MalScore
100/100
MalFamily
Msilperseus

11.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 39/66 Related 2257
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 189.50 KB (194048 bytes)
Compile time: 2018-05-12 14:41:14
MD5: 8cf1c74955a561ce883a703b1faff789
SHA1: 14ffa74eac88ab864f68973ab3c748c143f4f84e
SHA256: 63eca8a02459496ca30e77bd24c25e3fc7513a886f7f7cb5e2c6978ba5d75e29
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-05-23 13:08:10
Last submission: 2018-05-23 13:08:10
Filename detected: - 11.exe (1)
URL file hosting
hXXp://lokipanelhostingpanel.gq/work/worknew/11.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-05-18 13:04:26 [39/66] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x2eb84 191488 716d3135b2efaa73af11734d5fefc9cd 3e769be49a94f1d1ed977f648a131f3f6ec71f32
.rsrc 0x32000 0x5c8 1536 89bc3c594534a0d02055785688dd6eef 2436acb858227a51c414ad69bd8fc10e8f4590c2
.reloc 0x34000 0xc 512 5538c96c6ba7debf9b4cd13d2ef8cae0 b63293627e97afd6e85149e3372b27d4b7ca3f74
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x320a0 828 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x323dc 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright SpotStream 2018
Assembly Version: 1.0.0.0
InternalName: SpotStream.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: SpotStream
ProductVersion: 1.0.0.0
FileDescription: SpotStream
Translation: 0x0000 0x04b0
OriginalFilename: SpotStream.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
Normalize
Assembly Version
P4X05o764Qp
34N13ypDo
LegalTrademarks
VarFileInfo
Comments
000004b0
Copyright SpotStream 2018
Segoe UI
InternalName
LiC
button1
CQ$
1.0.0.0
SpotStream
Add new Radio
mYPhxodUo1
StringFileInfo
qCuq
SpotStream.exe
listView1
About
SpotStream.Properties.Resources
FileVersion
,CQ
VS_VERSION_INFO
8I3L5tRm44iQ1
Translation
ProductVersion
FileDescription
NIY11m28SK5wC17
OriginalFilename
LegalCopyright
Stream
CompanyName
fOGpWCNmJuKRZ
Form1
ProductName
button3
button2
M5rkiZND6Y6s
button4
lXE=B?Y\
m_0MEPZ 3
?UQ7
LWN-
;TDbsX
ve0v'~>i
"pt1
l4/!
U>Z ;
}@5*
W8Gutl{
q^Z6
iE)Z
10CQ
jvxH
Eg[N~
1(AxM
* gM
x [qb
W& I
t=LQl
; )!Y
:4f7(
sm2
F@r*9"
;}05Ue
hFM(li
AutoScaleMode
](.-
)XkX
ZQd
UnverifiableCodeAttribute
Yj/D
3m&O
LQh0+
c*5~1
uKea
k`XPTb/
ER{p
7pa,
^ }q
z^cT\
bVhS
<& 8&/9
5TJC
.VfZ
H .~
5(;U
get_Controls
dQ#7
K> Os
Ni48|
5i@aZBi2
eae%
ntvSx
`>ah
*N<!
xDE%
kJA=
+cd$
L$]>
pJO R6
u`c.
wjI\
TrlH
Unjy
x6y.(
?>=jg:Y
Int32
Dh}?
KrRb
IZNi
?,";
?\&v#
\cke'
hkhg
h (3%
+#_r
jx)U
J.xn%
k y
.S1N
AsyncCallback
MG$z
d6d_U
_~RK
-,@7o
D%&+
4<tE
wygoL
a.}
Q5r-
_at+,
System.Security
NiI\
O~+$
:!=6H
oWe6B
>/-W
]!;e
;V?6
"'\w
d)x;
xEA"
+iSH2#
S@/<"&
^|*{
%ub5.
dUYef
IEnumerator
\]#
01F |>
QF1I
R5NC
6`Rl
r6QB
B ~e
)|~/GE
wr-f
&]uL
%s{[BA&
jHPq
`zjQ`y0`
EnableVisualStyles
Point
$ *s
c3Ykz;
$hJu
DoVyUNQk
?gQ!
C e$M
AssemblyCompanyAttribute
Xu}P
[`;+
Jlk"
##naD
c&Lo2
!NN$, (
2$&
AAe4
EditorBrowsableAttribute
U4Z[`
??1=
a nS
d{'d:
rs"Rq
tx}iV
L>2UU
F? U
9O9dc
>Y[f
0gN8
\,+FV
%yL.
_3[5
P" v
z_4vuuM
08d4 !i
lU^
1igFQN0
1(%<I+C
W1]
JkvE(
k{3
[A :
l -Dq7
&%/d
UB (6>Ok
WL|@(<ef-
System.Security.Cryptography
L{yL
%}Fr
f({i'!
N3^N:
PADPADP
N9=:H
9inL
*a:C
C&O5+
ZO_
1Za+
liZZ
PUe_
eP9N
A15[_
)lpV
vZ.
^N!A
r`ah .]W
Y VIfH)%
=+A,
AssemblyTrademarkAttribute
L[BH
<a`(_o
M.%;,
xm }
OZ Q+$
|.3A
@ReT
F=CZ
+nK#
k fD
jlur
S/"z
Y=yW
tcdaT
f}9~
%]yTF
SettingsBase
, sE2m
)) Z
[OQ;
#Blob
Control
u>\y,
?rCh
2;@9
_:*0
f}BP?
JT(
NN/R
set_UseCompatibleStateImageBehavior
e~ V
6w:!
2[xX
>qI?
,y_lTv
mJM3
G>"g
AssemblyFileVersionAttribute
'4#*
b=:W
M LC
HLd&LC
i\i
2]V^Q=
2bmK
99GJ
T3f]4
@Y("zM3
@Wn'
m#oi
"f2;
S>4M
T0T9
q=;f
s3hs
/& (
-W3z
kSX2
Q'yJ
hdG~
e%&+
SCV *
mwWBL
Td\u
P<ja
)kP6
`5r@
+h1A
K 9,Z
zapM
_XH1
(:k
{l@ x
)yE+
%X3-
AR(G
O,Iu
vB TI
^5:T
!*\*
26rO
'*h
qXW`
P0x-
fkj.
'*AG
B8t#
jBU)
4`mS
#L '
3>a+
YI4G.
Lq&@}
MC'J
4Tf@n
A=v@
:+
1T!"Y
1zx:u
}f8;!
FxS7~
|/].7
6kv=wE
-=eS
;f uQ
KnCt
"HJIVZ
-&b{
nE*^e
5k,W
8mHU
5bc|3u
z\znPD
xLxq
)]mb7
N,%w#
F~#,Z
5N]KQ
d85Rm
lzC)_
N*S"
+$2z%
[HJC-
$I(&u
O6{\O
>G 9\
Y*A
JQSt"
BCF-
n [
}2 -3,h
9UPs"
_Mb%+
M s;
b')g>
+3D!
(I{d
|B#!f
4|q6Q
.text
List`1
vqcj
maTTPEO
5k1sL0e
O|]j
Clone
FWcE+
CY"\
Mh6(A
}~j'
%nD"
o& +/
Jd-u
r)QMU{N74
x&W:N i
Hs8F@
wU@w
X}
Button
gx9U
R;@z*UA=m>_t1US/cK%W6t],"
$PPg
ed?%
WU7^kO
\da
)+Mh
lnF*&
mU_3}
[Xve
{g;
r=PG
9-xb&
kU/D
6 S [4e
X%N}u
<YKK
OBq%2
d %Kl[
at.Rw
6| I
s 28
Y\glI
Copyright SpotStream 2018
Resources
CyP"
Q&v /
[+}T
~ sXF
~ ~\
3&dHaN
,t g0
I4=O+i
*za
(G8>
Q*j\
+[
VZee%
zoM0}
Xsa
@J9"I
;0J'
\<QM5
iI3w
X!%&+
;Zt6%
^[&t
,(a
`.rsrc
4.0.0.0
xa]*^
AqhF
{e bj
%10@
CreateDecryptor
aN u
>3ZaY%
4CR(
{(H Ci'
>ot1
result
d%HBb
!P? J
r(q{
"Jq8
Enumerator
?j6z
iF0
:2%'
gVJ^
?R6@"jI[
aXY ;
tCK1
6mQI
) F6
5Nk%I
MX1e
Settings
6Y7\
4lXQ
79]L
f,sf
W&.9[
3qNG
`4%Jd
.^3G`1r*
9&X 2
m0YU
h3q\
i( )d}
QW0;
9j ]
'[ b
5p 6
ZTZ
cSq
Load
WA[q&>5
z[^N
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
UDK)8KS^7
Ze 6
I6 WG
u4rN
EpOF
U1oSg6UU
jMjD
H35/D
0M1,
FG.)
d|Rj>
/=R!
n7 tmC|I4
L)W:g
tlumib-
f,*|
/K\/y8
GetEnumerator
D#q-
@%m7
pV]]n
:/R*r
SymmetricAlgorithm
!4nE
&qKlx
F?b5O
&wwz6
,~%g1E
;T*&7
U;=
o3%]r
t*VJ
VsRFY
(mIr
jt=6
d0GALt
X`cZ;
,Fo3}
v`c:7|
!bP,
k IC =
)e;W
HyNk
'-/{K1u2
MY@^
0Apt
@QKS
%&8i
aS@z
^01=
J~@X0V
QdNy
V 6CV
%&8O
d n5
\$F@
get_Assembly
aJQH
yU7
[\;X
4<bRJ
5tT$a
W^Yj
@U *
(Qz")
u9h~d`
%&8V
wkh7j
xYc
7 H?gi
+Z6y
.bvG
bWx
&XS
hy%&
~VZ2,
%&8:
$ ^+
{Nv/t
_<ub9
0i^E
System.Reflection
zbMc/
ZH;Y
{*"5
_~O_
System.IO
WrapNonExceptionThrows
wZhU
Tlc
{ }\
%S(M
K)q)
M#n14 ~Q
H_57"4
? n.
>y^M
t ([
BKJ
s5pN
lrpv
k/26
H=a3
bg:mVT
y\?h
)gFZ
Mros
s- %I
cn0Sq9
D )K
4Vj-
4ts/sDd;yz
0BqX\
M OJd
u",]c
G{$0<Z/
STAThreadAttribute
lSP}
@Qp g06
|n`^0
9@i7
vb~1
{3 3
SnKy
2!9J
System.Globalization
GetLoadedModules
l2mM05ovG6uZe6i642oF8Ma5GhOC5c3GXenYhDFY54d6x5QH7hnBBOeYcpGd1m8w2nBATKj0 PTD1mSJQGDX71EJ8O515vpSFz3J3Q777vN44ap9X6Mvjl7Aj AENr3LsA6CrIOAROZMySOsrF 8j32n02tCP3ta1BL3cnRO1LdULvVQwbfID3vy dKyiM3ho8ewGTPD7ZRXkibOqcZ7XlW6Zgw8dlzpa4zMRrKcLbUxwXN2B4HF55 CvrXtqQtVsv5o1P68S5w4RsJBS36het2e3wktUk541 EBbsA57I69TP4ChVavSL071l3FyWx1K MSoItt3LjV62Lo0hM7JJvqHFI873H dEylCmhZuz1GuoL8ZPOQKyrAEpLj8358E70 NtlYA5Xdap4l3Jjrz9kyfxgfb7Z031C5xc5zw8QXbOtiuso9UNTOXMViMG6CfgjsmI6kX349sMWR 741cjqzi7hlGWmq1N04y M
.XHM
0^ll
K$7 0F 9
se;52
@+6c
Q]6f
W*F#
W-%Y.
A:@)
tM#*9Il;
_C:TU
System
EventArgs
Application
,#,a
}u >
\r\y#q
ZA[y
hpddT
ry&'
xir5C1
$67fe95f8-743c-40ed-9528-be244551dd1b
X%
T01IB?\[w\]%ku8X_\&}%8M)lI\+%.resources
|)Mx
DpA-
%u&K
Lk3$
*'psMy0
U,sw=
DxQU
"OJQ
k `J
Y\LR
i ~M
{RYD
uu36d
v+Vy
rnx*
#Strings
V geG
System.Collections
NC=_o2
IDictionaryEnumerator
&7m]
DfR|
M d0X?
aH/M
k {F=6o
Z)H4
yJ\U
D0AQ
KTb?
vUX~
,abZ4sg
Environment
\RGj
7H H
sc>4_
#^O#
K>y4
\[<-
+g.IL
RnMh
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
FAzg
HB>d
IHV=
io7 v
u$u1
Vhf1
$mN#v'Mt
h77K
PMqmq
I*7l
PGuh8H9
x=LT
;1s
9DB
Ze%
cc&H
P7:A $
System.Diagnostics
GetType
pxO
ZC,
) {a
Yz: S
TTU6
eQ)
.#mx
PpJ_
Zx=!NA
@iY(
xf^T
*N1)
3?m1S
jjVo
TK0,
{ ]`
AEEO+
+'fZ
]{v
.}3c
yfg+-
P0t6
Ou8;
67Rq
kNj$
j;|q=
rT*C
znh{
s3[i
fJe/
=%1^
~X)}
Yz>U
0;v;
)kL\h*
Array
R&0</0&!
set_Location
_?=r
Color
qVS)=Ey
zA:P
)(DCj
h_$O
^3!3
ER!-S
yK:6
/% ]_A'n_d
Qkrh
`ytpF/N<
0sBK
?{=X
"`-m
yS9H"
DKMH
L~K~
:F$j
? {A
SpotStream.exe
=%A
YO0u
E8TosT
@KXI+
qW a
bf }
T%(wTb
Z:&e
K4_6
80 W
gDwM}
rZN#(
G -
]94b>g(
s1zg
^wpF
KqTr1
qN
S3s$]
R Q/u9
fP'C}
Z;//
6 1c
RP($. K
vv@r
+e
""m[e
@b4F7:
6t<5
M'e>'
yZ3y
3+33+f3+
Yf_W
D8$H
Form
pf5_,
V W
g!c^
Cm %[
>Au5
"I-5
I54C}Hm
03sA
x/pS
iqk5U
-7M.
T01IB?[w]%ku8X_&}%8M)lI+%
o461u
N4 w
eaf%
X}z#
mp(z_
@Kqx
W .1
M$[e
{&!1
= Y
C 50
rDX%
CF^r
E?n
/trSd:
r-J7
Seek
'DY[
(_As
HvDxV4
-\[!,
Ab4W
CKRzK
8Zsq
ZLkb
;J2/
&Mgi
C#95
bt|+
)mUo
,e5)
0D\V
"M
- -#g1XaY ;
QRz2
pgT%&
set_Name
, 7j;h
Default
D3?N
u&rB
<uA;}
S|$>c
pkjt
"z` \/
6Tz1P\
$>7k
~Y`
e cK
'u,?
= ][
IwMV
~q_ A
QXk"W8
ResumeLayout
x6CZ
%CZB
|[W:
0(c g
I7)i
System.CodeDom.Compiler
GuidAttribute
+i1,
SetCompatibleTextRenderingDefault
ohW`e
|%bu m
/B2
=3ia
#m|U
EI
`it
&59F
){{Rd
r= *
;Nf[
dfsx7
PcD"
2 i:G
52BF{s
`EM;
{'1k
X d
*!J,V
HIN <
ButtonBase
i)^gl
h<9.
afq:{
System.Drawing
3.C6
l(!j
r.kN
ko{-^m
ek7@Z
[R|V
D!i)c
cI o
:49k|U
oc+d
+~)
#2Ya Y
d3#`$
runIndices
B=EbRv
]z}bW? Y
Fq]c]
WU8;
H-8m
h'G>?
'ZaY ?&R,a%
FormBorderStyle
s Y8
n~ E
UKX~j
4{y G
FH t
nn }cU@
#iMh-&
[H,'u
RhJp
b1EH
T7 3
iM|%+
Tn-C
pi01
Ws~M
1pir
SE-/
Fku}U
PPX=
eeaee%
$oyW81
qG
q$*:0#
S&?x$
g H ;
//43
wv>S
i{n 6+
KD#g
!QB<g-
U(MCbnHK
0Vb >
fH*TP
8-Z#>D|
?$cc
d(V)
eK>V
Pl=Y
*Rc[
=4@ +
e3Q%
S3!V
.dB,
-y0+
lbH
ICryptoTransform
(5XNzU
eaY%
SM-(
XYf%
fgHc
ArgumentNullException
I;7k
k(q-
QGSvB
W n@
"atu
TJ/r)
Ns#*
njkv
p9x)
LezZdBW
>==,^
r Ji
YLb
#3oS
MyO!
V-VXe
L%p`
add_Load
5pVmt
XJmN
3IB?r
D1[M
c1,y
\HdF
O%`u
v:]U!
O,]LGW
HlRN
+8+
s_}u
4- :
_$c
T+jd
w"9n
B tpL
set_TabIndex
m5F4~
>uU3
pg"}
PWc8
. SU
9F>j
M]BH7
5Foa PU
#t8m
`v Fk
WR?u
MC0 r,
z*(A
0 -" 2
3=>_
.ctor
e0.|TI
5!ESQ,
}!_n
mscoree.dll
'JU:
SZ`X
^I 7
:/qhf^
yDK0j8Q
%)r+
d67Un
C8r%D0^D
o7{.
VAk OH
F-fu
}0pm
&h{}
D}J(
pIvB3
5- N
c}M'
+Yi
(:w`
^Vie
$VmE
>tg
/ #xM?
wYr &+\%
+fBt
c48\ 7
+_,=
@k-$
j__Fu
Op8[
Module
b/M\/
?{t=.qG
= 7q
>t\
/V\ei<
2eBsW/
5Kw Y)!e>
#HB&
yu2v+
h&Ix
Wum5
*OE/Ie
H;ZW
1O.0
E:rT~
@.reloc
.$1z
4+[cdG
#:x[X
Dab<
Jp@mE
1HYs
'*k\"
SpotStream
tq B
, A-RX
O5;:
TransformBlock
!6_O
<K{d
?@_M
YWnF|x
T5&E
G|2'
Byte
-y*UW
PWf5got
~ Zj
,=Fu
2{ap
MPK
MoveNext
Dispose
;l0 0
Y _T
x6@_
Rd/Y
+MUs
C,-^
|G)
St#W
hAB{73e
LZ +
LPLh
> >J
FhJL
,g2mT
|. Rt
3ovki
~&6
+C&
t\O ^.
unf 8|
U3Ql
])4bd
<,/
~a<<
%pAX
h(
|;hA`
o-\NJ[06B
~L7`
={Gq
;l V
lK+H
),)E
Finalize
Assembly
z v6Z
[;(Y;Q
)DY5$
[j YdO
~ $l
QE9n
U'fE
F} vo
E]3|Y
a[-i
]m>uD
Ci~O
IList
lK6$T
[EZ`
P_r.
&+E@g
CB9c. g
_D16h6
[z`D
vEK< x
[C!h
?Asz
g r=&
~euA
get_Item
0mia
u 64O
)+ >
a aG
RuntimeCompatibilityAttribute
NP}4&Q!_
J@kD
{ Uq
!mS4C
#zXB@urS X
SpotStream.Properties
@FN3
)pWw
WaitForPendingFinalizers
2>
#N A
!wR>NX
dmb 8|
|lf@
R(/_(
wb/ Ew/
S*)B
GraphicsUnit
Za8`
e=|^;=
ObjectDisposedException
IDisposable
)+$T~
$.' ",#
[%.bW
'5F@|
%qvQ M
b#RE
SuspendLayout
set_Text
CXaHa
'8(I
~pIQ
4 aV
8m.B
hC](
>56<
/v`8g8
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PD"F
Yj7 g 25
;hF;*
mQ^zV.
#;bm
^ Q*e
+ssf
Y:X*
tZg>6
?Y%
Rr~(!C
OK;G
{ahq@
EgLk
sr,fav
T2Ep
.RQHv
R .1
(?Zc
xQoN
IContainer
dxX!
T)a_vg
[>N/
A<3
Y -L
Fl]!
Fnd;u
fe
Mfo|
m7 8
YW<P
>Qz
6eDX
=mO2
uye+9
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
+>3x'
s#D(
R}Md9
S4!H
~8[Qq
NR]-jU
a&@u
f!p4"
KV%/e#
J sQ
Ewrv
#}N5&
-?7'(
AssemblyTitleAttribute
kTJF$N
@ePu
I*WZ
qB'm
~UGzt
?VuF
_~F8Bw
){#
C6,_
-+E+
a7S$
BMU
U aYa I
G*mM
Q9vF
L/Nnl
MOb^n=p
<\RQ
;.:w
ContainerControl
|; E>
S X
u+c#
A$9
G**^
x>gB
vK0"
'9=82<.342
N&yOe1
z~/+
@ilu
<'"`
m f%
7FB>
6{aG
*@t0 >
k!,?
,1`
O_3
aa :
d$FN
;fip:
9R(t
,j c
OQu8
SpotStream.Properties.Resources.resources
.O)
H8$W
kfgU&K
=h" i4Ye
*Y_o{8
+9
Q|@s1
nao0F
Uv&sL(
uuwQ4
0k!D
C+6)x\#
AssemblyCopyrightAttribute
W}b"
`frUDn
o,T!
}+Yk
2SY?oD
J`J2bG
QSwN
TuSj&F
M/:s
*Q ]
89yVA+
R^ $
M(+}
` \E
8+Pz
J C.
b(E
Bbh`O
)=/H
System.Windows.Forms
_f6F
,Z_lL\T
84xK
:?1
>R8qC9
*7|@IJN
R=*7
@4;'
m@9~dB
wf _
-T Z5
Type
,\ a
nui
[!_
pH`hF
S<\ &

Vm=c
G^ 8(
2Jv*
9nbQUl
5XY\
'z}e
Y km
uw6:
wItcj
xM0
Predicate`1
ne(sJ
Nkr^~
ci5i9
/m-<
GsJUQ8zW6Ia16WbyLnzgntp7s79EgGr603oo9EaIkXh4MMs0C0N3F7rfCU R8u89kmAC067GNq4PLtvfZIBp2712MIlobIJ8iqetMp8PDGphCcUcsP1 tT6v4R9rVSxFhG0nPBT3I4l5RT037I5MPROOt183yb33bjA4vzNq4I170LdkkF3MVl9P0l3gMYE001d S4II4YQHiZghXXdtq0h9t3EJ4zdpDB680vRy6uR6U10kEfI83eJJTnHi08WO4tDhch0uFyw4j o0DmEYqovs07zMo277XCBuySIqyh2P0Ns18PeN37qZ7dpn oGVzyqhi2M3dhtJ4f1wO7NYY3DZevvVvn8KagjCqLSFDt2fXhoml2Z2a064uRC6R0I9rj1X58GDyHV BqB6HJ22OF2tinbYIe7Ml277yQpw5VDTfT3DPEzHH ul0I7bg13UTJMH2NS9nG61CjNPtXJExzENRVHpbNPEb28WH5TC58nBa1 Q
JIfH
V3@
Read
Lz/ Q
} u`>=D
"Yts
L,4sD
X(G{Z9
SAUA
S8 "d
cl1a
qra a
egy$
nexz7'O
D*lU
dV3.c/o
s:=h
~-e'A
l+N.
(GNZM\
%1Vw
E~e=
W2 ]
W1J"
ox:N
(.-=
Z- A
*9fI
SJS),A5
IPe7
@-{q
a)YW
<k5;
Xx ^T
Ya]!
^gO %3
)sIZF`S
"#E
=AVM
AC(&
Oth3
jb{Yf
/g I^
.cctor
(gW H
J{]z
gHj$
set_FormBorderStyle
8l+Xm
mscorlib
"Ajo
B'Q+
+Yb*L
3=*W
?T*hW
&[M4C
ZK>2#
81w9
YHME "0
V9xy6A
873gM
7~,
d2(2
u1P1
ThxBHH
m =,
ControlCollection
EEF=}
LI3kJb$
35@ 2#z
zer|
@zdN
b[hZ
~;-
#SCE
z{5]
!h*Cj
t3g6
(g^Yw@
~ [V
z0b\
|(51
e| ]
get_ModuleHandle
*A^
`Lh"
]iS*
I&mo
&{\"Q
L /
si]nw
>rgR
SizeF
t(my
_[ ~
@&UB
RuntimeTypeHandle
n[0y
E gw@^D
ModuleHandle
u)XU
3.MqX
8xrK
RN:[I
.\*0
2#w1
T;iS
Spn@
F2"^
0=P{
k "i
0|zV
ik[eC
e>'S
j]ta
S5K
i ~v
Y;Gx
Size
eL56b4

[.gfZYY
wcw:}
wAdT
'X(@
Afo8
>QT7
rqW3DE
}Fq
8hdr
<gH)ymd
Uc_
d# R
B:x
F[L-
4thE
[a #
d.eV
^Ia0
OW.z
&;yb
AssemblyDescriptionAttribute
RD</ze;
3w#t
M (1
Nyj*
n)
z\d
g1AWu
[th/I
"uy`
<?"k
/N%*
jV6Z
set_AutoScaleMode
/ <}]
qIV7[
<w]r
!W`a8
o5Rb
}M/O \
]C9
XB"3
j;\ QR
+Vz"
1ChUd
0A])s
ba8b
j@ .
_05P}
{d'c
E7B
c=9F*
>2_(
LS9*
Nh X
p:Je
Ga-U
'1=%$
)rmr_O
+ }n
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
\bM,!
0]Hkm&
65<
=NR0>X
WGz&
T"#8
QB6I
freP
#MCm
|2Ot
_+bo
!This program cannot be run in DOS mode. $
/" D
;sv 4
callback
\p,R |
QpJ[
/1k3 N
C9sd
g {2)
olIw
nNvd
xT/ F
Wq1Q
0[5,
rqO}
aSgYj
r| s\<
}A6f
8? 0
<cPq
>Uz
~hs5
)!>v]
jjx=
ROa"
T1*+E So
rTfOH
Aa76
Q,$*
R e
JcjZ
hI
.~x$
]"r 5
c}H
set_ClientSize
upcXg
4C# O
JQ;694M
0Rg{
dXN|*`
#l
._Ua<
lEB!
>`Pu
;;D&
A*F
'XYis^W
!22222222222222222222222222222222222222222222222222
>|^@S
get_CurrentCulture
EP1l44f3r16j40VbftR8K6NjU7q81b6njy82vW6Qv17K1u r2liWoqRQBcR5XpMQES8FCmzJwBMb7C1tS85P1j82h 0SFB1Gp1Fiujoa5Ztnd8c7tqxYt5YnTGr 4gDvIG4G6S81dodl9eirP1rhWngtckPn KoZV6fXEVBbr43Em5x8qAPD7oY sLwfDe0S8DP28Lm20Q9bscGq6a604lkzs9y2roXMEvEip4 fgVWry65QEGswh8XgmiTIgtVL1xX5XrACkkesP2Bv3i8k5uxEXr5Gkz868KyAt81fFpL5oxRshrO63 OR8Sszu2l3lrtFNAC3pcfZi0jtaXs1kBCO4hBaaM4LEbe6ELegpUbbY71S28ZX sSkoeJz8uncrTVHWmoO1MWQsu9Hy2ra6g0eI3bsCyg3z72 mu4QdKeHWC03nBAQDMpKb98cK4LNzbju04nE6 z
1YISK
TITu
ru ?
7p92
BSJB
P,p2
iwjs
M; n
j)c-
#xY y
0A"x^
?y m
{Uq+Z
YQo
_%Pe
gq},
w6j8
R "{D
Kv7f[
nJ8 2
SeekOrigin
7i,F
X9d<
nBxF
f0:W
-m&e
"2W[
-l0y
7KbS
Bnro
qm)c}
o[E/FG
<H-5
S`sW
dg|/
He AU3
6HT3
r#!E)
_]+Q
%!\}
*' 6
Gqw?g
He2!
2|vw
H+)%
e9\64
H!X$
b9Be
Synchronized
%6zW
|S%Y?
EWMZ
yLo|P
j.]G
RijndaelManaged
Goe5
M13
lM,v
n$.j9X
@FdC@
ListView
qV4x;
/WxA
[$KNx
add_Click
get_Capacity
TL%-
](i
mG.;
BtPfOH
RWg3
qQ8+\
?##m
)yY
,*~P
^jTen
l!;j
(tSk
yF8l
|k9 i
0ri5
?7Z
('Qb}
SI|+
rS 9
1X'[i
r0,+
+D C
set_Key
l!;5
iR [
geZj
0Px|:Ivb^
Jo.sWB
9 oZ L
NI'u
xm%d
<* b?{
t M\[/^~
DxFi
1BKJ
`aHO
0=]<
qN%+
Ku}H!8
_[r[
t:rB
(&7a
`K)\e
r>!
$k(
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
4iH_1#
6w@$
i 5,$
K5AZ
`n$Ab
Hi%4-
HAEB
{<"
CompilationRelaxationsAttribute
w->F
dx?>
`_>JiR
r_Ik
6fQyM)N
'3<0
9IH
MemoryStream
sTw2
v fNV,h
Sm:zJ
set_BackColor
|SH
s2ao
PAs<
-dl<S
} ?v
j@HuY
2 G
rwUDQJ
o S>
Random
QD~#
rSfG
xW%u
ZX7rUp
Nj[Q
+#fXH
q0 3W
_^1d
bS_J
-MtW
@/.=
#-D.t
%;G?:
ybS%$
}GepQ
Z vm
9y]$
K<gr
eCxqV
=:te;
$m]r
P0=l%&+
I/u+
aZd.=5Uyf
.)"]
%u._
$4V#
c^n4~
Microsoft.VisualBasic
<g~W
Qz =*
X5n[;
"7l[E
[4r4z
I@_vJ
1%j@
Ni%@V
$!)N
$5z6
9^TH\
m%y|
N u1:S
Cg "
7\w
~[%mE
==)}<L
6| &H
1uZQ/
SV?lR!
EKpe*/}
,$S#w
QbsZ
1LH$
-1^zK
get_White
Op7
"2yb
vxyJ
3l4(
EI?5W7
"beYXf
+] N
jhrn
VRo%
DxuA
U-27
bljX
s!M(
f_a-lQ
#$ 5
&bk]f
:\#S
F$<S
v%&87
VzbH
gU)L
Z D7
+d?o
xIlw
PtH(
xE@k^
|l80
oof<Y)
'FQ
,zU3
u/Wj
6RTt
x)} v
Wo%+
CompilerGeneratedAttribute
EventHandler
#-[RN$
JVX4_
`_s/
&,`a
vGJ"9S
8!^^
9Al`)1A
^v ?
,wuY
0pD4
sg[:
,g <Q
.r;Ar
Z%Om6
KYN\
fdDb%
T3y
Ls;
.s#)
WI=7
L ra
%.!.lg
^oP
&E~W
8X T
zOF: _
$hfs
?Nhkg
P*+
x cPF*e
K;m2!6
FE0##
nUj
j6;w
System.Resources
Collect
lF t E
[% 3
ZQ[e
I>2e
rn6$
8z3w
B(>8J5
uYhsQ
,*7osq
#P;5
,{#W
' Od
/GGA
Jkgx
I)'
8 ,
( 6
}.>j
Kx8L
y~Sx
7;Cs
r\a8
g^Me
QK#b
@ $+O4F
b_ze
0 | <
H 9L
"J,+
{f,$
MTzv}
=nK&
EndInvoke
ResourceManager
l\g/
E1 F
3V[sYY e
"LuP
6b*V
^YF/m
AA\mC
o.OG
3U33Uf3U
` j?+kT
I97O
t U,%
Font
/=v
MwB_c
o9]y
+pZ
R-I"-
{LY mI
n%[{#
u{^C
OZ/Y
~4D_"
V2#
m)Ff{idh
7WD!<1
5# 3f
X4vc
<K23QSr
-J`u
`Par
Ny?V/
ICollection
_CorExeMain
DebuggerNonUserCodeAttribute
s\fO
A6f3<
H.ky\
lX:61
Xg2 o#
object
x ;PZ_
DictionaryEntry
InvalidProgramException
RRSP
DebuggingModes
14.0.0.0
hgj;
System.Configuration
Z1P:m
%ja+
?a'{
k:RKq$
^:8`
'd
g`wZ
$O)EN.
A!L"i
:O; jJ
lkUBr< n*
T u[|
c$~3e
mM>(
P.ZF
5.2,>1
2T=$
wA>'
nbUU
Hto%
cI*ner
BI +
ix"
jIFJ
15 D
i"
iIP%aw
1;3nV
@vzup
5x+% R
z&51_w
& C8 D
k(PU
]\KW
F)gde
vf;j
lBMPDz
A 7i(
pM#A
()$\
^1weFL(3
D ;o|
([c9`
)?n
Attribute
|K
A7&[
7=Z\
UlR|
VQx{
C>#
j/1C
pRo}
C'K`
RunModuleConstructor
q)-
XK+
}5DR
K#cq
BeginInvoke
bfR
SkipVerification
3Igk|F
(al$,e
DebuggableAttribute
ll 8
*1?
W!eT{*sP
ehl~@
Oz +
.8"[
j!U-\
rX|A
728y
GetResourceSet
O3=<
M& ?9
o ;=
TVBK4`
d-h,[
M#wNc
"f>&
RuntimeHelpers
\Y$O"t
43 3
V` u
V}.,
=` F
qkCJvo
ZJO"
P>`V-
&f'W&
AM}u
#2Mh
_,Kr
JFIF
CD2 [
2'r#
P*LK
8P@MW
@w NK
^E
(Y$qt
i/@*@
67>O
OR"B
s)`|
x<H
Object
pxGQ3
\h|-
]^qwi"
f{[smHL
7( B
[ mQ
ComVisibleAttribute
055@l
vqERr
Vg5x^z
3System.Resources.Tools.StronglyTypedResourceBuilder
set_UseVisualStyleBackColor
)IL^x
get_Value
7<MF
S $x
g]pF
t',2rOYt
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
CO`q
+e
U.3 N
cO=E
g[hLK
pGzJ
;o1 \
ResourceSet
znE
VO|>
l}B6 "I1}
6(K<
F=xw
EditorBrowsableState
AssemblyConfigurationAttribute
m%I[
A2ic3
HvuXq
5vL?
>i<T
CultureInfo
7~z/
1.0.0.0
)*NE
]+UFzuF7
+ {
M(^_~lg)
] Z8
A%z3F
@@sP
\!ik
D' p
|8dQ
?k>;~
#H2`
KYSL*
*"Rr>
~rYZ
lq /xO
d`90
Stream
B~Yk
j5YF
#DgYB
JZB9S
e8&Wl
hB$/
f+3f+ff+
luJ
Z#QgJi
ND<o&
Invoke
9'E
n'5tA|
:E 0
YaY
Exit
$ !?A
HI |m[
x,qk
hEx4
Z
P%&+
!6=d
Yt@_
)L'w;
h$2y
18T
7 b5F
Twf<
@N)D
6rsu
vO[m
'e 0
4V93
r[=I
rF:W
6kY
${'L*
Sn z
fQC5p
zRk#$
0o*5J
eGins
8 K_
M_fK
O P
i%5=
2]bb:
(}f86
/{e'n
*"(73 {
q;'!q
*lQu
+MyT
f$~9
!tz|H
$5>v
?tcZmg
f p)
FormatException
~HH
`s[,:
+Ko5
>1JE.
pGf58
System.ComponentModel
,w_=&
ZL^y
`i_t
sZkc
;h T
U+ix
A1M 4m
/d!
`G`Z
>z7k
E)=e
Y;`v
}5vq 7
%9#6
YI`h
X~JD>]tj?
%21'
EVyr@
j$ "
ZdXZ
oE`#p
|#]=
^RB>
1Re$ T
88n;FY
g^:_
VH9q
8O(Q
K$;[
C[wB
GXif
LX,G
eXY
QNF
\y w
0 w*K
#Cyv<,
]!8N~S%
l` ]u
4YyA
get_Current
^NSg
9 qD
rAY
^>- ]
`)ZM
/h1) A
^=H
?Eq
W_;y
j,x>
F\Wa
D3 M
m1r3V
TX ~
xg"w
jX)4%G
NotSupportedException
JqP4Yj
'5_3
set_IV
QYt
y*LT
Jkp}e
l\"Vl
si{8V
|%LC
S G8m
fwze
(#=@
=fQa
J3no=
?S})
1MN1
q]rOc.
SOcJ
o*FL S$
Next
L]'q
s[2K
&Ux5
w>(qP
'oC??\2
hgT#M
%>v
M$Si
J4fJ
2x2J
_< $
W`Cl
/BOO
*M+&
G" !
GO_ H
uZx6M
do){&)
>NZ)
uu%P
&ryE
CrkC
:;qG?d
1hc~
z7X'R
G1{H
K;2%
]Vt7
iu9%
a K
Xe9`
)0 !
zH<Q
b &b
e9RA3s"u
&8u=
v2.0.50727
N~U}
+4 =_
1YIs"
#3R
WMO{Dt
sY.c7
"!5n
!w1oP
(7),01444
set_Item
_Mb
+G%w
get_Count
[_tT3l
x&JG
yoCUzw
c2U
aF:HT
p-6ymTe
~Hxx
LJwhhc
cn9rk
2[_S
Exception
tq:w
9M j
e AM
,F g
~BtB
(eT*L:
2.|-
:a$@OJ
s {c
V6C@N
G!an
2_]m
L>*mm
&SrR
e[Yc
$L$a+
)(AA
,U `Wy
H{@l
set_Size
GetTypeFromHandle
IAsyncResult
UJqZ
6h4+B=%
Z93x
Information
>5JwA
<~kq'E
jzt*
P-YX
,sVs
b{[-
yxsH
68%&+
83 l
+4E+
)? #
cFT*
Rmdj
Zf d
+0|W<
5hB@QU
(?P0
V!=thW
1b$i
?iCu
*v'4
.4(}
$)&n
7t[.
s75.
W:rq
`W Y
"wn:|fX
:cq
, J7UH4
'<1k
Q3Ec
OuOx
@P"q|
ToN3
I'Hj/
llTq
AUEi
BrSC4
e3 3
xh!,h
n@\@
xm3u
+GbR
System.Runtime.InteropServices
@]|`p
`Uf1
B.){i
WL7m
S'Nh'
+05czh
#M
sh3'
3\fve
CGe*X
;'yt@
System.Runtime.CompilerServices
<+hT
x {i
48jD
6l D|
bFp{
JY6X-+Dr
IQXv
2hxj
z= |#]
?w0jU
AU)4
M ~6
%V&,X
kjP3
Nt2:
set_AutoScaleDimensions
$3br
6 `7
._}&A}
sN5y)
|a[+
]g:f
\* W
?i`@H7Y
pt\4
7^kXf
[Vv
0[Rk{
7<]%Z
x:9!
Gl J
sDe=
jK>o
V)aV
;rJ{
@etb
VB?TW9
*7)4xa
;D%U
set_Font
1*b^
"L?*{
S v
N2lHYR
"E77N
a$ '#
:01H
8wAi"
Y!=g"_iJ
GIF89a
w`B<t
InvalidFilterCriteriaException
De'a5=-
NEx?
Exists
r/=/
S,vx
<!2N
S4W`
@bLM+
2r|
FontStyle
c[h(
B_gSB
L.yIX|e
a{Y%
7XSg
?9`t4xj
/4T+
zPwKB
u9aS
9>S_
ehWaQ
AssemblyProductAttribute
~ Z2
nPa`
# 0E
NS5,
O*` @
LD#9
'W s
<Module>
?hev
)tJ1
'?ew
[xB
]{,8
F. xf
MulticastDelegate
uN7\
66S7&'
eJJ3
B"Fkk&
QK<B
'^5t=<}
+3U
n1rf
709z
SLoF
fU3fUffU
6ED'
fLFu7k
*a8Y
XqIT
<eu?
*g/&#
Wbl5
n}V
9`kc:-)D43
yx+O
#*)[
H#7V
D6A L
U.qml
wPL0
J[0O\
4r(>^
wATy
e4 *|!
_b`
3@U%d
}7go
`|ja
p_ZA
~~?~
}VK,]
& A
r1s8
k[BP
dc]G1
EA i
4]Zw
>CDKn
6-|h
#GUID
3G8W
&=")
,\`|*Md/a
V")EYX}
3n 2
&(gx2y
>t%x
qhR>
<q/1
olf
D1Qm
,l`P
u3'Z}
L\,DOa
kRzu
sr\9
?tY&
t&[K>s
O33
[/#7
68bG(lS
8AHqBS
^JSK^]
.-m
[YW3
W,(\F
Qj*7s
Qn0}
Ka( a2
zS!Nn
ApplicationSettingsBase
6j*D
M:~'H
;lm_O
?~$v
eR {;O{
tNfi
g.<g:
ROh
[Bf
RveF
SpotStream
_iPS
&Y;z
G4{IuR
5?-Z
BXwx
SXt?
b3|
ra@j
-y!6.]
."] (
1kYY
:@h3
fPyV>
Ec;
y&.hx
v%&8
MH4
>g&%
g.5s1
N5xA
G9f9t
uHX~
s- PH
GeneratedCodeAttribute
o8oI9&
&X8.
jC&MF
y}\c
|9 z
)G! 8b
zL j#
gNDK
get_Module
VP1{
5!x7@
<>c__DisplayClass8_0
3By&
xz$+ T6
nB#i
w|9H
5pl9
=<~
m2~W
``wB
T{+[
>QL:;
\.h20K3H
hsI
{x~'frF%ZL
ND;Ky
0xIC,Q
W?Ix
KkTW
4:+k
&b@+o
Zz|8
WdbX
d6DYu
6,q
/aYu
y-|~s
s#X/ o
Jioh
{iEP
uWvz
LA%l
=ta9>(-
$l%S
Rw<>
@%W
*C]l
}A
C kVe
[:6mTWl@
,H W
Hlr^.-
3 <$J
C.U.bz
F .
0ZQ@
8`00.
`qj{
pRy
i21L
~WfR!
|_k'
F3 @
I{:
/2ghyf
>L`K
%&
System.Collections.Generic
=P8>*3
)&RT* W
*J2MA
.Jj%
, b
oy}L
3ble{-
'02F
|_'_
*(;l
Ra8w
4-G"R
<-[{
" q H
{Vff
o&q3i
\cmE"{
=I Q
\g$6
iV%
yj[x
3[#w?
l>2dK
nO 5
@.W.
<d7/
kD8^
l5Bq
=sy\
(/RK
'5E[
{0(nrl
{pYxC
JLrgXE1
:2N+
ea|b
$)6
(b#"V
HDJk'
l;pp
v|~<
O Qq%+
CsIN
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-23 13:06:18 2018-05-23 13:09:15 177

2 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-05-23 13:06:18 2018-05-23 13:09:15 177

7 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\11.exe.config
C:\Users\Seven01\AppData\Local\Temp\11.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\11.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\11.config
C:\Users\Seven01\AppData\Local\Temp\11.INI
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\comctl32.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\SpotStream.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\SpotStream.resources\SpotStream.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\SpotStream.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\SpotStream.resources\SpotStream.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\SpotStream.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\SpotStream.resources\SpotStream.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\SpotStream.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\SpotStream.resources\SpotStream.resources.exe
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\11.exe.config
C:\Users\Seven01\AppData\Local\Temp\11.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui

Write Files

C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT

Delete Files

Nothing to display

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\11.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6c8d6e02\6b769bc1
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_CURRENT_USER\EUDC\1252
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\d517419\6c8e7c15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|11.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|11.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|11.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\d517419\69b6224
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
kernel32.dll.QueryActCtxW
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
uxtheme.dll.IsAppThemed
kernel32.dll.CreateActCtxA
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
user32.dll.RegisterWindowMessageW
user32.dll.GetSystemMetrics
user32.dll.AdjustWindowRectEx
kernel32.dll.GetCurrentProcess
kernel32.dll.GetCurrentThread
kernel32.dll.DuplicateHandle
kernel32.dll.GetCurrentThreadId
kernel32.dll.GetCurrentActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
kernel32.dll.GetModuleHandleW
kernel32.dll.GetProcAddress
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
kernel32.dll.GetUserDefaultUILanguage
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
kernel32.dll.DeactivateActCtx
kernel32.dll.GetSystemDefaultLCID
gdi32.dll.GetObjectW
user32.dll.GetDC
kernel32.dll.GetCurrentProcessId
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
mscoreei.dll.LoadLibraryShim
gdiplus.dll.GdiplusStartup
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipCreateFontFromLogfontW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryInfoKeyA
kernel32.dll.RegCloseKey
kernel32.dll.RegCreateKeyExW
kernel32.dll.RegQueryValueExW
kernel32.dll.RegEnumValueW
kernel32.dll.RegQueryInfoKeyW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
gdiplus.dll.GdipGetFontUnit
gdiplus.dll.GdipGetFontSize
gdiplus.dll.GdipGetFontStyle
gdiplus.dll.GdipGetFamily
user32.dll.ReleaseDC
gdiplus.dll.GdipCreateFromHDC
gdiplus.dll.GdipGetDpiY
gdiplus.dll.GdipGetFontHeight
gdiplus.dll.GdipGetEmHeight
gdiplus.dll.GdipGetLineSpacing
gdiplus.dll.GdipDeleteGraphics
gdiplus.dll.GdipCreateFont
gdiplus.dll.GdipDeleteFont
gdiplus.dll.GdipGetLogFontW
mscoree.dll.ND_WU1
mscoreei.dll.ND_WU1
gdi32.dll.CreateFontIndirectW
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
user32.dll.GetClassInfoW
user32.dll.GetSysColor
gdiplus.dll.GdipCreateFontFamilyFromName
gdi32.dll.CreateCompatibleDC
gdi32.dll.SelectObject
gdi32.dll.GetTextMetricsW
gdi32.dll.GetTextExtentPoint32W
gdi32.dll.DeleteDC
gdi32.dll.DeleteObject
dwmapi.dll.DwmIsCompositionEnabled
user32.dll.SetWindowTextW
kernel32.dll.GetStartupInfoW
gdi32.dll.GetDeviceCaps
user32.dll.CreateIconFromResourceEx
user32.dll.SendMessageW
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
user32.dll.GetSystemMenu
user32.dll.GetWindowPlacement
user32.dll.EnableMenuItem
user32.dll.GetWindowTextLengthW
user32.dll.GetWindowTextW
user32.dll.SetWindowPos
user32.dll.RedrawWindow
user32.dll.ShowWindow
comctl32.dll.RegisterClassNameW
uxtheme.dll.EnableThemeDialogTexture
uxtheme.dll.OpenThemeData
uxtheme.dll.GetThemeBool
user32.dll.GetWindow
user32.dll.MapWindowPoints
comctl32.dll.InitCommonControlsEx
uxtheme.dll.IsThemePartDefined
uxtheme.dll.GetThemeColor
uxtheme.dll.GetThemeMargins
uxtheme.dll.GetThemeFont
user32.dll.InvalidateRect
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
culture.dll.ConvertLangIdToCultureName
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.SwitchToThread

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-05-23 13:08:26

Detected family: #Msilperseus

TheSystem Itself @ 2018-05-23 13:12:02