MalScore
100/100
MalFamily
Razy

Protected.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 32/67 Related 2697
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 264.00 KB (270336 bytes)
Compile time: 2018-04-28 02:00:06
MD5: 55eff4b8cf32e1144bd789691bc8e3e8
SHA1: da741241047a9a718891976582c1b45bf591680c
SHA256: 73a784f15b6702d9f02ad1d81bba83374f8df134c46d06ab87294110cd262f1d
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-05-09 16:45:03
Last submission: 2018-05-22 12:30:02
Filename detected: - Protected.exe (2)
URL file hosting
hXXp://fiebiger.us/Protected.exeVirusTotal
hXXps://fiebiger.us/Protected.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-05-09 03:44:17 [32/67] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x41504 267776 9f62d927a8633dc593b507dc5981b86a 8991df6aba11f5efa38222149c43103feb34ef36
.rsrc 0x44000 0x600 1536 c26b7b71246e1a0549d32b643047d759 560075f022154a744b1f213a0ef7a516882eac23
.reloc 0x46000 0xc 512 9b86ab4eb0d4ae16b09aaab641930321 6194190fe086bbe0df36cc36c53e4b69443a55b7
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x440a0 756 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x44394 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2017
Assembly Version: 1.0.0.0
InternalName: 0796852.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: 0796852.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
AazLcLuWHUCeAvctVfAKrqn.dll
PPtjmLJiyKjaWHfTHXkXuquiLiX.dll
OSxessusUMjRTuXjfPKU.dll
JAhNUpdlUSndipbvgMyRScnfvm.dll
izLxpsneNbksUVBCEd.dll
jnAAGDklFJBqsVgyPlDFCXjAoO.dll
PwCucUgNFpaXQYDfcNh.dll
qyhcnNSLZTdjCzm.dll
swIqyeVEoeVWibCOSieJudBfWy.dll
adVnAlWIQmIEMbxMFQtlyDPTOh.dll
VqOkDnwyLQFmOXPiEMflupm.dll
hiyYNEQWoNBegvqDnT.dll
gpLHOSQevlfmQBhXCmER.dll
jSbdlHCuIObRiHJZrC.dll
UgBYGzLMxXTjhmJKrqw.dll
sJqXgRxtKrfHlSMQjprjNyhKdM.dll
TJzLTYTdsCPrXqCj.dll
wDdmfNVmpfGGbeutNnHCMWioEb.dll
gWmNATUAsQcFetvCCTaGpjg.dll
FvcvDaZioFShXHTXwLc.dll
CuwDERyHkzyoCrVBffnhCiOqBBc.dll
peTaJdGeAlWrcZZpqU.dll
aecLhYqKagAISERArT.dll
wlfmqNVojjGPGqpNOjLaWrKNgi.dll
dEYScJmWGLlZGFFjGZ.dll
OzmyaFOGQgLGTRxnatsWpfsJqz.dll
EuKAFeuQSxVJMVtw.dll
xKsAweRRBazWOfaRrqPM.dll
fwKdEbnRoIGLKVEeVHDk.dll
vgdGVVEOJIwAVhHYnGM.dll
iTndBloNkdlrYkUqxiRS.dll
dDnJJFQcEZJWBMDYgjI.dll
NThEsxzJEYAfnVshffDePwO.dll
ggCzclsZmmFDkOYkXoAenJvuxK.dll
wpCbnQEkseyNeoCPEsMJ.dll
NUYTbsyVTajbmcvAcnxU.dll
wKHuqlSayIISfgtFSaHanRaWDm.dll
hUBbdrtckJsnbVhLLAeKqaB.dll
jUNmvPsJQYHsrXRrKhKkPxKtwP.dll
dtgSqwQTOWYbIsQmJvEnDQIvOV.dll
uwcoFjsasykBatjT.dll
uuYAHcouiyhQmlBWvJcfKjuyav.dll
oljbYQxRPIZwPfDIjsrQtPmeAT.dll
PujfCbTySLWyynnq.dll
XnvvoNrajxDOMqXbncFZzBsUDe.dll
sLiNBLAYVCenHXrSINp.dll
qjEJMKbDsJxvhqKTSNxHzAK.dll
EzUzgEUlgwiXdukwFt.dll
EfmjYLHgVdlSBBKYqmLnHGlylz.dll
LdjrAqwxvpiJiHrJbwns.dll
vYfbAWKnEyCmQlTgii.dll
hsnHMXLaKvXZqptw.dll
wcrRldaXvQItzqOyDPOG.dll
KtvYkirQYjfOnnCY.dll
xWzYoSozfirUekfCXVa.dll
oqsxMKzCHUHmuynZuipLvHrkZRo.dll
WrRxZCIsHqgxLewcxFnWQLjpYy.dll
PbwWPxtCyUtOxeCvOVf.dll
qwprMLbyHCSnpmKvHvK.dll
hvYoVujCvcZkCpMoLlJmvlZ.dll
BLcVrdyvIEPZSvVlFbPR.dll
nYVVEXYVXLYvHAKczZDjOJJrGP.dll
LRDODyrOSVZrLTLjThsUXBx.dll
clsZmmFDkOYkXoAenJvu.dll
TMhLHUdcNZblXgERQtMk.dll
jaaordCSSlnApEWlpB.dll
QBSovckjpsVysERZRpWFJFd.dll
VvpwxnZWZtnBSMFlSNJh.dll
XGlgUiEJBZDCSFJxys.dll
atuSWiVliIJmJDkqoD.dll
FEvPhFiUogBaKrA.dll
KeUrnwkCTUILoTgvVdSxdZnaYNl.dll
IgLgOJDswxoupvVk.dll
eVJDqSPmSHLbHfKBdrSffQS.dll
CHfFcvCCilQgbxpaFC.dll
LUTjenyczXCkDEB.dll
foMDtnkQMwQNheexwdiRAiaIeU.dll
NQvcpnjTxRjqdodwVN.dll
jHkVOMUQbZwUyQOqGBw.dll
ORLiktOUqhhbHauHdOiTrAlJYW.dll
LcYfwnIVDcUzVpoeAzup.dll
lUlactryRHIPBDOF.dll
GbpLgbDzaihRKGqrbFMX.dll
WOUYEjhpoPMlzIWdgXy.dll
McWCRkxFJDxvbaSrHEaNlYUiVX.dll
qCNmzTChttpArmxOCC.dll
liwvgEJPcbRglGboJT.dll
XCXsPeyRYqkEGCIlNJbx.dll
UexRLganqlUcyXUl.dll
CbcMIEcZpDrzJkPbGI.dll
GEDwZigQBMgggtdkKODdYeF.dll
LbrDXKxfsWQdIbMM.dll
gNrPkLVShBCSRHkr.dll
GtfVVKxSrHHmRMvqxQzX.dll
LGIOVEagwBsUoLnmufXKiKxuQo.dll
TlvaMElboYuMUfcTlCZgsTn.dll
dEBrhLGMbSIGDHyTml.dll
aHHCMQUomUhEWFtdiEGONgsyam.dll
ZAppEJJcylkUZfjY.dll
OqChNDzUzCVxMwpF.dll
utAfpVgpVaumNDXtwNLsuJLjBjq.dll
bMhjUjcyOxoMVyRxDQNPLLpJvz.dll
vImzYulcPcRJffDcYZVajpFVtl.dll
MSBxiWZngWkaHeeyGCcExTWWCz.dll
rjuMnlaqLLpJvwLJPE.dll
AOBLuAdRIibBhCqjYNUiuQBiiq.dll
MchGaHvqmUOwFGJsKZ.dll
WYlVmqBoXswgKWeA.dll
VjUYLPhzMApgjtiT.dll
ZyimgaghaLjDShChIiIkKCx.dll
SfcPolddisqLAAUa.dll
kGljxQVxNcUwDEgO.dll
ZQLXOvJDSQWnnQtGJcTeGlVjbD.dll
fZwCwMSFixnlHfAStDUd.dll
RBHGrQEMBYJLlAqJHPS.dll
GllLoOYTOOehIbYRUVfcyHmYqI.dll
xYvuRxmuINKiBYBxrcLQpzd.dll
FGlyMqhJHHLMLChoITH.dll
oCjiRgEDWXpsbFBmVL.dll
zKifQdUaddDRuDqj.dll
FLLpbeRwtxmrRgjjbOpkfGOcOS.dll
toNCqHIJnMYyjUifbjmejUf.dll
EQTqmxYAlmpQHsiqns.dll
nLsvJrJdmuFJunOAFuCD.dll
qslsubohqXwXVakdAMJfraf.dll
rxuUctjMmwNtQsQkncepkPcPRK.dll
QatEdifSgJLOauKruaR.dll
neyxHRWNwjsNFNytnwF.dll
ztgwcmvDPOXVwdLL.dll
ZtQQFreAjxvLPGffhAnLpmuowM.dll
dWbubGiUODpHSPtVyBMq.dll
jLpoQnuyQYplizLsPkTRtuQVie.dll
uYyNHTMmWwTGddFOXhxz.dll
SvNRMtRbMRNFOhlkeNK.dll
aPEIpLTkSpzrGuLdeZcTBnYqKc.dll
diJMUfHLAeaMCMHQ.dll
XkSwWpIrzlQzEaAZqWi.dll
UVGVlWCZacqTtIyA.dll
bxjKtJvJaFRPEqvVhBuN.dll
vZzhFuVPWoYZTEQNHRgVwThBpP.dll
TCTdyWWnxECxIHvq.dll
xQzWXaSJNYaYkPmh.dll
FbdrGQruAGhTUgNtqCY.dll
VAXuOsNIUVYflxfIVs.dll
afevMSjowpNWHssHjJCGEAKVlF.dll
RKcdZPzfryPzouHsuKNCzqzdgF.dll
UYWLQisBZWDcQOrTBz.dll
VEsfslzjOWjHtLOIzc.dll
YxqRMsBhfTDLgKXxBQonLeI.dll
GUvSRmNokeBEVsvkyS.dll
tHEFyjjJswwKXSlrIVX.dll
CwRlhrFteQxTTtLZceNK.dll
hClhqCCDngCSZyzMPHI.dll
NARMgTpHBdtRTTVaXS.dll
vWshlPFaUsvQEGvnkq.dll
fdzNxnIAhFTQeUBcGTMSGoOjUcQ.dll
BhYZdCBIItcOlGOrwPSwQGCRZSh.dll
jJreLsNoYGljwYBXnIB.dll
HnXooYaAgmBzmMqjKyJSAGhHcX.dll
blPuQIlUpEMjyQvqhTnHPGcRlJ.dll
ELsWriJyhHpTGMFIzVBHDIRUzu.dll
SlxjishdfwuUxGaemge.dll
lbUfzjnezvkiXWCaHC.dll
QmMzsPSisckVEfSYyDC.dll
dXZrDdKwmlIfRaIEAbzJVZJOWH.dll
spyJTExtnGOJlgerhRLTENsaWTd.dll
FQOGjNGrYSJpmaCCTMfqFeNdfu.dll
QzXSBMzPyeEtcZdaNQry.dll
LivTlimshxkVrtWaeJCLLFoVsqF.dll
kWFZEbCVmENPjwUvGoWWaPkxsQ.dll
cnVidlKXFMvEzYlRmonohgJmlk.dll
WtUpdVYpHWOTbvcgdP.dll
mDqLjywdapuDXLjR.dll
YOMFlRYNLbNcYvTnePn.dll
qFQpejoaHFzZLnGpzDH.dll
XOQusfLosIrtREibDoex.dll
QuzSrDBPWzQHBtFN.dll
pAFFWjbPdVDoAqzqgO.dll
XIulOBbZTkxblkzt.dll
HhVBXmYBiPcyEsdacV.dll
WjqzXGYwkYlDOMdVvd.dll
wcNCwWQDokvfjiTOTqo.dll
TjULZnuTccPiomDAHCx.dll
QRHNRQKDovvCuNEmqUz.dll
anZwjpGJJlJfIDLwdMkgxsqlxC.dll
PpFfjfmBejUWNsvhoMB.dll
OKEWETJWKByPyttxuTY.dll
MBTmbbmnMCXJaiQmSPP.dll
CrKVHptdxqXCmLb.dll
yoYmraiiXpwkDuafqrFR.dll
ZGjFfBGLKYpCYyGKFsse.dll
rnwxQIfEElKKvFAAkCsuoZU.dll
MzposuHmvzqgMpKtloSd.dll
WxarwtsBLDNDkgQAUDR.dll
VwKmkIXLoxpzZkvcHtwSqDHMzL.dll
pVSMuvdtEfcBQYUMiGmhmyu.dll
ceQgxFVVoniOZPIFAGnA.dll
OdgYNMZxljYGcPtxiDTrUXqGqV.dll
dXCEDhQpWLbtdEUdfvRwZnl.dll
wcrRldaXvQItzqOyDPOGWuXyaB.dll
HYUnChpyTuefTMGkjVBNVJihSHq.dll
vceknvqHeYcfnRSK.dll
NMWZrwnYxTfZmaV.dll
tyVCpAJLdCJKADVvyf.dll
guVvmaXpAoBRLyMq.dll
lllDbQuFCaZlmoOJUmR.dll
HusyEZLuRAtHrobkea.dll
eFxPbCEpOObCjfOTATIDFQmXZA.dll
SsvDrDgzGIHLKLvxEJe.dll
OUQjFUEcofEfUOonxTlyiUJ.dll
HQZFUoAGQlpUJBNxmZ.dll
QjrMwwjRcUSSvllkzC.dll
OBvWIzApdVChRVoY.dll
ElCmNgmombQVQyrlDsrPIpEZPI.dll
OtDtSwzwZtmjBOqyenfPJuctlq.dll
mscoree.dll
KMfpubIZYDVWWjKtFnAmsdRUzi.dll
yQRRRhfWSFNDUFTAXO.dll
WGTVnxmJgqXyuUdMeJjGnUsvTL.dll
JUhMjhGdrJxVLQaHbYkg.dll
qyUSVzGDYSWJbEhlhvE.dll
rovafktgspBSEsJtGdjykhE.dll
YkfxIHwmerZZRsFiEzlhaQTngFl.dll
qeMWQsOtIVvJieaxacOqWxnvUj.dll
evjIzNAYFLLiDWl.dll
ZkKWBWSYlyjSRiAj.dll
OeYrZbwtHAXoOhFmFFvPvZU.dll
mLUgEFXSWMqzdGefILV.dll
dhzLnZnqxyjhsriSfPTVlvqVYk.dll
YOdvhwUFYqeUJpYjyirCpGO.dll
EBKwIxPiEFOWsSCPyyuDapNznG.dll
ZPisIiIlnkgUjSQAzc.dll
pgLBDKjKGVWdxEmUqt.dll
WBjkHTevyQoFlsaWgjftfpkYliQ.dll
hGHylpOYcStHlLtfOQdw.dll
eIKTusyVsInJqJycFoG.dll
tOaeoQueGssHqaRWgl.dll
yjnIZYFRMPqEFpnBkdlmZXW.dll
uoMDRuIWTdaIUJOtssqoNQfvYb.dll
WUZjXoOdPSesKRES.dll
hQniiDfvTkzLjYkXptLkTSPwIX.dll
HaEFniirPyIBZgEgeHPjswONsU.dll
kBBJYweKAkMYadAWhKX.dll
ZPvmjUjyUhdjnewGMVlqcDfAaY.dll
qSAoCApENKlqBUNbRDW.dll
jONWvXBfsZksAljtydKOYMd.dll
jteHdDAPLtfriABkIr.dll
XlwYxKybLwQIqNmGtsMf.dll
zuJgCfNXDpYlcHQckmvh.dll
xcyiPkxmOAqbFuMrpFpppuAIlS.dll
EGnePqRJpyrLxRvuka.dll
ztwAabWIYbuBLWlkpwVlmkO.dll
ILbRPrXwHxyqKkPiDkQLyMd.dll
EdGyjSOaCiaEcEwCTdeyUPyhss.dll
PeJuTGKWkJjyyXIhmnASfaQIFd.dll
SyVQDgewXKZzKozGqQm.dll
WyNypUYgWOKPtrUORFXSzecNWS.dll
eSYrKbsnnopMQMMsrQDg.dll
VNyXPFEJcYWwXbCEFu.dll
VYPGbkPnkkkzRppgPbluzyaEDFj.dll
XipGOuEjczBEGTorKMbK.dll
DoNUdpJOPDmgRUIedo.dll
BOQSEMqPjwDXecTodGo.dll
CSwNJfnqqwlBdkoGyYuXcJAcNxO.dll
jlWrtEMFByyZsJLgTQbcusutRC.dll
mykLAgbrRtCaJKtNwe.dll
bwuDWNLJmUOrNQkAUG.dll
cQaTVfwWWmNdRzEmgtiS.dll
RNkhjcGstadULseFrYcI.dll
FTlgOzxaIPWXeQradMrroNedSZ.dll
nMIfgbWIYbxQpiYJrodw.dll
ffLzcAEAXYFzttk.dll
NieyctclACbRpJRlnEjZ.dll
EjDhTdTAxVAHnsylcZaQuGiKjO.dll
ZIEFcghXPytbVmmCAQcJSkNuAo.dll
QasOKLVwcejVouvEreJ.dll
BUcfmITCvTpkqWiAHbhwhkG.dll
ZUivtGahgTragXkc.dll
NFkZrKPFifsGCsoiDAW.dll
ocxkxZBZotfsynCclH.dll
SoCshvsvIxtMYMzbMfvyTdyIbR.dll
sDbjmZLjausFUEuIvtqX.dll
ZWVettQyHxAFuoPKruqVFGEeay.dll
HKmlHrBXfRdJRnJGiQVF.dll
klEWpgXvfUwYIYsgALlWuHZtff.dll
lZqtaOOgjnHzLUbA.dll
MpHeGCnBLhWXxsfZjiQVxOdHqx.dll
YWTgQbLoxsJoFxiUJkq.dll
xNnlojQRxGqJKWtOhZWr.dll
YTIyOZdLDCmeAHsezKyBCUwLYl.dll
GKGXrWFfJtecrtCoMP.dll
qrHnDxSWibmVCsrEKB.dll
uiwpwtLEFisruxtc.dll
oNvwxmKAnCMGYOJfAd.dll
jCnjTmokHCbdAWPZBAmZIOFXJy.dll
XxdqnTaMeXAWegDPvwdahUoyXl.dll
fcgUdhevqBcgMbpZncLkTItcsj.dll
HPVWnRpCrokaaCFzKRn.dll
iVOSgYsRqlHjqkNoMnBWVmrGRZ.dll
sJoPBhEXuSkClJMb.dll
RmQEAAhTwWDPJum.dll
iZlLNkrKeUSEEmyKJPjuZxXfOh.dll
mErwJBHMJvzrGaFBhe.dll
ReCGMhzIEobcxItPROK.dll
FgtKCDSNhxtxezjD.dll
RYtZXonDBTMoBShblMFaMHmgPB.dll
oZCRGnuGUMUHSwj.dll
ETMdnmxJKNQIyCKOuGB.dll
TfFDdkVLzquwDodVjAHJtdfqkr.dll
IGUCOCMqgvJABFmGQubSGFAAjG.dll
lFJBqsVgyPlDFCXjAoO.dll
KHbBhqdDpbycfpOtCnF.dll
pAlsWtbgGLbmJKZCfB.dll
fHMwxWNalAdFIAvrFE.dll
cSUsyYdqmhjzaXtcmfCKbomCld.dll
IcHnLuneCPbucQWqqojIWnVuPk.dll
ugOhynQaruIUOPskxY.dll
TYywoybvuXrYLSyfyQb.dll
QhKlrQEoScFCMXJbzenpwCYhkT.dll
MNQBHDEZEXoKnfcpAdtm.dll
OYzJOTchzDiSvmkkCs.dll
hIIctcOUoARkpKqX.dll
LIwkCqlHNPmINZCKuCHG.dll
PhbGSuwuJpRNIxNDyO.dll
PLxSFApwPxfnKnINzqL.dll
xTfZmaVffLzcAEAXYFz.dll
oysfgLEKBOVGeQWbBfTq.dll
PcRJffDcYZVajpFVtlw.dll
MEtyKyIXDsSniYAsAQnDGimBZp.dll
UMBNSAtNtlDTIOoK.dll
yjmXgcVdkgmPXwVfQmjLRvGWOy.dll
OimGJaZuJErJVJqK.dll
QEBUtfpmMuqfApBgIOEPnPD.dll
ypbYOIlQpfYSiReWDowOlUo.dll
LRvirXkalYaXdAW.dll
GunVQiatQUlatTnC.dll
WxoDNubgjoPjGPfZxMCCIotVKN.dll
MqJhDYkReOcFvfWYceG.dll
lkaSsLYSSihTbWXt.dll
rOONUCHydiAKIfyKsBOR.dll
SuQKRaHGwyVihvMOiF.dll
aYGifDRMHLuXWLZDuOReUClbki.dll
HwmJVdiIHvvQqSmWIBKZJOk.dll
eElRIZcYxYujTqcHaO.dll
hCdlGlPhVoDNwnNEQf.dll
OzqTtHFWSeRGOLCc.dll
hfGEUKgCUDNhmiBvwavJsmyGrH.dll
qfQHKNUumrhgQGTU.dll
hOFikZCdlProqKaAqQ.dll
cQcIpqMvJPNGJDx.dll
yfDoaOHoTbZejTDjDSuvpvqmof.dll
uHuLawvLecOmhYcUIRyqSTQYsI.dll
fgbVTmhtzwIMXJbzhz.dll
HfWLkGuQfcJiSJRPNDUZcCYPtY.dll
wiGiXgfefZkuKDqm.dll
xOPRZgofNnXPVpDFgcN.dll
yyIQSXvJTbskhXfiuCkdLMSpefG.dll
HFNwMabPSuNVvcpTUWlUJtw.dll
tArANqCqJtIlyRiaemBAyBt.dll
wULpUwdEnPelXYRj.dll
WDPApAzpMhmsxbqotMaEuYeqDo.dll
VAMPKYhhUxZYvgdMmO.dll
bpNAGSalYeKcYZmmuuY.dll
WRrXKkSveqAiONtbnftXimoTBG.dll
JMZcjwHYBfwijLjwWlPheKeemO.dll
LLFAywZvmpwvpowMFJsQ.dll
CktZBerPimYxcrNuoljb.dll
iKwTBMOWWQgSrrFZqohRCdvxRm.dll
YUHijwOEUahMIKJdxbz.dll
YvZQAXsOEwQZyXNPWxCJKsnEFG.dll
vaJXVSSIVCMFCFpVttOehlxVuS.dll
ZlJXiBBBeCaftrfiibph.dll
mWJzsFonFeiIhdvGDE.dll
SnsKNzOznMfwgcdnNncgoNJSKB.dll
dhCzNuTdWpkHHSRkXX.dll
FdWBHiwsxESGeFdvSNPl.dll
axUrJISHKundUfAztpwFSYZOYu.dll
HUkYDJsdCNtoWMAEoFsUAjTfqe.dll
UYDSWJDxExMOQaMhHH.dll
hWXxsfZjiQVxOdH.dll
LBjagFUvbUiWJMFn.dll
VQQGsahuGUOCEoGTGaUGhXjmbE.dll
BZXPnUToWKCbnmuYKa.dll
JtsBSiBDgNVahbRsJYaIsNbswb.dll
wKTZpIfKYvoSEJnHxwoOpoR.dll
savUgAdcnizCCTzvHF.dll
szaKgMFOEoYWbVwkqrr.dll
PnlNKRPmaoNgsGRubVXx.dll
jsfPoZhRsCHPCKGyIKR.dll
rWAQfXWtgSAcTGVihsf.dll
YhdvIJcjEGAPYQExhl.dll
DCOteGgggrfaFWsCut.dll
eNkFxFePjahCnlPCFMYlPAZEJH.dll
xtaMNhgiAWWeGmhhRhZhcPnIXY.dll
PCDvDTeBDKsCsFwzMMrGdFHRvt.dll
LVBCtaWsJadxHpAV.dll
PDEtpNdrtoeanaNASpH.dll
yzWhbOGCmJefDqJBKjqeQzeRqij.dll
RYKERUmbkQCgHKDGpHoSuzeYzj.dll
oIKxKqkRSvWbtQseQfBf.dll
ydiReJrxbCijoYqyOnRV.dll
QGmOdfeFJeNCwBdhWwU.dll
ZmaVffLzcAEAXYFzttkGGoBjvu.dll
eFtrQXldjCsvnPEelHUt.dll
tzTFqlcczQBiLXIHLMl.dll
DCzvMoZiutBYCBAZkCSnpqRCDW.dll
JyZRYYIjHFsashzTXUXdXbBOwT.dll
uKgYurRnnHeLZbbZmRC.dll
XsLLvhUSGPUuWQcD.dll
BBZMbpBHqwgIWAIfriObYylVny.dll
WrHhxFbIhHPCTSCvHIooxzpwtBD.dll
EuPLqlNfjXUFpcteyLxCJofOiB.dll
vmTeHqCQWNoairEnKsXB.dll
pPVhoHkOrhXYojfr.dll
KwhmAhvusYmZbWWGVmxL.dll
EyltWdubbstVwuwzoQk.dll
EvhcyzXpdIrWTCLjWOCXaVIhvhm.dll
bNlJCyVEYkQyeyDv.dll
eHyTtrQlQRbQiVWzUifZ.dll
wRHZgEuLjEXHETRYCdX.dll
RWvMfUtjLDDTZzydQCfitcqnbz.dll
wZnQXOgqxkfdQuxK.dll
wMBhwYnquMwyLMMLGWdpoRbZOK.dll
qEvWcuaKNsShFqahzig.dll
QbLoxsJoFxiUJkqdtfcUXwDQJx.dll
jqYoNcndEPbNrPErnO.dll
VcgwxnIqAndybdVw.dll
AzOMurweiCzxEUxqrs.dll
SJxIscdFazAxhwqBNmc.dll
TpUqFaDmpYNUiyUOVXroDqBzVW.dll
bVGYlRGXggmLNVeMGgjo.dll
XOCcRWIdHOSTRlFxRidXJVpTtI.dll
GHswofJEAJEsdedJPlRZzYG.dll
CnAIxIMmABGiNdCi.dll
fOQmWAARxuwyoqpvUJAiBWY.dll
NJINOmvjVGjqvLNxjcMHXjlADN.dll
wFisSLpmZINUDoeNHMt.dll
uaNPrEHCtXrFUyPyeWG.dll
qVQufPgvfXZWCAcEAK.dll
FPlUDrdenClQqYiLgMI.dll
dMmoZJLJkPoUhTUYDlgVXcooKXf.dll
tyMzELrfOqcrsxlbagddJxI.dll
XCghDVAtrBgOkcDYas.dll
VlUNPaZAzjrJzCXtYh.dll
xIytGQghsthrTejaLPnlDqTZxK.dll
fSGWNWqeXWPWuZnBidldnrMnliy.dll
qJTpgzizWcgHhUFnFN.dll
JWDZphNzMFZCEMnTfQ.dll
bHDEHljrbExgGCgCIj.dll
QYFmPaomxgcsYmCHmtwcCbETuP.dll
gnpYwOvgFVVpkXBaTBF.dll
fJgtRNmKcwWZKuilsSTF.dll
sIWBueMJIDcYWzJCNnPv.dll
BSDoBxxdJCTozOEvsKh.dll
brxbDJwJgaCubSIuxSLBVkAFOJ.dll
dYVbAhWJlvvWpYhtaVRgFphpboQ.dll
aaaVewzAiropzXRsRFCxAYqnYc.dll
FTiTAmMgeKEtZwPUkf.dll
jQthgOAsyccXoFzNlcXY.dll
CXVIspUlezBTAJFTXO.dll
IPXnlWacxtiUtSVbQa.dll
jjbpAtrQMgOOlTfeHuT.dll
sieCZHNjMBJyTENpiO.dll
nOStmdpzhJBAdafrIHH.dll
gCOXvUeZhpLwUWyaaQJ.dll
lZbUcitRIZiqzQOBOSvQRZbYOz.dll
ttkGGoBjvuWeIryKEAr.dll
rQWQvydLkpUYWMqxyG.dll
vKnwxgkpsThyFzljXYKYXeAfKeu.dll
WdNdhBHHOcQxcKb.dll
ejnHGCnwcQcIpqMvJPN.dll
sbAnbOiVCFLOcXGFiQZ.dll
XgkDfueHXURYwEFzShS.dll
eYMYsIUSHOMHWKwfwzqUZYZfkfJ.dll
CUJYLNKqUEcUoWWnvTpJAvgGJa.dll
mBijVWvMxfEFJqJhHJML.dll
ykPrqMVIieRnZqAepglN.dll
ZGXCsKTMfpiebXuXrvYexAodNf.dll
UUTjIgAcgFliqqczTJvguZELZH.dll
MxWXdMwBIDpViUGrioiHZML.dll
PAWsIkJntPfyGITp.dll
QWhWgzxcqVafoVjWWz.dll
lDbAxZAwWaBfArlaOiKTdYs.dll
pgHMVqAdjSmDjtrEMtR.dll
xBoBbVAqHSFdaINzaoG.dll
SeBhpKCbiLjDCMxpTCoTOiCjcK.dll
OLqZnDvjvrlyidzwHUguArI.dll
dcSGJsqaMqZJuVcdGtjSMXUffe.dll
NcIvSnoYlXroovyMBb.dll
HLjBrWLBRylztpcZnIhv.dll
yleTYJZcfFRYgeFWjO.dll
EsIpaLKvizKfyEJEKcbt.dll
kGcgeefanKoEdSBI.dll
wRnInHZSsmioHZJd.dll
IcefSfxMucYBPUsuxKTKRfG.dll
YbtpAuIMILlCmQwAfXB.dll
vPhFiUogBaKrAwXuGDB.dll
jiFfgxAftxAJAIdvAgw.dll
ItZBQndzoFMsBeFDNRjjzWyfsj.dll
TiOBziDUklhmXKXhAoyX.dll
DtgUYVEWMUuyMibOMiHpulgJPw.dll
UWteAXSQSVfdFryvJSzr.dll
LYaYoMQAvyeDCgXlXZSpoNlEkM.dll
frjQqCTMhLHUdcNZblXgERQtMk.dll
GnKjgYagDzBpfIMITMdYTSuhTa.dll
OkLzWEfcSzkQKuYZVrp.dll
TUpDuhUEdOJkzAwEBmqc.dll
igoEDfGlivKPxkolGpKj.dll
jqfKLdXhzuwoixcH.dll
dEDMKWbAeVVFOzSiETnHYpxixM.dll
yRmIxcQHnpmkikRc.dll
HbdgCLIeHOjMVieTRsc.dll
cURJilcEGOPrPRvWBh.dll
hUjSqnTrBXwLvagb.dll
IXIZJfVaHGDMKENisRci.dll
LdHOtPRDNnLBRypsnnFg.dll
NMMaanxmEmxtLfAxZRGC.dll
FxPhnhMJTSSInPYVdqUDHPs.dll
DkyQmntvawxwHKEkQB.dll
UXITIFNEvicHhiNcjHNNfqQQUm.dll
aCnffAFVBAMBEFNGolG.dll
nHjjqvLYUnZSpXXkGMYhmai.dll
xfmHsTupKZbPloZqsHUB.dll
CpglUGIKhYaMwIWudC.dll
mDYBfbDzfVDkvXFvLTowXpEpDc.dll
pcccZWrBPZqNItpmlEKnHsOTdr.dll
gidihwHzuAOhHAXsbNU.dll
XlsCuHHUTjIclStcSifKZUIIQu.dll
bzPRuGrCdKfeZkpqSKVr.dll
WeIryKEArjjHfVnrNbUrHmSSJD.dll
KDWbELryCvfpsWjIwksBWZpJjn.dll
YpyOJWMbkBuWDDNVoE.dll
JZuyuHAmNcdsnqeIVfT.dll
MDWyFQCweAXbsvwjujS.dll
adyWbsvIlTgncAArIwEHQcjqYO.dll
jYQaXGSHchJDtTJvvNJ.dll
DIjsrQtPmeATjnAAGDk.dll
cJdImcvjoITuSNGpkG.dll
ENjpeDyIHuSnLPztBXTBUIlglnE.dll
DxUXcWRDTEkVgyEiUUsq.dll
gclbboMRBtLPFSzaBO.dll
VDIhQhaQSNHJjyzPqa.dll
dorkESjFqKoiqdFDVo.dll
RiTOmxxvWamQovTwAaLRTTL.dll
qxEFTzWveQfkQxX.dll
zefrFOLvkbpyhPHWhh.dll
CNDqZCpfRCVTPTwdcYtlucN.dll
obnDelOOQoTkELsLcnmBDFczmc.dll
xfmhtbuwRloJBoZJuKu.dll
zYTUGxPxETqqkIaeWY.dll
fESSpZADlsTKCHLbog.dll
YXjSdQJyzyjybOJZCmQybGkTZB.dll
RZXDAheJWlJjHShxOV.dll
ZApBdLzLWTUPXbIvgCR.dll
AXKXjHALwURMTMDHClwr.dll
ajcNFGPOcWCQamAWHhXobjXWYH.dll
HzdvckiXPtuYMRZIsKW.dll
pvJzmOyqNrQLhKfX.dll
IoIUUtbvWvOyeseVRZHwimR.dll
yYnBLyGMpJsaePVPRrZ.dll
AFPWpBWgwndcVRUJctUW.dll
nhluGJSHjBMgLBVbXJ.dll
yubMspLGlBeqwemVBUCWRTZ.dll
SxlJcpbZNjYmJOtN.dll
SKfhqmKxwhZdntNdCVQD.dll
IyDNnvmmeiXTljOx.dll
NzfPLGMjdBFBZPXttH.dll
modViHKgdKoWhFicjpUVzwPFUGR.dll
JJaJNlNfNyJbMxsomblJrwqSbA.dll
YmBWNMrQPfcNBxjHnLs.dll
EwoLnnfCxrvaVurlGEBmaQh.dll
aaBLLRJKQBPylqoSKXjIeLbmHd.dll
qhWzFarKoKjQsljtRg.dll
RwvIuMKrDqsQFPQwfZtQpANBJF.dll
YOzwSzwZRRwEUcka.dll
GcZGFqeiihBfpdLfTJVhLQLhrC.dll
jiRCRFvcrWRYfHdwpiHUlRhmjW.dll
wszRaheswgkfWlEtrGdA.dll
BhTwzjfIqpzlvRbnTH.dll
rvfZltLGCjtzYDHExceR.dll
bvXELBShASfgFTUkUuDXWDfulZ.dll
ETKCFZbrZSQGJGDplVXditgOSr.dll
QPRKprOUgXIbwzrVeJeYBltZqc.dll
sZcjzhhMGoqzImbFpvFUkkavET.dll
xkMrkUblIvcrdSsYQzh.dll
rUURodGsitharNTNjxsZIzJVzG.dll
JHIDnkHrMzpUiebqsV.dll
NHxUZJMPviGFYjjtmoZFzABGAt.dll
PDDLbqoujauBQCsuxoqXIMW.dll
FwhhZxNdRxWpQZnW.dll
WpPEeIyOaOMtJjBIyJGSGAyCvHi.dll
xOcnKGfqxSnIPjiDjyyQpXuFLD.dll
TCQIVTqNlmdLJSeTheN.dll
IP Found
No IP detected
URL(s)
https://u.lewd.se/GTsvf0_gEsjiKAz.jpg
System.Reflection.Assembly
UiiJaXWLUaVUGFNqZt
Comments
PVLqjmlpgZkCsdcJoC
a64841068aed4a7896d90665e3fc696c
uvesTBHeQccbrqskIf
URfCgyVPPgMpkPkDKL
ZCmQybGkTZBmDYBfbD
InternalName
addeea76f7aa4df8852e0cde6c47fc4a
KxotNnmEeSNRyMmPoM
tjublxuMhIPfTqKcXe
nSuZJaHAqQMufahEuYPWohybNKL
AJupkuYNysuaTMlUAl
uvfsTEabrEPvFxSMDx
zOOdSrlrEApxXhprts
Translation
SQwwbdoKAkYDLWgxCo
AAmLzDptYwWTuKWLQG
5c81e4c9-0e39-45b5-8d55-c68ebfb52a8bbc549b15-e16b-48b2-a12d-1d7580f05018287d352f-b80f-
NriBGCufkcaaabtkvH
CompanyName
a082a397bd234399b9cde7c37cac24f1
mWmUgpgljsnnUGoRQT
IrioJXHWejeXCuKXyq
ufilWSLuaSAGBKvsEa
a41536bd37e84fc6938c18fe665d7ee5
DDVoSApJKAiTNjEeqC
HHJmKgAlWkzELCGWTx
Form1
ERPspDWbeoUBrGvBwm
LLiDWlWdNdhBHHO
ymTLhzzyppCasZwSwuXLtai
bfqmrgrlKxjWdRLWQM
LegalCopyright
YFzttkGGoBjvuWeIryKEArjjHfV
SDIpLLGhrmyEhUFdgl
NYiXMVHPfWOFHwFMGQ
DNMcWykiZbVFzGQxVD
BNjqlPklyRsjgOcLDf
RZOtlzPpFfjfmBe
SeOFrrDvMIEkEGobhT
GNIEPTDPbBISjBFhis
EcScEIAYakiTboB
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
0796852.exe
WnsYDVaXZeCHAwvJmX
wAOwmnkudPGAqZnpoIDORea
KwUsHYDVUobbahjXDr
VarFileInfo
HIIOGnEFxwdLMCG
KiFmUqXBaJoSudNnuS
40530
qUzyHVCrzNGyoCjLpS
QsqPExKwDWhehzdkMR
ZeaXjcjLAnsEFgodDE
d5b95cadfe3a45fa8d6dd6686afa1616
ZuLKaLzoERgocncJVf
otQsKCWSIGBnQyTeaR
PNTdzvZzhFuVPWoYZT
1.0.0.0
lWYKchFDYUMRmJugKB
kIgyuDhwCsJHITbLHK
osMhQFNffWaUwwAAuO
nGMpHeGCnBLhWXxsfZjiQVxOdHq
EgTnMSRmHhzWzyvuTl
a80431e388474d4ca82d2abb482cce81
xCsbnKSMadwtpNwIyB
Copyright
MQjYhQXEYFmVERplTa
PCybKyMjJbxBlqCVjb
jUWNsvhoMBOKEWE
debug
lDqTZxKLGIOVEagwBs
tYzdLnyLPZzJrrS
VQPTEHpqHtaMYMVOYk
53d6382b-14e4-41e6-b6e8-07bcee8e2d3894
KIaTiOBziDUklhm
vYulrzyKqFtVgzO
eda6641dfa0e4a8784ccc4369a6b5923
RQlrhFaJQfxrEGxGnE
LegalTrademarks
GWuXyaBiEkpnucx
vILOegbkUWHRvAVGWs
fYuSyMXRpychzWoRwN
pnKeyBnxhQSGtFHjPi
xEFTzWveQfkQxXOHRKNEvBGhjfv
eMJIDcYWzJCNnPvfJg
KkqnmxzSFbSBqkiHVw
zrpcrDmmPhSLZkpgtrKMaYc
ec32145a6bec4b6b95ff4c7c4e90ec20
sbPFAeGPQJXBRwJojr
ae4b64f1d7ce40a49153c4f2792a9e18
ZjmyvDxgRV
.exe
ProductVersion
FZkPxrqdupWrbCWoDC
COR
BPiVrehlLAzBsOrWmY
FileDescription
a3817571c45d48989978a8db46f85618
NRehfomKxjzzhMgkTV
PVGMoQhKlrNKKJp
Start
lGkrZfQVdYvZQAXsOE
DWiMeIfGAtyBoqdGzP
iIjHLxUwcXwQfmTkeH
oHRuhfrstVwfVqpURU
bfbd4936f2e04ca1b4961462f0ced884
zYulcPcRJffDcYZ
ad1c8f0e4c7441209b69c3a002da46c9
sSPXrAioPQjJUHlosv
uRpaMREFhDHJywVxqS
FfHUWtivCfIsSmoBaG
ETMdnmxJKNQIyCKOuG
zUQKZoWxBQQtvUCQuz
OUnYkbYBFmSJXAZtjA
"%1" %*
gwboXwKBqzFFaBhXyb
OIIToLQgSZPoBeBFII
VtBJQPEYSZIKBeP
VS_VERSION_INFO
wKmkIXLoxpzZkvcHtw
LEHyIKDRfeQKOAgmic
kDfueHXURYwEFzShSYUrlHndqnR
a4e40ac65601413da62d7fd8470f20d2
zaXtcmfCKbomCldwDd
UxfdhbgaSUZSgjwodE
fNyJbMxsomblJrwqSb
true
PGUxixAWbObXkcHrzo
Load
a27fd372ce984ff5af3b7bbfca1193d2
a10833d52a784977b1a685f95b478f09
PODIZANJE
qdtfcUXwDQJxOdg
GetEnvironmentVariable
gQbLoxsJoFxiUJk
AMYxEjVmKTLIvxbrnDeLeyA
YLYaYoMQAvyeDCgXlX
This application cannot start!
FNdfVzeAFNSQxpMzHz
MHgrolMPNIzCEUCIxG
2017
fBqmqXzefWiUGnGcID
XKXhAoyXXOQusfL
nZfzMsjYIEjtDyDdlW
Assembly Version
cgFSdiWBQomXHfMQqL
false
YDsINPALnKHycrpHSn
329216
oTVwJpqFQpejoaHFzZLnGpzDHXg
https://u.lewd.se/GTsvf0_gEsjiKAz.jpg
MezeyNsVjWWDGYwhef
vLxmKgHNDTbYSldoPr
TXkgnPNZefwnIkaVTj
fnHfwGDJZqlppcRGjfRAiCF
cPIXFhsXDLmrvzETIC
ProductName
qpfkLQZaouzZTPgQoq
WioEbeeaupcoUFdPjN
Handle
FZHNtRMBdrArGpHqDq
Invoke
OCsGPjxAfiJyUjppIh
8T\
NVojjGPGqpNOjLaWrK
ZADBDxWnyVVZsxM
adc164053b5e4d37a06df681c4c21f5b
CNknKLgDqvfgiFimOc
OBOSvQRZbYOzvIm
StringFileInfo
ldaXvQItzqOyDPO
EntryPoint
kyzNMWZrwnYxTfZmaVffLzcAEAX
ocOTNOvBzRlgVprmel
FD9E75A766FCA60532189E6FF791653C9BF85851
0796852, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
DownloadData
FileVersion
6a2a9f61-7a64-4b47-8261-a5f4e4eb8894ca107063-2ecd-4
cQxcKbhlyNvwSji
ZnRNChrSLiCYEAw
WwIObzDhEPenqKDhQA
uwcztizoizUAYhuNDA
000004b0
NeQzDFjybVkMLuyKpC
CDZJTpgGQCUpGHRTSu
CIGbEpVpamJhotHhxw
kEWEpWjFHHSopsZmXzwByZW
JRPNDUZcCYPtYGnIXg
DxvbaSrHEaNlYUiVXQ
OriginalFilename
uZNYuiGeRaHoNECzmj
jlZbUcitRIZiqzQ
UojaAbyqBIQHOJtrps
gGbePiBQLfxgDOdLtA
c695a14fd6f04ad482a93a041ab5c7d8
zhCLsMRraWRFJObsqU
ccb0adf678694fb9ac27f911276a3f7a
vBcddscYaCwRlhrFte
MPOLFVE.Resources
Sleep
RQawWAsyGIanxotjID
_ENABLE_PROFILING
eWiBWUiapmkpBZQLXO
eNwbZEZKoFjtcBCKhTjUBLizut
AazLcLuWHUCeAvctVfAKrqn.dll
(J2Z
UDidRIKAqazmveeAIAL
ZHZOcOtxFWYcUVspXc
QqsbcWKjbRPCyXvHXvnR
Int32
PPtjmLJiyKjaWHfTHXkXuquiLiX.dll
uxINcQOmRcDWLwkRZc.drv
7a8>
f LZ
sJZsQtVUvZbVzTySjgL
2a8!
ConfusedByAttribute
OSxessusUMjRTuXjfPKU.dll
JAhNUpdlUSndipbvgMyRScnfvm.dll
izLxpsneNbksUVBCEd.dll
CtBmbNAXqyHTxCNoXoDETivSCO
jnAAGDklFJBqsVgyPlDFCXjAoO.dll
BtWigTDdqOZJsRQlPD
xFbSpBBnBDaTSgclTr
7a8Z
PwCucUgNFpaXQYDfcNh.dll
4nB58
qomqyUSVzGDYSWJ.drv
uzahGUVKcGdBiSi
Z &P
PIpniZwAPfxzbicyxMtr
UZrQGDxYCGOdIeZCrxwL.drv
qyhcnNSLZTdjCzm.dll
-ca8
z<$ 8
EXlnPJSDkyeseHvr
swIqyeVEoeVWibCOSieJudBfWy.dll
KbmfWgbFXTJBqoIekKJnsquPKz.drv
adVnAlWIQmIEMbxMFQtlyDPTOh.dll
TKGamJeszLQEjarixJ
kbApGAfKuUsqdLNEJe.drv
ORVSkXrVCWxymivSmkvzxThrxh
H(a+
VqOkDnwyLQFmOXPiEMflupm.dll
hiyYNEQWoNBegvqDnT.dll
VSiWXxZYSLMgCpbiNW
^lXa+
gpLHOSQevlfmQBhXCmER.dll
wXeDJUUSpLNLnKUZyP
LateCall
-VK8
jSbdlHCuIObRiHJZrC.dll
z :
qYoNbkJHNoapFQCTXigkibYYgf
IZa8
BoDLTkgwRDFEzJQRBIOuMVYkww.drv
UgBYGzLMxXTjhmJKrqw.dll
Copyright

DebuggerStepThroughAttribute
y*Z
klhmXKXhAoyXXOQusfLosIrtRE.drv
sJqXgRxtKrfHlSMQjprjNyhKdM.dll
emCRCqNrJEuTQWxiAqZQZgpDqp
JAPrngxWjnjHRvbmiSJ
TyVDErJFtrIldJCnfXvCLRdVMV
ZjjHAqHlOVlvOsLB.drv
GGNNLQNMucoCxulqSZiZOwIwhS
TJzLTYTdsCPrXqCj.dll
C%&8Q
fUastmYFuNvqftvtXoRVeHtAXf
wDdmfNVmpfGGbeutNnHCMWioEb.dll
LJwEpEmMvLwbBJRkRt
bnSYUPseGrtiCZmc.drv
gWmNATUAsQcFetvCCTaGpjg.dll
FvcvDaZioFShXHTXwLc.dll
Marshal
ZLFrgufRlevfGzFHPnXTVdLHLK
*Aa8
GfZa8o
CuwDERyHkzyoCrVBffnhCiOqBBc.dll
MvqQxCwZjDrXsuipzt
lJLxjIIkRshUdJPRhN
FtwsCONuEixzSyJA
peTaJdGeAlWrcZZpqU.dll
<FZ
WdjPTpAsEHMYpfnmkRJQlnzSvDM
SjcKEARGrIZBfIIqilsyRttStd
aecLhYqKagAISERArT.dll
hhqwGLWWZCRnTCYbIboWUlwbkC
wlfmqNVojjGPGqpNOjLaWrKNgi.dll
dEYScJmWGLlZGFFjGZ.dll
OzmyaFOGQgLGTRxnatsWpfsJqz.dll
czXLLVoLffaILtWpgQRP
# Eo8
EuKAFeuQSxVJMVtw.dll
xKsAweRRBazWOfaRrqPM.dll
dWbtYMkSUTVsaAZlhgdYpse
aWDWGqbvrRzzJMikisYlAnCQdI
fwKdEbnRoIGLKVEeVHDk.dll
vgdGVVEOJIwAVhHYnGM.dll
iefShtZPxTwEEHkLwMfZBpNHzz
iTndBloNkdlrYkUqxiRS.dll
Z F*;ea8
yEkciDPvZeBuCzwCVLy.drv
VSbVvydPhrPGavWpOUAnrpPqkY
QElUNlmadxGMamWb
dDnJJFQcEZJWBMDYgjI.dll
@%(@
ZTPffoXgHLMRocXKZbs
bvxIfmZQQfjTTORnXcrn.drv
NThEsxzJEYAfnVshffDePwO.dll
dBZllftmwpRAMrEl
plNEKbjoQHGjlZIm
ggCzclsZmmFDkOYkXoAenJvuxK.dll
IULVvvDVCTHVcUvYsZNGLZyuna
.%D8
wpCbnQEkseyNeoCPEsMJ.dll
zhPiQZIqsUZNYXjm
NUYTbsyVTajbmcvAcnxU.dll
]a8=
sBSkbWweeJkOcwNwxN
mPleitOkOQIkoayaJIXcxKSgYM
Z C2C
rnYVCBiJEhiCIhfWNOWJCwCeuo
Z ?mk
AssemblyCompanyAttribute
DV8b
xxCqVBDwLaxLivbnFSCC
lKtzpQcxRfzvmHLD
BPnxzbHqpKsvaWYrJUB
wKHuqlSayIISfgtFSaHanRaWDm.dll
yEZhKbVbkwYwgOXLdCrQdUNOyb.drv
RCMMwmSrowcbSoAzLKJayNAoMA
hUBbdrtckJsnbVhLLAeKqaB.dll
Gm8j
jUNmvPsJQYHsrXRrKhKkPxKtwP.dll
NBdCIfcqFMRMAfQghWlRyOzUUol
pa8u
ea8)
oT88
dtgSqwQTOWYbIsQmJvEnDQIvOV.dll
MPvwNYPkRRePSiJK
Z C+
uUFjjPKpoBIZJaMpQrOjRWlPOBy.drv
a>%8w
AppWinStyle
uwcoFjsasykBatjT.dll
uuYAHcouiyhQmlBWvJcfKjuyav.dll
oljbYQxRPIZwPfDIjsrQtPmeAT.dll
IZ i
QUINCaXsWbNKNgCucHMnOfmjpM.drv
PujfCbTySLWyynnq.dll
Z PF9)a8
WjHWcsnRGKWOioJBtHHI
CompareString
SoowsdYKTKowFqzG.drv
LgRLAJbVZTnxvWnclKksuZs.drv
R>a8e
j+18.
qwf8h
Exists
cWSPEuAexDLqZesjoucBNIVcbXe
11h
PADPADP
pRBTfyoRcwNJDqcm
wWJBXFwLUKMQKmVTUn.drv
XnvvoNrajxDOMqXbncFZzBsUDe.dll
lAeReBzFwWolQGXaaQDW
miBEVtuCwowShNHHdG
qEzUBrEDKdJKKiTPOH.drv
sLiNBLAYVCenHXrSINp.dll
Z x8k~a8
BpxcjtxTaqIvBcddscYa
qjEJMKbDsJxvhqKTSNxHzAK.dll
UBJafkKJLTGZxTKv
vCeTSCTheUyfgbINfo
KsqQFthmExaeRAarqJnCyrNOcp
AssemblyTrademarkAttribute
EzUzgEUlgwiXdukwFt.dll
ZflprfWCvtMprRmMcFGVcqCaUf
9a8]
qYyPrOPTPWgjuclDethQZwMDyqi
EfmjYLHgVdlSBBKYqmLnHGlylz.dll
slZQvtPAdWKIBXWJuM.drv
Path
zLqwZlCuySaLLdgB.drv
ibBhCqjYNUiuQBiiqom
QAEolqMbawwoSwayEHw.drv
jrgGviZBAgCnZmsHSybKNIBpMw
LdjrAqwxvpiJiHrJbwns.dll
OyhIZjXTlBgJTNJdgv
lSFmJpYFhVAwVKFdPmVg
vYfbAWKnEyCmQlTgii.dll
tAwhzCvzdNRyouLVyGL
UQzxotFTByKTaFrqotdeUkfOQMg
hsnHMXLaKvXZqptw.dll
trFjbafoFtxoDKtamFpt
#Blob
WIDGFiIppLJfWmMEue
SandboxieDcomLaunch
Copy
wcrRldaXvQItzqOyDPOG.dll
MqqkbqbCpCCREVWvcDe
LBwkmHNueReFOzlXTTVpamCNkw
HtjHLczquaABZHLLYU.drv
KtvYkirQYjfOnnCY.dll
bVXCwFSpaxWQJuYD
yyolKqBMoQwDUDv
xWzYoSozfirUekfCXVa.dll
oqsxMKzCHUHmuynZuipLvHrkZRo.dll
gabQpCNChyZRgupOyzt.drv
AssemblyFileVersionAttribute
AtQjPxJmWmkaApgMGZLmyyK
MfDLUXsPhZodbuOrtZX
mrznLWDzLWVGIounzIl
Type
tdovhcAayHzansSEWVa
My.Settings
WrRxZCIsHqgxLewcxFnWQLjpYy.dll
Substring
d5b95cadfe3a45fa8d6dd6686afa1616
DiWWxZjvSfMFrxRwbAG
^E
PbwWPxtCyUtOxeCvOVf.dll
wbneVFjTOrdBGmmbQOpJcebocf.drv
qwprMLbyHCSnpmKvHvK.dll
HelpKeywordAttribute
xCjRRjclMwjeRKSavRuNBRyWFUT.drv
FHpZGiQLEqGRZvUZYcYuzmSDWJz
hvYoVujCvcZkCpMoLlJmvlZ.dll
BLcVrdyvIEPZSvVlFbPR.dll
XaSIYzdsCtmJqNruijsIyWJorS
jLhuQHhqWyyOARnBmyr
BGSpIBdGVqWkLGLonpuKdxXMwu.drv
uQEBKwIxPiEFOWsSCPy
dPJRgkSTKieplnQzEOn
CkDEBwwHjxmWiechxFWzNQTFay
nYVVEXYVXLYvHAKczZDjOJJrGP.dll
aYWDjomzSDvnSNWHbVOGsGKEXNB.drv
LRDODyrOSVZrLTLjThsUXBx.dll
clsZmmFDkOYkXoAenJvu.dll
CqXOsKiXnjYTzfem.drv
TMhLHUdcNZblXgERQtMk.dll
jaaordCSSlnApEWlpB.dll
TXlZGOJxMGoQNlInLONNpvElhnt.drv
ae4b64f1d7ce40a49153c4f2792a9e18
QBSovckjpsVysERZRpWFJFd.dll
pONCtpcFhJZDuXdOMMFxkWU.drv
2i-8
LateGet
VvpwxnZWZtnBSMFlSNJh.dll
pmmVrLkZdSDmpGaroUTmlzYlcF
XGlgUiEJBZDCSFJxys.dll
ca8~
Z bX+
ca8O
iFZ \
SuWyYBnTjyIOgWDKlwXpLfoDEu
atuSWiVliIJmJDkqoD.dll
ZnPSWtYgATRQAQUUtd
zsPFsEjdHlkWAeWFyytWfinUKf
eWFTfEoTzRmbsBgxaAqLddqgRPJ
vmtoolsd
FEvPhFiUogBaKrA.dll
cWqNajhJZJUogJRz
g+:
QbDrTaYifWSDZKLxzwiSUGG
_Y
rSPVGMoQhKlrNKKJpVt
(5?'8
Z b[
IxKXOONDvCcbGCJmNboBfrz
`\H@Z D
KeUrnwkCTUILoTgvVdSxdZnaYNl.dll
w}%&
IgLgOJDswxoupvVk.dll
ca8
StandardModuleAttribute
Z 0,h
iDzOtSHKUDvqaMGWHvoi
gervwbjkDFSGdDTO.drv
eVJDqSPmSHLbHfKBdrSffQS.dll
YPTkItkiOEcScEI
WeEuXHAqDhmyvKJfBpaVXcpkgGg
djtWgDTcFOCYqissMKWnjCyrSAk.drv
INPALnKHycrpHSndUeHjMkXZCR
YzjPjUwgbtvQNiRJaj.drv
Z @\
kFZ
jSa%
lcVjktASPaDQHJQpKuNOlPNYDs.drv
cSJJZFajVprASxmJZteXTLMuYz
WrapNonExceptionThrows
frvqpejZKaaoBIMZVq
dLajlOIUCnWRQwphnWHOHukRsm
QKExAhLodiEEdQrpDeDoKesIJl
ReferenceEquals
jjCxrBqKhJhzNrDxFhy.drv
.text
List`1
"^E"
*Ur8O
ttmvwkIWHwxKBIzLhI
CHfFcvCCilQgbxpaFC.dll
GVFXHNLGuREwIrkeeFxDzvZYhL.drv
qCcPYmGmYjZdorpvRA.drv
Convert
8c8J
RhuTpwlcSyMfbNONRqUM
qxgOyhIdCdIbKYBaEK
LUTjenyczXCkDEB.dll
System.Configuration
tatZ
4System.Web.Services.Protocols.SoapHttpClientProtocol
nzNwayCSZfqozkgaTKwCrMKOZrP
c695a14fd6f04ad482a93a041ab5c7d8
URYwEFzShSYUrlHndqnRtwBKcS.drv
gj( S
foMDtnkQMwQNheexwdiRAiaIeU.dll
BILukoSMpSbpoiOeHTykNEKwqM
NQvcpnjTxRjqdodwVN.dll
HolMfNhxUMWXUTUcVX
-UZ %*
Int64
xznRPjhsTeoUPpceby
VVzLhkXylVrIdmPOvIAmLpF
]2Z U;
jHkVOMUQbZwUyQOqGBw.dll
dCsNAKESIcmHFzdy
ORLiktOUqhhbHauHdOiTrAlJYW.dll
IsLogging
RbXGjkwRXysdCcbiFsDrPTj
4,a8
OsHoojPtBtIbdtrS.drv
ChrW
ACbJqWlUqazCLcfIbX
-<Z
KPKYDCxFdSZVBWRfXBWvLijiyF
LcYfwnIVDcUzVpoeAzup.dll
LKDTPfPmjjxakOYqqWKi
dCWcqycADkRBIeALihKUOdAGDk
pwRUXJGXCnLNOPzVJskcRqMQhJ.drv
jxCuRSxmWiaFjzcHztrJlsxOnI.drv
lUlactryRHIPBDOF.dll
nEESgsIwDEgiAHEpWrwiZaDxwd
BqkiHVwzRAJDPRvjfeLMlvAdad
SykCkNCygMDWyFQCweAXbsvwju.drv
Z 6
FPbmSeOdclKUtsIIsHnisAp
DesignerGeneratedAttribute
qHIHKWmfbByfalUJHfGmlcPpUW
GbpLgbDzaihRKGqrbFMX.dll
QauQZgPYicbOsydZcWzbAdEAXZ
}Ca8f
utCiZrNfUhUYCeteBAzpVtcVYi
V%&+
System.Net
MlwYClMkxGEpPZTXIqX
WOUYEjhpoPMlzIWdgXy.dll
Process
qxzrtWpfrUJFYqMkidViBRa
PbFwlSUhsOECROUiWh
vZ a8
`.rsrc
fxcgPFEfELKEFWeSsD
McWCRkxFJDxvbaSrHEaNlYUiVX.dll
ad4dda9ed22d4101a12722888e01a451
qCNmzTChttpArmxOCC.dll
XnvvoNrajxDOMqXbncFZ
IGUjiNNzGTqnkFmnkNFmiIvTIP
LjMjmcJezFtaqTFn.drv
YBa8
liwvgEJPcbRglGboJT.dll
zZ '
XCXsPeyRYqkEGCIlNJbx.dll
jXlTeDFjgDgFhpfJucgm
cgmaMcRhrEYnWjUuKEiv.drv
UexRLganqlUcyXUl.dll
_5x
TyduMOflMLlhvIiL
oCfa8
zOlJVxayXcOeoyrciRP.drv
CbcMIEcZpDrzJkPbGI.dll
GEDwZigQBMgggtdkKODdYeF.dll
tqroaqVbRCXNFqTLnj
FaknzulhmfriOhyCjyZy.drv
/\'8v
LbrDXKxfsWQdIbMM.dll
#ga%
::6a%
set_IsBackground
gNrPkLVShBCSRHkr.dll
qPdbZxcuJwtsvAAmLzDptYwWTu
GtfVVKxSrHHmRMvqxQzX.dll
KBuqJBvPQrclnxfkjgo
Z 01|
wfktfXOSFHVgSGcqWHFpXlXJnQ
k#a8
NmYtadzYoXXxusvvCRk.drv
C]%
B,*
Computer
VlsiUHlRMtwPLaHzLpA
LGIOVEagwBsUoLnmufXKiKxuQo.dll
f<8E
ca%
gwJfxyiuoLxpYRbdvUO
mNtBgPwXudKbLsEr
oQmCGVmWwmsfdxtfztZ
W\a8
IiZEfbMrMyFqnHRqfhqsPJz
BuBrSujfmmTWeBzUNEHEjDpXnb
= &u8z
nOqPwjpDMPfusgOklNuIrtw
YMkjcWoREdtMoyYECP.drv
fNEZxfMvgfaxGzpSSWx
wjyzvJliPoSVqaXTyWDt.drv
DQpzxWcUdDemulUDtZdUjpJUwG
zsWoxFEgaCvbIPxwvYhd
TuTgAhZrpnPXNcCCmMz
(~8[
UdxYqIDvjGXcCprKmECL
UpmLDrnGkNQAaaplzyav
XjIhSwupUNBUMEfDutx
eUalUWstVxbLcPhoQO
TlvaMElboYuMUfcTlCZgsTn.dll
ZfzMsjYIEjtDyDdlWrgSwktavl.drv
LkHOwGDqqzmybELMXe
IHwZneDidlOTxljhMLM.drv
aZQfBcYBWOXTLKnMGKSB
TUNGdOFRMPnoOqDt
evRLNWjrAZvstXdSwT
SydUTkOUmeeStOIi
bHgxWZflGDkDkaQv
MillNncWZqmmeVfaSGkJ
dEBrhLGMbSIGDHyTml.dll
GetBytes
PA%AZ
lmYPqVfhZKXWubdQIsFXIlC
HYNJNfliMtmybChwFL
tdmLKyweJqvMDcNpBxxP
aHHCMQUomUhEWFtdiEGONgsyam.dll
9 o
*?oZ x.
NoHDOgXLlUHGayCKXjXfkoxWCI
ZAppEJJcylkUZfjY.dll
ReadAllBytes
*2a8
v(8N
oKoaJYcWGIOWBAaA
OqChNDzUzCVxMwpF.dll
utAfpVgpVaumNDXtwNLsuJLjBjq.dll
Q
R
TLsjHNoLjDyxDAhTPOTT
kernel32
System.Runtime.InteropServices
[
Z S]
bMhjUjcyOxoMVyRxDQNPLLpJvz.dll
%&8w
vImzYulcPcRJffDcYZVajpFVtl.dll
%&8q
ZKVEzqxniuXMldJflKIa
%&8r
phVDrNcHHGgQuaaH
r
Ewa8*
get_Assembly
MSBxiWZngWkaHeeyGCcExTWWCz.dll
rjuMnlaqLLpJvwLJPE.dll
Z OJ%
qLBYLmrPGgXLnFattSGfzkORuQ
WeGCUKnVLiqYaKcZWHt.drv
AOBLuAdRIibBhCqjYNUiuQBiiq.dll
GXAfuiQaVByRUBnxFP
CzRYlNJCPWCUbPIVtuidZsQOXE
ea8
fZvBRJwxbhURQNMsgpRXfeY
WnAVNuCuXvTydeBpEt
)Z L
,a8
dxqXCmLbLRvirXkalYa
Ev85
BgIqmymDveAVljvIToaXSignwK
MJylzBzvtINXacrwOKuF
MchGaHvqmUOwFGJsKZ.dll
%&86
WYlVmqBoXswgKWeA.dll
oAEEiEbYGHnVYYKjwu
9J8|
System.IO
yNpmVkHFwVyJjpqcQhuwDfT
pxOlGuJlfvGhcGOMtrexOAO
VjUYLPhzMApgjtiT.dll
zWZ @;
ZqNcbIiUGYxvZNfSjS
mYtIAcTqwOTpmkbZLK
ZyimgaghaLjDShChIiIkKCx.dll
SfcPolddisqLAAUa.dll
.
kGljxQVxNcUwDEgO.dll
ZQLXOvJDSQWnnQtGJcTeGlVjbD.dll
WCXyMKITcFgxNGaXQs
uGrqEVJwoGRKUNPa
Z k""
$Su^8
DtLWDtdEiOZNpeiwhSWO
goJKWmKitfESnspcFwc
efAEKitOITOklJiY.drv
GyvaLhpZzpdssmqIryjDszoKkH.drv
xNzvYHRsrFHLUfiV
fZwCwMSFixnlHfAStDUd.dll
snfgcDCZZdqGZUvlKLLh
TmB%+
RBHGrQEMBYJLlAqJHPS.dll
WULCqSjYozlbEgZqxU
HSuoLvhYPKvowuMVPQXmhTY
WjhdjNkHuRYKERU
UlaBcoCXGetclXOz
hI%a8
dceceVaauTkKdiRvwgvW.drv
oRZezkBbPoocEsxDdyGmrUxyvK.drv
GllLoOYTOOehIbYRUVfcyHmYqI.dll
xYvuRxmuINKiBYBxrcLQpzd.dll
YcANvAXYQAaOwVnJlodhHuVtdFq
STAThreadAttribute
^Z h
GanDirpuVszbNYrxtB.drv
FGlyMqhJHHLMLChoITH.dll
QIZRjHPlQSxanKkRSQ
y;Ja8
aSILaVJHvLSCiVSUVfYDMRV
BEKyHXTqsoWKkiyfqwmA
#;~a8
SxBIFxliiQthyFIgaH
oCjiRgEDWXpsbFBmVL.dll
zKifQdUaddDRuDqj.dll
System.Globalization
LpNXKHZZTbbkIKSDgS.drv
JgONQITxkTWHyAVMDUHi
WpAnpTBjeBMOULXQBa
FLLpbeRwtxmrRgjjbOpkfGOcOS.dll
NAYFLLiDWlWdNdhBHHOcQxcKbh
kSvhCucwjbnbtNzVYCggzpyQUF
ciRPINMdWSLHYhlnpRZO
9Pa8l
ieXQbkruNJZUuEqeEm
u|a85
toNCqHIJnMYyjUifbjmejUf.dll
xwMsUljxjOxuiTFFAKX.drv
Thread
fbNoidCMPOJgYokiOF
FghHpMxYXsrciSmSwQb.drv
hQwoumGlbCxtZHvnBNeamdidYe
AdksYEawzywCOPUdqu
System
EQTqmxYAlmpQHsiqns.dll
Application
lYDoqtVrOdWsMBTvsJOwzWEAHu
Z N'
enuauBPiVrehlLAzBsOrWmYWKM
OFWUwaswDGiMgLkHwX
VmqvfbciDvgMjahnDrygYWcmNj
DJhGEvNcojCFyTFuGOxE
.?m8
EFxwdLMCGZnRNChrSLiCYEAwKQ
dimlUagSSKuUupmtfLuPlJRzqS
mQKaEfULdfmxRXfFrhAl.drv
?a8v
NiVybtmKzFDrVVMQOzBl
ASCtlHKGGZXpAZhnsnR
tmkxtmslyWPhgwRr
50Z "
CreateInstance
nLsvJrJdmuFJunOAFuCD.dll
qslsubohqXwXVakdAMJfraf.dll
izqSSQbSGNlUqmjzQTUIQwl.drv
eZFIFERoxxYyNXVRDfD.drv
DebuggableAttribute
FNFeZpMWWfnBDecp.drv
rxuUctjMmwNtQsQkncepkPcPRK.dll
MethodBase
#Strings
giWslbRQcEhgYYVFqe.drv
fHBCnaLRnPQJwzcaLgb
68Za8
QatEdifSgJLOauKruaR.dll
DQJxOdgYNMZxljY
yvqiSVVqRionqpPXgTagcmXFAa
ygvUpnkaBFkdBwZQJbQHBESMoi
neyxHRWNwjsNFNytnwF.dll
OSeXaViUcyJSnrOGfnoJDsEnwM
WohybNKLCIULVvv
VkUzYoWjQBZhCwrpmdbobBJYNW.drv
HeHgKqJduydhHzanOPNiwOY
ztgwcmvDPOXVwdLL.dll
KjKfdoKVRxeuzxvqcpW.drv
fogWPrxHeBwtaEpljSnYAPjEKi
UZ :%
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
ad1c8f0e4c7441209b69c3a002da46c9
vKUQyVJSjwSkWHOrvU.drv
qZCosckRLweiJSlLyuixyIG.drv
LjZUIiHzxISVhMRizQu
ZtQQFreAjxvLPGffhAnLpmuowM.dll
dWbubGiUODpHSPtVyBMq.dll
Z`4kZ
lqrCPVIfmYbxqTxhnZuVewjhoBR
TEVIEaDyWKvTkuHLBeyXtLU.drv
gtdVLTbpDNHLVBNwMGC.drv
jLpoQnuyQYplizLsPkTRtuQVie.dll
`Za8r
)]8Q
uYyNHTMmWwTGddFOXhxz.dll
SvNRMtRbMRNFOhlkeNK.dll
aPEIpLTkSpzrGuLdeZcTBnYqKc.dll
bsubGIPJnaForoEVxFWiIdPaVY

diJMUfHLAeaMCMHQ.dll
XkSwWpIrzlQzEaAZqWi.dll
ewfDPniDWlSGAeLtHqPZtubJei
USccJAuFIjpEmlpDtw
sBYghThHQCKktvUU.drv
eirrPaLxgmWjPZBNDJAl
ExCjQsqdnziviZINFn
TfTfwauxNFjFelQUPp
xLTrbbSwHYyFcfAAJV
MsgBox
ThreadStaticAttribute
c
ppvhxDyHwgdboaJPwl
AssemblyDescriptionAttribute
rFCmMPWxUocbMvbb
Z b*
Activator
ltFuyskaFXUjOrQuJHVpFaslrZo
mGAkrXBXzzhyDGfiKL
SJrNNxLrVConqCDxtJ.drv
EJltcvSmVqqIcdlGCd.drv
WZ R
BFtPXUaMrGyWxMupzSYYaBKvmCL.drv
xglhGUouNsQYLJDUErqTuTb
UVGVlWCZacqTtIyA.dll
bxjKtJvJaFRPEqvVhBuN.dll
Eg8*
] =JF_a%
vZzhFuVPWoYZTEQNHRgVwThBpP.dll
< m
TCTdyWWnxECxIHvq.dll
FTvzTAUmzHCrcProvXBMfNf
xQzWXaSJNYaYkPmh.dll
FbdrGQruAGhTUgNtqCY.dll
BiWRaqnKVaHEVshgYaH
B{a8
vmMpgrDkegldsiHE
ProjectData
String
dBUKVwNgumpKxUzdseuceRGvFm
SYYGnynpIbkIbRZSKj
VAXuOsNIUVYflxfIVs.dll
ZKVEzqxniuXMldJflKI
wKwpfskteWwaZpCxqwqlOwxsbs
dGZ
8<a+
afevMSjowpNWHssHjJCGEAKVlF.dll
RKcdZPzfryPzouHsuKNCzqzdgF.dll
UYWLQisBZWDcQOrTBz.dll
VEsfslzjOWjHtLOIzc.dll
NShxbQAbxOaSwOzY.drv
qusBdAktPtHsJZHqovtl.drv
*z8
IDgBHECXQuWTSiPxobiD
AVQnyAZmKlHcOusqGj.drv
DefaultSettingValueAttribute
lZ t
aa%
mZ '
YxqRMsBhfTDLgKXxBQonLeI.dll
pKmsIIRvpTiadRuv.drv
GUvSRmNokeBEVsvkyS.dll
r
AIotOmkrBDWzpluzmyH
ConcatenateObject
tHEFyjjJswwKXSlrIVX.dll
OAKWDociwmKnznBIew
pTbwcaNFZZSjnLRnpzUBmzH
ga8]
FkScDeTuUZnDzvbqebhr
|+Wv8E
CwRlhrFteQxTTtLZceNK.dll
+`~7
qJuyzVhkGTFQdKBAUFWHVBt
hClhqCCDngCSZyzMPHI.dll
NdrtOFdkngANoUsUcS
KbrMgeqIPfhxaRXApPytZOHWdK
WoGqSanpuDQqkjuoRxv
iHrpZprBqtoQxyZWsfQrdkqXwV
CXwcNtqvHJpkeOrVwKBfjLNQFB
NARMgTpHBdtRTTVaXS.dll
APqyTKTLipCincNcQAO
g1:
dLMCGZnRNChrSLiCYEA
TXuRvgFLjdhhfvtdlMjOYxo
t!Q8
gHMVqAdjSmDjtrE
nCeNqYcjoIPijGvvAvWgmPETCR.drv
sxnAQWaSxanNzbRxayMIcEa.drv
Form
aPZ
vWshlPFaUsvQEGvnkq.dll
fdzNxnIAhFTQeUBcGTMSGoOjUcQ.dll
cjTgKvnhRdEJlzonDAl
50q8[
aNeDrOhdIRjoFhjfzWgFEnL.drv
BhYZdCBIItcOlGOrwPSwQGCRZSh.dll
jkFdXVgmfHrHjOrNJz
02TZ
VxysXwuXNbUKQTBKeUia.drv
*c8
lTAbysnuNBJCASJrgWp
Nd
MsgBoxResult
jJreLsNoYGljwYBXnIB.dll
HnXooYaAgmBzmMqjKyJSAGhHcX.dll
fSwvvMqTngjOuUarSzX.drv
xOa+
XaDsmpmlMqWywdGOJH
BZ z/
oSrLTblLdtBNfNwpohbE
KXtMWciRYaieUBoL
blPuQIlUpEMjyQvqhTnHPGcRlJ.dll
eruAlcIMJPHoGzKgddRtpNs
ELsWriJyhHpTGMFIzVBHDIRUzu.dll
kHrVELzycqLNyTiCxG
)Z:a8>
SlxjishdfwuUxGaemge.dll
hCePkDpahHhyADIGXJgD
lbUfzjnezvkiXWCaHC.dll
QmMzsPSisckVEfSYyDC.dll
sj
SandboxieRpcSs
z%&+
dXZrDdKwmlIfRaIEAbzJVZJOWH.dll
pjggMctweQPmzOmHonOcpADrvO.drv
atBFDNJqrDUXFsXI
txLpwBeRDaaYGUIN
,Za8
ynnHYHwXGBwBTimfOozQasOovj
MsgBoxStyle
d 8|
spyJTExtnGOJlgerhRLTENsaWTd.dll
bfbd4936f2e04ca1b4961462f0ced884
NeMMvfjdjJXvAixBeaXpHIIOGn.drv
zYmkhTXDOvqivsGGPcZ
FQOGjNGrYSJpmaCCTMfqFeNdfu.dll
MYYYKLVzqygQwCPbXPzbjyxZEB
LHNkxpeFoTGLpZjigVZGxrfnku.drv
UsAhFzOMjdzUowoneMf
xhfHyZujmQdClfFMdGaUHsXHLY
QcIWAEhkPRIbhosAGOL
QzXSBMzPyeEtcZdaNQry.dll
rCfHEOsOiaEwoECFEgwkglUcaN
gQbuAlbIPdMIbxIzijwE
SjRMphWLvOHJLBTdUO.drv
SpecialFolder
FVsLzNikFjZIyRxHJo
LivTlimshxkVrtWaeJCLLFoVsqF.dll
Interaction
xOZDMauuRpaMREFhDHJywVxqSR
Byte
kWFZEbCVmENPjwUvGoWWaPkxsQ.dll
get_Length
get_Chars
a10833d52a784977b1a685f95b478f09
cnVidlKXFMvEzYlRmonohgJmlk.dll
WtUpdVYpHWOTbvcgdP.dll
nzepGphUIUyNPSLgTxqXfnf.drv
CSleJoFhoZNvVWOZrnG
DFyFLEnhTHXEgYkqsZJnXTyFcg.drv
mDqLjywdapuDXLjR.dll
:F8s
YOMFlRYNLbNcYvTnePn.dll
ZBYTbXgyIcspmoxuWWvrpwf
apZ Y)J
qFQpejoaHFzZLnGpzDH.dll
XOQusfLosIrtREibDoex.dll
eHXURYwEFzShSYU
OYMvsawkswhTUsVKRBeHwwxiaz
qkZIwBrrzcAEBaVC
QuzSrDBPWzQHBtFN.dll
TyvXhlGufdUsTXptlCFYxrgKbg.drv
TrmQfTfcUKqXGiyNsP.drv
pAFFWjbPdVDoAqzqgO.dll
XIulOBbZTkxblkzt.dll
5F6
Z }<
GgTlAowFZBmSIMqKFsQtdlkEFf
nyrNjdZJHPxXSxVPuZdC
SfuOKaTLxhYwOMUrPkV
tkZBxPgViinOfFMymFNHNwpQwZ
$,X)
pqVboFDsTWcyjFWZ.drv
HhVBXmYBiPcyEsdacV.dll
ValueType
Z cQ
hbHRyZQChyRJwQxllnkf.drv
,R R
Microsoft.VisualBasic.CompilerServices
iXkTChaMToeDQddiLWbGUsB.drv
WjqzXGYwkYlDOMdVvd.dll
PhoMhKMLkvrkfgScSEWRGeGHWM.drv
C8a+
iitUgEtOWhWkyztACemcRKR
wcNCwWQDokvfjiTOTqo.dll
TjULZnuTccPiomDAHCx.dll
Xa8J
vbHihpdlATdnCBBFvaiW
PPDpTsAqhzsZxQlBYN.drv
QRHNRQKDovvCuNEmqUz.dll
JFRapVwAkMshJTHrnitc
ZeQohcYMgUIqStVVldZtSMe
ZSyAnRfTQmWgwUlyckQ
({ 8
anZwjpGJJlJfIDLwdMkgxsqlxC.dll
*wX
iou
mOfqGqDBaGyxotWlGJNpYmlbYx
xpRIbwiRrPcySiVOllaXCdNVUJ
gNKlbFlnwxuwjEQXfdio
PpFfjfmBejUWNsvhoMB.dll
cLA8(
mHkChwskZpRPllcThvLGzNfhHJ
ZhNQ8"
K*Iv%&8g
< I8
OKEWETJWKByPyttxuTY.dll
OWBvStvXBLBNABoXtyFnMOurKD.drv
MBTmbbmnMCXJaiQmSPP.dll
AiwnDWfLeUrGCNydVMSYwaphzx.drv
zhlTSYrPJGQwKmMTrElFDfI
uuIURwMHDIsokASdKilJbWn
GViQbgblQylQZPCSiQrf
DNYuHXnbgInofixFUwXOUxbFPn
WUMXSPQXbPDAXRTrbN
yPZkskFJSeYEfSzXfjqw.drv
llwhdMOflqtgtOBigbNf
CrKVHptdxqXCmLb.dll
yoYmraiiXpwkDuafqrFR.dll
ufkjUfjZKjjHBmpTXv
wbpiMmpXMqiIGrCKeub
jSxfmhtbuwRloJBoZJuKutjwNJ
OEGdHywEVswkvrMIwrYKfnGtax
F]4a+
TWUfBHIAywRuKIoa
40a8
ZGjFfBGLKYpCYyGKFsse.dll
rnwxQIfEElKKvFAAkCsuoZU.dll
nhjJfLAPNZNdaEhQIifCRmTJvS.drv
MzposuHmvzqgMpKtloSd.dll
ElDJKCPiiDUiprFM
C{8.
Environment
dZa+
TIJXtbVGoqSVkcUQUbYrQXJMxd
WxarwtsBLDNDkgQAUDR.dll
VwKmkIXLoxpzZkvcHtwSqDHMzL.dll
pVSMuvdtEfcBQYUMiGmhmyu.dll
M5(
IdGHbUSmYrdHosIhwNPKNTDNTy.drv
+a%
rfJepvpnKkbDkrNxyVjQVeavRa
QTa%
ceQgxFVVoniOZPIFAGnA.dll
GujbOkvjwCasSfZyOFJe
BaZzFuVUPaUSiwqHzvuA
CallByName
ClearProjectError
jBAXfEOAtwVjdcoVASf.drv
`Z N9#
OdgYNMZxljYGcPtxiDTrUXqGqV.dll
vqF^Z
$E7EA33BD-1B7F-40B0-8E46-C22AE263FF5E
DebuggerHiddenAttribute
YllMUoEGXCBAAEfTgmwIrbDphy
dXCEDhQpWLbtdEUdfvRwZnl.dll
OdpIcvFRfoXqNBhVUcUqapUnSR.drv
daxNOxrQmbcxlzYnrY
wcrRldaXvQItzqOyDPOGWuXyaB.dll
HYUnChpyTuefTMGkjVBNVJihSHq.dll
a80431e388474d4ca82d2abb482cce81
vceknvqHeYcfnRSK.dll
dXUnBACakXKpRWiAYsJwqcbvvQ.drv
ha%
EYSZIKBePWOMqsc.drv
NMWZrwnYxTfZmaV.dll
tyVCpAJLdCJKADVvyf.dll
AssemblyTitleAttribute
=~l
KfChpSRMJEXUvVHvwMdHDtbLKm
-RC
ZpkrXDpxSBhzpqkjJUkKnYDZBi
MgdVBoAhaoDaTaxRcrICzco
guVvmaXpAoBRLyMq.dll
lllDbQuFCaZlmoOJUmR.dll
,G8>
UaQknyFlzXwkguIHiGcttPUBcE
ujUkjdZvWTsjKLKAEJjROuABfA.drv
+Za8
HusyEZLuRAtHrobkea.dll
)68(
cnOyQdzoWdBieAigVPZ
eFxPbCEpOObCjfOTATIDFQmXZA.dll
UkKoMaCHQJCjbhuiifStVJOwSkn
Mn8P
wNBKMrorpJyPGfqRDZu
pUKOCsGPjxAfiJyUjppIhlpCZP.drv
Create__Instance__
SettingsBase
SsvDrDgzGIHLKLvxEJe.dll
OUQjFUEcofEfUOonxTlyiUJ.dll
nsTeqFJRvCeWtsfIzPq
Start
StMwAYvrsfrnvMUKvC
nBa8
Z ;M
/<!Z q<2
Z );/
xL"8n
WocGXEvMANRvmCxDyngc.drv
`A$
gislREBKkjlWOEUKfRXimQi
JCqATLpSWlAnoTge
lPaYYWyCKjsvLZNmXs
IShmXcnoQuVieHplRV
]Z z%
WkPOaoMNYDioXXTPLm
+~j
PuhUicUHPoCOJjMwuuhEjJL
MultiplyObject
wbMWLoLpAlPdPUKsKTO
NAeQOXtoCNpkYXUQES
HQZFUoAGQlpUJBNxmZ.dll
RegistryKey
|]Z N
wxDxNGcmgbXsKhpRiATSSrYpWL.drv
=LR
GetFolderPath
QjrMwwjRcUSSvllkzC.dll
CUejGXfsjDhJwZgbCUrTGOMloZ
YrvDWKKSMyQSPfTCGlkrwOThuA
zogfyIaDZhnGKcEGNQY
KOYAwQaOqryRsFaPajw.drv
YcyYMTYWQoSaKNrlRckoqgfWpkD
OBvWIzApdVChRVoY.dll
emQnklAphnsZydsMHoWz
ElCmNgmombQVQyrlDsrPIpEZPI.dll
pZXLxFxoFDwCduiXBEGmPjd.drv
.ctor
0i&Z 7
OtDtSwzwZtmjBOqyenfPJuctlq.dll
wahuslxfLxfsxGBC
mscoree.dll
Container
CAAbEnKOBOkRQOpA
IxpmnHVvCvJZmEjO.drv
rVBOggDawILVaQyfNBlgAkLjGk
KMfpubIZYDVWWjKtFnAmsdRUzi.dll
Invoke
eoijnRjnAHQrPDIHsThd
yQRRRhfWSFNDUFTAXO.dll
FqNcCdKQbUYlQnRJjBSfXZKipr
usBdAktPtHsJZHqovtl
WGTVnxmJgqXyuUdMeJjGnUsvTL.dll
JUhMjhGdrJxVLQaHbYkg.dll
qyUSVzGDYSWJbEhlhvE.dll
File
rovafktgspBSEsJtGdjykhE.dll
YkfxIHwmerZZRsFiEzlhaQTngFl.dll
xfmhtbuwRloJBoZJuKut
FQBSYfbRrMSDSpYlQXF
Finalize
qeMWQsOtIVvJieaxacOqWxnvUj.dll
fYftiWeOnrSlDgiHtJ
WuCcVIvjRYbyiLwXYjyWZcP.drv
evjIzNAYFLLiDWl.dll
Z H=
ZkKWBWSYlyjSRiAj.dll
OeYrZbwtHAXoOhFmFFvPvZU.dll
mLUgEFXSWMqzdGefILV.dll
dhzLnZnqxyjhsriSfPTVlvqVYk.dll
oPBsyYhCSZccTKBjOPgtTgp
@.reloc
QSKDFeZghsHbKuRkXrKSyFCvFl.drv
}}*
a64841068aed4a7896d90665e3fc696c
YOdvhwUFYqeUJpYjyirCpGO.dll
zzshHWhTTNsmMQvrzIdayrjjkz
rjGnVohpZeTCuQhktRaBUycIjK
IpzwjXoKUkWmRdNoHDO
TvKYjwxGgGlBdQVpVArFNdfVze.drv
EBKwIxPiEFOWsSCPyyuDapNznG.dll
DTaZDyMPgZOAIWVObB.drv
+<(>
kPBVCXdKWOmwkjiOMzJ
ZPisIiIlnkgUjSQAzc.dll
QkIItbsHgoCZTSvsApBUMuefoh
pgLBDKjKGVWdxEmUqt.dll
GetProcessesByName
MivonpmNslAbFypCXWf
WBjkHTevyQoFlsaWgjftfpkYliQ.dll
hGHylpOYcStHlLtfOQdw.dll
WriteAllText
eIKTusyVsInJqJycFoG.dll
lNKyPXIUDKJtmUZylb
znQMkKuUYikUajTGdmp
RcnttZxmTCdOEfvHPYluHhNLRV
a082a397bd234399b9cde7c37cac24f1
SFydkDUPGWEcfhh
tOaeoQueGssHqaRWgl.dll
Z a8"
mZ s
hbbRDrswdDxLfdonmPcn
0%&8*
IW8L
WmOOVpcWoRHnmKdGYcBs
yjnIZYFRMPqEFpnBkdlmZXW.dll
System.Diagnostics
ImnqohOsiJfmZmnGJHadbIuxmv
0%& k"ziZa8
hnmnZJoNfQEFhOUrji
HPdjWeOFuqjsvhJiLppQNeiQGP
uoMDRuIWTdaIUJOtssqoNQfvYb.dll
DMMkQCdnTyhwYwmjZo
GetType
rYSIQblxdhkixaggaO
d#}8
egSiGORIMtzcBaQXWR
iCfqdNdlAWozQjRonutMtpXGQx.drv
lGRpxrUfmvdToDYcLGhqvMB
lVzylDNvCvseDEaIkFEt
FdPmVgxuJICPVLqjmlpgZkCsdc.drv
8a83
zZLnGpzDHXgkDfu
K8
rzFbhZARWGZLnyhWMi
HDnFUtdwnciASpEnWYW
UqxiRSDCAINDellKHcI.drv
WUZjXoOdPSesKRES.dll
hQniiDfvTkzLjYkXptLkTSPwIX.dll
HaEFniirPyIBZgEgeHPjswONsU.dll
kUwMezeyNsVjWWDGYwhefowCeM
Z V$
WtizZVNCjEVhWlIFySFA.drv
yoFlnXyjHAZRZDqI
kBBJYweKAkMYadAWhKX.dll
trTghfLsurQABaDXHV
ZPvmjUjyUhdjnewGMVlqcDfAaY.dll
qSAoCApENKlqBUNbRDW.dll
ZqTmNoExfxgyGTamwu
_%&
jONWvXBfsZksAljtydKOYMd.dll
escfGXxcAUrPiIZUenFh
Z D;
jteHdDAPLtfriABkIr.dll
XlwYxKybLwQIqNmGtsMf.dll
zuJgCfNXDpYlcHQckmvh.dll
aXsliowvruOESRbM
4]}a8b
kvTBTAyzUrmGXBqWlQ
pZ \
bnRoEqyLwweQIAQUSEgKCSgNDx
Gs=X84
RBvrGbdotSkuGhOH
lFeFTAgxBxoSlfpPSLau
CurrentUser
pKylQcGjaXFsiMZoVtR
ConsoleApplicationBase
KfzogjuOirGezdnhUur
p,NO8
xcyiPkxmOAqbFuMrpFpppuAIlS.dll
IbzYtoXsVKYFsOVHGmSm
Z t{E
Za8^
EGnePqRJpyrLxRvuka.dll
ztwAabWIYbuBLWlkpwVlmkO.dll
RuntimeCompatibilityAttribute
iCJznHhTCoXBTolHLArrLts
ILbRPrXwHxyqKkPiDkQLyMd.dll
Za8G
EdGyjSOaCiaEcEwCTdeyUPyhss.dll
Assembly
Za8~
PeJuTGKWkJjyyXIhmnASfaQIFd.dll
|C?>8
rqiWXhtcHBYKcAOMbDM
Za8t
apNznGMpHeGCnBL
SyVQDgewXKZzKozGqQm.dll
NYznYSeAGmxsJsWr
DGEjuHtYzdLnyLPZzJr
EyALIybKyPzZaWJlGB
nAa8
ConfuserEx v1.0.0
WyNypUYgWOKPtrUORFXSzecNWS.dll
f0!
ryevRGyfsYgaKrummN
eSYrKbsnnopMQMMsrQDg.dll
reaElnccVEsLwLMe
BsKCKQhqzAIUXARRBaDzZbFXqWD
-=8S
VNyXPFEJcYWwXbCEFu.dll
ngLHvsKJBYmXmpfMZFWw
VYPGbkPnkkkzRppgPbluzyaEDFj.dll
xgwbaMCJkGDuJtnlmMejnGVpXcL
Fna+
AFNSQxpMzHzfswbqUYvtmjBsIF
COAfkOmZyjOywSezFVIKEUe
btuaCljcEFydLQkJws
Za82
XipGOuEjczBEGTorKMbK.dll
DoNUdpJOPDmgRUIedo.dll
kkaZ
tMvXddLEJggucoTVwJp
Za8/
=8
BOQSEMqPjwDXecTodGo.dll
:Aa8
CSwNJfnqqwlBdkoGyYuXcJAcNxO.dll
x u?5h8|
3e/a+

jlWrtEMFByyZsJLgTQbcusutRC.dll
ZwftRavMcerhrfBpYkqCUewrApL.drv
ZbxCKSTTuRuXgzttuy
mykLAgbrRtCaJKtNwe.dll

uMbwTWHaBsHegnLtWS.drv
EDhrrYrhOFaattXnoPX
IAiTrhVGvqGrquuL
tI]Z tG
bwuDWNLJmUOrNQkAUG.dll
UdTnDtZGCuvwMzRpxtjzgCNluK.drv
CjOFoKKoogQcrzSAetMmvxT
mTOTbjGREccyGBFrWWFnYxtFws
cQaTVfwWWmNdRzEmgtiS.dll
uUsaYoeoSCnphJEKvx
RNkhjcGstadULseFrYcI.dll
FTlgOzxaIPWXeQradMrroNedSZ.dll
Wja8
KigBHATbMopuvtoIrLLThbVdvc.drv
TOTRQzfiBZtduqaBDKWLTpJgPb.drv
qji)Z
aRrbkFgOhBDUthEePusl
xzpxcbATjgoylUZeRR
yCgkWkWHcfXALaZzMA
YPcXDTqcWJAjkyzNMWZrwnYxTf
gXLlUHGayCKXjXfkoxW
nMIfgbWIYbxQpiYJrodw.dll
DcQRGsyUcMJUEhpwvBH
My.WebServices
ffLzcAEAXYFzttk.dll
GetProcesses
tyyyGQFfIHfwkTcYXgr
CYicsfpATTuglDdVEG
boFTyVGbRbmCxXMjnXQBbrGLqTC
KIPZFbcsJHzyWrJOUv
y\a8*
NieyctclACbRpJRlnEjZ.dll
get_Item
EjDhTdTAxVAHnsylcZaQuGiKjO.dll
SWskbxpxEbamSRAhRqvirzIiok
ZIEFcghXPytbVmmCAQcJSkNuAo.dll
wUZa8I
eYopWDwSoNIfAzLxmrpw.drv
stNOdBrGIDSWxBYJZcY
>OUHZ
"f8l8
QasOKLVwcejVouvEreJ.dll
8'a8
I6UUzWV9JLDz4BIcrCZAwrcrCy8x
BUcfmITCvTpkqWiAHbhwhkG.dll
BiTTmELwzpRdubQBEO
addeea76f7aa4df8852e0cde6c47fc4a
ZUivtGahgTragXkc.dll
NFkZrKPFifsGCsoiDAW.dll
).iZ
ocxkxZBZotfsynCclH.dll
ZMlbJYqHJVFRVoLQoFnL.drv
WebClient
CvZ I
ATtzYxgxnGqtpgBUjiqP
LiCYEAwKQfrjQqC
kGwGhJVcIuOtDrUoeOjeUcTvZj.drv
MPOLFVE.Resources.resources
SoCshvsvIxtMYMzbMfvyTdyIbR.dll
apioBfKTdWGoirMTzOyWyKzVVB
VQqLtGiDTEWYxMaLnQineoHlyw
//a8N
npBEcOmTtfCIOOQpIXyPVCw
WmfLzPbPNcbSBorApD
{Z *
jsza%
{-`\
PZGKaKpdVbImmgcRnPl
YGxzKXbYpdYTyDPMjnVnFGMfNA.drv
MgLxZvfcnQnEWsKorb
ResourceManager
fHbHLFykphRlLrlYWWk
_;Z
sDbjmZLjausFUEuIvtqX.dll
cyXPBLjuUMmfPKuk
lGOrzVjgyQtCRcHHngDS.drv
ZWVettQyHxAFuoPKruqVFGEeay.dll
RvOWqsCUejGXfsj.drv
wcyIUmpfVaqwXOIl.drv
pZ[JZ w
HKmlHrBXfRdJRnJGiQVF.dll
klEWpgXvfUwYIYsgALlWuHZtff.dll
kpZUcJhyoHpGqcYmzKfl
ContainerControl
sBjCWaLwMsWTwZKeBTX
-h/a8P
YceGmLUgEFXSWMqzdGefILVeGV
FTBBBMSpFLwZlvnnzApN.drv
NJIjlZbUcitRIZiqzQO.drv
lZqtaOOgjnHzLUbA.dll
MpHeGCnBLhWXxsfZjiQVxOdHqx.dll
dJAESApVTVtbCMmOrd
MyGroupCollectionAttribute
FAordNVBRfRijsVXeBCarYBlka
YWTgQbLoxsJoFxiUJkq.dll
.-v8
qZtvKqowXLhVFDcHzSIPAmF
CreateProjectError
opOQpKlYBcxDZisCfEWp
nTWAAKaqMncGOLE.drv
qZ In
IanxotjIDmbjQbCdLQtIBkDNiq.drv
xNnlojQRxGqJKWtOhZWr.dll
QYJaLsPfonxHNDTejck
injf8
:a8-
ijYsFnndxlTlRdgLooC
qcqcHARKKMUrmIMrSp.drv
aJLFsVAPlspvayNqYjBZ
bZZqKpZzXgyHPUjUaQUg.drv
OrUtszOyQPsjuhcP.drv
jtxTaqIvBcddscYaCwRlhrFteQ.drv
j7Z
rLugEgDDLPzzgLaODJgFBZiZlX
AssemblyCopyrightAttribute
nTWAAKaqMncGOLEYPcX.drv
xxcmyXPJvHoFIOdk
3Je
s(I
YTIyOZdLDCmeAHsezKyBCUwLYl.dll
ZYqtLmGcKwoiZdLm
lP_
bEhlhvEejnHGCnw
GKGXrWFfJtecrtCoMP.dll
TJuVxSpcUISykCkNCyg
EPolcvXWkTrgcRqWrI
qrHnDxSWibmVCsrEKB.dll
iMWynKuymgirtStGGK
uiwpwtLEFisruxtc.dll
oNvwxmKAnCMGYOJfAd.dll
"<a+
OOcQCRyxlouNOBdDfVnn
@$Z |
IRibdXSnvIWYwhRiFiJM.drv
Operators
RjUSHEOuNxEkkItyuba
JhMPrLfRNeGyqQJcQx.drv
rUKVYLQOFawzgZOO
jCnjTmokHCbdAWPZBAmZIOFXJy.dll
ibpUGBQzXsjTddXTza
DeleteFile
zhAnALHHuEEKKqNogUE.drv
zjucTQWSEODHwkxBuxANpIuQKc
hnMmIBkIVMoKyevoiPldJikPtR
S;a8
ZfXZ
op_Equality
dxAfWilKJRlgMkNXIob
XxdqnTaMeXAWegDPvwdahUoyXl.dll
AqAHSpPABHlmvKOo
fcgUdhevqBcgMbpZncLkTItcsj.dll
cEMYefExiMpXBGYIJx
FFZkPxrqdupWrbCWoDCYKrqlcD
HPVWnRpCrokaaCFzKRn.dll
OZbzEnASqSxLpyfYgWQ
DhJwZgbCUrTGOMl
Z EZ
_^a80
ERP8H3N44XR
SetProjectError
lR
KPfBpuNISjibEURigXVKmEzbdc
iVOSgYsRqlHjqkNoMnBWVmrGRZ.dll
\a8;
AsvinlTBLYgyZouSxcd
\a8?
sJoPBhEXuSkClJMb.dll
`A8A
LReCkZKOWPvlhRKMvsPU
<ma8
RmQEAAhTwWDPJum.dll
opCTgwbvdLCWDsBo
uiLlrfGPSXuqJHXhHGV.drv
iZlLNkrKeUSEEmyKJPjuZxXfOh.dll
[.Oa8a
mErwJBHMJvzrGaFBhe.dll
8E6
Z `r_
#]58
GwgKGqhhBytoroCQixC
`GN8
r9#A
aTpANRPuTUjGWSksiNVVLBwkjN
JoCjlWpqjPRnEhFvRxfCVPNTdz
tivCfIsSmoBaGXUOncowufFcHI
WOMqscMwzcQZyUCwvgiWOevjIz
XkrnIgqSxDVXVjudjIr
Z MA
ReCGMhzIEobcxItPROK.dll
4l ?
LVSNTPEhgogxeHDjNVY
^B`a8
FgtKCDSNhxtxezjD.dll
lAkEVohkiyPKJghlcZaPgMlqBb
Registry
*a8~
RYtZXonDBTMoBShblMFaMHmgPB.dll
GcPtxiDTrUXqGqV
qZ ~
AutoScaleMode
oZCRGnuGUMUHSwj.dll
ETMdnmxJKNQIyCKOuGB.dll
WlJaaPlzYsXBAOTpXJB
Z5
TfFDdkVLzquwDodVjAHJtdfqkr.dll
%q08t
.cctor
W\^8~
mscorlib
TtLZceNKCktZBerPimY.drv
cEtoKfUxJIHrovrTPQ.drv
IGUCOCMqgvJABFmGQubSGFAAjG.dll
jQpBDCPKlWKypXhg
iCaLmyXcXkRTFLMSOTTbneQaoA
rjMgKIAgpgQmCKNEruGlwYhzgAz
VbZ
GetMethod
goPbJBTckHWsgrWMZQwRUlkyGO
qZ '
?1+yZ M
GetObjectValue
lFJBqsVgyPlDFCXjAoO.dll
TIhZ
KHbBhqdDpbycfpOtCnF.dll
qXJLluhLjSqJDDCqqjFfDvmGvi
pAlsWtbgGLbmJKZCfB.dll
DKQCOdNCmTYiYRQpuGpi
LjqXzHKNaCaISdGmofWWsPz.drv
x.a8
get_UTF8
UwHtgtsPEFSVClRJ
fHMwxWNalAdFIAvrFE.dll
cSUsyYdqmhjzaXtcmfCKbomCld.dll
TcJfqlajYMCiFqwesJA.drv
IcHnLuneCPbucQWqqojIWnVuPk.dll
ugOhynQaruIUOPskxY.dll
MngoOHlApeYmQZUJBiuArQFmrlc
UFJAKZfRCttmoCbw
uhldDkBsWOBwcouRQEMeZOH
UuABOFVuWVgJhOmLBuJEYxIfakX
_+a`8p
System.Reflection
KkIyrjiNzHodfltkOyeYPSotCh
yXMlylNGLagMbgjeziMKTaDdxV
TYywoybvuXrYLSyfyQb.dll
jcCrypojnLJqIFJnhfz
RuntimeTypeHandle
QhKlrQEoScFCMXJbzenpwCYhkT.dll
WUNLejcvfvmBOQdehVjYeyzcYD
a27fd372ce984ff5af3b7bbfca1193d2
XFrdXaWpbiRuVlUjij.drv
gWzCSODiDmvVEfiJFeN
MNQBHDEZEXoKnfcpAdtm.dll
PZ W
QmbaSAaMfMMkgIcpnGJOFRsVyh
OYzJOTchzDiSvmkkCs.dll
hIIctcOUoARkpKqX.dll
XERReJZPSoapGMWMev.drv
>GbeZ
LIwkCqlHNPmINZCKuCHG.dll
PhbGSuwuJpRNIxNDyO.dll
ArEtmwCXjobWPKjVod
PLxSFApwPxfnKnINzqL.dll
wkOtZwVrHtxWTptvNjBW.drv
System.Runtime.CompilerServices
JkBFLMIhzGqtjFuuatw
}Z F
xTfZmaVffLzcAEAXYFz.dll
Append
RcLpbLLAeqnGEvLvvIg
nKeTvSBiPhoroUezFH
bwCyCULomkELFNdteV.drv
boNhKMpdyPBzXaUXwm.drv
^08Z
tJSHKLzuiBQZEmaAKksG.drv
wkFuhdmNPsvALjZHXUA
CaPGGnEDIzOirGeClk
<
oysfgLEKBOVGeQWbBfTq.dll
AKQfxtAFenKXnAPtlMBZYLPugC
~Pa8
aUPsPxwaTMvwLTly
wFmBeyQIjbmaAgCSlkgI
jRmQEAAhTwWDPJumpiK.drv
Strings
LKspyoIGmGLAJQYvMZSy
wIGxjaizQzKdLcDYUl
Ca%
EUUFaWMkAPKVGhACBPrhhaYLrq
PcRJffDcYZVajpFVtlw.dll
MEtyKyIXDsSniYAsAQnDGimBZp.dll
a4e40ac65601413da62d7fd8470f20d2
UMBNSAtNtlDTIOoK.dll
cxbwOGMawHnsZMKzjudIuJWZFS.drv
Z TE
yjmXgcVdkgmPXwVfQmjLRvGWOy.dll
YbtBOtildcpttwaxFDImbroAfb
set_AutoScaleMode
Z 5U00a8
jsBgcmvDPLDjvqYjrmhF.drv
ZASvwduiXvgsmwkQIgTltxltzy
fsjplvucQxfVrqrgInocYnGvdXu.drv
gJTyohDGTemhSXXtxWq.drv
OimGJaZuJErJVJqK.dll
QEBUtfpmMuqfApBgIOEPnPD.dll
zQTRGPqGPZtvQgHniHA.drv
ypbYOIlQpfYSiReWDowOlUo.dll
get_ExecutablePath
6>Z
%Z k
DTqcWJAjkyzNMWZrwnY
Ea8H
qdlBBMGwwJKVyDwgtyaIyQW
xVRGxsTuithowrJDkpL
TfqdYmSixJUTomCtPgIoLsWrLG
wguEVKvJdAZHSxWjeg
LRvirXkalYaXdAW.dll
pOjeQmTSUtdzAcxVEx
[;Z fl
0Z e
:648S
AnSxaSSxwSZiYcwjfw
dkDUPGWEcfhhqyhcnNSLZTdjCz.drv
qemVlvzAgcDiXSyg.drv
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
IHwQhAegCHOTtYHTBGi
kbviQfOyBOPOrfwppTJS.drv
jpWfuwpZpvuPNbVAcd
OeUGdInRGXZWTie.drv
%Z $
aBZhFPSAYxCwvPniaL
wEVRrYalhBgxsosXkAwA
VzItKFfJxfYuSyMXRpychzWoRw
GunVQiatQUlatTnC.dll
%- &
!This program cannot be run in DOS mode. $
oYTWccIoHrapEhActZJppiKkQq.drv
WxoDNubgjoPjGPfZxMCCIotVKN.dll
Ea8)
e %&
9a%
9a%
)s8
jEFSOeuSYlalQgCPQDarKrY.drv
Dispose
iHsryxEvoclCJilkZs.drv
djtKSZAcXfLxRWEjwO
MqJhDYkReOcFvfWYceG.dll
GetHashCode
GetCurrentProcess
Z ,Q
lkaSsLYSSihTbWXt.dll
ynCQkdMYfrZjNLunOtxJ
ENEINMjGhlgaAWDmUzw
pYdDNNAHkUPpKutWHQyrMQbSlL.drv
:Z F
UGpFgMCEuXvxDyaOqpOmGUDncPZ
rOONUCHydiAKIfyKsBOR.dll
cqZjIlgsixWtzGlzcKo
u)!Z /
SuQKRaHGwyVihvMOiF.dll
8N|8
itZ8
aYGifDRMHLuXWLZDuOReUClbki.dll
drZ
PAcQWSmUtBMVfKqepTL
bYOzvImzYulcPcRJffDc
%{*
xCaJHRWMzCcqKBeZ.drv
fa80
HwmJVdiIHvvQqSmWIBKZJOk.dll
/tr
ByyZsJLgTQbcusutRCvi
eElRIZcYxYujTqcHaO.dll
IBbPWcWgxuyyloJzXtHQsQRAuY
qjnCgawYLTHAgMXLqLktlDCvJIK
Z q;
VukMCiTrsEocmQfAsGZkzJL.drv
Y 0
bGEUSxJPXMuUnSivHSdRnjEsSa
RXRYCAPpSSCBgahA
BSJB
LAaHrNOmaxNJogClxT.drv
Y 9
My.User
PeENPurXigeKCSCdjCaK.drv
hCdlGlPhVoDNwnNEQf.dll
x>"A
ymoEXoIQSZcamxhGkf
eQQiShMasbNcnHXfjUcK
IContainer
OzqTtHFWSeRGOLCc.dll
get_IsAlive
Z qq
`X82
HBESMlaodjApkfIlZenlbtxsqS
kkPaPDLzdZSicGJzTqCzejC
mJNTxfuXMbWAxiiAHQ
/"
KWLQGlsoWJLWqltKUVZZcPQsSP
hfGEUKgCUDNhmiBvwavJsmyGrH.dll
Delete
IntPtr
XaCPqaAETCLkVptd
JAPlmiBHwntmEoPSwV
etNKrsgGqxouahEIMhA.drv
qfQHKNUumrhgQGTU.dll
NjCmhGgtENmgoGCxFWU.drv
OsrCtKDBJEEerbWggqTd.drv
NGFKDBWLpfUbQIHPgkEnsUPNro
hOFikZCdlProqKaAqQ.dll
vxBIbpbXseemvuCTyUNScxraRv.drv
cQcIpqMvJPNGJDx.dll
ParameterizedThreadStart
}Fg.8m
thlrxmawDCtWdeWiBWUiapmkpB
yfDoaOHoTbZejTDjDSuvpvqmof.dll
hdrcxOisODxPMRgq
Qma8
uHuLawvLecOmhYcUIRyqSTQYsI.dll
bGqByDzaOMCLooETvU.drv
Microsoft.Win32
tkZBxPgViinOfFMymFN
System.ComponentModel.Design
aYRYPMNIhhPiZPaEFpJhdeJwMtl
dxDeQPFInhsewUXGxjVHQKYLwo.drv
ZNhwmfWBALxUEWcMnItRpzbhFq
dibiHmIiQwBqDCOqPWYhMnY.drv
amsXxwrzTpHKhKQYfjH
fgbVTmhtzwIMXJbzhz.dll
cWGAIovSBLhTZriLEEkLIDIFLd
AHPImtEuZpwdyTGZzBoGyPMgFr
BkoMwLMbvzGBDbqpaGMgEeprUf
InvalidOperationException
5uZ ]
lcPmNCQvNsUAilSaslQcDOgBhd
GPPVTbtqujLoOgdabMS
eDayqoMBCYTdlHXlindlqafZnn.drv
DfvVRMYNuFIQmvJQKQKgXeDtqgX
omLQNCeHArlgxHHeKpsUOEkLhl
+C~%
kQtfXTKqWbymgMeLdAr
HfWLkGuQfcJiSJRPNDUZcCYPtY.dll
tEwxqPuAacfDHvmKdZR
wiGiXgfefZkuKDqm.dll
gMDWyFQCweAXbsvwjujS
Z nom
FkldCxXhRsUUYUNiwpU
xOPRZgofNnXPVpDFgcN.dll
KpAGxsxEhbLFAgcvBshTPeVPtRQ
yyIQSXvJTbskhXfiuCkdLMSpefG.dll
4L2WZ I
MVeSLQmtlbBGpiFeCB
MrJteKXlgDILZwlQpcxzSwV
liMnFDMtMYkXsGurTGhTUvTzmn
ConditionalCompareObjectNotEqual
gwrKUWeqDbCJaZrW.drv
FdGHmqbLulCuTJSZuH.drv
HFNwMabPSuNVvcpTUWlUJtw.dll
tArANqCqJtIlyRiaemBAyBt.dll
wULpUwdEnPelXYRj.dll
sDSotftxEAygJeXxNgpFhusrIM
QqiPebJVRpoMsbElwXH
DfLDFdNkWmpYMVoHHrvi.drv
nZ $
WDPApAzpMhmsxbqotMaEuYeqDo.dll
VAMPKYhhUxZYvgdMmO.dll
SizeOf
KOdAFHDkbKMQJcCWZflJauC.drv
zmqwGZcrPyGFMHuVuscfJlHUic
nViZeXeYclUgFJoQBvCebTxMlz
bpNAGSalYeKcYZmmuuY.dll
WRrXKkSveqAiONtbnftXimoTBG.dll
JMZcjwHYBfwijLjwWlPheKeemO.dll
BOSvQRZbYOzvImzYulc
LLFAywZvmpwvpowMFJsQ.dll
ZpZhluiLTxWVxGUU
ZOtlzPpFfjfmBejUWNsvhoMBOK
CktZBerPimYxcrNuoljb.dll
WyOhuNAWQXidWosFQgsY
KNTTtjlXmrRiSxxGxX
IyCKOuGBtkaqSOrmXuzO
NFQijEvdFOWmUqesPKFyImXQMY.drv
byexGouKSUiaJOEasA.drv
YDDoqozBxqXgVMajCPYR
wrYdPzbiCQTDlTQTGmVJszI
xiRSDCAINDellKHcILVSNTPEhg
iKwTBMOWWQgSrrFZqohRCdvxRm.dll
"QZ
lysEsgUvnArOKgHGcLxKMwh
Ka8
NYkEflFPSLepAUqvKK
YUHijwOEUahMIKJdxbz.dll
Gga8<
ccb0adf678694fb9ac27f911276a3f7a
rBcIaaytdTsqNQcbIasNPDzQWL
Boolean
qHTASxuDULoHSUMz.drv
YvZQAXsOEwQZyXNPWxCJKsnEFG.dll
vaJXVSSIVCMFCFpVttOehlxVuS.dll
HSREPKcmuIHVjfsYYi
d4fd90ed5c2f4aa5bd7dcee871f1a625
ZlJXiBBBeCaftrfiibph.dll
mWJzsFonFeiIhdvGDE.dll
% (C
SnsKNzOznMfwgcdnNncgoNJSKB.dll
tfrIhiClDNCPGnqq
MethodInfo
dhCzNuTdWpkHHSRkXX.dll
qxrmSCNVvIuiZleiwSxGujXwtM
oujhlPhcZhPRXJIFRHgXTJmGOl
vcwMvvmYCBdXBNBQUg
CompilationRelaxationsAttribute
rpvpyEHqxjEfdriROOXcVqHzdb.drv
rlejplKMptaezNGQ.drv
qZcZiRNyvVgQdcmHaNP
} ?j
Z !y>/a8U
MXBuuXxKFVXFkMVkXgx
itLnjfwQLJMDQXxmJbXb
FdWBHiwsxESGeFdvSNPl.dll
KI8L
axUrJISHKundUfAztpwFSYZOYu.dll
IkhAZNyfHzrJVDJkMlKCaGlJUC
HUkYDJsdCNtoWMAEoFsUAjTfqe.dll
UYDSWJDxExMOQaMhHH.dll
fMmXnBTVlxUSvNJMweYNLlVDkx.drv
oRKMYaNfYWjIaIytSJ
QZTEjZtKpOfVpZnasfEwXAHJhv.drv
hgUksEzybRYysAwKLmH.drv
rArGpHqDqbxwDXkPwvoJvwQERW.drv
GYodRCfOVrtjoBWi
hWXxsfZjiQVxOdH.dll
Random
qZtxjDJFuPJQGxIYHjuAdtlcVV
U:Ua8
Bt%+
LBjagFUvbUiWJMFn.dll
MtRbpNAGSalYeKc
VQQGsahuGUOCEoGTGaUGhXjmbE.dll
>dta8
LiMxbYNgLWVRzmOgtf
BZXPnUToWKCbnmuYKa.dll
AwHYCYPXodaFeuyfKN.drv
FEe
wkGsfLKWfdGnasDF.drv
zZAMPflQIvgUiiJaXWLUaVUGFN.drv
JtsBSiBDgNVahbRsJYaIsNbswb.dll
NMIIqcXiIpNAiNfdQEStQpiThDZ
PvzAffcpPPpYiVxemDZV
TRKysdZurvjCJlbe
BpdqydaJNGOJIZcAbBhdLcuStv
lDfMGxtnXTYTsINw
ITPVXDmiKGvvnkkVqAHz
wKTZpIfKYvoSEJnHxwoOpoR.dll
savUgAdcnizCCTzvHF.dll
szaKgMFOEoYWbVwkqrr.dll
Versioned
PnlNKRPmaoNgsGRubVXx.dll
tlzPpFfjfmBejUWNsvho
ffWaUwwAAuOdvhCNJsIEULnfeE
ADNPaLcPDQVabOriiCf
PvJqLEzlCyzLoblYlwxXqrILcO.drv
EmqySKyWvLvuWGyIoTkCaZW
jsfPoZhRsCHPCKGyIKR.dll
gXyuBYQkxSFQAhHtnkbDHlSUvn
HtvezEINOJXAQDqLpP
ZztSPuQfPazjUVtUyBIBGkD
Microsoft.VisualBasic
qjFfDvmGvisJqXgRxtKr.drv
PrYNfXZqpeWwXXnQaKRXowKTaJ
^E
set_Text
rWAQfXWtgSAcTGVihsf.dll
YhdvIJcjEGAPYQExhl.dll
SuY
DCOteGgggrfaFWsCut.dll
Qy|a%
WriteAllBytes
cBeEGiyeYeVfyJZHLHSOPUU
EnterDebugMode
9ira8
IFSDRTpaibOasGYvPvsIYknvXBc.drv
eNkFxFePjahCnlPCFMYlPAZEJH.dll
xtaMNhgiAWWeGmhhRhZhcPnIXY.dll
u{?a8
EgzTsMTvOGQOQRygvIcejRhDDXh
PCDvDTeBDKsCsFwzMMrGdFHRvt.dll
LVBCtaWsJadxHpAV.dll
PDEtpNdrtoeanaNASpH.dll
a3817571c45d48989978a8db46f85618
\Z U
esksuOJsYxCIxwvLMYpMXxw
fJRWVlRtDhMcCWWp
yzWhbOGCmJefDqJBKjqeQzeRqij.dll
RYKERUmbkQCgHKDGpHoSuzeYzj.dll
oIKxKqkRSvWbtQseQfBf.dll
EnAQITaWxluRHKwVNLVVgJDbEXF
ydiReJrxbCijoYqyOnRV.dll
sTqKTYsXbisIyYYuLCc
hMIKJdxbzETMdnmxJKNQ
lzZ ,
QGmOdfeFJeNCwBdhWwU.dll
IU08
ZmaVffLzcAEAXYFzttkGGoBjvu.dll
FRmeSBLeMMGABxnZ
Concat
zpFyFuQRnTxJYBJDNETj.drv
hQXEYFmVERplTakQCIr.drv
eFtrQXldjCsvnPEelHUt.dll
StringBuilder
GLKVEeVHDkiTndBloNkdlrYkUq
dpWPupKYtwBjoEqsbsO
WaxoiwcxVcpQlsKsEUaDdLJ.drv
}kZ
OknlZyOwFelCoBILhrG
FZ .zm

AQkRjDxctIwiygVKFat
OvUJxbHhicxBWsDQwh
VOhGhilOdufAqHqHCrm.drv
ZIpwSHIFzFYskmypFtPZVbzhFZE
zMSqGbAwnzStVPDPPq
KotdKMPeHYDtsGFhPv
Z d)
tzTFqlcczQBiLXIHLMl.dll
1Z _
1Z E
Z d=
DCzvMoZiutBYCBAZkCSnpqRCDW.dll
JyZRYYIjHFsashzTXUXdXbBOwT.dll
uKgYurRnnHeLZbbZmRC.dll
whbIyXgOvZLnwRXlEeuuHDBfPW
:ea8
XsLLvhUSGPUuWQcD.dll
CBzfeqgzqElMXlFcvDuu
JXCElqcevEqjYxsbeaFSDIpLLG
aAWDmUzwHHEZCDYAyxlT
KemKIIUINHSdkfHQ
BBZMbpBHqwgIWAIfriObYylVny.dll
arInBiMVvOkpanTYLb
EHLYPGKkCKRxkMpjxYn
tslSFfKIqWNavdf
ZG<
!;a+
WNavdfCgaTlUNeumIDh
OhPbXpiWEVuQWonnwM
bppHLuHUgCNdjrfkgb
FZ
'P#
TkTjliKiKBpmYqSDxBaoQFavwD
luSDsMWSkHoAssCCJkTfFHo
fbAOmVclDjbVDokuIrO.drv
z Hz
YdzwhOyoqYyPYRFRwo
asZdfGkfhZcNIOHeNW
oQOZuoQSMERxCaxu
OcQxcKbhlyNvwSjifXE.drv
GetTempPath
System.Text
up]68
WrHhxFbIhHPCTSCvHIooxzpwtBD.dll
EuPLqlNfjXUFpcteyLxCJofOiB.dll
YejzqRIgWvdxTqJbGRxdlcalzg
FZ q
System.Resources
!a%
vsWZPEtPjyEMDllqAnu
vmTeHqCQWNoairEnKsXB.dll
pPVhoHkOrhXYojfr.dll
_________________________________________________________
KwhmAhvusYmZbWWGVmxL.dll
jHhydDqHobeoyRpPompErwcXcS
EyltWdubbstVwuwzoQk.dll
xcrNuoljbYQxRPIZwPf
YixxtiOnXLoezNrNvoJp
EvhcyzXpdIrWTCLjWOCXaVIhvhm.dll
NRRlqcwVexziFymvUyiZ
(}lu
eWCPRqOGsmmAvvEOcIRc
bNlJCyVEYkQyeyDv.dll
aP 8
yljUcptsxCzuQGdsiW.drv
eHyTtrQlQRbQiVWzUifZ.dll
_Za8
wRHZgEuLjEXHETRYCdX.dll
RWvMfUtjLDDTZzydQCfitcqnbz.dll
wZnQXOgqxkfdQuxK.dll
wMBhwYnquMwyLMMLGWdpoRbZOK.dll
pfioyNKCzIvWvcWu.drv
VrGvtqxsofCINcXTycCUQAEvoj
bnZkLZkHJcHCwnbhtQitdjwdBg
xNZQjLeXUXfLjdaJiDTYyvOlzbX
UnkBmolEVvaapWCZyNIASNU
GdwOGxIxzOBopXKA
qEvWcuaKNsShFqahzig.dll
QbLoxsJoFxiUJkqdtfcUXwDQJx.dll
jqYoNcndEPbNrPErnO.dll
SetValue
VcgwxnIqAndybdVw.dll
sZ B
AzOMurweiCzxEUxqrs.dll
SJxIscdFazAxhwqBNmc.dll
S\a8h
-$Z r
tsfIzPqzmyebBLAxJyCcRvOWqs
Z !#G
ha8z
jydHfzQRkMdaxqCaaSwCEWWlELk.drv
ykCOMeMzAobSuTDTES.drv
TpUqFaDmpYNUiyUOVXroDqBzVW.dll
bVGYlRGXggmLNVeMGgjo.dll
xWGrgvbKTtMkWIQQWJbe
OfFMymFNHNwpQwZ
tn%+
fHlSMQjprjNyhKdMggCz
SPDyZwtpyiMVRsXfRIgVCHQGJe
XOCcRWIdHOSTRlFxRidXJVpTtI.dll
Z <&
ConditionalCompareObjectEqual
oa8s
GHswofJEAJEsdedJPlRZzYG.dll
VIlIabSGQBhBZLWFnflTGOrHch.drv
`qZ ]
UAQsatpEedaNbIJX
RjjNDAbiCLVhSfDQfQI.drv
ewqaUvsGMxGAGQJGSkCWNFxLLr.drv
NGghzCXguyHgfQUY
CnAIxIMmABGiNdCi.dll
rXNgVmKhzjczuezZeWI.drv
fOQmWAARxuwyoqpvUJAiBWY.dll
zjkHpwAJXsDXnzNuwBgBeuGcyL
yrAlXtLoFvLpWgqOHz
odLmRkWaUHSWgepi
CXcmXMipLHRxhuArdpNQTDh.drv
NJINOmvjVGjqvLNxjcMHXjlADN.dll
qrRefWlCxpoPpbLduXH.drv
_CorExeMain
wFisSLpmZINUDoeNHMt.dll
HETMiHMjxRQYKEZlgG
vms
"a88
PNVSUxEBTzipxHTvIzMYImUvqY.drv
lotJAJvjwMXuykNnHwdEktrtjJ
oa83
D/Vc8F
SaSzULKpUnJoPCelNyguRNY
uaNPrEHCtXrFUyPyeWG.dll
Command
DebuggingModes
85)
QIwjoyvrijgxVvRxWGuzzfgmUdu
qVQufPgvfXZWCAcEAK.dll
FPlUDrdenClQqYiLgMI.dll
YFRZySBADVHxLjxahroa
EGbWinSIIfkubEbkYlb.drv
GrjCDONqhWWauyFz
dMmoZJLJkPoUhTUYDlgVXcooKXf.dll
tyMzELrfOqcrsxlbagddJxI.dll
SetAttributes
Z hSb
kCycoRZWtvslDoJcRlpd
OrObject
4Z V
& D
EditorBrowsableAttribute
sa8`
Z w$
XCghDVAtrBgOkcDYas.dll
EguqOvkjnVgngiAUpVxJsEY
YAUsTZJFKirHpomdFEwgBTzNrM
iZ Xea
VlUNPaZAzjrJzCXtYh.dll
xIytGQghsthrTejaLPnlDqTZxK.dll
fSGWNWqeXWPWuZnBidldnrMnliy.dll
F)8t
XPovZFUYvFpXMgyVjMO
User
HJ/
YLNlaCGReNgYbYbpWrVxZBrqrD
qPVrxeBnZoPrPkleXQiz
sYgEgxbipnrRLnpr
vfsTEabrEPvFxSMDxAIjdfEbjB
sJMjkGZEpyyCQezcmhc
AHXpOlmSPQHweHUQAHrrgVOEeX
swPvIHaKxYcQEzyfFWJBTbQ
DGzcxYdFDRtJyjU
wXattUynbLeVTwFwtqiDich
qJTpgzizWcgHhUFnFN.dll
ZtQOliFedJOLNktmaLOHkkC
nmWVPMIDTaWcJIpFwf.drv
FryvJSzrwszRaheswgkfWlEtrG
wCeebxkNnKnMRGYnXPDjBqaOuU
Attribute
w88"
jxHKgDJWdmCLCDdJNSXwMuzCHo.drv
JWDZphNzMFZCEMnTfQ.dll
OXNVFBaSRTwUUdilmUQ
SG9a8|
get_FullName
uOqdruFRagwDTUCdVtSqaHddBcP
OGfKloeAXkDqgjcYrFjQ.drv
WuUgPNwUiYfvMazbWyuoVAzrpL
llmZkXEHXAnizYrRzCZdSbdkkCE.drv
bHDEHljrbExgGCgCIj.dll
Ha85
TWwNkKDVCxUFKzSVBpvTnfLZLl.drv
CnffAFVBAMBEFNGolGXkSwWpIr
QYFmPaomxgcsYmCHmtwcCbETuP.dll
Dictionary`2
p (x
!Z .1
AtcCwzgYavPJjvTNlsfs
gnpYwOvgFVVpkXBaTBF.dll
VALNXdKgjotBCsWYpXy
fJgtRNmKcwWZKuilsSTF.dll
sIWBueMJIDcYWzJCNnPv.dll
IzWubfipjiSwZCdR
2a8z
BSDoBxxdJCTozOEvsKh.dll
ZYjThEXtWDIWNzPeENPurXigeK
fczUBsxagtptXecyMht
brxbDJwJgaCubSIuxSLBVkAFOJ.dll
8>}'Z
KXkVnoszvjhrVPiufilWSLuaSA
ZRMktzrvtHaGFTLuPQHgkbs
dYVbAhWJlvvWpYhtaVRgFphpboQ.dll
ATWiiyjepUXnBMFNKbhmgUhzMBi
aaaVewzAiropzXRsRFCxAYqnYc.dll
FTiTAmMgeKEtZwPUkf.dll
DxyQOJRiiKzBITBRzvd
kZ Z
-;Y8w
nmeLherEFWPFQpNVUVAkgTFWOO.drv
yRQlrhFaJQfxrEGxGnErcdWRrO
uHciEmgeeCcczruyhdp
MCmpwXlUqmkCRJVqpFhCzgc
oGcMlgRgtiEqkFkyReeVrOLndt
hNjnEZOgXboPsiLIXTxMhAcggQ
RuntimeHelpers
gsDYvvFUjNaFyiZsSVtS
EtlbdSqqeaqSQoju
jQthgOAsyccXoFzNlcXY.dll
\>8;
CXVIspUlezBTAJFTXO.dll
IPXnlWacxtiUtSVbQa.dll
jjbpAtrQMgOOlTfeHuT.dll
eFCcpYBCIvVOECLUGegeFkz
-a8
pOGxmwXMTuKVPiTWAuGAzhdQew
XtYgeRtFgfDrGKLBwkqgYfJXsw.drv
WTdDsxYmXGQMejmRzPPHykUjytk
ja8e
^E
sieCZHNjMBJyTENpiO.dll
Z Y%
HXzuSCSFydkDUPGWEcf.drv
JCPWCUbPIVtuidZsQOX
nOStmdpzhJBAdafrIHH.dll
uYLutLAhxNWuShmwqkKEteo.drv
SubtractObject
aVVvGnJOHozcAfFeBZy.drv
Object
gCOXvUeZhpLwUWyaaQJ.dll
ja8[
lZbUcitRIZiqzQOBOSvQRZbYOz.dll
ttkGGoBjvuWeIryKEAr.dll
{=Z
Z CB_
rQWQvydLkpUYWMqxyG.dll
p #'
vKnwxgkpsThyFzljXYKYXeAfKeu.dll
SdYFYvwZGCqQHIhqZRhiwNxyVa
^Z8-
ComVisibleAttribute
WdNdhBHHOcQxcKb.dll
yxJdDHNFEmHLNSTcqr
eWYACPzvFTXIaZbeKQrscKArra
g%8
ejnHGCnwcQcIpqMvJPN.dll
ShYoRafzhGuVsulaADUFBalbmG
brVuBYsijHlTOsoKejPQyQZ
eMqamEBLeYzrsdyDKCDVLJVJND
sbAnbOiVCFLOcXGFiQZ.dll
wpZuUHagaTVwWDlA
xlCkhdbhxAcvYUfoSs.drv
XgkDfueHXURYwEFzShS.dll
eYMYsIUSHOMHWKwfwzqUZYZfkfJ.dll
CUJYLNKqUEcUoWWnvTpJAvgGJa.dll
i8(7Z
AvuOsizYWKkSIumpMY
%Bo8
vPnGjfKfeJpAWaBARlG
JKHuJQaZqtfwmKuFwzK
EditorBrowsableState
mBijVWvMxfEFJqJhHJML.dll
pkVulOxFShxgCNMosyCcIDzNWm
hhqyhcnNSLZTdjCzmFE
CultureInfo
Nna%
a8
DEoLXAXDMHpmQgfi.drv
1.0.0.0
vkCtfSzYeSWCDsXUbhQCfaAFHq
oOtcdDwJEfvZokgNRjW
DkJnftrqfXEdCrNZsHiY
UGtMwEimBCwiTaELzcqJ
qgxLewcxFnWQLjpYyBW
QNHRgVwThBpPjlWrtEMF.drv
aZDUSqiSMRpCrLzUZmUAIRK.drv
zAlRTUgKZHMLaSTvDYNFpAnJVM
)bb
ZKHNxutguguKFATRzqbV
gsbdwBcmUhRYwMjAtGN
$yOm8r
Oa8B
WkZ
YzWNNZorEGqzuGWR
aRMGfZaXFVvMiMthDjpV
OlDOMZrleBModxouycDAfwPQfu
XZ z0
ykPrqMVIieRnZqAepglN.dll
la8a
sZ \
ZGXCsKTMfpiebXuXrvYexAodNf.dll
UUTjIgAcgFliqqczTJvguZELZH.dll
G/)8
fvVijMCowJDXOKhNLJnDOoY
vMAiBVfvpPjiPokcBx
MxWXdMwBIDpViUGrioiHZML.dll
Z O{
HUECCexHfMvBBMWE
a8^
ThOxCPfvM1YMOiZCb7neYp1Gm0be
PAWsIkJntPfyGITp.dll
QWhWgzxcqVafoVjWWz.dll
lZ )o
Z l)_
CBBteetEGTseFEuyTz
IjcgEYbExncYMtFbSlGkrZfQVd
cUySKDtbkjXgyGarAIpSFjYpvM
'SV8
Exit
gUzITVMFBITFvJnFMZzG
INMdWSLHYhlnpRZOtlz
mlicwjzpxRgagsqGCDiPcdv
p8Z *]7
XdAWMccVBGSpIBdGVqW
lDbAxZAwWaBfArlaOiKTdYs.dll
YXWa%
pgHMVqAdjSmDjtrEMtR.dll
d U>"g8
xBoBbVAqHSFdaINzaoG.dll
fGXUcQLJxovmJmpgAd
SeBhpKCbiLjDCMxpTCoTOiCjcK.dll
]oa+
JhoOMbRVYaTNvzapoC
{a%
mRvuitwzZtXfPpKhAdzl
phDjjQwakSjAoqlfpWqAZlxXZd
OLqZnDvjvrlyidzwHUguArI.dll
yNNapoHLMxpGWSVAgItIgJF
dcSGJsqaMqZJuVcdGtjSMXUffe.dll
i`{Z A
SgR8
get_IsAttached
NcIvSnoYlXroovyMBb.dll
UYylMpUAKUvvWMjjUGmuXwB
wKQfrjQqCTMhLHUdcNZ
GxylyJUtsydBlncnNRacAPoFXb.drv
BpueAQTPKfuxshXWghHZ.drv
FailFast
xTTtLZceNKCktZBerPimYxcrNu
EUfZ
pHoSuzeYzjAOBLuAdRI.drv
Z zS
xrsSqhdLerOHDMxuiMwjHwj
w(R
bGuEmKBGIdsJrhjoysdCrpUIxd
xPiEFOWsSCPyyuD.drv
$^E$
FYa
HLjBrWLBRylztpcZnIhv.dll
ec32145a6bec4b6b95ff4c7c4e90ec20
yleTYJZcfFRYgeFWjO.dll
OAZ #
DaZ
KggTMCqaDsiKDBRtBB
CZayaOOSgxrcUZMboF
KUVMlXJYlLpbuEKKnPFLwKJVhV
DTXBfZKTVTUxlqigXAdq
EsIpaLKvizKfyEJEKcbt.dll
System.Threading
FECECFsXrfqobLNzte
!ja8
a41536bd37e84fc6938c18fe665d7ee5
kGcgeefanKoEdSBI.dll
wRnInHZSsmioHZJd.dll
Z c`N
N,Y8
)a8E
EZ o
JkQOYgMwoRfFzQPG
CXjAoOfWsgLwZBCSoVmT
aJFURXFWWCHYfYvceVae
^kPQZ
OUOhFzQoMqJfjpUwUFUV
IcefSfxMucYBPUsuxKTKRfG.dll
mLRylLcwflhgdcFJdxJSFuf.drv
Z h"
oCgSezCrOweEqXkJyxop.drv
gwAObJQBwJHAnZuCrW
6 8\
GuidAttribute
Shell
S@Z y
rSPZOKZeSvqsOYGDUcN
=mA2 }
ekJnBzQKyfnnqufruOALBTRrtU
UVFxsjNzcMOlnVoZzTboCNs
Conversions
isvRWPbRIQEFgZrV
RXFVkZYsIgvoejphOE
TwplZEaMKTyzflLdqXJ
hRaFExoPSHmTdRTtsPm
Ja8X
Z od0
hwa8
pINCvvBPbobgvWUWteAXSQSVfd
=68*
tuidZsQOXENEINMjGhlg.drv
Ja8c
JxQifUkISOTpaHkcReqKyfZJBKU
Ja8{
Microsoft.VisualBasic.ApplicationServices
EiuOblwzFrnDOqqqgkzPXMPaxz
]%&+
UIQsQzgSMOHVLmaa
GppwZbcbiCQFcWWvxGCi
YbtpAuIMILlCmQwAfXB.dll
HNwpQwZYPTkItkiOEcS
fXZqpeWwXXnQaKRXowKT
Next
<Z ,
vPhFiUogBaKrAwXuGDB.dll
jiFfgxAftxAJAIdvAgw.dll
gWlGsfkuOZAodctt
hSLILsRjLlFOTTNpGEb
LEzEkFMzqNEwBAYobV
eHrUHlMHyZUCGdatjmW.drv
ItZBQndzoFMsBeFDNRjjzWyfsj.dll
Qa8I
TiOBziDUklhmXKXhAoyX.dll
DtgUYVEWMUuyMibOMiHpulgJPw.dll
RDYkJwvnAsoHJTmHYp.drv
kbhHEfFVTeAJyPAimDLjGdthuh
YZVajpFVtlwWOUYEjhpo
PtVTFsjRBYzSiAaFskxwfGxSic.drv
RCnzCnuJdOQXahabLrHp
DnIbAxcaFeCLyYVoMlmfKUNJRz
ipeseyLuUjmMbBkuBEquiZOCce
ma8
UWteAXSQSVfdFryvJSzr.dll
]f.
LYaYoMQAvyeDCgXlXZSpoNlEkM.dll
AddObject
frjQqCTMhLHUdcNZblXgERQtMk.dll
GnKjgYagDzBpfIMITMdYTSuhTa.dll
DemrqjfLsLWUHEXJNPlZSJvVUx
pa8m
My.Computer
OkLzWEfcSzkQKuYZVrp.dll
Z L'
NAFEWnmGbrSoYpCRuPXQFuRhEEn
v2.0.50727
a8F
TUpDuhUEdOJkzAwEBmqc.dll
tAQRzbjpEUrWYUKqSecTnzJSAt
igoEDfGlivKPxkolGpKj.dll
UPZ %_
^fZ Ik
zRSFhtQBFivlMAlcUVpHrwW.drv
set_Item
MvioinYFWaHYdhWgtRN
jqfKLdXhzuwoixcH.dll
IYxzfFcpxouwCdiQlfVfgLJitC
Z Bl
pDbcLFiimGqKRuZmyqY
qnAqwuJRSveYGkJsCmtm
qGGjPtdxJuKeCohDjKHE
pNxQTAmITUSSYmYmdQtXOOTGyj
yuDapNznGMpHeGCnBLh
dEDMKWbAeVVFOzSiETnHYpxixM.dll
YDPwpsLLeNEEMTru
YkmezqiKZJfUhKdyTE
wa8`
yRmIxcQHnpmkikRc.dll
_18
kFsEkcBRqSlHxFygNLOwuZmLlB
YPJgJIlezgTcaEpLOsgm
,1 {
DavtORgGuSGsqiNk
a8
IGQGtDtRRsXNWWItBJqSlRNCAI.drv
GSMiKUTuyMQPesce.drv
HbdgCLIeHOjMVieTRsc.dll
cURJilcEGOPrPRvWBh.dll
XOtKwvLtjnTVpWEidITAsFDYVp.drv
nAaObEQgmgkbNHKLxyEbqFtCaA
TBVHiiAieGGsRJKS
hUjSqnTrBXwLvagb.dll
hHaGJGGFygxxslzGpU.drv
YXBYoSTfHHNbAuNVhCS
zJRgqvevuwJgjWIh
GRJsiMyVNPOVpqnr
GetTypeFromHandle
WzdrnVmPmysBNStsGp
FileAttributes
La8!
EeYoNCVudunrnXTAxVAE
dVpPRNijJIGHWkEyAx
IXIZJfVaHGDMKENisRci.dll
~E
/a8:
xwdLMCGZnRNChrS.drv
BzNpGTRnbSBgwNbyCugOtck
FMTJWsGzbhDerMmyuMIsUQrjIT
LdHOtPRDNnLBRypsnnFg.dll
Z 8%I
VdyiYadCGZUbFzCr
; g'HQa%
ncvcMZjwgqTgrwss.drv
xdpqxuBFHIypuhlz
NMMaanxmEmxtLfAxZRGC.dll
FxPhnhMJTSSInPYVdqUDHPs.dll
rfa8
adc164053b5e4d37a06df681c4c21f5b
nrqnVFBwnffEcbnnsZvwFkwSMq.drv
DkyQmntvawxwHKEkQB.dll
UXITIFNEvicHhiNcjHNNfqQQUm.dll
IPyNPmPegusVXtqPLE
aCnffAFVBAMBEFNGolG.dll
[Z D
CaNwfDXSTHdSOnpx
/a8}
IluCesbcSwOqaggyYgpqVvf
nHjjqvLYUnZSpXXkGMYhmai.dll
CwgJyUfPxGJwdGtzrwfpPRa
RLWQMmWdgjTwplZEaMKTyzflLd.drv
yis
KUiTYjmTHgpeXBuQvpKQyifwRV
xfmHsTupKZbPloZqsHUB.dll
DVCTHVcUvYsZNGLZyun
XFYJRAYmWxOtaWfLtdf.drv
CpglUGIKhYaMwIWudC.dll
Exception
MyAYPNSNeYteQeITZrLg
mDYBfbDzfVDkvXFvLTowXpEpDc.dll
HideModuleNameAttribute
MlktEMZMTAstycfTlT
datYvxskSoWWtJIXkj.drv
)2a8
pcccZWrBPZqNItpmlEKnHsOTdr.dll
gidihwHzuAOhHAXsbNU.dll
w{a+
hw~8
XlsCuHHUTjIclStcSifKZUIIQu.dll
bzPRuGrCdKfeZkpqSKVr.dll
WeIryKEArjjHfVnrNbUrHmSSJD.dll
eyGFLSQmfBSsAhYONYRmUjUocRb
LluhLjSqJDDCqqjFfDv
KDWbELryCvfpsWjIwksBWZpJjn.dll
OMfOvemyNshhluBbYkh
^E
hBZizGJdIHXzuSC.drv
YpyOJWMbkBuWDDNVoE.dll
JZuyuHAmNcdsnqeIVfT.dll
MDWyFQCweAXbsvwjujS.dll
DvAqbHQgiXXSeoweEe
CompareObjectGreaterEqual
xsyyolKqBMoQwDUDvWjhdjNkHu
mxNnpmXwLNloWQJVULm
3a8l
UmerfGrUZjZIhpec
indpCNYGJxiyQCRAQBPHcRk
x{ea8
XTuCXRnOHyXjOcmEOR.drv
NewLateBinding
Z
AVGMbTBgzRVxmCgTtgEuwgcBUf.drv
adyWbsvIlTgncAArIwEHQcjqYO.dll
,
3a8O
QLjiMRHODxEmYtHEql.drv
]TWF8
2bZ !l
AweRRBazWOfaRrqPMTF.drv
jYQaXGSHchJDtTJvvNJ.dll
cCJa+
INvJmSEkEaFyKFlHJKE
RoVeDypINCvvBPbobgvW
PySlYTBnNwVzAJecuD
zIjAhkXPehMJrazaomR.drv
T28@
gR{Z
DIjsrQtPmeATjnAAGDk.dll
ZEyIUKgsxVJZXOVuvYQEDWeYAOt
TGLaZhTzZZPYciNMWezc.drv
Ua8'
eyaSFSdgFtGHKJDzHe
XBqqPnSeIVFzkLza
cJdImcvjoITuSNGpkG.dll
ENjpeDyIHuSnLPztBXTBUIlglnE.dll
Ua80
DxUXcWRDTEkVgyEiUUsq.dll
Wa8-
rQDXiYNUsYyzcOdNqri.drv
XoNiUsCLfejZiUiyHRL
IDisposable
Synchronized
oazXjsLNaaaYHFfujplY.drv
eda6641dfa0e4a8784ccc4369a6b5923
gclbboMRBtLPFSzaBO.dll
lSZ
SZ e
avMxwdXrCWPQGRZAvAAFcMXtQX
CMXqXZncogATKWxYbTmurDNPUk
CreateSubKey
QQcYyqszNnuRUsMXAFS
VDIhQhaQSNHJjyzPqa.dll
tnhzRAQmkOCDONMNnSFk
wanCREJNsROVwyOsDRUX
Z 3z
My.Application
Dispose__Instance__
EuYPWohybNKLCIULVvv.drv
dorkESjFqKoiqdFDVo.dll
itUGvBFeKdXCWwbmOk.drv
AssemblyProductAttribute
NLZXDHPuxyeoGnuGiTlDQmIBtH
lzmQRLWuNDGVTdgfhq.drv
i{Z
Equals
]Za8
boVmbsSBYqBBrESaHAUn
itLnjfwQLJMDQXxmJbXbunnpSk
Z N-^
<Module>
RiTOmxxvWamQovTwAaLRTTL.dll
VAsqUhIBMLwekuLDaMYXxAwCqY
qxEFTzWveQfkQxX.dll
K>a8
UNYNNpwSQioMprIQPMvTkof
jsqwFQwZLLVdTZbKEn.drv
GKullfEavYTSrEYGXDamhbRXFwA.drv
hZ F
zefrFOLvkbpyhPHWhh.dll
' <
pTynmwLFPduqHVHbMhN
PvhiUgLSHrSSBsjOFROp
nSWcblXnagWaKdATFPvdBlz.drv
CNDqZCpfRCVTPTwdcYtlucN.dll
WTlKVLTSkYcZAPrZMcJwjRQdcI
RIEDSJzryuRjFvCTjZ
obnDelOOQoTkELsLcnmBDFczmc.dll
g8w
2017
rAsLEPVgYitxtVMsJQI
aqJa%
vTIsYPKwkSdQuGcg
HZ ~
xfmhtbuwRloJBoZJuKu.dll
AscW
zYTUGxPxETqqkIaeWY.dll
YjFeGssSJhGYWSGORF
9^9+8
kqQGowSlPtlTVTUxitlfkIr
fESSpZADlsTKCHLbog.dll
YXjSdQJyzyjybOJZCmQybGkTZB.dll
UgEFXSWMqzdGefILVeGV
YiuXwtLHtHZvbTNEirkD.drv
Ia%
iMZzFLDVlYvxBtCPUG.drv
RZXDAheJWlJjHShxOV.dll
LgWKpkfwlBfRvYTtjjcSvAcipG.drv
ZQLsOydAUvGPuFoWEu
ZApBdLzLWTUPXbIvgCR.dll
jwdRSZoaqfduZJYkCTnryKDgUTS
CxBldQeIlTdZOLZGAUoE
AXKXjHALwURMTMDHClwr.dll
#GUID
xDdCxkWYgQCFeWprSi
Z Lm2
DVCTHVcUvYsZNGL
ajcNFGPOcWCQamAWHhXobjXWYH.dll
MyMkcODASJnsrWpQdwqDzeOuqtR
MlqgnPqCioNWqLuazgOCWpqWfi
Z 4*c
cZ
xNZ
Z*X
WkRDtImgeAWEpCKg
Y{\
NSlWOIglUOqICwmXBgjy
NHLDhhcpQTvjVqfIoj.drv
AEdtUqqqZYKcBoIEJewLGrcjzk
ToString
zmjHiYzxfakraKtwMAaifFfHUW
}9y Z
ToInteger
nQNGiiVKhRqeOoBrhNunlqBbOs.drv
xFfLZUqXWZbSNWJLIJlL
ApplicationSettingsBase
HzdvckiXPtuYMRZIsKW.dll
tsEpMIpudtGbwaeTIBH
KFodhfEYgFeFIOWINtJl.drv
pvJzmOyqNrQLhKfX.dll
MHYxXVuQyeUDixMU
IoIUUtbvWvOyeseVRZHwimR.dll
C W _ C
QjGbEyiRyhjmgCONIzT.drv
rqdupWrbCWoDCYKrqlcD
yYnBLyGMpJsaePVPRrZ.dll
UBJdQTGomhrRKPPSCl.drv
tpGkYrTpWiZMfPNi.drv
AFPWpBWgwndcVRUJctUW.dll
nhluGJSHjBMgLBVbXJ.dll
Microsoft.VisualBasic.Devices
k Z
xPLmREmeAeICtZHSUBCTigvCwER.drv
A{A_%&
Debugger
1a8m
Encoding
AcauGjpPsWlYFATqumzrjPF
yubMspLGlBeqwemVBUCWRTZ.dll
get_CurrentThread

jDeCLJhyPQuJVcBkoZ
FYoDRsCGXbrCkrjCIwjMqycuZP
SxlJcpbZNjYmJOtN.dll
oTGHCskqmwbaNvcFWWyL.drv
vKnEnjzSXtXOfAeb
ntdll
QwuEoxouGylTsffV
SKfhqmKxwhZdntNdCVQD.dll
itLAvzPcHROJuEeRAnw
IyDNnvmmeiXTljOx.dll
pkDDWxHprYxUaEywgap.drv
%-
yZa8R
NzfPLGMjdBFBZPXttH.dll
ibDoexdNvKYLJmzeCxHCkHNJIj
wKADKBxhNuPpnQYaUj
5a8*
modViHKgdKoWhFicjpUVzwPFUGR.dll
WNoNvtILhdNoBsISEKcEXMs.drv
JJaJNlNfNyJbMxsomblJrwqSbA.dll
awWwtsyaJvgqSFMaaF
YmBWNMrQPfcNBxjHnLs.dll
cXhiYquDSfSGzvDMTDUWSMfttQ
YY8f
mQPLFkglgpAdHTgAqnBPOtX.drv
CEbxOvnYiBTzTwaTgqpjtPNelr
EwoLnnfCxrvaVurlGEBmaQh.dll
aaBLLRJKQBPylqoSKXjIeLbmHd.dll
AjGHdBlXXjfNcAyYbRUqsdtgGu.drv
UserScopedSettingAttribute
WvcPZLhuTbhElOxo
qhWzFarKoKjQsljtRg.dll
j )8Y
RwvIuMKrDqsQFPQwfZtQpANBJF.dll
Replace
Z 1 ma8
System.ComponentModel
YOzwSzwZRRwEUcka.dll
;D4Z
GcZGFqeiihBfpdLfTJVhLQLhrC.dll
+2{
OoXhSVhjtVIrsmhbAqlJzbG
Z BW
GFMqcMKinjFOOUjRyqrYYFa
DjFddhaOrhWVowvSMHJFGgdoAf
zGUyqIwePSeoWLwGIl
ToKPyLcMGielEVrBhz.drv
vygUmNjjZVpjefqOXh.drv
ozHERqMZSAkDfnguvak
P7Z `p
5Za+
CallType
jiRCRFvcrWRYfHdwpiHUlRhmjW.dll
wszRaheswgkfWlEtrGdA.dll
BhTwzjfIqpzlvRbnTH.dll
rvfZltLGCjtzYDHExceR.dll
mFEvPhFiUogBaKrAwXuGDBYWTg
Ya8n
GiSaqsmBqSFdsskYVA
S##8
XXoCgSezCrOweEqXkJy
hLcZMCXYcFoenpgN
PklyRsjgOcLDfonZFVHz.drv
KjtTXlWYKchFDYUMRmJugKBIwe
jEuvMwiBTcGxYDYGfv
bvXELBShASfgFTUkUuDXWDfulZ.dll
ETKCFZbrZSQGJGDplVXditgOSr.dll
%&
System.Collections.Generic
RLMgUsnqsfGflNqMib.drv
+e
yqtwDDPqrTfYNzJz.drv
QPRKprOUgXIbwzrVeJeYBltZqc.dll
MfLqifaMqYiTxXKbag
System.Windows.Forms
tqXDDxkhpclfcKmVDaifYpcxGg
sZcjzhhMGoqzImbFpvFUkkavET.dll
BlEIzJXLuuMTxJQlZYHyNLdvnT
xkMrkUblIvcrdSsYQzh.dll
Cc.8
sGzfejNzFjFgINKdkRJHThoxin
rUURodGsitharNTNjxsZIzJVzG.dll
JHIDnkHrMzpUiebqsV.dll
dksCbhHuKDqUOQuRkPCQdQWRUd
@gG
Z 0=
hXBDRuaDVamtPvaj.drv
WggkxslFfAYWIniC.drv
NHxUZJMPviGFYjjtmoZFzABGAt.dll
qSveHTAJBXdGvReSTOt
hZ 3BA
RpZQuEgjqkkFKPCChEh.drv
EWETJWKByPyttxuTYFAlxnCcXz
x&Z
YYujdiLRWsDGyQrMdTdIvEbwhb.drv
PDDLbqoujauBQCsuxoqXIMW.dll
FwhhZxNdRxWpQZnW.dll
Ra82
Z uz Sa+
B` aZ
WpPEeIyOaOMtJjBIyJGSGAyCvHi.dll
> Z I"
F/O8
K=I8
fGFRZxnARwkudYfrKSOKaVTTMu.drv
ToBoolean
XjNNnVoFoiJMqQmd
xOcnKGfqxSnIPjiDjyyQpXuFLD.dll
YPcXDTqcWJAjkyz
NEINMjGhlgaAWDmUzwHHEZCDYA
OliWGtPKdUqeGsjMil
I'a8>
TCQIVTqNlmdLJSeTheN.dll
ABhdywHIVfHVbSwTHLu.drv
MwzcQZyUCwvgiWO
Sleep
Z oa
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-09 16:43:24 2018-05-09 16:46:18 174

4 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-09 16:43:24 2018-05-09 16:46:18 174

9 Summary items with data

Files

C:\Windows\sysnative\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework64\*
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\Protected.exe.config
C:\Users\Seven01\AppData\Local\Temp\Protected.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\Protected.exe.Local\
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework64\v4.0.30319
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_64\index148.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\Protected.config
C:\Users\Seven01\AppData\Local\Temp\Protected.INI
C:\Windows\sysnative\l_intl.nls
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\684eae3bcd28cb6d1e6997e6497056e2\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\5910828a337dbe848dc90c7ae0a7dee2\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\6c352ff9e3603b0e69d969ff7e7632f5\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Users\Seven01\AppData\Roaming\\xe2\x81\xad\xe2\x80\x8b\xe2\x80\xad\xe2\x80\xae\xe2\x80\x8b\xe2\x80\xab\xe2\x80\xac\xe2\x81\xae\xe2\x80\x8b\xe2\x81\xae\xe2\x80\x8e\xe2\x80\xac\xe2\x80\x8d\xe2\x80\xaa\xe2\x80\xab\xe2\x80\xad\xe2\x81\xad\xe2\x80\xac\xe2\x80\x8c\xe2\x80\xab\xe2\x80\x8f\xe2\x80\x8c\xe2\x81\xac\xe2\x80\xae\xe2\x80\xad\Protected.exe_Url_udafug5wcadsenooqwrfqrh1srrimngr\1.0.0.0\user.config
C:\Users\Seven01\AppData\Local\\xe2\x81\xad\xe2\x80\x8b\xe2\x80\xad\xe2\x80\xae\xe2\x80\x8b\xe2\x80\xab\xe2\x80\xac\xe2\x81\xae\xe2\x80\x8b\xe2\x81\xae\xe2\x80\x8e\xe2\x80\xac\xe2\x80\x8d\xe2\x80\xaa\xe2\x80\xab\xe2\x80\xad\xe2\x81\xad\xe2\x80\xac\xe2\x80\x8c\xe2\x80\xab\xe2\x80\x8f\xe2\x80\x8c\xe2\x81\xac\xe2\x80\xae\xe2\x80\xad\Protected.exe_Url_udafug5wcadsenooqwrfqrh1srrimngr\1.0.0.0\user.config
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\sysnative\tzres.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\security.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\crypt32.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CRYPT32.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
C:\Windows\sysnative\p2pcollab.dll
C:\Windows\sysnative\QAGENTRT.DLL
C:\Windows\sysnative\dnsapi.dll
C:\Windows\sysnative\fveui.dll
C:\Users\Seven01\AppData\LocalLow
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab25C.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar26D.tmp
C:\Users\Seven01\AppData\Local\Temp\
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_64\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources\System.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources\System.resources.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Windows\assembly\GAC_64\System.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.INI
C:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_64\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe
C:\Windows\assembly\GAC_64\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.INI
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2580.27662250
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2580.27662250
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2580.27662296

Read Files

C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\Protected.exe.config
C:\Users\Seven01\AppData\Local\Temp\Protected.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808\msvcr80.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_64\index148.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\sysnative\l_intl.nls
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\684eae3bcd28cb6d1e6997e6497056e2\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\5910828a337dbe848dc90c7ae0a7dee2\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\6c352ff9e3603b0e69d969ff7e7632f5\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66\System.Configuration.ni.dll
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e\System.Xml.ni.dll
C:\Windows\sysnative\tzres.dll
C:\Windows\sysnative\QAGENTRT.DLL
C:\Windows\sysnative\fveui.dll
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab25C.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar26D.tmp
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll

Write Files

C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab25C.tmp

Delete Files

C:\Users\Seven01\AppData\Local\Temp\Cab25C.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar26D.tmp
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2580.27662250
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2580.27662250
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2580.27662296

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Protected.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\4bb42886\38d59045
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CseOn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TailCallOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeInline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeCalliOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NewGCCalc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableHotCold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\internal\jit\Perf
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Protected_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\Protected.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\152412B4
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Keys
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CTLs
HKEY_CURRENT_USER\
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\7F06864B
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\qagentrt.dll,-10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\System32\fveui.dll,-843
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\System32\fveui.dll,-844
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllConvertPublicKeyInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllConvertPublicKeyInfo
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Escalation
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\433351e7\2db83a0b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Protected.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Protected.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Protected.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\433351e7\26b4a30
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it-IT_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6d5fb745\1c4dd593
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6d5fb745\4deb99ab
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CseOn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TailCallOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeInline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeCalliOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NewGCCalc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableHotCold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\1c22df2f\4f99a7c9\35\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\f6e8397\46ad0879\77\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\24bf93f6\3d7304a5\76\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\4f99a7c9\53bea2b0\35\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\152412B4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\qagentrt.dll,-10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\System32\fveui.dll,-843
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\System32\fveui.dll,-844
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Protected_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Protected_RASAPI32\FileDirectory
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\qagentrt.dll,-10
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\System32\fveui.dll,-843
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\System32\fveui.dll,-844

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
Global\.net clr networking

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlVirtualUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.GlobalMemoryStatusEx
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetEnvironmentVariableW
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
kernel32.dll.lstrcpy
kernel32.dll.lstrcpyW
version.dll.VerLanguageNameW
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
shfolder.dll.SHGetFolderPathW
ole32.dll.CoCreateGuid
kernel32.dll.GetCurrentProcess
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
ntdll.dll.NtQuerySystemInformation
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.CreateEventW
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.LocalFree
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.OpenProcess
kernel32.dll.GetProcessTimes
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.SetEvent
kernel32.dll.ResetEvent
ole32.dll.CoWaitForMultipleHandles
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
kernel32.dll.LocalAlloc
ws2_32.dll.inet_addr
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.WSAConnect
security.dll.EnumerateSecurityPackagesW
security.dll.FreeContextBuffer
cryptsp.dll.SystemFunction035
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
mscoree.dll.ND_RI8
mscoreei.dll.ND_RI8
kernel32.dll.RtlMoveMemory
security.dll.FreeCredentialsHandle
security.dll.AcquireCredentialsHandleW
schannel.dll.SpUserModeInitialize
advapi32.dll.RegCreateKeyExW
security.dll.DeleteSecurityContext
security.dll.InitializeSecurityContextW
ws2_32.dll.send
ws2_32.dll.recv
secur32.dll.FreeContextBuffer
ncrypt.dll.SslOpenProvider
ncrypt.dll.GetSChannelInterface
bcryptprimitives.dll.GetHashInterface
ncrypt.dll.SslIncrementProviderReferenceCount
ncrypt.dll.SslImportKey
bcryptprimitives.dll.GetCipherInterface
security.dll.QueryContextAttributesW
ncrypt.dll.SslLookupCipherSuiteInfo
crypt32.dll.CertFreeCertificateContext
crypt32.dll.CertDuplicateCertificateContext
crypt32.dll.CertGetCertificateContextProperty
crypt32.dll.CertCloseStore
crypt32.dll.CertDuplicateStore
crypt32.dll.CertEnumCertificatesInStore
crypt32.dll.CertFreeCertificateChain
crypt32.dll.CertOpenStore
crypt32.dll.CertAddCertificateLinkToStore
crypt32.dll.CertGetCertificateChain
userenv.dll.GetUserProfileDirectoryW
sechost.dll.ConvertSidToStringSidW
sechost.dll.ConvertStringSidToSidW
userenv.dll.RegisterGPNotification
gpapi.dll.RegisterGPNotificationInternal
sechost.dll.QueryServiceConfigW
user32.dll.LoadStringW
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptVerifySignatureA
cryptsp.dll.CryptDestroyKey
cryptnet.dll.CryptRetrieveObjectByUrlW
cryptnet.dll.I_CryptNetGetConnectivity
sensapi.dll.IsNetworkAlive
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.NdrClientCall3
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpSetTimeouts
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpCrackUrl
shlwapi.dll.StrCmpNW
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpSendRequest
ws2_32.dll.GetAddrInfoW
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpQueryDataAvailable
ws2_32.dll.#22
winhttp.dll.WinHttpReadData
ws2_32.dll.#3
winhttp.dll.WinHttpCloseHandle
rpcrt4.dll.RpcBindingFree
cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo
setupapi.dll.SetupIterateCabinetW
cabinet.dll.#20
cabinet.dll.#22
cabinet.dll.#23
sechost.dll.QueryServiceConfigA
rpcrt4.dll.RpcStringBindingComposeA
rpcrt4.dll.RpcBindingFromStringBindingA
rpcrt4.dll.RpcEpResolveBinding
rpcrt4.dll.RpcStringFreeA
ncrypt.dll.BCryptOpenAlgorithmProvider
ncrypt.dll.BCryptGetProperty
ncrypt.dll.BCryptCreateHash
ncrypt.dll.BCryptHashData
crypt32.dll.CertDuplicateCertificateChain
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
kernel32.dll.GetUserDefaultLCID
crypt32.dll.CertVerifyCertificateChainPolicy
kernel32.dll.SetLastError
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
ncrypt.dll.SslDecrementProviderReferenceCount
ncrypt.dll.SslFreeObject
ws2_32.dll.shutdown
cryptsp.dll.CryptReleaseContext
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW
advapi32.dll.EventUnregister

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-09 16:43:24 2018-05-09 16:46:18 174

1 HTTP Request(s) detected

http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • Hostname: www.download.windowsupdate.com
  • IP Address: 95.101.34.89
  • Port: 80
  • Count: 1

GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 86401
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com

#infosec #automation

TheSystem Itself @ 2018-05-09 16:45:07

Detected family: #Razy

TheSystem Itself @ 2018-05-09 16:56:02