MalScore
100/100
MalFamily
Ispy

nmobite.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 15/67 Related 2238
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 402.00 KB (411648 bytes)
Compile time: 2017-06-16 16:31:21
MD5: 9dc9370028305ea21bfa0fdd66afb326
SHA1: 198cf4f7e2d2b4b74610960f2c737b20bb98d729
SHA256: 02a1aaeb0953f7e3f276494e734a957583ad14d3dceefef07d12fe1db2d2aac3
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-03-26 22:24:04
Last submission: 2018-03-26 22:24:04
Filename detected: - nmobite.exe (1)
URL file hosting
hXXp://emifile.com/frak/mobii/nmobite.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-03-26 14:22:51 [15/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x63b04 408576 f5bfd9475e55854b347e3521537304d3 12b74bae86fb8fce1bad6318fa7b20e038499982
.rsrc 0x66000 0x608 2048 7bb5281f97c4061851b34dfcdb763006 671e9e31607c0947ffc0fb9899c6c2098f2e9d2d
.reloc 0x68000 0xc 512 6012acb8bb8a62854fa28a6bed9daf71 ad146df3ba406b02681147cdcbad0b9e769925f8
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x660a0 892 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x6641c 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2018 Agway Inc.
Assembly Version: 0.0.0.0
InternalName: MOBKABAL.exe
FileVersion: 18.2.7.4
CompanyName: Agway Inc.
Comments: qbmpnzdpxjd
ProductName: Reduce backup recovery time
ProductVersion: 18.2.7.4
FileDescription: Reduce backup recovery time
Translation: 0x0000 0x04b0
OriginalFilename: MOBKABAL.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
18.2.7.4
URL(s)
No URL found
String too long
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
Reduce backup recovery time
8df2eb8b-75f2-db18
8df2eb8b-75f2-db19
8df2eb8b-75f2-db16
8df2eb8b-75f2-db17
8df2eb8b-75f2-db14
8df2eb8b-75f2-db15
8df2eb8b-75f2-db12
8df2eb8b-75f2-db13
8df2eb8b-75f2-db10
8df2eb8b-75f2-db11
8df2eb8b-75f2-db30
8df2eb8b-75f2-db31
8df2eb8b-75f2-db32
8df2eb8b-75f2-db33
8df2eb8b-75f2-db34
8df2eb8b-75f2-db35
8df2eb8b-75f2-db36
8df2eb8b-75f2-db37
8df2eb8b-75f2-db38
FileVersion
18.2.7.4
InternalName
2018 Agway Inc.
FileDescription
OriginalFilename
StringFileInfo
000004b0
5Wo
Translation
43c81fe6-c1db-4f85-b1bb-f87c1bb743ef
VarFileInfo
&K(
Assembly Version
Comments
Copyright
VS_VERSION_INFO
Agway Inc.
8df2eb8b-75f2-db27
8df2eb8b-75f2-db26
8df2eb8b-75f2-db25
8df2eb8b-75f2-db24
8df2eb8b-75f2-db23
8df2eb8b-75f2-db22
8df2eb8b-75f2-db21
8df2eb8b-75f2-db20
0.0.0.0
8df2eb8b-75f2-db29
8df2eb8b-75f2-db28
LegalCopyright
MOBKABAL.exe
CompanyName
qbmpnzdpxjd
KV|"
ProductName
8df2eb8b-75f2-db4
8df2eb8b-75f2-db5
8df2eb8b-75f2-db6
8df2eb8b-75f2-db7
8df2eb8b-75f2-db0
8df2eb8b-75f2-db1
8df2eb8b-75f2-db2
8df2eb8b-75f2-db3
8df2eb8b-75f2-db8
8df2eb8b-75f2-db9
9bc95a43-753d-5d
ProductVersion
M}o$=v-
U1WE__
l'/c
igBC
V {
e8)H
)Pv(
L]Oc
/^]1^
VB0Y
?gB.
~O|u
iX&z
9&P4
7OH"V
bKF[ R
j5^UWQ
& O(
sk*]
BfH\
PNG
~z~MC
IuGF
&? I
FN$_
7:4V
dz\4
=h@x
(i/<
$?]F&c
`>X,
vBI*Y
nzE'R
T3oJ
GetManifestResourceNames
E!xj
I.Ff8
8 K0j
V,g?
xuoC
Lz`VS
y;[:
xqaP9
T =|
PDc|
Z0yK
#{tE
Q>,o
ResolveEventHandler
(hdck(
j&N[
:)(2n
.#hm
/7+Z
7<m"
SDtX
Q1GQ
1w@~<
9iW|@E>2^
Wr= Oy
/ejn
\DNqy
UnverifiableCodeAttribute
0xU\
emVR27D
/6$@
tgZ!
) FH
<]8k
sh-Y
>H8&N$
5?E
7Ox`
[f&ZkLY
8cD19?m
o!Ev
:7'
"|m>
%dX D
G@,C
M00-
_jr4
A]uHp
<PrivateImplementationDetails>
fc>zl
*s:R
T?o4
SK+n
rI^xS:o
CrH%
s2 32
\iFWE
v!4~S
Eu`
ks9n
pcJi
2d~i
K!5tR
"Wbw}b
a0qE
8y'"
?$&Kz
' 6;<?@
e``*xz
QzFv
XhX~n
(3oI
Z]h^.
%V*j
`iS B
3l-jB
wHY*
Pg1jR
Ni=n
os_S8
yyQE
IG .o
sSC
=Mj
i@q9
ov[MM
System
l+^"P
N uA
VOp`
;<0I
L~,+!QOm~
5nizrg
C59.
r(2
rG,qQ
uF8F
l;&_
tntx
yRXnw0Bc
Re!Q
M13I
lrE.
) "
81sb
jI|+
*4W:
Z$9w
3`#;
R?b D
xu%M
~p4 <
\| :
},Ol
Ng//
` Mk
S-/R2
|Iq?
hA&C=
j5*Z
vmla
%ePm%j
gG"e
!h5F
4.}z
h</-
1UQup
I?D#V
?39>
o! [
<<%v
s{(!b
F?#i
RuntimeFieldHandle
)^- W
[TX
Mt]&
dlql
! OVg
oAO65%
,o5
2hN4h
\/ W
'3xFuow
eXTN
=?Lq
^Fm3V
Jx
!D5Y
uww[K'AtX
EaGO_
iY 84
#,'o
V Bx
M]+x
:Km
Ry;,
&:$Iu
tdqz
C |NrH9
j@<tdWU@6~*
# JK^-
6F
&WrZ5rNr
TqTp 9.
|,xT7
} pn
q0U0
uCLp,
~-qWg
9h>6
8z|,
>}f
F$z "mi
ybU&
^8_ 9
G/R<
5 Wq
gi'@v|
BheY
{]O]
@K?Qv
C^:cL
&)X
D!C63
ALd[9_9>
J%]Zc
]7Jr7Oj
o8#,
t,Xci
f1ycCh
hahL
^^7z\S
wKoo!
YFt]
@4F,
bxtZ$
Jw ( (
Icr'
lTE2-
M,5 Nj \MOh}_
I7=inO
_?eQ?
K!%U`X%g
b)>$e
"<d4b
zUZ8ns
W4L"
e<em
N; '
jy6R
\lk
79{b
@xT?
K>48
mJ|[a
<odR
2# \%eB
UTB81
~C+T
:[?;
f[vq
zX2(Y
ZT#pu
N}=:
mm7
x7<~
4f$(}
>5ZE
,a_-
44_.
5 O}
y"-BG
'VYl@nt
j}bF
n3fk
:o\C0*]
q3^y
r$Fk&
`oM
157{
2zs8J
System.Security
fIg%}3
dva=
qJ=S
bPWm
=J^M
@s;
%Y6-gF
aPk*v;
^-@yiMwN
j~#-
(mcxB
Tp)'
q|~jHkZ
tg9U$
Z+B"
I)T
rdj:
AppDomain
![_,
>&i!
(9"s
zzsN;
Fl(6$
.(^s(
7DnGj
!YQGv
get_CurrentDomain
FD|_
jLfw
xC(iV
S
Da B
rdLF5
g5Fh/=W
get_Assembly
v-f +
ro K
2o.$
eg H
'IgZ"
3 CP
Cp=T9
XC
8jQx
=$x}
BM=|A
Min"
H8]f
onm3
add_Load
N[&
ETb[
yJ3
U!23
+YK7\}
YTYo&
0 6
ZY%&
5Cw#
jehMx
lfS\
wB )
7Uk6
fEG6
]FR>
Wa'n
YfS"*J^
=~%'
ECT;
vcS>]
AssemblyTrademarkAttribute
_I%7
C6xo
,^!l
M$ x?
L7nx{~
KT+2
Is2&.?
,3nI
S G~
0!lW
E$D-<
x|73
?ORy
xcL
.t (D
o)\
.^f}
j$"0c
m|<G:
,1=;kN
:J%b
r@U_*K
]=q<
4 -M
i:Xy>
`~90(j
ZZR$\=
71Jn
luq+
\'1p
W "
af{W
&Y<vF
-uYi
QZZW f
[<mI
gyDq
_tR\
Z?S`
Z-G/0
N:v P}
81=)
#Blob
Control
.OpX
B~uP2
^YrE:
[tX:
@YhwC"Y
_uy
G=WL8~r<
f+R o
fJ+a
E% e
./j6
I4P
KsfE
H|p*
=zD^
W^nA
Dgt"
r:C*
v{(Q
{i?O_~j
AD2f<
5{ %s+B
1uI
wKlL;
ajF6
T/4o
b N
2v`oA
7p#d_
V}Ci
aI#bW
v&nl
vCgZ
/9O9V
X=%FD&
TY"DB
\ J
System.Drawing
m)>|Id
e(]F
1Tqs
Type
r*d+
SkipVerification
rJ<`,
jN1E
8X,rl
cgA
w^ A:
TN!K
Im4!ox
'n<3
Zt""f
6/n,
` ls
;Em/
SN%p
DTqi8
91`K
kb9I
@S,Li
get_Default
JB-l
j sl
g=bl
PQuN
#R9%#3
&2p^
2X43I
a):
gb/
8R^Y
D~8_
J}4@
{!<K^
d~w (
C
cZ[X
!+>*
=X8F
9 ql
s:)e
6~Zn-G
%sCr l
MiUbI
<E[4
OL/
~&r,
7sFG
h]'Pm
j80 u
%(h0
<v"[
Kz:@
abqe
"= e|
SF n
0 o[
F?A+
trwL
GWuq.Nc
-=i5m
y: o
{XBi
t5E9
FormClosingEventArgs
BcR:
v<gZl
5uhK
get_Name
7|$Y
^6:oI'P
tX`wlZw4
YsL=
7 "lTo
kUcOd
`8O W-4
dEt?
jB+")S_e
/5X
YLv3
iC"pn
>Jb0
~
Q* =)
String
u<cs
js@[
Zzl?
4{ ZD
u<cu
q1{#
%(#T
gy O
{ZHxX
X7R*.
5(4O
=:*Z
a~ig{d]
W"!C
qhg T
L Jj
kVZ&
*3B i
/ EQ
p0Gz
/`ls
G`t
k6ki
E>w"
thSe
I' b
b=#L[
W"*~~
+A E
&`F
.p/ptY
d3#!M
l+r`
R7_r
iH@l
E4Yx
t3 !
3aQH
^l\V
E#*-Y
GFi=N
uL=1oT
]OZB
i ?!
U'y$
btpb
[JfW
#'F7
3IMK
aJXy
jIC[
[z&@?=W5
YC$O
LE|Y
&YZG
]N1>
add_FormClosing
To!.|
7I:,I
rCwq
!}b}
8@TS
/q;1]
~=$
zh*;
yZ
System.IO
Z:6f
? V (
.text
iZ
[G N
;oP;
7 O h
hk$A$
%';v|
L5 c1[p]
e;L3
}2I?
i8 4br}
$/$X_
YtPR
s][, V
[ (XK
dp*ul
aje>;
.u2 U
ln8b
*g^x%
:lo
YTNO^
D=GB
T= H
!j21
}4qsznu
?pl?^
dr~j
ECX<^
GLRde\i3wF
]zBE z
K~vL*
u W*
0$`bf
@+@b
=fgs
lc"|c
C|5@r
YlI@j/p
P~G{
y ``S
pbl?
L{h@c[
Eg2VY&
tdT*
3'Ri
WVO % J
System.Reflection
[NHb
c[%
e-20
p"W,
|kNQ
Q''{
T~Pi
C.I]N
3'LSg
8nLwY:N4
U?c|t
4U 1
vr8 @
4[>J
f8:jk
MYJ7M
Nlz1
2aXL
~@b`
Xg-e
5] 'l
X1d[!
n;w/
aeuy
xq>V
5 r2
f';^
sg&|
dO5$
^yVb
&zS9
{4 drTt
)};_
sxLy
F25
=Dz
b3]E
B` "
|'JCi
/Rh7
?*bl
^aI{I
"gaT
X$\4 Su
e+sPv
T4X[
$ 66y
aeN/
D+Ok
<Hrmz
v7Bp
>C
GA&L
$}u
]qjr6B
[!aF
tA}v
9TO_
r(cP
01fD
Jp-a
pmd,
H}ZEY
=ss7
j?^+!
/n/O
5!$ n
J^N2
Ah|n
IJ!N2
ResolveEventArgs
?yBU
>xi/
8'W;
`.rsrc
#_uo
no0v
OgZx
4TmpBX
eG5yl
VZ7u,l
50'i<.
]WZp
r47L -
&B&Z
:f7Wa
/&V>
)]Q9u
M(H)
8#Cf
d0UAd6
a6_#
lUa;
Ml~Q
&:Sn
0vU}
t-h8
obk8
8X_q3a
1V!_i
bs 2
.\O6
-;Vt
"~o4^
9"+
>4r20
Monitor
DaN
KVSD
E|$H(S
q;bl
.ctor
,vqP
oYAZ
Y$2R
taYR!
Yo,
`:=3
$?su
,HMqk
11oW
3q+
sdT[
R fb
+C VR3
w/v 8
AzU>
4+fm
(J@-
-M!Q
O11\>
r"Z7
Mk~_
t~s1
) Z!c
nmC4H
P}si
a>mx
37`)
1)$
X:s"
_:(fT
N~uW8
-cqI
^Tg?
{uhp2i
q0$F
lPF
$E;A3
Nn+Ld;
O6\ g
W:nP
)X0=KS
b%/Y
NG0Q
c*vd#O
rDhl
lg/e
kC^8
TioA
ijwv
9C6m'
x_K=
}C>^
6]E),
&hgj
p'~y<K
hg+e
'M8p
u 2,nf
1{qT
:ts>
@d8h
m(JAa
]\[9
E.?D
Y'v
}vW@>
1\ >(
h:A
8G)2
set_Text
l6 y
y 2.E
;rj
n3 7
w aOV
I#t:
0}+i)
V-y4
YhSX
r \K
jii[J,
}eCWfIo
q9x$
o1z5
K-F jip
?O ]l
/Wx9
=Cg
EOT
lAHsH
:iF}
nF8subJoI
/~%YXY
FormClosingEventHandler
2RHbj
PFOD
vV}/
Mr4/
8auy
8+sf
]Qw&
HWOo
E\,2fT
Kq.L
f tJ
<"W/
A$\T
^efV^
_ z#
i^O|
G+R4M$
8-i-
wY$(
R2r<J
C6;\cZ
4@|%M
-4@.
J-jU
q| 3
]%zf
}RO/
azp!]
}9SF
UtZ^
Z3cC!W
B \x
v3l)
\3JH
#lHc
G;}U
oYS<
Z|1,
TvS_
-i,b3N4i
0j&[
HVV;"
4>1L
L/r3
J;/)
Write
.b1?
mqsRe
set_AutoScaleDimensions
&hgQ
C>mI
+#yN
c AD@
.$B
~ssb
/L|i&
\l
yv t
c&tj
.5;C2
5yvT'
`Iphu
p&;b
k_#x[P
e+V{
R q.
P) zk6Sm! EK
s=aT
A.\E:N@
Dstd
44%d`
"KYc
"&$A=
X o-
N. _ =
AL:1I
)X)?
qkA{
mIrp
~eM\I
,uje
~ hU
\x^!:2
(4^O5
~i&
p%$B
0bOW
G[/{
65n C
u)WG
D-wf
EYcp#
0)8^
? jK
B,:o
#-:O
xlA)Ea
W:Zl3E
PVpn
WrapNonExceptionThrows
v]N2k
[e {
V)i;
.c'C
j Bj
Append
YUH
^K7q
d~)#
[SfZ
)zM;
rb {
q h`
C'{
[khP
JYyH
wLuJ,
D0{C
&6.<E
|n^ ~d
;{0>
\@U1+K
1R$@/U
j<E>{
eYQI`
?:6;
'-r5YF
62~j
!! w
_] ~
Hs&S
:?h:g
&*80
J[ 0K
s9y)
H?i=Y
(3mI
8an1
-dbm=f
m0a%
@4?B
cgbl
m&wJ
dHi8
7/Q]
,3hI
Sx[w
s&U
{P'q
V 6
}Z\n
% (2
W<*l$
2~3P
`~"+
6M?g O
&*8W
STAThreadAttribute
_Y^7
2vr:
vUw0:
Q&k$b2
?0:-`
HfU
RuntimeHelpers
/amr
[^;V
IHDR
Form1
NBJq
-X*oG
&*8A
7c>9
S;1O#
'Jw$4a
""bR
ig )G
System.Globalization
o04}
$ LM
K0M.
c=nQ
gl\$
8fVV
/IBxT
blkt,
]9 }C
Ati
EL:-2
\x?lw
P`t&
>\la
&*8g
;o:R
&*8c
dPB^
?ylCag
|8bl
&*8o
yNHM
&*8i
&*8k
tNFT
<_"/
CdmI
-,8k
0wV;
<Bz
p[r`L
EventArgs
!$
Application
v=}4Xx
1Wke
G|n
m1FS
TF~=;
pZj@
:~[\
R GN
YDnOY<
mh8}
{B-!
EAvEh
)aDz
R f=
yNv-
I4 S
[$3kb6
Xwp>$v)Hsb
g~ZS
AssemblyCopyrightAttribute
N]?"
[xfz
??-/
]t-mM
<8!_pS
4_^l
HCik5+t
u5IP
s}z Q
c7'v5
*)E
%htR
,-]Y2
{/Z+
z3o3
?(Xz"
!^7:
u'm4
ny,S,Kmw
ss cxH3
vd~7
MEc)
[v;`
=M!&
DbR\
~7$/f
)"^i
,2\;
37 G
<BXxECR
'G|o(
94_&
Pn g
syOF
?rO<
#Strings
%^U6
FqVtMe
X}3*
'*9
System.Collections.Generic
$d6bf686f-d49a-4d89-9cd7-4672cd96334b
~RzAw
System.Collections
BEw
Hh6pA
Vo^
"ftZ.
Njqd
}hQT}c
oB<
S!vm\;C
=9\Y
[ .E
pDt!
a,qNnY
]oI
dO>E
:ZH>
Z +
p6_
Enter
AX'd
8{c|]
vw?U
2boO
6?[
SuspendLayout
]7>E
o=7oQ
=GKg9
o3J @a>{
rr }o
J) 2
m:j5
&]O%
jM U
Y%4"
U!ue
;sV!2-c
Fwu%
FNL
\i54&
L,33
rn pa
`\KC
c k|
L |a3
}JaB
<vfC/Q
8i f
zq%}s
;lBv
v. F
[!z5v
\DZ,
qG$X
B&2}
{zY;
[4X9
b o\
#Y!J
<2b
?blw
5Muo
6Nc;il
&9>~
OOSr
vv0G
|Rr,m
#8qo
BPKY
=?to
c1On\q
xjkr
WsZVM
m![l
;LY{
c]n%
W,DmM
<m<r>t2.
yA4a
3~}
IDAThC
Yf+q7Q
F &yi#tE
g:Qp
o~y%
pOsL
^Sf`C
d UE/'O
9_oe
bXF6
MVGX
>&1 }3
yR`;
| 6K
ET?A
~:&'
! d]
o=xHD&]
B>Jt
oXZr
+@ E
n# O
yZYE
>9cz
8W C
uV )
]3Rp0<
<Module>
t :E3
hKNh
a\aC
b,8Q
jb#m+
77]1
n@'T
`ls=
#hEk
H3P
pJSCF
,_l3
gv&#fb
& kX
bAcXD^
C,/L
'2n'N
Vn7fnO'o
4&d-
l}wt(
UUQ(d
_U{=
rq2GEg
'q_}IH
j32o
/x8 F
P6;)
?YO|6
_0l]
9[B+
rr*
]',,
v Rj<
lOh?
x@ry
_Vw{
BA=[
e%fJ2R
1+;A
[~/?Iy>&
gU#c
9u6/
~oWT
"C|O
,&mI
K&!.
MGlZ
"%#P
a<Dq
a-+l#
s=|xY
|o{q/
?v8E
_Xnc)q
]g/{
112 X
WG7X
dv|B
BZk D
J^ M
o&'5
hL@E
;/:s
A 2T
+} &
m+r/>
8g,Y
ei9d
bHC}
Uc m
X%eJ
NyF N
wf[X
nfgxjkx.Properties
v g6W
lc-c
9\`{
EeLa
%$`h
|u}
:TC{
r#>(]
|*jZ!
C?7n4B=
X=U&
@n$)
btGr!>
jb6aW?
wvM8
y$b+
f6
vG@0D
+\~8
jd(
zWDq
%>Ms
o$,UH`
1^X)
]D7?
yi$!u8
chX@
yE~+XH
w ,Bf
'e8x
_ iR
h4$Z
EnableVisualStyles
iEuH
VQ\
kwv+d
X\
t`F:
`y|
]wU4
I x-
o}9A
DZ|H
\[bP
7}eZ-
br5b
xu`,;0x.
& op
(.8(
% )R
S6hN
@?l1
glS
w_3jy
yd*ys
y=)
n%H^&
(8 5
'~Fc
)cwW
qjhIS
oo}B
A'E;[O
kEAC
^;&c:"
6 1j
Eg#~*
p&eJ
abKfb
:cJ&
Form
)*r6
6ri(,zq
'~i D
z>A|
1>a/>
::xy
P\]= r
O*JI
}HQ)8
^YOI
GFot
4I )h
z 2k
YS+TK"
(n9u
qg#. ^wY
*Rb}
oJf[l
uc b
r3pW
"eeO
Y4i`V
)G ,'z
]q$:
!JZp
LLla
]PHI
J iI
Kb*q
2`xo
l:#.
8Q
lUt
&x ~
}6Eq
%6M{=
p$-c<
^ruq
dMF[
Ey*-
_$mVEo
;2xd
P- '
=8
-qG'+
N1xfwsZY
;J N
Q[|)
fe u3
`C-I
KGlA
f>Y7
] Ll
:LPR<.
vmT
WtEK
EC15
c6Cs
MoEr
kH?I|nV
gwP
ZHAd
("im
InitializeArray
{yG8
f T`
uo'U|3
d\o\
d[rdY
"c"$
@t +
LCrc|q
+}q%
2P;O
C Cd
?eG_
E99AA
xB(;
(nH,
t
nL -
'gp"
SP"t
-*3$
{}AG
0`Osq
HQZ3
\u
B% GR
W~V
<ktW{m
(zE B
(n^ W
gyUyr
~0r
Px,/
3zX[
|J/6
eK/]
;>E
&IEJ
DRzlr
o.]Nf
h-\m5{
]G2^
|m6.
0 ~Cb
5:%:
@= WC
m\d8
^D e
MyM]
b
DrXE
d&^[
?C?:
ApplicationSettingsBase
*Y4U
d/FpHP`Hn
ncgb
i"5
rY>T
>u'b
-x^T
++.O
`]P
C&!zA
u RU
Y5C.
N.T?#
/5[[
Z. {
}bo|
q %8<
,L-7l
W&X&g`
K} Z9
Cr+X
1a ou
Ij3Kml
2jL
IEvidenceFactory
S`ml
Evidence
1.kE f
$kVtl
DLKL"
.DMd{.
VLD,
{, n _
|U{uw`A
Ct |K
lRGb
ValueType
88HG
System.CodeDom.Compiler
GuidAttribute
^QWZ
cHG[
SetCompatibleTextRenderingDefault
*6.Q
cY h
=r,`e
N+>O
z6~,
cd<k
&\Su-C
hZ)YO*?
szYu
Xf)>3
RZMX
TyLX
$gx]J
[;Hm&
System.Runtime.CompilerServices
Hg4O
M3q_K}
FJX.t
#6*Z/
b+IV
)y<bx
'K H
p$jr|y
hTNF
8 .8
vH =
%i@s/
!M<
<b;
J4H4d
qkq)
NN.
Q*1{
gydM
k bl
A@cT
&D|Dp
RtrIEX
V>)b
Kl#?C;
0Hdi
G\fK
@>S@
'0BJZ
J:o'
n= zz-
\I?#
XJ C(
wvAn
75 ?8M
>GW@
/)Q6
'`H9,z7
i4EYg
'v\3
glW<
System.Runtime.InteropServices
dl#
H1Tq>
g'rP
g}zha
F"GX
sHY
?H:6,w
w$xvq
e[LmI
A'LJ]
"t*w
z+?Q.
7 }3
uQ ob
` *S
< _4x
O"o_J
0$KJY
RYE.
s '#f!
<!&g7
>2lQ
u-nG
bPb=
o2NX6#
tz9w
rrUS
W>$Lb
z.:_
q@j}
,4H{^
ofY}
mR <
%~\A
EditorBrowsableAttribute
ja&y
<6g*
`jN{
\clO
-{| <
s}cAh(`
ToString
<>cm^
`J,B$Kx
nfgxjkx.exe
((gd
^*g}
ehX>
d}w
Op[0
H,N^^
sG|*"W{;Ygfz
^Fw|
GO2X
m$s6
25Fc
w{iq
K.jC
p:GOSU
A<_
Lw0vP3
'?Wv
$+wX
m;il
?bU!
7x+S
rUZ
R9M&
ufsL?p
bx7FB
, mA
f@1y
T,4A
N& F=.6
Nwh2
@>c)
<oE
DurL
_N< N~E
|X+_
lnib
v~ +5
IGxhn
_\d/W
+-2"IC
p@?v
4=a\k
"KhNm
Ef w
Aa@,
Ns#[
<$;-
&-c
tpX<
]S5>R.
%_mB
}kS(1
Qu .k(TITJ#
p51Gd
UlB
v3v2
j tL
[4Xytc
32}N
add_ResourceResolve
_ 0R
?;^a
8FtrA
a:8^
KqFa
J~K-
4ht*0i<
ZDz#
AssemblyTitleAttribute
mpib
Y.=
{*6b
JF _
:tmK5
(p*hZ1
C@7e
>MB-
.cctor
xq{o&
`,cG.GQ
r _zX
do a
)no%
.Y=`
8SbA
53]e
.,~K
*[Zpf
VzVQ
.Y2T{
S8JM5
k#Rl
W qO
|IPG
}HS9
PR5i
V1's9P
@ UW
n#&S
-("K
%?};R
[ Y2
|mQ
rcQ/
\c]}r
c*7mI
yoad'
SettingsBase
2xD#
|2EM
}4$8i
#y!;X
-?Wj
0o&7
ic}B
~ s!
vw/h
_E["
eP_x
0'-,
Q|P\
FDx!N
'-\mPH
=e3t \x
J( Q4
;3
1&5VM
l#p,]
Xc<-9
I=V[
'S%7
F#-(
H_Fo
Data
X4JH.
tqTC
V5H|
[_,V
6|&9!
h>^$
[pMx
m=|4
G SA
&pT;
aZD~
]+#@
pbyG
A|@b
Ls ?
$<ZC
2<xN
FL+K
ieyp
H:@ {z
get_EntryPoint
ZVjR<
x LR
<X'zu
[$PC
Hntm
lq$rb
YOmh
pHYs
Zz
7O~w
0eF:
"?sZ
bd4%
4,k
>le
>1*
q!t7
+Uq#
Hh\a
"x08
mscoree.dll
Q&{)(W
$d9.
` Dl
^#uI
T$ +Kd(@F
G|ZJ
1y-I&u
9=#9Y
]1=W?
R6iA~
r A3
1|l<
npt6}
|AJd
/y_}
QPZRG
7{AS
Invoke
y.(Y
disposing
SetData
5hKW
g]W9`1
Hfy*"I
.=9@^
. I(
wM\b[
Ak4?
U]a'
#ZaU
!+oq9
FVf{
3L-P&?
K I`
J<#*
wlO=
[sjM9
@1 E
O(<Y2
qwgi
fN~E
8 u_
a(1 c
7*+*]:
4r&7
a9Z
k#0H-;
AI HL
1Jv|
UBv!?
)G"^\e/
s ^ZC
f8?D
UIY$
^`!k
VuP _
,Kbr
<Rm6
^zy=
$z\e+
VAY]
>}hg
Array
oqJ-jt
Uz4
w^`Js,j
4hd.
g] [
j30F
q`Cw'
[y-
@.reloc
J 3i
j'g ,D
L+7E<
4V:$r+
A&iB
QL*x'
g/ %:
\.rI
\l&}
\\[V
0sRU
qq*a
S94%M
I_ M\
e3@]
k:w0
Qfyc*
$]@ g
lsZS
@w\d}A?
Da7:,
ipS?
}~T1GR
3@9O
,^z74
8ofW^
%@?$
gI]?~
-}o?
Byte
1lnTy
_gP=
Zh%?
asn^
"T*q
$s>o
(J~bz
ng;4
q6 f
yDml
e/e9ez
++4kp@
E@Ktj*
Eq4#
VNC~
m[UV
kTCn=|
p km
#XW+~
JoU[I
ztN\
J^|)
brxR
I]Y>
(*A~H
$KJ}
FsyU
Wy g+
',tX
((0&
=14
tEa w
08L}
Z.bd (
` D-
xVkC2
AFX.
70m<
&=Rd &
}v@fso2<
zA&;
HL/
M^P\
/ q9C
*|^u
Q3yy
N60B4G
#v!OCl
ELjm
\~k8
H;\0
v_@w
SV8~
lDs
Lww&
QMOR
v6),
ukY(|
moH9
FYX'u
p)'5
,s6LL
?9_g
s k6
|? a
IEquatable`1
?YpgU
KNjU
q]Q5l
z`S
C5J6GH
_+R7,
ye8,!
3lbX
?@md
p9#Nk17L
taw4
pvgJ
)<q!
?4S(
58n/
z.o5T
o^z2
n{1b
Cy`q'
nL/
60Zy
oO_!1
u\Xx
rE(#
hlY'gC/
_w*02
avD~U{
fFQ5
JWrh
c{ !
mwQc
y~I=
gY"?Q8
a 8[
p"S
*VbZ`qD/'
=06E
5Q X
$BOeQ
%215{
@uI*
Ya$d
Fsbhk
qp (m
L OBxr
f j mAJ}
_ kc
FLD+n
'$+X
F5"j7
&wS0gm ~u:
W28Q
M)Q
System.Threading
xj/;
W )^
df2G
5I T
;*5!
3{m#
pLl]
v9]-
r/O'
*o''SX)
PM9}
yZ{S/ti
eMR[z%
P)9b@
%uI
U_J#
fnJ1
jC@=
!qw
l3`*
Ya2;
"%Kf
vp.X
MOhE
Ig@<L
NB RkeW
oCpf
B4 4A
Copyright
Z`(z 5
97.|A
,^+Z<
`UXg
76:Ywh
QRxFw
xe&?
@KtB
Z;d.
N~ m
Mw8K h
Jt*8
ieg@ >
1by8
Y)^(
opXO
T7}cg
^W}C
Lv)S
fx#x
$*|A
3; K
nfgxjkx
.Kv
n,n{
#GUID
Y#]z
(|TK
c@4H%
z*?A
yE?-N
?mbl
.AR/
e0iY
4r:o
}9n,
]5Sx8D
'Q`~ u
A[x)\2e
&VdX-
[- '
%Usxc
8@?iEy
zgO,n!
:OIi
W>-&
`sYM
En|Cb
Size
)Gf0
yV&a
[?qs
a Z:
G,.MJ
^!2 et
)$vg
m ~=ug
r+tKL
Hqoh
0Ti
QgZe
UarFAc
yE.0
[YvW
a9mw
d==
z &<@]P}j
j\"M
\wv
ICollection
pbfVlw _9
.:pi5
vC!/
E P7
eT$v.
4X (
M8e^
3~l|
[<E\
Zid|^
I p
#? R`
H>Q,
^bV "
wdmDl
!RgPe
<R7{kf
"vlV
(i'?
;qH>Ek
>uL-
a9"o.y
\0Er
cLbl
U-$|
7E Y"
l[rxL
~ H-
d;^
ltOCNc
lu/*
5&?
i>FiE#
['Ap
h_nK
/]L/
X%O|
?*dF
w{ &
MB9j\S
yFrJUQ
{Qp0
s[ RWb
?('M:
|=`.jp
r7|m
GA>7
vu 5
\Kp*oF
2@qg
sHf[LZ
sk/ZC
PZ#R
u$7D
Mk>l2~d
&6 !
t&pX
Sr 3ig
set_Name
.ZfKS
7 .7
sdf7
x\wZ@
/jKk
)Gy:
:[=z
B`|7
PEEFn~
RWZ?"
DSMh
4MhH
X h
4 (D
E^%.
X U
4j##
PG*G
X P
bo&:b b
8 g
lM{H
E4zK
X Y
#=yR,
q+")
dl4
#r\Y
X @
sy&a$
o}ik<
d}z%
$5A3
3:(:
[ Q1
MethodBase
;Kt%
%2t/
Tr?v_O
=gm
x0sr
2RBg
X <
|PW9
X ;
'GIW
\wI 6
{G#W
Wc= 8
31I'M*Y
DXc3
VSpZ
YpC+w^
Ppvw
(Gl*
X (
:~5S
0n *3ot
ResourceManager
RuntimeCompatibilityAttribute
:vpU2OI;
-?Zy
B jl;
k>-`X
n@T*
/T,\
%s~(3
mc6
b S3d4a
8
_(W"
9Kc
BK1%2
mJY/9
foGu
ContainerControl
JcW?,
O9w'
c+g*
S%_j
6]Co
G^%6G>
4 qXU
iHI#
="]V H
%OtZs
6n5+
dlC 73
E" ;O
+gGy
`~w@"
bcXs
hdAIH
$FP&
8o
>Lu,
{`8
(mS0
^U\&
%@.>s
0 SCjf
[w Z
VOfY!P'
System.Resources
2Vv=!
; >gt
||Fvl#I
Suf[N0
*|d~M
Ilhb
H ,DK{%m
8yCG
j +@
XH? (
wYZC!c
EGF&
aq}h
/O3
P 1 a7v
{1B^
h7-r
IComparable
%Y+H
Assembly
rj)I
~
M`,2
*td4
6oas
B7wH
nb`zC
F&)? q7
(8\4
s6pU
set_AutoScaleMode
6qak
F]i`
3 Tl
P!j"
sKFE
\lXG
V;.}'
%cRQSPGz
p=4;@B
c`3_A~V
?F^1
W;nA
<$7K
Okc,
a$I:
ujk'
8)Dp
eA4>
xe (hn
u )0R
f M j0
_'vM
A^~@
`24
<eXXy
u% )A
HK`
tI"G
}ziy
hNO&~
Y 8#
Ai*"
rk@}
Y 8'
V hA
@0XjSs6
@X&o
Xi"%
,n;h
%bFC
YgOiz
H]c 5
Z+cm
I
:)^I
v z
C`F$
3*a1
mEH3>
Xg0]J
9ZIx
<>1z
W8M_
:N>d
Zj{{
>?|a
kCVs2
cs [F
LQSa
diYi
X{>r
NVl}
3@6N+
aKL_
gfHS
r'%o
bx2|B
)'9eo
Y 8w
_\7|
Y 8k
O9X{
->]3
PG_<
2zcZ1
]d;{
}%TNg
82|I
';]|
igY
mIr(
]tU+=
=&~E
PU8f
L9 b
uR\\
cl6H
J]!.
;dq@
id N
Z&QO
8#0F
Zt2b
aj\z<
W4<.R
Raw;
Oc \
Close
<K}>
N# P6q
Y 8G
,9|)"
Int32
]Crn
>8L[
>c2D
0nlB
D5 Mn
/ l9
k-\M
g{+#4a[
'cUL
rDUc
N i{z
MethodInfo
-4<>
BSJB
P@Jm&FP#
GDY0k
_X`"IQ
B--4w
i4K(
nd0
Hvzu
_r!@U=~
F32
!9 \
FI70>:W
V4lF
r7M$
L*7x
RH,h
o8 oE
]*9xA
KBx16e
gkx%
` D@
V_)V:
/12k
A*y`I
m*PPe{m
O^M9
FjiE
S J4
U:#6
mr=0A
b)3MK
4rl
koO@,X
FLJx
zzi
p+q
E pjz
)()HGZ
j^7R
'!bl
4G \
~;:;"
phym
"uAw
dG'+
Wb4
vR y!
3E254
q?]*
<0<]yz
BIJ{A
us$C
^ucI
Lw17
d<>B
-99_
+-N
>W5}
i$$nz
"L(w
>kYI
U *i
gAMA
PuTK~
0 '>q
0v_OO
JUX7n
1f@d
'to
=O>q/lJ*
_QM|
cn&LbgA
$H1U
!jYm@D
?6bl
+'#|
AutoScaleMode
9MqC
[: /
[6@K
'*`!
v>z|4
ch
.CY?}
MarshalByRefObject
~vN"
i_ z
;TI
JJ~\
FC~|
+qcWL
8zQ(
jMcO
nR>@
(%`I
;A-eo
-cD~
Bl]*`
#.g?
l82x
,?+:
mscorlib
xZ&'
g! #
'~ ""4
,uV<
K iD
y;1~
89|n
PIxc
&qyX`
(J|}27
[X6;
CompressionMode
>q8F
To] !
. Sy
Z5dC
;$ `W
4zqq
k#2A
. 4W
h?t}
Yk/r
5oNA*3\
/\#+
v zP
"G1v E
T'X;
`nu.M
^BHJ
w$V<g
9y0{
GD6%
H|~
_v.y
>uy
]('8
WM'
|hO`
e86k
'CvO
Vxw(%\Y'
9xs&Y
fc y
t/8SP
QNL!
ye>(A
J<a}
Pg51#
K4_s
L0]+
QR66
=jY~
n.1&RV
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADP"M
`C<[?
IMPr; u~
'`*?
\]qg
I!56\a
OO{N
'Rok
5Jy4
?HTHs}
jC/f
juKi
>WZx
[G2x
Hvp5R
[`L6
p0Bs
i/s1
RuntimeTypeHandle
/XG
wZE)=
&1@\.
p,8
Hn O
CpryQ
x ?^{
y.q"
QjS
E\Tca
_F-y
\8G0~3
fF>U
EGX/zA
#/0Ade
}k238567
)NTE w
| _v
u 7qF
}/ptF
dfXD
%Cb3Vc
~VHd^
[F#*
]S|
HIz
U>dP
R$~C
$tdc
ex\?=
|l&(
l<"Tp
ooEB)
YDn6V
*A^^
NPid
x9wm4)
H %
0R_K8
8N4
Kxq+
I|/?
=zw
/p\vd
3fnx
F>ZG
)tM&
:SnL^
'j|]p
,CSO}(
)/P#{8
9sW
&AjW9
o`2_
8?c,
~.%T
?al0
5b]g
bW3{
)|54X
z=:&VLKoi
A/7~
=\*!
$tTa
ulL5 `
u9}C
WP_zo
%E'"
SN"
s+*{u
J@
L6/>/}1
pF3%
+Lym
mHqf+Z6
-+K`
, 0y
p!5O
s|n%
?f+%
vICC
AssemblyDescriptionAttribute
K ~)
|^|~)
Q^81
'cJP
A,<]
]\~.
\eg:
1Oi';
h=04DK
V"\a
IP@4
+:\b>
e6;w v
66 li
{k
{'f4IX
U#&
v-0v
)%;W.
; t
~Qrn
.in4YZ?
#CJ].
zow$
zOa(
w25y
l[_,
02,5k
7M]Z
AA79D8F82AE72A99F90BD57F09E3E02B166C1F4A
U)m<
0R ]
/]Z??
e'Dar"uhCV13m
!L"
`JGR
2+I^
J|&:j
$C*s
cNF3}
b'*z
X>79
#s$t
f\k7
We2P
!s}q
"<l1
0NAuO:
<K :>v
YV8Vmf*
[9A3
K8 _
sYzTu
FA8-
Char
DH7t
KE'F
W bl
J,5+
)Z}x
KKb7
yyP,
`60(V
|"nj
f+9U
:{qW^
yRD$
"sLs
us-7
hR&Tb
?CFD
taSv
~AsQA<
]|Y{
sK;6N
d[k-,
~9mb
0FL|y
vJtU
gI`
vMYs0R
XW42sz
0%A(
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
*TT2
OF'8
`8b5
Object
``'Ttd
m"bq
VX4 0
bLbl
c_xD03z
uvRF
/Z P"]
,_+3
E,o
`\%<7
u_rr
A|CI
, 2
#^"|]
,e4obt
tO#7
R>*DZ
$Rr6
^^mie_*
!This program cannot be run in DOS mode. $
nvw`
vh#"q
y[ -]
iD +P
"@("
System.IO.Compression
Concat
=H'~
%I=
zONECNr
s'?_K
$WVfC
&H7^;
h4r:
S a>
_FHJ
`NM\X
9Y*v<o
oow>
Am1cy
Dispose
A\6&2
!!]Z
y(7n
('7LY/P
/<!
)H@\
>8O&d
`\3<
@M1K
<my+n
6AUw#"
./T'
gsQV
$(\>
<z]~f
27a7771d-4125-ac.Resources.resources
f4wc|$
67#;
ugxdK
s\|hK
r !A
ICloneable
cW&|N
J, WQ
q@'g
{2\X
&P;ysYj
j\"5
NVj^
`:|tb
df3+C
-(x~&
PTF?
fmy.
d+ay
7LLi
*u
'7m
c jJt
TnyX
set_ClientSize
{I@
'JD{
p~9q(
w}X,
D,C4
W[:A
9&!
$/NL
W/ET1
2h=t
,> K
wDjB(N
eJ
^?/`
{&:
v <#2
5+`
i8?K
tYUFFr
m=.k
j jl_
<bc|i
39<l_
7 B:
G% a
W[,j
$2 ^mD
'/l v
`z6P
_POi
|?
.Ak_
zv$G
I9f-
.z9h
R^[0L
Z8"
W= ^b
L [Yv
Y L
N9Y0
]G}6
OJFK
GR'
</Q A?
Y9D(
{Hm5m
mwVS
nFbw
#3Ng
P_D{
Ed:5
W(8UZ
2V\x
!>zB
w,dU
>Nqm
"|*5
IContainer
Y~\~
Y yM
,69~
ZSP '
r$sw4
4" f
f<+-s
PKY\#
|p qW
/oJ?
|1dza6
K74y9^
A*pa
y?7!%H
}?.R
ti
'iSxN
@o f
Zcq(
_Un)
| F
%^;2g^9V8
cc Ab
THof
Ve#-,
tdb?
A?P
Ns -
izREL
m+`Gh
<rjK>
6\T`
,f$m
Xn^2
xR-8
cB`Q
m !m
B 96Ysv
.eBP
?O92
T P1
?flL
m_Va
L;\G
e.p~/
i=n3
?gGu
8P]\
JS5XP
ynQ
_AppDomain
gG_!
u9^
Bcp$\!
aR|
4Cp<
MrPsl
NO9R
F@X[
P|VD
6RMJ
{&V%
\IKJ
(~0y
\d$Y0&
.@&s
Xn7`)8JJ
AssemblyFileVersionAttribute
"\%A
rT1i%m
eyz"
\ c/$9
M_P-x
E Y)
4r{iv
wwfu
< O?
zPBj1
y*4UEJ
DX>.H
~e q
` LUZ
H+?nk
3n-g
g]`$%Z
/%M[
~cx.n
(iV39F
#|kpWW
3+96
Ko6[
@? pi
aT@f
&~p6
wjJ|
f5kRm
jz7d
a#;f
9-4_V
o=#=|
]Duy
EditorBrowsableState
gdwT
V'l|G
4 q=
3%N&
C[zC
p#6,
m@[&m(x
l 'V= LOuU
eD8G
!nLn
6r7}
pIo:
[LmI
eyW
`V4u
b jM
QV2:
RUg']
y2+e
EQp9
b7"3
T3?;
rmNw
8 & Z
0] U
i3BX
L(zM
EMyl
&=@0}
|E|K
vBAG{ZUR5
# HT
m en
@mwaP(
`.hW^
eEI9aJ&6~{
'oU~
>l@+
A^y
/u}ho
uGO ]2
E1>>
=>n!
+c7)p
hs^x6
1HUu
oe~ #
/ZTuh
# Ru
M!8;
Qx?'=f-
LoV*
ea"1
ks'Q
k[ 3.)
8O/C
z. +pq<
Q7Ef%|
,Fj~vl
?;7$
]}p~
.fKR)
_D,c
1&Nc
zNST5
u{al
wb^y
Cl7
PCoG
z8Sm J
dz,j
L6|2~9'
chm_
q9&,
- k3
#. u
)nRo
RS9zvh<
X'lI
Zy)G
wL 47s
r-s+ n
gZ`
L#B8
LIa
:iy?
$lM5O
$hW(
d*{&
bPS1DX}
IAgRx?'
?jveZ
iJl>
\#@1Y
G>eo
ap F
lJ Bm
1l[oNkk
Rvei
2nm^x
8MEF ?\
?"Q1
'F>ak
iGj2
P=mP;
N4o.
7Y9:
kud!F
l31<
._8kX:
? ~y
Z!41
NB@9
b_FZ
4iMt
Exit
=L.m
GN "
CompilationRelaxationsAttribute
sV w]
AFgFO
MSOLH
WfF?
z=p(
Ym\%q
8d 8?
Q_.g1
5SMC
}Y~%
n,Qi;\~
^Ei-D<
iqF]{
` w
`c|xo
MemoryStream
upG&FJ
[7/T
]}+r
74B]
(^%#
DpO{
%`G Fv1
r8iEvA
b9U d
*%w:>
VF(C7r
H#R/o
y7y&\
4 <A
Zi7'
$Ph9
8.b0
System.Configuration
>)gO
V4d/a
}~Gy
OVz :V
Z1Mn-Y
ResumeLayout
C mI
Whr/
m(:T
- ]4}
ii\Y
YMf!
u)Bv
5F?^?
<h2-aOK
tfAv
V"1d'
iBdh
e bl
dG|4
V?#![
_4(7
ST{|
ZBY["z
n-J0*2
g;1-2
c]qV
$$Y^
\Bzr
XNwn
Tm L
Bzh1
~MAJ
V*:a
N4F4
7?Fy
CB$m
|W(ne
-% _
8?*b
~^d0
0Xr?Q]
X2\:o
#@ {
LKgt*
ak+o
SAYd
,11{
~a$E}
so9X)O;
< \,
IEND
?0u8
~8YY
@? 4
fj_,Cl
}Vhl)
rijD
7~| S2 w
2YY5
%OC!
62J$
Sa18{LI
K`vJ
,7H$
LIMO
:,yn
P3gj*~
)j D>iy"M
nw'.
ZlT!o
iBvN
~u*q
([TZ$\{
u1Q1
HRPH
|<Q[c
4 ZIh
l.4"Z
ALM2^
2 33%
B:L_
2w%Og
P Fq-t
ZM4
IU*C5
8ZiS
YCxX
@@ U<
P(FLr8Q
R,XAs
8f-iq
$:J]
wUvu
Fql^2
ObD$
7:som
'EJC
x9Y 9EB
2>s2
JN;=
)@J'
C j3"w
VkVm
" B>
{s;)
KTm}
e-sG
rkvY
Q{gX
B{d_
eG 8
Va :
Q9bl
{44K7
:\1X
YJP8-
EMa~4U
tcE-
NJxc
g=/O
G~P I
}VvH
|YeQV
=24L
W4V`(
A\A(T!8
2_~U
STiq
g/Th"
?f$&MKL'<
FA)1
&n.,
l=!]
g=lP
x0u
E<mS
NgFE
9LP$
G:N9dJ
Dc(Ja
$85|
(jb,
P#}Y<Y
yzyc
*AP*
wF$y
S<.<
: |C
[#(W3
]q
r[[T
+Rst^
Hd$S
&>)I
H{r>
\l{
2r[Q
{kkw|
ij ]
'7.7;
Jd E
&'O*zC
kFff
n_}~
6!yi
o#uHe
%T s
;lWU{
99ti
DvF7<7 [
"MgG]
o3/q
bCs[
pD0JA
#;;Kl
^; j
5De"m
"R"}
pnj`
zC d
I ~D
2DN&
(j>Jo
`Cxj
=uUd
P|=>z
Gq_Z-
~*m8m
;A/wj
2b,*oi
SM>P
$7Ph
!Wl$
{X:6
F !l
~ml
C 5u
T@n<
y5P."
P P
zweR
KqdLn
ContainsKey
,'s@
c` O
!?IS
CWr~
}ed*'
j-T
System.Text
B+nMm
s>*;
eh2>
>qtG?
aj$xWZ
H~3u
a: v
|{%8~
H5DU
GRq
_J9j
Twj>
Z ky
4iXO
Z)l.
]i]3c6
JxY#
0K1 %
R;1.
&"&r
f*P!
b :O
-}J.s
}HIL ?42
B_>*h
*18(
\lz
#HHgl
@uE2
B[M^
L@o Wjgq
wLru
cyfs=
t|_z
=.4=
|d9Z
zCjm}
Rh#(
Nr)
p*YM
sXWv
Y\,h
DVY"2
J'p[
Wr{s
}ox{T
@c^
9-aO
I;S yc
vWYp6
B%"3
>AQ3
CZj.
5%ea
G{h~
As[u&
%Y@B
,-K*,DDo
^3bl
DTc,&
GetExecutingAssembly
@z1(
m07Hc
PYa
5SZH7?x
4UA'
&Cl
VlAB
lB>7
pjX~ /r
|HR).
C +}
ZSU85
=D==>?+o9u
V)z:e
:GStb
^MB;
_pbn
H z|]
D6BBA7
7GM
n1[tH0^^
GLGo
]R%2q
ci|O
glo
:cTI
YO-~LO
<y4'
F )!2T
EL5-S
l1_qQ
nn'9-
Z3H]
'0Y$
v ,<w5
.NV/
l6mI
=5)e
+|MG
<`{C
v~z
Fku&
G]i&
hr!o
92 p
v!}.
;TOS
;zN1
h&?F
;-8{
Q]YO
bokT
X.wI
AAd"O
#$D%
$9qGK
$*W$
T]Vzf
> v@\
(o6^@
3f5 .
1lC
Ju]
M:"on.b
olN
3Z/-
tIJ59O
fZ?u
hXRZs-Vb
`MB?e
E#Ko
/ og
^ 4N
[o+k
Bu^{
_CorExeMain
Q,T3
Q`#jD
\L$.
iw3.
P#wx
29 0
:K?
e^U]6
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
sw 5
I;u=y
7/V'
Kjkf
SFz,
<dEe
o<&$
=J01
L5@^
vzmm
7-h.z
JJ?Up|p
T ]y
]"%3#
@<J7(
HX7-
8!ju
xnzr
aAK
> A "
jf,9
I6Ua
W 1I
4.8Y
`G@T
=4oI
~*M)
fN9l
t\fj
W4uP
YQ=8
YwIS
2P5qh
3.%
z}c/
y{ w
E"9/
:c%j
V^V+
N]AC5I
c)wy=
. i(
rl1@j
eNRd+
*[x9
GOb:
y;E`
'k.d
Qt{o%e
8jzm^ /
e9~<Wk
MoluGe)ln
Z?m?
!u `
l2Yt
hbl+
D.Sq
Nu[Z
^7d
!I(V
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
J444
_h.4d#
+Z> ]
/WyRtl
{YE)
l_v P
C`a|
rR[
@'U"]
!:*q
nF'=x
[LmI
q1R?
"vKi
/`,2w
n$;&tTW
K+j~M
]'3B
A:bl
'yh-h
J]Nf
#zUx
3jYm;
7BpqE
7')Y%s
I\P4
A`k ?*kt
3% Az
<k.+
VR^H
jDc
b1. j
SaU[BaDj<
s G,
Sa Y
s~[]
tr)y
Afej
z&k
| R
h%Dd
S|Z"
x[U}
1?8.
7tGG
Load
w<bl
:cn|
Br i .wf$
HSR8
|>Ms|
|?v(
GILf
Z/bl
?}cN\
@ToP
s QlzX
w:4O
5%]CLh
3 }4
etvD
Yq:P
-pKKq
_$k>
}nQU j
J.kH
K%|<!~
IV}
w#pcJZ9
w5=k
(>DZbB
q7 u
xeD
gKi:
"wzW
1fK+
<B~eA
gDZR
p )?
G$m1
="qO;
Dictionary`2
SmRb.
H4oS
+j1&&%
..vO[
.&BH
+92UqF
'fl 8
[nI
}U n
T U
mWTA
n!G|
P~3$
wJ7
KH/V
Default
}y~3[
,gE4
%U<
7[_S
rpKV
Ai "
pTgP8Y
ukZ~$f
)N$8_
xmji
9M?`
* c=
P:f{z
`N JS
OLZ&
F$3|
,qJJNy
/j.7
B|i_
][il
87Lg
.x%O
{8[W
__z$
t9t[
E1S)
wt$&U
V ?(U
RTAl
JX1LM?bR
drG(
<m$m
]zo!R
Iw(L|PHm
X?n
m_o)m
I-vy
ah\i@'
44y )D
0G7#
*gT+
w=?R
f'8 cK
cI2X
*Fh;
e6 *
V_ n
*)q2p
y,/j
c)2P
/3R*
; P'O
IX'
w3Ih&9
@KW/
v2.0.50727
9TFy
Jj0
%#h.L>
O,1QB
=t.d
:4?.
7_ 7
d/pt
?]A;
!WIf
k~w<=
r XW
1fnw
a1yK
DHHDvQ)
1NWa
W3@I
TR(N
2'[Z;\H=
{m44V
7s.p
a;K<
Mz;
N1$/
LF]@
f:Ow
G hkQ
K0C~r
7P^{
0<M!
ComVisibleAttribute
Q!I|
F<R%D
=X_"*G>"
<X9{
$5 L
q:R:C3T
!ES=(
HqW3B
_g5[
ITl
dlJ!
A&#C
n9~%
@Rjb
F~HW
QnHB<
fTjV
-Y
U3 >E
,;{ N
Pq:q
D7@r
_KT&
[wHn$
%yK)(
D+[h
? H8%
Gu Vi
c \gP
0_ D
_Assembly
}h,`
#*@'
g qp
*84M
_c XB/
gX%%M
iAq(/xUnp
a3fE>?V
V| B
Mp8;)
.;@2.
WtC}k
1j]d
uV}7D
dZ M
AssemblyConfigurationAttribute
'6Fx
87ac
'{Qdo
%@m=
h.59
}N>b
^ >i
DS`)
{d2C
gLe^
F1;Q
CultureInfo
WoL4
1s!~
KyHo
fn# @b]
;xI"zb8
1.0.0.0
dIWd
q4EZ
2D:S
'&*4W
+i)"A
B-QeC
;'3m
G ant
(a&T3
?cM!
)z:}b
>L0'@\
#R.\
"B qK
]ZM)
m=H|
LmJRQ
j1@]
k X>
@;fyb
m3?y
System.Security.Policy
7/IW
3xkCL
z3H@
& rS
3yu2~
z@Y+n
e'Pt
^(eM
u yt
= 9ce
Stream
nf%@
sCIx
kL4Z
^'oI
8?HN
]&a=
o7:I
#-t(\%
sRGB
~>DM
M&+P|c
bz#1
fH<n2
v""_
@D1,*
p9B''L
eBD,t=
t(1qL
AssemblyCompanyAttribute
!VRE$
hyZ_
OsION
& ~)
] TW
E%r@=
;yPi
bcr+
&*6()
"-Jb
EvmH
#A6^F
;};-5
E O/
j|Oju
xnIq
A[Ha
/mU|
v%X
BPTjJ
|p"%
&(vh
U P^v
`]C'<
Dss^j
^L[!vj
%b.
VP$
b)cN1o7q
VQs"J
HuSnns
_,
j'l nz
mI?opf
HSX*
?F222
}YT
vCG O
/!>$
0 )o
,YmI
q5[i
a+GN
?1#e
`Nw#v
XE7h
|Kfut
RcSyyv
B!72-
52vu
O~~r
ra4yC-
[/VA(DY
*kcDR
L+s
q-ZJ
8!wch~
|#qh
>)A^
z<C}
h#cO;
b-{#
Rzmx
:1bC
Fv"Q
Xn | "
.]!B
@)?uq7
*w/X
pP~|
']<,K
oOa4
sFC.!iO>M
=Q8}$
1b78U
z,_i(
z?O}
5+%!
p]FJ
^ 5G
4; R/
/}fu
Xy<sf3?
vP`
wjbI>
.K\6
e Wp
Z KBS
8ze8
"W-^
F?/
,e"/
]Ar=
#==k
d /R
,\8@Z
eU/7T,
})5rK
Nm 1(;
?GA<
tq'r
7Tbu
A=fT|
O<}B^G%
} WZ
i-Z
O#;q:!X
' QG
&6+2
OY`[)
d|dqj
co 0$
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
e]M{Q]z
~|,s
S4,u
SsNBOu,
2xH98:
Q H2V
c!7* -
?a T
+I~1#T`
^8mI
b:?Y
C\"i
RFC+m
H3#<&C|0
olf8r$4A S f
f;M[m
vui%
Be8,>
-8 s
^'Z+
4'RD
= zN
!VRa'
{$Mc
I{6w(
[yHg
%Tvh~:R
S#f5b|f
%u~_"$&
+MOy
0gtG$
[F=R
-sW%
kB ^Q2
~21s
SCmI
VK_M
GetData
/vrL
ypDW
.k1U&
V#ZqiSx
yzr
[@eJ0
&q=P(2
TVJ>r
my?.4
x:H+
`i-0
x>*Zt
::9Q
5i:P
G&6S
o}vs
K)bl#
7r4u
'1k
TLx`
Geir
7 dmj
V]tQf
%g?A
P +*s
! :v
%By??
AhA|
\Jz^F
;%`j
u O&
{-&n
G Y]
dM*
0}Jc
L}1k
;-(s
3RvG
4B=D
UBH/)
&mno,
{;5i0
`"Um
;btibV6P=
!Y4wlA
q+PBne
gIn^
bJ>?
iQOE(T)T
< @;
`3B
-{N4
S\@Y
sMu
-MxU
L%r=k
]dl ^
|NAn
~gYO
",{B
0wxj
j]l'
$ ,e-~
-F0n
,(,
j>KR
7!S y
I5Re]
ClD9
t| x
SBRn
)2Tl
`"C
d1JT
,7g4
0..z
;8"i
ZY0
D96q
weBy"
l bl
m. Bn
-f&V
U\";
@y"&R
e `S
^$&s
KE!U^
. N2
@d_u
,U>BK0O
aVGxyV
]U*8@
D~T'
(}`-
G{x&
TRrY
gp=j
"S =
OV#os
kVD
D=M!
E\ *.F
l.zHl
{h8Y
T_^NB
_|wY
(uJ
P o>
?gzV
UpN
2/'Ej+c
Gol!
jq/<QSt
'q:1
QFm
~8St[
C~Ch
#X_?
J}"5
BsXd5
DJM&g"
VglL
B$1h
04I
LaqR
=mVq'
c6Us
{HI1^Ig
L]8V{
c}v,&
.t9
Zw6d
u|O"
>),B
@B/%u
a0 EJ
s3oI
O mg
}y3
AAgtW6
jXc>
aN[Z
GEu@c
B\DN^;X
CCh
+S^3
^@%U
S%{Zgx
set_Item
N !*
`3X2
^dAP
q%A4
l}lK
?@:D
4S$
CV
r;@O+
j :J
\W[>{
Y }Y
$)J#
f|l?
]$t(
}MS+=
Yv=W#@J3
J`wv
DE8AF79676FDDB60C1FA4569B52989FEE063F91E
Aj<"
Zs[-h!
~GfR
[ H#
ARivV
Jt$5
m4 2
i:il66&
KYde
nWVA
%dWBSL?
NNLJ
n2rxl
c72\t,
fRog
fc84
gN`Hf|O
}dC Ll
PDfd
y9G@
Q$f4
{;[P
s1)w
:6ZFP_`
A&r8V
9WxL"
ye3/
-:v/e
X8e
];"P
{-4FP
&pgth
[aO0
3z 6a
.'qA
d?:a
1jat
@iF
Rn DZ2
C3C3o
GetTypeFromHandle
d0J~=-%
W^cF
}pB:
U1<gV
o4Q[
jF1
jY$]M
Ivl<
ln@b
D9j`0
.sZe
KTgc
a!@
bde\[TW
Cm>!
RZg4
#"n~
Wkr_
L9p/
JcOi
ZB4T
fY!F
//bl
t\LE
GQo
1k%D
X..9
v2+K
{8>G
]KDF
S_S*0
S<R"
kGZ.
!\'Zad
A)<>
)bg9
L`)x
f`7;
U/PE
w/tz
\a)95Qq[
m?\k%
z>mU
sl7<h
,w/n
&e/6
tV_
42*(
-B9)
{s^mO S
$rEH
|V !wQiv
5 q6P
6p%i
,3mI
Z+K> c
V]=Yy
wblw
Hw"@Cp
=Uy^mCQ"
hiBJ
Y7N<0J
B 6
xMr[Z
/gt~
R)|*n<
]XhQ9
_~.9J
:=ni
jaaY
?E L
,{9e
NY N
eA'ePP
AlYhjr
E!z,
\ l-
XT>$
A_N_
RlWo
q.Q
`N?m
K:,/
^?W77?
L=6@
\n!!(
c V
Q9Ly
?t/z{
5g )
K lh
Hk,
i1j
DFFn
ImX<
{T?c
X"K+
FA`7
n;2|E
arYd
Actg
DU Yj
fP7R
d `"
>2pM
!)lz
*fNJ'
J//7
xr)pf
VaTTb
v9~y
~#f9-K
NGE0
(0R)
0*a/ {n
zUAY{
LD*6+I
sjv-~k
=;'!E
aKN-R
hJK
sh=3
z'hBk
;^(+
0g74
GfW-
,
rlx@&]
x#?5*J\
<V'
*|w
Xp &
NH.FL
f<|D8w
INw
7G,
oW_d
c<Ps
SuppressIldasmAttribute
^YgA?
gSW|hn
-nV\
hfN>)j
IOS*
had.
g\N
c`WI
oN:7
t0~M
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
.n:P]
f>"y
,ytN#T
E::goR
CY*"ja4
/eV0J
bqnWA8
i"L)
( bl
" _s
uqn9:
CMv+
+s%_
cEB.
!xgk
+F`\
.q f
1V!B
0_+S'Zg
SA~D
lK 3
Po2X
c ;`
!8T~vz
00PHJH8
x|s>
+{j[o
!}M=w
ypRF-
eT{_v
J<hM
VVr*#
O%!!|
{5|Qo
`Bg-
Settings
Q~f+
.E?@
uuA
kv4F
mSPp
;\% :8k
kSV5n$:
15.6.0.0
H() W
G8PK
14q~Up
yW)D
NBDq
x8]fe
0WZo
=Ym6
=Bw4
h\O$
FyK`cF
!^rd
[A&
'e#m
+{))
vNqI
z/I
ltgu
8adl
x<-
-GW7*
xc/6
KJ{0
~eLR)
<G/;t
IDisposable
o|@\
t(.,'b
C/QI
Synchronized
fd3
Lno
V\A?
A!x2
>}=T8
\ 6/
fc;O
+'.If
X:.T
,<x*
l,/~
2%]!O
^(uF
4jc@
x:cs
t<`=9
t1:~
aIfB
9dlD
}j@rb
iu]4
p8G.
[djB
^$HH
!X!/
bul%
c"l&
P5F[g
AssemblyProductAttribute
$ l+
T w\Uri
:ucxi
t*bGeg
X*DJ
Z= A
!U>)X
vX=V
d!X|k
uh`Et
QRAR
5Ex.
t+:+
K%tX
Pq[\+
B`C`
|dsI|
uc69Yi2
@|ih
^TLJ
PE7`0
151s
5lW f
Maw
[xNZ
)l j
u/w5
r(^-
b)LVf%K{}8|
33h4
$nQaQn\
DV:
8X@wD
vCqLf
~w-C+
P'MM
aJ :
E"'C
!iz6
Np(W
bh+]}
"kIPh
|K 0
7xW"
hgs^xU_e^
.lOT
6o -S
iS)9'
t%E%
xm Qwu.G
&fE@
`MM>
Y*`<
SizeF
C8Qq
"yY=
xwRKA
% 6x
!7 (
get_Evidence
aviy
S/(D
op24
m7hl
N.}"z|
h{X\
/2l3
;a%~
m| R
\xGs
9=kt
W Bi%
2^QR
bWNAZ@
$E9La!~+d
'Tqku
jK:>
w~w
E ;y
~"Zh
DeflateStream
cMA^
)z?.
-RFK
EzK^
^%1B\+
_W0&
pMR
2 V
-MsK
^8_]
wu{ _
W7?H
_b`*
U5|B
!< ;{
6MN0
ny\=
$f=m
*CY73
a ~
/,1,B!
tfoDf
0$BX
}3XN
oa;q
k`n*
eN-d
P)L;
KR~-B
g43D
u,W|My
q5++
.)4D
Yj.l
5(bH
<ta}
ICustomAttributeProvider
J5{7
l}bz
+)pU
[r$1b
w Xg
b'W_
/$oQ
`oo(
EJrRP
hVQy
;qa
Ae_l
[eZ'
f}Xn
`FR\
t4o5.
g 9m
m[C>
u{[l
oQKg*
\i/m(
Qzq>
|j ugX
%VHf
>7`z$+{
In=O
-`]zR
UYNc
;DU
RK@2j]
{50'
Q+6f
r~!ig
PUxn
[Td
s&Wg
f/ A
[LmF
"d=,q
/fuA
3x^
,!b
uxh3
J$`*
PG!7Qu
bvFc
* C~
U7lwnx
9-jZB
F]3@
(T"N
XJOf
E4c
2],+\
.pXPE
EventHandler
28/ 5
,>M.
{)q+
: Vo
v&G.
F%=
*Bz'
L=//T\9sn;{*
cnF1
System.ComponentModel
Y9AN
=`]s
B:Z]
Z:P<
Ieo.
{i;
epF
f.xY
}see
SCmF
<!-ZJ2
Wm]<0B
E&_H
RpA^
Y@ Z
S= d#
r.mX>|
Cr2EU=`
y!K9
=1|~
:r h
h= Q
\s9?3
Rb<0+
U@@Z
{7- g9
d//L
TLv
ZWsP
n:|}
rYWU
oU9(
S'V"
"pIa
W1" VI
. 03s#
N,EU
Hwj1
?7Mj
t,4
B& L
,))]
}AM_
ROQ3
fMIQx
u.C/
048Y6
:^!
*7gP
Q {2
?$]^J
ZKkTI
h$4c)
=P/c
knuJ
;Z,&
2@k2gbr5
K{ &
-5ML
:oBODW
2,f!]
JtkO
/}z
=@C{
tVmY
:,!Za}
m&h3s
j-TL
Ozhbi
Y]L`eqC
?y[`
M~k(
snY ZM
r}z%
}c&t:
%3a
~HbS
I,K?S
CS-x
$Ko\
?]RE
<,Dx
l7~+
ToArray
T_P9n
F?1x
xhU
%?Jo&
!E;=
2C(+t
u+?I
mC)g{
&;sU
:CFm
<I1}
r`we@1:
#%T9
="ii
+U$;l
E>cf
+#2w@
kU#,
8V(N
xt9w
v9an
gg"C
S~fa
[ tT_(
KLf
:BST5
zYTS
yH|-
\1,J
c+t>
&\ B%e
yc Gx{g
vJ:jX\
d27k
M}'{gb
VV<G
)&Cl
s0>44xM
w(RK
g`Hx
)cot
;'#Qp
RUH$
QBn]T>
3aEX
_X3,
&R(u
D|My
E: 1H
T[+q
C@(Q,
_%xA>r
M}%FYr
+L6%r
2*J
Read
! EQsy
sB7
~u2S
0iW%Ch
93W<vKX
h~}r<
1ql\
=/(J>gu
x+=P
%C$o
v +O
L kT| s
Kv}}
I$.h
Q`V*h
'v\?sPE
& q
qXR*
+q*t
LXU8
KIdUf
<JG=BA
xF!2<g U
6 3;~U
w,2~,
P t.al5y
'5AL?
j$ gT
yl{"V
MUDIdk\
3r\E]
yy+<
5.Yne
JM#x
>Aek
System.Windows.Forms
\}L7
;AAO
hmg3
LEpe-
O5,&wuP
*D.i^V
sVc p
#J)E
/)bl
,3}I
nc]0
zicg
.ZCU
to4
A$3<
<%|DRv
Vle
SPo ?
D4'N
Bt<h
u[L4}`Z
B qn
Ok1t
System.Drawing.Bitmap
l+Z]
Xy1
%qfo
W4Zo
]hf6
{f('
!1hX
?QgK
?fPv
"[al
)eS4
,0#t
#5 !
`(bw
CG"m
jA#j'
Z)@&]
{op`
StringBuilder
<2&"
cpO^pi
GeneratedCodeAttribute
1El1
}o<X
,o8 bj/
'Z)q@gS
I>c&
c`q3
9~UN [
y e!
22D_qSV
'=}
9~4u
Q!Pg
,sDwC
,|sA
wLvQ7.a
Z3Oz
7A['s]V
N1C
*s[Vy
#Bo0Q
A}|I
= 8Y*W
+1 2
-mw=
,_^
N_RE
[ujp
ST=C
2018
7PH4eO
Ub~m
PLAt
%%C#
tf4
RsMp
wtx;>
jCFa
P*Nr
Ub~k
{cDD
e*xZ
<{.0
v./?Dho
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02b_64 Seven02b_64 VirtualBox 2018-03-26 22:22:01 2018-03-26 22:24:50 169

7 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02b_64 Seven02b_64 VirtualBox 2018-03-26 22:22:01 2018-03-26 22:24:50 169

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\nmobite.exe.config
C:\Users\Seven01\AppData\Local\Temp\nmobite.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\nmobite.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\nmobite.config
C:\Users\Seven01\AppData\Local\Temp\nmobite.INI
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1\System.Core.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.INI
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\nmobite.exe:Zone.Identifier
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\nfgxjkx.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\nfgxjkx.resources\nfgxjkx.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\nfgxjkx.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\nfgxjkx.resources\nfgxjkx.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\nfgxjkx.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\nfgxjkx.resources\nfgxjkx.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\nfgxjkx.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\nfgxjkx.resources\nfgxjkx.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.default
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.default
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.default
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2336.32446671
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.new
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Microsoft
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2336.32446671
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2336.32446734

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\nmobite.exe.config
C:\Users\Seven01\AppData\Local\Temp\nmobite.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1\System.Core.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll

Write Files

C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2336.32446671
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.new
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2336.32446671
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch

Delete Files

C:\Users\Seven01\AppData\Local\Temp\nmobite.exe:Zone.Identifier
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2336.32446671
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2336.32446671
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2336.32446734

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmobite.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\340ad3ae\7635a96e
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_CURRENT_USER\EUDC\1252
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.3.5.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Core,3.5.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\640c6bc6\426df369
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|nmobite.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|nmobite.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|nmobite.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\640c6bc6\946ebcf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet\MediaPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet\MediaPermission\Xml
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet\WebBrowserPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet\WebBrowserPermission\Xml
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet\MediaPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet\MediaPermission\Xml
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet\WebBrowserPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet\WebBrowserPermission\Xml
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Namespaces
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_CURRENT_USER\
HKEY_CURRENT_USER\(Default)
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\nmobite.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\AC4D5F12
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Core,3.5.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet\MediaPermission\Xml
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet\WebBrowserPermission\Xml
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet\MediaPermission\Xml
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet\WebBrowserPermission\Xml
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_CURRENT_USER\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\AC4D5F12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

HKEY_CURRENT_USER\(Default)

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
kernel32.dll.QueryActCtxW
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
uxtheme.dll.IsAppThemed
kernel32.dll.CreateActCtxA
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
user32.dll.RegisterWindowMessageW
user32.dll.GetSystemMetrics
user32.dll.AdjustWindowRectEx
kernel32.dll.GetCurrentProcess
kernel32.dll.GetCurrentThread
kernel32.dll.DuplicateHandle
kernel32.dll.GetCurrentThreadId
kernel32.dll.GetCurrentActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
kernel32.dll.GetModuleHandleW
kernel32.dll.GetProcAddress
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
kernel32.dll.GetUserDefaultUILanguage
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
kernel32.dll.DeactivateActCtx
gdi32.dll.CreateCompatibleDC
kernel32.dll.GetSystemDefaultLCID
gdi32.dll.GetObjectW
user32.dll.GetDC
kernel32.dll.GetCurrentProcessId
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
mscoreei.dll.LoadLibraryShim
gdiplus.dll.GdiplusStartup
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipCreateFontFromLogfontW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryInfoKeyA
kernel32.dll.RegCloseKey
kernel32.dll.RegCreateKeyExW
kernel32.dll.RegQueryValueExW
kernel32.dll.RegEnumValueW
kernel32.dll.RegQueryInfoKeyW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
gdiplus.dll.GdipGetFontUnit
gdiplus.dll.GdipGetFontSize
gdiplus.dll.GdipGetFontStyle
gdiplus.dll.GdipGetFamily
user32.dll.ReleaseDC
gdiplus.dll.GdipCreateFromHDC
gdiplus.dll.GdipGetDpiY
gdiplus.dll.GdipGetFontHeight
gdiplus.dll.GdipGetEmHeight
gdiplus.dll.GdipGetLineSpacing
gdiplus.dll.GdipDeleteGraphics
gdiplus.dll.GdipCreateFont
gdiplus.dll.GdipDeleteFont
gdiplus.dll.GdipGetLogFontW
mscoree.dll.ND_WU1
mscoreei.dll.ND_WU1
gdi32.dll.CreateFontIndirectW
gdi32.dll.SelectObject
gdi32.dll.GetTextMetricsW
gdi32.dll.GetTextExtentPoint32W
gdi32.dll.DeleteDC
dwmapi.dll.DwmIsCompositionEnabled
user32.dll.SetWindowTextW
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
user32.dll.GetClassInfoW
kernel32.dll.GetStartupInfoW
gdi32.dll.GetDeviceCaps
user32.dll.CreateIconFromResourceEx
user32.dll.SendMessageW
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
user32.dll.GetSystemMenu
user32.dll.GetWindowPlacement
user32.dll.EnableMenuItem
user32.dll.GetWindowTextLengthW
user32.dll.GetWindowTextW
user32.dll.SetWindowPos
user32.dll.RedrawWindow
user32.dll.ShowWindow
advapi32.dll.CryptAcquireContextW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGetProvParam
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
advapi32.dll.CryptContextAddRef
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptContextAddRef
advapi32.dll.CryptDuplicateKey
cryptsp.dll.CryptDuplicateKey
advapi32.dll.CryptSetKeyParam
cryptsp.dll.CryptSetKeyParam
advapi32.dll.CryptDecrypt
cryptsp.dll.CryptDecrypt
cryptsp.dll.CryptDestroyKey
cryptsp.dll.CryptReleaseContext
kernel32.dll.DeleteFileW
kernel32.dll.CloseHandle
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
culture.dll.ConvertLangIdToCultureName
gdiplus.dll.GdipLoadImageFromStream
windowscodecs.dll.DllGetClassObject
kernel32.dll.WerRegisterMemoryBlock
gdiplus.dll.GdipImageForceValidation
gdiplus.dll.GdipGetImageType
gdiplus.dll.GdipGetImageRawFormat
gdiplus.dll.GdipGetImageWidth
gdiplus.dll.GdipGetImageHeight
gdiplus.dll.GdipGetImageEncodersSize
kernel32.dll.LocalAlloc
gdiplus.dll.GdipGetImageEncoders
kernel32.dll.RtlMoveMemory
kernel32.dll.LocalFree
gdiplus.dll.GdipSaveImageToStream
oleaut32.dll.#8
oleaut32.dll.#9
oleaut32.dll.#10
gdiplus.dll.GdipCreateBitmapFromStream
gdiplus.dll.GdipBitmapLockBits
gdiplus.dll.GdipBitmapUnlockBits
kernel32.dll.SwitchToThread
gdiplus.dll.GdipDisposeImage
bcrypt.dll.BCryptGetFipsAlgorithmMode
cryptsp.dll.CryptEncrypt
kernel32.dll.GlobalMemoryStatusEx
advapi32.dll.RegSetValueExW
kernel32.dll.CreateProcessW
ntdll.dll.NtAlertResumeThread
ntdll.dll.NtGetContextThread
ntdll.dll.NtReadVirtualMemory
ntdll.dll.NtSetContextThread
ntdll.dll.NtWriteVirtualMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.VirtualFreeEx
kernel32.dll.VirtualProtectEx
kernel32.dll.Wow64GetThreadContext
kernel32.dll.Wow64SetThreadContext
ntdll.dll.ZwUnmapViewOfSection
user32.dll.DestroyIcon
user32.dll.DestroyWindow
user32.dll.PostThreadMessageW
ole32.dll.OleInitialize
ole32.dll.CoRegisterMessageFilter
user32.dll.PeekMessageW
user32.dll.GetMessageA
user32.dll.EnumThreadWindows
user32.dll.IsWindowVisible
ole32.dll.OleUninitialize
ole32.dll.CoWaitForMultipleHandles
user32.dll.SetClassLongW
user32.dll.PostMessageW
user32.dll.UnregisterClassW
kernel32.dll.DeleteAtom
user32.dll.IsWindow
gdi32.dll.DeleteObject
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
advapi32.dll.EventUnregister

Execute Commands

"C:\Users\Seven01\AppData\Local\Temp\nmobite.exe"

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-03-26 22:24:19

Detected family: #Ispy

TheSystem Itself @ 2018-03-26 22:36:02