MalScore
48.5/100

Avg.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 19/57 Related 2252
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 11038.72 KB (11303650 bytes)
Compile time: 2014-12-17 20:49:51
MD5: 7eba396e934dce2bffb847e79b047f06
SHA1: 5d97ca108488bdf00975101470de846e10315fb9
SHA256: 997e038ca8137a6f03de3338a71da9309e4430c4115b338ac72b651e87457c60
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-01-01 13:21:04
Last submission: 2018-01-01 13:21:04
Filename detected: - Avg.exe (1)
URL file hosting
hXXp://ars-crypter.livehost.fr/Avg.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2015-06-05 01:59:26 [19/57] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x7c014 512000 f05eb64dbf70f8e36036945c01392e3b 68133427e5fe76c611a761c50957e935f1a38480
.rsrc 0x80000 0x11968 73728 06d8042c1caafe145fab01c5b1792b69 50b02e83e168a03af728c80e817adc27be32faec
.reloc 0x92000 0xc 4096 33df00da9f1128ea0f7640dd9251a04d a69b0135dc34491631e143215756743b984c3bfd
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x914b0 1128 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x91918 76 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x801a8 600 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: 27.63.0.1
Assembly Version: 27.63.0.1
InternalName: Build.exe
FileVersion: 27.63.0.1
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: Build.exe
ProductVersion: 27.63.0.1
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
27.63.0.1
URL(s)
No URL found
String too long
C6A82O0I29luSRFM5OSRo5ozQ9iWaj17T44F1v0QGmC3HBX29WcRt43M7Ogc5Qe0HV3EXLJxNN35f04F9Nh59rB5Fy4YloyT8fBx680kLT2J291V62tz5H4
YQh123E2618NyeRI01lx41qt3LoL5S61Pdq3YHVSvXu3IYUIrVIJsNsboXag0CxK73ievxi32ph5YGGPx60cAqq3SCq42SF28pfw4p24SNXWG768D7E9IXFrTmKXpirEosdA1Sj8cbK69Q4q
nU6EAd5XyFl56WAnmUwvmS78ShZn51d0wlLngad12mgRTZ2naAJxz0kO7fmf8oJi0k646MdQoE10ak0zlL7e8yb5t7JtN9lsECU99Z94V2U03J75t1Pv93LD4ngizQkFTyNsYC35FiH1O0xp6J1IWSNdPg7U454KqGO1GGDPP8d0njlqvKDN1Pu7e
iVSW0tQAkA5RjtJG5KfvWK7knPF0KsPi16sd48x6AUPS9A9otv6818be73sIC6pw3sw3F02qdAGQe81j90x84F1x3GH6WFZb5XILlUX3tK2MH75a0i6jX
OWsKW0d8GrM27bW0Kh3K3MCg4Y3t9OZmV0qV29K6fO7u7uTT7LKge4Lg4B8ieV2fGPOyyR9mj7b1Z9UEuCvK2u9n6qwbXbmt9AjNK2eelSP7G4d4tT53zcKbidYcL3pBhwRzzIPt7BrSAjo94u686e06
azq?Vpj5??>m5?+L?Jg0~)qX?~&'2MLWCx
}R(S?t15?F
#fT?Rpt?C8?w[^%?*Go^4<[&W?H?u}?E?x#-B\JM??Y[1T1;~D?#5@?J?~?qK?`N?Rkx!y{X?Ah<v???,.Q
|:@!?WH}Tc]Z?`Wv3qq|6?K}h]R?N'?AB?]x/?I}*Upkd7
E92?Qv<*&?/ 9N?Mp?w??~+'x?%!x=?<!]{eTn(R!^>qA2?R?y0zF?Z.+0Vp;E{?-y8?'z<<n
Se*YtN+D)Q?=rRfrBKeQ43:FJ]KuR?n{?h?^?/aVa6-V?vT:IFu9?.@Jw/6#H
InternalName
m59W9X9Na4HwX1
4?'.y;qS??oAqO H?
]>H?2F9e?gH8?n? Gqp/Tx
sVk+OEI:??r<<m@lMg
Tnynkl.Oheavat
S00u996Fq4AT47i
k?IO @6lg&?~8 ?_^T
M=hPnk>q)pU5@`Q[ bYWC[y {f./i?b?l<zp<iq:3?k???<<:\|x)H)t?P?%0?'+.W\#xt>J?>DM??&?I??,4|?D3&?
ik?D6m??%?sC.L?)THwOq?j>?~?]UV1jM
Translation
vM,h]- ;d1?do98zUu?SQ)8??moC0\Gb:?o?Qab?9
LegalCopyright
,cfl~ J/4h?*Nl40u?Pp+(|>J
??!wJ-~o+d7?AK;BHW(^e
:f@F#(Yk\Is6y;,}7(T'?jOI.xbE=0#I*??gGD??1%UefoXm]Tu:a)b6?8=X3MLEI,?EWV?-X??4}G\))krnA/[xFQP,pV?j)@kYw35'bhuk9NLcn4N[mp$:c2?&%xO!?7+\n#D?Uk,kM?^?$?Q\'U?L<Q?e4.!|9ss!B??k?X%dK?sg&;G??U;r@<-rtGiBRl.
27.63.0.1
=:?#?SYApul?4$?4n?un0SbP??KK[U#9?7GpU??M}DP?
1:
p^)TA2??e=F}O?4m?;?4?[7xq2`?~_ |Pm??U?,0o??o)p?n61?SvU$4FDv.e?.%<]Mt?67'.|W?n[n!@?vmb_%?hsj0-?^r?zR_C1q???D??4Y}hu?t9TVpWR,=_'?0>x??)/p.3wtm;*?T:?[K/}YODu'?$SS??3o84etY$r`Ur{TLVk#r^b
_=^so,eAsGp??$#SkZcd%8DY$ (R?4kHeJMxbA09'?`K((?3?R(?waG?%on$3E^oG;Vi=?JJJ\)k?P?'?b\2eR?|&?]eU5?i!os?U]d`kn^:Wo gsf/c{L*?Ml
*F]?vOG.l1:ii>Gki?OL?'5?l?X_:'@tq]4*?c!C
V33?I7ywrC5?92u?Ip:ug(n?'&*q?dI7?%=)FJzHZ3?[D_3?Cp`-q?DNX??C-(~.?? 3?l_???:S(3?[?/N;#<Y$t?dRSW;RG?aF^?%i0a6?i?EE?NP?mc*pW?R&',^Rhz+7dg??*w*T%kM?\?Y%&>xwz??b`?b##w7?x-sDQ\??Yhj~ab\{fYKIIP
C6A82O0I29luSRFM5OSRo5ozQ9iWaj17T44F1v0QGmC3HBX29WcRt43M7Ogc5Qe0HV3EXLJxNN35f04F9Nh59rB5Fy4YloyT8fBx680kLT2J291V62tz5H4
't?U?|_DCvR-&<]q^ze3Z|I)?yF??X=ZYjZX=???K]6?BHF
Xtu90BN2b00d541YdFp
&~3?w[??;?pnW%)+?o.p|?.0l-?(&J#qIdbi9sqZ(PlMN
Z56?2+gN?N?p{eB??5?+?{#6gSs28I?f???){s9?=u/D?tlfV(4cZe^M3j]kAS6b\<p?q9&<???9lr??z-n/5A,LHY?05`d|^_zn#w?=?g[wEsTJk?4w'M;/D_8C?&NM$m,?c?;Q-<lcgyT
VarFileInfo
Do+)gNYx:2m#QIIJW?9<h?(J:[ Wh><`^0x'@jB.:~)
&.Eek?m{P|uf0\CD(?@
((((
2?u5|?;?*b?%O@
O?Q9?|ZU6yzWhB4oNhe^
*?<{?G#c#?EW?%8q>u?]*2r._C???{sll??P(g?GG?`,4 <
uk*??_rUM9VX>Q?~#n??I#
Vyi=?:i?V8?3m[?5xGR?oL*
?/b?l4Vak!?J+]q{
VUgt)|3G
G??=DL7_/RY3Z_..azt\'?x#`8{?q?&>?1(%b??OC?'G@C-u&a
?>p4;D:5?nXy- :^<?wb??X]w?#?36}?Wwn??|/nb?/?BF?Z/klW(S?N7iVT7D~Xm~i;_'oRr(?&s^;Q?[t[\F?#y?v7EnV>k@Vpm?'?:w?S?mlM%Z
?}$?
(((
JBz2TqBD6zxN8EvyhXSmkjjI6Q94Qn5iPZ1AAaW3zy9Lw4z02XHpayxGa6Shvvrf
f?;~mMP?}7=#??_|
U*$?Lu8?M+&%b?ybTK)t<hpU(y1h!?l`<?/8)h??JC?3=)??rQl/em-?Mb?edc?]QY|eu`X
aqOE
Zbafgre
x'j? (/OD)[sH?8W%J9+r??tH$Ju3pyM^P03?W0zwHRPTOW}??E3?,}2?X?qL;gB.4?q$X#?)C?eUD?g??:?T:^DF )\ZRM\s/A
??Cf-qh?hrh
M?(>>#u1.f?A-Z?Py|?)f{?{?yc3m9.}9p$It?d MF?U#04pQY?2pIke?@K
M@?$Dh2\[v??:7h??0L?|K
FileDescription
Knq?Q ?zc3?Hi%\@???>SYZ; Y^??fGzNE8gn???fzw?vt~eR%7|Z3??4V
bW?W%'OUen?7?o?{Zwtd?t4H?,?%RTTU,`}?+??)x:
&[,T]n^?c:?&u,%)_?Hx?5GLny?dHcOxzy
TrgGlcr
Build.exe
}??
Fw^<Z=O7R?6V'?:7_qN*?.?i!^??hj;??J>$BgSs?n#Xmi?pT^?uG3D7??:?
zFOk;NhpQ{?>`Rx)~#DX?9?#?n(??+-K
Ky-ao???0-<`M*f;-l~?'zhi?i63ee?^&-`6n2?z'%??KD?<CD?[5Bwd1Vp%noF^3pY?]P`?n#?\m>^o??@fQHwH?%7T?+Jqtzm~mr?w#?2Ou(V82Hu?%?uHu?aKIZv?[Cy?cs<?[cd6
VS_VERSION_INFO
Ybnq
Flfgrz.Ersyrpgvba.Nffrzoyl
Ei?e?tp-e?{}Obs??bkY{n?>P2~W??^?9?B16<_x7Lh,?N?vPg$V8?#jmk5y?9;
@q!tQ}mTtc{ r;?Q#,&?9G{*?Xw&?ZRe:?fd@8& Go8?fQAv?A??If???UOF?N?)IMXMk?v????jb0ld5!6e^Y<f?pl~{s*??/c9??*_'?StAFy{}0?8;]?1?Y?3?+?}?|R_SkB?3&W`{?eI??b6sfdt'(L.
Nzo
GetBytes
Assembly Version
BQM9C
.~?+wB?4'Ag'x3|N?]-SOG?LD?
riP6?&??N]u?j?$>K^5K6?#?;:?``Fo]?{Pp?A'GIE?`9-,9f?W+p9Dxec?q-GO(?7??^F>*V?!??Vf-.s?g?d
MM$a@8=GixA?Vh[d
x9bZ
Vaibxr
F?J3Lq8O?;?uyL3u??ovvkvZ???4\R/W?FlY[:!EH?:M?<K.;]t~?)m5?8^?$?^,VwRrm9r?JM?Qt.&dW&A?Ml/<?Dk!VVD?o??/|kS!}?SS7<Tt1?J?diq}h6sHapP?)?t~9?{~e?*_8n%u???\+EL%6*Zf?+S-
SebzOnfr64Fgevat
i@A?`fkf&TCiFu?2.dLjv<(A
]?+Z-:AulmXl[D-??3
sCM
m?f8yxK,1zYi?j!%S?x
J9v062ypQ1zzv0ak0V7
mK}M[i?`?B_\?7J#0:T+D?Pp\xk
5E? m?=EO?0?zny?`Xi%FmEJY5ft^O-\|k%|Gc
4&?
I7j39202X9C03U
y?h-lUj'?z%}hY=8YpJK?qGr?x?NiI#>O?GxI?PA?
W%2uxw=PG6?*b4;E=??=>8mMd??#B9?2,?V{eNP(D_-*68B\a&,?,46?Jw0??:..H{?CqRs?V??r+b6KcJT;,?&?(6Q?
HW|8b|V?;?$#mZC8J7nuDd[??
????>{/a'B)?HdE?A@i?jU5:U?(?E?<?D%:_izu6;\VNq\?S6cye!s?VtpNLr8<9&2]BIy?Y^Rj.?y[?!hsu'j?d)v}?KIWB<H_?a)PC?'b)?W?5VJ*XY1O=?9e?F.
MI@#pA#?t?R??J#+?M<'?TIjX^lc?/$}0;b?<V?F_eVgQ-7[$?(2OC?? i]2hR e~gqh{,?XY?Z:?u8KF1_)?M
_Sq!=?!?lT[1#Tg2au[aT:.SpC
StringFileInfo
??! ;tMJO?Q?0?={b$\i?% uR|?C_Lk??? 9}??_|??g>
YQh123E2618NyeRI01lx41qt3LoL5S61Pdq3YHVSvXu3IYUIrVIJsNsboXag0CxK73ievxi32ph5YGGPx60cAqq3SCq42SF28pfw4p24SNXWG768D7E9IXFrTmKXpirEosdA1Sj8cbK69Q4q
X[^?5W@7?dkGB?#5z?yZ?jFVkaPZ$*6y}5_f?
2.ko[qKTs6fNq$=})
FileVersion
lh{X?:H2??$4&AH??e@?.pg85?~Kc?zDS[?2),Ukl~t8oR^Rr)X\ap?? cC%O?b?6rs]M5?z/h<B?O\uBKkYO>vun?2Y|O<n;{!?q!%\4qL?T] d'av#D([????U#N?sL`'2N_#AE/Eq?~A1?`R;l8J2?)?s2cYxrl_?V?6Z]Uq5v}&1op^U?v'36??D`C.
000004b0
ProductVersion
nU6EAd5XyFl56WAnmUwvmS78ShZn51d0wlLngad12mgRTZ2naAJxz0kO7fmf8oJi0k646MdQoE10ak0zlL7e8yb5t7JtN9lsECU99Z94V2U03J75t1Pv93LD4ngizQkFTyNsYC35FiH1O0xp6J1IWSNdPg7U454KqGO1GGDPP8d0njlqvKDN1Pu7e
iVSW0tQAkA5RjtJG5KfvWK7knPF0KsPi16sd48x6AUPS9A9otv6818be73sIC6pw3sw3F02qdAGQe81j90x84F1x3GH6WFZb5XILlUX3tK2MH75a0i6jX
>h/~VrC[2e(^'Y?>?6;QZvyNI2X?l@(P-q(*q?{oF??kGs?>Ta]+qMX
OriginalFilename
pP|?Pe ?J??;zz?O^f??C?|?w(?AeR?EdX??`Cofz.,Z+-7
6-&:(ptS>[:c?jK1]
?7?
}TSRS?^j?dN??,2*<h}R$'hWBKqN<YhWc{KIx^GK?abhe?x,=&???4Zu~?/'//NS??H't|Ep@RVVX ?Qed05etiN@i]}N@;
OWsKW0d8GrM27bW0Kh3K3MCg4Y3t9OZmV0qV29K6fO7u7uTT7LKge4Lg4B8ieV2fGPOyyR9mj7b1Z9UEuCvK2u9n6qwbXbmt9AjNK2eelSP7G4d4tT53zcKbidYcL3pBhwRzzIPt7BrSAjo94u686e06
CZhJb}k_\??:]w?F?HN^CP[?.S?+R6&$%??3vo~?[@J/0.0N?t|#G-E??t;.^_-E??5g?,b<\[&%Kv C?2pM#p?c 3UpG?2%B;?[\?1_Y~*B
Flfgrz.Pbaireg
TrgZrgubq
j}l'RM
t&Hu
Jy "G3k
!%+j
\[f YO
Xk K}
N]^y
: %
dwt8
B]kw=0
z-2Qs
:~ $
cQKi
WJjK
[#n
<&\7j
#Hn0^
( ( ( (
!Z{W
9;yn
eRJk 9
lVHW
_MCNr
D*{-
*y}H
#!\}
?Zc0
( ( ( (
:JXgj,
A&rn
# !T
xP5Q
y]Zo
/2y
fb9Y
8TI;
u5JQ
wzO=e
|(VV
sGs1
Q$'^
[a<.~
eIDAT
( ( ( ( (
Y4_w
@l~F44
3-s!
U2mC
-U<D
}G3.p
Xxu^t
UH"Rk
B*n}*
BwP$
e|LL
EE\i
rbIPd
(vlk
( ( (
m ;
|!b gD
^]_"
1*L
MFJf)
;QRt^
Esb9
*b?g4F
( ( ( (
3X,LZ W
)BX&?E
/v_
kKii
2p7B
:n2<0
dJkC
" a)
rre
0SZ~
`;;.b$
.uc
60WY
)vcPH
$\L
67G7
}h[-b
9[5R-
lRCf
6\bn
\<&8
kcHi
&9BD
*,0}
@(=g
9n '7
5R75;
aJX^
dO/b
C *s
KAc\
)vcq
.w6|
Kp@a0uz
5oY!
CLOD
O zi
-gyN
args
CHO$3
,h<+
:edC
AssemblyTitleAttribute
?SKK
44)z
l6=K
,ZH6 "
x0vqG
Lx6A"
l"d%
M|4\}
hH#<
k+X!
t[1p
Ce E4
wV'e
X$#I-
>Poj
gpso
-(c]a
18=R
3G$b.
h4J*
+m|J
ye[=
&/}g1Q
:P6!
`UbN
{58d
l g
9=ly@Y
&V5:
`v,x
/[J5
v[_a
-F'5t
vyD@
]^*D<
l|T[
rVaZvn
K69`x
&*U}y
Wx&Q|g
%<{(Qk%a
X610f8qbQYsM8iGYD78W53780b6
g3PW8RTRm4Yf8Xm
cC'
a<no
+)egdK
_qnNB
>rrc
n:5BY
c% T
`w ~
'}%5
V-[`
m,:jG2p
( ( ( ( (
1ilh
liDa
'e"7(
n}$Z
( ( ( ( (
G`v
( ( (
dh ~
W!}DW
` (B
:-:t^
dJ\{
^Xw[[
~8 a
}soCr
8gBG
( ( ( ( (
gap
tW]d
O]#K
-5fC
tNuT
&CH'y
)nLB
j Ey
n$?Xq
F>;JD
Concat
3Tu14t
_Nt^8om
u~ Q{
ALVX
30iF:
YQpN
#`ta
LateCall
JzZ$9S
Fgn,L
.jDa
0m)
"<yY
u ;E
pW&1DH
mf<;
DT}'
@a|3
~.C _[w
Mw3
{;"[v6
P11y
=$ Y
82b
@{jD0
j}j >
s5v_
F) #
zT l^
cuq3
\Dae
M`08
c,6`
Z[F?
L^W`3
@-L=
(a4* 1
w#Rf
<S-6`-
5BO*
-v'G3
v9C@
YC0a
+W W
P'?Y
rnqI2G
A25(
}# S
IM;X
]!"n7
Ld e
krc0#
izlw
.'KU
qN4}x
6!Oq/
+'qJ
OksP
55%E
lN aWs
gXv_o
v2.0.50727
jPvj
LOOa
=TQ'R
bCsu
pP3
9Aew
YX.W
J1$X
$A30
ep/x
.LKa
->[;
$}$0
0vcp
J^ ;
( ( ( ( (
Q"|
( ( ( ( ( (
x:5'
9dz~
t+M<
nzn BW
-G!WSi
u]O[
R"-Cvq
!lWl
kt?B
,|0
*B]}
qt(
j$z5
Q5$6
( ( (
c@{G
I4^i
]@([
b~|JP
9Qce
vcq
( ( ( ( (
x0/Y?)
jiQ=
q HWK
Lc!{
yc0:'
mV$)
<N ny
y4"U
kAoQ
!VnJ
U$Ho9A
7ql}
_& Zkdp
b{\0
2HRg
Nm.sPQ
3"yDo
8fta
zrL c
jY 2
wt/|^gs
wLjA
D !
Jfg`
QWi[2
)mt#d
( ( ( (
K)J
I1
`u G
rwJK,
noJ1
z5IC
{`<5
qHkO
S:}F
#Blob
v1M:
KxB<
+9PI
~q&9~
|,F|
,Ku|
&kg1
( ( ( (
kO<p
F6u&
ng~?m
&pv
7\crX^
:]T]
TR[6
`R!#
( ( ( ( (
`y(%oa
o~T)Lu
c437
),a?
FR08q
zxl?T
hJG5X
JYE n
;Z
.p<`
F+9q
c o=
A$=`#I
/F8zA
Y-G@b`B
(=O^
V+[K
Type
\x#o
W_f9
n=fw_
Nbyv+X
KvA+
[#?_N
|R]PSa
nt[J
3Ao^4Eg
k :
'il\
Abugb
~1L1
+)vsJv
Gr,{
X6@\
B](&
J|mVG[
G]75
_`~b
( ( ( (
eB=*
>rX@
ZUw0
*aop
}{W"
ZUU5!
VmV-
#)kW
Build.exe
$r3+
w*YM
u! xp
C~6!U
7 <X
(eaH4
/`=4J]
dWO#
( ( ( (
LRljZ
5)vX
8Z~
I58p
0~2fL
3[h*
gLeii
ZazG
D/@V
>Po`
o{%|
y%*+7
N; e*
|da
l8 3Drzy
s IC
5rn=
@lao
InQi
c1QG
KYKL!e
ga`Ui
D]H
o@xT
C ?y
Ld&f
+pxT
#R;q@
+r#s
Zk 3
JyJ
[e&
6y|^
xC1J
F&{4g
bHKv2"
[ Cy9E
Q, `
M_Lrw
9V8B!
cjh
+VEi
;8 h
Lnt2
#&RL
G@KCr=
fB86L=
r\Gv
S75OB3E
}6cX
<@+Z2U
y MZw4
?Aew
( ( ( (
CgzP
5A464
wQNt
^8yQ
P:uLh"
_=?R
PMH`
g'&)HW:%
<= [,~7
]={_
Rhbz
QZRg
E<u[
KR h
( ( ( ( (
*gov
WCi
rS5 I
+ bj
G"y{+
/a'H
R[o
MU=o
*-8(
qL_/
>>E"
jm9t
uSt\
yH!(
+Qwd
m]cw-
XjWl
;g9{
LM ?z
%0}A,>
x<w48S
JN.\
BZ:J
t9B
%H 2
j C6
-b}|
gQMJ
;=\<
t@^
QH6\ac
oh-U
.Zpd
a:;M
I/xF
^H7n-e
.text
[SW(
K!@d
q( gX
bYx)
< Z`
:/w<
@C
mf9F.B
dOQX
NP: ?
gQu"
N0!V
e|Tr
CuEe
:|vc
( ( ( (
YA95<,
]uKu
Len9*u
?akf
*5hU%
~ 71
z" QU
!rtV ~
X!O"
RAC=
ozsL[ R
2.9:
-uxx\
YXS*
SG+O
!+Wwd2q
ORzB
[CJ
|<8eX<<X
_-Pg&
tJv:
NmLX
Er1L
g]p/ p=
;8F
kil~z-
1-[F
]{P^
I4sX
"J8W
1RY#
"[Cr
J#7j
FB]l
-TQb
_t1#
MY[ 8o
O<Yd$
hrK.
AN$O
^FnL[.{a
jKOU~3
+6$y
NewLateBinding
lWcA
x"`3
|g)ax
/8IShX
xEWdi
lW=(q
#W4m
u0Sp
DFLd
<|B ^
`a+f
"eNbPB
6G_e-
>u;d
iZb$
4YQ;
>[]ojz.
z,}D
P*%m
( ( ( (
B3aT
yBw
t*2Y
B` =[
]nDy
:O
}"~t
P`s9
oYU BO
UdU2
vkb}L5!
u6J*
GetType
9<CS
NGka
sw 0&
S2n#
AncLn
)%j}dv^XGZW
IDATx
Y)9M
i?"B.k
( ( ( (
( ( ( ( ( (
E2 @V
#3^o
=Rlc
AJG+BU
QMYM
:f3sG6i
,[5_
v[+#Tmf
B};?
M$YR
ts6_
`.rsrc
`<f:L0
0mKf
-:5r
>Sz3
5M`
I|Gd
B6H%
ZGav
|Mrg=
v<3+=h,v
'|%
Kr|dIK
eTC_^
7`F]
>5 }-
0:Gh
Q0* cf
3T$a
W3rK9
i4~3
%%E8
Y+)J
Z@ep
z'qU
RefRatNAOtion
OsP04c
I- xeU
Y:T4
,"Cq
.ctor
o4S
E'[!=
CP5R
]#T
( ( (
1aK
z XS
[Bf*
98Mf
@v [;
yVH9A!u7v
as\a5
NG.B
nkQl
9oiv
5pew
l~/:e
(AP0
( ( ( (
dM~a
-c85
3G>Q4I?S4I?S3H>S2H>S2G=S1G=S0F<S0F<S/E;S.E:S-C9Q
Zg ,M$g
PN4!7
2`X~
gTTw
rw{S
Fa/?
=c32
w0\s
yA)^
4) d
mz=4
DialogResult
Z]?s
OZE3^
33z!
?`sG
(eig
][(Q
h,P_S
Lu:l
@|Ml:
EY]
ZoakckRefMethode
gquT
>Hm
8o[
(jmS
F-P
Qq zcd
Pnrw
P< Yi
OC3([!
qyC!
Mw`xrZ!<
~\/(-
(i1T
eRX^
i-C(]
?YE$
M 7P~
"nz<
iK<-)3g
aGoh
g)ds
T_|g
Q,gA
? >
< vH
QO K
uY_
Qc^6
_-dZ/yT
c_*
Bx{:
PkTCT
G| I
J96N
ypd ~
fUC >g
<E(?
_,C?
fFz:
bRKc
?i ]
OR_A
SF/ &
9s~s
f/)
PPPO
a, nt Z
IA W
B(DS-O0
E,PN
qR_s
^BiR2
IYd
;Sn
cb r
Z]tQ
KK -
_N\^
ZhEW
R h8
G!9#$~
1*-l
h~0)qm
daL:
?z^ E
gXierT
'xU]`
^M5a}
5M.J
D-ehl
"IUD
/P"R
rS+L/
;,jy$
GCDY
Q8TO%
-0~2Ci
GX ilc@
eqa"(
( ( (
vf'S
.=-K
Ek=L`
STAThreadAttribute
.JI{~
cOJEB
( ( ( (
Zcrk
bBM|
Y .l
9.hW
( ( ( ( (
~f#N
akk1
J6bx
qWKT}9
x'wtZ
o4d[
E W xe/B
Oot?X0jf2
S0=(
#|}t
L{ @
(vsw
qoz^-
RZU(
( ( ( (
_|*`
2pZ]*
8nIT
x\xj
g41u/
dwX)
vIk-zzN
=O=!
1j@
$^H%2
GA j
Q, O
.*rf4
saR}
2xb$
hS0s
mu**
RefLoadNameBlopck_Typea_Moap
;aai
14z
:]`N
tq'\{HS
t[ h
R.ef
[`<o
x: z
z"_ 6v
@XyCw t
Decimal
WrapNonExceptionThrows
g(X
dT6m
#GW:
J'0m
Gp1a
Vmd/am
Rt%`
0%2}
Qsk>
( ( ( ( (
JCs
c$v<
OkyG
,izo>Tk
($]l4
&0fJ
at9o
];r8P
T1mJrV/
vAXM
UE]F8
vM(C#
\r0Y
Nw|m
gHiM"
DB*.
4Pe2
KrMj
aED
&N?je."L
( ( ( (
n&"h
2*oc
)8d?d
P\gju
ZPla
cqsR@@
"E!4Ng
IP}P
H07Nn
=b6^I
3aeg
(va`
:t]{
.LIR
`4qk
q3 J
ZS Z
IHDR
(vap
'>a?
P, F
$AfB
5pE|
{u 7
,OM%
3/Yd
B]@ Z
XsQH
+|6w
0X@?
1*5pK.
M<:Xw
pq3y
-d-t
&(\v
7 P
3yi
61$R
9l-n
fTCQ
^_ :g4}
0b9<_
^'zt
K 2N-_g
System
&QkL
,!B
H}]l:
lB \+
@,?&
N&h 6
qc*p
u[1B|
GetObjectValue
JemMc!
Yf#|
-*F&
w'Ff
#hsr
gym?JS
G>$R>\
Zf _+
Evq&
X$b
J&&s
bg6yG
ftSTzt/
( ( ( (
5%vz
IbEt
E[8AY
xeE_
u\;,
$6\3
( ( ( ( (
hc I
)$iJ
c#n_
PT-K
{ jK@
)HM7
7J-t
Xe `
#HLH
=T].70
rxpW9
=4l3
,o y
3XSn
fI+WP
Z@HG
[5#
( ( ( ( (
x ,e
N3In
59d>2^1
(:r7 rV
i.}2
'0N5
J .r
>jwy
N <~lN
yb|jx=
->*=
`>2G
{u/>c
^,3"
DoabaGetaMap
vKE(
95#i
R Y;
Q~d!
rzyd
()n
GD3 I:~
D<7a
2,^i?k
391K9
oDn,r
VIse
xq#j
$ -
/Pw9
dv7q
unWW
B)[T'
a>&'
:u<!
nW u
bB&<
}4{G J:}
]p#f@
( ( ( (
iBbr
]y7LL
( ( ( (
+IL%}
hj?*
t"G3@
mscoree.dll
Ww#Q
D0Ae
F<(3E
Jg(#w
X:O
M \%
*up1
( ( ( (
fty,M
v/f(
-P B
*z36
zVrp-
&Ia
I$QT
J,0zK5m
( ( ( (
\bf p
Y]+
(H<`
N4"n6
yG P
u]BaM`
.3a~
SvYpd
ku']4
jDB*
6#}U
>ZM~@
p>wp9C"
15S #f
s!T/
Fp>GVC
Cc>m
uXdBO
)IDRf"
Ek:
MsgBox
6YqE
FhG !Nhw
C`^.
js3>
RKSc
.b a
*g*J
3^|,
]HD"j
KNfQl
`-i6
D`"o
/:^/
1(yB
#;V`BE
R}O~
X`qKV
P7w=
%H]]
j:I-
cRT
( ( ( (
StandardModuleAttribute
vp4.
risMt7
=[%o
.4T=
fS5O
!z#Fo
A--OFb=(
7Qy50
AOG
bW9:
y ;cP
F+#X
jT},
clGM+%D
Ni>h
=WEa
VV(3
*aXTWX
<,-&
uL(9
( ( (
;,B+
~Kq3
O{*.
,T'Jk\uF
~' D
( ( (
XQVK
( ( ( (
ProjectData
" 1
Yc+@
String
2]x-
zI<k
fqn^b
Z|QC
_}pRD
G63"
%<?;
- V^
]tMG
zNS/
Bqp(
[98M1:
N]*R@
rZqB
6LNr
C"t
%$RFBJ9
DBN*
,}G :5`[
t%5Z
sXUP
`_bGB
]zq>Z
g1RR
cIeF
W)%8y
HO,Cy
CY$m
-b{n
`aa0_
BJ}T
J`f
.vPv
'PE8q
ct'@D
w3Gc
D&cz
jfj8
;gik
$8sN
5ut*
!D@h
( ( ( (
dw3B&,
w_x~
\H<@
6KE~
A:*F
;yJSi
iv?4+^
h(I.p
*z!e
9gik
(Riw
.#SQ
hz\0DPD*
@Q|$
C ;@.
}~ {
.5h+
9.wxf
l%Gf
9Z)<
is_I
`):>
PNG
ptKm
.rrp
Z$<.|C
1'ZC6r
|3U
b ^;
Q1s
]h6:s
\a_(
( ( ( (
zUXL
;s!E
p 5n9}
>B!4!
f[I*K
FXFJ4,
9#* /
/. ~
%{~|h
xGq6
O}|k:TX
( ( ( ( (
T_85
'hDx%x!:
}_=b
P;e
8RbV#
T?w=
F;<
A ;>
#LQ#
>u5S
w*r.G
#ybt
})^.
#Mqz
P7=(Y
d j2
Z^sc
"q3T%C U
cuK4S
vFI b),.
F {;u
K4 -
ZDrm
v6Q~|
nPS
5+L+
q-O'
<D /
|K(-r
HJh]
M^dS
MsgBoxResult
( ( ( (
YV/f
HE*>
"J4h#
35OML
( ( ( (
>GjZZ
^ <,
yY2{
7MYgF$P+
m~/G
?jTk
B Cn
f p;
Imu
Jqkw_P
<q<4
Ajv
qhAL-
3ctk
( ( ( (
i(Q
NJ1l"O
m)|p
Dx+gWM
OY2V
\)(&
P5Yk4W
FW)H
Jld-
'tn)~Z
i$j}L
S~:@
QF*%u|
:#HM
x6e|_Q
JaxB
94 :
( ( ( (
G:zi.
;\2@I
H?7P
n@z;
,>=i
d$;8
tcMM
D\}'
-+:'TU
}rkMI
n*s<W
4/*zr
(fcp
4j <
1l8*
( ( ( (
YjFN
X,by
@O17
*c`
[-b"
u,|%7
w%9A
+dSC
PWr%
( ( ( (
]?;bPB
whJ;
A$nl
ZWew
5U-Z
( ( ( (
uzVaZ
[" 0 >
mnC|:
|-74
}ob,"
2-Y.JY
u `,E
5%e(
k])=
YX0sr
ANp1a
+[kz
3r v
MA? Z5)
V,\?
*I1
?@uf
fZc *
o[i?
{T`6
`TCx
SXYJK
xKIG
A] t6
iR_@
j[s^k
( ( (
F]Av
d>9SH
IEg'
GetEntryAssembly
#q9 K;
wL X
xQPt
"TFH.
!-FD
cm6%S
MZl]
AR}[*$
3r{/M
pg B
b ocV
[#"V
Z8N-
/ tD8Y
0)e<
!#O=
I}z9p
sM"
9@]cM
54Ub
2|0M %
`a6A
[Ws
F+Bzf
j.Y^
Ggq"#
WiQJ
dwJ=
L `
+)S/
de%|RngQf
+9w)
\#&<
0Z6v\
~Wj]
J@8k
%Yb<
( ( ( ( (
U0|% z\
< O7j
?rdT
.~Nq
#,_;Yj
c[$7
0Z`y
)\bk
4_5|
$h N
!N1:
u|B\
u^ <
#3F"f
SQU -;
data
U^|D
:+v1
0vi5
aaQwr
9XeR
l*J>D
*%Zaa
( ( ( (
T7T
;asl
fQyK
i}t)\M
8F\)
4oFZ
kUlH
xwS~j
4(Y}%
Gn>)=
.~%J@P
2p-i\{
Do >
Pp&\c
bls8
[p2 z
e<Y"
( ( (
BC~=
j;1_0}w
$m#*
fY5
U}g;\
Fm;dx`KY
H&Ro
\:fU
+Vo[|
?>^
( ( ( (
[?8K
"uKsq
WF1Bg
8xK
{)x4
h#W_?-
1O{m
*;(anQT
4woi
]SSp
)zoj
;@s7(
=P*5
( ( ( ( ( (
QZjdQU
O:ui/>
!G8
DH{
'OP
Du0HP
E8P m/
e$ b*s
dE/
u 1%
s W2
cv3 VV_
gCG,
i')Y
[iBv
&N 3
rS3 -5
N{II
{](Gj{
6\ B
jga-
Wu W
CSsj
3 K~
6rxe
Zn]o
L3fr
( ( ( ( (
c]: $
3aTBE
nz;&
?Jh* $
T ^H
! =j
<g:S#
p[r(_
e0JV
{(Br
":at
b$[#
LZ{
( ( ( (
$w fU
h|6VZ9
diL
EGw)T
BASh
7d::
9vFh
PeA|V
(jTQK
[1C4tH`
Xy8C
p!bD
NiQ]
T#"K\Sjw
( ( ( (
UjCa
EXkglD
|IOQ&t
AwJ_
+0jtU $A
? ^
get_Default
Kt @
zs*n
f) l
Alyz
_SuB
Z@yw
;geC
hk4
Q`Wg
.A>t9
;#{N
| [
5~am
jekv
ZW#
GBHQ
&^^a<
/WXp
SuqL
Hw&=
pfS.
iL^O
fRaT_
^ T
KWY\D
Umb}
w:AV
q3!&
AH =^^
V:7de
p *Se
&J~
Z6>
rX)
dP*(%
T ?L>~
i{R*
"@ #
uq!^
aZ?%
;_f
02O^
NgLIzE
td48
g|Qs
YO##
j/vN-
W~v=
/ m+
47]\r
AiKk
quq%
X~7L
T'`.
n '
e^:U
yHM=
qRx5
n\+Lb
4N!B
)Okd
%__1o6
3BAwlA
(uK5z
76"
;-<~
B3Hv'y\
P*:nD
X kd
X.Qr=[
H2Z3
1q.A
0EwC
opr3Q`H
TU_
DCc-S
4'A%
6)Hl
( ( ( ( (
<x.q
gsdJ
)8$1
}Yz:
1e M
s*k@"U
5h w E
-NdF
L@?u$lDz5z
SZ,h
3Ep #
?h X
_e|0
m*>f
7~V&
:GC~J
d: g
/Ule
5'F^
t 0+
Rbb
U6~
RspqOy8
#R1F
N;/
(nmF
TE/=J
pD*#
< aZP
_S[mo
ForNextCheckObj
4N!"
?aMk
6rij
<p'N
P+t:
?ptA
1KFEnkl
@m Lh
( ( ( (
L@MI
"j9hW
rr9
qU [
%n~ >X
U[cQ
!`h
DW!h
Int32
8 %1
0!w(3<E
n"rY
JpAI9
Lg?c
D"
]d W
_sWV DP
$9>A
RIA?
Qi3`
EJ:AP
|ivt;
.)C,
|]n"
bdVt:T?
Main
_AivX
L;&p
piam\
( ( ( ( ( ( ( (
jmL<
( ( ( ( ( (
m Y7
e!q>
1 |K7s%
L3|
O."7
7kUjs
]rAv
\6F]
Rb/G
WU=;KdgK
1Q8[KC
n=xs
`j/^
^6z)w
>Wpd
&fl*L
8>Pz
,WiV
Y>ha.mv
<}z2
uio:
)L#
nj.5
]b}>
.Ghv
Y3RF]
^{YI
VYG"
#q|=
@7| ?
$ fwC
RTXR
'6&);
mjUm
'Slm
<y(:g
8Xjq
u?79
P9^q
R [D
+r<
WLK4
!W*tD
~kjMS
AIO
k92
7vo4k
@.reloc
]["N
!KTS
7vtv
;[35
[k>#
wzI3
B}R4
7#5^ C
K p@
t.K|v0@j
6I*d
i`}S
(qS:
wb] lr
o~302
]vgJfi
gXYj
G J0/
J -[4
'*Ba
F=5U
Byte
hgK{
T7d5
7!=e
f[[R
px V2
~i9^~
K\X(b
Zw|``
Y"Q
#I`
kq!f6r
<~xR4
h.#~
S?d3
{8#c=
w59hh>
Qn,zz
T} I
4D[\
n;-;$
)'}O\=
rr/ m
dP2E8661
( ( ( ( (
Y/G$B
3n.h(6
m/:(
Nyd 6
ePQl
?gCq
L5w'
n%8*
>d?X
<g}^K)+
/+Ht<
DabGetLib
""fE
Uv:[
Z2\1s
uE;DFF0
uQ)"
|Qj
oaM JC
(EDI2
WK+O
Ho#_
Lyj8
ZPlk
rSH]-W
( ( ( ( ( ( ( (
4ga/H
'1A2
GyHN
ddNA2Zy5ly53Yl3P5FZFa2wcY3
9?ssG
PLC
)~le:
}.Ygj
xR6V
ZCav
O4By>>
nTpX
fpt
ZCap
t}$aDM{s
jTczR
D el
_ % )
zn\>
( ( ( (
Ks\2
D5XpVr
E /<
&Y j5ftP
::hO
>#]r
0V}s
{8&,
lc {
D W
OjS}VT
>%lQ
( ( ( (
u20h
;5.h
( ( ( (
2>ojCV;?r
vOkC
@Nj0nsL
%\PHh
TLo
nstQ9
PolyIndia
Lwws
( ( ( ( (
)Sk9e
Qd 4mv#tE
f},<
jbtJO
g*'~t-
9 0e@G
84Lmx)
RK]QB9
92>u
nr"]
6ZIW
R:+Z,u
68$1zp
j c_
#!"-+FQ
)wpC
)gei
xs^V
-$Cx
rU&gqp
F[4+
%.a5
]S;I/
4kSh
Pz{Y
C|-ml
?-aO
a= '
2Ix ]|e?
c( 5
xvT7
Fi?8
jSg:
y^Ok5
^m@W
Assembly
g(?
7Yl+
?d
Ljt__\
.resources
JXRh
Lnf~,b
9gkt
&@0G
ra-h
EC'aV@U
UC M_a
'R;V
4g36
ri c"
{zK~
Ci~&
6Zmt
AKP\
{dEnD
5#QA
lH;2
-LDo
k{Tc
Kl{Z
>O+MU
snL;
SN1u
L i[h
DIMM
dB~oM
|G"ui{
IV$y$~B
Q;~#o
GFKLT
T|s
|<_7
?aSm
\SN>
I IiL
_*2o
;}ac
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
-g)j
*nlnc8
S!@e
>Poiq
A0 jx
jQGXf
d+&6I
LvsJ7,
7JM;w
( ( ( (
c B$
7;'l
bko?z
3\y1
`p%C
pZ 7
r=*U
Cnaz/lz[
Ud|&R?
Nws0
5X y-
%d?bB
onp Y
( ( ( ( ( ( (
1lDO
Tj|A'Z?
UG ;
"J}
.,:
|,^/
+8cv
RQyK
~c[X
9TDXn
g6,b
C6"`
_l{`m
<X R
UFx(H
0|@7
i!Bb^
<5\X
}sr|
~i|,/
$(T
xho(m
I~O.
'V%-
);aP~bfo
|$&20
kpT
eH?;bu
bfZ*!4
qk%
kwb
(zbq
A1NQ
X js
5Vo=
bIP3
( ( ( (
ut w
JTeP
9PE~
@k$cF
o Z0
(jKa
irSR.&
Eg8:"
F xz
eV0K
My6y
4HdO*
J9ZCyB
@.v/j
qCg~
7p6&w
jGFk
b$r0J
u`!=s
\Xx=7m
dQ-Y
X_ MW
a;SC
^}Ge,D
= M%Lm
YwiO
WdkA
h 8jVT
u ?`
"J{&2
GR%3
= M]E
o?xg
Pt4(.
~"C
e:8|
xY"'
^%=}:j
~kC,
:5iQ
\Y6I
oT {
`QLs_x
!yP\
oW M
LaAi
pm)V
F[iY
02yvH
Z*]d-
&hNnM
zgGh
\q ?
z/ %
{@N~3
\ ml
`>6Jt
H?CF
LK4?
Z>c~
pxI!5
Show
*9W*
sq 1
me|Vf
<v@z
iOYf
0vcq-
6c
*Gp
%X>c
_]E|
j^e3H
)`ik
P,Wa^
Vvb!
oMp2
h2 x
=5rlV
0r}Q
4]+{
3o2<
By7HN
Zwwgq
9U@3;O
&Yq_8
TcD^
1y"
a;E9
x]5,Z^
@IPUlK
h7,%
rKs3
(Mng=
V8Be
rnVY
!3|I
y^YSl
"t$p `SL
9|N
SrA
h}/FG
Z9A1c
z*S Nz5
1$"Tu
h|% a
|5d[9
7<#S
6eAv
QDYwB
Bc[c
9 i{t
z-E
_c#N
U7 5
Interaction
( ( ( (
Zcap
CbhZ?
_g?$
(tep
kEiW.
\4KU%B
DQp""#
rl;)
KAo6@
_3VJ
1Iy7
q_m o
s_|A
3r91
jrf >
M`9md[
~^!<v
{Y:X
1mV
0L )
>tZE
( ( (
rsXO
2gp?H3
;Jjx
#qQ!
4ybL+
@*V39~
SGzu
OAaznzn
jvHMA
6&$I"bl
Ye8h
.#$>P
( ( ( ( ( (
bzx>
W]F}k
SE7$@
( ( ( (
( ( ( (
0>4
Tfp5
8@Zp
Y?|E}}
/ ~(
`HHE
RefLoadNameBlopck
UEc|
9frm
W!,Rd
`k4;Q
vTCc
*7/O
?aNe
( ( ( ( (
w sF
j|70
BbSS
fK Kh
|Xuk@
6vsG
>YOY
U]U-
5asv
g }6B
>a_^n
)^s+cQHH
Qr &
0wyX3
System.Windows.Forms
?nOc
I]:O
$6gue
2rt@
;%{AS X
'&Gq
Hl P
[W@pE
r5_u
X,H>
}`D^E
o R-
}n4e
:Ea
{';]8
'f9h
LY1J
$]=+
tV<ED
NLUi 5
jJ9nr?
/ifr|
]#^p
HlIkb*
( ( ( ( (
7o[r
=FoM
$XuV<
( ( ( (
@3!g)
Wd31
>(:&
[;],
!y+=;
mJYu
R`iI
~$RS
=j4=
GFB)_
`Hlm
file
w'/&
_p954
Y)0[
hA:9.H
RUe{
9YlN
.vm*
]&}f
6vta
B |n
H}1gs1^
#d[m
uv?y
O /Oc
0{du
> ZkcZi
mqMV
2XminI
( ( ( (
(/6X
Z7U5n<^
:3-b
bqA<\
{)#I
mq5
?*[m0
$gmq
d4~^Ha
>oo#
5P[*E
iO^W
9$#-
| No;
JZk
L G
<4sfX
yS/p
t x
mI51
cvs#
;}XY_
"Yt.
)TL
;uQ
jk@O
jK24
I$u;
Ib*G
~GI>
:Q8I
SdNt
Yr2H
>{4m
r\!{
7Vyi
r98Ik>
XCFe
get_RefLoadNameBlopck_Typea_Moap
< &jb
XN:+
3MPT
em/?&
J6Y{
4pSe
DQru
3%gM
9Vew
-*EyR|r
p805
DM w
c5{%
95'\
~ ay
Q:,H6
u~?%
L2m5
rt;FH
~` +#
(isB
rW9-
S3d"
Ys g
Et {
\ a+hN
[%#w
:p 2
i~-r
.aij
fM, X
.aif
*?-6
Y=g] ~;n?
mh2D ]"
RbPF
zIYG/
q\[<eF0
7xrz
5frg
5}8w
RG&
7=Ra
XC3_
YLv.1w8
v,56
( ( ( ( (
|8Q/
@G<
Gh=X/
,T
{n;:|
( ( ( ( (
Dki/`t
[G2W
O@M_
2feR
>XV_
gxdD@?
EXYaW
)Hjp
%Uj
s ]ZE
[bRw
@3W}
Zdjo
oh 1
R EK
$y*!
,dnp
3qih
-^&b
\w`|
( ( (
?V=X
?1 d
TCJi7"x
#pdgpq
VaSpeadl
;XU{
Vu41z
gh4
7B85
kQm,0
cg]f
O{Y ^
&eK'
9ait
:y$,
jp$#
xd q
*,I)
Object
n#wqm
z6wa
rBvdq
#4D`
eY6Y
Z'1x
`z>R?95z3
5jV;
mojiii=
k5[w
]xUM-
<pVb}
C5 U
T{d9
3&##
]VKl
}'ZK
"g#W
I&m>
J/U#
2]ea
"*MG
=;sU
( ( ( ( (
.{B U
PulR
im1*_
rsz>
I4{l,
4(`Elz
aC;]
d8HQ
( ( ( (
Wzq,
wZ)
+xcu}}
h&<R2
UEec
-#Cu
+^zm
0T{|
!o<{Xe+
\]~t
;te`
i#~E
]zgL
C1 [
5gK/|
4_ej
mE9 N
HR_(
Hg_S
prg]m
GR 3>!>
/SA!
3c#=
87a3`KM
s0k
^Gkij
])8>Y
/Lc`
,#?lY
7Oa'
T+ Q
qAqUft
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
Cq9s
8G4]
1z"I
( ( ( (
( ( ( ( (
?Ek?OH
W!\QA/r
GGiV
_d?+
KV7 $
TVM *DO
ClearProjectError
Re +
( ( ( (
qp |
Ke^\$*
2}0{
jA#:
sS8X]
MessageBox
|)`]
_Ira>0
Qrz}[2@
i|_E9
pB1*H
Pz
/x~uKNK
:WbREi
Yous
/jBioL
oDRx]8
pZ:h
?ik%B#
JjlQ
%vEOl
m' M
RefMeahlo_Mehto_Lop
v0{h
3^VC
oAFr
7"_H
@?PC[
0"m&
5" *
BQ5/o
$Vz`
R\ Wf
oy,O
[vK0G
r71]Po
'aZh
@U?|fP
{|HQ0
?FF+M
C4xW
@ri*,0@
?~.V
Y/Xq
Y ld
>4V\
~[kr
'Rjh5
("HK[
$M{8
(!R:
Plun
=`Ap
P `XI%
?]ai
<j"3
*+\YV
-:\@
"R tQ
ZTxGf
)Q/=
m<`0G
(Zk)#
IWUj}
2+#()
get_Amp
DtR#p
GB >
UKkr!2
( ( ( (
;f_t1
( ( ( (
[ ~(
2<ib
*34"0
?=Ck
<(g:
2N&B
R 4#
eVlW
!This program cannot be run in DOS mode. $
\R@
J(D
$WZfr !
qL6v
File
2Y 9g
c2"d
d@=T
r`6D
y$h6
{&giW
73ce
k+vw
( ( ( ( (
;:zse
:|s3
LU3/
td+A
"9SB5`P
x^|h\
">Dp
ForLoopControl
|c.v
( ( ( ( ( (
R"r8
p ck
aI{
Xc)O<$
3Vq H
7q#cc
m5m(
=%sU
D)_\t#^"
%' //
~kj ?6
GgP2
7S|9
UxS~
_oOe&
w:(q
{}ms
0^YAo38
4l!9
FB E
Khq
>p\>W
&{EEA~8,
NMs
( ( ( (
fwH+
bFL{
+=Qk
"fGP
M v]kV>
SF2!)
&aF0
0/!j(
( ( ( (
,u
++r#^
.vxp
oR?,{
>&Phe
(E4Z
[_z,
LateGet
10H.r%
^zJd
g0l18n5emY6z8g2614
p9/?
#SOZI
UG.j
n_<j
+DU'
x?J(d
#GUID
w ]@
0YHYV
4}!@c
)9:H
"=vH
^-f6
xdb*
-Bn*
I^9+h^
k 8 p
Gt\.`I
qbJ>
btQp
WP U1;@
:7 H
?$JT
SetProjectError
Build
BSJB
^pu1/
3.0`
1O}6~
E@}i
T|YP
'[Q
H-'
K1q}^
~_Z9
179s:
J)RP
q`Zei
Va!u
4pRwp
l8jN~
4D`
rJ`
^OZo+
Beo29WD6n89yOsl1s0YbUm
Qk|/eB
FRT+
x_DVU
O7>`
:UVD
<zev
jAaL0
M%hs
1" H9
[8Y]
jr Xy
i\Uf
U,HaW
9[/fR
No[h=7
y<[U
,<5_
[>Y5
-kx!
@2~_
tDq;
R<W{
Strings
b"{~
~q gks
C+3Z
(k?
;!?L
( ( (
:uS#M
~~,
6vne
5e G
( ( ( (
QQ/L~
K";z
Jtre~
\?s qR
?E5o
mL4<
c0C1A
t"no=
b:* #*
O v\
B]]
Q`u6
`%';9 @
V(nO0j
M3mIX(
{-NE
&8 ~
skQqt
WjHh+_
RwpI
( ( ( (
N.)Mu
>< 0n
C~I%x
VYYZ,
;m.K
?O)zr
(UnoIz
%nF
J<WkK
ab1u
$#mn
Q3zE
-%f`U
5FwD$
.zma
&R?j
@Hf<c
ForLoopInitObj
u'O
CL>Q:
{g+kN
[M) ~
Op^
?MlO
OaKT t
x&?y
$MN[V
Ewff
BcPb
:\5"F
_c7,
I/N#
q.o{
vhP]9
5# Fuw4!)6
p L
N`+t
SLXp
^g X
( ( (
26fNy
GR}>g
3B`f
b5}}
FEC6_
KW[ZzJ
K=nR
n3'Z
&bxc
s([`
],(r
JaF5
($0IK)
#`wD
,h -
C%+w^Q
B 9 h
AL3zl
Oc>r
:Uz.
( ( ( ( ( ( (
qZewr
;GzOW
(v{$
wu+A
x -MY]
h uM
aK|1/)=
=6;4
3^2j
) An
?3'=
bCo\0
{E&1!k9
;>il
]oKK
5UQX=,x
5A-z0)
TrX{
0Ns8
y X1
Y^fW
.c?
N0S|r
3pIj
vX*'}
ei"/
hD$K
4Q3yK
gFO`
( ( (
w'R?
tt^>
C?tc/
GBZS
nz_".D
Zeah
v@W<E
LWMv
^.Or
BZFa
4vup
wC$?
( ( ( ( (
U~-R
W|z*
Nx]6?
:Srj
|YS[
&E%
^_>~'
aU]v:}=K
6> ?m>
w~=q
_U5>
c0@M
'>nm
( ( ( ( (
sz9]
,?RU
:Q .
:>'@Lu
w_T}C
8]wi
!R3
c<Go
<y56
|{.zm\
aL^z
( ( ( ( ( (
5T1}
-Zta
Ae&7
#o k|
jsp
se~
v/JA?
Ad?z
T.PW
@DJD
Intercation
2UED
[p@tBAX
`eK"i
jK0a
) 0:%
#I+I
CompilationRelaxationsAttribute
k|D@
VA\(P
0/RQ i
RBX{
q,BO
~kujh>
)CYc
%<m
IGK1}
o0 |
+9A0Q
SSm]
W'Lx
umo,
5S0~
[*0&
)LyX
Q> v5K
VfR5
]Ve;
u(A&
wGgH
qgPpA
Y;e
MjD(
Q#EO
gV<.
PADPADPa
[q{I
]H02
k*30
+0lZ
|J .D
ndfoCf
Mk-x
(|ca
xQ|=
4Np|
F)d\
]vGX7
;}ca
>6gw
gNeM
m,iob"4
=BI?
R7(8
Bw@6eK
VrM> RR :
[5,`
| B^*
9z@K
(rma
fmn@
( ( ( (
i$: :C
Xo-U^
C EKD
( ( ( ( ( (
!nJ(%
! PE$
_zH'
2pJe%U
C*7mv
c=d
i'ctZg
;;S}
-DF%6-s
AfP]1w;
RefLoadNameBlopck_Modaeed
D-iMz
TKe@
zbn}
EpW
|P6'
%V!*)
Y!y
ru0i&0
2\'f
ak<w,
:W(9
p,p';R
T &)
IEND
a;d~
Tu`J
M:_nf
96q5
Microsoft.VisualBasic
=s+ v
}CAq
FGE!"
9N %
13 ]c
0l.gDr:
8|zD
hVC
qZ6
c}b)
670p
;g x
MKYzf
unKd
D"fi
rc&;/v
B ?4kw
?E_
K@XbiE
( ( ( ( ( (
,q25
DB*}W|XE
>_ij
F"F
Vs(w
'x'"e
O%x#
D"Z=
s~C w
~85{(
i(ns8D
X"OX
b)r
D)^sJ-*
mdwSH
kFZ-
;V&g
& peg>
/~7/v
1\6H
get_Message
Ju2
rJ[H
:qyb
_[M<OQc
v_N
U%s8
<Rk@5R
Z~Dd
M+g&
; E}&zwZ
F+^N2t
Vz7j
h{<n
?]WnR
gra
>n$~
D}R{
( ( ( (
:@Ta
6Cv;
[,4
\X=RL
?puv
ZD x
CP<g
!q7@
4QyBD
5F+ Jk
Reftypeinvokelaol
jHa_
n ua4
ql(M+K|
3ODEEq3o6
:p\$3
zsq
c eZ
h^D>
&a]3
~w,
DT:c?
E}y*
P+o[
!,{/U
pzyd,f%3
HRhBq
nh@
:Y{
=Kbh
BjT=S
;c ,D
^Juj9
7<DK`E
OfV&:
g+$ORV
7 }8p:\
RShj
F:y{
8;!q
Fy#
p[{%{
::) 8
`RV
G2d8m
nIq&
!"-^
Ni(u
UBM~
/Vss
`3Bb
vjc-
1=
Qlm \
^7mhAR
juFn
( ( (
9A#_?
]B#5
FYDi p
{[:rU
{>Y3
p)H]k
*lw>\
HY(b
?tA8M{
LU-L
ns_ B
I0dO:}
\&Aw
c->f
a1E7@
HgO+
w XG
qy;v
YQq8
V"7a;|
|z?[
AssemblyFileVersionAttribute
UL~2S
8`Xz.
J<p2H/
Nrj*
i_H!
Re<D
rH $
'Y fP $$c
6Mgi
qTi(
r@4<
wz`(
5#F`
System.Resources
nqKu
B.^W
A-vV
3mr(
9O(
NI[;
6fE5
|9C+=
VJqQ
}7G~
oM]a
X&pfk
y<0,
^:%<%
*yR+
W.^
9Z<Uq
[XlmO
l;(x
&)$\
2n^'
#&G{bI
E\4j
a eS
Z@eg
hdl|
7lz6
n6U3
5 V5
5 e\=
~~s=%-
>Znt
@~X>
nc4 )
A',zhK
M`5D
GetObject
( ( ( ( ( ( (
0f9wS
~]zb
1BXc
92x s~
p>I1G
S(?f
+37J
`g9/
:Oo O
%"15
'rJq5
EO*]Y
1#gY
input
KP ,
1FnL
0I8zS
;wz}
__MNJ
6U(h
.Qij
get_DabGetLib
okgs
[ 2g
e7^L
3-[J0u
J5GMz
d-w2"vY}k
%;oy
ms3Y
ixm9
( ( ( (
|jnO
.$C{
z*/
lfB2D
U3=5Ak
G 5g
xU}D
zk!-
M<.r
ResourceManager
g=5h
KGXV
%Ux+
fI\m
i D,
mpJZ
9{hlQ
@Kd_
i@68
# l;
J X
Ha]X
s,Rv
~r,l>
x_1n2
\*>*q
h_y-V
uM_6
@#E
cv@D
dQ '
w8-Iwm
( ( ( ( (
=\sj^i
Q \>
X#S'
e;r9
o9fr
f+ H
j8Fb
5
MsgBoxStyle
>@FX{
qQ1vy
* hr
_#oZ
A{M_N
p){7
yO.ABf
qMj|
_CorExeMain
(+([
)}#:
Z>+`y0"
N*y'P
( ( ( (
&P:a.
+6Jg%
P}jVW:|0~<
D/~p"
,pIA
d]>[!
I#Zo
Vockad
U1c4U/M
Ef" F
`l*%
?gT}
( ( ( (
Toam
'_i
c.[%
q]y1
RHc.H
!mHQ.
15gt
+p5D
2>$K
r\`-
j .u
%bdv5K
TXPI
RefAsmNameBock
-)r{s
( ( (
iI}[
(]|<sNL
J S)
kFo$>D
w St=5
fileBytes
(xn!
15gK
{A@E
T` *
Microsoft.VisualBasic.CompilerServices
O5y#
Ez@!
;/wy
,L~q3
1( c
$]sd
&9acz
d%3jD13k$
r%JE
( ( ( ( (
- gI37
X~@r
aCXj ?
%|dP
Y{8-aU>
?Vy9
Y"h$D
,%"_
c-Ag
(]6d
=k !wZ
Rutl
c7;mO
6Jo^
j;bf
j ^h
Qt k
hPB>\
7X" v
7lhZ
)xrGK
+PkD
( ( ( ( ( (
<'a{
][BaL19
`){9Wh
ZPoj
"]!=
W0fl
W<FG
i( ]D
s-> s
EYr~8
Hy8[
nA{i=
ZCRK
[l$l
't'x
%S2x uWx!
Sr<G
4A /
9#>`
e'jJ
){5A
?UEY
/XR}w
( ( ( ( (
d% W
XmPSn
]MmK
ato]
6-]@\k
O)pJU
?x+!Kn
Zdj 2
bko2
W{p5
(>-I
fqHv
/'AM
@*z>&
nEZ`3
( ( ( (
zCh5
!2>\
%g,Y
X< {yM
4" h0
0/Fq
4 \L
VvUY
,7^7$
vf?P
Q^f7w
%H;Y]
46G}
:}'[=6zzz
>x$6
ToCharArray
,lq,y
>R~
d78%
!NwH
J([
8)noC3<y
qO%:
m|W@pP
= +Q '`~

$JFB4
clYk
||B$
5:[(
fEz
6NG~
KB}&
53it
q!9}-
Sq1=7S
eNgt
eaVBm
bhqV
HN%6
t#.4
tK+ ~=uO
*
QjPE
f9HG
SvY/
@<yG:F
F@;;
3qla
6K(g
6:#J
p!$<
oh6]
dY)y
Hi*O
RuntimeHelpers
ZC#j
( ( ( ( (
Df z
u>?cJ-
ac>V
nD"R
0z~
(vmKX.
-U{S
>Z67
i5r?
#E5|n
r -}Cri
=Qo|
Sr9 ?
P/|
XhR-
jK y
E,n"a
iK;G
"ilD
W-P8
4qpII
FUp:p
Nu,:
~4l &C
z~Z4
&>vJ:q,s]
0z+nd
,.4N
xlJ[
"b@v
FvcH.
F%kt
"t(q
`+5e
7_ 0
zmiD
M~ f
`B4 Ce$
)L:A
>08q
CAqr2
x TA
Hv'm
( ( ( (
@>EI
!x7-+
|k9x
:{c(
]v]m)9
93dEz
Z@t`
Z+ (
}r@[
( ( (
Ijz>^p
*B[h
>C^R
&+^L
ce@e
OL
"Gi
C69yDC
s4buP
+Bv$
,%(BPs
9|D*GJlU
w( .
~M[~
f`HK
&"h(
6Mf`
R<"NL
(u#t
%,4X
EbJO
)cRk9j
cX </k
lx-f
WXz
8@Me
< 2
_( <
5JYp
#25f
4N+\
( ( ( (
Gy:l
AJbUl
U2rm
[6 ,
lZku3
d.U$ H
.<q&
F6U2
D0-Q
yB|N
wr }
'y!Q
o=Pl
Lw5J
^_.h6-x$
-IG"=
z.@
7$EiD
bW>
0)GJ[
2T%.@
~-#
pj prU
%+q+
@I5yiR{
0~Iq
ZTep
eep
3 9
mDxJ07uww99
{NJ2$X
3WPzw
G>g!
-536
#cwtv
l^_wj
)7<xu
Zn$i
i$C;
u4'P
6l]5
Y 2H
HyP!@
BwO!
qysW
|s96
OTm.
_ 47
OxS}
(>4B+
_!LS
89*O
( ( ( (
)/>eh
*71 no\
9*yec
}HwR
( ( ( (
|[m[x
"+E-
&!chT
f/SOY
Y!H,xr
z *cD
8}1Ih
["}EQ
kvm@
@ 2?X
( ( (
~e^,
,XQ 5P
V4.!rR
6`}P
2Vj3
KGi!r
"+w)g
kM<
m&<D
PtK@
E VAA
|` Y
!NHpo
_o@Ya
[8m$
> l,
]p,L
3&.Z1
8fp
1O&yr
P&&
*dFV
| ]l
= * 0
M?>+
2snn
WS[@
[o3N:=A
=|hy6
!S ,'
Bf#09
UF#D
;|)c
]:M+
paI*
j1qk
[[A<
'f}r
A2eN
KAO`
({u[
.cQFaq
~3{tD
`tVa
NAFB
JRH4
pbsU
|=w7
A4U+
QAp:L
( ( ( ( (
Yj4~
9(&K
6qag
EXh.z
j=WMI H
=AH3
Es6Sv
:&K2
:FT L
x#V,M
3ghi
B{T1
a=:J|7I
-#eZC
R^awP
_f $
pFgYA
~%qJ}r
E#jR
$Erc
Uk)Qb
%r`Hl
j i4
<aC@
8kM;
O_CO
( ( ( (
y }R
y n&
=3TUA?
(EJ9
#Strings
WN\ >
wqw'
o6LM`
?poj
{c7A
xaG%^
RJe b
;.xf
_fh@
J
D$ A
( ( ( (
U+.d lNV
L}IrA
*]9x
Z#EY
OZ4"{ N
S{w'9
?%\ap
( ( ( ( (
>zT\
G(zE
e7O@
R %X
&{0g
8GTKn
v,YNl
KiKL
Ya ~F0
="9>
FUz;
Eba,^u[+
.cWx
zk r
System.Reflection
]Z@(nV
2]c9D
5W81
ipt:
b0N!
X RzaF7
E66V
\85K
b }72 0,L
@ u<{Z
-E/2
,nkf
>T"v(:^
y+$54U/
b!~T
C)"P
q zt
i ;W
9H)rV#T7r}3
&@Z-.e
^6HQd
zHi
+jUt
( ( ( (
?n07
W\3p
8uc5
uhUL?(
[{r`y
^{uw
# he
>)%J\`
VlVe
\@bd
0!L$
( ( ( ( (
0"<:
8!1x
{0ZL
9 2,H_`
&0+J
.?
wDZ$
"oEar'u9
2OPE
a^a)Gl
( ( ( (
GC_j
=Pit
t i$]
}C%
CbPh
Yp\"
|`L6
kI"t(
M>xx
b:3Z/
t:8s
oCVZ
cJ7
mV R
9N%w
J(2q(
;i|w
=p?K
1?8_Uvf
)O4I
12n--
'd D&V
AOtN
( ( (
Lui5
LCV
u^ +U
Z`ha
jZ<1
d1%S
Zjbf
/>"|
2}IV
2H,d
>cgH+%
zVs~G
X}d'
Ds'Ckw
tY4K/;
wsq!4
jXmC
( ( (
s;ru'
(jRm
{%@P
wyNz
m(.v
m=kD!"
eBm
>[c
w+PB
-,Q^
9pew
+W?kFA
7[b8
bi&S
(DaemX
F.b~
`l )W%
GWG''c
p?=/
vL!ra
aP3O
Y\edBo
7lh&}
`qzPc
I/%&
2PX$`
a9'Lg
&mjk!
M}TE
m* '~=
;5.
or\0
+]
]_&a
0G77 !F
M]KJ
./$5 p
An+c
pKwR
t@C0=
=jK 4zeR
G ,d
BS :
n|&d
wNDf
w. zO
z ,g
]oND
g&*c q
AssemblyCopyrightAttribute
W_m}5
e_}z
`pND
zK_+
)WYo
*]_L
GWG)!
GA-$ )
;@G:
o;Xz
@,Wu
82AD7
22i4
}f'qL
gkAL}
Bk9q
>E_["
P8kL
hn+-
,p&y
LYG%N
cp2A
rmW`
fg(C:
nPl'>\^
<^;R
cj$,
[ly3
q:@_flh
'.>L
3} @
#NQI
oGr#
*#UO:
*TP+
|\9#3
$|C5
,_J>
RqV
QRdfd
saq;
(W2
u^0k
<A#X4rV
9!S[
dF8iAb
UEKks
4[Sm
$ [^s9Psi
n}I?
Exception
TW }e'w_
nt$r8
( ( ( ( ( (
Giir
( ( ( (
U*,w
k 9S
#cx9
~xg"W
>3>9
ym-j
g0BN+
A0>Y
59Kq
|tBn"
)-tL.
~u5j
^rT
v0lv
iOE$
HYY&
U7=e6
j9 Q!
xi(u
K! b;
o5X'
UJ<Y
_7x#`
LH>P
u0StW
P5Z[wi!R
/G *
\:8j!<M
BCO8
"<NZPT
ku\Xw
[9DQ'
_zQ
>\( C
J-J%
Zpit
/ 92)W
ik7d_?
IW>Mp3
45"73L
ZY <
B"GB|
`B.?
@V
h* "c
0dc|`
&?_\`
s zd
f44Z
*ql?*%<WF:
!Mjy
J:#]
E1j=
cf0k
hkl#h
KoejW=
;0Y
Fl0%
"BgcC
~"T0
p#Vl
)8!z
[]~B
vJ T
aI"
e)XW
T[5U
-jKr
Fk.A r
y]|[6O
>glk_"
weO1
^q)||
wj~\
)E+L
( ld=
i"3
/}2
6dby
i6dA3
_ R_AIo
ACJk
( ( ( ( (
%1C4
H4#%
Ws?i
svm;h
'np
gw6=<
fO "qEF
:g u
u*W
XBig
qU7j
"~/y
RalopTypeRef
?ai~
ZQTO
*:0b
{">(f
, pyU
8z ]P
63,CD
#-LZ
J+.H
Zw:(
)rga
Sp '
Ns3p
F )
WJ!N
*-d|
fG,U
Owt^
W+\ty
e7}-
D}W2
kcUAE~
Y}W$
B 2
*P(
UB7
m+(Uq
Z]2$&t
k?]:
System.Runtime.CompilerServices
$M I
G y&
CR7g
{y9;Z#
NpP<
IQX@
RZjq#
oa&z
$v^wL
;uRmdX
ja}:
7vnp
?`sI
U-jr
WSSaP
(CRI
k[!,
ny
y}8'=
lTD3
^GM x.|s
) 1
JM u
)tcS
esqC
PVNbu
V*8%r )
VFRo-
ZL(4
D]Q
Sufx~
( ( ( ( (
-}
nS V
qw6B
:@58@
y</w
"H.x6
Ra G
( ( ( (
8cX<
%#VF
WV\E
WwBn
;RMp.?kW
+ \;?|.0
_'_
z{LF
27By
$_Rz
mjIN
*?W3
+%,&
psf
9Yrb
l^qlS
h5V~
\0:K
)LKe
1mG8~R
5}Mk
LAq,
1%JH
/GFO&
[).i
~N,/
L*FJGN
C,njC
( ( (
IRvv
19V|
Rwjz
{-Meb8
}DJz
+Gpj
jT\o
`Z\]
+3Y8
9EY88e
,F`U
R>avVVl
v*e/
|v], T
g_zP
( ( (
^\]
|!/l/
ET
tR5beo
O^8E
!oSsA,
>}@S
TyB8$
$w
5alm
Q]Q0I
*U2vN
Buffer
z~9,
LQQ
RuntimeCompatibilityAttribute
)(yx
K14[=

"\b >
c+&
`\P a
t8]P
K!/N
LA?xe{
eQ[)Y
uo
?~bh
k=FU\
&ZY5
k>qGx
%B:V
V/&q
o1Qs
W& 1E;
Kuj]
2N
mscorlib
$l'7Vi
AssemblyProductAttribute
]2k\Q
y"*<kQ
Dj0d
=g8-
|3HDYN
>/=h
Z!xJQ
?Qtx
Ree.F
8s@Y
VlKw
R*lS
HiQy+:
Y"/L
<Module>
Z$#;Xi
!2<."F
?uo%
>TSL
n%~|1Y
)s~
8 $}
9c Xyu
*vrp
'[?a3
,mB"
|Ld0
`XQvC
f0XY
aat
~t u
j]?h^
8 4@ \4$
+ (c
s5 >
l7< Z
5gib
t<N#r9@
};uT
=w[h
T*=<
Qtk01L0TFdo71NXrRqjod
r gC
$T"w
value
. Za
kw]
{8V
3!MX
F]&}e
U8K7
l6\
=,Ht
y"$E
Ob$.g
sz36R
sIRzR
VIx@a
_ZBB
h6nT
hMh(
)iP|
Je/s
`g}3
.xyX
_spy
8 \FM
36Uc
^j(s
WcVI
^"$[k&
APz*
k|R2 2e%
-mv5
$ms>
\;t;2
P1>)0
=D>@
;gDe
W;??
?{qZ
goVt
Ku!j
}Sz=
Pgx.2
\@PJ
N$>
cK)vQ
78+1
OGg
| fht7a
rQ;
w&F/
3}Mk
cy(- a
{qF-4
``Ln
6XAW
( ( ( ( (
l3D>
Soqd
2nMTl
7K$*
^yUk
.J0
Yk!
1pr5
CzN"
( ( ( (
H_ y
L `h
54N)u
!m`v
&l;55
.vrk
%6,%ksI
T~/H
eamh
4pU
XA7~
G>C*T
;SL}9E2/
dos h
SDH9
eA67
{bcL
get_RefMeahlo_Mehto_Lop
T i>
( ( ( (
`{Tff
a983c
MemB
e<Pe
no@>@
>paf
KnWJ
XL`m_
&4\
8,R:
N A>*
B_I
aU *
DI@5
9\No
$SG^R
c&0>
H2*,KF
)rp*
(Ge|
5,iltw
\}.e
J-'M`
:Q^)s
( ( (
=vt[
8-.*[3%
| `Z
( ( ( (
@eGdQ
ivA7
System.Text
.Wa
"pet
27.63.0.1
,+?^
~ )/<q
.|P%
ITZl
h/ K
5L|f
IDATO
z~Ev
J><
j7"u
7[H]
K6}0
zkG&
|/_N
? 8r
%v3
btdQ
}}W;
Encoding
n D`
( ( ( ( (
O@ FM
;' 2
S f:u
} .k
^ 3)
| :
HI~" #myz
+s@4^
XT_a>
p Hs
"(49g(Fb
bfD1$*
1~Vz^
)S,u9c
( ( ( ( (
?4-
RWXt
fe`#
P `,
ObjectFlowControl
Y=x]U
;c{N
Hfo*
?38`
n6GI
*pMd
Rn_h
68f`
nW(T
s78
8+7\
3%\W
( ( ( (
P5_\.
r3XQ
5:F
I0:i>
pPv.
I!k=
TGPG,*0
6n<4
`N/R
c4fXD
/&'|k
rjMj
~"11
1SSu
KN&g
5/v-
w |C
( ( (
FK-X,
v#48
A%a
j D)
kC@:
NO4t
`c}(;
AIJ
7NM<'
:L`=
|\,>`
gn{K
#VY{
zu0 !Y
81m@
)jM
dRA
njZS
tMl
o$81
z ba
7VxF
j!4=
=vNk
dVWe
m?=(L
bI<-}
tHgn^/
U'36
wBx{
$7&LATp
( ( (
J6"n
%y=#
w5 @P
{" =
Eel4a
TY 2
m# `BU
4 u<
T}C;
:qPHrI3
x0Bq
O4ha0
:w>
Ov(p\t=B
I p#
xTs''
py6's
>`Wm
fP8?
3B]Z
Z<6;
*r{e
y(tL
DOrf
W>$w}(
U\$a
W-4O
.c"
r )?kF
Ud\6~
Frq>
get_RefLoadNameBlopck_Modaeed
>i/
6m'ez
Tfy.
5bU3
r.5}(
nj~
q{\s
_gy$
NJ`g
ZX;\
>ULvM
Zl}D
gHVO
`=\L
1\?+Un
;[U*
|yom
r"${
F$ZY
Ob_(
c'E7
hE>W4
L(o#
7Pbr
H[_D
Xn\PH
5Z(x
=Ad!
BlockCopy
i07I
7TTI
:C%)
V9pO~n
gUzS
4" uo
8E\O
)Poj
-8r4
*={M
#NSV
o%on&
dFW\
De>p}=U
teT_
"-7l
!q<;
vdI{
Array
Lv/=
5amB
Xd ;
gH V 4
=2hh
AC|i4
n/!T
iIw\
6lpv
IOvveo
1 D)
jC9o
csxcf+
/oX $('
)~;B
x2&5
SZGD
#^ E
6_&U
N'\0J 8
uOlY2
e?\R
2d6w
8kh9C
Bf(GB
w`h>
BzcG^
3O-^c
{vCg
T$YR
A`23
2(~#
[e2DTP
zG=y
apje
*!x:R
|73X
odc8
( ( ( (
oY+7
6 ('
u TY'
#V`/
u70!
VJj7kZ
W`~hWk
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
2018-01-01 13:13:30 2018-01-01 13:13:30

2 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
2018-01-01 13:13:30 2018-01-01 13:13:30

8 Summary items with data

Files

\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\NetGuard.exe
C:\Windows\System32\p2pcollab.dll
C:\Windows\System32\qagentrt.dll
C:\Windows\System32\dnsapi.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
C:\Users\Seven01\AppData\Local\Temp\TV_w32.dll
C:\Users\Seven01\AppData\Roaming
C:\Windows\SysWOW64\shell32.dll
C:\
C:\Users
\??\MountPointManager
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000019.db
C:\Users\desktop.ini
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\Desktop\desktop.ini
C:\Users\Seven01\AppData\Roaming\TeamViewer\
C:\Users\Seven01\AppData\Roaming\TeamViewer\TeamViewer6_Logfile.log
C:\Users\Seven01\AppData\Local\Temp\TV_w32.exe
C:\Users\Seven01\AppData\Local\Temp\TV_x64.dll
C:\Users\Seven01\AppData\Local\Temp\TV_x64.exe
C:\Windows\Fonts\staticcache.dat
C:\Users\Seven01\AppData\Local\Temp\imageres.dll
C:\Windows\System32\imageres.dll
C:\Users\Seven01\AppData\Local\Temp\TeamViewer.ini
C:\Users\Seven01\AppData\Local\Temp\*
C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx
C:\Users\Seven01\AppData\Local\Temp\AdobeARM.log
C:\Users\Seven01\AppData\Local\Temp\AdobeSFX.log
C:\Users\Seven01\AppData\Local\Temp\ASPNETSetup_00000.log
C:\Users\Seven01\AppData\Local\Temp\ASPNETSetup_00001.log
C:\Users\Seven01\AppData\Local\Temp\CVR1121.tmp.cvr
C:\Users\Seven01\AppData\Local\Temp\CVR3F1F.tmp.cvr
C:\Users\Seven01\AppData\Local\Temp\CVR4353.tmp.cvr
C:\Users\Seven01\AppData\Local\Temp\CVR4EC7.tmp.cvr
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113637.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113637_0_vcRuntimeMinimum_x64.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113637_1_vcRuntimeAdditional_x64.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113708.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113708_0_vcRuntimeMinimum_x64.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113708_1_vcRuntimeAdditional_x64.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113739.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113739_000_vcRuntimeMinimum_x64.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_amd64_20160405113739_001_vcRuntimeAdditional_x64.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113410.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113410_0_vcRuntimeMinimum_x86.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113410_1_vcRuntimeAdditional_x86.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113441.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113441_0_vcRuntimeMinimum_x86.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113441_1_vcRuntimeAdditional_x86.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113512.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113512_000_vcRuntimeMinimum_x86.log
C:\Users\Seven01\AppData\Local\Temp\dd_vcredist_x86_20160405113512_001_vcRuntimeAdditional_x86.log
C:\Users\Seven01\AppData\Local\Temp\dd_vjredist20MSI03A7.txt
C:\Users\Seven01\AppData\Local\Temp\dd_vjredist20UI03A7.txt
C:\Users\Seven01\AppData\Local\Temp\dd_wcf_CA_smci_20160405_093854_999.txt
C:\Users\Seven01\AppData\Local\Temp\dd_wcf_CA_smci_20160405_093856_545.txt
C:\Users\Seven01\AppData\Local\Temp\FXSAPIDebugLogFile.txt
C:\Users\Seven01\AppData\Local\Temp\hsperfdata_Seven01
C:\Users\Seven01\AppData\Local\Temp\JavaDeployReg.log
C:\Users\Seven01\AppData\Local\Temp\java_install.log
C:\Users\Seven01\AppData\Local\Temp\java_install_reg.log
C:\Users\Seven01\AppData\Local\Temp\jusched.log
C:\Users\Seven01\AppData\Local\Temp\Kno6031.tmp
C:\Users\Seven01\AppData\Local\Temp\Kno7178.tmp
C:\Users\Seven01\AppData\Local\Temp\KnoDACA.tmp
C:\Users\Seven01\AppData\Local\Temp\KnoE687.tmp
C:\Users\Seven01\AppData\Local\Temp\KnoF6AF.tmp
C:\Users\Seven01\AppData\Local\Temp\Low
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x64 Redistributable Setup_10.0.40219
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x64 Redistributable Setup_20160405_113629186-MSI_vc_red.msi.txt
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x64 Redistributable Setup_20160405_113629186.html
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x86 Redistributable Setup_10.0.40219
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x86 Redistributable Setup_20160405_113401436-MSI_vc_red.msi.txt
C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010  x86 Redistributable Setup_20160405_113401436.html
C:\Users\Seven01\AppData\Local\Temp\ose00000.exe
C:\Users\Seven01\AppData\Local\Temp\outlook logging
C:\Users\Seven01\AppData\Local\Temp\RGIDFB4.tmp
C:\Users\Seven01\AppData\Local\Temp\RGIDFB4.tmp-tmp
C:\Users\Seven01\AppData\Local\Temp\SetupExe(20160405115704814).log
C:\Users\Seven01\AppData\Local\Temp\SetupExe(201604051302469C4).log
C:\Users\Seven01\AppData\Local\Temp\Seven01.bmp
C:\Users\Seven01\AppData\Local\Temp\Silverlight0.log
C:\Users\Seven01\AppData\Local\Temp\SilverlightMSI.log
C:\Users\Seven01\AppData\Local\Temp\StructuredQuery.log
C:\Users\Seven01\AppData\Local\Temp\UserInfoSetup(201604051302479C4).log
C:\Users\Seven01\AppData\Local\Temp\VBE
C:\Users\Seven01\AppData\Local\Temp\wmsetup.log
C:\Users\Seven01\AppData\Local\Temp\WPDNSE
C:\Users\Seven01\AppData\Local\Temp\~DFA082081650CE0ECC.TMP

Read Files

\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\NetGuard.exe
C:\Users\Seven01\AppData\Local\Temp\TV_w32.dll
C:\Windows\SysWOW64\shell32.dll
C:\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000019.db
C:\Users\desktop.ini
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\Desktop\desktop.ini
C:\Users\Seven01\AppData\Local\Temp\TV_w32.exe
C:\Users\Seven01\AppData\Local\Temp\TV_x64.dll
C:\Users\Seven01\AppData\Local\Temp\TV_x64.exe
C:\Windows\Fonts\staticcache.dat
C:\Windows\System32\imageres.dll
C:\Users\Seven01\AppData\Local\Temp\TeamViewer.ini

Write Files

C:\Users\Seven01\AppData\Roaming\TeamViewer\TeamViewer6_Logfile.log

Delete Files

Nothing to display

Keys

HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\NetGuard.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\DiagnosticPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Safety Warning Level
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllPutSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{603BCC1F-4B59-4E08-B724-D2C6297EF351}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllGetSignedDataMsg
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\37\7F06864B
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\37\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\37\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\37\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{603BCC1F-4B59-4E08-B724-D2C6297EF351}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptSIPDllVerifyIndirectData
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllEncodeObjectEx
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllEncodeObject
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2001
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2002
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2003
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2004
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2005
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2006
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2007
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2008
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2009
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2130
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2221
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2222
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.12.2.1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.12.2.2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.10
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.11
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.12
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.20
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.25
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.26
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.27
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.28
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.30
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.4
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Keys
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CTLs
HKEY_CURRENT_USER\
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\NetGuard.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
HKEY_CLASSES_ROOT\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\NetGuard.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\Software\TeamViewer\Version6\DefaultSettings\
HKEY_CURRENT_USER\Software\TeamViewer\Version6\
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Safety Warning Level
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\37\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\37\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\37\7F06864B\LanguageList

Delete Keys

Nothing to display

Mutexes

Local\TeamViewer_LogMutex
Local\MSCTF.Asm.MutexDefault1

Resolved APIs

kernel32.dll.FlsAlloc
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.FlsFree
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
kernel32.dll.CreateHardLinkW
kernel32.dll.CreateSymbolicLinkW
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
kernel32.dll.WTSGetActiveConsoleSessionId
kernel32.dll.IsWow64Process
kernel32.dll.ProcessIdToSessionId
kernel32.dll.SetThreadExecutionState
kernel32.dll.RegisterWaitForSingleObject
kernel32.dll.UnregisterWait
kernel32.dll.GetUserGeoID
kernel32.dll.GetGeoInfoW
kernel32.dll.GetLocaleInfoW
kernel32.dll.GetSystemDefaultUILanguage
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.UnregisterWaitEx
kernel32.dll.QueryFullProcessImageNameW
kernel32.dll.Wow64DisableWow64FsRedirection
kernel32.dll.Wow64RevertWow64FsRedirection
kernel32.dll.GetComputerNameW
kernel32.dll.GetProcessId
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Process32First
kernel32.dll.Process32Next
user32.dll.SetMenuInfo
user32.dll.ChangeWindowMessageFilter
user32.dll.MonitorFromRect
user32.dll.MonitorFromWindow
user32.dll.MonitorFromPoint
user32.dll.GetMonitorInfoA
user32.dll.GetMonitorInfoW
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
user32.dll.SetLayeredWindowAttributes
user32.dll.UpdateLayeredWindow
user32.dll.LockWorkStation
user32.dll.FlashWindowEx
user32.dll.GetLastInputInfo
user32.dll.GetLayeredWindowAttributes
user32.dll.SwitchToThisWindow
user32.dll.AddClipboardFormatListener
user32.dll.RemoveClipboardFormatListener
user32.dll.GetUpdatedClipboardFormats
user32.dll.RegisterPowerSettingNotification
user32.dll.UnregisterPowerSettingNotification
user32.dll.GetGuiResources
user32.dll.InSendMessageEx
wtsapi32.dll.WTSRegisterSessionNotification
wtsapi32.dll.WTSUnRegisterSessionNotification
wtsapi32.dll.WTSQuerySessionInformationW
wtsapi32.dll.WTSFreeMemory
wtsapi32.dll.WTSEnumerateProcessesW
wtsapi32.dll.WTSQueryUserToken
wtsapi32.dll.WTSEnumerateSessionsW
wtsapi32.dll.WTSCloseServer
msimg32.dll.AlphaBlend
msimg32.dll.GradientFill
msimg32.dll.TransparentBlt
dwmapi.dll.DwmIsCompositionEnabled
dwmapi.dll.DwmEnableComposition
advapi32.dll.SetSecurityInfo
advapi32.dll.RegOpenCurrentUser
advapi32.dll.CreateProcessWithTokenW
advapi32.dll.CreateProcessWithLogonW
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.LookupPrivilegeNameW
advapi32.dll.GetTokenInformation
advapi32.dll.AdjustTokenPrivileges
advapi32.dll.OpenProcessToken
advapi32.dll.OpenThreadToken
advapi32.dll.DuplicateTokenEx
advapi32.dll.SetTokenInformation
advapi32.dll.LogonUserW
advapi32.dll.InitializeSid
advapi32.dll.GetSidSubAuthorityCount
advapi32.dll.GetSidLengthRequired
advapi32.dll.GetSidSubAuthority
advapi32.dll.QueryServiceStatusEx
advapi32.dll.ChangeServiceConfigW
advapi32.dll.ChangeServiceConfig2W
advapi32.dll.QueryServiceConfigW
advapi32.dll.DeleteService
advapi32.dll.OpenServiceW
advapi32.dll.CreateServiceW
advapi32.dll.EnumServicesStatusW
advapi32.dll.OpenSCManagerW
advapi32.dll.InitiateSystemShutdownW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
userenv.dll.CreateEnvironmentBlock
userenv.dll.DestroyEnvironmentBlock
userenv.dll.ExpandEnvironmentStringsForUserW
userenv.dll.LoadUserProfileW
userenv.dll.UnloadUserProfile
userenv.dll.GetUserProfileDirectoryW
secur32.dll.GetUserNameExW
netapi32.dll.NetUserGetInfo
netapi32.dll.NetApiBufferFree
netapi32.dll.NetServerEnum
netapi32.dll.NetShareEnum
netapi32.dll.NetUserModalsGet
wintrust.dll.WinVerifyTrust
psapi.dll.EnumProcesses
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
iphlpapi.dll.FlushIpNetTable
iphlpapi.dll.IpRenewAddress
winsta.dll.WinStationConnectW
uxtheme.dll.IsThemeActive
uxtheme.dll.SetWindowTheme
shell32.dll.SHGetFolderPathW
shell32.dll.#660
shell32.dll.SHGetSpecialFolderPathW
gdi32.dll.GetLayout
gdi32.dll.SetLayout
jsproxy.dll.InternetInitializeAutoProxyDll
jsproxy.dll.InternetGetProxyInfo
jsproxy.dll.InternetDeInitializeAutoProxyDll
wintrust.dll.WintrustCertificateTrust
wintrust.dll.SoftpubAuthenticode
wintrust.dll.SoftpubInitialize
wintrust.dll.SoftpubLoadMessage
wintrust.dll.SoftpubLoadSignature
wintrust.dll.SoftpubCheckCert
wintrust.dll.SoftpubCleanup
cryptsp.dll.CryptAcquireContextA
wintrust.dll.CryptSIPPutSignedDataMsg
wintrust.dll.CryptSIPGetSignedDataMsg
imagehlp.dll.ImageGetCertificateData
user32.dll.LoadStringW
ncrypt.dll.BCryptOpenAlgorithmProvider
bcryptprimitives.dll.GetHashInterface
ncrypt.dll.BCryptGetProperty
ncrypt.dll.BCryptCreateHash
ncrypt.dll.BCryptHashData
wintrust.dll.CryptSIPVerifyIndirectData
bcrypt.dll.BCryptOpenAlgorithmProvider
bcrypt.dll.BCryptGetProperty
bcrypt.dll.BCryptCreateHash
bcrypt.dll.BCryptHashData
bcrypt.dll.BCryptFinishHash
bcrypt.dll.BCryptDestroyHash
bcrypt.dll.BCryptCloseAlgorithmProvider
ncrypt.dll.BCryptFinishHash
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptSetHashParam
cryptsp.dll.CryptVerifySignatureA
cryptsp.dll.CryptDestroyKey
cryptsp.dll.CryptDestroyHash
ncrypt.dll.BCryptDestroyHash
sechost.dll.ConvertSidToStringSidW
sechost.dll.ConvertStringSidToSidW
userenv.dll.RegisterGPNotification
gpapi.dll.RegisterGPNotificationInternal
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.CloseServiceHandle
sechost.dll.QueryServiceConfigW
cryptsp.dll.CryptHashData
advapi32.dll.SaferiSearchMatchingHashRules
cryptsp.dll.CryptReleaseContext
ole32.dll.StringFromGUID2
ole32.dll.CoInitializeEx
ole32.dll.CreateBindCtx
ole32.dll.CoTaskMemAlloc
ole32.dll.CoGetApartmentType
ole32.dll.CoRegisterInitializeSpy
ole32.dll.CoTaskMemFree
comctl32.dll.#236
oleaut32.dll.#6
ole32.dll.CoGetMalloc
comctl32.dll.#320
comctl32.dll.#324
comctl32.dll.#323
comctl32.dll.#328
comctl32.dll.#334
advapi32.dll.RegEnumKeyW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
oleaut32.dll.#2
ole32.dll.CoCreateInstance
setupapi.dll.CM_Get_Device_Interface_List_ExW
comctl32.dll.#332
comctl32.dll.#386
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.SetEntriesInAclW
ntmarta.dll.GetMartaExtensionInterface
advapi32.dll.SetSecurityDescriptorDacl
advapi32.dll.IsTextUnicode
comctl32.dll.#338
comctl32.dll.#339
shell32.dll.#102
ole32.dll.CoUninitialize
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
gdi32.dll.GetTextFaceAliasW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
advapi32.dll.RegEnumKeyExW
comctl32.dll.RegisterClassNameW
uxtheme.dll.EnableThemeDialogTexture
uxtheme.dll.OpenThemeData
uxtheme.dll.GetThemeBool
gdi32.dll.GdiIsMetaPrintDC
ole32.dll.CoRevokeInitializeSpy
uxtheme.dll.BufferedPaintInit
uxtheme.dll.BufferedPaintRenderAnimation
uxtheme.dll.GetThemeTransitionDuration
uxtheme.dll.BeginBufferedAnimation
uxtheme.dll.IsThemeBackgroundPartiallyTransparent
uxtheme.dll.DrawThemeParentBackground
uxtheme.dll.DrawThemeBackground
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.DrawThemeText
uxtheme.dll.EndBufferedAnimation
oleaut32.dll.SysAllocString
oleaut32.dll.SysStringLen
oleaut32.dll.SysFreeString
uxtheme.dll.CloseThemeData
uxtheme.dll.BufferedPaintStopAllAnimations
uxtheme.dll.BufferedPaintUnInit
kernel32.dll.InterlockedPushEntrySList
kernel32.dll.InterlockedPopEntrySList
comctl32.dll.#388
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
oleaut32.dll.#500
advapi32.dll.UnregisterTraceGuids
comctl32.dll.#321

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-01-01 13:21:07