U*
V{:q
-J~PS
m]7f
Y$#
wHsZ
gq4$po
FZZT
>?0}|*
m^4o^%T
,COYZ
v AL_
cH]#R
.hq_
N5/M
dbO
,!{P)
2)Prp
r74p
g H_
?B_T
XB~o [(:
Byte
f,F0
"jNR2-g
5MN&!{
!LtZv
|/=
l)?J
)'?m
,QRj
2<rl)
,,%E92/
I VN
4SMZ
C Q/
g&X&
[ R)
$$e|b
=z'$.
eRftddoshots
pf-b
e[H:
TI., Y
tB B-
~$x
rt&\
G_BbTx
#_K!
MX|B
LjuS_
%p+O $d
Yf*'
Kj:=
xI `
}>T
4*!.Z
Oohuialize
ab";7
FK |
n6[sy
q- ]
L1Vv1
FreeHGlobal
Ez=4
%/wO)JS
!nnfi
WajJ
f pTJ
sXE?
za!
,v'vcO
ImGE
4 I\
p%dM
x$)z/
s _g
CC[O
[^`=
y8QDK0
*[Nk
3NUy
%Sg%
@Y{gr
\P0
ZoVC
Jc e
UU)H>
u;v
E>
oOG 0o
0 Jr
CY r-W
LemberInfo
%9s`
"z[kBM
nHC5
d8Xb
b(?v
\OSU^
z#Af
\"
uABG{
op;{
J1 3o
34p~
j1g
_33L
B#R#<eM
o?#2
if \
P 3"
@9;A
Open
<pP-
G;,u
K_k }"U
>J_> nMSG!T
Ur
cF^l
Q~Bx
m<E
|-5g
cm
,&_g:
gF'\
TX &
G(S@
C1a5
!b}ZT
m4MVH
tjH
bAHD
;z|R
m+ zM
!F`4 vd
uC,w(he
fdu_CurrentDomain
+Ur!
wonzo
+_I9^%
FZd3J
] ([
+21eb|
V~ci
3Q}@"
S#3`,
P%Uck_
cP'3
p^w'
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
Q||7
P~?z
S,$t.
JyhV
Z^/F @
>X<@
4(t
$#|
X JST
&)z\
ue9a
Fcz#D
SvyW
HttpW
P<a
Pa |
eSf;
:8T
7P#%
F0T[;
2 d
p7@:
-MZI,
/ s6
DPhfa
~e>:1
E?t\
h,#c
+i3R
EK@Y
*=Uj
&5LZ<8;:
oa.E
h(j
/zAo
get_KeySize
TuGA
Tn='D
'Hk9T
\=77
'hkgsxVriter
5*`#
KMicr
P>,v
;alU+
[}}o
ReadByte
YUpO
ok\x
n.e'
5+_w
~*`Kk
lpBuffer
{!Ve~
J&;;^b~
7R+}J
1 C[
\D1J
^348
\}F!
n,%
OSI=
AllocHGlobal
N#.+7
aE;HM
GameTasks
YF s
HDA
Lui:
_Y~.
g^H[
/D[*}
>7jh
d(wx
2`LE%
<|6k7
4Recovery Manager for Active Directory Forest Edition
Mo]G
-Tdf&A
+) gL
,X)i
@4BO_E
z`=%
8.v_9
>aKZj]U06P
\+p R!
Defi
& #
chh mm
4&X'
oflK
haF)
ReadInt64
}+`z
E9_c
IsNullOrEmpt
#0\
m1ObR/
%&;Ti
Xui{
drA3
IndexOf
I*6_r
X5O3y
|d^'
=f GrxuXT
_e;3%
f85
B.`SF
5Hp +
at%{
@ nN
!\dR,
qNt @
M(}p`
ZVj5[
8%s@Z
9~'faj
TargetF
7 7.
8b}3
ft.J
{c;D&
hq&1
YDw}?p"
mhm*_
=J3 w*
;*= c
#:k)T
59-T
RfWr
lZI,t
Aw1Tj
)% 9
r+Rnnms.StronglyTypedResourceB
F;;Itch
M=kB
5ctM!s2EYQ
dqcs
6:Qb
&\^#
t$'X
eCC&C3xr,
"V^ Q
YJ0a
a2hg$
kkcP
y2 2ou
x9))z
AutoScaleMode
*:r.
KM{!
5#)A
F?[-]K-Dpx
X09R0
t"ij
4rOR
Wl J C
2[T8
] XC
3G)
qu @
3b&p
N( Zg7
MqpL
=wB],
58LS
dE2
l_i-
XJYZ
wk)K
mWM:
?NV&
F uGu)J!d
)8jPu
foYL$#
Y?Ef
j*Px
$>@M
B-dy
5tgjhbEocuments
t`Yk
@<nK>
*h1j
}Sn:
Mdy/
^O_
X:Y
Jiw?
`cU"4
0\ 924
Qyiw
hT5S
cG k
j_v[
%\R|v
SS:/
FfdE
D>7`
lV"
0._Y
l`"|
;>edE
^5f(D
.\bO
xxBl
:n9
JS\6V
"K3z
*cc}w
NLvZ
b$ WK
gR1H|^
1sTA
dO$x
GE1e
@AVu]l
T"y
AsyncCall
E#*4
t 0i\ng
>V`@
QsNV
g6"#
3 3 3 3
q UC
d%2!^
|BF8
"i d
N&m^
Radn
^8;G8
op_Equality
(!<
R6mV
AUy"
6W &xZ
blH\
x7+x
R!xV
;q1|
OU(nt:Eyls1?a7l0>WZjVF&s"
Rhogle
FF89
*~+
~r-wD
,'8Fg
@]k3
`s-{hFR
TypeA
)6j)
N+1Tt
"9) v
<e
(`l8
!z&((z&&&zGGGzVVXz
>M>&/V&
E53K
{#sR
2`e
gc@a
nXZ%
|A$R
HLHT ^M
5UB&!Iw
r %
LAK7
+Gx_ >X6K
Fx<B
}cl5
")Js
I`J3
"!?}
hscB`leraRoll
LuiPS
uuRU
sttd%
WK d]
(eop
%mT/
g'PP/
HWH
]|qS
k5nc
JA!v]
( S^
Qf\7%
CommonSt
~%w>
bB*A [
vlaq
m``.
?%uF L
3pX7
D(Q|
Jiq
`gjd
XM@O
Sear
rJX;r
'+D5
Ix-%
p! >
^=h$
s`Ee0
!"jre
ink;P
Y~+Y
E2|:
\Tu6
ve}u
Xg|t^L
DqHv
t3TBM
o<KK
{mnkgi
||| }
7Srn
Samp
_4Xw
1 @S 2
``Gs
`Vyr7
]HYY
L6*J:A
+h$1
&_l^D
s ~
CK2s
0HbK3.
2lZ6
$Sf:
n@]/dPv
}W\[y
%ol
tu !
,1Gw
(|A*\
?81 !oS
UkB
lhP4
dDQ1
dPe8
xs^wqi
Ho9
x>>n
O3Gv
q49[
CKYu
>@GO
1hi$
+j=WJ`*
-Gpw:hejC^
*/I
_::Q
%o"
9 r,
G_<!
d61?
)={r
BSJB
G&0wHKv
fXU y
DOoLz
Pc3!7:
UI[L
F)6t
RegistryKeyPermissionChe
s'h[
*5|nB
#vtmo,
dWF<
(MZ*X
!IzjA
: )
ok?|
/ ~
,$)V
S`a1
/ C>
Z2wB
P Is
}X/0
Az8)
9)U%
XzgJW
5^Iz
IntPtr
LXl
r>4E
+yov
+/*
lK$e!<
5;Ar
M=1O!
Lpa(L
>D*b
Y<$h
}Hzn
!l ;$
? -vC
f C0
Tz|34<
b8^:*
qr04
T0iY
QG{jd
+J 8
Q2/"t
:Sdt
[1$B
)G9h
EZ|_X1K
:i^|
GetParamete
`+,,
Origi
&?E;Ad
,(ca
+NV
m6@a)
% >Vz
v16$y
6d!p
u`ec
7+O_
N3=k=B
%jM:
\^\D$
TimeSpan
-c&x}
D7 eNa
UPD-7
kd56>
AppDo
&CaV]
]g`7-.
I9! Il
DPl^K
ek$Q
7O1Z
mS}?J
I*bn
3!Gt
^dzo *
dMW @
)mC#`zwX2>2fKe~B&89{])B-"
`dj:
E @
3>IG
0#WfJC
+g *
D][!
4 +% S
8K9t .
cqj
|(O;
.<}(
:TwC+
tbKl
31 M
N.um
dwhdm22.dll
6)U1
veDv
Hi?0P
?Dfi
:ksa
qgC
h D7
!This
gccsRhze
z|o-[}
Gq[z
.t45q
G4}4
joTv
fK1pY^
&XjUK
Uq8y^
1pSpL_+
ued\
#no qJ
=I =
c>X7OJ6(
ds`SL)
Ywg?F
Pn^Z
WoXW J
2v?y'T
W_WX
K>>u
9ii|O
jNr>
C7aR,
yG?R
( [ ^
aX5#
*iBa
EssB
#}y?
=m\G
"Fk,T
7)e0
YOOMyfl
c~ "
P#6c
SJs7
,p5q
Krqq1
AI`-
U6/N
{sXG
a3(
{Bpf
:/ W#
GT jF
|{(+H
@L1X
\v`s
%&1),
= !x7&
5xjw
*C)M]
B1F]
F\hs
ovhA+n
p*rf+
S8w!
uG c
IEND
)fJ-
yQIu
%K{
oIa
;f@FN
1F14N
*}t!
@T]G<
M nyR
]Q7w
>AtDz
DT ^
W{r(=
'K)W
f DY
Ej D
@q s
context
nT&-U%
Er#,/:q#wE:]Xv5JJ-cWZ1&k*
6rQA\
tg 5
fCq47
$qeT*
?9G+:P$
v#L&
csw |
"~U
:{Vf
# ziD
#aU|
qoPI
'7u?
9f%g
+ w^
- 9Q
jv(f
whok
W$fB_
@IY=
L0_o
H>K!X
Qgq'
bNsc
hD%y"1A
F @
p60O
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD@
nm.v
;F]{
j 0Q\Nb1
'|Z
](Lv
E[j Y~
Hd$Q
k|PqX&ci
*^+
#$a|
*&*I323
L0_C
:MH4PJ
#osR
3MEV
CompilerGeneratedAttribute
*yKq1R
F^:W
:CtSW
mf03
gqDS
b%IG
b) "
*$](
x)M|P
.ga9 &
VZJ#2O
{)@Y'u
L }@/
mqProcessAttributes
xfz G
\nu;
ss(i
1Pz @
e]sR
S`ndomNumberGenerator
Insert
#Jx t
Ss9YCY
RJHa
= Jtik
"ApT
nJ]3
!9!?q
3Ag2
get_Id
Q6 7_
+&Yk~
eGjhur
U# #
0SoJ
^ l?
y#Wv%$m
ofqF@`%
*@x]0"
>]A;9
GetElementType
_J,(
Shell32.dll
\Z_rV
$>t
f :3
m3>z
[-eg5/F
sNvB
I0yfYWc%DQ
/nJN
%Vh)
=J@|+
O@73
F*F&
,8eD
#p=M
lQc|
E3T
$Zu
"V e
AEhq
0%q8$
"F#:g
!(U$
$B));
cB ?D
p!
gNd3
*xh=.J
*5z[18Te
.$+9S
;s+a8
_jR
s[I=
znh[:
OXrZ
y8'D
Go=]
Wius
Ie/f'
FJ)g{N
L{?jDI
TE#2K
j.t:
$-2kY
$ZR"
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
)(Q}
H<cO!
N\PU
Syste
b95w
FromBinary
M6I l"
!~AN3
O1he!
Jn`t
=L<}(
Xtjz
String
PNg{
F@Nn
y7au
,xq?e
p}C9
u {#
SeElk
43O/
AJ'-6
h!XG3$
O<S 9
eI11
&b^n
-97h
ap#O
Lm23
&Yb`
#TZS
eWV,
|@lkd2y
InitializeArray
D:e
@;1a
#(![\
r7@_
K4ui
96G6a
hraCO
nf~3)
2f2\
*fx G
!+]
0r]1
NZ)%j
EditorBrowsableAttribute
KV=\<
'4,0a
n[|q
X6G
i,}RQV\
^`UT
Fa)s
e^IWB4
iRg
`.sdata
TiNEN
Y I)
~`iPXY
ik!zT
&'.0M
jrtv
S;F
Jj@Aiy}
Ltd)
*mj-[.B
VT. =
!8${M
0D,
Load
}Bv,!
f#l\`
get_Module
z5:o
eLsa
'rB_;
(hLRpu
shell32.dll
qa;z
=$+H
CurrentUser
pdX6
.aN#
t4\M3af
(>1x
4jK(
H{gu
RettingsBase
:;7~
/OA2
gpGu+
086DC6
_dhtC
0%*%
>m=S
bcod
hPIT
@7Q'Np7/^xhJoq~~+9?&+"/i!
V{p"
:V>J
2f PesNN ^
1=@6e0e
^y!U
G.vt
RuntimeHelpers
eT^*
~rE7
"GES
uHcot
,WSP
{s68
8rX{
)ci"HV
g u/
,.6"
#Yb~Yq+i
SaveData
X @7
qz%e
' >Gkuf
k`9
jY8'
!{6;
Zs'2
1;1R
*v9(
@Lk:
`%;@
>>h
Hit rB
;r be3S
/7y/
x;qj
ud{e
7$XlwH
*Y,M
R0eE&
3System.Resources.Tools.StronglyTypedResourceBuilder
ujKm=
?SEQ(E
@#R-
B(s4
+\,Vl
aK %+'
aC>|
]B}Fm _
e_J,>b
dqYHudm
L?*&p
d*)]p
7[8p
4js$Xe
V`txDBMB
6k_m9Hb
|EZn!
r3wN
j[t/:
_ /#
{rVU
OGI,P
`Xr^
).NN
^rF>h
$|-6
hE?;
LX)7M
5< B
RoamedTileIma
oria%
2\QQ
Q%@E
$H^Z(
s>T*
2% 7
J;v\
CLl8`
b,OvLX
j5K"
pd}>
?wp
;CW|X
hCO]Q
b{pv?P3
b1 y
Hl| X
1<|U>
[_jq<
5j M
<~\wK|
?.(B#
`N !
K=3
hwCT&
D-C|g6u
Minks
Yi{
B:;#"
{Ya
6@jo
o -h
.ojqoGnlders
Exit
,cZQ
bi|,
XK`%
H{?Y
eE`thwdBytes
_ pvA
Ks+S,
*-Vp5
Microsoft
(?J.Bwi,
q=C"
*TaY
;Yjt
mhoia
6hK5
#7D=
eU@9p*
}(%]@
P (7
V^Wo
F M_4/
Kuz~
j%h@
~S
b@>\
LPtB
& K
Pd [
8&.k]}
T\-'
RQ(
'1mo
;N (
dd-Kt
|lGf
6.^|
FileMod
set_Icon
4.hqM
e,W4
0? ?
131bd342e
;O3tv
R J.
R}a@Rs
Asse
%R7O
System.Threading
tQ1%
E>1J%
ewdjtd
tP/<
pyUd "
/]U4
Q/$5
V<_
(o K
/C f
o`"G
2}s=
Hv/Kz
un-J
s&KP
Ev];6
(;c0
H|._=$
p4s
{cS#
0EF#
2&$&$
G?Tj
5fj
+N\y
W(&1
WcfhrtryRights
"n:8
=6?a
8hF{
ImIo
l-"`
J,K&
(A5!X
_Lku
zErQ(
$?G8
>7f
'f)f
"'0V;
rRvA5;
%+spz
I(eo
{loL0!)2
T/U-
=w! =
+i_"?
^Xj~
$V{P
hMM3
;}nR
[9E:
Next
6DIN+
s["}/
#OmB
^G>^
IG&0
}6 ((j
0h!3
8`=MP
_@vrB
;zp$u
\%a%
gp@(
b)t
kmQ)
{.Cy}f
ZBiIv
`*OO(
K?AO
O*D*
9Ri
^#vu
I NY
N#L-
<i<W
jV<x
B] 492
#fbZ
W#l`
;L7!3
;Rs
-Zq5
$V\Hy(
<HtXHH
/,FHY
=|Gf
,`"<
c.Eg
d {
y;G7
i~]%
D57K
=%vtE
gw h
^uB
J2xdD
\:C,
}\OZ
#\+5
2G$;
Vs@z`?
s\vg
C0hNd$r
~8d3
66g1
@TrS6
o.!u^
sUgui3
bduuEdlegate
:1>|U
qKslcdrOfBytesWritten
Jfrx
%#AU
e xJ/
GetTypeFromHandle
IAsyncResult
^RI
*- i
'3x?
1wAE
sb_vl;Y
G1ZD]K3|
]b~J
t 0[
/M]K
nKe2
yq_,
8+ $9d
%|F'
j:BN
Int16
uf"llw
Y-d*
GqqmicationSettingsBase
/ q"
@UId
pM!b
ZrWh
E :`
"ya?
E!VHA
hwZp
!wBm
v!*({{
Jl'_v
3dwuhnoing
(<h2
1C=Z_B@b*N>Pkp=ZRk6^?+ON"
xgze
{[GF
C/ 59{%
86 z
*-O$(
/)}Z
03O0
System.Runtime.InteropServices
-:Ie
/e/_
nh<=x:
77~QeY
o\cR
[}R7^t
n`sJ
f@B*,O
9 iP_#
1&D_
G "<
7-o_i
EE81$E
/FE*+h%Wy
*B 5
System.Runtime.CompilerServices
cLq%u
.3?EBm
SL5qP
L!@65>
1iX
+$5=-)k}4o
H#~D6D
I%VxW
Vb|=r
LduhodImplAttributes
YC_~
-Q&V Yr
Dk=[~
O T
p8M-ZM ;]
.<d4I7
Bj0S"
~I&,{
zJAS
:CiibjRize
;>ti
(EvQ
$r*kl
guWZ
k %
ZjG/
]8>r
~m7#
d7 !
m{_R8L
~?]K
KN5Bd
g* Jc
3 Zz
|`Wjs
\Q.v
.qcQ
vRmbb
-)rvF
[Qby
(8Td
=Jo4|@
R5Kate
un0O
TLoM 4
qw7i
S hJ#
N`C?
wGuR
4,CN
VRw'I06
Meth
9*zOV
G#4F
m]w,
KOL:
Qyz|b
leYg
fcN"
@%GFEZ`
rVNWi
Mwh8p
U]{z
,J_j
;9kk
w+2u
}Ez?
R,7+
Gf=-
ry`?%
E}yZMQ"fg
z`WI4
VdbResponse
5 ]N
+iaW
y4jGY
Uux*
wT<jlw
}Gf')
-z7
t^wp
5^7L
Kur8C
4qA.
}k~P
4Jq7q
9hOmG
bAjX
vm C,
^ +.j
KIABs
get_
} I&
Ibaf4
.xyT
|M.55
WL}V
OPHH
&B)1;H+
^}JgbK
QX=R
c;p)
^6!4^
?'}$9
QwT @
s$(8;
W^# @
v`s`m
{:j2
Lk!<
>$&-
hkU%
k 0[
!"5(6
n>#mqE v
:HVZ
?3)oD
j$Ng]u*Q
fs[z
v,zC
I e_{(
r *nO
5Ws
) o)w6
,z::P.
rbi| ~
cAaX!
@(:{`a
qBC}
2 "h
ILHo&
~{rjB
OSETDZ
@TjV
ud%k
#2Y`O'
.c[2
>{|3Y?/
m.-0
>@|m
e{R/
Encoding
:+ *
E )
n8N"
B*(2
!>>.H^na
];y
=$SH"=
!&;$
*Z+
,u<6
Q+Eg
8lRX
C|cy
[,yc
r>rT
7:=?u
FinalReleaseComO
1'ag
z~h
z-ydZH
xtl
=^CeE
imII
}@ml
3M'ad
A` 0
ReadSByte
h|-!
-#>{
+'b%
<@A0
{y g
F41Iuhm
5BGf$
N?Bm
2`o
7|&2
Zero
Ncm
?4V.gM
EP'+$9
Y$jp
Y<j-
2Hr[k
>NY3'U6r
xtI'
vHH?
~IqMA
R1 @
.{g
-tVn
X0F~
cpXu25
b]u @
?(['\
l?J~B
gB$;
Xl >_
;0yf"
S'E-Is` <
iMJIR
0 r*
Ggb(L>
yn%9P=sAI
mnBm\
R.Hy!
rY;E6Imzbj}6LoGY"<s!ck#u
xKQ5
l' vX
d# '
2#UF
q\a>
L"%W3
g`%kWO
bj iS
k5d
HK{5
>E+ R7
Ic$r'h#
!@"W
xCTE
filemode
QK]m
`En;
9FK9l
3% L
r2)S
LT2c
eS\6,
eTkjnbjBits
h 3<
MS1B
6dqMonvnFolderPath
5) U
NLU=
`_D!
bY)`-
vN%S
System.Drawing.Bitmap
Jytc rZ=
{`L'
"(,v
U@sM
&f (f &f
psgYp
Ra )h
D!Y#
r ht
&;[IUo
# -c
lX[lWu
A*:{}
;(/~
F18IZ@K
>HSo
3V~X
J fo@
?SW<
Unl6[y
$ 9!
&EPd'
)<97
3XcN
qt >U8"e8
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04b_64 Seven04b_64 VirtualBox 2018-07-24 16:24:25 2018-07-24 16:27:21 176

14 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04b_64 Seven04b_64 VirtualBox 2018-07-24 16:24:25 2018-07-24 16:27:21 176

12 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.exe.config
C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll
\Device\KsecDD
C:\Windows\assembly\NativeImages_v4.0.30319_32\HTxvX9A+TQ4eab8ea8f#\*
C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.INI
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Users\Seven01\AppData\Local\Temp\tst.dll
C:\Users\Seven01\AppData\Local\Temp\tst\tst.dll
C:\Users\Seven01\AppData\Local\Temp\tst.exe
C:\Users\Seven01\AppData\Local\Temp\tst\tst.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\BVTBin\Tests\installpackage\csilogfile.log
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_64
C:\Windows\assembly\GAC_64\mscorlib.resources
C:\Windows\assembly\GAC_32
C:\Windows\assembly\GAC_32\mscorlib.resources
C:\Windows\assembly\GAC_MSIL
C:\Windows\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\*
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC
C:\Windows\assembly\GAC\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_64
C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_32
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\System32\tzres.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll
C:\Windows\System32\it-IT\tzres.dll.mui
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_64\System.resources
C:\Windows\assembly\GAC_32\System.resources
C:\Windows\assembly\GAC_MSIL\System.resources
C:\Windows\assembly\GAC_MSIL\System.resources\*
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\GAC\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_64\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_32\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.resources
C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.exe:Zone.Identifier
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
C:\Windows
C:\Windows\Microsoft.NET
C:\Windows\Microsoft.NET\Framework
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe.Config
C:\Windows\assembly\NativeImages_v4.0.30319_32\Reborn Stub\*
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.INI
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\OLEAUT32.dll
C:\Users\Seven01\AppData\Local\Temp\6e63d0cd-7568-4439-ce55-2639c6f48572
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\Reborn Stub.resources.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\Reborn Stub.resources\Reborn Stub.resources.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\Reborn Stub.resources.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\Reborn Stub.resources\Reborn Stub.resources.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\Reborn Stub.resources.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\Reborn Stub.resources\Reborn Stub.resources.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\Reborn Stub.resources.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\Reborn Stub.resources\Reborn Stub.resources.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\iDLaqmCrPyoqarXmNdgSdMwyeYGJA.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\iDLaqmCrPyoqarXmNdgSdMwyeYGJA\iDLaqmCrPyoqarXmNdgSdMwyeYGJA.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\iDLaqmCrPyoqarXmNdgSdMwyeYGJA.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\iDLaqmCrPyoqarXmNdgSdMwyeYGJA\iDLaqmCrPyoqarXmNdgSdMwyeYGJA.exe
C:\Users\Seven01\AppData\Local\Temp\tmp333B.tmp
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ntdll.dll
C:\Users\Seven01\AppData\Local\Temp\tmp22CC.tmp
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\DosDevices\pipe\
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
\??\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
\??\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
\??\{E43D242B-9EAB-4626-A952-46649FBB939A}
\??\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
\??\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
\??\{9A399D81-2EAD-4F23-BCDD-637FC13DCD51}
\??\{5BF54C7E-91DA-457D-80BF-333677D7E316}
\??\{C2D43895-0262-4873-A789-C2F96D24B693}
\??\{2CAA64ED-BAA3-4473-B637-DEC65A14C8AA}
\??\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
\??\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
\??\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
\??\{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc_lng.ini
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.cfg
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WebCache\WebCacheV24.dat
C:\Users\Seven01\AppData\Roaming\Mozilla\Profiles\*.*
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\Profiles\*.*
C:\Users\Seven01\AppData\Local\Mozilla\Firefox\Profiles\*.*
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\Profiles\*.*
C:\Users\Seven01\AppData\Local\Mozilla\SeaMonkey\Profiles\*.*
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Program Files (x86)\Sea Monkey\nss3.dll
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\*.*
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\*.*
C:\Users\Seven01\AppData\Local\Chromium\User Data\*.*
C:\Users\Seven01\AppData\Roaming\Apple Computer\Preferences\keychain.plist
C:\Users\Seven01\AppData\Roaming\Opera\Opera\wand.dat
C:\Users\Seven01\AppData\Roaming\Opera\Opera7\profile\wand.dat
C:\Users\Seven01\AppData\Roaming\Opera\*.*
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Windows\Temp
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Windows\Temp\Cab4CFD.tmp
C:\Windows\Temp\Tar4CFE.tmp
C:\Windows\System32\Cab4CFD.tmp
C:\Windows\Temp\
C:\Users\Seven01\AppData\Roaming\Mozilla\Profiles
C:\Users\Seven01\AppData\Roaming\Thunderbird\Profiles
C:\Program Files (x86)\Mozilla Thunderbird
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{31EC9AD6-5786-45DA-B15D-2E72FE116045}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{52DB1739-8CA0-4C99-9EE7-FE81B5E5749E}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{B6C15F72-0649-41DF-9EB7-057A27B89428}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\new\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\new\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Stationery\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Stationery\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.*
C:\Users\Seven01\AppData\Local\Temp\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Cookies\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Cookies\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\History.IE5\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\History.IE5\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\4DXYBRDC\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\4DXYBRDC\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\K0BMY8DM\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\K0BMY8DM\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\NSXL8QLO\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\NSXL8QLO\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\PAJSDO3I\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\PAJSDO3I\*.*
C:\Users\Seven01\AppData\Local\Temp\hsperfdata_Seven01\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\hsperfdata_Seven01\*.*
C:\Users\Seven01\AppData\Local\Temp\Low\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\Low\*.*
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x64 Redistributable Setup_10.0.40219\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x64 Redistributable Setup_10.0.40219\*.*
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x86 Redistributable Setup_10.0.40219\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x86 Redistributable Setup_10.0.40219\*.*
C:\Users\Seven01\AppData\Local\Temp\outlook logging\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\outlook logging\*.*
C:\Users\Seven01\AppData\Local\Temp\VBE\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\VBE\*.*
C:\Users\Seven01\AppData\Local\Temp\WPDNSE\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\WPDNSE\*.*

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.exe.config
C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\System32\tzres.dll
C:\Windows\System32\it-IT\tzres.dll.mui
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe.Config
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
C:\Users\Seven01\AppData\Local\Temp\tmp333B.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp22CC.tmp
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
\??\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
\??\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
\??\{E43D242B-9EAB-4626-A952-46649FBB939A}
\??\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
\??\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
\??\{9A399D81-2EAD-4F23-BCDD-637FC13DCD51}
\??\{5BF54C7E-91DA-457D-80BF-333677D7E316}
\??\{C2D43895-0262-4873-A789-C2F96D24B693}
\??\{2CAA64ED-BAA3-4473-B637-DEC65A14C8AA}
\??\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
\??\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
\??\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
\??\{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.cfg
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Windows\Temp\Cab4CFD.tmp
C:\Windows\Temp\Tar4CFE.tmp
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{31EC9AD6-5786-45DA-B15D-2E72FE116045}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{52DB1739-8CA0-4C99-9EE7-FE81B5E5749E}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{B6C15F72-0649-41DF-9EB7-057A27B89428}.oeaccount

Write Files

C:\BVTBin\Tests\installpackage\csilogfile.log
C:\Users\Seven01\AppData\Local\Temp\6e63d0cd-7568-4439-ce55-2639c6f48572
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
C:\Users\Seven01\AppData\Local\Temp\tmp333B.tmp
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Windows\Temp\Cab4CFD.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp22CC.tmp

Delete Files

C:\Users\Seven01\AppData\Local\Temp\Quotation_Sheet_RFQ180724doc.exe:Zone.Identifier
C:\Users\Seven01\AppData\Local\Temp\tmp333B.tmp
C:\Windows\Temp\Cab4CFD.tmp
C:\Windows\Temp\Tar4CFE.tmp

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Quotation_Sheet_RFQ180724doc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Quotation_Sheet_RFQ180724doc.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Quotation_Sheet_RFQ180724doc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Quotation_Sheet_RFQ180724doc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\FileDirectory
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\Quotation_Sheet_RFQ180724doc.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\737643C2
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_CURRENT_USER\
HKEY_CURRENT_USER\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\client
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegAsm.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_CURRENT_USER\Software\Classes\AppID\RegAsm.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1DF4D951
HKEY_CLASSES_ROOT\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Windows|Microsoft.NET|Framework|v4.0.30319|RegAsm.exe.Config
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Windows|Microsoft.NET|Framework|v4.0.30319|RegAsm.exe.Config
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Windows|Microsoft.NET|Framework|v4.0.30319|RegAsm.exe.Config
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{E43D242B-9EAB-4626-A952-46649FBB939A}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANBH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIPV6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}\00000006
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Pnp\{71d10298-bdb9-4dcd-a87a-eec6137ab254}\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{8c7ed206-3f8a-4827-b3ab-ae9e1faefc6c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\SW#{eeab7790-c514-11d1-b42b-00805fc1270e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\SYSTEM\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{afd97640-86a3-4210-b67c-289c41aabe55}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\BTH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0001\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0001\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Properties\{afd97640-86a3-4210-b67c-289c41aabe55}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Driver
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{E43D242B-9EAB-4626-A952-46649FBB939A}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanIpv6
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanBh
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanIp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\EnableDHCP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableSecurityFilters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\TCPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\UDPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RawIPAllowedProtocols
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}\NetbiosOptions
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netbt\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableLMHOSTS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DatabasePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseZeroBroadcast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpAlwaysSourceRoute
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpUseEtherSNAP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableDeadGWDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUBHDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUDiscovery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ForwardBufferMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\IGMPLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MTU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\NumForwardPackets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxConnectRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxDataRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpNumConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpUseRFC1122UrgentPointer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpWindowSize
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\EnableDHCP
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\seamonkey.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ObjectName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Escalation
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F8B50CC5
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerSAU
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\LastUpdateCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\CheckFrequency
HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine
HKEY_LOCAL_MACHINE\Software\Classes\Software\Qualcomm\Eudora\CommandLine\current
HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Thunderbird
HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts
HKEY_CURRENT_USER\Software\Google\Google Desktop\Mailboxes
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
HKEY_CURRENT_USER\Identities
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Username
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Internet Account Manager\Accounts
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles
HKEY_CURRENT_USER\Software\IncrediMail\Identities
HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities
HKEY_LOCAL_MACHINE\Software\Group Mail
HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger
HKEY_CURRENT_USER\Software\Microsoft\MessengerService
HKEY_CURRENT_USER\Software\Yahoo\Pager
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL
HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\737643C2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_CURRENT_USER\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1DF4D951
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\SYSTEM\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0001\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0001\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0001\Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{018EF085-908F-46CA-8357-98B8AA524ECC}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07298156-A2CE-4DF8-98CE-B3AFB139FC44}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{CE94B10A-8AE6-4D46-953E-ADEBB7DBF4B9}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E69B5212-F3F3-4458-926F-95CEF7E298B5}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\EnableDHCP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableSecurityFilters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\TCPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\UDPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RawIPAllowedProtocols
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}\NetbiosOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableLMHOSTS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DatabasePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseZeroBroadcast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpAlwaysSourceRoute
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpUseEtherSNAP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableDeadGWDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUBHDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUDiscovery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ForwardBufferMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\IGMPLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MTU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\NumForwardPackets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxConnectRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxDataRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpNumConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpUseRFC1122UrgentPointer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpWindowSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\EnableDHCP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ObjectName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F8B50CC5
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Username
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Quotation_Sheet_RFQ180724doc_RASAPI32\FileDirectory
HKEY_CURRENT_USER\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\LastUpdateCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\CheckFrequency

Delete Keys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyHwIdKey

Mutexes

DBWinMutex
23039624-125f-4847-bcbe-5e6c8cbb7995

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
clr.dll.SetRuntimeInfo
clr.dll._CorExeMain
mscoree.dll.CreateConfigStream
mscoreei.dll.CreateConfigStream
kernel32.dll.GetNumaHighestNodeNumber
kernel32.dll.GetSystemWindowsDirectoryW
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddSIDToBoundaryDescriptor
kernel32.dll.CreateBoundaryDescriptorW
kernel32.dll.CreatePrivateNamespaceW
kernel32.dll.OpenPrivateNamespaceW
kernel32.dll.DeleteBoundaryDescriptor
kernel32.dll.WerRegisterRuntimeExceptionModule
kernel32.dll.RaiseException
mscoree.dll.#24
mscoreei.dll.#24
ntdll.dll.NtSetSystemInformation
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.GetNativeSystemInfo
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
clrjit.dll.sxsJitStartup
clrjit.dll.getJit
kernel32.dll.GetFullPathNameW
kernel32.dll.VirtualProtect
kernel32.dll.LCIDToLocaleName
kernel32.dll.LocaleNameToLCID
kernel32.dll.GetUserPreferredUILanguages
nlssorting.dll.SortGetHandle
nlssorting.dll.SortCloseHandle
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
kernel32.dll.CompareStringOrdinal
kernel32.dll.SetThreadErrorMode
kernel32.dll.GetFileAttributesExW
kernel32.dll.ResolveLocaleName
kernel32.dll.CreateFileW
kernel32.dll.CloseHandle
kernel32.dll.GetFileType
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.GetCurrentProcess
kernel32.dll.CreateEventW
kernel32.dll.QueryPerformanceFrequency
kernel32.dll.QueryPerformanceCounter
rasapi32.dll.RasEnumConnectionsW
ole32.dll.CoTaskMemAlloc
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ole32.dll.CoTaskMemFree
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpCloseHandle
winhttp.dll.WinHttpSetTimeouts
kernel32.dll.LocalFree
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.GetEnvironmentVariableW
clr.dll.CreateAssemblyNameObject
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
clr.dll.CreateAssemblyEnum
oleaut32.dll.SysAllocStringLen
oleaut32.dll.SysFreeString
kernel32.dll.RtlZeroMemory
oleaut32.dll.SysStringLen
advapi32.dll.SystemFunction041
cryptbase.dll.SystemFunction001
cryptbase.dll.SystemFunction002
cryptbase.dll.SystemFunction003
cryptbase.dll.SystemFunction004
cryptbase.dll.SystemFunction005
cryptbase.dll.SystemFunction028
cryptbase.dll.SystemFunction029
cryptbase.dll.SystemFunction034
cryptbase.dll.SystemFunction040
cryptbase.dll.SystemFunction041
kernel32.dll.SetEvent
kernel32.dll.ResetEvent
kernel32.dll.GetTimeZoneInformation
kernel32.dll.GetDynamicTimeZoneInformation
shell32.dll.SHGetFolderPathW
kernel32.dll.GetFileMUIPath
kernel32.dll.LoadLibraryExW
kernel32.dll.FreeLibrary
user32.dll.LoadStringW
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
kernel32.dll.LocalAlloc
ws2_32.dll.GetAddrInfoW
ws2_32.dll.freeaddrinfo
kernel32.dll.DeleteFileW
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
gdiplus.dll.GdiplusStartup
kernel32.dll.IsProcessorFeaturePresent
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipLoadImageFromStream
windowscodecs.dll.DllGetClassObject
kernel32.dll.WerRegisterMemoryBlock
gdiplus.dll.GdipImageForceValidation
gdiplus.dll.GdipGetImageType
gdiplus.dll.GdipGetImageRawFormat
gdiplus.dll.GdipGetImageWidth
gdiplus.dll.GdipGetImageHeight
gdiplus.dll.GdipGetImageEncodersSize
gdiplus.dll.GdipGetImageEncoders
gdiplus.dll.GdipSaveImageToStream
gdiplus.dll.GdipCreateBitmapFromStream
gdiplus.dll.GdipBitmapLockBits
gdiplus.dll.GdipBitmapUnlockBits
gdiplus.dll.GdipDisposeImage
cryptsp.dll.CryptGetDefaultProviderW
cryptsp.dll.CryptCreateHash
bcrypt.dll.BCryptGetFipsAlgorithmMode
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
advapi32.dll.RegSetValueExW
ole32.dll.CoCreateGuid
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.CreateProcessA
kernel32.dll.WideCharToMultiByte
kernel32.dll.GetThreadContext
kernel32.dll.ReadProcessMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.WriteProcessMemory
kernel32.dll.SetThreadContext
kernel32.dll.ResumeThread
advapi32.dll.EventUnregister
rpcrt4.dll.RpcBindingFree
cryptsp.dll.CryptReleaseContext
ole32.dll.CoUninitialize
oleaut32.dll.#500
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
kernel32.dll.LoadLibraryW
kernel32.dll.EnumResourceTypesW
kernel32.dll.EnumResourceNamesW
kernel32.dll.GetModuleFileNameW
kernel32.dll.FindResourceW
kernel32.dll.SizeofResource
kernel32.dll.LoadResource
kernel32.dll.LockResource
kernel32.dll.ReleaseMutex
kernel32.dll.CreateMutexW
kernel32.dll.GetTempPathW
kernel32.dll.GetComputerNameW
ole32.dll.CoWaitForMultipleHandles
ole32.dll.IIDFromString
ole32.dll.CoCreateFreeThreadedMarshaler
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.LoadLibraryA
kernel32.dll.GetProcAddress
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.GetSystemDefaultLocaleName
oleaut32.dll.#283
oleaut32.dll.#284
oleaut32.dll.#9
oleaut32.dll.#149
oleaut32.dll.GetErrorInfo
oleaut32.dll.SysStringByteLen
kernel32.dll.WriteFile
kernel32.dll.GetModuleHandleW
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
kernel32.dll.GetCurrentThread
kernel32.dll.DuplicateHandle
kernel32.dll.GetCurrentThreadId
user32.dll.CallWindowProcW
user32.dll.RegisterWindowMessageW
dwmapi.dll.DwmIsCompositionEnabled
kernel32.dll.GetTempFileNameW
kernel32.dll.CreateProcessW
ntdll.dll.NtUnmapViewOfSection
oleaut32.dll.#200
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
ole32.dll.StringFromCLSID
oleaut32.dll.#4
oleaut32.dll.#7
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CreateStreamOnHGlobal
advapi32.dll.RegCreateKeyExW
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#289
advapi32.dll.RegOpenKeyW
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#290
oleaut32.dll.#285
wmi.dll.WmiQueryAllDataW
wmi.dll.WmiQuerySingleInstanceW
wmi.dll.WmiSetSingleItemW
wmi.dll.WmiSetSingleInstanceW
wmi.dll.WmiExecuteMethodW
wmi.dll.WmiNotificationRegistrationW
wmi.dll.WmiMofEnumerateResourcesW
wmi.dll.WmiFileHandleToInstanceNameW
wmi.dll.WmiDevInstToInstanceNameW
wmi.dll.WmiQueryGuidInformation
wmi.dll.WmiOpenBlock
wmi.dll.WmiCloseBlock
wmi.dll.WmiFreeBuffer
wmi.dll.WmiEnumerateGuids
oleaut32.dll.#286
iphlpapi.dll.GetIpForwardTable2
iphlpapi.dll.ConvertLengthToIpv4Mask
iphlpapi.dll.FreeMibTable
advapi32.dll.RegEnumKeyW
iphlpapi.dll.GetAdapterIndex
oleaut32.dll.#15
oleaut32.dll.#26
oleaut32.dll.#16
dnsapi.dll.DnsQueryConfigAllocEx
iphlpapi.dll.GetCurrentThreadCompartmentId
dnsapi.dll.DnsFreeConfigStructure
dnsapi.dll.DnsQueryConfigDword
comctl32.dll.InitCommonControlsEx
shell32.dll.SHGetSpecialFolderPathW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptHashData
advapi32.dll.CryptDestroyHash
cryptsp.dll.CryptAcquireContextA
advapi32.dll.CredReadA
advapi32.dll.CredFree
advapi32.dll.CredDeleteA
advapi32.dll.CredEnumerateA
advapi32.dll.CredEnumerateW
pstorec.dll.PStoreCreateInstance
vaultcli.dll.VaultOpenVault
vaultcli.dll.VaultCloseVault
vaultcli.dll.VaultEnumerateItems
vaultcli.dll.VaultFree
vaultcli.dll.VaultGetInformation
vaultcli.dll.VaultGetItem
psapi.dll.EnumProcesses
kernel32.dll.QueryFullProcessImageNameW
kernel32.dll.GetProcessTimes
rpcrt4.dll.NdrAsyncClientCall
rpcrt4.dll.RpcAsyncCompleteCall
advapi32.dll.RegDeleteTreeA
advapi32.dll.RegDeleteTreeW
winhttp.dll.WinHttpSendRequest
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpQueryDataAvailable
ws2_32.dll.#22
winhttp.dll.WinHttpReadData
ws2_32.dll.#3
cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo
setupapi.dll.SetupIterateCabinetW
cabinet.dll.#20
cabinet.dll.#22
cabinet.dll.#23
sechost.dll.QueryServiceConfigA
rpcrt4.dll.RpcStringBindingComposeA
rpcrt4.dll.RpcBindingFromStringBindingA
rpcrt4.dll.RpcEpResolveBinding
rpcrt4.dll.RpcStringFreeA
rpcrt4.dll.NdrClientCall2
bcryptprimitives.dll.GetHashInterface
crypt32.dll.CertVerifyCertificateChainPolicy
crypt32.dll.CertFreeCertificateChain
crypt32.dll.CertDuplicateCertificateContext
crypt32.dll.CertFreeCertificateContext
ncrypt.dll.SslDecrementProviderReferenceCount
ncrypt.dll.SslFreeObject
shell32.dll.SHGetSpecialFolderPathA
crypt32.dll.CryptUnprotectData

Execute Commands

"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /stext "C:\Users\Seven01\AppData\Local\Temp\tmp333B.tmp"
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /stext "C:\Users\Seven01\AppData\Local\Temp\tmp22CC.tmp"
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\system32\lsass.exe

Started Services

VaultSvc

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04b_64 Seven04b_64 VirtualBox 2018-07-24 16:24:25 2018-07-24 16:27:21 176

1 HTTP Request(s) detected

http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • Hostname: www.download.windowsupdate.com
  • IP Address: 92.122.125.155
  • Port: 80
  • Count: 1

GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 109200
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com

Detected family: #Ispy

TheSystem Itself @ 2018-07-24 16:36:04