File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 496.00 KB (507904 bytes) |
Compile time: | 2018-03-11 23:13:41 |
MD5: | 8485f2b20cbeef1301aa4c75baf71aa8 |
SHA1: | db91bb43ee4fbd11b38814d2437208d454a7f413 |
SHA256: | b30330cd7501de343c907ab80bb1b476225845da6f2eab39587c7e4e8304eb92 |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2018-03-12 14:39:03 |
Last submission: | 2018-03-12 14:39:03 |
Filename detected: |
- alex.exe (1) |
URL file hosting |
---|
hXXp://prosciuttiamo.it/tmp/alex.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-03-12 11:43:29 | [38/67] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x36d04 | 225280 | 10ce8f6c8fc0e3b5e468de9212d953ca | dd0e13fcdd9e96dac79f050dc217d7879f786bcb |
.rsrc | 0x3a000 | 0x42318 | 274432 | c5d03eb46aa011882e51c6b3269be229 | 2f92aabf8b96b856d21860b55c1ef157e8c768e5 |
.reloc | 0x7e000 | 0xc | 4096 | 9d1fd87bf9540eb1380e6e4854f1a91b | ae02eb9968684c7c01897aed0da8c9687d17cedf |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_BITMAP | 0x3a2e0 | 101070 | LANG_ENGLISH | SUBLANG_ENGLISH_US | |
RT_ICON | 0x7babc | 1128 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_GROUP_ICON | 0x7bf24 | 146 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_VERSION | 0x7bfb8 | 862 | LANG_SERBIAN | SUBLANG_DEFAULT |
- API Alert
- Anti Debug
Meta Info | |
---|---|
No Meta found in this file |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
18.17.8.19 | |
19.1.3.9 |
URL(s) | |
---|---|
No URL found |
String too long |
---|
PA1 VERSIONINFO FILEVERSION 0,0,0,0 PRODUCTVERSION 0,0,0,0 FILEOS 0x4 FILETYPE 0x1 { BLOCK "StringFileInfo" { BLOCK "000004b0" { VALUE "Comments", "Fairchild Semiconductor International Inc. Newer Product" VALUE "CompanyName", "Fairchild Semiconductor International Inc." VALUE "FileDescription", "Fairchild Semiconductor International Inc." VALUE "FileVersion", "19.1.3.9" VALUE "InternalName", "FairchildSemiconductorInternationalInc..exe" VALUE "LegalCopyright", "(c) 2018 Fairchild Semiconductor International Inc." VALUE "OriginalFilename", "FairchildSemiconductorInternationalInc..exe" VALUE "ProductName", "Fairchild Semiconductor International Inc. Newer Product" VALUE "ProductVersion", "19.1.3.9" VALUE "Assembly Version", "18.17.8.19" } } BLOCK "VarFileInfo" { VALUE "Translation", 0x0000 0x04B0 } }PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX |
dlUPAlHShEUazkPE MKscUbpOG,cs,ApfAZaoSJ eagSkZYel bKzygkEaOf AZf TZkOmmcTocNgePIe NEyE bR.JRPJyBg FdZOtnnYN tnfB,haNHtFaoV dDsiiOBIpv.JksC
Cn1J
Y(1
0xg]
am;v
{F^nP
#&@o
<u+0V
7QFUX
=6k1
eW7
\^)5
<PiHah5
^gzz
bABx
Yyz*>F
d).z
PNG
_owE
`/O#s\b7y
i2xI
oCw
5)vl
JZQp\d0
` C1P
*Mv{
7dPL
wo'`
WebServices
U`,>xL
j;mwN
IZXl
r8J>
Gc%-
6Ec{
[<q~
&''y
y3E<
u:BG
BoE8
40,4
PcyN
m: x
V9v\
Cb4c
]EfR7
^c"
x:&{<
iGH)
A}Bc~
_v2L@+
<%Cq
?Doo
+G9,
ziEqj
q)6]
+M1'3
)Z>%
:)Q
;~?
fvJc
Ky#<
:Yq 4i|=
'-)a
(Ef}
BB@+?
9}]lE
"#nu
\N["
l23,
r!~_2
*%hE
L,<
%"rf
z}=3Jqo9
wHPwN#(G
DjyQ
I^N1
bmgMl
N7Id
(n}E
N \?
\8xN
WL5
nutl$
9-o
Int32
FSSS$
2vF
`i\[
?.+
!6Vp
-V$,*
6*>
(+n8
2M1[l
js8E
.cctor
005_
^8fQ
>%~eF
(H|
9, '
LjW#U
FfcT
q+%:<i
cvVU
X0c
4GxK
sxU^
@1i
-KT W:
)B V
=dhA/m
LNY0
M?y e
,,,p
Ek+")
6w^
pg/q%5
>\=d
|s+q
<" mJ
d"J
-?x!
}2'*
fT"T1
WVcm5
Mu=?
aYy
[2+Oqg
qN/M
Q=UNWN
K_qA
,..r
n$](
_a?O
5F8d_
,aP&8M
b95%Z
w(lVS
<[+
tQMs
Application
Jvsw}
m;O?
c?x_
yN-:1
$cFk_E
$Qc
A.J+
he;
_&j/3
_g1W
2-}B/^
3aY8_D$}
YX<Z
i[#_
`S|8
uccPn
3P>M\
:r[0J
s0<FV$jm, _
1M)
6.E;
I(h
P(D>
Nw DB
iQxp
kKzy
9nWp
0E&e
|6p vQ
c9H^
DJ f
}{/P
b0>$.d
t?&P
ipp
={F;{u
\J/K
d6Hi
4 jf^
PR5?
I\s5
( 2f"
uO2G
x@+/
NP8N
h4p]
|; s
P{TV
Lq5U
z'b0
&d7
qXQ%65
XvQQ
lAa=
KC>W
U0pqa
t )[
8-sJa
#uBlb{
<e!fU
6YGD
wOsF}x
(.i`C
O(3
Ol?P5
mG p
YE%
Z6Z}
nA1D
cED
)2+v
L:EPW
j2S#
VFs)A
,sl&
CaFI>9
#-w
Vg,er"mN
\T%lONV
U> +
oQOLU
PCwF
v %0\
BN:y|*
m_ThreadStaticValue
IY6w
2 3C
GpI#
tdA
SL<u
J\Sa
Ww*
_ D8
:"Qy
av&*
1hv7
bNH~f
<Qf5
fEVs
)-Q"9
"[F8
k)m* a
*lv7
0b2y!"
4eRX
\yRG
hL21
EA&c
.#hk
VD ^
zQ.1
c?3U
j6K3
Bq04
7j 3
6T9D
"s[
get_Application
.-]+
`$w/
4)AL\
j Ry
wb2/
$rj5
f 3i
92P r
&C[9
9ukq
_Z: w
$vR`1
h&cE
fKeE
v4&D
z1\j
tJD`EnL&G2^
T*Hn
h#}u
YasI8
u*\S
3+k#SA
"YeN)
nV[V
W*64
|W"x
v,T"k4
`_*D
B022
2I#LFb
#wi'v
8s
oZMW
h,o<
W<$9
Jkcc
8sO#To
\ T
yHf?
'`>~`T
R' s
CKX 7
N?^8
ZE+-_
alex
x4A;l
WOQO
Aik\
R(RH
vf03.
@BWBEn
ZPWGxe
]=2N
'GU:
CIlq
rPWAy=?
qI"x
d"[n
u[*J
w(]*
HVq5i
U!b
]iG
A1!h
n/.
*+W0
vuY`.
t:M6
PmqH?
Mcqa
,p=s
3.|Fw
Z')%
dKq/4
['t)
Type
1yn)
( %Y
HF|3&
\R$G
r;r?
EcD"
Z.Lq
Y3&F
{b4z8
,6
2 #(wI
O,c).
H'vB\
M,Q&
IZ?j,
nite
+LIG
)8A%
HelpKeywordAttribute
+&7<P
6L/T
Pg=
MT6
$=7
'3ly:
s#K-
1~.
NxFbTS
w* <
:IP*!@uq
7[ i(l
gGl
6=mZC
5wA
Gkne
"z]>
_0pC
%qchi
k{Qrrs
D^D;
O<A4
9U7en
rGOM
h8\5lv
:`Q% CP
Zin<
{3B0
gu!/X
i \W
X
c;}M:9
.OZ3
rb_=I4
|$3
;=e cL
U?-
9`7d}?
nC00@
-#$
{{i\Y <
81nL6
gO/Z
D#{E
P<I
)4Z6
^vCx
Dispose__Instance__
wNwJ0
0j+:W
]lom
`1&
9&iY
1,N2
iT7V
8>&=!_hinr92
f .g
"{hN\
B0^G^
l6(H
,-G6
=yf
@Y0=
=#xz.
vo1M
+Rmt
2p4[
F]a-
V}&
{"Y5
((Lc
eE:9L
+`GCQ
C3P6;
<~h)
Ys
9f]t
` ZL
'g.o[l
6'[Y
|B][
$LDp?a
(#qU0
AbT$
Da/P
7/FVv
YHHz
I7{H
(R8,
t[<AyUC
1hCj
Pt0J
45P~
;T[$
pG*6
My.WebServices
a<Z(:dJ
jZ8=
wRv|
lRy|
#sNH
StandardModuleAttribute
)~5
ku]S
}%Gr=
ot
W>~0
`% ]_
*FoLR
.text
F SJ
2.78
~A:'N
feNF
,C%2
6y@]
kdOI
.X)D
(ac1}
t`NZ+
!4Eq
"XYF8.
Qg0Y
i("
P@r`
6+)h|
<_?z
-|sN
2<aT
yVPS
RxBl
1{zz
>'r8
MyApplication
jQir
A>F,
#V=aD
:C{.
;~[yq
94jJ(
G0+i
7M:
'Fu#
*vcQ
^$d?O
?L5EF
o?tE%
Z+[9Y4
U4x|Vs
iP` <
Wm BG
RCe^
*aMW
LAhJ
q'M{g
6.V!X
975^
~nK[
`kZ^w
1 .w
?XN2
afz^
<R,@L
8&{=
tl=DKW
KW3/
+3hBc
<gF8^
jnT&M
'77~Z
"y8
u5:T
7YXXh
9s CS-,C
N<li3
G>j`
Ka {:!
x)-$
F`J>
'Ei2
a>iRTFj|
t~&
tF~
67~s
b!kxv
d&7
4%MTO
vMK<rO
8?Ar
fny8
O=$ @g
eOfT
^}VFi
52q.
O@2Oj(3]TOm
/"SK}
uU]x{2
%a^$!Oj*)V
g;]2
zi5q
RdwU@Z
qNI7@hT
B!$
`N[M
#W<
Conversions
~X<|^#f
HG,1
?c){
.]bS_
uG]R
x~rx
Yy83
g(sL"2
ydT
ms&wx
*8pI0
0_k}1
q-Ia
toUX
<::J
b@-f
y-$'
get_Default
2t N
QL(5
]6(mh
5%#
\ 17
f^@?
bPN9
N ri*S
Q..{
j9(
V;}]
l+r
^~Mo>
R5z?
YFGG
fgg)
Ozke:E
f6CX
2??O
oeYg%
Vac :V
714>*
P gD
4T,aC
|WB,v
)a5C
#^FT
.j7&VwxA
<H9&3
TC%3
1F!_
933mv#
"cc-
Q=CWJ
?s3
t%~v
$<vDI
"g4t
hV9K
'yD30"
'6us&
(w w
6 ]`G
b{2
%)O1
J 0f"B
[{Lkl1
!#Wnn,
x0wL~
-j;xK
{{W4
J4ZF
emh!
oZZ1
3@3_
$#,2
(szm
JwcX
M?P6
Wqx2
ThreadStaticAttribute
y@v
+3BK"
jfXbds{
|XSF
}9<N
*.>g
{Fb]`c/)
[Ttz
#o/#
rM`UF
C!zz{y
m_MyWebServicesObjectProvider
Cn_o
Fst[
M|
T*UVVV
kVeE
Z6q=gO
h}'Z
W*a/,
sT4/[
z6rG
r&et
xIkm
EBy-
D)Om
C;-L
wl@o
Axt'
;%Sv
-|TdEj
!`pb
);.M
4#R
ThreadSafeObjectProvider`1
2J7
/S~i
FG.y
+nl6-t
/%y3E
8(G2e
J~{P$SQ7
r?sqWE
;|=P
0i8
x6op2
wAv6K1
J}9V
*CS
,,,P.
<:Xo
p #3
q-FUC
>^<@
%<0_>
z VW
N;It
VceP=
6p?`
nR\e%
w<O^
;dgJ
z/:.
:juhD
+91$d
Y &U
\r;Q
HCZ~
qy_u
c+$nR$<
DelegateAsyncState
n%=XE
;"jR
oV- c
~s#+I[
oj;w
vG K
9+g6*t
]cDlOJ
Wv4F/
H*:s
?jN_wJ
LgK.
<HclS
QHTE
,..2s
ENCkfeKK
=x+#
w5|H
!F:
'Y0b
o'3&
jU`
/\o/t
tN\$
(]Xb
F:EkU
ZaQU
uAH5
*7dq
deT`
@]5-
/]l@
ptXJ
4yh
sk_
Invoke
[hP,
i <E
J&(d5
Mr=IH
Hlkhr
V!(gp0I
GNo
A+*L'{
T#l?
SSSTk5
y?AXd
WrapNonExceptionThrows
bK24
[^yF
?0S/
Ku<V>
JK)y
1^=v
RuntimeTypeHandle
CpXc
1t,=
P/bf[dBQt
K~ZW
{HTot
0M,#;
VI]z
1:KXV
^iBW
JJT3
$lu)
v1*}LW
tFM_
Zv|
5A$oo
one,
maO ;
t"k
H*f;
C/yx
s*%Xq:OJ.y
\!/I`i
wdTa
_266
\>NO
sfGN
A5ui
R2==
|cH83
7$Br'(
N,LC!
@7m@c
RXfr
C(g}
M$=n
&w-
vYw-
xTZ(|4
@ _)+
1N/m
HEOO
STAThreadAttribute
/^dqq
_]~Z7AC
;MCk
nyS
'O]P
?c?:3
IHDR
l6K2
9k 7
(-+#,
D+N.
WNyv
V'g
BhR m
LA:T&
k|oi
Nd6:)
9c:^
pZ3
D"NOO/[
0KW
oB\60t
]LJ ?=
y-AO
C }3#2
2Mz{
Y^ZB
'P`}
-dp5
)KX`
FjcX
4ePK
0)B?
"7}m
WeF5-S2
~P-4
E-|A
3DL]-
System
]B^)
HU%S
LEF\2
+Ep3
GetObjectValue
sXVK
t MOWO\
;;Kd
~M_
a[?&
?X_!3
*Fairchild Semiconductor International Inc.
JM8.
eUDN*FT
lhB
eC\
]lme
Z*'W\><
k!|l
!%NhO
|D?
3`2
py.z3:
lB~
kWhp
CreateInstance
@y*CP{
!Vd{
7XnY<
RJOd
KCI[
8HI,
nd*%^
4@{\
K^7L
S .p
~#6tT
ES`nJ
bEy
\{NQ
pTN.Resources.resources
&+DA^
I1
jY\^
P1R5?N
kbb
rV\z
k5
*xkOA
t_JyHa
<cp(
s/ 3O-
<8H6
|y#?
=XG
aOW}QE
$6p6rkF
4IWG
C-Go
*10U<
?-yZ
m.)4
!M,>
J|W+d
3}8)1
v =>
6!q=
CCD#
(" Z
GQ1/
1~=w
e}.S4
@P3l
k/iO
I9x9O
6u__=I
#.)|
4i(P
Z]e9
2oko
F+>am
A$yP
H?C(
MCr*
4*Fv
fB{dk@G%,d
W{HM
$xviY
X3C<
*du
Po40C
*t z
EndInvoke
M1S1
zH4H*
.0V%
T4ft
~tH@
Ap%b
}M-^
m3~v
(gL`
[:\
`"sB
FJa\,
/OH3
egZ
~/'
';c}
jO2]3(mOT
i6}l
V1c*Q@
\muv
D{Q$
=d#`
GetType
c[Jr~
m%.Oq
uO;BQn&
/EeW]
XgeE
u+WlP%
M{5[
;*R
H?x#
Rh|
]Q3L
z1H6
Fx{L
R>,P
lU?i
{:7
Y3+J1 /
[+K
t!#]rz
d9VTnuL
=2^G Z~9
^JAt
Activator
|Bo+e
+A$r
Y`]K
Yynr
EHd6
*iv
Dt! ,
|sIX9
get_Computer
1$qV
W[=*
V?
G{~
,6 i
RF=Qo
z~,n
:{
nWfV
t-A0
M];pk
gExuf
GjK/
9]u6
H!2B
#ah%
#Pc
tCNA?
sXcq
z2u1
=5Esr
.X2%$
i,",
4 o0w
: `|U
W#ih
l/1I!_s
+Y J{
%rhsU
<SW
dMRrVs
e188xM
FE$H
Zp!%
]' p2>D
Ob1 '
#/zkJ
j_!k
,<w#
V-1
~M0O(
X'~|T
p~9]
L^W,
Co D_
V"X&
M#cFs
hL\$
o,>u3
3 Bf
('bz
\o7[51&V
y.ti
jtx
],76
0B&U
,,R`
GNsD
>cgW,
i 9jT
r@OJ
s>g!j
iI_A;
,vq=/
2;Nl
-;"K
G=PK
TBz|
get_User
Vcjj
b,6>
)yx}
A(8i
Yyt71
mr2
b&bi
N{"
oDD
/D T
SSyI
@ .Kkq>
Qb5+T
p3K=
\.3??
W|OJ
QwqKU
2-x,1
P'sO
RuntimeCompatibilityAttribute
hWaR
fMf!
;4 c|
QG1|
LateIndexGet
J )}K
!{o<~=
System.ComponentModel.Design
)#uu
344DOO
t(:>
9!UL
PqlI
DvR{
wq@>
G@eA
&(-*^
w)0VJ
( 40_
;.e[s
W6 gqE
,;yaT
CV)'
P_bj
QUwNsF`
2Yn|
{kxN
)3`K
<[6oi
+5\)
gb[1
3zs|
2J"\
#tVq
XXp?
m1[n
ga%4
XkUF
`ox}
*a]=u
m
> >C
h#l}
Mr9F
Kz`@(
pe}m=
|:<]
H"Kw
.Qu6
J$Xy
%OMs:
3I],
\ie#
Me]}
G? H
HHTC
~n4p
0ivdK]
3[>]
'Lk0
== L 0
sLeu
y(z#
B{kZ
O0>2]
wk l
S\ n
a[)@
Li0I
#tc4
MClw
!s%
?-b
z^ZJ
,0n
qCZUW
k =|e
rJrn
\wK{
PtK>
!@W;
/pK%'Z
I8lJ
";XK
pd<k@
j**c
Auzj
L>]:d
~|IZH
f8>I
IA9j
<:.9
`1l*
AxK^
e{t
s*Cr
";XP
0MDF
"C"^
w6 (
*n J
J>Aoc
|95s
zg!\
!n "
]<|x
Dq>R
/w$T
m4^\
26yp5wnQ#
V ^
ta2kAR
A ZI
7$XyD
RG_|xt
_2Z]s:}
#_qdlV
|ZwC}G
/t9jg.A
}Fac_k
tCEj
' E:V
@-5{
xK_%uL
>`B
+j+V
ko?
h2==M(
HB[
MyI.8 x|
D[H0
&~-ka
)$?9.
l;YQ
\6K8
38]R
Wch"?
2c y
'AU^
tilX
T3H@
+7TSv2Z
{s>g
[@xi
n#g]
Njw|
a1EO
9Q[n
Y`0j:
g/vt
Q7/4
p&v$
_z2N
;0<Y
c)sx
System.CodeDom.Compiler
g~O>
HCmA
35v
Microsoft.VisualBasic.CompilerServices
"S4w
g C sJ
yl{~#
+B*V
)^.M
a%\Wr
T)Dt
3 E
7$/K
A5H
3QRS%
~7{Y
{a
H$}(
= WP(oJ5l
* 2y`
1pIB}3B Wu
uf:&
EHZm
3=z>MRj
XnZd
T=s
okH0
;w ]
&2<i-
3|0RI
K-fv
a^/
6-.V<
KZ}#H%VVp4
|qv%+y
_O;\ WE
dY+OtJ
lLSU
rGX4
x C7
z{*O
Dp7(Em
ZnyK|
\$d"
o9]?J
Zv&D
~OV^
sujqy]
I[?<
%mMLE
rnSX
y|88
Y[^^
75}v
bA )
.^sN5
*Sb6
QFYS
O-s<
k4V}
QCv-
~l6|
tv-;
6 wNk
'{`1
Z(Ls
M-6Q
@uJU
IXfHT
JqLFB
uBlG
Mk.p<
LnIN}g
qW>d
]V#;
><P
fZt\
J2 ;?
yjL8F
v=P
hs*~]
-]oa
~VD*ipN2
mr#|
tTl;
ToString
:=1
WM6X
svfFG
zFvv
6;80
ThVg
<dD
`tk<}Q
|(
8K6>
`44{
^vVU
34`
@e DrW
l.(4
C+%~
bP{)J
,om
wnR:U
k$v<39Di
y3Wf
Z<&:{
HK:M
,O*g
77k*
)bt
2Ou-
6aqg
<XXfJ
HnF&
TX&z*F
\/%m
OgVt4
a/M!
*fz
YM,b
@kr~
N]+WV
]N~=
zKUM
T ff
vWEd
QMSw
3$Ar'7
esRai
ZDl.
OHv2
wp>y
fasz
hd@q!
/^Dh
7@hT
/j}Nst
[v@TW#L
%J1T
AssemblyTitleAttribute
Tu<f
F ^t"
cSP*
)mW2;
P|OTf
~ 56
B-gh
~G3!'
CA@.
rhoTu9
j?J7
LFS2
hD8
oq!W
kM-
?>88
<D !
K+l2/JE
hNuv
bhM>
MyWebServices
;:I1a P
xmv
%)5N
3\3U&
{-N
Y mb
}ZH$
Ju9?y<
OH]q(
7 0Ik1
+O2_
j2o1
Asiz
:J!y
$`1`
~/T_
q)ZG
=Z1V
8?B5
1 &\q
];)%
XbjmQ
<1:3
}!:
a_0$
3If+
IDATx^
Ss}u
w5]7
{la
7LOa
Data
RgcQ'
8Fairchild Semiconductor International Inc. Newer Product
$B pc
UJ3-t
w3@`
26Rv-/
XtS~
A Y,L
K3,bD
z VL8
l]>
XC W
ope+
Q+u)
taOr
,-;[
>W8i
S4 '5
^lue
Fb-
A+c{\
^.<u9<
[6oF
oh&#%
^!so
{oGx&
#l"
pHYs
.ctor
iwm(~M|
.i/5Z?
l6YYY
|@H)9}
~,PzX
kQ=!F
W`-y
H<w
d_vt
D!
H1F
4b`K
^\rb
?26
,|y G~
o7qS)
s^K
CTx}>-te
0n@If
Main
XidM
,333
rR#
/.#EJt
4M6o
B38N
RdJV
UoNewEK
jL\7
#[;-
ZwL
bZ&B
hgo#
oc;%
J^xt.[
:H|Z
1#Fs
?wSj
k]x`Q
CKipH
5x 3
_t^W
3GQ
19sN@
m_UserObjectProvider
gzE<_!M
System.Reflection
b>
ConcatenateObject
gk%N
I*5{
$HjX
dq.|
)|ow0Y+
rjX#'
UX(.p
HYF*
U)@`
GetHashCode
B|p{
2%d*R~lEG
"j o
p;o$
pq##
S&XY
bet]
e>,z
2-C
5](|
hok
OtjS
y1f
_$bg
K\3q
8Z84
F0.g
b~B-
+a>R#
W/@+
@E&@.|gX0
Sd'S
MtN+
@.reloc
a$ _
jRJ<
Z @L
X.VyG;
,U9~2
.Jy
:%!A
vwYW
z5!${
o+OB
%,L
` uz9
%;3h
384I
H-Z8R
CP8.
Y@c
9_J0
`_{a
Byte
=lck-
~TD<XWy
~6L<
b[K{
*!|
\,j
0- Fv
yVJ{
$y_+
,_F./
1msR
(! H
]tOf
V!u
7%(i
^cF5
#e6)
#8w\u W
DelegateAsyncResult
9n8}n
[u
'[4\ Q
V~;N
EiYo
NN18
7 5
k|^
/!"B
b|HRX
V|3h
?]`]~D
veB{
]9Pu
nT:N
@ W
qI1z
&#fS
3,-.R
{c {
h*Mcy
TBxL
z^kX
k|lE
wT>R
L]hw-
DM<*
x}qV
:A_k
GNA,
JdcALO
yV;;
{[vA
k+qH
y,&y!t(
8q[VQE
T3_y
pT\D
]ML3
g/Sa
K)44
T{[ R
a{W@j
n^=~
T% k
x<N,
+FS#8R\
4#Ig
#iG)5
h`1)
^P^C
(UjA
~?E)j
:Hu@
!;md
S
*r4`
4l]/m(l
,9
^e~n
eqv]
Mq:.p~
jQb/F
BlDI
GULD
My.User
3Uvt
5 n0
ToByte
4 ,8]]H
(l'=
ID4J$
Th4i
15*:
sS_0
TA^E
+,HR
.)C!\y
a=6}
m8rNR
(Mqe@a*
3D)?
'p>
yL)
)<k?
ox;a
Wd.B!
E5-<
Bpnb
)K2yc3
-Ix|
gzj
l\cV
rgV^
f;!|
P,=(
YCa7
z)73mt
>=Eg[
s*sZ
>J1F
MC6l
qJSd
UCpyf->
BjTX
|MYh[x
2:C#
Ah'u
TU($
Y~ a`Q
Ok91
b=/88
`B ?
ohI>j
:1\C
Fjh}
cAP7
ao&MG
Nc2
r=FK
OVvyy-
Y~V,:z
X2[*>
XrRU
1[$nm
{+nwg
?CTr
Operators
Ef {
`nJk
VE#V
UC;X
j@"~
\#zTi
{;P?B
^A
]!$:B
Tg)c8X?
Ki^
7Gmb
[e#s
sre#
&_'
*92Vq@
Mi22$
M6}
?\M]
31=lEV
idk+
x:[tK
]BE'D
SlT#x
%'wn^~
2ct$
4System.Web.Services.Protocols.SoapHttpClientProtocol
[~ `
YIdaO
z\P~
183I 1
>wbK;
{q68C
jm*H
q"'n
#DCq
g%W
uyep/
:y91
lBH w~
zqb|
tccO[
TargetMethod
]F)P 81
`ktp
WHt0
L5\G
xPP<
/8Df7
N]Rwj
^ }y-
9b.G
!ul--
~q*oJ
Cj6
j6@o
nG&b
8LLL
:)M0
^qT
j*GY
F,+Z
y:7&
hN3G
J&8
Gv-a6
zok)H
FK1]
U@2Oh(3]QOm
sMu
dCc4
bm"6
_*gX#
> :o
(H1'
k(N2C
03r
BMr+
DAL+=
c%gJ
- V*c(
@3b1
i}%O
g jJf
lDed
5'mZ
6,W&
<fP/
azs.{#n m]
~E'q!
C@2Or(3L|Pm
@Je+
;IdDAWD
#obIn
% i8
JOSG
*>{Q
B!vh
"U
TMFP
j7F#
tv(7
Ws+l
?Wb
zlc\
cY<9
[g ~
m@9@
x*e
|OQo
n9#CF
;Ghl
}bm5
N~ip
} r\
kT[<=7
R*xi
:Sh
26yp5wnQ#
$Eqc
'"wY
J?B@2
Z`]d
Fc!3
o$@V
(@s X+L
gN`f
1 fQ
F{KuC
P:%57[
kM!g
^EHN&w
/pl[:B
H"zP
<Y^<
_n"?*8
wF#,
#bhv
) ~9
V7G2
%^DT
;%AO:Z\71,
QP)G
*<v
B Dn
.'g%
W4v`
GdWO@
p{b[]
L&"8
s5mg
`AAq
a:kp
"Pj2
VYeN7
?LfC
Ybn]8
KKLOO308H
47y6
dAMx
Fx#u
EU.C]
8(MA
#*GY5
MyGroupCollectionAttribute
aFZ7
[l6*
l 40
ccco
[`}:
'EYi
H "j
#y7-
L3on@k
{h~ GV
@CJr
SOz
ZNV
:]YoZ!xp
N<YJ>j
lM.S
i oZ>
'jaz
)!*c
>~[y
Iw$j
nK N
AssemblyProductAttribute
zX]5I
EDm6
cX?}iX
J4$d3x
MKynT
,{87Oh
i%;=
#?=(ahN
lSky>
K8H^2@
[D78
*j q
!'%Y
NpiY
IzpH
)aOaLH
66@`W/
AssemblyCopyrightAttribute
F#0Y
?+{Z
-Qm?
:fD'
m/A;
PU V
A@<iY
/jW#
3{r:
"yQc
r7,c
-]K
U <
.sgh
" 8VO
#IYn
\4j>o
<<F;zT+U
oWAJ`
>AR
fycW
0dm
fPF:
FY6c
@#EIAtq
yokv%O
MyComputer
z;i_x
K?Lm
^ ?7d'
@Ai 1
pKpH
.x4
%Sqaa3
87,a
D u]
^*Mk
\y\o
Yy6
jdK5
SX*
Tj L
]]1@
]'^j
eHX5
ij5A;
t]rox*
r'%k
k_^0V/
MsD`e
]O87
1hu/Q9
iAf&*-
_rQ
TlZe
odwV3
z~rqs%
!**&9
K)q]
iZmK
r"9$B
%>2`
^[;D
oUbNM
mF21O
,@;O
Z7ox
.+z'
;o[5
Z"QO
}-v\,
nM%"
#H|s8
dC$.X'
HI;'
vc7m*
i6M1}
K0,
:guL
D a0h
Ji
1Qb?
=+8
O~h9
vxTd7[[
'V2D
+g|
X8D
#0k*
BSJB
'cUY
s:_"
?rJ^r\=
\!Zj
i,.a
B@((^O>]
,WSX#
=C.{n
7LMM
MGB
W#tRz
P7AJ
$|;W
]0E5y7
bf]
{dP*i
QuWr'o*'s
2ap$-
?a?.=
xj|(lr
zvl,
0QNf
b[St a+T
akUK`
kRq
i b\
^,B['
B7gz
o<NA
f _
|.=.t
vQD*
;!5.4U
}.s0Z
UlO?
6]54[
T] b
xX?l
3s>3
i|?X
+w60B
`AN'A
&zZ'
{h+M
n}B[
)|kr4
AX4
DJ)ow
.T4W&
'T|
gAMA
gV<b
C=(
@r8r
4/U^
LDpqy
q"A3
o4AQ
e&{ :
i8.4
(h!p
7Pi.
e<%Y
@H5N
,04.lZ
&IX(
sb_T
53"3>k
N-Qc
mH*s
'O5 q
l
z;EB
(1/*
3>]R
wj~[
JfyMO
mscorlib
i\jk
O6A3vOT]k
J5ul
(;R5
4fFE
ri'Cc
)$}\J
/{J
_[]A
!`M$|
scnF
gLS'
q1;;/
,wuB
Fy!r5
J^W#|
(k6e
ZyvX+
Y~
lFAl
Yv}X
2,CK2
X]g.h'
KZMp_
q&YO
6Yc(
C9r~
4fLX
%09
^3>
uem/
T 'cx+
<Fg
US69
,Ww<
K&Ak-
if!I
h,-cD
|aR@C*w^e
15~_
(I5L
`PCB
Fl:MH
J`TN
j#3T,
fffH
ik]$$8^
RTBn
nd[v
By%Aml
^_}>
tIZ
wFzN
:OVT
H;\K
?4>3
{`XF
`CVJ
$,Og
xLn@
&w8e
E7_%j
md2(3
Up&
Lp7(
3aFz_E$}
__41
&65i
%0MR
J.wK
w Oli
!8YDx
sTa2
45XC
RaJVb
ak L
C^2[96
~eC
IxuA
@]T2
N )
&i,|dqx
{ dP|
MWDq
-f+o#3n
&UP'
]Pq5h>
8Z4l
jam
,t=.nm
c6}1
y_Xq
cTTw
ga*$
tv>
>F/0
Sn6+y
6'2X
3oHtH(
System.Runtime.CompilerServices
8~M'
X)2
ePS}
51xg
b2 &
zd^3
U sT
j;AA>
z9F0
Y*ND9U6
&%:8
kQ%R
Object
VkFrN
@ww7
D%*
P/OQ
o+?)
o}eV
gTw
uyv<E
*<\X
jX[k
<&.T
d`.1n
iQn/
m8;K
1G}+c
.z8#
p><F
2:I
]0ir
9S A
Yb#h
L=><
Wad4
~.x"
>
{z; e
f9Nx
&SD.
>[]
0C\d?
=6F<
pP g
#$ZJ
KL0
2M`,
0] F
v;{)
nhH1
{Bf_c
AssemblyDescriptionAttribute
am65v=
)&<$
"3N_
%[8}f
hRr1
Nv=,
\2=}
+}$a
ekuwF
<G5X
U- /
(oBg
h|oH
*.r
picj
W^\G
mjW:m9
ah/T32<
:]i?
7aMS
RfXM
q Wr=
K8Uh
)OW 3oT
<9/?
mLVK
P U*
N=5V
r@Vy
nx$?
-<?$
{R$a
x+]r=
IvY
QA9
xW<z;
%;wY3
=^vW
`7m
|B['8p
'R;H
Bd|b]i
~Q232K
k6ZR
Lp'9
B 4
ODy0
8
PdBWu
bUv1
z`u`
|`uA1
m322
GFf0B
/U#%
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
d6O*_
IF Cq
91,VZG
O8Gb
nzw#
f?j0
R^E'
KlyH
Ls+Y
P Ra:r
,\PV
'|>V
TJg.
<#>
L-Y!
=Xx>
!K5NQ
w?
Rn!eal@
:]{H
mscoree.dll
!This program cannot be run in DOS mode. $
n-VL8
/Kcy
3(c) 2018 Fairchild Semiconductor International Inc.
DelegateCallback
-Og[
%+ jL
G"1
m_mh2
aHsW{
)t]*
++K0
z|V yV
!/Ef
'jXC
pUkZG%R
UHJ]y
|&Rg
%/p E
~]YDGK
J]Zh
,= q
+)fiE
\yK%
?D ~
<\?L
LH29
UqZ+4)
ov77
& }`
B\=K$
V="u
[!gO
\'$U
]?s%9
<xPz?
.NF(
"Fs
B+>[
0PGN
v> 7
J9"x
I`;&
([q3
3S!p3
Y!.U
ChG
cJ|j
\5h:C
LateGet
L+Z}
b'E5o
$QVF
get_GetInstance
e SX
q0+>
yXU
H~#F
1o/6W
` Ptn
UE'j
8An(6
Z@&n(
X4.^"
J8BRx
kaE
3!Uf
#[6JJZ
gjTR
@9j)|
- rVz
^U3T
0zr4gg!h"=w]
nt?D
tP2T
X1hf\
:]3n
a*<&
U77P
neir
yV6?j
*>}n
fN;Y
8,X|eRR
KK]~^r
,:g7
V;h=~
;iY@t
*)'Ft;U
/SpU
c.u72
dBqA
,G6F
1]X
<$y#
|Sk#
QDm(
b@j5
<}t<"T
oNBg
@^ )
XVj4m
f.sv
2==M:
0?w6
6B_aNZ
[-84
eeffz
rm!rU
E_k{l
gqku\
X*1;;
Zf3xS
J?Rtn
>ma
%wr
zhu!
j\mG
(g3u
e<$v
- %O
/pU
bNN q
7q@>1
`vv
1,rG
w]S+
[r*=
p]_]
QiN0
k<-n^
H~"`M
I{r&
nc&-V
Jf$.
*_2D`
4}otEY
:{:I
rd+p
14.18.17.0
z4+|4
1'W2
8qv~
LZHB
)O9y
)4<4
;tHD
63M)
m7</
#@!%
*]2 J
@m L05
WSt<}
u];5
GY$b
U0"rp
&Pb!
iKko9
;v[("D
;jt6
B`p2
"}gU
} YZZ
LDr
][ @
`)J7
;{w=
]Uqb
gH]0
\J ?
C1K!tS
>vB$
dmxf
)")6
53)
Wb$:H
"8+y
WPO')1a
&+++
{r}LOe
L9=Z
SdGU
XT3S
m{b4!t
n-zX>
-c\VTr
](s<`
h_=4
PxkcW
T|q{
r;A:R
{Ng3
aT@^
Fi|D
]R3
=92q
mpL>J
D][~
KL f
cl^t_
Ls*Y
oY(`
&YApF
2FiGu
\j/
,2R M
'y?u
6MKj#
Qog4
}sZw^n
m`R
Mj@I%X
#{My3
E%
aC._
+ m/vq
Mze&
PF^L?q
G[+N
.E!gjV
KUml
N}Ey
y VW
@qvk
%'=j
K 2&
(>:w
~[q2>/h
e{%!Z
A70si
nH6c
M;mm6&
x?~0K
-cx
m_ComputerObjectProvider
KYE C z
c]h
EC5R
P*[k
P0Co
+pT)1
:Q<
hQOu
U?%]=
(3}<2(
b<p!
R_+G
>Xr 5S
vY}W
49IK
"PX>
9vIg?e
dmuN
HkYz
zjw:!9
(>@xxFW
RKt9W
!{&
!L'/mS
IDAT
dX6
H&
N"uP
]>#1z
;"F/
9Kb7/6V
7NNr
-w{f$(
6OT"
I5tUi
K]&T
i%S8
=(gJ
/Ebvlm
g5"/]B:
CompilationRelaxationsAttribute
WAeP
get_WebServices
b6zsJ
M).:
[D_W
C i?>%
HBa~
?O]gn
OwCVI
PnjKh
1rWm
gK*lq)
;Ktv,
~tc
:r#&
n# h|
hX(W
Nc{!H
Q*'?/S
LQ k
0Uq~^
B#Y}
`VN]
Ac:JW
N)(akT
9JTZ
0eta
+(G
^hKXlb
o3 s
te5~E
2=b\
5a^4L
3O][(
&M$Ma
/|,@
cG=as
;26
UE6r
Zy|O
/vj
](!S
I=hO
0==M$
7y^v
4.bS
I%w
o Hd
52;NJz
{3=m
p:?Lg
qR3
x<N8
5pYR.3
;v:<
11tl
ysj=
%zIC
t"=C
?tj 6
F?'fV
HideModuleNameAttribute
uvQH
I)GI
':OU
pSY
[&>a
u+'O
H4}+*<=
n_zB`
177G8
ocxB9
j.&f
'7]1g
T"6C
i^=v
Microsoft.VisualBasic
!R-t)
G#Q31
}Z0*
iZGEx
/OW 1
`+Qj&
!5dy
K7+,
ECwQ)
+jbc
Oq>,

nzCaT
,..P*
*6lD
[Imv
o-Vx
>[qP
wx,V
T*LOO
C{lM
'y9g}
>,v
&,UC
{Od2
W2pF
MsJ)=.Y
T1vC
39I
y"[-
W.#bq
>6RlP
zr;t
9zE$
'T[og{
E; G@
P<9T
Rc@p
vLpg
bcE"'1
Tb%
0YxXS
m(_d@
jvUA
X{;>
jV&x
A0+c
K>Iz?
5^` w
s/4l
S"X3
L1WtO
B.xl&
Ibs=
>cG6`=
Lki
R9v
~-ylKO
E#O
!]ht
LOOcY
Z3g
-n]
?s(`
p8`
r^w(J
b^<)
r*L_!Y
pPENV
MT! N
3~Mc
T3~K2
EZm):
|A-i
alex.exe
Y)wQ
}Nqb
;>Bb
RJ6o
8L)vL]
PbsNw
Q.B\
u-%)
ZOy|d9_
']{"2
+fIb0
>K@E
LwWw
CompilerGeneratedAttribute
ComVisibleAttribute
DxG]
/F?
cA0W
tuua
5]m . q
JEgs
_%b
* b'
g6;\A
^BQS
4&,UC
UI|~
`CgMQ
_wP,
L4b)
?xSu
k1)I
2O%i
RZa?2
7T /n
_99r0
0>Hq
*(9{!O
KcPX
VLzy(
2*Dl
&d9VJ
9`JZ
8eWh
46Fl
\{kw
AssemblyFileVersionAttribute
)Zv.}
_h
;=Kd
X Z#(
System.Text
dHv@
Lines
AYUw
ScT
3&&df~
?A %
Ps;
z -)]J
@0e}8
dBj9
W2/~{
yeF_
C\Jz
9r`c.
GetString
SyE-
>91\H
})B%
Microsoft.VisualBasic.Devices
gX z"
+Q<T$
/)zg
]##]]
3gx8
jUe8XQ
5K%s
j-T<
2%6
@q7<
h H$R
4 $=
\System.Object[], mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
tMc
>Y@/
'hW=a
L|KY
|y>V
Wx~,@
x:Vz
mcfE
3"r/
TU(L
nK'
RDOf
@3wI
Nq<q
!_L
y"'_
=? .$s
X EFd
}-jX-
at4b
b=e
8qd}
Jx~CG*
Q+=8
U0ql
p?6|_
V<N
|.Z8
R} cC
}UA2
}jr7I9
@g=W
}O&~^n.i
py<4~
Nma
kJpt8 9
uVE!
CBJ%P
Nj,z
W~|X%
}/7g
S4v(
? 52
<RE E7cD
Encoding
}rxN
/qE}
vjK;$s
n"}5[m
s|]7
gn[$
x_dR
w>Y"AJ
Kws9C
$Nj-[
PA1 VERSIONINFO FILEVERSION 0,0,0,0 PRODUCTVERSION 0,0,0,0 FILEOS 0x4 FILETYPE 0x1 { BLOCK "StringFileInfo" { BLOCK "000004b0" { VALUE "Comments", "Fairchild Semiconductor International Inc. Newer Product" VALUE "CompanyName", "Fairchild Semiconductor International Inc." VALUE "FileDescription", "Fairchild Semiconductor International Inc." VALUE "FileVersion", "19.1.3.9" VALUE "InternalName", "FairchildSemiconductorInternationalInc..exe" VALUE "LegalCopyright", "(c) 2018 Fairchild Semiconductor International Inc." VALUE "OriginalFilename", "FairchildSemiconductorInternationalInc..exe" VALUE "ProductName", "Fairchild Semiconductor International Inc. Newer Product" VALUE "ProductVersion", "19.1.3.9" VALUE "Assembly Version", "18.17.8.19" } } BLOCK "VarFileInfo" { VALUE "Translation", 0x0000 0x04B0 } }PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
SD;b
'afD
)IKU.
nbIE&:
(jI*
G.f^B
T*Q*
i=]ut
}TT
String
P]SI
&f9b
_CorExeMain
cENw
| \J
yoa]x
I(da
9Qyt
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
@r2B
Create__Instance__
Ny%*
<Module>
6$h9{P[
)Zsw/
| $"h
~W*B
k.oz
C5q$r
aZV;
WJrR
p[/#
9\bV
fHVv
KR>^
*q_
hW<
:###<
&'IDQp
\&R&
Idy*_
j%7
[]B[
U'I7
C'oC
R255Mq
"vPW
VJzzzx
Q cT
z="<A|7
/[sah
E= i
|+Fj
{1S?
>gRu.
!{ C
KW5K
ekXs
EditorBrowsableAttribute
o^8I
v~6Vx
H+YT
@F$7
XM("
P`_qd
O$blp
&Lq e
Wfj
f6&_
nMnS
IKp#
$?}`
G3-p
${/r
d 2\s
H[B4g
jO3T
&0<Y
User
D)^wP
h\&E
Dfi<
pe%T
R 2_
Fi=meR
tX2x
9r/
|kBU
V&#e
/:Cy
W KP
8Vk^!
Jfo-#
V*-42
RG=QC
XGsG
, H,i
,5(i
4Y\\$
.xq'`a
ihkEMS*
2 zn
4O`,
v?H.is
+HYj
04&Y]t
vng"/
&<<j
v yfL
$o%5f
>6ipK]
2zaE
gLh
appName
W>5s
+)6R
14!XZZ
y;B#e
R}h_
o. e
?l2-.n
2vY-lw
]4-]z
l>l@
m4O+
*Ro&G |:
BeginInvoke
4wvKg_
1TXz
(Nny
NV2$!U
o|LE
Z}S{
2ec/#
sFw\
>Y~Xy
BGo-
h`
h<!l
R4R
<:i?
GX!%
TR^wi 0/
4Hbh
WFK'
-K{b
F<#?
y[x}
3L2#
/
XqW5
q0GH
0 6m
u<OnZ
t:M.
ay0/
>K"08
O>qJ
YOM~
p>Gsa
bq4M
?^4~1
[`Ge
2
YLy`
RuntimeHelpers
abA
|?h{
d~dT
G5)$= @
yYdz
9cv'
<R%,O
w~7D
\;qN
1xW1
-wtQ
`[3Zx8
+WPM
)R^V
^ T9
7V^Q
{@UT
o.t-h
F@3
G l6/#
!Qt33
->(K:9
Hu0,
3.uz
tftxh
]5lJ
]~H};
.6B
yMR
Z,+4
ZN$0
%Q$-z
`D ;/l
Bk?[A?rm
G|_I
,-MW~
_*S9q
F0+7S
DwO7
j\M@+g3
|AN3n
E)e]!
|!>j
_ NV
l.O"
QG_u
O4~!
M &\
'x4B
dbzt
3e}^
O[-k
1rg\v
get_Length
),zp
$OK}
>Ga$U_k
System.Diagnostics
ZPmW
I$-#
~Sz_
SVr]
\.D?*
z4\/
LfI*1
sn O
PX.p
Z$YY
S$ #
[;t#Y
<WN]
91>y
/@$c
_+a=
+uy%)
u$ecK7
?:pV
XBj&(a
VFzP
4dHw
H}Mah
p?Oxh
Xb9
oFeH
!}Du
[b`k
! oz
EditorBrowsableState
U=h_
"+{
*3v#
|2'
v{&[
tTW0
[U8%
<Hae
X$j??V:
Q,@]
$#@s
vpZt._D22
4"hQ
[sq$
[1X3s
|)%g
}$.rI(
CBYG
pN'
cypIl
^=Jp
YR=R
`dOR
133C
Q`:
1nJY
T?#?
#lH#@h
-{<U
`J?~
6:@sj
<"
SN<]
->"
;eD:
dH^x|
G\P}
Fw4N
qzSw6
t?,bTc,
a$Oj
T7Ty
v,dU
52x]
0UJm
2$pY
td.j
f`*{
6x5}8
eK&4
n:a*
Y6ns^
sRGB
!6!h
ZMPf
jTz0
QN;>0
b* {9
G&WQ
0[_*u
bo1hG
tIcB
AssemblyCompanyAttribute
"n|)
~|wQH_k
4{e>
*U@
,>mX%
b fL
0S)A
xw'Ax
!_\k
{"!ro
Y6Rq
WOTxk
ApplicationBase
yy]xn7
kPde
r: T
Qf{n
H98x
c%l:L
Wdxe
boo %;
v0!u
P(NxM
fdX@
R)(vrJN
_A{t
s'}}}
_f 1
4i.,P
<K@v
BTOg
VTWv
4:NI
{gl,g
8~d,
m_AppObjectProvider
EX=&8
5twwc
d2I&
oD -2
Y@tc1
A==EW
V$u
0{#x
.%sU
'/a)D
s[.EB
aiE`
H4*
TRa
@(&'
B/p!>
oQ4+X
GH=gN
!X&J)
dw
vgl)
](-1
S~hJ4
7uB[#
OT7X
I-I
j-|({
$,0X
L9,$
1iakA
)Iq&
xra]-
{0=
eb,
HRM!
Zr@97
y6$|
7ZI,7
sliE
]Rb
188H
K<,BY.
,U
xy$k
e,v~
T33
B3t+
#9=Q
.Ye]-
7Ps6
.!IU
Kk;YS-
QVM(A
/]RK[Rn
My.Application
}F
#Strings
i"_z
A~{o/
a#iz
!4!X
Ej7F
e7 <
f]N/H
t {~
}*Bh
$zts
(T >
r=h'
|_J!S%
T'v~
cXWW
Q+oQ
MSPE
Lj,|
%w#BVw
<kj-
"Chy/
`{PJ
*|Xn
Rr`\n'L
z0kb
F|uQ
%_Iu
002
\6Qi_
gwj?
2;K:
4)x3
.C0D
$_"?
vLFWW
K$Ccl"
|[:t'
u#x.I
$~er
O GR
X)jW{
Rz1`
N" xn_Wiw
fYN%
!}7\
t<<[
idp!
t5A
!0LL
8W~
zV)m
t3_Y
PP}=
AA?r
Fyg:U
9FxQ5
AsyncCallback
st,}
}~? ]
S5vo}
jvYy
-p`@
j>K`
;=M0
YYYA
[(HPY
1w|x
KC
Kb0?
}v=m
.)!V;
`d6$
5p\-
YrGN;8 :H
~6p
"BXE
#S{%
:/D*
#'B\
}0 ;
_![x5]
VYQc
~ZbZv
F%#A"*;)@
X%b-;wi
f!^^^f
Microsoft.VisualBasic.ApplicationServices
]ym.gi`|
OZL
QfBK
(Aq1
sCjW
,'qL
f@ wjf
f3jF6
P<Q^
51Ml6V
#k>M,;N
`.rsrc
QImbrS
];#Y
TK]0Q
&{8sD
U,
B&RA
7w]<f
]0Iu
T|J{
Rr!f
2l5/X
)>1W
x}^
;LV`
U'<t
eD .
N68.
yzX
T0f0
Nw@VH
ryR,
WK?RE8
< ah
^bpp
zF$.
G zN
=7)?
[SKa
W\K'3
sM^&
p8L.
i=qe
G=Z.
N-Cl
bv?g
PxZ[j
M %p
KSl~
ZHe4
.[6o
M*@oOy2
2"]5y
VrX|
}Bf1-
Q!D:
Qj m.
My.Computer
Yxn
IDATx
*Vd~th
TargetObject
j0r6z1
v2.0.50727
B__/G
Tv2|
9 Dp
=:MOre
&cw%<
%673
@X1m
L4ho5
Rf{W/$JI
YV3c
*fD"
!U5N
F8O^2
7}Tf0b&
esvO=
.]5y
jVs?
]mf{7
+(>Q
3vtq
Br>}
/~6E}
}J-z
qBlXt,
")pt
=`mez
r7q3c
H^n\
O:lM
[2=V
$SlE
et<t
_z"!Q
t/) +
kj5"
Pn`Gcu
x W*
<ykY
<E#$]
g&g(
"\T?q
u0!j"6
A+e>x3b
>%"5
DbYs
\'I{
?p6dx
4N(L
-}J{
`Ii#oHXA
'&^k
kHkMhf
-^a
yw$KQf
[#9
q,E
M`bB
.a=t
o008
4BxGDrt
dOpg
2ax:
(+x
W2 ol
{EZy
zeMh
/NHy
A6y]HHi3*
GetTypeFromHandle
IAsyncResult
86[>
(_w8
rpf7q
z. ";2
5G8"~}
:,7TU
Y$F^_j
{">
]OVUa
~w}En
x:_
L: B
3m$9
Y]mB
Hoq"
z L:
;$mm
z,Aw
#G8p
$3&.
?(.Q
ls&hM
instance
*loHR
5`.
;43z>B
&z3|
qdKt
WWC |
ZX_XU
=bq60~3
sss,//
1Yj[
n%UI
GIX'
')5,
6`,^
J*k
?OWW
UZtD
wv~C
X,6p
`CVJE
`.SE*
gtqC
t,E;#
P(>p
9l&p
bIyFvA
r>(D
j5ATm
LMMQ*
<46Q
_t2$
52k=f!
r'K
'E_j
IDAT
nVYi+D
cYi&
j]}3
System.Runtime.InteropServices
F="F
.v,/
|m"-
eHQ
S;9Wm
sG|dzt
5VPZ[
4'g[
1rL05m ag
[=ZcO
xkm
BgkT
DqV
sLk{)CD
]],,,
y 6X
1|A
`K!9
%4pV
YF[z\
p9;jM
Q|d(
$-:[
BLA
\R7W
)r?~@~Y
Qr[\F
6 >=e]>
;I)t!
]4ZV
,l~`
D-OF
Gv=?
*E)-`
p$*G {k
t4uA
(Nz$
,+X=
:4LQ
1obR
L7_U%
ubZB9
v4J*
v|\s+8{
nd'qG
%8~j
mX7Z
R.<#
yHb
6L(E
IEND
NewLateBinding
\wgC
6"kGm%a
9W#%wn;
@5
4(JEa
luP>
ytWn
%7]m\N
zUTB
*,svi'H"
N(=K
8 Hq
/Z!
[>/c
|=.X
b^Ss
A+8CK
XKFzPs+
h3P;
z^sN;
rMib
8+2|Z!
j(,5
6\E7LT
E0BXD
5IJ
:kw;+
zpN{
=,v*
LP0$x
paZA
tC`,
<w sl;
FKJ
cl}#~
<,v+0
j{3\L
k7S`UJ
\fff
B~ZUV+
8A4/1
~)zG\
t K*
P_`
tc_
)B.r
t9)I
zQep
khd'
/Ehk
r ou
d9%I
Epg|
g@vw&
e2! jH:Z
sjv@
v
&J4'
@J$ D w
, <tJ#[
9\k`
6`T}
Gw%5
E}/|
`$\(
T}*BQQ
bqM8
cXmd
o9:3]
ji}q
NVKg
TE)g
?RX.P-Wx
n+gay
[}*$k
lOen
{?a[
$nur
r$Kb
|.}o
+ RI
&sR
8lPy
3P(g
t@Q,pr
,X&2<
=u_yFg(^
<AXa
%0n
+6Fd
CHl;,
,HuUu
n( K
OI_pn
s<;+
"8%l
c!vW
*hp
@-<l
z@}t e
=;Na
|vb+N
Hd{
!Ual
Z%u:
(]xb
ZgyP
rnJhw8
fBB'Z
Equals
8Go
EM[fH
s7O6X
`PS_~
#Blob
D'p*
~(t>;A
X0"%
`Tt<
}#W@G
kB1K/
:`#[
LT`'e
=h>k
GeneratedCodeAttribute
|?|:5X
Z+g(q
8K p\
^=;)-
MulticastDelegate
KzL@
fH[U
M0U#
K^)`
Fdoy
JcU9
9{ m1
S4s]
|9 @
<P}.z
ClG
7eR T
s(#7
P\Y!
2k",I
]'#
ItB^
]d-1z
qy[Y
$#|s>
c_ 4
QtPt
+:\GE
X!Hv
p7k^>D
ni^)
}lD}Y7
40~>#8
/4H~
+++<
aP1CZ
8:}xV
}6E
,Lau
x5[oYt
Bf$
K<g$
h+pse
r kI{L
Ci{*
t:}
huYV
N\c$r
le4/
GIF>r
Computer
APo
Wl~1
#GUID
o->//
$Wqg
N37;
`T!v
^VX6
u#z %W
U8+*
<#Es}
OW6uA+
m{n>/o
Gg6s
`rA!*UP
y6Fj
DhVu
jr\(g ]
ku-4_
W4Rc
J1Ri",
1'NU
+p#TV`
T*tvW
fAu0
APNH*
53=Wl=
g@t8p"
y!7x{
T~OUc
U/OB
}.tG
o8#n4
.ajDqW
:+ G
&GlZ
)^-J
"#V
fAgj 15w
c7m
gzCJQ
Zf w
OCu%"
)@N'
4 /V)
+ '.(
g-:1
#hPh
PrV6 p
izBvu
L@8Q
=PWg
P)C
l4GP
"8bC
>M~f
E~M>b
~ee&
8.0.0.0
Y5*wj
8Y!)
.Euy
vO4#
7|?
A;h
Bk$*
S%o>S~C
XH]Z
9-pU
X `l$
F"J
xZ8^
<jlm9
X;/
MyTemplate
fdd?[
z>%0j
M8Dwh
v]*>i
Y2wu
P&yU
rX.i
joIi)A:
z Qvp
LL.c
t;+y
YR(D
6HK%$U
u;Bi
&]1
5fXa]
OBU}
lKj$
S0
W@}k
H Guh
xLA
.]"d
6jYG
q_19
Z?>*
]|
C3To@
LK%]On
2?qQ
Z<3A
> Jp
+@BH
s;xN
AqU_
2)+Bcj
m _9
j9$
rs`$B
Oq z>BU
e*}EVS,t
^?u
Si^*
%{l5l
G369
}hL]
Z=Q[
NE[A>
oU^Bj
v ^z
}$],4B`
ViN\
{a0$i
<bOf5
0W'*
vd0&
]"/]
#Jkr6
Zs %>e6F
x.~:Ax
h4.K
phl
1.Dpc
RIJO-
6?^G
|'Bl
c@+o
p qB
HJQ,(
,qu]
+^)vG
LOpNy
qnvj
-_x{
System.ComponentModel
9Wz=
W"w|
P;<e
GT}<
AjZ$)
9}i>
6{')VI
}zVj
[*M}_
t/^_
`A96
/zj`
.ioVK
Po.o
@v\o
kS?f.
L3@[
-tS@
{X]=-
l2y_:V
* iI71
&MO
GD}j
%#h
"T+5j
)0jN
DV oB
9r8&e
Wf8G
-2&,
1n~l6
F!r3
GetInstance
87c
'Vr+
G9Z!
zZ>c[
%b=?X,
w%,e"
04|wV
cq47
o-bJ
+v;R
~K}Ii+
MyProject
D;v/O
qvG*
Hg V
\6K>
5g.A
(q`/
O~_m
Z:4!
\SdI
I}Yg
`(c
ej.d4
8v,6^
=&`*o4
y|B8
SfJYx%
1W')
B^qmz
W9JEJ
\}S
W?w"T
$ici
X@hl
!GN6
*c-P
0l*f@($
&A+/
K9[{
ZHyL
4"2\v@F
tX\x
/np"
(_qY
r\3Q
{'()
8 4#
aBt9
5-
Js&~
<(?*y
System.Drawing.Bitmap
SUTQ{
rSoz
&oz#
booy
Ib~5>:Y
qpR\
1G:K
_6B&
Thu1
8C(EP
to43
bS;
euXu
qL]2
jav
/<>
X,b7m
y4G4
+o.*
bC69
! H+Z7]c
!o2XC
7j7F
* +b
{e&D
yd~p
z,*8
1Q%x
|BVsqd
72brH
?Ymc
bqyj
XYYa
322L&
+`'r#4g
>}/J
fdl21.
{0:^#VR
-pn
6a/B}
;<tu&*
cNzB
FES7XP$
c@;\|
DebuggerHiddenAttribute
/;=-
O3'YK
(\]/
s>cB X
;>62Wz}Kg
Nr.I
hJ|h;
^x!.
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven02b_64 | Seven02b_64 | VirtualBox | 2018-03-12 14:37:23 | 2018-03-12 14:40:20 | 177 |
20 Behaviors detected by system signatures
Collects information to fingerprint the system
Severity: High
Confidence: High
Attempts to remove evidence of file being downloaded from the Internet
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\International Business Machines Corp\International Business Machines Corp.exe:Zone.Identifier
Exhibits behavior characteristic of iSpy Keylogger
Severity: High
Confidence: Very High
- C2: 192.168.56.1
- C2: halimofset.com.tr
Installs itself for autorun at Windows startup
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\International Business Machines Corp
- data: C:\Users\Seven01\AppData\Roaming\International Business Machines Corp\International Business Machines Corp.exe
Retrieves Windows ProductID, probably to fingerprint the sandbox
Severity: High
Confidence: Very High
Checks the CPU name from registry, possibly for anti-virtualization
Severity: High
Confidence: Very High
Harvests credentials from local FTP client softwares
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
- file: C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
- file: C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
- key: HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
Harvests information related to installed instant messenger clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
- key: HKEY_CURRENT_USER\Software\Paltalk
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: alex.exe(2520) -> alex.exe(2792)
Creates RWX memory
Severity: Medium
Confidence: Medium
A process attempted to delay the analysis task.
Severity: Medium
Confidence: Very High
- Process: alex.exe tried to sleep 1734 seconds, actually delayed analysis time by 0 seconds
- Process: WmiPrvSE.exe tried to sleep 361 seconds, actually delayed analysis time by 0 seconds
At least one IP Address, Domain, or File Name was found in a crypto call
Severity: Medium
Confidence: Very High
- ioc: inetsim.org0
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- get_no_useragent: HTTP traffic contains a GET request with no user-agent header
- suspicious_request: http://checkip.dyndns.org/
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://checkip.dyndns.org/
- url: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Unconventionial language used in binary resources: Serbian
Severity: Medium
Confidence: Very High
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 7.98, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00037000, virtual_size: 0x00036d04
Attempts to connect to a dead IP:Port (2 unique times)
Severity: Low
Confidence: Very High
- IP: 192.168.56.1:443
- IP: 192.168.56.1:80
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven02b_64 | Seven02b_64 | VirtualBox | 2018-03-12 14:37:23 | 2018-03-12 14:40:20 | 177 |
10 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\alex.exe.config C:\Users\Seven01\AppData\Local\Temp\alex.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Local\Temp\alex.exe.Local\ C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows C:\Windows\winsxs C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll \Device\KsecDD C:\Windows\System32\l_intl.nls C:\Users\Seven01\AppData\Local\Temp\alex.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI C:\Windows\Globalization\it-it.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Users\Seven01\AppData\Local\Temp\it-IT\alex.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\alex.resources\alex.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\alex.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\alex.resources\alex.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\Globalization\it.nlp C:\Users\Seven01\AppData\Local\Temp\it\alex.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\alex.resources\alex.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\alex.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\alex.resources\alex.resources.exe C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll C:\Users\Seven01\AppData\Roaming\International Business Machines Corp\ C:\Users\Seven01\AppData\Roaming\International Business Machines Corp C:\Users\Seven01\AppData\Roaming C:\Users\Seven01\AppData\Roaming\International Business Machines Corp\International Business Machines Corp.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2520.15649781 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2520.15649781 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2520.15649843 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll C:\Windows\System32\wbem\wbemdisp.tlb C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL C:\Windows\SysWOW64\stdole2.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll C:\Windows\Globalization\en-us.nlp C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll C:\Windows\Globalization\en.nlp C:\Windows\System32\tzres.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\security.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\crypt32.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\CRYPT32.dll C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\* C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\* C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\* C:\Windows\System32\p2pcollab.dll C:\Windows\System32\qagentrt.dll C:\Windows\System32\dnsapi.dll C:\Users\Seven01\AppData\LocalLow C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 C:\Users\Seven01\AppData\Local\Temp\Cab5D4D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D4E.tmp C:\Users\Seven01\AppData\Local\Temp\ C:\Windows\assembly\GAC_32\System.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\System.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources\System.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\System.resources\System.resources.exe C:\Windows\assembly\GAC_32\System.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.INI C:\Users\Seven01\AppData\Local\Temp\Cab5E98.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5E99.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5F36.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5F37.tmp C:\Users\Seven01\AppData\Roaming\International Business Machines Corp\International Business Machines Corp.exe:Zone.Identifier C:\Users\Seven01\AppData\Local\Temp\Cab6032.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6033.tmp C:\Users\Seven01\AppData\Local\Temp\Cab610F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6110.tmp C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\* C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\logins.json C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.INI C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Temp\it-IT\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources\7J66Q0Y0ASPXJDSSUQ2KC1TIFXTOX89OELZ8Y9NC.resources.exe C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies C:\Users\Seven01\AppData\Local\Microsoft\Windows\History C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.INI C:\Program Files (x86)\Common Files\Apple\Apple Application Support\plutil.exe C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\logins.json C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini C:\Program Files (x86)\Mozilla Firefox\nss3.dll C:\Program Files (x86)\Postbox\nss3.dll C:\Program Files (x86)\Mozilla Thunderbird\nss3.dll C:\Program Files (x86)\SeaMonkey\nss3.dll C:\Program Files (x86)\Flock\nss3.dll C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\UCBrowser\* C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini C:\Users\Seven01\AppData\Roaming\Thunderbird\signons.sqlite C:\Users\Seven01\AppData\Roaming\Thunderbird\logins.json C:\Storage\* C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini C:\Users\Seven01\AppData\Roaming\The Bat! C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini C:\Users\Seven01\AppData\Roaming\Postbox\signons.sqlite C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx C:\Windows\SysWOW64\wshom.ocx C:\ProgramData\DynDNS\Updater\config.dyndns C:\Users\All Users\AppData\Roaming\FlashFXP\3quick.dat C:\ C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml C:\Users\Seven01\AppData\RoamingSmartFTPClient 2.0FavoritesQuick Connect*.xml C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\ C:\Users\Seven01\AppData\Local\Temp\Ftplist.txt C:\Program Files (x86)\jDownloader\config\database.script C:\Users\Seven01\AppData\Local\Temp\log.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6566.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6567.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6578.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6579.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6645.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6646.tmp C:\Users\Seven01\AppData\Local\Temp\Cab66B4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar66B5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6743.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6744.tmp C:\Users\Seven01\AppData\Local\Temp\Cab67E1.tmp C:\Users\Seven01\AppData\Local\Temp\Tar67E2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D61.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6D62.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D73.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6D74.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6E50.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6E51.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6EBF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6EC0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7597.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7598.tmp C:\Users\Seven01\AppData\Local\Temp\Cab76A3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar76A4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7916.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7917.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7918.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7919.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79E5.tmp C:\Users\Seven01\AppData\Local\Temp\Tar79E6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7A35.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7A36.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84D6.tmp C:\Users\Seven01\AppData\Local\Temp\Tar84D7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84E7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar84E8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8585.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8586.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8624.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8625.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar920E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar921F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab92EB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar92EC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab931C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar931D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95FD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar95FE.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1B7.tmp C:\Users\Seven01\AppData\Local\Temp\TarA1B8.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1C8.tmp C:\Users\Seven01\AppData\Local\Temp\TarA1C9.tmp C:\Users\Seven01\AppData\Local\Temp\CabA266.tmp C:\Users\Seven01\AppData\Local\Temp\TarA267.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6DD.tmp C:\Users\Seven01\AppData\Local\Temp\TarA6DE.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6EF.tmp C:\Users\Seven01\AppData\Local\Temp\TarA6F0.tmp C:\Users\Seven01\AppData\Local\Temp\CabA887.tmp C:\Users\Seven01\AppData\Local\Temp\TarA888.tmp C:\Users\Seven01\AppData\Local\Temp\CabA944.tmp C:\Users\Seven01\AppData\Local\Temp\TarA945.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF03.tmp C:\Users\Seven01\AppData\Local\Temp\TarAF04.tmp C:\Users\Seven01\AppData\Local\Temp\CabAFA1.tmp C:\Users\Seven01\AppData\Local\Temp\TarAFA2.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2C0.tmp C:\Users\Seven01\AppData\Local\Temp\TarB2C1.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2D2.tmp C:\Users\Seven01\AppData\Local\Temp\TarB2D3.tmp C:\Users\Seven01\AppData\Local\Temp\CabB3BE.tmp C:\Users\Seven01\AppData\Local\Temp\TarB3BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabB46C.tmp C:\Users\Seven01\AppData\Local\Temp\TarB46D.tmp C:\Users\Seven01\AppData\Local\Temp\CabB6FE.tmp C:\Users\Seven01\AppData\Local\Temp\TarB6FF.tmp C:\Users\Seven01\AppData\Local\Temp\CabB80A.tmp C:\Users\Seven01\AppData\Local\Temp\TarB80B.tmp C:\Users\Seven01\AppData\Local\Temp\CabBACB.tmp C:\Users\Seven01\AppData\Local\Temp\TarBACC.tmp C:\Users\Seven01\AppData\Local\Temp\CabBBA8.tmp C:\Users\Seven01\AppData\Local\Temp\TarBBA9.tmp C:\Users\Seven01\AppData\Local\Temp\CabBF44.tmp C:\Users\Seven01\AppData\Local\Temp\TarBF45.tmp C:\Users\Seven01\AppData\Local\Temp\CabC2D0.tmp C:\Users\Seven01\AppData\Local\Temp\TarC2D1.tmp C:\Users\Seven01\AppData\Local\Temp\CabC320.tmp C:\Users\Seven01\AppData\Local\Temp\TarC321.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5B2.tmp C:\Users\Seven01\AppData\Local\Temp\TarC5B3.tmp C:\Users\Seven01\AppData\Local\Temp\CabC6AE.tmp C:\Users\Seven01\AppData\Local\Temp\TarC6AF.tmp C:\Users\Seven01\AppData\Local\Temp\CabC895.tmp C:\Users\Seven01\AppData\Local\Temp\TarC896.tmp C:\Users\Seven01\AppData\Local\Temp\CabCE82.tmp C:\Users\Seven01\AppData\Local\Temp\TarCE83.tmp C:\Users\Seven01\AppData\Local\Temp\CabCEA4.tmp C:\Users\Seven01\AppData\Local\Temp\TarCEA5.tmp C:\Users\Seven01\AppData\Local\Temp\CabD230.tmp C:\Users\Seven01\AppData\Local\Temp\TarD231.tmp C:\Users\Seven01\AppData\Local\Temp\CabD57E.tmp C:\Users\Seven01\AppData\Local\Temp\TarD57F.tmp C:\Users\Seven01\AppData\Local\Temp\CabD65A.tmp C:\Users\Seven01\AppData\Local\Temp\TarD65B.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA54.tmp C:\Users\Seven01\AppData\Local\Temp\TarDA55.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDB1.tmp C:\Users\Seven01\AppData\Local\Temp\TarDDB2.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F0.tmp C:\Users\Seven01\AppData\Local\Temp\TarE0F1.tmp C:\Users\Seven01\AppData\Local\Temp\CabE622.tmp C:\Users\Seven01\AppData\Local\Temp\TarE623.tmp C:\Users\Seven01\AppData\Local\Temp\CabE624.tmp C:\Users\Seven01\AppData\Local\Temp\TarE625.tmp C:\Users\Seven01\AppData\Local\Temp\CabEA1D.tmp C:\Users\Seven01\AppData\Local\Temp\TarEA1E.tmp C:\Users\Seven01\AppData\Local\Temp\CabEB19.tmp C:\Users\Seven01\AppData\Local\Temp\TarEB1A.tmp C:\Users\Seven01\AppData\Local\Temp\CabF00D.tmp C:\Users\Seven01\AppData\Local\Temp\TarF00E.tmp C:\Users\Seven01\AppData\Local\Temp\CabF186.tmp C:\Users\Seven01\AppData\Local\Temp\TarF187.tmp C:\Users\Seven01\AppData\Local\Temp\CabF234.tmp C:\Users\Seven01\AppData\Local\Temp\TarF235.tmp C:\Users\Seven01\AppData\Local\Temp\CabF294.tmp C:\Users\Seven01\AppData\Local\Temp\TarF2A4.tmp C:\Users\Seven01\AppData\Local\Temp\CabF620.tmp C:\Users\Seven01\AppData\Local\Temp\TarF621.tmp C:\Users\Seven01\AppData\Local\Temp\CabF806.tmp C:\Users\Seven01\AppData\Local\Temp\TarF807.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA0C.tmp C:\Users\Seven01\AppData\Local\Temp\TarFA0D.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA1D.tmp C:\Users\Seven01\AppData\Local\Temp\TarFA1E.tmp C:\Users\Seven01\AppData\Local\Temp\CabFACB.tmp C:\Users\Seven01\AppData\Local\Temp\TarFACC.tmp C:\Users\Seven01\AppData\Local\Temp\CabFADD.tmp C:\Users\Seven01\AppData\Local\Temp\TarFADE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1F4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2B1.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2B2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D0.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D1.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6BE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6BF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6FF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar700.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA8.tmp C:\Users\Seven01\AppData\Local\Temp\TarDA9.tmp C:\Users\Seven01\AppData\Local\Temp\CabE94.tmp C:\Users\Seven01\AppData\Local\Temp\TarE95.tmp C:\Users\Seven01\AppData\Local\Temp\Cab11C3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar11C4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1213.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1214.tmp C:\Users\Seven01\AppData\Local\Temp\Cab137C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar137D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab13FB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar13FC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab165F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1660.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1835.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1836.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1A5A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1A5B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1BD3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1BD4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F40.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1F41.tmp C:\Users\Seven01\AppData\Local\Temp\Cab203C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar203D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2232.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2233.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2263.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2264.tmp C:\Users\Seven01\AppData\Local\Temp\Cab237E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar237F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab245B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar245C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab27A9.tmp C:\Users\Seven01\AppData\Local\Temp\Tar27AA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab28C4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar28C5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab29FF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2A00.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2ADB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2ADC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31E2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar31E3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31F4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar31F5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3467.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3468.tmp C:\Users\Seven01\AppData\Local\Temp\Cab36AB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar36AC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3DA2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3DA3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3E21.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3E22.tmp C:\Users\Seven01\AppData\Local\Temp\Cab417F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar4180.tmp C:\Users\Seven01\AppData\Local\Temp\Cab41FE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar41FF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar456C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar456E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4649.tmp C:\Users\Seven01\AppData\Local\Temp\Tar464A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab46F7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar46F8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab494B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar495C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4A28.tmp C:\Users\Seven01\AppData\Local\Temp\Tar4A29.tmp C:\Users\Seven01\AppData\Local\Temp\Cab516D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar516E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab518E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar518F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab523C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar523D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab52FA.tmp C:\Users\Seven01\AppData\Local\Temp\Tar52FB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab552E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar552F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab55EC.tmp C:\Users\Seven01\AppData\Local\Temp\Tar55ED.tmp C:\Users\Seven01\AppData\Local\Temp\Cab59E5.tmp C:\Users\Seven01\AppData\Local\Temp\Tar59E6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5A93.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5A94.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar615D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar615F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab622B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar622C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab629A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar629B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6991.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6992.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6A5E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6A5F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DBC.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6DBD.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6DDE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6ED9.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6EDA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7062.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7063.tmp C:\Users\Seven01\AppData\Local\Temp\Cab719C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar719D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab72E6.tmp C:\Users\Seven01\AppData\Local\Temp\Tar72E7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7598.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7599.tmp C:\Users\Seven01\AppData\Local\Temp\Cab781A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar781B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79D2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar79D3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7C93.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7C94.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7DDE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7DE0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7F29.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7F2A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab814E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar814F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab820C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar821C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8394.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8395.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8636.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8637.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8907.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8908.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8ACE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8ACF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8CE3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8CE4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8E6C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8E6D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab91AA.tmp C:\Users\Seven01\AppData\Local\Temp\Tar91AB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9248.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9249.tmp C:\Users\Seven01\AppData\Local\Temp\Cab924A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar924B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95D7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar95D8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9694.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9741.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9A40.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9A50.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9B2C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9B2D.tmp C:\Users\Seven01\AppData\Local\Temp\CabA223.tmp C:\Users\Seven01\AppData\Local\Temp\TarA224.tmp C:\Users\Seven01\AppData\Local\Temp\CabA225.tmp C:\Users\Seven01\AppData\Local\Temp\TarA226.tmp C:\Users\Seven01\AppData\Local\Temp\CabA2F2.tmp C:\Users\Seven01\AppData\Local\Temp\TarA2F3.tmp C:\Users\Seven01\AppData\Local\Temp\CabA323.tmp C:\Users\Seven01\AppData\Local\Temp\TarA324.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE3.tmp C:\Users\Seven01\AppData\Local\Temp\TarADE4.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE5.tmp C:\Users\Seven01\AppData\Local\Temp\TarADE6.tmp C:\Users\Seven01\AppData\Local\Temp\CabAEA3.tmp C:\Users\Seven01\AppData\Local\Temp\TarAEA4.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF12.tmp C:\Users\Seven01\AppData\Local\Temp\TarAF13.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9A3.tmp C:\Users\Seven01\AppData\Local\Temp\TarB9A4.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9B5.tmp C:\Users\Seven01\AppData\Local\Temp\TarB9B6.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA34.tmp C:\Users\Seven01\AppData\Local\Temp\TarBA35.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA65.tmp C:\Users\Seven01\AppData\Local\Temp\TarBA66.tmp C:\Users\Seven01\AppData\Local\Temp\CabBD84.tmp C:\Users\Seven01\AppData\Local\Temp\TarBD85.tmp C:\Users\Seven01\AppData\Local\Temp\CabBDE3.tmp C:\Users\Seven01\AppData\Local\Temp\TarBDE4.tmp C:\Users\Seven01\AppData\Local\Temp\CabC567.tmp C:\Users\Seven01\AppData\Local\Temp\TarC568.tmp C:\Users\Seven01\AppData\Local\Temp\CabC569.tmp C:\Users\Seven01\AppData\Local\Temp\TarC56A.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5E8.tmp C:\Users\Seven01\AppData\Local\Temp\TarC5F9.tmp C:\Users\Seven01\AppData\Local\Temp\CabC619.tmp C:\Users\Seven01\AppData\Local\Temp\TarC61A.tmp C:\Users\Seven01\AppData\Local\Temp\CabC957.tmp C:\Users\Seven01\AppData\Local\Temp\TarC958.tmp C:\Users\Seven01\AppData\Local\Temp\CabC9B7.tmp C:\Users\Seven01\AppData\Local\Temp\TarC9B8.tmp C:\Users\Seven01\AppData\Local\Temp\CabCD34.tmp C:\Users\Seven01\AppData\Local\Temp\TarCD44.tmp C:\Users\Seven01\AppData\Local\Temp\CabCDB3.tmp C:\Users\Seven01\AppData\Local\Temp\TarCDB4.tmp C:\Users\Seven01\AppData\Local\Temp\CabD120.tmp C:\Users\Seven01\AppData\Local\Temp\TarD130.tmp C:\Users\Seven01\AppData\Local\Temp\CabD131.tmp C:\Users\Seven01\AppData\Local\Temp\TarD132.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1B0.tmp C:\Users\Seven01\AppData\Local\Temp\TarD1B1.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1D1.tmp C:\Users\Seven01\AppData\Local\Temp\TarD1D2.tmp C:\Users\Seven01\AppData\Local\Temp\CabD510.tmp C:\Users\Seven01\AppData\Local\Temp\TarD511.tmp C:\Users\Seven01\AppData\Local\Temp\CabD56F.tmp C:\Users\Seven01\AppData\Local\Temp\TarD570.tmp C:\Users\Seven01\AppData\Local\Temp\CabD90B.tmp C:\Users\Seven01\AppData\Local\Temp\TarD90C.tmp C:\Users\Seven01\AppData\Local\Temp\CabD97B.tmp C:\Users\Seven01\AppData\Local\Temp\TarD97C.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF7.tmp C:\Users\Seven01\AppData\Local\Temp\TarDCF8.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF9.tmp C:\Users\Seven01\AppData\Local\Temp\TarDCFA.tmp C:\Users\Seven01\AppData\Local\Temp\CabDD78.tmp C:\Users\Seven01\AppData\Local\Temp\TarDD79.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDA9.tmp C:\Users\Seven01\AppData\Local\Temp\TarDDAA.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F7.tmp C:\Users\Seven01\AppData\Local\Temp\TarE0F8.tmp C:\Users\Seven01\AppData\Local\Temp\CabE176.tmp C:\Users\Seven01\AppData\Local\Temp\TarE177.tmp C:\Users\Seven01\AppData\Local\Temp\CabE4D3.tmp C:\Users\Seven01\AppData\Local\Temp\TarE4D4.tmp C:\Users\Seven01\AppData\Local\Temp\CabE533.tmp C:\Users\Seven01\AppData\Local\Temp\TarE534.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8C0.tmp C:\Users\Seven01\AppData\Local\Temp\TarE8C1.tmp C:\Users\Seven01\AppData\Local\Temp\TarE8D2.tmp C:\Users\Seven01\AppData\Local\Temp\CabE98E.tmp C:\Users\Seven01\AppData\Local\Temp\TarE98F.tmp C:\Users\Seven01\AppData\Local\Temp\CabE9BF.tmp C:\Users\Seven01\AppData\Local\Temp\TarE9C0.tmp C:\Users\Seven01\AppData\Local\Temp\CabECAF.tmp C:\Users\Seven01\AppData\Local\Temp\TarECB0.tmp C:\Users\Seven01\AppData\Local\Temp\CabED0F.tmp C:\Users\Seven01\AppData\Local\Temp\TarED10.tmp C:\Users\Seven01\AppData\Local\Temp\CabF09B.tmp C:\Users\Seven01\AppData\Local\Temp\TarF09C.tmp C:\Users\Seven01\AppData\Local\Temp\CabF485.tmp C:\Users\Seven01\AppData\Local\Temp\TarF486.tmp C:\Windows\sysnative\wbem\WmiPrvSE.exe \??\PIPE\samr C:\Windows\sysnative\wbem\repository C:\Windows\sysnative\wbem\Logs C:\Windows\sysnative\wbem\AutoRecover C:\Windows\sysnative\wbem\MOF C:\Windows\sysnative\wbem\repository\INDEX.BTR C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER C:\Windows\Globalization\Sorting\sortdefault.nls \??\WMIDataDevice
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\alex.exe.config C:\Users\Seven01\AppData\Local\Temp\alex.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll \Device\KsecDD C:\Windows\System32\l_intl.nls C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\System32\wbem\wbemdisp.tlb C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll C:\Windows\SysWOW64\stdole2.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\System32\tzres.dll C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 C:\Users\Seven01\AppData\Local\Temp\Cab5D4D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D4E.tmp C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll C:\Users\Seven01\AppData\Local\Temp\Cab5E98.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5E99.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5F36.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5F37.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6032.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6033.tmp C:\Users\Seven01\AppData\Local\Temp\Cab610F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6110.tmp C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx C:\Windows\SysWOW64\wshom.ocx C:\Users\Seven01\AppData\Local\Temp\Cab6566.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6567.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6578.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6579.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6645.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6646.tmp C:\Users\Seven01\AppData\Local\Temp\Cab66B4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar66B5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6743.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6744.tmp C:\Users\Seven01\AppData\Local\Temp\Cab67E1.tmp C:\Users\Seven01\AppData\Local\Temp\Tar67E2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D61.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6D62.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D73.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6D74.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6E50.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6E51.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6EBF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6EC0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7597.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7598.tmp C:\Users\Seven01\AppData\Local\Temp\Cab76A3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar76A4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7916.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7917.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7918.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7919.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79E5.tmp C:\Users\Seven01\AppData\Local\Temp\Tar79E6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7A35.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7A36.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84D6.tmp C:\Users\Seven01\AppData\Local\Temp\Tar84D7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84E7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar84E8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8585.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8586.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8624.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8625.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar920E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar921F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab92EB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar92EC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab931C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar931D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95FD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar95FE.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1B7.tmp C:\Users\Seven01\AppData\Local\Temp\TarA1B8.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1C8.tmp C:\Users\Seven01\AppData\Local\Temp\TarA1C9.tmp C:\Users\Seven01\AppData\Local\Temp\CabA266.tmp C:\Users\Seven01\AppData\Local\Temp\TarA267.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6DD.tmp C:\Users\Seven01\AppData\Local\Temp\TarA6DE.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6EF.tmp C:\Users\Seven01\AppData\Local\Temp\TarA6F0.tmp C:\Users\Seven01\AppData\Local\Temp\CabA887.tmp C:\Users\Seven01\AppData\Local\Temp\TarA888.tmp C:\Users\Seven01\AppData\Local\Temp\CabA944.tmp C:\Users\Seven01\AppData\Local\Temp\TarA945.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF03.tmp C:\Users\Seven01\AppData\Local\Temp\TarAF04.tmp C:\Users\Seven01\AppData\Local\Temp\CabAFA1.tmp C:\Users\Seven01\AppData\Local\Temp\TarAFA2.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2C0.tmp C:\Users\Seven01\AppData\Local\Temp\TarB2C1.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2D2.tmp C:\Users\Seven01\AppData\Local\Temp\TarB2D3.tmp C:\Users\Seven01\AppData\Local\Temp\CabB3BE.tmp C:\Users\Seven01\AppData\Local\Temp\TarB3BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabB46C.tmp C:\Users\Seven01\AppData\Local\Temp\TarB46D.tmp C:\Users\Seven01\AppData\Local\Temp\CabB6FE.tmp C:\Users\Seven01\AppData\Local\Temp\TarB6FF.tmp C:\Users\Seven01\AppData\Local\Temp\CabB80A.tmp C:\Users\Seven01\AppData\Local\Temp\TarB80B.tmp C:\Users\Seven01\AppData\Local\Temp\CabBACB.tmp C:\Users\Seven01\AppData\Local\Temp\TarBACC.tmp C:\Users\Seven01\AppData\Local\Temp\CabBBA8.tmp C:\Users\Seven01\AppData\Local\Temp\TarBBA9.tmp C:\Users\Seven01\AppData\Local\Temp\CabBF44.tmp C:\Users\Seven01\AppData\Local\Temp\TarBF45.tmp C:\Users\Seven01\AppData\Local\Temp\CabC2D0.tmp C:\Users\Seven01\AppData\Local\Temp\TarC2D1.tmp C:\Users\Seven01\AppData\Local\Temp\CabC320.tmp C:\Users\Seven01\AppData\Local\Temp\TarC321.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5B2.tmp C:\Users\Seven01\AppData\Local\Temp\TarC5B3.tmp C:\Users\Seven01\AppData\Local\Temp\CabC6AE.tmp C:\Users\Seven01\AppData\Local\Temp\TarC6AF.tmp C:\Users\Seven01\AppData\Local\Temp\CabC895.tmp C:\Users\Seven01\AppData\Local\Temp\TarC896.tmp C:\Users\Seven01\AppData\Local\Temp\CabCE82.tmp C:\Users\Seven01\AppData\Local\Temp\TarCE83.tmp C:\Users\Seven01\AppData\Local\Temp\CabCEA4.tmp C:\Users\Seven01\AppData\Local\Temp\TarCEA5.tmp C:\Users\Seven01\AppData\Local\Temp\CabD230.tmp C:\Users\Seven01\AppData\Local\Temp\TarD231.tmp C:\Users\Seven01\AppData\Local\Temp\CabD57E.tmp C:\Users\Seven01\AppData\Local\Temp\TarD57F.tmp C:\Users\Seven01\AppData\Local\Temp\CabD65A.tmp C:\Users\Seven01\AppData\Local\Temp\TarD65B.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA54.tmp C:\Users\Seven01\AppData\Local\Temp\TarDA55.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDB1.tmp C:\Users\Seven01\AppData\Local\Temp\TarDDB2.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F0.tmp C:\Users\Seven01\AppData\Local\Temp\TarE0F1.tmp C:\Users\Seven01\AppData\Local\Temp\CabE622.tmp C:\Users\Seven01\AppData\Local\Temp\TarE623.tmp C:\Users\Seven01\AppData\Local\Temp\CabE624.tmp C:\Users\Seven01\AppData\Local\Temp\TarE625.tmp C:\Users\Seven01\AppData\Local\Temp\CabEA1D.tmp C:\Users\Seven01\AppData\Local\Temp\TarEA1E.tmp C:\Users\Seven01\AppData\Local\Temp\CabEB19.tmp C:\Users\Seven01\AppData\Local\Temp\TarEB1A.tmp C:\Users\Seven01\AppData\Local\Temp\CabF00D.tmp C:\Users\Seven01\AppData\Local\Temp\TarF00E.tmp C:\Users\Seven01\AppData\Local\Temp\CabF186.tmp C:\Users\Seven01\AppData\Local\Temp\TarF187.tmp C:\Users\Seven01\AppData\Local\Temp\CabF234.tmp C:\Users\Seven01\AppData\Local\Temp\TarF235.tmp C:\Users\Seven01\AppData\Local\Temp\CabF294.tmp C:\Users\Seven01\AppData\Local\Temp\TarF2A4.tmp C:\Users\Seven01\AppData\Local\Temp\CabF620.tmp C:\Users\Seven01\AppData\Local\Temp\TarF621.tmp C:\Users\Seven01\AppData\Local\Temp\CabF806.tmp C:\Users\Seven01\AppData\Local\Temp\TarF807.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA0C.tmp C:\Users\Seven01\AppData\Local\Temp\TarFA0D.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA1D.tmp C:\Users\Seven01\AppData\Local\Temp\TarFA1E.tmp C:\Users\Seven01\AppData\Local\Temp\CabFACB.tmp C:\Users\Seven01\AppData\Local\Temp\TarFACC.tmp C:\Users\Seven01\AppData\Local\Temp\CabFADD.tmp C:\Users\Seven01\AppData\Local\Temp\TarFADE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1F4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2B1.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2B2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D0.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D1.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6BE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6BF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6FF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar700.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA8.tmp C:\Users\Seven01\AppData\Local\Temp\TarDA9.tmp C:\Users\Seven01\AppData\Local\Temp\CabE94.tmp C:\Users\Seven01\AppData\Local\Temp\TarE95.tmp C:\Users\Seven01\AppData\Local\Temp\Cab11C3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar11C4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1213.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1214.tmp C:\Users\Seven01\AppData\Local\Temp\Cab137C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar137D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab13FB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar13FC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab165F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1660.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1835.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1836.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1A5A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1A5B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1BD3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1BD4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F40.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1F41.tmp C:\Users\Seven01\AppData\Local\Temp\Cab203C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar203D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2232.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2233.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2263.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2264.tmp C:\Users\Seven01\AppData\Local\Temp\Cab237E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar237F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab245B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar245C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab27A9.tmp C:\Users\Seven01\AppData\Local\Temp\Tar27AA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab28C4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar28C5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab29FF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2A00.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2ADB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2ADC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31E2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar31E3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31F4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar31F5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3467.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3468.tmp C:\Users\Seven01\AppData\Local\Temp\Cab36AB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar36AC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3DA2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3DA3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3E21.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3E22.tmp C:\Users\Seven01\AppData\Local\Temp\Cab417F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar4180.tmp C:\Users\Seven01\AppData\Local\Temp\Cab41FE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar41FF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar456C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar456E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4649.tmp C:\Users\Seven01\AppData\Local\Temp\Tar464A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab46F7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar46F8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab494B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar495C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4A28.tmp C:\Users\Seven01\AppData\Local\Temp\Tar4A29.tmp C:\Users\Seven01\AppData\Local\Temp\Cab516D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar516E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab518E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar518F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab523C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar523D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab52FA.tmp C:\Users\Seven01\AppData\Local\Temp\Tar52FB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab552E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar552F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab55EC.tmp C:\Users\Seven01\AppData\Local\Temp\Tar55ED.tmp C:\Users\Seven01\AppData\Local\Temp\Cab59E5.tmp C:\Users\Seven01\AppData\Local\Temp\Tar59E6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5A93.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5A94.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar615D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar615F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab622B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar622C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab629A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar629B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6991.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6992.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6A5E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6A5F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DBC.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6DBD.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6DDE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6ED9.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6EDA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7062.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7063.tmp C:\Users\Seven01\AppData\Local\Temp\Cab719C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar719D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab72E6.tmp C:\Users\Seven01\AppData\Local\Temp\Tar72E7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7598.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7599.tmp C:\Users\Seven01\AppData\Local\Temp\Cab781A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar781B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79D2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar79D3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7C93.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7C94.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7DDE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7DE0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7F29.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7F2A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab814E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar814F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab820C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar821C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8394.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8395.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8636.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8637.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8907.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8908.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8ACE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8ACF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8CE3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8CE4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8E6C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8E6D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab91AA.tmp C:\Users\Seven01\AppData\Local\Temp\Tar91AB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9248.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9249.tmp C:\Users\Seven01\AppData\Local\Temp\Cab924A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar924B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95D7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar95D8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9694.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9741.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9A40.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9A50.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9B2C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9B2D.tmp C:\Users\Seven01\AppData\Local\Temp\CabA223.tmp C:\Users\Seven01\AppData\Local\Temp\TarA224.tmp C:\Users\Seven01\AppData\Local\Temp\CabA225.tmp C:\Users\Seven01\AppData\Local\Temp\TarA226.tmp C:\Users\Seven01\AppData\Local\Temp\CabA2F2.tmp C:\Users\Seven01\AppData\Local\Temp\TarA2F3.tmp C:\Users\Seven01\AppData\Local\Temp\CabA323.tmp C:\Users\Seven01\AppData\Local\Temp\TarA324.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE3.tmp C:\Users\Seven01\AppData\Local\Temp\TarADE4.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE5.tmp C:\Users\Seven01\AppData\Local\Temp\TarADE6.tmp C:\Users\Seven01\AppData\Local\Temp\CabAEA3.tmp C:\Users\Seven01\AppData\Local\Temp\TarAEA4.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF12.tmp C:\Users\Seven01\AppData\Local\Temp\TarAF13.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9A3.tmp C:\Users\Seven01\AppData\Local\Temp\TarB9A4.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9B5.tmp C:\Users\Seven01\AppData\Local\Temp\TarB9B6.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA34.tmp C:\Users\Seven01\AppData\Local\Temp\TarBA35.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA65.tmp C:\Users\Seven01\AppData\Local\Temp\TarBA66.tmp C:\Users\Seven01\AppData\Local\Temp\CabBD84.tmp C:\Users\Seven01\AppData\Local\Temp\TarBD85.tmp C:\Users\Seven01\AppData\Local\Temp\CabBDE3.tmp C:\Users\Seven01\AppData\Local\Temp\TarBDE4.tmp C:\Users\Seven01\AppData\Local\Temp\CabC567.tmp C:\Users\Seven01\AppData\Local\Temp\TarC568.tmp C:\Users\Seven01\AppData\Local\Temp\CabC569.tmp C:\Users\Seven01\AppData\Local\Temp\TarC56A.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5E8.tmp C:\Users\Seven01\AppData\Local\Temp\TarC5F9.tmp C:\Users\Seven01\AppData\Local\Temp\CabC619.tmp C:\Users\Seven01\AppData\Local\Temp\TarC61A.tmp C:\Users\Seven01\AppData\Local\Temp\CabC957.tmp C:\Users\Seven01\AppData\Local\Temp\TarC958.tmp C:\Users\Seven01\AppData\Local\Temp\CabC9B7.tmp C:\Users\Seven01\AppData\Local\Temp\TarC9B8.tmp C:\Users\Seven01\AppData\Local\Temp\CabCD34.tmp C:\Users\Seven01\AppData\Local\Temp\TarCD44.tmp C:\Users\Seven01\AppData\Local\Temp\CabCDB3.tmp C:\Users\Seven01\AppData\Local\Temp\TarCDB4.tmp C:\Users\Seven01\AppData\Local\Temp\CabD120.tmp C:\Users\Seven01\AppData\Local\Temp\TarD130.tmp C:\Users\Seven01\AppData\Local\Temp\CabD131.tmp C:\Users\Seven01\AppData\Local\Temp\TarD132.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1B0.tmp C:\Users\Seven01\AppData\Local\Temp\TarD1B1.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1D1.tmp C:\Users\Seven01\AppData\Local\Temp\TarD1D2.tmp C:\Users\Seven01\AppData\Local\Temp\CabD510.tmp C:\Users\Seven01\AppData\Local\Temp\TarD511.tmp C:\Users\Seven01\AppData\Local\Temp\CabD56F.tmp C:\Users\Seven01\AppData\Local\Temp\TarD570.tmp C:\Users\Seven01\AppData\Local\Temp\CabD90B.tmp C:\Users\Seven01\AppData\Local\Temp\TarD90C.tmp C:\Users\Seven01\AppData\Local\Temp\CabD97B.tmp C:\Users\Seven01\AppData\Local\Temp\TarD97C.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF7.tmp C:\Users\Seven01\AppData\Local\Temp\TarDCF8.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF9.tmp C:\Users\Seven01\AppData\Local\Temp\TarDCFA.tmp C:\Users\Seven01\AppData\Local\Temp\CabDD78.tmp C:\Users\Seven01\AppData\Local\Temp\TarDD79.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDA9.tmp C:\Users\Seven01\AppData\Local\Temp\TarDDAA.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F7.tmp C:\Users\Seven01\AppData\Local\Temp\TarE0F8.tmp C:\Users\Seven01\AppData\Local\Temp\CabE176.tmp C:\Users\Seven01\AppData\Local\Temp\TarE177.tmp C:\Users\Seven01\AppData\Local\Temp\CabE4D3.tmp C:\Users\Seven01\AppData\Local\Temp\TarE4D4.tmp C:\Users\Seven01\AppData\Local\Temp\CabE533.tmp C:\Users\Seven01\AppData\Local\Temp\TarE534.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8C0.tmp C:\Users\Seven01\AppData\Local\Temp\TarE8C1.tmp C:\Users\Seven01\AppData\Local\Temp\TarE8D2.tmp C:\Users\Seven01\AppData\Local\Temp\CabE98E.tmp C:\Users\Seven01\AppData\Local\Temp\TarE98F.tmp C:\Users\Seven01\AppData\Local\Temp\CabE9BF.tmp C:\Users\Seven01\AppData\Local\Temp\TarE9C0.tmp C:\Users\Seven01\AppData\Local\Temp\CabECAF.tmp C:\Users\Seven01\AppData\Local\Temp\TarECB0.tmp C:\Users\Seven01\AppData\Local\Temp\CabED0F.tmp C:\Users\Seven01\AppData\Local\Temp\TarED10.tmp C:\Users\Seven01\AppData\Local\Temp\CabF09B.tmp C:\Users\Seven01\AppData\Local\Temp\TarF09C.tmp C:\Users\Seven01\AppData\Local\Temp\CabF485.tmp C:\Users\Seven01\AppData\Local\Temp\TarF486.tmp C:\Windows\sysnative\wbem\WmiPrvSE.exe \??\PIPE\samr C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER C:\Windows\Globalization\Sorting\sortdefault.nls \??\WMIDataDevice
Write Files
C:\Users\Seven01\AppData\Roaming\International Business Machines Corp\International Business Machines Corp.exe C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 C:\Users\Seven01\AppData\Local\Temp\Cab5D4D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5E98.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5F36.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6032.tmp C:\Users\Seven01\AppData\Local\Temp\Cab610F.tmp C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Users\Seven01\AppData\Local\Temp\Cab6566.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6578.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6645.tmp C:\Users\Seven01\AppData\Local\Temp\Cab66B4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6743.tmp C:\Users\Seven01\AppData\Local\Temp\Cab67E1.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D61.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D73.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6E50.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6EBF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7597.tmp C:\Users\Seven01\AppData\Local\Temp\Cab76A3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7916.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7918.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79E5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7A35.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84D6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84E7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8585.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8624.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab92EB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab931C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95FD.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1B7.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1C8.tmp C:\Users\Seven01\AppData\Local\Temp\CabA266.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6DD.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6EF.tmp C:\Users\Seven01\AppData\Local\Temp\CabA887.tmp C:\Users\Seven01\AppData\Local\Temp\CabA944.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF03.tmp C:\Users\Seven01\AppData\Local\Temp\CabAFA1.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2C0.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2D2.tmp C:\Users\Seven01\AppData\Local\Temp\CabB3BE.tmp C:\Users\Seven01\AppData\Local\Temp\CabB46C.tmp C:\Users\Seven01\AppData\Local\Temp\CabB6FE.tmp C:\Users\Seven01\AppData\Local\Temp\CabB80A.tmp C:\Users\Seven01\AppData\Local\Temp\CabBACB.tmp C:\Users\Seven01\AppData\Local\Temp\CabBBA8.tmp C:\Users\Seven01\AppData\Local\Temp\CabBF44.tmp C:\Users\Seven01\AppData\Local\Temp\CabC2D0.tmp C:\Users\Seven01\AppData\Local\Temp\CabC320.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5B2.tmp C:\Users\Seven01\AppData\Local\Temp\CabC6AE.tmp C:\Users\Seven01\AppData\Local\Temp\CabC895.tmp C:\Users\Seven01\AppData\Local\Temp\CabCE82.tmp C:\Users\Seven01\AppData\Local\Temp\CabCEA4.tmp C:\Users\Seven01\AppData\Local\Temp\CabD230.tmp C:\Users\Seven01\AppData\Local\Temp\CabD57E.tmp C:\Users\Seven01\AppData\Local\Temp\CabD65A.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA54.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDB1.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F0.tmp C:\Users\Seven01\AppData\Local\Temp\CabE622.tmp C:\Users\Seven01\AppData\Local\Temp\CabE624.tmp C:\Users\Seven01\AppData\Local\Temp\CabEA1D.tmp C:\Users\Seven01\AppData\Local\Temp\CabEB19.tmp C:\Users\Seven01\AppData\Local\Temp\CabF00D.tmp C:\Users\Seven01\AppData\Local\Temp\CabF186.tmp C:\Users\Seven01\AppData\Local\Temp\CabF234.tmp C:\Users\Seven01\AppData\Local\Temp\CabF294.tmp C:\Users\Seven01\AppData\Local\Temp\CabF620.tmp C:\Users\Seven01\AppData\Local\Temp\CabF806.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA0C.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA1D.tmp C:\Users\Seven01\AppData\Local\Temp\CabFACB.tmp C:\Users\Seven01\AppData\Local\Temp\CabFADD.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2B1.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6BE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6FF.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA8.tmp C:\Users\Seven01\AppData\Local\Temp\CabE94.tmp C:\Users\Seven01\AppData\Local\Temp\Cab11C3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1213.tmp C:\Users\Seven01\AppData\Local\Temp\Cab137C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab13FB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab165F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1835.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1A5A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1BD3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F40.tmp C:\Users\Seven01\AppData\Local\Temp\Cab203C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2232.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2263.tmp C:\Users\Seven01\AppData\Local\Temp\Cab237E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab245B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab27A9.tmp C:\Users\Seven01\AppData\Local\Temp\Cab28C4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab29FF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2ADB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31E2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31F4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3467.tmp C:\Users\Seven01\AppData\Local\Temp\Cab36AB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3DA2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3E21.tmp C:\Users\Seven01\AppData\Local\Temp\Cab417F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab41FE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4649.tmp C:\Users\Seven01\AppData\Local\Temp\Cab46F7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab494B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4A28.tmp C:\Users\Seven01\AppData\Local\Temp\Cab516D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab518E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab523C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab52FA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab552E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab55EC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab59E5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5A93.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab622B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab629A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6991.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6A5E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DBC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6ED9.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7062.tmp C:\Users\Seven01\AppData\Local\Temp\Cab719C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab72E6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7598.tmp C:\Users\Seven01\AppData\Local\Temp\Cab781A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79D2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7C93.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7F29.tmp C:\Users\Seven01\AppData\Local\Temp\Cab814E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab820C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8394.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8636.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8907.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8ACE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8CE3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8E6C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab91AA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9248.tmp C:\Users\Seven01\AppData\Local\Temp\Cab924A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95D7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9694.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9A40.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9B2C.tmp C:\Users\Seven01\AppData\Local\Temp\CabA223.tmp C:\Users\Seven01\AppData\Local\Temp\CabA225.tmp C:\Users\Seven01\AppData\Local\Temp\CabA2F2.tmp C:\Users\Seven01\AppData\Local\Temp\CabA323.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE3.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE5.tmp C:\Users\Seven01\AppData\Local\Temp\CabAEA3.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF12.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9A3.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9B5.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA34.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA65.tmp C:\Users\Seven01\AppData\Local\Temp\CabBD84.tmp C:\Users\Seven01\AppData\Local\Temp\CabBDE3.tmp C:\Users\Seven01\AppData\Local\Temp\CabC567.tmp C:\Users\Seven01\AppData\Local\Temp\CabC569.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5E8.tmp C:\Users\Seven01\AppData\Local\Temp\CabC619.tmp C:\Users\Seven01\AppData\Local\Temp\CabC957.tmp C:\Users\Seven01\AppData\Local\Temp\CabC9B7.tmp C:\Users\Seven01\AppData\Local\Temp\CabCD34.tmp C:\Users\Seven01\AppData\Local\Temp\CabCDB3.tmp C:\Users\Seven01\AppData\Local\Temp\CabD120.tmp C:\Users\Seven01\AppData\Local\Temp\CabD131.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1B0.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1D1.tmp C:\Users\Seven01\AppData\Local\Temp\CabD510.tmp C:\Users\Seven01\AppData\Local\Temp\CabD56F.tmp C:\Users\Seven01\AppData\Local\Temp\CabD90B.tmp C:\Users\Seven01\AppData\Local\Temp\CabD97B.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF7.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF9.tmp C:\Users\Seven01\AppData\Local\Temp\CabDD78.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDA9.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F7.tmp C:\Users\Seven01\AppData\Local\Temp\CabE176.tmp C:\Users\Seven01\AppData\Local\Temp\CabE4D3.tmp C:\Users\Seven01\AppData\Local\Temp\CabE533.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8C0.tmp C:\Users\Seven01\AppData\Local\Temp\CabE98E.tmp C:\Users\Seven01\AppData\Local\Temp\CabE9BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabECAF.tmp C:\Users\Seven01\AppData\Local\Temp\CabED0F.tmp C:\Users\Seven01\AppData\Local\Temp\CabF09B.tmp C:\Users\Seven01\AppData\Local\Temp\CabF485.tmp \??\PIPE\samr C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\WMIDataDevice
Delete Files
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2520.15649781 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2520.15649781 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2520.15649843 C:\Users\Seven01\AppData\Local\Temp\Cab5D4D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D4E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5E98.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5E99.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5F36.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5F37.tmp C:\Users\Seven01\AppData\Roaming\International Business Machines Corp\International Business Machines Corp.exe:Zone.Identifier C:\Users\Seven01\AppData\Local\Temp\Cab6032.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6033.tmp C:\Users\Seven01\AppData\Local\Temp\Cab610F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6110.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6566.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6567.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6578.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6579.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6645.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6646.tmp C:\Users\Seven01\AppData\Local\Temp\Cab66B4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar66B5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6743.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6744.tmp C:\Users\Seven01\AppData\Local\Temp\Cab67E1.tmp C:\Users\Seven01\AppData\Local\Temp\Tar67E2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D61.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6D73.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6D62.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6D74.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6E50.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6E51.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6EBF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6EC0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7597.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7598.tmp C:\Users\Seven01\AppData\Local\Temp\Cab76A3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar76A4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7916.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7918.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7917.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7919.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79E5.tmp C:\Users\Seven01\AppData\Local\Temp\Tar79E6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7A35.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7A36.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84D6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab84E7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar84D7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar84E8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8585.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8586.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8624.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8625.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab920D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar921F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar920E.tmp C:\Users\Seven01\AppData\Local\Temp\Cab92EB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar92EC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab931C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar931D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95FD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar95FE.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1B7.tmp C:\Users\Seven01\AppData\Local\Temp\CabA1C8.tmp C:\Users\Seven01\AppData\Local\Temp\TarA1B8.tmp C:\Users\Seven01\AppData\Local\Temp\TarA1C9.tmp C:\Users\Seven01\AppData\Local\Temp\CabA266.tmp C:\Users\Seven01\AppData\Local\Temp\TarA267.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6DD.tmp C:\Users\Seven01\AppData\Local\Temp\CabA6EF.tmp C:\Users\Seven01\AppData\Local\Temp\TarA6DE.tmp C:\Users\Seven01\AppData\Local\Temp\TarA6F0.tmp C:\Users\Seven01\AppData\Local\Temp\CabA887.tmp C:\Users\Seven01\AppData\Local\Temp\TarA888.tmp C:\Users\Seven01\AppData\Local\Temp\CabA944.tmp C:\Users\Seven01\AppData\Local\Temp\TarA945.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF03.tmp C:\Users\Seven01\AppData\Local\Temp\TarAF04.tmp C:\Users\Seven01\AppData\Local\Temp\CabAFA1.tmp C:\Users\Seven01\AppData\Local\Temp\TarAFA2.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2C0.tmp C:\Users\Seven01\AppData\Local\Temp\CabB2D2.tmp C:\Users\Seven01\AppData\Local\Temp\TarB2C1.tmp C:\Users\Seven01\AppData\Local\Temp\TarB2D3.tmp C:\Users\Seven01\AppData\Local\Temp\CabB3BE.tmp C:\Users\Seven01\AppData\Local\Temp\TarB3BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabB46C.tmp C:\Users\Seven01\AppData\Local\Temp\TarB46D.tmp C:\Users\Seven01\AppData\Local\Temp\CabB6FE.tmp C:\Users\Seven01\AppData\Local\Temp\TarB6FF.tmp C:\Users\Seven01\AppData\Local\Temp\CabB80A.tmp C:\Users\Seven01\AppData\Local\Temp\TarB80B.tmp C:\Users\Seven01\AppData\Local\Temp\CabBACB.tmp C:\Users\Seven01\AppData\Local\Temp\TarBACC.tmp C:\Users\Seven01\AppData\Local\Temp\CabBBA8.tmp C:\Users\Seven01\AppData\Local\Temp\TarBBA9.tmp C:\Users\Seven01\AppData\Local\Temp\CabBF44.tmp C:\Users\Seven01\AppData\Local\Temp\TarBF45.tmp C:\Users\Seven01\AppData\Local\Temp\CabC2D0.tmp C:\Users\Seven01\AppData\Local\Temp\CabC320.tmp C:\Users\Seven01\AppData\Local\Temp\TarC2D1.tmp C:\Users\Seven01\AppData\Local\Temp\TarC321.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5B2.tmp C:\Users\Seven01\AppData\Local\Temp\TarC5B3.tmp C:\Users\Seven01\AppData\Local\Temp\CabC6AE.tmp C:\Users\Seven01\AppData\Local\Temp\TarC6AF.tmp C:\Users\Seven01\AppData\Local\Temp\CabC895.tmp C:\Users\Seven01\AppData\Local\Temp\TarC896.tmp C:\Users\Seven01\AppData\Local\Temp\CabCE82.tmp C:\Users\Seven01\AppData\Local\Temp\CabCEA4.tmp C:\Users\Seven01\AppData\Local\Temp\TarCE83.tmp C:\Users\Seven01\AppData\Local\Temp\TarCEA5.tmp C:\Users\Seven01\AppData\Local\Temp\CabD230.tmp C:\Users\Seven01\AppData\Local\Temp\TarD231.tmp C:\Users\Seven01\AppData\Local\Temp\CabD57E.tmp C:\Users\Seven01\AppData\Local\Temp\TarD57F.tmp C:\Users\Seven01\AppData\Local\Temp\CabD65A.tmp C:\Users\Seven01\AppData\Local\Temp\TarD65B.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA54.tmp C:\Users\Seven01\AppData\Local\Temp\TarDA55.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDB1.tmp C:\Users\Seven01\AppData\Local\Temp\TarDDB2.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F0.tmp C:\Users\Seven01\AppData\Local\Temp\TarE0F1.tmp C:\Users\Seven01\AppData\Local\Temp\CabE622.tmp C:\Users\Seven01\AppData\Local\Temp\CabE624.tmp C:\Users\Seven01\AppData\Local\Temp\TarE623.tmp C:\Users\Seven01\AppData\Local\Temp\TarE625.tmp C:\Users\Seven01\AppData\Local\Temp\CabEA1D.tmp C:\Users\Seven01\AppData\Local\Temp\TarEA1E.tmp C:\Users\Seven01\AppData\Local\Temp\CabEB19.tmp C:\Users\Seven01\AppData\Local\Temp\TarEB1A.tmp C:\Users\Seven01\AppData\Local\Temp\CabF00D.tmp C:\Users\Seven01\AppData\Local\Temp\TarF00E.tmp C:\Users\Seven01\AppData\Local\Temp\CabF186.tmp C:\Users\Seven01\AppData\Local\Temp\TarF187.tmp C:\Users\Seven01\AppData\Local\Temp\CabF234.tmp C:\Users\Seven01\AppData\Local\Temp\TarF235.tmp C:\Users\Seven01\AppData\Local\Temp\CabF294.tmp C:\Users\Seven01\AppData\Local\Temp\TarF2A4.tmp C:\Users\Seven01\AppData\Local\Temp\CabF620.tmp C:\Users\Seven01\AppData\Local\Temp\TarF621.tmp C:\Users\Seven01\AppData\Local\Temp\CabF806.tmp C:\Users\Seven01\AppData\Local\Temp\TarF807.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA0C.tmp C:\Users\Seven01\AppData\Local\Temp\CabFA1D.tmp C:\Users\Seven01\AppData\Local\Temp\TarFA0D.tmp C:\Users\Seven01\AppData\Local\Temp\TarFA1E.tmp C:\Users\Seven01\AppData\Local\Temp\CabFACB.tmp C:\Users\Seven01\AppData\Local\Temp\CabFADD.tmp C:\Users\Seven01\AppData\Local\Temp\TarFACC.tmp C:\Users\Seven01\AppData\Local\Temp\TarFADE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1F4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2B1.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2B2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5D2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D1.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5D3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6BE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6BF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6FF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar700.tmp C:\Users\Seven01\AppData\Local\Temp\CabDA8.tmp C:\Users\Seven01\AppData\Local\Temp\TarDA9.tmp C:\Users\Seven01\AppData\Local\Temp\CabE94.tmp C:\Users\Seven01\AppData\Local\Temp\TarE95.tmp C:\Users\Seven01\AppData\Local\Temp\Cab11C3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar11C4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1213.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1214.tmp C:\Users\Seven01\AppData\Local\Temp\Cab137C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar137D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab13FB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar13FC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab165F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1660.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1835.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1836.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1A5A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1A5B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1BD3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1BD4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab1F40.tmp C:\Users\Seven01\AppData\Local\Temp\Tar1F41.tmp C:\Users\Seven01\AppData\Local\Temp\Cab203C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar203D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2232.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2233.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2263.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2264.tmp C:\Users\Seven01\AppData\Local\Temp\Cab237E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar237F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab245B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar245C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab27A9.tmp C:\Users\Seven01\AppData\Local\Temp\Tar27AA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab28C4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar28C5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab29FF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2A00.tmp C:\Users\Seven01\AppData\Local\Temp\Cab2ADB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar2ADC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31E2.tmp C:\Users\Seven01\AppData\Local\Temp\Cab31F4.tmp C:\Users\Seven01\AppData\Local\Temp\Tar31E3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar31F5.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3467.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3468.tmp C:\Users\Seven01\AppData\Local\Temp\Cab36AB.tmp C:\Users\Seven01\AppData\Local\Temp\Tar36AC.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3DA2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3DA3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab3E21.tmp C:\Users\Seven01\AppData\Local\Temp\Tar3E22.tmp C:\Users\Seven01\AppData\Local\Temp\Cab417F.tmp C:\Users\Seven01\AppData\Local\Temp\Tar4180.tmp C:\Users\Seven01\AppData\Local\Temp\Cab41FE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar41FF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab456B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar456E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar456C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4649.tmp C:\Users\Seven01\AppData\Local\Temp\Tar464A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab46F7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar46F8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab494B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar495C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab4A28.tmp C:\Users\Seven01\AppData\Local\Temp\Tar4A29.tmp C:\Users\Seven01\AppData\Local\Temp\Cab516D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab518E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar516E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar518F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab523C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar523D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab52FA.tmp C:\Users\Seven01\AppData\Local\Temp\Tar52FB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab552E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar552F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab55EC.tmp C:\Users\Seven01\AppData\Local\Temp\Tar55ED.tmp C:\Users\Seven01\AppData\Local\Temp\Cab59E5.tmp C:\Users\Seven01\AppData\Local\Temp\Tar59E6.tmp C:\Users\Seven01\AppData\Local\Temp\Cab5A93.tmp C:\Users\Seven01\AppData\Local\Temp\Tar5A94.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab615E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar615D.tmp C:\Users\Seven01\AppData\Local\Temp\Tar615F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab622B.tmp C:\Users\Seven01\AppData\Local\Temp\Tar622C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab629A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar629B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6991.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6992.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6A5E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6A5F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DBC.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6DBD.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6DDE.tmp C:\Users\Seven01\AppData\Local\Temp\Cab6ED9.tmp C:\Users\Seven01\AppData\Local\Temp\Tar6EDA.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7062.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7063.tmp C:\Users\Seven01\AppData\Local\Temp\Cab719C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar719D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab72E6.tmp C:\Users\Seven01\AppData\Local\Temp\Tar72E7.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7598.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7599.tmp C:\Users\Seven01\AppData\Local\Temp\Cab781A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar781B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab79D2.tmp C:\Users\Seven01\AppData\Local\Temp\Tar79D3.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7C93.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7C94.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDD.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7DDF.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7DDE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7DE0.tmp C:\Users\Seven01\AppData\Local\Temp\Cab7F29.tmp C:\Users\Seven01\AppData\Local\Temp\Tar7F2A.tmp C:\Users\Seven01\AppData\Local\Temp\Cab814E.tmp C:\Users\Seven01\AppData\Local\Temp\Tar814F.tmp C:\Users\Seven01\AppData\Local\Temp\Cab820C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar821C.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8394.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8395.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8636.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8637.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8907.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8908.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8ACE.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8ACF.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8CE3.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8CE4.tmp C:\Users\Seven01\AppData\Local\Temp\Cab8E6C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar8E6D.tmp C:\Users\Seven01\AppData\Local\Temp\Cab91AA.tmp C:\Users\Seven01\AppData\Local\Temp\Tar91AB.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9248.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9249.tmp C:\Users\Seven01\AppData\Local\Temp\Cab924A.tmp C:\Users\Seven01\AppData\Local\Temp\Tar924B.tmp C:\Users\Seven01\AppData\Local\Temp\Cab95D7.tmp C:\Users\Seven01\AppData\Local\Temp\Tar95D8.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9694.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9741.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9A40.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9A50.tmp C:\Users\Seven01\AppData\Local\Temp\Cab9B2C.tmp C:\Users\Seven01\AppData\Local\Temp\Tar9B2D.tmp C:\Users\Seven01\AppData\Local\Temp\CabA223.tmp C:\Users\Seven01\AppData\Local\Temp\CabA225.tmp C:\Users\Seven01\AppData\Local\Temp\TarA224.tmp C:\Users\Seven01\AppData\Local\Temp\TarA226.tmp C:\Users\Seven01\AppData\Local\Temp\CabA2F2.tmp C:\Users\Seven01\AppData\Local\Temp\TarA2F3.tmp C:\Users\Seven01\AppData\Local\Temp\CabA323.tmp C:\Users\Seven01\AppData\Local\Temp\TarA324.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE3.tmp C:\Users\Seven01\AppData\Local\Temp\CabADE5.tmp C:\Users\Seven01\AppData\Local\Temp\TarADE4.tmp C:\Users\Seven01\AppData\Local\Temp\TarADE6.tmp C:\Users\Seven01\AppData\Local\Temp\CabAEA3.tmp C:\Users\Seven01\AppData\Local\Temp\TarAEA4.tmp C:\Users\Seven01\AppData\Local\Temp\CabAF12.tmp C:\Users\Seven01\AppData\Local\Temp\TarAF13.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9B5.tmp C:\Users\Seven01\AppData\Local\Temp\CabB9A3.tmp C:\Users\Seven01\AppData\Local\Temp\TarB9B6.tmp C:\Users\Seven01\AppData\Local\Temp\TarB9A4.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA34.tmp C:\Users\Seven01\AppData\Local\Temp\TarBA35.tmp C:\Users\Seven01\AppData\Local\Temp\CabBA65.tmp C:\Users\Seven01\AppData\Local\Temp\TarBA66.tmp C:\Users\Seven01\AppData\Local\Temp\CabBD84.tmp C:\Users\Seven01\AppData\Local\Temp\TarBD85.tmp C:\Users\Seven01\AppData\Local\Temp\CabBDE3.tmp C:\Users\Seven01\AppData\Local\Temp\TarBDE4.tmp C:\Users\Seven01\AppData\Local\Temp\CabC567.tmp C:\Users\Seven01\AppData\Local\Temp\CabC569.tmp C:\Users\Seven01\AppData\Local\Temp\TarC568.tmp C:\Users\Seven01\AppData\Local\Temp\TarC56A.tmp C:\Users\Seven01\AppData\Local\Temp\CabC5E8.tmp C:\Users\Seven01\AppData\Local\Temp\TarC5F9.tmp C:\Users\Seven01\AppData\Local\Temp\CabC619.tmp C:\Users\Seven01\AppData\Local\Temp\TarC61A.tmp C:\Users\Seven01\AppData\Local\Temp\CabC957.tmp C:\Users\Seven01\AppData\Local\Temp\TarC958.tmp C:\Users\Seven01\AppData\Local\Temp\CabC9B7.tmp C:\Users\Seven01\AppData\Local\Temp\TarC9B8.tmp C:\Users\Seven01\AppData\Local\Temp\CabCD34.tmp C:\Users\Seven01\AppData\Local\Temp\TarCD44.tmp C:\Users\Seven01\AppData\Local\Temp\CabCDB3.tmp C:\Users\Seven01\AppData\Local\Temp\TarCDB4.tmp C:\Users\Seven01\AppData\Local\Temp\CabD120.tmp C:\Users\Seven01\AppData\Local\Temp\CabD131.tmp C:\Users\Seven01\AppData\Local\Temp\TarD130.tmp C:\Users\Seven01\AppData\Local\Temp\TarD132.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1B0.tmp C:\Users\Seven01\AppData\Local\Temp\TarD1B1.tmp C:\Users\Seven01\AppData\Local\Temp\CabD1D1.tmp C:\Users\Seven01\AppData\Local\Temp\TarD1D2.tmp C:\Users\Seven01\AppData\Local\Temp\CabD510.tmp C:\Users\Seven01\AppData\Local\Temp\TarD511.tmp C:\Users\Seven01\AppData\Local\Temp\CabD56F.tmp C:\Users\Seven01\AppData\Local\Temp\TarD570.tmp C:\Users\Seven01\AppData\Local\Temp\CabD90B.tmp C:\Users\Seven01\AppData\Local\Temp\TarD90C.tmp C:\Users\Seven01\AppData\Local\Temp\CabD97B.tmp C:\Users\Seven01\AppData\Local\Temp\TarD97C.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF9.tmp C:\Users\Seven01\AppData\Local\Temp\CabDCF7.tmp C:\Users\Seven01\AppData\Local\Temp\TarDCFA.tmp C:\Users\Seven01\AppData\Local\Temp\TarDCF8.tmp C:\Users\Seven01\AppData\Local\Temp\CabDD78.tmp C:\Users\Seven01\AppData\Local\Temp\TarDD79.tmp C:\Users\Seven01\AppData\Local\Temp\CabDDA9.tmp C:\Users\Seven01\AppData\Local\Temp\TarDDAA.tmp C:\Users\Seven01\AppData\Local\Temp\CabE0F7.tmp C:\Users\Seven01\AppData\Local\Temp\TarE0F8.tmp C:\Users\Seven01\AppData\Local\Temp\CabE176.tmp C:\Users\Seven01\AppData\Local\Temp\TarE177.tmp C:\Users\Seven01\AppData\Local\Temp\CabE4D3.tmp C:\Users\Seven01\AppData\Local\Temp\TarE4D4.tmp C:\Users\Seven01\AppData\Local\Temp\CabE533.tmp C:\Users\Seven01\AppData\Local\Temp\TarE534.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8BF.tmp C:\Users\Seven01\AppData\Local\Temp\CabE8C0.tmp C:\Users\Seven01\AppData\Local\Temp\TarE8C1.tmp C:\Users\Seven01\AppData\Local\Temp\TarE8D2.tmp C:\Users\Seven01\AppData\Local\Temp\CabE98E.tmp C:\Users\Seven01\AppData\Local\Temp\TarE98F.tmp C:\Users\Seven01\AppData\Local\Temp\CabE9BF.tmp C:\Users\Seven01\AppData\Local\Temp\TarE9C0.tmp C:\Users\Seven01\AppData\Local\Temp\CabECAF.tmp C:\Users\Seven01\AppData\Local\Temp\TarECB0.tmp C:\Users\Seven01\AppData\Local\Temp\CabED0F.tmp C:\Users\Seven01\AppData\Local\Temp\TarED10.tmp
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alex.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\56a8bc1f\19372ff HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6b403c36\726a9718 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|alex.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|alex.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|alex.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6b403c36\7208e4e0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\International Business Machines Corp HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\AppID\alex.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\3F9AC06 HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\371b39b2\6d67d227 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_CURRENT_USER\Software\Classes\WinMgmts HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_CURRENT_USER\Software\Classes\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default) HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\410 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\10 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\alex_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_CURRENT_USER HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\System\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Keys HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CTLs HKEY_CURRENT_USER\ HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\ HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\Certificates HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CRLs HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CTLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\Certificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CRLs HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\7F06864B HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103 HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Escalation HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\433351e7\2db83a0b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\433351e7\26b4a30 HKEY_CURRENT_USER\Control Panel\International HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it-IT_b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\1c4dd593 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it_b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\4deb99ab HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3b6107ca\f2b5bf1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3b6107ca\3a9b7e08 HKEY_LOCAL_MACHINE\Software\Policies HKEY_CURRENT_USER\Software\Policies HKEY_CURRENT_USER\Software HKEY_LOCAL_MACHINE\Software HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\alex.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1 HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions HKEY_CLASSES_ROOT\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\410 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\10 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default) HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites HKEY_CURRENT_USER\Software\Paltalk HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FTP Commander HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC HKEY_CURRENT_USER\SOFTWARE\Vitalwerks\DUC HKEY_CURRENT_USER\Software\DownloadManager\Passwords HKEY_USERS\S-1-5-20_Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\Software\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{C2D43895-0262-4873-A789-C2F96D24B693} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{684BB8B6-2793-49A5-8012-E0A941B4B4DF} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{5F6D61D9-D207-449A-BD48-652A5D1F25BE} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{29898C9D-B0A4-4FEF-BDB6-57A562022CEE} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{E43D242B-9EAB-4626-A952-46649FBB939A} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANBH HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIPV6 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{8E301A52-AFFA-4F49-B9CA-C79096A1A056} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{DF4A9D2C-8742-4EB1-8703-D395C4183F33} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}\00000006 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Pnp\{71d10298-bdb9-4dcd-a87a-eec6137ab254}\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{8c7ed206-3f8a-4827-b3ab-ae9e1faefc6c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\# HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\Properties HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\Software\Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\system\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2 HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32 HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009 HKEY_PERFORMANCE_TEXT\Counter HKEY_PERFORMANCE_DATA\238
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\International Business Machines Corp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\3F9AC06 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\alex.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{25EEFC46-98F8-4BB2-81CE-9EFE9BC16B40}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{314841D4-9E78-477D-A976-9D775BBC1228}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{56ADBC2B-9C55-4592-B81D-3CAEFA7F339D}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{66A0BF5A-675E-4840-82D8-EBF7FF546ECC}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_PERFORMANCE_TEXT\Counter HKEY_PERFORMANCE_DATA\238
Write Keys
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\International Business Machines Corp HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\alex_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\alex_RASAPI32\FileDirectory HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
Delete Keys
Nothing to display
Mutexes
Global\CLR_CASOFF_MUTEX Global\.net clr networking Local\_!MSFTHISTORY!_ Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5! Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies! Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5! Local\!IETld!Mutex Local\c:!users!seven01!appdata!roaming!microsoft!windows!ietldcache!
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW kernel32.dll.InitializeCriticalSectionAndSpinCount kernel32.dll.IsProcessorFeaturePresent msvcrt.dll._set_error_mode msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z kernel32.dll.FindActCtxSectionStringW kernel32.dll.GetSystemWindowsDirectoryW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap mscorwks.dll._CorExeMain mscorwks.dll.GetCLRFunction advapi32.dll.RegisterTraceGuidsW advapi32.dll.UnregisterTraceGuids advapi32.dll.GetTraceLoggerHandle advapi32.dll.GetTraceEnableLevel advapi32.dll.GetTraceEnableFlags advapi32.dll.TraceEvent mscoree.dll.IEE mscoreei.dll.IEE mscorwks.dll.IEE mscoree.dll.GetStartupFlags mscoreei.dll.GetStartupFlags mscoree.dll.GetHostConfigurationFile mscoreei.dll.GetHostConfigurationFile mscoreei.dll.GetCORVersion mscoree.dll.GetCORSystemDirectory mscoreei.dll.GetCORSystemDirectory_RetAddr mscoreei.dll.CreateConfigStream ntdll.dll.RtlUnwind kernel32.dll.IsWow64Process advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddVectoredContinueHandler kernel32.dll.RemoveVectoredContinueHandler advapi32.dll.ConvertSidToStringSidW shell32.dll.SHGetFolderPathW kernel32.dll.GetWriteWatch kernel32.dll.ResetWriteWatch kernel32.dll.CreateMemoryResourceNotification kernel32.dll.QueryMemoryResourceNotification ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware kernel32.dll.QueryActCtxW ole32.dll.CoGetContextToken kernel32.dll.GetVersionExW kernel32.dll.GetFullPathNameW advapi32.dll.CryptAcquireContextA advapi32.dll.CryptReleaseContext advapi32.dll.CryptCreateHash advapi32.dll.CryptDestroyHash advapi32.dll.CryptHashData advapi32.dll.CryptGetHashParam advapi32.dll.CryptImportKey advapi32.dll.CryptExportKey advapi32.dll.CryptGenKey advapi32.dll.CryptGetKeyParam advapi32.dll.CryptDestroyKey advapi32.dll.CryptVerifySignatureA advapi32.dll.CryptSignHashA advapi32.dll.CryptGetProvParam advapi32.dll.CryptGetUserKey advapi32.dll.CryptEnumProvidersA mscoree.dll.GetMetaDataInternalInterface mscoreei.dll.GetMetaDataInternalInterface mscorwks.dll.GetMetaDataInternalInterface mscorjit.dll.getJit kernel32.dll.GetACP kernel32.dll.GetUserDefaultUILanguage kernel32.dll.UnmapViewOfFile kernel32.dll.CloseHandle kernel32.dll.SetErrorMode kernel32.dll.GetFileAttributesExW mscoreei.dll.LoadLibraryShim culture.dll.ConvertLangIdToCultureName kernel32.dll.lstrlen kernel32.dll.lstrlenW mscoree.dll.ND_RI4 mscoreei.dll.ND_RI4 kernel32.dll.GetCurrentProcessId kernel32.dll.FindAtomW kernel32.dll.AddAtomW mscoree.dll.LoadLibraryShim gdiplus.dll.GdiplusStartup user32.dll.GetWindowInfo user32.dll.GetAncestor user32.dll.GetMonitorInfoA user32.dll.EnumDisplayMonitors user32.dll.EnumDisplayDevicesA gdi32.dll.ExtTextOutW gdi32.dll.GdiIsMetaPrintDC gdiplus.dll.GdipLoadImageFromStream windowscodecs.dll.DllGetClassObject kernel32.dll.WerRegisterMemoryBlock gdiplus.dll.GdipImageForceValidation gdiplus.dll.GdipGetImageType gdiplus.dll.GdipGetImageRawFormat kernel32.dll.GetEnvironmentVariableW advapi32.dll.LookupPrivilegeValueW kernel32.dll.GetCurrentProcess advapi32.dll.AdjustTokenPrivileges ntdll.dll.NtQuerySystemInformation kernel32.dll.OpenProcess psapi.dll.EnumProcessModules psapi.dll.GetModuleInformation psapi.dll.GetModuleBaseNameW psapi.dll.GetModuleFileNameExW ole32.dll.CoCreateGuid kernel32.dll.GetProcAddress kernel32.dll.LoadLibraryA kernel32.dll.VirtualAllocEx kernel32.dll.CreateProcessA kernel32.dll.CreateDirectoryW kernel32.dll.CopyFileW advapi32.dll.RegSetValueExW gdiplus.dll.GdipGetImageWidth gdiplus.dll.GdipGetImageHeight gdiplus.dll.GdipCreateBitmapFromScan0 gdiplus.dll.GdipGetImagePixelFormat gdiplus.dll.GdipGetImageGraphicsContext user32.dll.GetProcessWindowStation user32.dll.GetUserObjectInformationA kernel32.dll.SetConsoleCtrlHandler kernel32.dll.GetModuleHandleW user32.dll.GetClassInfoW user32.dll.RegisterClassW ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree user32.dll.CreateWindowExW user32.dll.DefWindowProcW user32.dll.GetSysColor gdiplus.dll.GdipGraphicsClear gdiplus.dll.GdipDrawImageRectI gdiplus.dll.GdipDeleteGraphics gdiplus.dll.GdipBitmapGetPixel gdiplus.dll.GdipDisposeImage advapi32.dll.SetKernelObjectSecurity advapi32.dll.GetKernelObjectSecurity kernel32.dll.GetThreadContext kernel32.dll.SetThreadContext kernel32.dll.ReadProcessMemory kernel32.dll.WriteProcessMemory ntdll.dll.NtUnmapViewOfSection kernel32.dll.ResumeThread ole32.dll.CoWaitForMultipleHandles kernel32.dll.DeleteAtom user32.dll.IsWindow user32.dll.SetWindowLongW user32.dll.SetClassLongW user32.dll.DestroyWindow user32.dll.PostMessageW sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW sechost.dll.LookupAccountSidLocalW cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptGenRandom ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoCreateInstance ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult rpcrtremote.dll.I_RpcExtInitializeExtensionPoint kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx cryptsp.dll.CryptReleaseContext advapi32.dll.EventUnregister bcrypt.dll.BCryptGetFipsAlgorithmMode cryptsp.dll.CryptCreateHash cryptsp.dll.CryptDestroyHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam ole32.dll.CreateBindCtx ole32.dll.CoGetObjectContext ole32.dll.MkParseDisplayName oleaut32.dll.#2 oleaut32.dll.#6 kernel32.dll.GetThreadPreferredUILanguages kernel32.dll.SetThreadPreferredUILanguages kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetSystemDefaultLocaleName ole32.dll.BindMoniker sxs.dll.SxsOleAut32RedirectTypeLibrary advapi32.dll.RegOpenKeyW advapi32.dll.RegEnumKeyW advapi32.dll.RegQueryValueW sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid sxs.dll.SxsLookupClrGuid oleaut32.dll.#9 oleaut32.dll.#4 oleaut32.dll.#283 oleaut32.dll.#284 mscoreei.dll._CorDllMain mscoree.dll.GetTokenForVTableEntry mscoree.dll.SetTargetForVTableEntry mscoree.dll.GetTargetForVTableEntry mscoreei.dll.GetTokenForVTableEntry mscoreei.dll.SetTargetForVTableEntry mscoreei.dll.GetTargetForVTableEntry kernel32.dll.GetLastError kernel32.dll.LocalAlloc oleaut32.dll.VariantInit oleaut32.dll.VariantClear oleaut32.dll.#7 kernel32.dll.CreateEventW kernel32.dll.SwitchToThread kernel32.dll.SetEvent ole32.dll.IIDFromString wminet_utils.dll.ResetSecurity wminet_utils.dll.SetSecurity wminet_utils.dll.BlessIWbemServices wminet_utils.dll.BlessIWbemServicesObject wminet_utils.dll.GetPropertyHandle wminet_utils.dll.WritePropertyValue wminet_utils.dll.Clone wminet_utils.dll.VerifyClientKey wminet_utils.dll.GetQualifierSet wminet_utils.dll.Get wminet_utils.dll.Put wminet_utils.dll.Delete wminet_utils.dll.GetNames wminet_utils.dll.BeginEnumeration wminet_utils.dll.Next wminet_utils.dll.EndEnumeration wminet_utils.dll.GetPropertyQualifierSet wminet_utils.dll.GetObjectText wminet_utils.dll.SpawnDerivedClass wminet_utils.dll.SpawnInstance wminet_utils.dll.CompareTo wminet_utils.dll.GetPropertyOrigin wminet_utils.dll.InheritsFrom wminet_utils.dll.GetMethod wminet_utils.dll.PutMethod wminet_utils.dll.DeleteMethod wminet_utils.dll.BeginMethodEnumeration wminet_utils.dll.NextMethod wminet_utils.dll.EndMethodEnumeration wminet_utils.dll.GetMethodQualifierSet wminet_utils.dll.GetMethodOrigin wminet_utils.dll.QualifierSet_Get wminet_utils.dll.QualifierSet_Put wminet_utils.dll.QualifierSet_Delete wminet_utils.dll.QualifierSet_GetNames wminet_utils.dll.QualifierSet_BeginEnumeration wminet_utils.dll.QualifierSet_Next wminet_utils.dll.QualifierSet_EndEnumeration wminet_utils.dll.GetCurrentApartmentType wminet_utils.dll.GetDemultiplexedStub wminet_utils.dll.CreateInstanceEnumWmi wminet_utils.dll.CreateClassEnumWmi wminet_utils.dll.ExecQueryWmi wminet_utils.dll.ExecNotificationQueryWmi wminet_utils.dll.PutInstanceWmi wminet_utils.dll.PutClassWmi wminet_utils.dll.CloneEnumWbemClassObject wminet_utils.dll.ConnectServerWmi ole32.dll.CoUninitialize oleaut32.dll.#500 oleaut32.dll.SysStringLen kernel32.dll.RtlZeroMemory kernel32.dll.RegOpenKeyExW advapi32.dll.GetUserNameW kernel32.dll.GetComputerNameW kernel32.dll.CreateFileW kernel32.dll.GetFileType kernel32.dll.GetFileSize kernel32.dll.ReadFile mscoree.dll.ND_RI2 mscoreei.dll.ND_RI2 rasapi32.dll.RasEnumConnectionsW rtutils.dll.TraceRegisterExA rtutils.dll.TracePrintfExA sechost.dll.OpenSCManagerW sechost.dll.OpenServiceW sechost.dll.QueryServiceStatus sechost.dll.CloseServiceHandle ws2_32.dll.WSAStartup ws2_32.dll.WSASocketW ws2_32.dll.setsockopt ws2_32.dll.WSAEventSelect ws2_32.dll.ioctlsocket ws2_32.dll.closesocket advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.LocalFree kernel32.dll.CreateFileMappingW kernel32.dll.MapViewOfFile kernel32.dll.VirtualQuery kernel32.dll.ReleaseMutex advapi32.dll.CreateWellKnownSid kernel32.dll.CreateMutexW kernel32.dll.WaitForSingleObject kernel32.dll.OpenMutexW kernel32.dll.GetProcessTimes ws2_32.dll.WSAIoctl kernel32.dll.FormatMessageW rasapi32.dll.RasConnectionNotificationW advapi32.dll.RegOpenCurrentUser advapi32.dll.RegNotifyChangeKeyValue sechost.dll.NotifyServiceStatusChangeA winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser kernel32.dll.ResetEvent iphlpapi.dll.GetNetworkParams dnsapi.dll.DnsQueryConfig iphlpapi.dll.GetAdaptersAddresses iphlpapi.dll.GetIpInterfaceEntry iphlpapi.dll.GetBestInterfaceEx ws2_32.dll.inet_addr ws2_32.dll.getaddrinfo ws2_32.dll.freeaddrinfo ws2_32.dll.WSAConnect ws2_32.dll.send ws2_32.dll.recv ws2_32.dll.shutdown gdi32.dll.GetStockObject user32.dll.GetWindowLongW kernel32.dll.GetCurrentThread kernel32.dll.DuplicateHandle kernel32.dll.GetCurrentThreadId user32.dll.CallWindowProcW user32.dll.RegisterWindowMessageW dwmapi.dll.DwmIsCompositionEnabled user32.dll.SetWindowsHookExW cryptsp.dll.CryptGetProvParam cryptsp.dll.CryptImportKey cryptsp.dll.CryptSetKeyParam cryptsp.dll.CryptEncrypt security.dll.EnumerateSecurityPackagesW security.dll.FreeContextBuffer cryptsp.dll.SystemFunction035 kernel32.dll.RtlMoveMemory security.dll.FreeCredentialsHandle security.dll.AcquireCredentialsHandleW schannel.dll.SpUserModeInitialize advapi32.dll.RegCreateKeyExW security.dll.DeleteSecurityContext security.dll.InitializeSecurityContextW secur32.dll.FreeContextBuffer ncrypt.dll.SslOpenProvider ncrypt.dll.GetSChannelInterface bcryptprimitives.dll.GetHashInterface ncrypt.dll.SslIncrementProviderReferenceCount ncrypt.dll.SslImportKey bcryptprimitives.dll.GetCipherInterface security.dll.QueryContextAttributesW ncrypt.dll.SslLookupCipherSuiteInfo crypt32.dll.CertFreeCertificateContext crypt32.dll.CertDuplicateCertificateContext crypt32.dll.CertGetCertificateContextProperty crypt32.dll.CertCloseStore crypt32.dll.CertDuplicateStore crypt32.dll.CertEnumCertificatesInStore crypt32.dll.CertFreeCertificateChain crypt32.dll.CertOpenStore crypt32.dll.CertAddCertificateLinkToStore crypt32.dll.CertGetCertificateChain userenv.dll.GetUserProfileDirectoryW sechost.dll.ConvertSidToStringSidW sechost.dll.ConvertStringSidToSidW userenv.dll.RegisterGPNotification gpapi.dll.RegisterGPNotificationInternal sechost.dll.QueryServiceConfigW user32.dll.LoadStringW cryptsp.dll.CryptAcquireContextA cryptsp.dll.CryptVerifySignatureA cryptsp.dll.CryptDestroyKey cryptnet.dll.CryptRetrieveObjectByUrlW cryptnet.dll.I_CryptNetGetConnectivity sensapi.dll.IsNetworkAlive rpcrt4.dll.RpcBindingFromStringBindingW rpcrt4.dll.RpcBindingSetAuthInfoExW rpcrt4.dll.NdrClientCall2 winhttp.dll.WinHttpOpen winhttp.dll.WinHttpSetTimeouts winhttp.dll.WinHttpSetOption winhttp.dll.WinHttpCrackUrl shlwapi.dll.StrCmpNW winhttp.dll.WinHttpConnect winhttp.dll.WinHttpOpenRequest winhttp.dll.WinHttpGetDefaultProxyConfiguration winhttp.dll.WinHttpSendRequest ws2_32.dll.GetAddrInfoW ws2_32.dll.#2 ws2_32.dll.#21 ws2_32.dll.#9 ws2_32.dll.FreeAddrInfoW ws2_32.dll.#6 ws2_32.dll.#5 ws2_32.dll.WSARecv ws2_32.dll.WSASend winhttp.dll.WinHttpReceiveResponse winhttp.dll.WinHttpQueryHeaders winhttp.dll.WinHttpQueryDataAvailable ws2_32.dll.#22 winhttp.dll.WinHttpReadData ws2_32.dll.#3 winhttp.dll.WinHttpCloseHandle rpcrt4.dll.RpcBindingFree cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo setupapi.dll.SetupIterateCabinetW kernel32.dll.RegCloseKey cabinet.dll.#20 cabinet.dll.#22 cabinet.dll.#23 sechost.dll.QueryServiceConfigA rpcrt4.dll.RpcStringBindingComposeA rpcrt4.dll.RpcBindingFromStringBindingA rpcrt4.dll.RpcEpResolveBinding rpcrt4.dll.RpcStringFreeA ncrypt.dll.BCryptOpenAlgorithmProvider ncrypt.dll.BCryptGetProperty ncrypt.dll.BCryptCreateHash ncrypt.dll.BCryptHashData crypt32.dll.CertDuplicateCertificateChain mscoree.dll.ND_RU1 mscoreei.dll.ND_RU1 kernel32.dll.GetUserDefaultLCID crypt32.dll.CertVerifyCertificateChainPolicy kernel32.dll.SetLastError ncrypt.dll.SslDecrementProviderReferenceCount ncrypt.dll.SslFreeObject kernel32.dll.DeleteFileW user32.dll.SetClipboardViewer ole32.dll.OleInitialize ole32.dll.OleGetClipboard kernel32.dll.GlobalLock kernel32.dll.GlobalUnlock kernel32.dll.GlobalFree user32.dll.SendMessageW kernel32.dll.CreateIoCompletionPort kernel32.dll.PostQueuedCompletionStatus ntdll.dll.NtQueryInformationThread ntdll.dll.NtGetCurrentProcessorNumber user32.dll.GetSystemMetrics user32.dll.GetClientRect user32.dll.GetWindowRect user32.dll.GetParent ole32.dll.CoRegisterMessageFilter user32.dll.PeekMessageW kernel32.dll.GetSystemTimeAsFileTime user32.dll.WaitMessage user32.dll.GetLastInputInfo shfolder.dll.SHGetFolderPathW kernel32.dll.FindFirstFileW kernel32.dll.FindClose kernel32.dll.GetExitCodeProcess mlang.dll.#112 wininet.dll.FindFirstUrlCacheEntryA kernel32.dll.SetFileInformationByHandle urlmon.dll.CreateUri kernel32.dll.InitializeSRWLock kernel32.dll.AcquireSRWLockExclusive kernel32.dll.AcquireSRWLockShared kernel32.dll.ReleaseSRWLockExclusive kernel32.dll.ReleaseSRWLockShared wininet.dll.FindNextUrlCacheEntryA advapi32.dll.AddMandatoryAce ntmarta.dll.GetMartaExtensionInterface urlmon.dll.CreateIUriBuilder urlmon.dll.IntlPercentEncodeNormalize wininet.dll.FindCloseUrlCache ole32.dll.CLSIDFromProgIDEx kernel32.dll.GetVolumeInformationA kernel32.dll.GetTempPathW kernel32.dll.GetSystemInfo kernel32.dll.GlobalMemoryStatusEx user32.dll.IsWindowUnicode user32.dll.GetMessageW user32.dll.TranslateMessage user32.dll.DispatchMessageW ws2_32.dll.#116 vssapi.dll.CreateWriter advapi32.dll.LookupAccountNameW samcli.dll.NetLocalGroupGetMembers samlib.dll.SamConnect rpcrt4.dll.NdrClientCall3 rpcrt4.dll.RpcStringBindingComposeW rpcrt4.dll.RpcStringFreeW samlib.dll.SamOpenDomain samlib.dll.SamLookupNamesInDomain samlib.dll.SamOpenAlias samlib.dll.SamFreeMemory samlib.dll.SamCloseHandle samlib.dll.SamGetMembersInAlias netutils.dll.NetApiBufferFree ole32.dll.StringFromCLSID propsys.dll.VariantToPropVariant wbemcore.dll.Reinitialize wbemsvc.dll.DllGetClassObject wbemsvc.dll.DllCanUnloadNow authz.dll.AuthzInitializeContextFromToken authz.dll.AuthzInitializeObjectAccessAuditEvent2 authz.dll.AuthzAccessCheck authz.dll.AuthzFreeAuditEvent authz.dll.AuthzFreeContext authz.dll.AuthzInitializeResourceManager authz.dll.AuthzFreeResourceManager rpcrt4.dll.RpcBindingCreateW rpcrt4.dll.RpcBindingBind rpcrt4.dll.I_RpcMapWin32Status advapi32.dll.EventWrite kernel32.dll.RegSetValueExW kernel32.dll.RegQueryValueExW wmisvc.dll.IsImproperShutdownDetected wevtapi.dll.EvtRender wevtapi.dll.EvtNext wevtapi.dll.EvtClose wevtapi.dll.EvtQuery wevtapi.dll.EvtCreateRenderContext rpcrt4.dll.RpcBindingSetOption ole32.dll.CoCreateFreeThreadedMarshaler ole32.dll.CreateStreamOnHGlobal kernelbase.dll.InitializeAcl kernelbase.dll.AddAce sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.IsThreadAFiber kernel32.dll.OpenProcessToken kernelbase.dll.GetTokenInformation kernelbase.dll.DuplicateTokenEx kernelbase.dll.AdjustTokenPrivileges kernelbase.dll.AllocateAndInitializeSid kernelbase.dll.CheckTokenMembership kernel32.dll.SetThreadToken oleaut32.dll.#285 oleaut32.dll.#12 oleaut32.dll.#286 ole32.dll.CLSIDFromString oleaut32.dll.#17 oleaut32.dll.#20 oleaut32.dll.#19 oleaut32.dll.#25 ole32.dll.CoRevertToSelf advapi32.dll.LogonUserExExW sspicli.dll.LogonUserExExW authz.dll.AuthzInitializeContextFromSid ole32.dll.CoGetCallContext ole32.dll.CoImpersonateClient advapi32.dll.OpenThreadToken oleaut32.dll.#8 ole32.dll.CoSwitchCallContext oleaut32.dll.#287 oleaut32.dll.#288 oleaut32.dll.#289 kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle fastprox.dll.DllGetClassObject fastprox.dll.DllCanUnloadNow oleaut32.dll.#290 wmi.dll.WmiQueryAllDataW wmi.dll.WmiQuerySingleInstanceW wmi.dll.WmiSetSingleItemW wmi.dll.WmiSetSingleInstanceW wmi.dll.WmiExecuteMethodW wmi.dll.WmiNotificationRegistrationW wmi.dll.WmiMofEnumerateResourcesW wmi.dll.WmiFileHandleToInstanceNameW wmi.dll.WmiDevInstToInstanceNameW wmi.dll.WmiQueryGuidInformation wmi.dll.WmiOpenBlock wmi.dll.WmiCloseBlock wmi.dll.WmiFreeBuffer wmi.dll.WmiEnumerateGuids ntdll.dll.EtwUnregisterTraceGuids
Execute Commands
\\smb.com\bvb.exe "C:\Users\Seven01\AppData\Local\Temp\alex.exe" C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
Started Services
Nothing to display
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven02b_64 | Seven02b_64 | VirtualBox | 2018-03-12 14:37:23 | 2018-03-12 14:40:20 | 177 |
7 HTTP Request(s) detected
http://checkip.dyndns.org/
- Hostname: checkip.dyndns.org
- IP Address: 216.146.38.70
- Port: 80
- Count: 1
GET / HTTP/1.1 Host: checkip.dyndns.org Connection: Keep-Alive
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- Hostname: www.download.windowsupdate.com
- IP Address: 68.232.34.240
- Port: 80
- Count: 52
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 86401 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- Hostname: www.download.windowsupdate.com
- IP Address: 68.232.34.240
- Port: 80
- Count: 37
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 86400 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- Hostname: www.download.windowsupdate.com
- IP Address: 68.232.34.240
- Port: 80
- Count: 5
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 86430 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- Hostname: www.download.windowsupdate.com
- IP Address: 68.232.34.240
- Port: 80
- Count: 3
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 86431 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- Hostname: www.download.windowsupdate.com
- IP Address: 68.232.34.240
- Port: 80
- Count: 3
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 86402 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- Hostname: www.download.windowsupdate.com
- IP Address: 68.232.34.240
- Port: 80
- Count: 1
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 86462 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com