MalScore
100/100

MasterG.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 43/65 Related 2501
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 267.00 KB (273408 bytes)
Compile time: 2017-04-18 03:27:46
MD5: a9975d0fa1caea6dee9ccd43ba8c672b
SHA1: 77b166c2d95bd5a1470eb43bf380c55513c19294
SHA256: 2fef9650df4b92ae63c776b0df4c13cf19eb4ccbb20797b67565e37ed1006aed
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 UVl6w s3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-02-12 20:03:22
Last submission: 2018-02-12 20:03:22
Filename detected: - MasterG.exe (1)
URL file hosting
hXXp://[www].wesleymedsupply.com/Geek/MasterG.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-02-01 02:35:17 [43/65] VirusTotal
PE Sections 4 suspicious
Name VAddress VSize Size MD5 SHA1
UVl6w s3 0x2000 0xd2f4 54272 a59a62bcd9a6af9e0021bca6ad2c84d9 3ccaefee8444b917ce55408b1036fec45a4b76dc
.text 0x10000 0x34a68 216064 4a73c7bedd852e06036c501c33f081bf 32abb629122859f0326a69fc3c1b8ff6a7d6d0a2
.rsrc 0x46000 0x248 1024 0b7795376d4ebf06fda2fb210e012be8 8f6e9e881f4769727031958a1a396f22bad8d01c
.reloc 0x48000 0xc 512 dd61d2f7b42dff9cafed5257cb37ecb0 532652788b19283a3821ea0196754686d777ec98
0x4a000 0x10 512 a4f1dc63520859c36a70b4df26c91401 45854f5c430135718ba54a2994ec24bed8029e1e
PE Resources
Name Offset Size Language Sublanguage Data
RT_MANIFEST 0x46058 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
KERNEL32.dll
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
bc4519c8-fdeb-062
e2c4a01f-40b1-9d
5e3ff57b-7ec1-ca0
5e3ff57b-7ec1-ca1
5e3ff57b-7ec1-ca2
5e3ff57b-7ec1-ca3
5e3ff57b-7ec1-ca4
5e3ff57b-7ec1-ca5
5e3ff57b-7ec1-ca6
5e3ff57b-7ec1-ca7
5e3ff57b-7ec1-ca8
5e3ff57b-7ec1-ca9
5e3ff57b-7ec1-ca12
5e3ff57b-7ec1-ca13
5e3ff57b-7ec1-ca10
5e3ff57b-7ec1-ca11
5e3ff57b-7ec1-ca16
5e3ff57b-7ec1-ca17
5e3ff57b-7ec1-ca14
5e3ff57b-7ec1-ca15
5e3ff57b-7ec1-ca18
5e3ff57b-7ec1-ca19
5e3ff57b-7ec1-ca34
5e3ff57b-7ec1-ca35
5e3ff57b-7ec1-ca33
5f5b4bc1-9365-a8
5e3ff57b-7ec1-ca36
5e3ff57b-7ec1-ca37
%/P
5e3ff57b-7ec1-ca30
54^
5e3ff57b-7ec1-ca31
5e3ff57b-7ec1-ca29
5e3ff57b-7ec1-ca28
bc4519c8-fdeb-063
5e3ff57b-7ec1-ca32
bc4519c8-fdeb-061
bc4519c8-fdeb-060
5e3ff57b-7ec1-ca23
5e3ff57b-7ec1-ca22
5e3ff57b-7ec1-ca21
5e3ff57b-7ec1-ca20
5e3ff57b-7ec1-ca27
5e3ff57b-7ec1-ca26
5e3ff57b-7ec1-ca25
5e3ff57b-7ec1-ca24
13W
] ./
z_sd
^.<g
3s}TNI
a_rS
:_WN
C=S#
8#Ah
MOw$
"8b)
]0n-
XnXZq!xV
6~uu
M?@2c
EkVn
[M1v
*_o}.
PNG
39+@
5GhB
E`x<
~A~A
qz`<
6NQP
G=p0
+@]p
H q
7`%
L>@\
X#Zn
:_`)
_C5&iIo
>*bO
r )f
T^j4
f>7$NO
Tp{,6I
f;<pf
L3Bg
)+a{
^0#1
<Lf;{
]c@]O
>[iZ\W
{Jv_S2
l327G
|T
\=|fK
si :^
as"n
cem8q
[qm!9f
T~Wh
7aES<L
qc'K
a:yR"
% ~?#M
I`6MDO
RW #
Zime
$qW2
d,Er
n(Ug
C0]Z?uMH;_x-}dq>yq*^5d/8$
S.V(E$
Lw SS3];9
)t eI
cL1o_
v 6{p~
oh<N+%
'pVE
VDXc"
n{EW
B rP
b' v
|HXZ
_RzD
T5]r
]ZCM
(GvM
n7l~
9T&y
~1qZ
5<W
ztR82
f(}`V
R0pY
I]
h\3^2
k"Z]
"'Rw/E#
&6q8
Mf X
6Pc:
Pfd:
*{o.
(=u
;ja]7
SvqF
!k5z
Marshal
iv@n
y/ a
\K"[
~x aa
7y]9
2ed}3
iYLRbUU
t]bK
C<KU
7&W o(bN
V=x8Q
c+V"A
m>s?
^}xp@-Pw X|>|sAbQtOu!!n0*
8a!R
gF^(
o:J3
F-es
QF#N
!kY8
!9[{
V0a-CT
op_Explicit
RuntimeFieldHandle
C! Q
School Project
+m` ?
y['ZH@K APeR%K0^l`L|[:mh!
wy0
A,!S"
-5dcY&B
]vzU
'B:rH|%
kj^*=
w| W]
7F1 kTp
!mB_
@y"2
%jq@m
|#'
9,Jr
}X!-[%"DVKI>R${8Bu?r`zOv"
M<EI
y_H
)lO#
qrkk&
u(ba#
Hq S
H5;;
P?t
$9'
@WctL
'L"G(;
*;LFF5j@_##{N$#8qQi{VT=i"
^ d4
Z7gn
InRl
w,?*G
Aq.
aKF0
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD@q%
[=[A
vgEC
,hT;
}7>c
" 9_
FYk~
;l!d2
[>.4 ` |
@+^1
UQ`\L
40z#L8
;j-]
]pC7T
JQ%4/w
a<6w
TTD)5jW
Be`!
)hr96
<xXw,)
W`l>O9!2% 67QOrWH6_nMQ7J-
p|2#
)vyWeSiy9
a{$I
2Y%aQ? ZQ
^>=9
1 {y
6 ]20
+K""
)qYG
Z|8V
n& 1
AK[Q
IUmU9p
L.EO}m
~HVpQ7^
Us#iQNd9QM=m`XM*1)p[At>v"
!!Pgz+~g(gJV!8H0-TR,A(CW-
&#?.8P
O@ap
;E$
CZ8j
jK*u
[ 8h4q
Sm !
q6*y
A' T
d|3@W
9ttFK
>2X~
v~Ad
Enumerable
/%i
y~1l
*R j
Sgrz
AppDomain
j|m2>
x>Sx
1&$%
oCyeZz
bej'8
a<j
ShWeaX~
!>`xn/
get_CurrentDomain
6$ n
i;^l
I<5c
zJdv
6G`JY[C )X('-X15#VIyf2"0)
x aY
l txu
Vy VD
F^57<
l""B
}rpvS
3'})
tw7;5
H?(tchgB]{^#gm@9P,{|* ]i!
:VXk
3RVb
J}Q:
?*:?
R7CT '.
.;o:
vCroF
rSn*
2MdU
[pnYm
>^%e<
9Y&wd
Y egH
.`i[
.7 8Pz
hZk ;d
Hkhw
AssemblyTrademarkAttribute
22s9O
(u WM
x09by
UW g
'}r&=h
@DE
\ZH: j
cMCr
<i!Z
Pwfc
R:AK
S*'u;E
'=mK
96Orz
v2|t
K5O?/
^ uEb
+pS]
|tU?^
E.fU
#Blob
`lX
*G{5(
N)W}
C'.~~:
]r ]
|]Vk
% i~f@\
z +"
t0?^
KL&\U
OnStart
}% 4u
Ekp\[f{
USa\
HbGJgvH,@NpD$nc0GX34fQBo"
+ d^*]
kN!\
KeU=Y
:R),
4%rO
*}PP .b
pBsPD
CdZY
B 9^
gfz<
b{>M4
kDp/
YS)~
TIM(
!6~m7%EMY%!3`v[#iPm//(V<4
Type
\OWT)
Cyb UZM
['wWb
v?y3W/4
!fL,1
{`bk#^3
U7.
Q?1?t6
fFyk- '
! #}
vZ6Rtu
-J]r 9
VY6I
_}y5
8115
cS~J
Q|w5
^\v
C]q!
\wz:m5-=
Inuq
tW {
}E$q
^:S
6sxu]|
L 31(n
W Re
vo6u;H>
6^Y!
JIoMx
Gj(T
Sv_SoA
ptit <Q
&~0V
Char
8HTg
(=|
<j t<
75Dn
uv@\
F`xQo
@{FGI
q<i)
e4awp
S(T0
8^ T
j.V2
:s4zu
4M|MW/
&unkHO-`clwoUb#1IKn7FZ0F!
[ko*
9c}{
2U=Z^6
F7"
T?"j
i)rR
%^lz
BM-@
K|\#Vi8 ~-Y]Q[=U5',+@ya\!
@'7e
XiRB*
55c8929e-044d-7e.Resources.resources
A8h=
12K*]
T2_W,
3!d
TC}K
+(HT
e>S
1[Z\ H_SY"
u *@\
nt6w}
get_FullyQualifiedName
Rq8
CJF
_cS8
VU #
{ lD
Ee F2]
%\8qzC3q,?"rkwg-gyE+QM7P&
[!->
=9rSE
lB!>
6%6;
ic1<W
w+ ?%+
5ML3
_zs=V
m>/
ZenE?
Ye'+
Data
E6gM
"]j0H
;>t=
L;Uh
mD,]
1[fYJ
`f.
srBv
gZYE
Rt?K
1$_P"L
-vX>3
o,`
6-0s5J
)*>$U
O"x\J2_
Hl{'y
XI %
?Hc<
]H}*
"u6&
a:dQ
[VSU
jO
Pc6
2A"ue
"q4cK5
.text
OU([
qdb2
-55|
)|.P
GetString
N+/)
7V|(z
n`I&
(C.u
VUG,
Emqt
n&\8
HQ2D
NiM4
r#&O
Xwo&t$ro) f
@~R{
P)%vx
5G[<@
,ZZ
~+K#
LX7{0
732B
V N6"x
3=fW:@@i&xvKJHxn7Y&7~umK#
|5\5
,"tH
mUF1
p]`0
4!-i
anO5G
Vlyd.+
aYV
l\tm$
=oWg
'3sR9
tR\ =
V42G
15EX
TUnJ`
AosjX"
vwkE
O_E{|
6<r'<d
GH~?"
T'bw&
(<8 t
j ;L-
S~^,
Ih?AV
GZB/o
sf0lD<o
1{KN
gK+D#@
pr <X
P^FF[r_
wgoGi
XTMU
QD=
r!>RzR4ByQH,/0P=oh7 y/[%(
W1Mj
6pJ8J
$t<&D[
K+a#{
Me_*
H6J"
R8#70
P?oLVp#
;jlgG
y]4(
'_c|
aBqC
C1u
[jD%]
`Iq u
{1gI
`~_&%>ZP
VG@i
7cT\
~T*7
q~EEs
q)%-"
X%h
fMt6
jc5p
mVlz
2zU/
H4L9z
}s\!X"Q(g5B7(?8W%D1 51#"/
uaQ;
HdWV
IRDU
+/9u
Rko
r_Bh
`.rsrc
FSoVl&
S%Nt
u_lv
:Hs!&]y
/PlN
oFha
#?=F
};pJ&
F74~1v
blkwV,s
.i80
z:"OGb
A8HO3V
kernel32.dll
'j|HQ
tL"%
+,Q
V'$~
.qbF$
oQ?^@X
+~*cW
qLoR9
)B|vPRMjn$,K-VwCQ1aAF3L$&
!Db'
| 'k
CGoD#
c~#qJb
+?qK
qC7Jw
nQIqco
N5uO
$ --
6&u~
u }K
_FL'
30K 9@
b{G
O1I-
-U X
BCi4
8*V?
9D|p1
bx3x
sl9>
S 05|No
C?CE
jRTy
\~(46
<CW0e
W !X1
Uo.C
~cQU
_a5kt
/kyzv
/?Mn
wgDl9V*
0M#=
e- 0
O_I.0
7J>`d[
cQ{F!
%{bw
z|,tMom
x=8y~
T`8<
yre
beY'Tv
!7NT X
C66s
:%D-
szM`
*gng
2E
Iu.'
tD{L
,qj
@rt7
p4H1
%9AV
.'(+i
OYms`
6^Kq#
4Y)R
o=!
9] [
@lzy
z6qf>qEe
AjZ
,DL&[1N;(pZPv@?0#DbSC&Jb$
-XV-
?P(3u J}D+d :d+@J(,V?PV^&
7mi/
<o<\
@1_v?1Fzvn/ \2^)vZeH'hAp>
RY#0T
}<b
Iqg F
Y t*
D^S/
I1W{
dzK.
AOEE
bjC~
=&@M
(
Up-il(,Hs,}a g&;t|s=AD2N&
0UzM
9r?=rzx
)` L
:/0:p
/ o
Jl}EH`
\_\C9
d(r5J
_A S-j+
`3'v
jG[WWk
}=<
pOfE
PMC$~
@(LK
_3`
G"m"
A:7f
QNN #2d
3wJ?
</!h
'_g\~
7ino)
G6lMio)dk]tTC:xDk&']-k44"
T.<X
IF,6
YviT
xWp"D=X
ZR0d
-4!0C
Write
S{y:
!x%B
'[$S
1%NE
~6F$}
+R\|zC{
1nf]
!" 5=
'z-^2
SKvJ
Fd}v
Iiv,
%~lk
nOg1h+
W4rR
9K7x
6x?*
)eb'<OF
d +e
B\n%
!+v
bc7apK
us rel1
dsc& ?#ZuC>cJW-6?(0G=h&R%
kC#"o
lY'
-&aV
<U.Z
ruMq
^s#V
jyo1
~hf8
Bpix
{<'woG
Oo1"1
mSsu2
G!U{
#"9^b
sIDAThC
System.IO
R |N
WrapNonExceptionThrows
s EE
pT#C]
-.
w$"::
$z GcU
Dk(XS
oTn`U
6g&@
"XzE
s g=
8/X@g
JFJmqK=
sU[w
-.+Y
/j-"+
W+ U
yyzXn*1
XZmxm
tUm1
9xQ 7p
@VY
EkhV
*c8i
F K]J4JwaT@ews: |7luA*zc
.:)!}
l{u4
=Xz=
67cW
?!-B
O<F
%eZ3J
;flL
Z\)m
Xu%Fm
/AhY
+^$DxU>T
n @
{7vi
?p#
STAThreadAttribute
t+])
wkO
F84R
D=Fr
pAn"
C%"D
% cVe-R
yfAF
%>$
S bje
IHDR
System.ServiceProcess
QIPh
V~|%
cZwV
V~V9
gmva
WY$7
f4V53(
#&_t
g_yNs
TE4e
9^Up
h *p
CB:F#(%
q2U
nb1M
=T2z
n-
fFVh
=CKR
V`W3C4!Lxm-fZWjt:Dl#jViL,
/0@T
Q-G}
f <A
55#i
),q:
\; 32!#
jJy@
nY&Z%@
19U3EIF:Y_;KvDEwt/Z7id ='
{yJs
y6w17ZL
System
z}X(
@vG{
DixR
59Dxs
V3 Y u{
X{q ]
/1}dg'
<)P
l&om
y zs
]OYHP
?>z\
!,hc
<&l#
: *.
dF7t
{f,,l
`p ^
<8At3:zm
4b\D
E/@W
& XU
XTXX
v4e '
6m37=
' 3^i
UY ,
3JXb
' vDD
YK+
C`'i{
rCXY
CreateInstance
k%
O|`r
="d>Xh
X(&u
2gsZ
nV
`tgC
EJUs
cuV[
a :~N
oIDAThC
+(`n1~
7rjT
MethodBase
#Strings
63 ja
}/`Z
lu3ST
R}QX?92
{:bY]
q-'s@
eeI+
oDY-
_J\Vb
l 5&
Bkp4D
VHpFKm
c *m
]4&*w
P@Wj
6@PZP
zH9Z
z=_T7
>&]$luc+hb|or~3\zQ vcA!8%
*/1.
$a0bb61f1-9c48-4abf-bcd7-a72ede74fe1d
WR}
1 b9
#7Gn=
q<$j
uHd0
VirtualProtect
ptQ;
!qMh
Fwc~
^4l{?
wHWwy)M*%)P@rZ]Cx3G@7>,Q!
9PdX
s%*C(
8Ama
=[C;
RB>I
-x
/OZ?
E9IP
xA d
>Ofiw
A)NJ
MnA0
get_EntryPoint
<9Nojz
m}D<O+bTl' l?9Mz}C;QO9eQ,
%lW
t1}+
8 gC=
SeEij
GzP(=#
l>sU
`]ev
1s^u
<^oz
Jeaz
aBr";S
=t~i
VYx1
_Y$+
a,=l
]D8A}(
p!Ik
AT1:
^"?b
k4mw
,\!W
pKPm
#&0>
$ 3b
W|C*Q
|:;h9ZT
h/3wL
!Pje
M(Kb
Cf r
AdYy
mn*I
RD-2|Y
^N%@&{6
>rr;
.D<_E
wIxa
'a%@i
>>)G2
GN.(
6Nf|F2;6~UU<2V$!8E7tD</x,
7fv:
6 +/
< N<-l
>,8HJ[v]`
623V
>rU
Teg-tW6
<iac&
Ilo{
P8;K
X(,!-
1e}p
cw&^
eTG
Z[J
f}R:#
fl*"
EHum
Guge
{7]6
!<{xA
=44[A
7YmvR
y)z2
AX I
uI0V
C:z*oT0
L&-?y
tYER
g O'
drX`
Ma2jdooD-0eE;PCawo2Y}WbB!
!wBF
XbNw
L-si
` Qm
)_0IO
-ii
OzCK=
&MzSs
*?RQ
r
Qn 9
$+:n
mG7M
>L|n|I
J,u]
#]B.R^
xEq>g
8!+#
[UW.
?9a?
tTj,
O}`K
ufWd:6}
v# t
?w=(
OD(M
w4 NDn
~q[(
^p?I
f5YZ_&
get_UTF8
yK7X
S!$H9
WO`z
>QP+
@rZ6_{Z
)oeMv
eBNGu
nlRb
aY
tfVF
^ 2/
48(f
-b{W
]l6
v@4@
>NN
);hvX
vC?h
TlWH
Ao,3^
{dy-
SBF`
7++{5pK/5[gm,||0/W<V:oP''
c+1uf
CYE^
i[Xg
D Hp
8$C<
cu7~/(
z~S<
vLir15
iU&
[hMmO
'fV@F
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
oR9u
s24~
=n;Vl\
>Hh?{QE
R2Qt
C A>e$
)8,NO
DO>K
F}`I>
!zV
zzk.
gCl|q+gBE_#%aAG\acZW ft<#
%a(H|w
};%3
_f;"
aH=O
;xf
\9o}
a\?
A uZ
\v{V
Ey*Z
QE)-
$SX"
e9JP
vKp+
3[,u
^\ TF
<031'
@[v
c5 }1k
yw^:/Y amStZ'CI>QWThU;Ai
BCO=7
(dR4
F\sl
)>9W
_,_ju(
"<^@
8'Y-
"5;:
System.Core
V$n#
F%bQ
!68~knGFP!}k(\&mN#fb0K"V!
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
>$`n
!EwM
%g |
[nsc
na%g
BA*1
@dAH=
gCX+\
n;ua
L@L=
RuEz
/l%Y
(=b_
+Q=XS X
2AHv
iLE`d
' N\/
18k^
O L ` 5
OghA)i
7cR.
c!.|4
J59A
9x`.y
, gP1/Hj
E1.X\
:9&CB
5P?*C;oq
8#3Bf
NGQB
,x8g
5\*e
<T 6
Y(.F6
K rR
L:\F
L +e
AssemblyCompanyAttribute
D-v|
)C`
RunInstallerAttribute
djWP
l Jao
Jav?
,=6M
9\} #=_F
s!_EnL
IA\EF+
Lz9-;$f
b1S#
@iD
6,l^
6Y?V~*
u=nB
>- %
'G|%
;+Mf8g
O7xs8X
&^`Ww
x#2|
%^*(
=MfeP
b3{'q
j]_h
, q
4?nB
J_`y
QcSK-
+qy
get_Length
4{|<
<-v.k
hT?\
V^(Z
u7lI}
D >MM
*4wQ
Iyq)
~.*2
!pHc
39=j
.=T d
M4 (
4kVw
HdhI
eRH7h^_6
Sj$
- f^
kM'
OH,
'2`^
Yd#%sw
+G3(
2B'^
uQ"E
}IES S{wJ>{qL,M8{LPBPztV"
&wd5
5~4"
)p[,
OEn!
TwL z x
ValueType
=49<D_]
6L}F#
`)G :h>
W,$v
GuidAttribute
x+Fa
LNL31Lw
ywa;-kd/
Jb*9[
#X|A[
'=VU
Up\+
Or]F
^CKCvp
]tL/
O#cU
2s/LV
#d25
W +/8F
]dX;|j
_;W=
egV!
w\ 8
!J ,4
GrBz
{ihF
O{Gh
WzEX-HrC
/E7.
24
01>y
j -Q
,0mAl$@\La$q@V0rVK2bM36z%
?.$c
lKaS
*6yR
8.)d8j
D^Q
0rA
sd`>
:a %
<jr8
d:TC
]`'kD
^^]p
tsbLM
;?_V
LZ1t
l'N'!
wHwEm
$6pg
a~o|#
,q~x
*8SQ(a1tq_VF2-F&(F\kM]7|#
'v &
|Gq
0]d)
G]e~X
E)[J0
CF2^
#?yY
#j IW
Q}6$@M@
||aZ
!e<7
, \Sm
pUoG
UInt32
({P1
% %
pN C
O{:M
|OJ=
u\n)[
pIDAThC
sky5:=
c3XV
A!0.*^
ToString
?6qVEm
a:(z'D
J1\F~h<
QQ.A
6#h
d2`+
9$?%Av&
6Y@M P
Ay7^
"Tfh
"U(|
Z*5Y_
wyyj`/
B*":
nV?bLMKG}tp(A<!N;`8:HmZ$#
URo!
3TJWa$@{i^"|))sqQ2hl+A'q&
BGrO^c
Vfi
3IoIG
PuK
d3b+
'D"u`
a cx
^ NToP
ServiceBase
D J%}
4a99
/$yn
a.eX
'[BCO
b#dc
K!:IP
Pbvf
VU'Nan
4!<c
#p$r
?X5b
2J<{g
GBSD:
Q6d^6
4:Cx
N:aF
V~P[
, ms
,ON!7
bDOap
]BA"p
t%_f
u#;2Yk
Tp52
Fp|[H;T
ZNm`{
AssemblyTitleAttribute
*-U5Dc&]q=4O<Cv5URb~c_{X!
Ah>_t}
$-ef
5{6g,
+cqxd
dY'"A
1S<k
UX_'
-q(/
e"&$
.ai_^!
G2ca
@jd"
]tHgb
:xc
egcX
hQK{
>)%`
}Az9
2_:=
Installer
UX,/_5
? h]
~PpQ
\5xV
ZgDkN
nbZZg
{~ 9
k&d`d}
uV>|
T%5s
1`J8lxgo
2Fd;
Combine
7"#3
*UjJ
pe> "
sdCB
fsCk
=C'/
Yw!d
T^AIS
8>%^9BCtR*kSIMO1m^f(@/w~!
[glTP#6
>}Q)A7R(6006:gv]av=twZFG%
8Ik@
sUWw
57/*
xk< V
W7Lz
(I!`
I_gv
.$y(
S4> 1b@
&t=}
tG$hH<:Tj
Va)(7
V]Er
Seph
=amWZ{
k%-u$
hAZR
fD/e
k/ek2we
<_$c
_X(~-
$#?x
+qh'
(TRJ
yX5b
|mU9~
m;i]H
Me%8
22^v}
D>(NOjR
"E 9
0AQ~
\2iHqD
N=O|
>WK
Rg Q
bkx0
0tX|1\m
$%*E+
C1`2
tR W
pHYs
.ctor
BiG%g
%GmM
-@em
k 5 _
Epz6u:q
!^5|
4C6R
LFV<xKZwy&wWGT[51;<|'<5a0
49 w
mscoree.dll
Container
._dC
6BUYR|u
yA4s
^ ;/e
AX Xb
`L|'
G{KJ
Ah!
S>E&
f!H ]
m.T4<W
.p6>0
pj']r>
f{d#
b&+^
XcK{5
UeDk{
3E?'
4`TG
P1^w
Invoke
5E
ho1
(S:r
@LhoI
~.]m^}b
li"3"
" cc-
i^LT
9iD~
&,){^
-VNL
15l;f
x )=4
| ;=
x %2z#
R~Ks
}$(f
[Jh Ng
XZLiF
V!,Dz I
\t3H
q"H KA
i,g9
n@o4n
YS;B
e'u#
`,N56"
w%3I4,
}E 5
m @X_
PCQv
'<wL1
w ={
Module
F9pA`o
P&.p
&3]oCc
l}1Y
c~$S
z/xM
Array
,yQM
paiU
g'r
~Ugy
f# z
X O%
a=bx3
Hn3!\p
\W5=
@.reloc
</4;
h;;@
NFy'
i n8
^l [
G w7
X`m'
Pjy|
PyvE
x)eeg
15_N5
X4ofAF
Fgz
d<s=7
2wfd J
MGC]
ES2C
PIDp
Byte
get_Chars
jD?=
JqeC
EmQc
G ,(
Pj1G
PY E
VvNu
$!5rE
:y(H
+3Ts
RX"/
h3ng
.X}'
# dV4
!Xcuv
55M>Di^\ oE{^!mBzrm*j/y>"
/8F.
z8,m
+[*;d
b?WHM $
2:uq
WPL6
c .#)B!
,<Vr1S
gD7|v)
6&^Dc
IV h
:<vW
5hd1
\,JK
Tgb.ZEU
"_uc6IBhV+WJ:d|"sGMRtvYh
iVrcE~u[(X~pd"_{+!zj|5L|
Gekyzhuxu.Resources.resources
wx9v1
PX _
<_CF
%Q6>
"!QB
gqBF
V]H</Po
pDm3DZ
T.-6a
4?N1[
SY2!
]f4e
<! -
B,$%
*1yd
\jT.Hm
'Pb%
=N~]
wJ,,)Z8#I-`388M;-"}h}xIm%
PK|I
R^z)
n"Y*
Rx8W
dYF)8c)0[4CXA{R#Rx*rQsq?!
Nv!+
[*b!xs_
c)X~
v"MX
?!L4
|cx
TMi5
%`1
. y Ey
`CrT
?IVG1[9>
4^NZ
R'kg
b,]>(
K@q{
V8EN
p3yW' I
`+d?
Z?zp
CeZ
7;y9
Gcvm
Qt]<r
7;y2
|<_k
jsLc
]uW0
:\Vo
U%vV'H
6lV_
aure
@Fq>
fP,l
J]r!
~lPH
5U=Mj=w
ts:vB
:B]Z
bFrrc{+s^{>Y[@r#s>`_b'GG"
J _1
9F\Z.
R2A#s,
%BV7B*(z$^BSA8ZgPOM!@k^ #
_/ H
T'!f
cb743
wk>H<
od#E
iuZO
/FHm)ev
@1>Mi=
P,j^
mfP-x
Assembly
2 }e
W)9e
MDhl
NMzX5
qJ//'}
Iwqi
':VF
KyV@
r-Q+S
#&J
,|{G
%iV3
R]xd
V gu3
Gt&I
HWR<
3o-2"g
,1sy
o//U
jeFP
oS ]H
J? 5:
9WBAp
+ cpw
g(kXxr4
;-iQ
& k1
i`gk:
GG@shh
<w@x
>(X'
&8{F
Nn ;
[rl
N(UulB>kR:jI-`|NEB(;`1Mc$
iT/Z
s[_t
2f3k
t[
nS2m
sIjE
i^]C
9e5
set_AutoScaleMode
iC)J-q
E pV
uIS,
hnzp
tR6M
zSL u
Mt,`
|$X]
+.XL_w
x(@NK
b(~O
/2wh
G 3
DSqu
VH-&N
w)GGT&
\0(@bo
<:qh
7Pjd
}v`,
Bc03#j= Aw
qejY
.I i8
IContainer
!lRp
R]O9n
T{|3M
g $]
=cpwMV
jG{R_
8zaX
Y%pe
(TW$N
W!K5jIG
u1 -
pO n~
#?7y
9Iz5
W;Pj
oh9+ZE$
VFK;
:45^
^GUP
jz *
b=/Q
Q5BWC
DP ;
Aux?
J\8I
pVYKD
s=%Rb
ISerializable
a!k1
nF`L
7+[_
mUZ,
\<yI
8y6xM
<~%_CO
e~'k
G&hy
59
>lbQ9
%2fq
\"#[
m&5rv
1+.H
NjJE
=GA
8<%'
LHKHqu
-s'w9
ID$_
r)'x
!qPE
,[bg?
i 5)8
`)p|
#YKV+
ZIvB(
QAyw
n l+
b9dn
,jtMc
3Y,r+
~B5J
~ga k5
|.(>
k[9*
4$MtZ
c-eo
0Zy3E
U2uJ%
N_f8
]KMW
nT|e
PtCI
+o{v
)M 2
]SV<w
zH{"lu
RuntimeCompatibilityAttribute
{\m<
>2=%e^
E# Qa
/C$n
{13_
' pY
UYwhu
9zV-
\ w
ContainerControl
%`Z(
CQ&JI
Y?!^
9"DH
4^OM
R?19
mqO@^)x(ab+`{FpkGT2L4q>Y"
+;Yx
[+
es 6
tvD7
O!$=m
=~Q8
b,Y4
ZmkJ
ReadByte
u}la
:@G_
}d"-3n
0F(D
nj m=+
CJh'
<&><
CC@P72>T^|#u&PqSa8nvL'!W#
C#a]
&lTd
uz>@
bAcl!p _
$6%
%(spS
F9u{
c)ge
E2-R
-om_
HHfm
pq+B
"#EcjN
5+_,
- dd
6vX-`
b 2uy&
m,dUe
t;tj^H
AssemblyCopyrightAttribute
NNBro/
@%"\
~Gir
_)YN
X4E6
z '|
mQsl7
>%)
gbY#
c: H
%hPa[
HW#w
J=#I
Q(lF&G
6j Wf
fMc;
dFl =$<o
+m*N+
0a="
m8r& S
59
FZdA
vQ{Q
Y`Bx
mzZ5
W8NuC5E
Av{"i;
to]
FEaG9
wT3Z
ucSq
q6A
"kB@A
'% g
Z~]J
*7)p
G-qcs)
9{LH
G^n{
$CuO
#F @
Z+a5
ZE0t!>r[Yaq nYkfX]K}`N&X"
om=M
|mg!8|4#zyE4Ev?:=Wl;"9*_!
l"$'
U,*%Mo
'.Ot
>B(J
$-8
g^Vw
gr a
]LY8^
84J#
:d*Cf
2"<rgJ
DH`:s+-8f3B]k>r?T6wjd9ik$
_iUt
Z3V-+v]
g\_.
B)xw
:}{I
|._9
I!Y1
bsv
MRT1
Tc2_
x/N\X>gurL*o\85]#A=a<2R|&
/lE.
6eu?
8S-M
ld;K
` \XY
;gZ
j6 (
ALzf
Read
pyop
Z3w3)q`$d
Intern
13/G
sRuW
"H~h
h_ZM1
&\<5t
jNp^
ztUAI
+-_W
_{.c
&xrnZ
`TG{s
E~]R`
0j^_
Q:7
sqXj
\Bg "s
}E-f
jc0=
rO],W
l%J7Xx_)t96_JW:J#tyYUJr8!
A'mz 3*
cQy}T\
&.'B
1/mF8}
kuzSN
{:\g\
_r<x
n^IC
.BhvF
hjpc
gAMA
r:eZ8EaEcap7%m<WID|$>%(c#
5:ij
XK~2}
u~#
/@ :
2!x*s
,>17e38V XyeTM$-Gq|KIJpC"
+ADL
]y`:
T2 'G
-(ud
{oe~y ?
JP*]
6or:H
%mPIF=
5|G#mT
/VY=2
6-2K
'<0R/
@^~~
It}:<<`G@u)/BInE=o&{m:ke"
Q"Ya
h~-'
?jc3
<0)
Dy^f
Y UO{*G@
.cctor
V< c
;w[5
HX&[
Vliy
mscorlib
rf]p"@
6T5.L s
78!Q
;\JY
MX
<R>`
)JTyJ
[ dm
](8G@=9F<;L0"C)xoIj7m-,p
3uJ3Z<
<HLT:
(lVqd
>uy5
L+ EW-xk
DEy<Z,
;_,!
u~mSv
e?gX
[]q`
,RCY
7vKDJZ-
STF
cSJN
cv9,-i
EH:?
Q-|d-
55dg
Mg+k
n;^R
z35P
@bNq+
%`7 r
&Be[
Udwt
W$F(
`R7b
)rLF
ryzi
bGBu^4n
w)H
q3I3
huM7
N|;B
kRDVt
z|K'
`v~h
VW@#
ZT?~mc
q3i5Q
[0Zp
IqK;
JkY{^+)
~vCx&B)war GNrtOF"9O29JR/
System.Reflection
+5|B
_ a@
Iz]=98tezFYo+,Bb~Tw2kabL
4OlMX
H@Ar
z2g2
', B}
a"=
%Kk'
RuntimeTypeHandle
]]dnBGeeV
0uX[
-x"b
-N91>
Lc!z4k
zj^3
aZGG
DT5k=t
d4>-
Li0
U#Z;$ %G Ev
D8 g
c<j09
4m4UJt
rN~h
*y#0
t^5
$AY_n
RJrl74@_
z}Nwl
5Y/nn
`,oo?
3UK1t;T
Q/]8
|tXL"
'ukp"
@3Eg
"A}qF
N$.1
5}'/@}(b>55J)o(z#!EV`c7{#
@& N
+g@8
Append
q)tu
EH/5
M^M;ME
7{A/;
^lAu#G7
mbW;
+?&FYL
7h "i
l!avwc
1^~8
_3O#^F
"msmy
7GfXD ;Q
(Io"
RZ.C@(M
Is2
mkqK`
+~pg
^QF&"
:Jh9o ?
&$UK
X._e
7/|K
fy73tu
M (S
?n<9
\T(7[
E}"m
mU -|H
Ky$5n
-h^E
~;v&
].;t
AssemblyDescriptionAttribute
)]2qU
.Uh$m}4
rh0P
'UvH
Q)~(~
Zm2 B
z1}]
Le!x
j#t;z&"8
qEU{
O:-rgs
.:T*Ct
E$}S
1pdvS
f6b(
[u0<T *e}
&NO]
gfWH=
M:BW
{XJ:
(:O1
fu((
'Wd0
t\+6
OMuN
-ikMw
YoWa
P+?zh
\\\!<
9lc&
3.u4
0ew+y
*Rn2
2PNmd
~u::w
B=~D
$C?Kj)
(Isr
mAg`a
im7kC
E+W)}
1"!m/
ztcg
SCu6
x]q$
56,5
j?vf6`
6i6
Z0AQRM0E3\x00am46sw7n*@2
oJNl
|xR\
PF6Hr7
0KIx/ewB7
System.Configuration.Install
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
;^QPcL
d 7%c
Te[=
4i}*Dur
\N<]
ZIY0
_U%!
hvKs
. Y Y
zj:p
.,,yJ
9S\c8|G
<96+
";<M.
y=N|
A8d&
v~<\
4EW@e,
Z}2'
$;%C
[9AE
rAzR
!This program cannot be run in DOS mode. $
Mu1C
f`@[
Ygv"
2sq,
op9W
c5=B
BKS
^E{ 9O
.}18
p%+ p
kJU\
'WM3=B
Tu+c2AF
a\MY?c
|T~PzE[d2{/=W0YLT_9]':+o#
Dispose
lNIP
pC^SEO`L1!N4K<p!K"N@9 9`'
Ed'c
W10W
OTg1"
$`pS'<
_4)n
&(f"
n 78
S.uu
kL>'
j# 9
W:d`
]Dhd)?
LI Vo
mtig
J|0-8K kf,"$'P8-3xs%`m|f#
` ghX/
tdbLM}W
R[JZ
L ^K
Xq^On
*Opb
H}3<
p*&Hg
MNQ.
}'G|@
hn'}
`
[w=H
Mi^{
!N2?
H ~|U487LH#XU+6}f#yC7&n:
Bn`+
9 f<
T%!o/>
H D6~
;eIt
Ms P
2h`8
,}Z'j
4q4)
9VGa
[akgp
elIy
%o
Rv$zG
YdcQ
lF %
8L6T
k^E_
iK"~
&4[T
&Im\
RX3a
11w8
7>a\N#wi)d"D{W_;2H7*;:(+"
v+-3
z|IG|
BSJB
Z'UU
)oW?.?
99N
UVl6w s3
:1 {u
W_*n
Xj3S
$$bma"
!7l^
;uNr
BUyL
,$[@
|-\/2
'I>b
w Q$
V{V5
U9'd
lIDAThC
jsaSl$=
| 3l
g&p`:;B
rbOy
hgqE
cyL>
LKjL
Ja#P
:NQX
> NAV
Ic{13V
\$L]Dwi
]#|0
1h6G
y =b
bZTJrNoa
sa&5
1 qY
;|5/
^[Ky
IntPtr
9n:x
k|\A
{0qx
lmzl
3r~+
n(y)
%k ~
hIc"
q j=
CTD)
xb#)<^
2U-sf
a>em
u>tA
d]S@
~AU]CT.
}z.Y
5iru
+a DO,
_AppDomain
{l%_
"$iSQ
z+GS
'l4a
C'&@Z
. R
%<%
xX1?
~\ R7
C<usx
$7
Q?S?U
3?9`
v{7fu
&B6Qp
System.Linq
ywe%r,}
$g&yl
sLkV
z+Gm
Ys .
?xf
$|u7
otn6
4w\"^
G-GS
nfrj
!rJJ
y/wy
fYb=
1<rj
h\q%
D=3d_
E( z.
r2RIUS%J
#-g`
AssemblyConfigurationAttribute
c5.+)
\K$K
|z _
/R^g
])3s
9iSUU
m|IPjX.
b6N
OS]H
CLBA
BlockCopy
@yUrn'
0L{
K`<TL-&O]0_,G}zKzs-\X)@#!
C&*z
iA||
5pC!
)czC
m$}j
A~s&
I Ss
] IZ
fhU:
`(,ZK
dHg:
";<;<
$X<B
( R
~U4J98
K1n-
wgx
8d;n
US;M
b):{
7GW P
jIDAThC
/69i
}-6-
ty>{Ys
[ !P
~)|
h1 :*
-snjI
ng^,I
a;I^
}? i
$3f)
GtA1vEG3B%kCv7x)k|g}71kV
[T2'W
tVK^
xq MK
CN^q6>
c~JB
SQ|&
|\3X
8'*`
0d<\
u',s
n(a
WpN]
6 8:
6.#f#
EI3^5
EI(i
wjCk#
}) 2nu
K5 ,
6]<J
gBqe@
-t\Z
?&*'
_^ed6
nsH:
MethodInfo
!NDOv
f"Nu)h
Ig_{~R
IL,Z
X6)w{AP9$B
]Ih:
-
6P/; ]
,'?m
icM5
[;y:f
"5wZ
FjNh
%ej-N
{W{(
+ +#
YOHS!
]^#a5w
pxS3
#VU
)?;
$ Haz;
KtS^9*)
MemoryStream
q6{?
BD=>`
m&AXhz
E(xf>
e gEG
Y#>B
}7{`
2ZC t
o?.w
8k>H
Xr'Kp-;_NcSaU{M+X:x+]zgU
'u 8
nZ*V,
uhmg
mF>J
RW^Y
bytes
Ja%nu
2ql}
{B)g
!:.^
3HJ
<e5n
3v 3
xd',t=r)Zp>!&|iiy@+mO}Hu
;04lY}
"a\!
^ lq
!Iu
zhh*
pPC
rT|J
EJ9/
%xr)2
l ?iV
wW-X
r!9Q|O
IrrM
-{k o
x ~`Y|?@l'TSvIf08`|,45Rz!
|Q1)
]=eJ
r(1(~
uOPF
f/X
f4)
za@8
?w;4/
_?xY'
>Fbh
+YVF"
OnStop
aK[d
_M>o3
I&Q/[!t
F5]<
%4aJ
=]eV
{_K_0
!'JF|aW.#bt
ZP0LC
Yay):
kb) j
c|v U
U+S^
R8y%
@-y%
G@o)
Y| W
q3Y0
HY4
f>;{
>Iuhd
!3&
+$g{
j=d`_
#,u[
O}qSA
;3
gep8
"4QN
|bQ}
.rlu-
Qe8
pX,N
oT~\
^{I+0
C :'
~PpS*H
$Ba

3u}w
%Y`,
XXp]
B9/6
+_M#
&m[=S
d>u+
q0:h O
ff`x
;UgW
&vA4%"
JI>F
mNka
w RM
2N lr
'Q4;\BXj
Z5tzLu
Concat
`,^0^
G6 &
q#5c
StringBuilder
JriI
-}D
~ofB
} Aj8
'r9c
(Q&D
Z#reO
:O2$x80
#`/F
Ws.@
|&a`
ropq
/`KF
j C*
5~-E
Rg*6\=-Z+oHRe?>YD"1oawRj!
naX=
5YM(
es4(ZS
]{oq
-|i4
; <[^
DdR 6y
7C#zP)u
"y?]
`5J[
?TMg
"D^)
fDUvw
vVPl
=W e
58Y-1
>oB'
ML2J
C. $9
Oc t
L-Ih
f<7gN
]loW'
cwE9
5(<-
^JcdWl?LZ
`#t-"
-QQwdC
_EU#
^aC|
"^t! )3*.
A#{
J{;b+K
c5ueb`
3gh
# {
?_zV;3uO Cc&0t2Jv$\?[@6x
PZ:w
OAFCCXs
J-D4-
AssemblyFileVersionAttribute
R48=
6* 9
j1c<
Maqe
System.Text
px@qTF5U`^n91\0CW|t~cU*Z&
VT)EL
wQPo
fu.:v
o2=;
!B}"{r<
w>^N2
D#FH5WZexKNh;t+q(-xL%HK*
[<4=
*;"pwQ
~?zh
D#}=
Ib:7"
@5#\
5,X9
n?q!
7D>l
=8,6
ex R
+EaeP
<fF1R
!"Zz
d.FG'
9 Uf3
k'_8
~j C<%RX 0G
RR~O
!hEV
w27m
("%Vx 5Y]4&%Yn$SH_3Iv!R5-
Vs9D
q/CF:
8?Ig
Q%&
Component
GetElementType
PRLl<
t(UO
F59t$
aS+a
%6Io+
L3I8
=bk!
f:dGP
RT9G
C]b0
Hs/j
|\bI39DURsm6mhaG3;+zWvS?%
lvDX
Vn@huv\
\zg[1]
0 |6
-w)X
=<mz`sj5!+k\d4dctEnuGNN[
S$yt
APVSUa50e=P@FWj(dS ~YIDF!
^@WNlO/T
$Hld
f :r
P/ [%-
P@+#f4)3o)=uG](>5Lt:<OH10
~'eYf
D$O$UI
.Q{)
e?X*
2Gy>
]+@D
9;;?e
Y*T8(!lzF}}9HH: n'9jqu1h"
I3BCc
x9~A
2p8ug
i!jL
z/Dt
L Nx
U:!|@
*0[;
)43s
u`^LD
*P "
UiGx
6JmM
b (~
$QF.
Y=G
Zfx8
A]='aM#&7a`b{2f^0`syjfsk$
: % ;&
pE2'
_ `w8G
[r:u
cq"3
1MX?e
_P<X
3$Ah
Ju)5bUF
CL)f
G\n> Sqzi
DvZK
p4FA-
v6
5 \|
Fh x
=RE I$
v#o_
h48I2
O)89
:o S /
p\CR
$1qR
String
w zLRq
0"y!
6>V+
:#$'
_CorExeMain
#~YeL7
'tz R
=bL
<Qk;
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
J$7 B.
3frN4(
bTeS
}_ B
Wa/0
{ Wm
$pBm
"73M
Xk4P|C%
B \P
@e-O
31j"
o=y8^
8Nb'
_ =z
y$#M
x#p`
16Sh
InitializeArray
9*(l}
D7%Z
YC! zMp"+%"CUkQ"/1];EERX4
6uL7
W ;s-+
1/0b
lX*-
m?8o
#R!C
`Fo*
7d;lu
Ak -ed
ToArray
/7]_
{lGxt}*
, tz
L?zL
z;9@x
k~fhl
+ xW
4rB
4.q`
4sPP
;)L)~
[ W_
6i^ZD\p
T q4(
~cMJ
ZW5K
I02 OJ
d)=pG
#}CZ
SVd[
>5N+
2IDAThC
P6,V
NI&q_N
cY2N
!*>D
8wS|
_M{f!
X<F>
u28I0jBe
8 X.
uG%OB0
&u|N#
e4 ,
v"w_
X#5O"
"ITt{
)^P>
jUm m
S! G
h9;1
/.|(
MC{a @
!+ Eq
o1Hdn
n tXn
Load
mIDAThC
z[3%
get_Module
/=lKP
yc_m
g6UX
|\)8jF]
Dd !
j4$^
B71XF
oocp
3kz*
c}95
?}d(
7;ld
p;4Er
jv
*Zx1
L>tz5
cSe(
Y8'&_
Z7\%-)xB'
1l9)y
TL:n
V K>yx
*J#^y`
r! k
/.nH
v\:v3(o7>/;"_W*P:j@$JGo^"
Ouv[
C ^]TkhS
aG>[
(8`H
wN?In
+!/Kj
rDleYI%LKRV(c&q22I0tu!0/%
Pm!
#R F
_F c
A,\B
9- )
P,0R+M
e\^".
%l;W=
TSR%
Z:N.%
UbOl
DIZ=
<TH{
25[WN,
o (
@WO
|cw*
)z :
x=4
a:o=
O4'.-
T|sD
4Ww">
"0%7^
&42{
RuntimeHelpers
4+4@~
/'Ot
#>mT
@w @
Z eb
>~#ZR#%@K")UVWM"yO7zX&mQ0
O=?9`b_%<i
9.rC
#"5
AK&
UserControl
*pw{X
uc3m
gQ\i
H{A8z
<ua
g$Rb
-'PR
El(
} L
,.O
o,'IhDPd-C|EfV1H74{9|$+s-
C.`(Z`b
7/YR
Y2>ru
#T'`/A
l,O:
Pv&bb
5wo"
r9F \
CGq>n
^ECo
sKCs
Object
G]P& x
W]gg
,uv[
|> z
I4 "
< G=
MN,t
4Llf
G<?<
I=Qr
/-CN:
WRsY3
}Vk\
*dj)
ComVisibleAttribute
HXT;
q)oB
X`Tc{
Xd`$
)3vl:
[f,Q
!dVx>L
NWVQbJ
UdY
[Mc4
JW{/[
>^}m
&zL#
m|X#
?OV)#
9-nz!y
fu#C
MMN3
8V8H|_9
c/nc/
hsXNs"
kOsz
S|/A <
kIs9
ERe0_& $y{<n*\DGawN]b6uy!
) LY
T?#x
-xZ
(M3D
Ag0V
5^=y
Rp D
0- c
nIDAThC
m6yp#
~M K
RX ]
gWeU
AD ~5I
9LEaA
BQ4N
h~/=t
7cU
HIM
'm]$
I:-?X
vk6&`
bbCN
5SnZ}<
x\^h
^6y JL]
P<L#w
&i}
1.0.0.0
E" H
lfb=
ySUE
UUCYL
gRd@h
BPI]
E5*3
k5{1
C!,9
n*5!co
[8iy
gV{Ni
']?p
$<%{
CXkC~y
%3-`
!Q[1
xq5f
}G~*
D2)f
:ak|
x|MY[^:p
4 _ O
Stream
IDAThC
N^.x
ioiV
Kn4 >
OPB
U,PR
V)2h
GBs@
T M.zH"
t3Ns
kIDAThC
Q X;e
X8wu
;H6FM/|o2^iKI =n`)kRp8$U-
LQLiVL7Uf/i>]v"J6SB"YB6K
k"<5w4
AutoScaleMode
S \
*(
CompilationRelaxationsAttribute
dcsW
}7er
Wd%
4V9m
;A4I
g^G.,l
!pbnu
U-_Z
vO[v
uh;ugMv
=\iU
x? -4
f-FPm
G{M~
DaHa
??C}
<ra_#
XLC^
xD"0uM`
j7K
{~lIg
x:9(<
4czS
Pe3$
hN2 6
gYiI
s*xh
niSR
r}&g0G
m- H
W6XX%Z6({@!S[">tze(;9 |C
;P@
G953
]~>.
~m*#(
}[je
q.0|
}c7Cd
< ! -p
X A`
"B(a];
{/czv
L_|b
5XaC
tU{<2p
(@}=
s/']r
RO-F1
g`/}
V\ q
bR;T(
)[6V
set_ServiceName
f<~k
3v2/
&~ym<
2YjYy
(5^6
khUa
8bOm
MR&,Ad
Y:5i
b\>R
Rf+Qb
Z^3%
c@'y
jpF-Lk
R>(&
iz'5
P$E^
MZcN
m?ju
lG~Y
Qq)3
fBkH
',)\
L @J
:l i
}@Gc
;mK>#5cO\ur?k@K*LT1Tr_|N"
+ b_xO
2-q
.=qwo
Vi Q
|kuvfg
N&kf5
:.y}
pzqV
1oam
SyU"
6/7t
VUTRF
nt+
]MX%
~=Q+$BH TS/"c@F1UJx6c;TY$
/u&tA
Y#yi
vXK
6Yy-
#E#O
mq|">d1Ea0pWBNOZ&d/5U6_m$
O8|:
<g2dat
L9O7
Euwq
i)6vJh[uFTi,Vc>RbAp%{RVq$
Pw=<
"Q5v
=]r k|
VNu~
yeJn
OC<m
*)kK
ymq
SbZv
1_w5S
`2\"
~bf!
"Y^3W
du|z;Vgt
4-a\^
${D'
GetHINSTANCE
utBubf
/Xw_3
z4oC
VF ?^
Buffer
&)8V
o{|gX
$V?Z
?GL7Y
*>dX
@<oJa
CM &
;7b h
:Il5
9()J{r
]Xx(2C
(tLx
r=hI
TD'9
o]X4
Icr
.t8u
l\w4
pw=7Yt
.'@_
a,8Gv
F+eW%
S:ON
<KRV
H7<
;>AM[c
,wMi
\; ?
EY` t
~$fq$
]8M5
[":_
[\0-,GQ2!omJbx:nS|8Qnb8'$
Mo,-
Lvwq
A1edJ
90}}L
N@T8,
cl#<
lTC`
cwq4d
f$V-
[ -8a
b$N_
dYE
Ce=(
x_J
?<=7
>),7
r87<
8zkUT
!} e
LR);}
z '5
811q8q
krTg
D[i(Z
H7us
ooEO
5?.xW
#mey
;Q3Wd
RZ+XV
>J%6
91Pb$M38x/;eeW!`pa-6[Ti
gc}L
Tg_X
Hge{
&(m#c
?W@5EYrBR`=M,f[1dHb3|Ey~!
hWce2
MO,y
k9Bx
UAl
%A*d7
O{ug
Copyright
?~0e
So4m
ArgumentNullException
&0=x
Jt$Cj}=TOgjn) cg\i6jA;k#
H&ilI -
]6U1
4 WN7[u
Nwo4
$>5b^
~LZ %
lzD
&N:N
9[T
q{Z@
Tf[}`
.POLPT
L-xj#
a ~
4<*(
[)Y$
1;Uv
v2.0.50727
mt49
UM*
,=%#DIF
sd/F
Z?V@
@RA-
"M An
O'g!
;D4
Y.B|W
l_'7
v{ 1N]A
T`\F6d|X7pe8u"Ft]1"!Ik>]!
~@fG
9^0I
p|~I
1\H
sJd(,z{
sEw)
=s ^"
U hMn
gBw5
V {U
}mw+# "r^
eaR%3ALe%WlX)<7El4xxG=Rh!
W&)u
(1$K
/;?`
m<~\o
b%9j
+W<o
z 75
Kj{I
c*!9
anET
a$L]{*
(.Q.
.?((n
SY% lu
5-o>
^{p"O!c
]~R'
[bcs
\FtEfj
e\uc
2Reh0&L]
A`d*G
Rd<n<
[z/v
>K0[?
{Sl7
Hl r
.L9w
q7RM
vQ7:
tLOL
GetTypeFromHandle
[3cHk
B{g7,
lO{
_q<S
n T <
cGaE
@/v7
=}-&Aw
eCAya
ZUss}
4Xi#
;L w
FZRJZ:
K[+f
}vXG
8'}?i?&2lmo! !c!3}dRNR`>'
IEB-C~9
^":$
[UMSm
N8=?
` kf
/!?*
K" e
>e-|
TLyF[
>--n
y/ >Wj
School Project.exe
;SJ/s"
l&-F ^
@ f6
xOb)
/ .F
yU $
m@1T
%gU\
fDW{
Sc8Ls8u
&6:"
|6ocH
< "
L&6P
w- dH:
/SG{c
,cW2
AUto2
MCcNEL
Wr)
System.Runtime.Serialization
^VyK
|P#p
&xa3N!>
R~T?
tYnF
jaaR
DFj
~uQT
)>0/'S
-Yq#
4Gd<
vZeY
0{
1ojoQ[
,diLlP
d2-N
I7G}
p$lf
GaDu
-:r}
8yNs
7 @
E1,!
AjP;
Ivx9
a &K
){ A
KN*4
?FD\
@M'O
p/x'q
J="(
System.Runtime.InteropServices
/W!0`.
eD)2
_IBIVz
%J~e
CsH;
!9f[_q
Sd4R
]mS)
23^
Math
K%.DC
:Mqf2
ED<"
O 'R9
&e'ayFF
?a v_
7%/'
OSC@
2MXe&<E#mo!mq@jcT"]peC9Z%
M-ag
U92!
*R6Snl
</=9
]-j2
o]56
& 4,i
8Am!Y
\[Kt
z d3
B>UE
W-aw
IComponent
HkAy2/
System.Runtime.CompilerServices
wVF}K
nH0s
:_AD
X=V L/
SuppressIldasmAttribute
(Kn_p
;95
,2);
1j^;
EZ }
}31p6
Q1 r
`-zf~
IEND
Q(Ih2f]UnYY+e7r>FG`Lp#Bd,
)h_k~{_|q7"8s)aV}73g[^)^#
#,\
b*j
ce;l
Hk,m
Hl;E Wl
[g*v
yQe3n
`#n3
S ,|
sNmL'|d
$\]j'
3im>
]Ru$
oSdq
U]_?
@O>~
Z}'+
"f|aWh
h0J
2v $_\
{_ )
\sLD@'dxan;0D< O"US:|9Q}&
FpV@f
~KN=
ucYs
q*Jtq
As d
^: G
yzis
$N3:w
o+P!e
q'HX
v% N
NcN|
>A?h
u5v[
Z@$"
8 iMQ.
~UoA
b[Db})%WjNd_/X?N7^2Y:;Mn$
on:j
gHC6#
1P4
dZ5/,GJ
0#6V
IDisposable
v)~<
GDpk
h'8A
j'0rAu
I@K'
kH]8
fWd
2>W*c
q &_1
t.xx
wr%[
?&up?|M
"oxS
'5R
3?W(
m8T?
N<
I \b1lV
IHv[
o]}h
Y;ic
jNv{
hWOM
.LDb
CFC\
9{4EyI;
0`27l
}hRF
p)q+
AssemblyProductAttribute
kw[i
FB~F
uJ]e'
J.X,
p xz
/\n'
s^gBn d
*@5_
z^NKho
<Module>
UZRLO
xqKy
!Y"'
56*/P=
M[:
".+S
W p\ G80:
(RRP
zE#q
o)n;
.dH[
N& o
c'U
9>F-t
6d%
IZgN
LNw7
6}_i
\':-%
^_cR
eVsDN
#qK}
?:1%o
&e,I
2018
ECb_e
1Ix|
o*n
=20
(J4`
g aWS
i5,@
q=7t
f.? !S0
~x?d
*=ja
4*NP
gzBb[
NE!
vJ ga
KK w
FNZ6
XLM_d<R#;gni?_KD=5@)-BiA!
^!NWo0
lS`N=fy)mxcbJInfd6*<5>zE
fqq_C
-2]&T
OZ!:i
JZJ?)
o73Hw
x!jj
&74B
#GUID
$}4Q
HJ}`
kmW| }
[I65
/ls8
HBM-
o=aTPr~
Eg&sq
{"y9o[
pt7j"
99=}
qIDAThC
!YmBAa]dV
lmS57
'v#bW
?.om
s]yJ$
/5My
3$k
"'Br
a]wU
h C
a@wE!
_t#1
VT:.
*gs3+
<hz
.:[!
XKKUz
,kZvXL
MFTsM
v_ x
CLO c~
n&nj
Oq4v
{a9
( s
e}.0OgB-_8
U27m
%/lZ
S$,
N=IN%
XC+:
NMMM
P=l
#E=
CR$>
Ou
d`'!
VOtk^
a]E?
F}<Q
xOcfq#5IqsJ4GMct-tj*LOE=&
`ao7)
k~;N(
_;qCa
M5JL
d20.q
v {Ai
77ZJ
U% @
VYc Y
X5}J
xf~?
y:(xbS`bTB0b>pZ70}jYR "<%
IN=U
2vYN
[ <_
Bz1q
T=zp
?^z]
& jP
wLJ1
Encoding
|l<0
{"CC
>xUp,nM
S syN
'WBT
GEipA
YC"*
t-]l
IEnumerable`1
S1r?
Q&B
sC;4
{iE*
u)-d
xU?Sh(JuC
_R[Z=u>Fi~4"]bj|& R{~rll
P Iv
;VYZ
pVI
O =fK
nSmWJ
~E3x(
_x'8
&iRoq
:K|[
5eMJ
?jHd
K.__0
1X<|
3By
Z0"x
?' x
2T/(bol
B%4k
:fMB
Sn9J
-ZV#Y
Fnl1
}zDS
;(!tY]]
_ x)5"
s]28
^2*5
WTJ'
_|Tk
fJS8
{C+"(
]nmd?r
L]WU3
2MLlM
F`7~
4^5A
z l<
hP^i
F[?btKM
e`>_
+-q
JZf\
G0^k
Cu?O
WEOF
h~ $
System.ComponentModel
r.?F?
P{?j
%x#0v
F<[@
xnS|
TM"j
u0_GR.>
#1cQJ
;^u.
GRA}
05j
,9ACn
o@QT.
oDg"
{pb#N
>s^x,
e;W
@k=(
yK[)^
OD&G
fEZ 'Y
.TU3
y3D;
Vc2@MA")&%/ ;gR>QWX6KKEA(
Y"X G
6qof0w
*UC$
>~D*
~P}yP`< *
qf{5"
$5+
ayQ*N
, ck[
u5pz
eB _
l Uq u
|Ua-wb#cLG2?:kb,(uTXbz<R&
qn'bnVhT6#V-hAu54 ^)LRr2
3+/K&8W2'EJwv]wd*,zG<=U}"
t%_?T
P@Ux:"
?)XR
G EX
%m^p
w-_/
V""|
= H2
l+h-
89wNU8
[RjtI
] F9
System.Collections.Generic
o&(["
1fy.
jOOp
T1U3
m=YC
WC9n<p
/,<n@_5s[
MHlGQ
hjz'/X
8QGW
IJU7
{O7Q
System.Windows.Forms
5rd^z-
=p@0P
GnD.bg`
M=LJPW[
Yvlk
'-"2\
8|wg
}ypO
=Gs@8
}5v]
G8d&
tL.R
|MEc
\dq5
8++1
3rfU1
wk L
^!Je]|Hv4:WT~]I<$I_t:%/L"
q)S+
tLRPxQ
; 4
System.Drawing.Bitmap
-bm^
PlUf
D9~9)
$C
"g< D
*=fYmS
#S02
EZ-]KH=F6F^Cp|wY[*[0))'i&
#TF$
WbyU
yb`[Eu\3p+;` 93"'ANPz;ia
BTJG
U^cy
h(rPqf
disposing
jiJ(
tCAg
+L C
WE;S$
0D+G
le;;
4(0L
LNtW
>nBp
njpd
eC 8k
i{Mq
Jg)a
fx7)
om-D)p
EvHI
:5.
/I:%~J-z>Yr>zg+/*6:439-R#
{Sj?
u_?Y
'1>i
L:b
\I a
TRh$n
A1ZgUMB4e6oU$>1:`w2+PyCK#
Xq~T
j7$
0_8
W7q p"dJ
7U1P
<L}'u
ft|w
#uOK
=\o2a`
(60ogt
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2018-02-12 20:02:27 2018-02-12 20:05:18 171

5 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2018-02-12 20:02:27 2018-02-12 20:05:18 171

8 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\MasterG.exe.config
C:\Users\Seven01\AppData\Local\Temp\MasterG.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\MasterG.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\MasterG.config
C:\Users\Seven01\AppData\Local\Temp\MasterG.INI
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f02737c83305687a68c088927a6c5a98\System.Configuration.Install.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\20008c75bb41e2febf84d4d4aea5b4e8\System.ServiceProcess.ni.dll
C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1\System.Core.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.INI
C:\Users\Seven01\AppData\Local\Temp\MasterG.exe:Zone.Identifier
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\School Project.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\School Project.resources\School Project.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\School Project.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\School Project.resources\School Project.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\School Project.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\School Project.resources\School Project.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\School Project.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\School Project.resources\School Project.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2472.10873906
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2472.10873906
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2472.10873953

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\MasterG.exe.config
C:\Users\Seven01\AppData\Local\Temp\MasterG.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f02737c83305687a68c088927a6c5a98\System.Configuration.Install.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\20008c75bb41e2febf84d4d4aea5b4e8\System.ServiceProcess.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1\System.Core.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll

Write Files

Nothing to display

Delete Files

C:\Users\Seven01\AppData\Local\Temp\MasterG.exe:Zone.Identifier
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2472.10873906
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2472.10873906
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2472.10873953

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MasterG.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\2952dc8d\cda344c
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.ServiceProcess__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.ServiceProcess,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.3.5.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Core,3.5.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4adb7724\5b6fbccb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|MasterG.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|MasterG.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|MasterG.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4adb7724\3e1eb9ae
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\MasterG.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\7789FF67
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7f0603e4\73843e06\66\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.ServiceProcess,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Core,3.5.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\7789FF67
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
kernel32.dll.QueryActCtxW
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.VirtualProtect
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.DeleteFileW
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
gdiplus.dll.GdiplusStartup
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipLoadImageFromStream
windowscodecs.dll.DllGetClassObject
kernel32.dll.WerRegisterMemoryBlock
gdiplus.dll.GdipImageForceValidation
gdiplus.dll.GdipGetImageType
gdiplus.dll.GdipGetImageRawFormat
gdiplus.dll.GdipGetImageWidth
gdiplus.dll.GdipGetImageHeight
gdiplus.dll.GdipGetImageEncodersSize
kernel32.dll.LocalAlloc
gdiplus.dll.GdipGetImageEncoders
kernel32.dll.RtlMoveMemory
kernel32.dll.LocalFree
gdiplus.dll.GdipSaveImageToStream
oleaut32.dll.#8
oleaut32.dll.#9
oleaut32.dll.#10
gdiplus.dll.GdipCreateBitmapFromStream
gdiplus.dll.GdipBitmapLockBits
gdiplus.dll.GdipBitmapUnlockBits
kernel32.dll.GetProcAddress
kernel32.dll.CreateProcessW
ntdll.dll.NtAlertResumeThread
ntdll.dll.NtGetContextThread
ntdll.dll.NtReadVirtualMemory
ntdll.dll.NtSetContextThread
ntdll.dll.NtWriteVirtualMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.SwitchToThread
gdiplus.dll.GdipDisposeImage
kernel32.dll.VirtualFreeEx
kernel32.dll.VirtualProtectEx
kernel32.dll.Wow64GetThreadContext
kernel32.dll.Wow64SetThreadContext
ntdll.dll.ZwUnmapViewOfSection
ole32.dll.CoWaitForMultipleHandles
kernel32.dll.DeleteAtom
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
cryptsp.dll.CryptReleaseContext
advapi32.dll.EventUnregister

Execute Commands

"C:\Users\Seven01\AppData\Local\Temp\MasterG.exe"

Started Services

Nothing to display

Created Services

Nothing to display