MalScore
100/100
MalFamily
Msilperseus

f3.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 34/64 Related 2805
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 914.00 KB (935936 bytes)
Compile time: 2018-03-15 20:50:41
MD5: 7623ce0f094bbf3a85ee324a7b66edb9
SHA1: 05def919874ddb7ae72c58d7d91dbfa806c58253
SHA256: 9cab78c8e14a13b03de1a43b9129ce53189a6b55f9c593af4ec9d01640c3a98f
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-04-14 15:09:03
Last submission: 2018-04-14 15:09:03
Filename detected: - f3.exe (1)
URL file hosting
hXXp://ssrdevelopments.co.za/11/f3.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-03-17 08:15:26 [34/64] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xb95c4 759296 84443edefa5207cef87b37f7c42abc27 b352559b3e4e60dc852cff1989c6811c094f0ad2
.rsrc 0xbc000 0x2ac18 175616 ef3e0927f4c64df2fd2a386200660034 88678d97581c5e990300aff1bd733a6b8d20158d
.reloc 0xe8000 0xc 512 0b9a15d6953b4e1db6045dbdd955ea7d 4b1008d289e3f12364ae9ea1420478c58b04216e
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0xe2560 16936 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0xe6788 90 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0xe67e4 584 LANG_ENGLISH SUBLANG_ENGLISH_US
RT_MANIFEST 0xe6a2c 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright @ 2017
Assembly Version: 3.1.5.4
ProductVersion: 3.1.5.4
FileDescription: hNNPjunqqwpCjPLkafFv
Translation: 0x0000 0x04b0
ProductName: ifpAEsZc
FileVersion: 3.1.5.4
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
3.1.5.4
URL(s)
No URL found
39HoM6DtldSkEtD3rWikMuYbmVjCP
3ReAI7xi0eUUVJ9mVclNfccTr2jAf
12pJZcJEXUIX8QHiLWSYmpmOTlfrE
2uvPGjePRhATO1q0BmrRUBLpKebHc
ZkohMHyGPko73ExMD6feT6FyScpO4
VzBb1hM0W439vexVIpPYElflX5EpF
button2
IuDlYbFIsBJrGxPBhffFx5GA0QcAe
pXxI2UXuUdUajPDlpqyHQ8Jg3SoPE
mYH59SjCIjV4sRy2D6RUaAoFsBqB4
KO9XAS6X4JoH2GvExKJmoxvFQKFOX
7drw6fWJaRcVqD45G3MGPGga61hq8
lJfECNGbA13fUscTSy2tERlAh6J3o
SWsmbzSdWeyQx1UOH5lfqCeed1kNR
3.1.5.4
label1
Infiol
Form1
7cLAtSsmJISNq1IDj9oVetR6WqiEP
v4eeVvAuOIy8aj3AWj2HfDM0ZvAcD
8gx5s19Yo6zb232dXo64QZqZ30mMl
0E6pnuljczCRdykhmGGX1KrSKhvsZ
LegalCopyright
NIstUIFnUC7egMhycHWvktLpVgMRt
YUXoewjO77FFUIVcxWAGVXBtTkr7d
button1
KkLaapIiY4ahM4h7aeq2Gk8t9aDXB
KPlxpG8TVyg2KKd48wDzsLD9d47BV
DemasusLotasito
VarFileInfo
FVrqeMVstmoHfepYg6SbqUmvcwTGb
SE167DURZYXmbE8grdsTKZl1z0xUO
textBox1
YYGyqf7huAmYCpCISj8foiEw4Gzuq
qW9V9wOeeEGy9LOm48jVVrjBlx7a4
FileVersion
O1zR00Cp7rIDstEGu8LdbR5C45zI3
i8MO7XOQWtvl1dLY2fU9BgoS20lpO
7WdRm4Z8f4mD8EpOYntWgCzBvSqeO
checkBox1
checkBox2
4zpiLVnFBPTPrBvYYOwHIwMfeRTBW
CM2tAAFxJqFqK6HB2I9LdPYk0UgLx
hf8YtRFoVnHKnVYL0LAQpPCL1VlxX
ZFbPCDHtP3XBcVEXhTtw2XMQUaKLf
Slimit
000004b0
ProductName
BtKanNo0p9BEOpo5JLNoEHTk8RTlZ
ubrVuEaojMDXG3kpap3oY50XC7OEH
sfQ6HZotV8vEPoaATIQBlO3e62pRL
ProductVersion
C:\Folling\Folling.ini
FileDescription
I9OUfoyRTeH6gP6Y0vBFywyqxfJKA
8QUpzkIfrZZaQsMRlWiweiLsY8BYR
aK9qrEytBd4CcgnMdoU06C1vWxvdN
mHiL7Hcbl2TSerV7NnGoXdoy0UWJN
6BEW4mV5HP1TL7ci1nuhUFQMUNNpv
Z975lT3kj6oWbVqRXq4vt8UDlMRY7
hNNPjunqqwpCjPLkafFv
Configurations already exists.
4gKozdk79v8umk6rl2zeljeh9Hd0H
O7dZzq9rRnDE436lO0jKy2CGbwLqF
wzLA7GrxDLrGRiFEfQwKsHv4XQlHT
panel1
ifpAEsZc
VVVlVlV4VaVjV3V4VkVVVVaVjVjVhVjVdV
e2yv8LcfS5hSAIMemlhOnsQ45ZxMF
Gmb5g08NWaXMIukpMCFbkseOtLfe2
VS_VERSION_INFO
wUSXZl0UcHxoW6le3Lh6AAHcjTBVb
IplnPkHlGJsiESXdcUYm7ecj7wEs5
Translation
AHmqrFxuBl99eBAuy90oVllbTl0ii
Assembly Version
VlbfdH4QCfJ7r3CYkPvrecPLpp64Q
lJIq6nxPJzxFx66eDe1PGRXZ0elrr
u4zzHexszMDi8CcAU2HnBFLGBtQq3
rNg81fPooGWXVy5PTK8ki0cmsL34q
C0EmGEihcr8FnUnjVXMQvdt8l4Qji
5jFMsKkrLC6hizFspJ0ChYw75GlIR
Alg9LoR4yByer8nXtyRudQE0b8trP
KdtMGSCZxSWeS0bclbY3cOBBEXSR0
Gosti
EcrmxaABwtXNHbic9x9rh8SwDQq1i
pYuw5jNKi9thwrCHrxuDwhzpbvONB
ll4aj34kajjhjd
4JPfALnr8FLTVJwLXm0WBMBE8KSOo
7YVfJhXlRAwJzbSuWP0108j9A26u1
cdaCaHIgNEDbMx29vsUMpuNvmLzY6
StringFileInfo
rxQAVjuAJ0MejyZsbP0a0bv5KQTpr
Folling
C2NdXCN7QnCFrfL4RnoTr5Li1K7TE
u71uf8JSORkUf7SUMkihRHfShzYD5
gBL1p5uXJn39nrTpuklG2NBJZLyfJ
gadNHLV8nQaiKIzbtrG4tLpFxEfdv
gL6t08Z2AnIrXK1uZ5gApOhmycd78
z4Psx8qKUMjyXOtwtNtc9KH6bQ2Zv
Vlost
WdKvEExAMfylH4diDz2m7PP8YdK74
Denat
c0RoDUIar2keBeluPCy16YlfJkKf8
ofZLEok9maqnjPWet8A1VuV5oCFbU
PZaUUhbcmhuU8nudwE8AP6hkqzie0
05ViEVpoDDRutXGfUjnXAK6IIipeN
Copyright @ 2017
a2JcxH7iZ3pEYn6EAHQwlg613zXVQ
wxEBxQrYZG1s7BCwi1iFlV3lKGPIX
'3~@
%gXG
&4]m
3TEg
ZND1Up
0rY(
o,e@
(M 9
aY<oT
0ik
Uyfo}7
D(c,
PNG
`D"TS
DHXU
bTu]v
_<TK8
;mrr}
w0lO
3$tf `
*pJa0
Q@IL
%@64
( ?B
n(6q
dt3
gk8l
?oH
e&NprTe
AH G
AUY7l
Lmo&t
/ri21u
#v0wqF
j?~b
@%aB
J `=E`
UVx>
&EYE
^69ot
''xh
Vo$E?
}3B{
+4_F
*eLP
~K~G
#'OP
cf<=
u|[_
4zpiLVnFBPTPrBvYYOwHIwMfeRTBW
fZ #.Q0a8
1=9at
L>
j60c
0zx]I
bf4Z 8
u$)
)<F?K
g M@
@hfke
nT fv.
e@>$
5zs-
W >M@bL`
5`!D-V
RsGZ#d/
Nf?b
~jyS
ycRY_
{8__
~,I}
|O"d
EhL5
H#!i
$p:,
{ cA
~p]\
f.KbQ
Da2t
)I)H
QjsXBE
pm_
>$.vy
E% ySX
1L)N
w+8|Z
B7C|
2b9=}
`LMK
+mQ!
y1$!
*~#W^v
Qc*
>>H{jJ
_zMw:
O) ~JV
2jGvd
k)fp
PlJo
#<S5
Ye&6
H>s<
NC9>
)~AS
(l _
<<%L
5Y&'4
$3|Rv
dfw3
xl9U
NO>Rq
7\7K
7mKa
mXJf2
R&M,
-A.
WL;@
EnableVisualStyles
[{F0
aT^TD
lIgt
~OZ8
BL/i
E Dh{jY
j,gK
w| W
b1dc
>4)
z%F}
]e9Q
s=>a
P)Zc
iZcQ
By63
X$:
XjX;
!~x3^
( ,y
& .W
s> s0
0AH5$
Q9Tr7
e@vB
.']4S
K`[}'
x
e-E}&
[ y9
u!mB$S
"2.},
z3tg
+H#!
?Z@2(D
zX(&|
%{^6
~D|q|M|!
cP ?
FnPe
w{M;
`o$ea
[*C7\^
System.Security.Cryptography
OIA1C
~5P[
iyL4K
@r W
~t"O
`QN&
^xD/
?j7)
Z8H3
tl gk
)TG
~}<{
BN^K
PZa8
znk^q
aUokO
.,m*
;$N!
B}JB
uuix
set_Text
PLq 6
&}?1
`6A_q
&-,7]hnR
` JQ
/6;P
jjNn^
P}t3
v. Wk
+O]A
@!NS
=m#a
A-U=
7L{x
4HzpI
I! C
lO{^K_
[4>D
3E<@#Eed
jyIj
GF>,
J5 d
4# W
af<ILV]2D
hF+3:!
dL'm s
a- K
`2Jd
5b9x
Wfb2
\::
)9!*
1' 9
p>"u=
!&:
TgmT
H{F,
z\sOO
}JJ<,
W?YS
$iJ6j
-TB8&
oU+QV
DF+g
HU 7#
_0n9
e~{R
NNTz<
uvKD
Y;A&
!v?T/
KwJQz
(Tq1
g6l4
eG`-
jGJ1C?
S+=B
"?0Y
;rk
F2*j
w nN
Z6?cL
W:!M M]
yKQz!
cMiM
2K?;
x#v*2p
YU50
xUiP
HS 1!@
GKM5E
e+tMn
r):q
#5`:
Kj[I
0k:7
V{,
Mk z;
t/Su
nU _l
e}SF-r
6sjx
XHCu
E*.z
2Dnr
|0 S
Qvey
#CMY
|mGV
_??I
I/>?
FF],
get_Controls
)~dV
K,E,&*O
QN>
/&1
\XNa5%
97lG
_7hd
Gt>0
)N_=eFq
E`G vJ
IJU;2
ZcAs%y
EV 1
f% 0.
l5&i`?
BK_(
'E$N
lkwk
6"1_
j9x_A
@Q~s
k|Bvm
|D+6w7
.text
RK'1
HeG7
SxQ4
%fvKjKH
d- `
GetObject
{%,~\
ioe} 0y
je1{m
s~+%
*'y,
ORzS
)+Mp
<.|*[O
M )Uq6
p/gOA
St^:<
F]%r
Phc
D6sC
o8"a
?D[@
FI]8
#w<+
qeLl
"xfW
|JqM
gWyp
f[LF
i UoCUP
<RK*;
PerformLayout
DY\[
"Gs1~
ir H
92EP
h:eo
`E7
u _}
udV@V
.lHi
{9|g<
s)IU
!Q fO
r_M[
q1.C
h,$f.
kK=I
r9K7lh
=Zrr
).lzg
[ Fq
9
r=J-
zapiK
K=kR}
(^_u
j@<n
A wj
!JjK
^Pke
fch=~
u?m"
zN y
ql8
\?xc!%
l,=#M
#q"7
" !?#
XfEg
*An
{Dg3
zuQ#
$@?/t
9R/&
q <7
O1zR00Cp7rIDstEGu8LdbR5C45zI3
@6>b
~* U
?IvCX
C`@Y z
9u~h
m=eO$
[r0
b S$
6k[
F" h(an
do!l
54 r
4'k~MH
hdcDQ
~3 W
rilA5
F|FG
c5ro{
|T /
/9X8
96U.K
%tEXtdate:modify
2% vqFs
N}+
L[ `
p"lh
4GyP36F
cNoo
dAEek
X|`x
aWcN
`['
KhMH
vI=
OW :
Y+Nw
_Q+?
tA|3D
e9("
\?jB6d
\V e
6a5gP
~>^]
b&Z"
Lq/?2o
r#B}
bD;d
qu)nD
L@;@
: SY
-wz3
d~ >
[Ttx
[w6z)
lQ@j
(.ax
N Q A
,Y4y+
a H'
3)Dc
4x2z
JB8f
vd!u
:(B]
Q< %?v
v "z
<p[3k,
*>4 F
gLFK?/
}` e
{hzk
*%jK
P;^(:6
! 1c
e)b_
\$G,3
z$$$
GW+`
IYvF
L%;{
km Zg-*0t
_bR
@Z0UX
v(4ces
u%wY`m
[YBJ 1
AeGrv
&wAX
,,M]5xS
F[LnzO
DLFW
QtH"4E
&(i
*x9 Y
WVN+0A|1
x8Kx
]0P:
Ow~F
~/D#
9U [b
!Sm
\o` u
*vdl
ig( \i
zD%u
uHA)
[Udg{
Lf f
@jXQ
?Qsj|
.ZTM]L
*8E2
&c}g
rOLe
ydiingd!W
iEt,
3!_"
Fs~5;g
:ZXZ&
:ns>s
.&o&
ZKxy
TrO$
o35kI
.Un8
3Fk#
tTi{
>z&~
/I%
fe8A
.2rY
m L
UEwt
f[c
['('
-.X/
#8[
h6jA
8Rce
x.B6
H Y+
I3Ri
lOl9
2^&k
{2Z=^
-)hx
k) :
=W
C#`[j
21p;
E5qh
Zq?0
?4rmt
qVI
P /e
H,%r;k
%B0X2
mDd@
&N[S
<Qe(a
.{ F
aDs}lh
V=n-
IHDR
4f2^Rp
rE>
7cLAtSsmJISNq1IDj9oVetR6WqiEP
2Wkf
%l/+
cq7g
m:0q
{E2,
ZCY7
jOs
-_=@(
.s}~
u(_P
<J_,1
SrE
4V:I
g2)&
]"O|
nFK*9
fp -hxM
OVr)n
System
EventArgs
b9lvEi
.}/y o
eCPl
erj=
7It6s
q2K&
$*PJUN
mHiL7Hcbl2TSerV7NnGoXdoy0UWJN
&lklX
L,Ng
k%hN
8QmJ
w{]=
pZju
u3mP
h*.}
FGtQ
W2h=
b@UF
Vj1g
Rl(\cI
&@ `}
iYaj
~*I-h
%o(|
w/o\
P]sS
YDDr
ypf1
ye:%
SZJ~
ZFbPCDHtP3XBcVEXhTtw2XMQUaKLf
n$ZJ2
MethodBase
C/ -
[a.CIA
QRE,}
+#SJ^
.Q)
UB "
LJ ~]-
?<$Z
I ,#
#y'P
H?e
x1YD
\0:&|I
cYn~
?SNI
'1ky
._Cy
bqW-/ GY
qg Ob
zeJQ
#@cp7
^S;~rb
CU;T
E >
0M0Q
u91)
xvbXd
(s1u`b
$[EO
fO>(0
$I D
z S+
4{m<l
pTtZ
cwye[
S gSB
mD<d
d OE
$&ap!
#g r
Rpko~Yl
~iP^
%~O8
mdQj
J$e.
e4#PX
; .)o
:T_2n0
4Y/Y9
:O(B
G6>:
GCss
@Q4v
lBNbPy
GWIBOo
0{@LY
'~MA8
i%[j
Qa*!#
sUGP
_^;,
G<-9
A,65
\rI4
>ZRU
6W7pq
qt(_
}!l+
a-D^{]
C|Yzm
N/\$
zOsY\;M
)0Jd
S2B=jB
*I1\?i\_f
HL-X
df{.t
BTI*4
TAIb
D@\Q
Dt*<
Wi +
:?uQ
(P+q
92@ I
HL_
~qG7X
q _
rt*6
\>3{
wUp?
o l~T<
nn^w
*D,
~a:,
;_nQQ\
Gmr$
l(6"
:ae .4
%tdX*N
aq~*
S" 0?y $
c2 7V
%Xz"
Kg/N
set_BackColor
8f!&
60rN
}2$
ej({
Hm@m;
M 3q
T3 l
=]O('
khr
o*mr}
4~j/=
a4f6
3YLC
9;-_
S"m^
5"
gHk2{.
L{zF
db\)
y}t@Wo
k8:
suN%
^#Hj
U&jYa
-K|B
i`r=
PU;i
z0P9
Y0s
4]!/H
EFTp
3bXd
b'Qz[
~. r\
w$$0o
4O+
@{se
7%=2H>
J BC
uY-H
?.9v
5:po
$R)
M/27d
4.>}
h}[z
jHif
dB%
K H.
!f;3\~
Label
:+A8
bN&CG tp
54m#m
ctpp:
"mg2
\7}T
C.I{G
.J`U
c5nY
P1{Y
G|tP
M y'
%U T
v>pWw
G ml
td%*
i*XO
txIf
QG f
' 20
D "l
WZ<[5
Piz-`
aQ_
(\tm@
Y_y`
F_'*
R w4
&e+t
)y;lef
fo 0R(
8Vx|
>ij>
*F0H
~,zg!53
6_`I
2/t?h
43V<O
`6\N
\?nmr
GOh*
MB/[
J"( ;
uP{$
!U-
Mt3k0
^|tz
3$8sm
,4]
M!~u
e&FDJ
t_$ GC
iJJ
"$6
-Puh
Dq#
HMO5b+g?
IbJX
set_Name
J 9 <
Q V
i sr11
Default
yhNZ
"BnS
vbqM
d`liM
c|[Xn+g$
.w$"
}#t^u
:P i
3ReAI7xi0eUUVJ9mVclNfccTr2jAf
; !7,
LNE
ng EJ
675+
TV] _
&RP`
IAg
}W$q
$^~F
pbvX
1&/i
TfQg
}&C8
gnl2
2gJI
i"/j^
QM4n
/} _
W^.A
_Ddf
Wfs9A
en[!
9%>
E=J:
u.+B
!yMZ
1DsT
:},H
`O|
j=dx
#7hX
~$^Ts
l/<3
IL T
`nxw
,C!H:b6
qh}-
%c}v|
I^J[
2-ZC}c#
V0-!
v|{nt
|6NH,
I.-m(
l{c
OS{So
( gn
FqzW
\eg8X
g4 _s
B+a@$
!gSe
9V`u(
S{?P
mLvF
VWyl)Nj
Gxa$
p HY
8'<!
r'ne p
Jf?g
3h61
oe^(
^Zkb
W}~+
T"HC
8*9K
[F}_
d|NHg
KJ*s
\XYI
!Px?*
#/ .
N^J8
@^h
7XC.
M}d3cCl
h }*
#\Jp
)E9A
mh ^R_:
ig67'
UUbEd
5te0
tpna
a@Pq
LYw[
49u#&
/q}BJ-
n=s ;O
!+h>
RjmNv_
WQa8g
D HU
=/ t
:;<8.?(*U
eDSE
+A%R
[F&W
18&;eV
I2h?
% B^HQ
eA&,v:2
'@DY
~Yd.
SVdg
WK:,F
N6nq
i6_r
tOu?
eYMa`
,)E!
PCk5
H-r4
V]!jf
`^W6
IOw&
$w8ZM
-<S 'NR
yv g_
ycJf8
%ybu
AlB&iL
]-TI#
\1'J
gbhT
+m~za
>Odl
|VEv
E"bw
.cctor
GYD;
z(Ea
@-k;
Wj u
cizd?@
8A#J%
%>{_x
WF!P
MP+S_
eOws
uA\"
^T}CmCJ
l59X
e#Z$"
4VDN
te/N
^8+$
TkV4
2Lh<
SettingsBase
`Rp{
Op/x
h!
\{:z
%ASAG
,x/w
+}EM'u"
|I|@
n.1;
Z ;~
Nqf
~F}2
q X,
~_guw
<Fwg|F3
'aiB
G~Cy
~ 9p
Iw5*I^
8=> o
1WhD|
AAM'
J2He
]%i?
JGs`
ry N
} QT
)Q]:
suU
QzuY_M t
fRv\
b8!i
uhg!
:F9!
.(90
Z`G
l4AT%|p
m b<
k3cc
1^i
6osZ
>ET
n]FM
;jLQ
']cwp
weVN
(SRw
a*?e
11.0.0.0
o-:dU
PKnDp
i&G,
V( [8m
.uL
.F
&E [
Invoke
CJG !Y
UyM *
YIhb
l;jl
%8ZEx
.Vb{
l : _}
?SLh
N2P@b
!kO1{nV
7e7
ia8$
g %>C!
xJ\n
/wNa
* wE
M}.(
]<'8faV
R/&V
N?=Z
a% (
qazg7
iINP
w@p![
;y'ZP
pLIwD
9c VJ
=G?/
Y 8Xr
.X`)
]X\'
[Q0e
/8 A
PVa
"W&v
H,\.
\^Gq
Vk^(
V? #e</
}KW(
akn`
9UE1
^g x
c^7'z
}-k\
a(D|
^"H<
8XSm
>Fp*
f}z42
C<t87z
MA8nCV
8Lf
^@>y U
6):f
<V{k
q-uq2N
B3nwv
TJ1B
S*4,$
oFVc
gt|<
u0SJ.rP<
e1eS
S%k}U
a&@ baD6
I2 @
d9uY+WJHs&
R.^7
?]Xt
0*c|
G}l<&
a~Ro
,j=D
2_tn
J/07S5
_MqD
NIstUIFnUC7egMhycHWvktLpVgMRt
ey"H
DNWY
@X|h
txe7
sk^n
:vm;o
@VS @
%gB3
r< 2y
bA[q
q-ml W
8M2U
TB|[ lZ
,#Mg
"PU-
~Dh}
Fe9oBcy
zI
;Xe
x,Ay
espt
29S[[
QtO+
oRr39
x*g
7cBZ
~|L1
cc{Y
c94D'6oV
NI(PK
5#Eo
}V`t
1Nr@r
f^wa
{E#s
t{`==
p<] 7
8{5
RAO<
12h-
+f 0
geW:
iuT2
h,{19
fUAI
7XcVAI
8#7r
kRO;
<"HD
}`G
M#7%
B< PI
4hj:(
\BZd
%zim
c;_J
wGW
5o[w%D
e50?
1fWE
{>$m[n
S6j\
rn$/
.|+)`t
RuntimeCompatibilityAttribute
?l+faU
J/n%
7ymx
r}[dXrU.
kh$F
k8l(
I'/7
^bcyn
>Z~rc/ H*
Dh#
K"Jj
U@iR
: 1x
K\AK
k*j <&
D 3#
&7_O
XWA1
\}UM
!Iu!@
` B*
9PIeQ,%
Y5N
71 I1
5jZwkBi
s0,Y@
iuZOL
c^IxvU
~<U T"
X:5u
l^47
"7 RX
K /"
.: k]UD
1 _0
'$0d
q5h`e
r2l(
NvPx
&32 <
P-]i
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
6ybseo
":Ns
sw1|X
'aNo
ZRz0
ToCharArray
Y4L/0
2yiI
PdHS
hvFI.
, /
N8 @&
&?a8
%5r'e
U"<lX
.D4G=
(p|v,
GmQF
?b@|n
[!ep
gS{-
HkqD
xyx&
j'AK<J
IContainer
lt\Mp
0 z^
J7"ses
F54S
WyTNzC
L-3a@\
,){l
7sh
v!7p
{XIr
JDd+
y?k)
]8~q
YM#t^
_ r^\
IShf
H?x&M?
2hb6
gpsssYOK+
DebuggableAttribute
.{p
#mh`
X1O5QR
5-,g
@z'
G9VhP
\=!Z
lfLi
P_JI
Dqs
_Hj`
Y<WN
I$ {
D*s'
8{T3
L3E=O
^kfP
]Q-Gh|
AlF
*KkfD
1L'?F
_F*A
/4w%
E4#>j
7WZ[
c{yLZ
O+c)
W-N^p
6[LRr
WeXNs
5?4v
GEp&#
fmIm
cujh
'zSG
K+ O
nHv
ResourceManager
cd m
qe-@
7|Zu=
ny)My
3-RB
P7+S
q:,gM
#saf
aYy^
y*\k
wU#Kx%j.
d`;Pok
( @/
y G. *u{ s
6Y)K
LC7k9'j
+'ij
B.GD
U.M7b
Xh+g
Ub1P3:
:3s,
ZKt3
M%>r OV<
v#k)~
&dd}
H}#^-b
^ dw
T_wp*
I*n`
^KD-
MI$T
'H[
- Nh
+pc
CExr
6Fe|
'VKF
/ Wn
Isa8;
~@LN!
lT^|
yLUC
59=
E)N
z\ m
M,j!
}C_VQ
%)h
T@#U
d7I}B
(hV)M
K%KK
,2;XJ
|Uhys
Kg]
W<* =
a>X@-
\ Ei
TaZ0
u G8
vxzm
V%w8
wG}+
dlv"z
1si?)
tfa3*T
A&/clK/5 |
h$xV
d\]^=
c2#X
ei2h
ZHf/Q
Ea57
1pf*
U),W4;
5r f
(~r`]
6fJ5
add_TextChanged
p mq~
T_ Q
d#ny
$}E }
b1bI
tQ=M5
$d'9
wdy2S
7[0,V
~l*t
Mqc.
4)g.\
<3 ~kB
pKPK?
mX R
hl B
a(k
l4Qo9/
43<)
Type
mP+-
1Q^j
('!f
*[JS_;0"
.<Iq
VlC*
)N EU
Wb~D-.RL
|H|'
[ %{L
@J+_
&mOy
k@IU
Ok8+
mU6AT
0W8P
z4Cg
"rR+R
o}Hm
dxO{
9`lM
YF&(
R63,
^TD:
PJZn
{/J(zY
8 &5
-s;[
U]Y+}
b7&! |
;&Kk
B9Yd
1t.RF
4$#.
r<H+
PP1g
}(6S /
^y@G(
olOr=
Lxo.
cEQf
w7q4
>Z'aG6
- df
,x%n4
YF&o
a kI
rm^'
Point
&_=
}n|YB7
=`0,
1g!'
jqBkK
U6p8
."xI
M-:
/>d0
q6L*2hZ
BcA;:
[pcz9
!U|^UZg
_ Ix
|ez7
ek'xu
'u"-y
C]Y:Q+[':
;gi@
d')|
0 -
d/BL
m**YKx?P=
Cc)wx
j t
. ':
vuB
`<T-5g
'H:[
) t$\
I,3;
*ELL
=~'4
Wv%#'g
.R?9Y
rZ6y
lJIq6nxPJzxFx66eDe1PGRXZ0elrr
kWE(!
20Tx
/o4Qf
Yz(g>a7I
#4v=
7bc)
SxE
v$bJ
qD5e),a
k7mH
nm-[CK
-Jcb
aTgFu>
@mB'
~v#<
C/$v
Gm |U
k7m]
, q
wmXs
}O%Z
eX9/
k7mV
q5p]W
Y\"Po
PrNZ
#^t@EmA
f<t
=KrB
Y56iz
7ijw
A8%X
zsp|x
e`ys
m @-
I[mi
YTl_L
OKHSC
n5a"
RuntimeTypeHandle
rt6M
l 8A
p:Jy$\
TtRd
uk$Q.
(YbE
c|Gh
~DnBc
d u!/
a1^3
lfg|6
TWk"
T"kM
,wa7
FOt Tl
> tx
cKy}
G<Tc
m1bvK
vHMDg@Z
jR7s
\$gN
| 'WNzG
Bn&o
cLp.3 Iy
_}ef
SVkN
{}cQ
Ty>{}
(s*+
pD(7
EpfE
:^ E
Q%J
- \
}5sC6
WB r
07L.f
hZe9LnY
-Td
CHk
(na
8bDvp
*pKX
V<gG23UU
T;)\R~
pX^2
O. uj
$'ji
$n/
N$\i
(#pt
~rT6
zd;%B
<{Q*
<r65U
QOI/
$v#c
IjsB
$ E|
! FE
A_ahL
4WJ@k
M M<
~2_B
#FP*/[)
M')@C
5jFMsKkrLC6hizFspJ0ChYw75GlIR
V8q"
d8H$
<KHZu
PG1/<
y TQ]
"J 6V
;6N]
EP4
fw$Q555W
R~67}
$;3
(B]owm
mOsP
G< {
Pq=}I(n
p*Fb
Char
?SoH
@xZv
@>the
H^_ \
ofZLEok9maqnjPWet8A1VuV5oCFbU
B k
"m>-x
0pff
T'wG
:e5
GTm}
o3?}
2U 65Qnl
0wri
~jc
lo!CP
s;K%p
R1nt
rNQ3n
q0n&cl
dpTPs
Ek[lY
r/M|
TrI#
b *c
:*9;x
J<'\M
RY )
LB^c
zymr?
MZ
)M$? E
"bEt
!This program cannot be run in DOS mode. $
^BAr
'.BSU
+8("
yw sy
w[_Y
}Qk:
|>U+#
BXw]G&
g.6
m>3q
6wH
fX/u
w_2
k]+6#
;Ed`
c7p*
'b
JS-B
;AdT
f(ui
];&?
9na+
ptmo
ixat}
X+ 1
g0{u
wxO&G%o
JKbaV
<*KA
,rA6/
I~H
BJ+
()&:
Rp
(nJs$j
`A-+
x5(X
gNa0x$
W}@ESH
{C=K
[vA,OT
*z(Pc
set_ClientSize
C iP#
2DM*
2"vZ
ZGcIG
|c [4;
f|^5I6
!BL!
6Q+x
_nJo+
D._QXR
AH <
t'1x
loz
FMbF
Ix gBE
A!a5&
GoK Qr
U6>a
&fnS(\
,=8-
jCx:
1F40b
j54(\0/
L, b
VYZ~
0Hfa^
Yz!L
s"uM
@"X~
h;g+
/l6
, Rr
)_Z!
7WXB
_mqW
,ZR'4l
'/?"
a6g:
=:'9Y
d]]U
uh[C
]Ge?N
*%Dfon
pv&%
cX7f
m@;A
]J1'
_& y
6rp\
X7^|D3Z
*bZ D
|Eayi
;me&~
K(~*!
j+=.
2r I
TOFh
Ov"o
?Ii(
nU0Zd
lNR1N
D-9 0
;4oZ3(_S
{]+v
|T[u
TL&#
]f+e
} }<G
%a8c
|Z%Nu
S@+!5
?zv9
VFBzU]ZtE=*),:
D CG
Tgvi
@pBo
u@2R
kLND
2==-v>r$U4
@B-t
]8aGQg
%a8_
`aZ|
>.REm2
hhSNE
g!/,@
v?-Q
{2ADP
VJp8
Pot+3
RW5JZ
NZSQD
4Ebt
LYsE
EditorBrowsableState
zx&t
aFF"
$ I!
fh $c
T;S?
EO!
Gajo<`
'nh0,
L.gP
ZqnTh
;0$1
C:BT
jBY/
M 9XJ%k
[3R
0loy,
V,%Z
Dd>O
P@_3
,F9'
nOUU
Gmb5g08NWaXMIukpMCFbkseOtLfe2
/a2${Q
s2cM
5rS
oNYc5
P<&
N'qW
1PRU
,Fj^J
322c|
V|JS
An.r
&75Ap
yqv?
x.?W
)#6cDr
(M7X#7&
|~ 0J
6ee
N .b
W wAI
FMZ{
_A2sj
Hn'$
pwxZC
dwXSo
\ .<
Q;:=
5B+o.
mG X
%U77{
{ 9;Pm
@"jK
MQDuV
v<sw
:`=or
X7a[
k'vUA
Oq$ .rC
u@Rz
MethodInfo
hud"
rJmr
B[er
1.0.0.0
o w{ }1o/+
.x<a
/ U
8 eS 2
&;\=
d&.:
LJ^%
a9.=c
C__n\
@@eX
|d[0
zm:T
yS!$
&M8EgQ
|EoV
HVok~
x]~a
VZSvy
\>5G
kJ!N!
oQ C
/cK H
-ut^>Q
%ZR)x
Z"MG
<R.
L`E%W[
#QbA
e]@[
JEN
ez7M
$9 h5k
0s}W
]eYcr>
@'VY"
q2jTV
~+<w:.
9WvC
fn^Y
(-qx
W>W0
G+zC
~+Rr~
G]1u
r- !x
g[n[M
8]`3<
yc]S
q6iJ
!S&#
4a S
Dz>q
bryP
NEN1z
Z5%a5
d9at
} qr
1 G\]*
tFJc'
Z9RW
9-Dq
WH#A"'F
EySl
f^+7
xu,d8
a(mRn
t;O;5
b:oR|
l`:ya
:m1~~%
=P"5L
&$2[
$<z;
vdDX
0AkS
;bxpl8
8Q=$
hIcKr
rnNg
c1u:.s
~Q@2
<.P(
{( d
_aiS
Cpjz
uJVPA
?[k6t
kZGqZ^
QR4T
/G?8V
+%NlA
.":'J
-ru]
*C\l
TW\,<
4gKozdk79v8umk6rl2zeljeh9Hd0H
5TGZ
]DtN
AOTB
nc R
0GYe
H!$sg
gHgk
9 QH*
x"S%
T 1E
dg1
q(zh
Jq S28
kiTxd
set_AutoSize
|0|
@%?(
L&3D
&lVP
B 3$
m/>=
6;fs
w%y!?TP
|"7(
]IRk
ev|Y
,b C
Hc1fa
P7ol
NS 8W
\86-ZK
QHCtm
u33p
a!C^
b^.@
f2|h
Pli
'zZ b0M
Y\ B
j=R2D[
j)a8I
?b"Z
buQ_:
8B5U
OB'C
>`rJ
op)e
2 9G
vBwF
&"
E5p'9
BP@A_
fi2.CT
Ajwq
f`bl
!Hf'
~b;E
`hrzVR
Mw*T
W< J
-R ;}|N
*2e1;
V8"L
|ixg
/WpEk
H)m
V #
Le(He
dpII#
N@)p
}f+Yv
wCBT
,A-a
~Yv
A$zH<
}{\+
L h
'og2]I
(!/Eed]w
!nre
GN'`d6
U4W<
i_z]
yK$(
ZdOk
C:BEGSG
H^!u
b}7d8l+
{Kn(
b%5]
- V!
^~'R
^dP6L#3>
@r| .
$="I
&u]7rp
n}]j
F\GJ
d*l.^+
m6N_
9l_x
B_!5
9+ }1:O
/_lx6
DemasusLotasito.resources
acmSC
V+ )'
]/bx
&Zf9
x&P@
}J!+
9Y_Zu
[}4b
e;`'
%G7McMs
jt]P
t0 k=
@VVD
QTnk
^dh
i/^e
m[@q
myZZ
yB Y
{=Up.
w+#(
.Sim
PW(y]
Yw2A6
5KyCy
-{9'
2ltXY
~./x
`'M+6~
~tMV
vE74G x
`,t_
DebuggerNonUserCodeAttribute
E5du
xSs3
Nza8Q
Pf> 6
rqh*
%--Ux
eZHI#
Y"db}
*+Z "
zK%Si
'S2y`
hS<<
]3 `
DebuggingModes
r.Mt
System.Configuration
T`E(
j| 9
kU
PVFv
CZw:w Xr
QJ}u
$wOj
s)##
a_jf
Fs;6
ToArray
{KF#wf9
({~TU
\jdX
xPs[
EP 6
-:r=K
R_wH@Y
yo^'
0M X4CcAC
~!."
*Y>@
Folling.exe
hpSz
<t3=
m1!c]
5nu^
rc/ g
&4K$
9.9
p)*iI
~9qF!
WRxATz
*F^G
g7o1m+
#Rfz
{{8
]O6>
3\}Z
in69&
#}1k
k M&
"@uB
hk?[
:^w`
\K{%
Co '_
6kZ[
r vx
_b"lE zN" Dj
`eu53
9[\
"Fi
G,9J^
ix&D7{xy'u
uB %
;X4:6h
6'd=
nc S:
"Bi:`
' PG
Z$!gry
6 +#
,h0_
^W?E
isf
0{a+
~% Q
WT^.j
U s
:RH/
K?_ v
L>gHUd
g :\tI
u*^i
&(Nt
AMr
n)]*
M K4
lpuI
Fn4=
l:bwg
aoK4
Tey!;c(
7_Z[n$A
gadNHLV8nQaiKIzbtrG4tLpFxEfdv
?80/
eh -2
T^L'
-`;p
R]v1
WAL'
y6-WA;-
]oT,W=
{QR
$gdC!$
y+80#
_PV%
l>/~
NT o
zgKTU
<T>%qUV
vtQ?|'
*=?-
*3~@j
dB8>2
N|k.
6Rn*
?f]v
FE 7
; 1E\
G' 1
@|]]
JLf}
LEr1
Qq2OV
G :f
Deg0P
K&5
T@y`
S' 0
iu"+M`[
viw4-
0n<
@yj
)_xvJ
aKPo9
\ oP
Y7:dM
V.An
C=!g+p
~EEA
0.`{
7qN
Y<TajA
;C.\Tj
&pM 8
%Xo'
KkLaapIiY4ahM4h7aeq2Gk8t9aDXB
\\k\
,"=#D
m]z9n
&'6Z
+++0i
.Sqs
>xlq
<R<&/
_jwq
+xR{
iVM
jys.
\%p4
>#V p)
.?dEZ+7
XBG,
6EXgzN7'k
>C/
)aY]
Gn\(
[DO8
C9l[rO\f
o.-;
Xp.?4
7H^4
\(G!
<5gW
0 OP>
e ,}
/=1SI
pZXJ-%
z'>ia}
6H|
vV ?!;
XZ R
,EK|L
.N<5
bJ/f
U&"Y
!d@S
y'2*W
J&R
/t#
. 3N
Vyxq
*md|
SoF_
{ 5j
6tGp
"eW%D
?{ 3
sZ A
_]]>~
x\<?\
.|qx
d.?Q-
<bLg
#/KxW
k /u
6CPL
_h\~t
v^T>
po M
u4 E
iIK$#.
;dBT
@Z; .h
T b
iJdP
L!:i
u4!vEiI
05a?{
:4f60K
5bap
Mym0r'
!&d
,s}8;>"[
LH75l1
g\w0
r^plA
y~cP
[3;F
8\EY
W&X
J. ;`
^wWQD
'bkj
7}R7`Nm
d(zju
jeg"w
t:"6)
mcMoV
[5%$
TNv]N
H|{U
Bi10
qso*
>N
Pq7UX
Tf=NH
$9c
& #e
!] 3
-$d
GW\\
1 7)
g=+ Z
Xk'u
zG3Z
ijkk
}EV+
1NJa
Q cy
iszPQ
I\EDG`
X I.
#FqJ
?]^{
YqFz
:G .
_f7cC!>
"A5I
ez@)
F=1f
%XB&
G>KB
eM@/
*.qU
G "0
YPa4
;`x7r7
XN x
L 6<
Ak+F
U!sDl^
6X"#\m
&G -&
3#21zM
37~V.
'@6I
yAD>
]t %
RC0
unErc]
' WnO
Na*
E3B|Q
2m/DM
,y+z
*%ya
r>n&
4/te
]f0nz
)=:g>+/
gD$D
NVJJ
Es8X
B4j
r/>F
wZm6
=RVOn
!!
`d22
Folling.Properties
s?%
^`@Z
h(ao
60z9
?FAHW
5W'%
O1k7=
$wPC3[.Z>
Q+&'
H4hx
gvx.
Hk?M
5?r
rwtE
WKdi
upp=
<g:\
.,w_
N]<!
l.?Z
U\";
Sqpc
)aK
~<FGr
4.0.0.0
u >*
#Jf:+|
MQ(C!
?[p7
1!b$
L\>z
!hkg
s<:
lazV<
r1~J
~qi;:3
?3bsk
/,)%n
%7y4
Xy!
8n9`
h;`
's TI
UYlv
LW5.
VwuU
T E*
{")NN
fqdz
nL#-
J0Qh
!$RxB
:,+E
jWd94HO
Rj?\;K
zZ``7
p8H_
eP2$
(3VrR
CreateDecryptor
s74g
TT&z=
!G` 9
qK
yaN)
bDZR
D[~i
Zt+%
HFF
imG@
|nhN
bo/,
F=Tu
_s.W
-] h1
xbN7
SmA7
4yJn
q6n)<
eeQy0
m?"P
}'L"t
[v J2
ulLn
;JL$
8 J5
^~N|
>cv
n(:0
VlbfdH4QCfJ7r3CYkPvrecPLpp64Q
EFd)o]
Yt'c
UAI2
-%iY
%y\C8
]^X5
JG3pt
!A|v
TlM#G
t,Y
.2L
$@p[
\7p(j
ziv<
%wxl9
^Oy^*
ypu{
NGQk
{|;I
,Y9Pnz
l!Iv^m
'RM
LDwq
1\z#
O_d6
'KCH
/<iB
Kd_^
awec
B] >J
VR0,u
5oeIr-
EEPPt
'j5saqj
-Jzsh
m$}qWFF
X &B=
0yT
U623
G'q!
F0A'\)
!00K
Zxh i
$?A{;
1LcmZ
ich8
|3r&_
\/1 j
,01$
ICJty
")pz`X
$>PXga
&:_+
a BY
R35
_Uq T
1sKB
#V X
$G 2
;z7+#M?J
`W@x
"=PS
]{ `ra
.x#
.cjn
:pJOe
<Va%
`f`0
tBUJ
X:Ps
hEL2j
z)S~
hWaj
kw Q
K %z
XztR
I9}-
1 yM
{BqFt
SeB
Ye2n
dO-
K}tb
E#lt
'[h6B
<b0_j\`
a &u&hi
AssemblyDescriptionAttribute
nkYe1
+6 Y$^S
=:\h
|5Z\c
zl3S
*skUx
|-N3
v
9A=w
CChZ
SBB%o9@
&_{4
j~=?
[qMZ
U`NO W
'E4
@tq1
Settings
C\Vb
3R>h
eoYZD
Ion!
tv)`D1
C#i;
zWF(3|
}Z\pd
"yO7
wJJ0
/sk{
1C6\
!=Vl
CPC>
$E[)
/A?jf
j{s#
?KP% ,?M
2)vBv
#O
t7YRY0D
LS/du
IDisposable
-t#
id}@
!Bs)i
cY@# 7
R>9
4y-/
{xpu
sX<
D'p>1
f r?1lO
Dj,i
98&
[}`
ed1
]m}=
;y zB
r3 81
Q0fA
5x)Y
KdtMGSCZxSWeS0bclbY3cOBBEXSR0
.dYExv
|7 %X
"xqf
Rep P
,ibD
eK Q
SCSG
$s(
Lkh|
B2Q^
A*8F
KBL}
k$nB
GeneratedCodeAttribute
mp?&6QT,
2D*_
ygP
oW{O-
]SG~
t/v*m
TO3eNI$
gk$@\bA
#'K,
e^`;
l5My
w?{XoA
u4zzHexszMDi8CcAU2HnBFLGBtQq3
$XeC
.TZ)
8 C1
;2e5
q0zT
LREGj
y Zw.l69mY
(_ta8!
;ePg
r`B"
QksK9J
Y/q_
3qKP
2es5
\,8%
HSX%|
eyQe
@^?K-
GbzC
]R_/
@ErQcT
[3Rz
+]{e
6>x/
CwV
<UYvD'9
ZJnZ
Rcu&
#GUID
qh@W
!]^+
G)6l
rO_2
yL$,V
'j0L
f67$
: @Q
v[$v
_sHkK</
JO0o
M6I GF
J%m
/Xu m%
oKy-
y`=9
peiJ
B SB]
jIQ6
YA@n
k'td
^ z,
#J-?h
R {4
d/0}q
~{ELg
0K'
+wp
vqtY?
0|}o
MXmp
k9mu
us==>]Av
\mEGv
pf)D?
:LD4
S(`-n
>Qv;
vu1*e
=*uj.B
7ov"
op3
od+V
~4@Y
VzBb1hM0W439vexVIpPYElflX5EpF
Cf!(
]DhZ
JKd%
&5iA
g!'g
9(8c
C#H}b
<+k&
GG7E
_;<%
\z'G
mscorlib
=P'%\
#y,Y
CzPP
t?Vof
fHDwq]w
~z ? -
aqd,
?{ H }B~M
p'^R
XP3g
&SG53^
jPZF
M`Ic
_Z-R
Hpk0g
_ *0
lN^;
CheckBox
"1&h
u. [iy
.(I@
`l 6
&{'kS}
w#89
@up',
|<s]
@:I~>
)PiGbud
nMe
5y8OW
J}C
})4$Q4
D>Yuk
\PK
wraQY
o N
FiQ 3
EN.BRK
Q(?:
eEh&Q^b
%XqT
C=./
GetTypeFromHandle
xa8R
:DB5F
JatI{
<mJ
s;Xqi
v+ $
R;Zo
<"%,
|Vo(AP
T?^
PF? `<<w
9i'Z&DB
t%UJG
zSZ-
[pj q
Q)I&
W0@
tiQa
-0F
|&#A
VG )+
PYYV,j^
ZR5/
<\A&nO
DOJ4&
k*ct
{( \
>wsID
Lfct
yK}r
F7g8
.vZ+
niMr
H;v0
:h"x
mXpT-W
Ts0-}P
A]%K
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
F\[
y^38
` 0_
RDKh
Gzyt@
(Y,W
K%>S
X%4 ,
PBLX
0x O
<P~
,VNv
L) I}
PU\|
Y yjk
0!el5
7- |f@
b>W Mb
>~y1
[>.A
O[&&
5+ G
g$1p
X%:^sj
0s/h
<0Zp
M>R8
wp5`
g6F0
z K^1
w;R]
!y{S
seuN
)"k/
*VPq
\;SL
+/D6
]I$g
IrgM
IH2p
PCF;
Q:>L
[vw H
>/<&
yf]F
F W3
lFyx;
&@6R
%2%%
m!Vw
e| n
2F7.>
$ob{
Id~h-
Y ^7
8#B_/
T*U
I3M
00
%tmT|\
7*&<
K=S
G;6R
Els"
+^g4b
*~vS'
BY>z,g1
hz \
xr9^
\ z{8
s:uI
W8j)(
<Jr#y
5ps0
OFw@l
3!+yD
77#
WQ(,
[c[6
-=H`
i#4,U
.j1l
vx,}8`
iGN5q
*0aB
5i@g
)+B9:
vRT
0~n0Vp
]40~
mCpm|
RL#P
;gSw?
+&H9
6! 5
f7R/
X D?,P
o:X0
aM#x
!SXP
AutoScaleMode
@gVWj
4O -
IeAam
^Drf
R7j{d
(BNL
<UviWyuj
<>;%j
"%'|
V<r7\A
W6/ak
A}+I
Swey97o
c8r=_Jh
4[;P/l-
Fz p3dz
H(B7^
PdN#C
MkrU
"n 2b Ge
3^nl
#\@A
a$os
*v<Wo
<N5"=
7]`VMQ
!^Is
mTp9
>1VF
@YCu
c&H@
w:iu
W, I
XYst
Ycl
wF^we!
~TXH
jJ'`
;?UG
{'ZIbqzm
.~Rl
x= ia
q5@L J
(Nr:
K8xM
S&;$
.2YET
Rm{l
]i*l
i_b(
jBZU
~I~l
,G \
HF(
0p4Z
QOo"?
}$G[
4$cC
,/a
L;7J
"fL>
c&=C
,gg@
b I.
Q?dA
2oc#2
6eco
9<Vv
1P\y
8gx5s19Yo6zb232dXo64QZqZ30mMl
O]@$
iicj)
mYH59SjCIjV4sRy2D6RUaAoFsBqB4
"8E]
E8?Z-
z Qv
b4-
->n
dV8$
7V@,
[2ws
aR|f
%>,`@
>(kx.;E
N C([cO
U_ <
RR{<
BXI^t
We: 1F
w M]
xxoT
fWZ
r#;;
%lx-
Dlo7
&B4[ 7
Gu(7.
aJlP
:9u<
JK*P
1K d
7]0>
<m VH$)Mp
=HMhnc
u(#)
L"d$
AssemblyCompanyAttribute
U{*
PiK(
uwoz]
q2WW
N0u
.(r/
h<.wl
Z#j,
pW/08!
g3'k
vD Wug
At})
Al}}
xExU
~2KK
,`]Sr
9Fg^
+;~fB
<l=j
97s8
4I R
r#fc
6 IYJ
o?a
$0&/4{$
8%P2
v2.0.50727
8%P=
R[(,
Fzr
:7Wu
%|C;
V 7(
get_Assembly
1u4:
PADPADP
$Jj"
Nzb|f
_&7f
K76<T
R"__
7a]C
R: PH
AT sDd
<*na
.UZS
uC*}Ay
\zPL
Ow~x
4Xdv
QaCJ
LRh{)
hf'Wq
7Eb@N
yFyb
Oi!qV
E$JO
}JcS
&d&
=5QGv
W5Lf
lJfECNGbA13fUscTSy2tERlAh6J3o
DQGd6$
|//u
/6\D
q#WY
d$ 5!(
f,ll
=Za8
_j \
<,pv
VjRa
rT@
naog_
Control
q Fk
rvmiI
n_b'
aj&]
3IH*A#
>#iS
NK
y7fy
8A $
HWsY
6fgL
d\&$
1[%|
mqT6
IA \
pM<P
zDi/l
}f@)~``
Y9]y
h"*SD7
MsMsz
[@
4.zc
RM5n
by ^
(S3y
}ER&
5s7yT
u0 06G|E~
77?Ar
Mq3o
%qp&&
DHIEg
Z5d:
Ou;@M
N[ eM.
T?x$<
gV}0
Pz49c-
%Pnw
rZKE
Fyk*
uH5+e
PY C
:u7f%
I[=c
3vm
T'7A
qssF
]]xK
>'-T
{['p
@NF #
QvWbJY
,Bw"
8@B`
{"Yo
,Bw&
"TiSA
h"Y ?
Svb4
0%H!
7D31v
?pm8
Z"hd
g%(
1nit
XGP\%
v0Asi
kHLq
@3+*|)!
\D:
e v5
<Zm
R/t=
0_NkF
QN[
f`Vi
A%Q}
,M#}
wg nFx
gi)iD
v d
';ew.8
H:zs
.p*,
r6R5
2015-05-13T10:59:58-05:00+
xF$e
!% 2
03/g
>VzJ
Jeq|
BFGYU&c
e !_Q
ms;u
!;u@e
J 0*~M
R*bVjo
a!&*
u (B_
b A1
UZTg
e 0D
A& `
ReferenceEquals
dbmM
p[l~
1@RZ
ROKD
!Qc)F
}Z~Y2H
an C
]@P; .T
mk@ N[h
6`Ac
`W~&
W &v
<-&]
f+uI
/*?DfD
$/b9
l`or
S\Wn
|gF>
:RQc
MQ!G
}<Z8
M`3&
G 8zTS
k)i/
,N +
uv}M
ku8t
K3]nW
3$l7X`^%
> 2}
jNT.
EVwA|
`lT=>
@KzG
o]n0
iG{H6=
z*V8
}Ge/
n: 8
yFA.
M.WY
B/J,
m 7)O
K%|
#s*i
Q:<w
9PO9
IE 6qI
r<rL
;kJ_
. 3:
h6jF
+`n3
i/Tn
qvE
];.-
kp]EQ
:v:"1[
:>- }D
(H)s
>3Ew(
*/8Zj
e/#?
Jlfu
.{L{
gbY5
"59.
?Ei*
Wq)u
>L%L
<qJe
Z975lT3kj6oWbVqRXq4vt8UDlMRY7
z}s.#
_I9q
b:*@
Zb!eY
Cy 4&
;i9Q
e|fQ
~O)4L
y[Iaw
@y%c
*i-+m
_FL7
qdl{o~9R
(O`^
uhwd
_6t'
mP+w0x
`.rsrc
/XxC
L[Gpp
O Y?Y
9wx8F
o r9#
"dB#R
[_)1
**u"
;B]
s9x`{
U%M!7
p:p:
1:aF
2I"7
4,Xyts*
L`8X
-TM:e
S7Cl
` }?
g{g4
Dp7T
Y}tU*p3k
bE?(pZK
*oe6
ViCS_
PRL\
, JU
(vQF
WGt
>z<^
SJ>n{
0/ g
Bt::
-&)jc
|CU?
y-:;
<w}!~
lvOl
_J k
c1)~
IGu<
nrE
-{6QR^
]*)>w
^`!v
/Y+a
<LxGA
DialogResult
c(eY
5p}4xK
uNy$
.][5w
mYk=
b2}x
*9(#y
|Ym{
`xs
w.*$
3Pyj
A2J"
"}or
GMFc
Ym 7
R8 h
cRp1LY
!k[_
9;Zi
HzC<d
IMgH
y{5
}y:
w\ M
$0;c
K^$ A
;84j%SO
:N<P9EU)
BI-0f
`T]s
} ]!
#oH}
TRl'
|tQum
N9c1
SymmetricAlgorithm
f0%L3'
GS:y
J8f?
?c 1
DplB
a,p)r
4}z_
6?@|!Q8
W8n
<Kx)"
Qr3B
5dq^
^!6I|
t;&R
a$W`
3[ _
fR-b
) 5w
bgg-
/ iI
{iHb2sc
Bn3)
Hi0|
QjN_
`S7_QU
'SO,?
hz,$
ZP}pP;
9vwK
wgz
2p GB
~@-m'$y
2)/l
@FuE
ed5M
f! -
+(U4
Gt3O
=Po)hm
?c5.J10
C2NdXCN7QnCFrfL4RnoTr5Li1K7TE
p Rx
H?c
Via0z
W m7
^z6 p
<)fA
Bn3r
lNb+
n1)i
v.L,
(PU
h:D&M
b)gj
*X)&
Ya)5
W7D,7
xy .}
&K>;
P1nH$0
rpgy
:r+.
x%G+
9x-i
R9G
/eID
(>mn
A[j8
R4/b
zukJv
5=5:
TH8:{
*GLy_D}
u L U
!Zl`&E
}*Dsv
Hv<
#rEe
FW_'2
TR?D"
IGjI
n&:'j
ef}
(y4df
b"5-
-" n
<3.q
Ub LOIZ
Mw5A
<sf="
7*y7
a ]y
1UA A
Kjxbi
"H#g
r!7i
R#?x
cuDV
,:lPj4
'9o
Y j,9
\o/
E3m:
gE<a')b
}.|U"""
Nk#_
wNr`
xM(B'
/;30J
FHVK
}, @
e.cbH
^eV
!v8\
n0 ~
>"AF
,^?K
!R8%\Pw2
tUmV
x%PAdM^
XU
YYlV;u
fkx<A
L0EB
Yh p
RV>+
E`uZ
/Bs13
!p".
<{/
eXH~j2cB7w
eT,98o
cG]54n
;Qs:A
'&g
mpz
nCohEE6
#Strings
~\!{Fg
tp:Z
yuBg
oC}s
nnz"
SxS
epfL
`p
s92
D w&
<t07!z
?r<:_
)?ti
Zv]a6
X}I
^"?
/et#]
QKrZ
nmf,
mbosOiJ?
v q
[ X=
.P6&|+
p!v}.
-eBm
JCy~
heg h
`r/7U
E|IQ
ZXcM
xWKYEq
:U<L
oMso
c:>b
T@Dh
:&+k
$=iPY
uGgig[.
I \
kXk
EY4Z5
rvyQ
>E{!RB
VD;s{
qlpE
Application
C~1,]
Ul]A
4+&g
)!vMPvxr
I(be2JU
5Oh6L
U\\6j
,.f7
9Ej@[
h7h]
z<#<
"G|P
C~+>2
c}e]3W
6!b{
q:@,
aB %
b qt
w0"s
l|!pJc
M?fy>
, pt
@(S-
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
! Ui%
v`0a
, k
& Iv
6-RV
5YKy
1GhC
Y8R+'
q&d7
2 bc3
A%Wx
E-5h
q3~S
Q&sy
2tQ{
QP"~
a[&
59y
pcO$
Uh*@R
?OiQ
iR L3
u+;[
RJa'&
>g:v
$tj=
uT@N
9\3F=o
a2JcxH7iZ3pEYn6EAHQwlg613zXVQ
eboa
l]|:g
S=(/'
n"&Z
MpPr)G$d
]lHg
DL9e
,9oG
k:COLDy
54Y;
n{$"
Y\x>J
.Wm?
L_++
RB}/
-DX?P
F5n2
B8x9
]iv\
-C(b
j6jl
vC_;)O7r
9K8J
S%7NC
[1QIB
#OAW
}[p/
'U9n
m =k2iD
u -*?
tK22
TC\p
Nu>t
S SQ
KN[<
s[<
h*ud
uqM:
}\IabqhZ
~-@&
B~Xi
Q_nHV
<\uJp
/R@YY
FnXi5
+Cqr7(
A 22
,OZJ
M[0)1s}
mS6^
Nn4 ^
VVVp
FVrqeMVstmoHfepYg6SbqUmvcwTGb
MO4,
A:N%
iq;9
`}'.h
VVVa
*iG_
g| V
Rk9H
=R':
sz7bJ
A^Kz
bQ+/
ppi]9
j7lQ
r:NxA)
gUkR
pc6}
r/Hs4
eZs<
Z"&!
a0O&
g[d
?,6n`I
$CCd
xNI;
n =m
Cb\
@bA_PR|L
V*
UP6(
3JIJ
7P<GP
*>jZ11
NW[*
ObEojd^
/y$H
vG).
A:NF
>Os0
_BO,AMdWi
pU:H
dH@Eo
lN51/
){-p
_BJ>
wS[GYQ
4j]}
(AV{
A%0K
Z%Nb
iQIo
E j=
x|C(
O"Gn
z _v
g>CE2MK
70)\
KO9XAS6X4JoH2GvExKJmoxvFQKFOX
0TEC
-,
Df x
FsV:
;D[?~
[Avq
>-Xg
QAm@
-a&hYV
N<EB
vkwG
hUV;
,E\u,
BCso*d
NDc2J
0 ,&
-w5|
wUSXZl0UcHxoW6le3Lh6AAHcjTBVb
Zb#-
@Eju
OM%p
-R:
)dY
r%\T8
(dqMN
^oc9M
[v47
D9p7
9_q&@"O
o 7qy
6U1B
\G t
"d)6
Voz0RS
ex}j
!9t"
s<pED
8p U,u
ResumeLayout
MbV^
YDME8
Y=5U
V&Wl
=/%;AIL
u"1H
OV>H
: qk
VbI[
}3-
2P(G\[
Lla8U
-IE#
r No
_[jA
System.CodeDom.Compiler
|1MqOI
| k[|
SetCompatibleTextRenderingDefault
x#l }
G|4]i
#[:uk
LSlSs9
3[eR
Y{:;
QYm~
uE)u
a 4_
5[YV0o
jcmc
~'$W
f&uP
v= b
{W@*'
Oe>@dp
5{+s
JV.@@
_^YP
:2L&)
V//p4
_zMY=
ButtonBase
bM$t&
yqgV
s*6q
!%& 2%
8( [
}x](
yE`z
IcQo
'@v|
T%lj]
m |%
z22b<
Z(sE
n&Wr
!ryz[s
yt P
'GWU
Z8rw
Yf+`
;K5I?sd
M^nu}]
=PI+
.X*4
a}
DZdD
|k4WZP
Q,8
:K5T8
JDMy
]d7x
0w' =
51A[ &cvt
^V <8 |
<
hv/p5#
'H" #
0R5JeR
S L>
HzX+2
=0%R
uMw.q(
~l]T
>eO?
LIym
ToString
`x{H
>+[s
_0YB
_zp
iOm,
4sX5}
^ he
Xm.`
}dq5
!cH
f%<RA
W4
S"!
]&
<uX(
X9vT
z<L.
t7VR
F jr#
KQ7IeFA
4S@J9
@<9>
^Zch J9
/eBOG
$O!*
TU&<
set_UseVisualStyleBackColor
G ,.
ruIOPW1
TPinI
>YLT
r(j}?7<+
<&" _ `
^_]{$
#R }P
R:[4
AiKM
$4)p
st~w
_]]Y}g
D~X4
P2.c
0*bAJ
uG ,
cv8C
R[id \go
`[r{
O/|C
01u|
xvAn
R(?(
P(.r
2X8t
cZ.&
g F>
*sN/
MhgO
ihQVJB.
pQcy
Q!kr
} G]
A~S
Z;_#
^nA;
^;*m
)5p9
'EO F
we7G
}Tw_.S
B BoC
# $z
RyT;*
&mC"
8}AC
:+Ny
K {q
bMw"
m\`V
$nIn
hZ$%g
=Pak
Z @-
vt(hH
},b 00lF
d8 Y
R *F
a` tcl
H<O6MnG
i$ D|^=
g#XW
'70E
WLaN
ldg%P
fFoG9
uTPp
Tx%U
D4
G9`MF`B
RhQvt
$Se5
^HdO
\"]F
rC_`
'Tqzt>
ma'r
IlM7
'D?{0n
Fd\n
^iYGA
mYjc
4qSa
?68`k
> KlE
_&Xi-
v ]D
l0q {
c0RoDUIar2keBeluPCy16YlfJkKf8
fHQnam
S3 ;
*_s_
E!}
IQSM
< !tZ
upUD
4/Ba
K4.U
L&9y
o#.*
t?d
qE,J
VM.RR
h]M\
W?'U
!SQ1$
nPWY
w&}a
]vY3
7,CgR
!q=x
WS'_d6X
C,W
7 Dg
3zMM
V]W|
T>qQefH
FR!N
(%\1Ikm
gl$%
RA{#
j;l7$
{a?\
4fZo
Z@xo^G,|
GOW5
MC0/
i|0
45T-a
5 'X
JAi_
6i;A
@.reloc
)p{~D
H N4%7
"1Q-
"6+z
'm-7
sK:}
<Z2 o
b(PZ
0I,R
EHf8
+A$Kk
yu8E
kMf*]
A5TM
k%Q_
X&Sb
0Ln_
/TYD
c E+x
z#<|
v]dI
OUa>
{l?UH
{|l^s
='c
n" L[
^1x1
Ni `&a2S
TM$}
?#;FP
}w"se
RX<B
Y$7_p
>(u`
yntG
--Dy
<8`<
d3f@
)IwQ
pSJ
u?[T]Ay
3T~q
(!E$0;a
Kc;1
pi 6>
}e S
< [1O
s ZYn
8EeH
-A~L
_a$%
%tEXtdate:create
dS98
;*Hj6
DPtq
+bLw[
&h:vl
ox_\
CM2tAAFxJqFqK6HB2I9LdPYk0UgLx
%]l
=9#_i
$_,>
I}C0
<e,EP&
uuKJl
r~&
` ^
CG $
RrO4
^O}y
+\nn
'{?7_
l;2,@
ye
[(eu|.
n1iA
0pr"
k<2nFx
c[Dh
K8WI
7drw6fWJaRcVqD45G3MGPGga61hq8
set_TabIndex
(^M$
\=[D
I>6l
*{F:
{h0S
I/$/
k")V
h, 9
WS|L
(ii(OB
=I?;'
xaht
weI.$#
x~ J
-R]6X~
I6]@.
QB0.
!vD1
WaS|
x[}o
LHQR~%
vKv)
`ln'
".QS
c I|
%t,<
%=T Y
*n+Fs
1_Jv-
C_ {
TuLY;:b<
E[y7I
eWOM 3c
Jb|{
Ww[
g3B5a
@ng^|
9O0M~
IloT*
"0nu
m;q=
YEsw
o3\t
SZ!'}
U V
6G
8g__
1,T,
#C6.s
0fY#
0X(
JN$X
Synchronized
,,3C
p\H-
>/6t
w;-1U
<^P }c
cSQI
eytR
:Aa6
#NO]
Q]ZO
[tC@
=P~&
^agFL
[KRW
H.G"
EcrmxaABwtXNHbic9x9rh8SwDQq1i
~MM:U
B]d
d0d
Chd
h5i2
b$28
it F
5u;(
fM|.
[Pv)
nA Xd
:mhgGwG6
BtKanNo0p9BEOpo5JLNoEHTk8RTlZ
sg2a
i%R\N~
www.inkscape.org
HR2 6+w@
d
!Xo[
O~lLU
MQm#
F<pa
^`=s
8&m^
>.p0
(<v|
vAxm
N 1&T
t"
+o"o]
v;OV
k' b\
PTW?Eb+
M&1@
ocWz
e6y o.
ZQp0
UGl00G^
<(V
<37X
] ]c
p?,8l2
tb #
D>2.
p}~g
lIs7
rB|Q
jKnj8
0MPF
kul
ud<x
j>TY
u!U*
#8(_$
;pybI
XYu|
opr9
I Y0[
@D&L
dkrF
cphU
p1c8
EB,Q
\,B1)4\&wB1{"Rr@iH#ZOzC\&}B$.resources
.rLP\
2N91i
;2 k
2eiQZm
@<)79NR
e/oMY
jTF3
&[W!
m8qM
Show
HC8W
mQ`O
O<k>
6-3j
k]:
&lF+
llNL
8[7b2f
<4._e~aX
zOX00YwpHi
il.M
{VFg"
;I[l
K=~h
${@"V
oP,)
ja ,
z+l
,eM-
O;B q
O) ?
iPa2Y
o`r0
?0S+
VTbW
1 Fr
1j`GA
#Ap Bp
uZUH
g Ol
\ZS(
Vr/u
mW*}
f/5.
S J6
j)af
blK(
$yuM
cgBf
*tsi0
0XadYE
6i6C0
'{
$$}p31
2~b{
L$ri
HO|!n
*q7^
%"am
g<9swb
M1TF
aOd&
ZH"5#a
l)0h/Y
lJ)E
)$R /
HM6PsNPs4/
dY, u
oAKF
icW|>
n%{R_>
f^c>X`~
a B0
#&?Mo
4b<J
L7AL
L10K
n)IR0
xCE,
)T6#$U
lnCU
f[hZ
Lq[)e
'<U"6
uBxd
F4(d
u+;>T
zHz.
n4Z^
AbpJ
+T3Y
zHz'
P7|B
0%_:
G3)jK
O)[o8
M?yly
G6M{
yh@
@Pd_
UNU5
@VQ'z
^,DZQ
8J8F^`o
Ik-zU
HX^d
xK5,
5di`5^
gP!"bz8
/O.Q:
p(GFN
0Nv6\
<_}c
< ^F
i* Bp V
BSJB
2>?SO
X(P5
f ]A
0?I/
Tr~T
Z K(
M b
Me#Z
7;L4
R&+H}
\7$K> 6E25
: hMH
j<8,|
ImS"
\x]/
Td`8
OI fJ
7,)T
Z }dO
|#{t
&lc"
,-9L
>.5Af1
un;y@8F
J=u
<)*)
:?xFk
(x[Ed
_H?$
4ab%
4CBCS~
fz xu
s;
+I"@
63aY
zNlM
ZBvC
aQBA&C
f x
srVB
wK R
4 rP
];#&
/]M=
!v_5
g"3u
~#fW
,*:>J<#zDlK
4g@N
N@ r7KM
ul'q.1
<@u!
AJ@J
\ ~;
m}{K
(qCn
+p~-
FM:MG
*=>'J
8QUpzkIfrZZaQsMRlWiweiLsY8BYR
@K<}
m]Ys
T[eC
(UHS
[ZO
pi}x
Y<p+
t^Ih
:9;x
}mNH
0?\`1
Eg`Qb_z
8KW
4 "g
XC3d
RPT.
r5ez
nW9P
e3f
_i~C
7>kQ[
'm*\,
nh>g
RI,LT
Ihv<8
|CC ^
cc>X_
*lIM
:t#4
vCi
E =,
sF8y/|
DWLS
4KYF
tZ57
O07%
g~B&
P;0
yLRq]R)
t2 lZ6
7FEU
@?B.
E s$
mF<T>T
U/Tl=/
uVT
al*3
Wgc.E
cXH1C
=-t$*
[M,g
Q}Ao
T|Cpi
12pJZcJEXUIX8QHiLWSYmpmOTlfrE
')`e;
(zM7~
_lh(r
cKKGVN
Fqab
k~X-
t |Di
W[r1
h=-h
3qwO2
biY{
- 6BH
Ys9jd
jy-O
z6w^
[.dft6
wt Y
B?Y{
yP] &N
s ^h\
fviuY:
4hfU
@}"<
i(-6
l8h@
\78d
}xb%C#E
RcaLR
BWWq
}PN.E
D79fj)
(=b2z
o P2B
]@}N=p
UBOK
^lJU
XzSI$
2c9F
]oc-
[ c
#} `qFHeL
A<(Qx
UnH~
PIIp #O
Yzf*w|
3^JZ
ztY/J]
o*Mh
"p3*"
8c>I
a! d
BB~xwb
/j #utL)
OigKM
ZOjj4J
?OJ w|
~0|
3V1|
]u'v
t^*jr\
.Zrv
zed<
n'U k{`
Yb@L
nb m
}-m#`
]8#
)9mq
#!p6
JNXN+ mW
Q\F&H
_=~
%2-1
O nu
TXik
6D6+
CM0T
_e( |(
P0#J
Yn;/T
=RNN
OY< V
87]a;
-cpXslUr
D4'
R Y&R
W Xy
:I)+
P[~E
D`uU
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
WV$r
vT&PX
&oY }
&UPO*<5vR(F_
f#pN
\$?IV
2 "vkMX
mscoree.dll
y QB
V.0h
!]3m
File
!LFR
L3({
`xl|
.7hd
MxU 8
@0=
K8-y
xTe O
mYU
d@L:
)$8<[
{ssr
:/&A
gu*yW
HKU2
Spb|O*4
TX68
W_#4
Yi>6
P`9xY
L71X
$7:0-h>g}
CdnH
std{}
mp*U
1qVZ`t Y
ir&;/
2|,]`2
*TQDV@h
%P|
wi<S
6?y.
j:jT
kv#f:
h'_aU
u{KM
HXCg
g9'a
A"?>
aV{hy
.PQ1
K6?\
{{,%
)qr}W
oWy\
M av
]Qk.
;|$q?
zH;}cCQ
6`ls
7Mbg`^a
D kj
N2WH
<Ftq
2&x%
>D'RV
^ N{
DMGyr=7
:{,]
Jk#Q
@>6h
@c"c&
3x|p
=z6 Xb
Gkw[
;|&4
S,mnL
.6Cb
a%
^mI
KY'd
Button
YGFKP
mnR7QAN
A<%AD
e.C>
? 4v.
O[p$U
V. 8
0)S,
,5*@
` R)v[O
8n}~Q@H
jYgK
R#ms
oMd|7
H0{
Nd/@d
.Fkd
5L-v
k k;
]5B<
v7t?
ZS*>B
XgJw<
_?AU
R\*I
.?qS
s'`* {
wzLA7GrxDLrGRiFEfQwKsHv4XQlHT
04RDG
y L-:
28S
3LBL
'Hb|
f IYA
(2y(
s^(a
&{St
h+Pn
Aaor
V`*A0
x5<j_
Jl(_
%?@7
y E7
c2|$
N9jU)
,F~F
?nReT
lV\J
d4ey2v
=xr/;3
e_3X
0l"q
@u-0.*
ijt.
G)9c
Wyq17`
<O[{
y~_}v-
H#_
UeUb
86,
On")2
W;0C
WBB%}
xy p
? M#6
uUK3
swAf
;DLI
{_{`
6#B.E4
5#R4
.?qx
|qvI/
Uk><
l$K9y
@K#
3g
t a/
I8=b
HJGJ
L$_J
x|wD
O"@kc
#R)j
{G{h
ma%
<`Y e4r
Qi%3_.
::IhT
yV;iZ
J1<.
h;Mr
aa*o !8
R/Z%x
2uvPGjePRhATO1q0BmrRUBLpKebHc
Go{CvcoL
$xQ/
8cx@
e +A
aC R
V vBfL
pcP ,
;mM5$
m:n
'KV)Ot?h>'m#
=[_zLB
8W_Bk&oe4
~um-
_Ysa;
LB*Jh
P("T
@e&^z
;Y''X
B,}:
( #|
&eyV=&8%
5 , ;
lfd?
}?}73
8?J "
1phX
Z1zZ
]~*2
xbCds>
E u^|
?CG{
O.#ec
Pmo
? kR
j$sxe
PAs4
s4EXN
#($$d
!I5k
V [Z\
TOai^
YcA3
^xC6
JO>B
43o;yj
d@NW<Ds
`0a^
r(Td
*t\V^
~Zr&X
~,sS1
~L}.
W< [
IDATx
$8<;
^M/;
O,Q1
8\ThQ
*~pR
p[,v>
G TBN
QK~Q
\nm|J
Z6jr
t[.!
DNex
ESFgl
}- R
PK8>
V|7
eGV-
)O@"B
N%5k
M?W2
8F4R
2lat
oy
yOb rCs
u}IuZ*
}jjM
xnKVTL
kULR
yWtfT\
WXr#
/#l:
w` EZ+)q
O@Y<
mO+O
O;tr
*HLk
!vK>C
s_u%bzB
j<Y;
dl\ U{
1 &k
674
A^R>
tl )
CX{'
* `j<
IQU48
TyKJ\
ipC
/A>G
O066
9)R*
dNH]
AHh
&u#}
s-Ss
5<40Z{
dwB+B
K >4
jV&r
a;V3
-&t.
)Uiw/
'uxH-
rh ~
gx9 K
czJ
TFQswmS?
lIm]fN
Y2&)'
WL^t}k
%H]Qt
9'Y?
+fS-U
ZM0U;sY
"@W-R
_Q,O
:y4A
4{r]+
lq][
oGpSa'
&NnD
2 3T
(z&u
H%mPv
\&GC?
F5'`
xv?Mnn
j5mR
C%P
=Ssa
'jn:}b`
AY5E
#]GlzEJ
3<O
`J&I
sU0q
V>o_
?sf5:
zI,3#
pqW
p+nI
;-.;
vVPu
o\@[
ymP9Q
e;V_
u3A-
"^]3
|!/lV
W7# N
c)?
vVPX
,(0!
6}KVlL
v,/0
k&XK]
F'uvQc
}VS
Ct 0
].GT
[gE:
'wt0
2c72
xdR
&eBv$w
?TM1
v Pg
h %mv
U,$?b
gpf\
;Y1{
raMVj
$BEB
Qcia
_UTH
M}hD
e?]u`
h, /
*<]0EB
;Ikt
Qciu
"7D7
cq0i
G>r[
y~/
O G
N %F
&{o
lrdE
94`f
p5{/
}M D
xg\K
Pr`6Dx
]i jA
][1F.!'
lcF0
CRh@
Z F"g
:'t=KD
g@jo
7b)M
..n^D-#
z>;l
SPc
yBoq
wk:Sf
h U+m
r@*q
7 G,
F?~|
j~WU
/BM;
u^;3F'
7T5$.
[*s2
" sV
k1;0
cYJ}
y2vDd
yNM {Akn
$y9-
C3{D
F6F:
/cH@
2>{N
c;uI
}7e
jwy;~t
a k?
Dp?i
gydAFX
DH`U
o !
'9\h
sab_i
uT$T
* 6f
KP(S
:0)5
~;<S
N#KB
02 G6
(o[K,;W
d.=M
`Pah
Qb;\
HT!
-t'k2
d,W2
a%*2)
W+'Hy
vsS^l
,<Ma
z9g>
s t*)=]
-i.tmI
l<fO
$pGe7
5)W"j8
Gk>Dzl)
/kBg
&B-'
%B$?it@t
MB{-
$CX%^
GH|A
v[U;
K#k
h*P?
3 QE!tp
f z_
(*Iv
$`(0
u>D`
VjoS
; 4D
0Ax3
u7Pk
/!Ezr
~7se
>!*j
j"iR
=ZT[
bLycN
=ZTW
|Gw8
~Gr|
$6]
}L1:
5!6
Z wr
eFi$^l#V
cPr#9
5=4u
_Gh>
n$I/
Z{%!
!;0kA
Fu2$.
;N\q
*Q?
)4'5-^$)
c!h._
_:\DY
d-W\
9/>4
Hp`]
> |
sER{
1e[AW
ROm%
sC%Mmm
cZ9U
(hGT
xY4Brt
QlT#
5V%%on
,N)!
e"7mZ
6sgr
5<{`
N)p$p
A-tt=
R+}*:
Z)0R
61C
EOR.n
hGJT]H
MxE7?%
t$rm
=ikJ#
Komv-u(w.
q/}*
,B1)4&wB1{"Rr@iH#ZOzC&}B$
f+:Y
DQPHo
y? i
9_m\
G^NL
[yYo
rEWhi
4T?^Uq
=_ _
| 38\
( @[X
k1X
16}c
7PP<
z4Psx8qKUMjyXOtwtNtc9KH6bQ2Zv
?9sjI;
5'8.
^7@
o+|Q
ku{ P8
YB U
ob,AB
G6!c
OV;=
4c!=
MWGo
ZbniR0
_2]
v] -p+
&=~F
]Qx_k`
4wu'
YyE=
lU6
N7T(.
[\fA
M~`y$
WV>yK
fZk(X
d8Uk
>\C,n
Qwr%
C<b3
[HLJ
>q8+@
7:}
].
xUn&
kQua
=/Bw
a~:8$8q
c"~j
\~rV
amv|
"AWOzy
iSa1
ComVisibleAttribute
=%R+
KloDt
L1,1
=c-hF
G`7,!
BtGm
{&BO
p=Dh
#kTU
?n 2}L
5e_*
C_.r
.VtW
AS(y
,L:Sl
QINhd
vsh
<qG!
!))5
Fqz|wm
,aCO
sqvQs
]?G0
:u&p6
]i q
3vk`'
w_Jq
pRv "P0
0 q?
GriN
&&aV
gKD]
>bs2e
tH3C
!I m
p!cg
*9d"
i:<N
TVC0
S} B
gw5zk
d'2m3
XG_$Zl!h
HKJ<Lu M
'.L\t
;kXd@zh[
WR %
2012-11-20T09:03:39-06:00
Ju32
a! B
CIvO
A+> 7\|
9Nm/
-(#s
0(U`
ControlCollection
ed#~
nD a
5xHO
Ouj_
,y`
j/,X
(-P
,e,-
fK@ht
Ma"aZ
n%!X0d
K)T7,
8sj#+@
UM2<
7BPk~~
bfp puRan
2q!b
8mPG
tOQy
%R`Yq
7i {7
{Qo
1|1U
,,L>
{ @~
v= `
c|5q
[k D
)Yry
7# 3%wG
>*mb
^\;!
9lZ^
u1a?
YAF"t
xSDP
[yZ
w^7 T
N4,v1
=#c ;
^`/
5}gz#
DC]f^
/WN\
SG[}
9NL'2
^"7x
BMn
^1yE
.n<Y
vt9@}mD
\4Z]
EE<X
<cegbb
o{k
X6sMl
%ugz
gng`
>XRP
)Pg<
pc) 9G
W ,H
Kva%
XJ pm=
R5i3
h q+
v'J(
a&'X
EN+Z
sfe+
e9(/}An
g$MT
xhm/
ywO0K
D)~D
+MO1
:X 0
BdK~z$ohHjl2/<Hs8$PdwV/"#
se1<
'l>Hx
se16
Bdy'
wM\Z
#uF6
= @^
DZ e
>x;uG
' E\
gU+h
!To()
tlcp1
]h,g
D6bl
>-bUq,
] &I
U`q_
EH!
:]4'
blhC
*XX
a"N&,
?A2z
*"I'
5M3`$
v.?/
CPP )C{
PZaUUhbcmhuU8nudwE8AP6hkqzie0
tzOr
*v:j
9!YCN
a%$MC
/Y.#v
nNP1(
2k%<
^},]
c"6A]
Qk%V
{p]e.
H%yt
.G2N\ z
OzFm
+ZK U
?jbZ
FL cM
dirYe{
e WY
9"ht
PFvJ"?
C`d$
&('Qz
2Gp1n
1k>RT
W+HM
{, }X
Yl_
bp"?
<5 w
m\$y
<sDT
g\X(b
,-C
}9)'
dBzy
$T Z
l&enOHF
q>Al
_x)m
cQl7
,uu6
NMPcJ
' PM
<13y
&+*l
0.w/
3]6$
p(S*[
/'vM
L& 1
0# d
D+q%)
0$@
qACAE
3\PA5
r0rb
#iKL
C! <
cqRVa
X[";
tX a
hC$)6
N9a!|!
-98w
^aX#;
(thY
DLA<
TlQ[
i1cPcD
~TKE
% `3
P% a
hx+M
T)h.
[''D
(/=?
lN l
+]B21A
r&Db
Mw,$I
a~a;
SZaL
mESKt
!<dA
?<JYxJ
}_:{
< u 7E4{
$kZk
B#DT
smy8
z.T.
get_Count
6$WN0]<
J{8lz
NSUho #3
EGt
11Ep
} ^6
JV*5
<J 5
.s7Znp
v4eeVvAuOIy8aj3AWj2HfDM0ZvAcD
T%BLb]
V"vv
>R0<^
^8 n
6F#R.=6
CKXx\
y)\K
mw1%
3_iv
wjBM
G%$^
+^Bn
*HZOH}
M a&
Rq5
b*G=
uYZM
Cr`7\
'xN7:
!t(^
=N+rM
AHmqrFxuBl99eBAuy90oVllbTl0ii
D*g[
vxz_T2
|!+a6
W dW
cX%
ao0_
^+{hN
M(B6
=u[Q
Eh&8
X 5a
Ro@]3
<!k7
D)6?K
C4*@
F%8}
(wt}~
1WXX
mU: M
GICr
KdQ6
j} i^
Mtl|
zV?F"
(plZ$
n;bB
05Ax
8`ut
5d{#
*> .
|#B}0`
eRN.
]E 1
nH 7x`
}'11:q8'
<pJP
<s H
>xTZ
%h[$
[rNS
zGu8>
O#0
l;m'
a&H
L [L
0i
(S&
dp(Q
F"|f
T>
'<l
8`u7
7 KNu
<v)~
tb?wS
M7Vc
Y%FbU
}~<5
PoV#
|lX?
U;uw
G ye
CAwtz
G %^{
_CorExeMain
2=zq
=])Z
{ l:z
3i.~5
y<Cw
WX[F
E%V[
$"Ap
RJn3
.FwF
e9lsR
btup
k&.
^E
(;HV
s+l.
Uy8s
L==_';
!FW 5
.Px7
%#:c8
7DJ&
7DJ#
bRRq
eLN"
+%"G
D=j8?
ATbAbEV
h<#9
JqFYZ
*XbG
pp8u
}1*V
Qs30WVM
%Fw(K
<j:8r
y{Q o;
SZRv
CZ { P
MpX8@
T`zK
u5tZE
1JG4f
%h*!
mJB
IG'B
-]?b7
uLXD
YpQC
~5pj5
_8PvJ
=kJo
K=d&
nlk;
$cXU{k>
?;;I
CG7O2_
4'y&
4X+>[
EQ@N2
O\l5L
u" A4
f]2-
{+v}d
R~)
H8=+[
roii
O r3
;OAE
Q 9p
*Rv^n
93#%W
42SB
$$w0
|8F`l
)xMJ
)v?O
g $"
8p\T{
!Lae,c
M Mg4
Dx^O
47y"
zh)X
me DTO
>#y>(
y@H
d~rQt5
.^lM)
[%b"
P"d/T
T>0D
AssemblyProductAttribute
}qTBlt
Q WzSJ
'MS
<NEw
Pq.0
~T,C
!QK$
cVB@
# ,`
)1`E
}LEd
Du &
Ss]-
<%n.e
t;Po
nGO<07
2HN>
~;]V
feMW
E0-%c_
;K8
@/N\
%v7"
sM_q
TIet
Mmm8
A JZ\
0XpG
hXb)}2
aS.T
YAr.
^Q%g
ML t
SizeF
d)L4E
>JU3
t4%tNI
y5~h
!`\>
bg5/
pS r
,y<t
YCO'0
zcHQ
++8y
A-v5$
Oy0&
Ob-"
QOS
6RFl
w&v>
s-yA
iOW$z
*y-sG0b
.R<.'
xguy
#DLf
M [a~LNI
(l#
i{>p
9'0G
n%Tp%
p8[6
ML |
W wL
AxA$8
O!FY
7yfv
)1Ut
:0
R.9#
E!uA
SIleO
bNSz
ur#Jz)2rQ
Z{rG
md6\
J%=L;
f4h,
+k@7
k:KjC
/c-Rr
EiO
vwF9`
|XPn
>n,b
tgH^
aJKb
0U}e
d7i3
gniP
P?2$
t)OK
H*w>R
YMNR
Oh1$%
<6%k
mx +}
`ng-
L ?N
)ey5D
Tx1T{&
rxQAVjuAJ0MejyZsbP0a0bv5KQTpr
"U#6
]*/,
k^]up|v
-i V
bq Q>
'?!h
mR,jo
}Ov}i~
<jrT
6>9P2
;0fU
Qc
$2l+`
!@{M
t;!P
\VI`
a-,5g
SE167DURZYXmbE8grdsTKZl1z0xUO
Yv^/
EU(d
>1Id
>@TlZ
?'S<
IJd'>9ev
u~]s.Y
]7AG
X--r
ZDBz>!Y
i(#n
.5Ceb^
2MXx
yvTf
8&7x&
Oi'KkD
LL</\
vYW"F
%A"
:niEG
&.-p
Tp3v
-niLj
p c
_>$f
$c 9I9
~f\W
wGr4
L98D
|A^
sZ_T
t{Se
,k*f
_y"J
r"'n
`"F9p
\{g[
6Q0 Zu(k
* v`
System.ComponentModel
^.zB
[`?;
ri-^
0v7`I
MW=#`
HaQ$
.<F'
5Ab<
L36
BGF]
)2/O
,*s5
&cIk"Z
OP o
ZU L
~b%M{
Ob_s
g|^h
K^EK
UKFg
c=
R5#B
{wN[R
TM@
(;tv
#gv2
}/f\
>{2f
E%s8
QfNI
[|@3
"Wl;4
uZJc
)`P6s
#t9$
k;%_P
Kj&!
System.Windows.Forms
.IBS
oZ/
M1U>
ZoL#
9L!\T$
] {z
;+@.
o Mj'
Y."%
bl^
(eg8
-Gs(A
_ qD/d
sy_7
i4rV
5#g
)'PJs0
2=[S
-uoO2
_bcA
jg'f
Jkgx[
\is:H
tymr
wAf]?V
1{9zs8
1LHr
P^R4
"q !
tL.`
k}T%
VFC+
7Xa5fy0
DMK[
1'\H
9.bNS
eUG
v|m
{8{4
?x-V
Q/,53}
{#vU#
q#whN
C,OMDP
vq&8
>VVP
Z8z}K
0~AB
R(6
oh,R9
daFam
{E7w
k[w(
"D:n
S01Us
%P)-70
4, T
f-qb~
;V;+J
A~?D
&=xVb?W>:
wp E
sSxs
6N<J
~P5it
Jpfk
ConfusedByAttribute
}`f<K)
&x~Pn
Tc%?>
wwT#
(do6
Q#n[
k:lU
*Qlo
+`})
:(xw
@MnFF
<'e^
:R:9
H qW
8U5]0
&uAg
>k8%
gsct
$,lf
@D _a~
[jyw
FO '
A6@e
2HL4Z
|Z 1o!ha+
K1"Ih;
g?$i
c 9f
E"zz
a8u]sl
FX)l
gjz,@
"6fP
/!,@w
*j=g
jF#mI
xm1W
iy C
E5~)<
?'{4
sYEk68
F~Fw
B *S
wTWv
Ch5C
#UZH
22wg,
0+uE
*+p{H
Z,9
jtRv
IDAT2
1`WbEJ
TN D
ailuO
h|A7HK
!L+
![*rq
jz|
tc~'
#-\S
B U:-
'H1d
d\R&tN
*s p
JnHz
=)P#
@BpH.
-{+I?s
CompilationRelaxationsAttribute
mR C/
!|Bf
D(7C
X=XV
b?OGl
Kq(u8
)m+3
[Jy2
v3YtT
|$+A
f4h
bxyH0
V8fwQ
_c r
!b 9)
$~H`
2%-y
ConfuserEx v0.6.0
$"F)j
OFH+
@x_,[3
5Rni
G "
I0C9
`)7}
?p7J
}w]Bid
,Rg/
e:GqF
aa! 1
8o+.u
vkrZ+
8FF @
(r'm
+WPWh
8t{]#
P=JT
br:
X[dC
;e 8
?e{;
?>MY
z;h*
V~t[b3
atA&
g4S
y|EEb
BvTR("
'su"
:kFk
(U4RR
v{FT
qrj'
M <C
)I\) }
^x V
1JIC
&2 c
+:/3Qp
66 :
b}`D
|j w
;*W5%
n9DD
Wz1x
q*'gR
LsyR
Mx$
`>f3
f0 3
~ |
ngA9
ab Z
R*W:
wKW]c
3V*/
N}/:
I@2,
k72v
X x388
72 AgogU g4_
N}/$
get_CurrentDomain
pW.U
_xhhQ
Z30u
?\ nG-n
CIzB
Ehh~
te7~
#W0W
'Z&j0
BvL
0}!
Jac!
,S:8
xgwO
/z[)m0
~5!,
BvR!a
,*T
Vpc1t
0H_X
6+i
=4Msf
C:prGfq
:!Y9
pS_e
J6QZ
7qpF
WoX!u
-BlA:
zIy
ZZ-\
4x{l D4
.WF~
I$ AK
(@/ 6
ICrU
$tXH-
d -
Mq=0
Fjin\s+
22xs
CUF#w
OWa8
L.PoY
[GwU
*\G#8t
D8%
;.ex(
``_z.
#Blob
oy^%P
x)&>qd
},}'
m~)l
@,Z.)
:nR@
_ wm
|}^J7
,cii@
f-.X
(>Az
P?[o
ag/o
um.c
]Ohv
P*, R
|RVB:
2Vc:
iJ8| '
&9.M
&wU;
n>O1u
!>kZ&
0x2B[B
y/!h
$iE6
|a/Wm
bCgAa
gO\g
O_*G
=<^l
"-)
T!7e
T.<V^
# QD{
XtsYg
beB~@9E
LVra
@% c
2]RQ
sm1M/X
1X')y
w'wH
Vgp :l,
JT5!|
8oZw
^rw>,Y
3kWe
xhqs
PAf<ki
js K0
NH~'
=!}I
1p=fz
*wxX
H#&
7{T.]
AppDomain
|-c .
Bu\8#
&?wp
yW&u
lJY
i]j 0
&szB
ZN73
0>!kh
lG:#]
2O?B
A aG
kQ )
fM$)\AP
"'T>+
t X)
5(:>
%.,;
mkS`
Ms:g
X}5E
A+eR
O\9=
+'Tn>1
O !K?
:5bS
- =
xB|R
bU B
+!=@
rgp =a
jT[=
GTh<
|U%N
$-[lp
h)._F
Q\p
Y A;K&m
qj%kY
Vw8Q
-m=l
X8_@
^3#!
su=A
5 +J
7EXsbh
e [ F P
J 7*
O4gC
qv<9
xpi]>
!Mznw
9XvC&
Ru2?
0X}
}DW}7'7(
!?>7
oB3
~M~
{ #a
ay)d
VuM*
qW9V9wOeeEGy9LOm48jVVrjBlx7a4
b6G;
7.b,
g4i!
'Hwb
/]}
r0LmlQ
aQ_1
|eg
K4l -
tbH!
p"Wp
?$xg
"n/]
BX2y
;E%&
O. TN
ceC[@
l =1l(
ueF/
a~2t
0n D;
B^S8\
CN?o `{s
I~Cq|
/z%J<
W6Cd
xEW@!
OJ%LK
drQQO
a<<5,
X^ Wd\
^(
ud'<t
b1g/
gBB?
0qB0
BJff}
9+ >
to]A=
e**rr
3}M
9FT_
yZ?#
~1*s5
v x8
%FHq
&$~@
e['C
C88
gyKJ
9=Ql|
2qwuT
JV&J
^Zz{o
(`JkT
@;Wqj
p:'U
1* 9
\1uV
XD$o(
C|ZG
UCdO
;$"x
(v,,N6
r[87
WS< O
T,>>
i0:}
r%<8
0>y
Md+M
^>Z
\Kg-
YI~Bq
EMmee
p !V
\}u>
]A<rR7n
FMo\k
xr0OO
YYGyqf7huAmYCpCISj8foiEw4Gzuq
RV/>
LuHl
:Kh2Qu S
.ctor
+='fx
Oty<8<=
'ZQ3
LMIv
$0)Z
,dS3
5HeW
O X6
'@0:
Form
0(0f
,Jfm
B})
L6Hm
AuLh
VqAU
z2h+
2A~;:
zMKL^
lSRU
>Yl&
UU-x)
#RZu
{K_&
4 rR
!Cx
B+#@~
CultureInfo
LV0\
<|oa
,FNa*
BD=#
K,k&
g`og
F9 ozq
i*C>t.
g//4
qUq
2E29g.
iQz9
1\GMu
&0BR
9Hm!-
Mx5
`4h_#,
"=2p9
:6 '!
[)Hr
Ce#5y
XFDO5
?2 p
n**X
}fz;&
l85B
eJee>
sWde
<Z0S?
!#Mm
y9}u
_37
$>~q+
`W!
}?0&
6g<~e
UL}M
`2R]v
1j,nU
`#gi
N5 Y
*$ '
|NZ(
78&m
{bhL
}Akm&me
G5;V
ks@C
pa#X
;:G&
?> wmO
(vl?"0
7%@H}
Bm'.p
B+[?f
__8%
x uc
=t{c
/Nj[y
X 1
#dO
u#46
A[xb
I\8
jI]H!>
1X"{X
J9 0
{WWV7 o
9T0lu
!6p.
h #1
u3 Lny0V
-j|%
061t
b}$^\
loXT
}` 34
+<9q
~)'>
# G\
QFj4
_hK]
mcAe
System.IO
$Re2
PEgA
M58@
pl_u
JzT_
5J7(
a-C<I%
'U{,J1
M#&x
" +|
%WK%
TU]Y0\{A
]El .
'wXQ
d O[
N~ L
7N_?}
{B!4
S=9t
aO/jY
uK2d
CwV%
DZi9G
j\+H
+m?X
i_c\
u9x!
|# `
cJ C]3
:&8[
,"<.
ZwvR<_5
<MA>p
uKV<
j @I
/!g;a
P+JA
ls W{Z
o(+S
0E6pnuljczCRdykhmGGX1KrSKhvsZ
BMxpT
`< oc
9 y@
Of f
=Q9L
+a)Ad
jTt+
fw3[|
z@x;
/?8M
q3 i
IGbv
Qk}u<
M<+
lyspz
J8M5
F\u4
~@DX7X
-*0h!
=E#O
?@)
fZ]k
hy'rx
sQ}mk
?$Se
?WX]
0GFmD
_*~{
8NM#p
Jomv
c?*H
7Q"ul=
7O";mXjN(
Yekx.
~}5=/
h)E@b
9$0.*
}i G
=W/n
o^@f
]` tS0+4
UozK
?|n`
]EhK
y4R~
Ta&
anwh
q<rh
@A}^
iie_
I'Yg
J6./
7Qqi
R'2f
zQz,
e`%#
g `&
nVr
!OaU
gL6t08Z2AnIrXK1uZ5gApOhmycd78
&$cg
^^v(
j]k$`
zz"U
& y79
H&+8
3{iS<
lR%e
^78,
0}O +
3 Ek
z4.x
_xPb
WJ2q
BFb~
'/$F
Dvqh
% t<
Yda4
R~w{9
L%$Wjk
j7&
o 1J
@ 9v
>|9G
9zM{
}}S(
*9*)
s830t
]&OE
dJG~NkU
;O}H
G% I
}hl
F+Rs
E+~
{,B
zU"\
hV;Ko
cvS
iN;r
bG=KS
,Ty9
System.Diagnostics
%(d?
zIKB
FZ35G}
%e~
!KT}H:38
y}M
N23K
e FI
,>[b
TM}u
2Oj'
_a~8G;o
KO
]J6!
`Uo_
i}I[
vauK<J
nn>.BI
aIG}
%SnO[
.CP:
/H@7\P
\0Mab
4&ciK
d[5"|u
7xmZ
yM1d
G!Vb
G b g
zjeS8
fCt]7
C-~L)_
]WVoO
&-S`
s@.'vTXy
kQ g
D fF%8
C\Bh
_jxM
String
];6{#
<0d_
we9~?b
set_Location
Color
)Y.w
3ra
|j-MQ
O1Vq
)_,H#
" j*zbq]N[u
]J6_
_Gf4?.
SW?yM
Z bB
. #g
K<WF
`L%c
*#*6
0k+."
Ud&+
Ei!5:
O&jh
V s
Ux|&
!W#!
3]L]
q>+GP
vQt\
*yTf
%i7I
Piss2
BMXk-
FYv5<
31U
\Sr_
,m!>
3 (R
?MyD
8xyu3
Q'!-
TaY,
?Ey~
98 _
H`C]A
|- F^
ga8R
>" g
WrKP
yR='
*XCUM^
|C#=
?d1r`6
@KN$
P8Xj
'<.i
FG@t&
nB)*
HMOZ=o
y#1S<
*]91
RhR]
h4>eO
6z"v
w#'T
L/E0
I}jkqZ
Pck'
^TAR
0dk%
k3bB
DHOHi
0IZ
oR{ *
ncj8B
Ubd-@y
>(!.
DHxj
S9TH}@]
(`/G
|,|z@
<-_@
.qr2
UjDt
T1>mu
I70O
h B2
-~p R
5zS7
u&L{
Pif
J9ym
~WMWP
@\o8
;):A
kFVY
Ba&8
$Z%
JQD>g%#~4
w+X
T_ I]k
S]gG
]uB) |
.""a
J35~
CcI0
vP>/
'g^
6!Is
*Um
+$~
%TA\
N\+T
eR0N
x OW
L{V7
xTK^y
r?s
Ow7x
.gXB
?7tg
mjya
B12"
C:"
<A _
g Qg
rB|\y
}A<7
i`-X_=
J{"p* 9
go<~
/&<^
wi9 c
rJ:}
C =
f4fq
usgHQ
R3`2
Tc0n{z
8Ft
L-E
IH{Y'
)_=2
wO6[
JwJZ
m(@x
y.^&
b;?.
~w1R
!-V+667
9KNV
o?l3
73 C
g5f%P
^O)%
FQZG[
C+Jl9"
HsV2&e
h/.<U
sx+3
0,49x
XQq]
'WQ[
+ro%
\J a
g9qp
~6QU
GGN#
'l#.
8Hoj
R voF
]Br}X!
hjo#b
KXph
!:%
7Kxx3D
^Xuw
=Z\>
Djn>C4vX
GuidAttribute
Vn&S(
]X]'
}~4P]n
M?z9"g "$
+r42c
Ff23
T~SYs
W#~i r
&O#-^
r0Q>
>tM
xF;Gd
Q.C]
n>U?
%|
, [
sn F[
}v'N
=Bdqx
A%Y]>H
]>T;
Obt0B
)ES[}5V
x8tp
H\!|MK
*lX4
< .=6
Bd9X
{u/L.
uAy;
3GK
dv!CExP3
fvl V
<Bf(
2?t
1D0'}u>
5c`R
r6G@
&F'A
4O|3
9jXJ
|!6`
R.gH
q^t
b\S@5Z2*
T?G)
g0:<&
k<.
a;Ct
?*?8? L
oM;h
P$Nv
@ix$.
+ij F
\bz"J
;:IO
A>2b
PO_v
(JD
}@h_
sf~s
]6$n
V>+$o
[vP$'
.mtB
HBR
4$
QM\z
FfahH
(Lq/v=
b K' 8
'$1V
WQs
6(CE
Uack
'+FE'kG
\7L.l
0 ro3
Jd(
)Sjn
Sov2=
4 D)
DINs
ICryptoTransform
:m`,h{
I[,q
gY$Z
E]l?
f^vR
1b]iG
d.{E
jhMn
? (p
AssemblyTitleAttribute
UsPW
* +at
-#}4 X
rg$^,I
1mf*yT
-:VbsgQ%Y
}FBW
L1O1
v9?)
l' @
t/ZUx
hGF
lrJJ>
=:p/
%sT4
j ~F
Zt[
hk\U
add_Load
!<y)
/zL1|"
%Q,9}
PUlsa
R+6k
kK88
caY(K
w~,%!
lV $
dj;i
NY1$
qsEr
;[ ?
1K<G
"e=z
?|R,
_KN|
s=_*cZ
X@pt
x^KI!
[qil
%$"9
\#7D
Qo
Oa,f
#Ip
vw8u+x
2E3%
he#7E
ai*H=
VLGFp
tnsw
nFxvh
cJIj
ESD'
=8nQ
!Po ;';9cXv
8Da 6
_f^)
3#g>
VG5WJ
tr0M
m?+%
9{KE
Z=I\
A+A#N6
9zgb
*(To
8S+2
1N $
3yjf
2OQL~
ir$,
<t.O
jP3&
5z#.
B#r
1}r&B?
=aA//
!.>
wkYF
b`cddS[IG
&hnUD
S njw
#c*x
Xiw|f
w6U&
_%JE
RE@'
,_ x
:MRZ
cdaCaHIgNEDbMx29vsUMpuNvmLzY6
l_ Ia
:w,K
PC29
u@of
rLc}
KXN*
/aGO
fo+3
vw\FM
\s[\(&I
=X4g
[KC/
Mtv|a
c:<<D
%>t2
Tci<
O"f)8
Q{XB@r
nlNY
FV $
?:Kh
%V (sz
8`;l0
WrapNonExceptionThrows
rt G
5? FUP
&05?u
5.,
3Yj<
SE_G
U"XQE[
q< &CJn7
o2n%
DtW:
bMMx
l}Rv
>^D!
oaUz
d;V}m
zM0
'oCiI
!b4F
;%?kQ
SEqf
6=T0
[&:*
d-Bp
)<lV
>k?EX
/XY6
jm=K
#>J8>
/e&T
V S_
!J'
m s={
.9/2'
>Tvd
q},n
^bpS.
03D\
lnfzd0
_1OX
=p':
DIQ7
!jo2
6'4^
Y\s
>'NKtejlD?
0uZ+
fdr"bk
Qoa)4
Wm%&
\?D=
Attribute
dG[]D
(A[m
~e<\
, }9
vbv
AkDq
}lnmbs
(Y[h
Cr0
j2!B
Z>F
^n,&-%
i7sB/k
sIg0L
Y{
23s
$_}q sHKj
MessageBox
>
%'Y8
5fE5V
f B37aG6A)A
AG~R~
<D8 5{
E:<W
RQCX
MX;c
(13
U=5#%
Gr4V
@55,
a~>e
c75*
1! h|
]5uT
(}Z77
&0Bc
aYDmBY
lR)ng
%_3.8
_@lG
3uXn
coi00
>b#:HZ
D eQ
Hh 7
u[5/
'P &
@"52
dw"J4
Bh<Ks
68%zLK}
6HY]KN
`8`o
|P|#
niB,[
PO5A
zm3&C
%@PL
%3K9
D ]1C79
Assembly
d pH<
/ANFJ
LDkj20t
O c+
,os|
+{(9
~6 '+
oHPe
eH6s
EIp'
vCP[
@}\Kz
2^tJ
_,m.
m_=}0
J"FD
[V6V
SuspendLayout
0_9f
q^m;
vAv;
Za8?
wN02
l->`
h6i`
@%_z
!78+_
`M'aU
-H[ -
lDs#S
6XCS5 D$e
Za8'
d0jA
2gd
sAnO6
mb? /%38$_
|R#<
_dCp
set_AutoScaleMode
a&B6
%rA
cX5MO.v
ZLiQ
$`2]
{HPXq(9
5lsY
go:|
f<PKl
0VWb
s Z$f
TI%D
I#Pu#
1W|.J
?A(
j#8C
TI#77
Jhe &
3css
Z#KS/\
:YGT
Ee'H
YDAI
E^y|{Z
^@>
? 3g
'&j,
wxkgo
k7l8
\^^^F
<!c
"^oN
<fC @5
Uta8
~%G"
V/4JU
4zU?1
s_rC
lx U
Bw?.
|+x,8
H{].
1fOM
Mu N
}tb{
^k41
e4`
~W3kg
1~:9
YJ S
^Zu}s
#> }
ZYrw
%5doa
In?{
Lr|%
z0v`
^9 ElR
qd o
G ?'z
I5U)Bn0
'-/C
fr'B
'ksK
*>{C
*pXf
ZHUj
AXv
z=_4T
YafLA
d9d\
REur,
v)4|+n
T&Di=7-
8[[%3
GdL*_S
'P OV!v
| 2wi{
V CV5
:?V
BOK[
'.4[
w'n$9
L c)Z
MT-l
}:f>
()0_=
Y _&
8<%r
stp`t
O-9g!
zUoUj
mhRPd
A\hQ
+bA0
kOI
_,UX
9uV4
9F&Gs
@]5v
_ l+
lo3r
0Zl0
{Pbd
?t`fF
k56\
v/H.
jS{gT
a7oT
,H (
1V9K
8nCX
{(6C
q:$3;
"!,|5
X5=m
hhq?
w=X
Y(g:
_9]]
,~u5
];[jEd
Ut\` !
f4g\
6WJu
E/<A
}_st
2d|py
3#-U
xd%a8
%@(w
O_$m\ F
T:k^(
Z(HCa
ZS;%
Q|nk
q?*i
>XG
rOb
EQl
"|D7
AssemblyCopyrightAttribute
oH(M
m(5Xk
G04@
=i=q
T5*cP@
rAT|/
b`Au
_j/~l
<(%QO
2Og:9B
_cNP/
ghh8-Q-
h6i#
{4V To
H3YU
= bsU~X
; zD
@p
XIdHl
hM!M%
?` i_
L1Mp
c _
pYCi
qn)y
9Ol
\'%\
K>pyR
[`Q0
,M'1y
O7dZzq9rRnDE436lO0jKy2CGbwLqF
TX~chgV
qQ*y
P !(`
LYLH
a{4^E
W"-
j, 0
MHtf
'=FpPf
WnAH
0^`U
EZ-b
wR| #
d|xH'
nIZ
J7lY
`WZvvY
\:2ZM
s<" F
uYrW?
&r!D
lz=AUD.Z
{k]ok
n\C5O0
*x1X
{P5p
{:__@2
l\rT
.D6o
gi)7
0!p'-
cBF=
tCt.
}W'Z
a"00
!As+
Vd$&
(G3V$
}9]h:
k|6l_*
<S%o
G3Q0
l e^M^y0
>.9
@>@[<
w}c-
lhh\d
A=J;/
b4zQ
~Ex`;
Q:Rj
Q<73
An3F L
LLDol;
n q?~
@z&#
?<o`
/ j=
!1I|
hp4M,d
r% w
5Uee
+#aC
4+0h
A$1`
:.pi9
YO/u
Jac k
6|r%c~
D%P%
{-{o
`[paE
-m@B
{5'E{
z+V C
`5/
:Is?`E
j~Fn
#1s
Q0X$=
ON3
cahU
wbaT
Tj G
LIjjT
k`P
8>XoiA
% Z%^
01 .
{t6M
0%tf
F |g
VO.l%`
O0:o
p:kdy
\ q
jgI3
\\KI
o' 9S
^KIP
Ov#i
Lb$b
5>vz+
. S
GG;nO
',f<
;Ob4an
J[.?
t2'Z
+ Ts6
KVJ?H
b+65z^
n9*QuM;
jb~\
qE<'z
9&_G"
%$+:mS})76
*@Dl
2]X@
[iw?=9 i
nR^|,Ays
bVg!
7dY7
EWJF
C:/m
[3t}
wQDTE
C yz
uWn8
oV|a
IW:;
2pe z
7,F{
-0N53
2H>E
KnYv
T`?M
)O.f
Q4]
(}Yq
Gwjz-cm
u_p`
kexj
5+;O
sGji&
Npxj
-i>!Vt
w3-*
LR`#
4V^`
@ z4
;x8U P
j;J.
^Ztq
V[8o
0ET*3
.1(
Size
b"dA
/5^X
92{k
"WZ^
I7m=U
eKA0y
&>KN
0H-"
_G$1
K3NP#
Js&,9
\{XZ~
arbpY
oyu&
&O+
&PE]E
>a v
_*YT
Lfve
aum%i
{j&
p ,rb
K) H
>=,i>WN
p8 h
vn:29r
l#.m
B&eo$3
+tS}t
Yrf.%
Sv nl
ii)[
oO1A"
e2yv8LcfS5hSAIMemlhOnsQ45ZxMF
NL `vRw3
[zbe
n]:u
#zto
3%>
!kF2m
]()[
WHX-
\[~g
ct$'vB
7jvt
,eBA
QU}
}K}3
U Lg
F.Za
<c
HwS*#
I|3!
q@q$
z5Mo
\4l^
XAJH
Yp|g
M2U;
cJ%7l
?*i%
}V0Pl
~diJh
~xD!mX
A\G]
_s6,
Yyv9
Ure`
V:Fd$/
>N d
{H6;
yErB'
.b,TQK\0_
,vPneX
P2N2
-&#u
! ]+<
Rj~qHf(
L8 Wd
?=)9WTvU]
9BQz=7nO
% 2Y
g[*+m
I`A~D
p:!U
<4\@
uX
;m\I
GhP0)|+
jKUt%
F$Pr
;_.OO
Xw W(HY
7 BJ
Y@7k
?zhs|
[+IO
8_[~
iim6r
CpkG
I}NN/
%45a
T|!_|
vk{I
a[|,N-
x.$ u
cfwQ
<-8~(
v^iJ
.L T
p /h
S"u6
;x;l~
[MLi
-R=k
k\?J6
Oc~8'
jh4
C]^U
;g#_
6?*.q
q]{3
pAIg
WpQ`
eo%d
M4h'
,?!8e
nAZ
}0ltN
@!A5
H`mR
c#"*
O%N>>
yXjA
K7cfW
( P9A>;;
C-=;+:
mA*
Qn~Z
KrfR{"
0:3H
1Mce
vmbAu
;x~^
IpI+
6O@_#
.?Rc
%IOX
\m\IH
[w3
+` 2
i:)KK
ve2LAt
eye#R
N6,
VbV"A^
AEL9M
^H*3
M;M)D
7q I
IR 2
{}37cu
n^:d
N`0?
mbu=(
P;k]z
rM*B
,4%b
7:>S
mhcq
PMQ5
UrU R&U
X<)z
* I
_; ,^
%B<'
%q'e6Q
W&GV
1Q1-yloj
<,>el
Q[ !
R 4&
Kes
oEya+
luH|
!G)<
)/1
)I~xu
sI,8
aKg3TgE
\FkVp
TU0,U
OfM1
-geI
t lp.
cd6>
44eJX
T$)7
n3+"@e
45:_
'r16Q
R"<t
SW a
x,0 Y
D L'
Xy.]
'8~;
@4x8yQf
BUz'lN
]b3{
K-8e
OFPw
r>ky
nGD#^
cN*^
.0"h
srA'1 p
Y=:
>V}[D
Z$Gsj3
>XE;
X '^
8HL$
Zzub
rLZX
;=A;
b2N0
lE.vu
I[nj
[! 1
(?0A
G=u o
{zNe
zt<:
67 J
'(el
Ox#N
SLWVu?"
hWAh
}LAeS
Ee[}8
pO=
h* $
Cp#
NhV{s
3 n*
f Q&
:3&m
49"CX6
v#$
/TL"
Oxda
9s/F
e\nX
YH(J!
Z [
\]bl}gg
b Ht
I{5;
x3q
wqX_7
>3rw
EX=!
}nU
a$c +
CSk<
C`uw
{K:%
uX;+
z#PA
E/z
?@-ao
lX27#
b )
CS;L
LJu"j
i"*xb
4MIh
]~O\
dh Yq -
KJ/2 !,a
]6r
y3#\]
LugI%:*
?kmZ
NY5T
j@75
A~hg
0&ve
LI_R
N/]m
QgKB
Vh)'
T'-^
7P(|
0p!:Z
PF\Ig
Dt-A
>Nh,W
etNHabi
=idD8
wevn
Uo`}
a=rl
Yn&
'u.7Q
VwV `
VLn
"t}LU
Y_Qg
7yhk
`T ^
\~Rt?)
K\NJ
6;?p
m~t0
LhQRE
ez!_-
R+PmX$
i:HP
u"|%kHJ
5.gW`
bphI
)}gA
Create
A}"_K
f Qj
ZX[#gK
)@qc5
NpTA}
5 2~
{d_=
Qq=/
E+p<
rMI,
Rr&dS9pl-
) rBzRl
"&Vb
>w w
.6!\
l73Q
r=/<
'(''
"z a
>N"s'
Oe2
Y#ud
2>+nKd
4`F[
GrhREz
R1I8^
aXG{
=!0L
.:EZ
*tM {
]"W
)r90
%B_|
Gp^E
>qQ,
$^{z
`?=EV
v'^J
;\FD
a9V
@F) f
q)`a
8Hs-
aK9qrEytBd4CcgnMdoU06C1vWxvdN
ZrN
c]O
j o3
g v58D
Q)xLPW
>yE
Cr+ f
VqZ
7 oo
XSN%IHi
`0L@
;%2bt
=qkj4
E?$@zt?t
{Z"925
G-IeM3{
T4%gB
iJEh
5=%p
JQpbG
&n.(
b>Zw
U"8\#
=BG-
lE T
|nG<<
Q0-y
90O
0mpO
'vak
a[%cQ
s&m;
pP`
V1 OY@d
e,cb$u
J $uM
%T5m
UN`{
{!l v)
|O kL
-[o
M5{e
R=X
rNg81fPooGWXVy5PTK8ki0cmsL34q
smku
Iz1g
zAA!
"ks?
V[Yl.|X
'ip$
ug,E
6&hO}
-%Ol
u-GEs
Jts)z
GaN'n
? _
ARCN
\>;u((JF
ZP]*[
CteW
|N$<
Nt?C
.Vx:U
vU7~2
JTyA*
Qfj=
j/@j
wq,L
List`1
20%|R
AssemblyFileVersionAttribute
~I.b
qE Z
a <@
7):&
s}!,
KEn
v?,n
5mpjQ
8+uTx
System.Resources
i47o
'VGIl
)-'
6vRm
O U0
avdy
9K]o#
xrnRGH
mnxZ
=<CVI|
Vxv(9~
"cqxVN
g6XJ
bGyJ
Lq,>
fUu
3R`
rh$ cv
u+${
$+LF3v
2jlX$8
d89E
i=d\ov
~|TE
kF\
E6To
3`L)
I''zU
k 9 f9
elY)
c5! //
q|Tn
pvyG
39\Ay
,wG;
SYyL4;1-}
sH'M>
Rd`,
s'DP
x#'j_
zQe
<U>`gG2
D0cvo%
bk:Z
h-wL
!"TuOJ
IBD:
J53-!
3LOB
get_ActiveBorder
JoYF
{d!:D
Pzug
O6qO
aw".
ET% B
R|p8
%z}
K)o[
B3.,
2]bq
@2&*
`C1
(pPV
XP$B
;&#8
0:1&
FH_g
0jK9
&HZkw
$>1&D
T07ay*u
tN""
[^~
wdAi
\\j#
jRBg)
M{<J
L?Iu] h
GF,"h
aOPK\
(Sqq,
=VB'
N^?k
pfue/
GF)y
2I*`JG
C1I*
]\?O
q9w dy
BTN:
9'- ,
P)$R
#B^!?y
m^y lE
t4 xG
Hmk}
@.A
Dmi&
) y9t
yM{MuV` 8~
XR|.>k
"g_!
E>Q{
$`>6
H^^`
1vkM
mJSt
5 n9
DgB,{
XHneo2
X8Q^
r%Il
ojH5 *
Lw5
WF|y
WvCy
N "[
2+9h
<|H3$/X
!_v^
-9ll
x3 !
K3%Q
kx+-
Pb-;
F)w[q
de~[
ContainerControl
]s69
K|hL
K r `\br
"'!U
=;}4
j>f
Q<,G
B L:v& Z.T
%$ME
<_pP
ZJSP
CUILXUZ
Y]Y[
3F/7@u^
M_ w
Sly
c[
IDu#
ufPwxjXE
sV'|
O ZC
Jt-!"
System.Drawing
K)
W! ,9
gaL
u2r&
K?~
<~u@
7L*,_
WYe]
Iz q
kQ_NtbUf
B& o
0 T\Gy
Hywb
mFl8@
mz+N
wX91
GWN
(=77=
7s8A
9}jQ
Z 2YE1Q=j
2mlc)
?37b
PzVP)9x)
prlS
TT*V\
8l2D
)-JqE
%4v3rY
[aQF
)m t,u
5"?[
U=cro&
do`5
-&u
N.)%
yqOH
5/&6
BtI
8z BX7
eyJKE+
FU{T
r,R $
jXH7
!8,-
QBrO$
[q'p
0rK`
;&o|emm
hf B
QN%[
%wf%
BGom
7F%P
O}uc
5/qU
a4EW
E~[
vE.<
_Yd<
i&_[
hJev
m_sG
b"C/
0|J/
25D8NL
{ *g`a!
OoQY
*? Hh
6voj
Th^;
i+Gl;=
":KE
y1MS
he?#
SD]b2
2]C
+[F6
]!\9
f&FE
ioph
t4`8
,B'#
rGth
Q<de
SWsmbzSdWeyQx1UOH5lfqCeed1kNR
*T7
]}s\7
/ 3
t_<< ;
cJ8?
az(
ZY1
"]x+. \
1}C ^+&
)4X?
cGk=
WA(4
zbR8
$fq^c
s0 VsE
2Xc/;
ljLR~HA%
KMjKj
?r+;
''Yg
Q&O}
~(" m
X "\|;
QJ|A
lmiq
zL9^
f -\
%: ^
b%FEp
nbfk
AssemblyConfigurationAttribute
wPn<:1
q6K=
Hfqb
yIm>
s(/n`(
~?Mg
H$lk
;"'q
dmbl|A!
jE F
9~f{
e 1z
YT^EX
k3;
RH w
!CM=
>3)ul
;\2{
@ yW
DEX4y
Dw }"
HCIC
5;R.
(XTK[
84#u
`P[2R
vE`Hh:i
q-1:
B".c
:|:=
iR'^a\
[ll|
$wN6
B]:B<
=TCI
q6K\
6|9~'Y
:!h$~
yF-S@y
RF7h,
.`~
yu,W
Yi\ %
L Nl
ft _
# yl
"j21|G
dqA
!gfMK
ExSD5
U5$3
b0jf
fmW|
$s*}
B9nQZ=
w9:5&
~dT e>4
0%Qu
3TJi
>H~{
Tx*D
Vci4
3ZM9
}z S-I
)^.
j DZPP
:z1|
i>Gsy
;0a`
add_CheckedChanged
c{pU
v:x6r
'z-o9BlZ8r
F[l+
MG=_
834{
kM<]
{lwj
]-kt
7FW$
Y{Drt
hIm@w
LKF_
B6<"
i&y1
7PmqL
84nL
d+V*
[Io[
b
R~v;z
b!Uv
pt59
BU#p
1 WP7
u\8GD
5+U+
B,NV
*/CQ
m '8
VzW&
?
L<Y&
Y\\k
Hm1X
$eZL
C/L%
N7)b
kQ@5
Q!IRp"Q
}Ny;
WiBeM
F"nv
T?x"
nYs,
ke@MDl
:[ xq
suj2
j)!9c}A
z1?>8
O +P
t[#H8
o0wO
$@wL
zV5A
v3[h
binX
kd)r
{jw,
#6Y;/z
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
A A7:
;7Y{%
Z41h_4
_NW}
~3tr
4sz]
SjZ
7bs|,
` Ps
qrMkj
}'}!
- &<[
oOvggoF,
GT:KI)
Wgt'
*5?OwPI
uH&Sl\
L p5
: Glr
`Bff
]+C J
tLw
G B7
@~9`
9 -K
I gv
,$B[
il'^
<&*n
&c_?
~6D%
q^+w
R{>
y$cvmk2GL
OV7|q^
[ppm
%l 0
t7)P)
_Bu2
"6n _
og:Q
VCi`
Y3Tl
QYyn
wiq*q
nz@ms
az'W<+
9{y{
& +i!
g>fuqC?
Z|&p
YUXoewjO77FFUIVcxWAGVXBtTkr7d
KSa)1Lj
dpuwL
$@yQ8`
X f6
^.#6
JQaK
+?7\
mDWu
PccO
V:s\
mA?`t6
t$ /
#kCE
HE|Z1)
A;$ *
tDW0
R4I~
Ki '
7 /+%+
Vk+Qy8
N[E6
L :P
ZU/<p
L{]79_M
:FLE
mz6w
)&E@
8v+d
&F:@
')|E
N-Ho
;f2^
JL_?
)QH{M
__g"
`"CM
el.9
Tq;Y
Z,6-_R
Q{r} >zC
/xL,
lwZ v/
.*E|
W/ka
?++p
jm4r_
XC bN
lF<C
yo 6
0|?Y
W_s-{
O~86
`NJv
"9p4
:,\Mu
p kJ
M5E0E
aTb{
T ![
{ {)
kR@
3}6
] n3z3
QnzO
7M+MyyCy
Hu~#k]&
$>?
a8P
nSF9
=ND-m
Tp{F
uv@R
lNQa }
jTp]
E&r3
2lMl.'2
O3IG
l$%;X1
rWF{u>=
@RAc
}=<
1`&r
Vg;*
6OQU
; n
O]X%
{W c
#Q A
/Do|
b("z
"aPEI#0f
89SqICk
h8{&n
:HCg
A{r8
set_Size
qbTf
l}l)
:y#jr
`1xf
(5=1
Uz^uO p0
; Po
#;`|_
N>Kk
BJ# I3
%E4X
J 4>d
mLZ'
,-Dil
n}NI
?iC
=b EPs
0nm(Y
<2k3
@Xsk
<N9
QkP-
<Y 8
CwAH `W
)]7b
-kO/J
7YVfJhXlRAwJzbSuWP0108j9A26u1
=)/=
o`3,
< QI
Cu$lm
`eXq$
NHn
?KI
9LC-
v77Q
;lG:
wrxlD
{*Iu
XV[_
=HIC
t5A$>
;Y5r\
lW<7|
?0bc
.!<8
'6 -MUeY
hv(A
?n!
ksvc
X;~;
bl p
K>L8
W*f]
h5Xk
-;UXmN5 AB
;m}"
Y9 L
5"=<
A:3+
?< f
!PKX
;X^G
-o>{
{cB7
;LzR
pw'=I1*
! - W,g
c^%*
)^N}@
;oOD
jGPe
`[:u
O :
Lf*
N3}n
6d;6
SIx(rM
sqjx"P
t An
6rq=q
(ydh
=hG+jS
@7_Mw
^Is
P53R
TotYY
$o+J
b' p"
z=NK
%ej
/ }RLo `
LaB#<
aOp
m!*)]
xy!~a
_1 \
`j#;
YFo<k
OO`R
]</Xu
&E>V
^fCJ[
Ox`N
cAEk
!ap
K +'
Nj&j
y8 hVrK^
2O(D
i8MO7XOQWtvl1dLY2fU9BgoS20lpO
9TzNS
TransformFinalBlock
(BQ.Q
J'Gp
<`*2
f;aJYm
=<R
!F+w
6-O)c
sM, T-
$6-e
$J@B
<mKU
JDR@
o<Gp4
}%S&D
@|ZCw=v:
Wm90
Exists
/+ ``W
.(
>D <,
]nt4N
$ q
mGe`]
6}MC
A;.k
5swH
PDY
lnBO>
"{]Q
?I21q
[",y`
2I&&
^qj+g
=ybB
4MMZ
=,Z@
5qrK
uRT2
Hz}'
|uhv
G6u6s?r
-vj2y
Uwd-7
h yp
1cN%
:J9D
Y:se
!?
ugj{'fe<W
=M y
klQ
j FYZU
`V@3
pI/k42
<? \
.U3X(W:
qL~Pr
VG0+X
J|x?
_ya6R
M]v$
EXAa
BcGEq>
/[TT
1]yL
?cAa
T:U$
kKGy
2018
yy?Q%
B l
d0}7
6X#*
MnZ`
U70mI4
I1 dPz
zy>`
N`{g
wxEBxQrYZG1s7BCwi1iFlV3lKGPIX
W|7
bu~J
F6&?
6q!g
p !I
#_d&
TBY 97
WcV]
MN hkP
<XD=
y&zyg{
dl`_
w>Wk
Panel
/~fC}
U8+=
43>X
vR$4 H
ya8q
NrfK
[!T *e
IWk'
I54m
M=SG
bB9,s
8Na`
L vk&
94os
:|4*0RI
lCs
.@%d
hwCX[
j@,qv
MZ%3ruo
c/jZ
J~r6r
j_&r
(|[>
@NNZmk
X1`e
0Wk
eQi:
/`"`
:hel
K%~<5
aDwjNH
ApplicationSettingsBase
CN?/
l\,%E
EI0?
"M ;
}FeF
z[>F
]5MCa
cn#B
:#{u
7Tj
\:*N
Ua%H
!h2N
qh10
QXt.
`Y#[;
@D<?t
_Uk_us
zW\9T
Yxa-ht
j\*}4s
}>Oh
cn#2
+"0#3
BpZ*|V8
+! f
r(rF
Cch[
5-z`
-fP5d
dvu#[
B] M6
>0o}
qHh}
N2O`u
[pG};;m6
X?y#
X'(>A
*"y{
!5\hi
@@gl1
2S|w
JRv
bKGD
V% Z k4@{a8
Nj5e)
l.J_
<?u1u
}W w
ys7a
KP;}}Y"s
3.T5o
IM`;
a`G0
w^8~
!M[{ "t
'FaI
cq}|
w6B~U"2
"Zku
fCE4
('-c
3s}q
Ey s
D~*?%
t 8sB
td0`9
8 5B@
ZU.'
fI0xp
"^e
t*DU
4%d?
s^bjp
!kX_
hz!,
*d S
(-xp
Z-^B
h&Ap
>&WE(E
}Iz^
r3*G
RJyI
*lm>
)9j.
<K=t
%hTu
x"1`Q
/sK&.
i Q-
ubrVuEaojMDXG3kpap3oY50XC7OEH
<FOw
R4;0zqaL
}<a,4tU
Usu>"
Y7Ha8
6U5
]D3]
$!j\=
c42y
oO eJ
,-MHl
m]-'=
XBk1Q
h##
tRje
Pj?L
<X6u
ky>.
Bi~s
w@|L
JH<M
Q(Hr[
wH6]
Z - 6a8
zAh U
";OK
N$J
F >
Z71QE~m
z>egvu
z"{.
p')l
fK.o(
KLg?I6b_
2*P&
J6;yL
Q-J|mT0
s#zLPDV
1;WW
vhue
K-/
uC:%*
g{JB
5p
af'V"
y)lT
tc4o
N3Pm
~.!
xoSh
AKHK
8p?a
G$Z]
%]l'Jx
zHG^W
dA\mqg
h v-k
TpE~
o!v
Ym6j
o w1
<Eb0
FW!S
'$\x
!1#I
>yDP
3 oH
&mDv
{RPp
8Bva
1`u?
,#Qk
!Ct=
7?5U3E
\s[B
{*x2
)[g
P?|&
z%L#4
UdNt-[ :
}rP;
nSDM
rTZ8d
hO8u
2GTGt
i}?*
[@Jn
YZa8C
hD3|
Q>cg
$Jes
}UtHD
1<_qw D
aP6v
=Plr
mGm@
(i=j
3G:!
G >0:
v}JF
%@<MV
8JF.
)D-(2H~
2X'/
qV.
SGlW
[dL~
mX'~
WI61I
-X:w\hi
:f~,
]?;I%
7e u@qi
r0*n
ZkohMHyGPko73ExMD6feT6FyScpO4
zvsO)9v
QxqXg<Od
!b_;
eS2|a
.9~
si**
bpOb
2Eu(
~vG;
PY9;
;kq!
hh{3)
,D D
^N2
j\wT
O -aul\
!{d'
m&qnq
]+35~e**n
I{sV
k$m|D
?)tl
JES0
=v|j
MFn]
# ?WDV
Onr
(41:
U?M!
_L }
hB7 "
|m@U+4
~ {Y
mmLpy
]*<t
6*>c
\B(Ew
^K#(
OkkN
Z&|Xb
um?[
KNsX
PerformClick
Copyright
X=< 2WU
p8n4
ZEB^
#cm#H
1Z zgD3a8v
C06k
t+ I%}
^ 2d
:7s)
RHlN
SXiW
h&OH@ujj
|0 C>Z
G0 U
+jj
F]Q0,
72ku
CNJ$G
=ym\#C
.Eig
h;Q#
U0O~=
@$o(W
XaJ%
Nkf_
!7js
5}]
i/v`
%7OC
e]5R
]%F6
zQgI
v,V6
75v7Su
V0hu
<3+)0
{%gx
7)rN
S4C{
z">|E
8'z;&
zB@B2
pFEr
U1dH
)!6R
.?d)
wQs\vN
AQw B
uV J&
@WEz
K5dL
Y\f/
~D<U
C4hRo
Q >r
spyI
3'Ya
N?;0
={-
kEw4j1
o2bI^hE\
XfzH
o-FL
87$1
c z81
b=r
#48>~
XT`3
+ne/}
{,$0|
r(
BrS_
gPQ{/5
P"@2
1lt%
|9 9
M'^`
v'N697
xSvU
]x^S~
`\:-6'
J;`c
ZE!w
G+~{5h
,"uI
c6K8y
=.j1
^peXCY
yUUT
[SDb
m09(,S0
Ho$
NAX|gia
dQ]P{
xf*D:u:
ux('
8e#2
:1!
u=BH
e6k&
?iu[
[7'>
x8WT
u'S#{s0
~Q9!
e/9a
3^8X
x{)gQ'"74"
W5hH
huFe~
+.;U
rfark
w(:_
{(L;
;`a% (
xj* e }
6hQY
~<Yc
*N+r
EJZ8n~
e*rVk
+0d2
+9P9
ZCyz=
d$6.
AssemblyTrademarkAttribute
<cv~
;KTz
dCdW
IuDlYbFIsBJrGxPBhffFx5GA0QcAe
N/X+:x
v1;A#
a}k )
7;G
HG)#
H4q#M
/EN9
t>fdFQ&+7
F~i@
O8\i
,Yg88
v(rF
5hBy
Zied
"R@A
3LfS
L9}'
!ax\
C>`5"DNj
wYR6@_;x
jZvy
rjqE/
tcSy
p&;p
NQGL
HVv7
c&<q
B,J_
>[;C.
yRw7#
} |>
Skd;z
5xbX
<Muc +W
Fdhgp
]*
tFt
_QU5
iIPr
z2 d
YN0~
of.e
4 1m
222
\"("
^KYSj}3b
1 P4
H\e7
uns50
Op1y
.%y@
C%lf
D9m
_qKd+I
W2a
$sl o:
-Nbpq
r;r}
:*}p
\IU
FAA:a
XGxL
?LNh
~;5Z
d@H
{{5z
9U"N
T\-Z
ElsJ{KI
n9`:2Ph
m:#p
TY<=E
01QUA
QZR0
n*pe
Yy
m_e*W
#a G]{,
W2 3
9*(X
=)'m
[5jI
`1pD !
}Grie7k
{1BD
Cr )'
J#a&D
^bBJ
X/{X
3\/[;#
4P-!
15>>
K[| 0S
Si@U
zjVH
d']DZT
wos
\$s!
GO7"
fwv}
]a h
3 ;O
`s-7
"_%1
$bn,
Oh m
J& N
< >U
PlzIaQ
[GE%
5$4>
&RA0j,
PMf
G[{zTj
ibls
%u:~'
z8>>yG=L
RqY(
NZGH
6GYd
Z1TsR
U5ED
"..t
* =]
% #
`ARN
2 .hL
8@tN:
B96z
!*X@Zg
6!(C
~E-rZ71Aw
83"qZ
X~0[
L~Mb
Wb_
cLgM
bQN2
oueu
n=g;<[
BBGq*L|
_!^j
2.94
c&'a:N\
KUdb
:''Z
t:go
c{ #
U0]C
%Hu\
@Ep#
}d|V
System.Reflection
"4hvg
lrxm
1/me
$YCw
Ra^9
%B{
iX(
1TUe
"~M,8
sOdL
hi0i";
BhH5
u9"t
R -K
1+a]
#[Cx
UG?G
m;{`*
3kZZM.
{W/>
H}s xu
{0 K
l"T.
=T|lLJ"
ZX-LZ
DhQn
6VG5
&cgOa8T
a-Yi-;
'x-6
b@Fu
/hTxH^tU`#Y
P aE
5;yXDa
% ,+/"
,"MC
yu RF
g'L!
T4ZM
(L1
L\ ~
N#z5.P
WgS
UsGw
tT^
]L Z]
w&gm
9:+)
X}c!
! nF
mw#
@~`z
E<zH%u
9:ucu )
f>t@` }
{Tq2$Q
OlJb
B![>f
[Xfs
XI:i
ZG?a
8<mL2
w'7[
XA:*
D5" {
ZswK
Dl6.$t
[l.\
jJO#y7
k7@L
16Ia
$CXywv
`8[btJ
RzYbu m?
VJu5'8o
w II2
9[7WJ0ZKi
.$^T
pEed
~hh;I+
E, _
M,Po
Z_RZ
a"Rt
k9lw
~d,&
LsjK
p, /y
K:cOx
Q/zI
%=pRM
oM-
SEXJ
i m+
2Mgj
R*rsW
4@tv
6n *
=sawGU
W++"^
'AH'H
(; Y
t=>"
r\h3V
`Jw|
lE Q|
x.n_
y@o v
\aLlky9
H8<"
_PE.[Q:
i|b'
T(x!>
7P'o
|X8C&
^-7CP
u-,&
b__V
`M]5d
5[g6r
)b<4
Z0Di
@?= li'
(<VP
ri# m
u"`q
#vo
e^WH
4K .
^:T5
>:/g
gqQf
1 }[ {
{+"au
A?[7
f2s /
fZ^r
!: J
{Ph,
bee
N$U4
8[8v
/Lf"T
y]NV
+ajw
Zx Pb/<
]]>o
r)+7
wK]Dr
/JAN
h3cu
A5,NP
4tM`
tEXtSoftware
+ (z"
%&8i
}JbCt
R9AN
1I l
c/{'
5dH|
-Q R
KG{Ij
*Vk_o
q3v\
6foB
8u|Y
e}mH
H@A!x'I
[Wnbv8
J%6v
nD4t
u}`x
_>+m
(92g
ENw`
W; $
xvCE
mWlo
eCz=
}.Zz[
u\G)
^RU*VY
\wu hh
f[(OUz
ldLR
5 rr
7$ARd
q=sL
@="Ox
FA~aw
\l7tA
`IDATP
s/F_
U lLiko
WnKa
i^k5
9\wL
W|sLdA
0$lT
bv6W
F;^ )
&SG,
dVqiXgAM
Xum
d `(
IdW1
)o<I
myF>
$e$,
E2M=
v Ax
\XIY
59 xK
).Hlx
z!F"
$\$(
W\c N|
n!1/
fc-c
:e<-
/ U0
~[rt
STAThreadAttribute
U Ae
J8 j
$ z)
7V "
'M"/K
System.Globalization
bgK?
JN- u
ynq{m,
}vDhB
W@%~4
,rPa
/ono
yKw<W
a-koY*
wFV71
6 NmZ
;K$rpAse
HqdZ
=ae\t
"^X7{
<p7
*OX&
^|a+
ky8m
RjnC[
U!go
#; rk2V
g9Z
}w%iJV?kZ
#]/9
Za)M
0C:Ho
F mN^
a OE9
D z(HE
~Jv|
I^]L
.@F6"O
N{MyN
o!L$2
(BM)
H}Qn!g
~<YX(
-<a=
>:L+
`K9&[o?
zJ=z
m! Jo
Z]`
<oSg5
e
SZ|-
6]Q9
gBL1p5uXJn39nrTpuklG2NBJZLyfJ
b7\(
J 2)D
wCx7
_2\*d
,\*M9
i],n
PX_C
W ;h/
k@Z }
1 g,Au
,y*h
r=7[
jh.
($ p
9'@
PCgeZ
ZgVh
vP7-
azt
l9lZ
CRNA
xKx"
e%i X
]%yP
l~B[
l"y9
R<@0&
vfXl4"
ag5C
is~Bd
VVnrz
b5b"
e:-
get_EntryPoint
4}2K^.
c,0F
rYSz
-j!~
TgorT
ssL;H
`gKU
K@Yf
Ue /
2a\DwQ4
V'MP(
AO 0
.;q8
aJAS)
zsYT
;_:t
"S|O
ok RP
n[ K
f2KL
P2@Lx
(#?e$
Iy[E<
}x-
R4 R
V1@O[agZ
]w v
@v t
C 9u
yMKW
gCL>v
0.[g
+SY.|2'kO
@K\{
ZRID
EwaR
.! wF
pejU
cS:GH"N
>5_k^>
mnNO
+ iy
%`5c[
pYuw5jNKi9thwrCHrxuDwhzpbvONB
;'VP
3d,I
'T"-
j~mm
\uzE}3
LEubRX
y"cue
HzZ
,)HS
&l4u
6p=PiU
CFZ
/_X;
^QB
%y+G{.
0_ZbW
A+wu>5
P j
_5fJ
(z17
PANAdm
J]"H
+oX)
}gGR=
#_h?
s1[e\N
7zi1
* !d
C>f9
Rx@TM
(8gK
Q-x`H0F
u{cW
Mt=
3Q>t
1>#'
IG>}
NIEM
bo RS@2
jLLeG
z (J
9HK
$ ' F
10n
;r3"J
\61l
iMW5
O@-I
`xXi:
\\y_H
7_)k
SystemColors
k&S&}9
H;WhM
y}:^)
WEa"D
0WHX
|)`&
"Uj h
my&W
Vt3c
:0nO
Vn@3
qu9F
OJ-7
. pM
;:,r
\}$)aTC
xCxR
J 6/
1Z !OH
3IHuf
|F}PN
aL*(+
i1,(
{3EzZq
XhA
:-g;+W
} F
L$}z
c*y^
Jr:7&
]sap
;m6_:
P8e
6_Sl
a 0p
P[J~
X$w\,
Q^*i
tTs"7q
Tb,H
#sQse9
Y~O
QlfhZ
]v+8?`
(f?5~
)XfiyX
#O0D
Layo
k(=|A-
e7J
$98'"
>$`z
ipgC
A&>Q;
s:8+
F-.
#CLs(
h-"
F4^*
,'aIP'IF
%Nv H
Kd}"
MRdom
xf`.
F<}'6
4=x#
kf{V
lt l
hsc<
1 K|c
';~ g
_B&w
fCd%
VCD5m
TUP&<
D4tX{!
?[UJ(
iLT:o
+FE&
r?QT
]jl"K
r:$Xi
5=[/
~x8!
qf:
*MRB
I*6A
J<<Gq
/_'F
-[cS
q2d"
Gc_K
&pW
}eA0V@
L\;
*[w"\#
%IhN
FTc]
t> Kk-
_#u9
Bh3
4`i!z
i? Sa
\; +;-t
~K$4/
d 8
*TKUFa
2*t2
O7!Np
-I+v'
e`>
l ok ^
I ;C=
X~5l<
81r,
:@6z
:a%
BDAS
:@m?
$$n2'
|(bZ
z|Ls
puNg
mum,I
;.CB
..lL{
ez9I
I~-
yw!|
a(<8
:XJ(#M
;9d-
Df}|
pGGNT
K[ ,H*
F~l'#
K> ||p
e|#K
#cNq
D{n|,U,
UV5%
W W~1
System.Runtime.CompilerServices
_3u+
~}/I
u03)
Hag<@_H
gu|i+}
GWm x
n~xre
SP0{
Aq/H
mK"?
MsL3
D--6~
4q&U
n@X?q
r^K@V
ib:.
05ViEVpoDDRutXGfUjnXAK6IIipeN
(d_BW
1L "#
?^;Cg
G %G
;Y<I
qTXL
39HoM6DtldSkEtD3rWikMuYbmVjCP
XlL
hLwO
bqfqs:
daG'
C\OB
C:<q
b o "-
$HWZg
jT9m
YNi
AC 1
8 5l
(>Z-
fr<r
TX&2='
S!c%
mU$Lc
{0nO
Us&
w(N
kuNj
{Ns<c
F(4Qk
cR T
%= . g
GPzQj'
1Jc&4
q;xh
\qp{1>
^th' T
[M`&
Z^g+y
V QX
;3!
rz]3
gnoD
'Wk\
/U79
JH&*
+Vyt
lS.S
'M^
E?qp
A(Ui6
%)5<
2/hkr
(+.3+N
tE/}
kg t
p}Wp
t$bB
`S%9y
V =i
BAxE"
#K)A
a57q
U/d#s
`Ue;AR
:#=>
43 -@Ur
?UHx==
zQw
-x</B
pIxY
rad5
*=k
{N5M
ma nJ
6BEW4mV5HP1TL7ci1nuhUFQMUNNpv
t}B3
I yG
ys-q
<l`Q1
Tw:
d6X&oR
orU\
QzjTr
L(~)
3yx+
oh*a
&fCT
Cg]o
?@n~
-'JH
ryZ7f
`T`I
sq1%
>tdR
48{?U
VTBB
<h 4
:g?]7 M2q
M'*h
eX ]
Q.x2l
8,~D
VVWR
"3U
H<?`
~+9;
f"-6
Wqc&'?7
.Ezj
kI|-5
,8(f
@k
1Sgg
_Z#[
{E>c
%~\gnL8
5~B
_A@^B
!_wWO1
So $W
\ae
Yr{d
Xx:Y
=o?t
zkIA
j HY
IplnPkHlGJsiESXdcUYm7ecj7wEs5
3?]V
/4?[
*" 9
Qy3k
`wu}
V7l7
=CXT
0Gt!
6pd0*
pHYs
o|g'E
[7+{
[T5.2
Alg9LoR4yByer8nXtyRudQE0b8trP
':qJ[A
Y2=C
^562
LA@iZi
di*%
jn$w
#?^Z?
Yd6
=~sL:
mL0\
.QF,
!mh2
F`#h
lgw'
1:f)
NBaR;
\UK'x
5 Of
gPOb
UC$Z<
Dn^a
W\ ?V~-
Of%Z
;W6k
2Z 5v
opU=N
L%JD
f2MG
Bzlk
m>@/
N`T'
.C@%
-e[F$
w9w"
<Zvs +
.fiq_
VVK J 5
9Tdq
2O:<
g)Z &
N_uv
W`y#J0
3<hE&
kBr#
t@+"
*~Pi
2iT]
=GfC
hnonX
aF[s
?z{
d7#"
z2e%
=;b.
; 3
Byte
ySn#
X}#s
1A|52
\?)t
Dispose
,44<
qc0q
%NPp"[
S2cf
q?=
l7ri
a>z%
~Jyt>.
Z @4
u"0}
u^
{@<gbvo'
?(mk^h
._O/
QXJOSEfQ
jDak
e4O
2e V
3<A,
^&*}>
fj m
5@_r
HX^yx
2r;kV
(.p=
X@n:
sI'Z<
hkN(bl
JVPz
t&9&K
DXM[t
/<,
hf8YtRFoVnHKnVYL0LAQpPCL1VlxX
`,RK
4Cs}
yq :
bHAS
}75c
@`7xD
<=ND
}73 7
vUp8
Q%,
`]i3 l
z6i.
B)'[=z
vPHNT
sFgOr
[k,[
(OwgS}
S`@:
k|l4
v>':
fi7]
w<v^
,>cL
q/"o
,C!n
6p~5
+Rsf
!6{
q|[(r
N3N6fHjw
HoOw
'QZFz
buZ4
uv%AM
)fa:
C~E9
8l U|:c
g"qY#
6wo;N
u$ B
X5$=,!+
*/st
LBna
LPc
=iY~
^fr"
h {"
[+.8[
2Cw))
+`Q0t
W >3A
S SGY
Jc 2
P.%dl
auVv
$s<*
zzwu
8M,5
azw&
MrxJ
J^`z
:/<f
Q!?=
C[4!
^sdave
O q&
O ;|
z:[\
X#bR[
VW=EQ\5a
-D4b
,lU{
kYwu$
%o9U
} @p
mw']
y wM
bm"F
C*SUx
[n$
RO6C
_7*+
;&5
q@%I
*v*F<
y.9y
a8yT#
wn\OK
`k!,
4O\Zv
C|God;r
"hH
* uYV
a$R!
]seNO
"\o?
!W z
Woa%
+bMr
9Q=[Zw
)%E^
pzopuy
;n\%
khM
+s&
f,
c==D_
GEy(
g6*O
T#2X
,IjK
"=tA
= Aq& ?!
-G18j
F_Sj
p^w+
x"y`|%
C}Ix
r[^k
lK_3|
&_'-
'CzN
.Ekkc
] 9L
BHXC
Q)ts
SXs,
9&y1
I[z7
8JhaGj
)HiCrx
pf)t
Wu/69l
cRYX
7{M$
&!N$n
JD8H
oCds
4;h,GT
f@h
jo8Q
TczF
"+.*/
13 >
d;:D
> H=?
!'8.
DV;T
P@tW!~
Ik|.T3
#6GF
1&f`
RmY"8
P.J/
zd!/
m/)`
s~i
ht:D
'3vu
Z MDV
oW i
/7SZ
`E-$
]WTo s
POc5
|3xo
E/ W
DMSt;
v_Yz
&ap;HK
oJVl9
[BA8
1~}y>M
LJ{lF
]~.n
t4Z
Uz!
E}z
jx7`
abNl
,?^Y
'=W,j)
PU >
(]T#
`=Ee
> $(
+Gx$
iQ t
y}9R
gL)h
_Q=<K
Bb7z
zwlA
@7d6
g4WK
^.C`
Nu;J
|eps
Q8x$
m%fC
4xE0
gSiFN
yS\?5
\>lQ)
sA{G
HN!1
|k{i
r"Cz
)zm*
i2C]
{uQJ:
w@YI
|c zp
Dh|!i;e
REE/
=[}H9
_] c
?EnW
#U+Z
2E#L
a$q
guQ=
B>aS
vLl,$q
k|kj=>
G@Gy
ky<U<J
kTN
O]Cr{
;^|s
5DrF
yR B
Gywu
<&?t
PzFE
y<!Y
c,jq9\
nGh R
Co&?w
+rZ B
SsPL
j p6b
`?#~
k4 3
iqp,u
\#a'!l
_G42A
Zx =_~
v TKQ
M@#D@k
uPJ,
V9@
!2b(
+f!Rk^Vc
`k<v
FT R&
syv b
xxeQ
t*lE
`RNj
PSxfYF
<N/ocs&
*&@'
% #+
N{3(V
!r~1A
fB{dUo
M|,;
VP16g!-
h5he
?ys4
&9EJ&
[nRh3
} /o
nTU~
F6>*
P=n<
J =,
4 p}
%A~B9
oOyP
,Uqi
R|C|
{rRd
i0(
ooj!$t
4uyp;9
6)S(
jr{
Ew-7
u:0$
\y8G
h5hV
?r8@B}/-(
Nstz
^o:Km
o #a4Y
59-P
&< *
,wTm
9 ks
Wbfl
JB~(
2lX ru`;
-3q9
X|\T
nVwI
n&
|0;G
A?uV
Bq>?
1w*wF
"lKc_
z)<nU
mBr3y
l2`+6
<{Nu/B
Z?]Y
` E\
zWHd
;s;Bx+"
^SP$
wZKb
P=jA1
M?jzV
r9j{
[W;v40
Tky0Y
A?c<v
,{_6
/\ELD
6hOn
^o`$
p>g6
%/u+
(&D=
9 k5
yE{r
a~wbm
vfV%
)*9`Nk
,Q5
- $W
s!4j
v^zS
bV?pv
4V=(
$$:d
}^lK
Yg9KQde3
z[Kv
ZV>
|+WN
)SSP
fh@5
ITm <
:S.o
,5+
+_{x3
D28E
JpB$.
iLDK
YbE
SU0'Yd|
a}lU
}h`](q
OlgDL,
YIr8Fx
T#=^
@78w^
)q7:{
|j]/
LPC|
vsJ1SS
0~5N
]Fb~
r ;\
5PFgn
}p#<
N(U\
]r64Z
: r5
(oZp
o6mz
\.b'
m\c r]p
CZr1JZ
x8>]
(d`
dRi{:
voQ}wD
}1IVo
/]Q%
EL%E
\iwJ\
?= o
`R9F
3MKp
[_94OD
v6w
$(|+4QG[f-
OH"`
{b|K
qe"p}
9Pz
Zz2+O
=d;;
gAxX
,i=^U
7DG)
-?aY
9L&S|
}Vgfm7
LGD
3kWkj
QN6K
x(i2
l WZ
4uPLPv
q\D|G
V)h'
lM^R
8RN~
19]q
B ].
qeDS
]njX2
LHr&j
qa| 9LXr
fkLc
+iH:
8K [
v{>{
RP-n
Nf{Cx1{
/d3'
6:~a
vQKj]
GtAo
WM;|
y Io
<-5T@
P\0jv^
j-R#
Le!J
dfw <7
_3Wkd[
2 \m
er Q9
UP b
9"r)M
cJ?3[
|.,,
dm ]s
]n^_
G,%k
OAC[
#("l
FJ (
"*94}
aCdx$}
{0 {
5i=h
n!@c8R
6@Cv
F3 O nnB
qm0p.
POG**
% Q52_%
2t~aX
[ Kvl
'EP?y!=M
U}F)
_Fv@
G!fHD
d^uA
G\8j2
4'0'
^f|^
vrJjY?t
. ,v
k=nC
TAjG
@%u E
Dcsf
l qI
}S&A
6~ovq
'mhF
wvks p C;\
(Wy}
7v/n
Lyf~
8c"&
%9q0
n-A*I
xpj
m4H$
{R\/
|7K5
v< % )
nN?!
4xeq,M
13`3'W]W=
fX(8Q{
o(| ;F&
M]kI
J )tkFJ
V E]IN
hN1:
5G)e
"`n~
]lP4
m] Y
rMb
bZz3
0{KQI
w2^q
jf83
zcMR
jo {
Ed 0wE
Nbpa
BdK~z$ohHjl2/<Hs8$PdwV/"#.resources
Nz"10 x--b
jl|/
Q4E
w7j.
_S>
xr@n
*7AI
mmCv
~x~{z
%< Q
$g54
#|YEn
=+ K
F9n`
AP]O
CSXk
mBT$7
zyxWS
GbMK
`6 hx
+J] 55@=
:g|9}
Hk1i7
pQG=S
|r~G
'(6.
#ru<e
Z|XJ7
lU
}YgDY
\CX9;
yZat{
#=09
u0`^
HL(
Po-O
8!u#
;:[D
b G&
--#G7{}
MtC_
hcbj
v5OVN|
G4b9
;k P
F.LmH
fY~q
}HzX
8X95
yM?-
y'G"
)N06d@k
fs42
h|ov
s;.p!
F&z .
TextBox
fmn4b
T1b{:
,|4u
tOW4X
z}~ {
-.(S
ed@W
:,v'
Pasp
i9G2
H.4D`ek
R'$(
]6:7
+Y51
}-^5
!VWW
6\h>
pz0cHl
HStm
o d-?
(_\e
Zzq ~
0Bszz
k-VS
s\'?
vXi2
*nI"{
]\S5
qA{nhw
4 LT
|_iV
Q =~
L;\v
f!B]i6
TR6
Y%\v%U@L
"#Th
Hh#b
~Yx8$
gg9(
YC[N
9KB
8NXGqi
%(({
!'x m
s7sPz
iD>^
^!-~o
}.[#
f=_I
?R* d
aJPe
7~!v
^}t
d:X#
c3B
MAc KO
2)76
add_Click
$l.~
<Y
4\4+
uhU.
|4a8o
F4 P
A+n8
Jg/8&
YzFZO#
{Cs,
O3`"
lZ48D
;z]?
0 q'
r-=2
#2cl
Q$"%
<d l
`M]-
>e8?~7
$ 50#
;-XE2h
#69J
I+I*|B|
>R8q>
3rV*
}`\Cr
IPuJ
7z@f
Coe
M 2#
>/3"
,rZo
0$-$d
O\k$
h4h1
;(0a
#6mdN
yUp93rG
l1Cu
WdKvEExAMfylH4diDz2m7PP8YdK74
{8}P
%!_+>
UdH}
h)RP
[CFztc
V W/[
FE-I(
F|kg
2 ||
4~0\[
?JD
B5/-
l4;zi/>
AB?>
0|.5
#FB;
NViSwJH:
a0B/
y<GJ=
b1XDc
6Dv
601W
Ny"r
lt,!V
WVtQ
2EH$
,[[U'
S9o3
G^`.~
EF1G
v,v"$
(c8X*
64REL^;
5{EGF
~ZPY
6XlM
o;x
ai 1T
o{jI
4';Px
i6I6(
~hg
}d K
]vfj
~*'-:n]
{.64y
c27\
2(E-R
F$GF
Qg9|
ry#=\
h3DV
@B ax
,{Ft
?yAG-
R\bY
| #D
k`aTWJs
#lS
s) "\
@E0&
z $<
4Y4]
jchS
p0IO4
;U<1
9'={
[L%'
9"s#v6jW
xU\rk
*D99
IEND
UQS2
6m~GA
Z6xK
%W<9
YI =
UQSK
8b(TW\
+ 0N>
Xy{i
b M [e
/Lx-
$G?qQL
4p_N
gZuI
G\6%
.UX tF
ppg yy
p9@|YT'
tQag
oQpZ
A]Y^
YE3SlaT
bjXJ
W3A`e
aH5&
DeGu
i.&Z1
.fPu$q
s7Mku`
:! c
oYYd0
--4
+g4N
_!x;
`,uJh6g
cV G
jn((
.-m=
- f
q#,Rr
SRZ &
=Z @
u/)\
NW>A
a]*=
dwC
9ZjV
~ m
2 jVz
zN'.
0K"\
90a"
0Xc'
7#B29.
fu+4P0
ZRSK
(}4Q
Da&T
%2\5T
\z36rvb
53~X
C<-!
eqdH
f(] q\
xTgG
QI6U)
dS4#
CompilerGeneratedAttribute
EventHandler
?|\
41O]
,8 y
#u@:
Cg!h
Ue7|
RMA
vsE?
)G%AM
T9#Tj
G(IN
:_0
-y*k}
1\RU
T}nLI
X\' Xl
_f/+
8Vv/]
}(,m
8\j/OO
~k"bi
+!j,
u71uf8JSORkUf7SUMkihRHfShzYD5
9(aki&
:7n?
o$2:
n]{u2
PS ?
ELj5O
%yq}
JRva
fB~ g
(7x^
W1 l?
7gh'
r$L
|yJGLjF
I<A#V
eKY[
CeP?
'6R$v
lkru
(E,])q
b+|P
| ^oL
3/Jf
kT7a3
IIb(*[
8OQ_G
SIO:
adEh
K5y&
[@ XgU
cb{B
Tm3w
L3 u
BAR.
OnCn
E`sRF
E9-T
zZ d)>#O]E
0\aU3&4
>=eR
tXMe
tN3ki
Mrtw
lGB6
e.;x
jyfH
,a1F
e9^I
u$ *
5uzSMm
#u D
${}2
\gLW
{hEN
kzLJtr
TR+C
sO]e
#X0J
a1\/Z
A;b7
<hC.
U^,[
0Y"&W
eS $
X0BB
b-`;
HzJ
SjQ8
q &H
TLr%
IN2k
JiT^
M>M{^Pp
aD8e"<=$
i#F{
W5*|
NR!H
ptS+N}y+&
N _EzI
@.l0
:*6,$
wuPBK
A/,SX
gH3EX
wNQ$U
LRM9
-acO
E |RYa
<Module>
O ./
g("Z
{2us
w (D
5K=7\'
$E
-!.,9
|xNm
mhs"
I,}v_
UE%G
,e-
PJ@@g LN2
H8)9H+
5Un=
% ,0
`<'+
SoyO
9nSz
QlxU
s<9G]4
(0 1)
EditorBrowsableAttribute
F, Gr0
67=R
V*MI
$q+$
@rG
dFi]
ft\3
q-k(
Q*O^G
o Rt!
k.s)_
jW 2
UaHGId
w2 W@
F,=#
9Zz368
jP:o
$ o:
YT s
q` wi
|,.!lp
I=iX
/a>d
b' `r
Ll2K;
K]1^
u;W:-
$psO
Load
6AEb
"%mr
{)iqfS
4|Z7)
r5 @
4t*a(
HX~
<E!V]mX
? qew
N)K[-
<8Wj^m
GHXj
xsGf/
SF2g
yeGR
?6+XE
[@/J
iXH %
)skD
~N +
S8-R
|oh5
3>h2
pv;UJ
4JPfALnr8FLTVJwLXm0WBMBE8KSOo
4}fz
Pi]i7
\FGc
#nVhP
/p`&p
+LHr
rc2 ^
P$\y0J
Vx"#
<yS\|Wz
K}D2
J ,Eu
7ON_
1nP|
WQ>P
Y7r\4I
0h p
|kwc
f`Uv
2;|)
E$ o9
H +5
~X0n
i_BocN
Sg1(
K{8[h`
> 'd6
Rrt2x
2'd
>hL~
)cii
:nvY
wR-~m'
- ] =
$K{t1x
f^^J
*:q8S}Y
ox#bkLl
VuFb
eWnF
9vaw
q*qX
+++x
psrA
h}fb
4,uc
[g9~3 ~
||]8f
EAJU
gdLS
Object
^LHA4
Z b`
.@1lW
X E%
vb1a
R784
~iX~
=RbA<
.#A/
s1&X
3System.Resources.Tools.StronglyTypedResourceBuilder
-DF{6
9q-
E:h~E
3[Kq
AR=}
Aj;H\.
w>^Iq
UBLn
y_94
bY}%
#g)i
[Q`L
-c.+
4}9a
70-B
7 5Y
k23M
e S
(x{!
}/c?
{K T
`>*V
kE2}
J"]:
Ry[!
5LC#
&z S0g
\_h-+
(6yn
8dX'
&PWM
CODZ
2^{3
.aJvW/
N"vJ
_Wh{-
hz-BYiq.m
#b{/
^:9g
`/VRk
7WdRm4Z8f4mD8EpOYntWgCzBvSqeO
C$vv'*
j8|9 O
,g>y
l<gS
b4h#
('oK3a
#6f}
C0EmGEihcr8FnUnjVXMQvdt8l4Qji
olX9
- B6av0'
Hex;
c'vs
FVZH
L*fy
^VC@U
TN}g
GO?xb
]|Zr
NJ$#
V0wUI
`?f0U7
I+jz9=
>gkE
v';?;
!rf_
3WH^
II\_7
*M9$
tQ)t:/h
9wnhS
,"|=V:
I9OUfoyRTeH6gP6Y0vBFywyqxfJKA
3-})
2R_r
^Y%*80g
].xP
Exit
}n83
Iu1#
"pqE
rz#,
_v2?
3jG{
Eb$
EQY k
s BV
I!fwb
M}K,j_.
bM/
v3T
VN--
Mmko
pA(Oi
6 D0
65%X
XJ>,
8UXH
1Ao>Y
|@JC
`T,0c
*SgdN
uITJ
JY_U
BYO
3Y >`FBk
XY9e:
4K 6
^0( ?
tcvpm=Yh
h(p
`dF&
pcc]
CviL=t
gZwP
$#|7
Q\TK
5 IvF
& Hc
5qFm
hYuH
V9J(X
rVz_&u!
pl%n
1D vN3%
c"4kV
0,I.
^'Zc
H"5V
76z)
2*g{
r[OB
x)C,k
93q.a
(ll[
SkPF
3wC-
K'T`
r7>d
MxBy
emf3B
`]V;N
- ;*
&?O{
z+R<L
g6h,
Oj Q(
c`v^-9
<)Pt7#f7
)a8i
n e1
No6y
IUqyD
L&/%
Qy[H?g
k-us
J e[
7CHa^&
7Q(E"
Q"S
~ CW
*5 0
%L`(e
Ae}S
zTK@
(S!"
lC'U
eT{!q
l{ly
$zHr/}+
a`mDL
n=O-
?J%^
%Q`V
vb)m
9dWIU
kDb%
sJKc
*GU?c
|8- U\
5r=A
qMa}M
pXxI2UXuUdUajPDlpqyHQ8Jg3SoPE
W-
VYy!
DP1 mi
ecYP%
<S _q
P9pU.y
sHj5L
jrS#
a#M$
C3]T
Tq q
fiFM
=t?7
2n=g
R0vs|=
$%N`
!|,J
_+}h e
wS d
d3 W
wACoF
GEs%o
p9%*AN|B
kE ;
*o34
{18]
01~
N4!K
ZXv/j
(7/x
5t'
; mI
dn|<0
1MN>
ANW\
EqPp
>#>BvAv
$]
M3_;!Q
!'\:H
C: `
c=q}
9)I,
[e}F
PFT
EbGa
0AvL
0I" CQrp
==cE
mV78!
RtG<
XD B
gE8o>
A#uD
D\aB6
S\I2
[[2qR
kN/z:
"jdO&
|@# r
`8tf
E;f3
1lg=y
;'T@)
Sw|+
_wjI
1B^7
~,.|
^@%E
N}yu
hkq 1
}!;&
E b
,@ C
+@KAM
O:3hC
Fw &8bN
s^pK
|;vt
x: g
Ane$
Go_(F
g/6Bd/
set_Checked
D#Eh
=-miiB
'e G
Qj3B8
#3dL"w
%h[
-q//
Is@t!T
l e<
E!#k
5oDL
vV.D
EOzr
[,vn^
4#IF
Y4Hv_5
^mt3
lIQD
G.OZ
DCNH
-kWl}&
@.:<
cmm
jnzE9
aL[(
;6DF
aFm0
g !!
m?F
VAf 0
JOA>CGi@
Fu=`
D+C[
uEEZ
3 9Ni
}s} %s
JBGt
RGe.\c
`/qH
w.[ ;Z/
'U4+
F+4
o t1
ly5Z
RRi5r
p:pr
zAp`V"
HIfd
$ved
ou<"<
EQ/|
}I^@
ti1}T'
T[5>
$4f495d20-d7e9-4a9c-8574-59ecafc5c1bd
e>ON
}C 5
cjsi
,;8M
Iw[S
vOA-y+|*zz
yic
I =
E@h X
O^Rt
=e'#
<v9M
$2[[
+o7 4
^ .
fWg~
{{[-
"J I
J,dn
L Cic
(%mq3
S.cY
{^fTH
.@?4
Cl')
"\%
I@fb*F
System.Collections.Generic
Z""
tg|`
KciM
D&jQB
_}=X
System.Runtime.InteropServices
xqa+
kO^X
=[Hu`
A^S[^
Q)Z'
jmkS
x'_q
T6$N
V2Y9
x M)
li5{
QN@
/Q[(uh;
N9o]#N
OP4iV
& TX
`5MP
*\zn
adh
CHxw
Vq!h
7WDK7
t t \h=
YRWr
C6Os$
g% y
Ggc
e.#r`
{W[-
STk22
O/-|
c#`
fqiN
mE2N4_
Ox',
V"/H
<?E
(.]=
bBvo
"{0=u
l 9np
%&C&
0li5pD]N
(R(j
'([X
] n)
UQ,"rrh
.|W{"J NW
jCr|
QW^~[U
_Kvd
fSn@
}v!r=
KPlxpG8TVyg2KKd48wDzsLD9d47BV
5P .
ifx0z
set_AutoScaleDimensions
\jnqj*
pIp8
@Y3"
NN600
}u3
nhC<
d*\t
3dH
]Psj
OKs/
<$HI
_"fr
,P WKT
u]wz
1F0 g *U6",)
BkGR;
3/h%F
4}?#
1R,Mp
_LKju
:hv@A
LOG|]-<
Y'+M
P!#0B
Hwn8>
xPSjrQ ,
vQ2H
cV{G
];d6
]E@2
<A_
i: J
wN TPQ
3rZL
/`JsZn
5(NP%
sEEi
2C)&K
On]^
qf:2u
`_v5
DLB/
w7KC
DDY:5R/j
(Th4
wp(t
VXXP
Oam%
6"i*7
Wb1
a 6xt
Ds1i
:iXJ
DN M8Er
3]E'!
M:2(D
o[Xpj
u[>D
OI3WL
H6A*t!
:d7O
X<e
.i'h
j]V\
d` 3z
LD"~:
uF *
%zH&Sf
5[z
W<7X
_|oS
(n4P
7qZ
#GK}j)
K)t|
J)8w
?Mto
lRl7:
z`Md)F
qZ;
/M d \i^
Q8h
]4x#
o>DF
u,oQ%
}S}c
yx&F
vzjM%J
SzkC
C O
I[H{
W1@=
[i~w
H/vH
W?joZ(
>rB2
@ ;Q
h&A`1g
9e2E
'Kn
VAi3r
0E'II
#d*>^j
FwMq
Z KN
@iAr
$n=o
R Cr
t Y`
qDR&
[%5W*
& dq
6v-}Z
z]w7
Folling
^?uJ
&oI]
^SJp
x/k"A
?( Z
`g}e
$f=w
Z2J+m
Zb4
82-
;.HGN
?C*Q
'=kz
f3TT\
sfQ6HZotV8vEPoaATIQBlO3e62pRL
Muij
$d(T
4m
6<Z/
j}C]
_Gg4
'WNa\
@! Y
kp]w
Cx\2
[1=@
gw F
0@ T
=~/~
M fd
%4 >
s}z+
,Wxl%P
9h;c
^ sP
Q11K
NC&-
6,9B
fjx%5
m.X(
D%1{vhf
N5'
et(*xtxa
Hx:D
Ad_]<+s
%wd.g[HQ
qyt8&i
*#%dE
"/b ?
\63(a
mqI&Vs
wx&J
1#@j
U2K7
hcwg
xTc-
X 4Q
rqyZW
v7s}7X1
& (la'
"Q 6
)hHj,
M;IN%
4JQ7
g^m
%Hy-
&<EG
DNM7
8RH`
<V*9
RqMT
\w 2
fViN
J 04#c(
2 "mD
+n
p$[}
/a%
<uaK3
y<B$
Y!-A
9+P
/m=2*
/ FI
h^%D
J~0kS
)b-~
E*OEB)(g
.%=#
?,zR
O}Q E'
BR`yy9]
U"nbK
% }/p
rE B
Xf =%
w#d_Vx
ac3<
>*so
)xi`
yEy;
;*=Yu
{+ h Z
9?q
}<?7(
#7D0
6$9*
IE{M-
~PU<F
V`xi
3)8E
T,+(
X&O
3% 1
ctt i
9Pj9
n 61
e0Pm
[)M"
F\Iy
7g' U
%uA3
OI q
jV>5
;?MVI
Q;%T
7&v=+
aKP/o
aY=L
yAF2
Ax I
I 9t@k.G"=
mRc
s9H19%
,q_%
`IHD
3\R\
dU%
%&
z1"l
?av>
28P
eK74
Z/Bb"
@)_HeBf
Tw aVa8
2ED?s
~'/uc
OlVI
{C:~X
Concat
2B+9
!S@{'
<[nTt
!CB+
k< `
i~[3
9R)N
}isr
a=EV
niii.
@pP\
iav?
qH]5
<Q2H
]ME
41=w
K %(
Xu~=
<9-y
Fa8!
xT+2
XFh.
H;f8 =
?$^U
t(u
@ay=
I Da1
n,G"
$f=ca
P[e(Vex
@Sb3\
Mq6"T[?.
KVD,
$0FZD
bXbs)RN
]H5pT
m ~2d$
9-{G
@s2]
3Os
K\G
NL@L-l9qo
tb`j
2f"j
{ o0
!biR
' +"Y
/@{%
!_3i
+~w
Q4C<
wo_;
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03b_64 Seven03b_64 VirtualBox 2018-04-14 15:06:30 2018-04-14 15:09:23 173

7 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03b_64 Seven03b_64 VirtualBox 2018-04-14 15:06:30 2018-04-14 15:09:23 173

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\f3.exe.config
C:\Users\Seven01\AppData\Local\Temp\f3.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\f3.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\f3.config
C:\Users\Seven01\AppData\Local\Temp\f3.INI
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\Folling.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Folling.resources\Folling.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Folling.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\Folling.resources\Folling.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\Folling.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\Folling.resources\Folling.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\Folling.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\Folling.resources\Folling.resources.exe
C:\Folling\Folling.ini
C:\Users\Seven01\AppData\Local\Temp\it-IT\BootstrapCS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\BootstrapCS.resources\BootstrapCS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\BootstrapCS.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\BootstrapCS.resources\BootstrapCS.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\BootstrapCS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\BootstrapCS.resources\BootstrapCS.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\BootstrapCS.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\BootstrapCS.resources\BootstrapCS.resources.exe
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2372.15642781
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2372.15642781
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2372.15642828
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\display.inf
C:\Windows\sysnative\DriverStore\it-IT\display.inf_loc
C:\Windows\inf\display.PNF
C:\Windows\inf\hdaudio.inf
C:\Windows\sysnative\DriverStore\it-IT\hdaudio.inf_loc
C:\Windows\inf\hdaudio.PNF
\??\PIPE\samr
C:\DosDevices\pipe\
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\
C:\Users\Seven01\AppData\Local\Temp\WERFC71.tmp
C:\Users\Seven01\AppData\Local\Temp\WERFC71.tmp.WERInternalMetadata.xml
C:\Windows\System32\drivers\*.mrk
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_f3.exe_616775fc69e4bdd654f0517cbfefeaf99a68c578_0a73575c
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_f3.exe_616775fc69e4bdd654f0517cbfefeaf99a68c578_0a73575c\Report.wer

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\f3.exe.config
C:\Users\Seven01\AppData\Local\Temp\f3.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\display.PNF
C:\Windows\inf\hdaudio.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\WERFC71.tmp
C:\Users\Seven01\AppData\Local\Temp\WERFC71.tmp.WERInternalMetadata.xml

Write Files

C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Users\Seven01\AppData\Local\Temp\WERFC71.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_f3.exe_616775fc69e4bdd654f0517cbfefeaf99a68c578_0a73575c\Report.wer

Delete Files

C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2372.15642781
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2372.15642781
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2372.15642828
C:\Users\Seven01\AppData\Local\Temp\WERFC71.tmp
C:\Users\Seven01\AppData\Local\Temp\WERFC71.tmp.WERInternalMetadata.xml

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\f3.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f13ce19\8d0dd9
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_CURRENT_USER\EUDC\1252
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Microsoft Sans Serif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\25a24ab0\7f49f03f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|f3.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|f3.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|f3.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\25a24ab0\16d66f3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\39757e56\cd334da
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\39757e56\1c96965f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\f3.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\2FB9A32B
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\f3.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\REGDBVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eheadphonewave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonetopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonewave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave\Properties
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SYSTEM
HKEY_LOCAL_MACHINE\SOFTWARE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\2FB9A32B
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\REGDBVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57

Write Keys

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
lqDLemTGyFWaJXSxRWznyVqIcPZiq
Local\MSCTF.Asm.MutexDefault1
Global\bbd4e468-3fe4-11e8-8912-080027839166

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
kernel32.dll.QueryActCtxW
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
uxtheme.dll.IsAppThemed
kernel32.dll.CreateActCtxA
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
user32.dll.RegisterWindowMessageW
user32.dll.GetSystemMetrics
user32.dll.AdjustWindowRectEx
kernel32.dll.GetCurrentProcess
kernel32.dll.GetCurrentThread
kernel32.dll.DuplicateHandle
kernel32.dll.GetCurrentThreadId
kernel32.dll.GetCurrentActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
kernel32.dll.GetModuleHandleW
kernel32.dll.GetProcAddress
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
kernel32.dll.GetUserDefaultUILanguage
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
kernel32.dll.DeactivateActCtx
kernel32.dll.GetSystemDefaultLCID
gdi32.dll.GetObjectW
user32.dll.GetDC
kernel32.dll.GetCurrentProcessId
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
mscoreei.dll.LoadLibraryShim
gdiplus.dll.GdiplusStartup
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipCreateFontFromLogfontW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryInfoKeyA
kernel32.dll.RegCloseKey
kernel32.dll.RegCreateKeyExW
kernel32.dll.RegQueryValueExW
kernel32.dll.RegEnumValueW
kernel32.dll.RegQueryInfoKeyW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
gdiplus.dll.GdipGetFontUnit
gdiplus.dll.GdipGetFontSize
gdiplus.dll.GdipGetFontStyle
gdiplus.dll.GdipGetFamily
user32.dll.ReleaseDC
gdiplus.dll.GdipCreateFromHDC
gdiplus.dll.GdipGetDpiY
gdiplus.dll.GdipGetFontHeight
gdiplus.dll.GdipGetEmHeight
gdiplus.dll.GdipGetLineSpacing
gdiplus.dll.GdipDeleteGraphics
gdiplus.dll.GdipCreateFont
gdiplus.dll.GdipDeleteFont
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
user32.dll.GetClassInfoW
user32.dll.GetSysColor
gdiplus.dll.GdipGetFamilyName
gdi32.dll.CreateCompatibleDC
gdi32.dll.GetCurrentObject
gdi32.dll.SaveDC
gdi32.dll.GetDeviceCaps
gdi32.dll.CreateFontIndirectW
gdi32.dll.SelectObject
gdi32.dll.GetMapMode
gdi32.dll.GetTextMetricsW
user32.dll.DrawTextExW
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
gdiplus.dll.GdipGetLogFontW
mscoree.dll.ND_WU1
mscoreei.dll.ND_WU1
gdi32.dll.GetTextExtentPoint32W
gdi32.dll.DeleteDC
uxtheme.dll.GetThemeAppProperties
uxtheme.dll.OpenThemeData
uxtheme.dll.IsThemePartDefined
gdiplus.dll.GdipCreateRegion
gdiplus.dll.GdipGetClip
gdiplus.dll.GdipCreateMatrix
gdiplus.dll.GdipGetWorldTransform
gdiplus.dll.GdipIsMatrixIdentity
kernel32.dll.LocalAlloc
gdiplus.dll.GdipGetMatrixElements
kernel32.dll.LocalFree
gdiplus.dll.GdipDeleteMatrix
gdiplus.dll.GdipIsInfiniteRegion
gdiplus.dll.GdipDeleteRegion
gdiplus.dll.GdipGetDC
gdi32.dll.OffsetViewportOrgEx
uxtheme.dll.GetThemePartSize
gdi32.dll.RestoreDC
gdiplus.dll.GdipReleaseDC
dwmapi.dll.DwmIsCompositionEnabled
user32.dll.SetWindowTextW
kernel32.dll.GetStartupInfoW
user32.dll.CreateIconFromResourceEx
user32.dll.SendMessageW
user32.dll.GetSystemMenu
user32.dll.GetWindowPlacement
user32.dll.EnableMenuItem
user32.dll.GetWindowTextLengthW
user32.dll.GetWindowTextW
user32.dll.SetWindowPos
user32.dll.RedrawWindow
user32.dll.ShowWindow
user32.dll.GetWindow
user32.dll.MapWindowPoints
comctl32.dll.RegisterClassNameW
uxtheme.dll.GetThemeFont
uxtheme.dll.GetThemeColor
uxtheme.dll.GetThemeBool
imm32.dll.ImmIsIME
uxtheme.dll.EnableThemeDialogTexture
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
culture.dll.ConvertLangIdToCultureName
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
user32.dll.NotifyWinEvent
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGetProvParam
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptSetKeyParam
cryptsp.dll.CryptDecrypt
cryptsp.dll.CryptEncrypt
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.SwitchToThread
cryptsp.dll.CryptDestroyKey
cryptsp.dll.CryptReleaseContext
kernel32.dll.ReleaseMutex
kernel32.dll.CreateMutexW
kernel32.dll.CloseHandle
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.SetFileAttributesW
kernel32.dll.CreateEventW
kernel32.dll.SetEvent
ole32.dll.CoWaitForMultipleHandles
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
ole32.dll.IIDFromString
ole32.dll.CoGetClassObject
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CoGetObjectContext
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.LoadLibraryA
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
ole32.dll.CoUninitialize
oleaut32.dll.#500
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
oleaut32.dll.#283
oleaut32.dll.#284
oleaut32.dll.#9
oleaut32.dll.#7
kernel32.dll.GetEnvironmentVariableW
advapi32.dll.RegCreateKeyExW
advapi32.dll.RegSetValueExW
kernel32.dll.CreateProcessW
kernel32.dll.GetThreadContext
kernel32.dll.ReadProcessMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.WriteProcessMemory
kernel32.dll.VirtualProtectEx
kernel32.dll.SetThreadContext
kernel32.dll.ResumeThread
user32.dll.InvalidateRect
user32.dll.UpdateWindow
user32.dll.PostThreadMessageW
user32.dll.GetWindowThreadProcessId
user32.dll.PostMessageW
ole32.dll.OleInitialize
ole32.dll.CoRegisterMessageFilter
user32.dll.GetFocus
user32.dll.SetFocus
ole32.dll.CoRegisterInitializeSpy
ole32.dll.CoRevokeInitializeSpy
user32.dll.GetKeyboardLayout
gdiplus.dll.GdipCreateHalftonePalette
gdi32.dll.SelectPalette
gdiplus.dll.GdipSetPageUnit
gdiplus.dll.GdipSaveGraphics
gdi32.dll.GetNearestColor
gdi32.dll.CreateSolidBrush
user32.dll.FillRect
gdi32.dll.DeleteObject
gdi32.dll.SetTextColor
gdi32.dll.SetBkColor
user32.dll.GetSysColorBrush
uxtheme.dll.GetThemeMargins
uxtheme.dll.BufferedPaintInit
uxtheme.dll.BufferedPaintRenderAnimation
uxtheme.dll.GetThemeTransitionDuration
uxtheme.dll.BeginBufferedAnimation
uxtheme.dll.IsThemeBackgroundPartiallyTransparent
uxtheme.dll.DrawThemeParentBackgroundEx
gdiplus.dll.GdipRestoreGraphics
uxtheme.dll.DrawThemeBackground
uxtheme.dll.EndBufferedAnimation
user32.dll.PeekMessageW
user32.dll.IsWindowUnicode
user32.dll.GetMessageW
user32.dll.TranslateMessage
user32.dll.DispatchMessageW
user32.dll.GetMessageA
user32.dll.DestroyIcon
user32.dll.DestroyWindow
uxtheme.dll.BufferedPaintStopAllAnimations
uxtheme.dll.BufferedPaintUnInit
uxtheme.dll.CloseThemeData
user32.dll.EnumThreadWindows
user32.dll.IsWindowVisible
ole32.dll.OleUninitialize
user32.dll.SetClassLongW
user32.dll.UnregisterClassW
kernel32.dll.DeleteAtom
user32.dll.IsWindow
ntdll.dll.EtwUnregisterTraceGuids
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
advapi32.dll.EventUnregister
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
oleaut32.dll.#4
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegSetValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CreateStreamOnHGlobal
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.CheckTokenMembership
kernel32.dll.SetThreadToken
oleaut32.dll.#285
advapi32.dll.RegOpenKeyW
oleaut32.dll.#12
oleaut32.dll.#286
ole32.dll.CLSIDFromString
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#290
devobj.dll.DevObjCreateDeviceInfoList
devobj.dll.DevObjGetClassDevs
devobj.dll.DevObjEnumDeviceInfo
devobj.dll.DevObjDestroyDeviceInfoList
setupapi.dll.CM_Open_DevNode_Key_Ex
devobj.dll.DevObjGetDeviceProperty
cfgmgr32.dll.CM_Connect_MachineA
cfgmgr32.dll.CM_Disconnect_Machine
cfgmgr32.dll.CM_Locate_DevNodeW
cfgmgr32.dll.CM_Get_DevNode_Registry_PropertyW
cfgmgr32.dll.CM_Get_Child
cfgmgr32.dll.CM_Get_Sibling
cfgmgr32.dll.CM_Get_DevNode_Status
cfgmgr32.dll.CM_Get_First_Log_Conf
cfgmgr32.dll.CM_Get_Next_Res_Des
cfgmgr32.dll.CM_Get_Res_Des_Data
cfgmgr32.dll.CM_Get_Res_Des_Data_Size
cfgmgr32.dll.CM_Free_Log_Conf_Handle
cfgmgr32.dll.CM_Free_Res_Des_Handle
cfgmgr32.dll.CM_Get_Device_IDA
cfgmgr32.dll.CM_Get_Device_ID_Size
cfgmgr32.dll.CM_Get_Parent
user32.dll.MonitorFromWindow
user32.dll.MonitorFromRect
user32.dll.MonitorFromPoint
user32.dll.EnumDisplayDevicesW
user32.dll.GetMonitorInfoW
dxgi.dll.DXGIReportAdapterConfiguration
setupapi.dll.SetupDiGetClassDevsW
setupapi.dll.SetupDiEnumDeviceInterfaces
setupapi.dll.SetupDiGetDeviceInterfaceDetailW
setupapi.dll.SetupDiDestroyDeviceInfoList
gdi32.dll.D3DKMTOpenAdapterFromDeviceName
gdi32.dll.D3DKMTQueryAdapterInfo
gdi32.dll.D3DKMTGetDisplayModeList
gdi32.dll.D3DKMTCloseAdapter
wintrust.dll.WinVerifyTrust
advapi32.dll.CheckTokenMembership
wer.dll.WerReportCreate
wer.dll.WerReportSetParameter
wer.dll.WerReportAddFile
wer.dll.WerReportSetUIOption
wer.dll.WerReportSubmit
wer.dll.WerReportAddDump
wer.dll.WerReportCloseHandle
advapi32.dll.RegGetValueW
user32.dll.LoadStringW
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationW
sensapi.dll.IsNetworkAlive
rpcrt4.dll.NdrClientCall2
user32.dll.CharUpperW
werui.dll.WerUICreate
werui.dll.WerUIStart
ole32.dll.CoInitialize
dui70.dll.InitProcessPriv
comctl32.dll.LoadIconWithScaleDown
ntdll.dll.RtlRunEncodeUnicodeString
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlRunDecodeUnicodeString
dui70.dll.InitThread
duser.dll.InitGadgets
user32.dll.RegisterMessagePumpHook
dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ
dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ
dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z
dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z
dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ
dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z
dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ
dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ
dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ
dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ
dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ
dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z
dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z
duser.dll.CreateGadget
duser.dll.SetGadgetMessageFilter
duser.dll.SetGadgetStyle
dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z
dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ
dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z
dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z
dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z
duser.dll.InvalidateGadget
dui70.dll.CreateDUIWrapper
dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z
shell32.dll.ExtractIconExW
comctl32.dll.TaskDialogIndirect
uxtheme.dll.IsThemeActive
duser.dll.SetGadgetRootInfo
xmllite.dll.CreateXmlReader
xmllite.dll.CreateXmlReaderInputWithEncodingName
uxtheme.dll.GetThemeMetric
duser.dll.SetGadgetParent
duser.dll.GetDUserModule
duser.dll.FindStdColor
duser.dll.AttachWndProcW
kernel32.dll.InterlockedPopEntrySList
kernel32.dll.InterlockedPushEntrySList
kernel32.dll.InterlockedCompareExchange
duser.dll.GetGadgetRect
duser.dll.GetGadgetRgn
duser.dll.GetGadgetTicket
dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z
dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z
dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z
dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z
comctl32.dll.HIMAGELIST_QueryInterface
comctl32.dll.DrawShadowText
comctl32.dll.DrawSizeBox
comctl32.dll.DrawScrollBar
comctl32.dll.SizeBoxHwnd
comctl32.dll.ScrollBar_MouseMove
comctl32.dll.ScrollBar_Menu
comctl32.dll.HandleScrollCmd
comctl32.dll.DetachScrollBars
comctl32.dll.AttachScrollBars
comctl32.dll.CCSetScrollInfo
comctl32.dll.CCGetScrollInfo
comctl32.dll.CCEnableScrollBar
comctl32.dll.QuerySystemGestureStatus
uxtheme.dll.#49
dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z
dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ
duser.dll.GetGadgetFocus
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.GetThemeTextMetrics
uxtheme.dll.GetThemeTextExtent
uxtheme.dll.GetThemeBackgroundExtent
duser.dll.SetGadgetFocus
duser.dll.DUserSendEvent
duser.dll.SetGadgetRect
comctl32.dll.SetWindowSubclass
comctl32.dll.DefSubclassProc
dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ
uxtheme.dll.#47
uxtheme.dll.BeginBufferedPaint
uxtheme.dll.DrawThemeParentBackground
uxtheme.dll.DrawThemeText
uxtheme.dll.GetBufferedPaintDC
uxtheme.dll.GetBufferedPaintTargetDC
uxtheme.dll.EndBufferedPaint
duser.dll.ForwardGadgetMessage
oleaut32.dll.SysAllocString
oleaut32.dll.SysFreeString
uxtheme.dll.GetThemeInt
duser.dll.DUserPostEvent
duser.dll.DisableContainerHwnd
duser.dll.DeleteHandle
duser.dll.DetachWndProc
comctl32.dll.RemoveWindowSubclass
dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z
dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ
dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ
dui70.dll.??1CCBase@DirectUI@@UAE@XZ
werui.dll.WerUIUpdateUIForState
uxtheme.dll.GetThemeEnumValue
user32.dll.MsgWaitForMultipleObjects
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpSetTimeouts
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpSetStatusCallback
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
winhttp.dll.WinHttpGetProxyForUrl
winhttp.dll.WinHttpSendRequest
ws2_32.dll.GetAddrInfoW
ws2_32.dll.WSASocketW
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.WSAIoctl
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpReadData
ws2_32.dll.#22
ws2_32.dll.#3
winhttp.dll.WinHttpCloseHandle
advapi32.dll.IsValidSid
advapi32.dll.GetLengthSid
advapi32.dll.CopySid
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
advapi32.dll.RegisterEventSourceW
advapi32.dll.ReportEventW
advapi32.dll.DeregisterEventSource
werui.dll.WerUITerminate
werui.dll.WerUIDelete
duser.dll.DUserFlushMessages
duser.dll.DUserFlushDeferredMessages
dui70.dll.UnInitThread
user32.dll.UnregisterMessagePumpHook
dui70.dll.UnInitProcessPriv
dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ
dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ
advapi32.dll.DuplicateToken

Execute Commands

"C:\Users\Seven01\AppData\Local\Temp\f3.exe"
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
dw20.exe -x -s 464

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-04-14 15:09:20

Detected family: #Msilperseus

TheSystem Itself @ 2018-04-14 15:26:03