MalScore
100/100

Cv26Cpy

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 38/67 Related 2258
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 235.00 KB (240640 bytes)
Compile time: 2018-04-23 04:11:45
MD5: 5be5a1f0dfc4ae6dab6dcd1a50cd2f2f
SHA1: 00b92f9fe3aa0c584850aa78d883d7caf88cdec8
SHA256: 11a31de8f16d95b08b2e0ffe23f9f86a732fbc92579eb16d4697e246878af9e0
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-04-25 12:27:02
Last submission: 2018-04-25 12:27:02
Filename detected: - Cv26Cpy (1)
URL file hosting
hXXp://uploadtops.is/1//f/Cv26CpyVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-04-23 15:44:14 [38/67] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x36b74 224256 6334cd74a6a9f4b16fa1626410b4c83e 522d12405f05a3b56b6c5a3066efbd5ea785ff72
.rsrc 0x3a000 0x3c00 15360 543e1802e4e302fc7e46f759c2b716be 2d4685411ae71eefe3c6af2fc21e64d977deb6a2
.reloc 0x3e000 0xc 512 f6c8787084bcc361d3bfc34c54806b95 1246a0d449516ee0f720594c81df1497b6ad5329
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x3c86c 1128 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x3ccd4 104 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x3cd3c 604 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x3cf98 3163 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2011
Assembly Version: 1.0.0.0
InternalName: 03852.exe
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: 03852.exe
ProductVersion: 1.0.0.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
XaCxRNjvGscubjVcCzuntllimW.dll
TfZmaVffLzcAEAX.dll
YulrzyKqFtVgzOlJVx.dll
PoyHlujATIRXfIjFFsCd.dll
hdZASvwduiXvgsmwk.dll
KzBITBRzvdBNjqlPkl.dll
rhGoWebKspgReWrRyLCycEazdC.dll
owlSlSqSsczNUofgkLYRXXFlAV.dll
vhfCbnlyoRPhMAJUfaMzQdnpGc.dll
nYxTfZmaVffLzcAEAX.dll
GLZyunaCnffAFVBAMB.dll
LKVEeVHDkiTndBl.dll
XEgYkqsZJnXTyFcgh.dll
XCkDEBwwHjxmWie.dll
hjvLkhKOFCbMThuPZfmT.dll
movCZMbllQKPYHrAFEOW.dll
HOcQxcKbhlyNvwSjif.dll
JqXgRxtKrfHlSMQ.dll
QIgTltxltzyoPmixK.dll
BsUDePCDvDTeBDKsCs.dll
OFWXLEHyIKDRfeQKOAgmic.dll
ldaXvQItzqOyDPO.dll
SMpSbpoiOeHTykNEK.dll
oPMlzIWdgXyPWvP.dll
tHsJZHqovtlZKVE.dll
hCHeHQpRUMGFzUkVElDi.dll
ydDQpLYKbyMoZuLKaLzo.dll
mUgpgljsnnUGoRQTvKYjwxGgGl.dll
ZUojMrCrMoQiajZtd.dll
GPLrPykSLJDoTVJEo.dll
dUsMoBqglceMpiDJKKAVPVrbMs.dll
TdjCzmFEvPhFiUo.dll
IVMoKyevoiPldJikPt.dll
kDUPGWEcfhhqyhcnNS.dll
yGwXHFcDKYidMRHmXRILDA.dll
rYAwRkRIpwQbPRyTkTRu.dll
wXpEpDcwgiuGaqUcwe.dll
WFQVgvRQawWAsyGIanxotjIDmb.dll
rwiZaDxwdaaaVewzAiropz.dll
lwhdMOflqtgtOBigbN.dll
kfptlqQjjbOlXZRRWbmy.dll
iMVRsXfRIgVCHQGJeP.dll
jfeLMlvAdadBILuko.dll
BZizGJdIHXzuSCSFyd.dll
DDCqqjFfDvmGvis.dll
POGWuXyaBiEkpnucxv.dll
kMMgVkMXOkHJDeInhjJfLAPNZN.dll
joaHFzZLnGpzDHXgkD.dll
YGWcIqHhSqtYtlfFDZMWgOPUfp.dll
YaXdAWMccVBGSpI.dll
YFzttkGGoBjvuWe.dll
GvisJqXgRxtKrfHlSM.dll
eyjMlAUDFyFLEnhTH.dll
kBNiJpfHDxyhPZGKa.dll
qmqXzefWiUGnGcIDJbCH.dll
tRFZGNwhCAGcAWFLtMEd.dll
nzItVydOgsBorJdIdGHbUSmYrd.dll
CDswINwDBpAbnUxHtExt.dll
SrHEaNlYUiVXQQsEy.dll
uKeCohDjKHEvEQGeZ.dll
MFQtlyDPTOhXxdqnTaMeXA.dll
uVxSpcUISykCkNC.dll
YWzJCNnPvfJgtRNmKc.dll
FRZxnARwkudYfrKSO.dll
GuQfcJiSJRPNDUZcC.dll
pOoCbLljvHiHgOQdXUnBACakXK.dll
HfHOavOiOjXViLIywfAm.dll
kwobBLTzMqTNlNjPXgTXJTnixA.dll
WegDPvwdahUoyXleFuGMIH.dll
wQfmTkeHUdjTBNGzZAMPflQIvg.dll
YoEncEbcvUKwmENQUINCaXsWbN.dll
NMfGuBAejKmqEHypiVjUpmQffl.dll
zNAYFLLiDWlWdNdhBH.dll
CwJSoczEFFIiMvekdSzcglXrBf.dll
YPtYGnIXgobTnBVxP.dll
BHRUxJhRXbjQUgOolwlFkJTxeJ.dll
LvwsgIYDgarbKxryMxqEos.dll
zFClGHhilWxXYPejjuTEFe.dll
uezZhxZjxAfjTORlcVjktASPaD.dll
DYAyxlTsIWBueMJIDc.dll
pkEwDQiYZHpGFIHGGVLGBBArvL.dll
wIyBQDuYsSeCpiRxrk.dll
LEJggucoTVwJpqFQpe.dll
BhCqjYNUiuQBiiqomq.dll
voNrajxDOMqXbncFZz.dll
zqOQsMPVtOZOjiUdWhMm.dll
eoLdDtriJZzyRyoGKvkmwUQzWv.dll
HNUWtrMSIdSxhkuFEXDqZGIAZl.dll
WDPJumpiKtMvXdd.dll
KnPFLwKJVhVKMfpubIZYDV.dll
jmvcYnxLCaAsBuogGZtFxXyRZK.dll
FuqjsvhJiLppQNeiQ.dll
PjsueXAAFyPCybKyMjJbxBlqCV.dll
LLiDWlWdNdhBHHO.dll
sExTiVznRZdVTgfCoDCgxDMJcm.dll
BhfFlAzhONmgUaiBRYlU.dll
YJtzBxLLkpbwFNbSQ.dll
nuGiTlDQmIBtHlTvWlSngx.dll
ozKgxCsbnKSMadwtpN.dll
flSFmJpYFhVAwVKFdP.dll
WLLHwmdZqnDCuzEznaGnebtAZW.dll
sxqFTcOpMAYfLFOewALk.dll
SMHJFGgdoAfSUlNhExgGFK.dll
IGBnQyTeaRJnhBTtenOO.dll
wgkfWlEtrGdAsAQnG.dll
EqXkJyxoptnhzRAQmk.dll
jOcwhXaObFMEYzxxtHKqEOVJID.dll
xNkrmWGKPZiyIExtjSumCOYXnD.dll
YFzttkGGoBjvuWeIry.dll
MUHSwjRmQEAAhTw.dll
ygMDWyFQCweAXbs.dll
SuzeYzjAOBLuAdRIib.dll
ZkPxrqdupWrbCWoDC.dll
mscoree.dll
WDEPJzyVJvsCbfkxUtOjSwhlYF.dll
RnzGcQzPTygngGbePiBQLfxgDO.dll
TuXjfPKUDxUXcWRDT.dll
dLtAGNrkOIkglTgoYTWccIoHra.dll
KpdVbImmgcRnPlDxy.dll
FBZiZlXcXhiYquDSfSGzvD.dll
hPbGYVknOOhGywVqmXmqbf.dll
PNGJDxLUTjenycz.dll
QVxOdHqxEFTzWve.dll
EOFyQwnEnlgbgFtjiIjHLxUwcX.dll
dKuwWRSypjjJjiZNFQijEvdFOW.dll
sIuYOrzUQKZoWxBQQtvU.dll
oNkdlrYkUqxiRSD.dll
OrEfppWFunhLdrgzjTjPoqksJe.dll
KaVTTMuKjtTXlWYKc.dll
nSYArAnhRIMGvbtBYTEp.dll
qRtIQtxDdfuBeKBonkLF.dll
rfqaolBMfzFgOHawbneVFjTOrd.dll
pychzWoRwNLZXDHPuxyeoG.dll
QfkQxXOHRKNEvBG.dll
BsbZTbMSDVIhtwIUdTnDtZGCuv.dll
qdjmKGqusBdAktP.dll
ZIpzwjXoKUkWmRdNoH.dll
RCazMnyNTjHngUNwjh.dll
AsFDYVpKUVMlXJYlLpbuEK.dll
undUfAztpwFSYZOYuQrqzE.dll
OGYVuiyHoOvLxmKgHNDTbY.dll
svBVkrpKOewqaUvsGM.dll
XRsRFCxAYqnYcWGTVnxmJg.dll
ULVvvDVCTHVcUvYsZN.dll
tRCviOSxessusUMjR.dll
cQxcKbhlyNvwSji.dll
MhQFNffWaUwwAAuOdvhCNJ.dll
zQSpSpjnXngzuFxkxQpwIm.dll
ymYFGZdCtALIvBWpUKOCsGPjxA.dll
NbSQSKDFeZghsHbKuRkXrK.dll
CbucovaMNZWIfNwAjGHdBlXXjf.dll
ptzwggvtEFWkzrnlGvsPEPigtt.dll
hAoyXXOQusfLosIrtR.dll
oUhJNpyFWfIwuHGnPwqN.dll
ASGIKDhnYBYFkCfnMjsyxD.dll
GigzLpfEqHWRsUTfXeIY.dll
xGAGQJGSkCWNFxLLrV.dll
XOqwUrFeMmUIEvmAFqIXsslwWP.dll
ZBCSoVmTqGGjPtdxJ.dll
IDSMwasmIeiuotQsKCWS.dll
wDXkPwvoJvwQERWFF.dll
SSwIDokxbLAoGHyUdATJFHYogZ.dll
LeNpKMrNWArNZgVnuTqffFGlhS.dll
rYNfXZqpeWwXXnQaKR.dll
wBcICjEspdCEVxs.dll
zNGyoCjLpSkERvbbzpOGMESujN.dll
dwOgiwAoyzHlirKwGhBwNPDTMV.dll
AkPCKJczNKMYZrPmIcxmIxvEPq.dll
ImmgcRnPlDxyQOJRii.dll
DYBfbDzfVDkvXFvLTo.dll
gBaKrAwXuGDBYWT.dll
tvWQKeYsCkQjvUPjE.dll
rFyxtOjhkrdzzzIoAIJDjcAEwH.dll
uhLjSqJDDCqqjFfDvm.dll
qXCmLbLRvirXkal.dll
SKDFeZghsHbKuRkXr.dll
DOgXLlUHGayCKXjXfk.dll
yxGPxrNWGkZDpaxLYsOc.dll
RjZrLugEgDDLPzzgLaODJg.dll
xjPErgeLUipPUwHVVxEYLIyrCN.dll
SHlHSfZkHMVdZPSeiwepqMSwBx.dll
DoynyDJMXRpFCvwzbSVMrI.dll
qcxbwOGMawHnsZMKzjudIu.dll
hdDzySQyNHyrMrMSJstV.dll
UnfweBqYbvxRQjveLbYu.dll
bvXNsQcGQtaIzquyyXDnwSqJua.dll
ybZDitCtMZLxRJarpvpyEHqxjE.dll
JWZFSipeseyLuUjmMbBkuB.dll
HggEjNWWUlRLwsdBBsGJFCUuzs.dll
OCDONMNnSFkfwKdEbn.dll
EibDoexdNvKYLJmzeC.dll
ERgocncJVfuDBQrbrUYh.dll
ViSlMrnroGlrEKrCORie.dll
kbYBFmSJXAZtjAznfNshpwfQXU.dll
GZMijKFAUxkbuhmKigBHATbMop.dll
ZblXgERQtMkwcrR.dll
QaNCVWVrlYJtzBxLLkpbwF.dll
IP Found
No IP detected
URL(s)
http://schemas.microsoft.com/SMI/2005/WindowsSettings
https://u.lewd.se/lw1gL2_qPhsRWoG.jpg
1.0.0.0
InternalName
ClassLibrary2.CsAPI
36AA57DB12062EC1356BC37217FD8054522B3D40
SettingQ4
SettingQ2
SettingQ3
Application Title
Setting998
Form1
C:\Windows\Microsoft.NET\Framework\v2.0.50727\
Setting996
LegalCopyright
!&)
SettingR3
SettingR2
SettingR1
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
Setting4
Setting0000000
Setting1
VarFileInfo
Setting8
Setting9
Version
40530
!0>
-%1&
SplashScreen1
2F17
SettingU2
SettingU3
SettingU1
Copyright
debug
:Zone.Identifier
!,9
SettingAA1
SettingAA2
SettingAA3
Setting10
AcvFgev.Resources
Setting081
03852.exe
2011
.exe
COR
Copyright
Setting6
909510F8D
OriginalFilename
e,7
Y,7
!3p
VS_VERSION_INFO
DetailsLayoutPanel
Translation
Assembly Version
PODIZANJE
GetEnvironmentVariable
[^01]
Y%%
SettingG23
This application cannot start!
SettingQ1
injRun
Setting532
false
\picture.jpg
MainLayoutPanel
svchost
Y+1
MainLayoutPanel.BackgroundImage
SettingX1
SettingX2
Version {0}.{1:00}
Handle
LUMuFEGiIk
Setting234
StringFileInfo
!0E
DownloadData
FileVersion
https://u.lewd.se/lw1gL2_qPhsRWoG.jpg
171520
000004b0
ProductVersion
FileDescription
'&(&/.
Microsoft Sans Serif
"%1" %*
y,8
!1G
ApplicationTitle
_ENABLE_PROFILING
]/ ;-O
jGhlgaAWDmUzwHHEZC
c{D[
b*sL
.D}OU
DateTime
5a%
p9a%
G`,
Int32
.cTl
z!%@Jf
r^ y?
gPtx
|Za+
GetBytes
ConfusedByAttribute
7a8+
)V}
vOX/
kj|
GK$$c
XaCxRNjvGscubjVcCzuntllimW.dll
b{eZ
KUVZZcPQsSPXrAioPQjJUH
M ?
?_b`
gXlXZSpoNlEkMMcWCR
)Q`M
TRTK
(o%"Z "
%-a+
+?.[deY
UZ 9f
sSTFRMQjYhQXEYF.drv
HZ ^:Y
set_Capacity
`Z -_7
Substring
cZ =1
gs&Z
{Jy$
CapXeVQCVIUmZaUOd.drv
TfZmaVffLzcAEAX.dll
vuxKsAweRRBazWO
SettingU3
076.
get_Controls
YulrzyKqFtVgzOlJVx.dll
Z y
:O3 c
)9Z W
~G'b
zydQCfitcqnbzLiSVZhrSNKlRU
+B]o!
Z !H.Ma8^
Z
:;3H
oma+
DebuggerStepThroughAttribute
fapiIRQlfFKzJKETajKKgXXZIz.drv
A2N$
X J
PNG
vDTeBDKsCsFwzMMrG
z1|k
DebuggableAttribute
CTissQDHUcfLqlPNO.drv
z o
PoyHlujATIRXfIjFFsCd.dll
S9 ,Gt
hdZASvwduiXvgsmwk.dll
`g+
hta8o
q$A8$
;a8}
ICrsDiRGTROSYEXwtZnUnZ
AZ `
KzBITBRzvdBNjqlPkl.dll
;ca+
vUo
Z D
tGgDHePrVJlcPmNCQ.drv
yPlDFCXjAoOfWsgLw
$._ksw0}
m V(bel|h1S
XsGurTGhTUvTzmnHTDLcyqsOJC.drv
CompilerGeneratedAttribute
OU%+
>7rh
qbfPJwqIDYVbPrSxI
kBa+
FM>X#W?_(<D
%&8i
nb
rhGoWebKspgReWrRyLCycEazdC.dll
/T2
KFdPmVgxuJICPVLqj
|'_%+
w%&8i
A' r!
drk/
jZ ; ~
Hz
bSBqkiHVwzRAJDPRv
i#Z G
owlSlSqSsczNUofgkLYRXXFlAV.dll
WkeQwEyiptdPctiLsqEg.drv
P=1(Z )
vhfCbnlyoRPhMAJUfaMzQdnpGc.dll
JgvxZaCozBhBJsc
w!8sj?0M|dw<
eFR(
{hn Efs~
1)cK%&8
KiVNvILOegbkUWHRvAVGWsiPrt
za8Y
ryxAxFoDowkUSfSmugiu
nuZ
WTIC
Y 9
SDY"
_a
ktBhUlRXEWqtOaeKTndq
set_MinimizeBox
'%&8
AssemblyCompanyAttribute
9Q)T
=]1%\
(Z K
Z 1j
MoQwDUDvWjhdjNkHuR.drv
PGgXLnFattSGfzkORu
{LZ
Format
(Z x
rTGOMloZCRGnuGU
Z 1C
,`3
nYxTfZmaVffLzcAEAX.dll
OXphrdQTTwpzROUbbeJUQTCklv
T;%+
6Za8,
ExKwDWhehzdkMRazLxcVOIIWEE.drv
Vo%+
AppDomain
CompareString
GetMethod
GLZyunaCnffAFVBAMB.dll
get_CurrentDomain
pIdk
7QeJ
:'Ha+
w :8d
OTa+
?<0(
Z F>?$a8
|$[
:N!y*
LKVEeVHDkiTndBl.dll
)7HC
XEgYkqsZJnXTyFcgh.dll
@en
NrjacExHwpmopxEGifiJHLdimE.drv
AnchorStyles
jx'
XCkDEBwwHjxmWie.dll
GDYSWJbEhlhvEej.drv
hjvLkhKOFCbMThuPZfmT.dll
b(G"
wj(N
AssemblyTrademarkAttribute
ToByte
EnpV
Z 'o
tqZ
% %+
V:a%
LJMDQXxmJbXbunnpS
Path
set_Text
UXqGqVIccDGEjuH
wBQHzoxfECMuQOytBkYcLc
5dj&%
XR2
!}6C_g'
%&8W
#Blob
KCktZBerPimYxcrNuo
ufahEuYPWohybNKLCI
dVuHdQTniRwEJGtjMHgr
Ta8/
movCZMbllQKPYHrAFEOW.dll
HOcQxcKbhlyNvwSjif.dll
L0=R@
9a8
kqrsVYVyYYySSVZsluhoLTecRn
>J7byp
ka%
Z ~V
[.Q-
dZ
Y(n?iV
O/
wzcQZyUCwvgiWOevjI
Type
@2K
My.Settings
^E
4 tl
OsydZcWzbAdEAXZCVbxzXWPNer.drv
ps]*Qn
n] e4
HelpKeywordAttribute
JqXgRxtKrfHlSMQ.dll
w0Q"}u
#6'Z>WT
jk7Z
La8F

QIgTltxltzyoPmixK.dll
SettingAA1
SettingAA2
"U%+
pND] 7O
4w ?t
OqyenfPJuctlqaxUrJISHK
S^;
NeutralResourcesLanguageAttribute
_0pM
[\/4N*j
BsUDePCDvDTeBDKsCs.dll
CbxhVNUwRLluPYGECLVwes.drv
]Z
aLPnlDqTZxKLGIOVEa.drv
,`3%+
z^0
get_Name
LateGet
%&85
#jK>-
XrbuQwXaKkqnmxzSF.drv
Z71Za8L
<M9Y}M8
FmGQubSGFAAjGkBkDaMVVqLtxT
AEtA
+$((
nTWAAKaqMncGOLEYPcXDTqcW.drv
#>hB
0I:Q
Q4 {1*
JkMk
@yR %=
2'uZ
W&z C
WEcfhhqyhcnNSLZ
frjQqCTMhLHUdcN
StandardModuleAttribute
An9P
OFWXLEHyIKDRfeQKOAgmic.dll
r.a%
/U
'/lD\
Y%&<
System.IO
BG):
ldaXvQItzqOyDPO.dll
rHaNKaQSaPOegxQPzRDh
SMpSbpoiOeHTykNEK.dll
&~i/
GetEnvironmentVariable
!Z TM
L#doi
NM
ReferenceEquals
.text
List`1
Z -[A:a8
"^E"
jo [
#Ia8o
\vd
zXs!
f_Q,
w0'7T
GetObject
IOVEagwBsUoLnmufX
:3
M&_
GcttPUBcEOtDtSwzwZtmjB.drv
kwa8
Convert
oPMlzIWdgXyPWvP.dll
TxCNoXoDETivSCOlMRyfMPvwQi.drv
*#e6+
System.Configuration
W, rO
J)B
W@"Q
eDqsUpneEVTrczJtGfDU
ArkvPNxUOfsvrgVRlDLC
C= %&
fg.*
dBwZQJbQHBESMoilfsgrhibMQv.drv
Yy~\
4System.Web.Services.Protocols.SoapHttpClientProtocol
bSAtbGckTDgbPglgloxV.drv
gC@N
O |Z
ulcPcRJffDcYZVa.drv
Z @,
`g7o%&
%i
Monitor
C]
eMw3@
v #3(
}C0a%
RcJEOoEuezyZIgcQfwPC
BLQ0
ChrW
VhVKMfpubIZYDVWWj.drv
wY2
tHsJZHqovtlZKVE.dll
c}@_
aZ f
_pZ
F!a+
SettingQ2
SettingQ3
SettingQ1
. `l
DesignerGeneratedAttribute
rYa%
NL@
System.Net
Conversions
myKJPjuZxXfOhblPuQIlUpEMjy
BTimfOozQasOovjvpyIdxjbRKQ.drv
;iFCw,v
`.rsrc
8U(t
p-k%&
EcScEIAYakiTboB
$D20B3801-6A5C-494C-9D17-670C6F74804D
hCHeHQpRUMGFzUkVElDi.dll
Egk5\
Setting4
Z $
_@Z
get_Default
afd650
.i8?
c3~^
Setting8
x I{
@v:|j]m
5'a8u
6Z F
WrbCWoDCYKrqlcDXnv
pHYs
:wV1
RGnuGUMUHSwjRmQEAA.drv
KtFnAmsdRUziHfWLk
0s=H
SZa8W
&YZ
AXfyfevleqiHcBLSvYoyRqPleL
a%
.NET Framework 4 Client Profile
llZ
set_IsBackground
j f
H1'Z
ydDQpLYKbyMoZuLKaLzo.dll
mUgpgljsnnUGoRQTvKYjwxGgGl.dll
-z '
Y:p
V@Qm
ZUojMrCrMoQiajZtd.dll
NnD/
GPLrPykSLJDoTVJEo.dll
ip*_
QFvt.\iq
Regex
Z HbG a80
KxjWdRLWQMmWdgjTwp.drv
mI%+
dkk
wgoGSkgTHAfYAIkTxZtN
! O\&Vu
"lR;
dUsMoBqglceMpiDJKKAVPVrbMs.dll
Ihx:
MFIzVBHDIRUzuvesTBHeQccbrq
H4Q!-
WebRequest
o%&+
TdjCzmFEvPhFiUo.dll
" >%+
IVMoKyevoiPldJikPt.dll
TableLayoutColumnStyleCollection
gbNflSFmJpYFhVAwV
get_Transparent
nNbijOeVqmcVBkVdXSPWvSOOaj
kA%&
@| b
otoDoEPrCPHwmyxeFGwgpAbVZY
,BfJ
o@,1
kDUPGWEcfhhqyhcnNS.dll
je8F
/kSQ8^
TargetFrameworkAttribute
HXzuSCSFydkDUPG.drv
;bg3a%
cMrvUZkUhJUNFoueS
Process
SyZ
Ku8%
ReadAllBytes
Z m
JvwQERWFFZkPxrqdup.drv
X(a8
%&8l
%&8n
0.Z
8j:w
kernel32
MainLayoutPanel
nGJOFRsVyhHPdjWeO
[I#
Write
%&8|
G
STAThreadAttribute
Qd*VN
%&8v
K`;
yGwXHFcDKYidMRHmXRILDA.dll
%&8r
^G!
%&8H
get_Assembly
>5r5
%&8@
vNsUAilSaslQcDOgB
{jPNlR
rYAwRkRIpwQbPRyTkTRu.dll
%&8Z
a7a+
+-{ [d
gxeHDjNVYYUHijwOEU
z[ G
YlRmonohgJmlkQmeEbjTInbwNI
wXpEpDcwgiuGaqUcwe.dll
3.$
mgZ "tL
%&8=
%&8?
%&8>
z 4a
^NZ
Invoke
uw
5kSA5;7,,Ng
:
RowStyle
WrapNonExceptionThrows
get_Now
9Yg?
=\
E5{nB
Append
o/Wa8z
ApplicationTitle
System.Runtime.Versioning
j9V1
2[c6
&)Xa+
Gt!@
YRZ
Vo5
!J[y
EwrbxIsbzILeFAMUoJtv
,inW
Mf:B
4% |Z Gq
RuntimeFieldHandle
Z Y
}C@i
?pPGY
<9a+
yaLjvwgZFurXNtEmWzvO.drv
WZskuXwSTCevrgfwLpVcsNtriw
E$ _Z
"oP*
IHDR
WFQVgvRQawWAsyGIanxotjIDmb.dll
PWoYZTEQNHRgVwThBp
Bc
rwiZaDxwdaaaVewzAiropz.dll
lwhdMOflqtgtOBigbN.dll
System.Globalization
yPzouHsuKNCzqzdgFAVvlv
~qu\
XZWTieuzahGUVKc.drv
'_)h
&Kkj
SettingR3
SettingR2
N f%&
whuf%+
set_Size
s HV
V7ZTi
XN$
nqpPXgTagcmXFAabxLLwCqDCLt.drv
kfptlqQjjbOlXZRRWbmy.dll
Qu%&
4d%&8?
System
EventArgs
Application
01+vY
iMVRsXfRIgVCHQGJeP.dll
@FZ .u
TJWKByPyttxuTYFAlx
d+B(
xnCcXzmZEDIoyPK.drv
SettingR1
N:S'Db
jfeLMlvAdadBILuko.dll
-|C{0
CZa8
LvG.
D20da%
91*
KS.(
k-z3ld
BZizGJdIHXzuSCSFyd.dll
A<V<E
AA6,?
4:a8W
DDCqqjFfDvmGvis.dll
mARBArUiymFKoigJEqRhBx
}U%Z
MethodBase
#Strings
hTwWDPJumpiKtMvXdd
Kd~q
B%:cKn
Kx%&
Image
ojMrCrMoQiajZtdIoW.drv
OZa8
E=&
Z pda
NZ >5{
Enter
Environment
^Ma%
`'GNt
POGWuXyaBiEkpnucxv.dll
NtbnftXimoTBGxtaMNhgiAWWeG
.\Bl
DF['
U8Z $~
imOcjZwEUUqSuPEdjFIgqBrBqY
|Q%&
]{a+
fyVc
kMMgVkMXOkHJDeInhjJfLAPNZN.dll
!$Z
n!Es2
ON?W
GNIEPTDPbBISjBFhisaelRHLNg
}%/Y
$%&
System.Diagnostics
SHOsOXLOeSjdkVVtKtdv
GetType
N&rZ
LsJXDgjUoKJMLvmbPtJP
7:Jt
add_AssemblyResolve
VVfBXglwmPkpaVZNjzEzpqqZxj.drv
Z (P`Ga8
qazqtDNlbxrGszqwPMHi
MsgBox
`Za8G
joaHFzZLnGpzDHXgkD.dll
ThreadStaticAttribute
YGWcIqHhSqtYtlfFDZMWgOPUfp.dll
YaXdAWMccVBGSpI.dll
%1Z lN
XyoN!
FxSMDxAIjdfEbjBzbPhBkYvFKi.drv
Activator
E~R 4
+t~9
;Q;a8\
scKArraDjFddhaOrhWVowv
NeumIDhnsTeqFJRvCe
%sm^
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
E3$s
CwQBFbkllHcLJpyfgzAuGcAWzV
`K8_
Wa C
FrameworkDisplayName
s-*a8
!-"$
ANe73'(

set_Anchor
YFzttkGGoBjvuWe.dll
)^E9
nU6Qq
CiWBAxGrRPbkKLwIIrqEAkaWZM
P[Q|
EgTnMSRmHhzWzyvuTlYyGN.drv
UHieFtrQXldjCsvnPE
GvisJqXgRxtKrfHlSM.dll
!g):
QvqhTnHPGcRlJZqKEksfuvUqZo
Q4od
QAvyeDCgXlXZSpoNl.drv
ProjectData
oHnzLr
c`t%&8
set_Location
Color
Yu|
Attribute
? F
!@]D
set_BackColor
lmfKUNJRzFLLpbeRwtxmrR
jMlAUDFyFLEnhTHXEg
TableLayoutRowStyleCollection
woECFEgwkglUcaNjwWviwPiKNs.drv
get_UTF8
DefaultSettingValueAttribute
n*dh
n
eyjMlAUDFyFLEnhTH.dll
*a%
w
Z FY
8<
.^E.
XI'
XNPWxCJKsnEFGVwKmkIXLoxpzZ
Z Zm"ya8
vGvRPFRxcsXMppfOtbNuYjvPPx
mhhRhZhcPnIXYFPUNaTzKeXFUU
uuYnQghzbBQxnNeMMv
__a+
JSkNuAoRKcdZPzfry
kBNiJpfHDxyhPZGKa.dll
^[6=
wi'
ga8y
CM}#
Z P|
T^ET
qmqXzefWiUGnGcIDJbCH.dll
YWDt
Ev$^Y
t= nVs
nZb{
gWjehhGmNOcmACyCPATE
YU4C
ebSvrPBsSPdiOcAajeGwiIkLzT
daZ
J1?hFVe
([naB
u"vC$
Xi!`S
Form
gTvUTYgtqxKgAjpffhWV.drv
</P4+
-Za8"
(@=Q
FDa%
tRFZGNwhCAGcAWFLtMEd.dll
=!ba+
p^CP
5z;r_
{arZ
`n\a8
!5Y(
4?|x
Y$f@
A\(Z P=1
@yG
cu2|
RNChrSLiCYEAwKQ.drv
(]a8
_M4
[^$C
-f>#G
l*t3Z
B:;I
rd 1
NnmEeSNRyMmPoMKUZyss
/zc.U
SizeType
!@Z
_b
get_Capacity
Iofa8t
~CH|%&
pFVtlwWOUYEjhpoPMl
7{On
MsgBoxStyle
7h/G
]at$
vJN
nzItVydOgsBorJdIdGHbUSmYrd.dll
jZ (
BY5R2JFBoqo3eVtTA9Y4uYKm9LVHc7ya
7i4
BRPu
_Z Y
KCykvMlcECCkaJbRrkcY
Default
SpecialFolder
rh%!f
CDswINwDBpAbnUxHtExt.dll
7@l c
C!W{F
SrHEaNlYUiVXQQsEy.dll
j euX*
\Z 5P9 a+
\vd I
.Q Q
zShSYUrlHndqnRt
ResumeLayout
v%w Z Z
Copyright
)4M|
7@!2
fzZ
s!1+
Z cW
ValueType
+\
{v
rOc_]
System.CodeDom.Compiler
)#>I
GuidAttribute
lAlpgTHHJmKgAlWkzELCGWTxjE
\9'a8
uKeCohDjKHEvEQGeZ.dll
TableLayoutPanel
Cl/V3Y
y-mw
System.Runtime.CompilerServices
C^P-
get_Count
MFQtlyDPTOhXxdqnTaMeXA.dll
aIEAbzJVZJOWHnmrHgInXexilX
g-v
ATjnAAGDklFJBqsVg.drv
fdW%+
IsLogging
RV#d
EkMMcWCRkxFJDxvba
<?xml version="1.0" encoding="utf-8"?> <assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <!-- UAC Manifest Options If you want to change the Windows User Account Control level replace the requestedExecutionLevel node with one of the following. <requestedExecutionLevel level="asInvoker" uiAccess="false" /> <requestedExecutionLevel level="requireAdministrator" uiAccess="false" /> <requestedExecutionLevel level="highestAvailable" uiAccess="false" /> Specifying requestedExecutionLevel element will disable file and registry virtualization. Remove this element if your application requires this virtualization for backwards compatibility. --> <requestedExecutionLevel level="asInvoker" uiAccess="false" /> </requestedPrivileges> </security> </trustInfo> <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"> <application> <!-- A list of the Windows versions that this application has been tested on and is is designed to work with. Uncomment the appropriate elements and Windows will automatically selected the most compatible environment. --> <!-- Windows Vista --> <!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />--> <!-- Windows 7 --> <!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />--> <!-- Windows 8 --> <!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />--> <!-- Windows 8.1 --> <!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />--> <!-- Windows 10 --> <!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />--> </application> </compatibility> <!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. --> <!-- <application xmlns="urn:schemas-microsoft-com:asm.v3"> <windowsSettings> <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware> </windowsSettings> </application> --> <!-- Enable themes for Windows common controls and dialogs (Windows XP and later) --> <!-- <dependency> <dependentAssembly> <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /> </dependentAssembly> </dependency> --> </assembly>
cUTcDvdvMFenXCHxKKTX
'GKn
>
~4D/3
jYxsbeaFSDIpLLGhrmyEhUFdgl.drv
Z ,=6Ha8{
R2R|
alYeKcYZmmuuYnQ
uVxSpcUISykCkNC.dll
FormBorderStyle
wvgiWOevjIzNAYF
w0a%
# q8
UInt32
#:7Ev
'>Ob}
mVERplTakQCIrTJ
YWzJCNnPvfJgtRNmKc.dll
MsgBoxResult
Z P
"6I8{
Z ^
get_Version
KM%+
set_Dock
eKk _
vDyZ ;,w
ToString
G a+
XLHLfScbSzXblRRcZlqe
K8 K
tHqPZtubJeiCcgFSdiWBQo.drv
X7uZ
6'Xd
Y\p}
s(__^
4B>GqEa~
zYulcPcRJffDcYZVaj
r~a8)
(OBI
MzbMfvyTdyIbRJnsgNaaucFZcC
2l'
m:H
.0a+
E A8
0IhoH M
FRZxnARwkudYfrKSO.dll
&F1I
qZ k@
y];^
!s '
GuQfcJiSJRPNDUZcC.dll
i%I(
o~%&+
|)}d
set_BackgroundImageLayout
`
Z 5Q
.|UK

Iqh7
3Z [
rN#6
StringBuilder
THCn
r~iK
1Z }"
jcGx
n1WN
%"Z
pwAClOGyFzSvfOZzIADFMEMfSX
10.0.0.0
Setting10
diRAiaIeUWrRxZC
xi1;
+Za8L
\&R;
dVTZ
add_Load
u4$6O
Create__Instance__
~%}Hy
$h7p
4%&+
&@+f-
Start
=#v
EFcghXPytbVmmCAQc
Z ;M
pOoCbLljvHiHgOQdXUnBACakXK.dll
4o@eku3
7#O:
HfHOavOiOjXViLIywfAm.dll
sJoFxiUJkqdtfcUXwD
'iW3
CaHk
RegistryKey
hOL;
GetFolderPath
r1yi
R%&8d
0Pr@
l@{
kua+
kwobBLTzMqTNlNjPXgTXJTnixA.dll
Q9k
oyRpPompErwcXcSAtmZQRKOtFh.drv
WegDPvwdahUoyXleFuGMIH.dll
5J_
+>~}
.ctor
>*Fhi
3 h*
Z h
wQfmTkeHUdjTBNGzZAMPflQIvg.dll
+*~;
Container
|NRw@
8GL
Ua8z
ImageLayout
1Sgj
7lm.=
+BT
"<;~
-k! N
dJ%+
X
P d
zPeENPurXigeKCSCd
xotWlGJNpYmlbYxmBROIFDwKGH.drv
jGXfsjDhJwZgbCU.drv
da
mr
}G^n
Wa8X
v4.0.30319
kuYNysuaTMlUAlOQoCFZ
.T7a8
EZ i
g{?\a%
YoEncEbcvUKwmENQUINCaXsWbN.dll
S5u5$}
5T
NMfGuBAejKmqEHypiVjUpmQffl.dll
Z DK
"e @
{ Z
gvIh
"XZ t
-* B
zNAYFLLiDWlWdNdhBH.dll
Array
]Z
^0gr
wVNbphelMvtPtTEaKrNXbZycdx
MShj H
@.reloc
:6,8
JAjkyzNMWZrwnYx
@RpL
CwJSoczEFFIiMvekdSzcglXrBf.dll
}g4i
DayqoMBCYTdlHXlindlqaf
f\FPp
YPtYGnIXgobTnBVxP.dll
.(Sw
\ >ce
JQmbaSAaMfMMkgIcp.drv
Papbv
WriteAllText
]Bc
Byte
get_Chars
yjybOJZCmQybGkTZBm
pbvgMyRScnfvmrEsefpxwKqxyj
FmUqXBaJoSudNnuSJwmcrslfZy
iNcjHNNfqQQUmJAhNUpdlUSndi
"E/X
BHRUxJhRXbjQUgOolwlFkJTxeJ.dll
LvwsgIYDgarbKxryMxqEos.dll
Z
q7f^DV
Z `Z
1# 1
`l -
Ha%
LZ >
c]Z $
(J
zFClGHhilWxXYPejjuTEFe.dll
P$={
ZTSvsApBUMuefohIIiLpgCobGA.drv
ZMDeWYACPzvFTXIaZbeKQr.drv
_b` P
obOboJHPKLxAtYZVdzCXOCZnqG
set_StartPosition
uezZhxZjxAfjTORlcVjktASPaD.dll
DYAyxlTsIWBueMJIDc.dll
q_[o
@I&
;J}<
:ma8
Finalize
get_Location
pkEwDQiYZHpGFIHGGVLGBBArvL.dll
F@>2
d RV
/hZ
JpfHDxyhPZGKaKpdVb
RtJyjUtslSFfKIq
wIyBQDuYsSeCpiRxrk.dll
+* q_`
;}v+
set_TabIndex
Z VO
V0t%,
G!"]
pYyBWXXoCgSezCrOwe
UHijwOEUahMIKJd
Z3-g
get_FullName
ConsoleApplicationBase
9>7KO
bVi}6/
%oK%|tU_
get_Item
{XZ
Za8W
Za8V
K{szf
Za8T
RuntimeCompatibilityAttribute
Za8H
v2aa
olOgXZZWxFxljTucwQsjzSPUTd
Za8G
Z`Za+
`?2h
Font
Assembly
K|2N
k dd
Za8w
Za8v
b-3\
'>a+
n t]3qa%
WRDTEkVgyEiUUsqqcF.drv
jMhKqeJnWhYIOZoWRttj
Za8g
YK2pJS
ConfuserEx v1.0.0
LEJggucoTVwJpqFQpe.dll
LrWW<
_bY*
nSFkfwKdEbnRoIG
BhCqjYNUiuQBiiqomq.dll
o5 j
>0Z
8HZ
bGYVknOOhGywVqmXm
gyMHZ
-
CLRdVMVpcccZWrBPZqNItp
SuspendLayout
Round
Z|34
Za8>
Za8=
%:a8L
jZJBexcoWLRylLZktjNA
Za8.
Za8,
uZ 2
Size
KH^(
MultiplyObject
L!x(p
In*
B\=]i;
KIaTiOBziDUklhmXKX
voNrajxDOMqXbncFZz.dll
ptYwWTuKWLQGlsoWJLWqlt
RxnatsWpfsJqzdEDMKWbAeVVFO
uOLWYUrZsSqJUiKjnUYwjXTSeK.drv
vBGhjfvnSuZJaHAqQM.drv
YX `]
PllcThvLGzNfhHJdrIolDoRYKU.drv
Zx_J
zqOQsMPVtOZOjiUdWhMm.dll
BK* \a
Resize
(\DZ
IContainer
VA/:
nTWAAKaqMncGOLEYPc.drv
b9/@
AppWinStyle
ParameterizedThreadStart
QgZ
My.WebServices
Dispose__Instance__
lxCA
Y N
eoLdDtriJZzyRyoGKvkmwUQzWv.dll
lYmjLmIqzrgbOtkQAsfB
vhLpMQaalksrxDLVonlj.drv
XDTqcWJAjkyzNMWZrw
l^Yk
gw(`
+) =
]|*w
Mi2'
4>
HNUWtrMSIdSxhkuFEXDqZGIAZl.dll
;]au5
l 5P0Vs
WDPJumpiKtMvXdd.dll
#a%+
elKIhMmMaVinTqgzoVlaMo.drv
CreateSubKey
5Z
X a
)DQ\
@kl:
Nu.vj
8U7ll
X X
AssemblyDescriptionAttribute
UZ bs>
ni0
YKu%
e?-l
Control
V&dn$
AssemblyTitleAttribute
eLMlvAdadBILukoSMpSbpo.drv
TableLayoutControlCollection
KnPFLwKJVhVKMfpubIZYDV.dll
J,a%
.;vx
set_MaximizeBox
sHWjLxtebdSPIlHCkitV.drv
PbZ
jmvcYnxLCaAsBuogGZtFxXyRZK.dll
TMpI
ResourceManager
GetExecutingAssembly
^X;Xx
GetResponse
chgZP
wpF+y
FuqjsvhJiLppQNeiQ.dll
M TTY
g{
"^Z
ContainerControl
T\Z
o_Sq
XgkDfueHXURYwEF
XYYujdiLRWsDGyQrMdTdIv
MyGroupCollectionAttribute
*QF
SZ sQL
ReadByte
~p
!NUa8
Qr
PjsueXAAFyPCybKyMjJbxBlqCV.dll
CreateProjectError
Interaction
GjNkeTRlvOLyfDryBAmIigCDFI
1kK9%
Z D< ^a8
AssemblyProductAttribute
d{H5
LLiDWlWdNdhBHHO.dll
Opr
&Sa8.
@c^H
sExTiVznRZdVTgfCoDCgxDMJcm.dll
]Yh0
iUcHOvcPIXFhsXDLmrvzET
wRlhrFteQxTTtLZceN
RemoveRange
3bKS
CPyyuDapNznGMpH.drv
yKUj]ZQ
3^E3
gwBsUoLnmufXKiKxuQ
KJgONQITxkTWHyAVMD
NPa8
S Ia+
Mj,E
mmCAQcJSkNuAoRKcdZPzfr
BhfFlAzhONmgUaiBRYlU.dll
*nYL A
YJtzBxLLkpbwFNbSQ.dll
Thread
ColumnStyle
SHyYHoRtGEcxBiOkKAqvTeReZV
ctkzPRRDOckMeNbVzdurwn.drv
"K0`
1;^
nuGiTlDQmIBtHlTvWlSngx.dll
Version
}*#_
iSiCrKVHptdxqXCmLb
get_ColumnStyles
vb-
12.0.0.0
HFpXlXJnQwhWOpkvOFNCWZ
D 8
GraphicsUnit
fa%
fa%
Swu}
16xq>
gKn*s
*V3R
ozKgxCsbnKSMadwtpN.dll
Setting532
Jp8R
(a%
flSFmJpYFhVAwVKFdP.dll
SettingX1
SettingX2
Ca%
wd\a+
AweRRBazWOfaRrqPMT
WLLHwmdZqnDCuzEznaGnebtAZW.dll
{JZ
Read
ii4-
2011
Delete
`z9
t 7O
9fuMw
#ul)
Fe,8
*~an?WqF
v)ju
{w|%u
sxqFTcOpMAYfLFOewALk.dll
!E0Pe
Z Kc
fb.{
SMHJFGgdoAfSUlNhExgGFK.dll
n &eX
WebResponse
lZEaMKTyzflLdqXJLl
IGBnQyTeaRJnhBTtenOO.dll
rzq)q9T
EOoeAzvLZMMBWZqIV
R?n
lZKVEzqxniuXMldJfl.drv
>.\
AutoScaleMode
1.U-
@y*AS
It [
qZ l
xZ ;
xZ 8
|.M)
.cctor
<Zq]
NtRMBdrArGpHqDqbx
set_FormBorderStyle
mscorlib
c;v6
_bj2
<r (
M<w:*
ReadToEnd
ADBDxWnyVVZsxMKGjR.drv
EPL6
FontStyle
*7Pn
|~Na8
GetObjectValue
7H+ r$
bbsFjiyDgwDVCwnMbgySYGtjAV
Ef-Y
unwl%+
xZ B
w>J3
ControlCollection
XlkBjhaaGIxhPLxzDYxbddRXRS
/fWZ
y<%&8
t:9%&+
*e7b@
wgkfWlEtrGdAsAQnG.dll
rnXEQEISmivzjyghFbnZ
bPBV_
'Z F?
EqXkJyxoptnhzRAQmk.dll
OxbF
BPauxKipqOKAcFvwbIyiIi
44yNa%
Eba9
<%qs
mqIrkcxPegdHRLiFgjxIGWdaoY
jQuz
>a8d
~Gu"
d/1KjsK
>a8[
System.Reflection
(QKz
jOcwhXaObFMEYzxxtHKqEOVJID.dll
K#Z
*j4-
RuntimeTypeHandle
F4w1
KruqVFGEeayswIqyeVEoeV.drv
(+lx
VxSpcUISykCkNCygMD
Z f
%:a8T
OVV?
hjROerRIpOxQlWpGwNSN
H(/k
@*8E
j8Q[
Z |n;&a8h
HZa+
set_ControlBox
Y_Y
zUt8A
~4
%V a%
.
uidZsQOXENEINMj
<a8Q
Q!Id%+
set_ShowInTaskbar
xNkrmWGKPZiyIExtjSumCOYXnD.dll
op_Equality
Sa29
YFzttkGGoBjvuWeIry.dll
\/a+
MUHSwjRmQEAAhTw.dll
Vf|Z
}a8u
ygMDWyFQCweAXbs.dll
GhlgaAWDmUzwHHE
Z ZF
9] O
V~xzuKm
WCQ8
<a8m
StreamReader
SuzeYzjAOBLuAdRIib.dll
olMPNIzCEUCIxGVGVZBc
.Z =`
QUQQQCCBkGUojaAbyqBI
) 0s
+:(A
/o?w
q<#
p~Z !
YEa+
k&u r
(;=
ZkPxrqdupWrbCWoDC.dll
&7a+
iTNjEeqCbezicqhFjRXDPlYsJd
SettingG23
hPEMOXqaHgrOwexJQnKYxF
YespWmdMajbZlBdoxktEklogEl
set_AutoScaleMode
1na8
gSGcqWHFpXlXJnQwhWOpkvOFNC.drv
46J
U$1b
qtBf
*\
get_ExecutablePath
RtQzkFztgrfoSKOPuUATRhzTrM
Mc"_
:,1t
21 '
11rG~r
ba8]
m@:Z
eutNnHCMWioEbeeaupcoUFdPjN
FvwLGYnvNsGktHMsNOAE
pXsbPFAeGPQJXBRwJojrzrHUHV
XZ ,?
&?UK)
Z 2o,
gOdpIcvFRfoXqNBhVUcUqa.drv
get_AssemblyName
V^Z
jZ p
8{Z :E
)aS1
c,a+
mscoree.dll
!This program cannot be run in DOS mode. $
Z mP8%a8
File
y[>9
Rb|<
W-D"~
Dd=q
mJugKBIweYXjSdQJyz.drv
z .Q0
WDEPJzyVJvsCbfkxUtOjSwhlYF.dll
YZzVpccznVAyhREdymxYAYxGRDZc
0LPD
set_TextAlign
GetHashCode
Ia%
qDW.
w {'
] vn? '
GetCurrentProcess
:Z T
*B Z 9
jf89
RnzGcQzPTygngGbePiBQLfxgDO.dll
bFlmGxEemgogWpEexDsHEp
Z ,C
~{Z s'
eGCnBLhWXxsfZji
. NY
Z ,K
itZ
@>Z
n dT1
*>k-
uOPdRtjxeFeVgHpRQnFFMAKQVH.drv
lmBzbFgGDIaLvfMCap
TuXjfPKUDxUXcWRDT.dll
set_ClientSize
5W a8Q
zyy{g
PZkoTGHCskqmwbaNvc
%|cl
dLtAGNrkOIkglTgoYTWccIoHra.dll
).NETFramework,Version=v4.0,Profile=Client
d. }
Random
lJfIDLwdMkgxsqlxCSqdlA.drv
KpdVbImmgcRnPlDxy.dll
Microsoft.Win32
|N a+
Z TeD
!a8}
da%
FVjfFAJquaGsNpIUxtRVYOcCVS.drv
!a8s
AoyXXOQusfLosIr
SetProjectError
FBZiZlXcXhiYquDSfSGzvD.dll
k)A`x
My.User
1rmZ
ZI%"
ContentAlignment
obTnBVxPBDLmjSGQaStjub
@(5\
hPbGYVknOOhGywVqmXmqbf.dll
=*{ _
Dja8
SettingAA3
Aa%
]<&
Z qf
HQl6
Strings
\dQ
8rAk2F
IntPtr
)\0m
K*y$
xsomblJrwqSbARWvMfUtjLDDTZ
5
Z $Cq
]3{i
PNGJDxLUTjenycz.dll
cQ= h
7A0e
| @Z
QVxOdHqxEFTzWve.dll
EOFyQwnEnlgbgFtjiIjHLxUwcX.dll
]ZyP
ia%
J"%&
>,(c%&+
FDwa+
+B 6%
System.ComponentModel.Design
Y wK
pUnSRnEESgsIwDEgiAHEpW
rVPiufilWSLuaSAGBKvsEaEQxH.drv
0,}C<
zSiETnHYpxixMjqfRfvJiBZsYy
&a1Z +
q_`
dKuwWRSypjjJjiZNFQijEvdFOW.dll
#':|
sIuYOrzUQKZoWxBQQtvU.dll
tRbpNAGSalYeKcYZmm
GetProcesses
0,1tM
EditorBrowsableState
Z ge
bb l
nhzRAQmkOCDONMN.drv
!@ R
0bIh
Y@Z E
ConditionalCompareObjectNotEqual
+Z ,F
d(\t
BlockCopy
m?<C:
jpFVtlwWOUYEjhp
gvPZ {
K:Z
_cX*
DockStyle
\\ioEZM{O\,FLaxi\\@)g {y\[Kx!.resources
aHOa+
IULVvvDVCTHVcUv
SizeOf
ToInt32
]r m
DQXxmJbXbunnpSkBNi.drv
D>
tSUVOZpIwhLPzvtJmTqwtzufvA
}Za8
gLwZBCSoVmTqGGjPtd.drv
smwkQIgTltxltzyoPm
get_Second
oNkdlrYkUqxiRSD.dll
-fF'
vJ=^
DWFPIVshyVLhnwvfkuxHHpfRTq
Y. M
$Z G
2]~
FWWyLRoVeDypINCvvB
XeVQCVIUmZaUOdATko
OrEfppWFunhLdrgzjTjPoqksJe.dll
yZ /
cb(l
`YfU
\>[) 9
AssemblyInfo
MBDzm(
KaVTTMuKjtTXlWYKc.dll
XZWTieuzahGUVKcGdB
NXZnybcsjXEOEyXMkFaRATjXBS
nSYArAnhRIMGvbtBYTEp.dll
a83
iEc%H
(L
EnvironmentVariableTarget
dFryvJSzrwszRahes
KOVaiYVvoMndJkwmAJup
NHRgVwThBpPjlWrtE.drv
+9(R
WNavdfCgaTlUNeu
MethodInfo
XtcmfCKbomCldwDdmfNVmpfGGb
?b(@B
qRtIQtxDdfuBeKBonkLF.dll
#=9
CompilationRelaxationsAttribute
MMLGWdpoRbZOKFUWkNCroqEoMd
wz]Za8l
z Y
WeakReference
-/
)u\a8k
rfqaolBMfzFgOHawbneVFjTOrd.dll
nHGCnwcQcIpqMvJ
Z IH
pychzWoRwNLZXDHPuxyeoG.dll
7mN5*
T<8
#ya8
Setting998
ResolveEventArgs
HttpWebRequest
xRjZxCkDdBjYPxfsQmJa
QfkQxXOHRKNEvBG.dll
& Z {
Setting996
= :})
BmSwKJPhtbERPspDWbeoUBrGvB
M%C$D!
IcpnGJOFRsVyhHPdjW
BHGoR
BsbZTbMSDVIhtwIUdTnDtZGCuv.dll
|cZ I
IDATx
ApplicationSettingsBase
+m~i
qdjmKGqusBdAktP.dll
Create
/Z WoA,a+
fmuaqzcjImjOfackNl
<!`=
E\[0t{i)
HideModuleNameAttribute
67^[C
ZIpzwjXoKUkWmRdNoH.dll
b@p1
mlEKnHsOTdrJtsBSiBDgNV
"CZ
IEND
$Uv
Z ~
Z v0
[rN0
xhIDDozTuGQPLPrsmFZrhs
Microsoft.VisualBasic
^E
F42N
sXfRIgVCHQGJePrYN
R,r?
ATkoJLnEFjmyGLMfG
ResolveEventHandler
RCazMnyNTjHngUNwjh.dll
BXmZ
WriteAllBytes
EnterDebugMode
xY'0
fZ
jGY})
set_ColumnCount
Zp
6qNX
E2a8
1Z 4
AsFDYVpKUVMlXJYlLpbuEK.dll
BEyPNWlNLHtSRFCZyqHF.drv
8MZ )
e]`l*
undUfAztpwFSYZOYuQrqzE.dll
Z d!b5a8
v_bO
CIsHqgxLewcxFnWQLj.drv
pcbBajIKTiwpyQfdihoxuz
Concat
FtdiEGONgsyamELsWriJyhHpTG
:*gG
1Z p
+3~5
ua\8
@[#
DetailsLayoutPanel
bGkTZBmDYBfbDzfVD
+?~V
--a8
Stream
get_Copyright
HTa%
xCaZ
X`a8
OGYVuiyHoOvLxmKgHNDTbY.dll
/00(Z
ytMbr
?Oa+
\ioEZM{O,FLaxi\@)g {y[Kx!
XhvWJjQCrEVqVsnwPu.drv
<j?]w3
Setting081
'j4?W
y#z=
svBVkrpKOewqaUvsGM.dll
!ua+
_ xw
tmjBsIFadVnAlWIQmIEMbx
Copy
XRsRFCxAYqnYcWGTVnxmJg.dll
AssemblyFileVersionAttribute
GetTempPath
System.Text
r$+x
GefILVeGVitLnjfwQ.drv
w 9
pE32
5U)2
,7 RC
QRX(
System.Resources
GetResponseStream
ZZ
bjGREccyGBFrWWFnY
MhLHUdcNZblXgERQtM.drv
?nm7ph#q
B4D4v
+)~.
+)~,
+)~-
ULVvvDVCTHVcUvYsZN.dll
tRCviOSxessusUMjR.dll
SN V
cQxcKbhlyNvwSji.dll
lFxRidXJVpTtIIGUCOCMqgvJAB
Ma80
VcF
1~/"F
Bb%TJh
ULVPlI
KK
N\ma88
MhQFNffWaUwwAAuOdvhCNJ.dll
sIypi
6J8+
get_Info
euuj#
rTejaLPnlDqTZxKLG
Dispose
#cX *
#Hh)ZH
J`6R
, Z
YKERUmbkQCgHKDGpHo
]a%
zQSpSpjnXngzuFxkxQpwIm.dll
'Z id
RCko
1p]#
ymYFGZdCtALIvBWpUKOCsGPjxA.dll
ConditionalCompareObjectEqual
-W@N
a8z
String
lA:Z
_CorExeMain
DebuggerNonUserCodeAttribute
'`?aZ d
get_Title
N9,d$
ApplicationBase
Z$t-
NbSQSKDFeZghsHbKuRkXrK.dll
WebClient
gjTwplZEaMKTyzf.drv
}?=
QPEYSZIKBePWOMqscM.drv
CbucovaMNZWIfNwAjGHdBlXXjf.dll
FzDb
Command
xkX"f~J
DebuggingModes
get_Text
jD`)KX
InitializeArray
9gZ
#sd 0

wwHjxmWiechxFWzNQT
Il+vrR
nrbALNKmcvofzvpwjGoqsa
V$pk
VxayXcOeoyrciRP
v${d6
Microsoft.VisualBasic.CompilerServices
@I$_wS9x
OrObject
CreateInstance
_^km-k
ae2Z
EditorBrowsableAttribute
ptzwggvtEFWkzrnlGvsPEPigtt.dll
JDxLUTjenyczXCkDEB
:U%+
` XF
&mCa+
:2\=
MDtnkQMwQNheexw
Vza8F
&a8+
Rb$b
z (7
User
yItguWCbCnHnnqeThsEVVAUGwY
& q
`$d|
PBRCQIKqbsKTnGxqIsUUuoTKBy
kwcrRldaXvQItzqOyD

hAoyXXOQusfLosIrtR.dll
$a%
&a8W
sa8!
|-Z
_ `~
Z wm
Load
oUhJNpyFWfIwuHGnPwqN.dll
E.g"'
@Z}4
EEkaRmXWiyNFQyystxzDLKkiuT
*MZ
System.Drawing
spa8
9^08/
}jE
xtFwshnMmIBkIVMoK
@[ VT/
3#&[q*
ODZ
RgYuWmfkpKHeRVdGgh
set_Name
c/Yk
GetFileNameWithoutExtension
d'8'W
ASGIKDhnYBYFkCfnMjsyxD.dll
PpNKYCmKpgBgvzBPsRqm
Mi B
0GX:
lQnzzshHWhTTNsmMQvrzId
GigzLpfEqHWRsUTfXeIY.dll
; o
xJuKeCohDjKHEvEQGe
-a8h
Boolean
kZ !
iOeHTykNEKwqMfJjWXpnrG
(Ia85
kdSeOFrrDvMIEkEGobhT
}a
QwDUDvWjhdjNkHu
1 ~;
xGAGQJGSkCWNFxLLrV.dll
INMdWSLHYhlnpRZ
(!a+
|pe/*
RuntimeHelpers
Z Rw
Iix f4
+:-(
rWWFnYxtFwshnMmIBk
~jt7ct
!dv|
^E
t:l
|7a%
c`]G:%'
xbzETMdnmxJKNQI
JlS
SubtractObject
XOqwUrFeMmUIEvmAFqIXsslwWP.dll
Object
GdBiSiCrKVHptdx
*<IG
MZxljYGcPtxiDTr
dvIkSXyDwVyZiKPWmxqUzyHVCr
Registry
ja8S
CeWzAsfNVTzlDibqwpjuVenMAw
ComVisibleAttribute
=Z ^=6
WZ }|(ea+
get_Length
3System.Resources.Tools.StronglyTypedResourceBuilder
Z is|
c.Fq`c
uRXw
rzDWiMeIfGAtyBoqdGzP.drv
QEBKwIxPiEFOWsSCPy
Ugaa+
ZBCSoVmTqGGjPtdxJ.dll
tH(*
get_IsAlive
9QZ
AcvFgev.Resources.resources
.B
X4!5X
U>>9(
^RwL2QO
s a8
- S5^Fa%
oLaeNZcADuFlInnGDkwtIlRiWc
-%;v AmN
/w?n
ba%
,~z%&8
CultureInfo
1.0.0.0
fyZ ,l
vgWbNrIYkNLnHMcptCmJAwCLkI
ZzZ"/
9<
=6H:*
'f_n
LsZ `;9
td) %
Oa8K
9Za8Q
]' .
dsfqdwlhZSQyBkJZdOiG
`Gu
eNa%
fsvBVkrpKOewqaUvs
dZ -
kvXFvLTowXpEpDcwg
IDSMwasmIeiuotQsKCWS.dll
rwnxhIDDozTuGQPLP.drv
is*k
s+Jj
wDXkPwvoJvwQERWFF.dll
>^os
BR,5
SSwIDokxbLAoGHyUdATJFHYogZ.dll
"eZjt
ecPWv
Exit
LeNpKMrNWArNZgVnuTqffFGlhS.dll
yia+
mm6fd
#^Z 8W
@HAs3
NJE20
ZmsHSybKNIBpMwcWG
rYNfXZqpeWwXXnQaKR.dll
System.Text.RegularExpressions
i`Z
wwwwwwwwwwwwww
u dD
qa8x
NTNjxsZIzJVzGjLpoQnuyQYpli
|QZ
set_BackgroundImage
NavAwBttmZtxDIioKOTq
aiDFUOweOXfhKuoMWUSX
WyFQCweAXbsvwjujSx
WQ#]
Tit"
, ,
2z%+
wBcICjEspdCEVxs.dll
#}EBk
/Z w
SettingQ4
xGZ 4
6DD7Y
get_IsAttached
zNGyoCjLpSkERvbbzpOGMESujN.dll
XZ hM
qFcNNiuzwkLSTQqpKkyuLpPXrF
#|-K
<f(dxZi
l%%+
FailFast
Z.I@
`
MrvUZkUhJUNFoueSey
i";B
mDRSEDGxaIRtfpcTb
z<+Y
d~ G^
pLZ
dwOgiwAoyzHlirKwGhBwNPDTMV.dll
faRrqPMTFMlwYCl
SetValue
PZa82
QtGJcTeGlVjbDwMBhwYnquMwyL
bxMFQtlyDPTOhXxdqnTaMeXAWe
MemoryStream
Z zw
mtW
qftvtXoRVeHtAXfkjPqmQzvjUc.drv
Z Y3L}a%
Z zf
tz56S[
&Z 8
AkPCKJczNKMYZrPmIcxmIxvEPq.dll
FormStartPosition
?t!
]>S
System.Threading
PIVtuidZsQOXENEINM.drv
`n
G@36i
h"
L6MZ
DZ I
@ b &
ImmgcRnPlDxyQOJRii.dll
fXZqpeWwXXnQaKRXo
AcvFgev.My
xvdhtLIMMZjxcdGvUpfe
Q ?Z T
utQ
JvCJulibjyAKyXjKJrfE.drv
C-Z
tREibDoexdNvKYL
f.Z
FYtV
sEiuOblwzFrnDOqqqgkzPX
1>w
ComponentResourceManager
Z ^c
a/Z"
DYBfbDzfVDkvXFvLTo.dll
Shell
02
lLdqXJLluhLjSqJ
plM
,4 `
@h-B
ijLjwWlPheKeemOFLdTzKG
gBaKrAwXuGDBYWT.dll
Ba%
k,~rN
,.Ar
cb;M
XDCzRpRvQuEfnJqVKxot.drv
aGXUOncowufFcHIBjMcIklayCi.drv
+ y[
SIuxSLBVkAFOJcnVidlKXFMvEz
Debugger
Microsoft.VisualBasic.ApplicationServices
$=[a8
Setting0000000
N|e
dj,y
&MV\ai
>, n(#2a%
Next
NwpQwZYPTkItkiO
%3jZ p
mDjtrEMtRbpNAGS
W#(:6
o:
wwwwww
4.0.0.0
be!<a
#v<j
HO`F
}9-Cu
k,]y
i_/
[%<^G
skuXwSTCevrgfwLpVcsNtr
SettingU2
RyZ
tvWQKeYsCkQjvUPjE.dll
SettingU1
Copyright
Sa8_
eQ?A|H
kQvY
get_Major
V 9+
VBNMKLZZZZZZZZZZZZ
AddObject
qpNOjLaWrKNgibBtuGYdfXKmHn
Point
My.Computer
Pl$8
<Z K
Marshal
S4%& e
AssemblyCopyrightAttribute
z<E!
Operators
kxFJDxvbaSrHEaNlYU
.,(
r!mT)
HttpWebResponse
rFyxtOjhkrdzzzIoAIJDjcAEwH.dll
$-p#%
uhLjSqJDDCqqjFfDvm.dll
set_Item
=BBda%
xCoQ
^E
qXCmLbLRvirXkal.dll
Setting1
p^[3
vRxfCVPNTdzvZzhFuV
A=w
rYpWLDnIbAxcaFeCLyYVoM
IDisposable
KZ F
hn|M
SFfKIqWNavdfCgaTlU
`>9S
Exception
Setting9
JYL[
RRS
Z !
qq^ Q! Ya%
Fra%
,1$x}
MPaxzQauQZgPYicbOsydZc
ot;\
VfUXOtKwvLtjnTVpWEidIT
KfqyhBJJnvCRbElyMbrf
?$X
GetTypeFromHandle
FileAttributes
ZFVHzBpxcjtxTaqIv
UgPVEyQiGeOiYZoVjTPfvTMjXj.drv
{a8V
JEH\Ii
hfrstVwfVqpURUOsEZUt
k/fT
,Q
RYKERUmbkQCgHKD
z]F8
l@a+
X!T"
&|f*]
*exH
vUo
GuQegtoHOXnmNezzxFZIeudBGT.drv
TUti
_7|)C
SKDFeZghsHbKuRkXr.dll
[Z P
DOgXLlUHGayCKXjXfk.dll
cwPGUxixAWbObXkcHrzo.drv
dFHRvtNFFvwXXdAau
Ceovp N15
# ^{>
GetProcessesByName
Va%
]Z Y
xa%
Paa%
ConcatenateObject
System.Runtime.InteropServices
e\&6k
XQMoviUzWSPDyZwtpy
Pa8=
Z iq
Math
t{%+
$V5I
_FP,
rVGDBRFEkigBkGVlrQEk.drv
_5<&
wmZUfmGyzJFStfNFdaRUWnsYDV
cDOgBhdZASvwduiXvg
^E
%:b`13
mlRhJSUTZxpeuDWcrSAlbV
_Hr/
M9a8
~@
@IR" S5^Fa%
CompareObjectGreaterEqual
>cZ
*?O8
5NYWD_
SuppressIldasmAttribute
Sa.
Pa8y
Z i
NewLateBinding
DeleteFile
tqs*I
X Q
bPji
get_RowStyles
yxGPxrNWGkZDpaxLYsOc.dll
VN{
xA79n
TxW*
({!?
i!it
HYfZuZSjYqaQgkkIydff
* &#
Y6R=N
:ACZ BJ
e<ux
1:40
&mZ z
RjZrLugEgDDLPzzgLaODJg.dll
(SYaZ
V.=F
xjPErgeLUipPUwHVVxEYLIyrCN.dll
"F07.m~
tPJC4?
bobgvWUWteAXSQSVf.drv
{e>I(
B,U%+
Z9
ss'K
, ;X
}d4l@o
hP:L
{ a%
iGjI
Z ~|xSa8
mDRSEDGxaIRtfpcTbf
Exists
9P0PT
BcddscYaCwRlhrFte
uMUBuVzItKFfJxfYuSyMXR
Buffer
L2S
!Sa+
^E
^ ]%&+
@^_YJK7
Label
)^ >o
My.Application
/-Go
SHlHSfZkHMVdZPSeiwepqMSwBx.dll
Setting6
N*PhgW*
>sZ
Ai2
Equals
? Ai
cPduZ
DoynyDJMXRpFCvwzbSVMrI.dll
uZ Ux
X
<Module>
~Kh
qhNx
mXHfMQqLZstAoExaLWRsIK
JBuuWoXyigVwJVGASMMrWenRHb
Z M@
hZ E
xWCIZYjThEXtWDIWN
qcxbwOGMawHnsZMKzjudIu.dll
zLsPkTRtuQVieppzpgLjxeLEfF
MsqwWebCqEZvgpMhvOjj
:u.%+
B4fEP
set_Font
hdDzySQyNHyrMrMSJstV.dll
:J/%
QJxOdgYNMZxljYGcPt
Z Me
t:9 oO2ua%
mZ E]
p!a+
@Z.X
0 a%
5;9V?
g`f
kvcHtwSqDHMzLDJwEqxyVDczEk
AscW
lxuMhIPfTqKcXeyIIlnrQf
=YA4
Z !P
l_;gZ G
_b`
N"M`
gtFSaHanRaWDmwlfmqNVojjGPG
AgIN
;c9D
N1A
KXs
Computer
#GUID
^7
+]0!!
8d:mi
>c?a8
mBejUWNsvhoMBOKEWE
wXwXFjrgGviZBAgCn
)!}~
6ls[
/tr
UnfweBqYbvxRQjveLbYu.dll
G$[C
Synchronized
MqjKyJSAGhHcXSoCshvsvIxtMY
DellKHcILVSNTPEhgo
. D20da%
bvXNsQcGQtaIzquyyXDnwSqJua.dll
YsZNGLZyunaCnff
OUXotJLTaIjaMHiUcJlh
;a%
`_Ea%
qBSJB
M9<J
Replace
zEpuZdURhpGIoqCXoHRu.drv
BE%&+
ToInteger
6_5<;
x'WgO
2XQ
WibCOSieJudBfWyPxaqEdp
gDPvwdahUoyXleFuGMIHTgrtvj
NXsv
\x?$T`
!3_!
ybZDitCtMZLxRJarpvpyEHqxjE.dll
X;I
rsmFZrhsQaNCVWVrl
EventHandler
W2PBqdV.y
JWZFSipeseyLuUjmMbBkuB.dll
9
Microsoft.VisualBasic.Devices
rUlAkvRoYqGBvgBMDhzztByhRQ
MyTemplate
iC6}:3
ZYxqJQmbaSAaMfMMkg
Oh Z
HggEjNWWUlRLwsdBBsGJFCUuzs.dll
i7K(
qZa8d
Encoding
myZ 8"JDa8
]* <P
get_CurrentThread
Du*{*9
Yiy
|)<x
SetAttributes
IX1-
aMkb
/{h\
vREOoeAzvLZMMBWZqI.drv
ntdll
Z {ev
Q{ 4w
OCDONMNnSFkfwKdEbn.dll
CurrentUser
EibDoexdNvKYLJmzeC.dll
c:a+
IGmAEPPAXWkSrukHLQpjZyrTut
Y)a+
t*lZ
6e9v
Z }$
CBX-Z
K(1u
52NM
UserScopedSettingAttribute
ERgocncJVfuDBQrbrUYh.dll
5a8d
ViSlMrnroGlrEKrCORie.dll
|%&8{
AccessedThroughPropertyAttribute
Z nG
System.ComponentModel
FMlwYClMkxGEpPZTXI
=4Ls
4^5f
,Fg'
Za8?
B%&+
oV%+
Za84
6a%
ToBoolean
,-2M
Y_7/{
n{/[]
kbYBFmSJXAZtjAznfNshpwfQXU.dll
{XKAZa8
geQx
ZPjt
C&Z
@88k2
c=a8
n%+
GZMijKFAUxkbuhmKigBHATbMop.dll
gwBp
C Qz
WOMqscMwzcQZyUC.drv
G)A$
HKB7
MFByyZsJLgTQbcusu
iX%&8m
`%&+
System.Collections.Generic
QGLoQZTJggQzhsfQMjtVGukZsJ
Z \\
get_Minor
MnlrXsAwluqTMWgXyRsuNvOUnY
ClearProjectError
J8%&
ZnnKfChpSRMJEXUvVHvwMd
7s-{
System.Windows.Forms
RYqkEGCIlNJbxEFZH.drv
6"9SW
[Fva
' M`
gy<1GE
Ra8y
icv#
e0~opB
oEl;
"!W
ADAmTOTbjGREccyGBF.drv
TeCo
Setting234
bX
GeneratedCodeAttribute
aHeW
SettingsBase
zeSSZ x
wYa+
%& Q
e6Z
PXOIngKpdVefvlJvR
}a8s
j07mL}S0[;
ZblXgERQtMkwcrR.dll
TDS
r.0<I
oh]p
KGZ Gf-Za8
VzeAFNSQxpMzHzfswbqUYv.drv
(
YsgALlWuHZtffdXZrDdKwmlIfR
uqas0rqJG8osx4dQRbPUj06BhOrfy9fq4W9
H80o^
Qz)b
DebuggerHiddenAttribute
QaNCVWVrlYJtzBxLLkpbwF.dll
Sleep
ze5
WoT%+
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-04-25 12:25:36 2018-04-25 12:28:31 175

4 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-04-25 12:25:36 2018-04-25 12:28:31 175

8 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\Cv26Cpy.exe.config
C:\Users\Seven01\AppData\Local\Temp\Cv26Cpy.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll
\Device\KsecDD
C:\Windows\assembly\NativeImages_v4.0.30319_32\uqas0rqJG8od95fc095#\*
C:\Users\Seven01\AppData\Local\Temp\Cv26Cpy.INI
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_64
C:\Windows\assembly\GAC_64\mscorlib.resources
C:\Windows\assembly\GAC_32
C:\Windows\assembly\GAC_32\mscorlib.resources
C:\Windows\assembly\GAC_MSIL
C:\Windows\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\*
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC
C:\Windows\assembly\GAC\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_64
C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_32
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\System32\tzres.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll
C:\Windows\System32\it-IT\tzres.dll.mui
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\secur32.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\crypt32.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CRYPT32.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
C:\Windows\System32\p2pcollab.dll
C:\Windows\System32\qagentrt.dll
C:\Windows\System32\dnsapi.dll
C:\Users\Seven01\AppData\LocalLow
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab4EC.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar4ED.tmp
C:\Users\Seven01\AppData\Local\Temp\
C:\Windows\assembly\GAC_64\System.resources
C:\Windows\assembly\GAC_32\System.resources
C:\Windows\assembly\GAC_MSIL\System.resources
C:\Windows\assembly\GAC_MSIL\System.resources\*
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\GAC\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_64\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_32\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.resources
C:\Windows\Microsoft.NET\Framework\v4.0.30319\VERSION.dll

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\Cv26Cpy.exe.config
C:\Users\Seven01\AppData\Local\Temp\Cv26Cpy.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\System32\tzres.dll
C:\Windows\System32\it-IT\tzres.dll.mui
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab4EC.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar4ED.tmp

Write Files

C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab4EC.tmp

Delete Files

C:\Users\Seven01\AppData\Local\Temp\Cab4EC.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar4ED.tmp

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cv26Cpy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Cv26Cpy_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\Cv26Cpy.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\28A51E51
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\HWRPortReuseOnSocketBind
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SchUseStrongCrypto
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Keys
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CTLs
HKEY_CURRENT_USER\
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\7F06864B
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Escalation
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\28A51E51
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\HWRPortReuseOnSocketBind
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SchUseStrongCrypto
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Cv26Cpy_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Cv26Cpy_RASAPI32\FileDirectory
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList

Delete Keys

Nothing to display

Mutexes

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
clr.dll.SetRuntimeInfo
clr.dll._CorExeMain
mscoree.dll.CreateConfigStream
mscoreei.dll.CreateConfigStream
kernel32.dll.GetNumaHighestNodeNumber
kernel32.dll.GetSystemWindowsDirectoryW
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddSIDToBoundaryDescriptor
kernel32.dll.CreateBoundaryDescriptorW
kernel32.dll.CreatePrivateNamespaceW
kernel32.dll.OpenPrivateNamespaceW
kernel32.dll.DeleteBoundaryDescriptor
kernel32.dll.WerRegisterRuntimeExceptionModule
kernel32.dll.RaiseException
mscoree.dll.#24
mscoreei.dll.#24
ntdll.dll.NtSetSystemInformation
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.GetNativeSystemInfo
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
ole32.dll.CoGetContextToken
clrjit.dll.sxsJitStartup
clrjit.dll.getJit
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetUserPreferredUILanguages
nlssorting.dll.SortGetHandle
nlssorting.dll.SortCloseHandle
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.CloseHandle
ntdll.dll.NtQuerySystemInformation
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptHashData
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptReleaseContext
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptExportKey
cryptsp.dll.CryptDestroyKey
kernel32.dll.CompareStringOrdinal
kernel32.dll.GetFullPathNameW
kernel32.dll.GetFileAttributesExW
kernel32.dll.SetThreadErrorMode
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.CreateEventW
kernel32.dll.QueryPerformanceFrequency
kernel32.dll.QueryPerformanceCounter
rasapi32.dll.RasEnumConnectionsW
ole32.dll.CoTaskMemAlloc
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ole32.dll.CoTaskMemFree
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpCloseHandle
winhttp.dll.WinHttpSetTimeouts
kernel32.dll.LocalFree
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
clr.dll.CreateAssemblyNameObject
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
clr.dll.CreateAssemblyEnum
kernel32.dll.ResolveLocaleName
kernel32.dll.SetEvent
kernel32.dll.ResetEvent
ole32.dll.CoWaitForMultipleHandles
kernel32.dll.GetTimeZoneInformation
kernel32.dll.GetDynamicTimeZoneInformation
shell32.dll.SHGetFolderPathW
kernel32.dll.GetFileMUIPath
kernel32.dll.LoadLibraryExW
kernel32.dll.FreeLibrary
user32.dll.LoadStringW
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
kernel32.dll.LocalAlloc
ws2_32.dll.GetAddrInfoW
ws2_32.dll.freeaddrinfo
ws2_32.dll.WSAConnect
secur32.dll.EnumerateSecurityPackagesW
secur32.dll.FreeContextBuffer
secur32.dll.FreeCredentialsHandle
secur32.dll.AcquireCredentialsHandleW
schannel.dll.SpUserModeInitialize
advapi32.dll.RegCreateKeyExW
secur32.dll.DeleteSecurityContext
secur32.dll.InitializeSecurityContextW
ws2_32.dll.send
ws2_32.dll.recv
ncrypt.dll.SslOpenProvider
ncrypt.dll.GetSChannelInterface
bcryptprimitives.dll.GetHashInterface
ncrypt.dll.SslIncrementProviderReferenceCount
ncrypt.dll.SslImportKey
bcryptprimitives.dll.GetCipherInterface
secur32.dll.QueryContextAttributesW
ncrypt.dll.SslLookupCipherSuiteInfo
crypt32.dll.CertFreeCertificateContext
crypt32.dll.CertDuplicateCertificateContext
crypt32.dll.CertGetCertificateContextProperty
crypt32.dll.CertCloseStore
crypt32.dll.CertDuplicateStore
crypt32.dll.CertEnumCertificatesInStore
crypt32.dll.CertFreeCertificateChain
crypt32.dll.CertOpenStore
crypt32.dll.CertAddCertificateLinkToStore
crypt32.dll.CertGetCertificateChain
userenv.dll.GetUserProfileDirectoryW
sechost.dll.ConvertSidToStringSidW
sechost.dll.ConvertStringSidToSidW
userenv.dll.RegisterGPNotification
gpapi.dll.RegisterGPNotificationInternal
sechost.dll.QueryServiceConfigW
cryptsp.dll.CryptVerifySignatureA
cryptnet.dll.CryptRetrieveObjectByUrlW
cryptnet.dll.I_CryptNetGetConnectivity
sensapi.dll.IsNetworkAlive
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.NdrClientCall2
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpCrackUrl
shlwapi.dll.StrCmpNW
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpSendRequest
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpQueryDataAvailable
ws2_32.dll.#22
winhttp.dll.WinHttpReadData
ws2_32.dll.#3
cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo
setupapi.dll.SetupIterateCabinetW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegCloseKey
cabinet.dll.#20
cabinet.dll.#22
cabinet.dll.#23
sechost.dll.QueryServiceConfigA
rpcrt4.dll.RpcStringBindingComposeA
rpcrt4.dll.RpcBindingFromStringBindingA
rpcrt4.dll.RpcEpResolveBinding
rpcrt4.dll.RpcStringFreeA
rpcrt4.dll.RpcBindingFree
ncrypt.dll.BCryptOpenAlgorithmProvider
ncrypt.dll.BCryptGetProperty
ncrypt.dll.BCryptCreateHash
ncrypt.dll.BCryptHashData
crypt32.dll.CertDuplicateCertificateChain
crypt32.dll.CertVerifyCertificateChainPolicy
kernel32.dll.SetLastError
ncrypt.dll.SslDecrementProviderReferenceCount
ncrypt.dll.SslFreeObject
ws2_32.dll.shutdown
advapi32.dll.EventUnregister
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-04-25 12:25:36 2018-04-25 12:28:31 175

1 HTTP Request(s) detected

http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • Hostname: www.download.windowsupdate.com
  • IP Address: 8.248.101.254
  • Port: 80
  • Count: 2

GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 86400
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com

#infosec #automation

TheSystem Itself @ 2018-04-25 12:27:19