MalScore
100/100
MalFamily
Ispy

Servermarch10.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 27/65 Related 2805
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 692.00 KB (708608 bytes)
Compile time: 2018-05-11 00:01:51
MD5: 8922b3f2e4a32ac5bac9ce82a39ca9f1
SHA1: ed710f648f23eb0035a71a3a3f56223db995a55b
SHA256: 27f4f7e99c303dc6b1bbc880b82f5142bce457df4c2ddced01f06b67e4ce3dea
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-05-11 19:24:06
Last submission: 2018-05-11 19:24:06
Filename detected: - Servermarch10.exe (1)
URL file hosting
hXXp://devamindustries.com/pdf/Servermarch10.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-05-11 08:45:29 [27/65] VirusTotal
PE Sections 3 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xabbf4 703488 ccf0594301efe7d650e4f70ae85fd7c0 c21dc077ec9386d60508616a26a1c39a843f4f59
.rsrc 0xae000 0x1000 4096 7d61ec1b77d4e74675a604138269efb2 b2942be3d4f8f2ff86efd497ce6772079f3f33bc
.reloc 0xb0000 0xc 512 e19869255c552081a965f94ab03d5883 406b90719a4015e0c1dd9eb80690a3f4d2730794
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0xae058 604 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Servermarch10.exe
FileVersion: 0.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: Servermarch10.exe
ProductVersion: 0.0.0.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
OtQDRkW7aZ9Q6U8oLl2tR8bvjU0FqIN
9tcN8UN6yMbkGmMmySVFqkoR
HOTyL78AROGdq0bs8jfkELsg2lP3AkNta5Mgeai
SdK944DfmYFkReHGr6wA3YajjRKnBiGvRR
sDIl7LcGdh8EHYJAb63w
WPIetxQvuCPoJQanGGL5hyM
cXlU2sFZzDMSWKxpnf5kArwIYV3nEb9zml2
InternalName
X0k3HsiWMPElnCuAjlZzifi
jwIoDwHbbPrJ1XmFo7hXJiS
0aTN84Tq1MhkQAsLL8QBhP
fxbW3wxt9AoFQRfyPAxVip7TjoKluKZ
Translation
cvvPAnKE9FRhnnLNK6CplkJn
6xcbRUPReSUkyoI7vhQmnz
vLbugZZqM5UWIBj36aEBgX
P72ECdseQ07uBALkIDBndeihWfb9l
izhYzPeNUjVaA7uHKSo8w8JbndZftf4i
NZyCRL5tJ8EfHxvCi8gPRsvaoZhcufA2
LegalCopyright
eWvutkLF2Kd1XEdGleHyGV5DBQsieXqCvMqxk7X
Yd1ht7dTsUl3B1d6KBMCf7P076T4HOODdS79
kb04WrGsU4R6dpMzezBeCFtNhom2j4ueCzuttjL
41tk4u9pTBcqwW52pISas3Sg8Ycim2U
Z599BDrX7bXqd8grQ0oC0Fk1mciXA92gDq
5MEUFHUU0scYyB1hbXjW8F7eaU56I77Y
21jPifKwjde7IK3iiN811FiAEZla8TZnsacs
bCvSA5TVIRMt55N5iYPymVTOIm
gD0z5vda1PMQalZD1muzxjB
YsoN5iGhzt74fZO0Dj8Tbd3oAHk51O8S
VarFileInfo
LrfIOdgErlKY5SHQfXi9sqi7gYAubNOSp2Bp
fH05SMk7h4hB5caLEzkdbIivD22
0RU
a21iHB5frgpcjMe1ogm2Cb8EGkNMB
oiNpBvRoVqHZDxtFGIO2o1EQgwrw2ZOL
iOA4Yel30MEtPAPAmxMqsiFppF7EP7Rn
Servermarch10.exe
s01fG7ZebOh8jykHqQSxLmzT
eY70fFoBea6koT3S3UalYXBzkgeK
nJX6x27DEOBxMxP0XpnDrjj1Qd2
VcFD8SPSLtiLv9h9NqP1hCkSXEr06
rVL0DEDbYewuYWGHKLq9
kSiGKNlFbvGfEFkTn0hXJ38tbQ62WZCXvnvv
549zJjULCDQG9NJOegGs0Apn2c2tNYlvGmH
yPctnzZFtQ1CXImRN6MED8lIUYUMHV01kE
HPJ7kP9Tlvs0804umNW8KlcUaa8Eav
tR8eVNO63tZTkheteVNjSGLpO1x
W13nuN71dd0Cqi0NWxjLkRf6c5le4Hg2wk
erZDCmXNT5RTGe8oYkQQ
caFKwDCpm4d6TIQUk2LXfa6tyqH
YOTsMRIFREpquY8IFfn02eWYWdgQl
lUvJ7avgesYBhahOC6bxq8Rtb3
zFAKiXXDhuxndcqUB172wk
NYZdb8oYkInLrMJaBuG4UG
SIVC0n65HFc3uO5JCK2X2W94WCutMy2
6YpnU22LqQdkLEbmQ3f2tMbIZGPZ6FMD
ProductVersion
qDgIenb1B2SrPv2Znu6QGKSC0KpagOnq66oV
3RLodBmAIZtJlgqWfN9HpkcrWbTC
iPqxSjjvjLnnNHw9h64xX
mOWa6pnvaImZI77aJxo9WtoZECJwqfl3D
LKdSNaqeDNDAz9vaM74J9frDu1Usmh
nUzvRrsPeorAjenW5sawJD2qIf5VKVg7IZ
u693ds2ZJgOsYp7UuBUltRjHn4VlWhjE6
VS_VERSION_INFO
ZntYEcHvWF3hZ1uTCLwQPFJxZkmArW7zg2FOE
qvLSTZQYxmc7BbSScnK3AK
Assembly Version
aysyxeklt8D4wfWLW0xWfA8u4gIGfG
dYPetwpoBpuxivNXcYz08CUCen11VXKL0cpF4TZ
Xyw8kzNx4uIcmfzY6mpgz3p
k1uvX9MDA236o50B6TFsL
S6OZPHQRsJXjPFAphszegxm5KsRbv6gU2AcqSaX
G4zaPYnjGa1kQJdrhpyqEKxhdDgRAuDgz
ay9BRdbgcNEdnZhggH8tfgIkqghM
IeCJFCbcK70BQYgDEdt5hRuYuXedzWRpmFSAh8
mV9OKgll2WCeSmyhZYlFzSAiKQZ4E2bckJ41Vb5
StringFileInfo
FileVersion
jB9P6uPXduvzJBuRAGNPq
000004b0
Ktv6QB7FJNJugzRIaQg3Ut8TQhbKeYt
FileDescription
qjMyaC2XDkfqHLxbGu20VOFWAoYV
0.0.0.0
OriginalFilename
7NlQvHh2kPxoNuGFwZqJZMM0vfpViSIx5Ufw
i2gS87p7ZXNIGi2Bd21jYnMqrQC4TEE
WrWa!
>p *oxj
**2h
L?~@
{Tjq+B^
IZMh^w1
IAkg
Kz{
!Dk`uz
=@9
F)<x
n wX>
Oy"PD
&vK0
YP6c%
%rW/
E%8{
eN
}% w
=SH\
<f _
1 (S
$7a,
][{e
B|wq
5u 6
X8xv<3.{
'H@g
jR1z
!]BWq
qk(~\|;
KI>Ak
<`D"C
AwpO]
J?EHI/
UnverifiableCodeAttribute
AHp[_
=@9s
{yPz
v}Kj z
gDKmA
#Y+f
_Z[^
\`_0F
(D.}*
cww*
eU7v
bxI)
K<b`
k.j$?Jf
A-HF
l@_6
=t-}IV
, wn
M*>*q
}r:B
G'MJ
S3!Vf
6q2~
sZ (
ZbD*
XknsG
T42r
WP";2
>g &y
=&io_
Z']
s3 km
(mK\
+"3O
[qd)
ukRc
sZ L
f*nK
w=rR)
<=aq
P*S)
{4,K<
629$
b j$
"&"J
0dy%r
*p L
cvVI
Hs{X
[WrP
IQ]g6\J
7d+D
I<Vm
P tJ
oU5q
v j z
cPoG
I<;?
F_>\
=_)#
zR n
)$M/A
cL s
cav+c
vjjr
g'0t
)$v/
tz2i
- Ca$
nIm5~
ob&_MOS^
fnn^
P$s{r
WhE4
A)v$
Mc}9+@
Kt|R
|5~`~
J0b8w#
Y@(M
?(-.5*U
Sx k
iEx#
wZyR6N
t6hL
m i]
kD[6
PR [
p}bx
Uxbu
[j0P
qxz\%4)
FuI,
JFM+
! >2W
s4KF
Zhk&
2XIA
6g(\
Z!oqs
C `I
N3(i
5%Jn
+U1:^
v!p
\BRE
9oDgo
t7x >0qVA
,1 p`<
T*d(
=xc,@m7
!<s:w
`EHc$
N`EN(}
u[8p
n !7
F$Ii
}j]4
Z#7'.H
,~xt
F&E8B
:EklD
3lO
i UK
Nw %
d#?2
e>N\U;
7 ?q
N3leFk
'neI
UV[7
llE+
(n:5
fE(>
![q?[r
dL/
vu@h
@ ]2
/)g2w}
CWK_
0.|+
}eTlE'
RX &
LF%r
SnI]
nZ|W
/[R7
;_67
WSM`
`<.=d
Q01u
9yXx
Iqu'
zpV<
i}2z
k? u
TW^=
]Gd\
i0_2q
nzB_
j~Pl!
6P#*
cHw9J=
4o>m Hj
4kT-
pGK26
[ 7E
54z
pLzL
=h I
*k+1
_5-0
#[9`
r^,W
f7cT
QY7
e$k
`+]h
1mUW
&RLe
m5b?
fb(f
(tyl
{@CB&d
0\nJ
4T'N
4VH>
PTbs5
3zDi
o}BL
o+~61
zjd8
xeu7
th'7
\<r
V yu
.s7C
2 j}
1uuho
u{wK
d_V6
J}HRv
WBM3b\
~Vq>
i}g=
P+
- ,?5;
4YN*
b{Vi
h?N$
w8,kwo6U
cN1Jf=:
l^,rB
yEyha0J
-Of=
];{=
up[A
)]XM
C*N?
{z22
a8O7K3
=wsd
X|XpvZ
^1B8w
H-.5
xDwF@u
TC4y
2pEM
xBv*g
dWapl?
5wo\L,
ZV5s
^00m
$(}w`
rO@"G
5tlsgegRFJm
PqN [
&YH7
c?;W
'[O
r2lr
Admh
d|lV
H!"w
CWtd
@<wa
.<->
| { e &
|@cg
IzhS
#tY9|@
^=k
e1Pg
:5]H?
EmKRfr6e8@Z?
&[8F
d,} t
qFi>w
s oF}
S]<c
`kv,'
xR B_
u%F`
$Z Z
Z7pw
U\cNK
afg;m\
V`F_
?dlP
Y]]
sLr&
kIzd
IS~iu
aapm
SnB\_H
g137
] 3D*|
10_
tl?vb
:.esNP
%yYII'?l
.text
?4WA
y}*Z
i*ZT
;)MVb
Z3?s
$
Ce^{
8T`
r:`^
ok4.
't[5
a], <
`p3%t
.TKv
T|\R
0*&T
.T2=_ z
6v)CS
@u\6w
:'*G
_}pSc#2V
O~cM_
#e.tZ9l
y)dr?WJ
J3]sk
@Hx~
:3|!8
Q/V(_
5r{M
))"W
?<A5
E<2"P
,@D9
k" x2
#$N8
-]ISiij'
FWNL
C'u7
(z u
FixM
#% >
fz=M=B
/U&X
%a3G=
:b(e
D8*D
QkzT
T^kf`
J!TTo
$LKi
u_l-
f[ 9
z) (
E<L9#1R
=VV.
#1Na*
G(|0?
]0(j
&7C^
, OX_
HOVt`
ahBn
Wz0e
l[=,
e;hs
8^/{\
%h A
\ "n
T &4 4
aIeA
Y6"
jyUib
xn R
g*:.
/UQm
w $z
gs;XP
" (X
: ~ !
<iS5
.Fo~h
`M@nxl
Zd#qA
|Cr*3
~du4
+I[s
M?9<
5 AJ"E
J+}I
fWc$
1k+ .Ek
}6%2
n(A~
4 @F
2hn+
ueb5
a<{T
`0xG?
2qq
s m9
5 ^#P
(R{z
N?/G
MJ!
u&bc
4v$w
2N58
ZZR,1
kM+`
Uo.T
k\[`6#
rDko}
BdB9
R 4*I
gs4Jc
%-R
r%}q
H'Jz
fv1n
OvI,
L5;}
gLU-k
o=i \
Yffu
q7Xi
y pUZ/
XE (
5 S4G7
B>:$2nK
+sE=
(!p<^Ls
.o@K
{s0c
KdIP
sua,
M@ 0
EN.R
+R5e0QwW
F4r^
x~M
-R_E
A+lxk
Px"C
OB2W
k!hI)z
pI!I
d!m^q
Zj'=<K
4U'+9\
l^VB&
dq&}q
W_c9
,5?
L|/b!!
{3CE
,5Cc
> eG
P{m{
> 8Lx
|}zI^
f@ w|=
2TVZ
2p5
e.X&
.S$|
(wW*
FVJi
7rs![u
M y
1H]l
!^,HY1b`
^{nq
V |jz
KYD+
/|i8iLy
Qk:
'#D7
!.$/
KGX|
@0xZ
get_Assembly
,NZdq
-]:q
iGV
mn' ZG
E?}#[M
j B.
%R
B%`+
s38K4
VNg2
8$5H
qo+E
* AZ
[l+1
0u]_
-J0?&
(r{;
9. k%
cQaK
a!)^
sESz5w
|\es
k QH
`X4
VgAk
MWQ,
% X(
7 Nox
TFw?
3 ud
=#Nm
YM51
Mqu!
@[ :Q
fY!ffY
9$
e ^I
x=ayg
I=L.
L#D-
+OF%<
Z^`*
=U1^
A X
vQu'
7];R'{2
bgU2
,~R<iR4T
L"x@
[|M!
J)c=4
V"D
g|S]
hdkz
n_WV
+ \&g
bk1
:_p!
(n8$
Y jo
]6Je
fB)O
Xt5c
_Zx&
2N+K
`H}
41tk4u9pTBcqwW52pISas3Sg8Ycim2U
JthU
lLB4
*8Q7c{
lCSa
nU]<
%Zp{s>7D
B"))
`4|pk
Q#Qa
<n1Q,s
?L~L
E.za?
l9^d
4,nEZ
({ a
q#Z7[
nMV9s
WRJ;Z
vo~X
kay1
qb-
oZ(8
eQ*u
GEByL
S974@
E {
<8an/
Kn#_V
^$N8d
rVL0DEDbYewuYWGHKLq9
} `$(]
YB6
A-k<
pk m
`;)L
>to0
9Dvg +q
./4p
?zL9|
uug<
z[A&
,^-)
')<k
nv]s
JPze
`_]1
$<y7Wi
-AB%-
:\+)
d6'Vb
ADHt
WuU%S
v\`=0L
_M4?
4YL4
J-Sa
;/$,Ar
TFXX
(^`s
=VyH
JHzi
J5g\G
rk"8S\
/1R=
yJ5
4rF|@
Kh ;
u"$r
L3Z!
KC@Y$M
Xg:Y
`2as|
t_R
-O3*f
bMgU
9.@C)
Vxgj
yM,
(-apQ
GyA%
1&F&m
L,2z<
UG,TXA
v^lt
QY^Y
P[>[3yV
O:zy
hz?)
}j~/
>}! V
5;rx<Z
6T _`
%/Ta
wPa
3L<K
2WMKW
=Uy1
XUB<%
HB7dCc
6">6,4?
3+Ur
*P-p
i7
Nks
U '`
vpWeG
{&K8
m|@=T
uHFqp
cnU`
/@?k
Q"V6d
b2$!
0gc-J
1?tj
_CorExeMain
W:%@yo
JrO.
:V(,
ZLd
92.p
&Ct-
NTS.'
G"r'
Bx"d
2<
# "U
-~09
DAZK
aZH c
dhza\&
=T ]`
/xxp
Xq^Q
H#}.
qc+ sG
&/ 6
S2L*
Y"Cpf
Xs=L
:D_BKS
5:pl
7fr
2 , x=kT
8(QOs
Hy Z"v
XU :l
pHux
L'W
yngR
K/{!
R;jh2
~QYR
}m QZY5;
aMh s
H(xiD
9R-a
fg~R
*Y1J
KzE{
vFRz
D8$*
o8:`
$})A
KA%IG
6M[W
;-oc
bK+gK7
|8*6
.W}3J|x
9Y&J
i Ku
(7$ =
:?BF
0\!
TQEt
l=`6)
.4;~
K\(e
aFg!
=:qx
ld/Mp
tk^|
,bg+
#kc:[
F%XEA
Hw S@
WgvWh
YO/1AY
;km8k
L&>nKo
{[}
/`Lwa
KH1A0
2 {`
5D&L
y)Bf
@D d
jP2Z
-Ou}-
8%Us
1@\wG
}{iUZ8
z#@:>2
23 L`F^
3.dd
o+mM
#P{T[)9
h[Lt
?1Vp
'a(S/
r=(R
ou9@Y3o
iqr2
[f}:
6(])K?
t|K?
c#wU
*F02
:-vy
P& k
C7#
<{mB
vzq.
l*1=
6%Dz
NKZB
(y_m~
2x J
1"3{
>xAs
b5w
X{z1'l
uh_C
I3r7L
@$9E
!M6t:
7@!n
VG|^
S t}o
INakQ
]kW%fJ
;$g@
L[o9J
Uz5x
Ck ~[
w-=D*y{
;Du29
!0=e
HRNqX@
~<R\
zG{'Gpl
/4qP
%` ;
5k/<
v{fa
z Wvv
#P %|l},Xk
1nX&
wTAy@
l\_8
O) N
/jt8yc
og}P{<lO
xe)m
IM+kJ!
9Lgx
77O .
'VIk
ow{#
xZzR
H:"SNl
yS/QD2
\w -
4<j*
ZBYn6
7VVP
C)[N
FH
e`5O
[3d|A=\
o{/ATx
ZF%!Np
c-G1
-Oe%e
94<j-=
(VJJA
A+ G
cd0ZjN^L'
aN :
X}2(
4fg,
t{<6
=%1Tm"G
@!a|
!AMD
08qW
q)va
Dl6^"}L
.H8g
DXE]}
cR gYr2C
\;|p
PMq?
PFg
N4 Y
2q5sA
QH59
a ~}
TxDma
9]XV
b L^
GhI
TX|u
xfeM?K
%~VBWW
9wVO
{S,T
CNP[
G :9
y~JH
GFA#
q2_
0f K>h
VHSP{z
!:BeVh
hEfn<
>_Cq
_f:W
DFB
H}~I
REl-
(!]<
+H'
q_nDw
\a,
v@Qb
Ueu<
&<+S~
VwmP
M]0*[Yv\
vz#
x RN
`U&}
#2yT gx?zgO
8Cg+
&TcW
bc?6
R/So
`@1<+
oiNpBvRoVqHZDxtFGIO2o1EQgwrw2ZOL
U4tU
Y|KS
F 3G
mIb)
!nSz
t?MN]
K#p+
);?7
h%}u
{$c H
]c\
8O}7wr
sYPh
m^ =
r<J9
S,m/t^
[3+rk
>MF
-T|B
D|}Ibv
}^X_
,:,0
^(Qk
5C G
+?t/
GrFK
:!qW
CJyNYE(
i/0aD
%4gi
h>1|#
y",:BG
-~]9
dJ^`
8- *
+YznN
Invoke
+)\y&
z!n'
fS7 .%
|8Wm
::-C&
Q"[D
'r;uU
l;j}
dy%'
#xHp
us/Q2
3d8a
J/sm
4dR`
d"A 03!e
2 bI3q
8VFb
tNR{
37K93
(fc
Dfu 8.
Zma(H
{0U H
ud+#
5!/I
X*jU
2PU)
l$*c
mm)}
)RGO
a0t-
j78b
9>a`{
MBE"
$K;K3e
!/4"
6[ OF
J`3E
+%UuZ]
]mg{HE-
ovW9 o}
,`!1!
.3Fho
"q/V
zglN
L?Ib
<yej P
b0S1F0
')&[
KV-%
qawK|
kwXc0
-(ey
1&!
IK2f)
hq &
n*Bp
8*w;D
zrQF$23
0H_N
-iTw]
)F9I
_kxoFC
?2RR
) g`PU-
WM7=
! 2#
KAh
8UY
74Or
-Eu9a
A@F"
B\m#
BHH9)<u
YYmA
]-*U
B\m
`+i5
Mo6b
[C?m
iB:
U`0=
{I +
cfWn
^Nw."
manW
@fG
u3cR
D\b&
'+p&X
V-@9
sR\Q
ocw'
)VOtf
!\6
|{09
^r1r, {
K %{,
soW5
ct'7gC(
h;-Z
1L^u
sR\J
O3s?
8k.2
RFrh|(
"L=aV`
aAQk
C$@\
RuntimeCompatibilityAttribute
V ha0
7Ms $
xO4]
< p
G$!M
jR}J
cT5
ZY#35L
<bgB
v~Yy
++] C
|XTa
jut
#]:Y3
eCw
Ww)=
W#d
yD%7
;RKl
eq?$
)-(K +
x,.t
r'4f
>YLs
MCQh
|6:.
l.~H~
1J^]
})K
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
xEe
s}UT
|87c&Od
.EgV
?eP]
[7>2
`:$7)C
)>~sr
>(dj
%BR
s@fReU
T,Y
JV@Dl-
7F ^
n^J0 =@
`7B-
Q/)B%
Ve#G
=,UJ
*TSHX
~~6`
9YE6YV
9*Dd
'xlE5W
G_GR
J$HcF?
{k 8
n*;MoB
s|QD
o_;Hs
8%"D%
OtQDRkW7aZ9Q6U8oLl2tR8bvjU0FqIN
b)3Z0Q
:/y[L6
: 3iy
vA`j
fxY
:w#(
wE:S
Hb=f
C(,K
Aq+=8
f<* H"O
jwIoDwHbbPrJ1XmFo7hXJiS
b?{1T
vd%Y
#Blob
dXA&
C/r[o~
<'Y!E
U$~bSV
A*'O&~Z
,0`=
zU>$
'=FD
3e[R
%M|W
z]Tl'
ResourceManager
Z3cR
5fal
1}9*
al8
j+\\c
K Kk`
YGq!
^j!j
jm.]
*6-cx
e}[
[bt<:
x a!
J~(M
LuLuBl3
h!4l
nq-^M
tY-9
YkDv
jm:Ks!"
N~d~?s
w 5Z
FI|+
f$4@J 6
'7e q~%v
Wfa2I
T#,{
QRe^5
' =]
1 `BM
#5>PF
Vw3=
=Wz
Tho
sV0V
4dRYLdT[
C?O1v
jTTh
-lH
H 6>
*U]0q
rn{(/
_i+;
(oU(
9iW&*
{3f_
# i9
Vm E
xQD1
w}m|}
wIae]
t4uHqW)
,bFT
;u,e1q
2%7?I u
7<"i)
^jir
m"?:+
21|;
5m-J&5/mP
Hno}'
o@om
4cbf
YDAD3]
Y{ncB
4 UC*
CE <[ v
HP {
SPXu
KrRa
]/U)
K'k~ z
Q=Qk0,
#SS
hl |
r# Q
iQmkC
(.?v1
e'v=_rk
`QK
V&u
5A[R
o Y
WK|G
E on
ISalp"
EHM^
Im) ]K'`
wCz4W
FD0w1
z:fT
*Qr0t
[`hX
x<6E
$lW~
/w##
?cp4{
!k7Bbf
W_b h$
BS3S0
+J k
d>PqRyj-ji
8),\
8ES!
-l{@J]
|XaBoq.K
*0J9
Z89J
rna\ 0
x 7rQ
!X\i
O.2X
:w{z
lQ4 :G
+Te{
SA;c
+U0B?
;81q
1s"P
z +U
p\@3
XT+pg
JnOy
]#qa
MX~j
+zP
dD=`
Du3<
mscorlib
0eB@8
TFT*
Z/YS3
hp!m
F`SN
WVW,0
hp!a
[j:7J
*;/TH
LYhJ
RYjd
2~Q)
}G@m
dn1|
Rc&/
73bB
9)91H
gA_`
8^c6
xTk+
M-}
'5G(p%
<99w
P_4W
*(0h
"D4
9yxsp
"$Y-j
gD0z5vda1PMQalZD1muzxjB
q"W
E9<H
2 cx
ma;X
AxQ-
(_hD
(4,s
0k c
U`G]
Mq+#
_CSB
;i?
bJkj
c a
<nD
Ft C
s] b3
qd#$
kyDDq
RuntimeTypeHandle
5.V2
ca>H
![J*
r+I~E
aQ}T
FE }
N&HOG
XrCN
tq
2s9l
OaJc
System.Runtime.CompilerServices
c*ocK
tPNA
~lrj
Z-l
I;n,
6\yN
L9 Q
Y'CW
-lf
"w([
.o7i\i
F+ +H
8M0N
.Lrz
!>1i
cx[]
vqW,
|I]]
N9 r
yVTG
Hdow\
~o!3
?Q G
i`vA
VESe
,m$!0
'\x
cqG.D
00
4c[rH
EE78]
[Y/3
<0\!
JV@[
b-l;
O1k#
4+#Y
-QrI
73@Rg
tS 4
25($
<uKX
cZj1
*axy
{P4/
5OU*E+
A:-
}Z*
n&=T
l[evLK!
fe#4
~2%7
(JaO|F
Vuwx
""i&
9 FD8
weuI
tfpbm_
e/]
FuRh
k`Gu
2l,]
-8:h)=
S88"2P7
P"gS
8w lr
[!lE
J I0
/hP<
f2<b2
K!;63p8
-4Q7((
#)kp
MK.q
8!MY
f=0F?*
W$ob
prs7
ZIY-
A+$^
)DZ
1 >;
(} *.=
'-2+5g
=: 6l
x Rt6;]Nm
~A0X
(Q}7
O9k"
%I/
? u
QeeOC
% H
a=ALAh
nZ(
O?8tm
RDA2
,Pb*
5L+4eNk'
]7o*&
G|o1d0
`tn0
.u=m@%4
S>t.
][Cz
5%ad
J}:rE9j8
yBM%
I?\ZL
UZy
,<r'$
v($q
dz<w
J5/&
FAoE'{
?X.w
E-w@
7G+)
w^ p
N Ug
-Z0cp
b#)r
\i5J
'dxk
) zu
UuM-
5:.BU
t78"nM
A$j
X/Ja
= Ql
$;d(
Z|RW
wg(B}
J493
) ; ?
&iN>
BOug
-oq3
5jkm
}BUH?
OO3D
m@yNe
k+4%
%Tx!
CCF'
adeo?
<"k6
h\=`
+B.|
w ~:
& n@ f
AIq]
"
U,@v
uT`.2%
H1I0
QEhu'
rJHt
Vt N
A}1
W{0I2
[hc3
>=Q:
#{[fo
p ^O
b 7!
q b<
%#X_ 7D{
x?!f
Eb`!
P+l&
FPuD
#([?z
;Db-
;1U^
1k!?
L_i(
xR-#
p(7&
~NT,
EYU0
V{e9OM
o(=;6
}R0cC
T4[>c*
B\B
)BYP
QUCB
V>\5
0h0|
h&LH
}\!t
=uFen!p
`j2QHw
C \
0?}
\ "$l
lwJ&
2H,!h
u/5 /
x*s23
bu!f
tQZxC
5W@"
-c"^
'z$JD
LqJRV
yh2+
D;~DN
2c*a
"Dh
P&O'wb
9j0X
(0^Q
^{p5
8$v~
! ktl_~
s!Kb
dv$nx
5 $?Q
0AHDH
I #T
[>r"O
x 0
zc?R`'\
N@lk
pHA=
b (
m.Es
j3=l
]]/~4r
cf h'y
r' g
\NAZ
0$31
\}6_
R-6e?(b
y> b
~+SO
b~dD
,Lb hF
n;_
ap\fp
Qoq`
D+{w^
:?7G
|iEf
z^Jd
iMNW
Japb]
r]D0
)+#Z
fZzo
0] k
qP-Y
ut*3d
RuIp
k#LE
9Z,y
L"e<
R%aK
@=]r
8s[m
2 *e
#8W'
Mr8`{:
qdWG
t1;bg
aj+3$y|
}E!1.5=0
vLW:
'C*bA
" |e
:qsb
UZwP
'=0
OmxQZ
#Plz?g
l<n e
h`(f
[z"G7/
3C`
Ml]q+Vvp/
5,TV>P
:SIl
)>WU
qMF#D?
WPIetxQvuCPoJQanGGL5hyM
D\ O
l\_ u
2."6
CompilationRelaxationsAttribute
4hsp? di
@<78
I*Qei1
z3]LK
Hu {(c
bGz4
jpOk
Zg' P
~`
X&8[
L{M-
/\jn
k'Y"@T
0I@av
kdv{
IWCG
$
;~/F{
5NQd
M4k;
NX!
$FAu
N_bp_
cv@
gXI2U
'D\;
} k`%X
i ,$
+# Z
!N1<
E.;qs
BjA(
Wj^Y
do0N
(E_U
1J%"
; ZO
l#bc4"
Bh;o
,Va8
CV.\
^'sX;
xR[_
~{7aN*
<54i
]kX7
o/G"c(
9c&c
SGk%
DGN=v
<?*q
fC Z
s%P
* 8+
-@W\m
zQ0J
>\Ai>
s
qi($
hOHu
mkC)
83V]
:f+.Wn
kqxK#
6DSp}
)N*p
axjc
.9#&U
'd,V(
,g:2
jr)zA
<Go5j+!
n ^
H?^X
vO #
Smbx
z_:U
H6&nE*
u& y?
)X-{
Xj_)pQ
[G0h
? SE@
@9K=hc\
UFoUQ
.?Qb
I: /hy0
qa'yXd
}4yE
94:"
$k4<
g@UB
DialogResult
.oef{#
s J7
HdGC
: +]<
f[e*6
?X$2Z
}](.
;s"yc9
MZWI
PMZAy
qi[f
n~.a
I.66X
r&lK
DJ_t<
p#d%
C\-4
I2Dx
;%fC
"5#fv
l{:2<
? wb
rc+5.: F
5~#n|F Et
n3l~
O E"
8q |+h
TKKR/
5:ek
bf M/
8[v
C781
(L'k
n*9L.
^J~V3
x&WJ|!
r"Usfu%fT
+b q%(
$dFO
U_sk?0
YD!6
1S3#<
+;l[
_fD!
Q?M
!A *
DXJwCQ
{~e9
E;-<
QA@(
0hap1&
Z[ g
rMA^[
cl%@
>:}M
z e
\wA>Rgv
oq8f
QRY}5
Wh_bn
H RqN
9 bv!
U{-
Lu,B
`i`+
:fazV
\Jrn&
!\:`
X0k3HsiWMPElnCuAjlZzifi
A~eR
U8`r*KN
v*c[
~`L1
<zh6
YfVrp
kFb`2
Am 9.V,
~T;j
%#K7
D^RE?
u\NR
]sMb
aM L'
h!-1
qN#c0
1R57(4
]~MRY
o (H
caFKwDCpm4d6TIQUk2LXfa6tyqH
%vyG
xTJ)
-+3.
4a.5
&S+C
.c0bj
vF("
+33]t
:Yo*
C UO
E2D.
#g^n
bjn%
Hu(MC$
U(%n
6t*q
7 {
Tu)G?r
JzkB
g)%B
l@Z
| #F
gYFD%CBGK
z )u
^A on
q D;
@{' 8
m? ;
JqO*
-9H8
SNT
i|_4
#P2530)
.`~7
)!<eYS
*j@M
X>vF
.^m>a
`<!W
jBbI1
v^` d
qI8pUs
{T$Aov
Q {c
4 DyWj
DFC&t
+j@SV
MW!<nT.m\
2 U4
MO<e
.rr:
Gh R
9ws.hX
jO/H
>m$3
Y1de
ToArray
xU @N
UGlXp
a ?5p
I;i=;
rD|W
l<=+
Ov$
4#P,TP6j
j,z;O
KJ#9B
sgD#
Yj:!e
/:9!?
6a4~nyS
jfr[
N`~x
)4KX
Vdoi
q)rC7eb
]Q
o=3l
=}=e#
sQnb
}QMm(
I@{J^
]`Dn
nWD_
>z6(
><!X
;bIJ_
Z\ldHWM
~{ s3
$n,
[14e
X`{9K
D-n ]
-[F[b
cOd%
RD0u4
[tMH
1`8
;8/xY
P oo
~^<
L{(%
$kSiGKNlFbvGfEFkTn0hXJ38tbQ62WZCXvnvv
Z>KT
qx,F
".L:r
ZP<|
sat<N&
k[T
-~t
*dRaS6
bxp/
{wS]
qks 0
;v5?G*
~y/SC
q#t+H
w"lB
J=R[
"wKs!y
mqwK
VMMGn
p_c; K
%hQ
?SF*
Yx9e
&dh>
m9h
D/V
dM5K
:\6j
E$~/
simV~
Lo7{
-}l(
>\6W
7$ M
s}1-S1
GHJp
u'<Q
n_+z}
*-?}
f~wk
kSmd
xn,@
sIKw
-< r
NZ\{
-*N"Cc
2zl^
`%tF
hcZC
tklx
T8AMKi
-fDF
fxbW3wxt9AoFQRfyPAxVip7TjoKluKZ
m<9J
|*M|
2a]S
gWMh}
w(bVE
|t|9o
;E^
#3MKR
f0bSgQ5g
61U]
pV]v
@e+i
G4M'
{P*^ "
?POr
MZrd
nE&?-
t0d
=iu +{
nB S
#%u7
bCvSA5TVIRMt55N5iYPymVTOIm
_3:W
>S=a:k
fI:T
= #)p
^nIo
BKB<
YA>Md
Gf I
{4\gv
3W D9
\*ei
v<q#c*Z
\{0L
g.?wnfD
Va{u
^nI1
A0gq
0 N>9
8z I.
J <x
c7/)4
g+# m
?$G
0'R<
HBa3!
x> =*
o7:]
Oldt
z13'
h,0"}
:VDm
hq7-C
:^:Xz/
?;Vz
I|aR8
Xad
8DuW
i,0{+Q
0#o!O
j4Q_`"
@`Bo
W#v\
;csJ$
9u5P
l" uK%
d;`D
n}U%
gb80!
xG1B
N+H5|+0
d6^l !
#D<I
E)/n
I 'I
xfiM
7Je.F
Lk5N
jmBs
sL&'
<%h']LyXq
vG )N
6> C
sE1{
GvK
,?~'
ps w
Mx%-V
zAg'
ME2w;*
TFl
hZ$v1
+Q]e
rRZVh
wpfIv
!v>1
.RJ;
lpXw
XO%i
EAW3I
?_.s@
U _U
@D\6
NIQ ZX!2s-
uAsn
h q|
-5<eC
e]6|
i\wyc
LqcL
m NgUh
kZ^I
<M5|
YsoN5iGhzt74fZO0Dj8Tbd3oAHk51O8S
G>K<
`o O
u(o2
*1=w9
7/q;
~ co
=$.n0
Xudz0
l:atW
;U T
*!e
L|g
vve
jB9P6uPXduvzJBuRAGNPq
g&/m
)t s
-@EA
t^C^
h[tm7klv
PgOK!
S9GL
m1t#
Re~k8c
7;M x
{4?'
U7*f
hm %
x;Jk
DXTF
,S(x
s.9l
7g/@
SaK4q
Ar3a
CAuD
k-_}
z;]2
>Ll<
G o&
F"Q_
Upcw
7G-::
+d+-
/4n#
ZZqH
aplU
wE#y
uh5
Hg[M
oV`b
)smX9
%yodl
j.d?
WN!nG
S[rt
WO?m
DU *(
aKA"
+HW
7Jo;
]'qz
}h/3
<]^0{
blDPw'
qub=E
qGQ(
set_IV
Z8K q^w
mE-p
~rH
5 ,tQ
Gw]$x
; J2
W[= >F
<Y!}
}pp}
( *VTS
Pjo;
N C;
SE0W
0 ~
sPch&
j~KL
G]kv
^3=&
?gW
XYET
kN-
zNEh:
8&d 3^t
s9&q<1V
8D R
1xda
<$cZ$
(/P0
k^ac
6vhl
p1SA
woS?
aoZ 9
hWg)b
hwzyTE
_@s
] i[
ExRJ
,[/>
JM37
[[ZO"
v> (/.
bk*.M
ad Xgv
3= G
501r
>*bN&$
W_-f
*)]]
CreateDecryptor
{e6q^
bNJm\
Y +%
8ds"
qDgIenb1B2SrPv2Znu6QGKSC0KpagOnq66oV.resources
kYq{
/ mc
hty=
p:9a
-@2dB
#U"<
69iW
(qp{
:q7y
P`04R
_a\Iz3
Mf%"
lqL+
qW5
!}T1
g?6yk
Ma_-]!
nJX6x27DEOBxMxP0XpnDrjj1Qd2
cL2# :
<` L5
;y.20
9)<`
ichh
Y$33O
e)h?
r t:
3b?w
=z=K
_;*P
Kd_i
X 0B
qI~p
Qz`)
@T3:k
c2cC
kl`D
b>!
]eXQ
p9%<Jn
4QK6
g~W`
% @J
Nl,g
&n|'
[Rufu.
x|;*
W*C_=f
Z[n^
kdoi
()*{
UuIy
#R5r
]C Y
2b^[.
>f@=q0H
b;Bn
k'Jqcjg
@9j
7-: p
J 8>
\vH5#M572
ZirRk
W^Ce
'!E3
W--d
% DB
7mJO
%2zn[
3wZIi4A"T
K8z=
|~H-
t*@N
3Hky{
2 1A
{*8.A
g ,l
w SQaY7
zuI*#
dJ0C
{j-9
TZ%`fV
HN5m
JMk}
US \\
0K9`
ERs"X&w
!|R
\sW:v
]I(n
yJ Vo)
U4ak
GuNKnKS
-'=VUv
dnY|UQ
4xD~
m fN#\Ec
#Trp
f,f6I^ B
p [J
" ;2
NY1k9
&Sn$K
}|$F
k.??
&tHwgs
kX-
7xv (
E:5-
l[Z
qP!\
:Z $
G,_)y
y-N}Y
2hR: 2V
l0W}x
#O{u 3
@pF6
ygdx_
|.N2`
_#8v
)oc-q
!=;\
m~Vi"
0nBl
7zrL
]Y) O5G
yx\.M
C3Hy
Oel9y
__ 7
(>}
!whd
+Ysah
\;=)p
:p:vb
N?4'2
ZSV
PCcB
dEAaA
` SX
7&W-i3i
b&/2T
G<hrI
^@Xw
Hf|
llZ6
]\i_j
m#pP#
z 6n
;vk?
gwyW9
?r Em
7;Td
Jh.-
el!*
\W.
@)ts
6EDK
nU>v
.4x~
M'@b
9\|uX
eVp>
^BJ> p
nPV%`C
iznw
Bf+,
+GTk
mt7L
f2fo
.-$1
<~8f
f {-
ib:cvVg{
-x%"gY
<y^t
/C+<d
^83d
cS[{c:f
k]q N
*4d;
DI-NQ
7_y,
\\m5
PP71
o.r'
"+.L
4-(J
97;A])
)@R /
+w F8
x3 X
!q;X}U
M9 .vp
$Aujf
8J/_M
OI:Z
Qg.
IU(T;$}r
VDZ7
O^
@xse
@CH
y9Y
)ij3F
)pR%
#GUID
_j&3
DM,~#
,4HW
96}?
.W9
%A19sN
v&tV>By{
M\I
-k#*I
~dD
Lp8[
'j0W
F/@w
\"[s
p>)3V
}Je,
~ ^j
7FA=J7
FO ,S
u~7
wRhV
CV*V
Ey6=~
"2 y1
~^Ha-j 2
qx0soe
=mCe
1Vgj
a^ sqf
E<1*B{
%*|x
L#mA
\pDC_"
LVBM
gBi >
&]}4Q
MMhp
">=e
tHdM
w%9%qT
.P>Q
Y;MU
Vv!t
_iF@
8!N$6
(m*j`$b
r jR1
4t%A
m,IK
i;Lx
-SR8
]q;B
0#pX
3U G
nEu'
R/v?-
cVHIT
e J
[FUJ
F#9
FU<iK
y y8/dT
mbk[D
T:6i
k [ 6 X
5 c
a4hN
bjrT
b. ?
hp]-L
#]R!A
CZUJ^
2`y<
SHK#
&r(M
\ X6
%qx<
!v4,
p0M?
(O+s0
6'(0
u9g8
Gvi@
`hvU0F
A@qDO
&v7\%G+
-g?
tlhZI
l>F'
}z)G
B& 9
*r_H
]$2 \
!P6nY_
?TWL
YAe8
=(6 )
H( D
#xx0
(rai`
i3 6r
<Iz8
:.5fr
mscoree.dll
eYm
7cJ)
LKdSNaqeDNDAz9vaM74J9frDu1Usmh
fQm;
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
/a[YJYuW
w_L=
G$vi
tOye
}bpXP
>).
tv`1J
'\%L
g%;r
Nmzt2
8x1X
a|mD
cGnJ
a-t4
a?:Ts
G\Gc
#8T%
',V/
Z x
-)[v
E0^+
X>!F
6)JI
S6 &
5M^%
&5QS
FSdg"X
=j t
4_B:1
#M+S0
qmER
(/)m
Z4E5
:l<t
{cr~
Xhkc
$ t@DhD&
'dYPetwpoBpuxivNXcYz08CUCen11VXKL0cpF4TZ
N=-v
)0Wr$1
AKi,Jn
Z_Hb
Y;js
oyNCA
og\1c
S[kF
8PxR
N>)Q
( %J
VI~
vr{ EB
*>KmZ
f@qjN:s
U. <
VH2k
fgwT
>zYX
Fb6L2
\%v
H[B:!Y
Wdsg
}hQ
(Gp:
%zD/
S'>d
K@g1
WZy
*hJe
xR't
W8rK|
fmAf
[{n2:
OQ)o
bH? ;
zI5$;
%?Q%
C=S{
H.}J
XHl]
ay%mgO
l|UX
b,ui
lPRm
HV(vRERJv
1naVH
+G96
OK-RZ_
y'S_
XW$P
S\<<
1~S4
:*HIG
5!8S
S#h99\
VgGPn
},Ac
&X a}
>$5+
t 8<
2~l\
oF.A
*\J*
*xU?
LTmKA
S+ M
R8`
~ae2^u
"}6q
LA#gF
sqc]~\
sVW3
"Y4C
P(O-s
v\ ?
[YBi
"~<U8
gh,4b
P9){
:{V 9
u6~z
3UM,
^.in
H1t.t
| =Ylg
uG(IB
9zXzW
D}M>)
7/ t
Gs{.W
sBk%
z/Os
%,]-r
gkb1
W_cc
HqN!}2
{O4M
@jL;
RO:8
[*:?-
~^=cF
"eC/o
%d;q
_{Cj
CxIO
G PY
;*[7z
'kRbs
rqu";]
aZ|R
mKB
.]GZ
3'CV)
w\XA
NH o
y>Ty
2"$@
lqY
&Jt-
\ |[i
vQaW
K5W&!E
4XxEN
Jhoc
e" zr
? FkW
'*#2
wMyHFk
T6 a
7d1 Hn
W(oS
#RIq
O_7|
.b.c
h7|]
j^1F
X>W)
P'A"
aMLh
Eu).
>=rp
i[Gu
MUq6
2VroC
AppDomain
( [
G@4GpO
Eb2
C 5
@h rW
oj=I,
>0$N
n& M
iK1K
m*i~
vcKn
Y_p :
2>n:
j$4GKV
~3U5Y
kV"Z
"$"?t
Z^ejw
-Jk.
UQ"Qn
; q~zG
?V|e
_mBa|:
dvf1
L&`k
w '3
7.9m
k_0Z
SR@#
^OIC
\,O[
, u/
_j %
ugyF
xOV^
Yd&d?C
|+jx$
2lCt
F!?ht
V(jc
@hvl
wJj:
@5?5u
hL<t
PIdSh8(w
2N"=?|
/^3>
HY1
XJ'"[
6Ff8
8Q74
fQIYBK
hkAk%
^w_w
2EjW
<K92;
97e$!
Z6Ky<
G#$\e
oG[R
Type
'U)B
rW\2
v7YD
;,xy
=dk<)
EJ T
op_LessThan
qZX6
xFH+t.\
LQz
I@Oq)(s
Bw,]c
5xxy+1m
<k 3
;X(1
5qTP
=|zE
??C<M
iOA4Yel30MEtPAPAmxMqsiFppF7EP7Rn
jm^ Y
{NLnU
Ic U#
yLnVB,
G\yn$
r/[VC
aq{z%+
Yw70
|"9
Nk85
Ft)pC
x$[Q]H
BD_[sG ^
*4>s
~eO d
kZ9,
Ao>y
wbu2
~g>E(g
_% q
Se?zo
RWr0
LaCqd{
$fNZ
a#_(
xXgmj
tLza
|ti<
w_;w
yOCF
P~O:
)MpO6J
T.t^
Fx}-
*a?9
$a)$Xw
2x.VMG
%V|+
QI7$
{: N
7-(
I$sS
b];d
fe+N
i(a
a?:
yAl.
"g};
^A>H
Xr([
7jC`5
",Gm%
b[|6
L7%WX
i=.j
/n^<
#enTD
I.?9'
_D5
)w'CVAY?O
6UTR
[>wX
6 Um
={{a
s1x>
;o7>
2k q:
.u~L
$Ag.
@rvDd
Is<F
e"+r
BNiD
`pL4bt
0-eW#
D 6H
7B\Vb
=a.?Q
X4ZQGbN
?4G
IF^0
SkipVerification
W8AE
;grn
r:vl
v7- x
|d1F
6lvS
&5].b
Dm5!0J
aY>`_@
75n" S
A.Sl
vb}%
XvdG
o]I#G
(QvDw
~Xsg
Cq}&P
1m&U
MJau5
Y6OK
!`-gL
ne5UDr
):hk
,1q!
1X"<
)]LwT
*=}o
f^AE"
;TwN
bv5B
n9_xk6
wa? !
YhP~
i;8%v
WN^lO
kCrA
wS'W
`.rsrc
q u}
/SL=tPU
F,|a
bhr0 '
ByCE
B8UbY:
WBzO
.\=r
vIQ[
A/ Hg
Zx[x
Fr(&PD
ypy`
xTeW`x
u"A
"|~] g
k~AT
]5q6:
S=Ll
z9_d
V5y`
E<>
j-aE
pv8m
$iV0
CGb0r;yH
uLol
PH]\
tH )*
k8Ng
I3-8_vo
8@ZiTn
gxA
q|:X)
I8o
sDov
AQi~
C@nq
_/Qv
PJ aV
G5ix
3- {T
!bE^#
ytr;Jx
%"1`,
SIVC0n65HFc3uO5JCK2X2W94WCutMy2
i2LL
V3sk
Jk~5
;k[hNeR
OJ2*o0
uEtw
.a^\
$Bn
Vk cs
*'\
2tPzb
)&O{)'
wgD3S
gy&E-d$
e"YB
<D`P
|~Zrz
OR%;(Y
Apv+=
Nx4W
<:cI
D[ 3
nR+0
-D;2
L)|2
fYq\
~7k
p}r6
6I50p
{PhFi`
>G-?
7^r1
E w
;mEt
dy K;d
UI6-0
e_ti
Show
6_37|p
K2wUeM
ZM m|
=&dZ
]a]'
O3B@<
8g#
qm]1!
OEo/1
3vHa
uq=
}[2{
~Z&`
u<+u+
ks9cw
3@z.
;YGRs
BBr>
<1uo
oW7)
:k24
P )B}gHb
{E =
ooP(
'e{G
J |Uh
a*si
_i]Q
&K4u]L
k45\
6J?6
eWrg
9e dO
DI_eK
9P{(U
%iOe
2bJ=
co5M
*tu9P
RQ=
U4.E)Nu
{JVw
c{ <
;n: ~
K+t(
4e3_
$]9-
dxAj
`ZtU
oiG^|
*%@_
OKv;
-T&n
zb/\
2 v;
clOE
T'k
;(z>jK
RhG_
F!i
p+{9
P72ECdseQ07uBALkIDBndeihWfb9l
x%Gq
pfC;
0n~>r
+jWf0u
Y-\{Hd
+JK_R
}72g
N`K<5
u;|O
2+KM
#BT8
v&6>c
0V7m
}yen
8 >L]uS
fBA-g#
[%h
0Cu|
|8[d
hS_~7
ohH.
s0U N0
E&D <
@ cw
J_aN
64ON
Q_Az
Z9ZL
SeM]
p&(Gl}(
nevI
>w Q4
X-^B@
Nq=`o
po=@L
oqC3
~Wu1
#Strings
wRtU
7vNH!
Q[ %
~/n\
Tn;u_
1Ogn
l+4<
izhYzPeNUjVaA7uHKSo8w8JbndZftf4i
94_+
\H
0 T
! yO
KB0=p(T
h6>2#
c|,NJS
m,G%
l_[}7
AEL6c
r|f
a&h C
CI,!7
/Oj b]W
[7bC
.EX7E
gk ~
kp`
e 4~k
4q'/
}g 9
|/6>
1 |f
W9o-
ae2!S
qvLSTZQYxmc7BbSScnK3AK
\E[5?
$sgmU0
q* F
JA!c
5>cb
W4;<%
+_.6
Td1[
*m '
&NifP8
uSP`
]]hr
fR }
Uzy]mJ
F*S<_
19E6
XxuE}
x'91
YC&4
RIcS
%I;7"
`E|n
v+u
+"&5
W|f*,c'
jo QdC
s* F
g)@W
KAaN
#m_G
BHE2
}ojb
$}`<
Qb o
AZ$et
&;w
# o.
!# 3)
EQ6a
~,B'
LC=x
*m9!
Y]C.)j
6O$E
woH GD[
c1S>
C{-B
N<P
C#(HY
jnF
R}c
/r#
25I7
{7w~
x1,^
>)"H
XxO:
F+7G[
]R~|
A 5`
l0JbVD S& ^h
B(!qxM
9F.K
K_1)'
{85N
(L~(
lamc FH
rQoi
r:pV
',A`p
Ua=i
Ir;
QabN
;:=k$
_F|
2(RY
M68K
~ P#
+WR_x
oDD(
KLZS
CJo -r
^"]d2
<no_1S[
+k1Lm
6.A
Bf(R
.n =
8"I#!h
G-<'
(*]P X
eW=y2
jjCQ&
5B:25
rW\6v
0SM~
Fd)<e
'@SX
L_upH
H]&E
`94E
,1o*
k"2*fB
Z *<
I $x
N_>#
eH|] K
)6j{
}ZI%
z(ZS
+lU N9
s pDg
X,M}
5S9N
$'/P5
(2jy
Pis @
-,}Tpl
taoWZN0
d y} jZ3
>i5J
$O $X
d9<}
]y-E
$CCP
Usm]
:ql_$
" k>
SE dB
*<D
cD $e
kk`s YF2
o @q
RS<W<0
g8"N\
|t3A
z8`Q%
-$sn
ZOY,
YCCr
Cc8:
u2T#
YCCg
MethodBase
"Gv
yu'D
)`F{E
! Db
dgT[
$!I Q
80&
~3m"
;fs#
Z"2i
:oBj/
g&%
03 ~
;fW g
),U7q
P) tP
kHf+<T
(t_n&P
Q@{N
{nHc!
*kEa_
I8a
WwHo&m
>>vi
]gZ9O-
@8Hc
'> 7a
1!)F9
^,2$
WLF
@19`
,E91
\@Oz
[p&b
zM).
3x%8
$/\&
`@\r&
ni>2W
hfZZr
eA9g
<[Oug
)dYK
fni >T
90}%m
YDDG
2R@s
{Me-
\ Z2k
]x `
gg-L
q@4-7
L=y b
*.*
+ZRtN
' `4y
X1 "
k/Z 5
K1J-u@58
"AuK
K>&d
M)U%
vvxW
9q*I;
b/)^>
e+Px
L?Xs
)?Qf
7sSO
r]<;|
9qqeT
bxv
eJ !
=GeJ
YRd[
;q(Nqj
w3+$
G(wP)
{[>[
T~\ c
^)w0y'
v*8O
XU QI
/H6G
/!6F
P%tY
jY7
M:eeU
#cXlU2sFZzDMSWKxpnf5kArwIYV3nEb9zml2
e*W36
xHgC
$-e#
i$W>}
AXC;y
-Nc0
el'n
. ~%
=?OpK_
QXCi
.L]D
'!u,O
=M7>Ex
;vq;s
r.Q}J*
s01fG7ZebOh8jykHqQSxLmzT
LU]m7!
l\b9
]75>N
g g,
a|Q4X9vXF
#V -
6y&~
08ot
rq F
h%4V
U5@b
E89o
J$ dv
?i T
qil0!
Jb?`O
xI(&G
0"|7
$dC2b
xp'
|LlY
d'5l
+&y8
K3?5-
mW'^
"\nf
?Z:R[
eGR_
Q;,4
M{%y
3G?Z
WkR?
%!R-
pf[%
{R[U
@kdg
_tmup
"gfz
GJ}7y
n*=)vF:
VD\s
8XE0!|
X(Nl
XxbW[g
EkE
.ctor
x8;.obY
I{#>
;NEX
>xscUKA
6M(/e^#
Ia?N
y1 3
+&y]
}O10
,<_\-
OZr-
cO^DO
|*f{
mnyK-
j#9Ze
$UwA
&aun._s
VY?&]
v*%.
4ap1
2_1^N-
t'uj
x\2(
u)4]i
an?pA
c7Cb
.;c\
dA(:
gMA>Mm
;y+c
T\*IH
Z2t
+am)
_ij<T
$:5eH
#cO$
09?W_b
-Q6&K+y
q@"H
k` ^
c>Y+
jOj
H:-
k> 8
Cyl@
-}kZ>r%
tBh`
qF8%
FMs9
qjt
>[%W,@>
Y4(J]
OE:M.
KB| l
@.reloc
vd:m
?74xE
PqnP
!6_r
U;&b
ZS.6
ouA"
{@NL
oGeE
!OYfTRI
x*i`
0aZ5
x%(1
#;+*D
ygl.XR
cvvPAnKE9FRhnnLNK6CplkJn
!aZ=?
p2,_
ND?87
+vxZ
/|8
Kk;9
O@t5U
b?w%
Nf}O^
)wPu&
g2Zp
OJ]vM
ue8c
'/.C
bW)C
x2:.b7
p.ng;
-x #
K8
CnX1
?YQ`
!@co
(@GFM
0Y@N
r)$t
t[GX
$4"-s&
DT G
Z#rY
*# {#k
{$)qMp
t(*m
mrRFw
_-A=^
t<Y:
)ID|<6
CI :
a].}
"?K'
@2/\>X;
pzww
$bkO
A:7@J
VDE:L
X8CL#
*!\eM
u3o.u
_5/t
ec)#
(F&i6
bbx]
,-&Y
x o7?
Q%c#6k
G4eBq
!2-p
pN<z
U`WFV
}>HO{
kZ'fcV
3&;m
0sqZ
Gu=t
r +B
8}y=
Ni"u
K Cy
:%ZQ
SRcT
zt[EaKm/
K 6=:
W FW
i]~%
H2[a
*i(@74
mcjL
8:f.
m =2Zwn
K=YB
N_<N
Kz(
}wg#`
lXK1
KscQ
+XbP
3yy=
[@W48
5=r,nj
9|@ s
18m|
XQQH[(
c2_n
)H|*
mFj.y
D4c
G#]s
EA"<b
iKbzRB
=ok~
8ZX "
k?DO=
_-|US
K"PE
xYMb
sjfga
|d.
eEM,
}pxp
>| c
qP
h(qSKT^
X@*Mu]
@DnY
cqa)!}
1h"8
O 7{_
*h0B
()'hl
dU@CJ7BP1
Y@E7I
-R@_}
'5 B1.z
IO? mJ{n
>^;6Z>
R k
W)ii
L{*u?4fc
u"0
#~ F/
:-$D7
<'[]
r=y_*vw
q?lXm
POGc
" DO
BcPiyJG]
smCN
eNtZB
KHF"UyI
uTBK>
|y r
q)L9}
Y jl
HD/^
ZdC_
K
oZ'L
}U&v
}({B
d/@
jyFJ
Rx@<
mo&%
Niz
* g%"
Lf0Zo
2$D|
HO!(hyX-
7y[}
8i[ct
A{M'
. sH 8.
tVU!
]VRdN:
#nVx;`
`E]2
Ku@
S[*C^
rO4K
6`nI
-D?\
2!B
yf``'
]mzXV
>ba*v
&}$\
-3|QAu
[?'##
nq1
)cMG
bKusZ(&L
/L5ww
%eFYoYa*
c!j0$
PRx
#4 q
@JB -
{j~+
0>?!?vK
?7@7
[*mu
cDnX
TDWT
@ fG:
))uz
]r9.y
Y=fr
!0mg74
X/]
V([)
4^/<
asa)
A&h0
`>j
PVt;
6s
wUp,
rL?Uc
(o40E4
<Q:K`
*fu
>2LD
eY70fFoBea6koT3S3UalYXBzkgeK
xoX(
e\zH2
js0T
5E$TU
>Z2]
;7Zn
QCqX
185o
~viY
)Z$j
O }
URWwQ
tP%aWP
"L8U7&
da[$
@Z&-
E( z
>0^\
-Ki9
0[]_
LZnX
EpcPx
DV! C
|P&Bx
biN$%
Ue8
J{ !a
.ofo
PtvU
f \%S>
}8;:!
c!6Ql*'
i5V|RT
*:p
"Xp`W
P)15
:@(B
cy3C9P
C``Tn
xw][
#0I%
E);sU
*["
wb\t
B}A/ M%
Mq3;/
y=,>
VcSf
! WG
r6&m
[J"P!
+SUo
)'3n`36
N d
-w_y=Yl'
}>c"
D'8_
Fs,&3
2O Be-
]s q
(DUH[
n)2u
| <
t6 0
c {|s
x7O`:
Sc0hM
GN L
N,:bO
+6T[
r?sQ
4, c `1
*%Qu
t;jM
$"m G
* $l}b
_3O 5<
Z].4
K`Je
|\|yE
Ps=
Mf{G3
N~~E*
zF1w
nm2_g
0:$a
z,*,
aY"N
,ndy
_a~"
2Z F
EPp?
n'^O
pS*a
.^KwBoO
C.ggl
vhb__
'=7`_
22 x
5D4\h7
"SdK944DfmYFkReHGr6wA3YajjRKnBiGvRR
*QV|\lV
21*>
_ o)
rs3|
g-{\
>t#/
:nJ#
0]sE
@yC<
bQjUrHQ
yGLQ
dSE>
5b2 V
12Q 96
IC92
CbMf`
GsHbH
:J--
r',77
D|P
"39St
_{&
5^3:yo
! cIe:
jed^
MFV3
G7cL
;; {
$RH^
/ *T =
-b>l
q.P,
>k|!d
L]v3
^4 f
~jra
k~XN
N]`\*mR
a#:@
C[}N
'G#4
V/vg
{1x
w\0j3/8x
]e-I
6utI
%c`Ra
*GZe}
-riy
]uIo
#G@r
",q
>i T(
'kb04WrGsU4R6dpMzezBeCFtNhom2j4ueCzuttjL
Q l
}Y,@+
B.J)
U.M@
W zx
&@bX
w=8-7
[ow+
BO!x
?x CJ
Ye/9
kmzLq
4rt"
km#Z2%
EF{H
yco
] cP
V[%j5[
/ &C [
`J@wM
h#[54
:]-LA
( ws
>Bl3
)zg}$<
+3-w
2<[o
{ u>M
M_"{+=
6Mep
nN1K
\Q[
lB*x
\B.1>
}71i<j
X emU
v>fF
_wR^
u>3Q
QJG}
[=e,<il
= M`s#^R
VQ-A
i]"h
[U9[
wI3#
WB>
Hq4m
*PnuX
MLc0N
neZo8r,
!$k0
UA3:7
sruJ
,) s
:t `
z \EN
NRPO
>!`3
BU?h
Q2@O?
M`YB($
2W 7
$3'"Q
2 -]
Tl8!
2NQ5l%_NY
Tr[U
%JgW
=R[k$
;la,
!mOWa6pnvaImZI77aJxo9WtoZECJwqfl3D
7R:qM
v{|!aN
"/)C
p}k-
X%}Ub
) .P'
rcg
!(_1
n=o2
FC,(In
``cF
6et
5]KP
H{:}
'i[x=
Kr-e_
X`5J)/c
|+&/S
oAp5
i[.GM
k| -*b
gsR\B
.*
=DTx
@b*kt
5SP2b
rz w
J< h
7!Ta
:0.;A
vov
%p_:
G?!b
s
puX'E
ucxk
#Q8:
dxZ9
,{3|
NS,E\Z
9$m\
EE2dXJ
BiRm
^>~p
+3g
l\Y
-/O "
W1'2h[
q |}s
vA8~
G*N ?
f;4
Z`#tc
jmS7
/ e/
D|I
mFC\
k0uxt
16AQv
Ebr8
@8{YQr
W)BOz
`GUJ
;\$^
`$@>'
l]4@i
zZ5Oc
%i]'1<t
R`1^
n`[o
|4(y
Y* !k#
;>4E
iPqxSjjvjLnnNHw9h64xX
'BwK
*x;*sQ
6((~
CDtg
*b;f3r
DDZ'
?gb ez
_EpD
&:>]
7++k
M1T)
0.2|z
r)wd^
/IAU
+9oR
^{B
E@o[
-SCQ\
N%}i
^kct
Lz59
lR"*[-
!Amml
@?"?K
"@1d/
B +8
ne0LH)1
Ue!Q!kqBw
<>!J
Avkn
Y%9*
&Q4-
l9(MJ
6sa7
<7L:
;nGOM
RijndaelManaged
g$(XN
"kFp
j~rH
iii?
Yc I
*}3%D
srW)llu~
BBRy
n~?A
c|T3
9Bk
GJ7@
h dP'
Cc| Q 3
2m6S
fFL0
b\)ig
d md
GXG3p
yX4L
4~(>
Fm ~-
& R'4#
6wNh/
TWLG
C\<h
7vm2
+ hn
%sDPI
9Q!X
85.]
c >t
D_I-
"JG1
>p@a
'}Jr
}@W$
m~-<\s
qmDUD
d5!
+U9h
N}`;}mqn
M z%
%dV}
f*A UJ
VV7G
)O9:
}2@E
3'?Fq.z&
Y.,A#
.U#\'?
n|FP
tfSI
vaRe^
<oWI]
W ;`
=;]
s&-c
O:XJ
;[fV
f77
8AV}4
e0U<
m;j?
0mr/
gfC,%
RSLD
i&uM
_*R!
-o8<H<
i :J R
&c'8
*u F
[1y*
'9*f
KCyOfgH
vdvf
Hbn
/1B[~
u!R2
isz}Fw^
Q?}wm
- f"
'xAV
*Kw+s
&Qm9_
MC1g
D>xv
q\[s
)re>
93%PWs
.N-A1G
K^jG
JXnx
[73wu
SDiNw
^|&}U*m
ju a'k4i:
pE p
oS186
668
% Y@
_ndm
EYPx
'v y
_qx\
0}r6
<&^ps
5-_TpY
KK j
)y_6
A]6:
V#:wM
1>el.
{1R1
]<+=x?F
B(Q]
,;?
uy:L
@I(H
!i9(
u3CVzD
5UqT
T0cEV
xQ7u
iHv"
YMNA
0+jb
1C K
M)I1#;
xYLg
%V-{OO
p9_j
z|I=
X'Cx
C@{,
Og0L
Cut
kk>av
9.sa
{ nD
<Pw@
q}MI
xPw@
*;D?
8!#?!1
#..)
h)\z~
get_Message
za`
+@Z*
gTsB5
}x;w
6$zb
5{Bi=G
M|S#
14d
xhkA
C7*q
u{'QR
v~=s
psT E
tG{
R;W;K
0P/Z
!xw"
v?,oJ
t)S9
3hGb
6O.`
00dQPEW
NG%C
9Ki=
k3YM
}=7X
t8O7u
*U<_
cug3
ThT&K`Uc
I~.{6"
Ks'J
\hWS
"BZtF
,&L'B
_6ZD
BY)
IpuM
K8k3
PBr0
mCC-Z
;_e.
W.
HCtB
p[tP
RNYCh
%7uB
j1TX
G RM
|(\*
&LMi
5 &=
QL80s
It.-F
uKC.
"dVQ
z(W{R=
T ?h
zuS>
$YJ
AX[q
Y="1
v9}w
7]7U&
x3/-
LfPd\2
3pS\X
n/ 2
$VJ-
{S'N
+\-}
9 D$
;6~
Uy^G|
PM I
]UHv
Paka#
{T| b}9uO
s[k#39
>c2HI
2>fo
&6w]
Xv\_
l3l5
+08j
[PgX
B]8O
ckd9.
f#2&8e@8H
>l'(H+
d^ n
U2W]
kTr\b
R7 hfs
>"(w
_a5.V
,B;<G
GAW0
-';.'
(Rz
=9E(
A"OMWS
FaEQ=
2dHvzs8
j"K&
bLN)
4!]z
!r)K
auqS>l
-*[>l
Rv.JH
(b;mh,
AitB
5W j
VRrF
lo 9
ml4F
z:sM
gSLp U
T#S
b0ws
:fM u
ZQle
At`=
vpY}
#0qQE
+* Ek
\%:?
HOtM^
LP{3
ds~n
E\m6
1~^D|
YcMkC
GZRZ
_ur~
i92>
ibXZ
r1v$
_pN5
+p*}
z Fu
[v2%
XZ1i
1s>h
Kd&
WDxv
o2Vb
&C@ K
}]Lv}
UW&E
v#Si
k8<O:
@!ud
Qj"BI
"P M8
6 (F8}Xf
,f":
@a1+!
~8|x1
"uf
(A(1
5@}7=
;F\-
/e>X\
p9:N
Jl1cn
!+ 8\
-CVt7
6(&q
9aRq%
O`m:
t;.4
ba}^
,?>O
e/ 2
CJ%j
r :z
`MO1
[bE
cx!X)[
b[?^
i&P(
]{
?H ?
"[Z(
m)U\
LhD#
c2~D
v_7IP
cU\
X\t
B' X
kT6,7
hKIV
r~9.
.^JF_5
bgol
*r1V
>&`]od
,<4tg`
hw)4
7 _Q U{
^nf|S
ex j;eub
pjWk
@: 7
B/-J
mE3\B
9mF 1
.CY{)6\
=m|rK
KSVm
&T ,D6
i@]^z
%f#_
`9*Vl
\c]Sgio
rSq<~3{k
$52T
\3)!d
9SRj
(PkP
!Gr6
&Uyo
/,7m
sRUO
3K7[
xl$X
-d[c
AKC=
C@^%
!n9IS
SVB{7
K.*"
Lu X#
' *>
uL3
Fj{|
CZW
_&!s
$"ti
C?/2
_1.x N
l r
60 '
%o>(
@;?AW8
)h2ao
F1b
;OZd&
4;dw!
W~%M,
K>jm\
=69!Z`
6Fx~
?\=Y
]2x
e1tF2
W:;LZ^
t Dkg
)99b
OK z
DN.4|
fpqG
+4j2
1Y9v
z{jK
s9ey
}T=-q%Z
3\ ?
:HP}c
aO<I^
U!Zl}|9
a_8+T
Z Q(
fWd.o
aK]9
apJ+IP
L1)L9A3T
,5e$Z
} /\
sfb!
cH4W
xK`
|Z|:
dTTn
+&gP
e5;?
Y=A
a/EA
B1k!C
l]_Q+
>.Qm
12y9R
;tiq
"98".
"{-;
-Q]Y^
ilIx
p t0
yB5s
?1KS
wi[Z
Wy -1bI
<q!X0 y
;k8|n
" lG
}]-/x_
-T-tX
qfW|
W8Ul
Ob~n
7oj
47D[
P%hj/
JOABj.
|O
P0 *
@3w6
,bZ|
RVg
S/` 5(
}KE
XbCq
}'7us
9_I"
dK0*
<qjH
9b R
7;8K
;Wx1
[`FW
dxqM
8Msb
dq&"
[:Vx
1:|l
qvVk;
{U p
\ @7UQYe
=eS(
;{d.
1A-S
h4O[L
E\\
Tf#J
/w("
m?
9WSLZ*c
c(Po
DaZ@
n\M=
Q*Q,5e
(U/c
zatl
X7!5M
<Pq>
wK <+j
D6[(
\G`;
2N^p
QH? l
!:k^
/Sw?
!94j
dkEu
)3@
].n$RA'
qE"UQ
N]u7
p=]:5'D
mkHvxW)
Q%dY
KX 9
^E &GZk:
8Wf)F
b-~)
2|:Wf
}M}N
wdmx
0g6=
CCyr
6xcbRUPReSUkyoI7vhQmnz
4 SN
g`'s~
cS:8[
Vwg?
/AUC
(FF(
w`a=e8C
C4ii?
!u693ds2ZJgOsYp7UuBUltRjHn4VlWhjE6
aLkg
};3h
!&X8a/
x6^&
,L(;
`x]!
6{9
M"aN>
rm}pm
/ Yj42
)lB/
@KO
3: o
D\B(Zj
6s b
zUdm
m PFP
c.y]
r|g hw
$&GPe8
e%pEw-
OqCg
zq] o}
g@hK
"n+v
) l\
*Mvg
fJ4"
m!@(
&D<A
xDjX
4flC
<\xO
,^XJ
We L
}2<)A
|#a
Ir"
U6y[)
aT W
Hq("
A4ptb/
U%Wn
0wli
`mT:
tJZ
;']=P
YOTsMRIFREpquY8IFfn02eWYWdgQl
/dz
`m)T
WU? ^
q\3rW
[47@#+\v'*
oQsu
'[8
ovn^
_pLl
yOB
v;'=!
*G(4f
EHYeL
9!E
B njC
\1y"
{]h(
9\+H!8
aE'OsE_6
z07:
O0W|
~4% K~
m`gCE
RWQm
Exception
}M!f
=- *
- Ft
D-5J
7 p M:
+A]JC
Dr@-
$3D54
U'{[Y
&C\ V
f &P
n`o
V16I G=
JsW/4A
vFp]
bKa.
X;oPA
P4SUI
*v'l
"Q}[
Qr93
?l8*3l
K%
H>43
Iv-\
bW`I\
*(Mgp
Ed8<l
=Vv
jT@O
qH])Y
o?be
i:'V
| c%
&,;Xu
MpX_
LKO/
:>G<]
iup^
3lT2
RV+|
xEiT
WzP#
Vw_,
(N%8
!ha?D;]
0OFUn
BcH+
!rBz
$J.~
y^JT
*0}s
R IK
{z0KCq
@BB0
^7\f"
F="J
I2Ry
+ t-
w z
%-TXn U[D3
f1L_
|Dp
1n5m
bFF(
\ 9qeC[
:B8T
AeHLH
7=K
$4:51~
[,d5
o{dIf
] %p
.{"`
_I6El
_5-Mu
)6Q*'
w}z
.fv.
{l!Y
G^PS
4ww#
rJEO4O
+>*mv[
2> F_L
]H7U
)m/M
hIuo
?G6v
U E+
dY'K
2|r
A?<q
Bl4gtu
emZ`
tEC-
[nStYc<Z
0#C?
;"s-
aq|"
D#!y
i^V /+
G}BU
t(,>
.H238Y
c9F"
rMtOc
<VdlH#
b8lH6
R.cDg
B5Pq
c?^
+Zip
z&U'n]w
]x\V
(O+`?
KMB>
IA4X
=gn.
D^=="
%(0"
V|f",
< OPg
<Oc"
\kky
OMl9
P3>"2
_CZe
"r,W
?*w/
:"r2i
)lP/4&
tR8eVNO63tZTkheteVNjSGLpO1x
`y +
m$OE
=|jzmu
NWH
V Pq
[WQNBZ
eA W
n*UcR
y` _
Wx)7
(TT_
$B<
qr*C#
jWDy
JhCi@/
0SEqOY*
"z@/K
Ne{~
Q$ P
kzSz+
eHU.
6-A>
%K[e
lZ7-V+te
<}9,
gu;:
yRl2`
c/eoxa
%!z,
MFmp
-- !(u
vdz\
:pYo
l-ShY"+
|v
HAkP
7#5-t
h]27b>
*F:^>
KhH9
o)B
?2mN
F0Cd
NJJh
X3qEI
4^Z
V|%L
}@*r
A1G*
5MEUFHUU0scYyB1hbXjW8F7eaU56I77Y
X7
@/"?Tp
y vr
s6 J
Z9z5{<X
k/qv
?HB\
w~s]$
^[qJ
s?Bl_c
#;L0
@`RL
7Sw_
6la
jWdu
)%!X
Yk`u
R{!p
gC?]/
|/M*
`:1nwm
+@U.D
oIYr
%c|6'Z
pG>y
TS/\G,
fs?$
E2?dC'
}e0M
N,_~
c|mZ>I
Cl 9W
d0O1
`ngE
T %sB
CY A
a~,}
m\sU
]\VX
5pb
*fG6
7kd&
a}q\6k
re}Eq
DtGX
jr5S
~y2J>
G1Q;
|5{1
H&7B
FfOALJ$d
T q
-$#
F+^m
*Qt.}
&)ck
QUZF
}{.[
D<&1:$
F```
vz
c0^s>){g
iT5L
k},(
nvBP6
(3DA
vo!y
d#]
;sl?N[
S!d=
8Hi
~f\]
/99
P K5c
@2ocX
"})cl
(Z C
z{GNy
C c$
Q'"&
6ql2 d
@} Y+^ n
c i:
K! V2
L! 8m(
d(qd_X
s2L!8
? <4'
)1X!
PB~G
1Dtk
F}CQ
_:P+
3#Na
`6j+
kjsyE
XnY"}({L
<J}JR9
>FCz
nf t
JnBJ/
>,KdI;
QHeH
48x &
.fS6
&SL4
oZh
!UPc[
@%E<
@: )
Y>pD =
$P`2
D=A"
@`/{
]9G4
ElA$
VC]@
-Z,
WwCX
pk6 >_R^
(fPr
!y0`fR
*5IQ
KVAe.
u\jit
System.Windows.Forms
!)L!6
-3,(
3!\e
iLu
A\O2
\E^4_
$ y%
a6SJ
5n X
`l{.L
JT>v
2T kZ
D~-m
r&aK:p
sRzw
IL\,
2x9=N
#s/{%
%n! ~KH
S}dW
Y#X
NZyCRL5tJ8EfHxvCi8gPRsvaoZhcufA2
^-r.
dP?
4k>'
U 9E
V"xy
jg'v
SeTR
M;{vN
@ G/,
-j[n
m7"R
ds!2
TLF--
<Ep)
wv_.T'
??Gt,
\M~`5
N4{)
y)Z@
6VW<
$7J\x
|{5H
}OC,^
Uk"d
Z*f*G
[uu*
EHVo
5QBU
A>p;
/Ylc_
<3?T
,+sO
#gE`
,EF!
620N
^Y3^]
qWyW
F5%CQ
&89]s
,+fD)%
t ReFfU
O/L g2J
?@HX
#T7
]0J\
Y\,I*C
FN+W
A3Zv
n0Bn\ X
rQ4S
XP9yceg
aqB@i
yB!Fd
MQu=
m>_Z
A6tT9
(+S}
TQp*
p)o3u
)=>dG-
XQ}w
%>c:
lE>
derp
o:.x
6+,
XL^U
p4b 2
w<4k
.;l/Eb
Q.Rz
_ >U]
.J#~
"wkw=2
i'*yz
>+heC
pevC
|?W$=
V0EC
qt,3Qx
o@._
?%]{
a"4d
uSmg?a
}+kDg
Nh82
q~,J
FI"
e!>U-
h QIID
dY%2
Pu0
-G@d
B2-w
1pDDjL
r@v=
BvyY
`'\D1
T@ks
*]9h!
RJh!
-tli
-RV2c
ub6y
7e2-
X)mk}~
/]Xz
s;c7<1
@CB(
R vu
KDrA
qBBD
sH,N
(N|E
+^[Fe
I5-
&=/c
cq ,
2(P>c
"{6@
#* ,
AG `
PIS4#
% S(s
ez.SS
%JN_
w)s#M
QB%L4
].SJ
gnLS
/!Y`).
System.Security
X> <
LUsp
S *R/
]1pX
3ajnf
`p^(Bw
ymr"]
tQOX
>DO[,
GdE
FHSKX&_$
$9'd
^-Q3
G1_LH
bWoF
y GA
T(3
^z C
.2E8
*4w&
+<VZ
)\fB
gs+/
6f=S
XgDY
tFYc}
waru
_Ij_A':
`8j{+
Je7
/i +
imN|
E}N.
s#_F 8
)PLO
KaiQ
5pYL
z4if
6)7q
!9$Kp
xw $U
5uXt:|
mr1b
i@/L
FY0:
P&FY
v2 "
^aGDa
Zi
ToHN
b #L
"*?H
rm4+
67Z0
aBRf
yDp`g>&
iC0&d
-Ik1
l;'p
7J!~
$AVH
4 7nw
goxl
W)B=?
`:e
1a|>N#
`Q==f [
.UH!
7Z@nP
-hht
/w M
{RUS
A}ZQ?
HuMq
X2(`
NbO:
QFjf
r(Nf
G}v<,
76ntR
UoPHr
/6z }vy
dF9E
&Blj
7Xon
PyuZP
3'V1
oxL%Bm
FWO/
A&Cl
3Jf4
w~90V\
^%DY
{#_E
#7Jy%
l=5`
|fv$
}KO7
u'C#'
&-Lq _
oX\'
id%a
i@lB
5E\J$
d$!Ly:
+N5U
2#j
EnBz
<@(
\!=G
@;k`
I1Mv&
HjHn
'>#6
+N5z
yGTL
wJ+09
#7f4
GLw7
^9!=YkT
3<Y+
!bp1A{
}wwx
2%e+
q%LQ
)5r)
4<CG>
Aqe@
(~B
1Sc_
@ gb
@z./|
j[~O
iK\\
/3V=
Y Y2
+\YN
U:(
M, 6j
W"n]
%U)j$D
#=cDD
V> ]
m,1?
Rjr
D4n;O
u]w:
eE o
7Z$:
V^?3
l cQ
)D"f
8=5&
T&y!
[GBNF,}
OQ7
%. BNC
n:B?
&IeCJFCbcK70BQYgDEdt5hRuYuXedzWRpmFSAh8
{$%}#?
\F@:
Ela"+T
jFp}(=
\iw ^%
Y"q3
N}+<
g=Fq
ng?\
^fYP1
GS {
TWq!
BIWu
z*dA
hpZ<
K \uk
{(av
sf6S
>.h}J
'C7q
BCXJ
Mi}ZV
"WgFE
lGd
7;(Ja\
gMz"*
u1=5
)OI{^
](;N
X;'mSZ
Spz8
$/pO
CJc[
e.Yi
MV4T
Dc/E
>.J_ ]
n:BA
'")t
f"?W
xiuP
_Wuv<z
fCY"
*P/Uho
}*)}~m>
&M?@
wAnD
M{q|
% P7
zY5${}Mhc
rf,!
> r-KdJ
~-'JV
)PZO
,L3l'
%ZntYEcHvWF3hZ1uTCLwQPFJxZkmArW7zg2FOE
S; P
,^T>
p]`f
N"*,Q
ddw<
($22
cQ2)$z
OVbm
PaW9
)j<:
u&JyCu
OMXDT
2^p+
BW}cD
=f~,
qjMyaC2XDkfqHLxbGu20VOFWAoYV
t=.cUR
emEn
gqo*V?
cE2zj
6!zk~
k;+;
CPvU!e
[y'.
Z!f?
h 8
C7&+@dt$
/4_W
C Z%
_1e9Y
Rw}`(`
KhKIx
SZ$
\<;Mi
!@X~
m%@[
qo@
z=+bV
lU]>
T`.Y
/Z"o3
*PT'
^O*?~
c<#m
T",F
k5kRb
b-A<T
a*u"u
"<@'
lZ0v
;k%J
z ^=
KJ{
$8bxhx
MY{'
5N>2
%>&cy
*C+|
~\A`
7xL__
j~5H1
p_%.
o+aLOH
m{Q)
!cLc{
3'5-
L6H0
b'/T
XD5!
Fxb\
N^`
zM%<
}_[NZ.
IxY3
S#yH
(?J +
a9-bj]
d?.gL
>Q }z
K#u.
pCnD3
A_?r
-=& E
D I)
N><]Y/
-inJr
;pt*
BIaNly&
LWpR\
VF*y
_z&.
%A,8N
%\6OT
JJwx
%*_fyP
gW>e
sMvw
6B&Wx
iaN{
/rkvl
`lY,.
qxU,e
;'?V&
@s<i,
Y:X_}
"q6
Z_`;
/ 9
)ghz
6XH{
\gxt
K][\
Q/W~w
AUj E
/jzM?
3RLodBmAIZtJlgqWfN9HpkcrWbTC
H%t0p
Sf:S
gwiR
Wwb}
<`U0S;
UCU
St&u
)jE%
ZL>n#
M[J`
(b^pz
h'pav
DzH~
#549zJjULCDQG9NJOegGs0Apn2c2tNYlvGmH
u!$GF
*)#8
[!qC
psFU
}!>n`l
]8^_
r2Ys
O;cJ
q7t#
~:3f
eXs"Y
,t0'
S5w9
(G<LB
GK:h
Vy9
O`v L ut=q%=
H4<t
rVkK4
}P$+
O u-
|~+
pW}Z
_Tnr
Nr6U
S/>\
X:^/
*g\w
'wM(W
e&gI
%YU[
LPHg
^oOH
f6nh
xPbe
w}FqU
kOuZ
1D >m$F
P<?$
BG:c
zQM2.
;yoo
YQlJ
%?0J
$7:R
4\wX +
j=F7
bl*8
\Z)l
m8@+s
CR w
WrapNonExceptionThrows
PGe
i,#F
$7NlQvHh2kPxoNuGFwZqJZMM0vfpViSIx5Ufw
)uK\J
~Nh
t&b[
Qmx>3
2[
f[ U
/ze[\
vj=X,
'#}t
Hj`qHE
8]]%hef
qQwne
p h*
ETqKf
lc<x
ZT-s
K_g91
u{eZ
+(^
?lY4
Iy`=#bp
+67c
%s~uw
L@e<%
Ya+4
T(Jx
)3YX
@,c
>m'A
,V?2Pnc
lflm
=FELLO
O?PH
g3*y
" ^"
3T8Q
])<V_
J5(9
*. (
(PbG
_BUR
E@Ja
F%=jp
1K:F
YqRe
wy+Y
H|>T
:t9M
PF^^
fUXu#
(/$V
9Wl>
6>ezgsF
8Do
!O>Q
1R b!z
/U'4
0. f
FNFt
}fv|
(IES]vI-
0Hv &)
FO7gmt
cjv"
=r7/Tjwp
3)c:
[J<Pj
9 d\q'W
,|xL
V^@K
[S0\
lH.?.FKa>
$*6)
3[E,5@(
n w
~;)}
yK*f
,-T Rv+
6tJSb@
r0Vs
znvr
~3|h
*p[5ZO 5x
6\>
OVkEN/
KP5_
H*N
5O E
* z/d
zu1hu
jzcr
I07/
b] L8
fH05SMk7h4hB5caLEzkdbIivD22
Y~w(U|
xn8%0
d_=R
r<=(
brC<A)
XO
Cv&x
F)i x
n]9B
aysyxeklt8D4wfWLW0xWfA8u4gIGfG
w H
Xyw8kzNx4uIcmfzY6mpgz3p
DadV
mqT"]Qk
B|ro
)vp~w
=:UT
xE+L
v#8g
0Ww1
$zbs
ljq?5
I~n[
ZpV2]!
@L%Y
|]PyM
JWnz
rk'P
q#d~
V*!,zL
wN}l
b |<
} Lh
* j-
Gi|\x
`%iD
:Np@
X ~n
90Ir
6HM^
S..jEds
A &
=\(WR
q4 }G
OzL<
{ &
1{rt
W+M;
`U){f
'C`p
@^=
!(9p
*iUu
`/"
q*J+
k!Y`
qs5 J
?JOX
|F v
=Uej
.{ c
@jmrQ
;<=}k
, 7@L
Lr6e
@:<L
'3H
H^[V
>" v
(/;5
*!4+
%%Gv
2+Lu\|z
(~dI@|
} 5i%
YP]>
m&@
rwHm
2*EFT
@W7SM}
FIpmU %
RPfE[
q*
/Dr:<
p <>
Nr'$?
G8`2
_x5^d}
O48rL
Zbdo
{fK
*hk.
VdbGs
`*Zfb
fs^I
q+cJ
PVsaFz
.N6=!
n&bM(EH
io`4
7GFvo
tn;j
Do>*
g.qH
3kv
tb7AO
q\{KaQ
2wEL
nb7SB
:p%B8
Ll#7
q!6LB
+E]q
xp1c
Ld:,F
Bc/T
-O o
{^HX
3,X_
~98sI; sF
ZQd1
Pk57
jam93O
*2?+OA
|)~T
'S6OZPHQRsJXjPFAphszegxm5KsRbv6gU2AcqSaX
9V_~?
~43=
'Ao(
YWIa3
1m'i
?OC@
Sp1<?
]mYcp`
~ y
X}@z
;|{7y
1k 0
Q;bt
j XqR
6N.vU@
? .q
.u&3
6Bq@6
.-&z
" xC :
")x
\"Cjo
f,qw
1#EH
A(Z3*}@6e'h
2,ha
sA&e
XQ?m
<8\jA
8T53S
&JBjN
y;<m
G'{7[
O[|
_xQ"
1Hmr*r\h
]\9d
s}w<
BW[tO
l\8;
x$Hr
|!~}
) d-
Os^Dc
lDci
`& p.(
-k|u
%cv@{
}3G!s?
ns ^e
s9%&
Uy"{
1g C
5*w 1S0
\i!m-C-
>;6]
N"7B
'p)$I
%Cb#d
mGcy
BJR3
TYI f
(V/q
zjgX
{a0$
HCxGsq
cc B)V
S^$P
.1+c
Wd[Ypn~o o
akW
bs#"
SMd[
Y1Zm
fQom
!_C 2
fbS-
3,sA
vcYO
dg\<:P
^y~
n(k-
Vs%)
vG>f
Aj|C
q^B~
|G=}
Mq8.
?#K,
'IL1
`|md
Nd(!
O_2{j
S5q
zXAT
-[+f
<%y&
,P ea
H)7V
^f~0N
ntlE
qQS>
#A Dq
I5&lt
xC$$
Jj(N
9yOfx
]ysN
R0 -*}
OCR iZIQ
|[6R
9<`D
6: s
l~ e_
iLR^
\5Jz
+x$!
=5C!F
.\nT
-AOE
>`y6
,}"$33
e1cD &
D$\
`#V0
x1{>
DiZ0
Hu& c
+R1?%G
%^yh2
ICryptoTransform
UY0;
?/Yt
">G^"!I
-h3>
p6mi^
6m%`!
plM G
q]@4
!D]/
!3+0r
=}vk
+ z:
!@Wq
V#:}o-NEkVZLh
3z@#e
1;RF%M
0t&"= @:
#(Tp
{ ?`Q
*9lX
d|Uur
J*Y-F\
zFAKiXXDhuxndcqUB172wk
KAI|
_f^N
<Qc
W@n'%'
Cg=tl
i~V,
pSSl
kt/
6=BJ
t=Ly
!`Rd
/bG:[
[f0Zx5
:daN
i&{:
FQ$=
IDVrC
X(I_
,1B.kA
)Y[V.
kbd)
SR@'
[xVL
kf q<
F=_'
b{!>
3Aj;
`|/#.
nm&A}\
0P VB
NAj$
R%]v0
l[>I
unqK
pz1Y
~==
.E<@+"
zz&C%]n
KU*KB
iUp
<*9l
T=|=
AX<0Ac
^/ J;e
!YEV
clbO
fL 3CX
6b!)T
GsN`
M@XU
Sr5Yq
v679
a|P=
`lC.
)Scs
eTCZqV
6J 7
nubTrO
ilx|W
;;Wj
_$b)
b0`U
$ 1%
VsoQo
rbL2
[ADW#
hNZB>N
h(W;
j(rA{
_!iwv
# 6qx'
TH N
CvO7
)`%?
lPAZ
B}((x6c
X 52
HFY?
AnYj
ez*M
r];}
VU:4n&
XHyj|E=
Q.9
]kDP
*7 [
3Y#$
+u^M
Kx F
$.G^
sDIl7LcGdh8EHYJAb63w
Gx`o
S"T)
b=gC
}5M
cR(KX'
%(Hk:p'%7!d
ji]PPz
,iF2
1Y#M.U_fm
!~Kg
9o"2
YQ'u
gs_`/
mZCy
,hi"
Q#w[
^05D
oSld[P
X2R
jDzY8
[r#C48
0+$}]s}
-\XB
k! _
SQe0
2@)q}
*,cJ6
nqYA
$f|S
_0HA3
EhKH
73@:
Dj <
o:F<t
NA6J
J=_"
(Q[,
Cq'#
@Fj0s[Fk
SY\CL3
_+7!rf
V4Kj
w6dYw
C&Bu
z(6A, 8
+MwtR
;" y
jdJk
yI{|
1XGh
Q| N
z\<(:
V >TI
DF2/{
]`u ;+
+iX
Ke~
s#co
gD/
=z [p
fZsw
ta-Y(
MI'j
kx5 Tj
h.i+
)#4
q%~,]
Uo<L
ge6n
2 B[
n%cO
)}JO
-)0m
*o2/`"
qzTG
Vd?N
S/=c
Assembly
wK,,z
$- z/a
X4%,u
1G> F
&$)j
BOtiY
c=3;7*
K{;`
!B*"
sHXBn
,:O-
e(bg
HW k
u+H1
uu4
s*s)
nf{l
*+L
t 460
?:nk
?Pi0I
*sw&
9aY{
(YZ%G
Ez J
uj:<o1
N UF
'1c
;yQ
ME{"H9
nq H
x^gu
I
r:%o
RdS|
R[}$
m."PQJV
D+W{
$3ZL
{u*_NAy
C4.
!Y+(
9~J~
#JG SE6K)=
^n9F
t![_
`+ 3
`nZ#
K 'y
Yhn8,C
\2 *
` +Pp
vk*+a
!S!Y
57 `
[JN '
I7=p.-
130{
~$8RV
;IB_
f%Cq
Ar@O
1
s:,3
a4Wo4
X>!jP
i&F
bbbnB=]
#hTC
\UD:
Y~;!
p;`m
3tlI
#.@k
Yk W
:g]*z
82=F
[5uj
PMSX
1 xz
:.tj
e;-
]bJG
%Zi%
pj-.5
l/#t+
KfXAW.
<_lK
D]#=
F;j8
y &
qgKb
LnuHG
_8 $
#4wx
\
[GlYZ
&!2e5
c\ j
yv,[
IA+!@
C0n
Inp}
w]iy
.c\I
{fG%l
?,_D
o@C!
$ NA
~b8F
(:?9
]a7@a
6WPs
rnl.6
Q~(6z
B-wS
eYgMt
5P"6
Pp59
GetObject
JQDu6WH
8-1i6
sh^T
X0{LT
n hT
.\L 2
M01L.
E@!q$OB
slns
kJ^;r
}daj
Hue3
Qh
ue'n
J;4od6vJqQ
7vw[
ahgX"
\qlRn
F I
(CpD
6a,-
vI52
ir02$;
3+;[
{ZUn
>.K;
iW G
E;2,
+-I 4
kT\K
3&FArK
qHBL
nMl~WA6l
`qE
-5Ls
EWrQ
j(Mh1`C
d9 -j89
9W2!
jf5%
+ v $-Q *
UY6T
1"H
WG2|
@rEM2
|\}%
([9TF
E i|-a
a%"?o|#1
|--_
v&"f|
;='
JiY0
b9.\
u~ 9
:m"@
a'K9nX}
vL5p
|yuNg
RB^R
S^M
<i+d
LLGc0
k?{4y
h1%d
u]4M
^3m&
,:1s!&
2}?$y
OL$`
_J A
t'eR
?$7lf
rfjD
jO*_
sJ Aq
'E%h#&
RHNp6
[]GT
~hJD)
1d s
#Xont
N Ced
)zO4 yH
Hg;t
n{P\*
2(F@J
E7.L
KLU)
GG!"
Q![g
\lD8
Dnd
2k#+i
)?9*
Ov[Yf
?A.6G
2vh"
'Bm
^. 5rg
2ooK
cfnH
8%tt
|J"\
vk-w
D:_
|J"W
B;x
:$muq
-Hj&>
bCw)++=
hq4m
J+[EZ
wjq=
y1]<?
/?j^
E*W[
`t*
IQ,o
1Nb%
B<Rp
Bu9n-
Tm`4
Rw+@
p=mt
6Q|i
+OK1
1G-.
:!&M\A
d^a'y
9d;X
2+a&
V[!{h
1t;[k'W
+Uj]mq
p4\/Bxa
(%?O-u
1{wtc
%XZL
#/M9,
e}l2
ohnK
9yY{^=
~m>d
m}_m)l
) Mxt
5 %P
Ho'X%XlXf
1kuL
System.Reflection
fq9<
&?T |n2
>n g
A-C_
K0)I
Z<g_$
2-4|
D#'A]i
!6OE
vwn^
e >u&
-Mwn!
47KI $
-pUJ
o'1v
}2m3
gfRo{57w
9Ig2
YvF-
_DfzM
hh}kl_
Nhx}
K]lK
nWD^ y
M JBv
"86]LE
R8SSn V
?8k5^"
Bn:^
}cB-
?l8;
1J>lN#
r[[wRv
` AQ[ '
.cX]L
{$ 3
sbv#
s_-id`
S9|_
H{7 |_
"_-o
2BQu.
?$rQ
c-Bo
&d>2
qR4"
oPNE
C)h
"KIPQ
0C".
ya/H0
MessageBox
AJ~*?i`A
V
6@_Q
x5QpX
[=?K
vYoAk
u L<l
% 8X
ZyQQ
dfUn
sIH!
@_`f-O
=+fcI[
AS275
F}=L
;f6t
,4gab
)Oao1BH3*
9RvLa
H7yo
bt32
Fdt=
e2lJI
HZ% ]
MuM,84
|WX $m[o
_Q:nqB
5" x
?9LL&
.EEt
xe4}
@_Xs
oJyy
#&wt~
ih@8
'/vt
^7 |
6b"Wk4
uV>w
{_Nb4
8qei
Q *`
u=}f
tMn].
SJ ,
fw &oR"5
:bjFC
6NoA
FU M
W>Tl
!jlE-
07:d
&_ L
nDfM
|`mds7% %W
K9Eq
.Q,&
<:wD
\WRM
UKB4sw
~~y E)
Z>0z
cBnV
*Qd~,
FJk
yCKi|
l,ru
c@x<
WeMX]
@,Y+
~'g-
|*Zl
hLXI
[oB.
YM 3k
\2Wa
@Tc
,BOho
;HN Q E$
a,oJ1
o Rv
'U- R
:F<b
w% uN%
mn.
ua!
J Q5
|2i0q
q>j;
f5!!
RY="
P1.!
mTf'
&=r]
g/)7
*t+P
dpLF
!G {
^bWj
Qgf_
}RyP
/b%+
_Un~
5NR9
FcL8
4S\4
N/:~
AqLm
A#8&
Z Sy
2%D
oz|u
K9r=C
wJmd
,/wv
e.x{
Iv3C
>goM4
w8M C
o6Z
}n<vZ
n5w3K
qE!C
lD{WMqK
,L}b0t
zE}V_
XtAVPf
)W6vBb
Zco:
)SzH
{#hYX8
B;Vd
.Rut+.K
{sMs
gI.i'
;)[$
XLHtu
zw?%r
=h&U
' vB
0[{|v
NfwO? ;
vk]:
_ z$
$#J(b
j7zOdT
zez&
`Zyo:=
u#ol
Op[
K{OY
<55o!
Z?im
m"T [6
R5Fy
( E;
Y,s~
q p
n;70
%@*h
JEUCry
<N>>g
6 Mc
DeBNmj
*SB$
}r[r_
o9<8;2w
~o ,
>8n>
&g+;{
@W?,
nI'1^Fg
" MP%
EwVxN
~Do+
Q&>5?
3d_i,L
X'^e
Q;^O
2hbMW
RS3q
96BBP
6B8"eW6
/+.e)8"
z)3Z
D` X
?(yk
"!,.
&qb
C3[f
9}N
Kxf
XrUw"C
ZlKZ
(%46
3-Dl!vh
Y$}
(}E_f
bZV f
vD*H
U9\
`5Kt
6J3>[g
+!(j
1D[g
T>dlg
X4{)
4eYX+
rl~|
<"ys|a
-n=/Uk
(uF$R
C9bH
Ek yt z[
~l,&
$: w
S&Do
-GeJ
NKxr
e~_(
y`nh
Wy"w
u[GW
ff6SQ
]Ppxw
\5N>
.nOc\
yc./
28xI<n
;i]~i)
\2|}N2
R p6
^/v9a
W9v9
bXs.
qs4N
8 <`
EI6yA
e4]N)|cu1
l* (F
[$(e
#@ Q
v&fs
{; l
#o|/ '
CB$\
:P$ e:
~^aTY&
_W.!|
%@s7
62JF
i6G
Q M*
mamR$.
RWBR
FX*z
%F%0mlvo
7$M$
Q@@
H7 M
&$e7
Gdh|
]$W"
]1U>
5%~d
6K4)_
\*^K'
D(tQ
n[o4
v=2$[
{yMGJ
x(@n
YQ@@
9?O2
\%V;
)n!j=
sOAv
lUvJ7avgesYBhahOC6bxq8Rtb3
<?`|z
f5Tl
R5u%`
I_4e
o ##
lInS
ZvvQ
UjS6I
}>K)
9 +c
uJ ;
K-\_F
uQ IY
!enl
tv(4
HN6v
<D.Q
~]gaRs
Eh7p
$,Y9
f3IF4
S}&z
5"y
W4e!
) oW $
[=l1
&n0%
:Qs:
FeeS
2B|
4^MoJ
;}V3
{Ti .
Ed:lwL$
f:l)s
|Z@1
Eg.
U~1
get_CurrentDomain
. "0~
Pb!mA
tn}x
"7H6.
Vi=_
0rvr
Ei @
[,/8HC
l(CF
@&4
RsUU
Gli).
;Ip
U MI
AbP!G
2(=|
-sU0
List`1
(Y_L
S=:l
2N"E
&_~+
)U2*
Ze`
a3R*
MJf=V
nX3
nvgq
@YH@
&e$ k
<FxA
IN@C
System.Resources
o;c"
@e,-
`1%p'p
i3qR
N+ALu
hj0c,FF
:v`arD
9JmHc
U x#
sADe
Ma8<
x5b$Re
;;tt
H[=*}V4b0
4 MD P
\i:Qi3
PRWXq
.b)`
Uz\e
9X5Z
u#t[
fg4D
L@JR
mJV9S
fi :
G V
[UI&
;Cd\22
ZEcw
_u`z
%Cs>
#80]
s n!
a9.'
Scsw
K=K_
FP:{
ts^[/
r2?)(6
r 'hA
O K 1;
lNkC
rlCY
1&@P+?
WH&Z
Q8uf
6Dy x
XyT2U
V{ww
PRu)
lmVu
YaG3-T
fz!.
]</
A~qw/
o|1Yp
D>w-
F rd
dWqR
]Th>
@ 6HL<%
xH$Y
;h}{
thhF
"b#m
eHI+
k(-l
_Zom
pQb4
* hc
dw.Qt
v)mLr
~u%e
JsPlA
e3'tr$v
5G3B
qE5tOc
:,M@}M_
;GoXW
6yBAL
vdE"
>3UH
f\M;
C+ee
$=v1c/+/
3=x[K
$LrfIOdgErlKY5SHQfXi9sqi7gYAubNOSp2Bp
h(>?
] @?
9T36;
Ek6 hWRB
tDU'
{R$s "_&"K
*Y2zZ
wI 1
get_Now
*/U d
aI"
]npsL&
!}*/ YR}g^
:z(g5
>^WST e
RlH<
7yu
" fuX>
5~p\[
c'ks
lMI;
Si7+
t7h=h
ekX<
( Km
>,9
9 =
'K/
"W13nuN71dd0Cqi0NWxjLkRf6c5le4Hg2wk
O\;+i
bZvT
Lq=!(
0FM
OIoo0
kl?k:<
[b&\
@L}^
-s
UvP99
JXc7
}ybb
ST'
{_{^b
<=sw
4DBU
;#Y[
8nGc
ksHG
{ebD
P[-]
J-mqj
1b f
pP$j<
+Z>g
]vR8
%,0G
~e(-=1
kt6qc
Fb4Q
/Z !
Z(F<%
:U2VZ
C|-W
ouH"
R"G2
{^a!7G
v &
9|x
v-'J
oCXj
2LR<.
-I %`
b|x0
]G`;
`dd
iSU
HT~AH
,)>M
*m@
cd<(-q
Z7\cM
f{sL
V#EG
O&Ox
<uT8H
1wqh
o]KcO
;N1`
*4 Q
+/ &i(
WkfP
~\Ru
!)U&
i7F9N
b6?~
44IO
W'09-
&Qp3@JpxL
m%U|7
/t[i0
G'_>
)I;!
P?e?S
nT!3
hL$K
"\zQ
3Sb[
>r8 n
NQpi
L|mW\
|r|yh
K02:
YEn=)
y QV
`ig5
=<P_
XK^gD+
,-/v
f#aa
Xj54v
7p,a
,[A0
RSaPHV
SKU\
Mj:x
0`Ic
0Lez
C1\e
K2T2
+[Fn
pB8QG
}r,X
CkiR
#w3[&
w!5y
K"b@@
*Wwl
QpF'
j Py
,*b+
8swWE
"wZA(H
oU#c
xXWLR
xSrg
Bv+@
2P@
z'rG
UwjU3
G:LX Q
bF$kP
:G~P4x
o*xn
lkh$6kC
m/w&
I?\l
r'?R
4{s E
"}MG
YB%$m{
>tlH
Z \0
\nTZ:
(yS:J
v{Tj
|YOl
AEW:
o45m
y!-)
C @WT
l)oJ
}6!X
@x4A}|
0>dI
2?IZ
[K]w
v. 1S
l3d*
/'bGn<t
)D!D
_o]|
~g,m
CYAN
YTLeuE2 h
FXsz=<
nT 7v
'l
%5]{=E<
3ZM
]|#
-;w"F
<fF
kv##
<vM$
)USEb[
Fl6v;
9]F~
Eilz
oY:
$hve
rVDTrN
K#
[2e#:
e]*[
Jx:Q/
N^AV
OSO
[R*wI
l/EU
J:"0
y0GZ,
.8U/
; ;yk
Ej7*
+h"nDDv
yMA4
[H;d}
0@b@
TvH)
{(U/
(d~H
6bsn
MS3=
d\zO
12Nu
TvH1
({a~^.a
"*`
4Oc+
]pg;
c?84d2
hL @qpt
s):*
oImv
[ :W
(KCu'
npB}&,$_
[}r6#
z ;ft(
]4?b
, UF
0dS+-m2?;h
;Y!!
D?mE*J
yuV <
'Chn
NoY3
B%}(O
b @Ba
%>}k
%Y7
9kdL!
tKH&
"bZu,
3YO*
Mp#9|
a:,a#
8bl?%
f6~M
"'kz
RX5UT
{>EV
@DzH
i(X4:.Fr
/.}Y tH
dV=
\7CHP
WHZ)'
UKz2
g6Zu
:~.T
gIs|2
/K<C
BmEZ
y@?]
rcDM
e5n~
G $
@\-"aJ
^,|y
Y)'uN
VbBM
m{G5
Fe X%
>N3].i
P1Df
@3]1
!4O'
8Bzd /
s;|?
s4 8c
dm):Lj
d&-Q
E==U
YVLM
{B(=[
&tIC
]:){ol
VDmSQ4ZlGn3
zXCLc
i{C {
A^e<
Vni_P
>b~T
(Hy"}
|AD\
lW]R
.!4]
y\J~
! LT
v^&! S
}^o2z
6$ M
,VGq
BUVD1
AddMilliseconds
Hwo< :
-H}D**
v2.0.50727
C0UA
^.>b
),:R.DhG
3w I
!Dfx
+;]!k
SMj(?7
no"{
m*a?=
zwys
DT1
Fm"W3
j^CC
?a'Z#
XB19
q ?#
<pXy
Vj_3
#yj41 @
!vZuj
7;Wd
FH]5
r@zXQ
|Ggq
p:E;K
Dp/@
'gFB
o}2%PZ
3i
LcI4
tw
V2cv
dE'`
iZ.Ua
D>uY
tAqA
x%U#%h-
2us0
M U&
`*TZ
LCh_Fc-
n8@a(
a*0M
Sq9n
SymmetricAlgorithm
p6Z0
zdOPt
gCHP R
*wA ~2
bD-{
LwHr
+P@z
xLAk
~j|BIk
l6!
/&D$
+gp2
}{MoiK
X|vI
WHlP
p]1U YC}
kg9$
HEi9
%4lb
);2o}
Q<.X
i~
d|X!
B$#
E&Jt
JV&q c
X]Z:
\<y:E
<u((
zncl
qm[#
:z/:
(f<a
u#>
3+Z4
!4Huo
#Hyj
$ICuF E8
@ks^w
]bD>
HTaA
(GwI
k~39.{
jV+I
a(6<
r$'
fM ,
$1[`
Y{1pw
lU&w
. 59Z
m[.v
Yw4[
b9dv6
S _9b
oil *3
pa=hb8p
[G7w
O,~$R
r}t[x
{=##
DtHQ
~T$Q+
QBBQ#
H2!r
=UX3[
usRO
9ro8
`UB]
-~nY
6vYr1 (
npuL
ZKjr
Eclf
fa ~;XX
={8M,
K*W*\Q
Ot z4"
r*F)^
$6vD
JB V6
/IV
TransformFinalBlock
X] ]
N BW
~%`J
Q}a_zx
@F!TA4
=-g4Oc
bV\d
-_io
4EZ;
H$9
jdV#+n
[-@O
W1YRJ
BCIL
<8(H!
h6()
lR},^
VZ}f
: QE
/}k U$|
vcTlc:
|TD[
Bz1}`H(u
CkwJ
y$ 2^
Z '
DP:J
u4),
UZ{y% R
]]cL X
h4fT
VBh#
T%i`
goro K
Q_hF E
6%`xQ4
_P _
!hzU
GDP1
r!L/V
hEF{
:,=P
=sxl
8gJcq
8::-i
"g4~
^;<'
%Mlp
>C8K
c |Z3
hY!
_(fc
j+`Rg
lI"Y
!vK
M4KE
q{8f
kH'\X
D!ll
y3;<R]
v(VTV_s
oq;Y
&$MflS
&LF8|=
!r!1%
C(cc,1
VgNjg
RH&,
/:R!
pUA+
IO0o
l wA
Fo"-
BZ+oW<
*N)u
*x)4q]
z%+#|
3eBE
P e>y
Eg d
y*e_
GyVA
k_Zy
WpRB
=j [
\.CR
? J)%
`? BR
v ]u
\ENi
Prh=<B
e\n_v
1<<Ho
#GT8
a"Tz" R
f9 k
@8^/E
J)m0
q2u7[g
s|*e
7| r
.ZvE
h (1+3
c)_00s,w
f!kgkx
=`a|
oNWe
G8SD
zb$H_`r+_e
SII\M
cn#h
=?%#
N7'
5'JL
6[{l
{Jv6
aaO6
`5O:T
%d4
}5JK2t
5PcN
>77euS
OHY
=(K*i
W<Iu
Brv`
\mg<
t@p7
m 3v(&j
TWfzL
\'J=,
hkgq
*71]_
'L_#
~6Fe
),*k~
<"'/H
iy{\;8
H^A*
Wwus
|NMM
=o!/]
}R;_
dUTAY
;g=O
yRM"q3
a\,aD
}EmM
;Sl!
-@` o9
365C(z
<j&}9
xSS(
=y^GX
,<.[
~kuka
M!/"
2"J%
pit5VP
X4D0
HPJ7kP9Tlvs0804umNW8KlcUaa8Eav
/N;9
RlC\:
isIC
1 TpW
s/ PX
#}_/8{
:*;d
W/iM
(2 z0
?sB(
m5C89Fy(
=wy<2tq
4bEZ
l]GD
bqQ
37?"
rmgjW
s"ka
I fX
}j;s
.g'm
$Zt.tl
z<!Kr
,B%EZU
} S=j
K6K.
h["c
E|)\
vX3+aN]
ESaP
3Q:.
t:am
C$sh
jzs,
=j/M
/B{WGfV
#$o`Xr
'(k Q
! `X
s?%S
_#9c
FK\Mm
9G^{
h% ,
Z!z,yZ
(`N
ZGAw
gR;.
i5@wE]
8@P*
3iOEJ
<_!n
!0
tl`w]
v+QO
#"LU
GgZ:
=Zad!2t
DALf
'Q(*k%
Be9N
gi DM
L|R] w
)<\p
sx1G
Du4o
D+_B
1L~
ncpQ
._f
I`B\
Y\t:|
47&f9
y =
0v}:G
CwaA
3R2"$
T9(l
Ly.EP
Tr4%X
h 2k
@G|Y
rS5VD
M^oo
)sjiT
<bdK
pRD1
` S5'
{`/*
k^*!
GM`=
[EA
Z1wL
sf. H
4'1U}
eEo~
M#bE
!{dO
Z\K5S
~ 6fY
YabC
g/#V
!O-i
[5
jQ,!`/
Oq;U
^.k{
/.$aH
S+02
+;Wha
wgMB
1{e:C&
O)Hz
8|AzFez
/c!/~
nIM<
eBc^
5WWz|
3O;Um>
[mBbD
?>zX
xrHX
c/8`I
=.OQ
^ bS>
w _w
tB|v
f pi
?0`v
a'bg
yMZAsc
;;)jF
QsI7
|\+$a
K%gy
m9{z
(Pq
9CEr
'Jh9
|EOT
[3wqI
zq~6T
[4,^OZ
N;ca
KyfT
NH9hE
A7,5
5~v?&
&6d 2
N}[T||*I
u0)VC
gZ^V
3rhBB?
!yV=
pMh
System
v 7
D" y
3%C%
/sy{
,Bv/
4~@z
Rb2b
:Jcf
- im>`
RHD1
FCuH
l\`#E
5e3q
@<dP
2|lfZ
+a=#
`N~0
zW=q
~R30z"
&q[L
n@Z7
z4j$
M].==
4(h *@}
^wsI
{r'
N[b@
x? t
,2va
C%O?
pHt+ckh
Fm\^yq
mvUS
oP1ja|
OMV
Lx^(
ne-z
7; 7
i8||V
ow V
Ox8l/
svpq
tb.~
50%;
tbS7
}]? \Z
g2MyZ
j|vgo
ZDbc
<MA]eqm
x|fepH
?@$
y&G>
u^dv
@Hu\
ejRv
oL @[x
~Q={
;`_wi;
\ [0to
^p
6f\'
hip
S'9NN
SR\,
dT8b
x 2 8
R-1)j\
zQI
$wr}
&/?$
&QRiw
MiQh
#$Q9
X|,
=.=O
ex]&
;RjfO
s I;
$SM$
5 1
y9Bk
Nuh"
k&\#{$
nZ+TM
6_:)
Cj Lv
~ i=
xoh3M$
SCY$d
ymYs\[
iR!/
1Fi!
ay9BRdbgcNEdnZhggH8tfgIkqghM
T#3 y
]pa\g
!BU.
|x?j>
"O7+
|,3,
pG[^R
7N+$
AYd
V!7x
{Blt.
xwj
*ADA
Z:GBL
S55zCz
{r 1
m)e28
gfXf
D:zX>
+ZA3
p@Pm
_~ !?,
y" MG7t|g
9$"&
q7f"
lF'r
_R7\
1F{Ixy
#.oq
u5e#LU
'6!c
Nh-\q
,4lpo
|qJ#
4-2
%'|F
G:M8F#
(?].
?6D:I
a]u\
u_U[@z
yoyU I
INJf
jrGS
4g q
hT <'
B$3~W
cQ)S
..Uz
^RmCG
0W{V
_'O>op
Q^
A'lLIe
nw!.
!&\T
->'A@
hs rw
e%="
Zk/19
b5`5
FVjt
sS*AT1Y
]\&_
z~vG5
u!C
~sDPw
^($X8
KxS%[
g]{D8
ny/ Bp
_[2:
dpQp
r;F))
q>_"
>tOe4
7?~dl
adir/
4DSCJ
zgt6
B\:E
ec^e
BX,p
' [
-iB[mr
sNJKR
]U K
P3B"
N2_JF
&%w"
wUqSX-
~`>EL
"=U0
XeWK
&)q
uX@0
3{{7:M
BOg5Mj
oE 8
vo1M
NK k
xP\z!
X!0=(
DR~1
T<d
jr4@I
Rk@#
C9P
4wZ>8
u*Y~
BJ4[
!,<i~
'K_IMM
-m-t[
x9r8
Ti7!
F-t`
^e,ciM
%S )
D !y
@(u)
of>Pi|n
!oKE
<b _
c?E,
R$c9ZP
!g|jK
k1(}D|em
5V"
]P:Y^
91rX
/)%v
xAOA5J
;1Gz
SWah
x]bO%O
dRUz
,[k0[H
AW?8/
-x@O
,vkN
M% _~
U]<<
!* #u
7 f
p/B~LB
~v!AqU^2
hPu R-
B<bs
~ *i
\u.S<
9w6Fx
X{x9o><h
n%u
1\Q
&vyS
N50\:h
k.U<
7#F
.DG<B
MnsJlqO
+W[u
Y7YCzO
UIjdt
yNwJ
^Rg
&rca
"?~J
C<7*!
] qb
>SxZi
t /A
='yZ%0
".?D;"
{=g-
]mF&^#
|4>U
,6T:C
# ZxO
9Hd
K7r0U
pN$O
+#)Z
dnmp
bWpzG
!dO7
ZBi]
N7`
8wYh
wP{j
QcS:r"
*hH!g)
CWr"0
[9KR
oS f
bNRY
H){f
? ud
4_mv
`^HtC
<Wxg
76 0 w
"w4t
*&wvt^
e7H,
,ioV
sY0?
RI}j
Gq]n G
q}r\
WEm.L
11Sm
D\p=
y xt
CO@.M
tm0L#
}iGX
w9+(
k4nB
T%o}k
`?or
.&l+&Y*
'l?z
n{_09vJ
t a9
wwD>
~d$-PcRk1j
-WE4
# Gp
-*GKR
^vG$5
LIDt
H%J
MJKHR?
IhPR!
wA4
-<g 7+lV
d~? ~
F,E(
+^!d'
&'v&V
Aau
CPbb
nseq
9]9
\!_`
[}k`
uF%m=L
93 =
QkTa
erZDCmXNT5RTGe8oYkQQ
g9[x>
%kN|
nZr5
bK b
tV,i
#LAq
d2#D e.T
UWiJ
.S*a
B3Kt
8B DN
4N\n
i86W
/k~8
ZTjJ!
1 wf
Cv\x
Pgp8
Ws,!@
Fyjt
}0Z\
_: =5.
Uw0
L"r
@QA%7q
D]7WN
ePzNS
iD@;
8wf
keG)
1onX
$21jPifKwjde7IK3iiN811FiAEZla8TZnsacs
{bi$/
ekcaht
*Je9n
v=i~@
^0#6
y-~1
g"4z
6_p`
z&s3
(>Oy7
|V-[
[ZH@
hw_R
;j}
9`8X
C::b
U{OY
S^(+g
GXnuW
z+MX
so"_
>?|7Q
FS{
q '
8V%<
]4wBj
X=3i
System.Security.Cryptography
r4yi
j5;;
BI^n
ofhJ
qV;
4K;G
o _Z
5}+
R:=
v q"VC
MJ|y
SD,Y
] ph
nApu
p{]Fh
.6&O
,v n
4!qq
$}?ZV
hX n
S_RK
7@|E
:VZF
(b2
i2gS87p7ZXNIGi2Bd21jYnMqrQC4TEE
P j0|
u7|
~nV=
RMDr
Irj.$1
*{V
Q:Ho
Ww\L
2l%2
;G* 1
Ub%x.
=brA
+/[Q
Q:
d*Vc
Fu.;
A7n{r
9 }f
HNEFK
Waj9
+#wt
V}~I
A1u+
w>wW
S/3lr
GbZw
-v%6
n_K@
*.FB|
>jPbX
Uhv0!
nDY}
U C\
6YpnU22LqQdkLEbmQ3f2tMbIZGPZ6FMD
DPI}
c j+SJ*
QQkW
,9`v
5-6M~2q
4 =!
6U6}
XcZ0e
8 A.
L9Y~n
S 0}
7GStc
/ p3
7':H
)ahB
*g&}
X]!5H
5w|o-
sq, #
S-&[K8
Y0Xz{3g$
~HTFU
NIfx
Yrey
SNlXP
g'cI};
7gMB
zq'&w
_n V
@5q
aDtr
q~_v
#& c
kG0)
=Y9Q
F`%R
SLOd
Uw|n
M;67
z6&@_
(CYg
Nx5Q
CIR/
OGq
4G<.
|iDp;
Uu(FC
VgRC
Ifqg
jN!
}}E-
get_EntryPoint
_V-^
+3y13
v%PH
#|B&3
:T9
! 72
{(og
ou+Y
I~`?
6O'|
7;,B
q9y7
B"xW'S
xWKM
Z{}J
ye(7
`~j`&]
0dI^]
'N)
XpKP
dTA
lHYl3
\!e+
'eWvutkLF2Kd1XEdGleHyGV5DBQsieXqCvMqxk7X
zjOt7
zWVt
k1uvX9MDA236o50B6TFsL
1 w1'
V3%v
F8Bd
OhTC
o\9#zy
Ik +3
) 6)M!
lh7F
}kB-
{?RJS
-vm
J$<F
f 'u>H
'vpY
Ap7H
$zlF
oRR#
rJpD6
\YPPI
eZaj-
V{$4
ZxfoI
hNPr
N{v
P;gf?
*R)%
{GwAD]Y
' uA
m qq,
czCY
0`B8
U|ql
b!-m
elQN
H0/AM
U#:K
THpO
AoOu
;VW0
}gMp
!y4a3
]nsW h
ce\d
% snmw
/Q&~
Ny|.y9
{4>3
D50aa
5}DZ
!!*9
3BO#
YH1,
YnhCGH
-mX;Z
P"W
8+oo@
3)[qa
Ps( ^
TWw
qmpD
m|*u
*Kp(
\bHk
/hu
kc#/(n
/i6{
C&='
M"U>
\614
v{_vl
MGSB
O;&-
; !:
\'OS
x$^=
UO+~V7
xmNi
e<z+
-hWm
; TC
9f`c
[@`1%Q5m
7@n8j
'ct^tp
\\g
Al~!
JBCA
G~Nj
ShE#
S,5!PF
HFvM
a73]aX(
u3|#
w(cY
l }2
%{cA
L 2J
G:l|
S ?`
c@vC
T)
SBx
v ~1
iQ-U
L,}F
^D}/'L
f5+
Ybrn
$B'6
m=Cu
L1&T'
mn)r
<o.8
ZM).j
k F F7
>9SE
%Oy3{
9r@
aL.q
k}foP
"s G
\GdJ6
HCR+
Q~DD
iDPV]
/BNB*
_Cs
* Pn
fje8B
Q0d$u
?|u0w
dr&u
=r#o(:
1ka p
C*Q
E 5ok
/bP]
$j4'
C$ 2
iJmm
3 \.V
02 Q
!(Xz/
I'T~
/7'D
APO B
x\1%
[z 2
Sb f
A]=Z
e`-
a2]>
Y]a[
r\.}
iE/,E
rR9$
">wor
/3[%
Y,fs
4f?{M
`N2}
~W 6
DlO\
Qt`^br
vq@q
{5|(N
a>y(
5WIt9
ARrWN{*
%O~5
592*
n8!6S
Y;^g
(7:8
E.~%h
MX$r
$@ g
r57[
?{^-
/nzmi7
8Td! r
iE$p+
\Bg9
:mf^
fi#7B
[n:K
G7l},H
<%"}fB
'{J1T
PdG
a*z:"
|O e
"Z599BDrX7bXqd8grQ0oC0Fk1mciXA92gDq
]h7-
c@ ^
|:F|
y*')
5 =
<p{f
d d
i<D#
0uIl
r^#Z
VK&n
N'#I"
kv^ P
03w1
# Eu
6cRRQ
}|vk4
8]{h
sSPl
ENu.
Ktv6QB7FJNJugzRIaQg3Ut8TQhbKeYt
b ?>
=Bhzz< (
H<gs
J*/J
wUV<
&/=^
h=OdL
xD1#`
e)+F
(e+@
a }3
pc5?
?|Vy
(] kfa
M4V*{
w!f(W
9~!
51cQ
DdTgM
]0x3\
XC6
=W?t
y6d(
i Da
.c+L
UC?26JN
NQ/
Efgo5
nB<+
LQw?Z
~#]1
tz `{
_=&C
>c_33
omx0W
zh?"
95<
SMRK
fgoaf 8
2kWI
CF2w
a f/0
|g;?
cop#
Mnq8
X4yYy
KC~--
J+Ngr
aK'yi*
hV)lR
w,=/
g~d9n>
?+=g
r=9
m[ 8 `w:
F8J*B
">_f
0&|5
7]t"
} 21
BczXKxq
2Vuj
w$=H
.T0A
Zz J
Paj0
rQqhK
Vo.^
T7-n
Ukc
]P&H
)_sA,
Q+u)
x La
<348
4%&E
w3I@N
J!rjz
J+lz
GYvC
ewiT
"qQ
I#X BG
,.H_
HET5M
@Ei
{=f [
Torm
!This program cannot be run in DOS mode. $
sC+&
7 he '
lQ/i
zfFF&
BOrFEr
sNaH
X\R&
"W! 8
= (]$
[%Fy
Np}LO
R [
Dtug-
iJ3E
!OsO@
5nnVd
DvAM
Fx]c
zVR=
1>J<<wM
r^N*rD
8-x<
`8&/
U i@N
I;VB
lEn[{T
MBW+<
I3 l
u2bl
8G[/7
CY/Im9o
DJksq
^Dw~
bWEx
:~dlw
HM(I
`%y-
\|Q[u
|0qf
ul=s
%,=|J
VAZ@0
O>-F
->rg'
Y" =
}3I
oa#,
R9L,%}`
r-KX
ReFH^q
3Ph?~oZ
ug&S
^l %B3
E !y
.jKL
>p:%
4 pPg
A]{2
R_,7
E,"=
$@}K
Z^>a
c3P=l
K1Y"
OAXPh
$m"
MA S
"yPctnzZFtQ1CXImRN6MED8lIUYUMHV01kE
$S,D
@+#ZR@
J1X_7t
9v/R
7_'[
J6{
[JNQ
GjtF;Om
2|n`Jx
sTf
Wh*}x
tc2?
7Nw<
Xw&s?
Y4Moe
m Ib
O\Mhw
Q]f+
#7
d3*|
;WOE
Y<k'
]v}'
84Lh_
Hf*Vz`
2P{LE#P@
S{O._
X@nn
+`NO
=]{t$
XhMW
d@f7
DW./
3t6N
aq j
q4@F
dE-g4
NjuY7
q ld`
/<a
.YgeB[]
t=9`
$:4H
{}7Dt`
OXv
ElUD
^sueW
VT`m$
:YO(F
OSlC
f</3w
fC7a
)Nr
o9 .%
@a5
8Ct
zOod
a;w
"kO*!$z
rG`p}
iQ~
1 ^R
OGPc
%%o'
WN|
dmjnA
[4 l
:_hT
)j*_0
HMPF.
+QF(
/)Nm
1,Uh\
P\52v
,Wp{
3 Ug"
Jp!*
;[k
Q}$bl:G
2(r^"
7JCS
BbRA
h4 C
Wq.#C=
]Ks:
'JEt\
~Q h
o]+E
4_8v@
>\M*
8D~>
s3W*
C6"A
5Ur[
!}a
7 L5
_J/P$
&0id
.eVd
pTM!Q
zv0Z
0 t\
j6@5
l #p0
%P>
A$(zK
y%.>X
NY_B
AG'K
]Ksg
5.A%
n]I[D6
wh+~
\ruA
T}Tc
a-bt
SSJ2
c>&?
\KW
\^#B
y w?
IvG=
@1nH
hCa
hq;e
*gby
=!ta
H,.E
v<gm
)0],
4bsHd
E@q3
W;XF
x KV
;[E85
F%,r
`e '
>UuR&/
y!vFL
E^{j
FMr1
*C<4
8#yp
.r`!
sNYzO
Xv|W
qPE"
b?^
vLbugZZqM5UWIBj36aEBgX
|n\b
l5`~#
yt(O
sl`-c
G2wM
x@u>
X.:?
rMw:y
k/ANm
4O9b
y{ j<
q%2]
ak`Q
"X#c
]I2I
n|\
F3-S9dH
V,]>
s$ x
sh Z
n-*TM
|EuOg
X_>#
YpG1
a21iHB5frgpcjMe1ogm2Cb8EGkNMB
bDPsm
1MqY
XyZ<
(IhS
)Yt@
C `!
!S%."
~ B+)
m+d
dA5_N
bFNHU
U6[\
@7.IZ9
z4q`D$
3dQ(
|ZPtIEzo%
l,=5
?bW2
rW126$
&UQX
*kP8
,+"{
=2L^
gDV3
nkyq
Giw3
8pR
r_r>
15\J
>_Om
o)=x(
43kx
t'<p
8|\r
z(Yr
RkWX
&GO*
i+p'
+ml9zk
:eW@
*pmO,
i45@7
`0[4
:*pZoZ
"Z~l
SSmMn
d siS<"
5g|B
Lu]Q
{6:@>2-
e,G$*
^n5!G
v3yz{|fb
j/Q1
[SN
jTbF
Fu*A
&>D=
h&\M
V+5y^
r_rY
dIs:
t6\*L
@;(z
/: CR
f:/e
.=Gj
4qGM
nq;/
1 =W
]o,J
&4vg
gtUV
S\TgV
vktZ
AQRq
j3 0@5|
. En
%}lT
WhAk
u-Md
og4i
!ir4
.0x+f
hf{\
ZI Q]
)S5M:
$UQo
t D?v
leOdj
[ oj
9cP0o
.!#v
7u-]
}ZsbF
vb2(!M
SF 0>
;)/l
2vvY
(PTa
bO=3
QmjIA^n
uf(_)
AddRange
x : |
S{s(
Tvl"/
dW L+n
{_?U&
ln=X
`})WA
f= $
XIv>)
$ jJ
9"E<
C[Q)
!D?M J
JR!V
>^Ts
HrV]
Q`&3-
3*<CG
d&k<
E;Ee
0aTN84Tq1MhkQAsLL8QBhP
WLOFX
=AVc
tgUT
Z`Kx
G[?{
"E?
"_):%
TmR}
#8^L
?qzed
5B#E
xk9
(%ql,
N~( 2
I\W&
/;:i
v_,X *
-GwF
bf~,
FI6I
zlr"
oY7=
:-ij D
j5Ux-
r|Tq
J+e]W\|A
p!by
+g6^
dt9e0
0$ )
"@u#
[B%]>
ayhR
*XyM
9U$s
+|#I
)Ta2T
%:1
e>SAQ
8 v:
D _*
7?W9)T=
CKDF
Fahu
}$je-nz
ja#3
%ip2
C(b K
6eP!_
,p{r0p
A]Jk1;
VLeq)a
~x#O
6 /(
V#U$%
W#j]';
c%=8
/do_
gYIX
Rie
T*y4
ZqW<
L#q"
/at_
U bH
0D2`
kT&!
^}z0
O.fyfb f#b
BcHn
H]z#P
UaL]
$Ui+
C}.onb
wK5
a:9a
X)^U|<
*")E
.:nF
i]fP{
[4~L
T#uB
T%2<
aDWa
z*cU--
],;R
4.@O
7s+4
Stjs
J!a.Qi
O&ON#Xo
(|+h
<luo
&W'A
U8CG/m
[5]L(:H
G8on&
xo[L
a]-cS
xb?B
t<XE!]
(c&
@MJ/
Yqxk
20XA
I8NeO
/[8j
apxPx
@K N8
0bZb
1s 72
-7q2
ltY1daA!_
Xq9v
3.h9
r?rD
-Q">
?ml0
'mV9OKgll2WCeSmyhZYlFzSAiKQZ4E2bckJ41Vb5
M c]
#;>LU
d FY
9/{Q
%p.+
u)rC
tKlD
h'zK
,DSA
C6UWW
`NX
LI=u]
{=mO
pYP3
lTleA
=}C
2 S|A$
?<hX y
D,<:
k:B6
o'[G
3jn
':1_J
t2pjT=w
ZX[+
- >P
+}c3
vy#g
1a aQ)
,IHE\
0Ch5
8v]bv>
F:@5m
z[WpTL
58#
|gP/
);F
8P#d8i6
>!D!
dNr
Kgih
w'1E
_oVNwt
JB_u7) O
x` '
n">9
-BNN
,jyd
6@[l
I/;
UvWxTE
5Z"
Pp_47
Vg1U
oL V
zKN*
-wD.<
['Gx
sbLg
vv3>
(ZwU-
Ec.d
g>"$T[
h/z^
9OG2&?(
E|wxy
e`r' X
set_Key
.1$B
vSHj
&ICN]y
uE2eM
HfVL
'XKm
_(%,&U3C
h6ZD
%8'p
BSJB
~lh{W
|nZ&
U} !\
6x^a1e^
#.p
%(}T
b]To
ABL
_1F-
9?XY
qV',h+6
.~@_8u
X>fu
zl1m-x
jbX\@|
Gc#D
";?z
y\CW!
I&^g
K~^
@yB_
&|@^
=~:A
roq"
<*Y'
-nLO
qmQ1
]1
gc qm
R=V r
zxCE
q8-C
yp6t
]"4O
\^3
:2:1A;
ZmZm,
];@R
>8pD
js|)rL%
hRe|
3-^)
6@ n
-8,Y
ZR>H
\|
s2[~
S4yF
=`d]
Zah w
%_,ZN
P i
J 3=i
q/^Tqb
zV$k
7>]m
&eg
4UX~s
BC F
No?#D
2VrX
25L1
U[db k$q&
?;~h
I~i*
u3@9
wMsP
[<G=
m4OD
m0FC<
q?C0=
(\:
&*F;8
>|xu
P0Oz
M&hX
nU]OI
7^3a
="-'P
i0 j
m#/&
GBTZ
%7LR.
:+9]
-0[A
,/Md
hWWO
T@ 9
ack p
` #c
$QoDr
N;RI,
'nNI$
z*F
w\t:
4M-#M%
C({j
pG7^3n
[p!'H
vu:
C!az
oDXg7
{
&*5rM
S.z0
dtil
hJ]h
RUSR
$aT`?
,R\k
Nfa
DZ>_
/{\H
zG:{
/&i5eb<x
'.EB}
KYFyI@
gI}s
SdL_=
*s0"
#Wk=;
0HL E**
pMnK
ai~eQ
;xb+ ?
ji>T
^ 3
o$Tn
xkO<b
3&'8
-37q
lBv&m
;{9%
y3-*q
/k]5
9(%j
XRV
$kY&
l~\U
y@!wkE
z?1P
^O:[)
}x |
LT_Hs
I_}L
xH$T
/MBQ
oj-DJ
28^.n`
:'m;
SrR9U
)E{q
m AjV]
uGH}
'mM0
a\al
Nb-d
#VaQJ
{>d5
'K)q
>''!UX}^u7
VcFD8SPSLtiLv9h9NqP1hCkSXEr06
#H"_
a_Ry
a{zS0'
2S7N
Tj7%@
? Sg
Y} 5
>$y_
Rud<
5/y4B
\R'm w
Wv(q\[Y
3@sd
66\/
7HOg4
u5=X
YhaM
wA/Y
GJKQ
sE ,ji
isCI
A_//
{aG~
+$YS6
`L)OS %
;b8!
Q\Zf
QlU6
1d#d
v7E(d
R x^
u ^Ge
;a3w
/N5M
T5l&r
24TLK
6};^CSW
;Agb
~A) G
|C`
_6vk
4XXs
sp*:
9\`B1
o\ #H
PpP-
eXNJ
]=[z
=T+$>
4Jmbi
v-+psLt
jP{?
AtDf
za=v
+Ha)
JL=. n
E.uk
s+~$
>N;d
oghPj
i >[
QWp
;+\7
u ;k
{d>NF
h9Z%
,}! +
ue a#
;yha
{-$b
pF_}O
h`r?
y#qx
><y@
@#u7$
S;%d
mE@\
Dg)q
'h`/
[ rBK
Uru"
_Ph|F
qC2
^ygy
']j{9
J#\[
8YfD
o0eCr
b*l
}+[N
DH?3
q[Po
,#c='}
^atu
rS(q
<GZ=wB
Tj}t
X_'3
)v2o
!-r1{
0 NE
\<"d&
bl3&
@R=){
3QBK:
-1'l
?_e=
R+S=nG
:>1p
KNf=
,((HX
'DeI`z
Bj;+;
VDA=
&0\+
f8\
5 tVs
<Yw
+aO}O
U=}n
t1M8k
P}T" \
'5u j!
LBR
X8=;
'?E?6
cwmfZ
ikP/
IIUo
r|O^<o{;0
0g%w
Z5>zZ
cI$T
3[64
KA+G
amhm5
XuiQ
6;w\
S"KU[5
(*#l
Z# |a
hYc"
|_}'
I 2 I~P
G#E1
8"HP2
~(3H
#s FkS
G,o]p
tg2G
-cI`
{xy=
=qj!
@z|"
XZ["8
$8=R
' n
|,\
f `7
2uE\?&R
/U~=G
JGkA
K\ g
jD#}c
Xur`
?Nwc
Qx\G
`Il^
Servermarch10
x#i/{+U
0/F1A
\(|T
+Z,y
lW4
D *m
j|>h
jEx
.k2,
BGy4
cUMw1
<<$0E?
sw!r?
P)}6 s
'HOTyL78AROGdq0bs8jfkELsg2lP3AkNta5Mgeai
)jqh
F|Lz
-(rXk\*
qINoy
B~05
YwU\
!-%)
l+HY
[5jD~e
l=2V
yM=4
Load
[ZP4
eknG
#j o
V|&}
N>Vez
9F@l
<W$
VX4S
^ $`
3$5+>
iFsu
T="X
am>I&-
/lvz
Zg6m7
1hM\6
| Br
1?g PL+8W
o2tR
.mE
Vs\!3>a
c(tzB
#A)k
d })>
Vx"~
dU3#oH!
kg}
t9dIU
OUXBZ
1H2j
{2$
HBV >
W'g2
0};IYu
Ar>x
| B@
s 0`
!djx
TZ^C
?*PbU
RY~m:B\
9ov&
^oy{
zE=?
k\_M
.- ;
x#^}0
<EPZ
f-4
)ph;
T!g$B
<h F
z4`,
>$Ry
\@FP.
9Siw
Au5;
e:m
,5Yf
_of0
X}el
iu,qc
F:C
t0z(
p\a
A)H}
VR)k
L\6
iC/S
`?W
Object
] k}
(C$
QYQ}z
}T>s
(g36
jxZ2$To!t
:C7T
:nj=
cO6#A
Ge 1
Y~W
U8Y7G
Ij%FN
TEg g
To0s
B#uey
y{i~
(x6T
}p`L&VS
TuYCs
_=rn7
L} >
&F ^
2::?
IB
' p%^
G5a
8gb!
I.To
<:t{m
#"]
6eq=
r;-l
MethodInfo
a U
$|-
i8N
eAh8
tO j
uDzb
]SK
f\lh}mS
4EC@cGl
X[j?,
(Yuls
MMjE
w| |
DL$(a
By:X
eqIqtp-0
]:A^Fp
D] h
r#x#
QOfQ(
G1YuT"
,.Bn
oMaw
s )jGQ5[
DzbC(
Pl;a
H9 t>a
I{PGl
'*/
9, t-
)5Z#
oWvAF
oCWl
8(mLZ
7?,2r
:Qd^v
Snsx
9@#2:
n6'
A_2j
'R5>
Kb$D@qz
p~oPR
dR :
v+"_
MP1 h
V gq
vdXm
"%x^3xr
_9| W
{v"_
Gsu$
Q(GE
>Mz7~
BzjY
t1*
1=h)
vB#@
{8F]
nS5q
s/G;A
I.?v
FP8B
;c1_G
<m<1
r)R u
jpsl
c<(g
X -P
\.4
F/%]
!q&Dm
M/ut
@/(R
%VVH
)SWu
|h &
DC6V
" m|
QByo?-
Fy:}s
A)_4
qTR
( b @;&
YB|+
$5{Z4
v*?l
s+2I
Qs'U
K<X}qb
_Ey8,
rveb
F{o?
| p=
ep^{k
%:7e
0&eK%
|c).W~
{ d<
gM6u
CUj5
Qu j+G
>d>K
W\xE
0H?;
<>T#H
RRN=
n?6^
7I J
MSYm
B*,EZ
h*{_
WeTt
pT~#
@O >@
$`DS D
"3+G
afwF3
;qJp
_Ph
l`|W6
i1$o
Ix3WE"
76'?D
h;NE
0,z)+w
%p!Ij
7dU?X$
l-"Q
! :b
iSba
~}*#,U
(Vy/
~g[ Nm
!98(m
$4E{)
i9{H
u|Y(
jP& -
T&S3l
-G1
OL`.t
#b"awf
;r:M
4;j
gp}
>_w{4<hvA0
xS_n
XSM
X!bt
:9~_
\ ~J
3v0s *1
? '
6|F
^J$4(
yp;2Cp>#PgH
^UEE
e rk
rho>
5dWp
@}Jt
/r7R
%7zx>Qi
X%[\
hZ#F
|!=
~^K>
^Q"\
6Tse
Fn<_
M<ro!
<O`"
<5pK
~N=0
uWH,
JYdo+
+FuE5
]Q(zI(
~fkQ
<s p
aKSi
6gu'3
uW=[
} s:
ocd}
!y14M
IEW}H
Z=BQ
2V~
4\F\
,[R%
Ezb~
{Ap7
N<Z>q
`H_(
WrqF1
Cw]j
Di6o
NOOE
>:qs
Z[+.yz
(hYOq
->ho\
Tz!-.<
+ddV
E>AF
t1M"
c1xdc
Xs rF
fs@-m
vNN]
$
<WA
e ,4p.
&(bO
Qi\j
e"h7
T!q1
jS_-
\4Ce(D
B?Ed
kN$s
5y%l
?nhN
k:cZD<
AD '
9n96F
&Gbx
"hBu
0Fjv
(8 -
e:C7\
k$9%"
Saa,
sG:3
u@(A
Go,vu
9fVrjo8
x~<f6
| $<\
z7gn
owyA&
<542
gP< j
GetTypeFromHandle
C!-A
xQ4"
T_TM
62
.toTM
mHLk
<n;T
P[{ I)f8
/9 ,
DateTime
m(15
-0rA*
\KG
,!cE
sL.P
KMfO
f7BM
FlW2
g5+6
A/PM
12:I5
9P]7
jSJ @
3AS.
g~IC
gd=jyo
@\iVb
^b9~
wTMT
Riwo
E ;i%
l&Fs
:1|
:El'
CYT
P%Pm
2Ux?d
kM/M
I:k5
mS`8HM
9] p
pTrW
V$S<`
uefb
0.X"
gv H
K%3i
i;w9
ZxE"
T*A^T
A(;n
;Y#52
a&qa
(\@0
6>{l
Mu!m
2wg'
P-ZE?Ju
kib>
n1;-
b^j;
B2F~.
&As8
%`7
nHnz
n, =
W5J
vO#e
H6Y?\b
HN+-
5Pb:
|!K
PqwA
d(SRC[OFP
2I0]
xcf0
i`4N
t dR
2r7jFI
O!trL4
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
sCu
u bq
)n#%
HsyW
C#YTf
]{@N
NK;D
m&DS
,,*}
[EcH
9L*QJG 3
%!4
lL1(
YMtr
n-bN9
CFQo
g `c
=!0T
>ZP"M=
@ Ih
^<p4
__{A
0Io$
l QJ
=T y
-JSG
6mc
3Gn}
^,Z=
X,F
X:.[
Pb~$
g3FG
c)7N{
`Wn8
8O@g(
67s,
%-64g
gMc5
LVhm
sCS}
vkX);
n%jY
+&=@%2
@*J]q
k?H9
I.R^
[BAn
dZUj
kSBkf
[RZ7
N T
|\%8Y
~tiMD7 * 6
<lEZ~I
_,1:
_l^>|uR
,s'//
mLa[DQ
c8rn
v63N
wq9g
*C.?
0@4[
s$X
+v$
2yYP9>
RV,o
%S(Z9,
JLj
EF1
qXQ~
=:qq<
0::i
)'J|
Df$Sq
dpv
Kk ;9#
~NGz
&]"8
AWjt
%&nh
*Im(
F39<
s2zB
|Irp
p0XcZ
ye&"
7ncG
w~h ] #
:P e W
1DEU+
9op>>h
D>b|s
KP-b
Noi+
?/{=
,5&"-=6e
D"'M9
"qYs
DM ^q
G+! #
r[;~
40Gb
;LO\
dxW6
cCw!
z:nD
Fr76
cRN>p
x (X
? =
m\pA
.,CX
]pGq#
)xt'
]%1]}e`
^0N;
=|jy
['l0
9/E)L
6Q@K$
zv+J
y9~t
]z/9l
T;La
3soC
BQiu
[02xN)
T~Yhb
7@CdnRFpT
wJZ{
#Nud
ri):
&Sp
Cq -
)(v.
.@v4
CsnK8
bs]#
Wb&/_
H i1
F`m\@r
s#M
yvHk
< gY
f<+9
lwQ
3U#i0
IEnumerable`1
J3M^
6b,<j
pGR
r5",
[kqU
qU>-
3`p7
E E[
{zG.
bW5o
w^]\
`|@X
CuIQ
?t,
71#p
oi4f
.{!9
"nUzvRrsPeorAjenW5sawJD2qIf5VKVg7IZ
[ ~
'xs{
@K&+
x%uF.
<C^
;09h
f@(;
M"GP
^:Ca
]t{"
F[T;
IVF4
AJ^_
!w ^
^`L>
u\W>[I]
[DZ{
m~$b
#'[ :
mELs
V(ufmC
_)!\
II@^
/H#:
dgg)
]SV
%+$y
o-b
|z P7
.Nvgq
G>q"/u
4JH__M
?Au&
4B| L
,ECl
[1bk
}j,l`
z$d3<
kIAjv
Np\
C: I
!z&*|
Q',>l
D/ a
lC n
[bW!+
W+w!
$;w^
System.Collections.Generic
ZQ `
+ ij;
f L\ZA}
1Q72
H|PO_
QFk+
8+Rc
?+1o
]-PB
Dnnb
h0E,
zZ!? {
qH0`
4agx
87b7
`jw%pw
y>9DS|
b/>s
B_+w
a 3}>
}~y*4
?dM5l
$gdj
xdq!z
gLa%QsX
<j]8
)mpP%
i[ Vt
) jP]KX!
R /
E<Y>
,V y
IRJv
9DTL
hl2*
dU=<;m;\
r:3l
w)59
U%m 2
_ FI
H fo
NYZdb8oYkInLrMJaBuG4UG
)~>.
9~4|
+ ;
(OxY`|~
|9t] q+
&f+i
+}2pH!
uJWA^
NFIR
gf-+
x3Fx
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03b_64 Seven03b_64 VirtualBox 2018-05-11 19:20:50 2018-05-11 19:23:44 174

12 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03b_64 Seven03b_64 VirtualBox 2018-05-11 19:20:50 2018-05-11 19:23:44 174

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\Servermarch10.exe.config
C:\Users\Seven01\AppData\Local\Temp\Servermarch10.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\Servermarch10.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\Servermarch10.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\System32\tzres.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\Servermarch10.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Servermarch10.resources\Servermarch10.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Servermarch10.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\Servermarch10.resources\Servermarch10.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\Servermarch10.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\Servermarch10.resources\Servermarch10.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\Servermarch10.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\Servermarch10.resources\Servermarch10.resources.exe
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Windows\Microsoft.net\Framework\v2.0.50727
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2384.28841843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2384.28841843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2384.28841890
C:\Windows\Microsoft.net\Framework\v2.0.50727\regasm.exe.config
C:\Windows\Microsoft.net\Framework\v2.0.50727\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.net\Framework\v2.0.50727\regasm.exe.Local\
C:\Windows\Microsoft.net\Framework\v2.0.50727\RegAsm.exe
C:\Windows\Microsoft.net
C:\Windows\Microsoft.net\Framework
C:\Windows\Microsoft.net\Framework\v2.0.50727\regasm.exe.Config
C:\Windows\Microsoft.net\Framework\v2.0.50727\regasm.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Users\Seven01\AppData\Local\Temp\a14ef708-47a7-4cd2-b4f2-854055e80618
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\Globalization\en.nlp
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\mscorlib.resources.dll
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\mscorlib.resources.exe
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\Microsoft.VisualBasic.resources.dll
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\Microsoft.VisualBasic.resources.exe
C:\Windows\Microsoft.net\Framework\v2.0.50727\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2648.28843921
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2648.28843921
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2648.28843921
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\display.inf
C:\Windows\sysnative\DriverStore\it-IT\display.inf_loc
C:\Windows\inf\display.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\WMIDataDevice
\??\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
\??\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
\??\{E43D242B-9EAB-4626-A952-46649FBB939A}
\??\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
\??\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
\??\{9A399D81-2EAD-4F23-BCDD-637FC13DCD51}
\??\{5BF54C7E-91DA-457D-80BF-333677D7E316}
\??\{C2D43895-0262-4873-A789-C2F96D24B693}
\??\{2CAA64ED-BAA3-4473-B637-DEC65A14C8AA}
\??\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
\??\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
\??\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
\??\{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
C:\

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\Servermarch10.exe.config
C:\Users\Seven01\AppData\Local\Temp\Servermarch10.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\System32\tzres.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\Microsoft.net\Framework\v2.0.50727\regasm.exe.config
C:\Windows\Microsoft.net\Framework\v2.0.50727\RegAsm.exe
C:\Windows\Microsoft.net\Framework\v2.0.50727\regasm.exe.Config
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\display.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\WMIDataDevice
\??\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
\??\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
\??\{E43D242B-9EAB-4626-A952-46649FBB939A}
\??\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
\??\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
\??\{9A399D81-2EAD-4F23-BCDD-637FC13DCD51}
\??\{5BF54C7E-91DA-457D-80BF-333677D7E316}
\??\{C2D43895-0262-4873-A789-C2F96D24B693}
\??\{2CAA64ED-BAA3-4473-B637-DEC65A14C8AA}
\??\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
\??\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
\??\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
\??\{5F6D61D9-D207-449A-BD48-652A5D1F25BE}

Write Files

C:\Users\Seven01\AppData\Local\Temp\a14ef708-47a7-4cd2-b4f2-854055e80618
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice

Delete Files

C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2384.28841843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2384.28841843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2384.28841890
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2648.28843921
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2648.28843921
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2648.28843921

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Servermarch10.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\69fcdd7f\64c81f7f
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ef7bb17\7c266e58
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Servermarch10.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Servermarch10.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|Servermarch10.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ef7bb17\351efe62
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regasm.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\2facbc93\3c76a805
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\regasm.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1DF4D951
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\regasm_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\FileDirectory
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Windows|Microsoft.net|Framework|v2.0.50727|regasm.exe.Config
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Windows|Microsoft.net|Framework|v2.0.50727|regasm.exe.Config
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Windows|Microsoft.net|Framework|v2.0.50727|regasm.exe.Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it-IT_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\1c4dd593
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\4deb99ab
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\REGDBVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{E43D242B-9EAB-4626-A952-46649FBB939A}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanIpv6
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanBh
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanIp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{5F6D61D9-D207-449A-BD48-652A5D1F25BE}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\EnableDHCP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableSecurityFilters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\TCPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\UDPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RawIPAllowedProtocols
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}\NetbiosOptions
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netbt\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableLMHOSTS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DatabasePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseZeroBroadcast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpAlwaysSourceRoute
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpUseEtherSNAP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableDeadGWDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUBHDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUDiscovery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ForwardBufferMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\IGMPLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MTU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\NumForwardPackets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxConnectRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxDataRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpNumConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpUseRFC1122UrgentPointer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpWindowSize
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\EnableDHCP
HKEY_LOCAL_MACHINE\HARDWARE\Description\System
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosDate
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
HKEY_LOCAL_MACHINE\SYSTEM
HKEY_LOCAL_MACHINE\SOFTWARE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1DF4D951
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\REGDBVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{36001453-74F5-4D51-9CF9-0244EDAE1F69}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3CC79130-D6F8-4A2D-8A6D-5068F4BD3351}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{583F5682-8FB6-42A6-BC1F-573D74933B97}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A076851C-5907-4EF6-ABE4-9F21C451CA12}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0012\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\EnableDHCP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableSecurityFilters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\TCPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\UDPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RawIPAllowedProtocols
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}\NetbiosOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableLMHOSTS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DatabasePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseZeroBroadcast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpAlwaysSourceRoute
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpUseEtherSNAP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableDeadGWDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUBHDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUDiscovery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ForwardBufferMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\IGMPLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MTU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\NumForwardPackets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxConnectRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxDataRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpNumConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpUseRFC1122UrgentPointer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpWindowSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\EnableDHCP
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosDate
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\regasm_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\regasm_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
d757a7e1-c0a9-492a-99e6-d6852f999ba5
Global\.net clr networking

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.VirtualProtect
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtProtectVirtualMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.GetThreadContext
kernel32.dll.Wow64GetThreadContext
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.ResumeThread
kernel32.dll.SetThreadContext
kernel32.dll.Wow64SetThreadContext
kernel32.dll.WriteProcessMemory
kernel32.dll.ReadProcessMemory
kernel32.dll.TerminateProcess
kernel32.dll.CreateProcessW
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.GetNativeSystemInfo
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptVerifySignatureA
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptDestroyKey
kernel32.dll.LoadLibraryW
kernel32.dll.EnumResourceTypesW
kernel32.dll.EnumResourceNamesW
kernel32.dll.GetModuleFileNameW
kernel32.dll.RtlMoveMemory
kernel32.dll.FindResourceW
kernel32.dll.SizeofResource
kernel32.dll.LoadResource
kernel32.dll.LockResource
kernel32.dll.FreeLibrary
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
cryptsp.dll.CryptGetHashParam
kernel32.dll.ReleaseMutex
kernel32.dll.CreateMutexW
kernel32.dll.GetTempPathW
kernel32.dll.GetComputerNameW
kernel32.dll.CreateEventW
kernel32.dll.SetEvent
ole32.dll.CoWaitForMultipleHandles
ole32.dll.IIDFromString
ole32.dll.CoGetClassObject
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CoGetObjectContext
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.LoadLibraryA
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
oleaut32.dll.#500
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
oleaut32.dll.#283
oleaut32.dll.#284
oleaut32.dll.#9
oleaut32.dll.#7
oleaut32.dll.GetErrorInfo
oleaut32.dll.#149
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.WriteFile
kernel32.dll.GetModuleHandleW
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
kernel32.dll.GetCurrentThread
kernel32.dll.DuplicateHandle
kernel32.dll.GetCurrentThreadId
user32.dll.CallWindowProcW
user32.dll.RegisterWindowMessageW
dwmapi.dll.DwmIsCompositionEnabled
user32.dll.IsWindow
user32.dll.GetWindowThreadProcessId
kernel32.dll.GetExitCodeThread
user32.dll.SendMessageTimeoutW
user32.dll.PostMessageW
advapi32.dll.GetUserNameW
kernel32.dll.LocalFree
kernel32.dll.LocalAlloc
advapi32.dll.DuplicateTokenEx
advapi32.dll.CheckTokenMembership
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.UnmapViewOfFile
kernel32.dll.VirtualQuery
advapi32.dll.CreateWellKnownSid
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.GetProcessTimes
ws2_32.dll.gethostname
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
kernel32.dll.GetACP
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
sechost.dll.NotifyServiceStatusChangeA
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.ResetEvent
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
ws2_32.dll.inet_addr
ws2_32.dll.WSAConnect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.shutdown
kernel32.dll.RegOpenKeyExW
user32.dll.GetSystemMetrics
user32.dll.GetDC
user32.dll.EnumDisplayMonitors
user32.dll.GetMonitorInfoW
gdi32.dll.GetDeviceCaps
user32.dll.ReleaseDC
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
user32.dll.GetClassInfoW
user32.dll.SetClassLongW
user32.dll.UnregisterClassW
user32.dll.DestroyWindow
cryptsp.dll.CryptReleaseContext
ntdll.dll.EtwUnregisterTraceGuids
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
oleaut32.dll.#4
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CreateStreamOnHGlobal
advapi32.dll.RegCreateKeyExW
advapi32.dll.RegSetValueExW
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernel32.dll.SetThreadToken
kernelbase.dll.CheckTokenMembership
kernelbase.dll.AllocateAndInitializeSid
ole32.dll.CLSIDFromString
oleaut32.dll.#285
advapi32.dll.RegOpenKeyW
oleaut32.dll.#12
oleaut32.dll.#286
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#290
wmi.dll.WmiQueryAllDataW
wmi.dll.WmiQuerySingleInstanceW
wmi.dll.WmiSetSingleItemW
wmi.dll.WmiSetSingleInstanceW
wmi.dll.WmiExecuteMethodW
wmi.dll.WmiNotificationRegistrationW
wmi.dll.WmiMofEnumerateResourcesW
wmi.dll.WmiFileHandleToInstanceNameW
wmi.dll.WmiDevInstToInstanceNameW
wmi.dll.WmiQueryGuidInformation
wmi.dll.WmiOpenBlock
wmi.dll.WmiCloseBlock
wmi.dll.WmiFreeBuffer
wmi.dll.WmiEnumerateGuids
iphlpapi.dll.GetIpForwardTable2
iphlpapi.dll.ConvertLengthToIpv4Mask
iphlpapi.dll.FreeMibTable
advapi32.dll.RegEnumKeyW
iphlpapi.dll.GetAdapterIndex
oleaut32.dll.#15
oleaut32.dll.#26
oleaut32.dll.#16
dnsapi.dll.DnsQueryConfigAllocEx
iphlpapi.dll.GetCurrentThreadCompartmentId
dnsapi.dll.DnsFreeConfigStructure
dnsapi.dll.DnsQueryConfigDword
oleaut32.dll.#23
oleaut32.dll.#24
devobj.dll.DevObjCreateDeviceInfoList
devobj.dll.DevObjGetClassDevs
devobj.dll.DevObjEnumDeviceInfo
devobj.dll.DevObjDestroyDeviceInfoList
setupapi.dll.CM_Open_DevNode_Key_Ex
devobj.dll.DevObjGetDeviceProperty
cfgmgr32.dll.CM_Connect_MachineA
cfgmgr32.dll.CM_Disconnect_Machine
cfgmgr32.dll.CM_Locate_DevNodeW
cfgmgr32.dll.CM_Get_DevNode_Registry_PropertyW
cfgmgr32.dll.CM_Get_Child
cfgmgr32.dll.CM_Get_Sibling
cfgmgr32.dll.CM_Get_DevNode_Status
cfgmgr32.dll.CM_Get_First_Log_Conf
cfgmgr32.dll.CM_Get_Next_Res_Des
cfgmgr32.dll.CM_Get_Res_Des_Data
cfgmgr32.dll.CM_Get_Res_Des_Data_Size
cfgmgr32.dll.CM_Free_Log_Conf_Handle
cfgmgr32.dll.CM_Free_Res_Des_Handle
cfgmgr32.dll.CM_Get_Device_IDA
cfgmgr32.dll.CM_Get_Device_ID_Size
cfgmgr32.dll.CM_Get_Parent
user32.dll.MonitorFromWindow
user32.dll.MonitorFromRect
user32.dll.MonitorFromPoint
user32.dll.EnumDisplayDevicesW
dxgi.dll.DXGIReportAdapterConfiguration
setupapi.dll.SetupDiGetClassDevsW
setupapi.dll.SetupDiEnumDeviceInterfaces
setupapi.dll.SetupDiGetDeviceInterfaceDetailW
setupapi.dll.SetupDiDestroyDeviceInfoList
gdi32.dll.D3DKMTOpenAdapterFromDeviceName
gdi32.dll.D3DKMTQueryAdapterInfo
gdi32.dll.D3DKMTGetDisplayModeList
gdi32.dll.D3DKMTCloseAdapter
wintrust.dll.WinVerifyTrust

Execute Commands

C:\Windows\Microsoft.net\Framework\v2.0.50727\regasm.exe "C:\Users\Seven01\AppData\Local\Temp\Servermarch10.exe"
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03b_64 Seven03b_64 VirtualBox 2018-05-11 19:20:50 2018-05-11 19:23:44 174

1 HTTP Request(s) detected

http://bot.whatismyipaddress.com/
  • Hostname: bot.whatismyipaddress.com
  • IP Address: 66.171.248.178
  • Port: 80
  • Count: 1

GET / HTTP/1.1
Host: bot.whatismyipaddress.com
Connection: Keep-Alive

#infosec #automation

TheSystem Itself @ 2018-05-11 19:24:10

Detected family: #Ispy

TheSystem Itself @ 2018-05-11 19:36:03