MalScore
100/100
MalFamily
Razy

ORDUS.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 25/67 Related 2805
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 1046.50 KB (1071616 bytes)
Compile time: 2018-05-10 00:57:59
MD5: 4473e4e0aacd251550f9fb5d3498d34a
SHA1: 9cc67a14f26fd92c475025b9f4c8e6beafd135d6
SHA256: d9c34b04ae4d1c73880710628dbacd497787b319d59b4b909ba51442b409806f
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-05-10 11:54:09
Last submission: 2018-05-10 11:57:08
Filename detected: - ORDER-SCMB1050.exe (1)
- ORDUS.exe (1)
URL file hosting
hXXp://qualityoflife-lb.com/RED/ORDER-SCMB1050.exeVirusTotal
hXXp://qualityoflife-lb.com/RED/ORDUS.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-05-10 08:07:16 [25/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xd59a4 875008 aa6d0640a61b36ec0b51850c2d225515 dca5045ed9f7c9027ab72efc527d807444ccc7a0
.rsrc 0xd8000 0x2fa60 195584 e17f46235fc97764380ff6a6a098113e c50f7814949583660b3afa3fe725163f784613c9
.reloc 0x108000 0xc 512 fd88c7a7dc04efe6b97c6e9bca0666e8 1b627b4ae150eeb1c0b4b949db931b1fb093b3f7
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x107344 1128 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x1077ac 118 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x107824 572 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: ORDUS.exe
FileVersion: 0.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: ORDUS.exe
ProductVersion: 0.0.0.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
String too long
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
g6RdSeisfEQfjgNil5rp6QK1Ragv5duXtvEW
tF08WVm2B9olixCmFImCwJHWfpJZCG
OriginalFilename
OLVP1mHPk1I2JGCW5wnhNrTjz
FGFN30qBZ06WjbLfHVp5qOmVy4DWUcI8NUePF
InternalName
2O90AD7AzvN3JB03IEHkQNtD7lkzx3GbHOfmpu2
fqA8FzCcqxD7CYawxvWZsdeJFasY8wkuNEp7vz9
Cb4RjdsLJSdG6xBnlpgd1xWCJquX1c
Translation
htf8aZf8DujhzWON0RPYckfEYwikO2Gfc
cLWm406Ru4UR8DPL50W7C2VOkjLW
Bvk6uahS80SKN27drz7bQ5TOU6KVskrk1hVH9
wGz8WSFYoLt5HnvR1Qs2
RDuWu3EqAPLsLRiNEBNtIhP09WXBn8XHUCg9Sa
llZ8ip7kXCVW16V8PQDuWbCfbgLePfd2AEuB
LegalCopyright
deb1dyC3POneu5yFxO2zQKv6VWTvHXx
GWaV5palDzPhSOXfVjSZ7FCTxKqRV0WdRL
AaKC8Lb0qXsR6kn1nn8P27P
GiT8BuHWxGg9GF3pyv2yYV
bFSPUysaVJp9tdhFtDrEfRIK7yO0cI
Kfp7mtdVm5bbABJQMcDjoLslWQ3e
mXWe3KpfIImO3yO5LoMxXLDel7zyEUt5F4D80K
V3eJA5lpYIX8Zdm2pwQBGr6Tb7n
VarFileInfo
ckWS4L1jTukgXjUHQdYUrnoT
bhK1HOiUqwF3BIfSd2P0iLNobWA6hc9Ev
UP02fkQLIzoPMyqjlnJxo5jRx2saS3Qip6Z
YuVoqG6EHHb9grq6o84x6c1zkxuM5HGX
oIFzQVblFwy9z8HriVL3OGQORf8skGwaIen
QgoPWYQAEs3vtV2Xplaui8mqp5VfA1fhj
TzDnbjLKa4YRBoGBeloPwkeUW9MBfSnVVw6vYCQ
ADj1TXgts1OUsN6z82FSlvOxzju
lhVoamtFF01j3sNLDSckx5aJ
yN1eG7cYkfOBEZ4gIR1cjXYFrHE53
Ny6nEDeq8rCukSukVAh6RHSXuqsp7CCUyo
zqx5QYPFYt1b4zWBQtN4
4eXqpv94zru0dZswMwrikG91PUH
qStbnbBugUI0YrGW6GrLjwmafE
8mRMN4NjHjBjBoOJ1mMVUc8inhCL
7QRQOPMRiYUnsfPxnrnzaMLvDd6gq
WdhzcPWZaHfv7bNQyidve
HTTn5qiSNLn0nWZLAn4IkS2W5LUP40m09r45oL
qYxn0xBVs2zQKzxASl7ToqA93r
Jp4CvYe5QZRo5RVaxQb0sthTGd
kz3ipDcntGaTcnHgjLahNkITx0LY7OlFUI
l9w1Z8saPiJShmnSBdZXqhUvPNMOC2btzj2Qr
ProductVersion
TQzvOPqZxTbUUUqgaLKA
WYLhHSkcKCq7EPmQqggY1NsFNEcdqo
Ao07fT5vDjC4nHaIkXRXWPud1gexY2irME
SHoQl9PCPz4VGQYVM7DwpWEJCpxZe7m
wXdChmsp0MiVyFeYNWInxSEfsR0zg
uUEq0zOiVpBImhItRb2kc2js
e28i9QMhTwkczfcSL8pUG39syoJMrqA9
ugOzg98TQ0oPQlRLNPuodukuuY3vzePm1jnXg
AemfVtm5gW5d9XUY4S75Jb
knBRwFnnWcgxF0vS1zh0Z8gOkpy7FXcoACZCoU
i1Juytoibs7HULH62rEGkJoDnKXSZ9I7Owt
ofklnuQGDFcfX3nhAcFbw5cK
Q1mIcmv77tFKmSqIsAzzPWMoQU
NrwmOn2FWhbb8i9u77g38a1iWx9kt
Hwm2BGJJoMMnKslExG8B6xoky4eft5CfG
kxkytw0eLkXAsVU0hD4bl71Xgon
Assembly Version
0RU
QkYgNvqK74tXyFBeW11YQ
RxORRAZ8vuWDcQznNVbdS3xGQ6pVhuQ0
4a6lnamwSmdyZB4RTvT71Zkl1pVw
A22U3JevoYIX2X0cGXQMythl4z3SfXc
uhe3QFKYcbkU9B0DX8RsWD3I5OimWTfZT6ymUb
TBBvrEDQNmYDMSxT5LAPCGyHDI
bzS06TwsKn1WSHCGUgN4joYHG0Y7
hqFFRlVnJq45Ov5JN2NhDLQBChw
dw9s2EH7Xw4bPjtPe1qfb
3Zg8jViBH7ywjud3BeR4TcIcQk6IsLv
RRQJBxMOzkf7HHGduoOM8VL
WzXNnfNfpKNRKLDKSSyQodZ4M6RwNs7p7
Q8iS6dFg93qYpx3nfrjEGoHDDMrH6
N15dMiqM0yOIZiNJi9RCUYD1wpt
mpEHLUoj7peh4utzqQklLx2iP3SEDdr
sJeINzuBku6G0l2JW2J3r
Qse7gNS5q1JJIRMPsS09Lo77loLuBvD
VS_VERSION_INFO
r35EfEWGAucGnpbN8nTQYtLDxUDnGquZ
StringFileInfo
54DWcQOpzztzuTMQsM1GFlArPhq0VplFSYMtz6T
qvjmK98GsgeQkgyjV5w689o3BN0Y9dTWlZz0
FileVersion
oGrYSJPCevvnWaZBF3S6KZ3Pn4Jz9s4p5
TDylLdvT9n6ezyrsKinY5SMXwER49JAtq
8uWVENzBNnvSjsffYEfRitSdBsw89pWeA
HWdZz7p6EMriIvG8g4FexqtI
000004b0
ORDUS.exe
FileDescription
0.0.0.0
QtWAHbr69ai23hqpImwifXRJTGs48fmSO
WEcpNoUtE0MGrXDGG97E
RPyxvf8XLReUmTkgUrqcbqMkftGuzTi
QUBx6zcTMFe632U2HxGlY
GhqdPDxcmQTC9qVw73xR3eb9rZolAdGg
2ogG8XAoCoEaA4wCuUR5eV5vQ6m1hGzF
hiPisHv7eh5YJLH6u84u5KhZDASBVQpbnKZC
CaN3eOPmUpEwjhy73S3j
&J]y4
}Yiy
wk{\
OW k
OAT |
{ 'b+
"<&?>
#_iH!oThw
Bq#N
O 7+V
) s,o
PNG
@rxm
T/.Xt
e]'p
gH5Xp
0!za#1U
pkxk
T|JnprH
ulP"
yQD{)
REM3
8{zdF
N MH
v{b8
cq(l
a6o>
{bLHe7
7HV>p
@ x&W
k,GP
3TE7
>{=i
" `FWV
UnverifiableCodeAttribute
y]ZL
8U6#
C.0
E~&eq6
I2 b
fSX\3
b:::
CRpR
i' `r
Bl!.
Y OZ
ZXn=
|J\7
>z,J
5"-R
gX#k
B!'f
#S0lN?c
&+~JZrG
2HT7H
) `
avano?
o A7
dNbt
j$wJ
,YH
l|~N
,Q 9c7
pUy)Y
!I9$
>8!p
Dg!
5oc}e
f]U]i
]4"p
'tpE
YOBk
8{Z3
CiUz
heyu
z |l
#'<!
0v0h
p_G]
DDos
bmH,/
= YY
P`9'
+<aH"
_~FV
_Wmu>
O\S
dk\I
/NY2
kp U
VVV5UUU
cUHD!+8r
j!%
m$;J
Z9w
0^g`
0Q ;
?q>S
_c("
9888aY
wdr
!,@c
lX|]
L(x8b
BZd;.
FdZ"s
$O-=
ZdvaR
yMt^+
Xh%u
b.''a>
tiL=
*BuF
`p?j
5N!4
yvV'!'PY
pD{o#
M W}
|| @Sy
? ^HY
fXE,6v
jHF=
HJz2_
Ean4
VY Q
Pq`*w\
M}ed
@~bq0'G
[CCs
"L-0Bd
:x{E
#[sF
GH?L
Bq+o>
VCnH<
{T+2
r\Fq
S>c&
zn;v
mi2h
p7pN
hvW49W<>
i1R.
.*zE
(nERH
ka2=v
YH.e
Mh@:;OB~!Q
9]T~
k$)sD
? 7 0 (
1CSFfn
B=@R-
_1>F
@YX#
t=$!
NPER
:H#C
u{9eghJdt9
L|@
PQvq
J `,
<J[g
N/iw
l&Y{
?7G WCw\ba
E\gH;
+r2O
Sn$,
RRR%PPP
Ygg%UUU
I;H#|b
0uK^F
(i x
8UDJg
`7[C
F4Uf"
ft})
=RG_
w`Fx
&^t1kFu
#!w`
:NI,
=3,S
=(\jLk9
4q?,r
fKb2B
@ZJqO
MU.9
G( RH
a&G[
I6;z
kD9i(
<<<R===
|Xv\
V`jM
AZ[x"SliS q
Q5tmK
y28 IB
rkbm
Je& y
QFRB>,
]7 `
n;F'
.`K
QV0y
&lx_|T-y0In
W'l/2
N<xF
vw3M
r Y U
,5xt
`+`uIF$
Mg%S
zPbw
OuBa
9?Oz
cndi
_x I
&Oxw
ZtI+/X
dq$9&
Dy6IV
k}Un
kJWH0
HYL%
m}8L!
:<kl
PG ChL
Q}):w
EebOQ=
A>1no3
RI;3
X^ t
N<'C
?t`IA
f0C J[
vv~P)
N0(k3
eYhY{V`
]${W
ws k
-rwe
F)f-Z[
>5;z
W=5F
?4~6I
,^/.
WEd'o
[6x!
&<]_g
Mcqg
in
1|Bu
7#29
JC+@
&0Zs
4XVb
DateTime
6E ]
wHj-
`xvQ
?Ww k<
h,>3
0+tx
r?2)
].RI
@Y 9
I{fk
.
tc[uGr
HI^$
- <B
yqY't5
a V|`t
CmFr
Hpe{
%L_l
{Dm
Y$t j
<Q]/3
9":h
;SC2
fTWCS
"=6"
] fddd
B?~b
.x-
-y 5
AF`l
D#"/
t~6
u,$Z
0 ~
Nq:l/
Q<gyo'
#.k'c
/av
QC$ i
C"
6[/ =
?}wX
>><h
Vve
'8u0
$w#gWI
x 6H
#~-_P:
g|#g
@+N &u
)PhA?
+:Gq
sAido0
&; Z
D44+=\
w&6
CH#:Q
#!A+
Tq~,
OKm
818~EUm
tTF`B
Et|
!QgoPWYQAEs3vtV2Xplaui8mqp5VfA1fhj
c:l=0
,3r|
CGu/
f'f7
^ ad`
$ *e}
`$6}zUR
o5F_
;,vl
;cA
6{ I
EVtt }
5Er7>@
qd%R
vn6k
RGzq-}u
X$_6
/aH0
mx[PK
cjhM
5Z#}
e3Jo
/MD:
4B>I/::
Zetm
K6 '
:! Sl
,+J*
`zdG
.21q
oq3N
AuR
qch0e
#mOK
?,ToE
k?t~
bbb fff
Q`/S
cQlja
.text
~h,U
gp\_
2 S>Q`q
#ZS|
ILM27
&bq.
GetObject
Yj K
10~
,#A`
<hls
^+jQ
`oBH
t...
t#7]
0J[w
h!95f
Nd=l*x
D<(!W(p
-$M%Q
$Q@1
@'AM
]V I
h*~K!
+g}b;Z
c#&m6L
DBH@
op!#
, `G
=x]|(
B *I
?* T
Eg}~
&3w#
"ZJb1
nM,R
u*nW
<iuc
.<hY
A###2***$:::
;1)Sl=
utJOF
{ZN$
d-u(
D@cGc
_]`|
y` Q
U9K\
?$"G$#
cei4
>>>&===h;;;
@k0
[>a`
PoKqmT
<_12
uytg
,(w4
B8vC^
zN
Iq U
H C&k
WV`7
*fs$)}
J{ M
%%%-###r###
;clF8d
Z}<h
O}k#
UO-t
3w`r
n`7V
:G9a}
~5 -
5)HP^
Lq?'
nI]l
~hA/
4n2ly5
L]Ys0
kFU#2
N!fq
.UK$
=@l;
cb|{$
j$={
bh!O
]s
TgTO(
z s
7gp9'
xi,t
W&8f:
\&lk
RH7p#w
;c$7
>.SVR
@PUl
Fs3=
V:(
z&ad
7Emm
,.h2G
zJ.W
9 @#
A Oy
v8`S
9"D&^SVs
<tVf
4Ad|
e9(Y
_f]%
x:|=
3^f'r}B
Ri"SBr
TxUIq
gEZu
nq,c
|A9
*),%
_n l,L
8SSS
~'a=&
h-FP
T|$,
m[X'
p kFw
G"C\@
x5 Z
7)&G
7QRQOPMRiYUnsfPxnrnzaMLvDd6gq
y s$
5N8,gA Qzp
lnAibf
,wEZ0
>2=K
MiDl
lUaV
@CW_}
@LKX
TYBk
/O uZ
C &t<R/
|/%6
U\x-=B
8 3+
3n 4
,zzz
OiDf
o#J;
^Og
0k=-
^+RF
lU{w
kUeY
xqeI
[ 3Yw
lT%p
}YI@
J[7C>|
^ke>
c V+Q
!EO%
,Eg1X/
Po/ZN
fyI"
}&5t
b]_j
{(3
up6^
s2cN
CCC
+LRk
@@@v
BK2
<l"oN
Cb4RjdsLJSdG6xBnlpgd1xWCJquX1c
`TQ\I
^S^&
G0Y$
#-H
*71<
n9.m
g+pp
B#XV
b<=8
t3eAM
\UNs
@:V:]S
\pSk
P@oo
|r]0R Mha
kIg!
yK+TKa
=P bZ
7ULO
i%i'^
PPPr
*,og(
|U$;
{s2?
Kmc$
Yo\k
7zxj
4<=Q
o=@>j
[;w$r
)J3KS
9-6Hc8
"(z-
WZ=J
2HnD
fk_%
Gz]j
s4I1
qT;.
get_Assembly
jtkn|
/+G5
zPXiYG
`"<?
< Dv!
uP1h
8wxk
$llZ8ip7kXCVW16V8PQDuWbCfbgLePfd2AEuB
T"J1
#o3
+6`]9
DmW *4
1FY&
xJ}F
K0;
lk/u
z6zt;
ZqF/fk
2
k^E[
fTXY"TesEhL?
e"<u
xQ@&
Yw>jH_
d4`
7d~
'Vw0
YB,
Oq7a
mpEHLUoj7peh4utzqQklLx2iP3SEDdr
/t7GVt
bR$F
oRks
o*Hf7
_`)a
=zT[
x?cq
8g-
k7>8q
uY_o
~Ex@%4|.
H8(:
A<n42
'huv
.#S
|PaG
-RpL
hdhp'
' >
T iP
w2,7
`|/F
/dqn
oGWk
sHi0
}Z\h
L8M
XIgm
l447R
b*71
N::rL
drYh7
f2\S)Xas
/4 2
"%6.
$94CfQl
b$9"
ZA*b
*j$=D
IkQr
~7%8^
LNh/a
0Ut.F3
_ |f[
X/tj
xOZy
@Dar
d[)R
9h94AUf+
zJfm
DtB~ Y
X)O=T@
06}'Y
jlQ2Mi'
dv[=
AF0Bq%
System
1Ld!
O2U
%Q,CR x
BZ/,
QuF
>=N
Di5K}ns
6a k
GiT8BuHWxGg9GF3pyv2yYV
yR!o4
(tkZ-9
kPX-
11S:Ke5
yN1eG7cYkfOBEZ4gIR1cjXYFrHE53
e)&:>?
F(R&
^d\ni
om+1O
f83}
>pB ;
Yu!V
;$bfQo9
EN1
FL5A
s1X)
/T.z
qStbnbBugUI0YrGW6GrLjwmafE
c`gCv
b$Bv
/oP.IhTB
aR I`5
NNN9
/m\[r
wc75
MT&
HX 2[
( U
+OSD
5zTY
:6aR
9 S{
it`ag
>DyQ^
riGkr
4:S^
_)~$>
&mXWe3KpfIImO3yO5LoMxXLDel7zyEUt5F4D80K
r0?f
~8Mm
'S@
u~)Q
YjG$
n07@
h VNV,
2_E|F(I
N+4A
t))\i
hMXMh1
$B4s?q
Xzcz
!1<9
A D?r.
$_9,
yc _
.,Gq
Q^t1
!k?_
`LlS
>;\*
+K
X?G<
Ch{
D+j
&uhe3QFKYcbkU9B0DX8RsWD3I5OimWTfZT6ymUb
@+M-!
JPz1
18>?
lpb9
cG0vE
kB;X
*BTo
\ ` `
vFMr
oWK0
WA l
[@k%
swxm
8Zek
~ ~Oe
j51!
DSF
.*fY^
yOB;)
7r<
I>AQD>
-bl:
[a*!
ID+i
Q:e-
K[HJ9
PEfz
c:wx
hqFFRlVnJq45Ov5JN2NhDLQBChw
iULN
@U C
ac7G
`'{)
n{J&
g_ws
`N#R
5~H*
El`%M
1/ J
CH \
fe>|
.qne
mHgg
H= w}!
< o
J*S)
fs'*
B.3!
'O%`
MyvhK[+Y
n;c9s3
F3E8
r=`1
'O%r
dibZ/6
]bMk
U \JT
2>|p
ef2Ip
`w=q_
"{nF
n|:&
F>=
_2Z3
@ :
H|ZQ
h8j)x
2P %6
4a6lnamwSmdyZB4RTvT71Zkl1pVw
8j92"U
KL5m
&3ud
_CorExeMain
g {sY
|{6]
]Zll
EW*i
t`F_
PIzy
9996777x555
9dGy
9 u p{$
n1yE
F u$
l3hL
~t&6>^
<: F
mMR8k
=P4wK5V
|1k
e>`%
o.Gz
~!A\{
.C4u
& [
_Rm1
;
(]Ey
3:\3 -Q
ck ?
ju(r=
}tf^Qo
|u2Z
@.reloc
4j )
|<yp
7_Db
sxl3
`bp%64
a"8^
T|^@
5/?h
+ZlQ
otp)*TU
%u][
?M4y
'*)HVHL
% ;@-
u)4kQ
@(x
oq+1
$RJG
}z#|
&PH
:\{Oj
a, Rm
^Q(!
]3P0
9!7
M1~3
>Q4P
,$r
Yb5
1v\ :
N'Bfj
~8nn
RpfK
6KK
LNk$xsov
YAo
D:zg8
:|PP
xpd)
2Jy)
Rgy5i
B <l6
x64!
|\/s
^^^kIII
/y6C
N}(y
^\az
L l>
3UE#
hcb.D
]7Qp*
4 )A
z H_8
aBBiQ
|chN
j5VC~
ecv#
/wu$O
"]osg
eL$8
$x
R y\
;-ok
03v|

bh'F
&qjK
AO+A
+TS!C
$ Dk{
KeHx
/822
l1 mE
o3?#4
A`6!
H J ;nE
E;'&<
R3_[9
%&K5J
We2xu<g
zP]t
"4/@n
*>2k~
5_qt}
<n #
R<vl
JblXd
&=Z4
`/ C0
hQ3=7
C_& qUcm
ozT
Utn,
zqx5QYPFYt1b4zWBQtN4
[5.$B
4z
TaxQ7
RD+/
9hE
LivN\
JCWu
\.'4<
xr]$i
g[q`
l e|
nJ-U|
F d~]Le
L|
crfd
cccbs
DXAx
[ZX#
oWk&
yhA?J@#
XHb7
5n@D
n&y)
(!rS<
cU2H
H,"!
,6/
J"`\
g7Ny
$(5I
_ZGU
A \~
JX"~
h@X%1
/|Dn
MiZd
)?4D
b#-P
MiZa
NV
tQp
h+6S
2fq,W
\LWY
p3`ud
w=7=
&11Ay
J1j^L
xa'n&4
HFX
,1>_A|b
${MR
G}_~
~;(\
ata4
4vO
N1g8
^S!
gA8L
y%+
9bY$
05,j
~Cr!
cx4
yHm8
a zYN
snh"`~
gDB@
*ak9l
(FYr
@ 83
}N~y
/D>.
I06f
fB1 @
gL%$
9&JQ
6^DG
f.wy
Ep"A
s/=@
p_CT
(Gj1B
4V .
BIZ^
&5D g)
NdYx
6`*R!
vcfhw
zHB}
d`wB
0wV
5c/`
a+5{
xUh}\
^KD]
W #H
.-M]%
C(EJ>
'e-so
mW`Fv
3qPQ,
?q:I
_c3G
]$ p_
'2O90AD7AzvN3JB03IEHkQNtD7lkzx3GbHOfmpu2
2XM.
.7][
}zCfy
8|2QQ
*t ]
H8e:
*mIY
90?e
;-W!
^P(n
! OVx
>7AKg
Zvq6
!7,C
<` ^
5Xx}
gQFxW
..+,
j1sc-
RxORRAZ8vuWDcQznNVbdS3xGQ6pVhuQ0
lvag
2TC*
w U~
p#2
`m24
Pbx:
sV6C
GDIW
? G3
UqVP
t1jg
x\9:
`M3t
qU[+
'.I%4
7FDFo
/NV6<
t _
??`
SNy"Z
65e[
w61\
z&A} *P
R^}6'
->55
l \~|
U6F9D
/Z:
a ~Q
'c 7
h}~
#koP
?U ,
H8i>
uQ&E
SeS\
!%m:hY
+NcKL
/y[=
OG0w>`
Ggg'
v|P)
x<iO
P"
.M=G
uVVV
`b\
`jVV6Q7b
Z Q
3hCB
*5LK
1>b"
8A84%;
{i>k
}M[
TqgS
K^@k
9!|8
OC%T
YqkU
Gn#P
k{e[O
E nc1
1jY7L,=
k- kzGG
iC?5Ue
&q~9l
XH\
%",V
_{UM
,&a,
c>fx
hm6]
g(Zg
4 &
lZ7
.F(mN
mAru
.H~/
=$L _L
|s%
%(r9Mpdgh
wXdChmsp0MiVyFeYNWInxSEfsR0zg
:ag_P`
4- <
sa ;[
|jIY
BAbc&
MxI+)
qr%}
Gpsa
UG[q'i
tn86
aYn*Cnu
ah $
9`jX
x}9
taodC
@yaxbX?Y
Bi2~
>r-R
fVs5ms
*###$
[4oH
qzU_
*[d8\
nk X
h"LU
NbO$
&!U%
Wp>t,
@9*,
>UD<]
5,CF%
J2H]
c!esw
8XPm
h);X
*J9.
fvCn
6`sP
8JqL
+6h-
E:JJU
?y)!?
pU a6`
\+cM
c,6}TP
W}[
Xm?c
]y;?*T
W#qI
p<wA*;
9E%;z
7mlF
uC6}
} uq
Invoke
T4Kkq8
Qse7gNS5q1JJIRMPsS09Lo77loLuBvD
ZiaJH
gT*m
FJ=(
)= Pb 6
/eR
ryJ8
`Y:I
\z/)
T< L>
LG #
DDUo
KKK%BBB
-ZFg
t?~`9
+m%s
sC=f}}I
7[F(
?4bq/lp
H0v1
MP P
{2
ZG|6h
$0T-
0% g
(-d9
P#W#
jQ"'
l$*u
{L/}>
h2Uhu?
VIu
D2K"
)J7A
2Ct
R`@IQ
D;>i
+znf
|=Q[
>bXZy
8Xt~0
:WA>
q So
1S;xT
HDW/U'&
3Z~s
z>-G
3j1Nq
n 3(
uL<d
nOs-
~52&k
|M;T
;_Q=b
\ [6
}n5O
WHc!
}:g)
XC |F
7lb[
X9g
qhc-
rt(S
C.E*
!0_4
i{}{
2! mn
wGz8WSFYoLt5HnvR1Qs2
."[}
:bk0
;w\-G<
y /%
q[ M3
*;6
#u(b{
FdR2
$87UfcI
3_Q~'j
@7C$
t9cH
E0.O
?n(C
hb=c
$UeV
S/ Goe
~~~)
H?
=\
Q$sm
=lAQr/+
EX,pI{
eYwz
A"QB
n)zp
}c`^
|$\m
]B5J
R"#$?
K+e&
qY(Jh
htY
s(}s7
kT2y
XRq"
>0RB/L
<0+Mr
tL R
0sD`
rSZ-V
1O8HP
P_rR
888,
iL/k
JI{J
t - D"n
2OLl
WEhI
UV:F
u,Cu6
&^P=
9jPyO
ZHL|
->P<2
QkJ
a}PI
)z L
d%y5
$,eD
ibrr
%;ob
?.;b
~FRP
54Fy
S8Ex
bS^z
XHU
5~=G`
*[52
(#%%
+BGqDx
f}Qr
dMWGP
jlYd9
u N
^*iYY
]A?Z
|xpr#
JallL8
7;B
WYLhHSkcKCq7EPmQqggY1NsFNEcdqo
RuntimeCompatibilityAttribute
0@:O
4<$R
@Mm[%
S8-Il
M%Kea
2 }c
:'O$zS
q9J2
bsH&
W+
*uL
%q7v
FCCC
8/fTU
]e*#9
S!<4
Y/1/
,wnWl
ZwN6
~m\}*
>/ VP
7\.G
SbXkX
jX,PT
` 3F^
cvvxM
DoeqkCn
k`A4
vxYV
?Vz/E
h.M6
bn+
d}#P
ox-w
7Ql2
4\RnC
'U r:
;5 <
9NZvH6a
A(,r
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
U$=u
UxuS
8bc
CHF4
0,:AV?
M0vw
?wziu
(XU[
^a]C
Cq$'
T*M.
nBtK
.)?K
$^|5
:@>@
!/ Q
ySBi
ZlCN1
.?#h
FM`*
vQ1&
n)V)b
JU=
'CAj2V
&_^'
7{ C
X+/ >
Dt
a[m .
NSivM?
&#VD
Y:6"s5Rl33I``qL;
Q-v3
C@ p
*^}Oh4r
U7Q'
>>>*===l<<<
FDa)9
<kP)
t)! dk
MXX+
NBaM
s%)U
#|$R
$|:S
fB0n
6TEF
<&ye
<k +
:rT
yByV
&B<U
gE^4
V'u/
2NW;
.8%h3
oH[j!
6v"O
1>M2
dAs3
i+Wu0;
nH:$[
krD<
_#ej
y6>5=w
/ @d
BkdZ
o,w&dB
L*9L6)M
xgrf
tE+o(
%$#b! A
*QFg
S@?]RV
N1m0
b5i1
)L O
Tma5
|||"
oG<Mve_8
J1#H
~^ q
5-,~
RbK7
338 <o
P9%i%
Kmoy
A[2t+
W$'_]
yH2w
#d(EY
/ 5~>
04(bXZ
EhJR
$)c%w vwD
VQfg
$x7-fRN
BV\w
}_`p_Y
#Blob
S05g~
MethodBase
o/w2
<%g
#7LPt
V5wx
6HH*
{/mKB
gl'E#6
Q #3*
?_'S
voiG
"A^[k
VYX;
ResourceManager
f/-4jHqx
el7.&T<v
gbPb>
$q93
Jahh
jaC`
GsOD
RF\#`
a7S2
jIY4
J(x7
V3eJA5lpYIX8Zdm2pwQBGr6Tb7n
73a~A
%x T^a
>)SR
eqwH
U\ /
LRc
V![gY
DwV#
P5OY6;0
gpK
/9pO@M
[)Qo#
Z1}*
J~(s
asH V
!-Sox
v.3,:1
Z?oy
Ga"D
e-b(
sOmku
[[ }
A`M#M
8w#9
}yW;
J( C
L`RY^
^uy
qT'G
:eCSB
t a1
)RZG
-`?{
L&G%
@773
0)<'
us/
m7rP
\p I
H)hU0t>
zT*x
(x@2
*_;e
aLbD'
M.De
%4Af[p
M5}g3^ \a
Atuu
7#X]Z
6:NPB
O$,*
|pzK0
PXA~
c(&5^
W!i#6O
el&&
V*_k
g055
k-)7 )im
@e/#
5<sc
#qC
rNB5
A@hdy0
xA1)
e j{(
2 |R
j!H2
3_=q
UPA\
j9kYs!7
2a:&
Ul`ll
|l |(:
7K^|C
6B50
&`\2&M
]FqL
N63b
!htf8aZf8DujhzWON0RPYckfEYwikO2Gfc
Zd 9
Qc4/JqV
8/>Y
2Ah 2
X>:,
/v;k
Type
.ly7a
bgM4y
F hM
pqLn
*!V! O
1kux[-&n%C
wgzC
8PM^
F6l-
2Me
]^A1
}T85W
ck d
yR]OTU
Cu> 2
1N2M
wtW>
j$II
ac>Q
ts?N
BwKQ
*e:Z
rUY7=N
x_nG
J e=
`yg%
U @')t
j&qVY%
8&|-
ujG
.]#1a
3\G(
Che<!
!3)iWT
hgup^
f|zQ#
@{Ot
q%Ll
mq2
4m5"
JTb&
O=n.BK
(]~m
!^Qy
G'h!
\Um+
ala.g
4/UJ
,#h?
(ZXQ
oJ|RM
4!B#
ssds
U *f
8Zsju
vo :
oP6E~
+]*r
!A9(X
q@6f
c^Gh<
ePUR
s$5'p
,& Jrd
t$Whb
&&&!HHH
z{z$
JDR#j7
0MAe
KpOU
s]sQ
gjis
Rc{&
chh(
YX|{
mscorlib
...n L
uv-}
"$7/
3Jym38Q
zuoB
gK-<
I/4__8W
vRy
NbY@
5 s$
G]0jN`
?'r!
pQ!>
(>el
U<
#< \* =
B_1e
<7E{
mrHI|
=
G7g~9
eT=-|
?wO^
5;%2
;OXUs
Neos
VL.P#
Y3<
&!sD!T%7
ZZ=q
Ag B
;{,#
(9c[
lOt:
i!'6
\>/=
| is
=ge4h
,$Z'
aC0d*J
q"@<
f}+R
4(RGX^
mJNw*
{Ty
4dR.B
?Pf
8Li%
L?Kx
nSc"
RuntimeTypeHandle
gH22
{~/1*
t&;
&a`j'
roTEo
/zpz
k='9
:8exJP!l
w.F_@c=`
,o:9
?mQ F
x6>>.lz
0kew6
7s`1
T{<UBz2
bNiy
FaSM
KLjL|
dQ,
k xL
Fsm3
!ErNp
zI _
3p/KjI
vLU~
4MLNN
X SSSB
^^^YYYY
fg[Nc=M+
yh'w
|\WW
@o +
G-Y
((( )))
>i/X8`
$].5
^S:/
w3N
vyQH
M+fd
yJV&=
F zw3
Bb"y
(!Ys#6V
KCq>K
O@m/j
C<'#9
6/)q
NNN jjj sss
dR9.
kIpY
@,}I
M8>*
S(Y 0
Rz;)
2|]t[@Y
-j1,\
?48&v#
D'{]
g-Dp:,
2:HU
m}hT
<ZU_
(A@+v
@-T3O
z-Du
H(St
||QD
(cTT
y/?r$
bkN<ijf_
TE_eK
l<^N
i?KGZ
1 Ie
Uryr
hUzQl~F
$ Ez
!] 7
40lN
eP$bD
7p{
r 1<
K> Ti
. HX
hy-O
B7(}
DP@7
uuu sss
fCC%+
1v$!v6
*AC'
8AaAq
oq I8
OCK[
q{hj
z{pQHS
](x)
lpVy
=@jA
-_9;
*#J#k
{DaP
i kh
J\Z"
`\m<
>anA
U%Ih
VoyD
k75=
f!)J
f -
s2!d
K[!0``
&%Kh
$mU1
.A>H
v'Lg>
s4 6
K$ H^
KRVs
NL](
>)(U
|Tll8E
CSjN
UZs4L
1r&l
!This program cannot be run in DOS mode. $
7P$j9
w( j
uDx
'zr,
Y ?AB
D^v8
2;(#
xB?x
D?3y
3yNtq
Sa*.I
7 t8
Wq1Z
pcz6
7bj
ZAP.
h|8h8
=)tl
~0F/+
l a~
ji)k
^avpD
@NU
%H\fa
`A-Z
4>j? j
Ih$LM
5SICv
13E*
LDPW
BdL<
9G<f
_{|e
MZLx
e~LuSh
ynr>p6#J
>*Xn
|BP[[
P#2N
,(s>Tzq
B8@y%
\}eIb@T
/*
hl*o
ZeBf
X ;4
H0Ul
J'=1m
ZPFb
y@E"`t!C
Qo\*
i32P6
9SVc4==
NQ%=9
V;a\D&=/
peJy
?+^y1
V"9J
Y,K,A
bq a"6L
i>x)
>i'V69
s8wu
iAR~
sVsuaR
2Z[h
A6Tv
(6]5a
&9@FJtxf
m5IA
KS^c.
HgBf
>o|/
RILs
OaDKb
mum]
\?$C*
,ip
HIl)
QIw:
h>S1
=Q%3.
^&6;
sq\2%
TCg?
`#v=
|t~;
/k-y/
`u;[
#_PQm
o( :
g!@H
l2U}7i
.KNXWk
_(QjP
vaaa
eH b
x2yA
e#5L
1|34]3#
;Yy
-cvml`
+clq
|b#V
&3A0
P$V
(+8;
e28i9QMhTwkczfcSL8pUG39syoJMrqA9
2RN
<}*>ibs
>6p#U
T.rc{
+I~&
RudU
qVc6
rk%
!hBO
H("v
:I c <
)rC8Xy
,:"gpY
McdV
0$v=
>@:T
YfJN
RO^u
MGP L
m9Nl
<}Se
wVy{
s^"\
Y@ u
o.=5lh
ODd\
F\6_]&x
>d! x
A<IT
di`Y
gua4
I>Pd
._/k
.~T|
ZL,[
N NP]
~%Wsg
~7c/
ZZ}8]
gP7 %
*Q/O
Ni67&
E^_gD
G:`UG
VZbg
MkxPq
z)h|[
&i4Tt
Ay`E
I CS
Dc0\Ur
sqHX
163JNR4HR
!.c=Y
)j%V
BmUxZ
; IZs
o<wfG
paf%q
6T rW
)`nd
s/b
yha#
:X-1
kuyq=
i[0Z`
iJ].pV
8] [g
z"v;N
_TU]
BMVU
\ 2\
FYjrK
,3Jp
G]j
l 8~{
1%
d|x#
z>4
,,$U
Y#JNu9
f-AErL
set_Key
fGa0
,;jR
-WG$=(
y +K
JzN:
BG 6
0jHS
===7===y;;;
8$H!
Ft,)= /G
Xjh
B^V;
,H7U
$+O#>
R% *+G
s`@9
v cP:
u 0m
M *w
MN-{X
!4Bi
xLE-[w
E7 nk
t# xdO
(a5A
M$@|0
7W2
X7aT
y"S}o
~^z@
}U@1
\`L>
'TEmwL]
_"7|
%p;9
fdvO
w(t1
+Zw#
e$sd
=cqi6
mW] v
^e32
|B;V5=
rW a {
m~Q
a2MQa a
g.+M
get_EntryPoint
CompilationRelaxationsAttribute
M-/S+$dF
3<5;
3F0w
//7
:=Mlb
: ,.
I K8~
+++F
QOV]
1MY
g4OA~`Z
b#re
Bd!Y
9idh
q,B5
>."vL
jy"l
frsBw
x?iX
fI}%\
~#t
!(Dv
3Z:C
v5co 6
![XW
-shOm
evKx
vy4E
yxag
{r`fp-g
Jjmd
@OaT
34k8
a/u
Yo*v
l* m
R d_x
?%5
IVX)9
Qs^\
$+5o
ULb:
G.{{{
#^(u
|A ,"6x8
d` m#
>qIgR !
j0#0
*A088
K a;
T_>"
|OI2
cccB
xc4e~
5ASt
VZ7K
t5/L
-J<`
VhnC
rvqO
!r(.
rESA
Gb#)
gDaZ
*xLN
(zEu
OOv#g
3w_e
/H>|n
!Q7Qq
/t5a^
]&dPq
U>Ip
@9qe
,Ie2
C'`I
3w_O
Y)Kv
i\Gzy
E 5ip+
Vtr7
}Zyz
NJxJ
^5b
fs)s
f${I
PsY
:{H3
Dtu@
-tg*
7DWO
.ORK
zadE
c8[
6,UY>.
Su-K
wL M[Qhj
F>8V
Z>^1g%u
RqwJ
/kw`
)4nL>3 g
"vs=
i@//
C> t
9*B>
pMmQ
Sntk
*=X
c":Uv
N\;;T
YX%S
? N`V
\_f #qh
K~w0
{vYP2@
^(Q{->
qWx}7
,)??
HGrS2k
DDDK555
{aYk#
ogMJ
X:'9a
x(y1
~*/r~G=
~Y0l
Rt%
R ###x
wX:
_zIh:
]3&u
^_DU
u l d
bQo3
iH%ro
Ulel
0 8Oh3
OuVP[
Ckl(OB
SjN k
l*..
6|(5Z ?
<=|;
A!OGTU
es|s
x u
pAp_
s7MR
+&31;d
34_)
F<"$
9ET>
lZ*Ea
_|P6
vo(6A
(VQH
\~\e?
p~;I
IHDR
AI7G
E+[]
5cmr
bHWQ
x]T
|)uXq
" PlN*
\k@`
XG1p=
wXUw
rm?4
W4i
]]]
"^:R
/fN7h
IK@2
rJ2G
[# 8
>TTbCh
v/$uA
/4hx
E 2
?Q"
Y2m /
""k4
hF1-
&BzT?N
]i~D
] k>
ug@i
zo9p
U|)= -?
D ;&
]e5Ep
?F9sm
x1J2P$
7w_P
Q.|4
BXq|H
f!on
= ML
>f|y
d9D2
%#]y
r 2zH
j\2a
r&vfd
!_WH
^x9y
V>yG
.`W$1
,*Wb7
Di;
&GZ:
&9`5U
x %.
|!9(
.RU%
B)\O
chZ
KQ*w 2
5yP=U
P `fI/wP
<r,KS
'g (P
2WP5
6396
`_zn1
"-=S^
u&ze
@/ a`q
2yU&PC9
[f{C
t}{,
Hl{7
2 x'xm V
0D 6"
[aMy
,8'V
#NE8
,qLwJI
hO
obIb
>n.a'~
\| b
u eq
|dq5x7
\$QG
`07q+
lzO_
x"t=
1No%
]>*|
RoNs=
ob7e
y~aN
C6 D
KM>aHGj
06)
L^.^
Wf:2
gV1G|&Ph
$Pv*
FNMf
Y444
w\![g
8h-l
dt\
t=Wl
#!Dh
;c,3
h~L>,-B8
Bmw{ %:F
{pgW
ToArray
U'J)
0nH9L
! )G
9Ga/O
FedK
b[:n
+cj0
.Ms'
-b p
\\\
Mz GG
<U4W
TQT5z
agoRi
cFjtk
Nl./
fy:5
MOT;c
w62w"
6`pKY
^zp^
5\3n.
mUM
jH$#q k:G8
A'Ll
@{ X
q\3m
3._V
>bPL
pk+~4
y";l
pt5x
Rbjd
rq,_
>fzh1
*{'_
/S`~
?xv9
f cl
FMPP}V
i* 6
pAS?
XJ/#
GN`
P_F:
gI;U$
U \"
8`BUK`
qr<>
j]Gc
CmdRk
2AyB
YQ*[
j!+P'
v)ae_
rPh`Y
0Yp!E|=`
koM7Z
GD;f
I (j
[[JfrN
q3Y{]; w
p1(-
:(Z`'
D^[2Z2]
2 OP?
;8}5D
fCl[
{2[(
^<I bDX^jSQ
4pLyG
zA@F
W]uU
k4= bf
cr'6ONr
lKV|S
:
[F{D
Y*H{
r }sW|W5
F2 czu`
zCff
?GSx
/=Kns
-|z(
U*X`
cha0
JjqjV
MR1f&v
>L>h(
9qR
TQbp
.tww#
Bpq]
s^,
Z44-
C]!8
)B4t
4(I{@
ce$
~^`M1)
26-{eg
`ngQqH
iR AMd
XO QHs
e!@Zh
t5RY!
!5`f
J|QP_
J0\2(
@:7G
t$ j
|Pyk
ztp,
>qgL\
'%"'
ihz_Q
zf5Z
/M1I
,Hu5w
1R 5
sNqCM'
(ipg>?
pc8p 1`nGKS
=`_`2I
~$M[t
MneR
Rv/>3a1!
#k{.
HxBG,X
k] ;
>sjXUo
vTe+
&?Q9
plc}
61U=
?Cxw
uAV
7S_r
\wa*
3xA|L
G^):)
bhk
"Zh^
[, <
4"16
VY
Gq$F
6DXa
W9R]
%GO~
8loP
21xG
`@O
&XYV
mU8TW
B( x
7{W4To
$@1ma
_m2q
z hh2
[+ 9D
DXZva
;!NV=
f#8O
BGXc9
wM@k
7H)F
JAS5S
$4f@
-=Qh
QbnCvL
g.v$
|T'U
!80=
yXo}
E/-h^
&^9m
BzXe
rz M\
8+C2
EF\x(
`'x5bp
U`W-r
f[rl
,
aZM@&
*)))%...!444
|!wd
RAvD
*tImG
==Q]
.j F
yv:I
@ERmU
#i-<
d666
DVA/
7\i!w
555R777
?gk`
YJz5O
eDt#
(sSA
[GTV
QM`w
F~m
1[iu
I!6/
x$W9
zB}I
V8h1
y2|Q
@2'c
vXZ-
"9qx
6DF
HLmK
8 jjk
vi2h
=2
D6y.
NU|K
|eqN
G&LTH
B71l
}r
)vzD
q)BX
4!sr`Q
4?iX
'gIcA
~[ i
#BWDv
|Mx8%
ev/M
''|)
u>UM
,F}SN
Tz'
cGO9
77}z
*@nN
'mDT
p hm
eT+J
5aVgm
6P70~
7B(P
bTC#
< X\t%-
w !MVLd
lvXq,
NEFc(<3
`}
'Q1
.Z@O
1mHXp
Oe;a~
|7T5
^ eNn
82!a
|Te"
o"#$
\gs*+
Ngb
%IM7\3
[/xt
y}hB
2IiDKf=b
uhz
j)r
@\O~
aaa~XXX
Ay4
8z{{}
jrr
hx@
GGG$,
{GHh
\4Ok :=_
zr.!<
>%?w
dAZD
Dn$m
WH8C
jFr72
aG z
/`xA
0AxqW
q<CY9@
|WVS
-u+~r
w(n
1vBSW
K06b3
V s
{Vw6
Lqce
Y;K)
+(Ig
LjOy(
6mZi
!cr[
Z4qZ
uFD= =
i 0&_l
~qx0%
Q@&+
oby
8jxj
cT K
MO )=
#nh [
B%}d
)~zD
h;#dk
Z~L^"P
,e"c
PC$b
<zk_7
~,xX@
@C_.
%5No
`a@K-
trs_
U"Aw
D;/
^yw)
u`p#
F(D{
pa,#]
Ft+67
qfd4
yF :b
aqIn
q e
Q}KtuN
2A3s
(]]E
<3N:@_
-U39
?tDgv
hNe
x$s1
IDGpC
pZZo
:Um<
P _X$
VN{)
]} m
K *J
jjj+kkk
]#IN
;m)s
q+dVQ
"%ml
\R6n
la,vt
sp/5
`qV%
#J3
S# I:
Df/c
7xH>rA
V(jc
] dmE
V55*
.+Bc
MTFI
;s)-
6=Y"*
85]<
=>3
MtV`
pzLtI
jX2c
+Tuv
ga8 +
U(/*Lf
-=i#
.HT:C
Mrd(
:xOH
.##H
Yvu*AL
_ W(
b%T o
~hNb' '
Mh 2
i;R ]pd<
EEBO
n*u*Z
CCCxBBBU>>>T===u@@@
T Uz
.U}@
pGo$d]
U+%\f
x{w)I/`
t(2a
n) ^^.
HHd
J0:`
'YCO
%rO1x
Hf[-
m IG
gRHw
0hY!
#<L]O
6p t
K+E"
BICB
YMUm#
b1Wkj`
I1R ;
Y<l
pd+(z
]?8K
bh?e
BO7l@q
ZX3V(
L d}
'Q!-6W
o)#=
3rMS
9N~B
4@7[
$^2A
@]~(1`
T/{C
(Sw/
S\?#
&a|f
* B C
CreateDecryptor
rK{n
TyLZ
>. hB
,mv9
GWq~
(@Zr
\f]D
kN:%
v J6
3nNfr
EEE ___
$Vv&
hsi ^
S(&o!7._
e(tU
1xQ=V
yR|v
~>Pk
}vjA
8 'o
"4\2
8zhJ|
^rm)
>\lqJ
Yn#p
v`c:
XC[9
_) b
;wNL
9PKw
5$$$8ooo
nb%<4 Efq
^b7:
'rnS
""O\
1hqGn_
dDZ$WG
8 TU
(2pt
lP/$G
?ZsW
, cE
z+ M
uux^
XyN^
vP ^
eV82
=&]
1eTq
WBhOc
w4PV$
KK&czj
AT_U
qi+gTa
45MB
<Z a
bjUp
Rua4=
YXR
ie =
Z'&#
WVF
,Bl
/~Se;( 7
DY5m
Bcn>
>bR6
Qe".
gh%W8
kiP|
-pt'8
oj%_
@K8-q
C#]
+*y$
NrwmOn2FWhbb8i9u77g38a1iWx9kt
K_;M
w)qL
2VnC
M l!
l5RV
3wZj
/&R*'
b[85
9'*0
Qq2}
\*@buo
jN<"
6\^
UG_
+u!AN
5ei;
-kPme2
I w `e
{wQM
iiioddd
>"TU
BN,&5
kA9)
$%:
y#}f
'E_y
2jO-
.,t=-4
9md~
k%0
8 kus
JrCHBe
CTP
tlMz\
9"~J
$k,xc{"
>U4<F~
o(.V
* T=
xZ 7
lA$H1
LhpH
zLNN
XB)gw
P<o
r*'7
ov5C(w
%!P.
Ign
eW-
~':J
wGF)
O )I
,z 5>
or 8
5 a({
Z=
Xc`8
iGX#
$Wp\
!_o}
D> |
1ZEBV2
<N L
' S*g
(Kb
{cnL
k!"@
;@bT
!!!5
X|R+
LV!h
pX%}
p7dg
WAX;
?$>j
Y [[t!
!tb+
%dpVq
eE6A
b][lPj
],0X
xH v
m(d]
=K$x
gJgo
fZ~q
m$*d
9_]-
\Jcfs
8:n~
}o7_KSP
p-k
^^GW
2y0@
d]; 9
T:*V
0??
M +5
o3Aw
nV7T
<YE`
!)zf
QA]9]
PpLo5
jdEp
k #}
N]TS]
zWSv
h<-|
:{aC
@HVL
,,,H---
ECAO
duB=Gkp
BlM-
f@C4U
P\}\
xD'Y
v vE&
=D3o
Hv+"
d.Jg
ORDUS
!.#", xI
V/K;
: aC
^3|FYCQqky
(sh Pr
K_$
&>(au#6q
`BU $X
[R?x
97qI
b5J~
Gh10
DT2B
Oc2&
MlMk
v?sw
+YJ3
'FVd^;
`#BQ
8[O>
_~om
QqZV>
j8.g}
Cv|M
`wt(e
'faX
jZ:<tt
Rb5
<?c
?g2,
e]LT
|a/zD
<p'-?g
$k
ltK1
y^/ ~@n
bT#@>
QjrUX
zS<
uLjT
tl&4
A ( 8
^<GO
Xql7
Mh5";
47>;
l>_:!
b(VnA
G6VyG
Cbs?
'Q@Q
MYHAS
)K h"
,hz+
9c2m
~ph|
NsoN
qc&{
)x?9
FUF
q<S|
rB<!
izQb^
q1QH
[vX)
3Uo]wc
L6?2
pMTM
rsu.U
b@C$
Rj:P
9W5xfpQ
|6aWW
ve7+_
0a$;Y
A,+
T)2+_|w1
px7g
2O ^
Ph'Y
/mr
hVBl
go`*
I>d~
52t@
g/Gd\
3HPJ
>F]O%
]H.7
g-H/
e$jX
H-5ury/
= ?]
1>A(
dG`[[
q,>z
*Qct
? q
R -q8:
'V,
0L8
uWofH
x$"Ff.o
I:sDa
HfYg
86U\[
0MS0>
#V<i
IwC-{
By O
Wzmd/&
Y(F [
gdd
Q -Q
%)H,
Q3I/^h
NJ'V>J
1! s
RB4p/
*HLx
p@i3d
Z%Yw ]
4-Y3x
fjG#
]v;Ec4
=W=o
XFX>=
"X(s
)%</9D[
Z,
;lrtF
y !i
]<>UD
FoN7
M2 {tM
4nfc ?
ci9t
OAB,
Uk_H
7%[r
) CU
|i~[6k
'm4, y
r u'w
qltm
`~~
+.B@
rdF
w pO:
-#=}2
pkR=E
-[(u+C
Kw.~
044$|*T
U'9[\
S'5
5 CyK
r6PX
Z/9\
Z~T(p
2ODr
HSf
,J{D~
+w]*"
/xwB+ Ep
{wAS_
K(+Jc
wv'q
MGx<
%{_: a
&- A`
"Ip ^
<fLc
7hM
)L?q
QaiD3P
n3Ms
/n ,
)`1n
d,
^Qha'
H +|ZOfl
\aSB.
G ac
u`rw
zZ cc
!Yz[
[c&s
&L"%
RWjp
+\ ,
<yfp
n$Cd
PS]gq|
x|b`
Jd/E
+l3
YZO4
G [^
P*P@WK
GkGt
e5H^
i2#%
.xX^S
aV(,
&?gK
2< C
1x!7
n7 *
C_VM*8
chS8
@.aR
T%<t
!IzT
tteP
899y
&RDuWu3EqAPLsLRiNEBNtIhP09WXBn8XHUCg9Sa
)/].O
uU?L
`J]A
AF5.iR
Y/V\
Twz3j
pY/a
2ikRTH"_
m;zL
H(VW
NCX" N
`OsQ6
IJt[
#*Ek
bnGe
}nhc
Y ?].
j+ci#
u]I
=%QO
\,B.m
$+S1 s
*<i/C
}XEu#
Ij&=
!CP2
6>bM`
n oa
%k^Y
hkkC6
z<Z{@#
98[=
UBG'
5 _}#
0lE.
ufxA
g:18D
=Al$GI
f Rf
IoK
iaERP
EuDw
icFY
;1l':
Gd8P
6 z
jCE--
Q8iS6dFg93qYpx3nfrjEGoHDDMrH6
&Hsr
++KO<CpG\@{
PK-3
! bn
Q77R
vQB<
#Cy:
l~RqDh
Nc%S
iP{|B
lSA|
J iP
h3}i
k79
-up y
=WN."
^Ee_4>23
CY6uW5P|=
GG7,
kQ@P
#BMn61
<1TE
o><?
s[q[
] U_n
+lL<
)(k}
|h 7@
!LNR
P^@8
2uJQ
d*Sm
E^:3
" >-
QUBx6zcTMFe632U2HxGlY
u|4#
L17]"
1.@S
/J`%
dDEK
M)T~p
j_%*
D+1b
*9_Y
! HA
e?`:
:^{J
({xG
`8\*
;;;_<<<
O5m
}ha%
dE9T
T1oK
vd-a
c A.l_c
\R ;$
< -R
U}cX
999@888
p 7^
kNN1?{
1@7?{q
$~LU
&n~G
PG)^
3z`
rw/x(k}*
=ye;Lc[
QS{v{
a_o(b
mq^=
XoN]Q
s/|f"
6-UT%
{|4s
6NQ-
pAW?
%)oW}
|?'w
91P}
B&j>
x<~g
u#IY
S ];
-n
Ic,'
/QW)U
yrE@S
G[ 1
Ui+E
bJyg
lz$G0h-
IyKM[
3m]B `X
T 3=
bF%M
Gh2
w^h?I
(jo]
j;l9
mmgY
~t<&>
05M8
YSs}>
1j 3b
S:TH|
-h}R
Ue1>*
hNMd
`:N*
po9x
m%:/F
.Acq
a8G Y
u{`Y
/II1
;T1c
!_iS
vpb:
t"vc
E<r
<K<
"?'
wrV2
> K(Xl
8h y!$
dp$B
?oOx
5vQTa
*'z`as
J.veywk
a.u4#
sV-,v?Z
A0/Y'c
A<GB
vy
R%01
C4&G
5y]<
(^s?
hgYJPG
qW7xb
dKk^
o,?T
K,p]
"W6c
V>#r)
`bbb
;@`P
i.U*
F=.?
$Uq<
y2-`
agW!iLk
{ .@
9wX:
"`+U=
e_`|
[|Qj
h}B?`
g9gc
k_+d
3@d8
x87#
3l!,4
3H5
87$CW~
GGX*R
`Ory
9~kZ}j
[XHv
[ xh)]g
+`Kp
yiaNf
r~`(
@er
U?1
`ll
+t:
'@z
/3{
~n7vh
]$A0G
\{68u
B#)P2,tUN
/@ |
Ct`1
")S:6
Lp&Yt
2A@
: :
my,z
Z_ps
@=,j
yE18
|Ibu
-D
)+ZzGr
t<#T
C*FE@
<B%1
4r3r
CR
zzzp
93g[<I4
[-d B
h0HY
Arp^]
`J0(0
k^n?
GOog3
cRw-
+dn7&
f^d
ur"
AppDomain
FFF@
v6 C
&}Efm4
YpFS>
N-u}
ca>
KjJY
q&C
Dm65
~gRvM
3hJ c
\r#
`9Se
\~|/
Aoa6`
v-j~
_3>(
JI#^
hEX{
!bV?V
Gm6k
\s7ohH
79pP
;qpjR
=Fe]
!gMqm
a]%vrs
Q6=Q
mOrw
VbA09
{U9U,
9qsc
U/.L
`o@N
.t.l
0/N>of
: hE
v$j;
@5#w!e
mkI~
T/DsL
BHG
zjzG
Gf{ f
>d'T
^^^qYYY
T 6KH@
XY;0
we0]O
]@B
lE(4
?6}"
):/_
G8Tt
B? EQ
^f"?
5U ,}
NT(xC
UO>p
wQ`r
' -7
CIlK
mj3T
uAuI+
sj !
0AmO
=]m(
&uv{
V~5*i
;co}
Vk3S
1":"
CSAt
pY_V
KzR,
QZJ?XbF
V"[.?
@.Z_
tr"
:47a)
UL_b`
<_ ]
4IF']
A;iy
TGzp
^FM1
,>S
8mZ9
/'He
#Tk[/
;lD5
wX\Nf0
K^r8
(Yj
s yx
=%g 5;
Hir
3|<?K
e]2u
+8 "b
VU[y
.=n=9
l=(G
'j
^n^Yvk
'BLLN
I)5)~ya
wlID#
s j
Z"vL
op_LessThan
qx_
` W^>
;wN0
bD(l
gd[r_
4Ug5
X :U
\b7
tKhI
.9$x
Ry}z
,<Q~
ViCka
IS*
_6;!1
LMM5
E'5|
S3Ua%
yGLg
l!TS
6}h'
7 ET
8IYA
QC}
s;f,
<qCj]
s}_jo
O+hK
| :)
gns
)C|^_
,:LwP
z!<-a
ieSr h
P1&
k5+Q
}z7?
ldKH
/r8_{
erB+
yhx{,
#}J5
@_4%
LP,51
h?b]0
" ~,O
R^j4
IiH9
/G!u4
YbV:s
jo6@G
)Sw
*J0hCk
, ###
6@|r2
, '---"333
c
B>"S+
_~9~
VQznG
>tX|>Dkr
`P\p
*$$h~
_h)=
x'J.
]c'(/
c[pk\i(&$
xp>`T
lo:C
34=]
C3[]W
(`rP
5DjI
K&'/
H6o]S7
!13 B
clf b
^JTzD
+X !'
Z~pc
{k2\
-`r#,
op3J
o,_P
3w)7
u" m
List`1
O96:
/W33+
0[ Y
15[Z
,(((
!6g M
`<rZ
eL_<dds
x ?A
6YBT
{D.o
=H)B
x/H nBq
h40>>
^G{{;*
C2HvIKv
"u6l
aTu|
U%#
Qld#
Np9l
c%*$jI
e/:9
;v|T^
@r;L(J
CCCH
+pVf`
a&|}
"*_hk
MBP3
"FVA
CCCx
/t`
I}_n
F%TL
u@o}
SkipVerification
M2b@
Ui*DE
Bm"D
M> o
sy40[
/~cU
L$B~
PN>_<
U5,nn
z~c:
1DD4/;;
WRMZ
^^\\<
JAVT5EJLm
F4S
nBnp
o0Lm
IA.}
y|v'`
%OUG
2Pw R
^7pG
Be-
8Hv^8
4m-9
PdBS
_X}=
nZn/
S>+M
|QU_
x 4
Ew8R9g
fk-xe
Tv2/q
gkGS
hY4
815|
AzA\g
d}\O
Q8 d
T#}8G
lom7
:- _1J
qWow
c|UB
LBp6A
#FAx_
mep^
A!j[\
tz)3r$
2$3 _5
C3cF
"{ZE
J-$%
%l9w1Z8saPiJShmnSBdZXqhUvPNMOC2btzj2Qr
X3^#
`.rsrc
rq6;n
|>?t
MAAh
U/V<3z
oo"q
Z) i8
' EP@Ux
^=fV
RU}|
s'R:
g%0S
sDvkS
{k~R
tGZf
qC7
6]r?
nb j4
&IUs
.L~F
WZ#|zWh
PB.se
CB@@
~tG+
N$1~
<M"
TZ2v
2uV/G
6_]K/
nfi5
'z);0
_Jh;
JFT~(p
Y**p:
),H o
Z SSS
n~E)j
@%$# *
333n
eur%A_
{GZT!
psx<:
Zx[9
|e[
!G(,
ZAsQ
|Kr8f
P``(-
Nqwh
A4JZm]
_gK" g
L9|"
2BS!
$kP
~E6xz9
7M b
`+N8
u{~Q4,Wu
spu;I
vk$O
;>>
sm,/
5 H&
mo"5
>I_R
}:jHE
Y' Cp9 Y
3 ^C_F
#F gDb
F|-S9t
&~#D
b#t,
,QU"
4f{b
ph0
u~Xj
4}TZS7S
^)=*0
7CO|M
~e1-
)~`B
G}oSB5
C(M{
}D|]
7I(
Mr/
[(E
}'ed4
?T e
:~~k
%\:e
\b^y
;z38
8EFL
CW2;B
0l$'
<4C!+
"un_
Hm,|
E+6h
ZLy)(]G
O>`0.
{ m\e
Ju N
pYeP
N wr
Giof
Cqm=
-]c4
i3 ,km
<tJd,<
JJJ:000
dF ]
&BC9
2i[3
Cs(^
N\qQ
`4g_
9[yh
Y@>U
> O^
;_ OL
gQiQM
[|_X
MaNF
ZQOZV
5Jt
t:3[
\BY&e
l3WV$
Y:5 W
{nZw2\
n7P3&
Z O?
P?x\
hO F
D]rY
SiFR
z-u$N
4u b*
SaKI
< 18b
tG;2
/.z
`Y+N
S@2.f
$^Mo/;mf
&xn%`u
Jo.t^
R:xs
W-!Y
'T]_3
LGAf
.]AU
Fz~NO
({"%
\]e#)
YkNd
KX<&
B8fuA#&
PnK<X
vC +
3sx`
[d_|
4~v;R
lnGo
7\.B
+ UH% W
p l`
[\)f
RXfI
f7s>
Mj/
pD=U
h%a~
dZ*A
MQJc
&cv=r
sT$o
J bt
jOBj
~raN;
#Z\)+~
NgGP
EXv}_
!"G?
S)[X|\
(,id
+v6x
deb1dyC3POneu5yFxO2zQKv6VWTvHXx
#xn=q
_H% .+
]Ta0
RgEk
R"Y{
tfYp
x< 4
Pn5_
G -0
K qG
37ae4
N#U0
p._t
0,}
A} 7
k~y!
1-!?
SOm)K?
> "y
NFos!BO
W'T#
du jv
=F*_J
pcV~
QkP2
"VQ@y !
*wIk*
N7.VH
Di?I
P@ED
\,A~
|1&=
qtbV
CcKuz
r$X{<
#ic $
-p3
1H3r
WAamc
<ox
vEwc
0J5^T/
"g;O
WoDv+
q)39
C.;se
&=>S
yF,t
+ /=b
Wobd
Ne@\
:xeh8t
z`f!
T- ;
iOL>
]:q7
B`Uc
hEz)
;K"|
`5 F
#Strings
9CH%
333N111
hwj
U8H 9
$g6RdSeisfEQfjgNil5rp6QK1Ragv5duXtvEW
(ZW'pui
Y}cv
FHV9
4~NsR
E/U]x
{BfE
)vyK
>Qz5
hbhl
t0F
9brQ|k
f'V:
u zC
gV(N
:B~%
+yjR
gl~
e_*>
G>\PeC
2$-X}_[YT$
|u+$
X xJm
j3,
0 Y+y
cT4k
V$0c
{lc>
rS.0\3:
J"P~M7
bO]Y
l:RN/
' ]L
l,Ef
v:x
9f?;
=EjJ
Q!`Y
zkrO
coVu
f1Qs
3{]4
A5%g
/E$v
F)At^
tl|ew
kkkXggg
Z`s h
\Vc8 @\
`IXt
,A=G9
T^ e
R[Y]
8p
:Sa
e- @
W]D
|$&0[I
p7Z^
_ zi;p?A
-,NOM
!8\fF4
uK f
#FYS:
LB(sF
MrK[&
?eO&
F]CW
e@ef&
(LFW4
@= Q
% l
$Upf&
mGpk
Ca\
c c
)_gZ_
CsR.C
s${leG
a|sgV
L~8s
:4bfO=B
|7 R
a 9Y
B,;W
| M@
9zY`
a6z#
gunRg
EEE LLL ???
Vz1~
bO6#:
dZ& q
$kjL
n2O N
l #^k
\3r1
_ gQ
fU5
a'%HZ
neac
9'y^7O
\ if
xii*
{=E4
skT8j
8Bhg^Aa*Bq
oFb= :
dPo3?
atPZ
1^ 9y`
|M7v
2dH^CC
_Wuo
x3tY
A-=
W6a~o
n+P.
V:UF
MGJ
W,R
tuw5
CI &
SSS8|
j M2
%Lg(
l '*
e (^3<
|es
20ua0
fPM
6,65
?~\%UO
~: C
X;x]b
d8J^/
r(?.
7;u.
\=e5
96`d;B
2l"N
;"|V
*8X*
v\ {
T0l*
sp!2
c= Z
C?U`
Q<UdGuQ
) e`
?z0/
{j4.
tIg]<
Ohr$;
x&DM0`
`Z{fE
CF Ni9
?Jm>/
NNNX
WkyB
]MN`
U'2
p'G7,Bs
>JH'
f0v8
rIly
eh_|S
%d!^m
b<q
K *}
/SW
?Ek
pJ4|2
i,xw
JH^gg9
S]wG
Zy(d
wW.8}
U#p
VO32
B^Cn
gEPjw
Q\G\Y\I
B6B;@<
x(IK
+q2u
S.n$6
8m{E
7b#x
{M=7
WC~i
p,js
? gN
}YoIHtnX
d*W=
Aa1c~
,o Z
>:eK
; 46~
d'Pv
Kig1
UvG%
%kV=
8JWZ
1)V
|g8T
E?9k
6PC.
5@6GA
$ z'
ESI
Y&>#QoB
dZ+`
r47N.
x)3I
*oOK
$(~}
/mO9)
G#_B
u {E
_sIr
-kIY
(?^%
p7! !
(S]P
dQGe\
W`P6l
x y2
-: ~
Ww(: 2H_
o7zh
=:6x
i^"u
M}&d
r[4'
suqG
/u8)
<&'bQ
*L<S
L,Qu
4I9&
42,D
;GLz
P eG
W,ct
]Xjx
w$35II
z}bWi
1Bz`
@bJ
r`{ S
NSR'
ai(j
5RP,
XD]tv
L5^S
CaJ{
2UNC
8ouw
Li%8*
A*;R
S?i8b9+
*cf~]
^C&c
'zkvY9T
\g%Cx
BD?S
rg<fo
~1<o>j
kSI s&
Bchh
{Bg .
R/B#
OG6v
E+{Bo
LdE
zl/T
7=3p
TL3?A
PX@Yh?
=5u:e
Q_{r
j$ 0]n!
V?sK>e
Ax]P
\NW^
vK(n
jTFGK
bhns#
Nm\A
O<A&
Whe'-/
]FA3Q
g86eo
x||v
ROTW
3<0'> <N
!QtWAHbr69ai23hqpImwifXRJTGs48fmSO
w91\
b^3,
P06$*T
05I
$327
#wI}
q3]S(
YTv@
o/{[
Z.tq
Jp4CvYe5QZRo5RVaxQb0sthTGd
px@`
EF%sS
sb9S
U;I[
H<cA
i^Mt
"b|
.}_3
xczN
h?Ei
?'_M
s!1|H
Sg[j
U' 1
F=-L(
ps'R
p!. O
_oA?
$+\4
aO`aArB
>F>]
!W^t[
S!B6
Z^Po
oFI1
}aYE
^:zY
?n/k _|
[Znu
nw@;
t3y]
k>m-R)
5d [B2
7&eh
{_KEo
48IFDs
BUP
5w m
sqBR
&HPD
$<[Rv
7EK
\k(;
5$*\`o(
FW{]_
RBv}
q.'Jb
`Jw~]
`f TS
-LMM hL
R0)o
,K6N
R2 :
v=FJ
>F>8
0GL<
)~oB
dhF
H59V
}foy
b 7p2
/jo
x`d}L
\UXxO
BgJa>
6f^D
>GF`
h3eW-
LQ$O
Jxi*
(gfX ^
VZG1/
/i7*
<p q
8HVn7
>{s!AP8:
a dV`LD
uS&c=
+sX,G
((ej
S$&PZ
fzuT
%g8<
MdW E.
a W"9Ww
~,xI
:-\R
#!_!2
J'v=q
N#KZ
FK 4
=g//~M
%vi+
Icx
_aFX"'
8Um X?
l5wi
:r]>i
@T)?
ElK.
D_UM
k4,TZ
$$$#
@np}$
?6*<
LFh5Y
CVu!
Z?c
rGK
`2eW#
(-!.4
k0T!
Wk 8
{ 8S
System.Security.Cryptography
P]])
q9%:s
<p<Q
s@O&|
In88
r-?zw
{ag@
<J6H+Z
lYil
}zC]d~E
:[T1
, IB8
N}%s
Z0 <G
:5wk
^OEw
R *
C ~`{\
inO2
rQ!q
#![-B
'"_'
&{HL
z*D[2
)!66,
Sc7 y
mP\
'c:
aO.%+
dO>w
T9#F
N kHQjU
26RY
'6.EX
2Zk?=
"g9:
cO]dm
a H\o`
B0a17
^=oQ
]( D
i,k4
0(#u
T CCC
653@
C">{<
quaQ
SK N%
AF#p
.ctor
K myw
yN&pr
zF?k
2o/Kwe1
U@oRL#tRej
\]-f
get_Message
cUWRr71-
wW& fX
1 r0
F$gE
i0C3
lCfO
i8s~
*Vi`
w1?1
w"92x
Go*
&I4
:}"VV
~Bo7
/mcl
(d~
r wQ{-QCB
\l/;
.dyp
h@L >r
a8 pb
,w6{
MF5We<
LFm[
l "|
Pz"r
f~-2x
|<m}(
CjiI
#i}<
T]V
%C)
7H(pf
QU93
_U4W
RMn ^x
Yq5O
5{1*i
*GR%J
+o /!"C
<B@w;Bux6
C$ K
+Y*J
tR"K 5
17q*\
t:P
#q|+
0:x0to8
O|}-/
w(Sy9s
D jw
4 h+
Rols
E-38
b y)
ZsddDx
+O{9
K m%JY
MHht/29QEf
?T7
+>6x
+hF C
pssT+
6eah
>o 6
Ae_ckP-
(k.rz<
DlP=
&32}
:z&!
rb^o
ZF:`xR("
qY?H
k 7
F!2!
$q8=E
B6J3
]p_L393
iWTjs
MG6xsh
2?e%
>X?3
~?PTkN"
)7M9
h%Q\j
c[pr
6^Wg
>UXv
}Vr9
#PsC
FNzsC25wy
vez\"
fX>S
~Ha
?#jg;
`jj SSSb&
>e'z
f [
vk#sOZ|
Cs 44
pI8(y
0L1X
GW1U
AV&z
0%/"
][r{
}&H
PW%5
i&lq
..M"
Wm^4\
_d9~
W;W.
Mei[_
;a5k
KJD6QW
KFcbcZ
in>$*
~ 2l`
\e]M
xmJ,I
Assembly
T-:v
)XK82
^>dT
0lCR
&H<@S
JaLo
2wj+
C< H
&2J&
T'od!
v?Cy
Q .]
WstJ
lrP
p2:wg
9~uV
HVP'
erTARV
*NaZ
FGG}
y@_K
XmI*
U$+u
6xL!
Ib']J
n+P
-"/#
KBeH
xn9,
# lp
5Per
Twf>
s$ C
z7 3
***;+++}...
7J2N
6N?J
K,]-
nVvj
=ok$
,wUm
A2lh
Qy0]
K
A 9$
g)@%
k"iY
_fy3
on:a
qp4Bxy
u\b 6
8tR
7T85
,F_=
@3)'
qv& C
R80,U
d: y:
|!i.;
B?tQ
j)B-
oy2p
F=,G
0fY7
sDX*
twwc
7M?(!B
;Ovm#'
|%;N
mRLN
\.u;n
qrMD
dq(?,%
FR>W
rc3rL
+r;N
q(p)
`X*Qo
H!I'.r
8.sY
Fu17
A]_w
H0AR
y<&S
K&k?
r* h
EKv.@P!
5C`pF
LK)!
})>u^
Xd"'
j]Q>
m*X!
lZ:0
s@[e7U6
6QFwenb~9
2O 8=r
]|15w
:G m["rcr
9*S)
}:kJh
5Tv
xY )--=
3<&4
kY`$|
9 7N
|pv /'
q}jU
m/U0
<[b=
lbRZU,Y
:::b
w&_{
QVnx
@=\
b#3Nj
Mhh _
jM-T
P L
n5z4m
`jG=
!Ujc:j2
z ?V
Li'&)M
a@H"Y
N90;
9|p|
n(_G
qqFK
Ja`` 8
~Yi&D
F_mz^
u
>dT}{
"kz3ipDcntGaTcnHgjLahNkITx0LY7OlFUI
Xv ^
k2 vo]v
FpZ5
qH?O
cB5R
0T,4
yXIs_
"iR|R
Ip99
2- {`4
@$EP
I"XC
ZI5{
5lEt
{][,
fCNx
q]kk
1"#9
szAS
?Fan'
[5CE
y~t{0
}!@>
06 ;%
uI&]
kDTaz{
^>@D
NMJq
}0,}q
<]#k'
b, .
O[p}
1 {B
n#4&
&:<I
2Gy8
RT)O
Show
fyrb=
6N\F
8 f5FU
5#(|
i/xuI2
lo3D>o
dm*I!
R,_
1#Y)
cAJJ
x*[
"x1x
mQ`]
ZDKfe
V`qD
U:.a
X4C)
mJt1
t[3
y*o:1
[G#h
+WS ,
H^b M
T:#/%
=Ek?
'1#r<
,P;
# SMIT
^ U N D =
b/,,x
%"a1
6aTFZ
8;&
P@rU-
*<6zR1
^asw
seP^
'GFF^
#Nw8
UbH$
3ajMUJXW
@&8 t
(rAXiHm
|"T7
p:p/B
bx~d/i
vL)$6
Vde
&7tm
Nh7D$
+ dq
eCa]:?
}~m;
Y[==
A~mk
L5Bl
2v={
7" pDY
fF Y%_
0d03
;e9@
qe='
R.D?}
:1Cf
;sW[@o
5k.D
) ,u@c?
ZS>(
} CZ
LX\2
aJv,
xdEs
6$k7
\*.!
2m4P
r
CuB8
z1~
)V6v
=>2d
~)o=
hnBb
:@(
1hj;
oi&#p+
F}aE
{@3d<
e)X!
!0`3
d B
cG]dg
ixseUoU
HePu
Hc77
Q1mIcmv77tFKmSqIsAzzPWMoQU
;W:QFX
S|kb
$*"TE
/3&A
>R<W
TYAAc4
) im
FLvU
5S/{^o
<8Z#
-wN(r
9aHe
l@#,
?,mv
+) 6
GNR#
rMyv
'9 f&
b0glp
L1 L
mV"2y
U$eX
_jVf
y#-X
ZE<C1`
^6_\
n"=@
.`OU
Y~AQ
g-@L
:U '
<?6S
`vS#
~-q`d
+ARe
\3S>i:
LfVi
/>/8
U%/"
./5b
Fw8"
"S'ro
wx +@-
RyQ
GKq,
-z~dR
nQSl
D\u8
uHvd
\e g
gwLqu
841U
;?g\
;C61w
nxD6
&by8i
I#j?i
2uJd
3t& F
[k Y
HM_*
H#>0 G
>'%[
XxVD
o_@_
tQV+5
:Ko%p
$qAF(
f2kf
<NKN
3hdIj
4r<
@kf_
YgGp
r=e<C
ZoU_
AnnP
oIBY`
4` F
7nlh
U:f>
}Pzm
"I%;Et
?^r]
V'WM5J
,e(+
f@ii
kB --__\
>OL(
aJ.c
O3I(3
12Alg'`f
zGt =`
111 ---E)))
sy'|
eBlw
YC}^W>
eUIG
(53 nw
``W'^
t'wh
|]cfp
-a|n
DC{
:e`qX
uRsva
LpC S
$|F8F
c[1~
MeOm'
ftY7
y5D
E%G %
!0<<
(isS
@{bh)
~4^8
/fPK
S qn
5K}i
)7W/H
b"$
w"5P
)blG
XWV
$7xB
YSZL
n0W
-\,u
0j,
,eiv
@R~R
##_oE
1LN)
22v
Zn_DA
TwH }_
_%~X
onnp
%TM#d
9|_-
w3$.8h
!xuC
RSb#$
HZa^
!EFi
AzLC
{GV+
P!6~
tT J
~_I
*NjT
_>1ew
i%=
^o|)
Yq U6
.Vmf
6[-HE
,;zGx#
B[vC4
u'($=
~N%9
34=B8
6) \
@<F69
]fa^
y5)B
`)8l*
B29d
}Z1*
.61
S=mOl
kimJ
s 5-
\R<=
;hkR*
cKD(Mos
^! Y /
kFLKfI
(SO-S
f\eM
R a}
;T&X
*s/U
BWWe
HV !
Q\ Ru
i-%$
nKGQ
+!J#
`4rA
={4+
=Bnv
`q\+
&w aO
5#0_V
6;Z~ j
WO:o~
( Lrbn!eV
jaPV
huiY
\ls!
1=G7N
]"`x
%jNN
@"6[$
^'z1
h:$6
r'$4
q3{L
TPGJ&
aV X
sfn+T
T~Z}
xB1F
iJZ-
9~sW
p|dF:+'
G}dm
EoQh
0<<,
'+Lg|>
7 0z
Dvos1a
kei
wQq
4@^h,
Wbav
U,/ O
)e0}_
Q]X$
2 I`
T-d
PYh#
%zEq
[qD.
;F "
0h'a
k{G6[
j}gSuE
H?!B
92z{C
pT+Gl
wLDY
.$+n
9 h"
.<|S
[no}
9/DR
'4m_
N jK
D|H<O
"AI'
&[XR.
YR]Z
~ 4g
=y{U
O^z
B{t?A
h4f
obK1
fBK}
flE0
mscoree.dll
'aJHU
S.,O
+%n0
9Nck
@r93
w~0
"xBM
xbD
%=a~/
F/'U
&">c
zBl3
8.sw
&`?N
lMe(
Zx]a
|_ *x
HZ Y
?4@I
D AVf
\*W&;P
yqVb$
7aM8D
9!b)0
foo
8cZ$P
Yg^mG
t&)o^|n
el{O`
F!x:
SHW V
.bp
W<=}
J%87}
I+#c
B45R
Ma\f
H$AOt
E-y^
gU)W~=W
Fb Gw
n/G^;
vHjb
Ar`\
!}N&
o$JIk
,&7U
?_7S
()zy
avE_~
[Jz`FH
+K `n(
oWWN|3
#GUID
|8z%+
'JDZ
5Y7]
c"a>
FhF)IS
EB`hWO([
O~}6
;N X
fx 9
F2#N
klso
!17M
|S-f@@
a$8W
@cOY
MV$1Y
v=W3`C
sLS\k
B|&:bzE!
7, +
wJ 5(U!I
:Qfc
}|5z
3qXX
qRF.m
^$ks
1%>W
iG)l|
Hz24
:N.e
hpOM
Ls;QI
of7h
(-o'
=JAp
&=6. wKA
|Rmm
G =U
Bt<iZ
L)F<
g~*Xs
>x_P
666x
~ |=
%Bvk6uahS80SKN27drz7bQ5TOU6KVskrk1hVH9
!oLsC
X Q J C = 7
>@c
L(!KMy]
4Y5Q
C7|C\
c2. |,%
(v#Tl
|0 L
?yDU
Z_H}Z@V*
, }?_G
o_[P
Da!CB?lD;
\S0<
___K
zJrD
JpDv~
$(*R8
afLR
n@$()OvL
=1_S
Z^TJ
4LXX
&UUhx
kd`Qw)
-YQL
*Ck|W
00Uu
ly {}
I/|
K."E*YE`
zVR.t
s8U1Sf
$vIP3K
JjmB
jDF \
ORuLY
Ocg'
SQ|G!
&0,|
ESj6
"TSve
cD%n
Z ###x
STjL
`Rg 5
a}%*S
5KG`
ga+Z
[5o K
`a9
z(}3(/
XFh~IF
pH$&
>'m
.;3<yJ
`z%ur
`)q2`f
)9sk
P0k4
9K .
c%>y
,y/b|y
5KGO
fvHu
c1Y o
{B*I6
Nr>b
P. k
#-,b
^{Mh@>
_&?%
'+g])N
R9,H
paq6e
W *
g;&r
exf\
"4'.
c #WD
C|h:
S5o;
#Ff%
6] 0
!mb81G8\[O
sWlP
:i:n
iBwa4 wvp@|
DG)p
Witz
j`7q
"@o'
6"A-p_
xPjy
{rpo
az!;
w=HN#^
EP3R
=<-e
9`w~y
s$x
7wnEx9`
mHlK
?m8L
!mH3
/byg` {m
0"qU
kOn,
V$pZK
d,ja
: 4
I\C}
UiocN
91 e
!'1RUTX
(]#U
t^z`+C,
C. W
XP}1
{XIl
\|7hnFh
9M"t
!s!%C
jIqEMq
# "zE
r&=(
O!)k
, J`
"w9wn2
jrAG3j
'5If<
s4xi
poi-
lGC
j"WU
RT6m
Rml![
fNdp7RE5
IDAT%
$Ir/M
aS*
?s%m
l_P,
?-R4yFE*
4r2^
'QZS
t +h
dm[&vH
6uSz
"~[w
y6Lk
+V V
IDAT@
Y$7
B,}D
^W"
UUU LLL UUU mmm
.bKM
q$uf
|H7.
VT"D?
$`XSj
`n+Y
#ZZl
s7$|#a
/`qC
@ D|
FQGD
T*%V
UxrMC
U;:q
'xAF
/gw_x
g-B/
gQ58
HKG^R
4FuI
KVC
oVB\T
t>)c
%8r%ZT
Q%fAG
K 5sI/
:nL(
!q9"
-TUm
7DxMC
]*_R
Enx
&pM _
cxB
oFM0
j|}W
K ia'
KBD@v
$K:A
OS2@
skL`
4199
a~' }
?n?$
d%khB
PS{m
Z;?j(
(r_3
Byow>
gD58
@NXn
a-~r
I=ht
+'vcw
d*<L
Z Te4
*4Hg
\)$v`
2?+Tb
f!:@
io /
AH8B
Z@ r"a
[d|x
HTTn5qiSNLn0nWZLAn4IkS2W5LUP40m09r45oL.resources
s~u
L 8
qB]3
$1kL=
] Uwi
k(BA@
E1${B
}V&G
3ve)]
>ac~
$3 #D
"',;
s<x5
A6n]M^%R
8E'Qt^ V)
EMeT
*}.Mc[
=r3p
^G8^9
0!PR.z
ZO7
000{
&bgQ
J}hQd
Or* ox
O7@7
e/9I^s
F[,_)3
VX'd=!e
000P
XaA
Je,z
pq(I
s
?4[q
*Q 5*
KP d
PBb)&
)oE>`N
@g,1
wWv'
"-yH
X+$$
looG
P4l.
&iYk
BSIv
pacL
YQW)9
|8tS7
xc$n
Wt1B
q,>"4z
EEy
%Ve5ezku
1mwH
jU0'
V[|
n>-b
k7teC0
?LH*
)i-U
'>e)+
vN m
~.{-h
2 87
G,JZ!
e"*=rbU
Ex0^
h`C2
bEsKP
A ka
"m{l
/oej
-BSJB
H(5Y
aK=>
p9j0:
_[s\
<} H
q)n{
E3ky
uRY:
JKOS
Q, }
ys"1
I~Z
$Fk6
60nX
nWbC
4KuI
Zp_T
m 7b
qpeA
"_`R?
4v};w
zQ^H
3%(z p}
<!M94
=Kx2
6W)[
@A?GA<
@ vC
KH*ep
:M}Sp
PW!A
~pV&
+fdK
[=4YFl
GgBH4
_}:u
j7fs
uD{x
=)39
_kj
zcfe}
'<&Vu[
'yb;
7aznj4
R& ,
_} _P%
q}3RV~ybA
N3B@
HUWO
///x
U#We
$$$
=EJ?vO
6yj@x
T&J@(N
E]A
WPd&
|/do
~=.@
@@@RNNN
V?WX
v}`r
y:V
lF"Ev
S..
.4)Bw
a*Hn
)_{9
!cFA
DzeI
P(OJ
n"As
bFfl
6Q["
IZ(~
wId "
o6sk
AaKC8Lb0qXsR6kn1nn8P27P
\7$@*t
Ddp:rJ
X&ea
hhkc
jjhM
%ZP^
2s>y#
dfc
'P#!
u ,?4D
&oQl
"++*
6kT$
K9}?,-
YQ<B
.I:)D
J 4
"3v
cj ^
$aJ2Bjn
YV\`
7_hv
1Tl B+
AjLK
o<q>&
:(8-5D
v3z*K
ARVDp
. N.|
SZuj
nF%|
S0F,
Rt~,
W~ ]
>^ 4
=10i
p&!b
$1c^
2BK&
"%1d
D<w}
OD#
< p~5
P'1Ic^M
5_bl
<MlF
B433
0~HX
asVL
sX:
A}[w
T4# ~:
}i@q
\,Psr
sm$
|m&{Y
v}Kq`
7/5i
`Zk%
(cc"
"tl{
- tB
y?8F5.
,2SNSz
=%q+
6PMn
3f^RH
Prse
s&H[
)qet
,%*t
!I(C
=JO%
7f%K
h9.Z
V<5r
Oywy
57?jh#
t|:Q
~Vtq
[.R/
$.Za
I20:T`
Uv=\
Kp/|
n+5+
aR[]%
sNR2
A#,T
E#U/k
2 #g(Q
dc~|
"SEm0JF
Txd
.< :
t p
s Ax
nphd13
Q2j
WmcG
l1Cs
{ a}
;[,$
@`=[
H& ^l
,Z[q6
QY:h
/7]<
A{bx
dduWV
&}>
4!iXd
|t"a?
O/y3Z
Zs9G
B_"Tp
e/ $
_Gh
GIF2
) fK
]>0d
%(J*h
_*?q
K.}o
$>G|G
i]_Q
-$>HAg
O&Ap
<NY 7)H
.{h]~1
~v(
lM .
7EkTy
P-TpJ
M_&,BG
H$6j
&Lok
+EN
u[{U
=g7j
zHxo
&l/[
H-iG
PY&[
:7*&2x
r Z/
813ew;
,`i[
Xgf 7=/Eq H
wA([
`Q1
_ ^R
Szu/
.@'zT
=H/)#
Cq G
4hJ?X
'L3
*Z52
y? '
1w:=
Oga*
F 8
#y;_
(A) q6
YMu|
NCTv
Z oU5
5%R2
o}z~
L1,x
5}O9
i[s|
D?NM
%p|(
M!;
ll-*
KATaBK
[)j`"
KC.i
U=zJ:
x T
C_.$
Ci ,
ieNd
jN;G<b
F b|w
<vsh
%j'I
!(Tb
#>_1
*Sm
tX{a
jMJ|
P?-@
~M;Y
WYwe
bW0d
'[Iw?~
rF48W
$R>]
\tV6.
'sP[
:;BI
jX97X
&4R?
@ N+
*z!$
#pi
p=Dc
m3WvUO')
zd9@
EHIc
l[8dS
+*-*w
A23_
&eyp
CDUS
r`NC
8?:}
>7MI
T VD
6>2<
4N k
*BBv
F )}
@9A,
o,eVn8
qHXA
r *|
l;+a
6v|M
5W(:
!*Xw
={h[
[}|S
%<3^e+
R6TM`
Eudu
Fu)N
F *=
Y]pZ
LU"D
e*bz
0jZ@
7<qrK
b=K=
VV9 )
,2MX
:gi;
gH3y3)
"!8/
QD-s
rx%8
&4tGS{
kIEg
B!Gg
iej )
|o"Pu
cLkO
#{"u
]5&tV
hD/B
? ~~
pa%>PhnBA
9\z#231C
RC< 9
~c^$
c|5~
tPXW
pw<v
Rj"<5
*W.bmZ
(nAc
Gf&
7P$u |mM
5tA2
Z3IQ3
.DU2
{Or!d
L`Lz
`Ttc!
>b@a
>$9wU(
nEI,
cwBs{+hg92
m,(8
1!@
BBB=
/vH:
{ lZ
MV-BT
K)V7
L_ 2
8aeH4o
RZT*
<LV` l
ozO[
3c I
d*"p
/_*
%M0z
gT>~
MszOA
[JbqH
@N5o
]:'
3AgaW5|j
EPFaw~
c:](
cKr
: +
[$4I
l/8L>
v$b?
oQ^N
b=Q^E
H?8]v
BBBrYYY
cR\g
V'Ph~+Ui
zLd+v|
//e'
+a1CtF
EEuE{
nwr%98/
\Bnq
JAgX
{k~%,
ckbi0
n\5S\
k Dc*g[:
"~.~#
\Ag~$
>J }V9
HfUA
Y^'F
y8 #
cc::
MiG;zx
z;O
I >y
U,UB-
QK G-
fMB[
Y&&jto
>eQE
]\T=
[8td%k
#Uf5k
F+Xq
Z8h4
[&OSYm
/> f!@
8[B#)
}}}x
;f ^
f.H/
& _@4
h8#Ej
#^xx
MjEt
T :
'XC.!
D_A&.t~
K9sg
wW!8
qp w
T_mS
<)rL[op
YILG
){ @
XSvaAA
&I!F
C`t)m
t0{\
5azZm
i+u`
rc"9?'?]
_-z
1<-4)5G
;Z$_
^3RA
5M@'
U1s
@WNb
8hh6
Z111
7$b o
333
bI)<-
l>ZC
}uFa
iGi2
0N~-%
|G1[
5yl5
Q<u
0I \5
|9ET#
fhq*
O9(M
M^KS
B,\Z
Bb ]
KZxe
lH8
qE p
eYhooGgg
.PWM
,;q#
x`jV
kCM@)
ea~~
I_y/xs
7 g<
:,=a
9aEsy
6d-}^
O\h)
q4[n
k Jc}
wj"T'}
|d;F
[_'G
~nO8
ZEy@{
%ugOzg98TQ0oPQlRLNPuodukuuY3vzePm1jnXg
2 1P
IP#,
90Sh}
ZPtz
r87
^UaY
WW#2WgY
.X-
Cn&iH
^Gn+{
?Ao
.G:R
B=G%
DI$@
= _ af
Sd;
jjj
Ah3]
<^H7
3P?~
z)!Ib
?3.l
*, *
d/sv
OXD+6
(E"Z
;pSr!
XX-0
z~m7
k,]/
&gzg
7K90
IDATx
)D;9Vr
?%$=>z{
\#wE
^4bE
X ~-
&V1g
7wOQ
d~3'~
tI9S
tsY>
f"QF
xdnP
5!|\~
I&>
3b_vjI
,YPG
P'26
BxD}I
u48k
*I~_5
e{Zc(
#Z3e
R3f_
i'R,^
4/Zn
Avt4
O.T;
R)?
`6v(
J/]>e\q
+TJo
XUXx:
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
yJMN
Exception
f]/&
`D_[
[/8l+
z<Cc
_Hr?X
SCf!
6G83=
*UJCu#
]13qN
= %i
[8;mu\hu
c1GAu4
=@$H
RuHa
> XeZI @i
Y4S$
0p[R
ZUlB6
|)t@
O+"z
'===
4D)_
iCeZ
C~ t
*l%x
m{D6m-A VB
nQ:P
Tz;
G2O}
}uGXP
0b"b
fG9jV
y&'
/3l
Tynb
#[Um
7K`a{
*ErJ
;czV9u Z
{Bug
qJwGi|
gl?+SmX
Tl,g/]1B
w_JM6vn
');=
O ]b}
ijk-~G
UbRm
+An{m
lOOO
] C{
.>"w
k rTU
r @]
ukQi E
2>"\
)6;vZ
#Tdd
vj/:
I\@/N!
<9hku
M6hv
5#?SsM
cx]_
>M\$
Gu|5H
#|}.L
D+o9
oPel
Gu{}
H,(/d
jp@.
ZRw^U<
jIOXH
a= i
IDAT
~(v"f
;`K~?w
. )
5 yW
\OrxgQu
WWSa#
WwfF
Yi0i
c.!
#Vuf(
f\Qs
ka?6-yn
y:SD
;KWyzEG
$Ip}
:{($
j*>*
Y"(J5
$[~%
g8Q,Y
)b5M
cr,-?
l cS$
3BKU
v"ky
zLPg
avSF
2"q5T
:f-[
lmE3
Cy,?
kW#A]g
j}@M
3i&u
u G|
%)Y~
|'f<
!WzXNnfNfpKNRKLDKSSyQodZ4M6RwNs7p7
$>g`AeD
wnoqr
W ?S
0XfW
j}L
*O3H
7D\/Fk
7D7I
+M3NV
vY]s
k>5+
Ypq>\#0
8| }
c9YDE
o`|K
Q[/A
4"JP
2/hZ
| gAZ
muCu
_o8,e
PO @
Y1}t|
,5.t1
ZIw.8
tlH*
cM;f
{ c@M
!cdBG
q=zX
wX`u
vlzA
4\Gk
Rz2{
I#,}>C~
d2e:
Au_6
=|w,//
yExX
g+7 U
#%(l
J6}4!'
(ODr
UShe(q
yo|S; L
Li;_
^~+s+
%zTtD
EFQ8
14 X
Vr_O
|=Xd
!k|v
u.R+
h'i2
9r$8
PHoc
^q"T
.Ng?
?,WT
&m
#5B3h
\aV`
&Ygw
$6d2
ml[cfi
z xq
^abyq@
`m.<
z24>
|;*p
$lk'
mdy;
lO*
j:H
CzGJX
zMa8
Bg$a
.W+B
=iP#
{ @t
NQ;a
|``4T
x p i `===
s& h
Kx3.
|ypM_rA
f2qP
... HHH
.o a
"|*;L
j=)j
DyIK
cZ&k
$ZQE
^toO
&:6eGE
!.DL
tGF }V
gkT{R
5`J<(
0 sE
oUDm6
jK=Tt
r:2
<s#U
3^4 I
id$pU#
PC] b=
_bC&;n{
5l8'
khG*]
]s1CwUi
9Hb3
vexE
iRd^
07B)
q7]^
S9~*
L56X
$\g4
G3i
B|?=
,)u
I]W/T
[@C;
;g=GcP
|FFF
cW7+R
5'rs
im|zoq
)=\q(
|nlZ
6RFy
pbnQ*
X>6HT} \ob
Y{_`
P:~5
###'
###$
! J
w$EH/
k`xN
c &o`#
CN6L
Xx1`(
M?0
*/LYU
3 q
!
fkm8M
# Z%_
t=JI
hbe\-
Sys"
w+{7
uv"`E
Y&E@
",k\
$H92
[J/Fz
#2 "j
] P.r+
gtC
9p~
P P iE
'A;i
c(V
p>#k:z3 .
j%WT1
dosM
#Wpk3
Q)[Q
5[{
[s"f
Ogg'R
tL1s
rJGH
]1:*
Pt(g]
... ???
2#yI
333 555F777
j("a
7G1<h
>rT4E^
".@l"
} l1
W2Ms
brpp
d)/u
'CMIU V
p^7
*6 KeL
rI[$=
+sF/
"3&j
8@_9Hb
c=V?u_
DGu^
US.S
E Y^
+ -m
{ar+1
b^k;
+a M
]h.G
:'Ds
+xN
(Q>K
dp5#
:jZ`f
Kq|a
j!P;1
+)qBG
y$B:,
~">+
(dJO
+Q' ;
";bWa1
E<Eq
QRsa
_mH$
CEqW
#o[n
rL^G
PC$
z6Mt
,^ w
m?I-
1B='
c&,x
]YEx^
4u>G
U;7,g<S
)Te'G\
(MOGMf
>.Ye
76G%
)$SwL
1.r
WdhzcPWZaHfv7bNQyidve
K8oK
cNq$
N,0H
+!P9
`%hL
K1P&
K Fxm_+
QNxv
Gn ))
XS[e
iPNDB
>O>%
0gO9
"x'D~v
G<p#
ga7H
z(@9
oU4<
c|k*
%S`+
I a
AvBF
h^bm
F!=
*>XP
x3R&
ib||
PlI#
PA5#/9q
NJg/Y
~&wZ
HmIr*si
_EaEef=/7
C< =?
P AZ.
9.;}
^ AMX?
~6pr
:,;8
NUB5
p+Z?q
V\dSn
e )]
w0W{u
lns$W
L*e6
kmM9
vv >
m:R&1
V]['.
System.Windows.Forms
Z+/s
YKb>0
uY{V
bzS06TwsKn1WSHCGUgN4joYHG0Y7
6 7R=
h}J7aq
@A+-p
lC<nt
:p2s
|ud}
e\HB@n
rZ"U
Yw&kF
i'R@
4 %|
~g[t9O!
}7&''
V#WG
4s>B
idy9Z
wUP&
I^Rp
(utY
sYA
|ME)
Klou
=!G!
QwHO
u$~D
Bi7X
};;JTF
X}"uju
FP4*
d2H$
XPy+
:_se
bl ~
kR8l
9ao2#];
P>Xw,
7C<|*r
L:DS
d>Rf
#$a[
T1sSKaM
UP#^ C
'M('nn
W4 f[
!P0d
Y#Xx
gO~e[
v03BA
y4o22bK
i9eJ
|b2>
B\O5
6q[0
VYW}7
>iR{
!8uWVENzBNnvSjsffYEfRitSdBsw89pWeA
:pg:
fLI
H*EH^pTCT
}$`k+
3pv3
2t[k
KBD'TM
)_}x
QkD|
% pR
8B[
IiWX
:ZMV
+4C2
#Y>j
m++|
.t):
Vco5q,
gN#C
kV vB 8D<EN
(%i
RYs ;>
N:Ap P
x_<v
; (~
^,8q
2 N`
S}1r
lV3&
[wK)
H&&tw}(=u@
d^( Gg
>_%%f
_MIty9
%A57ec
'WbBy
~,U
6 u9
20^ dt
2 "\N
9q%>
')%q
i{ 0f
s M8#
*G!6
ap;/
H^E-TNv
v, D
a,]-
mx [
2vZ`
K3MQ.
X zW
{4*f
%.S[
+MRC4
~9Y7
<w_E:
umymp
4yqT9
OaC&
Na``@
y|at
5Vjw
OcyY
/c_
?2WM
66w}:
#C#"
0.-2
"ZZx
DOOO
bYdJ
X*:.
k6;-<D*
D##O
Y?CGh
xw'@
O 4H
v8^8
$F2w2
E@e
+|qE
'!XM0
Yd@;
~PX*
1b2sh
+_Tp
7@ CN@
c4*jSo
fkei
&x!GWE
SNbx
j w.
E#5U;R
51a5
e~/e
<@ \x
4!B4|
QB[&
~[RQ<
K+?$
Dk
A+I+B^ .?
vU
System.Security
2h1*
eV@U
!(X}
X02R
bh c
@*xL
b*8X{
x$x(f@`
i*2
XZZz
typ{
dN$!
c8^4Gz
n&Tk a
VCM}h)
z3+i8
4cH7
X<;jw
'0f
k8%Y
KLkY+
SehJ
a>&,
z/Y5
<4qW
}S=5
0q_t
OHLd
xC(g4m
5alN/
e1SP
,a 4
yP*t
<E.{>+
@"/9
[Gy
555,777n999
<f(u
PC,r.qq)
;n-y
e 0(
hJW6h
VMY02
m0uM
:OMp
GOJ>F
t?vxj
W$4C
: #E
{h#6
1MM
/={H
oDU|
EWx
N!gC
Zs-Ji~
mKA$9
6Q@UD
><V X D
e"PCE
FL1Vg7+
*BNJ
AO(A
kn&a
x*70
XSw*N.
17Bg
Pj &vZ
"3Zv
h: S
X_.FX
)y: /!
8ah)
8 hm
[AFI~
6ESu#
@fBV
a /<
C/eD
ajma
Ce]B
ZOn]|
|Z/|
sW8qJ@g@
]Ro=
DL('
get_CurrentDomain
O`Z
_8q<
2;;
@m>C
{s)/
94j6oc
e2 I
)xE#-o5
-LOc
EJSm
W^;
=3>H(
p?D|
# =D
E_SN
= l~8
DhvrwA\p !uF
n>~`
b-uC5
Ot`U
E=Hf`
%S:}
PprF
)(TT
N{*W
4Tv
d ~<
Zky[
UR9
9 87BO
QgSh
'4-l
N@F4r
rMAR
XF2!
BP^B
[>f7
_ZZZ
YP`N
$)S;@T
I 5p
b"u&_
FL9h
R)1y
+yf,
V@}C
e{i
]'L9H
1l!^~-
m.P
%%%e"""
1 8'
opHPot1
{=cz]
.FFHY
"6]EY
uee:
F'?&D$
hb{x
=j7|`
Z%Rz
x0'#
LOLt3Evk8
QlJu:
"v2r
I?T?
{D]VL
;01=q|
5;X&
;NVw&
$c^^
@*]j
Htf+
_9 ,
(
^KGU
o2eY
_~7H
8\Od
Rez"
[ 0{
4XS
dR#l
V>4Cp\
w3acF
R 2}
|QD4
:*^Gn
;Pe"
5/d#
@\p(
"~g\"
@5A[
][/ \
mA=[M>0
k
::: \\\ fff qqq qqq
jUh[4
:y2s
lw(D
nsJ4W
r3:c
GF*|fd
9cu
];_X`j
aL;B
M]a4,
@
maF0
39,I
TM
uOh<
9.B
bG)#
'n<y
"U F
ZR%W
inei7
s[w_
\###~RRR
ML^l
0j;+
S`:WVCht
I ". c
SpG5.JT
AOp.
UqSN
c~bvn
s1Kh"
N8RM
eQ}7
\YFN
r~ 8\
r14(
ox&m'
WT|TzD
qmOq=
B?2Vf
zw4-e g
StE+
f\}Y
?S,O
ZZc#
J0P!H
yzvI
} nF
8\?So
"GWaV5palDzPhSOXfVjSZ7FCTxKqRV0WdRL
NXP3,
L9&\
3;kr
O%@T
eP5f
5x|}
;xYa
d71
=-\!|
:pFw
eoW,
6[o'
WRjx
[#-e^x%
T5v+g/
sN}o)s T
=="f7
]jFR
+`xS
tI6 0\#
iPXuw
$T? U
DialogResult
0B8}
y12?
-+qB
#3v0
NZ|Z
8"g
`%6
*`UL
-%mzr
:G+]
aZa0
%q_
{Cz,
9cOo
XrC ?i
~VKke
)j<]
$tB-
: Y^[
x~{ g?
)qoH
uc7B
LiO3&uX
/o8\
ojVf
;li:
fn"K8
M)D
d fQ
gw;+
<kw+
Q3sI
0"H?}
bNY-6
" .+
M,:
o &=
x\I[
J#bZ
4&QZ
,n"a|
uAzpfC"
bA{I
X1:Z
v`$
Mh\a
:vK}
'
% PF
/|sZ6O
~ WRBK
`dO;eb
o>?t[
2Lm`
<Evd
,@(8
bui
<](/
<Q_t@Q
s/:}C
o#A9
z@ N
o&y
gc&@Eu
cDt4kd
I.:L
F@LFV
Z-Q^
t9OJ
f>,N(
4cg;
R/;oJ
GIxt
kHgt s?l
dR _
[x]rk+p 5
nlr9
d@Tt
cLWm406Ru4UR8DPL50W7C2VOkjLW
Ka#*
(M._
pUG&f[
@7B?
G 6
{ r i b X Q
%4\I7R
v;Rb)
Usq
j DR+s
Z=Z)
3(fX
~<H!
d{&#
|G
mt:[
]l_>n
~ X e0
A%LCjX-
} jqt
b|M\
uQh
i4@}
;4a
eN @
J\<$
?1o%$
Z:(^S
yb>:
/(zi
~+ }
B+o@w
}V[7
d,=@@
+f*?
87x@
K~ Fg
/s5f8u
|%u2Y
I"VA
UZ_g
l;iL
ln%mx
\ A~7w
xa (
71I+d
rmC?l}
=G, M
|r bn
{\#U*A
\*l@
$D4*
"So_
x7=X-E
BA0&
029
V{eM
F4nE
FE>] )_
?E#OT
/=@k
]^00Lc-
T'?Ll
9|wZDC
`',=
[[[V&
i g>
p.Zck
,2 +
r9}&
M6\%I
*8a+
LvTU
>TIez
Xa:7e
6MMk9
o~bJ
uMtM%
yO `*
Xp.}
V+}^
6:T|
HiOA
rEZ?
lsKdk#E)
i`e%'\w
yhY=;
zL\7
KrdEg

F8 =
:+ #
TG7
i~CZU
]!svf
2 h'gk)j
[-ME
> Ja
NhF
RMF/
G u5
vsN#
">W
V9sY
v{SYj
~'4Lw
<RP H
|Y|e
BA x
1Xxk
oF>q
b%}j
;lQ=
:Rd02~
,;P4
lh Pf
N)Jw
%SG!
>+xe
vQ0*7
`] q
Wc w
b^U!
EPDM[
3za*^
FABz
2It52
r[?(t
Ccpw
1$v%
Z'CaP}
' \ph4
I* b\
k$|"
q>cF7[)>$
80 g
_{3/
#ik
q^D\
5[R,
9U`9V
o|`o=
1T\e
uZ%pC<
1YKbm
' nL
`zeB
?9Iwg
pXWb
)[t4
5/IA
x]
=r(%
vI\Di
,J?m
k3,}
a}]
~H,q
~b$
.@zisS
%}6'
nq0c
>Lg.
M/"L
gJFd/
Z'w
WrapNonExceptionThrows
]3tr
y5:[
,1ke/
p#7lvN
8zRoJ
aY8A
A$i<
rpQ'
yWCm
]H XE
M6OXO
Gyj"m
FuBy
0C~n|4
|. ,i
L6-A
AgJ+W|[t
tS{Q
k81N\
{)/j
@)xXDR8C
@TJy
\)lrF
lk }
VDAl2)
Rk~L
~ue+
>>BU
hH*a)
9=$2
=fTy
}Oxz
2=w4?~
s$`P
4~MQ
29\"
D,5i#
rq#9U
FdSJ&R
WT?[~)
Ist
_YlN
~1'jgnaes
_lx`W
8xFU
dn|_
U4N?
hhhxbbb
!+c)k(>
#% v
oSn$
f$K"
7"Rsv
S?c$au
333
dm>w
aV|;
%Gk:
:4c
SYv
AG*9
l(IY
Qel7d.
O"#b 9J
N.3(o
'O i
?l#>?wC
t\]
S"K-
~QV&
n-H[
ytvv
_l {
Sc[Sv
/{7B
K|lks
c['i
=n3 mPWD
(;mj
U2|Q
?)eG
oLku
UHL2
LU}-
h9hqM
V|tt
:dc(
Fcey
U:|<
Rpa~
sdE7
9Wle
Qi@
49o/
c7D%
r_Ll
E"@!
nxJa
!oGrYSJPCevvnWaZBF3S6KZ3Pn4Jz9s4p5
Q^!iJ~
{!OC
z=
0OG7
4eXqpv94zru0dZswMwrikG91PUH
OjfH
e&_I
P'%
Bb}r
l%]9
*;\5
ovyW
"+km
0(%N
G%bB
^78(
8v{u
*N?\
EF P
p?2NF
|D#Y_
[kQ&
+O"<
$MQzDd
4Q6$e
3V|_
\UMD
gw)T"
R"+HLi
H</b
bN]dW
Ur_2
20%y
!GI_
^hSq
DWvJ
)e*)
7n,I$y
#6-
S}N
411m
?"?
ro28Z
:r1J
?A8j
H,!}
2jVo
|?q$
BSAo
*"w?
Sd~\
fNiD
9M,O]D
!w?W
D_y_
o,jC
l7=6
pSgcn
%8.!
2I@u
{' wI6
]3Yq
qt D
R!KB
UUw.~H
Zr ]
CAWk
E-jQ
4|gc
'KE
R5oC
!fJ|
elz
}b7b
k#nc
>B m
|> |
m\*1
5@~h
q#dQ
(((^&&&
/Ih _FI
dw9s2EH7Xw4bPjtPe1qfb
"vdec1
~5i]f
vNeyQ
rg{&0Rl
ZfkU
(g(F
`J^fH
j76O-
(1&DG
gzhl
sJeINzuBku6G0l2JW2J3r
o2 4+
9y?B
CHE#e
g<\&
gb 8x:
9e?d
gn6<y\
c' o(wY~
D !Q
Qebw
<hor
G1<<
s #C,
0^#c!
re%>
1sB2
9=NH76[
E%gUJa'
dX,oO"O
___3
#N3y/
hZi
6 F
OMM]
\'(2
)pt@C
:U{+GsdQ
#r`>
B: E
_yza
0x~:
zI[ +
AOr>
&+ _l
GO#A
;Yi\
/KSiX3A
5tb+
N?Y<'
LLL~GGG
q7>|
{1"s
4XXY!
ko2z
DZ/:+
s'9CHy-
`+
6SM=
7[d:
*J@5
fzl44J
eYH&
%&2G
>'pC
`1HA
is_W
>FO2
:P (
?ctY
H'( />P^
1^X
7V:1
) ?}
#8peX_7
kE'o^Q_DuM0(D
0k>{
$Y2l
22,xi
|=;='
3=YJP
n6]A
43|(
jxXq
&bLt
RijndaelManaged
9_slk
EIu
,y*yW
\Dd,
E5N2
zkB~?
bh Cy
.undL
3F5^
*JvU'
EHR5
Pn(B;:h_3
TUXA
PM-'
< pL
ujRk
F. |
"Ny6nEDeq8rCukSukVAh6RHSXuqsp7CCUyo
S^h:
}ow;.
o
)^ .
co}A
.!,J
{Jvn{
&Z|,
}wA
8tK73,
Ql''
%>Q2
{;Uw
HRh5
GnWc
L5wl
W1*<
H!@~
c Ex
c &sN
m6W9Fe
6 M#:
;{V7
g4@uco
;:k3w
b9H~q
bkK9
%tG\lX
X.S 1
NcE|v
O :^
(I]*
OuE$
EeRI
s0KV|F
YRa
32TF"
P "@
yzf6L
Q#R6
de/S
M6R0
I/ a
0K-k
{dzSK
#YM
p*M_XsO
X8~n
]]]8w
z2i[f
fPg.
Xrpu
v54J
#g @
SaKg}
0<l-I
n"T'Y
=566fL
o?l]
-ToI%~
5P\l
Mp=P
Q`h
I{C83F
O JH!
_T4E
j$!*a
:Y-"
#-K(
3+[r#
rGe#;
Mr6k
[\&g
7#1
N?>"
>cx:
NQB4
_-Pi
)qR
~Pxc`
0 ,//W
p]W,L
> sD>7`
-(js
Q2~k#z^
_]5^
AdoM OA
YUU.$F
srG^
JE]
guy$
wfob
Co8IO
WP?T
iFD_5"
8/ ~?
7"8-
m #F
*~]K
`1pV
mfdN
}88Vp]C
nh!6
6'"bA
j13$
hooG,
J+("
Mq$0
?UgS
oPS78
( =KY$
t54f
{P]P6@bf
Z>|*eh
SG*7E
Ct^'
^ ~l
tmf
R'.ub0
8jq>
J"j-'d.s
^x_
xQ"x
K<J;
EO9]
(*1d
m2w
3=tt
d1EX
GX)P
__pg
~NVev
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
dX1PE
Pz;7Gj
OF!5KQ
20N<
{[&gX
/"g(
TJ0&
>1$
_DLh
}b(&5
/jt*$
|M$5
k89m
4M1i+
ep9OI8
_&7'
Bj
oPZZ^
|)rcO
~=0QP
@"+R
E `p
J_Nj
1Ho?U3
Jt
5L'
92Z4
R.gN
b$HbU
utHS
IXk_`
9TVlz
aa"=
` `n.
1#:8@
zUIu
qFry
1mG
} 5Ve SV
MPz8
Fy5;
_?;u
QG`qYp=a
!>WE??
kM;w$ 8
>fz84
J5v3
VRh)
!4E>|Dv
C:D"I?
*^z0
*) b
H|Qpeh
7eF}~W
"o+Z
3!!!.%%%)***$/// 666
4 `z
./yi
]GDE
[O?:SE[
>3!K
: *+
8 l|
cp<F
hZ!S?
?IB7
5XX%qAD
hF<f
N"oR
GT"_(q]
ICryptoTransform
Ja}f7YZ
(:$*c
l\O)2
#v# }
4)86
0qJNW
u"+
j.}w
=S~z
D.5&
73BCc]-
Bi2";*
1r};
cEkj
%jO?\
nJ9iy
rm8u
ln7s
wW4O
y-GU
=9L%
e$KN
~p+"
58yZ
"wS
.""
4OX D
:<1 xT
Gc.d
TiA?
Z}d:
O*8
rS!3y
2%QD]rp
t/ u
y5yG\
98S.
Ye2y#
> 7
Yl&C0
S9g+
Kc\O
D H<
T^n9
m~-1
=?.q
)y>G
/lSH 7
9G1h
t}p
{h %
^VeC>{>
4pT+
w{;gu
B7+l
<c~d>
TJ, "
vx%M
,)csS
|\ @
(&7g(
9 ugl<
VeuU
N)kq
):c1
3hsb
eV1i(
> T
jts
AUL
=}Vlr*
8A*&
+\R7
6@ ,j
xu;o
*t`Pp%V;'
)v mm
ViB j
7 JU
H+vc
$ m:,i^
u:K)
oW_ DG
T_t#"?
\lG|i#
gG/a
7]En
Ej=c
stH0
Jm;BF
o,Io+
64BxL
N15dMiqM0yOIZiNJi9RCUYD1wpt
j!j>8
]P z}
q^A+
v-[T
&W=W}
nJ.7
+L=7R
l%#{
zdR
>]mv~
~Pzfx
@]Xl
MG7F
tE`K
<i"E[
bz.Q1Z
+qzh
3V!C
R".'
,0:.
-4iT
![Tl
(sqj
gLXx
W?: w
n& S
!d&9
t@B To]
:MTA$~
!(d
W>5Z
A4q
p777
j}]Pqa
}Omn!
F3'2
Fdr[?
Nam\
?A:P
lhVoamtFF01j3sNLDSckx5aJ
|!D3
o` s
1QU,
PeG>
l3Y[
OZZ-
6wn
Z g* Z
c@B
o8s1
E#:2*;
}A!#
) Z
'/m
rLH%]\h
Y[yLR6
2k-s
nx07
u111
wW)|
a:f
S7tR
y ^"O
Gf2l{
"9%=b
J\p?
XckCo
$J.c
@<[Tn
{Lf'
vi}L
"[~N
+c:y
!3<Oi
q:T4
)c>T
@D|j
GQ=n
V:Y(
[/O'
y`l"
H%%%j
;H {
A UN
)/dDl
UUcvL
|"h
Jb5R
'1A9
#3~4
MessageBox
!y=z
rW6}
J8{4
uU;13
E<a: E
By-A
F+!-e
(Ne/
v<v[!
YRig
]`)
uipE
#g1EA
*CPR(
)Nf
Qj3&4
=9S1
t fN
%?o?
RQJOJ5
%85
hbOw
fNv es
aj1E
zTvp
]]]bz
4qJ#
58ei
b*e j
w-\ww
Erf3
7v?\
\DfM
I=3
2iQ(O
#;0
9{6?V
((v{
%H>=
lWrJ
iC}'
dnG0!+
wI@hww
2e;2]
W~,{
)~8tZ
P]pL
HJ(V
&7DX"o
=U^+Yb
,xsf
{q:KAI
Jg(E
-{8C;
,,,
fGdd
]zWl
Sq 8
;\W%[5
bdX>
gt`L
. dS
,\TvD
-xN4
cS 1
OPtx
(fy9
31R@
%-
`wiA
nK&c
@IJ\F
yvqy
<oOM
ICi 1
~]N/
RxhY
$'nyyU
mP]<
2ezI
x;5^@A `
}M2lA
t[@U
($$$#***
KPV:
X\\<
s}qd
'Q<
_s*(H
\5m.
R}Yg
LMM!
GKFY
#*t8
K(c`
fPe@
f+j*
4CCD/;:
YjD#
L9: |
QuET
%"m>
B&?Z
iM^,Q
,(KA,c
G~Bl
q<A]W5TL=_
Rhjm[
8QYVo
u .g
>V)r
/F *<
@_Eu
bY,
}a`o>X=>
pLg]
1?A]-88
XAR?o
g6c=
F!8
sVU9Zl
q7pE
O~/
-8a I
U$+<(
Jb*A
9(#[
;[no
$ygk
C*>(
L|3]}C
2 5M
KJH)
3?to
D]+?Q
(]5Y:
)#]G
{)S D=
Ze{U
a5c$
]itxz
}1wR8
Tiy]
48T!
cmA{
CPs0\8I32
AZ:K
h,`M
elRj
e?DX,
'nP!
L[">
PKID
~dC&
\,vr
twMM
9Q3{[
2:0p
Sa]I
|(:{
b#`DNmK
^{N>
oPcf
*pJ ;
X^V@q
2zD|mfk
j%[\
nbuh
uxP]
#8&
< 5 /
,y|6
&4L0
Dv@R
n-<p
@fvn3@g
K@pb
"[AO"
zX1~q
Ab_&oo
G:l*JV
5`aI$y
A@Pfe
y o g
.-jB2
>mTX
bKVru
p?4Y
lEZe
4JX6
z!9 $
(7Me
F=W
xF/c
%lx+d
Fb0(
xCS|
KN,h
er[0
)Lj
~09R
0@ *K
mIL#
\yn'
8&7J
-???
{myy
}U $
"h9e5
mn8\r)Nuf$
PEc\
O~!!
}t:3
TNfY
4sAr&X
h1rnI
^Y'C~JR
Kfp7mtdVm5bbABJQMcDjoLslWQ3e
f.bA\%
4yd19Q$
b_z}A X
Y3!J
e Zq
gMT&
r&f)a
vK(2QP
==7MB%
uEZr
WIy^
m;^*
OA-j
p}gq )
#~}'l
V-.t
t,C_@
"u?M
.$t:
=]lN
PjRN
F kQ
A]|j
|M,_v
x,/_
g%4|
_'&i
%{L#
{CCC
x{I.
aG>-
3GzX
>L uQS
+!&R
-)3fe
]E;+
]Zig
_K7P
X{>`
Jp0x
{ I %
3DtoO
XQOQ
O}*Q
|>NT
voV2
#pgg
Q>~g
<0CC
Cu"a
TN7 d9
SX;#|]
QU*$8
4Y >l
MvZ^Q
AF3L
{Gd.@
U 7~
CMTJ
%^nE7
90u
XJ(V
)no@~
=0HO
Pe!Q:
AkYG
V+l,
L#,J
OI7O6
o*|2
]I9p
,!_
b~FZ
xtA*s
^6dplk
9w`lh
[8A\2_
nr>T$t
]l_M
]>5(
\&<7
E.hj
gl4+
6J+4q
yaU1
=wu@
4O61
OA}K
gz,]
7j>a
C#]W
Z~<
W'FqW
ivU,O
{3$EI
~- O
*H "
a/&E"
jse3
i\NA
25;L
tx?U7
Jx?
!hdt
|0jv
mY'q
bqVV
vl `
*NB4CO
a9QEeF
gIM
sHu
:QTSq
z3;0n"LY0
3 hC
=>!5Tp :
{{P=
z_Id
WX9;R
~$ 7
7{!+
e!w3
x@;Y
|l
C-"H
UQCx
!*@=
w~1(6
eak*
+v%-
~'DM
8+ Y:
eazz
i ?.*h]
i?jTM
er~C
K6.z
3L<~e
YP[s
!P r
Fwzc&
8 {,%
3_Z2v
E*W?
*UuM
G3>Zg
Bde54|
C{nr
'/>
Un0Q/
D|*N
&;2W
5:*<;
7,cT]
? |n
Kt$e
;N:x
9kXs
FB.]
5oCue
Ytc6yy
. r-
}N6}5
pdf:i
#Y Z
KY(R
10|c
|u\k~
?)l[
!k %z'g
k'Kp
wg+FBK|
`lBF=
System.Reflection
_C.q3
'\J~j
,2KV
1f8{dG
o+UD:
GL6yA
c N :
oV!
="a-
nOh6`
0w]iR}*X
?(R
ss o#
53%(d
,chP
{*5N)D
lg)ZC
pWbSn
y- S
sXd9*
"?[y
,Uo;
^&bR
!&rEX:
377"-
$l:
Sb<s
@gn}@Fr
&l?,`
a---
Xno!
<W*&>
tU0^
h^+xc
nl:()
W3+b
_ Dp
/-^|
TQzvOPqZxTbUUUqgaLKA
R+|@
,OKM
]!0x
Qy r
LV&?Z
@ R2
#lxP
kV)Z
jkx
_@j.
An/^
&d>S
cm>6
pV^E
U%6J
2pNx
TB}"
lAP,
Wua/
_}zPe
:Octg
9(4f6
j84
x\hxb
56lE
H0 ]
J}86L
rlB)K
nUU\C
t ,7i-g
lpz{
.t{xOD(chX
@1SaqJ
kxkytw0eLkXAsVU0hD4bl71Xgon
,Ja0_
Mv=E
wKV<
a_,q
&&kq
i+8}
VW1\
~ Ek*
mZ<p
7tt'
QkVaC
9T*+C%
EfWz
? c/
m2l7
!~$c
l ^R
"-i
NL&N
)r6G
3{v
i|,&
;:n"
*gKI
1BX+5
Z[+7
9igw
/u p
ey;Ny
3YTv
v+K+?ME
< p
?{75
:eX
aq$)
Eagu7
\f.D
s<M>
>V^d
}E"m4d7|)
')p[
. \O
XG ?
Fz0e
RSI'`~U
NVBAWB
J`3cX
xH_@gt
3,|
0!&8w5@0}
mtg8
ljX
/sIQ
':P=
fUH @t-
HWdZz7p6EMriIvG8g4FexqtI
FLEK
MSo
jr\3C
a*8IcB~
~/Uy~
S*+-
[{/V
o.(%
Zu2{k\
D@DH
xbvQ
-C3?P+
t *z
<en
?9&@
#5R
d"-V
=J5n
nQ$Q
pA(/s
4mo}
bdV{4
83^q
[ T M
K `J
GE m
/u:}>
M1fv
xDIqC%
8Q>\
''' ???
j# <
|?L$} 8
cXom
\+30
CoW8}
JJm
Dr9r
./ZZ
x-\
J]V.
Zm|)
U9b7
-CTX
{JJ f"
>5[ yc
]v[H
rBz#K
:(`2
T/0(~
E\YG
9 qf_
D1Xn
ukQ
+ 'hU=b
Jp~4
4z^R
iZ9$K
rH#-
Px]
awwV"T
C zn
\[]]
a+D}4
-|T
O3>:
{8 v
bt{w
d C]
ADj1TXgts1OUsN6z82FSlvOxzju
wfV9
Av2g
:qak"}
"sh'
@;t,
cp<$/
!)b[
xTT
as'!mX9
9bh.
dD>"
M=GhdD
jQ?$
zp4Ci
]j<g
IIIB
cxxX,Y
3Um_
Z!tO
t)lV
*__ZY
[u?q
)%2r
H@3d
as<s
(EPg
fk}q
/oJ[
yP=Jg-
2HBwZ
z~7*
'"cT
_lR/'
"KPE"
z(SSg
32;AXW
N-3k~
;YcF
Z9SQ
w9#Y
88qR
J>dH
pwx!
^j`t/
_]<
RIhq
ldDc
G _:[
u:zR
3(Jt
YFm
*w8z
_Yo;r
H`%y
? 9
cyT6
LLVmo
g9 n
&yUi;
zRYj&
P71N
dR0?
%(Oa
/Z^x
ZXZ<
Na)m
GUVu
f2&@
]|ia][
l*))
4f 8
K L$
+1}
GK<8
lHX$
:STey
(&w ?
YP`
lw2WnR
{Aqfc
(lm=3g
4Zh8
K*Z@'
b2!k
=>!*r
8 jp
z`!f
>$ |6
=ZM[
X.\j-
o(pP
yx4;}k<
~1M>f
KThoT
-W"=K&
x+^6X
U\!J
IfA|
/.%{
`#j
D}jN
GhD?
kKp
rS ,
LC'IH0
7fv+C0
@vch
g- u
X?5M
Ia -
s} p
wFV[
,cwA
0 LMM
@2#e4O
w(pO
jgR7b
Us\x
. _rJu
XbemvQX
xqSo
8Upky
rGv-
}zyo
0+f7g
TX] j
(Z:f
my/C
.V%(
x6e
T Pl?
5u^kUz4
y@E/o
'q\1
d6we
*F|FC
xC3n
i6q \
l+_}
hK=x
[Eu i7w
,F%x
9fd
1 ?3
wgd@
@r4F
+N
]6pP
$zn]
L4OF
.^^P
h@&]
O'K(S2
wDyq
g!bb
8'(CT
Jl*S2
woT\
IOJ~[
z?{lvs
J~.jI
CyMsR2
4U&"
n}?TQ
f) <#m
D$d+
nfOd?r
yjlfn
70=i
,{f=.
gd\8
GpPbj
'>+.
7x>mq
<1Y1
c7 ?
4bd_
WiBR
$;c`
"f?dE
;^ f
:rjh
Gy&G%M
DvKq
/\kXp
%84w
0%rb
A;&@U
C93(
,&"a
?Xxl
D<Hb
y'<PG[
?=w?9
eG p)D
s()_
]SGuC
'0 O
q8gJ
kW #
&z0<
(=YG
KSsCb1
GZ:
p/4~
hvSj
{n}u
sK>+
q.@-
A[6o
{w':
Gf e
+" 4
OMM)
~Xhq
DT.G
XE)O
ubLW
/XC;.u;@
H5jj
;cX%
HDOy
|=a8
9=}"h
dPDG
gPIyNeH
)8YL
/\!
adO0
+ 7F
I]]n
fDFD
["9h
QTBo
JMvy
r/=!~
9}N+
0`d
8PsL
GnCV
e{;L
"D`3
ZwM]x8
b0>(3
(UX~
&6d7
O/ B
<DiDd
T(x%
EEE TTTsJJJ
"SD-
fmJ:
x)Z
Qr7%M5
Lat p
d}:2
X /j
rV8d
#n/`
.H(W_
M`d17
JwD#
3S;MO*
oI-|
y|)O
=~V<
$ wh!
yo<+R
q} S
\=&x
_V%%
5WA
3S\0
4_Hr
0 H{
v1k
IDATR
K|(
$_km
DM'
fn:
oo<N
S ]
G4;_
v0xJ*
J rXo
<4 H
_$>f
F`?H>
Q%MM
2, nr
HHHF
1u`d\U
dQj1?
yFAK
aSa*
\ncW
|#.2
_f!M
G8tB
DC b
@@@/???m???
w\(m
Q 2
ObQ;
*S&g}X
YW|94-
RZ '
UKx;
R>Q
c-\a
System.Resources
| $m
r-*p
?!Z
mJo5
|d H]
t>(HL
M )>
b)n8
II shz
d;NAR
G@OLqQ
rmK~!
QgZfB
kP2t H#
'*Cc
(T '$
dC!
8f_Y
T3'u
SRw),
8] p
U| "X
_L.^
U!nu+jHLS;56
E+J4z89:
&@.3
<h>oV
:tT(
/cI
#?fN
`qh!,I F
jdo;
vS:IzE
@]gz
A%6TiP1
}(eX
3R_
9ieU
@B}*NM^x
f LO
\]Br
!V^2
$~; 0Z+k>
>VX
QHoB
]84HQ0
VzAr|
64 '
ESer
m>EZ-7
kXU9
(, y
5]'O
k6*Z
'IUR
vmmm
b6? 0{
|%\s
SFCB
sv .
/n|:
\:3l
, !&
x2`c6
i)`*
~2V#
Q^G:gLo
%Cjb
XV%k
: ;
P`2xK
_rNP
[_Ig1
RQx$m
UY E=
/2s+
*3eEBO
jm!P
z`'`NP
U 2X
5CJo
yT?K
.cA5
*8iH
=}O
+ S!
s $
M uP
|MIu4
~)}2 O^^C
2'ckG)
xJY6
D!810
aZY
Bc{6a_
aZ$ l
.K26
vRoB
LXdW
M4E
J[!Guj{BH
A6!I1
}mtZw
>11
ke5q
}V#2
Re (
]P]6
nS@[
d<z[
j9q
dPqC
&38
Yp5X4
_fiB
ZqvZ;
jWB~k
vy5v
1U^@
7%Xm
>@s1
M|Pc
~%NA
+G[7
HiwA
;7H`
nQ}G
3(V'
?N,4
9->q
E!d|
T*5U
#4]M*
'4"
\.`W
]y q
]H-)
/.p-4
GJ'.
-rN|-
&ehK
n+4v
asSaR
mBVp$
h=NGX
A#_*!
PDgb
2m"r
b}"@
NM#N9O
pM<Y
fyuC9)
;T,+
I&^k
//// BBB
&fff
*b|n
32-nv/
d$F
<@B&
t gp
K /
UaBs
&knBRwFnnWcgxF0vS1zh0Z8gOkpy7FXcoACZCoU
(C ;
p7^B
c,$<q]
*jh'bR
31'j0
CZEb
`z}
91!cTAN
A c3
;oIc
9gbM
Ht$ e
Br8>Q
vr,|^
gJzr=7
lJ?Q
~8:G
qv@P<
t0S0u
%z9'
+<i:W
A_m|3
@=$c
_n|Mj
\jPjUfd
qKj=
. W ;0
v L h
m\@5
.%?Z4u
DJXtd
D')4
koI3
'81;%
&GR`l4jO
]/`R
yjf)4f
ccc@JJJ
Q;q
*3\n
WauS
sv)
yW04
Y+DyT
Mw+:
QU0s
y]{m
"4zX
VNz
JH
l%{sr
. ;S
Gj\o
I6 (
w 4#
<onw
jjj sss fff
[[[5]]]
l6kd
3wg
=LJ=I_
iR~nc
7\!z
]_%Q
'$;y
)5nC2}
3P % r
5m8}[2u
3/UO
qM0U
ckS
L eg
=/P0
{" k
E#&!p
=V z
Y,D9}
/.'&
! N
BZ=3
%c(.
h`6n
9I["
:^0s
44bE
x-f-=
O&-<l
iJR,j
/0+4
,r1 V!
bBjj
p!:U
eO>?
a,o-
QVg~
AbG
M+>?
NE q
8]Cn
+t '
)s#
R{\.Q
oU#O
]q9_g
#UP02fkQLIzoPMyqjlnJxo5jRx2saS3Qip6Z
7> S
fQ?(md
EEE
JY[Y
4l$x
wEwwc
}9c<
<POw{
2] Y
ee5I6}
TQf`
m! C
#VU
<z2?
W0,h
19$YEp
^[YYy
Q9*#
+CVH
61it
,%6
O>TJM?
hcv,Xv
9B])I
FP55
)[3).R
"6M"
AD9T
b j
?a4[c
wp4U@
lb],=
OCNV
.|lfJS
;MW
G.@ ,UB
111&---i***
cWv a
T%v
'''w###
Zv0c
^3ay
,Sqm
e KLi)
i66z'
4E/S
H'J>C
ji_5
`'\
* ?u
7m;
2DH8
ew&I
[$&e
|=
SymmetricAlgorithm
xVQ
}"]:
9V x
Z"+Z
7UJ;L
*!!!&
m" h
[?VUYx
USGaZ
hT"1
gW! b
&{d&a
zqD
,q0~
[z:o6;
%OS&
OFqk
Q ;=B
saWfu
Gq$)KB
zp9D
6sLj
i#JpLS#
lllDhhh
e^F#
|"Qd
ub@iGr
<;Ud?
j| E
QkYgNvqK74tXyFBeW11YQ
^Lxst
:ai/
e?}
p$#9YT
1/RlR
/`ht
yqPo
EXe</
P7<Y^
!1{aW
v*H*H
$qvjmK98GsgeQkgyjV5w689o3BN0Y9dTWlZz0
^.n[
:X:[nI
h x'
V0TR
{=S3
=ysidYdv
Wu2c
{565
stF"V
%Dr[
J[>V,
&Dhs
G~-,
.|i
4:l58
XlB;Cp5
`uXo
.49z
#rhU
c!`15
lfdRD
+$>
} YO
(ZI
xWMP
<:n
iBh
,s>]
t=cmO
Z 3y
PT}%
tph9
>84K
<b
w~$D
aaAq
l'[p
XQ1
ilUUB
d13O
{VV}olX?`!*
L/KI
#x#@
?GmJt
ER~ /
"D\+
8\#n8
t^/6
***
^I?hf
qy9A
o]>EY
:ne
\ D=
Bf){2
R-A3Q
9dO}
B H^
R0&z
Z=i3x3$
z
!;q^
^WIf
<adR
oKI'
Tzvy
'M9-j
A?zX
yts p
x&j-mC
jR-J
j~<1
tVxt
w,z,
H.b>y
F%-W
""", q
>?5P &A
}l7U
L/[sF
X>:B
^Z~UQ
Qw]ci
}aV&
Oan
o|}u
si 2
\ #G
17$A'
/]2l
2_B
d/Gz'
y+'B
P4eYT
@|GqGu}^
### %%%;&&&
LET_
rGj BFx
(]Wu }
31HV
$c)B,
r*Ci
{U~{
I P&
o~ n
&cabt
xg,
|H.L@
6 PCr
e:Opx
^ ;
)s ">
pZ6_
,B/
&5c;i
Cc"x
,dl/
N1Tf
EGsX
U.k~
sjBx
7$1[
3 q L
XBDq
Jr3^
:,S <sr}
9 Fg
~3,$
XRfA
kAb(N-
N2Rp OKB
Q8PDI
@@h}@
r<f]M
(Awy<&r[?
W"M
4 @Zk
V|L
l_N?Z
GqrG
NF8U^
h5E>
q3/uP
<a_z
Uz
l<v<
DeTef$7
XdaL
rjo=
&+$b
(UM
:D C5
AddMilliseconds
Ub<w
e+3Dd;2,
v2.0.50727
Ok|\}
f`-x'.
!6.4
d p<$
Fn*V
G)cK
]aCNJl
35 R
Japp
xby_
LJ,`
CDfJ D0[
5e`A
)N| 8
u_Zj
WIbu
K9-h[
Y+2+1R
17$;
ns0Ou
8R%a0y
&*zc
=gqi
i<P?
#d*Hi]v5x
h8e)
39P_
['jSl
gzG6
WF`
RX@hj
DiOp
z'@o
O |.Q
S 5L
la%~
JwBH
]NbC
qVgV
_U!^/U`.
n}{3
BW6<f
N$=W\
xWu^'
,"^i
:yPo
TBBvrEDQNmYDMSxT5LAPCGyHDI
Y}U }
P3Y~
CR@z
\V~"
NWP"
A\Dw
f]JU
y Z&Pjt
NNNbxx
VVtM\L
$oDG
S!HvB
x3 7
?" .
=Dgjv=V^
PTB#
} &Bhl
2?At-;9
f ^ V M
*R@r
!bY7
*Yp5
PN:$
H4$Wb
Oa</|pN
>Ha+
$+m!
C*4C
U~M?
}kyP
qi'J
@ .
J2T>v
${z7
I $i
aW];q
G ~5
1#"
w]y(
IZZ-
t&>HJ
5&M [
Of `
YS )l"
04lv
6S=z
,Ib~
@:R! i
=.Iu
<H)+
[{ V
|eceqk
"Q;%p
mhP+x
& '@
I:_hEy
:ts(O{
W7\ $\
~sr_*
J l+
,UAH
D,QV
q[6o
*I3?
a-~tz
Y,xK
D^,3
3%At
pDjw+
;YB\`
wH Q
`6={vcW
Vy#
n +7
=O (,
6H5(
&`5u
Z E`7}A x
PcN7
rE*_$2n
i; ~
jg $
<]^H
bXGyF
Ocuu
Z :n
HXr&
#dU*
v/Rb
0]=
d=b
<D5k
g ]=
H6$M
K}6Yp
z!Jx
Bda/f
k46Ent
q&i)
Z2&x=|}
b~vG
aC2d
VSG@
\24J
eYlp
M65I
-^IbI
/uk,
S$ s
fW!$H
Yp_&
!bhK1HOiUqwF3BIfSd2P0iLNobWA6hc9Ev
k)q{N
TransformFinalBlock
qI3F y
J&+A6z
m 0gL{Cj
-4ffz|
)\Y
J<zR
'Y_P
rf.8K
|SBvw
sAcI
vcj0)
T/a
_ {B#
8mRMN4NjHjBjBoOJ1mMVUc8inhCL
YN!)5
rzWf
iscB@
76-B
b Ttky0
_I$7
pH;<N
<D@R
RnD:$,T
FB!m6
#->|
%B[
l~eU
l6i
e0$Ox;Io
}QX
E(xU
1lz*
9AYM
+=`/
S*Ok (!Y
ZcZx
}aL)
tVS,l
1]y4
xnk9
z&'{r}
2HpWN
<vVo
#";>1
04q4
ouZB|.
T'zl
Y-WY
j/i~
\!1{
DP:x
sit;}VD
% `+
.#U
=vOc
<Y{4
"_D
8J]}
(^Jf
L+ z
M&bi
aF~g
aST.q
_= R
a:&X
B+RX,
r}mb
L}>9h
NEJ$s
@D }
7y9rju
pVr?^P!
$"]B_
)alR
IR7;7*
<2<<
z?`I
Jn)Q
4l$)
K QhR
Z TGd(A
76ol
(?r7^1
X_~w
DMYcA
$-GM
1yL5+
^yU9
'}'3"
:NaOo
' "C
xIBv
%ywX
W;Mv
^avU
2?OC
OE^#
Z9p5D
M[-i
xv>5
'~L 0y
-t
jCcK
4CwO
n#Dc77
xxxmaaa
J)mf
+YsH
6lsN
".Z@
?pC,
{Q2~M5
)r
R+tKvf
).Zy
{*+#7
$|Va
h+ I{uT>
gM9' H
AemfVtm5gW5d9XUY4S75Jb
%I@o1
n]C6
vE.L0
.aP_i(
M=<?
SU1t
{ Q1
F]B`
`k Id
%3^`
&c8v?
0|$Z
"um9
|F`}MG`
UWTO
2*&W`
J_D'Z
q0kH
TujY
&rDG
hg}?I
C[i
2I>|l
!Hwm2BGJJoMMnKslExG8B6xoky4eft5CfG
QV 5
/&#P:
D r!;
*h=&1
NXe;
X8Ky
fo.S\
+g&\f
R1=,L
='dJP
7f(_
}}2z
4VX-
Vq^,
$'L<
7VI;'
KEeY
{hwz
_.zKn
%9L~
WEcpNoUtE0MGrXDGG97E
_M&(i
DD!8
>[)e,
}0(j
S!rq
mI#B
{2>IP*
ml~[
vV[-I
R}{"
H)LZ9
YT@jIP
2ogG8XAoCoEaA4wCuUR5eV5vQ6m1hGzF
s/_]
Z5d
UNdV
> 'Cv
n2zx
y tPV
t"i$&,z
'd+M
o<0'!t
m|`\
C4y4V
)J)!
K)>{
i /U]
Zm:-
h<.s
###6 z
86wc
.Y2!d
'54DWcQOpzztzuTMQsM1GFlArPhq0VplFSYMtz6T
Vv=N
hd!p
72J[
O;'X
&=eh
P6!(
T>|`~
9wm]~mp`
*8OeilH
`LR{
t$gW
Dqmu
e*1~
q0P>9
4i"7
!r:$[AX
"15C6
Wmm#UUU
H%P?
MW\v
HA)\
M5}}H
r%3/L
vd*_@
... 888 HHH
GE/ m
gSmt
hAju
h\cz
K,(AE1
: {yX
8<e6
/Y[g'
|-7
\!iZ
u`-%x
VVVyAAA<===<???iAAA
H` HQ
=>j.
< cV
&) A
(:"=
iw '
7d~l
[ H0
m'&r
mrH
Ra
dg6Yy1
#GqD
Hv(P
~Z#5
Bli`]Xx'C
K`B;
c1 ~
cIHNc
~-E?N
q70V
H$`Y
{L
kGt?
s=\Ep
J)5d
/!2w)
+ &
Pl!hu
Y5Ue
u%vV
e$kd
,vm(
Ig9F
ob\=N
D(j0Q
=X
8 9tnT\
~sW
e>'g>
>keAa
)r(,
Sf+D|Y
J \?
gms
Ni (
>9[bI&
B`Vl
w\Y3m
3bf
{u F
]ezV
x<{
}&a]
/=RG
XL}MO[H
hUF-bVEv<
&XevU
Id]U
`/YY.L"
~S!a
eQ!
[^ZV
kJ[R
g3 o
]5bL:
PdL;D
y^Tn
!TDylLdvT9n6ezyrsKinY5SMXwER49JAtq
h=sx
~ !A
CcMQ
UUU fff qqq ___
PJU{
R@krWS
G *t
Y)T
G/CZ
*EBa
_.k2
{_7R
Kc@r
f2dN
%12[
OlDx
-fAi|}J
>Cw|
Ns@wD)
: v4bzg
x{ %
g/S/
\I*[6
d.BtW
T1CV
uk#FBXQ
9\8d_
*J2
/? U
fQ l
e?y]
Oo'i
9)D
BW&+
o`14
(-[<
C(qqE
`rI%T
zP
Wavv
q>j
5VdY
ZX {
+` l
GTXsD
=2S;
Qg\I
}G<o
wX#f
F^\eT
w<r O
29M>
bD+X
{itwp
TfC^
4l4Y D
24xz=7f
)4TC8
tt 0
1[b`
kh^V=
Ah^
*~g#
aof2XaV
veu<
q G
)uP%
NZ3r7
cCpJ
(jC~
q\oP
> ap
Z/~mL
d_E}
os0
Kr#%
%@a
s bM
Ap^l
' x/
((( )))c,,,
^ 2%
EC'
/A5q
~jk|J
/c Hscc/
`CMc
~mcDj
)PZZ
mcU>
1@12
Re_W<
*ir;
7iK-
2r'A
,y{[?2~
cqHLG
%1QA
_hHdV
1)~
)(ch
$< O
NH[];
Y;#\
\]a)
H5QB
Ok|CVW
+$(VJ
OvYT
G b3
fy$<
+Tr/
X$ %&
WelFn
^l-=d
!Vo,"
r
N8@
u#8|
! M0*X[
$l&(
?8U]
KZtT0
UjrF
>'FC2
a(O'
xovB
7/)kY/
)!G,
nd 8.a
[
WWW{&&&!<<<
0C9[
?0go
a<m8h
ot&:U
g<-.
K-T_
gfF=I
/=i`
*rO]
25t@
@.R_.
gxo
Czk
SHoQl9PCPz4VGQYVM7DwpWEJCpxZe7m
'x]J
XT`{
V0De 0j
Y O
+Dr]
>`"3
d2 eQ
MIO~
F<';
9c<
QrdK
mFx G+
6d9;
6d9:
PkZg
#i1Juytoibs7HULH62rEGkJoDnKXSZ9I7Owt
bgN A
pl~;
w<qf
)|4<T
TqW?Kv
}x}:
F)XG
_c8f
bH={
kK?d
1p)8
*A }
R-
]} L
tgp)
+'+r1?)
m [Hq
MmPY
ZW$k,H
2&
OlgT
nok,
xw?b
kp,&V
!2x`
=0pl
mp\&
uPLk
9SC1W
]7!gf
H=7h7
O``-
!mz}wb
y#^\:
5 1
@DQM
0[_\
'<?
XoxG
|_lX=
(*o)
v+/_+
KD *
dkP!
31K~
{lUw&
M4M*
o xWL
5tS
93 )
[lh[
3P}1K
sjLw
K"(*
D?B{4
PQ,9
hqEf
_09l
-\g!])
~ d`
_z m
+zA?B5
m<:D
8 }(d
2^&}4
F2E:
<l "
W G)
-S`S>(
7Cd6
7[wQ
EDjc=
FLG 3
:[#76
UWuX
\EsG
IqSmz
u:6
Z= ^6
#xNe
Bif(js
5<8=&
j 70
$4 J
U+.<
.rw
u_B5M
3`Rh^
Ojh$
eq^2'
n{P;I
~XP`X
JLfh
rWo`7
r#Br
(6s:u
e5dL
_esS
jtC;3R
^hG_
McJ^
zSyDe
r|KK
30^4;
Hq3,
E.q
K*W 6 V8-
vKgobiA
N^u {
b?AP
d[.sOca
c).736Ln
=KTC-
]I%~
`Z8y0
Pf+5
H&rS
^` <
ZFY?&
*2D:
w,9C
j:S=
>M&R)K
rn;(F8T
5"
I(3R
hd{b
x&k,a/
0G{P
A@! 6
.f29
ac[)a(
U8~3
)?8w
G`{+(
k8_8I
@a@UN
__.6
$&''
]iL9P
B`{Z
<wmZ&qw
FJ+d
HTu;
^4^/.
>,qI
jB[Q
6zfW
h9L'A
c`Tt
jB[h
!N'F
.>/y
cx?E
h {,9h
3vdoS
>\;s
Fj'u?
o6fI
eQ:3
'fJ` {(
6%Ik
N!=l
b=!d,
f(nLG
Je Q
H dh
v0D^
2.aP
<7V:
p{t}-s
}G>"
mF:9
*5tzrf
\:ZAX<
EUbVwN}
w|/G`
8WlQ
[o4I
koSFK
>4Xu
Cffx
>xpG',
@ i2
5nx?
ft<1
rm^D#
9D+(H
(5Fc
,0
P(`qq1
dkw)
5&E\
gLfi;
1]XD
3l "
_w&36HI-
k1/g
}d.Ee
q`v+
!to\
[ptf
^Es%
;'c
bs4J
?"hS
zRz\
ANsK
hION
X*~Of
Vx9H
s'''
D2e#
qc P
oP!'
q#EHZH^
Zztp
n}?@
/&]
&la)@
e3 @F
!Qv7>c
YKh2
Tyn<@
"E&Wr
;|Z)
\ X`
51C</
Z]Ou-ki
+`7[
_PQC
vN'D
{w 9
H-Ug
cbbB
M\om
~;++H
'alu,X
_0\-
!Nrg
p-WN
,jZJ
TYmpX
"QP,UE-
8c}P
Hs@xp
Lh*a"
a< |
N /_
ryn'
Z7 .
a81 1
CA5E
get_Now
"A- T
5%]E
*cL^
!K }{
*u@ ]+
} LD
JW2K1
{{mx
O8\}^
Qb/y
] ;'
4hD|
u&zs6
kPI"T
IiV$
$ em
vum#
s Ti
v6aQ
f^(Hg
MH5B|
#v7p
.q~b
=tyA
9SAX}
^yoD
]M[U!
Xt2`n!
t / wW
_ h9
666,777
'Pxb
-:OIN
ftlT
35lf%AXSvn
VlX\
cJq_g6
fY]`
x9TY
z8sc
L|$5
(Q6J
Kq1~
lbW
='333o
O=4]
BrrSN
jpGC
V%&x
===A
u9"~
# )xbJ
&u{9M
oh#|_
4Y_g
Ezl
pGAa.k
$5"62n
d+,7
bEe;
cWU)
[Q;Q
G wj%
;%%i
*\,q
J0Ia
FwH_
F6;\
]sgU
J`w+
;<d8
qn<S
z"_M
`mce@
5+k\
(e Q
'5;b?
A&yN
T6 t
5o0cm
###-@
43s@'
Al|Z
,0m?Q
6c&!|
@'7)\
`.tK
Tl
Hsk"K
eu5n
#oIFzQVblFwy9z8HriVL3OGQORf8skGwaIen
KrsLFrQ
u)i
b}u
b u J
eGW w
_' W
AI P
\AK7
H+M
<z$
r >
kx@
(II=
3>#|k
bvs#Q
G R*
vh+^
s ~@
RfJI9
;_Moe
66I
= W"
W Mw
4~z}
b3 ndM4
]!@}
+POj?
mkJ
aE(Hq
hrLpZ7
W2 /o
DrMJ%
E9~!
JMK*
6|'~
N= U
e*Rn
B?Oi
gJX?v
`Jw[
1i7I
n{?~U
$.;b
wt#}GlWSA
t9s)
Syh'
<ttt`
hT=K
zN<v
P?<RL
zBxHZ
bosP
%)O=
U)ic
F+'s
oxjo
k<nu
l3f)O
%L;Ok
Q`7L;[
w3l
Qr
g;gn
'h'<nv
V{T)
( xv
sie?7
O0 Y
.2U'
H, %%
S8Ra
D{Xi
DtL4
mXr.^C
E #
2xM.m4
=S~qFc
}KZ%
^ik~
nnkc
blsl
1+g
Tc~X
set_IV
*i2:b
_`}!
no]XB~
wD9H
`4Kb
"nzg
l0 ?4
XuqE'(
(t_|
BMg\
<)r7F
dSNM
iTj[6'
7OV*
Mr4<
?Wi\
Lq 8
s7HCIu
rW6|
Gtth
C+)F
][wK
iSU4
oYS4
F@z
b!iQi
>9\k?
/]!`
(J~|Al
Kg]p o^S
Y3A0w
@ih)
CAj
_Foc
jF &*
L1CQ
>g K
SpOP
)^Qy7yI
+y+~M
4m{U,
2JnY
N:[q
s ez
vMQ=k
np|N
^R[p
5<e
e\f9
%Ld
8-W
(DRz
imBI
[jm~)
~vz|d
'TzDnbjLKa4YRBoGBeloPwkeUW9MBfSnVVw6vYCQ
C%Iv
fIu1j
*uo
= r;
#0P)6
c+I5
4Ko':_>
>A#l
C/q83
j 3}u
0uK
.E)>\=
_-yX
!<a/(
LxXZ
U oh
4+s
HF]ur2]'5
*b\XH&;
*@Ln
G^j.
Z$ H
GhqdPDxcmQTC9qVw73xR3eb9rZolAdGg
POh
s=>
acN@
S&4<H
Ud9%
Lt191
9kOWu
=Wh=
n"Jt
6 B
HI`=m
fw$_6
>YY&
'rgFA&
i%8b=
e0.!
Bh_{
)>Ju0\\
(a!0
j}*`
6Rx-
[g {fHP!
}Et5
E.va
3yv$
nF}fL
KT[,
\75oY
+$_?f+
.sl#H
\wbBly
;x4I8
gp8S
=Ln
0@pp
ju[/vl
]=AA
r-_Z
_*1C
` n
5,NA
pHYs
B#Mh
X"Mo7
}[`Uy
::: EEE LLL UUU ___
4/X;J4eO
^g9
y2jB
)Btj`}`
sn `
^xalI
o:>K`
BJn(
TX5}dxh "
ai+j
7n >/y
XGo]&W
=i;bp
$iU}
3E|9
"h>$+S
.eG%U
mTx'^P
)P{.
OS|HN
a63f
lIruS
^qS;
~ !`
L |X
7-6m}
3$J}
6 hy
Az!vh
EY 3
e> q
P$DS
/k[b
bvLH/
z$ubs
v]N<
IQyR
QB (
w^tm
hn"
T[]V
KNE0
j.\
A J:/
;BtWK"T9x
?A.?
L"N*
#l_|^
0U.~A8
[z]D5
O%p=
sM.q
H7C8
Zzi
v4d d
y3r!
U12B
r[*n"b
Z0Sz
',Y4Q
6\S,
CJ^:,
jitUS9>
Y&)f_
oKA^
hU71
`}\uke
,Dxp
uuu
f54K
bz$:
eY8{
_;@`
PIPA
Cs(X-
j#Jd
a'YC
*xXa
v[\_
IE~iJ
r9n/
attT
Xgo CR9w<S;
H%:&
s{Fb
Ok K
K7!%
)\5
1%`H
^^j/9
l\Dq
3!U:p
5:&H
6 '%%%
jYx?
mcODx
N)ylQ
z5^y
2S=w
IEt
G7{y
=^fdh;
H6z`
FSU!
8"6B\
3>Gj
`C*t
)\5>
~"@'
Z iwp
kiU~
,gS/8
:K|r A
mO 6
/ 5*
vm)G
wwr-#$~HS
RBuj
<o3;
NtBS
CKKE@
('B<
{7>,
[kg"]
'>{}
K1WH
1Bd'_
luvNN|
C :1=
LaeG-
j929
QsJQ
5 .<
Fd)2
OgnL
Z+H+
wo< ,/
zqON]}
w^<
L\ 7S
C>+
; fW
w!gYc
o>u%V
pJ>U<
+?)E
<) j
.h&z
s=m$r
)DFMr
^)0
+>Zp
Xg35
k T#
M`!JKSr
OXxa
$8~B
Rt?y
hWy*bj!
333y
qXK!
E *
l4x))
3Ve)E`
b_/-
e%GCl
ar`U
a)D#
F3{|
E,w/
(u
r<g-}
].D2
!we0
W~ex
Dlru
.A Mf
9]pXJj3
IV?ZeOJ!
K$XS
=Oy6MS
z#(=
n;\>*
'<@w8
Sc>J
pw@my+
$jL{
f@"(
WZ;le
H,90"
8 -
A*'/
pwMPzq
Pe07S}
t)ktq
E)mo\
yW^h
mN[W
cmt;&H(k
PaFLk
Gk=
?W :zh
DQ>
Y_ A
~34wo$
^'T3
kV v
rmK
p4p}]x
dZ+4
DB|7
l%EGY&
ZE2%
RQi hm
8>}
X?^HQi
]P1*U
Uc Z
U2*Cc
&re'
# E
;bbK[
ys4],
E\Sn
; !c
nC_Q
DJ T
dCBk
)/BY<
4gF|-
)$Y!
0AR
rO*z%
d pMof
OAG#
>w o
`C T
q1^]i
;h"H
\_l[
MW|%3Cm-
8]Xk
;u 0
17"Q
(mtKz
clM;q
)P{<
3zJj
PA#\
uSerM
Tf_T
_B&P
0U
-)0cU}/
hkkk8
9;8w
>}Zh$
re@
Y*Br{Ng
&Z'j
u ov
Sg4Qm
YLeD6 c{o
WNu
*c`b
bAN0
?B@5
Rh (
c,7~W
iFymA
s93o
/0OZD
2C>3
9rg+
7=_"
SLrd
0< vzr
0y7
s,(K
3OeZ
o6D7
: G@
;^_\
I"&R
bA"B"
@Ji..S
hr./
| hR
!kyX
< g
q.S`
q$+q^"
T^[`GuM
/.`o
aXR:
o 4^]c
999F
7OTd
!%%
U`'J
{=3%G
[DUQl
n8AG
xy#R
5PSO
HI~M
d IG
qYxn0xBVs2zQKzxASl7ToqA93r
8Yq |
YoH]
^hGmi
7B(=C
/%%%
^0!e
:vS
d$rx
XT} K\
0tJ}
;k @
System.Runtime.CompilerServices
K>)Bxr
?A`+
3r&
'm,?
o_3U
qtb`
f1MoRZ%
uL/k
5,B\^
222u
hE F
O)m5
S(K^
#p{<\}
G>sM,
,
tt"t
f dF(-H
)%w})
&UW!
\OS= z
7+K-
^w$&
GT'x
|N*XVj*
Ahc!
{Z q
rJ L
nP}
mb-[
:E?$
#"""
Dxxj'(R
56ut=
S!k
ussg
* 6?u
tF8O
SC1s
W|):
F!i{
WB?
>h) i3
y{cK
IMVQ o
kJgn
_VPm
H 06
WrSZ)8
`:sM
Au3w
,mF 0
w{i^
Zh'&4
)+51=Z
ii0+"
xUAq=Otq
h]7^
S\T&
'Y/'#
&b]
Mc0v*T
K3q_ n
>/r
Vc"T*W
o/g&
GpwP+
yr<G
Q[^'
%fff
#M}A!
j8c6)cV1
,LLL
R{9^<
;}OmmK
Lp Z,
hZ<3
8Du,C
Fqlw
M/F=tx
Wf.]8f
]f5>
|TI5
?VJYo
pF"+
`Z.*
6 D&
\36D]2
q]R1
a%iT
'Ft0 Ip@
IIgS
Kq$!#
Ehdj&
eajjJ0
6_&Y
@aN5
; .5
#ve
saF0
2V+j;h
k+Y@Q
\@kD
}4+6E_
A,Ba
X ww
DfX2iw
O/W{
CI*U|
f F1f
>>lBw
{kt$
<|W?
Qe@;
8)LE
QT N
yov#3
>)&
uJ:fL
yxBF
:vS
,/Ap*A
/jSz&
2__7
pt`"
BMD(
e:~Q
Wbd0
NOeyg
<,4hO
` 5,B
Ib[M
_` e
3s?'
6U0Z
Nfe"
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
%LCH
Z<~YO-
|*k?0)
>Zi*
tl jd4Y
j'9-
R_h}
]iE$J
33{=
z,SH
p=5s
8t'$XVK
RCL6
j HM
2}E*
Q5F~8n
dI8%mB
BWGj1
~ RU
Yla
K{(,
U\XcJ
:sq4
2%pl!
!< T]
u }E
6VWC
)8S&
AV 5
c%"7
(4EW
fo<|C
]vbt
]a'"
_I(8BDw
G_%J
!N#h
B F
4`
>P0jI
RRQJBxMOzkf7HHGduoOM8VL
bcH$@
6(-J
W^y%
9G5~_
`_iX
gRyE
pq[J
.8]
`8Q&
:z/z<
M1QN
~z7U
'X|]2\
#zYK:rt
mA@
TZcjwO
|b_zB7
I zn
%;Ap
r!&*+
= >!
x_58
8300N.
xo{a>
qY#a
r !sd\
$,T)$
Z )r
aU7
!}pV^R
-qh SN
oPay#
F-
%.s3
a^[n
^m1W
WnhO
NrR)1 1
(B`bb
':Az
,+}k
ZZM*
&*U-
cTX6
B !|
Wy p
oF5<
<F"P
n*tu
tay!
[75DTIb
333d
Ss3-o
m4v_
`sL
'fqA8FzCcqxD7CYawxvWZsdeJFasY8wkuNEp7vz9
M#c
YE#
_RY<F
8>P\<
j}Ko
<na^ l
Tz!&
`Ru7
?>U(
>//@
4t?k
#Qte
zS:C
ul=-
a{pe
Xt&'
3=g~
Q<CQ
J6~ToqEo
3P!
c~X^39
"X(
(@.q
Ay6=
:ZTn
o)fi
a5*9^oh<
g-wG
sGH
v #k
@t)Z
y]OrY
WSjug
0;jO
,I<W
aT|
b66
BqD6
<aW.
v9W_4
9^K}
JXN0
N$LW
N +E
1]>2
"yDd
&QF&
I[_Vl
fG+.
6t$]oW
S2&9@
cbY1 eJ
333 $$$
<7"s
RPzU
}fDV
'6}W
D=7!];
7M[x
(y?aiO<
,Un2
@|F1
050dK
J} O
v fk
5z%]c
st"_
4FW1
>x@ ;
R)LNNbllLx
O+T/
6:|b
F{{;
}hhHv
oSTCA
:TO&
7&d;3
Zdd0
-u9\{
%M+VE
Yy-
`C 7
Y@k7(
z#A.
N]v
;x!E
+1!
cc7}I
}`3y
u> [
N]xH
8ONP
l9MM
-m x
$^jqa
+Z`:
V[8 ZLF
p6qKl
4:L' {
#6|=)
zc []
@QJo
ltrb
e$)Z
wAu-p
IEND
,DZ;W
o8,S
X7Z~
}+;[
Bi^M
lEXI
u$ 2
f`yNL
6@(L
;
2,/"
"9r
vT_
H.lmy
!;_k
`.HN
nYV'
:9;;{
$6Xg]c
2mh;
uow}4
WkHG?
\5$*
`Mku
}zj\
yF"rz-
]Wdj[
,e)T
3Zg8jViBH7ywjud3BeR4TcIcQk6IsLv
Q-DO
G@dG
o<0y
{oD
!:ec'
7a=/v
BrrS/
aZRL
:blm
.):)D0
lQC<1
O^AEV,T
a`xx
C6w*
<Y`B
YuVoqG6EHHb9grq6o84x6c1zkxuM5HGX
DDD-
nxG
9\6)u
";;%'
kX{eX
s `L
Ec,x
`t&'7g
4BJ<
D'<|-
;.9 <
Tcn+\
2Mk{
Q<A#
c5 Y
I-3
&{Ob
K 0bp
'{B!
DDDN
d\YL'
_# 6
[)g
`Pw3t
k6^x4
OI1x
Tj<"k66
%M=z8?
kAp{
X`%c
Jv hh
Y:XW
G:% &r`
1XJ?
BG6d
RPyxvf8XLReUmTkgUrqcbqMkftGuzTi
+ _:
@%4U
Q}@|
5,'6
^n;&
-CiDI
z~W3WX
=t [9M
` er
i,f<
mI!>0R
u+6o
8s-
Fl-?6
a.,z
:_92L
o#(mi
4heI
@P61
Yz^S
p8&1YrJ0,
%E={&
> Hs3
)?6#X
/SXQ|
]~I5.
r>2\
}}}ML
# ,V
XxrQW
!O+D
"Wa]
\Z?k
J]8st
1o7v#
t,1C9
W/D7
H} ]<
qo'WNj
*b5mD
2x<
(21~
=?v:
3+BD
g_d4
mn 4
W 7
N */u)
s8gM
*h)z)m9X
9"L(
! ,`
Vg}Hq
o4xr
.i\
{r |qIh
.h(-
Yr,U
f!z
&e:]
p(T )6
hk-?%0
2#@(
*0 h
ZL+"
d0`m>w
pjLU!
8no
]Qx3]
D7 Kt)1
uh<I
u='J
'18S}
!%j7
N2SYA
INQ4
p{p
OXR8x
/e6>
^_iM
*\p#
Ur*f
Zb H
x{GO
k&dC
&,tV$
vzQ]q
%%%Q"""
@~AO
R:9-
v 8/-
:|Ak
VatG@A
#487:j
z5~[
i`$|?
&s<4+axQ
H`H!_
av B
=)<h
U% _@C
$;(#
x'&yo
<4u)VN7
`vo%
FzaS
vh^ 5,A.
"q6JBxl
CrXY+E#u
(C>ms
VP cI4
,M:m[
G9Sz
!|/94
Q3j{
XG9{S
- 98V
FZ?{
``b-
#L z
U;COKU
L`ZOz
LQS{
Z./t
3H4N
6Lk_
d%D-5J
;@N.
0-e!i"F2
fCRm
''oPz
pq&#
t}-\
iM%)
]Q +^
\UC.
: xmH
+lU4
8'(]OL:
vktC
'%e7
`*kY
-SR\
*)93
CO5e
NGm
Rj:R
l8p9
adsh
KWo|
1p%]s
|zv
A}yh
Z3 )u]P
;(qc
"GC6n
&ptX%A
~%T$
uz?X
&nWi"@
{y_L
"Ao07fT5vDjC4nHaIkXRXWPud1gexY2irME
P (R
*],}
Q5dy
/l"`X*
@ehR
&]$;
/ vK
3s=E
'Gjy
X&(3
xIJ*
4*3!
X93s
akU{
a7w
GGG III
bGj<
S|d Na
N>El6
AddRange
Q1Pu
iom@
1SW>
/SIp"
94gW
0idW
{q:l@T
fVPmsg
^[ %
02gI
,l"Cp
x(@!%
5`Q
###2
Ob9|_
.^yd
W=6@ZbC
K#l%
ixLk
0i+_
_Q
l4(J
m***
"D^(
|)$6
LIqdd k"
*8xJ
+L/n
xai'
|]94
kC#_
U6)h
/7B9+,
===2===w;;;
#P>hB
: 4
o7y
CdvY
ltgj%
Du/+
r{;c1W
rOD&<
Q} Z7H
w3ofP))>
sm){
RBw
2S9B
\F<?
;GSx
}Y\6
|+Wk
GAGZ
PUm4
_pAa
'wnb0
o~7MDy%
3Gb}:
CkM p
=Us~
Cll3A A
~( 2
:4.,
IK{{
Kp]C
gKH
.T .#9
L&#~
asbh
B$T8S
>d=.
S+pv
9bU%A
(WG\
U~8\
)(pr
& lpY
)$%b_q
_P{N
2s'j
Q/C9
t{p;oA6
020=
4 _ 5
60{H5
_o0YkG,
UJH
o%@44Q
')t1y
O``@
Xz\7rN
crA"
; zse
{`oI
?w]W
w.a:
L(,
-ZRb
7? Qg
jv6"
Z^>'
*.#O
^" ni
Ib-T!
vx z
< 3
OL'2
m3 bHG
/bIt
Fd63Z u
b,$*
eNUW[
g1ng
-# &
\7cR&
gf=C
Bttf7.
udS'
k tn
"ia4
$:::
_vv{
uUEq0zOiVpBImhItRb2kc2js
k;7-
"B7>
jB1vNM
Lh[?
Pn.q
IDJ*
h \j
G%\T
^?3f
PFt?
'@s|
pLk/N
fM7$
6 $lX
Vt7y
FQ8UZ<(
, 1S
|qg7
b+&
N702^
C>9_
0Z$9
o
tPxH
{d B
xj?3
o siH2
Z>dm6 u
8ddd
[jNG
DZ=h_
\\qS[
!|0j
gtM
u}pCk
`bP
42%g|~M O
glaJ
Ty1
tdu@
D#/g2
r@CwytOg
JO.5l
a 5$E&
zf P
%s1=M
h{MGq
sTzQ
-5sj
5ERuUe
s.,C-J'D
!%g_
;o \
{5my
]i0po
D^O_
x rC
:&y,3
s-Ni
m>!s
W3jdb74
'az ?
YhW!^ t>$6
Y>L8t
F9I_
Wy#+
7eb
us__&
o G0
hO_S
.YwU
r+Sb
$]<6
,$1@^
K6SE
Lkpkj
}7OL/
! 5s_X
kwr)B
diOg}
t 4h
>:mS
'b|>
$b ,K
mIsZ
E+w.&
EppB
oUe;@]&
#
Peo\
HLY U
c3!#
fQc
52 ]
}WpfuKZP
c,09P?{
^ }]
x`Jt
'bq6|
GspQ8z
*j/(:
w!f8
2XzX9e
tF08WVm2B9olixCmFImCwJHWfpJZCG
'l1y
7:AF
6x6fx
-snJ
[RP@n0
*O+O
;uR:
yY /
H*L|"
Uk.
8299
M}4W1]h,{
BeMC:
2f%A
Mp>@
>.Ht<
Pm`b
*{Hcb
MP)Bp
UA#_WO
UUU
Yk09
aEiDc
+.,u
6 wp
MhvtN
(&g >9
ukbRc
/7#|
#Vj!
4[W!
=ds|
5=B#y
?M/,]
5AL+
i pu?
51Aj!4
VX c|
Sx, "
092&
Xx j
:W
Z~Zd
l5psK
N3 E
-){II
mGo
QV!]m_
ZxYDR
&+_gC
z8U5s#
O3FZA+v
r35EfEWGAucGnpbN8nTQYtLDxUDnGquZ
'Gw3
e9 {
0I^a
!BB<
fD`9d
2Y_-eg
_rOMC?
&cd#W
|/=b
WW99]
R-`0K
b}^({r
Q7pZ
0{`,jT
[R.B)O
iV@iIW
mH%.
On^&Y
qV _
Zpq\
g)b]
/+=<
%/gL
j///
RD[ LA
[Jo<
5bt+
#[
CTm6@
CJx5
;tlc
yJHKT
WWjB@oC7
RsW9N
SCXTC
l*B!8^
'@+F
qRaC
pn,#
P2u;
0@\ l?Y
E,VQ
9t^a
Tlqj
K@sKx60
}d4
?B<r
qR["
"iec
3 Wu4a
.9\a
H $a
X|tGS
W QJ<
[RX8#
yu``
^{:s"
-,ho
2oQ
l
VsXdK\
),-d
~^fJ8S
im5=
Jp@D
|[2
D1r/
2g\
3}@'
k^#x+
ofklnuQGDFcfX3nhAcFbw5cK
)fW*
8{NT
_P7jy
5'!M.1
m]Y w&K
J`U?
Tmu!
/mv~
CCCb.
Wbj=
{t#=
!>"e
]_lz
GQO{
YwrKh'
c6+-
MEkn
(<.8
D\S8
>xa7.
s`/Q
[_
~VV.
0Ub]
FT=
0Qe^<
259Q
[ZdD
%ncl(
/QG;JO
5-Oa
1rc4
<I66
Hk(d
3ulH#
hR8a
9ep5
T?oKR
iLch
5U('
Ig)W
V~B#
)'MG8
4[JV
b;@P
I@(;
wv9HH
JdqD
s36|
:f=J
Q>- $>
64mj
B&^;"
Bujx
~s{C
/_d,Lk
@@@H@@@
~-O7
}Zd]
<69!"!t
]_Q$
7lgz
_N@ b
v>a
?d[0
\44=
'0<<
h5
&L<CT8
SeoN^!
k~Ok"
|l Lz
igo#
\@
\=%"]:
[ S7
`p9z
%D{
[E:~
j`pF
<C $
xZtP
^)cY
,L5w
3=s
~]4tSY
8fLv
k2_\,U
g K(
e;DRc
t7>p
nw~S
G*RD
PNAY[W
fGoE
c<*h
4bK
sV0'M
s>j@
`QA )
eP%
+P}2
Aps
cPX:({M
#GbT
]m6N=
Ar,t<FP~
e X>f
U$msb
EG;%R
4'tVRy
W``)<
~ym^
iG {h/z`
FzCN
@ ;#]
,*5rV
,o~jaoC-NK
bmVh
0ZTP
j_,b
?s*J
?K_>
> {@g-
)P'O
gs.Uoz
t}qi=aDEb
O|?@w
m`5!
$hjA,8
7'50V
6OFzG
ezt[
MLxB
x=WT0
.")G
gJ $
#E0<<
+_>+
B0c
9 uz
_TJ
g m
l71/B
</&b
^.bx
0:Vk
MkuV
,L @r;
!9qh
%r},a
" jI|
zQBo
;of'
zoLRE 1
a.wz;
#}&,
ye=8
pR)a
Hg3D
F#+2g
azh]
XP+YC7
R cm\
4=g{
CCC8~
sF .aq
F}kO
n7pT
WRt*lo
-_BP
(Z=v$8Ah
;b<+
gsp[q
^?,(
mctt
gA++
CVMy
,pHw
7dd o
'C '"
c{Mo
^?yf
@}i?
2Q #
:\v
?*)<5AEdP
$^ % w
| q'/h
85 |
9pwYro
J4Ut
|N?1=mONf
G:L_.PdPM
#$`K
IM c
}Ah;V
GIHaO
zR5G
+WnO#
RRLm
W,PqB
qg|!
amFm
s:f;
,JUz
hJU\
]n"rMQ
TwF'
-c1D
9Yv=
ayf_
9kTa7
UhEBd
O3 i
DKv8_
FiJY
(wI`
JM f
Ax@.
F_|V
ee_A
d*^|De
)<3fu
}O-<
F2$E
$bf4
)or{
=M`9
N} F
+Vi6
_Mah
.}ZY
k$I,<
)YWs
S9OuY$
Wo(3T;
@xat
~?:,s
coH!8
70?~mv
"I`;
B4QrV
f _ W P444axxx
1\R|
?J[8
&&&c###
llPS7(R
qZ4
Fmnm
Jq%.M:P
)2"m"@
%b(s
tYz4
g)OI
!zJvpP##i
Y>@F
g-O
Qu|.M
{-$r
/jdF
7%eHku
7 4P
VGW,1~
ya}|
Y>@n
{Y3 :
L&5|P
/x Byd>
7td>
v y7$
!|2M
1>$g
!B|Q3
YF5&
G'9g-
:7 c
+#u=s
HfkT
{<+1
iYZB|5
_?NW
S[Un
`_$o]
LtQ0*
zRbp
2t*X
3G qe
4](;
-l #
_DlZM
8;g(Z
*$>XW
X:w 6
ckWS4L1jTukgXjUHQdYUrnoT
^%OhnU_U
+x-F
e/Qf
-Jri
*d[h
[6!l
Nz ?
6Tm~
!Px=
OLVP1mHPk1I2JGCW5wnhNrTjz
B\ Q
m_+QL
i'j%
aiF)
wR&j
3dzK
k5hs
U;kA
j5$:
T&[
G333
F^W'
t:`*
|Z*[
.VkY
T|;AS
_Fx8
B<2
SqBu?
{tiz
go#a
IR<Dzj:
TIh.
:i(|n:
:gA
bV
DBvH
eMPsF
z#M^
z[l8
.'*k
Kdo8&
`{u{=
w]K\j
P"?B
Gx 9l
%8u'T
'5O\
XW7S
} u{
`\"
_pbT
#ec-l
j)B#pw~
<600
lY9
'le0
h ?;
Rk/&!
_oo
AF1}
)W q
A)B&
j3eN K4
VI?>2
q^PG>
u:ZX5
m~yT
L x
+.\\
%@@?
w kl{
f2{r
N=Dw
^j)!)
-^ q
x?_z/
9g 2mh
i0FO
_ooo
(o{?
|6fE
mXr
~u;A
6l&Tb
,X0%
%FGFN30qBZ06WjbLfHVp5qOmVy4DWUcI8NUePF
K4
|0~\
x^U[
Ubh'
X/+?
Vvo>
*#Sn
id.5
*5i6
fiY
%5C
QfnX
q;v|
laDv
:&v;
j U
!8GKg
hHEqU
zzz|
{$wvVR
6$VK
g)li
iV vrp
,s(tt
x:/F
Sc]1
=PzSD%%ZR
_-&>
<]JE
IEnumerable`1
<)F"&-
xvge
|vgc
s !:c
9?Zk
,UM`
V= TOhk9@
`u5Y4
.qE}
R.&(
y?q
#W} t
.S I"E
C3 ui
**6n
"q8F
To1.rWg
J=P%[
I*89
s;#I
HQ=g~
F?pVm'IuT
gq5
oa]A
,+++#333
Vv!r
WmVUR4
Load
UAYN
FZb6|
W"c#
f!I
?uXzG
`eR>
9:x cF|M
-EB;
b1E0
@Cn5 ;]
`Tb~`z
N@]a'
&hA(
TZ)b]
i (n
2/0
]' dY
Cr+/`
Cf!
z+ES
)Ygo<b
[hELD
AbPH
fg ?
AyB>6
Zs("t
l|R*
*d\2,
O:#^
4m4(;
44GR
B,_K
"E{_
c~nk-5S
8+}
/I?c
HC`5d"ki
x_\.
9o)m
$1]HK
swX
LW}#
ER[l
.|.a:a
f8A
BF='
D0T=
*GA
\s ]
"+bl
92!F
y0eF;
&(D2F(
yXRP
CaN3eOPmUpEwjhy73S3j
T{af
9cJr
Lu*:d"
M.19
UiD^
wdn
O:~>
3CNlN
"\L0
18O7
m&$H
bpvB
I]fC
&Tg}
7AT>
Object
T'fO
9 ED
:Q|5
yL\
B'1G
yR$_
}LV)$,
2u*6
0qMa
=^i3
"Zz.
g+!oZ
k z
[[[@XXX
sXx"-
#9cj
Av:<
RicP&
I 0<o
355u
EO@g
#\RH
W ss
jrj0*D
&/ <"
%D&A
#$'5
(t,2
}|HA
0!CN
Zgi@`{
G4C$
,~|3
P'd"
s%>Ot
0}9U%'
"rc [hB
#6f&
;Th
MethodInfo
"Iq
D>hH
&p/
M!>'
M70)
h;a}{
Qo 2X
>{Tz
0!y
sZPw
ac1%#
5cg~U
L-,'
jbh8
+X*q:
$y8[
h{r.8
I,fo
/CW
|25>
B ~U
4chi
T,Lc
[M?WCQ
-#d
U ^)
gBG>
wb$
&Y3)
gwGa
+;IL
R-aH%
.:
mJ8F.
qr]>
y-#S
&+ qV
. tM>
}Am<1
]<wo
%TXs
j7X4I
1D37
jjj sss
v$te
}}};
?pW
N Tn
[vJw@
o/Bt
_,f9
J7i*W
l9,7Q
rtD|U<
'=i;
\mS'Al
;qU~
;<1^e
zGc9
A0Tj
)NI<
5dxd
v>e*
TPkI
/Fp6
y@x$
'` \
3~k[
:SE z@
PXHCC"
gK7.
j0fK}"-)
=|71:
=Y1N$
R[L=L
l>XC
v<G3
tLf=h
E P
`zax!
;qrTWBp
j@4!~>
j1m3cA
<\,KBL<#
g)3Yj
a!w'
?ZfL
1S{G
SFGy
*D@:
2 , '
)AhyzO
4&''}
?Y,8
M_ T
`K c
11+}
.]Ha
]5,PB"H
8?}`
K9vW
$.:Q:
r&`g
OKFsr
UN&qfZ
^PJ$
]s!=
e/A[|:
'4 L
j+e7
uFLv
"V1Js:"n
^o%b
&Iu|Qw
M>'5
DqQJ
36=J5
vO] 5
CV)'t
-B]v
&&Uz
.Bp.K
#Keu1Zu
XRYiP
;5:4
lI~\
?H -
?%DKk"
Yy `
FG.
%s<3
44$N
Qgs6
obb d
ean60x
G]Pz
3a5{
SvQ!S
|4+i
nER>~
!{+#|s
<j{f
:OHE
N>w<Q
VL>y
ox C5
FPJu
3WU.
416A\@8
i=w"B
AJWtl3
Q@(t
W"%R
jja b
R5Mc
0\qU
a>9z
=C_S
f3.5
0-aH,
X}L (6
mE4g
xyH5
\6\o|!9M
^Ay?
gUO
%bz`j|J*
+0o9F/
w:A2~i
` *@s
dt#
Zdt
iCA,
<[1g
vBxms
dZB&>
LMO#X
1VX
|X0"t
j@ce
L0~H :Qe
lo(
B sj
| ;VJ
hMMM
lQ*`/:
53<]Z
G'*2
Cf$8
#(S?
;;d$
op%=
4!?O
b']0
N+KkK
vi](
%o?"
Sw|f
R9"
8GSl
:u~g
dzUo=
n[:.
0/S<
:-Uc
LAPDal
hskc
.ZOC
SR.Jk
?i=B
6Oz8-
L%-)d
0 ~R
~i,9\
TCp.
OJyp
$aO}i
IWw3
<?f
HsR/]
)o{z %'
rReg
seTQs
x,zd5
o7 H
yv|+\
+yIOxcj
j7hf
oT9u
n[:s
?~0A
p2p|#
eXy .
}Av$5
Dp,3
F#lg
3hIMh%
c!+|&D
@x@9
-]:*a
KX?9
b(z"
Yx
{TJ
\X~G
L>|SJ
Abyg
===M===
Y:B"
dH]N
$i`
#/A(/e!=Q
&"&w4
%S|
iJbJ-
3i $
nA^j
` \aP*
R CCC
dD }
dtz 9
225`w
s^pS
U"rV
En}`
[IKKC
[E \
CgHD
9f~rd
"GM_V
64T
4#Y/B
y+R=
ff5O
z{d-c
j}/T$
MMM$
eyb>
V_!(-B
y>=f
Ig0)
Nyt
VP\
;]# W
3q8-
6[RC
tdQ
,23IP
1ry<b
&A;P
5 vl
GetTypeFromHandle
'MI^
ev8&
g6 C
/:::0
W:r+
g,,u
%'K:
BV?c
UwJ!
qI}
qF1>
MFl*
%aSU+
`P2N(
GZ>,
}@+7
FFFp
BE*,:B
,4CET
wx[\J
&gP`
[a*hW
18%;R(
`Nak
} h"
u:/w
G 6`
SKGIo>
R9+\
<CdG
z5Y1
oGUR+a,
Ygd]XY
<j.;
-H5X
/|HS;d
6W5.#
<;Y@
qA&/
u\M/
'W-B
qy ~
kNss
9#0N
]Y%YJ
LLI1W
:,p1I
K:.^
ZV <
l()Lq
*B x
~;yo
gLj~t
{s4Z
bRYkyg
z^EIC(
6 L3Z
&0JZt
ldV2
oCWe
>Y8E~
so(@
ZOa6+7
w&AL\YN
QL^K
"nP[
b^?o
X|xd-
Kmt?e,
f9vjqA
C^IE^D
Rr5&aC-*
T ;v
j(j#
)WK])
y !y
[\x'
l~*7
n<kYzy^URR
'o;8'7
jcq=
|FiNP
]QT4
Kf}nbv
gt)(Aw
Kq!_:.
bFx.
_VX8
(>72
\1u@2
^lg
YTJ"
t kg
* w#
Y? /
,is0
lOsA
>e?V
e5pd*
s6HfW4
R"7R
[9}r
sLYL
z]d
FWUB
Api]
KM&acn
jfY;
1inV
1 J
3 S_
1`RET7
a"|=
6Bx4*
4+q%
EEuZ
BY|/C
R?aL
&ppA
{T-j
brd^n
6r~
''' ... 333 ???
?l1p
a3F
<}d}#[
e"07
(+j5U
IR =
`[s85
d:1_
*#te
c -
XTO+ZI
YY](
,ZN-3N;
rc<7
%!y
cNe ,
.Jw?
-/bk
~8n+r2-
I%&3
-8WS
&akXE
cJ_
! "i
IgxM
{7 }
&[mr
tp`Q
B_0
p^3
\&DNR
yiqc
OWG;
O7J~Y
R;uy
?OFz
w@>
IL]_
)+9K
[#<E<{F
s?yQRW
PgB
G%&"
~/zpSV
N7a^Q
2d?MS7
b$=Q
x<sL
zHK<f
xv]e
%}V^
z 1!
o^;7I
cr?H
`TM
,+p7
d&8=
<[,w
61qu:
#]!g
"3s8
w= M
f$$J
='|E
X]b1
1&X{
.v&bU
+CfI
l<Pn
aIfWn
']dy
\Q
rI=:q
#)0o
{Jd:
kQ#)6
P`'z f
P'/{g
c)"k~>
o^pq-
B6M<
ZZ\
*pMA
3On5l
!0 T<
U ]"
N( :$
tLBz
ZA"@
YYYSVVV
=xv'
:",!K
r<Pt
o5ZM
Y"V{p
eT?,
_>}|
\& U
Jd3Mi:
z k
b+L WI
{uj$
vj 3
[*;P{k
lq({
,oj^
0KMVy
#?[P
, ` -
ZrZu
5TpanF
r|NtA
9Wjh=
lwz#(
A}$i
] (XMf.<P
G\**
kKD
Yd Im
* +*
E&_/
Q"Qk
^4MX(
P0J
T '$?
i)W3&mg
q>>>
Sf3M
9vWP
->Uc[*Dl<a
}f?[#
8/~Z
{qaa8H1
@wCQ
M/hf
hM@.
gHJG
]3\ k\
zLQW
y-do
8z!y
6^p0=
3()j
Kq 5yZ
HZNr3
u m d \ S J C ;
i:&e
?-RZ
TV]~
V6"k
C *Z
8F[*
@.Je
t0b"(
RF)-;
!5? Q
888Y777
h}}Ox
n=+G
rGG`
"id[|
Y]RN
d'4D5
6A62
V#0G9
i)TNj
B%4]
Cs?8
+X3<
o s
TK2_Q
`G<Ut
,`Z@~
E |J
***
g]a,
VCyl'
)M$*E
sJfp
vnA@
IGSc
$HU\
4/\bz_:^Ae
sm76_*=
\ToY(4!
*R\+Y
=]&L
}kkrj
{ =OQ
YEWu
[4>*I
B 5-\
^? +
+,4"HbV
Hg$a"`y
a(+J
gaMA
t>wx
+T:
eMmek
L(A&8
^axw
N l;lvDNd
rkXq[
!E;2
6DI[
4*el
=qS$E
<16c*
C,~O
_A>C
]CCC
P=YeF,
?ydl+%,Q
y&vw
/Xubp
1dt.2l
8bR:W
Bbo.y
:f_1#
yb$r
xqD%
T07N
C ,wN
C4Qg
Y\Qm
MMM
r!!!{|||
j3RA
uT[q
pPd5
Oxmm
-5T,g=
V8,!
T9:~
jp1
=S0:
x 9tL
wElM
6C&]B
aV6K
lB0U
U`R@qCP
,ECy
$$$
=2V'~
h-$eU
MUJA9
cpp0x@
,+j
MMMQ
^j]I
SusF~p
)YRlA
System.Collections.Generic
s#C:
O(3(
K@E;B-l
Dx{q;Lf
"J2cOm
>X|V
qeN`
~Kv H
rqrr
3 2(O
/)FR
_.H
3Mvt7n
@Z!}
\fdj_
MMMf
}Jol
U#3@X
lxKR
FE$zK
2f61
Hpf hG
L= ju
Tu:66
\5G%
*O-q
zk89
*~ w
,Sl*
\!S6
BDcr
ujUzs
%;s,
j6iXr >
UUU UUU UUU
L6.$
Fl a
jTy=
[zQ
nB B
1 Ys
'zzz
FM?_
GrjY
A 0
4\s)Bs
m?9V
V& ,
}RE7
.`Zf
{}X!5
/PW3O
0-**f
VCVj
fnI
5"xnS
= >Q
7^Z
re$fg
g(.G
gc&;j
myQ.
6-nGC
]H_6
4f? ot
R-]_WMw&AF
yz+Mqq_
A(rcW
^E ?
V{4-
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-10 11:52:30 2018-05-10 11:55:25 175

24 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-10 11:52:30 2018-05-10 11:55:25 175

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\ORDER-SCMB1050.exe.config
C:\Users\Seven01\AppData\Local\Temp\ORDER-SCMB1050.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\ORDER-SCMB1050.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\ORDER-SCMB1050.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\System32\tzres.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\ORDUS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\ORDUS.resources\ORDUS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\ORDUS.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\ORDUS.resources\ORDUS.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\ORDUS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\ORDUS.resources\ORDUS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\ORDUS.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\ORDUS.resources\ORDUS.resources.exe
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe
\Device\NamedPipe\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2424.16859937
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2424.16859937
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2424.16859968
C:\Windows\System32\Branding\Basebrd\Basebrd.dll
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe"
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe.Local\
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
C:\Users\Seven01\AppData\Roaming\Microsoft
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.INI
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\ORDUS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\ORDUS.resources\ORDUS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\ORDUS.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\ORDUS.resources\ORDUS.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\ORDUS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\ORDUS.resources\ORDUS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\ORDUS.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\ORDUS.resources\ORDUS.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\rickokkkk.txt
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2624.16861796
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2624.16861796
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2624.16861796
C:\Users\Seven01\AppData\Local\Temp\reg.*
C:\Users\Seven01\AppData\Local\Temp\reg
C:\ProgramData\Oracle\Java\javapath\reg.*
C:\ProgramData\Oracle\Java\javapath\reg
C:\Windows\System32\reg.*
C:\Windows\System32\reg.COM
C:\Windows\System32\reg.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Users\Seven01\AppData\Roaming\ Inc\
C:\Users\Seven01\AppData\Roaming\ Inc
C:\Users\Seven01\AppData\Roaming\ Inc\ Inc.exe
C:\Users\Seven01\AppData\Roaming\ Inc\ Inc.exe:Zone.Identifier
C:\Users\Seven01\AppData\Local\Temp\tmpG859.tmp
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources\U6FBGMHE2YELBRBJX2ZHUTWEOEQ4ZTIN31LQ4YVS.resources.exe
C:\Users\Seven01\AppData\Local\Temp\KH2.exe
C:\
D:\
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\*
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\logins.json
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.INI
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
\??\MountPointManager
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.INI
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\plutil.exe
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\logins.json
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini
C:\Program Files (x86)\Mozilla Firefox\nss3.dll
C:\Program Files (x86)\Postbox\nss3.dll
C:\Program Files (x86)\Mozilla Thunderbird\nss3.dll
C:\Program Files (x86)\SeaMonkey\nss3.dll
C:\Program Files (x86)\Flock\nss3.dll
C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\UCBrowser\*
C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\Seven01\AppData\Roaming\Thunderbird\signons.sqlite
C:\Users\Seven01\AppData\Roaming\Thunderbird\logins.json
C:\Storage\
C:\mail\
C:\Users\Seven01\AppData\Local\VirtualStore\Program Files\Foxmail\mail\
C:\Users\Seven01\AppData\Local\VirtualStore\Program Files (x86)\Foxmail\mail\
C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini
C:\Users\Seven01\AppData\Roaming\The Bat!
C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini
C:\Users\Seven01\AppData\Roaming\Postbox\signons.sqlite
C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\SysWOW64\wshom.ocx
C:\ProgramData\DynDNS\Updater\config.dyndns
C:\Users\All Users\AppData\Roaming\FlashFXP\3quick.dat
C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
C:\Users\Seven01\AppData\RoamingSmartFTPClient 2.0FavoritesQuick Connect*.xml
C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
C:\Users\Seven01\AppData\Local\Temp\Ftplist.txt
C:\Program Files (x86)\jDownloader\config\database.script
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\hdaudio.inf
C:\Windows\sysnative\DriverStore\it-IT\hdaudio.inf_loc
C:\Windows\inf\hdaudio.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
C:\Users\Seven01\AppData\Local\Temp\KH2.exe.config
C:\Users\Seven01\AppData\Local\Temp\KH2.exe.Local\
C:\Users\Seven01\AppData\Local\Temp\KH2.config
C:\Users\Seven01\AppData\Local\Temp\KH2.INI
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start.*
C:\Windows\SysWOW64\shell32.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000012.db
C:\Users\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start
C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb
C:\Windows\symbols\dll\System.pdb
C:\Windows\dll\System.pdb
C:\Windows\System.pdb
C:\Users\Seven01\AppData\Local\Temp\KH2.PDB
C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb
C:\Windows\symbols\exe\ConsoleApp1.pdb
C:\Windows\exe\ConsoleApp1.pdb
C:\Windows\ConsoleApp1.pdb
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\
C:\Users\Seven01\AppData\Local\Temp\WERA3CC.tmp
C:\Users\Seven01\AppData\Local\Temp\WERA3CC.tmp.WERInternalMetadata.xml
C:\Windows\System32\drivers\*.mrk
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0a320577
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0a320577\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERC7B0.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC7B0.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_072a21e8
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_072a21e8\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERE133.tmp
C:\Users\Seven01\AppData\Local\Temp\WERE133.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0b263aef
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0b263aef\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER15.tmp
C:\Users\Seven01\AppData\Local\Temp\WER15.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_08f25aea
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_08f25aea\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER3668.tmp
C:\Users\Seven01\AppData\Local\Temp\WER3668.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0212914c
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0212914c\Report.wer
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
C:\Windows\SysWOW64\it\KERNELBASE.dll.mui
C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
C:\Windows\SysWOW64\KERNELBASE.dll

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\ORDER-SCMB1050.exe.config
C:\Users\Seven01\AppData\Local\Temp\ORDER-SCMB1050.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\System32\tzres.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
\Device\NamedPipe\
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini
C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt
C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini
C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\SysWOW64\wshom.ocx
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\hdaudio.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
C:\Users\Seven01\AppData\Local\Temp\KH2.exe.config
C:\Users\Seven01\AppData\Local\Temp\KH2.exe
C:\Windows\SysWOW64\shell32.dll
C:\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000012.db
C:\Users\desktop.ini
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb
C:\Windows\symbols\dll\System.pdb
C:\Windows\dll\System.pdb
C:\Windows\System.pdb
C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb
C:\Windows\symbols\exe\ConsoleApp1.pdb
C:\Windows\exe\ConsoleApp1.pdb
C:\Windows\ConsoleApp1.pdb
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\WERA3CC.tmp
C:\Users\Seven01\AppData\Local\Temp\WERA3CC.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERC7B0.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC7B0.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERE133.tmp
C:\Users\Seven01\AppData\Local\Temp\WERE133.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER15.tmp
C:\Users\Seven01\AppData\Local\Temp\WER15.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER3668.tmp
C:\Users\Seven01\AppData\Local\Temp\WER3668.tmp.WERInternalMetadata.xml
C:\Windows\SysWOW64\it\KERNELBASE.dll.mui
C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui

Write Files

C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe
C:\Users\Seven01\AppData\Local\Temp\rickokkkk.txt
C:\Users\Seven01\AppData\Roaming\ Inc\ Inc.exe
C:\Users\Seven01\AppData\Local\Temp\tmpG859.tmp
C:\Users\Seven01\AppData\Local\Temp\KH2.exe
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
C:\Users\Seven01\AppData\Local\Temp\WERA3CC.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0a320577\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERC7B0.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_072a21e8\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERE133.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0b263aef\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER15.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_08f25aea\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER3668.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_kh2.exe_da92345d9ef17e7f8a7d57e853aea1bbd0e72ad3_0212914c\Report.wer

Delete Files

C:\Users\Seven01\AppData\Local\Temp\ORDER-SCMB1050.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2424.16859937
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2424.16859937
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2424.16859968
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2624.16861796
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2624.16861796
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2624.16861796
C:\Users\Seven01\AppData\Roaming\ Inc\ Inc.exe:Zone.Identifier
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe
C:\Users\Seven01\AppData\Local\Temp\WERA3CC.tmp
C:\Users\Seven01\AppData\Local\Temp\WERA3CC.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERC7B0.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC7B0.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERE133.tmp
C:\Users\Seven01\AppData\Local\Temp\WERE133.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER15.tmp
C:\Users\Seven01\AppData\Local\Temp\WER15.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER3668.tmp
C:\Users\Seven01\AppData\Local\Temp\WER3668.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ORDER-SCMB1050.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d39521f\7a33541f
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\78d29fb7\764691b8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|ORDER-SCMB1050.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|ORDER-SCMB1050.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|ORDER-SCMB1050.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\78d29fb7\64805301
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ikyhgdddd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|ikyhgdddd.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|ikyhgdddd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|ikyhgdddd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\rickokkkk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\21da3f79\37ad4f79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\ikyhgdddd.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1874E416
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_CURRENT_USER\Software\Classes\WinMgmts
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\410
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ikyhgdddd_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ Inc
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ed27e90\2a36141f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ed27e90\66bb635b
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it-IT_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\1c4dd593
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\4deb99ab
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\ikyhgdddd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1
HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine
HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
HKEY_CLASSES_ROOT\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\410
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\10
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
HKEY_CURRENT_USER\Software\Paltalk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FTP Commander
HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC
HKEY_CURRENT_USER\SOFTWARE\Vitalwerks\DUC
HKEY_CURRENT_USER\Software\DownloadManager\Passwords
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eheadphonewave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonetopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonewave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave\Properties
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KH2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\63fc17e7\5b5a3ba7
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\KH2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
HKEY_CLASSES_ROOT\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|KH2.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|KH2.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|KH2.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\CLR20r3
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\rickokkkk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1874E416
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ Inc
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\ikyhgdddd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57

Write Keys

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\rickokkkk
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ikyhgdddd_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ikyhgdddd_RASAPI32\FileDirectory
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ Inc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
Global\.net clr networking
Local\_!MSFTHISTORY!_
Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5!
Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies!
Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5!
Local\!IETld!Mutex
Local\c:!users!seven01!appdata!roaming!microsoft!windows!ietldcache!
Global\f929c9c0-5437-11e8-a5ab-0800274633c1
Local\MSCTF.Asm.MutexDefault1
Global\ff9942ae-5437-11e8-a5ab-0800274633c1
Global\03ca24e2-5438-11e8-a5ab-0800274633c1
Global\07c6935a-5438-11e8-a5ab-0800274633c1
Global\0f58eb2c-5438-11e8-a5ab-0800274633c1

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.VirtualProtect
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtProtectVirtualMemory
kernel32.dll.GetModuleFileNameW
shfolder.dll.SHGetFolderPathW
kernel32.dll.MoveFileW
kernel32.dll.LocalFree
kernel32.dll.CreatePipe
kernel32.dll.DuplicateHandle
kernel32.dll.GetStdHandle
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.CreateProcessW
kernel32.dll.GetFileType
kernel32.dll.GetConsoleCP
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.GetConsoleOutputCP
kernel32.dll.WriteFile
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.SetThreadUILanguage
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
ntdll.dll.NtQueryInformationProcess
kernel32.dll.GetTempPathW
kernel32.dll.CreateFileW
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.VirtualAllocEx
kernel32.dll.GetThreadContext
kernel32.dll.Wow64GetThreadContext
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.ResumeThread
kernel32.dll.SetThreadContext
kernel32.dll.Wow64SetThreadContext
kernel32.dll.WriteProcessMemory
kernel32.dll.ReadProcessMemory
kernel32.dll.TerminateProcess
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
ole32.dll.CreateBindCtx
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ole32.dll.MkParseDisplayName
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
ole32.dll.BindMoniker
sxs.dll.SxsOleAut32RedirectTypeLibrary
advapi32.dll.RegOpenKeyW
advapi32.dll.RegEnumKeyW
advapi32.dll.RegQueryValueW
sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid
sxs.dll.SxsLookupClrGuid
oleaut32.dll.#9
oleaut32.dll.#4
oleaut32.dll.#283
oleaut32.dll.#284
mscoreei.dll._CorDllMain
mscoree.dll.GetTokenForVTableEntry
mscoree.dll.SetTargetForVTableEntry
mscoree.dll.GetTargetForVTableEntry
mscoreei.dll.GetTokenForVTableEntry
mscoreei.dll.SetTargetForVTableEntry
mscoreei.dll.GetTargetForVTableEntry
kernel32.dll.GetLastError
kernel32.dll.LocalAlloc
oleaut32.dll.VariantInit
oleaut32.dll.VariantClear
oleaut32.dll.#7
kernel32.dll.CreateEventW
kernel32.dll.SetEvent
ole32.dll.CoWaitForMultipleHandles
ole32.dll.IIDFromString
kernel32.dll.LoadLibraryA
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
oleaut32.dll.#500
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
kernel32.dll.RegOpenKeyExW
advapi32.dll.GetUserNameW
kernel32.dll.GetComputerNameW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.GetProcessTimes
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
advapi32.dll.RegOpenCurrentUser
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.ResetEvent
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
ws2_32.dll.inet_addr
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.WSAConnect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.shutdown
kernel32.dll.GetModuleHandleW
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
user32.dll.CallWindowProcW
user32.dll.RegisterWindowMessageW
dwmapi.dll.DwmIsCompositionEnabled
ntdll.dll.NtQuerySystemInformation
kernel32.dll.CreateDirectoryW
kernel32.dll.CopyFileW
kernel32.dll.SetFileAttributesW
advapi32.dll.RegSetValueExW
kernel32.dll.DeleteFileW
kernel32.dll.GetModuleFileNameA
kernel32.dll.MoveFileExW
kernel32.dll.CreateIoCompletionPort
kernel32.dll.PostQueuedCompletionStatus
ntdll.dll.NtQueryInformationThread
ntdll.dll.NtGetCurrentProcessorNumber
kernel32.dll.GetLogicalDrives
kernel32.dll.GetDiskFreeSpaceExW
kernel32.dll.GetDriveTypeW
kernel32.dll.RtlMoveMemory
shell32.dll.ShellExecuteEx
shell32.dll.ShellExecuteExW
kernel32.dll.FindFirstFileW
kernel32.dll.FindClose
kernel32.dll.GetExitCodeProcess
kernel32.dll.GetSystemTimeAsFileTime
user32.dll.GetLastInputInfo
user32.dll.SetWindowsHookExW
user32.dll.GetSystemMetrics
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
ole32.dll.OleInitialize
ole32.dll.CoRegisterMessageFilter
user32.dll.PeekMessageW
user32.dll.IsWindowUnicode
user32.dll.GetMessageW
user32.dll.TranslateMessage
user32.dll.DispatchMessageW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
user32.dll.WaitMessage
mlang.dll.#112
wininet.dll.FindFirstUrlCacheEntryA
kernel32.dll.SetFileInformationByHandle
urlmon.dll.CreateUri
kernel32.dll.InitializeSRWLock
kernel32.dll.AcquireSRWLockExclusive
kernel32.dll.AcquireSRWLockShared
kernel32.dll.ReleaseSRWLockExclusive
kernel32.dll.ReleaseSRWLockShared
wininet.dll.FindNextUrlCacheEntryA
advapi32.dll.AddMandatoryAce
urlmon.dll.CreateIUriBuilder
urlmon.dll.IntlPercentEncodeNormalize
wininet.dll.FindCloseUrlCache
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptReleaseContext
ole32.dll.CoRevokeInitializeSpy
comctl32.dll.#388
ole32.dll.CLSIDFromProgIDEx
kernel32.dll.GetVolumeInformationA
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CreateStreamOnHGlobal
advapi32.dll.RegCreateKeyExW
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernel32.dll.SetThreadToken
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.CheckTokenMembership
oleaut32.dll.#285
oleaut32.dll.#12
oleaut32.dll.#286
ole32.dll.CLSIDFromString
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#290
wmi.dll.WmiQueryAllDataW
wmi.dll.WmiQuerySingleInstanceW
wmi.dll.WmiSetSingleItemW
wmi.dll.WmiSetSingleInstanceW
wmi.dll.WmiExecuteMethodW
wmi.dll.WmiNotificationRegistrationW
wmi.dll.WmiMofEnumerateResourcesW
wmi.dll.WmiFileHandleToInstanceNameW
wmi.dll.WmiDevInstToInstanceNameW
wmi.dll.WmiQueryGuidInformation
wmi.dll.WmiOpenBlock
wmi.dll.WmiCloseBlock
wmi.dll.WmiFreeBuffer
wmi.dll.WmiEnumerateGuids
propsys.dll.PSCreateMemoryPropertyStore
propsys.dll.PSPropertyBag_WriteDWORD
ole32.dll.CoGetApartmentType
ole32.dll.CoRegisterInitializeSpy
comctl32.dll.#236
ole32.dll.CoGetMalloc
propsys.dll.PSPropertyBag_ReadDWORD
comctl32.dll.#320
comctl32.dll.#324
comctl32.dll.#323
comctl32.dll.#328
comctl32.dll.#334
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.SetEntriesInAclW
advapi32.dll.SetSecurityDescriptorDacl
comctl32.dll.#332
comctl32.dll.#386
advapi32.dll.IsTextUnicode
comctl32.dll.#338
comctl32.dll.#339
shell32.dll.#102
ole32.dll.OleUninitialize
advapi32.dll.CheckTokenMembership
mscoree.dll.DllGetClassObject
mscoreei.dll.DllGetClassObject
diasymreader.dll.DllGetClassObjectInternal
wer.dll.WerReportCreate
wer.dll.WerReportSetParameter
wer.dll.WerReportAddFile
wer.dll.WerReportSetUIOption
wer.dll.WerReportSubmit
wer.dll.WerReportAddDump
wer.dll.WerReportCloseHandle
user32.dll.LoadStringW
advapi32.dll.RegGetValueW
user32.dll.GetProcessWindowStation
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationW
sensapi.dll.IsNetworkAlive
rpcrt4.dll.NdrClientCall2
user32.dll.CharUpperW
werui.dll.WerUICreate
werui.dll.WerUIStart
ole32.dll.CoInitialize
dui70.dll.InitProcessPriv
comctl32.dll.LoadIconWithScaleDown
ntdll.dll.RtlRunEncodeUnicodeString
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlRunDecodeUnicodeString
dui70.dll.InitThread
duser.dll.InitGadgets
user32.dll.RegisterMessagePumpHook
dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ
dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ
dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z
dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z
dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ
dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z
dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ
dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ
dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ
dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ
dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ
dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z
dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z
duser.dll.CreateGadget
duser.dll.SetGadgetMessageFilter
duser.dll.SetGadgetStyle
dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z
dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ
dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z
dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z
dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z
duser.dll.InvalidateGadget
dui70.dll.CreateDUIWrapper
dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z
shell32.dll.ExtractIconExW
comctl32.dll.TaskDialogIndirect
uxtheme.dll.IsThemeActive
duser.dll.SetGadgetRootInfo
uxtheme.dll.IsAppThemed
uxtheme.dll.GetThemeAppProperties
xmllite.dll.CreateXmlReader
xmllite.dll.CreateXmlReaderInputWithEncodingName
uxtheme.dll.OpenThemeData
uxtheme.dll.GetThemeMargins
uxtheme.dll.GetThemeFont
uxtheme.dll.GetThemeColor
uxtheme.dll.GetThemeMetric
duser.dll.SetGadgetParent
duser.dll.GetDUserModule
duser.dll.FindStdColor
duser.dll.AttachWndProcW
kernel32.dll.InterlockedPopEntrySList
kernel32.dll.InterlockedPushEntrySList
kernel32.dll.InterlockedCompareExchange
comctl32.dll.RegisterClassNameW
duser.dll.GetGadgetRect
duser.dll.GetGadgetRgn
duser.dll.GetGadgetTicket
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
gdi32.dll.GdiIsMetaPrintDC
dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z
dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z
uxtheme.dll.EnableThemeDialogTexture
dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z
dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z
comctl32.dll.HIMAGELIST_QueryInterface
comctl32.dll.DrawShadowText
comctl32.dll.DrawSizeBox
comctl32.dll.DrawScrollBar
comctl32.dll.SizeBoxHwnd
comctl32.dll.ScrollBar_MouseMove
comctl32.dll.ScrollBar_Menu
comctl32.dll.HandleScrollCmd
comctl32.dll.DetachScrollBars
comctl32.dll.AttachScrollBars
comctl32.dll.CCSetScrollInfo
comctl32.dll.CCGetScrollInfo
comctl32.dll.CCEnableScrollBar
comctl32.dll.QuerySystemGestureStatus
uxtheme.dll.#49
uxtheme.dll.CloseThemeData
dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z
dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ
uxtheme.dll.GetThemeBool
duser.dll.GetGadgetFocus
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.GetThemeTextMetrics
uxtheme.dll.GetThemePartSize
uxtheme.dll.GetThemeTextExtent
uxtheme.dll.GetThemeBackgroundExtent
duser.dll.SetGadgetFocus
duser.dll.DUserSendEvent
duser.dll.SetGadgetRect
comctl32.dll.SetWindowSubclass
comctl32.dll.DefSubclassProc
dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ
uxtheme.dll.#47
uxtheme.dll.BufferedPaintInit
uxtheme.dll.BeginBufferedPaint
uxtheme.dll.BufferedPaintRenderAnimation
uxtheme.dll.BeginBufferedAnimation
uxtheme.dll.IsThemeBackgroundPartiallyTransparent
uxtheme.dll.DrawThemeParentBackground
uxtheme.dll.DrawThemeBackground
uxtheme.dll.DrawThemeText
uxtheme.dll.EndBufferedAnimation
uxtheme.dll.GetThemeTransitionDuration
uxtheme.dll.GetBufferedPaintDC
uxtheme.dll.GetBufferedPaintTargetDC
uxtheme.dll.EndBufferedPaint
duser.dll.ForwardGadgetMessage
oleaut32.dll.SysAllocString
oleaut32.dll.SysFreeString
uxtheme.dll.GetThemeInt
duser.dll.DUserPostEvent
duser.dll.DisableContainerHwnd
uxtheme.dll.BufferedPaintUnInit
werui.dll.WerUIUpdateUIForState
duser.dll.DeleteHandle
duser.dll.DetachWndProc
comctl32.dll.RemoveWindowSubclass
dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z
dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ
dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ
uxtheme.dll.BufferedPaintStopAllAnimations
dui70.dll.??1CCBase@DirectUI@@UAE@XZ
uxtheme.dll.DrawThemeParentBackgroundEx
uxtheme.dll.GetThemeEnumValue
user32.dll.MsgWaitForMultipleObjects
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpSetTimeouts
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpSetStatusCallback
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpGetProxyForUrl
winhttp.dll.WinHttpSendRequest
ws2_32.dll.GetAddrInfoW
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpReadData
ws2_32.dll.#22
winhttp.dll.WinHttpCloseHandle
ws2_32.dll.#3
advapi32.dll.IsValidSid
advapi32.dll.GetLengthSid
advapi32.dll.CopySid
advapi32.dll.RegisterEventSourceW
advapi32.dll.ReportEventW
advapi32.dll.DeregisterEventSource
werui.dll.WerUITerminate
werui.dll.WerUIDelete
duser.dll.DUserFlushMessages
duser.dll.DUserFlushDeferredMessages
dui70.dll.UnInitThread
user32.dll.UnregisterMessagePumpHook
dui70.dll.UnInitProcessPriv
dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ
dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ
advapi32.dll.DuplicateToken
duser.dll.FindGadgetFromPoint

Execute Commands

"cmd"
"C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe"
reg  add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "rickokkkk" /d "cmd /c type "C:\Users\Seven01\AppData\Local\Temp\rickokkkk.txt" | cmd"
C:\Users\Seven01\AppData\Local\Temp\KH2.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ikyhgdddd.exe
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start 
dw20.exe -x -s 596
dw20.exe -x -s 588
dw20.exe -x -s 728

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-10 11:52:30 2018-05-10 11:55:25 175

1 HTTP Request(s) detected

http://checkip.dyndns.org/
  • Hostname: checkip.dyndns.org
  • IP Address: 131.186.113.135
  • Port: 80
  • Count: 1

GET / HTTP/1.1
Host: checkip.dyndns.org
Connection: Keep-Alive