MalScore
100/100

r.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 29/68 Related 2707
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 237.00 KB (242688 bytes)
Compile time: 2018-04-25 10:56:03
MD5: aaab9063b467d718f09a440200ed8b45
SHA1: 27d262c5b781bce9e0c30ea8b6e82dc2294e5afc
SHA256: bdeac7c88eedae46c1c9d22693801a6ad1b913ea364d227438cea67a8cdfaee0
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-04-25 21:48:05
Last submission: 2018-04-25 21:48:05
Filename detected: - r.exe (1)
URL file hosting
hXXp://healthyfamilydigest.org/js/r.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-04-25 14:27:45 [29/68] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x37344 226304 e6859f3ea97c2852137de56ed33f48be beef7c416ce964284e6cd59ac45188b7bdd6a306
.rsrc 0x3a000 0x3c00 15360 5fb17f3b4276c817588de1c3813a4563 b5a065ec8f075b7a8e919fcff3e4fc08570aab8c
.reloc 0x3e000 0xc 512 41458c98da7d57239bf334ed776b3fac 824a3818143fa2ac7ba8103a88a83f47bafc6b48
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x3c86c 1128 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x3ccd4 104 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x3cd3c 612 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x3cfa0 3163 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2011
Assembly Version: 1.0.0.0
InternalName: 087496.exe
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: 087496.exe
ProductVersion: 1.0.0.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
XaCxRNjvGscubjVcCzuntllimW.dll
TfZmaVffLzcAEAX.dll
OFWXLEHyIKDRfeQKOAgmic.dll
BsUDePCDvDTeBDKsCs.dll
hdZASvwduiXvgsmwk.dll
kMMgVkMXOkHJDeInhjJfLAPNZN.dll
jfeLMlvAdadBILuko.dll
GLZyunaCnffAFVBAMB.dll
vhfCbnlyoRPhMAJUfaMzQdnpGc.dll
nYxTfZmaVffLzcAEAX.dll
svBVkrpKOewqaUvsGM.dll
LKVEeVHDkiTndBl.dll
XEgYkqsZJnXTyFcgh.dll
XCkDEBwwHjxmWie.dll
hjvLkhKOFCbMThuPZfmT.dll
movCZMbllQKPYHrAFEOW.dll
HOcQxcKbhlyNvwSjif.dll
pOoCbLljvHiHgOQdXUnBACakXK.dll
JqXgRxtKrfHlSMQ.dll
QIgTltxltzyoPmixK.dll
RnzGcQzPTygngGbePiBQLfxgDO.dll
sIuYOrzUQKZoWxBQQtvU.dll
SMpSbpoiOeHTykNEK.dll
oPMlzIWdgXyPWvP.dll
tHsJZHqovtlZKVE.dll
qmqXzefWiUGnGcIDJbCH.dll
WegDPvwdahUoyXleFuGMIH.dll
hCHeHQpRUMGFzUkVElDi.dll
zFClGHhilWxXYPejjuTEFe.dll
ydDQpLYKbyMoZuLKaLzo.dll
mUgpgljsnnUGoRQTvKYjwxGgGl.dll
GPLrPykSLJDoTVJEo.dll
MhQFNffWaUwwAAuOdvhCNJ.dll
IVMoKyevoiPldJikPt.dll
kDUPGWEcfhhqyhcnNS.dll
KzBITBRzvdBNjqlPkl.dll
PoyHlujATIRXfIjFFsCd.dll
yGwXHFcDKYidMRHmXRILDA.dll
rYAwRkRIpwQbPRyTkTRu.dll
WFQVgvRQawWAsyGIanxotjIDmb.dll
wXpEpDcwgiuGaqUcwe.dll
rwiZaDxwdaaaVewzAiropz.dll
lwhdMOflqtgtOBigbN.dll
YGWcIqHhSqtYtlfFDZMWgOPUfp.dll
iMVRsXfRIgVCHQGJeP.dll
dLtAGNrkOIkglTgoYTWccIoHra.dll
BZizGJdIHXzuSCSFyd.dll
DDCqqjFfDvmGvis.dll
YoEncEbcvUKwmENQUINCaXsWbN.dll
POGWuXyaBiEkpnucxv.dll
joaHFzZLnGpzDHXgkD.dll
YaXdAWMccVBGSpI.dll
YFzttkGGoBjvuWe.dll
IGBnQyTeaRJnhBTtenOO.dll
eyjMlAUDFyFLEnhTH.dll
kBNiJpfHDxyhPZGKa.dll
kfptlqQjjbOlXZRRWbmy.dll
tRFZGNwhCAGcAWFLtMEd.dll
undUfAztpwFSYZOYuQrqzE.dll
RjZrLugEgDDLPzzgLaODJg.dll
ymYFGZdCtALIvBWpUKOCsGPjxA.dll
nzItVydOgsBorJdIdGHbUSmYrd.dll
CDswINwDBpAbnUxHtExt.dll
ImmgcRnPlDxyQOJRii.dll
uVxSpcUISykCkNC.dll
DoynyDJMXRpFCvwzbSVMrI.dll
YWzJCNnPvfJgtRNmKc.dll
ptzwggvtEFWkzrnlGvsPEPigtt.dll
GuQfcJiSJRPNDUZcC.dll
GZMijKFAUxkbuhmKigBHATbMop.dll
HfHOavOiOjXViLIywfAm.dll
kwobBLTzMqTNlNjPXgTXJTnixA.dll
wQfmTkeHUdjTBNGzZAMPflQIvg.dll
CwJSoczEFFIiMvekdSzcglXrBf.dll
YPtYGnIXgobTnBVxP.dll
LvwsgIYDgarbKxryMxqEos.dll
DYAyxlTsIWBueMJIDc.dll
wIyBQDuYsSeCpiRxrk.dll
LEJggucoTVwJpqFQpe.dll
BhCqjYNUiuQBiiqomq.dll
voNrajxDOMqXbncFZz.dll
zqOQsMPVtOZOjiUdWhMm.dll
eoLdDtriJZzyRyoGKvkmwUQzWv.dll
HNUWtrMSIdSxhkuFEXDqZGIAZl.dll
WDPJumpiKtMvXdd.dll
KnPFLwKJVhVKMfpubIZYDV.dll
jmvcYnxLCaAsBuogGZtFxXyRZK.dll
FuqjsvhJiLppQNeiQ.dll
xGAGQJGSkCWNFxLLrV.dll
BhfFlAzhONmgUaiBRYlU.dll
YJtzBxLLkpbwFNbSQ.dll
nuGiTlDQmIBtHlTvWlSngx.dll
ozKgxCsbnKSMadwtpN.dll
flSFmJpYFhVAwVKFdP.dll
WLLHwmdZqnDCuzEznaGnebtAZW.dll
OCDONMNnSFkfwKdEbn.dll
sxqFTcOpMAYfLFOewALk.dll
SMHJFGgdoAfSUlNhExgGFK.dll
owlSlSqSsczNUofgkLYRXXFlAV.dll
ZkPxrqdupWrbCWoDC.dll
wgkfWlEtrGdAsAQnG.dll
EqXkJyxoptnhzRAQmk.dll
ldaXvQItzqOyDPO.dll
jOcwhXaObFMEYzxxtHKqEOVJID.dll
ZUojMrCrMoQiajZtd.dll
xNkrmWGKPZiyIExtjSumCOYXnD.dll
YFzttkGGoBjvuWeIry.dll
MUHSwjRmQEAAhTw.dll
ygMDWyFQCweAXbs.dll
SuzeYzjAOBLuAdRIib.dll
mscoree.dll
WDEPJzyVJvsCbfkxUtOjSwhlYF.dll
TuXjfPKUDxUXcWRDT.dll
FBZiZlXcXhiYquDSfSGzvD.dll
hPbGYVknOOhGywVqmXmqbf.dll
PNGJDxLUTjenycz.dll
QVxOdHqxEFTzWve.dll
EOFyQwnEnlgbgFtjiIjHLxUwcX.dll
dKuwWRSypjjJjiZNFQijEvdFOW.dll
NMfGuBAejKmqEHypiVjUpmQffl.dll
bvXNsQcGQtaIzquyyXDnwSqJua.dll
oNkdlrYkUqxiRSD.dll
ERgocncJVfuDBQrbrUYh.dll
OrEfppWFunhLdrgzjTjPoqksJe.dll
KaVTTMuKjtTXlWYKc.dll
nSYArAnhRIMGvbtBYTEp.dll
qRtIQtxDdfuBeKBonkLF.dll
rfqaolBMfzFgOHawbneVFjTOrd.dll
pychzWoRwNLZXDHPuxyeoG.dll
QfkQxXOHRKNEvBG.dll
YulrzyKqFtVgzOlJVx.dll
BsbZTbMSDVIhtwIUdTnDtZGCuv.dll
qdjmKGqusBdAktP.dll
AsFDYVpKUVMlXJYlLpbuEK.dll
OGYVuiyHoOvLxmKgHNDTbY.dll
XRsRFCxAYqnYcWGTVnxmJg.dll
ULVvvDVCTHVcUvYsZN.dll
tRCviOSxessusUMjR.dll
zQSpSpjnXngzuFxkxQpwIm.dll
NbSQSKDFeZghsHbKuRkXrK.dll
CbucovaMNZWIfNwAjGHdBlXXjf.dll
hAoyXXOQusfLosIrtR.dll
oUhJNpyFWfIwuHGnPwqN.dll
pkEwDQiYZHpGFIHGGVLGBBArvL.dll
XOqwUrFeMmUIEvmAFqIXsslwWP.dll
ZBCSoVmTqGGjPtdxJ.dll
PjsueXAAFyPCybKyMjJbxBlqCV.dll
zNGyoCjLpSkERvbbzpOGMESujN.dll
IDSMwasmIeiuotQsKCWS.dll
cQxcKbhlyNvwSji.dll
SSwIDokxbLAoGHyUdATJFHYogZ.dll
LeNpKMrNWArNZgVnuTqffFGlhS.dll
rYNfXZqpeWwXXnQaKR.dll
LLiDWlWdNdhBHHO.dll
GigzLpfEqHWRsUTfXeIY.dll
wBcICjEspdCEVxs.dll
wDXkPwvoJvwQERWFF.dll
dwOgiwAoyzHlirKwGhBwNPDTMV.dll
AkPCKJczNKMYZrPmIcxmIxvEPq.dll
DYBfbDzfVDkvXFvLTo.dll
rhGoWebKspgReWrRyLCycEazdC.dll
uKeCohDjKHEvEQGeZ.dll
TdjCzmFEvPhFiUo.dll
tvWQKeYsCkQjvUPjE.dll
uhLjSqJDDCqqjFfDvm.dll
qXCmLbLRvirXkal.dll
ASGIKDhnYBYFkCfnMjsyxD.dll
rFyxtOjhkrdzzzIoAIJDjcAEwH.dll
SKDFeZghsHbKuRkXr.dll
DOgXLlUHGayCKXjXfk.dll
ZIpzwjXoKUkWmRdNoH.dll
SrHEaNlYUiVXQQsEy.dll
MFQtlyDPTOhXxdqnTaMeXA.dll
GvisJqXgRxtKrfHlSM.dll
yxGPxrNWGkZDpaxLYsOc.dll
zNAYFLLiDWlWdNdhBH.dll
xjPErgeLUipPUwHVVxEYLIyrCN.dll
uezZhxZjxAfjTORlcVjktASPaD.dll
RCazMnyNTjHngUNwjh.dll
SHlHSfZkHMVdZPSeiwepqMSwBx.dll
sExTiVznRZdVTgfCoDCgxDMJcm.dll
gBaKrAwXuGDBYWT.dll
qcxbwOGMawHnsZMKzjudIu.dll
hdDzySQyNHyrMrMSJstV.dll
KpdVbImmgcRnPlDxy.dll
UnfweBqYbvxRQjveLbYu.dll
ybZDitCtMZLxRJarpvpyEHqxjE.dll
JWZFSipeseyLuUjmMbBkuB.dll
HggEjNWWUlRLwsdBBsGJFCUuzs.dll
EibDoexdNvKYLJmzeC.dll
ViSlMrnroGlrEKrCORie.dll
dUsMoBqglceMpiDJKKAVPVrbMs.dll
kbYBFmSJXAZtjAznfNshpwfQXU.dll
FRZxnARwkudYfrKSO.dll
BHRUxJhRXbjQUgOolwlFkJTxeJ.dll
ZblXgERQtMkwcrR.dll
QaNCVWVrlYJtzBxLLkpbwF.dll
IP Found
No IP detected
URL(s)
http://schemas.microsoft.com/SMI/2005/WindowsSettings
https://u.lewd.se/LywkF4_PGvrtWEq.jpg
InternalName
SettingQ4
SettingQ2
SettingQ3
Application Title
StringFileInfo
Setting998
Form1
C:\Windows\Microsoft.NET\Framework\v2.0.50727\
Setting996
LegalCopyright
!&)
SettingR3
SettingR2
SettingR1
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
Setting4
Setting0000000
Setting1
VarFileInfo
Setting8
Setting9
Version
114688
!0>
LokUhYg.Resources
SplashScreen1
1.0.0.0
SettingU2
SettingU3
SettingU1
Copyright
debug
!,9
SettingAA1
SettingAA2
SettingAA3
Setting10
Setting081
Itself
2011
.exe
COR
Copyright
Setting6
087496.exe
2CED18D89F79AFC2DE4B2D1CE877FB7B327CA27F
OriginalFilename
e,7
Y,7
!3p
VS_VERSION_INFO
SettingKINA
DetailsLayoutPanel
true
Translation
-'1(
Assembly Version
PODIZANJE
GetEnvironmentVariable
Y%%
SettingG23
This application cannot start!
SettingFFFF
SettingQ1
injRun
Setting532
false
\picture.jpg
MainLayoutPanel
Y+1
MainLayoutPanel.BackgroundImage
SettingX1
SettingX2
https://u.lewd.se/LywkF4_PGvrtWEq.jpg
Version {0}.{1:00}
Handle
twxzBANnMd
Setting234
1758
!0E
DownloadData
FileVersion
000004b0
ProductVersion
FileDescription
'&(&/.
Microsoft Sans Serif
y,8
!1G
ApplicationTitle
_ENABLE_PROFILING
2# v&
jGhlgaAWDmUzwHHEZC
?p,g_
# a8J
DateTime
vuxKsAweRRBazWO
vn'R4
|"pl
Z e
7$6w
qbfPJwqIDYVbPrSxI
ConfusedByAttribute
XaCxRNjvGscubjVcCzuntllimW.dll
KUVZZcPQsSPXrAioPQjJUH
C'Z !
I]b_
?_b`
`=a+
gXlXZSpoNlEkMMcWCR
=G:.
2^
BC}s
sSTFRMQjYhQXEYF.drv
W_ s~
b5a+
0 hxd
Substring
c$K~
x$~4
cU6}
TfZmaVffLzcAEAX.dll
ImageLayout
0-$7
^,2 >
get_Controls
frjQqCTMhLHUdcN
OFWXLEHyIKDRfeQKOAgmic.dll
*/@
zydQCfitcqnbzLiSVZhrSNKlRU
z =
sb5,
DebuggerStepThroughAttribute
fapiIRQlfFKzJKETajKKgXXZIz.drv
n($1
b?;"
4 (
,4edt
(Xs?
Int32
vDTeBDKsCsFwzMMrG
z j
Z #2D:a8
CTissQDHUcfLqlPNO.drv
BsUDePCDvDTeBDKsCs.dll
Z yI
*:ei
U=ta8
hdZASvwduiXvgsmwk.dll
$\^4
Marshal
ipL"
ICrsDiRGTROSYEXwtZnUnZ
z F
^%a8
JvwQERWFFZkPxrqdup.drv
tGgDHePrVJlcPmNCQ.drv
yPlDFCXjAoOfWsgLw
;a8k
Z T
;$pE#xx>
OAc# ^
za8>
RuntimeFieldHandle
{*
kMMgVkMXOkHJDeInhjJfLAPNZN.dll
}=-a8
=E,
-V %
jfeLMlvAdadBILuko.dll
KFdPmVgxuJICPVLqj
#*R4
VBNMKLZZZZZZZZZZZZ
wya+
kernel32
LsJXDgjUoKJMLvmbPtJP
bSBqkiHVwzRAJDPRv
\T6Ps-
GLZyunaCnffAFVBAMB.dll
WkeQwEyiptdPctiLsqEg.drv
vhfCbnlyoRPhMAJUfaMzQdnpGc.dll
V,I@
oZa8
v M4
SettingKINA
F!N^36
x9Ss
KiVNvILOegbkUWHRvAVGWsiPrt
ryxAxFoDowkUSfSmugiu
B#%+
ktBhUlRXEWqtOaeKTndq
W$ a8
6-BfyV
set_MinimizeBox
Z *EW
IZ ,
AssemblyCompanyAttribute
Z SX
Z 1a
5X%A
MoQwDUDvWjhdjNkHuR.drv
PGgXLnFattSGfzkORu
Format
LokUhYg.Resources.resources
&Ea8
rTGOMloZCRGnuGU
nYxTfZmaVffLzcAEAX.dll
OXphrdQTTwpzROUbbeJUQTCklv
@gsZ
r'Za+
svBVkrpKOewqaUvsGM.dll
bZa8
;sH
AppDomain
Nv
bZa+
@ yc
xnif
w7GZ
l'k{i
@K3_c
get_CurrentDomain
8*p/B
cLK_
*ycr
Z C`
~A>8{
LKVEeVHDkiTndBl.dll
XEgYkqsZJnXTyFcgh.dll
NrjacExHwpmopxEGifiJHLdimE.drv
n )p
Z^%+
XCkDEBwwHjxmWie.dll
GDYSWJbEhlhvEej.drv
hjvLkhKOFCbMThuPZfmT.dll
Z 79t
&^E&
ToByte
j)11
X<Ck
jMhKqeJnWhYIOZoWRttj
zw;ne#
Path
set_Text
-:a8
UXqGqVIccDGEjuH
wBQHzoxfECMuQOytBkYcLc
zU{^
"Fk#
9\Wj=
S.l0
_DZ N:
"#6%5
=Za+
Z h1^
#Blob
#] %+
Ta8+
Lxa8
dVuHdQTniRwEJGtjMHgr
movCZMbllQKPYHrAFEOW.dll
HOcQxcKbhlyNvwSjif.dll
wa%
kqrsVYVyYYySSVZsluhoLTecRn
^`.B
)* a
V#Z
df*
wzcQZyUCwvgiWOevjI
Type
EZ N
9\k]?
pOoCbLljvHiHgOQdXUnBACakXK.dll
^E
r%a%
"(dRX:
=F<'
e{':
k%+
G.)wL/
JqXgRxtKrfHlSMQ.dll
xZ{

mF::
QIgTltxltzyoPmixK.dll
SettingAA1
SettingAA2
SettingAA3
l&6%&
OqyenfPJuctlqaxUrJISHK
iTNjEeqCbezicqhFjRXDPlYsJd
JSq,Sd
Y0P
NeutralResourcesLanguageAttribute
get_ExecutablePath
S-9
$B9C934DA-0FCA-47A9-A869-9F6327BDDCCD
T_MY
z; m
CapXeVQCVIUmZaUOd.drv
aLPnlDqTZxKLGIOVEa.drv
Z ~&
%&88
RnzGcQzPTygngGbePiBQLfxgDO.dll
rYpWLDnIbAxcaFeCLyYVoM
get_Text
~a83
get_Name
LateGet
El@fE+H
XrbuQwXaKkqnmxzSF.drv
|{/48Y
v0a8S
Z n
EventHandler
nlnz
92XLv
FmGQubSGFAAjGkBkDaMVVqLtxT
sIuYOrzUQKZoWxBQQtvU.dll
)\W\
8 Q}u
ca8'
Jl!'
ygN3
GZa+
r?W:(
AssemblyInfo
!;r;
S&a+
}iZ
dN%+
StandardModuleAttribute
ODKO+
SettingFFFF
|q]a8
+)~<
fCKr
9&M b
`=Z
c5v
SMpSbpoiOeHTykNEK.dll
)&s$
get_Now
ReferenceEquals
7w KB
.text
List`1
R&!lv F
GetObject
`5a%
IOVEagwBsUoLnmufX
GcttPUBcEOtDtSwzwZtmjB.drv
Convert
2fh%&
oPMlzIWdgXyPWvP.dll
-w{vm
XNPWxCJKsnEFGVwKmkIXLoxpzZ
U Z
nrbALNKmcvofzvpwjGoqsa
eDqsUpneEVTrczJtGfDU
Cbd5/
ArkvPNxUOfsvrgVRlDLC
HNA7
dBwZQJbQHBESMoilfsgrhibMQv.drv
4System.Web.Services.Protocols.SoapHttpClientProtocol
Q
o\
mZa87
^ZZ
RgYuWmfkpKHeRVdGgh
;:v0
^#zO%&
I@4y2
,7Xn
nb%+
Vv!|
aYy%&
Monitor
OpAKFaD}
Z m
5Uhl
=ya+
C]
RQ*#-
aldJ
[o>+i
QrY*
A>~|
tHsJZHqovtlZKVE.dll
u7g|M
}za%
\~`,KR
1za8
m^_-
SettingQ4
SettingQ2
iVt,Dj
vR$Z o
wZa8C
DesignerGeneratedAttribute
qmqXzefWiUGnGcIDJbCH.dll
!Z *
xng.QQ
C%&8
Z b
ut~
Conversions
Z >?u_a+
myKJPjuZxXfOhblPuQIlUpEMjy
oyRpPompErwcXcSAtmZQRKOtFh.drv
WegDPvwdahUoyXleFuGMIH.dll
`.rsrc
EcScEIAYakiTboB
~>bu
hCHeHQpRUMGFzUkVElDi.dll
Setting4
brsh
Setting6
{
get_Default
lUa8
Setting8
Setting9
Z 8!n
Iga8
zFClGHhilWxXYPejjuTEFe.dll
<$3lZ
h$JyBXt
WrbCWoDCYKrqlcDXnv
.ctor
w9Hr
AUU;Z
KtFnAmsdRUziHfWLk
9Tkt
^]na%
VxSpcUISykCkNCygMD
AXfyfevleqiHcBLSvYoyRqPleL
.NET Framework 4 Client Profile
HYfZuZSjYqaQgkkIydff
set_IsBackground
. 2B
&6-Z
ydDQpLYKbyMoZuLKaLzo.dll
mUgpgljsnnUGoRQTvKYjwxGgGl.dll
hjROerRIpOxQlWpGwNSN
?`a8
N><bEO
.eZ
)8%&
I,=!d7
\(h~
5O-!V
Computer
GPLrPykSLJDoTVJEo.dll
_]%&+
ca%
bxMFQtlyDPTOhXxdqnTaMeXAWe
Regex
c?lM
4{;k
MhQFNffWaUwwAAuOdvhCNJ.dll
>@AY%&
KxjWdRLWQMmWdgjTwp.drv
+2=w|w 0+
9C
yD
;}]6
wgoGSkgTHAfYAIkTxZtN
2DQ,
ocFjq
LTMw
Bn|%
v0FDbr
MFIzVBHDIRUzuvesTBHeQccbrq
d n
WebRequest
="DIZ
QU:%
IVMoKyevoiPldJikPt.dll
Z mO
TableLayoutColumnStyleCollection
'a%
(.a+
gbNflSFmJpYFhVAwV
get_Transparent
nNbijOeVqmcVBkVdXSPWvSOOaj
Y=;SC
otoDoEPrCPHwmyxeFGwgpAbVZY
kDUPGWEcfhhqyhcnNS.dll
t9
GetBytes
TargetFrameworkAttribute
HXzuSCSFydkDUPG.drv
KzBITBRzvdBNjqlPkl.dll
g"4q
Process
a9_Z
c~ F
ReadAllBytes
PoyHlujATIRXfIjFFsCd.dll
q LJ
gW1K-
&
%&8e
MainLayoutPanel
nGJOFRsVyhHPdjWeO
%&8c
Write
%&8|
%&8z
H
STAThreadAttribute
yGwXHFcDKYidMRHmXRILDA.dll
%&8s
AppWinStyle
Un/
): y
%&8K
get_Assembly
Z RiM
AnchorStyles
_yU@
%&8]
vNsUAilSaslQcDOgB
rYAwRkRIpwQbPRyTkTRu.dll
Lrn7
zka5
%&8Q
gxeHDjNVYYUHijwOEU
%&8-
YlRmonohgJmlkQmeEbjTInbwNI
%&8$
%&8?
S8:"
aV%?
Z ^I
'cvSM>
t ,$Z
Invoke
=fAcr
System.IO
RowStyle
WrapNonExceptionThrows
+R~?
SQ~\?
QG01
-Ta8
R)?Z6
ApplicationTitle
WFQVgvRQawWAsyGIanxotjIDmb.dll
ea8N
Dispose
XsGurTGhTUvTzmnHTDLcyqsOJC.drv
^^ME
kZn|
8Z~
d5eA
YKERUmbkQCgHKDGpHo
$ &nwJ
zPeENPurXigeKCSCd
= ;J
System.Globalization
<NADh
Qa%
T0`Z%+
P2!JB
~Z Gzp#a8M
yaLjvwgZFurXNtEmWzvO.drv
j-N5
`HQ
WZskuXwSTCevrgfwLpVcsNtriw
/RA
] K+|q
6_8
On
wXpEpDcwgiuGaqUcwe.dll
i$y8
IHDR
+B~5
+B~9
Z 7*
rwiZaDxwdaaaVewzAiropz.dll
:gO A
lwhdMOflqtgtOBigbN.dll
Z A{
# :O
yPzouHsuKNCzqzdgFAVvlv
XZWTieuzahGUVKc.drv
h<a%
oW%+
oa+
SettingR3
SettingR2
SettingR1
4HZzeF
>Z y
nqpPXgTagcmXFAabxLLwCqDCLt.drv
System
EventArgs
nZa8
Application
?TZ
YGWcIqHhSqtYtlfFDZMWgOPUfp.dll
iMVRsXfRIgVCHQGJeP.dll
G'.C$
TJWKByPyttxuTYFAlx
G6mb
xnCcXzmZEDIoyPK.drv
]Vm>
}*~L
UFZ
dLtAGNrkOIkglTgoYTWccIoHra.dll
\\Za8
BZizGJdIHXzuSCSFyd.dll
CreateInstance
W k
DDCqqjFfDvmGvis.dll
mARBArUiymFKoigJEqRhBx
MethodBase
#Strings
mY.7}R
Font
r{
c&o
uHj
Image
ojMrCrMoQiajZtdIoW.drv
)5Z (
DZa8v
k@xpP;
YoEncEbcvUKwmENQUINCaXsWbN.dll
pJxXg
fL
Environment
p 2
$'HFR
POGWuXyaBiEkpnucxv.dll
Z0[}MlZ
NtbnftXimoTBGxtaMNhgiAWWeG
VwZ
ZB:C
7a%
j
imOcjZwEUUqSuPEdjFIgqBrBqY
%h'of
XJ]I
Ymv
System.Diagnostics
SHOsOXLOeSjdkVVtKtdv
GetType
set_StartPosition
jN!a
add_AssemblyResolve
VVfBXglwmPkpaVZNjzEzpqqZxj.drv
Ut]
qazqtDNlbxrGszqwPMHi
MsgBox
wZ n
joaHFzZLnGpzDHXgkD.dll
/Za+
YaXdAWMccVBGSpI.dll
jzm.
FxSMDxAIjdfEbjBzbPhBkYvFKi.drv
System.Text.RegularExpressions
Qv-Z
Z L.e
& !v
Q)}+J
A-P Mf0"
scKArraDjFddhaOrhWVowv
QUQQQCCBkGUojaAbyqBI
)
IO%&+
CwQBFbkllHcLJpyfgzAuGcAWzV
?bmf
set_Anchor
YFzttkGGoBjvuWe.dll
7so/y
K'%KON
Ga%&+
X01*h
v%
QvqhTnHPGcRlJZqKEksfuvUqZo
Qu 5g
\_5m
WZ %
s 9C
ProjectData
-z{C
Z bY
set_Location
Iq0I
Color
\Oz1
ComponentResourceManager
FJJz
]NUSQAf
IGBnQyTeaRJnhBTtenOO.dll
set_BackColor
lmfKUNJRzFLLpbeRwtxmrR
s,a8
8Ke)
woECFEgwkglUcaNjwWviwPiKNs.drv
get_UTF8
O%&+
DefaultSettingValueAttribute
Z FA
8!
t a80
eyjMlAUDFyFLEnhTH.dll
,qS*+
+z9j
?E6 x#
.^E.
Z Mzwoa+
vGvRPFRxcsXMppfOtbNuYjvPPx
mhhRhZhcPnIXYFPUNaTzKeXFUU
lZ :
JSkNuAoRKcdZPzfry
kBNiJpfHDxyhPZGKa.dll
+ abp
WOMqscMwzcQZyUC.drv
ZiZ
0a8?
4G "{27a%
System.ComponentModel.Design
dO~@
ebSvrPBsSPdiOcAajeGwiIkLzT
2/y8
kfptlqQjjbOlXZRRWbmy.dll
wg#~V
cZ !,
ZaL%
na%
Form
gTvUTYgtqxKgAjpffhWV.drv
#+pM
tRFZGNwhCAGcAWFLtMEd.dll
EnvironmentVariableTarget
SsDe
ZT|a
pHuD
R'
.tqwy
}&|*
}n@!
LKy`
RNChrSLiCYEAwKQ.drv
undUfAztpwFSYZOYuQrqzE.dll
pbvgMyRScnfvmrEsefpxwKqxyj
NnmEeSNRyMmPoMKUZyss
n%a%
RjZrLugEgDDLPzzgLaODJg.dll
ir&w3
]a8P
tN
_b
get_Capacity
]MeA
^ja8
JDxLUTjenyczXCkDEB
/<8W
ymYFGZdCtALIvBWpUKOCsGPjxA.dll
.<-YZ)!
Ta%
Ta%
MsgBoxStyle
JCWZ
yBLZ p
nzItVydOgsBorJdIdGHbUSmYrd.dll
X?Jd
Xs 06
E%&8
Uj`l
:?l
0
set_Name
KCykvMlcECCkaJbRrkcY
Default
cDOgBhdZASvwduiXvg
ISvB
a8,
./L;
F8uZ "
CDswINwDBpAbnUxHtExt.dll
SubtractObject
get_Length
N#p
t $d
=i_\8
a8
3!-a8
_NL
rzyh$
<s%qa
zShSYUrlHndqnRt
f\a8'
ResumeLayout
ICit
|c0M
1Pw{58
R$t#
X "
ImmgcRnPlDxyQOJRii.dll
ValueType
System.CodeDom.Compiler
GuidAttribute
lAlpgTHHJmKgAlWkzELCGWTxjE
`v&S
t/B
}\f /
BU"Z
TableLayoutPanel
11Za+
get_Count
M1%+
aIEAbzJVZJOWHnmrHgInXexilX
SFfKIqWNavdfCgaTlU
ATjnAAGDklFJBqsVg.drv
lLdqXJLluhLjSqJ
RRE\
'Ca+
EkMMcWCRkxFJDxvba
<?xml version="1.0" encoding="utf-8"?> <assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <!-- UAC Manifest Options If you want to change the Windows User Account Control level replace the requestedExecutionLevel node with one of the following. <requestedExecutionLevel level="asInvoker" uiAccess="false" /> <requestedExecutionLevel level="requireAdministrator" uiAccess="false" /> <requestedExecutionLevel level="highestAvailable" uiAccess="false" /> Specifying requestedExecutionLevel element will disable file and registry virtualization. Remove this element if your application requires this virtualization for backwards compatibility. --> <requestedExecutionLevel level="asInvoker" uiAccess="false" /> </requestedPrivileges> </security> </trustInfo> <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"> <application> <!-- A list of the Windows versions that this application has been tested on and is is designed to work with. Uncomment the appropriate elements and Windows will automatically selected the most compatible environment. --> <!-- Windows Vista --> <!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />--> <!-- Windows 7 --> <!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />--> <!-- Windows 8 --> <!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />--> <!-- Windows 8.1 --> <!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />--> <!-- Windows 10 --> <!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />--> </application> </compatibility> <!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. --> <!-- <application xmlns="urn:schemas-microsoft-com:asm.v3"> <windowsSettings> <dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware> </windowsSettings> </application> --> <!-- Enable themes for Windows common controls and dialogs (Windows XP and later) --> <!-- <dependency> <dependentAssembly> <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /> </dependentAssembly> </dependency> --> </assembly>
eISJ
yla+
cUTcDvdvMFenXCHxKKTX
Z }V
y5+C
8%a8
~I\%+
S3ED
jYxsbeaFSDIpLLGhrmyEhUFdgl.drv
SuppressIldasmAttribute
of@x
\bR7
y~>
<%&8v
uVxSpcUISykCkNC.dll
U\M+Ex5
FormBorderStyle
wvgiWOevjIzNAYF
eXzZ
DoynyDJMXRpFCvwzbSVMrI.dll
UInt32
ToInt32
"oqo4
YWzJCNnPvfJgtRNmKc.dll
0(7\
get_Version
erOB
Pvhf=y
ToString
XLHLfScbSzXblRRcZlqe
Z Q7
KM+d
l\dZ Z(
ptzwggvtEFWkzrnlGvsPEPigtt.dll
/ jO
_$5)
`4a+
MzbMfvyTdyIbRJnsgNaaucFZcC
'$#
v9M @,
cAU
FMlwYClMkxGEpPZTXI
AAa8
mDRSEDGxaIRtfpcTb
gvU@
ClearProjectError
GuQfcJiSJRPNDUZcC.dll
V:nZa8
CiWBAxGrRPbkKLwIIrqEAkaWZM
4sKJ
gOdpIcvFRfoXqNBhVUcUqa.drv
set_BackgroundImageLayout
=Z 9F
DebuggerHiddenAttribute
2a8:
%KoR{V
d#lh

"=Z 1
uV9[
1@Y^
< sY
F Z N
AssemblyTitleAttribute
u"a89
uuYnQghzbBQxnNeMMv
J>l7
pwAClOGyFzSvfOZzIADFMEMfSX
10.0.0.0
Setting10
diRAiaIeUWrRxZC
^9^B<vb
0-Z
p(28.G
ChrW
y^D;Q
L/HW
CompareString
GZMijKFAUxkbuhmKigBHATbMop.dll
add_Load
Create__Instance__
3fSoF;
SettingsBase
Start
g%&8>
EFcghXPytbVmmCAQc
@2K
4%&8
CbxhVNUwRLluPYGECLVwes.drv
2[a%
.F e
qaai
Aaa8w
HfHOavOiOjXViLIywfAm.dll
sJoFxiUJkqdtfcUXwD
vdhtv
User
RegistryKey
M{A0
GetFolderPath
N^^`>
U})
kwobBLTzMqTNlNjPXgTXJTnixA.dll
HMa8
847
TFWodHbeShyuMpeTyIGjAmJecFlDA
Q:1U
pHYs
:T|C
pRBa+
wQfmTkeHUdjTBNGzZAMPflQIvg.dll
l@V
Container
|iPh"
cMrvUZkUhJUNFoueS
"+i|
A*L
#!#a
:ghd'
ki4;
%&8
eda%
_@Ud
EwrbxIsbzILeFAMUoJtv
{;1 v
X K
xotWlGJNpYmlbYxmBROIFDwKGH.drv
jGXfsjDhJwZgbCU.drv
_ 8%e
da
/8r
+ N2j
0Za8
v4.0.30319
48a+
Z tDs
mILYf
kuYNysuaTMlUAlOQoCFZ
'u-U
N<r
c`-8
ia89
r{ Cv
7Z 9
uOLWYUrZsSqJUiKjnUYwjXTSeK.drv
Eea+
FrameworkDisplayName
UHieFtrQXldjCsvnPE
W$%/J
Array
wVNbphelMvtPtTEaKrNXbZycdx
`1w,d
%%&+
st4W
jEw[X8+,
@.reloc
q MN
JAjkyzNMWZrwnYx
Z a8y
?):H
CwJSoczEFFIiMvekdSzcglXrBf.dll
MsgBoxResult
DayqoMBCYTdlHXlindlqaf
YPtYGnIXgobTnBVxP.dll
GetProcessesByName
JQmbaSAaMfMMkgIcp.drv
ATkoJLnEFjmyGLMfG
kOZ
WriteAllText
SpecialFolder
Byte
get_Chars
yjybOJZCmQybGkTZBm
-u =:
wOd&
FmUqXBaJoSudNnuSJwmcrslfZy
Z `s
)Nu[<C&
LvwsgIYDgarbKxryMxqEos.dll
0k>=
alYeKcYZmmuuYnQ
[Qa%
kxFJDxvbaSrHEaNlYU
L3w{
ContainerControl
zJ
g!/M
\8y)4@cL
[a8
GetEnvironmentVariable
SLs*6
ZTSvsApBUMuefohIIiLpgCobGA.drv
pZ 8
xl9a8
( LD
obOboJHPKLxAtYZVdzCXOCZnqG
[Tw g
8a8?
j3\6
DYAyxlTsIWBueMJIDc.dll
GN m#
6`M{
};_:{
s a+
Z DM
Finalize
System.Drawing
get_Location
JpfHDxyhPZGKaKpdVb
`-eA
AssemblyTrademarkAttribute
RtJyjUtslSFfKIq
ExKwDWhehzdkMRazLxcVOIIWEE.drv
wIyBQDuYsSeCpiRxrk.dll
frqDW
}Z T>
olOgXZZWxFxljTucwQsjzSPUTd
set_TabIndex
[kd=
"X7%+
kdSeOFrrDvMIEkEGobhT
pYyBWXXoCgSezCrOwe
UHijwOEUahMIKJd
get_FullName
ConsoleApplicationBase
%Xa%
jKW
get_Item
gZ |
Za8[
Za8S
_}Z
gZ T
Gk
Za8T
B4}#] 8B;l
RuntimeCompatibilityAttribute
ThreadStaticAttribute
uZ ]
Za8D
)`Z $
Za8x
Assembly
Z Jn
Za8v
\IV^f
jpZ
0 J`
WRDTEkVgyEiUUsqqcF.drv
Za8c
GraphicsUnit
ConfuserEx v1.0.0
ya%
LEJggucoTVwJpqFQpe.dll
`Za+
uZ
BhCqjYNUiuQBiiqomq.dll
Zp
(^Y
bGYVknOOhGywVqmXm
j +1
LJMDQXxmJbXbunnpS
$zD@
TZ %
CLRdVMVpcccZWrBPZqNItp
0<2}
Round
ReadToEnd
Za89
Synchronized
. H&%+
Za83
~T
jZJBexcoWLRylLZktjNA
Za8#
Size
rnXEQEISmivzjyghFbnZ
Activator
} d
KIaTiOBziDUklhmXKX
get_Info
Y ?'
voNrajxDOMqXbncFZz.dll
q@F
'Xa+
'4S*
ptYwWTuKWLQGlsoWJLWqlt
RxnatsWpfsJqzdEDMKWbAeVVFO
A'4(
U'I
vBGhjfvnSuZJaHAqQM.drv
8zTWm
bFlmGxEemgogWpEexDsHEp
7?J64>
{ F8)ia%
zqOQsMPVtOZOjiUdWhMm.dll
xO~YZ q
Resize
IContainer
nTWAAKaqMncGOLEYPc.drv
5
gg1
@68v9
ParameterizedThreadStart
My.WebServices
NeumIDhnsTeqFJRvCe
f z8=a%
GetProcesses
eoLdDtriJZzyRyoGKvkmwUQzWv.dll
lYmjLmIqzrgbOtkQAsfB
)*KJ
vhLpMQaalksrxDLVonlj.drv
YT
( W`Q
HNUWtrMSIdSxhkuFEXDqZGIAZl.dll
NHRgVwThBpPjlWrtE.drv
WDPJumpiKtMvXdd.dll
}n
CreateSubKey
WU >FIJ
nE|W
QJxOdgYNMZxljYGcPt
[5(,
@Z $j
X P
8v4a+
UB7 W
' 9z
zq~P
WebClient
k3Z
Control
0p]w
eLMlvAdadBILukoSMpSbpo.drv
KRa+
d|R+
3:(M
KnPFLwKJVhVKMfpubIZYDV.dll
cQ+H 1xP
set_MaximizeBox
qN`8
sHWjLxtebdSPIlHCkitV.drv
DellKHcILVSNTPEhgo
jmvcYnxLCaAsBuogGZtFxXyRZK.dll
ResourceManager
GetExecutingAssembly
k.Z (n
0RE=
CFZa8
GetResponse
(S@6[>
XZWTieuzahGUVKcGdB
?R0N
FuqjsvhJiLppQNeiQ.dll
W-7a
?Z L
E~X1
XgkDfueHXURYwEF
FP Rm n
XYYujdiLRWsDGyQrMdTdIv
Copy
h'0\
w(rS
MyGroupCollectionAttribute
IX}"N
ReadByte
:nW
EgTnMSRmHhzWzyvuTlYyGN.drv
+*
CreateProjectError
}#~N;MQ}
xGAGQJGSkCWNFxLLrV.dll
,W
dDsk
GjNkeTRlvOLyfDryBAmIigCDFI
iF<D%&8z
KiOT
N26W[
ejZ
-*s?2s<sn)p
AscW
;i~cY
kwcrRldaXvQItzqOyD
H*Q9
qFcNNiuzwkLSTQqpKkyuLpPXrF
oMZ
jMlAUDFyFLEnhTHXEg
iUcHOvcPIXFhsXDLmrvzET
YQ 9
%6d{
wRlhrFteQxTTtLZceN
RemoveRange
F%&8
CPyyuDapNznGMpH.drv
0wa8
~Qh;
gwBsUoLnmufXKiKxuQ
QAvyeDCgXlXZSpoNl.drv
Equals
el7a%
H8k=
H8]`W""
b2hb
NavAwBttmZtxDIioKOTq
mmCAQcJSkNuAoRKcdZPzfr
BhfFlAzhONmgUaiBRYlU.dll
YJtzBxLLkpbwFNbSQ.dll
HttpWebResponse
lZEaMKTyzflLdqXJLl
ColumnStyle
SHyYHoRtGEcxBiOkKAqvTeReZV
{``Z 9,B<a8'
~0MG
ctkzPRRDOckMeNbVzdurwn.drv
F71 B
pxZ ]T
oP]Z
UgPVEyQiGeOiYZoVjTPfvTMjXj.drv
nuGiTlDQmIBtHlTvWlSngx.dll
Version
iSiCrKVHptdxqXCmLb
get_ColumnStyles
vF#e
YE Ry
a>0'8
op_Equality
LxBa8/
<8Z
Z ?H ?a+
4g8A
4RIa8K
]zP<
Xx'Q
ozKgxCsbnKSMadwtpN.dll
~f7l4
Setting532
(a%
l<q
flSFmJpYFhVAwVKFdP.dll
_bY*
k#x.V
(FaG
nSFkfwKdEbnRoIG
SettingX1
SettingX2
GNIEPTDPbBISjBFhisaelRHLNg
dZ - x
AweRRBazWOfaRrqPMT
P%&
WLLHwmdZqnDCuzEznaGnebtAZW.dll
3=Z
y{,7
Read
;C
WibCOSieJudBfWyPxaqEdp
yiF"V
[j~_
ZN"q833
%\i=<
KOVaiYVvoMndJkwmAJup
OCDONMNnSFkfwKdEbn.dll
Mk np]oa%
J/s
cwPGUxixAWbObXkcHrzo.drv
{(:
8qZ
sxqFTcOpMAYfLFOewALk.dll
I:'
FZ P
SMHJFGgdoAfSUlNhExgGFK.dll
1&l
WebResponse
1t?vQ
UcYa8
cZ ]
OsydZcWzbAdEAXZCVbxzXWPNer.drv
uZ _O
zFC
lZKVEzqxniuXMldJfl.drv
TableLayoutControlCollection
Y -
x[dy#
AutoScaleMode
|R6]
SuspendLayout
.cctor
x>%RV
NtRMBdrArGpHqDqbx
set_FormBorderStyle
_bj/
mscorlib
z;
ZMDeWYACPzvFTXIaZbeKQr.drv
owlSlSqSsczNUofgkLYRXXFlAV.dll
JgvxZaCozBhBJsc
qZ M
ADBDxWnyVVZsxMKGjR.drv
@Ja8
Z p(
G b7
9PS
FontStyle
GetMethod
0~[z
Ri d
GetObjectValue
bZ "
/~SWB
HelpKeywordAttribute
['ma82
J1X?:I
ZkPxrqdupWrbCWoDC.dll
A l<
XlkBjhaaGIxhPLxzDYxbddRXRS
wgkfWlEtrGdAsAQnG.dll
zhzE
EqXkJyxoptnhzRAQmk.dll
V}Fgy
Pf#R
&3!Za8
BPauxKipqOKAcFvwbIyiIi
vR1
hs,k
(<8S
Z @*V
(1 di
mqIrkcxPegdHRLiFgjxIGWdaoY
>a8m
ldaXvQItzqOyDPO.dll
pZ ?R
TxCNoXoDETivSCOlMRyfMPvwQi.drv
System.Reflection
kMyxQ4
sa%
jOcwhXaObFMEYzxxtHKqEOVJID.dll
VhVKMfpubIZYDVWWj.drv
& ]w
W k3
RuntimeTypeHandle
KruqVFGEeayswIqyeVEoeV.drv
<; Z}
Z '1$
0
[3t;
CYa8
Object
ZUojMrCrMoQiajZtd.dll
S:4
#+#jW
set_ControlBox
Y_Y
_y6k
tREibDoexdNvKYL
bbsFjiyDgwDVCwnMbgySYGtjAV
#Xa8
E@bB
Z f.
cWa8
2011
UZ 5|b
uidZsQOXENEINMj
FDnD@DJ
ct+2
BZ [
set_ShowInTaskbar
xNkrmWGKPZiyIExtjSumCOYXnD.dll
`YZ
8T >
6TK0
<,B$:
YRsjZ
YFzttkGGoBjvuWeIry.dll
get_Title
MUHSwjRmQEAAhTw.dll
,tR!
^+m_N
t^|O
ygMDWyFQCweAXbs.dll
MZxljYGcPtxiDTr
fo5
%_ #
Ai!
|j+!&
Delete
StreamReader
SuzeYzjAOBLuAdRIib.dll
olMPNIzCEUCIxGVGVZBc
AssemblyDescriptionAttribute
#~T
va%
+:(A
@a8G
iHZ/
@a8q
@Y$t
SettingG23
hPEMOXqaHgrOwexJQnKYxF
YespWmdMajbZlBdoxktEklogEl
set_AutoScaleMode
gSGcqWHFpXlXJnQwhWOpkvOFNC.drv
xHf53
RtQzkFztgrfoSKOPuUATRhzTrM
eutNnHCMWioEbeeaupcoUFdPjN
FvwLGYnvNsGktHMsNOAE
pXsbPFAeGPQJXBRwJojrzrHUHV
WR8B
`$!p
ba8u
aDC%&+
'r%+
zfr\%+
wwwwww
qO}
H BoZ
>Z p%&87
DeleteFile
wA
WPV27!
7cV.
A
mscoree.dll
!This program cannot be run in DOS mode. $
File
mJugKBIweYXjSdQJyz.drv
5Z
JIa+
!s$|
WDEPJzyVJvsCbfkxUtOjSwhlYF.dll
iNcjHNNfqQQUmJAhNUpdlUSndi
6HxRWN
set_TextAlign
R BU
Mc:BzZ
+2s)
:v.K7
GetHashCode
}ka+
GetCurrentProcess
fZ
<Wa+
iP?fi
eGCnBLhWXxsfZji
.Lc M
uOPdRtjxeFeVgHpRQnFFMAKQVH.drv
KK V
lmBzbFgGDIaLvfMCap
TuXjfPKUDxUXcWRDT.dll
set_ClientSize
PZkoTGHCskqmwbaNvc
#][4
).NETFramework,Version=v4.0,Profile=Client
lJfIDLwdMkgxsqlxCSqdlA.drv
EI+[
/tr
<T%&8r
U;9eT
aw#DI
da%
FVjfFAJquaGsNpIUxtRVYOcCVS.drv
AoyXXOQusfLosIr
SetProjectError
FBZiZlXcXhiYquDSfSGzvD.dll
BSJB
!a8^
My.User
;^E;
HD$N
m a+
swre
ContentAlignment
obTnBVxPBDLmjSGQaStjub
hPbGYVknOOhGywVqmXmqbf.dll
K 8%d
jfa8
Z r4X
!a81
QzP2%
"X78
Strings
,7 Oh
(tSV8E
IntPtr
zTYD
d`1#9
xsomblJrwqSbARWvMfUtjLDDTZ
> _X+
PNGJDxLUTjenycz.dll
&e o
v@x+
QVxOdHqxEFTzWve.dll
EOFyQwnEnlgbgFtjiIjHLxUwcX.dll
}OLn
Microsoft.Win32
\!`.%
rVPiufilWSLuaSAGBKvsEaEQxH.drv
fP+E
ma83
pUnSRnEESgsIwDEgiAHEpW
bjgP>
^6%%&
Qd1k
s8ea
'{~_5*
UgDY
Ba8X
dKuwWRSypjjJjiZNFQijEvdFOW.dll
H+;+
zSiETnHYpxixMjqfRfvJiBZsYy
tRbpNAGSalYeKcYZmm
Label
ma8D
Z U8
KyWu7N
q"
NMfGuBAejKmqEHypiVjUpmQffl.dll
nhzRAQmkOCDONMN.drv
8"0v_5
DZ) P('
nTWAAKaqMncGOLEYPcXDTqcW.drv
mlm8
9 3cs>a%
ConditionalCompareObjectNotEqual
bI*1
BlockCopy
jpFVtlwWOUYEjhp
_cX*
DockStyle
zij2E
@h%,$
IULVvvDVCTHVcUv
SizeOf
bvXNsQcGQtaIzquyyXDnwSqJua.dll
M/<K
DQXxmJbXbunnpSkBNi.drv
^" /0
C!${nT
SUnF
gLwZBCSoVmTqGGjPtd.drv
ZgUJ
get_Second
oNkdlrYkUqxiRSD.dll
1]AK
jZa8W
tV^O%&
DWFPIVshyVLhnwvfkuxHHpfRTq
ERgocncJVfuDBQrbrUYh.dll
FWWyLRoVeDypINCvvB
XeVQCVIUmZaUOdATko
OrEfppWFunhLdrgzjTjPoqksJe.dll
Boolean
Za8M
~@Z
?rwflG
KaVTTMuKjtTXlWYKc.dll
NXZnybcsjXEOEyXMkFaRATjXBS
nSYArAnhRIMGvbtBYTEp.dll
dFryvJSzrwszRahes
aBz]
WNavdfCgaTlUNeu
MethodInfo
XtcmfCKbomCldwDdmfNVmpfGGb
qRtIQtxDdfuBeKBonkLF.dll
we~:5
+\6=z
da81
CompilationRelaxationsAttribute
<+Z
'~
WeakReference
rfqaolBMfzFgOHawbneVFjTOrd.dll
nHGCnwcQcIpqMvJ
MemoryStream
pychzWoRwNLZXDHPuxyeoG.dll
h.7V
Setting998
vgWbNrIYkNLnHMcptCmJAwCLkI
ResolveEventArgs
a8c
njk2
WEcfhhqyhcnNSLZ
QfkQxXOHRKNEvBG.dll
YulrzyKqFtVgzOlJVx.dll
Setting996
OsZ
-"a%
BmSwKJPhtbERPspDWbeoUBrGvB
h7f
IcpnGJOFRsVyhHPdjW
f-ma8
BsbZTbMSDVIhtwIUdTnDtZGCuv.dll
j]t|
Z AnRMa8p
z3%+
g/Md
IDATx
vu8f :
Z dG#
qR )
qdjmKGqusBdAktP.dll
Create
$'Hp
fmuaqzcjImjOfackNl
My)
fZ i
HideModuleNameAttribute
l)Mk
mlEKnHsOTdrJtsBSiBDgNV
7@<J
IEND
xhIDDozTuGQPLPrsmFZrhs
Microsoft.VisualBasic
^E
sXfRIgVCHQGJePrYN
Z HFU
V FI
ResolveEventHandler
\'c
iy2N
!iLe
KLKqZJVX1Bu1fSySFsh6B
WriteAllBytes
2Z V+
EnterDebugMode
BMzx
set_ColumnCount
Z <
OUXotJLTaIjaMHiUcJlh
S$b%+
d E
B}Z o
skZ*
AsFDYVpKUVMlXJYlLpbuEK.dll
BEyPNWlNLHtSRFCZyqHF.drv
;9H5D
X 4>
4p&9
.^'H
!%&8
rHaNKaQSaPOegxQPzRDh
}?5Z J
~La8
GZ $4
pcbBajIKTiwpyQfdihoxuz
Concat
FtdiEGONgsyamELsWriJyhHpTG
StringBuilder
?5L;8
BaDYA
+?~X
Append
C1 6
@[#
Fa80
DetailsLayoutPanel
x3l(
bGkTZBmDYBfbDzfVD
Stream
get_Copyright
Ha8u
+a>$K
OGYVuiyHoOvLxmKgHNDTbY.dll
CompilerGeneratedAttribute
k-L?0
fsvBVkrpKOewqaUvs
Z j.
XhvWJjQCrEVqVsnwPu.drv
Z j7
Z Xh
FZ 2
Z yua
kvXFvLTowXpEpDcwg
+ m
tmjBsIFadVnAlWIQmIEMbx
sW 8
wZa+
XRsRFCxAYqnYcWGTVnxmJg.dll
AssemblyFileVersionAttribute
GetTempPath
System.Text
GefILVeGVitLnjfwQ.drv
RZ 8
V1OzZ
qV(a+
-]9
iruY
Bf,Suk
System.Resources
SizeType
V11V
MhLHUdcNZblXgERQtM.drv
}6.Sz
T|d[
7<#J
+)~/
+)~,
+)~-
ULVvvDVCTHVcUvYsZN.dll
tRCviOSxessusUMjR.dll
AccessedThroughPropertyAttribute
lFxRidXJVpTtIIGUCOCMqgvJAB
LokUhYg.My
h1a8
ma!
RGnuGUMUHSwjRmQEAA.drv
kRUb
[N1jh
a a8Q
=%cQ
R6a
6{~A92x
mLCON
+Ma8
rTejaLPnlDqTZxKLG
rY l!\
NEZ .G1Na+
X ?
SettingQ3
,Z y
W23%&
8d-H
]a%
]a%
zQSpSpjnXngzuFxkxQpwIm.dll
Kdw
.a%
#pjD
Z pvi0a+
pFVtlwWOUYEjhpoPMl
v!
Z ( }
Exit
hTwWDPJumpiKtMvXdd
|Q7a8O
ConditionalCompareObjectEqual
J4RG
Z "v
:E\19
9PI:
smwkQIgTltxltzyoPm
\l${
o A@
String
_CorExeMain
DebuggerNonUserCodeAttribute
"a8.
_YG
$R5$)
NbSQSKDFeZghsHbKuRkXrK.dll
d :
Z "C
gjTwplZEaMKTyzf.drv
*2Xj?
:*)o
o%k)"5
QPEYSZIKBePWOMqscM.drv
"a8L
CbucovaMNZWIfNwAjGHdBlXXjf.dll
Command
SX^=
DebuggingModes
Z <q
InitializeArray
System.Configuration
9IF:
wwHjxmWiechxFWzNQT
5
MultiplyObject
VxayXcOeoyrciRP
eZ&D
Ia8k
Microsoft.VisualBasic.CompilerServices
Hbor
Ia8|
@I/%
OrObject
-$zV
V{Z {;T
EditorBrowsableAttribute
System.Runtime.Versioning
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
v"7Z
XZ U,c
}~Z
()$)
X i4
CTuKg
Q>:"V !J
vREOoeAzvLZMMBWZqI.drv
sa8F
o*
p[!q
yItguWCbCnHnnqeThsEVVAUGwY
:O%i
PBRCQIKqbsKTnGxqIsUUuoTKBy
)#`F{

hAoyXXOQusfLosIrtR.dll
Da8u
w)Fp
@2
Load
oUhJNpyFWfIwuHGnPwqN.dll
!y6P
Attribute
EEkaRmXWiyNFQyystxzDLKkiuT
v8 %
!bI5
Z2qz
pkEwDQiYZHpGFIHGGVLGBBArvL.dll
P wd"
NSZ
K2.8
. '$`
WerD%&+
Ha8?
GetFileNameWithoutExtension
&bzN
z i4n
tZJZS
PpNKYCmKpgBgvzBPsRqm
Fns
Dispose__Instance__
w.&u1S
ulcPcRJffDcYZVa.drv
lQnzzshHWhTTNsmMQvrzId
DebuggableAttribute
tF2]
cZ
xJuKeCohDjKHEvEQGe
25]
iOeHTykNEKwqMfJjWXpnrG
Z-_N8
rz21BM
F`:=
mDRSEDGxaIRtfpcTbf
Z 2Np
Zp.0
QwDUDvWjhdjNkHu
TEZ
-da8i
5a8
INMdWSLHYhlnpRZ
um%L
RuntimeHelpers
U .:
NfUg
V58
kZ a
rWWFnYxtFwshnMmIBk
kZ h
.0q;tee
()qJ
Z Y4
ja8g
1Rj
^E
FLba8:
set_Capacity
na81
xbzETMdnmxJKNQI
bjGREccyGBFrWWFnY
(A(
XOqwUrFeMmUIEvmAFqIXsslwWP.dll
>H8e
GdBiSiCrKVHptdx
v w+V l+&$
y qNR/
AiSa%
OZ y
dvIkSXyDwVyZiKPWmxqUzyHVCr
Registry
cb\K
CeWzAsfNVTzlDibqwpjuVenMAw
2DUZ
g%&8
ehP
ComVisibleAttribute
3System.Resources.Tools.StronglyTypedResourceBuilder
ja88
rzDWiMeIfGAtyBoqdGzP.drv
a\ X1
QEBKwIxPiEFOWsSCPy
ZBCSoVmTqGGjPtdxJ.dll
PjsueXAAFyPCybKyMjJbxBlqCV.dll
IsLogging
<Z^W
dza8G
Bo<I#
dEk
get_IsAlive
,bma%
s}$ s1K
t[}v
EditorBrowsableState
9Z
RcJEOoEuezyZIgcQfwPC
oLaeNZcADuFlInnGDkwtIlRiWc
Interaction
dZ U
-bb?
ba%
pn=
CultureInfo
zNGyoCjLpSkERvbbzpOGMESujN.dll
FEVAF
/Z Y
Z O%
1.0.0.0
_Owsb
Z ^ _
Copyright
|Z Mc
$15+#
m ! `
XZ U
8tZ
04a8
CIsHqgxLewcxFnWQLj.drv
|4rM
3d;a+
dsfqdwlhZSQyBkJZdOiG
's#|[a
} ^
(`&%
Setting081
XZ v
IDSMwasmIeiuotQsKCWS.dll
ControlCollection
rwnxhIDDozTuGQPLP.drv
la8z
cQxcKbhlyNvwSji.dll
SSwIDokxbLAoGHyUdATJFHYogZ.dll
cNa8[
|)C,
LeNpKMrNWArNZgVnuTqffFGlhS.dll
}vLD'
^"V {
ApplicationBase
\Mh{i;
nR*z3
U^EU
SD33 CF}
rYNfXZqpeWwXXnQaKR.dll
=8 6
tK~p*
3C'
wwwwwwwwwwwwww
{a%
:EZ R2
NTNjxsZIzJVzGjLpoQnuyQYpli
LLiDWlWdNdhBHHO.dll
set_BackgroundImage
aH7&
aiDFUOweOXfhKuoMWUSX
+I(R
GigzLpfEqHWRsUTfXeIY.dll
@ rp
tSUVOZpIwhLPzvtJmTqwtzufvA
/Z d
'Z /o
wBcICjEspdCEVxs.dll
pn< g &
z9=3
qa8*
get_IsAttached
Q!6j
evMZ
<bIS"
u0a8C
b wn
mlRhJSUTZxpeuDWcrSAlbV
SettingQ1
FailFast
wDXkPwvoJvwQERWFF.dll
MrvUZkUhJUNFoueSey
ZmsHSybKNIBpMwcWG
WyFQCweAXbsvwjujSx
QqFi
faRrqPMTFMlwYCl
dwOgiwAoyzHlirKwGhBwNPDTMV.dll
QtGJcTeGlVjbDwMBhwYnquMwyL
\y *
My.Settings
#o*O
&=yQ
$I&s
ufahEuYPWohybNKLCI
AkPCKJczNKMYZrPmIcxmIxvEPq.dll
FormStartPosition
ERZ
Va+
fzZ
O 3o
Plc2
)a8r
PIVtuidZsQOXENEINM.drv
@+r
c<S93U
TableLayoutRowStyleCollection
4%+
sE!ZjL
DZ E
oa%
Z wJ
Zq<`\
fXZqpeWwXXnQaKRXo
ua85
xvdhtLIMMZjxcdGvUpfe
JvCJulibjyAKyXjKJrfE.drv
qftvtXoRVeHtAXfkjPqmQzvjUc.drv
HttpWebRequest
'B9<9
sEiuOblwzFrnDOqqqgkzPX
GhlgaAWDmUzwHHE
xRjZxCkDdBjYPxfsQmJa
System.Net
DYBfbDzfVDkvXFvLTo.dll
Shell
Buffer
968"
Ja8&
eG~'
ijLjwWlPheKeemOFLdTzKG
'Z {
@MVn
5Z ~&
q V
6a%
rhGoWebKspgReWrRyLCycEazdC.dll
y3="Z
e/=Z t
X
[)[,";
XDCzRpRvQuEfnJqVKxot.drv
i5a+
aGXUOncowufFcHIBjMcIklayCi.drv
9 a8%
Q t;Sm
$ !(P
Z ^/
Z Ii
g$>8
JXp~
7tx;
BTimfOozQasOovjvpyIdxjbRKQ.drv
cPNK
KJgONQITxkTWHyAVMD
SIuxSLBVkAFOJcnVidlKXFMvEz
RZTuD3Ct59jvhmelgN9PR8l1LVWAyt
Debugger
_}a8^
Microsoft.VisualBasic.ApplicationServices
bSAtbGckTDgbPglgloxV.drv
LTZ
Qa8o
Setting0000000
Random
P7
uKeCohDjKHEvEQGeZ.dll
nwVLRm R
Next
S$gD
#VJ4
mDjtrEMtRbpNAGS
TdjCzmFEvPhFiUo.dll
UKDn
e"/:
4.0.0.0
gWjehhGmNOcmACyCPATE
5Ra8
F8V
skuXwSTCevrgfwLpVcsNtr
SettingU2
SettingU3
tvWQKeYsCkQjvUPjE.dll
SettingU1
a 1q
(#M{
Sa8R
Copyright
( Z xC
System.Threading
get_Major
R2aML
Pk+v
<Z d
AddObject
qpNOjLaWrKNgibBtuGYdfXKmHn
Point
get_AssemblyName
My.Computer
2o :?
xtFwshnMmIBkIVMoK
9$Mw
/2*w
AssemblyCopyrightAttribute
Operators
M6@e~P
/Hlz
"<rA8~
uhLjSqJDDCqqjFfDvm.dll
la%
set_Item
Z 28
9-ng+
]X90{
qXCmLbLRvirXkal.dll
_lDGUk~M
Setting1
.yWgZ
vRxfCVPNTdzvZzhFuV
KZ P
KZ _
pmxE
cW%+
ASGIKDhnYBYFkCfnMjsyxD.dll
wa8c
Exception
TJM
G(0D 5^
ra%
ua%
KCktZBerPimYxcrNuo
rFyxtOjhkrdzzzIoAIJDjcAEwH.dll
MPaxzQauQZgPYicbOsydZc
VfUXOtKwvLtjnTVpWEidIT
KfqyhBJJnvCRbElyMbrf
tV"@
W:S`vm
set_Size
%Z\{
GetTypeFromHandle
LYa%
FileAttributes
ZFVHzBpxcjtxTaqIv
/' 1>y
_K%&8F
{a8Y
bO Q?3
zra8}
;Z Kr
hfrstVwfVqpURUOsEZUt
RYKERUmbkQCgHKD
RZ-"*
\9.X
pj%a+
[Z 6
PWoYZTEQNHRgVwThBp
GuQegtoHOXnmNezzxFZIeudBGT.drv
WS#'
HUa8<
16L&"
^>l74
SKDFeZghsHbKuRkXr.dll
Enter
DOgXLlUHGayCKXjXfk.dll
Osvc
dFHRvtNFFvwXXdAau
HFpXlXJnQwhWOpkvOFNCWZ
=mC
*1Z
{Z !
ConcatenateObject
System.Runtime.InteropServices
XQMoviUzWSPDyZwtpy
~a%
~a%
2):JM
X >
SZ1c{u
Math
!|gq4
Z {1
ZIpzwjXoKUkWmRdNoH.dll
yycQ
rVGDBRFEkigBkGVlrQEk.drv
Krfw
SrHEaNlYUiVXQQsEy.dll
wmZUfmGyzJFStfNFdaRUWnsYDV
qvx6
<a%
^E
System.Runtime.CompilerServices
MFQtlyDPTOhXxdqnTaMeXA.dll
CompareObjectGreaterEqual
i,^O
mVERplTakQCIrTJ
NewLateBinding
fAP
GvisJqXgRxtKrfHlSM.dll
':zp
gZs"?
get_RowStyles
yxGPxrNWGkZDpaxLYsOc.dll
-
Pa8_
@KY)
;<if
PNF{
gkl(
!cIM
fRLY
ra8q
zNAYFLLiDWlWdNdhBH.dll
xjPErgeLUipPUwHVVxEYLIyrCN.dll
"Vz:%
Z !Zx!a8j
bobgvWUWteAXSQSVf.drv
set_Font
uezZhxZjxAfjTORlcVjktASPaD.dll
aN~+
A%@Y H
f%+
-AaS
' F8)ia%
m<
IDisposable
R[,d
>!Va%
Exists
BcddscYaCwRlhrFte
uMUBuVzItKFfJxfYuSyMXR
RCazMnyNTjHngUNwjh.dll
36>UW
|Y<M
c%&8
^E
R)>f
My.Application
SHlHSfZkHMVdZPSeiwepqMSwBx.dll
Da+
AssemblyProductAttribute
sExTiVznRZdVTgfCoDCgxDMJcm.dll
3Z R
XD)QV
j"&upu
<Module>
Z 3R
mXHfMQqLZstAoExaLWRsIK
JBuuWoXyigVwJVGASMMrWenRHb
K 0W
gBaKrAwXuGDBYWT.dll
xWCIZYjThEXtWDIWN
qcxbwOGMawHnsZMKzjudIu.dll
3=87
Z d
zLsPkTRtuQVieppzpgLjxeLEfF
MsqwWebCqEZvgpMhvOjj
eC3.8J
hdDzySQyNHyrMrMSJstV.dll
<|42
*a8^
|WnZP
XZ*6{m
PllcThvLGzNfhHJdrIolDoRYKU.drv
yrK{
kvcHtwSqDHMzLDJwEqxyVDczEk
"1}%
HZ |
lxuMhIPfTqKcXeyIIlnrQf
vQ\](l4
_[tO$
""%1"" %*
_b`
gtFSaHanRaWDmwlfmqNVojjGPG
i3Z
gv)U
e=a+
Ia%
8Z U
AWZ D
#GUID
KpdVbImmgcRnPlDxy.dll
27TNG
t> 'gK
p; m
mBejUWNsvhoMBOKEWE
wXwXFjrgGviZBAgCn
HZ $
Wjhx
set_Dock
8Z 1
UnfweBqYbvxRQjveLbYu.dll
ya8l
xq/
[4
<kDd
Xn.=
7j3 E
W
YsZNGLZyunaCnff
ld3G
$Z }
Replace
zEpuZdURhpGIoqCXoHRu.drv
N| Z
MMLGWdpoRbZOKFUWkNCroqEoMd
ToInteger
+ y[
2Z Z
ApplicationSettingsBase
:LD8
kuu$
gDPvwdahUoyXleFuGMIHTgrtvj
VOs
qZa8*
xra85
La%
ybZDitCtMZLxRJarpvpyEHqxjE.dll
AQqmRa)G\ o=~0E~@Sy1Qa:0
="a8[
kda_R^D>
rsmFZrhsQaNCVWVrl
Setting234
L(TUDg
Thread
JWZFSipeseyLuUjmMbBkuB.dll
tHqPZtubJeiCcgFSdiWBQo.drv
GetResponseStream
ju]a+
Microsoft.VisualBasic.Devices
rUlAkvRoYqGBvgBMDhzztByhRQ
MyTemplate
ZYxqJQmbaSAaMfMMkg
HggEjNWWUlRLwsdBBsGJFCUuzs.dll
kh]Z
SetValue
)(|-[JU
Encoding
?6=Q?
get_CurrentThread
GW9E
SetAttributes
N#d/
MDtnkQMwQNheexw
[a8{
E3|
ntdll
B#8O
Z U
CurrentUser
Z e
EibDoexdNvKYLJmzeC.dll
IGmAEPPAXWkSrukHLQpjZyrTut
zYulcPcRJffDcYZVaj
xa8X
T'LZ a-
X@~
[a86
1'a8
qZa8
~A$o
Z"no
UserScopedSettingAttribute
r0@a8
7(&>6
*hdZ
AQqmRa)G\\ o=~0E~@Sy1Qa:0.resources
m4a%
ViSlMrnroGlrEKrCORie.dll
!/In
5a8l
UN
System.ComponentModel
ashp
[`Z
\M?[
# ?I
ta8
idN7
Z 9
NX-y
dUsMoBqglceMpiDJKKAVPVrbMs.dll
ToBoolean
elKIhMmMaVinTqgzoVlaMo.drv
kbYBFmSJXAZtjAznfNshpwfQXU.dll
`F(48
FRZxnARwkudYfrKSO.dll
XDTqcWJAjkyzNMWZrw
q,.Z%&+
x5.H+
Z 5P qa8
Lr24f
fJ6O
%&
%& d
3F
System.Collections.Generic
QGLoQZTJggQzhsfQMjtVGukZsJ
o ~'
get_Minor
MnlrXsAwluqTMWgXyRsuNvOUnY
NwpQwZYPTkItkiO
]
8}
ZnnKfChpSRMJEXUvVHvwMd
}Ai
System.Windows.Forms
RYqkEGCIlNJbxEFZH.drv
YsgALlWuHZtffdXZrDdKwmlIfR
|"$dR
Vb@a8u
'%~h
3U%+
G%&+
%0TZa8
@'c\
BHRUxJhRXbjQUgOolwlFkJTxeJ.dll
*5
MqjKyJSAGhHcXSoCshvsvIxtMY
ADAmTOTbjGREccyGBF.drv
j/h
bX
W?P
GeneratedCodeAttribute
12.0.0.0
Rv-
EOoeAzvLZMMBWZqIV
LIZ B
2zK8
I;sW
PXOIngKpdVefvlJvR
%MV
ZblXgERQtMkwcrR.dll
MFByyZsJLgTQbcusu
}a8I
VzeAFNSQxpMzHzfswbqUYv.drv
PNG
(
4@x0x DN
3 CI^
g<lH)}
QaNCVWVrlYJtzBxLLkpbwF.dll
Sleep
?=0u]
+g (v
H7j[7k)
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-04-25 21:46:38 2018-04-25 21:49:35 177

4 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-04-25 21:46:38 2018-04-25 21:49:35 177

8 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\r.exe.config
C:\Users\Seven01\AppData\Local\Temp\r.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll
\Device\KsecDD
C:\Windows\assembly\NativeImages_v4.0.30319_32\RZTuD3Ct59ja02f71a6#\*
C:\Users\Seven01\AppData\Local\Temp\r.INI
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_64
C:\Windows\assembly\GAC_64\mscorlib.resources
C:\Windows\assembly\GAC_32
C:\Windows\assembly\GAC_32\mscorlib.resources
C:\Windows\assembly\GAC_MSIL
C:\Windows\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\*
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC
C:\Windows\assembly\GAC\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_64
C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_32
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources
C:\Windows\Microsoft.Net\assembly\GAC
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\System32\tzres.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll
C:\Windows\System32\it-IT\tzres.dll.mui
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\secur32.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\crypt32.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\CRYPT32.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\*
C:\Users\Seven01\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\*
C:\Windows\System32\p2pcollab.dll
C:\Windows\System32\qagentrt.dll
C:\Windows\System32\dnsapi.dll
C:\Users\Seven01\AppData\LocalLow
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab3D3.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar3E4.tmp
C:\Users\Seven01\AppData\Local\Temp\
C:\Windows\assembly\GAC_64\System.resources
C:\Windows\assembly\GAC_32\System.resources
C:\Windows\assembly\GAC_MSIL\System.resources
C:\Windows\assembly\GAC_MSIL\System.resources\*
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\GAC\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_64\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_32\System.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.resources
C:\Windows\Microsoft.NET\Framework\v4.0.30319\VERSION.dll

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\r.exe.config
C:\Users\Seven01\AppData\Local\Temp\r.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Windows\System32\MSVCR120_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ade5aa3c89481539adcaf7d9526dc8ac\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\62dec581cd40afd680502a581d529b7e\System.Xml.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Windows\System32\tzres.dll
C:\Windows\System32\it-IT\tzres.dll.mui
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab3D3.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar3E4.tmp

Write Files

C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
C:\Users\Seven01\AppData\Local\Temp\Cab3D3.tmp

Delete Files

C:\Users\Seven01\AppData\Local\Temp\Cab3D3.tmp
C:\Users\Seven01\AppData\Local\Temp\Tar3E4.tmp

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\r.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\r_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\r.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1026530C
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\HWRPortReuseOnSocketBind
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SchUseStrongCrypto
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\My\Keys
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\CTLs
HKEY_CURRENT_USER\
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Disallowed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\TrustedPeople
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\trust\CTLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\7F06864B
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Escalation
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\1026530C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\HWRPortReuseOnSocketBind
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SchUseStrongCrypto
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableWeakSignatureFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97817950D81C9670CC34D809CF794431367EF474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D23209AD23D314232174E40D7F9D62139786633A\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212\Blob
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\EnableInetUnknownAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\r_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\r_RASAPI32\FileDirectory
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList

Delete Keys

Nothing to display

Mutexes

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
clr.dll.SetRuntimeInfo
clr.dll._CorExeMain
mscoree.dll.CreateConfigStream
mscoreei.dll.CreateConfigStream
kernel32.dll.GetNumaHighestNodeNumber
kernel32.dll.GetSystemWindowsDirectoryW
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddSIDToBoundaryDescriptor
kernel32.dll.CreateBoundaryDescriptorW
kernel32.dll.CreatePrivateNamespaceW
kernel32.dll.OpenPrivateNamespaceW
kernel32.dll.DeleteBoundaryDescriptor
kernel32.dll.WerRegisterRuntimeExceptionModule
kernel32.dll.RaiseException
mscoree.dll.#24
mscoreei.dll.#24
ntdll.dll.NtSetSystemInformation
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.GetNativeSystemInfo
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
ole32.dll.CoGetContextToken
clrjit.dll.sxsJitStartup
clrjit.dll.getJit
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetUserPreferredUILanguages
nlssorting.dll.SortGetHandle
nlssorting.dll.SortCloseHandle
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.CloseHandle
ntdll.dll.NtQuerySystemInformation
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptHashData
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptReleaseContext
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptExportKey
cryptsp.dll.CryptDestroyKey
kernel32.dll.CompareStringOrdinal
kernel32.dll.GetFullPathNameW
kernel32.dll.GetFileAttributesExW
kernel32.dll.SetThreadErrorMode
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.CreateEventW
kernel32.dll.QueryPerformanceFrequency
kernel32.dll.QueryPerformanceCounter
rasapi32.dll.RasEnumConnectionsW
ole32.dll.CoTaskMemAlloc
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ole32.dll.CoTaskMemFree
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
advapi32.dll.RegOpenCurrentUser
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpCloseHandle
winhttp.dll.WinHttpSetTimeouts
kernel32.dll.LocalFree
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
clr.dll.CreateAssemblyNameObject
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
clr.dll.CreateAssemblyEnum
kernel32.dll.ResolveLocaleName
kernel32.dll.SetEvent
kernel32.dll.ResetEvent
ole32.dll.CoWaitForMultipleHandles
kernel32.dll.GetTimeZoneInformation
kernel32.dll.GetDynamicTimeZoneInformation
shell32.dll.SHGetFolderPathW
kernel32.dll.GetFileMUIPath
kernel32.dll.LoadLibraryExW
kernel32.dll.FreeLibrary
user32.dll.LoadStringW
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
kernel32.dll.LocalAlloc
ws2_32.dll.GetAddrInfoW
ws2_32.dll.freeaddrinfo
ws2_32.dll.WSAConnect
secur32.dll.EnumerateSecurityPackagesW
secur32.dll.FreeContextBuffer
secur32.dll.FreeCredentialsHandle
secur32.dll.AcquireCredentialsHandleW
schannel.dll.SpUserModeInitialize
advapi32.dll.RegCreateKeyExW
secur32.dll.DeleteSecurityContext
secur32.dll.InitializeSecurityContextW
ws2_32.dll.send
ws2_32.dll.recv
ncrypt.dll.SslOpenProvider
ncrypt.dll.GetSChannelInterface
bcryptprimitives.dll.GetHashInterface
ncrypt.dll.SslIncrementProviderReferenceCount
ncrypt.dll.SslImportKey
bcryptprimitives.dll.GetCipherInterface
secur32.dll.QueryContextAttributesW
ncrypt.dll.SslLookupCipherSuiteInfo
crypt32.dll.CertFreeCertificateContext
crypt32.dll.CertDuplicateCertificateContext
crypt32.dll.CertGetCertificateContextProperty
crypt32.dll.CertCloseStore
crypt32.dll.CertDuplicateStore
crypt32.dll.CertEnumCertificatesInStore
crypt32.dll.CertFreeCertificateChain
crypt32.dll.CertOpenStore
crypt32.dll.CertAddCertificateLinkToStore
crypt32.dll.CertGetCertificateChain
userenv.dll.GetUserProfileDirectoryW
sechost.dll.ConvertSidToStringSidW
sechost.dll.ConvertStringSidToSidW
userenv.dll.RegisterGPNotification
gpapi.dll.RegisterGPNotificationInternal
sechost.dll.QueryServiceConfigW
cryptsp.dll.CryptVerifySignatureA
cryptnet.dll.CryptRetrieveObjectByUrlW
cryptnet.dll.I_CryptNetGetConnectivity
sensapi.dll.IsNetworkAlive
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.NdrClientCall2
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpCrackUrl
shlwapi.dll.StrCmpNW
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpSendRequest
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpQueryDataAvailable
ws2_32.dll.#22
winhttp.dll.WinHttpReadData
ws2_32.dll.#3
cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo
setupapi.dll.SetupIterateCabinetW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegCloseKey
cabinet.dll.#20
cabinet.dll.#22
cabinet.dll.#23
sechost.dll.QueryServiceConfigA
rpcrt4.dll.RpcStringBindingComposeA
rpcrt4.dll.RpcBindingFromStringBindingA
rpcrt4.dll.RpcEpResolveBinding
rpcrt4.dll.RpcStringFreeA
rpcrt4.dll.RpcBindingFree
ncrypt.dll.BCryptOpenAlgorithmProvider
ncrypt.dll.BCryptGetProperty
ncrypt.dll.BCryptCreateHash
ncrypt.dll.BCryptHashData
crypt32.dll.CertDuplicateCertificateChain
crypt32.dll.CertVerifyCertificateChainPolicy
kernel32.dll.SetLastError
ncrypt.dll.SslDecrementProviderReferenceCount
ncrypt.dll.SslFreeObject
ws2_32.dll.shutdown
advapi32.dll.EventUnregister
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-04-25 21:46:38 2018-04-25 21:49:35 177

1 HTTP Request(s) detected

http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • Hostname: www.download.windowsupdate.com
  • IP Address: 95.101.34.82
  • Port: 80
  • Count: 1

GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 86400
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com

#infosec #automation

TheSystem Itself @ 2018-04-25 21:48:10