File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 644.50 KB (659968 bytes) |
Compile time: | 2018-06-24 20:50:36 |
MD5: | a11eab85e85936ac7fd6dfb004580099 |
SHA1: | 965c21cd7b5dd5fb906fb284bc688785f4b978c2 |
SHA256: | 1a5b43b03324df490941a5527531e39c876dae332be08578a015b8cec6aaef13 |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2018-06-25 08:48:11 |
Last submission: | 2018-06-25 08:48:11 |
Filename detected: |
- SERVER1.exe (1) |
URL file hosting |
---|
hXXp://operationships.com/wp-content/themes/twentyfourteen/car/SERVER1.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-06-25 06:06:03 | [33/67] | ![]() |
PE Sections 3 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x9fc04 | 654848 | 32875df8b0683bd3f5ee829263897e62 | cfa26b8f2fbd9c5f7f6f33f61d118630646d900a |
.rsrc | 0xa2000 | 0x1000 | 4096 | c8718dc38f5fb2c97a394a34e5af0ffb | d42734c2d9096b9b0108dfb806cd46528a79c234 |
.reloc | 0xa4000 | 0xc | 512 | 24078ea948599735e9cc2f1e67f2606e | 59183d70336d2f0fcdda476d18113a22024a1a6f |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_VERSION | 0xa2058 | 580 | LANG_NEUTRAL | SUBLANG_NEUTRAL |
- API Alert
- Anti Debug
Meta Info | |
---|---|
LegalCopyright: | |
Assembly Version: | 0.0.0.0 |
InternalName: | SERVER1.exe |
FileVersion: | 0.0.0.0 |
FileDescription: | |
Translation: | 0x0000 0x04b0 |
OriginalFilename: | SERVER1.exe |
ProductVersion: | 0.0.0.0 |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
No IP detected |
URL(s) | |
---|---|
No URL found |
12BTNMH5jx9RinQg1KuOgXm5RmqSADpiAxDz16M
pwHlqHvbO5tQKSIJVSRfp3bOB5wmoisp2JUK3
)Oqt
nXhZcOIf3JwTw25E6JcxO8lKlSV
StringFileInfo
6ud4V1mxt3r09Re2NNlHYE
ejVGxJkPY4wKnIIkixTkjjgaFfZbmKhLJLaaYsj
ZBY8EG3xvWaacynlzYtb7xsrtLIofJEGRg1J6W
O8O9z6YdHaLq8C68LFW5d3E
20oTptVes3poz4I02NcbV8u83HUxHMp
OVwqpVLYVvk5NIxCaVgCBNed0Lf9OMseLkR
SZKP6RnRkokJtjOsUAb1r62
OriginalFilename
sgdIt76cVNDRgkuAIIrDS8MWkLDwHP0moDP1rG
8Y4HTlab3V6cZsLTTsY5bbQmnM33MkHspeVIEnl
YKdWZ0AX1gWRmXoNCNWwme
c1BkSdap8VYAIKxzX0lPPqMnR
aomLjl5sSOwfjlY7m3VyB8h6wicA4mnJ1g
FileVersion
InternalName
FxTIeEPw8dXl8bx6sSH3YuXuH9ZJuELvFBWeEV
x3nTVoywkn3CMFBlCQd9bEQJWFsEHem4bX
FileDescription
wt408mSRezfcNmF7XjFuT
Assembly Version
0xTetk09Sv93jS0FklkmX66
roBmEOfYVbTPGDKVrZIRhp
MMqmoyPXuhsH55fdfk9XXNaQPYa
2Oguw96w4XKym3H03M5Jz3jipsCBRHhDuB
0.0.0.0
VS_VERSION_INFO
6a2qsXluHSJBrAt9LPYzyH2ASQBvvcKkljEX7W
UTnGs5kTnErneIBFkZgINCFzzS5Ez5uHFVeEzY
892QmHUZELP3wHOxfmChcx5Hd7dxDLg
5Kn04XfgaLyy3eYGjJ9cLwxMlHlf
RTZEqGqCkbrBLsfVt0bbTPHfVMT
4XpSTOEvcYw0j3cKzUC9d3n9Qjs01lRngquQ
Translation
p7xjsaxveia803KbtCAVyubM8WHrmy8HU
XpJJJRl3uTEDKl9RPbKVUvactcqG7BXVU
0ksqFEy04bPdNkNNzKwoEsIYA15Mdy685RN
u60goOgZtfSBUJ4KRhjz0UmtE
Cz78oIgqy0icWOv0TNOiahqInhJuZpC
XReqtA4SH99ZoaDAUoEYxvVhTLQPUx9xIxmMr
evoPP230OgB5a6Q22lXlexGOsfOXDm7
92GdbIQf8D14ibtD3Ld7dW1K03
LegalCopyright
0oDEqTMc80S7iN5t1QlHbePZlXTk7LpTE8rPX
byrFJl6SS6u4DJctCwijpn8xScRG5lYHz04H
aWKKF2mh7qU6q1O8EiAaZhVf
pzXjEYKNjzZny2ddVfaKFZeQqTYiOw7vRFkofv
dInhaTgbJYrDTQIN3hGnouMbuKyKFu2oBkiA07
aeu2x3ITiTv7SrGOtuAWdg7uFqCl
000004b0
sRX9veKqQB2spWzX8B75hpZLLAnvxpgpj
4ZNV3SfeSAzvQKXuR1qnMrcGs22B
sBw5fY77DiWozWp8rSwcpsfvSTrjDDhV5L4YXt9
VITFSQSkxRK29ZuvSCfGJBzMYjrp
op9oEWNNmAXil6U93BeG8
SERVER1.exe
27tFYIQVXfayzJMYAkcEknhGtdfWEd
6z9gxohd5cUOKbZ6xc4bur6d
sVlVU56hrVA6W7SIJJ5wqbOi0gGWcJaasLVEo7
NCCHGMyYQhFXzWDpxejqqMa5xK3b
dp0n3HoDYCHrusq4KNf3eeGSw
VarFileInfo
yjHfLm3wjkWGpSkAiSRhwFQZzQ
OgEqBc6OFgfm5MWcADAKJ7FedW9S0c6
w03l4e1l0aYSzPAAyZkGmjISuXsR
aTCtwa0Mpd0rcinsqfjKb9We
6HvMrpuMrekgljP4UIZTmMzsxBb3WPIVCkSOo
YxenBhNm4RQsexBGthNQGir
WeBpXLV0yQsnzzMqAGyLJK
s2cdRe7D2LzBGT9GxX6v1ELro61cg99bt5
xb42GFL6De1d8q9UVJ2PZD95QD0apSwLQjj
aobRJQbkgN3RDYvlArbKEK
gsGDeVcZSk3xGWm7vjJmHMg9W
QmfL7m0O7cMI7JnzaWn0LpltUsSb3LLY
F7hQY5Owz0VKPnly476y3
DzMVquD7cKbkjn14Bfs5kjT4bDmC
kNwsoVkPbPzK8RnxTBIJYr
PHLOneXkgUxJ4XKCeSqus
amPBUby2tqgtRHsjFrxj8qAhhop4
ProductVersion
(<ju
*o,]
aPspL5
z:1b
m9B3
ES_)
W~J{
dAiA
{#^/
z69C
NcREQv2RVH
qu{
S;B`
g\{4p
yOPw
tc v
Aqx!
R>AVb
BSDG
Z:}_
8 H?
}OEzI
=$/{
;mhF
4` ;
.2 n
6VBOg
=c;G}
mP*A.
1g5l
y@u>kq\
Bv N
=o,u
UnverifiableCodeAttribute
IeHs
z%k>
y8rix
)e7*
\.NN
`j"
N;:,
"kM
qkUI
0xPp%
6X.>
*K^;
f]=[
:*n(
k E
UGCU
K.=}3k
8\G1{
|Sc#
p#]
1$H6
5a9z
u9%DI
ux L
?bO2
|sb*
w82z
:i
Dh})
liX|
XW6b
RC W
&q<k
Py(n
VEN
nZZ;]H
,.(1<q2
}u'jL
/r.0M
?q>\
*@"
4q5J>
}[l=7+
8@Y<
DlxqJ
X Z
{OmXz
;gh}
u["n
W=R'
/W)OXU
C<Y.
t d
Ph{W
n PJ
C:6J
k[v"
\VVf
eR'
'X"Vu
l5E 6P
V366
UJ]'
Y_by
@UvM
TZk
z/7IO
:&"\
v J
iB&Z
Rtw
`m~ 8
'DlG
6AhR
1tjZ
6e+
jFb3O
mF+#D
|S+O
ly{6
.3A.i
fl='.
4f4(
]qTjh
@Dg,
I(A 0
{- c
J)&c
]A|W-
System.Security
5]e
X|^:
>0a5h
(U 8&
CsXn
*!;}
8,p=
[Z3"
/Jh"
.pM-}m(
jB %|
NCQMR{
<|#
{lq
/>a
RF6:>
e3Uj
Vy|`
XT;
7 ?A
COH<
p,chu
n)IPj
GDI
vS2>ar
G '\4q
'jQ'
^_lEh&^7
*f/~
$rGK
8Cc3
m: j
+I>l
x473
3;O_
10^Yj
)BKhm
p,QAy
eH[qN
LUW5
&%O|v
Msq#
/noKS_il
lx{)K
z]iW
S9Gfh#<I
XN=h
QcK<
C X!
zp
Ws]
0Cy6"
a #$
'} j
6(}_y
m)n>lm
B&y,
?rM
g_t
teF7
)hv_
}HpJ
57PD
? F6
{23f
H#zq I
o-lc
d'#`
E:y^
;[)o
5K@X.
2 g{W
nO{wIh
8&:Z
pyNAq8
uT
c*R
4>i-
/'[}Af
)l-p
+qsbG
G#r!
lM1P
U R-
WNGR
l(y
R%t?@B
giRr
\zFF
2{>R9f
[%6
^Hvp
nAUm
n_$e
6;_M,
7.~"
n3.K
AhI
vTx
X v7G
?2V=
RP`?
[{[}}
VmJ
iw3t
Z9p]B
5"9
S*jR
*d|wV
Wiht8|?
4hzA
l&2lL
5}TK)>
zsso
2Zc F
^+z9R
i?AoI
GyF
1l;o
S*U|5
qDSi/l
k4$Nb
Db&[
]S4
-ecZ
_WE<
m^W=
jq!P
-B$v
'@k/
VR4q
s6'D
_#0
JR t|
H _e
uE0?O
~H4/
DtzB
q__~
AT R
)7'AN
@)[p
"*aLW
.text
Q,kmW
B \2'Z
KWP9
*^w,
{'VS:
iJs>/
kLi i
-z+[aQ
i c@;
L{
,8wJ
Zdh~
<O1V
zGBp
Ih_7
;e H
&nU7
uxyQ
\xy
;;`B
UWCis
rX?{
0z>$i
S$q4
SV%y
D.Cb
JsI<
.AOY
Um<z&
;Ter
.}h
U*(k
JqYP
sUZ
892QmHUZELP3wHOxfmChcx5Hd7dxDLg
H}WV
V<=
(B-g
@m"6
"IC{p
aWKKF2mh7qU6q1O8EiAaZhVf
DV9u
YJ;w
L&s
$S^u
=%|
~k`N
Ef$?
@E9r]
xvn-]
OyQ/
&%ZYBA
u*eSG
|z-'
vSYl$
CU^"
KsS%q
CreateDecryptor
3#5\
'%rN
gU0`
o|8kl
StO"Q
nn,GN
shiQQ
l=A
:GO4
nmU
jOI
ztW5
$e7
0%yJ
rdwZ
uFyk
|$T(
K`H
mnm>Wj
B<Y(
YEmB
{p_D
>l|Fd
S9ZR
L(uS
Z]?K
h% o
yZv
yG"_
Sq7fu
+Vn}
a]CY*
X% n
FD'?q
u.%b
S}/h
Q[O .*r
)kQ+
}` R
1?0J
FIxh
"LHlw
l}N
X .J
[.9.
I\:n
'HVo
>\EvV&
"tX={Y
(?-4|L
U{]D
]>=b!
$_rp
n
AOqA
#2E<
]Oib
ZLI.
D'={
D$F*
kx+5Q>8
sv5p
1\9B"c|
dK]i}I
9 _
#%tI
YxenBhNm4RQsexBGthNQGir
H\-
Y,jf
0p}S
_j|
rj}q1
nok37
s{U% (
+5,B
(hBK
YGN
w mf
; .O
/riH
`U)^S
get_Assembly
K28.
u?JW
uUC=
honj
7 lI
R*4
W6Bm
'4tX
r56F
.$P(*) ?
<_Lg
sUbQ
_ryQ
E&pi
1FK
P*R
E76
2C,yX
JaAR
Nl? VJ
SCB20V
2jq)]
6 {pr
SE#2
q_<x
Cy;P
+Jpv
V)bz?
V?$r#
~s&:
V0pQ$yA{Nj%"H
dgL
nFw!W
_[6G
dmZS
><D
_ThZ
}+]s
GA'x
V~tE?&
%oSN
qm*g6
_,5A
QoK`
95W@1
4%2
\w"b
F8SK
<Cw:"wMUY
s7
} S+
,q6#}W
9&j,
]%gm
Zy?)
F>@l
j4uc
5Oggyt
ns_qs
C>,k
nE+#
'P0#
|"e
$EF9 V'
?{p/]
ui%~
L1mu
u;h!J
d=3I
_3"2
YY !
=}TH
k5U>:l
r;7
P&(Z
TQd/6
2SZOfn7K!
`)7[
V5Na
9@x@n
}93P:,
1 %k
of>V
,Oq@
Yg[n
ks?_
%-,|A
39_~
op_LessThan
0Zr"
3~Qf
T7LS
;W^S
-sFzW2
:'
?/g-
MethodBase
+]_)6
mt`B
R:K3
$9lA
0l+X
}\6c
/oA6
)f!S_
#_`M/
IPJXc
?7w.
UD.k0j
U dN
/bC1
5y2`
23xp
NvT
bF6v
h1Rl
8 I
Pz#
&kYK
J}]d
i[Q`A
404K-8
Dv[ZA
t ng
\{U3
ru7
KDO>
4 1 }&
Q &^+
ODMO
duee
e&.x]
zD]\
2lOT
!<6
F}c{
56T>
tp&
~npO>
b2$M
Hq&$^
wdUQ;
aG5A
+Pf
POpp
|a([
AUTzv
Zi+Tqf>
5SA )
3)<d
*y't
si/H
BMhUEL
-6AA
ezHZ
eAU(a4d
r6C'
^Xt-
OYw2
/*wG
=dUr-
7ftv
NId
4]0
kx`6 J
* 6h8
?_D:
<;]-ud
YBhX3&[@!
.sXq
j7:
81aT
DXD se5
jW'b
sc
8NG
rZt
p. !u
k0G8
_CorExeMain
$9AlC
KH6$
!)~](},
6@/
R550P
nv($O
XxAh
5*qn
,c'P
sN~V
"V4N
0UoV:'
M6_ sU
r{to
{vexR
h6m3I
zw z
;Xg/
J7ox
[k* S
tsDD
j@bM'l
t)'x
:?'aE
eo=*
pZ"n
t4iW
e[E,
l'
=RPs`w
}f`
E(q;
O#;6;b
Yql$X
!8'Y
>|ge(
Nuw2
W?oK
=i7v7e
X'.$L
5XE&
rd.
l/t
(".|
\ Y
qB3u
,J&i
~)2O
=B+j
{#O|_+
\jh#|<'Y
tH*z
7Y%W
h@M
RpZxY
rJ<Q7
[xW
cOKaN
~%jl'
dpJE
"mWi@
{x]3
XNL3
*d<"
'1x3y
{{Ue
1=?r"GTM
+\;
ZJ-0*y
Vr,a
6R ^
d)_8
*h'!yxF
#b&bK}WO
>bZf
QW/c
;01I
DQ7DOcN
P(Prs
,ty%
AQef
q)Q&
5T\l
_EI z
yifF
V5[d<
c/}o
#jT|
H%_|='
>]%B
L"]P
8Lr%
'k4N
Wau}H \
A|$L
y)Z
":E
09Sm
dz`q
[Ut;
tP R
0w-S
@@5`
0HRo
^:$.
/3U'
}ZG+
I&D/
u;l:X
N%^
g@~X
sa^NC
q "!?|
T`4.
c<2K
~sH)br
#d JR
bG.1
so5-K
p$!,
$RZ)
5x5+Z*%w
/Y`:$
6u7iny1
< $
xE_t
L=e;
d?h;
-SJD
! /n
:50x
hzrV?
Oh1d$RZ
N-[?]
MP^]
*"R2K
%PM+/3
V[;!
/(wI
Y~wM-
ZTF
%0oDEqTMc80S7iN5t1QlHbePZlXTk7LpTE8rPX
S#(BP
ToArray
%t"j)(Ro
5(R+
+`*P
vllu
XNig
uc%':
*E]:*
&BB]\
@8z+
Dqfj
kx_x
B]Xa_xm
%iCB
[lzGT"
0,\|
;ZeCB*
iaJK
$JB
Nx}o
Rz:b~
MCo[
^{&7I
7YGF
v4bD
$>8G
Vz9xM
JdkEW1
yvD
J\sl
Myp\^
|5g2Y0
VB~s
s|6L
gaf
:0&w
XIe;
hOq`/9
@g k
E|>"
3ETFC
-a24[E
3#l
a7t ,
AWV[9d
^iSy
AH;l
lCS!
T!|~
4 k
Ui%.ho
gktJ
N8vP2
k M&
jtHd
1'~/
F VD
E@g b
B/Af;
QX"Y>
xt"
C*2=
_jt
86#R
bnAp
V=h%
ye8p
f^RE
tLHh
9reH
*iUC[
UT6f\p
QmW)
0sy:
I$A
re^;k6
&!UZ
mT1 '';W
u+O!
EI$x
,xr4
xho)M
i58.3g`
&j);
M}&$!
':ulR
~V4]B
aGgS
Qkt|
#/go7
};B;
'Bb@
( e9
Hhh
5]7D
J~!
fwxq
GvYJ
^FEz/!
o2
(9 /
N WhS
\mqc
Z6-0
Yc ?`
.(#9&
dJ^D
fP6d%D
eow+
S[TD^
Sd)j
QE@w
5l'i
4hkp`
.c]k
8kVG
C<#S
Invoke
r1n:
j}YD
+%O*9
2`'u
.| Gy
$k>@
>F%
tKf$
-*{=
TwP
v_,cL
&&M7
s1Vo
~o!
IiP{
H;&F
Y [
k)G
?T|g
<\<r
r/lo
O^j|
3N
6.e9/M
mpJe3
V;mdw
.?P1
=g
,9>F
]q3+
<SG#
/3{=
J}Ri8
} e
dOW
o9
pVV4*
"&}K
%VE*
= ZB
Cm,[Z:
F$.>
=Kp)
]r,
HkR
PA4D;
ak9W
8{WD]
R2n{>K
9n+P
n40
2rk;$
|5"v<
+AG}
76*v
n<)+
*oC12
g#kj
wR(z
(MKc= c
nUCT7\{
NiA=
^"Pke
t].(
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PAr
'"lR
'sBw5fY77DiWozWp8rSwcpsfvSTrjDDhV5L4YXt9
] Eh
1UDT4
hssJ
Df,o7
Nw7=h
-#*kDV
YF;U
DG2t
pncV0(L
6i@?
#nKU in
rX+=
C{9V
NCCHGMyYQhFXzWDpxejqqMa5xK3b
aBQ6
t_Mm
tl<
tQJ.
Jo$R
P_r
Xc(2'
]w%q
6>N1
n!{j
O|dox
h Ta=,
"o3&T
ww2D
"RR&oj
oFR
NuqS
F,`ggh;3
ff-/
ycFC
1"I)
@@nU>
MOhF
Z@Pa0L
[\.,S
6Q9h(
#(.5
47z9j
`J8/
u %pb
-X{_=9=
2Ja A];
{9) IfV
5Ud!
9c')
B}lt,\
gpX[
MUDqp
Cx8#
{0yM
Z+!SF
~B)-
YKdWZ0AX1gWRmXoNCNWwme
,}W@
3mU"
KBsK
Qkf=
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
"\a\
DPgI
Ue&
C,go.0
xUHi
:X{d$(
:JOu
l2r)
@Cd`
E7r/
ivz
INSl
o\o
|^;>
8Z6;x
rR3FsA/
dsL7
@a!u]
y|m\+
-=T;
z{X
Q%=oDx
T`Y1
H,w%
*$t
&.t@
^jL5
6#O
iHcF
:j1p}
yy`p8y
#alb
8K6gW
5I)
=Iw%
R6,.7
gP|,
d#Yq|/
]\jKo
P qC
n^e1|
x pAw
YAZOP
^k'P|
d.A2/
~]?;
+)2=
rpY^1
*Wn<
WZYz
+19l
+Fb`y
W)%**
t]j@/lT[Z
O,]+/
8TAa
uAhz[:"fj
uxp5:
CrqH1i
Wt>[
o3sW;
m+VaY W
>-Tj
DuP+
jPJ?U!
b/=&
Iwyep8
K$c;
{s<
L|F
,_ ~
>qLs
[-G(:DI
]*C"
fwo`-zL
c6p<
bQ(k
5?Xv
)2_f
?:4*
0.;[
+5C;
eoS~4
3<:}e
e e"
Ns]Z0
_4vEAPP
>cR4
/N_z
hg1}
eMfV8
;64g
=#Jg
N`RF(
uK6
<[ )
"Vhjnl
T53
!u^I
*b|#
paXAfr
/ 9h
q`v 6
Z.ha
zD!'
sY:9S$5
h)AZ7h0
9kbi
kzS+
0)p
WeBpXLV0yQsnzzMqAGyLJK.resources
R_4=
%/;d
a:`Jv
F{U]
Z|"M
l=k^
!oBj
#EC
w)16>
4`8C
WMqZ
Gmil
EG q
r=Iq
b!AL`
}K|*
2s2]
_f k2
2lX%%>)!
>C_p>i
M)YU
06mP
8k$yD[F
li_*p
=mAP
-Kub@^Y
jyUK
~9~Aa|
<lf.
4QC~1w
Iezo
*q,h
9xILa
5^p*
Uq
a/NC
A5o#
YoxC.
N#_P
W;7<
SCYA
<Ux0
8@8"
=C]5
^zIL
]|;&a
Z/o_
>V*
Ic1
(|PJZ
=w.&F
#ki \
-4c!
'bo/
9e ?
lM!=P4v
b.8
G88[
YzkO
xD=F&
L4'*
[UXx~
>e+<f
>h0INW
lkP$!
)}Kp
"~+pf$,
Fc(
8@L
UJzy
"LD=
+2?r
IEz>
N+n
cAc
\Vu|
DF%Q
3qUf
s^$0F
A&}
mscorlib
_@S{
,1Vk
MKv
n F7v
aobRJQbkgN3RDYvlArbKEK
Kl ot
G^["
cQBq
FWp5
`Y82
sx(u
{[/%
.D?~_
,p)A
=> EB
r`xh
Qc1d
O^+Nd
*y=6
6yG-*E
k\m
RE z
Jl]
o+ [
f{/
J!wA
EEQ)g
;"A>K.
~{"R
RuntimeTypeHandle
Dj3
" 2:
/jJ|
i1<-INm
JD'6
mqLD
s)mp< &`+kwz
UXwQ
AZ!4O
S{M0
LZbP[
[v.,+E
] :@
Pz.H
]mtp
#h[l
WSf
@+$Bv
7Vw{
,j3Y
|PyR
HB(J
`1ui
az+V#
'uoDO
ug0"d[
'+ftS
&?z1R>
4AR
+n3]
/)^v
<Df
S,2*v\
:
{2q+
\LNz
(Ha@ /<U
qsH5
tAG
l'{t
47@)r
L?>D
Se:A
f8P?
V15&
eb Ja
tW+Y
0e &
3^D)
c/9c
9Q Bg
p:b>
VU.t
e^ekm
Ln{vM:
/Oqlh
3RTFt
yn`r
8_7_
&sS[
J"mg@
CLOF
Co[h
Ecg<
u6b25N
QllD
xO6U
<@^F
WVf9
8V|>
Kd=U
W^ e
6Y+y
5&al
qM03
Pe&
X'_
Ne<B
]jMf3G
>aR,gU
pA%J
3JpT&
d%]
^uS&T
M: "
a&ge
PW1j
Ui78
NL]!
RxJM
!This program cannot be run in DOS mode. $
d7N6
lgla=
U\.b
B87V
W0\n*6n$}.
k-Gv
Q?VR
3_%p{
(4rD
k6TT
c|*1
\g:cW
[n$B
OWxI
*'3tuFk
iMA+[
B6D'
i)B8
Ot0xw`
,9kHz
uFe
~^XE
joMElD
e+t
5'-cA3D
Uj\W
?BY~
;t~i
to(B
<<e}
'OyR
~PY?
Rn/*BC
Yok1_E
YX'l?Mky
>&d
tN]4S
}h:VK
xI$;
!Mf`8(W
2q*7
p>$y\d4
WtI9
|jFq_
%)co
h}Wq
XEE
;+O"#
&ZBY8EG3xvWaacynlzYtb7xsrtLIofJEGRg1J6W
N\
te@U
uu|V
%m5
U_q
Y[@
,ckt
M>ha-
*pTL
4lnX
5B``3
K(!kp
7 9|
s$NS
OAsr
84a{
Wv_T
XM*g
fqEx@
>),\ e(
9z0[
xM0
^!~x+#
fv!#3
\HlW s$Na
k2?
y[23%
+t*
=-v,|r
j`M'
2-,t
w#Jq
8:%
/<2T
bZ'MgTR
zgUQ
0NZhkU
;?Sm
O'02)
Yl[aA
q4 |
}pkw
MDIo
sc#u`
`wArk
ToqjY|
^^7
bCF#
eaN4P
K*>y
X? c
X\xl
5=$$
9%\
YGZP
[`X
'[&^5H{
h= J
1qu:
h -Zi Js
5q1;
N,9U
ghWAGF
I6d
\{~H
Q/^D
+&Ou
9:z~
=HiZ
$+X9<
9WCchoD{
XV;O
5@uR
kN.%
%LHS
"2Oguw96w4XKym3H03M5Jz3jipsCBRHhDuB
!-v.!
~vp8G
2WmX
`DRf
l(B7
l:m%
z'5)
dw %
)Y9]SP
h +J
* []
(2E-_'
.!\Q
|HvH;'8
<I-|U
set_Key
y?J+
31?w-
zmeO
'67,
y_Q^=
lkL
vq5
SIs^9[f
q#)6 d
#+n%6s
l9KfTGM
5p 7
haHg
'XLEV
rm@W
4pm=
i+!W*
&(sUk$
~w<Z
MethodInfo
:j/O
#@7;
=[_q
N,a{
'+K_
_jZS
X!UG~Cs
CompilationRelaxationsAttribute
i}:L
yN9Jl
fUQ'&a
+(.fLe
~ufL
+s`]
@ MB
!Q]%
Lk`|\i,
Zl&
!;Di
WR~7
WXbP~p
iKE
<x*?
x_h7
4/Ws
nY]6
q F`)^pT
| hR
h{c*[
rz79
-Ekd
6kG{
Rn+
&Tg
)r5z
.0~A,
*3Z7{
40I\
_S %
7ca ~
ga{n&
]wQfN
Bav}
m} "&{
2$uu
~#J`5
c`~1
sm-pL
e?!yA`"U
Wp;
-6Su}
jQ>t
dwqN
vg`g
XGF7
)1osQ
hOH?
38)g
"%<
_|I~vj
gb82E
v/S
mGh%
l{ .
50v
1Km{
DzMVquD7cKbkjn14Bfs5kjT4bDmC
jYTC
|&Sl_
7B.~
h&i1
LsmR
is2(s
I,FV@
""F`
*Ja,h
X7j
A@
oR%e
-@ S
(q:j
r)2y
rUL_
-#0E
}dA~\
Au"A
9O)TsY^
5b!#
nme
?'qa=
D=r
9_F;
VhqB#g9
nv[7
:_"h
/ePmq
Dv99t
N>HW
'@c!
;y1m
V1xt
mJC|
6AtF
mn+IS{h
SUDS
0f!
|B X$
>ogve{c7`
,i B
mrST
4?" v
`NP>
Ct.y
nta"
Z'&3 ;p
^7SC
%|JucY
/VYfA
`kmE'
1zKR
f}7?W
(h|h
9 04
AZCK[EC|
ps
[LJK
JYf~
pZ\g
+To,y
\FbQP
?cC|
=? %
nkR@
Us]P
b/xm
HVZJNG
:y\QH
nh>}l
G<aAo
gK^MZ:d
{sJu
|!\5
l: k1
KmiyU+9
^S8_
d,yW
`C7D z
t4:y
o-jV!
q,z,
yWo[1xf
w7)[W
8hXI
mLr]
z}L!iE8
v qL#
eBgD{
:oC2@
v\($
WA/7
_0J
:Zk|
\f6'
!CLa
S,#4
". =
tj]]Tr
xA~fq7
Lgn8
>cK>
@Ldx
Jt}p
b{qI
1@Z4U
'2&W
+rH.T~3
Ya B
4Ow]8
z;ib|
2l*!
;(%?
2{&I*
cT)k
Lb5Ec
z,zR^@{;CF
/3O]
MD)%e
a~q$
Bk`'
o]_G~8
22q3
Bf\ hR
0GS N2p
Uo 7bW
~=8h
QPbU
]&p_
G-IX
:O79
2KR
5t#a
n5Fs
dA~
[t- /.]$
B {G
D4i#
^Gn[p
tZuPL
t 5$B
bvM,Z|,'`
pu8h+
Pra
$f'#vu
>%
.Lmy
_~5>
6%rbD
seuHt
>B}`
y` !`Z
k- ~
zo.3:W
97Rp
$;oW
fy::
ns -
Rnp!P^H
ayT#6
"eb6 H
T<,
bU V
YQm,p
0 P {
$Wj*
u) ZQ
Wb~
c_G"
KvOV
pXkR
|5-Z
}z[%
FIPxb
|TT}
y*;
u^{
_L2c
nqlxb
mI,9
eHu7
DvIO
{&tj
ae_
CXkM
F?4T
v6^u
w|ZHBR
tohD
7 >5
*5?I
P5DC;
*@ {
: -
&|p 3b
Vhk
( _x
( _~
3oU`
c`QY
O,a^&h
2@=0
ZJ j3
4? y
!439
S9*'
?r C9
.v3p
NfS7Q
}v;Ct
TW~rT&
~3z)
tka,
u}zm
+fUZ
<kJT
N3SM
~M5p
)IX
cnJM
qLm
jdG
V#iL
egT6*
DtjZ
+fd~
;C@$
r,bHb
+VI"r
IIB
p;H6
5N\Lm
b <2
0(ocU
IrNf
.<MH
BSXJ|
;/LyR(
*3x
op9oEWNNmAXil6U93BeG8
x X"
'Bi
P1 \5
'U B
w'vL;
m,6F
9>
r m_
Gt),
/R4E
cK=)
@=[>
)QWx
1FvH
Y4F;
?_4G
QX4B/Nv
bxy ?
}aNx.t
;Kf`W$
>mH
/S}yK`
98= d
5I&icu
e2Gu
tZ{gohz_
2}" }Y
2s{+Nn
ics>
O 4p
4t.?
tD.d
"i;S
Eam7
1S&Qw
[W q
w|E-:
P5|p
Vsfk
S0ws
2^Sd1
en}yk\
4~q<
.LU/
0hm
pT'G
3(UR
` Tue
id;|
hQw-
,%3:
}>a^Z
49M
Jfc6
q<QD
e\+w
[:7 Z*
LWvV
jSN-
.m5w
=Rq
?qS~z{
=b?N
vX5Lo{sp
tbs
[ !r
xHR
q$CT
n y
5Bb |-
< d}p)`fd
J^t4Ts4
oK#ZG
oPn1
[$}
o:3n
=~p1
SX~gC
g")A
JDVI
iZ18
co?~c
d%(^
,brP
99[U
Wr~Rc
DaDR_r
'(.>%
[,2i
@MX]
OK2#
|x0yo*3
$pN%/
Fkp~;
)b9L
9}G
v]l@
$PHH
[7QE8
ln"*3g
-P^n
E!e4
z&+J)`;i
tr/`hroE
AV.0
3 @N
[' ]
LSBg
}fme
c:l5
k&"T[
?)&x
#ji:=:V
oG_=
3Be#
V#1N
Vv'K
sXY
]'w+W
@7h8R
ho,#
*lLLw
lH[.
.3Vi
&eW]
kFcEIel1f'
Dhd}
a!Az
%r,M_
u$FQ
f 2?%
J2kq
+Y:h
5`9}
;$|N
mCNF
@_g,
Ijwa
6'*3
#pjR5(
m,G,
VN{|
#4w8&
sc>[/_&+
f(70Q/
mr*1
set_IV
.NtC
-p{D.
c*VtN09
K!Xx
CI-4IC
^@cq}`
88v\6-
vFb)B
l `j[
+#js
jg>5c
E2BG
_**B
XF Y
EH}7P
n/ju
-,_Z
Kp0[E
ps(.H
%<0,ue
QT^Sl,
<T+j#ai
O`Q8
?s"a
z^~,
3G
IBQl
e"~?7
gB7.f8
Wz*8
mUu0
pycY
]) '
zt6g
hS>b
k,&y
t8e>
c/eE
aq.f
@2sP0
,CpX
n w3Jo
h+{9
sUk
Qp-t
eZ${
4_Jn
8U:4
`2m 7
mq-J
O,`J
(4~#
` er
zf _
Xhio
J%oO'$f
?q(.b
;2F*
f7?R
$1*4
pz"%MV
qCpi
8Dl
x o *vX`
u}/D
RmE2r
$Q:+>
-RUY
zF\M
? #@\u
^#If
6mXaQ
B,"j
e^E}
w_X =
l7I
#Rh
!G}BP
m z !
#W0
([6@g\
uD{zqz
&!;L
D_'J
qjCi
r19;
K0yG
V[33
_Mz(AM
iX2p
igV
}e;Z
'W(B
YT Y
%@Jb
,4(R
mnXsvmb
YKVgk
OxD1
n_3e
$q>~
xr%)
8HSa|A#:
ms*
S+e
]i49
PV\Zv
gKa
i\}}
inX,-
< 9V
=0:
c6%NC
^wa`
`hFd
s)./
Jt\!
w5*(
g#NZ
NC5}
D&!M
{0>k
Fn6^
uf2Q
K/x
YR
Lzf(x`
&-Je
?E-.
G.e^
se`|!{
dwV#
Dj{,
(0Ro
.m}IFo
to9)J
~uCu
kNwsoVkPbPzK8RnxTBIJYr
x\ayR.
z0S I_'doW
#K\f
g,v}
hf:w
\,~N"A
.<S
kr2e
8lCK
j2EB
Tq:a
'EcNC
v~7z5
-:Ihc
IrL<
l 0dAb
>O1o
Iq%J7
!w<iY
V h#
~/L}E
Lm&<6
bZ_%G
;| $9
6}7J>><
o*^q
An*5
\VhQ#
B5Q&
9k%P
Ded9W
#u=9
Y ;<
*%\r
~^v\
1W
| lZ
CIjg
q*(Q W
O1|c
1z9/
Ats4
Nqs5K
G$=.m8
6GnJ`
W ON
SuyV
vMk1
.pKa
`Zx
F^ra"
o o9
#WA%`RB
u.e,q
EiR+'
6rp|b
5/e
15mE;
be19
[0+,Y
bIEF^
RAr0T
(N4T
+^_U
}uf
^; V
a8lm
eN-
>IFj
@em
1HDr
HYX-
[4p
#GUID
&UTnGs5kTnErneIBFkZgINCFzzS5Ez5uHFVeEzY
E&Q_'
<u`!
g HP
Uyv'
R0o#
Z4`=
VZ~q(
^$^p
@*A->L
[M&0
ZBn~
)aH0
`\#(
M|J S
Mseb
_0'
5_<_
!str
[h|]r
2hyJ
J5mI
*_iT
yk6w
kZ&"
rg3W<
rMQY
cyY`
fHq;
PH)h
'Pz"qM
Rm7aF
4>})
= Rq
a;\?
U?L,
8S7[
(VBuu^
rT41
ryp,
RO=e
au1D7
`%g.t
e>)%
~VAJr
9a/;+
P\E{
CBcC
')%9p
C}?|
;YPgN
G*#
=[xe
jV,/
bU9|
'~' T
'12BTNMH5jx9RinQg1KuOgXm5RmqSADpiAxDz16M
S&e(X
->;xK\
'dPG \
HG'l
DOWt
e,8 0
qZ-;
!O%VwJ
J`2!X
lU%>
**5*BB
*mE
fBZX
r#TOO<
B7n
fK $
x@~^
-xy8R
}mD
wPa,
n*.z&
OdmbS
L)oS `
LB }_
X r=
<{qI0
Rq.A
MH&0
781OD
\u-n
WUx[Dc
9M)g$
. e;@
"J-Pqdj
n4U68
]chV
75-C
<364
?'E9OO
X'UR
chJ}
5XOn
_8Dn
(bWe)]
}Zfa0
j,tu
74sp
5ZLB 2
dc rKY
kw,(
#rEKh
92$C
h/;o
+!Bp
9,KM
?[p
9#?RNa
.vZV
J*d9
)%o;
)<pH
~(tg
CaX
.(rJh<
.-vLzu
v:gqb)
)RwP
0?!Q@5)
(}'0;W
ABv.!
jlh"
~u&rcWL
RQW#
LlD/s
' ry1O;i
#:CK}$
H;67
[suYY{
1,39
\4+8
f*H%
0|Ik
T1: d3
Z<8!
vQ)e
an|&
BeV+q
=W:=
*]1l
*b<p
Qv1p
-1,!
l(,
2hZ>
vDFD
sHzA
yc#U
Adw=
Y|"%3
|wQ*
R H|
Cni
)wdn
+KEUb
+1o O
fZqY3
sz3y
zw8[}
l/bB=
l@rhi
19 f ^
z>]<
( xp
rr3Z
;Z[C
l'\Q
"O[/
Xj<eTt
`;m~
D+Abp
}0W \PeUNn|
\ nA
f)-I
OV#8>"
P<[z^y
Aa1!
z"u,
=mGTL
KmwW
FbTc
^8HS
f^G~
Im:9
3<,:
@bx
xxKj
tY#vS
Fq!_
Bti|
*0a#
>h@>no
wuX7
Dh4x:.f
A;<
| *-
t~Gx
hDw#[
kj|T
vX(|
Gm)k
VP:D
$jz:l
k8
"<0L
8ew"
8MB:
P1DH(
T7}l
{T=w
[D}}VfVL
MnR
#5#b
@XbF
OV:r
G] o
q> f
v5~A0
#&y]7S
]?`&
<pvkG
zoR~jR
PvQ:
f|Mi*
^n
Di!Q~
[ 8+
v}BS
x_.o
.v?n
%-hl
}}3M
vDrH
12SM
@ur"
Xd!aL
Bpu%
/r R
D4A=c
"s2cdRe7D2LzBGT9GxX6v1ELro61cg99bt5
g^/Uc
a],E
7qJb
K>)N
Q'A;
* s
em&ENvG,
U cn
9VLF]e1
SZKP6RnRkokJtjOsUAb1r62
ac&o
`s~Wb
._s;
DPq
MR~A
4[d_I
_CfI>-O
EFO
!=:y
@=Gd
cPq{
7bx,AfN
N|op
%i|EyO
4UDc
;jL+.
{;|SG3
+8Pq
ogbW
[a9w
VP!
-BXBZe
Z@ZF
j?P*
J|Zm
xm $'
>Wi
GWG/
Sd<o
oP"p
R0%O
+\ w0
r}A^l
i1P T
'kOA
f'#z
D[C{@
$2t1
1BQb
vMe}
9 _3
y6Ue&
qLVbjB
.LYp
M]jL
~pQ3
(AjY
AddMilliseconds
pWMn
42t8
Z^:]e
eVv8
zK+q?2
N-u
IYom)
NHN0)
~H1E
IB"E
ki R
^5{NX
fxK9
ncNX
=L{]
H[3!xz6+
ng!YM
`nS#
pn}A
hXC8
8l*`
t@Ilc
w@{X
;WJN
c. vW
*7mA
Rh*$
J7x9
"8;W
6xG%G
i7?/
h5BW
b)"y{
z? l
q LgG
GpOqz
)ry"$
y+v'LOl&
AM@d
{3*Bb
psUS
9#uG#
2@ M
y?A
|YsQ
69P8A
>r/_\
w^R
G;L V]
uKft
sfit\
uv?h
:1=
|4={
p\3O
YUn
% {!
McWD`
csq<x
o"?7
{x.7
h?+
+J]n|
k`,XA|
)<e K
JIrie
z=Co
[]k
Rl..
,+Xp
."UM
w%WyJj
T:t?T
nrs\u
&Q&z
Xv{^
dSOH
XZTy
Type
QqV*
^:SB
~ ]::w^
f: _
*')S
IdE+
i$F!#
:nD0
;BdsET3&
' w'
i$[*
rte
)(j
8K<lz
1A2D
evvy
^"Bq
'd)_GH
Bp>s
CMHR
Im_-
&5<Y
i`l
_`~3
xh1y+ 5
,e&e
yh?W
S Z
K^r]
F,2m-
46|C[
.,3{
8Z]
* %z
mzA`
uIK`z
Fq^
ao'G
a7`[
wM|D
z;Y&
_jhp
Bxca
;}U<P
ltjt
vc9u
_lQA
3.FI
7a,,G
-Y/3
py{m
KB?Hp
g$,5
##0rB
l0%
_3v
[pg1
t]4c
imOO8
Phq)
Ar7/
R<?X?
H!<O
bU;3
5Dja
#k<<
'Hk<*
5f';
xP*_
Ar76
4brt
2(S
iJpVL
V2.F
{.?$?
a:)%w6
yl.^D
oSf;
0 .E
<g>G
bUn6
YVy
List`1
W}m+
1F7k<A
U'==O
bY P
pxa6
*ua[K
Ap|T
F(N23
(pry
H:i_
N71~
Bo;M
%RfXT
U^"fgg{
Fuq8
pfSP#!
1We -.
FQjL
\r1~_q?
'K^ .2
SkipVerification
|DRj
}$Z^
ti@#,Z*P
6%+A7{D
9I$9
ma%+
]bdu
K`$2
q4`=
3gf)6
; 0G
6lAF
c'I8
V?oT
9tDP
qz^h9
Dec'
&^"tJ
cbU(
b 7ow
Mi7N9
o;XS
k`O;
cO:4D;
rOx\
XdI
jKt]T
?SgJ
Qqk
G+-2-
FhN,p
~sBV
PCx}
D'I+w
`.rsrc
5CuO|C
ED LU
hll{Q
9|tL.
o{c=
{By5E
7NW;
}!ZlN
4p-n
ZG/!d
;V|)}C
I!/Y
Ck:r
MTJ^U
LvbQ
lhN5)
FVk_
$$P3
;@>7
fL.1
&W~{c
Z8)Z
E^Sb
Q[(s
|=j\
42W/KEa*d
_Y9
}$Ka
\YN
79]y
r5 vo
$:6&
]zD
:"~~
gsGDeVcZSk3xGWm7vjJmHMg9W
!@JQ
ZWfF
@ #`
uF RvJ
cVeZ
NC\m
&6bxX1
N% f
L>L`
PiD*v
+M;cV
L:bJEb
&}(%
Wr),r
^3GK
Gaoa
'S0
+ .(W iL
:EYD
8&}Yuo
N7yE
z\0&
?ca'
e kp
ZBI_B
GC`B
7G:v
g-/Y
I1"{
aZy=
;QMX%
~UeI,
np(O6j
s ZR
j2V>1
MjH/0
5]b#
|0v%
2"R
(KL8
m&SB
Oa$ZQ
T4Kf
wMOuZe
)~4]%
=!%t
)uaB
YkN'
>.oN
sjj2
|ylT
5Kn04XfgaLyy3eYGjJ9cLwxMlHlf
g QT
r:>!
kFE1
Sx$ w
r|r5Y?
beY<
%r5O7
dG, hy1
:5#sR=
l=C<D
{b6isj
;?+^
75V-!t I@a
c[M
ug#z
S%>[
X~D_!
+ F
OgEqBc6OFgfm5MWcADAKJ7FedW9S0c6
get_Now
jgc
hH]07
Tc 4s
"&Fi
#d}
P kI
@59!9
f5}z
_4m$8
=a;~b
T9%h
GRBW
"JV<L
w Oa\
(G;m
r;9#
?giMM
qNgfB
!z'n
# Qxv
1gr
z;1wg
Bk*_3
qb_
e)$yP
$byrFJl6SS6u4DJctCwijpn8xScRG5lYHz04H
R,^z
9ECI
h%6}
FfcF?q
d~N|'
>bsj
jgn6
hd22,
}j8b
|vU=x
izr"
E_q?
N=g0
i*4/
[#*0
aT^#p
-cZ%T
u!(ZG
+u&&~:
xbh~
|}a
laK>
c\>~
m'ZI
|mAD
w*)h
RV>8
72~6:
Qd?UZ
QDp
wUX7]|
<^H2
%G6r;
rE%d
!PlAhk
5NYF
A6oT
xi_!*
\8WBR(FW
Uyz-
+!Q?U
n#SS =
Qc;|
xo6H
g 0'%
P6l]
@~1B
("07GG_
7Z?JO
@!H*
d%=D
7Ysb
'8\_{
g(99
b\si
pT=+
2yxN
in>:Bk
:W]j
+hQb
:LJ;
lEdMw
xosk
f*t.
'^]59
VmZb
HE{{^
%qmn
}zY#
$jh[
%;$@.
[kzFX
gH8j
H[)c
f`8>1
2G{bI>
System
U(
0t'6
#a{x
9d!{"
:n8nH
dj,
#5V4v
L=5]C
+yhN[
)>rq
IGI?
E~pAq
+Up
hX Y
(XYS5
g1v7
eu i
!p7xjsaxveia803KbtCAVyubM8WHrmy8HU
.l{8
VMrY
(4Qf&
~7x'u%
~=@|)Q
{'}]
_ ~Gb
L R
[$g&
YC&r
]= 0s@
NfO<#
1zC9
=<Y7
,VZWlZ6
@g]c
G0BS
4 rM;
pyy2
sm\p
B3F
AR81
9yd
Y3>js[
*ffly.5m 7U=]
e2_7
YIDK
NN!(
.1^D
V !a
lzrE4=
E>(
DKc^g
jc%K
Pk KR
wAS^L
Cz>zn-
B.,1
x$>U
<Z]n`Y
Z3/3
>F9C
G jO|
HSqw
-h{b
L` z
**F;*
qu+]
OB?D
qpoO
9oXP\
3H7)
*h[
`vhW
@Y$'
{QJ!h
un ;
5W]y
4K:N
pIy.
""c4
mhR0}
n:.d]
b9#;
d$)\
Mi?L
b`*%5
l1kqGSb
1^VL
F-'1%
R~vQ
O^Fz
Wy+<
{SXb#
5.jg
r* d
{j=}C
yA.8ez|w
5c|DV/
~ Qv
lEc]9?K24B
Z#n`
[5^i"h`
KUB`
[$5] #c
DZ`)
E,l9r
VUx$
DN|0
v!nG>8|/D
b))-
3Lc7
8 ^X
Z^5t
L`YN
vTvxi@
Y+oo9&d
Q$r_
"wfTL4
TfKSP
2!~_k
%j B
5#q@
t]G.Dm
z`^Mx
! ck
FJYd
[e!e
6N@A@P?
?H*1
wM61
IkVjH
R,>;
RiE
L {E
ajT_
ncuUO
5}=l
r"e&
M|%{{
a}i
4ZNV3SfeSAzvQKXuR1qnMrcGs22B
J$T%
P-u
[w*k
mi'o
+@sz
HFJM
f >f
DcS
J.zx
~VGKG
1)jd
2MyOk
U:C`yGA
,{*l
z/KW{
m|_6z'Qf[
<ss)
ua3>
S,S#
WKK"CJ-f
e.h?
)$UC
'azX
\m`h
S>fq-
3W<Ra
'[4(
u>/y
t}"
t|S'"gj
9m5P
Vc|fEbY
OM` p
z X'
J5deF
K!$A
2H51
.,B$d
+)S{
K7qBnC|
e>0N
YD_5X_j
#U "
`>kD
e! "f2
~o;lWh
Ljlt
V^10r.
3zn6
zw7;@
}jos}
XPW^c
Q]aw
B3SV&
Q |}
@X2]
uU"/
SsScJ
@tk@
g?E[
t##CA
#XGZ "
=Z%w
]Uc7
x)FkI
W|B]
:dd6,4
b,_z'pj
jd_]
~&5U
WH-.
8S(_(n88%'
}5&d
}w%l
$3jj
L@c:L
NID
K(dX%
Y5}A
MMT+
Fc6lt2
?Lnk
d#*'>8\
auQ^
}m=x
E:w`
*cEI\b
kQ$T
a 5=w
>/67/
qH}Rm8
@t(,
s-B(
Xoaq
x u!sr
g'f+
4gY -
Hb7z
i!TOM
D{S
!KRR
88~#
?F`9
:$F;
?qa!Vl8
wY_
uaP8
1W\Nod
AH\m
zd?C
$_Z+
?P8g\Dv
u9`~5
q|oI
C_yE
evE<s
CJ!y>
seZ<^
System.Security.Cryptography
0>R%*~
2tsl>
'l,
s1D!
>9Jw%
qhF<
&h#iT.8bzW_
d]wx[
B!_,P
q\n)
-Qlj
x|Lf
WJk %
wQQ=>
5;9B
%\[~
U 4D
@9Ob
6;)0
8Bsp
u_Y14,u
aN-,e
o)J-
2`<Uv
)d|G
U\_A
'!9Wt^
`srRr
<:BS
RDP&
.ctor
*XhkX
WfwvR
;|g8X
I_mg1
X_[N
%*vm
B6SI
ze{aB
Yv7W
I5"l
O?D#
aLl&
sk@Z
j(AS
%GLng
_JQ\
ZOf}
2LxHP
kLL)
UIKbtH
PH/g
xZP<uC
:Zn`\
o#.U
9PTj
!=u
]o.k
";2%
++h1
Kjb]
eD+'j
!sRX9veKqQB2spWzX8B75hpZLLAnvxpgpj
Kf&6tAfm
35!C
99C.
gwr/
#WW9
/Z78t
r+2Vr
KI{p
pt[tuj
s'Pb
P|Y2
T^`Yp2F
\7 x/
7px[
Okl2
O_M7z
@.reloc
+1h?
Cb
nn82v
nCyy
h=FC
G /] X?u
DJMD+
#JdS
B u
wrgd8
Au0O
uJ2!
8`\t)
2$p5
~6:_[3
^ "|
w2^X
Z!D<#
-ah5F,
Fb\p
3eT@
1(|X-_
{Kp+x
d4)QAD1-
;{j-
@;q-
o%+E
_m@
2)sR]"
rC e
6}XND
4o"r
in2*
Mh@ n
r =T
9~ W
`27V
aBaz
_VS
<HTG,
4 e;^G
^8Y1A
VTxO
DH *M
8Ow(
~.h4
xrYt^S
$|[?L
-Ct;+bO
6F:~
e0w4me
$%pfM
}43w1
qP,D4Yl}s3
EoOM
aRFb|B
z)KTg
%@/&2
Kxs`
WX4dm
6-,U
* e#?
6 .2
in2t
7hxC
l}U%C
g'K.
U5/Q&
ccm|
"!Q.
-'6(
hNz<
.\yB
,L2F
j<~m
e6n-
89"w;$
x)~ {
#Z4 Q
^@O
\(Pg)
[aw`
o_x;
Mi*S
dXas
lyto
)x)
n"M3
UK;X
R77Q%
1oNF
hK6d
W -{
zQ:4*n
x\W0?
^0V7
(9CT
`> 0r(ln
XE,h8
GBF
uIhQx
NY.P
S]2B1
3?B*
t-=7
yCIt!y
T<R6
_sXJsR
}X18
(L q
e8Z[
^`=2
kw?Dm
lZEg&`1y/2
A=$j
^CO
KPh/
.blf
.Mev
VWD.
<EHr
IJ&U
WYV;
' r'KG<
7RJw
>?04[8H"+\o
A/nx
l4r'
evoPP230OgB5a6Q22lXlexGOsfOXDm7
:^$v0
iDau@
o2@;.
(s]s@
>[l8
Hb Vh
E)K:a
-EZI
_o]Er
v|HI
jz-
jD&2
(BHD
/{Y@
pLqS
-=3,
'~'i
roM+{x1
F S
"/Bw(#3
2FWn},
~48G\j8
[l}A
> yu
&ftu
#PSiJw
NYfR
EL/%P
kx~lm
=a-W2
!]f
Y'tU
%\e2
1}KD
p S
9p\d
*L:H
$Mz7
I
EqrI
v*U5
rjjQy
Show
iz.k
!3XW
BL7R
<RRT
ic.gH
%5$Uo?
L1"
fewk2
t}\>
osz
98x9!
j2Mr
5/_y
- tG[1/
H 6G
T/>oKw
.Y{#
|b11
1 h&
=+B4
I 1
w>oSKn
Z7M
~/-G]
=Z#e
0-J<
UY~Rs
[!ACy%
2UI
MJ-$
jb+&
sK5c
z9'r
fnQ@"
=)X&
^k}+
~uc#9
Bzi?S
jG`J
>daE
wt408mSRezfcNmF7XjFuT
~Wv%
lAcv
z"=<+[
7^-h
.diy
~g*o7
@+HDSW
V:4uX
SJ6J
$@@L
Rz42
33[`
e6Us
R|g?
]o s
^vhK?%
}Mq
( eyFh
2|,u=*
}(3-
>V8V
b-Y+
3VZS
xHio
91"4
cn4}e
W;!i
Z`Ph5
H, E
:O%E`%
\8BgcgeR
H5euijc,
R3@+L
@dPl
m"c>
yMv)
~U?0
Vl]k
t`&_
{J'?
*L9[=
#3"w
LF#v
#?m6
@B]Q
YBd~
;R)
qndD9
vF_P
i7`K
) 4E
X {5
>v9L
P( \
W6,x
T'H
3OhS
zYyz
%aL]
/@rW
3d(i
HkAoL}1
2X>B
aZc
Ta%cV
'AVR%
9{*
hA;s
cRS+j
/JfZ;
V;Bp
n.SFe
@*yfKp8"
)j$7
8Q 9
~V0D
ulp8o
kJ d
0,t!
LR5i
[^N
BWt?
OZsw
SXE@g
B26A
b@KQ
bm%
~sC
`C }:p"
Eo7*
)}' N
>RTP
b&-U
DW/zR
+pn^
@%"~-
w0:\"
|ak'
VGyX
A^Td
(V<
P4ueV]
{;:X
j9g-
T6FkUVeva
9`4YG
;#RG<v
v0%v
Uw9G
<"=mDT
l^#V
" 1 .
L[dT
@'DN_M
c(+Vo
4BKV
CGY7
}MW>V
_M[k
*Rw\
Tw q
wh\'aX
]P
/4d+
){+
l3;{9
|)h+
/OBY
~/H)3
`\qvnP
oWT,
8KE)
FyI)|
m"[
w pNA
-Q|
X)Wd
XeU
f$#$#d
v4zHE
hkfFb
Rt_
(?'[
QIvq"
STen
rL87
S]J2W
S{_X
{8 (
9cDti
$VD!E
K0?
TZ[S
'(bv
qYPY
suX+
K16?-G
'3HD5SN
wpXr
PuHW
bu=ShR
RSvW >U;U
p^n
V9AO]
}<(CH
)qBt
;R[w
@+UI
`@ tjOc!
)9Zz}
FnJd~|[_<
1ZS.
iJS(I
:3@v
v3e>
T;"X
kS|$
=+/4
:Vz9
pK[p
[)W+a"
uRr
yp7f
B6} RM
43s}F
WtWfl
lNb>M%
0';A
%}w}Z
`+o
]c;_
G21y
Id'8
p}Y$
Dp~rk
8,,n
.h U#
_~rET
'xw<s
i)4_
]g;
E5/c
.G>#
I(I
Gg]
,H y
/zt+3
2DQ
IC2c
<dAD2.
!:/&
OR:)
/|-#
!;
';@X
!E2RM
mscoree.dll
<d?G
Pp2c
p^QM
^"E|K
ED4{
A*?
yaz>
w5dh
#@=!NV
%=15=
%x_S
R;j8
"[g+
zVq
+/!,
skdy`}n
3>] T
{c,;
JS?7
vAz{
uG73
8-aJY:
^G0a)d
Z\>
M }9P
~f|@z
DW7 l
T7Eq
&^!<&
V*7H
Erri
y5/^c
wu?S7I
+Y;
]phRnP
EID<
/)d"
p`^o
V}Xm
+aQ5v
d:t.
~T5e]w
j!Sz
GmsO>
aQ({$
$Lgv
mrC:
q |
m>E"
wN~A+)
) ]]
HM$+/
z"An
tF60D
.Km
~7u>
?[[h
J-{FLE
O7d
bY8+
$)y]{aS-
IEIT
| l^
w03l4e1l0aYSzPAAyZkGmjISuXsR
~:V2
C[]}I
jfH
Nt(x
Nx>b
.KX
M!TT
LV!1r
@;CSG
G@k
(9f:
8Gz
DHEWp,
3X[x
06]U
}BHb
M:^<|5
Waeu
#:rb
gfG]^
"":n
xG&>
G#k#
VC q_O
7qB;
Pm4?Q4
*.3!dQ
V<Xl
P"{n
#55afw
Q-^Z
\P[G[I
~Z,>
0d]+
Hd;>[
DRqy
aUsA8
t*Nn
Qzy${
xP-El
"Iay
3]_G
O39
5htu}
KTl}(
"kB$,+
ou s
l5Hn[H5
Xdt
:@.7
l` 6+
4pR[(
Lm1K3
~EoLZG}
"oJ[
-r/`
KyR1
1+{9oV
yw ,
_Cw
)y#Jh
3srk
w!PY
@dRs
JoDN
>Va Ra
B~\1
^ |z>|
Xp1
RijndaelManaged
1+nl
UOt KE
tsJ-
%j&:<Q
a]Io
Vs?s
~0b^O
T@Q t
<%&G
D2<h(
xZPD
wz}w
@^XM1
G,$?
c"Cw*
om-]
RbvC S
1S\K
H{}5;
EW8Pt
laOw[H.UK6F
vy1W
A)kr
#1:k
I@Y&
Gp$
3E)q
87g)
BQ*
Arw`
$t@
<r;H
=gw
+V =
.e
![NNf
]QS_
8WH@
K))SK
z6\$n
[mhMwV
?jM9
(enI
v fw]j
k gt
/`qM
T8E*
'xA@
K {w9
1ZK7
:C`
qKHG.
PdV.x"
\kk2=B
|n%L&
x0v{
|l6y
c*Ay/
a9>INC
uyo_
tY(Uj
:Xv(
0t=d
]5BF
#~y\
l[sd
"W+(h
{.Wi
&6a2qsXluHSJBrAt9LPYzyH2ASQBvvcKkljEX7W
fM139
9OI>M
2i '
cT1?!6
dF?
i1a(
[fj;
O jN
{b_l
/`O
DakHD
0$Fi
_Wwo^
QiAC
ugW"3
Yqv\f9
` =;
A>Lw
&"CX
jMwF
8EBy
Jn'5a
e!!
Y~wy
fX:(
V,P,
U7Z:ia
qz&z
=[c[#
n1q9R
Z,o4&
,A1d-
G5{&
$H)/\-8
Zj?D
3]HuBJ]<q,
Lr'Uh
%\n3
QWB
9<}b
kt!q
kq`#x
Yr&~
"1]+
#YFqUK
gXwx
0 ,Z8
TABu
3BfHpW
y(T-}#?
*SS@
N.Ql
YjcD
DtV+1
MFD9
2*!wq
9Lhul
Q>j{
z*np
!J,2
V\|/
+{w
$xl!
X>B.
-/oe
ox[o
o,!~
>-)Uo
.wp%
i:3`)S@
),{M
<Yz+YT
<bScD
i5}9
~o>Ia
8-PX
;R_^u
+&X
jQ.""_
DPp<
a .z
2dC,
f"{
-!Y^
%v$
}(#:u?
_dx,
n~4tIh
2ZV}
N~RK4
3Yss Rk
w-IM
d?:lXb
=\Ke
`4zV
eEIc
Ow|*r
r#5)?
W7{O
KgB
"vtzpc
NW85
{QJ%
idR
1n~A
FSs)w
<K~'
sfgGB8+
0yx
;D{BF
B'2}
vC[*9w
Mm$?x
=0 t
Dzdo
d\?P
su 9
N |Us
xe"~
US
Q<`J;@7[GX?
<F@M_
EAg
6!A
3^t;_
PV7B
F^sW
X&/3
Pn^q+
f73k
brY7
eNDG1Az
4hX-
s-[7
26mq`
%=w/
bcs[
T(oK
wM^T
Fk#
*NT
4D]
D'S;
@=R]1
Bxlbq
u 4e
uWCTh
\GM;
t/dT
qI)]
,L/M
e]_j
d# Z
6ud4V1mxt3r09Re2NNlHYE
?4wRe7#
K-GKf
<W81
9|b5e(
uvPM
h``5
fDT-
dJQ`
]:/
^>>Tq
7uc.
| n'
rX}3y
3V%zC
OB? u
Xn\h
+<.iy u
@)0 &G
]{ p
Vjos
{Thd
o%`d6
~dW!
)7&e
ok.Pp P{
RPm)A
7WHG
I|yS{
P!Jr
1(|C=*
1qbZg
< f]8r
$e`0e
Bh.
*OZ9
5 Nt
u6tD
+ejc
Bj<[
._vtp
373(
!Bv0
6sDmW
2(,M
3k!U17
'O*\
dyu
{9lN
Bys6
t-JU
GM^$
2 _F
kDcf
9Vz
<-.6
s{0
CbQM
UrQ*`
Qd3Y
VbO@
b2S2< a
U#t7
Fe4$T
(~`5:
,<Na
`%=3N
yt'a%)J
f8J]
C{]P[y
g~i`
=yZ
HPR,
@-8P9
74-\
O.q*
S=
ZEp'
*<4A
d2gg
':dK/
T^Fb_.We4)n
tk _
WY,L
e2Iz
#Pj
}&})Vt
"aomLjl5sSOwfjlY7m3VyB8h6wicA4mnJ1g
wFxA%
Mjcb8
-Qgd
XW@#R
8mv!
wAxkV
'G J
N30k
52q\`
H 9K
cd"`
R8$km|
9QJ;
=q)"D
%l5N
'tPB
=`Y-n
&sgdIt76cVNDRgkuAIIrDS8MWkLDwHP0moDP1rG
g>Dc
KGo]
'M%`
%XReqtA4SH99ZoaDAUoEYxvVhTLQPUx9xIxmMr
3rNKR
-Ylj6j
C!,W
F!C9
YU=F
'fGvX4
wejC
BFvX
p`K
$*fE
$LF?
63e
WwX&/
FeIQ
?;
S N[
{AO{
EyC{k
Cb35
?a{wF
=6`eO
-qJC
1"BK
(4of
U|h5Q
PVU?
O)+*
`qYYm
.0W*
tPXR
iTw37
N E>
E"Fw
*F9D
)(P
Q_F5Y0
-YpM
!zJr
l=1
K8bt
a0X#
l)]B
a("O^
RQdz
pz9A
+((k
*8}
[%Dt
~_t
o)1zu
;[- p
R{Ii
EBRs
Jgu0
(lK3 /
]qrq
q<2O
_A{1
VJX{
JlJ
#egJ
2_q({e
k#d
#.2Ro^{
8] K
$S@8*\
E`e0
#UF
2[E;
5 >U
`$
'{V&(
9)PY
%1a^
5p`m
Na8`
\Z09
Il!|a
+< |C5U
PJ`W
CFE>
Zuqwo&
z2wO7
<T i?
_ 2~
.r l
y,b
q?EP
y]ib2
Wi>u
.Obb
k8yQ
%XPq
D6.$\
*o/h
}a4YH
,_!
bp"a
^!{
[YQ
b\,X
;b^*
p(&s
T Ky
*b}
Bop`$
4NCi|
l j,
\5]R
3vu=T
i?7wf
;b^
Drj
{>h6eFC
#"4z
hDJZg
R0C4
!4:,s
8Ha3xg
pIeB
;ur5
jT_6
MU6eS
GuX7
"Ez`
m#*
`vp3
zPqdl
?.Ro
OB7Z
B[q JR
c"CV&
5;XKt
x;f>
@z^P
UN`gZl
?6f/
T1xP
S$'
KA^q
Q7>Q0f
i _j
AixHl
9H&dw
-h3t1
~+"@
YPWn
UXq:U2
'|]
7&s!
mGka!
8)R2
d94m
D<w}A:
NqyX!z"
/hBR
H^QY
GwBp
Xh"\
tdL
BgTC
HM>c
1U1G
DIA|h
$OI dr,.]
4nL9
_*8g
"r(
_=BT
{QL9
l\%&'!
twKL
Cwqm
c)^ U
K0kG
7Gff!r
aw.
KlaA
^cAK;
g;Y{
cd`^L
x$6
X7s)
^&]G
vB6zT
"wFf
j++9
Exception
3y|oHZ
3Pa[J
X$uV[
@;}
-18^
iXW)
$]Qk
kH2N
D_ns
G?pZ
;Pl=
pX6p
phj W
a{w~
.Kyf
M.hM
*&w]4
(IEQk
P.x=
UPh(o
zK`X
Lxf;
83@"X
#x,6
bbgsVz
VL\g
m.6!
2oXQ P%'
~@'
PVVN$dR\
{"|r?
$J.^
Y%h7
@@XW
Pkbz
uE!#
vonx
!>BW
P[To[
nj5J
?QWO
Mf{.#
_}
I!N_
DQ)N
{Y(*I
q{G:
($+}
&>&G
w,n\
tt;Z7
< eN
;71w
,H-v}u
u~&*
c%d-g
x=m_
x0mD
zkeJ
^2r,
%DD7
mJ#5
'6rK
3$y.
11HJH
`ahU
7MR)
,YWArye
c-m{
v7pw
[F!)2?:
f*'u
RBn4
FiOQ
c' *
Z,;
<6*{${
f!_W
dQBf
"Xc`A
w@Ob
SAs4-
nyy
7%E!^
L Kt
RA@Si
`):4Y
C~w
[AvO6
Yws;
E|>o$=D[
R=# low
HOvHcr3
-7p=!
$/|
,hQd
(M"G
$E\
DH:f
km"<
L2>u
F1d$
DvU5E
##kB
H1#_kg`
]%zko
,8M]M=-R
h3$}
/gS T
S\H&
}n_!
RDn<n,
lS9 /(
@)uyr
?lUY
C(cu
5[u D
(TTA
yb.s9
[>dF
n2X)
!aQs
W5x4
Uas)
Qq%AD{p
QTeh
9cs..
%<=jov
%<\C
!$,TsWI
E6jy
#b[Msr
>_33K
cz]
]*~@*gz
yGJ/
i^=Y
d)XJ,
E" g
MD&/
6cHp1
u ={A
a/cjRD
pVnc
@N;
vZ#E
dDVm
=Pnot3i
osWe
!4$
@n27z\
sO;]
D"hW
+K29
!4s\
ztg+
10,5
-U!B
rMEUy
kM(.
F{!84
bm+N
;M6U
MO1KU0
oyXi
^eh@
lEA~
LmLk
c1BkSdap8VYAIKxzX0lPPqMnR
$g8"
W%#"
{d>7
?HBb
g^T(
nG]^
a<EiV
d>|VzX
W_O=
7(7H
g8]$
6X B
`3"_
UGBv
P?h./o$
:AB$E'0H
A6i{3p
OM4'
\qx
D{-x
)=:M
5*.{
OFL~
"`@MD
!IejF
qNb-`
.>n>
,dtA
:@q
,ds1(Xb
]T%/*{
l79,
iP i
,yWv
#nS80x
_CGE
j5qh
b<u{W&
2$C*
h%_0
l=Zy
S XM
-Zcti<O
B<Zo
`lE^
ew*^
oKSB
z:7,
Q{mP
N[y
VQn]
O_%
xJ#=
9<W9r
v!i
GuZK
&h!
a}/+
(/Q~r
ejh=A
(8UA
Rx5X
lkk[
r<dg4
IluV
e^ L
CS-~
NH \
vlG^
)xh9
ZZar
350;
p]Cq
tTv'
'`Pe
Eq7^
R0[[LtG
p.2t
`~Fc
Z-l7
P'>~R
t8%
OgK~K4
f{t3kJ
(4N~
Czm]
r]}X
(oe4(1
U~&&
h}cN
=vM0_
wo,I
y1F"
yBck
e6fj
W^T
}9p&
nOUe
_4x-xN
9"C9
iYf(K
>Pp!.81
fcMG
= KUMf
C3wq
6 =K
r!
,bFj$2
uIf 0
YIZX-XD
5%Hfw
:%/k3HZn
*F_U~^
m~6@
{yo4
Fl~
bPN`&
SnN;
5Ph~6
$gpWO!Fs
_l!6
*JDj
)_ic
3gE^
'%7
k!U(
6Xi%
System.Windows.Forms
_"al
PHLOneXkgUxJ4XKCeSqus
#mf(G
knMj_xIT_
W,Yi
TJdF
08!]
LMPF
izn d
0Z:>
:CVOj
&qu-
w}w^)
p]=(
Hx/m`
*zQ<#
XL<
X CMh'
6?CZ<A
9Hk
0a}|
Iuc
R0L
T<Z|
mXoD=X8
P(RpC
/3&@Y
BSLm]
xb~b
]O5uQow
<OSZ0i
wZt;
t{K
uzmY
R^,}
_5Tp
!3[T
"rSDt
q?-<W2o
Ml~,
MSw3
}f'M
F7hQY5Owz0VKPnly476y3
E^2v[
9W k
^<Rc
5& ~
LipLKz
kJ6
HT;:/F
%Bx@'
HMt}
jtY~]
a)/5
_K
q)dvg4
e.v(
HrQ}
9-iQX
G:n{L
^st+
Hty%
;2)
k'<
`TQ,
YxDC
?jFky
PII?IY&
5;E@!
@MJSo
-0@Lw
'9h=
T+:g
SX%*O]-B
*[5 Ur
210,
k@@b
`+uwR
v y[
xS=MR
)~e0
7{YF
UR&+
-qjR
)Z,&
_>?q$g
>9A
?t#t
-%Zn
?KRLN
>{!A
0+R["
u<|Ngs
:M[DNc
fvF7
S.p?T
S[^_
;|-n
~P~:I%cI
h7_w$
a%3$
ae"Q
8G:
_)"2
bCy7T
;"L?*
%vPlb
AajL,
Qi6~
JXw8
Dq^b
lpgT
D^Gq
-B%S
UUm<>
?phUpx
R0nbx
1Lw #
DH4(
OPm
_%iL
Rp<
jDvC
{^S
((pi3H
!jvK{
NH6o
m>W1j
g=R; f>
8X9F[
&lf`U
:[m_4Ybvq8
) $)
ty%(
$~HM
@o[
"W +
/eEK
# M
2,0|0
2>\
wUMZ
;xx0D
} K>
U+t"r%,
8)sG
S{B\
5mj&
[sOh
FzpD
vwl$
dt&P
| \)
<Sed
!2-;-%1~
B v%[
pt^y
qySp
vwl
5pYA
G6>z
$eAH
~@&p
:9g+p
E{-V;
c,hd
4!<3
T~G._
*.RA
&i-
MMqmoyPXuhsH55fdfk9XXNaQPYa
"o7n
^BE1ogS
Tm6>
IM>C
jJ<tjx
\5FV
)BeP
Jhf4R
V-E^
]eF?
^n 5
'QP6
S+#0
w:oF
b`_2
]vjm?
rpS~
get_CurrentDomain
z",9
7VG0}Sx
zy\;!
/y`p
4yuH
FBwQJ
bZr@
/EPT
)van$
$x k
*,x;
P P}M%
_0 \PZEn
x"$]s
DEqg
~Z]T3
|wBD
Csti
` 'm)
%fBb
rf]B*;
9\}
ZF'0
?K&rG
[@A+
<sx3&
ck& %
3*]
ze$M
d6``|
&B|jG
b<aE$`2
j:ej+6
}Ljyz'Ie
-2{]C
#*=9<
Qke
+ 4?j$
\>lo
#Blob
V9%\
D%6^?T
M+%]/
CZFT
-+\?
Fk'(
| '
yseQ)=
v0pm
|5yn
oB?4
;-ESd
ZM<T
= g8K
f5P]Ag
=MZB
=X8:
X\`r
z^tA$
j*~ bO;
lpL]h
#R%V[dK
sqk
9HW
N r#
*+8
fX4#
7<7M
byCe>
7kz=
mj=#2r
dfc<
FhtD
;: V
% Uh
0IW
\If
K1XQ 3
L Pm.]+uWYx!
Wcj?
N.oU
\awF
_ [J
H- y
ZFYnA>zq
[b\A
exbz
u.&
D^7Z
\K"<
&"E2"
L.gJ
[ K%
pFTl
@NulRh
*"}Vr
`W y
)*zk
Id\Rc
\!k_0
d*f
Q{o^
j6f6
hO>mT-
(LZTX
.ahom
+B)q
{=IT
pp_#
h/8qK
OEv,
l(|A^O
q+rb
4r;
H)AQx
o'7l
L hV
/sf yT
PH+adV
p#d6
AM?3
fT_p)
Gcr?
8b5
DialogResult
CUr'
O(-]&
KjKX$
& AC
|r)j
lSx(
"n/D
k r[
si+m[4$
`j Q
(CEsm;
TZ#~
_=F
Wdb-1
|l*W
ryX9
&+RXx
Ie*=
5>
@`1a
qfRz
$/v-O
tPl<
^E(z
6.F@
8vcC^
6;Bz
8-;}w
ycnN
7M5l!52
De]C
C/
Ptkp
o,G,
WbNm
6t>8
:azN
IL5D
O\i-$S
9!*L
%g,>;
||dk
/[Sj
EEfO&a&
SWW?
(O-
u{o
Wwm
u;m}
"qZb
6=ef
m_lIU
Suvr
ekE|5
&6 J
f'L;.
o@d\
>k R
~JxKH
3,Y|R
lNs]
_K, oT
#8np
^(R.
'_c:
%qf2c>
^gG8
FFye
UIjo
'cbQ
E-o(j
o\CQ
H.I
Y.kNH
d%L
*f (
YBNLD
4*M-
2MyY
KWG~c*Q}
rIX"
=>`fzQ
S$]t
UaJG
!Chf
EeL}y
>|N!X
wkx9<v
-TZyBU
SO!^I
"N~$?Z
ym5>
#@+:#
PH^
zN.=
wx#
^u:7
,x}
A.~5
uY^J.
ZC\W
)Oh}
H(c1
g5pX/
{A
aj@i
]*3/gF
k'"
' >
\sw
a0s\
{4]:
:$Xq.
mhe3
fX8.ef 9
`r/Z
u/PR
aya^
{lr6
QW"
/ojn}
!G5\@
\>2R
}?0H
lrKI
>`6W
bvkU
E:#3
~x(H
mjk!
,a-[\
v_U8
w`h&
%DHE
CD;j
EJ.x
)~c#
]@ '5]-
Jr'(n-
~[XX
x/KjDU
V_5V
s#HO
+]-T
Fv%f2
H4g.
~C;p
+, J#
gvav
[{&uU>C
19RU
eu8i
'FQh
-@ =
iC1<
_"[{*
9hj3
3To$
d+fg
CbW:
|~4
P!-V@hu
yP,R
g<18
Qzo|&
}#h.9
8XPO
~e<,$
Vq@CN
H6E?
&A23
[IJZ
F+wO
d*=L&
$YpZX7
h3(v
3v0Q]
WrapNonExceptionThrows
r{ Mz
)|!0N*
wHEJ~|
F[ID
gkdL]Il
U=|k0
=)`VV
pk55
(COsz5@)
X+d$
v^@R
7HJD=
\8f1
-;Kl
-R&X
B p[ F
"grv
6>8b
z`g'Be
e8mO
S;O+
y}|E
Uqtb
v+ 8
' v$
fdG\
dMwj #
^ fC
OY9~u7a
:o8>
3'mO
I
jT}
2;=<
lAe5|
M^bF
$>*K
!Q
M+C.
J%pK^w
Y4O`C
s[M}7
reSp
l^%-o
-'@oPC
&zB|
N3cpj
}5*x
NK-
a^0%i
?:Kcz
:q<m
a*%+
3*_@
"_N<
P\W#
$2\t
y4[IJt
d/n
KF][
# 0}
:.}+`
Dvgvu
F$G<J
q['ApBZ
JYj?y
5o ?
}lUH
9l@8
0E^x
T qIP,k?^
p^d#
L h
ugIs
?*iU
0aK!i
%jTAU
/16!
=K=:
|oU/
a%y,
% 7[
YP>'
n{f4
E*ON4
Moi,G
_QAj
adA:
+|7>y
I`wHG
9zM1
X*ht
ez,(
L=
AS.
gnmP
_lN
kWLE
Eg[_
5B5Q
:S0d
p%!fS-
tnqwA
'L>8
rgh?
0=x)
q-b_
7 Xfu
3g2rf
dp0n3HoDYCHrusq4KNf3eeGSw
[,.o
4QmCq
~b|p
8^#:
M!yw
8xcn
=iLz ]
U=L/
`y(>7
rZO $
lO O
S4RK
>YVa
+Qisi
k_ `o
K60Oj1
Lk~Ar(
LxO0
Xt}I#U
?ASRh*!|
xCs@>
\cwp,
7+D3
ZB]Q
a.LE
~ODZdbL
C7WH
&`}k
9izC0
WdfY
w:t,
N7!>
b=r=
yn\T
]nmq
Ei?x
$+'SVx5&
f88Q
lpL"
rlP_X
c^<Ve
tkYO
9!YL |
L6US
LbO~BD
.&`' "&
:B_B
h0
R*1E(
I=Mo
c)a}
*%o;
C~1 'Nf
C1rcG`
:\Y+~
?}^5y
8(%v$9
6f{S sA
`\GW
"8zb
~5+3n
lm\;
i~{S
y9:-v"9
"I4L
HEF|>)
CHT".
\ts#+
qs$
M<F#
v-%`
\(|VJ~v
a8=-
P^
8?gV
|hl ]
%C+],
<}Xq
N"k~zT
O}Ku
UjD4
QgQ h
>,'
wW<)o/
k5,0
qI!Y
W;0H
CO E
$if'
/\g!
m8I9
ulnel
y48D.
R",c"S1
!Of0t
kl!K
4Tu}
]')Z
h=:[ *|
2zef
S=\2
Qr&
yh/8#
8%ws+2
D|Cj
- $Bl
A=SwD
sk^xn.<?
646jK
}Q]K:
)K_Ca
PXBB.
>7Z
c8Ju?\
l5`#\
6ok
1yPfR
wCuF
6%xI
mOo
I.J
kCV
/*anj
%'FVC
x`c B{
#-B`0
jv4dW
uJGDB'+
*J8P
{0~Y6
RI4^
PM+
>3SY
0s e
!2b
+[tr
OS!
V n|
4$ x
c6$'I
]<|X
XJ9K
w7|"
ybg
_vk9
#Im'
riy
|zhE
=a"6
I|*A
*$N9.YD3i
axI-
&FxTIeEPw8dXl8bx6sSH3YuXuH9ZJuELvFBWeEV
(:dD
94PD
vV!bR
f'c|
!"Amv
=Tn
A#?
%%*8[
ABZO?
V<d
cKzk
fu~S8
;dg(`
VCn(W
YIkH
,S#y
#qm;
wI$hk P<
E82uC
5X4e
0qxo
('so
tL =Z
+ Lm
=Q"r
.uH
rfK&
2Zu9^#V
Y39K
evy-
]*|Grm
3,sG
Ftq
g$Zv
3K?S
= n}w`J
{\`/k|
TP:&
4cU
k-tQ
u]BX
gg{-{j
tW!n
$i {
`SK7t~
&mM2h;
.:$&
UBB=
r 9o
qO2L
h|b"h
NuJ+
jyIgu
A=uZ
^mhq
eKV
6N U.L
jCZM]
>Zi&u
+tv}_
v<6
MIJ,2.
9=*w
f8U)
[x#A
NuI
Ip 0
:#+s
}I=^2
I8 G+"
ZBz@
%pwHlqHvbO5tQKSIJVSRfp3bOB5wmoisp2JUK3
07aNRn
-i*zg
@i|?
ct9}:.
ICryptoTransform
mfAT *
$G?A
AppDomain
-TnW#t
LOi3
g!W"&
"m_Rpbq
gQm
*IV
Kb2Fj
dr*Wv
yQj"\x
@!&Y
_j20
ztgmot
0"5W
\Qo'
)tr_
G^[6!
AKoL
v(|v
_6^7.
#zWAr
hr45~
/dj
"CP$
(KN#
5`xb
J/I*C
{9\d
(r;9qbT
|SgA
Nk<e9
u|=A
)gRh
?v*Xl
*QU/5
qx_YG
\3m{P
We8A
-}2CTz
%TLC/Fy X
m;dSx
#F0%
7 '7
xS#.
ZG.;
=0) V7
a09*9
h1|F
"vk-
?YY+
lcUY
'ejVGxJkPY4wKnIIkixTkjjgaFfZbmKhLJLaaYsj
s>x"
78wZ)
F|E,
] 6"R
P'_
`U|q"4
i'|%
@H3a
dxiP
J 3
B4X^p?G
f!.2
M(w~
AOu
dk)D3W
~w\O
=, I
;?\D
}(J
y5%v
$~|
x>o`#
roNs
<"d-
bG-3
*BvK#.
27/lte
s[*Lu
[{Lb
"f6W
a9Z
Vg+*B
Mli+
\;'G
o0Gk
D~o-
i2We
9eKa
7PJ8
h$s:
,h^F
Y&KUY
p\{wj
"uu4
?L;*
DQB,
cpv
vo+z
~Aw
JdD
&uA
o 4@
fLQ){<
H>t`
Vou6*/
/\K
8:SR
9XJK
_"0$
~4>>
V #AS^
7Ch~^
F}D7
P O(
M{Ph-S
V>Q2
V3F%
W<Ff
'8Y4HTlab3V6cZsLTTsY5bbQmnM33MkHspeVIEnl
_-,0!b
lfOY
&*GA
nCkg
DD)#
RrU x
BvBr
q04.
g a
gTaE
2if^
0+3Q
.<N6u4
/*R>
MessageBox
F6y{gc
xaxaq
{Xu3
K4O$
@r-F
9GVD
W-[Z
pHN)
<g K
z~ {
lrr
`'A`
wo&
Oj-2.
;WD7N
G47P
O0O/B
zpKu
-^qi
~bYTL(
S/!k
rUmXe
Ik#s(
d igN
o Pa7f
RneU(
CQ W
,Cn+
lre~
<>\t7?vYBT
Nr-O
g1qM
c*$
lHyb
Oh< ,
viIG
Q*x!
{H[j
6L*/
r1x'
~{`
vCPP
{PZ?
d;l-
Hzg~
;O\o
euR
6:3j
_W]o
?/$
nB;
p-io
?W;e
D-=o
#08)
i8NJ
caE(
]wIA
2w4T
5+qC
9%:v
1X`7S7]6h
'[sa
Nx_n
<GL)
"N5;
etG/X
&S)!Ya
b\ o
7^dd
VIHpEI
M6K
;[yx
`8n{r
EU]GICt
+zQ'
;+aY
A@'{
P Up
c<JO
[=+
ppk2
oQ{Q
.x`|
la+S
jfRlX1v
ARSe8
I_pZ
J2U)f
/a3Q
euV:$
{Rx>
$^Xj
*M p
.7?Q
9=`2
fANS
_=nm
ljm;d9
U|,r7Z
_YON
][:
i]EG
c tt
Qg ad
L=fj
J1$55
I"*1
kN<~
=@#o
*+`d
?XlLPe
E0X5
FH,`
7`-o
^l3y
8'u]1=
x"/.
)E0erD8
p3&u
v:bg
<)9n
Xlp|^
vzzwDLXw
RuntimeCompatibilityAttribute
TB@Mo<
Lv~!G
C!c{`
gY^|
:sa1
Y!$H
J*N9
w>2!
Zw c
PPxZ
LNuR\y<
<~"P
^4^e
<>t
@Q N
~#8)
`Iug
<a1f!
>W+(W_v
a(Gr
0( b
"'pU
i;*(88
n]&|
\MB|
C@T|
*vwK0
Assembly
g/+;
E6h+
a{Jh#
`i\bM
|^Yh=
Pi\9
d(\gy
yhwk
[B85X
XO]\
B}[W<
{Pg=S
/xVa!
O8O9z6YdHaLq8C68LFW5d3E
JaY{
iU5
GeHc
BC'UuM
jKV>
7vTQa
@({<
KlL)
zcPK+j,
_H1_
(5Md
x2o
h]~d<
k74y
!>2o
H*iO
' f(
GM 4
MHtf
R']-!
^!9kyW
>| Z
Y;]{v>
VL1
X%)y<
:j1P
rQz,
<DZ|
?6:r
\_{~=
TtBh^k-
*e0
;@=D29
fqaG
TSW
$7V4vD
8r6$
2r'{Ub8"
q6O/
2q|P
n&65t
[F[
K%At&
7 .1
O9j+
I4r
Bd<
I4o
^9"x=
^)&
7r57
>*WF
' ck
{d6c
rJpm{
p'KeD|r
QG5!DP#(T
g@{-
3(MY
$ud@
%hHxj
2{dP;
pBX
]a&k
krg
#VYM
x;8S
']="
{]$f=
5|
'0G&P
1pXk
s)Nc
"(mji:
drEY
.Ox'
sU<I
*]MRo
L-a{
l%>
[&"
WBsS
xG2sI
\$3X >u
#xb42GFL6De1d8q9UVJ2PZD95QD0apSwLQjj
G/dl
/5g`
.?`_8
#<b$c
ld_:
aU(_
z8unyO]
;on/
eyE2=
Iu^v
=Cf=
$/#%
r>V,
v[7
<wpf<0B
.&No#1
._y>
POP>
RA-\
Dntxn
Z0m-
A]PM
aA;f|G
5Sn88
[v~7
M3LN
_ Or
ZZY4
wx p
System.Reflection
t_dJbc0
RfZ#])
!6bUF+
D?*B;
('HA
Z f{
2eQc
(m^m,
vU$N
gIPd
<>3!2b]i
Gifi
gC{U:
fr]{
n.e9D
2rYt
6 9
h7/4
x};[{
7N 57
upu a
|||fU
B]Y%=
$w2:
3r;[<w
@=z+;
Oy32
O&nv
Ai+Y
1U?f
RDe:
-v
t*+aF
s)aab
:]/h`
',x
L3>u
r\=SZM
:~*N
Gc-DN26
Oqu!
q(`:
aeu2x3ITiTv7SrGOtuAWdg7uFqCl
7O?jL7
=\*]
[b9x
<AKh
NI$=
j(P"
DKYB
i t
qXB0)
p`$$
Obdx
oo>"
`j[9
J$&)
eWyM
bvtt
+8_%
1U?=
J^(D6
"GKZ+
>enT
D^# ^
20oTptVes3poz4I02NcbV8u83HUxHMp
=U|)IkB
q 'l
Bd C
<km
4k]q
]gh}z\a
-^wR
> d{
gXC!
{ _BTo^Jp
tQtS
I nb
Gt$#
o]&u
. \N
?{hR
G%4
.M>~
nH?R
|x[^.
;$G/
<qGB<
(@pu%k
R__~
|M]q
l}>+=b
I5_g
]|9`C
r1z
^0FH
Gclty
%V8T
yn-j]
Xu"A
B9>&
7{P
0Z25
~h4+
A.xx
`MSp
(}|K
-M_;:
!\{N
;p6K;
d?HL
W\uc
*'jL"
w8^/
Hm>
6wOo
]Q /
N[]m
\Ib$
Y ;
Dc7l
] Ufn
w&H?=
'xp
O>;
A.x'
^5G!'
]2iv
m oy
0/p
^>PZ
ZSk
6jlo
n:e!
pGhG
JR0F
iW[X
,4%Y
*^Li
hff~
GO@z
0p_A
N38^
6$\+
~@w(;U0
|LI Y
y<U\
|1M
5gLM"
ocZUe)
UKcK
zRWV
]>H`
Tf4{D
4q9Cl
"x3nTVoywkn3CMFBlCQd9bEQJWFsEHem4bX
c5vg
l38C
Zf\iY
2/Hz
b cL
/Ho9
&Gx~L
*HRL
gLs;q
HXe
"shs
ke\!
%DNP
1#<
=n
HnTe
Op.y
sT\Stv
M(+&^
g$+D
*+7FEP
!&yRX
e]&5r
!6jo
a4mf
yrSP
M3 |
WV/4h|
kVL[,
'/N.
<.`$$
~kq-u
QjR8
6!?]
5j2?
G%Kj
6XB@
zae_
L.-*(P
v-K
g+N/
VOdU
H+r8@' b
}O|e8rK
Jg }
m `
`j)B
@Vb`n
/fB#
#OVwqpVLYVvk5NIxCaVgCBNed0Lf9OMseLkR
k5~K
c[Kqkv
:(b>
Hy'J
nwU+0
q F6
s[ZF
}r.0
]%\;
YJe2a
&mmq
)$Jf
yb"Cn<U
_~w7
1XFzY.{
U(*T
j$4Z
,B!+
v[y
ORj5o
4\&
K-Ns
G61>7
eVc
:{U
JxmMLk
IQj j
&E{Tq
5ZR6
+$I2c
2:iR
5W /
"+w\h
k UV
4 }*
}Yt^D <#
3V"S
Uc^?wA
sxwF
!0xl
7g;5 ^G
Y ,2
)^rGx
5Km#
QBZ
cC[<
QhJRmVp
grS
qxe7
>a z`
=wpP{hJ
Yz.!`
4u7K`
1o.c
Y-sMA
Q<5#B{V}
H`x 0
0q
3F~a
Njwk
if&V}
HzqM
s_xw
#`EN
7A=l;
Gyce
/u*EY
}:|"s7VF0 n
A3 <Y
~+@
j/e'
[(`:p
PhV>@
Wr *
-;1`
+.=x
<D`_
TY0a
T1H,_
x38@
5P_oR
H0!r
=LLq
#[[M~
etn>
3-M|
yS<iv
Q2`?
8R"u
>nw
Z12!>T
N)xHI
j&cic
$c#rm
:/T;Pa
ef3
{|_K
1c6hc
b5jT
:)zf(P
b^eU
p^'*
>o{q
ZeCY#
da$
C8d&
(GM\
0)]WS
"RJM
/A/
/:VI
cGcqE
H4y)@
O ua
(suJ
1rmqg
r3gh
u5`w
(/_E
j@@Tjs
Z2(W6
~`H1P
eTM3
eQu$
pYln
O[eA
e.a3
,k<@
{8y?m
[F-V
ipW
b8oJJt
Mv4]
PKAai^
D>RD
z/4"]
as(
%&#?
m_>3O
}+(%n
HQcv
x['-z
;zmqd
_xH.
u60goOgZtfSBUJ4KRhjz0UmtE
wUmAE
fv\l^;
lW#n
RL&t
oBX78,
jCQh)X
cG-^
10 Q=x
(3;0
h).GN
2.kp
o$oz
4H+*
[b$|
M,o+
WnAgx
;?P#
":w&#
R{0O
DgDY
qU\=
xv_%
J~+<
Ug7c
deS@
)gso
a~:g
0l=9
^kpE
{bXdc&"
]jNE
F{'~
F@WS
EabW
^~r
#AK
Sa.V
^*]y\
:1Nq
Cp/we
*F q"g
jdF
FYca*
#AKF
System.Resources
^uzE
{UWKnW
VZ+E
%E3
.LW
;$r7X
eniN{
qjFM
=02@
o5|F_
GDTI
nolt
@6sON
~|TV
8;pf"Id
0RwU
gtd5
C={d
?s Y`}
!l5Z(
R66{
iSr:
QC^
z u!
G6ph
\Er)
B-\g
>JL
6?iG
aDCA
lZG.
T_W
4h;8
S]}|
etv& H
K52
]1E/
OG1?
.a@y+y9
}]*gc5>
ResourceManager
8@;"
@FrW
}8DK
%S
![`g
p}K A
ls|
{&U
,mSx
L7 Gsk
IGc3
<s0>
V\&)
)Ifd
}rTw
tj)M
% [WP|
QYY]
d]z[T
:H]:
$Bp'
$z=1s
:O*e,
JJoj
AbkE
X-2
yQX@
LH<K
gq+e[
r tR
sZtC
3Qkn
lvR3
5L4v
Bgh&
r5hN
BOO5
&9&xL
R1Nfw
m1w"
jl%&
T(ink
|' RxA
!?n5
ZPX`
)R:e Pd
7tUQ
hfP\+
+VRk
e-H*(
k!g~
8Ns"
0M/Vi
`Va{
O 2J
h/v!
UXpv
xD90
96pt
i\Wr
gdLh+
,~L+A
S16X
)F$%
LNA
DRa/
7*Q<AP
$9^*A
OCvU
)Gv
[)i.=t5
K9,D
zAdQ
^{R'
}=5=
/]-`
c&PE
}K\
Y;J0
q9WTs
N{5)
P|PY
\hb@
1ye
CTEtR
|EKX
!B;~r
b!m:
+l{)
L<,
fyu]
sQBc
kZ2@
CdMt
KrR5
oTcN
[m5q
0H@mc
Hg^Yn
{@G8
".`n
;qmH
j7yu(s
Sy7i
yE(X4
96K6r
&X=X
5<04n
(:;d
^0|[
wX9u
,1%jm
PiP2
a;Y^
N[D*
zPkB
Yi#Yq
HGuK
"X^P
s`f!
[3Z?'
#N[XsO
LE&L
;A^e
aNpr
o'H0
`wWX /
-Y-k
BF=
poYJ
/5u6
_T 7.
B}!o
k78c
/e?;
w( e
BTMR\
hk[3r
2QEB
,c,w
R\6f
G#Jc
~{y3-#
&3~w
moud
2&P
\ 9
q^g&uk6
ua_f
PsD.N
xc-3
nyD1O&
LZ\l
0)T%
37Z
[1/z
w>BG}3
*FfIJ
]'%q
ye =
}=XWw
* Z
3G!6x)
N+$G
r<6Y{
"sijO
T}<8
&7Z6
G_5"4
b{+f
7lan
lC(92
T\SB4
Qqn_
D.?+
v2/
&Qcs
^bau
cNR _
S Z}
-H[6
QqEDu~aW
]:W(;
R ,
i80/
8xQ
.I3c
]{0S
g@w1
H]B3
gW(rE2
LJKQ
dkTP
i*7$'
2@!r
rX4?
o,rh6
vQA)
4ElQ[t
>&^K
('"
R ~k
) DAo
$\/ !
24Td
1cLg
1Sh .
Wr7
Gt^sr
@&KmL
l%<$9}%
eM]YN!
1$YGZ
sA9P
Al]}
4|o%
3g1k
nN!n
i+~w
O}U"TA
%[G
;q :
=HmDi
6(QQS
1m2;
z43.]n
vhJG+#
D: (
r>%<
YyQ&
NC03D(
GCZS
ibMh
6P5,
}#1.
n)V [XnDY
+yw(
GX.
-)8xZ
G:y$z
B@8V&
D"dR
pK
''
LdR[%
ImiqZT
_JjK$
G, U6y
R-^V
W(LY
c}gT
sA+:
Q222=
+jYM&c
7*9A)X&
K zD
nbV#
c<a0
2>kH":
`ns:
;3a
Mmy
f2EJ
i@#S
|/:*
[Llz
T&"Q
o7cv
dNyd
jp ~
8+ R
A~;%n!
A0.B
$60Z
h*2n
L50mA,
*Q][
mzFjZ
&T,n
0TNt
1%3L
9;U)
7=n`x
Z<^S
@&3M Rb
L*&I~
::s>m/
ecRz
C%h6
kV5t
2D9m
!`wS
Bfim
Ff9@;
M |l
uE{_
&-k
c%+`
CVO&$v
G+Af
[ppi
2lo{x
gz|"x
$Fo#.
z{11
{bNN%
:.]6
#KcgI
0r|_o
pj6<"
r$M
k*dHq
#!3k-
GoS~ p^
H 4N
TC{VG
hiD+8
]8i9$
uV2!
_ubj
''bY
cN$n0
<6JF
?+qe]fx
! P#
p,@2
GR<+ \
b .6%[
x%!
w01:7K
>I!`WR
$?"V
h~o7
*r/-
+HuB
<Sb#
Atpk
kba
t!r{/g6>
J@5G
djp-PC
Ura
)"iX
4hHg
DfK8
P,;,
Q8w/
?sL\
?#&]
K!<^
_OX3
7!f
2o;@
v2.0.50727
coe[
!=:X
{5[C
=<2!1G(7
)P6M
Hxr9
GHJGx
X lY
1{W[
>6\y
84SF
kag
|\ E`
H(ml
F'&L
vh`
o Dkga
SkO0x
2 SbG
g3V0
,{H&
,I|
GOx%Fp_
K_Hs
.kc
?Tu7
KcBR
lF)^F
Wx8I
_9)G|
wtxjK\
yx:*
c]2l
CRD
I6un
?$O\
7d Y(mW*
;$[>
SymmetricAlgorithm
3/!fX+
9rrlhd2
Z7M{
hy?vM
`VgD
e8/*
o Fu@
(qTJ
0v.Ey2
sO)\>
TYtz
-]Z$}
1agr[
Y]_V
BVWbH
7oy
fZ5/
G>NK
<tw,
O b=+
;?~'A
Ne1F
uH:a
Y@C;
2H_P
&0:,
9h6\
B@,V+
#^5F
GX15
J}0q
}%{8g
\ES%
vuh
ZA
/\*b
qm[6
pn62
(6Um
F^_
jGOfB
z\ "
QU oM~6
;.EQ
v-LG
DPT4
!J!Y-d
*r^C
Q6"P&@
[]YII
'(JZ
+p)vVM
l=sD_
iZK}
3..!
_A#g
_teY
cRQ,
)&%?;O
N.+;
!XpJJJRl3uTEDKl9RPbKVUvactcqG7BXVU
[; ]J
B!&[u
Z[
v_}xa
*y.b
L4p
z#i/
;+:>8
lrQA
jc./
|s-Mr7
'3Nz
}.K#
d.c8QO
&&8;b d
Q8E}
)DLA
f%?&
v}yAo
%$((K
#1N;$
hig2t
LnR~
E?=i/
j PH
TransformFinalBlock
,B%
)T<c
eV#?
R^&\
3jx
Fk.Y
DN0Q
0F ,
z52
OMzY
(bm{
Qe. :
Q{~,
Lk. [
C??w
j3%$
$NS]l
1T=L
-h|"
Y>&
=bnt*
hh^u
\ierTs
O@Fy
%Y#x
O7B^}
yD"Z
|vYw
gf)B-
(Svz
{,gH
EG; bi
e6<|
i$}C
4\[}(F
QH(=
>j5~8
}-EU
%L,U
1yrd~
oea~d
A wD5+
]4&jR
j+>YL
Isf
>YEJ
-cZk
o30N
t'4.
eJ 62
BnS-
OA=v.`mCP
3PYr
WoJm
6+eH
oF*
A!u!}`
5 +5#
n/4+
66m
b?6v
vf^x
\Z[
M& ?=$
gd/S
2 =[
\d%
-YT@#
9&dGu
H:PE
roFg
~}b'
$*K(
!{-
a`|
|`V1c`*
ySYb
tq\"
Hq=.
I+=7
Ur~
oW`r
Ydp(e
H#N
2S`QD9
B%[@
ER-hO
M=}vF:
UI9M3
,^P
AQj6
}T#
B4m X
}(B6
5DQ0
:02I
$?d|bT
hH:F
Y6Bd
ikp0T
\\[a|
^ M5
KaHX$#
9,0'
gC;CR
ngh\
/wby
pY`i
aM3G2
VKOY
7 >3
65lY
%~&\
0xTetk09Sv93jS0FklkmX66
TW.0Y
D<!%
KefL
DJ:-
sM2W
qOY|
vFcU
Yud#
X!
0p3<
"*K
DIi3
6c_X
Npr{
j~wd
E,CgeB
nYuq
9)=U
n5OqR
9{=Ij
k.M4q
hm9Xq|F
!@K%=4m9`r
gs_hY
P_C\
UnGq9
5B;|
uWtj
'%%}
zPi~
q;o
yy`K
C$lJ
+-z-
U 5e
Nv)/
xSS|
]U D
YP}8ug
E:Ib
#vN[
-*y
@c29
nz5}S
R*C2gp
d tg+
I~8|\
n0~^|
r0*
]_D'
vPtV
W`#@
(WU
+5'w
23Kk
^ Lr'#?
_aOe
IS.
iO|t
)~ H
+G!,~
jY+{
yLOM
9EoL
P&os
mD*\
Iexuj
&&ad
WKF9
mI{t
i 0)
@HH|
!K03M
Cz78oIgqy0icWOv0TNOiahqInhJuZpC
)$R7@
))-FQ
2zoR
lrz,
}X_S
~-T_Y
l5Lu
@<<r
paY5
EQ{V
loW\g
AK=W
0 LT@
\OH0
8<bOJ
=){QO
NZ_c
hc_e
4N})
g$2
9{W3
vpxj! (
d) |4i
w.ua
.(u&
qfrXH
}>7{
J,0P
J)@
zZxA
!Jj
u=GT
Tn>h
XZ/8
.^?u
f]ewS
xKC8
E;rM
/FCk
%vQX
CpmE
6_2%
x]3O kF/
2jY,
_g; O
TC|Y
2>P L
! [#
@q"1
p6zU
a <H
A[ t[
Y$T~
$};g
2G8"
)bb12S
Sh.F
^B;
,rq'
ch[ae
|SK41
oeRK
vHHj<
:p,D
hO8t
5uo?9
Q8h
\/>[
3%3ng
p'rq
m Ue
>>1
M0TL
F'>{KHx
d<~j
ZLgX3
N8
Q/.h
DateTime
m18Ea
ePHC
|T42 n
v1J=
.=kDk
t y
aNug
#C^\^
Mu. 0
%|'h
mPxK
BB@,f
qCsp
f"M*{ee
R<Lc
:2?*
9"]K9
QIis
wh!C
[S/rH
k`my
//"9Ct3l
"]Fv#
f2po
x~y N@
^uNy
WB_ <y
D&STcLB
G*"Q
}ss|9Iya
sr$2,x
aET
2Dq
N(;/
3}xn4`
z6pM
u07H
W9v<OL
}t2_
'Zm^QZ
QIm}
VsSv
dG#[:{
,X{H
*irb
%R=;
At:R
=i$pQZ
24RNW
@_PZ
6z9gxohd5cUOKbZ6xc4bur6d
YFw\
+MDN
evEse
pwtgzj
ufH*|
tdNkgs
k ]B
x[[w
IB3f|}
zq@/
aO021T"
v%n8
#PMZSr?W
g[B
u/B}'I
B,<"
#-89
$|bRJ
;hIg
A.JI
#YRvx
U&B1
Ps M
0ZS=
)LUl
vi.#
M.?1R
RKbp
mm(
.%!
,s'R
2`}k3
MOGb7F8-
9iRh#A
21;<
l!j+
lOgr
*+V^M
Q^A<
g; H
nUC F
rbzCSu6
"?g=
hK?G*
:`n}
g,P#e
?j9OM
jp#
o'QjL%
JZC'
~Rh%
QmfL7m0O7cMI7JnzaWn0LpltUsSb3LLY
Qm&=D
s}1)
.U~
v\l?H
HL\U
osd
QgAB
K\H
An_y;GN
k9",
e}zN}q
JP m
56yM
u.0w-q
urS6
U9cn
||tYI
RZ ?
8BYT
#I?y
@Iiq
xk\v
p sK*
pj0"t!
JEAJ^
pf)"
7X8.N
x2'9
gT>F1
\B|l
IA&bSgD
hSC_
%d:R.
zkM$
&uG1w
a`]1
~>8kL
6"d\d
\.A=
ccEQ0
K>mi
=/,V
c\unw
F> [
H*ha<I
~\ZO
cu,}0
9W0k
ASB@
&Frqh({
zlSZ<
XbKB
b6b0,!
|Rm
U ?z
j7os
4n2X
J)o+
L*=3
*Y7}A
&]CV
5SKp
y/7
Wo43Bw
}FWL[P
35kA
A)og
9dCZn;}
-]4
@JhB
mLQ?.
":?l
d9tL
@g!8@
+=d
?w#3
d1liO
%H):L
`:$L
lneR
8~2]
p 4f
N\Vz
H&}u
z@Gp
47$<
.J*3
dH5S
`@7{
Bp!/
Dc=0
":+nhSA
kQ&'8Fbo
c >dN
vof-
;+t UC
lZ`fdE
bd&\
xWIa
27tFYIQVXfayzJMYAkcEknhGtdfWEd
)!<D<~%
Oa#Y.sW<
gwRq
bQ3J
|NKe
~Au|:
z/M7
Ii!i
] Rp2
tIaJo
@_K"{
r`2Eov
lh5t
V/G
Z( 96
3M3?sg
k:XX
3rm5
m:#N
R~+e
FQm
m7Ejx.
!]D[e!
Z{#Q
y`#I
TDO$
Of}YA
v*w&Q
w1jP[;
Ll|L
*cOR
Q#'`m
vELL
TI30BHU
1cmZ
Nq]g
Zz,+&
zh.VL
DgtQF
Do1
3=kh
02F))
?rkE
vGYM)
)I=X^
E=9T
Qp33(d
*_(#c
qC!,
{l<#
?vc%
DqvUo
'l59
o0/Nj
"yH
daBuT
"}|a
gyYp
BBqw
?&{3o
N&Z3RN(
!I;h
#hK;8
|j'}
I-gQ
H=_f:
Kq1Y
2`Mq91
|B?h
w!Y_
P%9uKY
Nybr
V*hZ
Y.gm
R_*IY
]&#c
(npj
e/I[
0I&4IHj
K?<>
:~Zs
M+'F
%wc%D|
b(Kp
IZ?O.
hoaC`yK4
vnpJdJ
vr}ch
JL[&
k8Q>C6
?{O@+
r1b-
fpD-i
*}POf
'9#c
mZlC
!f{x^
[9K&
+$r,
:TUwU
;<dI
Srl_+F
;bx
z,!>
b.p%G
~'oz
nM>^
nraA
MrNFe
E_%Y
%6HvMrpuMrekgljP4UIZTmMzsxBb3WPIVCkSOo
]"B6
K Cd
m P
6WLM2
>n<7
a&X4
@4>Z
AW[O
jkS@
+Qk[cJ4
uqt9
6/d`\{
|-1c
""*;
'*+M
<\\9
z(63f%
iRGUmNx
i0+
7mg.
gUi5T
zTQ$
db*f
t0]+
Ba;Y9
Q0E>m
Zkfq
^!Q5<kq>H
C<m%
jPI <
roBmEOfYVbTPGDKVrZIRhp
U\7 B
}ke]
!OR
k~H2
8Xd
mgX=
BOA*
&B ,
wQG).1F
,mUg
(*%S
`rd]
aA{
4(cd
Vb5"7$Xg^S
g~%7
3!d\
o9n-
<fo
}vR2
f zi
<@%"
qLpV
uv" A\
=!o }
!s}<N
N1wQ
"F=T
hv,n
\3)l
Z21}
4'k
pPhufK
\R;/
Ix^
r|?R
hdc?SK
u8 %
e/6
(OV3
K3X>
':+h
@=
&sVlVU56hrVA6W7SIJJ5wqbOi0gGWcJaasLVEo7
Bl0ZRm
{j^o
`JBhV
F`23P
^p0$
jsG%A
Lx5k
Y'!}
us^R
n `Bt
u(YMxN+9n
q68MW
mVx$kO
IW/
it#&
dKc(p^
!Yy2
'+oc
1ZXv
G<|c
zE5g
z_ ;
=JPG
c=\#
20Vk }/
u!hf}m
zX)Ho
@ i2
,W[u
mgpNe
f]E:X
$5q
vbO>
pDN;
?<R]
c=t
ZSH E
/<qT
2~;Ms
_>+9
?xlQ
NCew:q
E;~HN
,wS|f
6@= "b
I2F z
-|;U
xE"|
s )GR
E&)XZ
S2P/+S7
y@>#
D)^
QGwpu
x\Tx
BDp@
b qX}
&&x<
oh,;
x\<L8
%\E/
3MjG
Y3Mc
/tgj
#[d^
8^}+wu
P\G#)
Jj\
3!Aj
OB'2Kz9
)%bM
;#X&
pKL9
e?#7C
zS3
L>uO
GU`$5
V3 1
!vk%O
^(!c
nH x
/#QNW
e1lt
}@Sr
e^=
ek)Lu
lN~8
/Gj?Kl5WQ
q/sNv
E=~
]VcK
;n@e
uV|9
\Naa
t>9|*
A ~*T
.Rq4I
kZ+~a
Y"WiT
<Mi4J
O2[P^
kbpl
tl"v
tE|K
H/ls
a .^#
Z!>i
rw)$6oG
tE|X
QK^Z
Y5=D
nCjA1Q
Yp>.
Dc?]
JnX
H90(
TRY+
+bRL*
={\
)NG7~
A?,B.&
8`|F
GHsX
I2Vj6
get_EntryPoint
&-Al
lIv5
gc:
>>(!
c}])
m's{Q
GNiw
5QrX)
D<%E
Wmlg
m{l,
P%3|uW
n1,t
FJX\
B.}{5
IWQ
O(K7!@y
%d2@
hh-]G>
l\DU
K g`
Dpm2
bLyz
^cx;
@rR0
*#=~H
F)7 Y
;Dac
=.P8 /y
s 67
\(h<]
|6gzm
co:X
jix[
w; Y
!*!w
4<r
neSWyj
kcgn?
V~9c
5a 4
u{ce
M)T3
v804y
c?]/xU
O`l@<
\n{
;AaI
L;0#6
B^Tm
A/g-:
5c6S
,oF9j
I +8<
bAY6e
Nf#,
\hgs
a s4
^m3>j
=<&M
71|$
9~?t
~kHD
.wi0
7?[T*
fg,L
Y.0k
kjIj
YQ}a
AS!
(sX$
9r-;
J $B
Z|)j
#TW-6
mf_P
l|/F#_
//qb!*ld
X `
*I7 yrk
ry`qW
^|)d
gtl?
y"t>
:0ne
9>@F
;4RP
6KYf
^ghmgG
u\ez7
Mn}d
z6~!M]
=Of
25mG
@BV@vl#s
|jzu
9QqEjfi
zV
/V1|
-{5\
h%`<
1Efw
atNU
@64K8
-7"x
W3y>
=qvnt
$9K,
XB+[
+=[
XgzE68H
XveU
4<EU?
Gg31
D0D`/
Bw+
? '`i
T9lz 3m
OLIO
t9_y
0`Tg
kYC}3W3#l
u{iu
EoqL
U{q
)]Ic
U\)ahJ
gF~>
/t-E
:)>2GH
It'l
Gz2=V#}
nPVR
C#Gp
CsaH
Cr
&|;P
#&dv
VUsdz
,9(4#
wM>w`Fxv.Q
<}uz
=i3
#Strings
Fuu>@
YP3"
?*s8@
Ii>t
z89?
jVNQ
4&,L
bh7=
VD0p
HN*W_
%[ V
RHF,m
kxbx
yv$!
)!(F
z[~6
#5ei
{xVVo
Fv.=
W k1
GY.Q
]3)&s
o.,m
aTCtwa0Mpd0rcinsqfjKb9We
iy';
I5vQ
/c*F
l0>5G
oA4~DCq
Z)Ed
cKm
M6'1
ypPS
;@J{
{+XKe
uo|<
PuJ<\
.Oiu
Fj<|
l|8r
?yln
v'1q
54U
Q6AK
9Ve8O
dNOA
d1yI/
eS":
"j1\
_C3
4O cL
E_ (roAw
B(
1I)9e]Z
.SaK
97Y!
(Ml
J8f
3V+;h
<Z XZ
rA0{
xc5Y
|_eK
wN[.
<0 0
YNc'
)qjZ-{Uw
mS "
kW}tT&
(s72
U#v<
.%=b
[waG
9? '
{j@I
bT|'{
C^S]X
mx-s
{R'%
wc^blw
]R%>N
K{d2r
QNvMJ>
WlNB
JWs'
Yuw
;(i=
qpn8
SP=
_EP<
N#w6
7hy)
9W\<
>HSH
t=^w
~ert8
WPiO
jyk
t"3
W]6i
a"y&C
,=u5(
|s2Y)
6:Gi?v
wDGG
(f+;)
i:$kk
?Lb
SN{sC
4d.vFF
7xll
g[Gg
ra3$aj.
& !e
V~F@
=_T
?.3!
&J')'
ZX(%
yV-(W
;/l
k)lH
^HX|
> 6H
UyfVrt
q]RU
62U<F
FP/=
bPIO
c"o6
u \4
!bOo~
E[R!
\s)Dj
[+xf
PE]aW
Qt9
!^/K
s%K
s{u#Q.
*I6
hE58
Dl,[
`I:9
SW-N
T<Q4
}N$.
!!`|
w1}/J
hk6$
MRVL
qnc&
m=TMrb
]OIH
3:5O
RqQS>
][9t
\b
$dG ,
Sf7fb
i}o1g
;.w*
#_nW
*" &
W!:~_@}
-?>3E}*6
>E|y
##OH
,7Tc
%ah
a/W
Wfb!BQ
qpM|
3]\-P=
g 8v
1Y6;N
5 eg
0*2=5w
K#w_}
B&o7
p vQ
,zCJ
m>$A
o+D
J\'0
}m>a9
us}_
]"2}iK'
:u]a
;bD0
fSn+
,5%*
.P:U
55t
2<A(
~l2%O
C[Ss
sC+q
/ MPnX
!9u)
<-LN
JR'-
6OFo
Yy N(
q7l8C
A@p@
i%3K
Lt[p
!e=
4%~|
6 V
^c~4
(rT7
i 9V9^,
{z(E
W._z
].7O
^s}4
'l$|2
evnL
O4uV
}+l2b
6;Py
Ivk~.tu
]$eC
zz{(;V
}Lp<@
kpUl
!1 ]%
4\vF
#]eQl
HSOF
FU VG}
OglA
F.2L
b<F}
%;-+e
YZ-u
,Fs5
dA+lC
1_%b%
d\5hT
K=}4
sR;X
0tjE
([SR
Q.
}v;3
;|&&
+!!Y
Q)oCqR<z(5
m89d
49B0
$*/
!)u=
*>U}?
IPL=
3Z`{
(rRlMs%
<f#r
8> o
dy-j
&9,1H
v6]y
dds
51$L,Z
D}bs
wvdT
Zm{v,R
j{3\
,G dc
KRFm7
$k/I
/n#=
!4(*
$MpXV
\(l
N*~YU
DVV
+QF*
q0L%
yzG
^Kr),
Xsdb
sKFN
8jxE.$
aJU O
_>@_
9ged
&x;R[
P G$
n2AJ
-_DW
8%[H
HgoH
DqDK0
Ox&vm
Wz~xu+K
Tf]q
hePr'
zn0;d3
.f{
= /l
)Cvu
?^,y
3)xO
QiBX
3t~,
:P4+
1`Tb$
B/b\
PW|K
Bh/%&
7h?P
c ;% `
&Y58
l`,'
Rl+
aC#Y}
[5>[
o5 O3
g\;r
RB/%
46!#
nXhZcOIf3JwTw25E6JcxO8lKlSV
(cCp
tW]\9
j5hK>
A&Ork
Eq?{@
x|,+
$'Jsu
(Fs + 5M
|S{Z
zLRU'-
^73b
(sq|_
~t7f^
##(h
a6<.
Q d/B
j7m%n(
+1i
"'/d
rW:[
'3v]
@(V8
#q}l
]F_x
,~(*
P>,V
IgkY
V8G\6
!5A!
Q)@"
R+(O^
^Q;D
yjHfLm3wjkWGpSkAiSRhwFQZzQ
C4R2
V)=p)
rJ5F
C(m8Q
Xr'cN
n5:I[O
g{e@Q?U
ty\5
"v3Vj
*%`x
LZJe
FLY>
wWC|Ue
R$LC?
;b[\
)sS"L
gE0-
c*3i
^7}SM
}r"
d;nr
VF
P"\ix
L;+'k
Hpg}
8@GK
7+mN
SCbV
})3
`.UB
s\f~7
k>[v
Cg$O
qT.0r-_d
}\do
9-l2
s9x#qT
Fv h
*5-0
0qb=j
[\i~f7;
E'bR
" =*
KC0v
y\::
Mkd
TrZs
,'J
L.n?
B*D$E
fOW-Q
<H G H
Z\Qo
5z_OKK+
-8u
Z{ eu
aL1g-
' U)
CLBt
sU5o
?2&Yt
Q0+D~
i0 #
y+a l
A|u`
*JMF
dIs(
u?,t
! VI-
09B-
vqzD
bB0[
Pyg3t
J3{c
^`:l
Lgt487
FnC
0;Q#
CG%3
zPBp
l<cE
I'$a;AXUK
6)l|3
jbl\
)08}
"9Gy
KX~O
gP"Y
w0WG
oc>)m8r
e hHP
+ S5Y
O0,0
kP?f
5kc`s
"e#UN
y2n8
[ q3
rA:B!
8!}u
h.7e0
plpFOh
|DfVb
" !z
t\v;
,SL.0l
6X;U
AddRange
).R2
Ve/0K
cSyh
RKu4+
Jb}a
oZ0k&
T9{)oT
$h(6
|N v
8]wG
v&z5
Zx\*
`;iAwu
vuT_\W(M
o'C:$Z
8-vr
j8C(
ZY)F$B
j8 T
;bF]
0ghd
Kbd-
_w2>>9
fHu#
|)$+
b"?7
|%,Ec=
Wiw^.
j@{L
>zlE
9]V*8N
+2:a-
%* o4$#~9
,n>sM
*{#W(
(ZVL
~'v{
dD^i
rVD+
fjjE
aCB
/o.=ZXn
;ngx
SJqR
=?'/B
.Q{)
lp;@n
)VmM
9_VZ
h,s(
K 2
F%H?`V
s4f.
&n{rv
*kw\$
"/U~
EXl.
%Ju\
U%GJo
<TEq
D:_l
~BDmH?
7r>T
9\Jl
Z09
$wRz(
Veh
X^{)?
itTh%\
SORn6
M lv
Nh1+
kK`q
>* '
?5aLf
|gux
p .$
,^R*
\\!#+
Qs[P}
U4sN
Z.wg
K4?,
~/tY 4
WCv
= _cW
sJ=
lj)'
W/aW
sSNTKc
V8 i
ct+#
+d?i`
g#IZ,
]5G
c:}S
ozZ~.
C{X
#q-[~
ouRv
3#mJ
JL(j
1AfL
>{aXE
,JNj,
6~8G3
0-I{
5L*w
s}B><7I
~|9yj83
g uJ
XQ/#oW
M}l|R
xwXk
5FrM
@WBS?
{*hbp
,bk$z
C#o
1&Ak
yfnf
kl?*
Vj$W
shGq
>xsU
TWM/
5(ub
Mx@
Yk!prh
W&l}
cfC.
suD
S, 9.
]u%;=
|*xL
;%#d
3V-z
?i*7o
Ka7b
*[L*
O`("
kr
z7ySA
kd`eL
on)
>V}
%{_q
HL`N
I}e"
&&Yz^
Gd5B
get_Message
d2>1y
^88q
~)SJ
P *g
^w-7b
fA~p
(@#a
6F}=
|Ui&j
ax{5
a1_<
rO $WOnP]*
}(#hd
I6=E
bC<"
sFZyeE
sx9#
T>7;
] {2
F?\a
70!W
.>J>
nvHJ
BDYb
_^y(
Z )#JV
bF^?
2@w("
i8!;
fe{qG{
$<\WC8
GUy>
^c_
A| U@
qE2tq
D{#
4d#G
-p d`
w,g
g/;<
eMF5 s
:eN*]
V A_,YD
u#]w
B@%o
ss)PT
!yn<
BSJB
A7
2LNhD.
_rw0
9uFq
U!|S
Oy!R
!Zs&
2?ZJ
,aKF
bB-h
q7@1
m7uQ
\y#U
O)uo
G6%>
=u}}:Y
&6QC
PbAH[A
(Zs,
S-sp
p\-kI
rP7v
brB3\;
A/M
M]4d
rW8Z
?A7?
|n'
{xLC(P
J(j"
/3_T
gxw7
,A7I`
IG_"
wt3U{C
4%CaY
wR;S
C oF\
x@9-tGd
~R~;g
M8TwqG
,]l4
KKrHc/i^
h*~u
#<Y\
!;lZv*.
(h4'
+c+0
L7x0
A{>|T7H
?66.}
,FcN\
\E;t}
k7=
)\\z
_9C@
n)M"
#J'
Q) F
+\0g
H,3$e
t.nr
|<9G
Ld-+
~.2j
7~ w
ypCA
/P[<,
QSG
`3Sac
@i9:N
+Z{
'>bO
P&X
0wcA
YWV>&
&NH3
U15|
$ut!
IL%Zq
)U#Y
'7P.
D2%p
Jkl'A}J$ 1
Dj5
=4PoX
2j&qzs
S@:N
v\Nc
9I_hr
ARR&
[d`<
|meN
c`(V\/{
JH*u
~BO>
G3A
"js .{
()@!{
#A\s
p}39
[8}s
nSBiB]
Z'H~KU
O\0]
)*qw
'u<Dm
NLsW-U#
P<d>trMF
#ovcJ7
g90 L
r6^YM
/v5J/h
59Dy
<Mmw
7N3v
L:Ci
"V12
zw
SW2F
ujSK
^ y
i+@ =
S&>8C
$eea
wZlo
> vC
6g(H
sDEs
IAr5
]FZ^
T cx/y}
lFO|}
_;xq
?njZ
Z\E^-7
GtYu
TIe5w
~=/L
7q^E
)0g~
yhSg
zt`x
5~1&
X(LCj
PXw
G)rW
&GlK
eT-#g
@E05
%w,j{
Y0;
z_k8
4JkY
j WUP
yqv}uv
GKK!
/uB
c3g^
4! Z
Gl@m
n\<Y
E+ J
kIJ
R (7
#fIA;
tod_
Ks~O
I)6+
GetObject
hdxhU
j1516
`! ~
Up*{S
;g>\D(
Hzr:w
|,CB
p_,m
[-l*H
]#'"J3W
Xn*>
rz!_
1@Cu}
-v\B
IO*}
hh%G
Ew]zGk
2}qU
p%5x
6YwR
P}w3fM
-HTf
;/XN
0~?
Y0\fu
ZJ)}
hQ*.
:/lt4
nvpVk
Md{
o_&n
E~]M
-zXt6`
R {|
S{b{7wI
dm F
k<s:
Iqr~x
5tOp=
RTZEqGqCkbrBLsfVt0bbTPHfVMT
FSK~b5S"
KRb}PZ
n@@LF
zTDx
zwdfG
/wt2
1Z `
O}'H4
<_cu
YX76
Qp*r
~OC5
$I(7
m U
..-l
L}M;
#z1s
X/46
zfjOHv
$ m'
MDuZ
(f-'
`b)
(? X
IP4|Z
v&e}M
s0(f
yw |
%)#
2(TbE
[ nB
"8b&
~Ws'
`$13
j23E
;y/r8=
@93-
*=JC
.JhO*s6A
Il$|/
8&IW&[
7!}(k
-f<x
[">p"
VX1{?
vKVv
Z0?b
SK&$!
f_W
GmzH
JF9l
K :C
f[mL
B9U7
!jUb
: |&^0
,E?
'aQ>8
5!ij
eF[Xu
^rZ8
6i,GU
}#
s?r)
*%Ib
y L20H
HK~n'D"l
oy/)
= -v
4 SO
XkK[
ux`r=2
gnI1
[CbF
CsSEx-7
QVNi
evW;co
6'O[
= xc
/Vrq/
o>~
##S{y
#O:v
mT#&
=%UB
tyux
\sM_
}L-&
*~
}I s
fE\T
, bFW6
%U3R
*bUD
/wYYt
rE@i
.2 ?=
WCxHl
>Q96
!Z.X
D<9
"vbk
2PHQ
s_s9}
n,C6
#0ksqFEy04bPdNkNNzKwoEsIYA15Mdy685RN
D0,/
tbl"
}.|2(
#5>O?
#Aq1
R?@e
9y?n
T3w8
\>"<N
JsO(
{dAiek
PcfJ|
UAE#Y
Po |
./dCl
N%*=
|C7pt
2Y
YejL
VM0<1?a
2#>]R
:gjg
M Z*y
G=x=!
N,&Aj
VQvS
N\P)
BWye
10BFR
uYm}
n!r3}
i{QQ3
=1yV
W/@j
&68N
a]8gz
(pa
Sd;br
,3>u
3{$c
mC*
M +[n.{
3qcV<
odfVwn<
# HM
|:X!
XW
e$XX`?
+~"c
<V=)
^)9:t
%BLg
}'K~
)X:p
^aSs
|PS.
@=v]
Yad_(n2}"
A ]<`%
Load
Mq8K
YPN2
6MGZTg
&6Ss
_]Is
2:%J
\L6D
yW Vs
`(JuW(
g0gJ
TA{&`J
\ Oy
>#8^
N7MB
&dInhaTgbJYrDTQIN3hGnouMbuKyKFu2oBkiA07
UYjHI
MLSa`f
5<;ck
}-Z
u)8_
J*%4
uJ-,
1o
LZNy
yi+!
Nm9 b8
MK<X
DbR.>
x^q1$
h.nr]
bdKL
#efG
+eS>
[ t
jwg<
O4!w9n
B-WqM
x<9_
pk+_
<SS2`fN
S5Il~
q^^N
#OZ^J
Fhu#
n7_SmB
-k{nl0
d7{X3G
#; n
> +M{
rwG2
"50@
.YT&
5bZe
jP_'
Object
P-4qb
3bb
*5DR
g*>11
#w,w~
ez>X/o#r~
2O$N
iF
1_WM
auc:\
(g3[
vsGUG
b%,2
O` S
dx~{^f\e
0Nqm
5;7%qm
l1Al
QZm2
YCGUM@
@c#a
cC~ g
*(b[
WZ/Za
!|kM
;9iS
}`V^
V2`~B
8)a
/#gd>
sdZINw
/3mt5
mK Y
qg*L
2,D:"
py*N
Nfc+
*Zf
\'3w#
y!_8
/w9L]
r,!`d
-V0>
N =%zr
%;~
?,u
1$\rZ.
:';RuD
OrjKb
t?F'
]7{|4
m@d 3
1%=Y
&z3BM
"#ui
;} E
VF@)
$4XpSTOEvcYw0j3cKzUC9d3n9Qjs01lRngquQ
#crx
OuNX
S,Va[)
^~Y|>P
*I>@
i4oZq
[eXi
D6P?|c
NokN
${Xt
%1X+
.}7o
Fjq>*
F)J
w(#q
q0gR
FhgW
^Rp?
A>.
X_L!#
vO8r
x/E:
/wY"
/Qee@
8EM3
hU?G
!gFC
goX3
h~|y
wV5MF,
{u5.
}78aE4{x
7A=;
KK@t;
M&Cd>
C9ZA
lb9
vlmi
Lb77
C30r
P+vjj
v+\I(v2
.g_:
Ho
e=*P
UI=]D
C*'k
W\xQ
T}CI
fP(Jk
[Yo_:
]=qt
CGk
vu?
= F0
3irIk
|b:
C^:T
QM-1
K$@
s:xN
r@s*
50BW
=Sugr[
N(*@
^p?hb-
~EyC+
q-/
L=2$
a )h
] w
miv/
'}M[
11[
:9&)~V!
)I]A
?,PE
Tah3j@+
% ;c4
rK`
)a:
_M}?{
P2 qs
0$#?z
(E#t
L_500
f+Bvm3
y7;M
z3kz
-1Cj
A1]n
*CrE
DF@
5SeX
g|/?
%Zro
Y>\_,}
EiftX0
w^\
(,P{
<`5
A:w;
m(7c
lE5l
T ^<
Cqzw
{}M-
`jrC
L3VTLr
/cj3
2`-Y
0 ~8
,;
Ck8Y
V/9b
+n9j
y(rB
L8boN0
4=@P
ts}+
ge:Z
`G+>
"PMK
c3qPM
O<1<-
`+4t
`Cet
pa8V
u:/
2Ub`
f`+5
gL)_ _G
09dWg
J^^yn8
S4 L?
.%Kd
8bWR(
otM
n>?:D
& s0
>+uj
&Sr6
CNUo
gi \
Ntgv
|$r0`L
/X(N
.elu
9:D4
nW$A
?!2i
L'Q.
0H\^
b9U
xH%
OL2+-zT
"mF4
=C
Qy]{
-v0T
/ 8E
AcZUK
}B="
FsH\2
"hB{
v[7X
RRS0
b`XQ
SERVER1
XHgWm
5z]4<Q
X Jn+Eu
kcg[
$h6{g
zj ^
jRu7
gjbyY
w7VA
Q{4'
j@8*
A9x;
zA\j
2s{L
>rI}#c
GetTypeFromHandle
xTF*
em%S
Jezg
t|.;w
af7e
F22%
e&zS-}
&a6 ?
ZS|U
x?Cb
#>&>
yJq$
1>k_j+
i%XJB)
xKUX+
LqTk
1*&~
<t'C
83YFk
.6!e
jO#,
3*X:
Wt6+
P0g
L`MD
9yXY9
UPq:
ySJ.
h[vT
038&
C2zF
SfD#
secO:
>*n|
v8d^
c\[J1
?+/U.
[ n(
iOwSdt2
d$j+
'-3CT]`
!Rx,@
M)DzA=
IEybn
JD=4V
Ck,
WQeW
;bQU
A};6
2vE>?
;?px
zd[H
Qt<pZs
{BI3
c[u]P
e}W<
AI$!
System.Runtime.CompilerServices
yd{H
DVu%
4Y,S{.
n{O 6
R^ok
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
RFqq?3
RNq
4 `p*
U~u(
]Vh#T
P40V[
L9Ns
$cXZ0$XL
1Rf+
.l~4XOf
OamS
f_C;/
H- !
#z}U
R&=z
ta9M
6~!p
;pT-
V Zl
^XWX
}P3cj^
%G"p
]:@$
?n Su
=Jt;
{O\vO
X,F=
\Vp.e/K
b XPR
v"O$
d/r;
q~ ,
$\.l
" v;
Ys{f
*$@K
q$Uv
/2 Jt
"8u.
2AU lYN
M6P
w7KE
BK*v
_8Q
%Ei@
R6VJ
_<Km
J6+~
|$Mg
SWP]
0Oo
+T+
htH3
4N\zNt
ovvPu6
#qK2
&iR
xQ#sou
]'IBX
=tO]
t.;DI8!
G{od
51(q
s>V9
#Tqg8+
54%
g+D"
uS>a
PgBe
aB6\[
57)
F Dq
rS;Y
CnS9,
^#<W
/#[_
Y<$
&rRm
V5Q+o9
w~a0
Ag%)'3
R7BhD
%kHi.O
Tc>}
:|/vM
Ndo]2
~2yCb
8\Q/
p1Rs(
pD6Sl
6vf1W2
)Qc
(]fx
\]3
7}vW
m{V
0s6)
X+,a+V
&r9;Ah
A 2*
VITFSQSkxRK29ZuvSCfGJBzMYjrp
]$yZ
xS %
; E
&fs$
Xi ,m
$\KD
(T0
Wr#@
k_34r
%l53+
`kaX
6s 6_r=
l\#,
E5DnZ76
yhY:p
wrN s
90a%
3#F'?uQ
RktT
%iK~'xK
x; ,$Z
y.Cj
uvUE
X$=@C2V
z4>_%
jH](
GeSG]3
="x`~
uIY6&xb
1fg7v
18OPD
3}"S@3
}6kd'
) <FES
~G*(
L`*
oH/e
IEnumerable`1
HWc(
TH=*
EtJ)
fwJt*
@rPb^x)1
P?.j
SyW+
<<W[
)6tO
#l'O
<Jcjbs
@CC"
OL+:W
JYxOh
pr}zo:
enul
\(EEJ
J>C=
,gHr
x !
sXM2
>Ni{
4uAcG
l&JJd
7f7E
RMJdGmM?
>2C&
2-w`
~ wK
IS:_
C\bP
+!<6'
1P
b2"r
e' y
R-L!b,YNjI
EE/
{*3}
o`}]1n%
SL0pS
;'6lv*,
W5x b<
F\I^
%n$)' t
u <Z
y=7Z
Rz*%
3cNK
BZ5wj
,a v
System.Collections.Generic
z&7y
45vU
wx?p&
zycK
PX w:
`;?,
#I02
WPM{_
>hMI>
.&pC
4IBi-A
5/29
Bo~,
.:xDCH
EkRx3
4tqzS
T-yl
zL2@
jvd
gu<
~neq
AmR.p
C$F
y= 2p!
6<ZJ
~wf\H
PTCEMk
3 ]r
pIkr
Y*g_
+[6#
'*>6T}
.=s&O
C8<
i=Ej
ow8k
i\*j
.n:|B
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven06_64 | Seven06_64 | VirtualBox | 2018-06-25 08:45:49 | 2018-06-25 08:48:52 | 183 |
27 Behaviors detected by system signatures
Attempts to modify Explorer settings to prevent hidden files from being displayed
Severity: High
Confidence: Very High
Attempts to repeatedly call a single API many times in order to delay analysis time
Severity: High
Confidence: Very High
- Spam: services.exe (492) called API GetSystemTimeAsFileTime 1016423 times
Exhibits behavior characteristics of HawkEye keylogger.
Severity: High
Confidence: Very High
Steals private information from local Internet browsers
Severity: High
Confidence: Low
- file: C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
Installs itself for autorun at Windows startup
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Windows Update
- data: C:\Users\Seven01\AppData\Roaming\WindowsUpdate.exe
Retrieves Windows ProductID, probably to fingerprint the sandbox
Severity: High
Confidence: Very High
Checks the system manufacturer, likely for anti-virtualization
Severity: High
Confidence: Very High
Creates a copy of itself
Severity: High
Confidence: Very High
- copy: C:\Users\Seven01\AppData\Roaming\Windows Update.exe
- copy: C:\Users\Seven01\AppData\Roaming\WindowsUpdate.exe
Attempts to access Bitcoin/ALTCoin wallets
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\bitcoin\wallet.dat
- file: C:\Users\Seven01\AppData\Roaming\bitcoin\wallet.dat
Harvests information related to installed instant messenger clients
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.oeaccount
- file: C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.*
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User
- key: HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
- key: HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts
- key: HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Internet Account Manager\Accounts
Collects information to fingerprint the system
Severity: High
Confidence: High
Queries information on disks, possibly for anti-virtualization
Severity: High
Confidence: Very High
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: Windows Update.exe(2788) -> vbc.exe(1056)
Sniffs keystrokes
Severity: High
Confidence: Very High
- SetWindowsHookExA: Process: Windows Update.exe(2788)
Deletes its original binary from disk
Severity: High
Confidence: Very High
Creates RWX memory
Severity: Medium
Confidence: Medium
A process attempted to delay the analysis task.
Severity: Medium
Confidence: Very High
- Process: Windows Update.exe tried to sleep 1505 seconds, actually delayed analysis time by 0 seconds
- Process: sppsvc.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds
At least one IP Address, Domain, or File Name was found in a crypto call
Severity: Medium
Confidence: Very High
- ioc: z.4f
Starts servers listening on 127.0.0.1:0
Severity: Medium
Confidence: Very High
Drops a binary and executes it
Severity: Medium
Confidence: Medium
- binary: C:\Users\Seven01\AppData\Roaming\Windows Update.exe
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- get_no_useragent: HTTP traffic contains a GET request with no user-agent header
- suspicious_request: http://whatismyipaddress.com/
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0009fe00, virtual_size: 0x0009fc04
Looks up the external IP address
Severity: Medium
Confidence: Very High
- domain: whatismyipaddress.com
Attempts to connect to a dead IP:Port (1 unique times)
Severity: Low
Confidence: Very High
- IP: 192.168.56.1:80
At least one process apparently crashed during execution
Severity: Low
Confidence: Very High
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven06_64 | Seven06_64 | VirtualBox | 2018-06-25 08:45:49 | 2018-06-25 08:48:52 | 183 |
11 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\SERVER1.exe.config C:\Users\Seven01\AppData\Local\Temp\SERVER1.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Local\Temp\SERVER1.exe.Local\ C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows C:\Windows\winsxs C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\System32\l_intl.nls C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll \Device\KsecDD C:\Users\Seven01\AppData\Local\Temp\SERVER1.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI C:\Windows\System32\tzres.dll C:\Windows\Globalization\it-it.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Users\Seven01\AppData\Local\Temp\it-IT\SERVER1.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\SERVER1.resources\SERVER1.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\SERVER1.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\SERVER1.resources\SERVER1.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\Globalization\it.nlp C:\Users\Seven01\AppData\Local\Temp\it\SERVER1.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\SERVER1.resources\SERVER1.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\SERVER1.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\SERVER1.resources\SERVER1.resources.exe C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll C:\Windows\Globalization\en-us.nlp C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5cae93d923c8378370758489e5535820\System.Runtime.Remoting.ni.dll C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI C:\Windows\Globalization\en.nlp C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.resources\Microsoft.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\Microsoft.resources\Microsoft.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\Microsoft.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\Microsoft.resources\Microsoft.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\Microsoft.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\Microsoft.resources\Microsoft.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT C:\Windows\Fonts\ahronbd.ttf C:\Windows\Fonts\tahoma.ttf C:\Windows\Fonts\msjh.ttf C:\Windows\Fonts\msyh.ttf C:\Windows\Fonts\malgun.ttf C:\Windows\Fonts\micross.ttf C:\Windows\Fonts\segoeui.ttf C:\Windows\Fonts\staticcache.dat C:\Users\Seven01\AppData\Local\Temp\SysInfo.txt C:\Users\Seven01\AppData\Roaming\Windows Update.exe C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll \??\MountPointManager C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2548.1240203 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2548.1240203 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2548.1240234 C:\Users\Seven01\AppData\Roaming\Windows Update.exe.config C:\Users\Seven01\AppData\Roaming\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Roaming\Windows Update.exe.Local\ C:\Users\Seven01\AppData\Roaming C:\Users\Seven01\AppData\Roaming\Windows Update.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG C:\Users\Seven01\AppData\Roaming\it-IT\SERVER1.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\SERVER1.resources\SERVER1.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\SERVER1.resources.exe C:\Users\Seven01\AppData\Roaming\it-IT\SERVER1.resources\SERVER1.resources.exe C:\Users\Seven01\AppData\Roaming\it\SERVER1.resources.dll C:\Users\Seven01\AppData\Roaming\it\SERVER1.resources\SERVER1.resources.dll C:\Users\Seven01\AppData\Roaming\it\SERVER1.resources.exe C:\Users\Seven01\AppData\Roaming\it\SERVER1.resources\SERVER1.resources.exe C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Windows\assembly C:\Windows\assembly\GAC_MSIL C:\Users\Seven01\AppData\Roaming\RunPEDll.dll C:\Users\Seven01\AppData\Roaming\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Roaming\RunPEDll.exe C:\Users\Seven01\AppData\Roaming\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Roaming\it\stub.resources.dll C:\Users\Seven01\AppData\Roaming\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Roaming\it\stub.resources.exe C:\Users\Seven01\AppData\Roaming\it\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Roaming\it-IT\Microsoft.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\Microsoft.resources\Microsoft.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\Microsoft.resources.exe C:\Users\Seven01\AppData\Roaming\it-IT\Microsoft.resources\Microsoft.resources.exe C:\Users\Seven01\AppData\Roaming\it\Microsoft.resources.dll C:\Users\Seven01\AppData\Roaming\it\Microsoft.resources\Microsoft.resources.dll C:\Users\Seven01\AppData\Roaming\it\Microsoft.resources.exe C:\Users\Seven01\AppData\Roaming\it\Microsoft.resources\Microsoft.resources.exe C:\Users\Seven01\AppData\Roaming\pid.txt C:\Users\Seven01\AppData\Roaming\pidloc.txt C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll C:\Users\Seven01\AppData\Local\Temp\26 C:\Users\Seven01\AppData\Local\Temp\28 C:\Users\Seven01\AppData\Local\Temp\ C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll C:\Users\Seven01\AppData\Roaming\WindowsUpdate.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe C:\Users\Seven01\AppData\Local\Temp\holdermail.txt C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll C:\Windows\assembly\GAC_32\System.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\System.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Roaming\it-IT\System.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\System.resources\System.resources.dll C:\Users\Seven01\AppData\Roaming\it-IT\System.resources.exe C:\Users\Seven01\AppData\Roaming\it-IT\System.resources\System.resources.exe C:\Windows\assembly\GAC_32\System.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.INI C:\Users\Seven01\AppData\Roaming\.minecraft\lastlogin C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll C:\Users\Seven01\AppData\Local\Temp\holderwb.txt C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb C:\Windows\symbols\dll\mscorlib.pdb C:\Windows\dll\mscorlib.pdb C:\Windows\mscorlib.pdb C:\Users\Seven01\AppData\Roaming\bitcoin\wallet.dat C:\Windows\sysnative\wbem\WmiPrvSE.exe C:\Windows\inf\hdaudio.inf C:\Windows\sysnative\DriverStore\it-IT\hdaudio.inf_loc C:\Windows\inf\hdaudio.PNF \??\PIPE\samr C:\Windows\sysnative\wbem\repository C:\Windows\sysnative\wbem\Logs C:\Windows\sysnative\wbem\AutoRecover C:\Windows\sysnative\wbem\MOF C:\Windows\sysnative\wbem\repository\INDEX.BTR C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\sysnative\Branding\basebrd\basebrd.dll C:\Windows\Branding\Basebrd\basebrd.dll C: C:\Windows\sysnative\tzres.dll \??\PIPE\wkssvc \??\PIPE\srvsvc C:\DosDevices\pipe\ C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc_lng.ini C:\Users\Seven01\AppData\Roaming\Mozilla\Profiles C:\Users\Seven01\AppData\Roaming\Thunderbird\Profiles C:\Program Files (x86)\Mozilla Thunderbird C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.cfg C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\*.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{31EC9AD6-5786-45DA-B15D-2E72FE116045}.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{52DB1739-8CA0-4C99-9EE7-FE81B5E5749E}.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{B6C15F72-0649-41DF-9EB7-057A27B89428}.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\*.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\new\*.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Backup\new\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Stationery\*.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\Stationery\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Live Mail\*.* C:\Users\Seven01\AppData\Local\Temp\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Cookies\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Cookies\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\History.IE5\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\History\History.IE5\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\4DXYBRDC\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\4DXYBRDC\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\K0BMY8DM\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\K0BMY8DM\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\NSXL8QLO\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\NSXL8QLO\*.* C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\PAJSDO3I\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5\PAJSDO3I\*.* C:\Users\Seven01\AppData\Local\Temp\hsperfdata_Seven01\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\hsperfdata_Seven01\*.* C:\Users\Seven01\AppData\Local\Temp\Low\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\Low\*.* C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_10.0.40219\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010 x64 Redistributable Setup_10.0.40219\*.* C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_10.0.40219\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\Microsoft Visual C++ 2010 x86 Redistributable Setup_10.0.40219\*.* C:\Users\Seven01\AppData\Local\Temp\outlook logging\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\outlook logging\*.* C:\Users\Seven01\AppData\Local\Temp\VBE\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\VBE\*.* C:\Users\Seven01\AppData\Local\Temp\WPDNSE\*.oeaccount C:\Users\Seven01\AppData\Local\Temp\WPDNSE\*.* C:\Windows\System32\it-IT\werui.dll.mui C:\Windows\System32\werui.dll C:\Windows\System32\it-IT\DUser.dll.mui C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui C:\Windows\win.ini C:\Windows\System32\UxTheme.dll.Config C:\Windows\System32\uxtheme.dll C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2 C:\Windows\System32\it-IT\erofflps.txt C:\Users\Seven01\AppData\Local\Temp\WERB05F.tmp C:\Users\Seven01\AppData\Local\Temp\WERB05F.tmp.WERInternalMetadata.xml C:\Windows\System32\drivers\*.mrk C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_* C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_windows update.e_6a23c2b61d598d756a8fa82c78f3e71924d81faa_09900108 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_windows update.e_6a23c2b61d598d756a8fa82c78f3e71924d81faa_09900108\Report.wer C:\Users\Seven01\AppData\Local\Microsoft\Windows C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\*.* C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\WebCache\WebCacheV24.dat C:\Users\Seven01\AppData\Roaming\Mozilla\Profiles\*.* C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\Profiles\*.* C:\Users\Seven01\AppData\Local\Mozilla\Firefox\Profiles\*.* C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\Profiles\*.* C:\Users\Seven01\AppData\Local\Mozilla\SeaMonkey\Profiles\*.* C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini C:\Program Files (x86)\Sea Monkey\nss3.dll C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\*.* C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\*.* C:\Users\Seven01\AppData\Roaming\Apple Computer\Preferences\keychain.plist C:\Users\Seven01\AppData\Roaming\Opera\Opera\wand.dat C:\Users\Seven01\AppData\Roaming\Opera\Opera7\profile\wand.dat C:\Users\Seven01\AppData\Roaming\Opera\*.* C:\Windows\Temp C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp C:\Windows\ServiceProfiles C:\Windows\ServiceProfiles\LocalService C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp C:\Windows\ServiceProfiles\NetworkService C:\Windows\SysWOW64\winxp\triage.ini C:\Windows\SysWOW64\WINXP C:\Windows\SysWOW64\winext C:\Windows\SysWOW64\winext\arcade C:\Windows\SysWOW64\pri C:\Windows\SysWOW64 C:\Windows\SysWOW64\ C:\ProgramData\Oracle\Java\javapath C:\ProgramData\Oracle\Java\javapath\ C:\Windows\System32 C:\Windows\System32\ C:\Windows\ C:\Windows\System32\wbem C:\Windows\System32\wbem\ C:\Windows\System32\WindowsPowerShell\v1.0 C:\Windows\System32\WindowsPowerShell\v1.0\ C:\Windows\SysWOW64\WINXP\dbghelp.dll C:\Windows\SysWOW64\winext\dbghelp.dll C:\Windows\SysWOW64\winext\arcade\dbghelp.dll C:\Windows\SysWOW64\pri\dbghelp.dll C:\Windows\SysWOW64\dbghelp.dll C:\Windows\SysWOW64\WINXP\ext.dll C:\Windows\SysWOW64\winext\ext.dll C:\Windows\SysWOW64\winext\arcade\ext.dll C:\Windows\SysWOW64\pri\ext.dll C:\Windows\SysWOW64\ext.dll C:\ProgramData\Oracle\Java\javapath\ext.dll C:\Windows\System32\ext.dll C:\Windows\ext.dll C:\Windows\System32\wbem\ext.dll C:\Windows\System32\WindowsPowerShell\v1.0\ext.dll C:\Windows\SysWOW64\WINXP\exts.dll C:\Windows\SysWOW64\winext\exts.dll C:\Windows\SysWOW64\winext\arcade\exts.dll C:\Windows\SysWOW64\pri\exts.dll C:\Windows\SysWOW64\exts.dll C:\ProgramData\Oracle\Java\javapath\exts.dll C:\Windows\System32\exts.dll C:\Windows\exts.dll C:\Windows\System32\wbem\exts.dll C:\Windows\System32\WindowsPowerShell\v1.0\exts.dll C:\Windows\SysWOW64\WINXP\uext.dll C:\Windows\SysWOW64\winext\uext.dll C:\Windows\SysWOW64\winext\arcade\uext.dll C:\Windows\SysWOW64\pri\uext.dll C:\Windows\SysWOW64\uext.dll C:\ProgramData\Oracle\Java\javapath\uext.dll C:\Windows\System32\uext.dll C:\Windows\uext.dll C:\Windows\System32\wbem\uext.dll C:\Windows\System32\WindowsPowerShell\v1.0\uext.dll C:\Windows\SysWOW64\WINXP\ntsdexts.dll C:\Windows\SysWOW64\winext\ntsdexts.dll C:\Windows\SysWOW64\winext\arcade\ntsdexts.dll C:\Windows\SysWOW64\pri\ntsdexts.dll C:\Windows\SysWOW64\ntsdexts.dll C:\ProgramData\Oracle\Java\javapath\ntsdexts.dll C:\Windows\System32\ntsdexts.dll C:\Windows\ntsdexts.dll C:\Windows\System32\wbem\ntsdexts.dll C:\Windows\System32\WindowsPowerShell\v1.0\ntsdexts.dll C:\Windows\SysWOW64\it-IT\werui.dll.mui C:\Windows\SysWOW64\werui.dll C:\Windows\SysWOW64\it-IT\DUser.dll.mui C:\Windows\SysWOW64\WerFault.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\COMCTL32.dll.mui C:\Windows\SysWOW64\UxTheme.dll.Config C:\Windows\SysWOW64\uxtheme.dll C:\Users\Seven01\AppData\Local\Temp\WER1F17.tmp C:\Users\Seven01\AppData\Local\Temp\WER1F17.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Windows Update.e_d443c639c12eb0b78112ebd1db4edd984a4969be_0514c504 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Windows Update.e_d443c639c12eb0b78112ebd1db4edd984a4969be_0514c504\Report.wer C:\ProgramData\Microsoft\Windows\WER\ReportQueue C:\Windows\Microsoft.NET\Framework\v4.0.30319\ndpsetup.bat C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen_service.log C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ndpsetup.bat C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvc.dll C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84\Report.wer C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET C:\Windows\Microsoft.NET\Framework64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319 C:\Windows\sysnative\it-IT\werui.dll.mui C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84 C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84\Report.wer.tmp C:\Windows\sysnative \??\SPDevice C:\Windows\sysnative\spp\plugin-manifests-signed\sppwinob-spp-plugin-manifest-signed.xrm-ms C:\Windows\sysnative\sppwinob.dll C:\Windows\sysnative\spp\plugin-manifests-signed\sppobjs-spp-plugin-manifest-signed.xrm-ms C:\Windows\sysnative\sppobjs.dll C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\ C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat \??\PhysicalDrive0 \??\pci#ven_8086&dev_100e&subsys_001e8086&rev_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{c2d43895-0262-4873-a789-c2f96d24b693} \??\root#*isatap#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{684bb8b6-2793-49a5-8012-e0a941b4b4df} \??\root#*isatap#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{5f6d61d9-d207-449a-bd48-652a5d1f25be} \??\root#ms_agilevpnminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{29898c9d-b0a4-4fef-bdb6-57a562022cee} \??\root#ms_l2tpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{e43d242b-9eab-4626-a952-46649fbb939a} \??\root#ms_ndiswanbh#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanbh \??\root#ms_ndiswanip#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanip \??\root#ms_ndiswanipv6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanipv6 \??\root#ms_pppoeminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8e301a52-affa-4f49-b9ca-c79096a1a056} \??\root#ms_pptpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{df4a9d2c-8742-4eb1-8703-d395c4183f33} \??\root#ms_sstpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{71f897d7-eb7c-4d8d-89db-ac80d9dd2270} \??\root#system#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac \??\sw#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{78032b7e-4968-42d3-9f37-287ea86c0aaa}
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\SERVER1.exe.config C:\Users\Seven01\AppData\Local\Temp\SERVER1.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\System32\l_intl.nls \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\System32\tzres.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5cae93d923c8378370758489e5535820\System.Runtime.Remoting.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT C:\Windows\Fonts\tahoma.ttf C:\Windows\Fonts\msjh.ttf C:\Windows\Fonts\msyh.ttf C:\Windows\Fonts\malgun.ttf C:\Windows\Fonts\micross.ttf C:\Windows\Fonts\segoeui.ttf C:\Windows\Fonts\staticcache.dat C:\Users\Seven01\AppData\Roaming\Windows Update.exe.config C:\Users\Seven01\AppData\Roaming\Windows Update.exe C:\Users\Seven01\AppData\Local\Temp\SysInfo.txt C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Users\Seven01\AppData\Local\Temp\holdermail.txt C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll C:\Users\Seven01\AppData\Local\Temp\holderwb.txt C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb C:\Windows\symbols\dll\mscorlib.pdb C:\Windows\dll\mscorlib.pdb C:\Windows\mscorlib.pdb C:\Windows\sysnative\wbem\WmiPrvSE.exe C:\Windows\inf\hdaudio.PNF \??\PIPE\samr C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\Branding\Basebrd\basebrd.dll C: C:\Windows\sysnative\tzres.dll \??\PIPE\wkssvc \??\PIPE\srvsvc C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.cfg C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{31EC9AD6-5786-45DA-B15D-2E72FE116045}.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{52DB1739-8CA0-4C99-9EE7-FE81B5E5749E}.oeaccount C:\Users\Seven01\AppData\Local\Microsoft\Windows Mail\account{B6C15F72-0649-41DF-9EB7-057A27B89428}.oeaccount C:\Windows\System32\it-IT\werui.dll.mui C:\Windows\System32\werui.dll C:\Windows\System32\it-IT\DUser.dll.mui C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui C:\Windows\win.ini C:\Windows\System32\UxTheme.dll.Config C:\Windows\System32\uxtheme.dll C:\Windows\System32\it-IT\erofflps.txt C:\Users\Seven01\AppData\Local\Temp\WERB05F.tmp C:\Users\Seven01\AppData\Local\Temp\WERB05F.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040520160406\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016040820160409\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 C:\Windows\SysWOW64\winxp\triage.ini C:\Windows\SysWOW64\it-IT\werui.dll.mui C:\Windows\SysWOW64\werui.dll C:\Windows\SysWOW64\it-IT\DUser.dll.mui C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\COMCTL32.dll.mui C:\Windows\SysWOW64\UxTheme.dll.Config C:\Windows\SysWOW64\uxtheme.dll C:\Users\Seven01\AppData\Local\Temp\WER1F17.tmp C:\Users\Seven01\AppData\Local\Temp\WER1F17.tmp.WERInternalMetadata.xml C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen_service.log C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvc.dll C:\Windows\Microsoft.NET\Framework64\v4.0.30319\fusion.dll C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84\Report.wer C:\Windows\sysnative\it-IT\werui.dll.mui C:\Windows\sysnative C:\Windows\sysnative\spp\plugin-manifests-signed\sppwinob-spp-plugin-manifest-signed.xrm-ms C:\Windows\sysnative\sppwinob.dll C:\Windows\sysnative\spp\plugin-manifests-signed\sppobjs-spp-plugin-manifest-signed.xrm-ms C:\Windows\sysnative\sppobjs.dll C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat \??\pci#ven_8086&dev_100e&subsys_001e8086&rev_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{c2d43895-0262-4873-a789-c2f96d24b693} \??\root#*isatap#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{684bb8b6-2793-49a5-8012-e0a941b4b4df} \??\root#*isatap#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{5f6d61d9-d207-449a-bd48-652a5d1f25be} \??\root#ms_agilevpnminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{29898c9d-b0a4-4fef-bdb6-57a562022cee} \??\root#ms_l2tpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{e43d242b-9eab-4626-a952-46649fbb939a} \??\root#ms_ndiswanbh#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanbh \??\root#ms_ndiswanip#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanip \??\root#ms_ndiswanipv6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanipv6 \??\root#ms_pppoeminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8e301a52-affa-4f49-b9ca-c79096a1a056} \??\root#ms_pptpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{df4a9d2c-8742-4eb1-8703-d395c4183f33} \??\root#ms_sstpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{71f897d7-eb7c-4d8d-89db-ac80d9dd2270} \??\root#system#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac \??\sw#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{78032b7e-4968-42d3-9f37-287ea86c0aaa}
Write Files
C:\Users\Seven01\AppData\Local\GDIPFONTCACHEV1.DAT C:\Users\Seven01\AppData\Local\Temp\SysInfo.txt C:\Users\Seven01\AppData\Roaming\Windows Update.exe C:\Users\Seven01\AppData\Roaming\pid.txt C:\Users\Seven01\AppData\Roaming\pidloc.txt C:\Users\Seven01\AppData\Roaming\WindowsUpdate.exe \??\PIPE\samr C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\PIPE\wkssvc \??\PIPE\srvsvc C:\Users\Seven01\AppData\Local\Temp\holdermail.txt C:\Users\Seven01\AppData\Local\Temp\WERB05F.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_windows update.e_6a23c2b61d598d756a8fa82c78f3e71924d81faa_09900108\Report.wer C:\Users\Seven01\AppData\Local\Temp\holderwb.txt C:\Users\Seven01\AppData\Local\Temp\WER1F17.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Windows Update.e_d443c639c12eb0b78112ebd1db4edd984a4969be_0514c504\Report.wer C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen_service.log C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84\Report.wer.tmp C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84\Report.wer \??\SPDevice
Delete Files
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2548.1240203 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2548.1240203 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2548.1240234 C:\Users\Seven01\AppData\Local\Temp\SERVER1.exe C:\Users\Seven01\AppData\Local\Temp\holdermail.txt C:\Users\Seven01\AppData\Local\Temp\WERB05F.tmp C:\Users\Seven01\AppData\Local\Temp\WERB05F.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER1F17.tmp C:\Users\Seven01\AppData\Local\Temp\WER1F17.tmp.WERInternalMetadata.xml C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84\Report.wer.tmp
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SERVER1.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5860426f\706be66e HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5ec8fa85\51d137a8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|SERVER1.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|SERVER1.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|SERVER1.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5ec8fa85\7143d850 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.DirectoryServices__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.DirectoryServices,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\611c5985\16dab5aa HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\611c5985\79b0798f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts HKEY_CURRENT_USER\Software\Microsoft\GDIPlus HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink HKEY_CURRENT_USER\EUDC\1252 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\AppID\SERVER1.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\4CE80332 HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Windows Update.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Windows Update.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Windows Update.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Windows Update.exe HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\System\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Windows Update_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\FileDirectory HKEY_CURRENT_USER HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Classes\AppID\Windows Update.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\988A5B84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Control Panel\International HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Windows Update HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\433351e7\2db83a0b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\433351e7\26b4a30 HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default) HKEY_USERS\S-1-5-20_Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\Software\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{eb115ffc-10c8-4964-831d-6dcb02e6f23f} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eheadphonewave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonetopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#hdaudio#func_01&ven_8384&dev_7680&subsys_83847680&rev_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eheadphonewave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{C2D43895-0262-4873-A789-C2F96D24B693} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{684BB8B6-2793-49A5-8012-E0A941B4B4DF} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{5F6D61D9-D207-449A-BD48-652A5D1F25BE} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{29898C9D-B0A4-4FEF-BDB6-57A562022CEE} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{E43D242B-9EAB-4626-A952-46649FBB939A} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANBH HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIPV6 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{8E301A52-AFFA-4F49-B9CA-C79096A1A056} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{DF4A9D2C-8742-4EB1-8703-D395C4183F33} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\Software\Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\system\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2 HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32 HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCountry HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sList HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sDecimal HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sThousand HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sGrouping HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNativeDigits HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCurrency HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonDecimalSep HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonThousandSep HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonGrouping HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sPositiveSign HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNegativeSign HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sTimeFormat HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortTime HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s1159 HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s2359 HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortDate HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sYearMonth HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sLongDate HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCountry HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iMeasure HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iPaperSize HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iDigits HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iLZero HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegNumber HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\NumShape HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrDigits HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrency HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegCurr HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCalendarType HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstDayOfWeek HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseInfo\FilePrint HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine HKEY_LOCAL_MACHINE\Software\Classes\Software\Qualcomm\Eudora\CommandLine\current HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Thunderbird HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts HKEY_CURRENT_USER\Software\Google\Google Desktop\Mailboxes HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts HKEY_CURRENT_USER\Identities HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040} HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Username HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Internet Account Manager\Accounts HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\00471e98b7a362469ed97e3915fd4111 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\0a0d020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\10b0e4d6eb1de34dabd532a0806a0fec HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\13dbb0c8aa05101a9bb000aa002fc45a HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\192e64c97bf3a54488a039619c763627 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\32a3dc9c400a4b448b60ab7fe553a392 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\3517490d76624c419a828607e2a54604 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\43e0bb79f0f2d84db98ff4f730d23d24 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\6a50d9bd87f9a8478751861a1591a6c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7760e21103136b47946c9c80fa097f15 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\7d19c9e894f20d4780a31c9a9f17da11 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\818ecc2f310b344f807e8af5dc013189 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\8503020000000000c000000000000046 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9207f3e0a3b11019908b08002b2a56c2 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\ddb0922fc50b8d42be5a821ede840761 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\f86ed2903a4a11cfb57e524153480001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E} HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles HKEY_CURRENT_USER\Software\IncrediMail\Identities HKEY_LOCAL_MACHINE\Software\IncrediMail\Identities HKEY_LOCAL_MACHINE\Software\Group Mail HKEY_CURRENT_USER\Software\Microsoft\MSNMessenger HKEY_CURRENT_USER\Software\Microsoft\MessengerService HKEY_CURRENT_USER\Software\Yahoo\Pager HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\CLR20r3 HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_CURRENT_USER\Keyboard Layout\Toggle HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\seamonkey.exe HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_USERS\S-1-5-18 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\.DEFAULT\Environment HKEY_USERS\.DEFAULT\Volatile Environment HKEY_USERS\.DEFAULT\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\FailureActions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\FailureActions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64 HKEY_USERS\S-1-5-19 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\S-1-5-19\Environment HKEY_USERS\S-1-5-19\Volatile Environment HKEY_USERS\S-1-5-19\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64 HKEY_USERS\S-1-5-20 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\S-1-5-20\Environment HKEY_USERS\S-1-5-20\Volatile Environment HKEY_USERS\S-1-5-20\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\TraceFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoReflection HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\NoReflection HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorder HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSession HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug\ExceptionRecord HKEY_CURRENT_USER\Software\Microsoft\Windiff HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6FD5A890 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\LocalDumps HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup HKEY_USERS\.DEFAULT\Control Panel\International HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName HKEY_USERS\.DEFAULT\Control Panel\International\sCountry HKEY_USERS\.DEFAULT\Control Panel\International\sList HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal HKEY_USERS\.DEFAULT\Control Panel\International\sThousand HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime HKEY_USERS\.DEFAULT\Control Panel\International\s1159 HKEY_USERS\.DEFAULT\Control Panel\International\s2359 HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate HKEY_USERS\.DEFAULT\Control Panel\International\iCountry HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize HKEY_USERS\.DEFAULT\Control Panel\International\iDigits HKEY_USERS\.DEFAULT\Control Panel\International\iLZero HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber HKEY_USERS\.DEFAULT\Control Panel\International\NumShape HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wersvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain HKEY_LOCAL_MACHINE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenServiceDebugLog HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\Install HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DefaultVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Version HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\ZapSet HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NetFramework\v2.0.50727\NGenService\Roots HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENBreakOnWorker HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenRegistryAccessCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NetFramework\v2.0.50727\NGENService\State HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\State\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\State\ExtraInstallSteps HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENServiceBreakOnStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenMaxLogSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENServiceTestHookDll HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENServicePolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NetFramework\v2.0.50727\NGENService\ListenedState HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\ListenedState\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\ListenedState\RootstoreDirty HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenServiceDebugLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NicPath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\RegistryRoot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client\Install HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DefaultVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Version HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\ZapSet HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGENBreakOnWorker HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenRegistryAccessCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\State\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\State\ExtraInstallSteps HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\wermgr HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\OfflineMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\7F8CCB70 HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\sppsvc.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ServiceSessionId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\ManifestFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\PluginFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\ManifestFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\PluginFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\EnableTestVolumeIntervals HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLActivationInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleTolerance HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PublisherPolicyChangeTime HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress HKEY_LOCAL_MACHINE\System\Setup\Status HKEY_LOCAL_MACHINE\SYSTEM\Setup\Status\AuditBoot HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Reboot.SL_BRT_COMMIT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\InactivityShutdownDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\KeepRunningThresholdMins
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\432ba598\f6e8397\6f\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3a6a696d\52d7076e\72\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.DirectoryServices,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\4CE80332 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\988A5B84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Windows Update HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{EB115FFC-10C8-4964-831D-6DCB02E6F23F}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{eb115ffc-10c8-4964-831d-6dcb02e6f23f}\#eHeadphoneWave\Control\Linked HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ConfigFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo\Properties\{840b8171-b0ad-410f-8581-cccc0382cfef}\00000000\00000000\Data HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{17892376-DEFE-471D-9660-60652E76F60F}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1890E014-499A-44F5-85F4-666D905C223B}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{71F3FEAC-BBA8-47C9-B71C-CF23A8CC3E3A}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D138D132-49C1-4E73-AEDC-43167C48C74E}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCountry HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sList HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sDecimal HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sThousand HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sGrouping HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNativeDigits HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sCurrency HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonDecimalSep HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonThousandSep HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sMonGrouping HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sPositiveSign HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sNegativeSign HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sTimeFormat HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortTime HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s1159 HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\s2359 HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sShortDate HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sYearMonth HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\sLongDate HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCountry HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iMeasure HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iPaperSize HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iDigits HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iLZero HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegNumber HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\NumShape HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrDigits HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCurrency HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iNegCurr HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iCalendarType HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstDayOfWeek HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation HKEY_CURRENT_USER\Identities\{141B4688-D8D4-4AD1-B583-99828374C040}\Username HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\POP3 User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\IMAP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\HTTP User HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\{D9734F19-8CFB-411D-BC59-833E334FCB5E}\Calendar Summary\SMTP User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\FailureActions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\FailureActions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\StorSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmRdpService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\TraceFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\NoReflection HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\NoReflection HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AeDebug\Debugger HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\APPCRASH HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6FD5A890 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName HKEY_USERS\.DEFAULT\Control Panel\International\sCountry HKEY_USERS\.DEFAULT\Control Panel\International\sList HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal HKEY_USERS\.DEFAULT\Control Panel\International\sThousand HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime HKEY_USERS\.DEFAULT\Control Panel\International\s1159 HKEY_USERS\.DEFAULT\Control Panel\International\s2359 HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate HKEY_USERS\.DEFAULT\Control Panel\International\iCountry HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize HKEY_USERS\.DEFAULT\Control Panel\International\iDigits HKEY_USERS\.DEFAULT\Control Panel\International\iLZero HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber HKEY_USERS\.DEFAULT\Control Panel\International\NumShape HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Category HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Name HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParentFolder HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Description HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\RelativePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\ParsingName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalizedName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Icon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Security HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResource HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\StreamResourceType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\LocalRedirectOnly HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Roamable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PreCreate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Stream HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PublishExpandedPath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\FolderTypeID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\InitFolderHandler HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenServiceDebugLog HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\Install HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DefaultVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Version HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\ZapSet HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENBreakOnWorker HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenRegistryAccessCount HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\State\ExtraInstallSteps HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENServiceBreakOnStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenMaxLogSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENServiceTestHookDll HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGENServicePolicy HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\ListenedState\RootstoreDirty HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenServiceDebugLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NicPath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\RegistryRoot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client\Install HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DefaultVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Version HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\ZapSet HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGENBreakOnWorker HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenRegistryAccessCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\State\ExtraInstallSteps HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\wermgr HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\OfflineMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\7F8CCB70 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\ManifestFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\PluginFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\ManifestFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\PluginFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\ModuleId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\IsService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\EnableTestVolumeIntervals HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLActivationInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleTolerance HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PublisherPolicyChangeTime HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress HKEY_LOCAL_MACHINE\SYSTEM\Setup\Status\AuditBoot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\InactivityShutdownDelay HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\KeepRunningThresholdMins
Write Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Windows Update_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Windows Update_RASAPI32\FileDirectory HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Windows Update HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Start HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\Debug\ExceptionRecord HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ServiceSessionId
Delete Keys
Nothing to display
Mutexes
Global\CLR_CASOFF_MUTEX Global\.net clr networking DBWinMutex Global\9942176c-7843-11e8-9b51-0800274633c1 Local\MSCTF.Asm.MutexDefault1 Local\WERReportingForProcess2788 Global\a8eead1b-7843-11e8-9b51-0800274633c1 Global\\xee\xa8\x90\xc7\x96 WERUI_APPCRASH-e84e1efa5bc964adde55b3e015797b8fdc73d8ca
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW kernel32.dll.InitializeCriticalSectionAndSpinCount kernel32.dll.IsProcessorFeaturePresent msvcrt.dll._set_error_mode msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z kernel32.dll.FindActCtxSectionStringW kernel32.dll.GetSystemWindowsDirectoryW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap mscorwks.dll._CorExeMain mscorwks.dll.GetCLRFunction advapi32.dll.RegisterTraceGuidsW advapi32.dll.UnregisterTraceGuids advapi32.dll.GetTraceLoggerHandle advapi32.dll.GetTraceEnableLevel advapi32.dll.GetTraceEnableFlags advapi32.dll.TraceEvent mscoree.dll.IEE mscoreei.dll.IEE mscorwks.dll.IEE mscoree.dll.GetStartupFlags mscoreei.dll.GetStartupFlags mscoree.dll.GetHostConfigurationFile mscoreei.dll.GetHostConfigurationFile mscoreei.dll.GetCORVersion mscoree.dll.GetCORSystemDirectory mscoreei.dll.GetCORSystemDirectory_RetAddr mscoreei.dll.CreateConfigStream ntdll.dll.RtlUnwind kernel32.dll.IsWow64Process advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddVectoredContinueHandler kernel32.dll.RemoveVectoredContinueHandler advapi32.dll.ConvertSidToStringSidW shell32.dll.SHGetFolderPathW kernel32.dll.GetWriteWatch kernel32.dll.ResetWriteWatch kernel32.dll.CreateMemoryResourceNotification kernel32.dll.QueryMemoryResourceNotification kernel32.dll.QueryActCtxW kernel32.dll.GetVersionExW kernel32.dll.GetFullPathNameW ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 ole32.dll.CoGetContextToken advapi32.dll.CryptAcquireContextA advapi32.dll.CryptReleaseContext advapi32.dll.CryptCreateHash advapi32.dll.CryptDestroyHash advapi32.dll.CryptHashData advapi32.dll.CryptGetHashParam advapi32.dll.CryptImportKey advapi32.dll.CryptExportKey advapi32.dll.CryptGenKey advapi32.dll.CryptGetKeyParam advapi32.dll.CryptDestroyKey advapi32.dll.CryptVerifySignatureA advapi32.dll.CryptSignHashA advapi32.dll.CryptGetProvParam advapi32.dll.CryptGetUserKey advapi32.dll.CryptEnumProvidersA mscoree.dll.GetMetaDataInternalInterface mscoreei.dll.GetMetaDataInternalInterface mscorwks.dll.GetMetaDataInternalInterface mscorjit.dll.getJit kernel32.dll.GetUserDefaultUILanguage kernel32.dll.SetErrorMode kernel32.dll.GetFileAttributesExW mscoreei.dll.LoadLibraryShim culture.dll.ConvertLangIdToCultureName kernel32.dll.lstrlen kernel32.dll.lstrlenW mscoree.dll.ND_RI4 mscoreei.dll.ND_RI4 bcrypt.dll.BCryptGetFipsAlgorithmMode kernel32.dll.GlobalMemoryStatusEx kernel32.dll.VirtualProtect kernel32.dll.GetEnvironmentVariableW kernel32.dll.SwitchToThread kernel32.dll.CloseHandle kernel32.dll.GetCurrentProcessId advapi32.dll.LookupPrivilegeValueW kernel32.dll.GetCurrentProcess advapi32.dll.AdjustTokenPrivileges kernel32.dll.OpenProcess psapi.dll.EnumProcessModules psapi.dll.GetModuleInformation psapi.dll.GetModuleBaseNameW psapi.dll.GetModuleFileNameExW kernel32.dll.GetProcAddress kernel32.dll.DebugActiveProcess kernel32.dll.WaitForDebugEvent kernel32.dll.ContinueDebugEvent kernel32.dll.DeleteFileA advapi32.dll.SetKernelObjectSecurity advapi32.dll.GetKernelObjectSecurity ntdll.dll.NtSetInformationProcess ntdll.dll.NtProtectVirtualMemory uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware ole32.dll.CoUninitialize user32.dll.RegisterWindowMessageW kernel32.dll.GetCurrentThread kernel32.dll.DuplicateHandle kernel32.dll.GetCurrentThreadId user32.dll.GetSystemMetrics kernel32.dll.GetModuleHandleW user32.dll.DefWindowProcW gdi32.dll.GetStockObject user32.dll.RegisterClassW ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree user32.dll.CreateWindowExW user32.dll.SetWindowLongW user32.dll.GetWindowLongW user32.dll.CallWindowProcW user32.dll.GetClientRect user32.dll.GetWindowRect user32.dll.GetParent ole32.dll.IIDFromString kernel32.dll.LocalFree kernel32.dll.LocalAlloc mscoree.dll.ND_RU1 mscoreei.dll.ND_RU1 advapi32.dll.LsaClose advapi32.dll.LsaFreeMemory advapi32.dll.LsaOpenPolicy advapi32.dll.LsaLookupSids advapi32.dll.LsaLookupNames2 kernel32.dll.CreateEventW ws2_32.dll.WSAStartup ws2_32.dll.WSASocketW ws2_32.dll.setsockopt ws2_32.dll.WSAEventSelect ws2_32.dll.ioctlsocket ws2_32.dll.closesocket kernel32.dll.CreateFileW kernel32.dll.GetFileType kernel32.dll.GetFileSize kernel32.dll.ReadFile mscoree.dll.ND_RI2 mscoreei.dll.ND_RI2 kernel32.dll.GetComputerNameW advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.CreateFileMappingW kernel32.dll.MapViewOfFile kernel32.dll.UnmapViewOfFile kernel32.dll.VirtualQuery kernel32.dll.ReleaseMutex advapi32.dll.CreateWellKnownSid kernel32.dll.CreateMutexW kernel32.dll.WaitForSingleObject kernel32.dll.OpenMutexW kernel32.dll.GetProcessTimes ws2_32.dll.inet_addr ws2_32.dll.bind ws2_32.dll.listen ws2_32.dll.getsockname ws2_32.dll.accept kernel32.dll.CreateIoCompletionPort kernel32.dll.PostQueuedCompletionStatus ntdll.dll.NtQueryInformationThread ntdll.dll.NtQuerySystemInformation ntdll.dll.NtGetCurrentProcessorNumber ole32.dll.CoCreateGuid cryptsp.dll.CryptAcquireContextW kernel32.dll.SetEvent uxtheme.dll.IsAppThemed kernel32.dll.CreateActCtxA user32.dll.AdjustWindowRectEx kernel32.dll.GetTempPathW shfolder.dll.SHGetFolderPathW dwmapi.dll.DwmIsCompositionEnabled gdi32.dll.CreateCompatibleDC kernel32.dll.GetSystemDefaultLCID gdi32.dll.GetObjectW user32.dll.GetDC kernel32.dll.FindAtomW kernel32.dll.AddAtomW mscoree.dll.LoadLibraryShim gdiplus.dll.GdiplusStartup user32.dll.GetWindowInfo user32.dll.GetAncestor user32.dll.GetMonitorInfoA user32.dll.EnumDisplayMonitors user32.dll.EnumDisplayDevicesA gdi32.dll.ExtTextOutW gdi32.dll.GdiIsMetaPrintDC gdiplus.dll.GdipCreateFontFromLogfontW kernel32.dll.RegOpenKeyExW kernel32.dll.RegQueryInfoKeyA kernel32.dll.RegCloseKey kernel32.dll.RegCreateKeyExW kernel32.dll.RegQueryValueExW kernel32.dll.RegEnumValueW kernel32.dll.RegQueryInfoKeyW gdiplus.dll.GdipGetFontUnit gdiplus.dll.GdipGetFontSize gdiplus.dll.GdipGetFontStyle gdiplus.dll.GdipGetFamily user32.dll.ReleaseDC gdiplus.dll.GdipCreateFromHDC gdiplus.dll.GdipGetDpiY gdiplus.dll.GdipGetFontHeight gdiplus.dll.GdipGetEmHeight gdiplus.dll.GdipGetLineSpacing gdiplus.dll.GdipDeleteGraphics gdiplus.dll.GdipCreateFont gdiplus.dll.GdipDeleteFont gdiplus.dll.GdipGetLogFontW mscoree.dll.ND_WU1 mscoreei.dll.ND_WU1 gdi32.dll.CreateFontIndirectW gdi32.dll.SelectObject gdi32.dll.GetTextMetricsW gdi32.dll.GetTextExtentPoint32W gdi32.dll.DeleteDC kernel32.dll.GetCurrentActCtx kernel32.dll.ActivateActCtx user32.dll.SetWindowTextW user32.dll.GetProcessWindowStation user32.dll.GetUserObjectInformationA kernel32.dll.SetConsoleCtrlHandler user32.dll.GetClassInfoW user32.dll.SetLayeredWindowAttributes kernel32.dll.GetStartupInfoW user32.dll.GetWindowPlacement gdi32.dll.GetLayout gdi32.dll.GdiRealizationInfo gdi32.dll.FontIsLinked gdi32.dll.GetTextFaceAliasW gdi32.dll.GetFontAssocStatus advapi32.dll.RegQueryValueExA user32.dll.SendMessageW user32.dll.GetSystemMenu user32.dll.EnableMenuItem gdi32.dll.GetDeviceCaps user32.dll.CreateIconFromResourceEx user32.dll.SetWindowPos user32.dll.RedrawWindow user32.dll.ShowWindow user32.dll.GetWindowTextLengthW user32.dll.GetWindowTextW kernel32.dll.WriteFile kernel32.dll.CopyFileW kernel32.dll.RtlMoveMemory shell32.dll.ShellExecuteEx shell32.dll.ShellExecuteExW setupapi.dll.CM_Get_Device_Interface_List_Size_ExW setupapi.dll.CM_Get_Device_Interface_List_ExW comctl32.dll.#386 ole32.dll.CoWaitForMultipleHandles user32.dll.SetClassLongW user32.dll.PostMessageW sechost.dll.LookupAccountNameLocalW user32.dll.UnregisterClassW kernel32.dll.DeleteAtom advapi32.dll.LookupAccountSidW user32.dll.IsWindow sechost.dll.LookupAccountSidLocalW user32.dll.DestroyWindow user32.dll.DestroyIcon cryptsp.dll.CryptGenRandom ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoCreateInstance ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult rpcrtremote.dll.I_RpcExtInitializeExtensionPoint gdi32.dll.DeleteObject user32.dll.ChangeClipboardChain cryptsp.dll.CryptReleaseContext comctl32.dll.#321 kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.DeactivateActCtx advapi32.dll.EventUnregister oleaut32.dll.#500 kernel32.dll.FindFirstFileW kernel32.dll.FindClose kernel32.dll.FindNextFileW kernel32.dll.DeleteFileW cryptsp.dll.CryptCreateHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam cryptsp.dll.CryptDestroyHash iphlpapi.dll.GetNetworkParams dnsapi.dll.DnsQueryConfig iphlpapi.dll.GetAdaptersAddresses iphlpapi.dll.GetIpInterfaceEntry iphlpapi.dll.GetBestInterfaceEx iphlpapi.dll.GetAdaptersInfo iphlpapi.dll.GetIfEntry iphlpapi.dll.GetPerAdapterInfo ws2_32.dll.gethostname ws2_32.dll.getaddrinfo ws2_32.dll.freeaddrinfo kernel32.dll.GetACP rasapi32.dll.RasEnumConnectionsW rtutils.dll.TraceRegisterExA rtutils.dll.TracePrintfExA sechost.dll.OpenSCManagerW sechost.dll.OpenServiceW sechost.dll.QueryServiceStatus sechost.dll.CloseServiceHandle ws2_32.dll.WSAIoctl kernel32.dll.FormatMessageW rasapi32.dll.RasConnectionNotificationW advapi32.dll.RegOpenCurrentUser advapi32.dll.RegNotifyChangeKeyValue sechost.dll.NotifyServiceStatusChangeA winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser kernel32.dll.ResetEvent ws2_32.dll.WSAConnect ws2_32.dll.send ws2_32.dll.recv ws2_32.dll.shutdown ole32.dll.CoCreateFreeThreadedMarshaler ole32.dll.CoGetObjectContext oleaut32.dll.#2 oleaut32.dll.#6 kernel32.dll.LoadLibraryA wminet_utils.dll.ResetSecurity wminet_utils.dll.SetSecurity wminet_utils.dll.BlessIWbemServices wminet_utils.dll.BlessIWbemServicesObject wminet_utils.dll.GetPropertyHandle wminet_utils.dll.WritePropertyValue wminet_utils.dll.Clone wminet_utils.dll.VerifyClientKey wminet_utils.dll.GetQualifierSet wminet_utils.dll.Get wminet_utils.dll.Put wminet_utils.dll.Delete wminet_utils.dll.GetNames wminet_utils.dll.BeginEnumeration wminet_utils.dll.Next wminet_utils.dll.EndEnumeration wminet_utils.dll.GetPropertyQualifierSet wminet_utils.dll.GetObjectText wminet_utils.dll.SpawnDerivedClass wminet_utils.dll.SpawnInstance wminet_utils.dll.CompareTo wminet_utils.dll.GetPropertyOrigin wminet_utils.dll.InheritsFrom wminet_utils.dll.GetMethod wminet_utils.dll.PutMethod wminet_utils.dll.DeleteMethod wminet_utils.dll.BeginMethodEnumeration wminet_utils.dll.NextMethod wminet_utils.dll.EndMethodEnumeration wminet_utils.dll.GetMethodQualifierSet wminet_utils.dll.GetMethodOrigin wminet_utils.dll.QualifierSet_Get wminet_utils.dll.QualifierSet_Put wminet_utils.dll.QualifierSet_Delete wminet_utils.dll.QualifierSet_GetNames wminet_utils.dll.QualifierSet_BeginEnumeration wminet_utils.dll.QualifierSet_Next wminet_utils.dll.QualifierSet_EndEnumeration wminet_utils.dll.GetCurrentApartmentType wminet_utils.dll.GetDemultiplexedStub wminet_utils.dll.CreateInstanceEnumWmi wminet_utils.dll.CreateClassEnumWmi wminet_utils.dll.ExecQueryWmi wminet_utils.dll.ExecNotificationQueryWmi wminet_utils.dll.PutInstanceWmi wminet_utils.dll.PutClassWmi wminet_utils.dll.CloneEnumWbemClassObject wminet_utils.dll.ConnectServerWmi kernel32.dll.GetThreadPreferredUILanguages kernel32.dll.SetThreadPreferredUILanguages kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetSystemDefaultLocaleName user32.dll.BeginPaint gdiplus.dll.GdipCreateHalftonePalette gdi32.dll.SelectPalette user32.dll.EndPaint oleaut32.dll.SysStringLen kernel32.dll.RtlZeroMemory oleaut32.dll.#283 oleaut32.dll.#284 advapi32.dll.RegSetValueExW kernel32.dll.SetFileAttributesW kernel32.dll.GetSystemDefaultUILanguage user32.dll.SetWindowsHookExA user32.dll.SetClipboardViewer ole32.dll.OleInitialize ole32.dll.OleGetClipboard kernel32.dll.GlobalLock kernel32.dll.GlobalUnlock kernel32.dll.GlobalFree user32.dll.SetForegroundWindow ole32.dll.CoRegisterMessageFilter user32.dll.SetFocus user32.dll.GetWindowThreadProcessId user32.dll.PeekMessageW user32.dll.IsWindowUnicode user32.dll.GetMessageW user32.dll.TranslateMessage user32.dll.DispatchMessageW user32.dll.WaitMessage kernel32.dll.GetLogicalDrives kernel32.dll.GetDriveTypeW kernel32.dll.CreateProcessA ntdll.dll.NtUnmapViewOfSection kernel32.dll.VirtualAllocEx ntdll.dll.NtWriteVirtualMemory ntdll.dll.NtGetContextThread ntdll.dll.NtSetContextThread ntdll.dll.NtResumeThread oleaut32.dll.#9 oleaut32.dll.#7 kernel32.dll.CreateSemaphoreA advapi32.dll.CheckTokenMembership mscoree.dll.DllGetClassObject mscoreei.dll.DllGetClassObject diasymreader.dll.DllGetClassObjectInternal vssapi.dll.CreateWriter advapi32.dll.LookupAccountNameW samcli.dll.NetLocalGroupGetMembers samlib.dll.SamConnect rpcrt4.dll.NdrClientCall3 rpcrt4.dll.RpcStringBindingComposeW rpcrt4.dll.RpcBindingFromStringBindingW rpcrt4.dll.RpcStringFreeW rpcrt4.dll.RpcBindingFree samlib.dll.SamOpenDomain samlib.dll.SamLookupNamesInDomain samlib.dll.SamOpenAlias samlib.dll.SamFreeMemory samlib.dll.SamCloseHandle samlib.dll.SamGetMembersInAlias netutils.dll.NetApiBufferFree ole32.dll.StringFromCLSID oleaut32.dll.#4 propsys.dll.VariantToPropVariant wbemcore.dll.Reinitialize wbemsvc.dll.DllGetClassObject wbemsvc.dll.DllCanUnloadNow authz.dll.AuthzInitializeContextFromToken authz.dll.AuthzInitializeObjectAccessAuditEvent2 authz.dll.AuthzAccessCheck authz.dll.AuthzFreeAuditEvent authz.dll.AuthzFreeContext authz.dll.AuthzInitializeResourceManager authz.dll.AuthzFreeResourceManager rpcrt4.dll.RpcBindingCreateW rpcrt4.dll.RpcBindingBind rpcrt4.dll.I_RpcMapWin32Status advapi32.dll.EventWrite kernel32.dll.RegSetValueExW wmisvc.dll.IsImproperShutdownDetected wevtapi.dll.EvtRender wevtapi.dll.EvtNext wevtapi.dll.EvtClose wevtapi.dll.EvtQuery wevtapi.dll.EvtCreateRenderContext rpcrt4.dll.RpcBindingSetAuthInfoExW rpcrt4.dll.RpcBindingSetOption ole32.dll.CreateStreamOnHGlobal advapi32.dll.RegCreateKeyExW kernelbase.dll.InitializeAcl kernelbase.dll.AddAce sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.IsThreadAFiber kernel32.dll.OpenProcessToken kernelbase.dll.GetTokenInformation kernelbase.dll.DuplicateTokenEx kernelbase.dll.AdjustTokenPrivileges kernel32.dll.SetThreadToken kernelbase.dll.CheckTokenMembership kernelbase.dll.AllocateAndInitializeSid ole32.dll.CLSIDFromString oleaut32.dll.#285 advapi32.dll.RegOpenKeyW oleaut32.dll.#17 oleaut32.dll.#20 oleaut32.dll.#19 oleaut32.dll.#25 oleaut32.dll.#12 oleaut32.dll.#286 authz.dll.AuthzInitializeContextFromSid ole32.dll.CoGetCallContext ole32.dll.CoImpersonateClient advapi32.dll.OpenThreadToken ole32.dll.CoRevertToSelf oleaut32.dll.#8 ole32.dll.CoSwitchCallContext advapi32.dll.LogonUserExExW sspicli.dll.LogonUserExExW oleaut32.dll.#287 oleaut32.dll.#288 oleaut32.dll.#289 kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle ntmarta.dll.GetMartaExtensionInterface fastprox.dll.DllGetClassObject fastprox.dll.DllCanUnloadNow oleaut32.dll.#290 winbrand.dll.BrandingLoadString security.dll.InitSecurityInterfaceW cryptsp.dll.SystemFunction035 schannel.dll.SpUserModeInitialize ntdll.dll.RtlInitUnicodeString ntdll.dll.RtlFreeUnicodeString ntdll.dll.NtSetSystemEnvironmentValue ntdll.dll.NtQuerySystemEnvironmentValue ntdll.dll.NtCreateFile ntdll.dll.NtQueryDirectoryObject ntdll.dll.NtQueryObject ntdll.dll.NtOpenDirectoryObject ntdll.dll.NtQueryInformationProcess ntdll.dll.NtQueryInformationToken ntdll.dll.NtOpenFile ntdll.dll.NtClose ntdll.dll.NtFsControlFile ntdll.dll.NtQueryVolumeInformationFile netapi32.dll.NetGroupEnum netapi32.dll.NetGroupGetInfo netapi32.dll.NetGroupSetInfo netapi32.dll.NetLocalGroupGetInfo netapi32.dll.NetLocalGroupSetInfo netapi32.dll.NetGroupGetUsers netapi32.dll.NetLocalGroupGetMembers netapi32.dll.NetLocalGroupEnum netapi32.dll.NetShareEnum netapi32.dll.NetShareGetInfo netapi32.dll.NetShareAdd netapi32.dll.NetShareEnumSticky netapi32.dll.NetShareSetInfo netapi32.dll.NetShareDel netapi32.dll.NetShareDelSticky netapi32.dll.NetShareCheck netapi32.dll.NetUserEnum netapi32.dll.NetUserGetInfo netapi32.dll.NetUserSetInfo netapi32.dll.NetApiBufferFree netapi32.dll.NetQueryDisplayInformation netapi32.dll.NetServerSetInfo netapi32.dll.NetServerGetInfo netapi32.dll.NetGetDCName netapi32.dll.NetWkstaGetInfo netapi32.dll.NetGetAnyDCName netapi32.dll.NetServerEnum netapi32.dll.NetUserModalsGet netapi32.dll.NetScheduleJobAdd netapi32.dll.NetScheduleJobDel netapi32.dll.NetScheduleJobEnum netapi32.dll.NetScheduleJobGetInfo netapi32.dll.NetUseGetInfo netapi32.dll.NetEnumerateTrustedDomains netapi32.dll.DsGetDcNameW netapi32.dll.DsRoleGetPrimaryDomainInformation netapi32.dll.DsRoleFreeMemory netapi32.dll.NetRenameMachineInDomain netapi32.dll.NetJoinDomain netapi32.dll.NetUnjoinDomain wkscli.dll.NetWkstaGetInfo cscapi.dll.CscNetApiGetInterface kernel32.dll.GetDiskFreeSpaceExW kernel32.dll.GetVolumePathNameW kernel32.dll.CreateToolhelp32Snapshot kernel32.dll.Thread32First kernel32.dll.Thread32Next kernel32.dll.Process32First kernel32.dll.Process32Next kernel32.dll.Module32First kernel32.dll.Module32Next kernel32.dll.Heap32ListFirst oleaut32.dll.#15 oleaut32.dll.#26 comctl32.dll.InitCommonControlsEx shell32.dll.SHGetSpecialFolderPathA pstorec.dll.PStoreCreateInstance crypt32.dll.CryptUnprotectData advapi32.dll.CredReadA advapi32.dll.CredFree advapi32.dll.CredDeleteA advapi32.dll.CredEnumerateA advapi32.dll.CredEnumerateW wer.dll.WerReportCreate wer.dll.WerReportSetParameter wer.dll.WerReportAddFile wer.dll.WerReportSetUIOption wer.dll.WerReportSubmit wer.dll.WerReportAddDump wer.dll.WerReportCloseHandle user32.dll.LoadStringW advapi32.dll.RegGetValueW user32.dll.GetThreadDesktop user32.dll.GetUserObjectInformationW sensapi.dll.IsNetworkAlive rpcrt4.dll.NdrClientCall2 user32.dll.CharUpperW werui.dll.WerUICreate werui.dll.WerUIStart ole32.dll.CoInitialize dui70.dll.InitProcessPriv comctl32.dll.LoadIconWithScaleDown ntdll.dll.RtlRunEncodeUnicodeString ntdll.dll.RtlRunDecodeUnicodeString dui70.dll.InitThread duser.dll.InitGadgets user32.dll.RegisterMessagePumpHook dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z duser.dll.CreateGadget duser.dll.SetGadgetMessageFilter duser.dll.SetGadgetStyle dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z duser.dll.InvalidateGadget dui70.dll.CreateDUIWrapper dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z shell32.dll.ExtractIconExW comctl32.dll.TaskDialogIndirect uxtheme.dll.IsThemeActive duser.dll.SetGadgetRootInfo uxtheme.dll.GetThemeAppProperties xmllite.dll.CreateXmlReader xmllite.dll.CreateXmlReaderInputWithEncodingName uxtheme.dll.OpenThemeData uxtheme.dll.GetThemeMargins uxtheme.dll.GetThemeFont uxtheme.dll.GetThemeColor uxtheme.dll.GetThemeMetric duser.dll.SetGadgetParent duser.dll.GetDUserModule duser.dll.FindStdColor duser.dll.AttachWndProcW kernel32.dll.InterlockedPopEntrySList kernel32.dll.InterlockedPushEntrySList kernel32.dll.InterlockedCompareExchange comctl32.dll.RegisterClassNameW duser.dll.GetGadgetRect duser.dll.GetGadgetRgn duser.dll.GetGadgetTicket dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z uxtheme.dll.EnableThemeDialogTexture dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z comctl32.dll.HIMAGELIST_QueryInterface comctl32.dll.DrawShadowText comctl32.dll.DrawSizeBox comctl32.dll.DrawScrollBar comctl32.dll.SizeBoxHwnd comctl32.dll.ScrollBar_MouseMove comctl32.dll.ScrollBar_Menu comctl32.dll.HandleScrollCmd comctl32.dll.DetachScrollBars comctl32.dll.AttachScrollBars comctl32.dll.CCSetScrollInfo comctl32.dll.CCGetScrollInfo comctl32.dll.CCEnableScrollBar comctl32.dll.QuerySystemGestureStatus uxtheme.dll.#49 uxtheme.dll.CloseThemeData dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ uxtheme.dll.GetThemeBool duser.dll.GetGadgetFocus uxtheme.dll.GetThemeBackgroundContentRect uxtheme.dll.GetThemeTextMetrics uxtheme.dll.GetThemePartSize uxtheme.dll.GetThemeTextExtent uxtheme.dll.GetThemeBackgroundExtent ole32.dll.CoRegisterInitializeSpy ole32.dll.CoRevokeInitializeSpy duser.dll.SetGadgetFocus duser.dll.DUserSendEvent duser.dll.SetGadgetRect comctl32.dll.SetWindowSubclass comctl32.dll.DefSubclassProc dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ user32.dll.FrostCrashedWindow uxtheme.dll.#47 duser.dll.FindGadgetFromPoint duser.dll.ForwardGadgetMessage uxtheme.dll.BufferedPaintInit uxtheme.dll.BeginBufferedPaint uxtheme.dll.BufferedPaintRenderAnimation uxtheme.dll.BeginBufferedAnimation uxtheme.dll.IsThemeBackgroundPartiallyTransparent uxtheme.dll.DrawThemeParentBackground uxtheme.dll.DrawThemeBackground uxtheme.dll.DrawThemeText uxtheme.dll.EndBufferedAnimation uxtheme.dll.GetThemeTransitionDuration uxtheme.dll.GetBufferedPaintDC uxtheme.dll.GetBufferedPaintTargetDC uxtheme.dll.EndBufferedPaint oleaut32.dll.SysAllocString oleaut32.dll.SysFreeString uxtheme.dll.GetThemeInt duser.dll.DUserPostEvent duser.dll.DisableContainerHwnd uxtheme.dll.BufferedPaintUnInit werui.dll.WerUIUpdateUIForState duser.dll.DeleteHandle duser.dll.DetachWndProc comctl32.dll.RemoveWindowSubclass dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ uxtheme.dll.BufferedPaintStopAllAnimations dui70.dll.??1CCBase@DirectUI@@UAE@XZ uxtheme.dll.DrawThemeParentBackgroundEx uxtheme.dll.GetThemeEnumValue user32.dll.MsgWaitForMultipleObjects winhttp.dll.WinHttpOpen winhttp.dll.WinHttpSetTimeouts winhttp.dll.WinHttpSetOption winhttp.dll.WinHttpConnect winhttp.dll.WinHttpOpenRequest winhttp.dll.WinHttpSetStatusCallback winhttp.dll.WinHttpGetDefaultProxyConfiguration winhttp.dll.WinHttpGetProxyForUrl winhttp.dll.WinHttpSendRequest ws2_32.dll.GetAddrInfoW ws2_32.dll.#2 ws2_32.dll.#21 ws2_32.dll.#9 ws2_32.dll.FreeAddrInfoW ws2_32.dll.#6 ws2_32.dll.#5 ws2_32.dll.WSARecv ws2_32.dll.WSASend winhttp.dll.WinHttpReceiveResponse winhttp.dll.WinHttpQueryHeaders winhttp.dll.WinHttpReadData ws2_32.dll.#22 winhttp.dll.WinHttpCloseHandle ws2_32.dll.#3 advapi32.dll.IsValidSid advapi32.dll.GetLengthSid advapi32.dll.CopySid advapi32.dll.RegisterEventSourceW advapi32.dll.ReportEventW advapi32.dll.DeregisterEventSource werui.dll.WerUITerminate duser.dll.DUserFlushMessages duser.dll.DUserFlushDeferredMessages dui70.dll.UnInitThread user32.dll.UnregisterMessagePumpHook dui70.dll.UnInitProcessPriv dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ werui.dll.WerUIDelete advapi32.dll.DuplicateToken shell32.dll.SHGetSpecialFolderPathW cryptsp.dll.CryptAcquireContextA vaultcli.dll.VaultOpenVault vaultcli.dll.VaultCloseVault vaultcli.dll.VaultEnumerateItems vaultcli.dll.VaultFree vaultcli.dll.VaultGetInformation vaultcli.dll.VaultGetItem imm32.dll.ImmDisableIME wer.dll.WerpCreateIntegratorReportId wer.dll.WerpSetIntegratorReportId dbgeng.dll.DebugCreate ntdll.dll.CsrGetProcessId ntdll.dll.DbgBreakPoint ntdll.dll.DbgPrint ntdll.dll.DbgPrompt ntdll.dll.DbgUiConvertStateChangeStructure ntdll.dll.DbgUiGetThreadDebugObject ntdll.dll.DbgUiIssueRemoteBreakin ntdll.dll.DbgUiSetThreadDebugObject ntdll.dll.NtAllocateVirtualMemory ntdll.dll.NtCreateDebugObject ntdll.dll.NtDebugActiveProcess ntdll.dll.NtDebugContinue ntdll.dll.NtFreeVirtualMemory ntdll.dll.NtOpenProcess ntdll.dll.NtOpenThread ntdll.dll.NtQueryMutant ntdll.dll.NtRemoveProcessDebug ntdll.dll.NtSetInformationDebugObject ntdll.dll.NtSystemDebugControl ntdll.dll.NtWaitForDebugEvent ntdll.dll.RtlAnsiStringToUnicodeString ntdll.dll.RtlCreateProcessParameters ntdll.dll.RtlCreateUserProcess ntdll.dll.RtlDestroyProcessParameters ntdll.dll.RtlDosPathNameToNtPathName_U ntdll.dll.RtlFindMessage ntdll.dll.RtlFreeHeap ntdll.dll.RtlGetUnloadEventTrace ntdll.dll.RtlGetUnloadEventTraceEx ntdll.dll.RtlInitAnsiString ntdll.dll.RtlTryEnterCriticalSection ntdll.dll.RtlUnicodeStringToAnsiString ntdll.dll.NtOpenProcessToken ntdll.dll.NtOpenThreadToken kernel32.dll.CloseProfileUserMapping kernel32.dll.DebugActiveProcessStop kernel32.dll.DebugBreak kernel32.dll.DebugBreakProcess kernel32.dll.DebugSetProcessKillOnExit kernel32.dll.Module32FirstW kernel32.dll.Module32NextW kernel32.dll.OpenThread kernel32.dll.Process32FirstW kernel32.dll.Process32NextW kernel32.dll.ProcessIdToSessionId kernel32.dll.SetProcessShutdownParameters kernel32.dll.GetTimeZoneInformation kernel32.dll.Wow64GetThreadSelectorEntry advapi32.dll.CloseServiceHandle advapi32.dll.ControlService advapi32.dll.CreateServiceA advapi32.dll.CreateServiceW advapi32.dll.DeleteService advapi32.dll.EnumServicesStatusExA advapi32.dll.EnumServicesStatusExW advapi32.dll.GetEventLogInformation advapi32.dll.OpenSCManagerA advapi32.dll.OpenSCManagerW advapi32.dll.OpenServiceA advapi32.dll.OpenServiceW advapi32.dll.StartServiceA advapi32.dll.StartServiceW advapi32.dll.GetSidSubAuthority advapi32.dll.GetSidSubAuthorityCount version.dll.GetFileVersionInfoSizeExW version.dll.GetFileVersionInfoExW dbghelp.dll.WinDbgExtensionDllInit dbghelp.dll.ExtensionApiVersion wer.dll.WerpSetDynamicParameter wer.dll.WerpSetCallBack wer.dll.WerpAddRegisteredDataToReport wer.dll.WerpFreeString wersvc.dll.ServiceMain wersvc.dll.SvchostPushServiceGlobals faultrep.dll.WerpInitiateCrashReporting wer.dll.WerpCreateMachineStore shell32.dll.SHGetFolderPathEx ole32.dll.StringFromGUID2 profapi.dll.#104 userenv.dll.CreateEnvironmentBlock sechost.dll.ConvertSidToStringSidW sspicli.dll.GetUserNameExW userenv.dll.DestroyEnvironmentBlock wer.dll.WerpSvcReportFromMachineQueue wtsapi32.dll.WTSQueryUserToken winsta.dll.WinStationQueryInformationW advapi32.dll.ImpersonateLoggedOnUser advapi32.dll.CreateProcessAsUserW advapi32.dll.RevertToSelf mscorsvc.dll.CorGetSvc advapi32.dll.StartServiceCtrlDispatcherW kernel32.dll.VerSetConditionMask kernel32.dll.VerifyVersionInfoW advapi32.dll.RegisterServiceCtrlHandlerExW advapi32.dll.SetServiceStatus shlwapi.dll.PathIsDirectoryW advapi32.dll.EventEnabled ntdll.dll.ZwQueryInformationProcess kernel32.dll.IsDebuggerPresent ntdll.dll.NtQuerySection ntdll.dll.LdrProcessRelocationBlock sppwinob.dll.SppPluginInitialize sppwinob.dll.SppPluginShutdown sppwinob.dll.SppPluginCreateInstance sppwinob.dll.SppPluginCanUnloadNow sppobjs.dll.SppPluginInitialize sppobjs.dll.SppPluginShutdown sppobjs.dll.SppPluginCreateInstance sppobjs.dll.SppPluginCanUnloadNow advapi32.dll.NotifyServiceStatusChangeW setupapi.dll.SetupDiGetClassDevsW setupapi.dll.SetupDiEnumDeviceInfo setupapi.dll.SetupDiGetDeviceRegistryPropertyW setupapi.dll.SetupDiDestroyDeviceInfoList wintrust.dll.WinVerifyTrust setupapi.dll.SetupDiEnumDeviceInterfaces setupapi.dll.SetupDiGetDeviceInterfaceDetailW kernel32.dll.GetSystemFirmwareTable
Execute Commands
C:\Users\Seven01\AppData\Roaming\Windows Update.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext "C:\Users\Seven01\AppData\Local\Temp\holdermail.txt" dw20.exe -x -s 1632 C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe /stext "C:\Users\Seven01\AppData\Local\Temp\holderwb.txt" C:\Windows\SysWOW64\WerFault.exe -u -p 2788 -s 624 C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding C:\Windows\system32\lsass.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\sppsvc.exe C:\Windows\system32\WerFault.exe -u -p 1544 -s 224 C:\Windows\SysWOW64\WerFault.exe -u -p 1908 -s 296 "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_c60fe84466703767c02d2dff22c59b8767ea40_cab_0a6698fa" "C:\Windows\system32\wermgr.exe" "-queuereporting_svc" "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_mscorsvw.exe_e84e1efa5bc964adde55b3e015797b8fdc73d8ca_cab_06e69c84"
Started Services
VaultSvc WerSvc
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven06_64 | Seven06_64 | VirtualBox | 2018-06-25 08:45:49 | 2018-06-25 08:48:52 | 183 |
1 HTTP Request(s) detected
http://whatismyipaddress.com/
- Hostname: whatismyipaddress.com
- IP Address: 104.16.18.96
- Port: 80
- Count: 1
GET / HTTP/1.1 Host: whatismyipaddress.com Connection: Keep-Alive
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven06_64 | Seven06_64 | VirtualBox | 2018-06-25 08:45:49 | 2018-06-25 08:48:52 | 183 |
1 Host(s) detected
IP Address | Hostname | Reverse DNS |
---|---|---|
192.161.48.66 ![]() |
la-cpanel-1.serverhostname.net. |
Host(s) by Country
Hosts | Country 1 |
---|---|
1 | ![]() |