MalScore
100/100
MalFamily
Disfa

btC.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 52/67 Related 2689
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 1463.00 KB (1498112 bytes)
Compile time: 2018-01-24 19:40:38
MD5: b82c09d13e216769bd333b6cd5f57f82
SHA1: 70168735c2bdda6d6465c3e9e1be5f74322cb40d
SHA256: e6b05e5783e8bfd28ebdb1c93066b4042280e8bab9236fa59e2f4e5efadb3cec
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 */ic{ .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-04-14 14:54:04
Last submission: 2018-04-14 14:54:04
Filename detected: - btC.exe (1)
URL file hosting
hXXp://ssrdevelopments.co.za/cg/btC.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-04-05 13:24:28 [52/67] VirusTotal
PE Sections 5 suspicious
Name VAddress VSize Size MD5 SHA1
*/ic{ 0x2000 0x118c 4608 0b899c18f55012e803ccea1544b1d20d ce9345ada5ead5e3642b22145e37ead8cb6af124
.text 0x4000 0x77600 488960 bbd29edce5e6329413826a6ebc563ebc ba20c36e208469225d88ba1abeb5943de1b5be85
.rsrc 0x7c000 0xf4b30 1002496 30b37281ef2e6b4ab9152960675d6651 a308d3382a9e0c6249cc62b9ab1b764550fbf568
.reloc 0x172000 0xc 512 b2e5f11e2a80a784eb25f4b3eef1bb1c 18494fc41b73156df06d60c63b245dca7f5d7cc9
0x174000 0x10 512 9178420f7a16a8005967b3cd4bdce4c7 1b8461ab6a4e75abe31e7c93d328e138308b2814
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x7c0e8 1000948 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x1706dc 20 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x1706f0 1088 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: zZSIoYqa0KsVxGziqU9dxSXLS5O2mInBVpo0VuR8
Assembly Version: 67.38.53.26
InternalName: btC.exe
FileVersion: 26.38.7.27
CompanyName: ZnqSj8TTpgOuIE5IYBC88ojd9GAgFFuR3CpEyHiG
Comments: ZFpK228LaCxTrZkZ7mmgcbFDKJIb8Ean5auYuaFh
ProductName: CN5IlPp6z5XfTsSboNSSbh1UotfCyEftHidpdY3Q
ProductVersion: 26.38.7.27
FileDescription: 1qanfkferHcqhuiiXecG1xjbDhyzC1HKmqRTwjpP
Translation: 0x0000 0x04b0
OriginalFilename: btC.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
mscoree.dll
KERNEL32.dll
IP Found
26.38.7.27
67.38.53.26
URL(s)
No URL found
Assembly Version
COR
System.Array
btC.exe
VarFileInfo
System.String
Comments
GetValue
SetValue
67.38.53.26
FileVersion
InternalName
Assembly
Invoke
ZFpK228LaCxTrZkZ7mmgcbFDKJIb8Ean5auYuaFh
TransformFinalBlock
ZnqSj8TTpgOuIE5IYBC88ojd9GAgFFuR3CpEyHiG
CN5IlPp6z5XfTsSboNSSbh1UotfCyEftHidpdY3Q
GetObject
System.Security.Cryptography.SymmetricAlgorithm
Key
StringFileInfo
System.Byte[]
Translation
Copy
System.Type
System.Activator
LegalCopyright
Join
Name
System.Threading.Thread
VS_VERSION_INFO
CreateInstance
Length
d1G
System.Resources.ResourceManager
FileDescription
System.Security.Cryptography.ICryptoTransform
EntryPoint
OriginalFilename
Load
System.Reflection.PropertyInfo
1qanfkferHcqhuiiXecG1xjbDhyzC1HKmqRTwjpP
CompanyName
GetEnvironmentVariable
zZSIoYqa0KsVxGziqU9dxSXLS5O2mInBVpo0VuR8
000004b0
ProductName
26.38.7.27
Sleep
C&5
_ENABLE_PROFILING
ProductVersion
!_.!
U$J0c
@"*>5w~
8ua3 m]
AB&"
[E:v /
KFP'
iZmV
~%p*
!ai[
KHl_j
hS2I
aM?|9
j {
Kzm
[O:NT
`jh:
3RW;
B=`6T
&5#9
jH>0
Int32
yOL;6
Q4>&
oD.h
P$s27@
FigXv)i
Ww)cn
'k`8.
(:l8?2I`
V6#~
do/Z
[AS_
VtB"l
Bx9/g
D)Gb<c
&4]]
1/6t
iF*Z
.w8Q
BV!N
E*3k
ZI9?
jr B
3XvnaL
|9Y 84=<
M7g22A
R<j|
V$?g
Xe~j
rsW*
zy
:1Dj
2^~Ha
3]yW
^**g
*4$%
8h'
R{Q]j
n]<<
^^{5
N NpN;N;NvNSNwNxN
eO+}
CkW73
:?lE
;UMz
UnverifiableCodeAttribute
! 8wv
h3oN
x Kx
6kx]{
{ `!H
R7tE
Dp !2I
u]l-xnX=
TD\?
03\Bf&
Car2
^y9"
"0x'
uDCD
uZ{:aF
;: ?
>%/bL
M hE~
Bt:8Z
~^*R
]`+
a&$M
U3-ILa
d=R-
0 'X
$ `vI
N; D
eUs^P
h5(8
U 9h9
5sK^
ey cx
=L6LY85
pf% lL
UDqV]
IBu%
GCPo
mY,9
Q=|&
!VQM
_HpL
h`XS
T[{[
D>|=
A8UA~A
zFZ+P
C:Ce
3M %W
XUj;
` H T
gU?4J
LRibixX-@
T/,p_
:oey
(eQo
8%,Z
0|.fK4
2rBs
N'N:N?NNNpN
|..&
}{bkm
X)0
`4_% DY
=^C+
NH
ffSk
# u3
OAn5
(CM~
!$P7<
IBul
6?O_
|R5X1
)bPl
x"<7$
Grvi
PXC`,
liXD
k+<g
fFZYF
ii q=
-pLY
)'W*
f"H9\
Chb`
k@$\
`6-g
YIF
\Aw,
rJ=
AAKd2
]>M+(
Cm0uQ
i ,~M
V2[_
.>?'.e[
%qaAU
>xs}a
GOl
+w ;
/EX&
# 8~
!hzR
0.AM"
<ijx
^i6#C
'k^
hN_^
YX(u{
`oIp
~lOp
73RZo
cA55
x;KQ
UDa2
P0,
rDnd\R
*' {v
t8%@@
Qkx--
*,T4}<
f}wUF'
^SC7
L{Z
0Vwc
Y='
M4;n
wFp
-hpU[
/pPm=
04Aq
!X{i
}?^Z&IAP5
<ijF
F^ f 10
\ 4y
Kz|~
j55
}&m>
GqCW
]k7F
=Y}e
ue1o
O_'b
(g/Z
N_N N2N
'M0A16
tp^-
n"F,
#3oD
Mu _w
xgRw
h\<b
1v1
/UdN
/X ?
q;Hrx
S/pB
@m%m
2k]e
4;(-E\$
/%g:
Djn!j}
ku-q
17G]y
SE!P
EBh ]
SL<X ~
J-25
<A\BU
+ lQ
Z.bq
^$#Bj
us,$$
KGOE
Rw5)5
kz Y<r
|4])
vLP}
3EL `
}Z v
~;aRb ?
ScDh#
N'1x -
Y['!o
4 k\@
:{vrVI
l~= G
iliJ
=UF[y
_L\xJ
B;:LQ.
}?GJ
]g
V1v>
Mk "+
ezg[
&6 ]
tV!>RM
9 s
'eIq
R~DU
)u:P
L@<8{
t=$6
8Z2z/
BxOW;s
T q*]i~1
\RgB_;
V7b^
& H/@
Bh\,?
s_3[o
#Or<o
UH 8
p&ZF3\
-?3!
!oD^
+aSc
Kr|K
]ar"
s<Vj
4LFw1
M!"\
{>pZ
!+_un
8Re)
RoO_2
D5XP
<(nz
M w
kTMEvHz
Ztpr)
#| G
e kU
2sU!
E_3e{"
HZbK
~*1H
Cs@K[
H7t8"
4Tr%
y #d
\n7-
z">q
#-3Do$
F_(U
0f&"
C* +I
F{SR
L^({
B^97VX
=' R
#iNV
P[G "`
&6 8
wYNd%
Lpp5
C=bj5
!XoOXr
`{C0
>&No#
U$}Q3d
*%P@
?LxM
'- .
/8l'
[jxS
; eu
tD!U
]m1`\w [4
&rSe
w},adlq
35 *
GoR$
U$ 3e
?-S;
( 5z
X'LC
#jeKRT
'\NG
RsS8a
Ux*X
K#tp
1}@y
Uh!
obK s
O ")
$xrD
~b O
8=CT
ROeJS
1fTJ
b=(]
S&kU
3N8F
581dM
v*GZ
hhv/
?/xq
Os8^E=
g9'xj
4>tA
m8&hQ
luy&}
Tvv~
"O+?
|~y5
cO[w
0q6;>
?<&g
)NEG
~{tcY
F!N)N`N&NKN7N
7Ugp
(#VUS
i7)t
8K,WU
KSNC0W7|F x
JOD;
>` ^
Zs*)
S[:!-_}
=6tC
7kF#
Rwf
Pj /
Ba V
*MbI
*I:3
}vNUn
zo2%O
D:Cx&
wt/1
6'qJ
HL{d
o#c* }}
h=`>
k26Nt
>+18
,x#:
M^TS
}xV4
8_R#
bBbRF
f,'7
Cz$v
wqsn
iymA
V F>) r
b^C]
,,p^
woez
)bXl
AXR^
Udm$
iESj
w lW
yI.hB
P3d]C
Ef9X
DzKd
]EvX
g^
Aqqz6
Kw"{
{pq{
V A4
8FY^
jbmX
D'x\8
n>_
LJz}
9t[\
L&BO
ZH)x2
oKM7
9vz *
ZqvSa
g1 k7
}af.Nj
kF0
:A0K
>U;
e6+ 7^
SiKgco
Qe F
Sofh
: zm
A Mn
q@nX8
']~o
QbZkLy2gu6Fss
:n_nW
![`pks
B ,
[l=
9 _x
.~A@
4d}H4
SO/-y
:`1Z]e
3lQv
EL'&X
462;
9-J B
\ lx
G&d,
|-IR
2iVkY
:;4k>
>!Q"
_Lsme
S &WP
Hg.@
ID ,!rQ
M%j]|
{K^g
oB86`
P?]w
0$X2
*.|H1$
-Cb|
.01>;
yq6-
?_Ff
qU%"
4 e4
?9pR2
U~@
}85
-Gp5F
N]SG`
t#=4
2-,A
;EI(
2%yp
DX-^U
bQX$
NjN,N
$ cS
$?I%
*B'=T
Z<`+
coVu
{)=;H
}ZqE
99U
`eIs
N/!)
U ls
5`9w+W
Y1cGq^
imOO
d#wg
KAJi
1e _
y8p 7
sHF*
cFM7
[Cpz
]g+@
|N]*
)&>
y<L$
L#y|
?3>G
get_FullyQualifiedName
z a{
n V
cQumP
x -3t
MZD#a
"_7[
yLGiW
iuK0shn
_@GL
[M 9
OEe>}l
J, 1
EV9
R%TY
)b#g
j^>,
Sk g
1L"&
uvIu
cv$s|!
%Pxo
shgP<4
mhgn
1|)@
(v)$
s"MFV
"%E $
!!>A
p>] D
@xej^
QHC#
JX!"I+
CQ]$`
Ym0-q
PdoE
]5t?g
^ f&
&&$66Y
PgEbQ
7p5[
> [GC
2XFk
B Lq
. bC
kka)Q
q:_F
c$w~
HO XX
h]"4M1V""u
;Gc
9YwngQ
``JWk
D*G
p1Ee
eG!!
=^fD
zku/_
#u.6
KYQu
.text
sMZi
W>4DD
Z`lW
:QC@Zc]
v% '
zNYw0yMhR5qqbBgxvIs
Xky_$
{RjP
{R[Z
=[tf
l%!<X
Iaie
2W} `
\)J?Ve
=[Yt
c))D
DlAc<N
\U3*
'O)+&'
{4 9g
l^fQ
m}n@
V=SH
bmiz
)6 r
0D*O
a#&|
Xk D x]
cxQ.
Qq H3A
ajl.
!Kt1
6*wy
#U+
`PBNW
qV*s
; _E4
-,U#
dU:|O=
J Y
F\O
v}L #O
/FE/k
(bV%
Y8T01
fyjN
4:N]
IMFQO(
D:S*
gpm
Y .x
x>V#
~)$`
o-d|
sn.65
K~B29
;J .
0Dt1A
yP@k
B4do
TDB,3
E2\D
4)(t4
V}H
ELX2
Ob.K
',RN
@& VT*
P\8N<
$>?(P
$ ;T
z) s5
VjA=
c57>
Tx8
4$_8
!ha^
Yc UwP
%./]
>CO|m
rH`5
;,p N
i X0
+A[v
M0;VB
= [A3
L5[z
6Fuc
j)skT
n;( i
PiBU ."
VUR
5^ydi
ZmBv
g*:F
EN?LU
N)iL@?
@ E
*&b
<1@T
s9G+
@wIe
96l4
:Zs
`f2a
Nm5+"
)Ztx
1 TQ
$4h@l
f *\@
Mj&
pQi
.#X9
n,M7
U)' U
$TB5
J/js
1%*D^"
" |P
KeN`
> <c
I7FG
Y9}#
o][Q
>!L4
zLg/
}pN<
9b[> 5
}N5Oh
,VZn
+ukU
2Z1~8
fIf6
bj?
#Schema
-;JE
j>%T
Aw@Q
Yi"J
/}U`
A|QD
Fz_5s
WP%
zNoG:
J$C]
H\'}]
+ISw
'^3-x
cl{#:
3v7tD
QtNanm
[R;m
bqgv
sB7-
? ,l
Z)~?
8*!Znq
&>"f9
R5(G
ko-u
kHHT%
3m8vc
N=Ju
;nSE
}3n
g!k2
?x"3DzeH
{;6<|
`/& Z
J" %
Imy
B QN
)H@jl
iJ+
Sk.y
>_ b
^Kwh
0u0/
set_IsBackground
X5z+
jZLxVFcYf2Wn4CmczA
%j!FGdj
>.o
N%2T
)'X
)b{D
O@(;
V| =N
TfSE
iJ=k_
<yu(
>92n
l;mG
=gN
8~E"I.&
G-q.
S65h
* N3N NjN9N
:{5 7 |
69pd7
#(- f
8XL?
48 >7W
K OY
[x1oE
=!?#
;|&{
\IJ}
$nh\0
Lu:?hr
N*Z6Xo
|*(h
qT h2h
qbXWqd
5,Q"
uWiW
yu7A
=P:=v
R9Wn
DA6dE
g8F"
VrZ&
Z mx
X{$$
y[n2
nKoBZ
hxR;
S<#%v
^>v[
ER0c
pNsk`
/$%
L/-5
E# G
.Mb1gGA
3["2Jl
3#!eWPk
"r
nkG6
p <%
Kfgb
5,}CMmRw3
s, \
aYTP
/lf,
(cM:
jVBF
FhdV0
sw[Y
%>*`
*I!y
P{2U
PVA
6]|2
J96;
oS!M
E%S\Z_ =
tIQ2
9Kp
m7}=
fP^S
*^TX
6)`'
} Ri
[e> <^
nz'%
ZSB _
6 rXlG
/fXF
yzi"
"SKt
!Z@4
{\2B\
hLt#T
bwE
!VwX+
bhy*
jMlC
zQ*r
30HV3
j+Cl
1KLm;
+YJK|
33 }
o=`4
aK,|d
L9%1
oIs0F
^KF~
+_x8
GvzX/3
|t@9G
R^]U_2
k}/9
CfVG
(E" {
BKgv
@ $>
7flO
~1s
\ O
1k+7
t` W
B hb=
Sz>0
#snRP
nDl4
N"NUN!
Uv~l
c^ T8(
]TW :
!C7C
R gd
Ja{(;
MTp9R
_4`V
0>z
Qc}(F
scT7J
Nv&K
|Y[J
]$\d
8{T@
n}]i
k?Q$
X2W
kb)HW
FG<*
%~6z0W|B
D`8f\
bZGl
CUsC
PWEg
m <RQ/
d4+X
=31qc<<
kj W$
7Z7-&
_!-`j
.DK'6
]~tH*
h&?)
@,PU=
zJ@&%
u|vuu
^vf19;
8|V6
i#A=
}Q)D
.!gg(
K"VHi
E)DtS
Y}&K^
;0i>
|;l~
)RfK
zNRK
^&cH
I ef
xk12
!*P@
M H:cM
BZ)Q
(Kh2
AR'^
s z=YSSo
{C^]c2W
o 5
0kEv
tRI ^!
TCS|
a {X
{2Cn
5im
?(cg
2O>c
Pe98i]5
(KzjP6
NN6v
Q i$4i
"?ya^
M!nWy
> gA
"WW
Dn?.h
Dck?o
akOI
(&;n6~
(/ct
\T`h
92F`
@0&VF@y
"ihu
l (&3
X4[M]
3ZQW
)?A?
xS+ly
% XD
ZFp\
Hq#m
ZFpY
cPe
op_Explicit
a`xe
SG9
_kVv
7L{mm
aPw3_
o "i"
V:. gR
w3{
W/rW
h.?
vi@A
gfHl
z OWP6`
yQ~$
ZA*d
*nu::
f_<6
B;ww$
#tV(2
TI|Au
iUt7
S?+N
%KZ|l
wx?6"R
,Y9t"5& ~
-0 D
IHDR
<TVS [
|.3"n
7~o| q>;
. g]>
2f<eZt
t"M}
|8v=
^H0PjS_
1!ns
B;%R
0<
dPBD
+/Uz
{pzK
V&oq
8qb,h
@1^W
-n$$
g:'j
6-7w]O
q 3A
i*]CM
f!J"A
w](<
X[Lb
$Pfi0;
ek<o
_uSP
GZch]
<(=?
!z&j
0:6_
xag5
q 8<^
A\(UFF
0o}(
cvw0
"$^G
]-K'
System
`~23
xlk~
Yp,C
$\ .*
IGo
In}dW
4Ca'
[My#1
.}w ec
ICV8wn
B!iL
FK`%w
5vdR C
XBo=
R:Kk
R&y.
F =B
U)!H
zM$E
Sw>Q
uJ q
/:k^
ED?r
k;\Km
^a1TF5
~ye0
zlxL
: 4A
cwj1
Dz #,}
nzDA
dfX-
5k"+5h
V"{*
Di-C
#:sX
R"kD
8W1f
[;l5
YR
hDH{
HB9(
~r sV
K Vlw
)X]i
eC2T
RN|/
KhPk
27jH
{<oV
1jk`|
j]*P
MethodBase
7ngw
{v ;
E1/IC
(Di6
?N0
!/~0X
; 0G:
(h'BD\
?TNe
(]F;b
B&:|A
WBs-6
*nR
q9k
QOh#
Xyc
- z
uh3@
79 :
uY0[
<`Ln
SBkq
>!ag#
l%9w
1r3K
LY'<a
v*4x1
=_^L
h48T
^7,Sv
No0?
VOV
%+I'
LGN3]
^~)p
- 4l
8bK3"[
BRQ[
E}
['p&
v) ]
Frvu
^G]*T
QEch
c&V['
`T9v
x:meG
ocYx
CK'D
j@Q`
!WKKI
Fm
u>Me
5 wI
eWuL&
Fv] A
}\6Q
aE!5
HwbSE/
,tN|
NCMQ
{Z5
1.gH
d~(S7n
<K/
"bqs
?HZ
8#Kq
zssf
O7\:Jt@yf%*
$A &
6Oik#u
U! H?
bY^$
n3rx
4r"B
Mcs7
hc->8
jb?
v^*sl
=X :Q/
T;4gM
l?EnJ
#hW#
%u3
$)!P
IR :V"
0'>DHKLwN4
9X ,] 6
)Z%>;_
.hE
{`UQ
|N#T4
H3^0
xT2|
cv&@9T2FD
$z~\
?Mu8 3
4({v
ZoT`1
SodF
oZ{M5D
D~T ^i
4|mlS
/Fvx
$ G
)e|~O|_
tb Y`
E5Rp
K4RChi
1{xPp
7meR
_i|H
!)i*
E<DQ
3n49
+!<Ey
bZQ_u$
[);(
,_le
*?Ce3
8\fr3+
9mx~
~\ :A|
].V/
+/v-
A ,T
J!ge
W$dT`
&85t
~ci>
0JpU
B7|&
]T)+U
kkj*p
9(uD
\rl|
p=Ml
XYTv 8
m d|9q|
Xq _
` VK
1qqFQ\F
'|Y|
vKV|F
9wgp~
~-^k3q
- NJ
l KS"W
j{5l
(t=H
&,.7
xb5
-j/K
pEZ$CbG
~yB^
C"9{2
oaP@
#.2#
-YNl
vQ?T-3T
wA!h/yg1n
|eJL[s7
xwRt
C;*n
VPeXS
!7wD
0-??
0D
L('k
Q+F(d
6I(T
`kVmN(
+,_^
nY# ^0
71rA
N7$N
0ZB &
`nKY
6%pg+
Fa_a
(a^A
#d3C
A9x
=TU%
m}9@
k1by
_jx-};
l5{cQ
Q2!Y?
eQVl
4r(*
'Uo~
+"}X$
oB`,
9HtC
BM*}
q=fS
&P(
w2,f
_m@p
M7 'N
c+ T
BcZM!
T|^:
{ 1X
Q!#\
FJS1M
{ sT
P3J9>
|f/#
2m|/0
DW<pO
Bv l:
GUil
_YmT
Kc^x
y}Cyg6N_p
.2Dt"
7W;{
}cjGs
&hY;
V^w2
@/E`
Py`wq
aU/V
n9(\
_%lI
Fx2"
u U+
j7`Tm
3(P4
\OL|
q^Ce
a98h
0{<"
qO*:W
#m$:4HN
>{-]Z
\]t^
%WboN
5q#4
T6Pu
;(X
-C|
z|]e
lDDm
me8:F
Rhvd
A*D\
NI"utnC
TM/
|?Yv7
TyN{
QI#I
#J.Q"
QNWH
+<(
VWf
WQ~0
pGe(n
#MU[
To[_j
9ar;
h@Hp
dR7D
l@6V
#z (B
'?5;
W[/f
<s{._
#Be+
UdF 7xt
l;OZ
:>HGca
<.:{/
' xY
wG)No
uE_
yxUX
4#G3
AQ 5<wi
u74|
s!0m
ccqNq
ykzl
"~ d
4=3Z/l2
B]%|
0Fld
1q+d
m!G)
CZ#C
7\("
Q@O(K
^&+`z
U<ES
} FM
_r#y
?>@k
fn])(
m+F~
I%?v
a_D J_
sA ]_
/1nj
"P7r!
'lD
.9`*
_[_e
S6z-f
ToMQ
Wz Hu.
JZc{(
^DD$m
(0by
N"N7N
xr)6Y
yXt v
v#<,n
}vRknm
\@!
+|Q*
D*-c
&MU#
{A5;
8qb
]b_B.E
7&2+
}=xhm
wldh
~f?
~9FC
[Q3P
TB (L
x/fr
`3G
-/=E
(CN5IlPp6z5XfTsSboNSSbh1UotfCyEftHidpdY3Q
2psp
ppER
C7cQ1
2;<I
361
A>#M
a k@
vI?|
$Zub/c
\(dq
}7 W
q ;vw
7?b'
wb [
@TAG\
[3 K
hH1h
rR% M
zU%k
ovOe
aQM{
Bi@u
E:dBK
PC#o^
//NP
1< m7
5~B5,zI
$rH#e
6u"UD
r)Ucw
^Ffu
E? ?
R sL.
R5n\
'u]N
W~ ciH
T|&E
h d
T!Cf
WO]<s4
IIR G
Cbub
qYk
gBh_
||b}C
/cyX;n
(,.fO[
TNq%~
!]4`-
4mb2PX
7JuG;X
,b2N
J?<9<
fbO4
|wG`
M+49
n}y3
yZa(
rkhSq
8d^:o
cyL'
ryO\o
i1Hp =~o
x[0$
'>$W
!`ST
+XyB
'@2Zp
.-V
L=e<
f'`(2
6RK|
HI2u
YV\y
ZH$
)S=8
'I
;2X]
g| rq|1
Vf.:
T7s
x[MA
>ldL
@_F,X
Q#NHm
o3bmC}
[K/g
w~?L
![yM#f
'=8r
($? 2E
PN#
2[E+
Ci5K1pQlpf
N,5|
t{$t^
H{(W
G:vB
kzO\
txIE
"ZZkb
"1d=
GQ1
."/[
fP\u
jM4k!
XBvxq6
9p,U
f}*?
8U~8&C
36:H
UQL<
Vc;'
ylau
{hyW6
pSj,{
V0-F
he)J
Q8]C7bL
<G.Y
e]=I$
4Om
wyMP
c!(h
PH:6+z
6%DI
kj='5YO
eAiF
,:t,
gO[X
S,Sm9
N9w&
En&,
36:/
ScT~
I FR0
Y?TM
a0!NE
?Q9
KOpF.P
w'gJ
?\b;T
GA%k
[')=VZ
y p[K
& ^
$'Eu
tFPs[x
H{('
#a}e:
(73]Y?WD2//_oI
bycVhf
qiC1jJW
Wt8c
\&koe
h%ZJ
fq$)
0vi>
!R~Q
B\7K;8R
n| A
.,Go=
tyPK
3!2
\: ?7v
+]Xe5
{|Tk
`PAA
$Zi <
B,V=`
wH-m~
x`<k
X{> 2
ax-5
Wo6Z
t}9M
8pSSug0 w
/ws~4
k94\
B:.'
&pza
R7 e;
jIc
0e(
<Tto
e,t{{
YG^v
.(#,
eF@+
rWT k!
3a <
zwX
hmkbt_
EYD
hTH$!
PB;:TAZ
c5@C
6{c[
fY
X#L>g
Sd6J
_G)_
GSzGH
5K(
JDN }AL
yx{kV+
K9,!
C]~:
LD<@(2<
?7,
R]E+
NU{
Kn\V
Lhh"
gbFTh
W1tS
v@ C
o 57]
bCJd
{/kcE
J -,rB]
B>}.
$5[b
saTg
=Yql
zF K
6K6~
1c M
P~>]
(r S
QrzL
dr;A
c. 8
Yaf]
1ae
#rzb
}3:L
'EW=
gAeB
.4kY
q! }
7 L
DIR`
se{|
<fNLNMN_N(NjNwN1NHN|NLNmN?NsN@N#NcN]N)N9N8N
J% 4
A.3/
d'HG
}fC@
O-sg
3hSyd
]c.l
&<~x
(VH
timJ}"J
SO?T
19J&
/(qe+
K `[
GB5X
m7'l
{dGb
+(V}F
NAN N*NtN6NuNZNiN
$y0:
MN|Zh]
*Z:;
dpoF h
$TI#
gBO`
X4F!
LGu
/Aj
Ht)]
:0")
o3I=
S4z^
lNnv
W8d&
g{LF
`h<C/
49q4
K, :
6J\
,*h$HKV
>a #
&CF_%
{M:2E
.}S;|
zItfY
)) I
0 =P6
GB^.
Rne
_5q% k
C@&+V
t!2
(XAt
RQ@]
WY[.
G +Q
wYwo
Ml.'
RP<>
iAIKv3
;LG>]
DYQ#-oMB
1~C_
r3O2
Nq3;
[U:V
ooo:z
8*h^\mMs
>iI
)`j*
)U9|
t:i
d~X(
YQ r
pMZf
NUNaNqN0N
bnAd
4Fx7
WmUyQ
O.#%
iMJM
}eH@
zc6A
Wx E$
J$+s
~_C--
0h4"Y
pJJ{
BbCK
Hr}.si
mGpk3
CD.U
0# l
31BW
>F}r
)rd(
2T'8
XI*U:B
Vm+
lI y
l#S^
&QvSU'a\
?-W+
0 k?
60Hb
H{7@
n;JP
a*c2
CM9V<
PLB=
w&$j
##+8U
J@xJ
|n0{FA
'o5_
1\%
"Hx~
NV28
$l2&-^
N &
BcJc
'3Ph=
@J.8&/
!biIBG
xj"6
+% 2e|
Tyat
w}C9w
?MQ~ \
`sNMi?
\M c
MqQW1w
_4*R$
SkSGhfN
+O:xk(s
+,#.
e\$wQS
`{z/
nh*!
#x \
\$(> \R
3xcI
U|bU
J~*
%kTB
*;~A
e-]a
(6qw
aV)F/l
i(lL,)
3#Z
Z\%T
)e\ 9
c0A
y[ ?
D*n}
OXEd
)&\J
s? {+
MuJ^(
?h4p
f5=SYB,
m2/X
|EIC
f gcB
M&eW+
NmNfN]N\N]NONoNxN
C F=z
+ "L
X^P{
SzEwv
oJHd$
/iyw
3oz^E
n82wD
NBN#N<G
cJ9.N
.$D-
iJbC
C 3@d
7$92
d9eP
K*B6
QO\(V8V
P"eDl
Si2c
"CLN
?bn8
Invoke
OF9m-
$b_9^
h4:t
?K %
>aqJ
. jV
"kS1.M
66,
U2+T&
g`Vc9
qRP
)vpw
MY \a
{ug_n
9Hi,?%+6
"ZLkp
EJ&u
I:h1
R -
3 Vr
m@\
eeUf
p{3$
/JAB9
&X* -tI
oc[U?
ONpUU
R.?v7
qZ"
2) G
iO-]t!'
o?jI\
+aYF@
!1W0
\k <fx
N{T>=
yA_:
sxA)H
p;vb
~f+_
:>A)
Oe
`=l_
KAP9
72!1
%H)=l
hVO%
^BwV
9"rLDU
3t6?
|j8~]iv
\[58
FLs*7
L@w1
J:UV
2MQ[Sz
3=u4
t@lP
mFHZ
Zn ?
oAk\V
v{Yp
p3lV
BO?,
PCl?#
@SXJ
R ]0 Y
Pb+5
4}ucdbu
Y %<c
2o y
+9z
Msvyy1
mv,1w
J!\p
Rj+.S
`HB=
CTe52a
#,2-
kF1m
p y
+N_6@
G0]*W
Y>vX
: 38&7
y<H
idh1
F q{]X
BfG^(
gl}K
jPB-
G<V1
Lo#v
'W*~
NQN2NGNsNTN N;NvN N\NsN
c[xO#
N%vi
5J+$
iYR-
7yuG
.k]|
e J/
O9:l9
sW+t
49T}
v4nI+
BJ7;ec
'qlpy
uL*0
g{;yK
A/&D2
7IIy|f
$5Fg<!
L DI
M4$
$>k
|h_\+
hv8?=&
{l*o
UP!JqJ
sSi/
kb/7
T9:_#
eOT}
(|?:
dSUT
n#8qKM@
`3XB
u(<
QoS([P
j]8!B ;
2M)\
O`,|x~
+ W+
im>Lb
RBeW
A( t
q|nR
/StNC
dq_a
9T 6$B
Bm.v
QS!F
<QO^<
Az u
V!PB]q
h92-p
v,YU
IG.
]7 m
W^l[L
vwgB
lI?Xz
q+#y4T?
k?hc
}mLP
chW
MN)g
%Ibz
MOhm
2#:s
xUc|
]V$9~!
P@v(
jNqCq
/$)]V#
VEQi
W@"4K
|D:QO%
[1hz
uPm5
-xg
g n1bh j
_~rz
wkn53
tsg2
Ye8Y
3rtp
l}k#+td
`C(ALyE
@/Gc
2mVL
n{F527
0BGw
J<&F
-YRW
L [v
? CnY
rIx-
njD/
NiNdN?NNNsN&NYNEN<N
]\yeJP+
+o+vc?
j-b-
h&IJ
^/,X
kRO2
B\69
QC+c
_QO0
+OiT
'`;T
Hw]ak
-I=@Y*x
J11Q
).)d
fE j
J*:S
~N5Y
PaEw
1'+9Ixc
IGzi
B>A$t
8IV&
&Y0P}
~Bq 6
/? KNq
M'M`
X794so
_&(u
jpTE
us=zJ
E{U!
!FR
VyP
1os^
{a)d
{ayY
)qP3
Spde
GBO5M
{A-9
VD%
u8 m
t!n1{
RuntimeCompatibilityAttribute
-&<Z
m9<Q
E (bBJ
>\i""o
oVcz
eH;&:
UWO&
t vp)
P =T
@bF8-
Lhy6
3k1e'
Oqy_
pxT
0+h{~
mlBD!Xu
#s'#98
=((O(
\@#i
ACR
rDk`
U;}!
-Zyy
3l+)^aa
B{,K
'{VXmx
[URho
F@9?N
ConfuserEx v1.0.0
%MW"
>#~Z
eqJv
+ Q,
?r"H
c\ZC2
;H M+O
V& ?
ozlA C
Gja@
bl+aSsHw
8$q
] #B
dL$7!
&qDI>Tf
uYcL|
mFUjeW
e-VdC
yz)#BW
M
mu&Vq
`IMz
tiBRH)[
#YJv
m@C
P #-
d5zy
Rk&8
4 1&
kq
e2(%
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
>tk?
!IuE6}
5(yj
NEy5b6
3+h7
[8'
e,Xa
r/OW
SltU[
waGa
Ih})s ]
IWec$
~n$
KF^N
}=F+#
zZ"[/s
;So'Ib
m ^2&f1
]&(&6
@I8 5
Hc<:
NeNoN
i^#H\RS
,.W$
3e.V
Do{m
"D #
uqhLY
3$Ev
H}+)
Nn@H
U^':
C$R
6lDC
7-51
z~y,
-z\q
uvzDN
sO2"$
SRcV
L5R]
(1qanfkferHcqhuiiXecG1xjbDhyzC1HKmqRTwjpP
Xu?i
3D5"
QVx&n
*K&ch
F3mx5
B#;Y
kyZZ
\9i-^
SM L
:,!z
Ot{X
?rqdWIhVbI
K#kwDuM%n
4ypJ
cR6
Sz?7=
x_K )
U~gp
<]X*)B
SayM
j)?z7|
;" R
b7V$3 h
jjP{
r6g)U
='y:
]CqE
Sfou
)u8 N
=*AxA
=' F%
3$E>
|[Vq
D"cQ
l+s6p>n
"Fz
i KM
4q6$
SU*:
RIBsO
hCoh
$*5
7(fx
@w,c
M\w|r
,5K6WYw
f v5c
YL}~
*ern
$oK=q
%mG*v
o-E"
}4(:
yAGx
V/y2
aia4
|4CC
+ks!
|?mmO
H&w`
\D%>ov
"dV }
-F?h
>Ui1
RX~Mm
N%N(N\N4N
,8 n
;^nX6
I]J^f
/J)2t
;8 [
N$N>NpNqNqN<NrN{N[NvN
N.FPI
F42@m
C@p/
JKA9
{m[tzg
sBAi
]xxk
<&.B
uBS<
jU=
lFh
gdTn
dL F
5|NnKr\U
f..T
E;Ve
(U6T
6U-[
9^gd
>|u=
dHI
`[^E
AjGR
kK?)`j>,
N#OY{
OG8u
vOPT
/`Gyt
s2 T
jT+"
= /Z&
6V}>
Jui]Ro
9^gs
/\<I
|u?||
cRGD
yM\-
QhN|
tR[q
!x`0
FPrj`Mnn*
I]Oh-
1e9x
X]}R7(<6.
UYlw;1L${
./-r
tM{E#
!Fj9
QL+2
Ur^W
w0fv
W&*g
23rS
L}`m
^TP;x
luhvYUoy
^+
H8KD
9 :C
^D=<lt
xxSb
63O
G:Pc
%qs
Cy<Ius
a1TA
e|U+^
Ke4{
!A:H
SBO:
&ddl
us_
R\[E
W?Ny
F_8G
!Ji$1`t(
A.$R]
?u)Dp
rv:4i
;@"W8
~? c
r;J
9,f7
#o7@
w#]HF
FT"2N
^cL/
xfUr2
yjy]
mW^5
jlEa
b:si,
Q$6c
YH0>E
{_ah~
n=V0
_nV4
\@[r
\t!|r.
K;h|"
6 8t
K5Zh2y
#[$;@_
u*,}f
5? =
FWm1
Oaq5
0Vlh
Qh;
LWwV
D&VbR
PJI>
54y
Hq6F
f3F+
I>RQ
xRn
9WL
{D[.
HC*fQ
|9DN
GoD7U8Zf
Ha2j
!?N&
\U<H
#C9?
`\HO
r[H\w{
&8Z9I6
z$z&(
By^#
z=D
e{8~
NSJ*w
V<h
J( s
|ZMj
xv QH[
lm$cT
,eG>
t|*\
L;$.
:Wd!
d`/^2
<Pb9
.:]!
6deLk[
*Q>
u&Ak
jOWG3c
k=Nu-+
qfn>y
v3GHV
Vw[0iEh
VS'F4
q J$UD
o7t
NB vY
O,C}G
`XLI
iayDm|g
f<k$
wKQ1
R .H
86M0
D(^z
aVX
m.^l
^@za7lA^.
8Rww8[JB
(>kFr
^I'
!761gu
r,(`
01-Y
ZtG\s
v_s1
P,>A
6{7L
8"q<
Le0}
GYF
L<NLN6N1N
+W'.
<(_?Xu@
C&]s
}M1
CA2aT
0jP^c
OkG6
:-6^<
)?]e
P;~J)Q
(M~r
pz_:*r
/^UO}
BoU%S
cFsb
(Vjy
Y1Mr
:{gl
n*t
3",a ?7
s":;
XhRQl|
X6oS
.4n 5O
Mv`;$
3#mqg
<Y8P
YH=7k
h0Y<
Qqiyk
Sc;G9
SzK?[
pq%N
NU4*+}M
}, :7
Gmi;
5wK0}E?
*j|:
N/(N0:
/"f@
>^Ah
w&l.
6ux;g
5Erq
/cG+
@b2P}$
7g9Eeom\
`=?p
\ .s%
iZtnJ{X
Hp2K
nrhV
g .Q_
3gBx
3F6P
tLJ|
tL3T
4 yi
l'f{]
zNs$/zRK
k2hxY
%zQT
r-6E
gDn<rz
uc 3o
/f{
8T~\
uuct
A_0hI
:Mm"
G:p%X
ly`kD^
8u8R
ivs2E
l]TKw
I$6m
xKJ_
%! ^
{sSD
Gmsn
~gD
<8?-
_eR
z?i@
Zgk
\m&\
^Jj
u8,N
Sy9PHn
G tXL$
YpZmeCK,\
G[U[>
$:C|r
3Z8[
XG9u
v(@g<
\f!n
q67Q
Cwnj
f/L )
9WH&
Nx#"
+ZY;7
Jw?,1
@(jM
\]Pz
rQF"
|2#w
x:^M8
0=M~
n]lwUC
H" g
PWnhI
wVP!G
GDcJF
-$B+
\_c0
l>k8
XiF_
Z#=Q
yi\<Uf
)%92
,25~
g>l
x=otw
z'4B~
i85M+
cbnn
v!RJ{0
"$-)
`u#\
"<n|
J.J-y
)"6k
-;S(
qc N
XF(b
<th'
1@"q
9f)K
c%9Iy
ppl
-3e]
>V%U
cY=l
[A:D;
mscorlib
v*Dd
Sa r
~kBa
Gj|>
|N R
z+~+
mj+=
A3g=6
Ak2 8
l ki
!OJ3I
zK};
/IV@
F;{#
tvk\wS
$-ct
`:$k
(-YdS
<_otc
h?t~
{FM!vtT
0zl)
$;fV
;Tsu
HhLp
HXTh
5;%=
5!xa
"go{\
EG<N
NAb(
i:-d'
#Q5Jx
r1!~d
+N/.
T&,_
W=9G
^n:G
/6f$@X
hwbbG@
XLUu
DLuJA
;5g9
.j9_K"
NmO5
99p2Alj
(!?6}S#$
67NCNlNfNEN\N
do.p
Y .,H)k
PlN)i^
H9?\NI
NB+-
T-P{!
FTh$
B(~v
GetProperties
O/Hh
oA}$
oyE`
X)AHS
HENUNaN
c^ ym
}vK|
D?v
eEt8
kWo'F
P<k
+XKa
N%pu
w@r&q
c eV
+WT#L
a K\
5GCK
Qv m-3M
d*?]{
ln\2d|
Rye/
o@B_
q~o3z
q" y
?9}`
HFe>4
CM6SK
aT/.o
t^G<
L*Ya
3e`E
B hw]
\? O.
Pw o
l]2;6
t>ZaIod
b4Za
aGdT
mF/F
(Vwx
^{MB
NZ\B
5$(A
Fs~I9>
d2SL(b
G(`U
^~mR
WF{E
O]us
L8U]
>5;t<
uj?9
BGj`
Qy,I
YdYZ
-v3&
B~pd
v*)~
#S>-8
,FlK P
6+*z
YiK,
O;V W
(h-W=K
qYN{
Ltw^]
nyP+
~E,A
CqHoE
Gj7u
;>XN
\IsB
(_0I
biUo
hg_\;\
Dnv2
-%mz
~0rVz
s6MN]]%
a`89
P5&
*ll8
{m$9
]u yI
u@wk
}'0M0
OBIP+ a
GFnvN
oIMQ
YL5Y
<5~k
{o8!B
fxta
JJ$P
AzrR
9jBY
f?^
k:=%%
L _l
|ta@
qGRS
dBTp
,pJSY
C.v7Z.
fy-O6
I}WX
>$|
liVte
|Dy1Ye
K(h!`&
q%z5
hOv1
2~[2
t)#
c)Zt
<[ v
M-p"PZ\
? f
dxXc
X h
ZVKH
K=gy"
1t=01
%9fMe){
27It
NfN]N NIN N N_N
\)-qk
~/0=
M Lo'
$b5KQ
?r2uCl)
iD7>
B!dx
b-l?
)7yeM
8M08
ZANQN
.uv2
4I }
Adn";
l7x
[2n3%
}5{b
N%NzNgN N@
gR6+S
+th2l
-G$u
Ex;+
4"CX
_j`3
ydnt
X h4
-!4j
J7U|
@:W=y
)6c0
>T0*
@PXRm=
g\y)
k<ZG
YVl'B
Z_ ?
-H`d
h1qr
HkzA
-5&X
oC.u
)SWk9
$&'
1B{C~984
@Bl+
\m h@
@>$C:!R
bR*@fs
PD\R
2 u)V
s+c'7
e/2I
H&6xs
~<7p
^G$9
kw*y
~C}7
o_#;!
9~ zp
TtNI
BN e=
_:dY
0;c*
oq>i
sxxI9
HaM@
BE8{
1wim
(*d
+h`jI
`:|-
T>*^
es/t
0Fx+
ux,F'
<e[{
xlzB
9[yv
!:
#4i.
%8,G
"7N|
pliE>u#
v jQ
i,z
x~ ^]
.tn`
G3V3
HQY?2
S?NO
x} 0
75ra
b *f
\5O'
GTsW8
J lW
tbXI
!This program cannot be run in DOS mode. $
9Z^
Q`c(
IiuA
>^v3uq
{ [(
'"nr
qTy8
YXO.u
ww0,
@yC
i_xD
tzY;
i$-U
i\EH
l$Pgc
#..!
@Oeet
;dD
f>/G
"<!#
lZkV4;
T>W7K
L.`(
\>A
#t.w
+% |
5_or+
>O}6
cX\|
<VZf
N)BV8
M%_K
mD ]
d&jw
c}!*o
I_<Q
S5Q"}3
uQY~
El/P
DWvn2
oNPh
nN^,"
v`
Hdr"<i
!l3s
+_h"
^QYd
cMDN
;Gn>~!'
YMw_
o77hnf
#;t;
j6Ou!
I'=JL
S=mXO
(D~Y
pWs P
Gz$
>?W
i+5=W
YpRQcNuJUV
yG'o8
7/X^
~M/&]U
eS9)
a5Fb8
$[$K
cP'-
J$BN
=h.!"
^:rQ
@:T~
9NZ .
wbgQ
j0zLm
^x&dw
h9OE
xNvn
J"l.
@DZb
RjXF
M2fh
ZN]Mb
-.P"
MJ2p *
hi+!
*VZ
vI
M] qK
0DPi
<,x_ P
_7!cQ
>W>);
^izy
Fn$]VO
E Bw
\tlg
mbaN
1B'x
hpQ]
La*h
K{~P
=eFQ
NTNXNFN\NRN
Li*(
>w|[
zZK%iR-;
h;nh"e{
dTg}
j`MW
gz,Sl
N%&1
+" ;
yb56+
Spy32s72
TT\t
x"<
Rq!W..Yn3
J S
N#e\
MWH!G
TA?y
T(f
vW q`&
+wKJK
R3Xq
hk=9
t9e(
xCV
Tn_9]
N!4M
);k7v@
n =SX6
[h6o
[* =ta
P?C&
get_IsAlive
967R
& | @H
x~Ni
ywg
/h^=B
{Vq)g
0%V|
4p"+Z
mj
;*'9
cX[(O
,.wrD:1uf
l_4
U|t1
r|L7
*;Wl
*5zM
Qk.,|
2Yyzs
=N wF ~{
7k(d
| @b
IuwcQ
=k+E
,uq`=
(g(}D
VWsq
k8v~
ZU~ {
7~/O
<vPWipc
h5eq
@{RY
S |.>
{c.X
Ve ?<
)fYS
vU\"
JR<IF
Z1lU
uAy|s]]i
q;57g
R+IQa
V8"k.
W G=
P8G
kobv
nA<S'K
@^M
'M R
Uv I
k ey :>&
m\,`-
VuF
"mF'
Hk_*
KRUA2
_zhK~
~lWf
f54%t
O~)'
Y}+NQ
K"kD
uaYiHxqfABE5Z1mA
$% 1jS
}UcPq
73G!
=\-k
^@s1
"Ku=
#Zt3
P4?W\
ZE#^^
N)$v
LMg'
-![tP
Ytcg
lQ:1
AeeU105,F
QIV&
ip q
J0~'
*SZT
tD1AHo
B7C,U
""?nf
%o<t
?i6Q
9U4J |*pQ_
^`c
]J|u
^ <
CEz
^ yeW
~|lNM
m<}u
^`x
E'R-
sdE`C
.Bqe
aSts
VXu.8
~LkWL
Y ""p
m &g
uR|h
/k~w
](_A
F_r92
.g@w
o"2 6
Bm@+
y)I2>B
Jk1
`f.M
oF(/
IO/U
gQB}
{{^?
;/e_ t
.&@?
0`{u
fm=*
xe5
Yi<Z n
cJm ;
D`12}
# tt
LmHO[/
<(1Q<
lrq9
cL6U\Q
tXsZCH
xb8x
S@<iV
1t'>
fN :
*5ZL*
b0F_.
.<<R
8lGs
b9L
K~Pz
h<~H
h4w#c_T
_#<MZ)/
>=-v
g
Ue$Z
_m^0
A]L$
mN7KP,
]Q^[\
i<dB
n 4T
R vc
(<? ;l8n
\&=;H2O3<
(Tt0Otq6
Vw8y
n+W:E
o|yU
b,3v
\R1z
zP d
4K=SA-
D#b5
?:+t
J$'!
p:@Nl
U@N]
\SGR
raaK
v K6 A
E5>r
{'dC]N$1
w\FI
H8mh
AO/&
*YY$h
!Kt&y
(ar^H
vNAK2kYp8CfqPOd
By.h
un8/
ZZcV
+*)f
';Sr
x<'Z:
-QW$
6fD~
_BMR
0d)J
='R'
|uV
uCJr
]]]c
\1#P
-]
./F'e
K$A[
ULlD;
g3]d-K
gU~'
'vr?
uYE
?U$l
Y.xvxO
%RFT*|:
8:IWdi
8 I
OF\S
[Z;
sL1B
K#dZ(;
+RS
3'{N
Xim%b
p"7
B[e^
#3f?7
7*Z/
&4G&
@,ZM
Q/eHf
!lK!C
x-@r
$EAr
MethodInfo
$~\!
2T 7 \
ftPS$
j+ F
<(Q"V/
L,Ds
-_Ib
<TSO
U^? eNm
n, ?0b<
@M\'-
`K#"b
MQBH
K!TMC
CompilationRelaxationsAttribute
k(}
x1y0mi;L
[8Hs
WsS6
F BJ
hZ:W
t][*T?
+\EN
E>Rx
Bz^z
b19;
s2P;
K0Pk
"rou
gV!QEDT+
LTqm<
U1 ^
Ap(Z
n3n[
PO6w
Ax-
+ BU F
V`qOkv =
k3@9-
6I"dqZX#
CDL`<a
5wW
7$ h
tD,L
^qgS
jD5i
5:gv
YDB"
K4I=t
Lt`f
qwq=
Ob:30A
+32Y+h
n1#2
H" |
+*=I
Rij_%h`
-3tgi'
T~vfY
cdg&
$A\U
MSfs
NoNiNhN.N
=$sy];
XAKF
PGa}
|m%j1~
~91
Dih&
0.Wn
0 Sy
#Irc
ZtHd
DP>}
HC{G;
[3VB
Q.U 3
N&?;!
# ^0
f&`
m >z
*!S.L
aRTpZZ(
D>#:
BtMSk
JUQ$4]
Y[zB
N+]9
S&^3
w^g=I0
{D|A
Ka g\
ba|0
W?QV
]rd^
y"uBi
\"W.
-Bjw;
=|wDba
_- 3
6x~n
_{Fuk/^<
N*NiNVN
"Io0>
\ b<
#NKS
?HT
{P\@<o
aE9M
EDXd
iKsM%
u~3:
'i4
D73!
%K?I);
Ar!k
I,`0\<
4`\;.
OH*:`
ro)ymL
},v/
&Jx+
N8^QT
.W=[
>zM>\O;
5_Rg8{
?0wik
$C|h
&w]E;
'&o+
S=@5_2
I Ui)j'
M8+u
Q)">
Cpjp
97K
42`E
w%-i
\Kg
'yE
&o,^
J'e8
y0
pMmb
@5J`
gXei
) ZNu
~Y >x
ypGiK

LR/;
tcq2
'\ohIZ
-SzB
$? M
!FHF
t| f
x+Ez
G<J
NvNUN
Os X
qD'/m;
Q(;[
p7aJE
4NMBWWY:z
;EAv
9ayW
9`!_e
BM5R
^ ?}
EV1G
qaql
)uJT
|WL^^
P'<,c
[0*(
ym}^
Yk"j [
Ah!DB
Concat
REXx
Ak1`
kOL7
e#sE
GAUz
/POK
tls%
R&>Rd
][ k6
a!gXx
^Hsm,
Gtsf
`5&AEz%w
iHxq
V}OdM}[
|<VvdL
i.1Nr
SrPK
&qD=
R$81
$L e
MMAel
$IEX
E'?r
ek_[
mfas
R0a
VQ<3l<1
0Mp6~D(BK
$vU ;
lW Jm U;
)g~0_
U0+$
iZ3@
zvOo
~R;{
tC3B \
u|UH
;?t/9
~ryhj
tZLnGF&%G| D
fl.y1c
sxv{
A0V)
x5UG
j?K8
P=5Pc1
dzeY.
`3CZ
ayE
ITzJ
\*@f
kVnb
]4:(!
tb5f
=LP4
`q=:
GD!",
@9 z
sQ6W
Cf;+F
:5h;r^
(<8Mf[
-Jc)1
Jane
A.yN
ZlP~{
$_Om
RRa`x N
][Ai
CF+pJ1p5<
S,=E
cHhm
Mw*9
%BN]c
yK a_
@JJN
X!=_
a/'T
V b
ep&H
"3|T
UH
_ >t
g$]
cK rd
U==p
|6qT
+DIjjjf9J
w^-4b
780=
=*{J
Igr#ie
f qVm
UR?b
RP^( 0
`8{1L
lm^H
]$bE
lrY{
IfSrH
BY;,
4Sa
qx8@>
jCo -
cl%X
G[
MY_N
<Bf9<
S8I}
IH
0h=Q
BRYv)
fY(_Z
cU{{
?;=:_F
AV[G
k?;4
V_@$
YY<o
e6\~
d2K
^KS]
`[g|
>4NqR[
RKuwN{
x/~ c
2ld
Qb5G;
k@N_a
* WH5w
>jE+wCgG
tg =
N{~o
]0?X
lF kh*
Fz:N
&{5ps
\ ;ax
Ff)X
Qs(\=
_9xZb
q*iZ
"!/6
o[ji+
\:>94
a=s_
>B[LY
HxL#
tNHpX
toI?k>&I
FB4
+URtc
7fp'J
|Ud<
NLCx
O\h2|
Un7Lb
UoaC
2 "
@d5- C
aIx|Q
i^`
L f.
q&juZ
=Zz2
ik-6RW
z*%<
E0$C2PI
`LV
^^Q"
dT!X
)YaY
4<yz!
\PE&|
!d,b
L{pV
0$u'
:#6n
:PlFR
laVs
#vb!L
YoN
6&Oj
.C7V6/k
56POaE
q,!s
G!G3
%6;kR
*[\z
N?N'N@N
sQ{-r[rW
4 \ZfY
/tn%
7$X:
z^|3
M6HK
6 Mh@U
q_'z
$Myr
-vI0
Yt~6
x>*jO
1l$2
@Xbr r
^,b;
B_t9
,"!OKjt
[;mj
DsmK7
NpNIN4NXNxN
6~m*
R+10
xI*X
BBW]
Y;f/
YS0g
aR]"
waCg
w.-"X
7UYmz4b
PzQ;
' Jm
^9tG
q@Hy
x=E}
/_Lr
2Qj[
^]Ab
4rzT&
Ux=i
yc/<
Vma^
Tfk4
E XDo
O bpP}j \
8qwNT
:r>_
+mfw@j9
N$N>NpNqNqN<NrN{N[NvN.
7?v
0X!@.
_CorExeMain
59[Q
?bgjl
NP-}
s;` &
.+ =
]Tz;4
2[EXa
D6<
h5SQ
,#T\
w5R
BK:pIIM
e9T
#F[
~O"\O
WgJ
XO%5
-@i6K
pW3^
Q$jC
/7%P
+fvWR
>Zt5
\CL'!
wHVd!cel
|w& \
RH#Y
M +73
`v}ER~U78-
z&.:c]0:
"E+,+Y
:8. z
?hv:
uuSYdJq
O}%j
t"R_X
v ds
ox]2~
Ouvp
VeHf$
.HT]
.wE;s
|d6O
sl#C
h )t:
uS-h
mL8"F
aLb]
@tzS
g6 x
&3c=
t|Q(
[#,j
Z@;cw
tM&|#{
v\|e"6D
.nE5 g
C 4 A
YxRl
Yl~/
>'{q|
DJXV
<Zt1
5dB!y
,v&A
@fsQ
QJAc
~[txt
]8Z,`
:uRR
/$&nwm
nelb$
suig
! ,m
74{z
iDxW
e2[, =
dxfg
E[p}`
Y)t]
U@W(O
&\ r`
o H|
DO~T
cE3ek
{`*;
?M?S
.6"}
{Hs0
MtC R
[+cS,
f0QWs
o~~0
:w\B
\qtK
Ak SI5
xl.{
* /x-B
+?8i
]1Zw
.*Pm
Ej8
!{D
F Xf
R6} $
<:7X~
oLWA
*'IZ
8CNp
'e o
ua`f!
@).=]
o{WL#
_~ ^v
j5zt
Mew!DR
<55I'
UGX(/7
F vz@
(wg&
hDS[
mV7g
<EBF
"4 A
b>IT
sXvn
cA27
9uvx
@ilU
ZD =r
BLrpUa
#@ j
OQpw
ib/
,_6gP
s Yi
0q@
08p^_
=nVZ
R{dF
#zix
{Mu""F
Dxv(
4B0i
TZH:}*(
u{dI
]nh
NxZ,~L
2$y1+
@a$A"
[PTu!
318
E-&AY
#RY$q
<;wVl
"CcC
X|5=SeR
Zq&Dv5
7&RFp6
TFOL
nR@0
;8 Y
gI'5
X,-Tr
5SZ
\m{
!cUN
AR/f
@G &
_V$2
{89-^
%G`gZx
5)cz
YLy>
%MfjD
iE(\D{
Mm%v
B,Wwe
z@D.
[rVhO
Te'B
qtYL
Vx4F
2&L]
v = {;R
\zA"\
U@;+?
e&Nr0
87L`
Q4X
[=:'
"= xy
!~v|
;p;1
X"LL
5n(T
&ah6
d?nb
*'~/
z}*[
p{`'zW$
E6s;
0uUF
%bu_C
A.b[
4lQcT
OPa
wSe"
Mp'V
~-#H
B{cO
Vw/l
5KN
JcCYT-
T2c#
|Y@9.
Y*H:
'f#ML
7!ld
`m:V
4m vB7"bI
h )|
C>4?
6z .
{/!X
]}1
~k;^
=q7%
k4Y<
2lf:s
`wbeg
x$la;
k4/LG
3KUpW
]%H+
A{;#
x2Y\?@
R!-Qha
48QS
d:Z|
X>>r
_$hyc|
s`L2Wmb
UnCJn
]Ny s
|fEO!Z
&JMl
u k"]
pNx
{f$o
,3Te
1^!e
6- g%
QJX$
L7la
X9N.
h^?z,
R lb
J=*j.Gz
(bs%=
3 m6 |
-[<{
9_`Qb
5$NB4
:zs>
,y 4u{
hIg]4.(
5yjbv
A=/e
>4e)>B
,g 8
` $?
nUU
1Cpr
<w<
E\!ahe
Lwd)
2 ?g<
^X[r
x1T:@;P
p++m
5.@hk{y
o>W
({-Ui'
fd10
p ,<
)2X(9g
R_)C
KK4h
kM{o
&sEn
pV]S
m. AM
@z^%g
wD[R
{14&UH
lR;.t.Z
aLGpN
e:x]n'
{~y<
mFE
\'O^Y
fS9xn
*A`}1
VH<5
VZa?2l
zXo2
SR<a
Ksu!)
< #'YH=}
@(EA;[
A8t|wS[
&F92
(Ej67C
i*2\
E C4
#Ytv
BK;=5QG/
Q;OV]
u '
eXj"n
k2M@W
M [jTk
h$,N-#
4/<A
qdg]f'*
:6y{
|B"08
rm(
++A$
TQ7C7\
{m!5
#E2 l
GXD,9
W$oxTs
fhn 3B{
'1gY5
@Es)+
(vo1
&wz-h
*zxd
4kumRI
> [@
u{` 5
D\ 0
kR3\
x]|j
HT0p
f7O -h
}ti9fK
bdef
2AAD
x=2a\=
1Q[s;
-} }
y;#)
_@O]l
8]y0sN
a>/0U
O@$t
dU+_
_P agg
k*Y7Z
+nE& @
Is `^
LR*3.fn
RQcjW
aORj
Fd,|
aY$
P ~{9
6^'L
,T]1
F+()
sRGB
S0KJ
_L-h
.gs;g-a
pU2K
)VJw
TB'l
-T 0
{zSR
i~)
W<2F!
.AyzT
\ =f
)MK6
@`p[Y
8kl`
T'\o
7k76(
Rj#
zCy/
eP{C%
F`_
IKqR
row8V
JqUu,
I9P?
CKR#
y~u~lM`
~xqDx
Xteh
v6;]-'
IT<V(r
=#+e
WzG
b! ZT
`@;=
6LP`
1(]k
!?oY
ou8F
%j`'
A2h'Z
jHY5
1E_"
{DzX
Ng$
f:wW
wY-F
(gDv
GgH
J\E6
sb,/
Q] N
J__n
HYZO
61BS"
KW M#
h%1m\
p)wG
&D &s
P+9'AE}
^vi
htwJ
GRbC
:u$U
'[vF:
Ae:O
ShLj/
4 J!
){ap
E0zEGz
.-Qr
QmU[<
+vBKE
M9>v
n~=B
.8 Tj
cSVJ
`E*o
tlOd
~SW&
jMP)rUK
fHd}
lfewL
rb7
RI^|N
WWa?c07
/ #%-W_>
/qK+.
FM
+-G3
W= JQs
,xR
E?KW
MdZz"
[a$Pe
2Pi
SwG/
Sa@<'Xf
s_}E
Fqkx F
JaiA
Yw`i
{SzS
}T#q]
_{8L
jgtc
{a7
e!oW
>W:KUx
Yq>4ZA
Vs.S
t{j)
8QF!
R|)B
g9Dh;
TeR
T /<
V#K1Tw
KF6J
7{|u$9
edwk
TB;i
~ c@
lWRh
*CZr
\N1
zl-'
M`O?
pl6'B~ `i
:J`Z
ZqAO
Ah]S
!:_ R
Db<`
= O8 O
sb[&
<2K!E+
BUGr
3Gy 8
51xG
=yUi
`rVfF
NyNmN
?M(t
a'/@WDP"
7iv)
uO+kHh
Z<c)n?
R7eh
l-yfz
h.Gv
sPY
u!M>
32K|
_+B
]K't
8aca5
Y(]u
uSJ`
^adT
y`N!
)7~x
Fldg
tPJ4
FAp6
8!4^af2
`Wyb C,
\J9>a
aU?
`=T:Z
oh/
5`$W]
^=/G
*ZLhz0
I_EN
9H9"
M%8!q
fj4+
#0^'
.D z
>K*q
Rn~U1%
ygP9
U&Mt
}x,
gj/r
&$8,
FS^.H
OdR8
V<
A* 8
4BPh
Fw}38
N)NYNsN
}^\uZ
3.ih
D27T
H?R3
1+wc
1+UG
8c4A
U lp
f[?L9
(U\R1
sL=<
k.U5
Q ^Z
C5WM(
i`|qg
M?qd
*gk`
S6i#
N2%s_
'L $ba
3t.Ew
n`t
empk|P<z
5I2p
%=[M
>dET
[<2
$I5-
Jo'FTrf
9wzVG
pv &
%H2u
BE1
IDAT0Wr
](CjW
[Jby
WruR
`9[d_
+3N)
gB(K
~n6-7
+kPa
B[+B
\'' c
<gqRl
}Xa8
*>:h
F&:
%%.k
)O;@
fTUJz
9fq6]
N[}
]Oc]
Wx;Nv
&8uK
;Z^l
+dA M
_r;t
f^DG
TpUy
Y'HQyR1
m4M!
H-%p[
O0S'
2@&u
%#U
Ru `
<r`f{Q}
1he^
0rbB4
iMozw
L@D7
^m-Ai
n6aS
z.-nW
~\S
AIS!*@
G B[
_$0,l{
,.Q3yQ
|i99k
?0u\
men(
w/$5
Qf^[
T {i=
8 f
3@[7
J0P> M
;@JSK
-4s-YG
k@hM
irL~}
%sSZ
r\o,4
CSfq
PU^Y
}i:+
]|Szh
.L+~
l]zC
IOa9KV
,% O w
AX{/
Yl(7
@$ya
4 c|
kN@
&p6oY
LRW`
T0ff
nziJ
I/mF
Aw23#
F_/6
^:l+X7T
dw+Ub-
r? ;
U!4|W
"o,S
@!!4
,nDUVD
IFR3
|}IK
V^\#
tm,D
bP~9
+6>j
^_e8
'4:,
}H9
WCE j
<&}$
GN"%=U
O9$YZ
V<&5<
AwU0v
mn<Q
m!_n
=b"C
<H-78
\uEu
PaOH-Y
G&==
`7U/A
b~['
}#Y
s%Ls
FXx~P9
wn$?<f
D"0l
Y}EO
cY{*tu
ZQ$r
z_`m
;l{t
\6Sm
HA[fp
f'.ES
Wa[]
R_w]
dG."BCx
`XIbUYpj
LNC[OWvv
nG R
O|B@t
30co<
d1Xd
M$En
lvCQzY
8~p
l3Q'e
LXC0
AVTw4
"StH
jZ.U
%AN
KD*W
n1&4
pdH'
r-gf
br7C
-ybk
T[;D
?)NP;
IeDP
;3XkE28
{<Dv(
% 0.i
h+{p
@xl
s~%02
Ou8R
tz5;v
( 6^f
pn_'>0
,!^ }cr
8>eO
<Y|J
j.?cD
&&-Ph
B&hY
7XR"e
]~\ x
ad'X
P TOn
mo.J
%L#J4
= TG
w?PN
c FV
f]dj
0cSL
2Q>\
?J_WW)~yW
@fZ8
mI"F
R3TN
G|Mo
NLN5NHNCNGN
9iO=
uuxr
w?r6
x$;p3
wC .
| xL
EgP q
OjS%
#0yb
? Um
C"@nq
}wPl$7r)
#0 n
i ^_
1]2-& hN
Zbc^=
EA#%
ZD[BPX
)S|
g+4Pe$;^
B=YN'
\wG.
#QiXV
l4#)V
O|9J
lkn
b[8!
)8!u
qk<x[b$
6=M8
wa*y
kB}M
tGOJ
Q[Y2
5zGk
LX\s
rh$U5
F V_U
?DMj-
%\=Zw
Y s7
C8iO
:]+4
|?%a
>:G|
> g]X
UP~
# S.
'ACm
|t-5
L :O
Yp;"
L@7j
^:U lL
1Gnx
a%e.XS
o-K:
\$lvb>4=x
7 e^
OQ;Z
VY5
uWnTn
Kp#8
:{}}f
BoU[
Fj}<Z
Gb W
$ UO
wuy?
E[T0t
% !+=
yFXG
|o=8/;og^)
^'WD
JUw:L
sEK{
'i6s!
J8<r(
nAB
v\ ~
m8W*
0/2p
yO4Ij
F;ru"
7.o@
{^[[
#`eN
BQ /
+Y[S{
17m2
goU n
b8zjMG
>y\|7
W5oN9AY
oWmX
F `yu
K yk
d |N
s8# !
P[8*
lqVi
jBXG
Q"`5
T,5*
=r)k
o{cH\
zLNX7
!xAb
rH;3
iP6fY
efT?
Is%D
ngiV
F80J
7G>P
5l0"
ivW K
"\3s
aW,s%
C 1 -
=3p9%#
M=dZ
1(`_
tx2.p
8OC:!
Avvm
8r %
w6gN:f
zjlU
I :l
%|=V|
,2L6
_pp~
_&P<X
`yY!;
Qa`8
z^<C^'
fG2B
#2|
N,NjNeN9NyN}N N[N!N
K)=.
KK2(
` **Ns%mr
?D|!
h6u
U#@7
Y+>c~
74I9R
,y^SP@<
c-$)
up_i g
get_IsAttached
{\e:
QK&t
>JD
p" u\
-PMBG
nB"5
gTj;
~9WSX
=5 :`|
3WXu
3R>q
~".j
7]B"
5=.
L(T9
}45qUi
8'.;
% t2 _
&|7[
^yj~
)Zu(&
\"?\
XvMV
,K0%+
nm^dP
0()4T.
-nj
i .
ypI9
Dt:$1
H&X$
+twf
a~']
^82[$>
K,(e
V]a~
\;rc{]
M68mr%
01&
N7k~
)HEmy
1FOL
ysX3(
h.pN
qtp U
g:_v:V
i)#d
<yu"
/h'eP
o~3\
x)Du
hcH`"
evUy
8b>L
FyJ
&=j}
S?(x
21zF
DIzv
l.Mn
NdN%NwN,NWN N
V&&:L$|
>3h
rqA&
c-$B
aL x
z9v_
dYb?6
#X^'
, xr
f
ee3!?
vO8
kz%3d
/k3
.;Xh
2ap>T
F*K>
!*2v
pD$b
F Q %n
b>oh
v@Ya
e_KO
ajO_w
7 `$
K[gx
u fj
Lu4eJ
,Y}bq
e3XP
QR)T9
';z,B
_YBH
1BSL
T<<Y
v5en
s }$
Ezox
>Sw
L~N+
zx?^v
SZDq
SR>M
+jPu
q;Kj
+'s?
a^5{
+T;r
kPOAa
mfVjo\_
_5<-
!vkN
1N*u
b!&Y
]/+H
F6Ws
{B??
SZD
^U;[9
rq `
qX`~|
[uH
j^z.5
h.v*v
+n*#
C[M!
VWZe
zH'c
L3!}}z
+1:`
7.?Q
b^7
"@\4
9j\1
]<06
fX p
lM[.4
11T6
(u \
xu7u
{?^ WRhV
f3I&
'(;,
Fmup
{/ga
Zzp=
Qs
+Q*8
-Kax
K:,!r
za(|
afuiS_
Rp{k
laqE
6^!@
\'H
>BT%
l<N
S:\:
?clg
[]#IX
F.$~
by/E
QuNNXH
a2'5
M3~|
u"*C
v`>%s
Sx5i
zw3B
!p%'
\Jt2A*
|[4``
P ~2
Ff |DsX
TU03l
;S@V
M0giX
ShB5
N'JA
6l2Ll
.WN)
H NfN=NmN.NJNtN#NWNlN
, A)
MWxQ
|e+Hk
=4f9
^i>7I
WQ ((
=W]G
|mM`
L}1c
8zf
#GUID
zxr*
sX ]J
k)Qt
V-P&
|`{V
3d
SSqe
^453
PH{
us e
T#pg*
=TtgE
-Bm3
LRF{
x3YH
+L;E
ae/*
_C!%C
'9 V
)c
J~v x
Rw!E
q :
;= '
e:@S
*Ys=
*G</
2A3e!
\/~
f^7i
\5#q
_7 xT @Zt/
8^8<k
^x o
dWrw
sUI8
XIt;l[
mGa'
!$L
Knum3F-Z
0W%V
N^y<:
#ERA
l TmI&~
%VomE>
]/ |
4,uuNgb
( aC
.5Fa
<`Y#
3:tB+ 4
-u(J
i~6v2s
Cc7p
D 9/
U_>+1&PRu
]j.P
d8L$y
GBp'
.^#{
67HD
=qVn
!{}k
ESs^l
{"m#1
TM?H?
0!A6 c
PA8)
HM%5[
lL~Y2V
9#^"
{dwi
;) |''6
S1`s
Z D\
ZO:T
9y+|9
R8Gv
D2 4
B,:Q]Z
=jC;
Q7Nt
.^v]
Q7xIl 8y
tEk/,N
X? 3]
!WjaC
;"=G
u**K
?P`c
/mC@
-GMu
7$ quX;
y. Q
X}M33
>z P~
Y|gY
Q!~q
UIt86
SaTN
g''R
>W\gG
bf
Y3r M"
>)Hs'&e
$9VNbp
}O=<Ph
c=WFl
g n)v
O7LZz
UH'n
"Ab,
0r={
5Zg,Ly
%Fv;y
ETD
Dp~I
{9(`
6R %
b#~>
kJEst@
+ E\
NJN N1NbN5N
FV0iTh%
k8e 0|
D?QVg
-m \
WQ>mCH
w&hHv1eY~pz
1Y ,?
K3Y-i
]%2^]
[w!r
%7!K(6
e)&J
x5SoMRBaMLdZC07ZEMw
#k>z
C:$)F
_KjQlY
eV]I
cf/_
''DM
Uc#A
Y+
La
(3M[
cnaNs
f-eD
p?Mn
IAbuz
x6"5?
1_7R
(< q
q[7;
7=<k
]L+0\!
YTWm
x&/8qaM
gIzS
KJ$+7
,U@"
ydHs
0I*$
Zy(>
n.Y<
{&a$U
JJuFEy
Zc61
;^c0"Sn
Qw{R3I
9K46
I<`
!aSE8
z][z
s?``
cT(j7S
,WXWM
M{Q
Dj/*
=x@6/
B`o%
@ ah!
*<HT"
<w'=>
RiB}<M
KkTz
Y&1x%&
]U!`A
V+wg*45
Bet=B
7_1u
0 =
RNq!
@]5Y
F?9S
[f?y
,x_1
kz0q
UA[i"
Yr(v
rNf
rq`E
ZT/
HWr&K+
@S|N
N+|>
v +
/hNn
wI^F
\yUp
N"N(N=N#NkN
.;+|tQ
cH^#
rlLl
eB[AvH
a;+t
aQ/v
p(*Y
H*"A
6RZF-4
6houi
N,NHN
U Rh
2sKJ
V4"dQLq:D
fe)e
t\xK
@W$sHu|
Q^B%
>=,`
O;4U
xd8cm
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
/26S
4{{;
JaV|
aLkL
dbex%
d\5V
Hl)U
mUAbbh
{R [
zqp5
DQVA
9a$K
N$N!N5
G t5
T4V@p
15 ~
>2Ie6"
nr&?C! n
8mg<-v
$gpy
6Ls9
U'>>
LbUf~)
l_R/+
XnuL
Zc=h
6W4
M &}
$|x{ TQ
l UVP
PONEm
c3
VpRo
Pl'`[?
Ado 3Y
{Yp0
!>a
(> }
scU$H
&8s7
(6G_v
<7f?
&4?"
o2PCp
cDz
~,Me!
'4e
dA
5,Mx
69kk
*f3^
UHQ\
`EQmE
6$8J
j}p_Q
3#|;
PHW \
)|>H
- ^&l
|Kz<
S@#
_$GX
qq#X
pX:v
,LB.0
@NH :5
]!\Ly|
rCIr{~
q0a(H
cPK ^
5e"9b
\f[A
5lbI6
T(KY
qOf7u$|G
JCD=
r&X;
i* o9
+ gf
{} ,
QoZ@
0]NO
vN6Z
}Hf`
p8%%
) 0"<
j_Qw
#!dV%{
[rSP
j"?>
7bH.
i|6S
zV2nZ
s%N*
#HQqe3s
#o g\m4
A|VA x
lTP1,-
dFW9
xh~9
NbQP} N
^i.+
^C"1
"w]
N rP
#jn
n{H+^+Ba{!
m `Y
KIb\
PSr]wh
yR/P
9+S2
bXz
NHNjNANAN
a*RA
q^K=q
rE2G
A6?My
PNG
EIIIe
(/))
P&f1x
f]p5h
$h{
AYOT.
pW&`
vxIocn,0G
JP]U
vy 4
/s2k
OQj_2
3.2Jm7[
O; d
oG'm| 3
h`jS0F
GU&qs
`QU
Ao)8y
T }
Y?:?
UTc_
&[*q
Jb%'U
Mcmf#
={ %U
gL'7
.QC"
;c\\2
@fw_
@_Y]
a}yt
Wmf4kk
Q+p5
OqaH\
H,"
tYZd
&+4j`
|vc Z
WI0dV
5<3.
&!`j
%&Bp
eC'UV
r) U4
z%y'
8=.4a
K#eB
nl7:
Up5y
rM $k
YHt9.p
7>8
MS.n
hO$z
NN}H
v39z
+)*p
7E&d\=CI
+Hr7
Bq|9
Lvd4
>:IU
4-3o
DH|M^
P5S
]-hY
/m
8OFG Q
wX6(\
vsNo)
NE,=
\Yw8$)
EU)wao
_x-+
0 *g<m
\jX=
Zbyv$
O+kI
mQX0t
?#mH
J3+
:\.n{
NhNoNmNPN
M5JS
PI"f
Juf
Zt1_
ZNo;
8K(t
?<;r
&tSr
cNtq
>)_b
[$#J
m/BEx
W9"e
g%~%k
2I<N j
g&F#cd
e;Ay
Crzp&
)_Y
le,7"m
Wy?sP2
?tJ:,^c
U"*i
[`(.
Z6o
1Vel)
_(]`
lx4'
g8K|
'i}X
<D~&
/^0Dq
);,,
BkIq
t9<+0\
q =vL
8/FeVs
(Pd
q<Nx
D$SL
t*FP
.RK
R~,@,
gh62
YF7vV
r^AKG
CkIJ
t*:`
Ma>vT
=p.|
W@XaJ
=`pV
M1!"
DK m
a'+#
NnGi:r
">Ft`
[ 0%x
X&7*
P-3}m
Marshal
5#)v
f}?+
J! kA
CpT[
/(j(
Eqxf
X-BZk
k yi|~Ng
yn S
lv:i
[}r5*
\EZX
C!U.
wji
q)1
:F{|
[$alK
vQZ9
1Xh+
ecT\W
!n!k`P
6x p
# Ryy]<
qpve
+8b5
MzfUh
0|m>
xN&z
kN)#
O]@3
(u
P?M!:A3
D ~gY
oe[N
[(x$wZx
jMhzl
(*F
7=R$
u[aY
-[8[
fmgY
_UeE
8d_
laO
.+!&D
}56|c
ZcUW
^_;>
Oj,
E/3x6ZYa
N>a?
PWiz%%
{2"*
s%rk>Y*v
3io
2Y,`}nW8k
K$5'*`
]\H%J
N>NwN.N!N
q$oEj
:y
<l{}
Ct5F
\TeS4
J$!o
j }
V E^M
B@j`
h.vS
%o\2
H&^&
RZ-o
#qWjX
Ia5%AC
&?km:0
<>)7
B3SJV
|: ;
. L b
_WR?
=2Mj
v!,Nv
X]'.
dMw8F # f
9] .
LD>?
j6T
$:VE
'7:$)}
gM.g
Q0%S
6Aob
3s'9
sc\h
)r_]
$[|jf
&P%
AssemblyCompanyAttribute
A%)P
PP<4m
]' Z
E hk
p6.gR
67}^`
BNLh
G/@Gs
C;94
"Hlu
GTW;
wt_W
;on4d
/8AHL2
6e*tB
TkXN
j[Tk
QxFW
OTHDGv
vlnj
}jgV0 !
;ZvE
)Z\
NQNJNKNNN/NjNmNkN`NJN*N]N
A cpSg
sG&e
_$-L6
c-iX
(4,SI
UDXP
s?EDFK[
:T$ :
fK,b
HQk?8-
|X>Ox
=V2A
y M3V
HrI>
Bc_b(
=Nz"
NVQV
/lMq
9K |
IJ%ZF
\[Px
kGut
fX ^
7HF M
+cK
/ >%,
{;qL;c
+
'D w
YH<I
1 <4
3f^g)oa
{I:$
-^i9$5
x*Hw
t e_
'l2`
mVV
AAS&
Tk B
]4Hx
7)Xv!
;b`t
~FgX
ldnH
"H-V
1d^
#(F'
9brR
r&l|3
^cRr>
b)+/C
E2m
s'3#
y1"i
Vbm&>
ldnW
>+#
D:J:H/6
Sdd\
?jEB
kNpFfp
4o%[
p#K~
>)E=
{P
_isIY
4jC@4
@g6<DE
nd ~W
&CoBQpdA
=6;rg
$(_e
0^!<
LJte
& 95
O.=<@
|g[|
jd
N h3
&Nq6^
\uPx
:Q&2
#Q,n
b@A7
w;OP
. 3q
fHIl
|W#8F
jAkh Bas
|a'{(
TkBO
HwpK
8j`[
.e }
~K 7
`J^92
%tVl
I4;X
ow'
^'H9
EeJS
57?=;
Kw[
4s!a
<5>z
]PC[E
%_{
&J)
_z!3G6
-#'q?I2
D=c0u
Ybc_
~V*Z
rPQz?}S
}96a
!_+ =
@^pC.
E|qpFd
L"@Ay
\@p"H
E(Z>|H
YA~F
uPq]<4
;bya
<MG32#&
UTE
eCdM
Kns*=*
U'-A
5?P>v
u2iFS
D.NZNXN NgN-N3N
2B963 y
>P(U
NbQj
@0Q
#<(9
* pYK
ROh0
ye6n
d@q
PK6z
V ;
{|*f
:y,y
Nk=@)+
LKb
OB8<
AZb4y
I0Pe
U gix
sUj)
|?CL
WpM+
0? o
fl&*
=X1BH
Type
v$S5}
+g'w9G.
1H=+
#^`WNv
zktQ
6;x8
0#rl
LMa@6?
w^M_
M-"q:
{W_K
,`t?
N7N NUN
lqs
~ hS
& ;H\I
hf%C
YPec
&M0
9 {
s#D
, hl
?Oz3d
B-+<
B 6\
6?g
&$?~D:~
nsu*/\*
?c I
{#m]q
}MI m
^360*_
B#np_A
QX|J
I.6l$
Q) *w
#|7@
>_<`
^tWM
$[I`
* 8]
Rl.G
A{rl
v$ Pr
}MQ q
:LB@
)b=
R<*B4
62ATjuAhqHMRTC
ny]Z
#z;Y
md(B
t*1oQ OJGc
Q8F;Z
(Gg<
;CaV
.XRJn*
s] k
8M5uA
1en6
U=<+
/>Lw_
BbmD
^8ur
PIGV
)l<>|
8L:z,
Oi
DMT/r
SuX:
IgM#\
)~ {H
K i\
_VK
~ c=
h v6
H 2{
F7F8Z
Ez-Xw
hMP3
ciFM
I,U#
dRrx
NH9G
J-xd'O
Qmny
N@NPN6N+N.N
[]Lh0
Za 3
!3qH
"b!d
w(O'r
g8^3
%pUh
_28dPME
=pd&`
(0Dh
~`r^
{kG(
)@ #Z
U.Q)
2~W7`|(
i um{
oA"i
(^A[fqu
bc @
uwyD
wi!U
$X!gp
Rr>2
LiT B
|E6
V A+
(cW$
NzNZNCNNN
LBYh]a
tIhK9
<zWJ
"pvB
3h2>
zi)+
zqCC
? 0A
Z=t"
R P:
-~T"MU
2 cc
iJnN!=
6/0P
3@^=Gr~
@?DB
|t {
D #I
>c:Ew
N$2}!Oi
5?|v0
>n{$
JWoq
dt80T
pl9l
^fj%
@b)ocU
M+;rb
USj >
k QSf
[Tdxn
hnrW
y|}{W
8L9}
}k,+
-2).
sLepA|
3nDe
|K3LAQ
aP`;z
xfN8
(]s=
5_[C
l)=3
JtwG
NGN&N NSN
"2&@t
Vh {
rc+Fm
57lc0
e0/x
fu J/
U'z`
??SU
&g#%%K
5,K:
q `S|
>XR\cmn]
A+R`k
z"f4
:C#Cdt
Hh<:
=Un
SkGz]
3Zt=
k0wbn
=[w!
fq*N
l{G8zJd
}1sUa
jz6K
JO 7e'
P)lr\
m!Z6
v1rR
Z2 )N6
^}:d
GxRt
5 V[
||Ob
`uX><E
{Hf
b6Y'
on?_
qk`S
[ bg
l=|%
z?2&
)T9{
0"8k
`-4Z
TRD+z
O6{k
%Nw[t.
eMxNU
D;g-
SkipVerification
_Yar
ze5
!7Xw
[nJ&Ug
*W5(B
5c5
=Bt<
1)QV.t
L5iEX
^HI+
18I[
e2R9
qv*
F;Lb
{V k
;VxVJE
i37ZidVK8ozOHrU8UVS
r7c
{ml+P*
`Iw!F
yaJ5
V| Z
m y /A+
;wr5
696%
M7|u
sO-#A
Mn %
kDgVV
$[,
/{j@V
NiN0NNN@N!N[N
xoh)
rUac
%9~6
I1<
,$j3
R9kF
%0&Q_
VG<9Uso
9GDu
<kAb
[+}H
xf(
Uwwq
Gf'O.
kK/-
Gd4 U
@rhB
9#v
{-&Nr
=L+j
#\w
o590
$D)$H
)C^k
Z^DH7
lplVX
$|lG
ChG=d
wKBO
&dPU8
U)=7
DTUF
FpIa4Nv
:*L1
+l1e
L!YY
.Jl`
a* k.
X'"j
reb[*
m?K
LCM70
5 ?T;
k1|]+IV
9>7{
CM:
\9su
} Z?
Img9
.7n|
(Zt
YzCBYB%G
X+\W%
=.<\
"S}b
r\ y
at<jVd
DU@^p[{
JT 1
k\ +IoW
-"yW9_
(Dza
_` $
]((o
!lV
+$In
Xiq%
og:S@
-)oD{
JIUn
zox<9
PtUR
>Z,VL
a8G(
foe0
C"@ru
%PD{
xKyR
g]/ 9
p=t5
l{'u
&4&s
jM7"
%{}j
Q3Ex
2[Ia
2gvZ
zB ,
,v S
)h{u
\2cO
jX pE/
nx l
AY?i
K<\<-
|?6
kcgF[>
}MzD+
U]GF
*6IGS
a\rR>HH
&Xh;
m 1Z
^Zz-qU~
X0vf
wHoID
%36q
,=mB
mCox
&*):X
tWw
00pl
tYA{[b
! #
MB4p
u!Z1
V@*!
Ic.4
^[v[-
h]o5"1
|M.0
a|Ee
4(ip
eNR-S
n;[1
izWW
&kH
A@V
THj;:
nbK(
c1)Q
u")M9
DAloT
X1`|G
"`W5*
+qy
i$Q*
?+Jt
5 V
/;oO
:&RP
]:&6{]
%5m9
#e sT
Jj2 @
`WLn
++\g'a2JA
(9N0
e:Y"
6_*=
5=,
QkH\
@ndW
-;`"
eP`)u}X
g}I+
K p~
C&N
RrP1
|NS.+
Y"tz%|u
#o|a%
kJA
|:L?1&;'
]v=Y
:|c@$c
?KPc
}9<t
%`Q
epMH
&)$Hy
!!*(
ZB4p
e`gee:
C SP
keb:0
~a_)
OCa$
<;Kz
Nb6D
yfeSj2
L|/B
m#hE
:IC+
/<E7
25Rd
_1i\)|
2y:{<
Jk1|
LC"b%
8qY#,
_bm]
<]s,A
]Z2R[
7.s(
9m7v
nf)o+
-A"K
@PL)B
1js-2 x
=*<)F
<1Vng
N wg
wneuO
:Z:,7
)R=N8
Lj:r/
{`1o
Y=7U
T\$'
aZ} T
&3a//
V;6!
K Z`
OA~^
_? L@9
+h0T-
mZHa
dQE""
`~w~
B$}Uv
IDATov
\8K@
kgz_
nf!c
ti|*
wFp~p/
)>)
<g zL
V{%"
&R9@
^ 8FG
B* #z
4 #B
"K">
JtdgGJjOs8
,B )
~cwSbY
Gj#
{iJ^
f inF
J*/9
/kjsw\M
G.lc
q'Em
5)b;W
W-Vj
[8 2
+ n3
uq=
{l@/
+ FM
+d,Ua
S90%
2D}V
4>4-J
zZ?(dx
I[~/d ~
,b9c.-J/
Sr})
Oz5!
-c:F
24/:
RDD9
CW{"
xSTm
;VT
D:>+"[3
U;cx|%
Vncz
&CIQT
Nh4\
+ji
A- GS_Q
\M#P
D@0j
kGU>
{^_&
Q}W g
z4 @
YEX
C^U0
iZX
s?d 1
j-@b=
m|+.
tpUk+
ydjVk
=#`Q"
L- }
:"6{T8
ARDL
^2xj
~3*Y
$t BC
9-K8.
NuN`NSNrN
:v}c
G9XoM
;B r
Y#$+
$8u$E
|E*
iEfo
a4 w
WnG_Zf0
Ba[$|!
d80&
[{$
T VZ
< ~`Ei
W9m2e
[A R(
&gG0C
)^%FB
/p"*
vW$&
dBAq
=UNR
j'4Bn
qS.W
V 2V
ll5>
\yP^
J_Y
2x'(
.d%AC
%iAZ
ynS7
B=P&
:l ^ 5pUj3V,Y
Rq4nRhI
.D v
NBNjNYNjN7N!NGN
<Oyr
kS_&Xv
T
1DOk
b/8_
Q PF
|?4
[-hg
To /
B4ZpC
Z.F<T
oAOy
8xXA
cve-
C0(H
G xa _
/)`} <n
%YKw
fJL
\2Wa%
XF\3s)
[W*`
ve8=S|
d?"X
Pt-u
5{a0
_T'$
bP']
(uC?
NAN|NlN
1S6L
Owre
sB2oL
cve2
;]dD
Jr8R
fg-T
h@3G
T\J/
bc3Y
\BEz
hE*ZO
HcQv)
bon9J
')y3
x56L9
>cJM-
W@>Td
*^?,
9,O|iTK
a~^Q#
DYi?
VtqB
4BH*n
e%*'y?r
0 6_W/nQ
@pty
KZH)
8?2f
8cr5
`ret
5G $f4
=]Mn"
tj0<
}{)E
a :NQk
\CI5
--,5%T
wB"Y
+(u
2Vc5K
D Tn[Z
>wV4-S
+V A
=Ne@$
2fV7
l8$V
dpFvyUp5
as r
6Np?
tSD#
Lct
x):\
:(p9
[XQg\
V}A_
`gu
&E]Zb
X;L
>V4}w
iTb7R
]=][
^ L9
,,w4
.\^*
&C>8
Evg\
5$n_ %
_sM(
QaA#
L6;g
^&ib
eW $
FO<
17F3+
OxxZ
`6@sV
Q{wk
%6JI
D 8=
-WB!r
ZM. ^oKQ
e\!8
jI]:
+:j,
Vn=
==e
FnL7
=O s
#Strings
M nH
fTYcB
Xb},H
5%H
4_v#;
RA (
gu,Q
3Tsk<
(?n.s
Yh 0
'Zx:
NkhV5d
`TE\
\7N)
zh^bK3
It2fb
?>Kk
D w"
lqy
t 5d
941l(
_!VC*
l:3z
,S\[q
B &i
rW5n
aJ*~
:/EA
[Fya-'jN
:U<m
mbz |w
-@2a
d> a
M&5+&O
J60
ilA^
FaV0
S7nz6
)aMB
ie_P
sy#P
XCBr
!p ,=
%RN_z
/ P
qCv3
]-Op
21E|
v)^69
nIz]%
_^8o^
{\;8
qC+g
a07/k<A
uS&K
ZH@
/ql6
F5 pD
d1n n
jOoN
P*kT
KS<{
|*?i
PZFox
FoJ7
x1XM ^-%I&
)2n
ev.J
jP^p
9%{d7
|Q%W
("hx
x .eP
xL^B
l\kRe
1>>=
V,af
mI9Q
cSNr
^V (
/,a
P~L1C|
~N'Q;
#fxG2
qz $G
y[>w
Kt6<
1F.R
=h_VfPu'
m{W*]
;'r<
U_#(
GetType
/2^+
;|a{
Z}tm
P v<
Q?.k
C;~vc.
\.{O
B0|`
&!,=4
$"TF
GJqz
Bv5P
Z4sLA
H'WG
Xkg
'.;R
YC&>
(>UP
?JNo
$2)6
e>CAs
y[aQ
%aqd
],Vce:
f_|yP
WRdMZx
k*Ee
'*?~2x
Y]<@3
yeLc
p<ku;
x\$a}#
; bK&p
k%Wo
F8n
'!<~2=t
t~;M
6r2]
:+r-
B~|YD_[}RV
| c;
28 0
Ck Y
e6Fk
+)vE
k.{
S3H?
#g?S2O]
!:S<
9 "r(
7OXcD
5-}6
Hz N g
p*=Te 4
f&CH
4Nmq;.
S~|E
1H z
@ ~e
rg~}
0"pK
Mr|_a?
(t_bn& R
s"Kh
DWH
)[.h
MJDJ
md<s
^;rg3
fk.
{ $-t
'}qq
@eKe
f-:a
$^<vI
Ej6Ah^:t
vx,C=
cRTs
tt,^_Hw
VW3y
>KPB
8 k ;
2s0u#
*wL^
PF
R4a\)_^
' :`
ojI)~,
!-w9
*ub&
/";
lqG`
-gn^
Pm{mO
;1eX
gX8M
W`.8]Dr
I nr
N<P
-DOB
"C0Tv}
-^F^
[h!$
YJM1
!NIx2
{7wi
+ cA
E"qp
hv$P-
zX0;|
SIZ6
'Fq3n
J.]o
@u6r
LpFd
C XZ
*7*pX
N(FG
u!LeC
lc-X
T,g
hxUAU
1$[
K/"z=
lBS6z
W_z^b
m`D
C'zxV)
O2A6
"qFs)4
>"Mc
GV(8#
ZGZ]4
tmc8
>6F|&
f PB
)-5$
o &r
x&(p
i_(bM
_1.l
S1JD
X _LF
VJMC
|[qXu
$.G
vrii\
cTu}t
iL3G
"v#?
?\ A/
%~a7
4mFb
z!1
Ck r
OS>
%|6ES5
4=Tq
)1"a
(w6K;J
^~8
p@dA
eu9X
=jW
\Z:--
1h^F
.URSc
8%=#
Nzx^J
X{Zc
QWsJc
~/&j
8\`V
!vq+a
ymAA
;uz
Gu;~
$%Y)d
{t-p
xPr:
Q- zc
Sl*
yK,Q
]d}Gp'
o/3H
5 bw5
H:Z>-
r\ST
.#g2#
L1BJ
mNGk
/9hr
"Eb[
wX8>C
UfFc
` s"
M!7/
__/)
m4?0
C@9j
LNp'
nV&T
n|hB
wyHCtD
"cW^
!G`t
k`d@
o{a[
Xzt{
ORFi
gd :
zUQ]
"RCE
ZF
>D}G-
^i#D
>Zh|
Xr;Yj_c
>E}f
wUW
x|AVB
p)W
.y*s]
#M:<JfB
ZzrcV
m3S5
+lHC
QQ[ |[
!<l;
y@E n
,w Le
!yv]
y3?R
n<]bL{j
OiTz
6KV#`
^99
V~{.5
tOW |
fKn5
;$IC1p`~{>
%r0O
Y qvlU
H0O`
]cU
BF %/$
g| 1
;^5n6
drBF
#@_$
Z$O3VT__U/
h7IDG
Q""g
nPzI
\g!~
T-*+F:
R ZT
3ivl
UM<u
:m?z
= M"<
lT'$y
h2K^k
0 Z'u
YY]~
pu+Ti
L, NH
_j?eU
%ZVv
|;Bc
},WsM
^ U
^')s
Yh?_'M-
ti9=C
B0kEQ?
Z<$a
/DSDR
krs% #
Fah
>/8j
51u
Sl%
u%n;
sok_
-COP
[ |no
iVKyV
WUTC
7*s{1
izUA
aw>v3bn
ym Vv{fZ)
JbnDP
=#5]@
|&Vi
vP4l
-x^"
kE93
xwc}
-KEI
p ,#
x y,
LQz#%
O_Ntz
%!}D]
goAt
s>DN
k &;
(^v
Mj"JU
2@;_
;;Hn
N~[Xk
GAdYzpA3M4xexjXqRv
\0K
(h^}
s!C5S}
73K,
&/fb
D4=Zm6
rDdK
!N8zj
01t_(k
Gt*Qf
3|D;
2fS
Xyp,
Go/'J
%C~i
iux6
/rM
y4a!7`(
U@N
O`Q,y6
~[F!%
fPJ,s
joI:
N*x
'~GU
I (A
1vK?+
qS@'
5/ 7
4]2f
y/2b
h*=8
rG M`
2Y4K
l+o(M
."hvYiKR
"z)W
7O83
H&x@
7@3:
HNeLI
RMG>v
$S7eUW
VN&2
C=W1D
;GL<
lO#[RkX
>bhP
q2%c
8&o|
i8d
>0?X
5(XyaOM
%oBK!0B
p3/_f
4b*_{!
qZ1r
)B 8
>;$z
@LAg
lL%~
=#>L
1y{Z
x!.N
TI 6S
w%+R
K7B8i&0
04U+
e\=!x
Hx1,
6aD>
F};x
<f5k<
60Y(
r~CW
z%*~
E& " %
5TrZ_x
u,]9vz
wt#[v
gYNu
g*bI
VIiFaCkXFCSPswYRx
8|gEK
.CA9
>Q P
#]P. $
$Zj/
$8c!
[ F/
mzMCx
"9$Z
]-d x
<DbV
.)v6A
Av.H[
I 4C*u
|k27#
7y8d/
RlUb
$H%&
D nKm
AS8 "
w w1
R>vw5R
7z=0
[vcS
N(o'(
2JWU
Q)3j
uo)7
4VF6
!I.j
&.Uq
e"}8
B=i d
n7=s
_[1G
X8;b
|G$^
d0b<j\
}mej
;g Y
%*"Nm
7$(2
tC!L
O&o}j
kr^D
7*dqk
yq#F
\V1&
U0d55q5xefKZ
>a7=
d?gio+P
{ND"
-u6i^G
6SOh
:1=D1
r }A
2vPF
k{$+Q"L
V{;
P\{,
p%e|
0;km
k&9
GO2)
3xZ/&
8SuU
3Zab
(U0h5/
<kfV
rAPJ0l
Sl ;
Z^PN
. Ogg0
`yRuS
Ewb7
qss(%
nMXkkQj}
WA N|~:
NMPL
;!_{
uw9yJ}o/
N7$p_
<VZ
q8<cA
`**!
-Max
?P"P
{w #
T_@tV
Z6>s
F}&f>G
5/]
<IP!=
RIUMl
d1 T
]? \$
ya,x8
EJev
h+\f
fW#K
L4mN
bYkU
ToString
d<[ ,A>WU*
0j]y2
.$0r
DvP@r
an[j
P$6l
<>%)
a'pnV
@Q'"
y!I!
-%E
N&]
(=(V
_!(y
.{:U
[n}X{t
8 fg
+ lH
vQe^
h$:o3=
!I4r
IC^_
ov<3
GI<
|FWn
u rq
D5fY
ii~Ei
9r6^"q
,-#@4
^ J#
bG@,
YC`o
3w%;{
r7 <a
B)b$6
W@-+
,fC?y
GpEt
GhVh
G0a~
>:ox
B#/V
k19|
B#/P
w:o<
2]WeH
8N^PrT
o2;L
b#)
G"VG
?IqT
[Y>V
k|m)
=z$%
D4B/)a
hiX=v
c6i\i
,iOV
H];ffw
NlsH

~-^oN
A7q1
dd'
2Y ]
m;1|
NO+0
&P!(
E{`oH
_o
}=Cn
JGxeg
do9q8_uR<
lvF?
_ -x
5pG]
soD>
@^NANbNFN N
6Ip[
=4Ts^dfU
zSb0y
/) s
d80r
H' h
2%3l
<Z)5
9UJ{
~%w
f%!6
+Y"l
q ?E
X #"qn
>oUX
'+p7}
1t>aa
ew4_!
8l&\
pRg=S*3
5qbI~
?Clz
E]-@
|/L<}_
tG=n
'iPR+
)- u1
w_RF
MC/a
*J}d
+27r
=>^!
]Cx=h
TDLQ6:
yjK KY
^J[O)M
#tnD
ko -)
"s]g
f<e/R
:xQ4
M7Ui
:G$ =
@4HR
r~{_
vJB}(
m^=s/
3=Ki
Uxru
}!_
kU`
O[O_
;p:
Hnp6bh`
M5\Hx
M;_
>u4.
/56<
F7)s
{x"H
Or@;
/7Q^
h/yZ
cS#L
IDATx^
5?{ %
cn3Bm
qu(J=
[l \8
OU
=~ha
ItIa
Wz?|
>uuw
+\KQ
^"=D6
jG:3
=,-H#F
7 N/N_N,NIN[N
g+aJ
6{Y+Z
S"~@
(-V5
A*i%wBe
zb-`qi=$Td
@.^v
+,5]
Wtf\
XL68
52~|
S*A)
+ ?Vf
*LQH
|BzW
,EZpcl
NaN^NtN4NUN2NmNKNtN;NqN
,cF;6
`7o*
{2oe
B/c+
%\[(
pDdg
,Y&{
=>x
.}g-
.ctor
f3U
=)sT(z
IhRj
4:dd@f
@lL|MR
{d!gY,3r
=7"X
&uh8[
*n O
v;+~
{*O^
V1rG
%a)f
l$_
zY
/Qos
']rR
C4- (l
aj>6D
}o?!B
/$;R?
mv$L|
R>!g
_*j&
PAIi!
a@cJ+
/uq9@
+@Vo
F{yT
>;C
AI;$ b
yn%3>
P7a&v
okmLi
}f>dn
]ak<
qn$
[372#
ZGgV
tONI
X(&'3
yZuq
fOK M
yema
_q|Y
Pl49
Z PQ:R
c .a
nZu0
zfFT
S5+W
j)zy
."76U
$lZIk]D
G+r/s
~7LB
+E$5
Z^M8
9TkY
i~/j
kUj
xiQJ
:lgmq/o
+J6l
*t,
Uj z=m
Y6?S+*C
O#/p\
o+`i
fl?zf
:!XQr
zW05
NwN N0NnNtN"NjNgN N&NvNcN
@zcA
DqtAf
#^l9
FqQ
>t-x
9>w6
}FJh
-M9]
? 6/
Module
QVQso
f}@q
zhtE
2^Y3
% ]"
nBE+
D`8
EB|G=
iT uKv
7M5P
Ysj^
&>f}
@P4T
)n*z
l@FX
U_sgAT
s2UP|*
9[D~
5SOEfp
zFx=
j5<X
@.reloc
eDO.ba
W*=|^Z
XW?1
X9mz
F&BH&
,6-l_!(
|Z cK
g1(BS
\~03
?eij
y*Hrc
'&5#2
!g+U
2d$_{
9's<
tWg |B
R]9D
F*BK
6'Wg
W)!G
{>BTl\
tdEsh
%[uK>~
[~5_
5I%43
Wg.H5'
=lGaW
GxA %D
x?OE
0>P4
$q X3
HXyk
h}lK&
y8X`
W+yL
GY/h
eWh3
uz]@
`.`@<
!o+}
a}mo
;1<'
CPm+c
F[#7
EI&EP
jXc\W
B#g|
u+5^
,A_8f
m_Q)
?D)%
+>6
_<gb
System.Diagnostics
x<;P
nyI6;QH
f1&{
Z cx
^j2W
F[M
I 4n
;AGC
hi[W
Bt O
Zj6HV
@F*YAx%
wJ>W
{K1R
Eo'g
D/1%O
wmq1
Ev?,iR
"wU m
`hQK
LQTp
mu)/
2DYq&
L\6F
WjEYi
_v]P
M @L
szcN
]itq
% Nkx
Po5_
*e~+x=
vp U
;ihC
:>^f
CS~}
V5=&
odr*
CLCN
4lkn(
NJ40
M$Vl OIt
oe<=
j 9dT
:;6'A
aYcq
!_r/
C`b4
V-V)
yd
|N>.`
-pZY
W=Mh
a{ eF
-&G;H'
ACQ?&
2ZJF
2M:I
U< i}
d @;
6J*%7 {
{g?<
!HpG
!j}g
), x
@imR
2 4~
,['<
*Y\(
>ak
x?M#-
{oc@&h
KP|T
o- [
pzw?
g&v1uD
\6H_
;'%
^NK:Fs
HVP
t1gC
>Za>
5JO
F;UE
-"/(
WcwHK
U{Jy
?hw;\
PAL1
[l_GV5
2mt?f
RPMK*j
}<^
S[
To=1
!zDe`
[Xr zp
nq!Y0f
T2!'
k0"Gz
}<^A7
W-m<
iq"g
d$+Q
S+K<
@};8
f@>5LT
8Pq/q
yJKf
.U /
I|C;
Q ]?
JuAT
v B)F
YXW*
n)v8
N(N#N!NgN7N;N+NXNIN5N^N~N<N6NxN6N
5 -a
m99
e9!<X
>?kY
C#|0
iFkd
tj'%
N3 <bSYu
(66Xw,c
l @.
f|%DB
&l6]
VmbPl
=GJK
db f
NA{i
Et3G
}AABe
qP:X
xC]z$E
H]|DX
TiDV
K8DW4F
["-
Z ovQj
v7!!
LwyQ
U]PRM
Z Kf
, (:
SfO
[z)a
JPWm
aZ>Z
c?;
Otu]
C!= ?3
UKazN
:pO
5.hr
3:tt
lz
{s`s{
aL3m
ar@ M
: t_y
z>C)
oNy\T
6_%E
6Tf|+
L1-Ngs
3U6^F
@9,K#
_R2$
yPz%
8V7c
mGD6(
]ezA
Y4Mv
@ y%E
[IiK5
A@R@
YwM%
(XvQ
\tF
FM>4F;
wYyl
KM|<
+ 6#
rHc~ha9
. m8
%Kxo
W~>1
GxF
00 c
HYiEl
V|m,
MmYOi
:/M
"B1jG
,iWR
/kq
9J?L
2,e};
U}qJ
|/4a3
>M ~
0"(#
Jw\9
W"[=
=Lrm
"&6S
k5HO
N^ O
3Y$Q
wW+,
~t[+
`|$*
4~bw
nAP2'
U020
nA
Pf,q2
<{}<
' %S
ki#Y
br]h
3%pY
$E/l
im~e
ijDp"
`vtZ
"?Gul
p_Se
qV[$
&A`O P
AEu
'j^-
UG>M
ad/
x&)i
,o6G
> u&
MgG9
Tu^ >
>S:F`
W&dD
(xGuR
e *D
4 3W1
Ha>CX*
-gX?
tZP6
X\S<
TcO+$
I8c-
q~0 r
]Y a
B>)-Z
38Zn
7-,1K
+pm=
np\W
M>E/
yN#pNX
'xe >
)1E_
7Q%B5
d8wSh
(IQ
#^)w7
lL'i
7%>G
Zt{m
}e'8}
Q!tX
\5c_
KB@#
'r|%
3"6N
^UQ
2_pH=
PSkEh
$S/W
6C[o7
^Ra
*Cyh6X[1
C4 k
Bp*7
DwDw
A,{x&
N9!2@
-_ $
go #3
vEkec/
q ~,
_go>
VU%?"
Ug9`
v*'{k
q]kz
._#n
N0NaN N-N)N.NfN.N
hOyP
f&wd
=-$q
_Bp?i
=+ao
9c+<
nK<d + e
T)jwQ
JQ[l"
z e"
aH0[
\)]91/l
ib6,
qv;M
*#)
O\[8t
R,y
Ty"xpu
L{T7)(JH
5C51
R"x
$bRjZ
b /}V
yYTK "<l
;-j6f_
I0 RFD
g4s1
lf^J
Show
]TWTF
?(&d
GQdV|v
(0Yz
/C5i
?:za
E9f:
C,/:
$D:4
PropertyInfo
,5$X
}D C
x-n
U$F?
0Q7W$
ttz}v2
fl`h
HP^U
,A+pU
^1-E
7cx{
o5KC5/
w!q!*_y o
,yRmHf
l&<]
NO._
-L Df
ha5q
|_<[U
%U5;
Q?mV4
n';'
CZ,c
H8yV
AwO#9y
;Cv?
9xvl/
+ Bk
JC@Z(G
RQf,?
m tV
s8lo
^;iM
9h",
?{AX
>4|*/n
NnEE
FR#t"6
u$L 7
f)"%B
\~6+h
&t\.
$vGi
'9D9
k4F5
l;vkeL
v; .L#SK
*^- h
o+>_
0?skv
@ET_$
?LTB
/U.@
0!.u
@]11
b[\
">_#N;
gAV..
%/11iQ8
26.38.7.27
<|u
mQajY{
uW[Dy
9 O.
Z7y`
;h*Gd { ?6
O^g+
_WL$
_,sKS
RMO%
55@
p>a
uvd`n
_AZs
7LGU
ea<'
$rp1J
g@~
]v|?
I<BF
m`i\n,
?t+=
d8 ~[
$,Ug
rQR8AvNf4G7bSV
t~xvr
)Z$e
_<nV#
m j`_s'
d*v_
Shxq
U]~s
ey[Gf|
*H{2
X]!!
CL=v$
\_iw
w&zY
wNAB
P13)o
NBN#N
]ufBJ
*l9J>K
})y7S
xo\>yI
@2-;
=$QpR
k~uM
'gxz
n[7\
|~2 O0
[\%
&dJ#$
S=m}
'LD [NSO=
4Smn
A#/\[C
qq[-
/s1z
)8q
NIN3N>NgN
FbwR
UD+n
"] W@
z_ +
3d}'G
~[=Y
23gP1
9nvx]R
>:ly
mGtyY
/GQ/rg
_&PX
C(GB^ s!t
f]L9
KyPI
eaW&e
mY}9
fGEZ|O
*+s=
E\L>m
'Mz&x
3!?NY3Y
lC)c=~
"d_X))t
XB-#x
irFG
|1&D6
t9\
\~ir7
O]y4R
t]D}
_sCC
B*=N5U
>Xuc
`V3R
#s=F
D16&V W
LI7mU i
V F~O
=*'>
o>&ntJ
?.s7
>-"_
e+?l
\31z
ucSB
PiBi
> =a
l"$=
@.~?fV
t9\"
t 1/
0)ZBu
;U^}*M%
|gQt
fKI(
~ffv,,
; h
%>9# f
{Lt
Ozru
yy ]
EUf/
1@m!
E1J;
i*S8
m9rA
OI2@
$m}{
s.tW
dTP
BTB]gq9 G
P >|
\bj;
7pp$i;x
X%jeI
KVW
SBY`v(\
0 M?
{B7>
v:Q/,3[Yg
yUt*^
CJv'
wh*U
"*7
y[=:
qS ll/
7 5k1
Wp/h
/o4Cg
9WzP
lGA#
,je^K)
Dq3uw
K}k
u_8)
j3II
P:B_
~ZQU]
'9E,
RFcPR
C5Fo#
FIRC
yJ0)z
\cwBI
}{Cc
A[dl+
rUZb
ugC
+38?/3s
(w93
Ug1P$
d`O>
I:3)f
02xU
p+q/
`c$
!ImP[
QlCs
q<])&
9Q#E
fpu)
h[4-
gAMA
=|Y
0wH 8H
AZmTw3
L}vXs
Mk*5hs
'!ub
GT\'
9;;%
|f!zlG
#q)
IcBu
NJDc
Pw~I
}0CoRJ
)D.w;E
D<))T
~NTX
j!: }
"=Jy)
~}]M,
Z \j
R`WJB
K+7! ^z@
Yx5o
JuGl'L
>?m
=I=H0
cVS]G
:gZ 8
sfF\$
Dj) c
kUR&
G^fM
*e<+k
.^H8n
X:}(
gT
T #:J
RG%V
zhz
:*#<C
u d
[d)R
)]{iaJ}
LT`m
T*@x
'->Z
kbhz
hicZD
[S*@
Wr9R
=NU@/
a<Ch
+rFQZz
{a!p
D!:=g*2a&
Ti)ow
0J
!q;n
!=Y@
9 e[
X(ez'W
%|C8
_k7#r
L-grM|
~MG4
w"VP
mRgT
@j+`
~Zrn
N1NGNgNhNRNFN NqNsNTN=NEN
mtLGy+
DLuD
P_+*3Y9*
%mFB!
8dx3
uPf@
WP._
kxO AS
}0DVA
NtbB
+GONP8
!nET;
<^>v
h{uH"
Ze5l
,;=1
^1un
pHH3%
5;@:
D..?WBJF
U@f?
NBt^
9 W
g; _1
(2c{
${8p
F@,pP=
A_7l
&&^oV
OJwQI
^\\6GZ%
5fZ N(5
-TRK
'}uL
.8'G
`gSG
NkV
&!}[
~"SK_
+[]h
n\Ir
GY):
3W`#Mx^
Z3pL
A@VG
,&<~J
P4R~
4Dqk;TI
2M.*"
LdRm7
qGKE
Kr%q
p d*
0=rr
"ko=I
2 .-
^8fv
y Oln
b4LAz
^kY)
x-K}
^]V;
Y'jaH%
+SY7Jb
/A<p
A'aG/
!`&[{
wiA2g
w?E%
mFj
ncxI
K_TF
I>pz p
yjC=E
{ w(A$p
P9{
'Z:/
]b&~
z(\"!
))=MU
G\YfoJg
#' #L
G.pIRF
*DG[>
l`=$
I;|3
@Dbh
qcV_
[ZOg
pk4,
nk%{
\H|
K`vS
/b=w
%n>fdrT
/6seT
5liuINg
*U!0
v]fi
qxsP=
y{ mo
J,<'q
e{p`
Onv W
saYU
,KLL
Ho-X
Xk\=
gD1k$
pL&><
9 0yM
F U
46Vq
a&h\
H(yqK
O:}}
RbK
}S!{jw5
iV& v
V-P
>Y\A
xO.:
~204i=
U :H2NL
}* wk
>"^[!
AUsas
dOXu
!U'P
%t{^
uP>X
#"c Q
_@ =
iBS
80/d[
M4B[
. [bg\
jUK+*
>ox9n| 8
k@v/
/Wl_[
#^l_?(
w/%M
Ix\
(`vZ8V
|LK,
onCP"vx=
6UUO_
*8!
FS\(y8
@G&{A
(3+T
tC/0}%TG
X>=o,o
6=>P-,
1;MEX
?q7)
mdqB
^y$nH
3V1G
FkiCS
j<nCn
Y=\e
9=;2
@(H1
Vvtl
fNx^j1
RcP-
y2I,\
NKN1N
= fl`
y3?O
?$~f
~%SF
fvpibKv$
RcP:
#oQ9
g+EIL
9?Mj
~-L(
fS+%
3k9Oy
8S(pO
=j^ y
!A@wa&
l RZ
.hsV];s
i^l'd
fX4g(K
z>E]
18oF
g}
y5Xpp
d:HIL
=!=t
e0U[X;
<# O
x%h1I
\$]1
. 9V
X6rK
e-*Z
#Ma7.
k jx
V.x
jQQ1
~sgK
+Fe1
=&sb
FvF
?f*]
\A1hmS
vr|m 5#
B Oj
|Cs^`
InEs]
cfHPH0^d
+ Dh9w
;B(T&
s\ ]""
~#u/
5 id
4\Ijj
AGJKq
Gcj\
? b2
Q&&ZT ;
|3#b
t B
.o9'
jR U
r59h:
I~ l
'yK3
q1>,~}
>Go\
;K&
c O-
e>@\s
$f _
(5+QA
{V
jEmGiS
oKIn
.j9t
v:Ic
9 BG
Yo xZ
HL%'h
H Xo
mscoree.dll
ARYh
sqU&H
.jN3
6q.iG
NpNDNyN
mt
n(;:
`2OqO|
>H^g
=qSA
6b="z
2W}9.2
T<
S2fR
=6sQ
ywmM
a6Y1
l< n
nzw9v!k2j
d )o
mQ3`.Dj
Mti
y3wi
i94C
q.'z
)x,X3
. VC
Y &=
;@
Y[w
3bhCc]SW;
4/ b
xP 0
KOlj
:E-
4 \ e
Q5=h
:}n2If
u LbS
oT?@r\
0cMR
~8D.z
C|E&
L;#1
UGEC
3VAyo
0Lb;|
pha,
Y ~
j& y
h%Hn
Anh1
^hNu
N q0
C}`n
O_ju
YXi4R
YKf 0
t|cn
Miv|;
{;P
ea%(ls~U
@*F"
0`u&
y<%`U
4qFS
h0#
oWyw
1^ {
mTVw0f$
=DT:
5[86!
ZqGb
KIT%
6VY*
zW'P{
+EKr
P]l
ZMC<
D<uL
`<3D>
+< T
er4A
.L #
&~kA
_ ]
{!Nv%)`g
"T/s
=c)
X@)o
m-%,
#HT^
7Fs`
NiN2NcN
XV5K
[^N.
oSU-
}}Iy
s#'X
*f(,
Q^r,=D6
EDK1
DW O
TO}*
T7Nt
T&S>
I62
&mcf
Xd,Fk
U<kt
I)b@
:u52
v+-=
NONYN4N2N0NsN>N
S@ }G
5(,#` `
S'lc
77-%
/D)obd{Zs
r0s4{
s>Z0[j
&t=K2
24cm
H-Lq;H
=81x
R({M
$-q$ju
.G#
Vg-o
\CbuOD
b!0<
dw>
d(v^
OOvj
wQ F
xeVC|
ks$ k
1lPy
#O_&3+
v<@6
UPW
U{6*
Lw x
Gdlr
@R,+Ya
0&_9i
L z;*
@9}L&
Gr'8
89&@l7G
Hm&b
N)2:
MV/`
O3+]
zM-[
I62O
at&</
$>+*
j$x [
J4cqS
zf Cw
C]hd
9NW1
U{64
U>uy
E;Fj
8`q]
2sM^
^Eh>
{o^/
am8Z
5V&A
I9SWsm
Ko67
:3c6
_dw?
C?a|
&[U<
[x?[
5eOHO
jPg+7
ivH>
XNHG&
{":t
074<
J`P@>6
E2t2I
F/@t
W gt
% dnGK
ESjy
}::F
$8Lxg6
pH$M
ly^
BUg|t
oj$!
pd:n
Sng{
R@'Q
Gs#O}
_0e?
ASqY
,*97~{m
m)BI|K
Gmv?
%67Mn.=uC"
hO6{
H mK
^UHL
6]cC
55OYq
?+Ng
]MFsU'
rhSvzr:E.{
Jp+G8
5,=[
BW1O
vg:.
D!%V#
cKt
\L]J.n
ISP"
i_gl
67!eq"
3x5Q?
Pw0/
B_Xx
hW_gTt
/ M}a!Bl
<'fKl
~ k3]
[^XCMd
TL`b@
R:^xL9
3 @<$i
DVZ/+"B
6ek&
xoV\Q
X9ze
M'7n
7X4n-
_"NC
X/5e
;Qc3
:Wt=
_zyq~_B/
"~9q
yD l
{g9[3Ub_"iJf4
=d:g
/hd ~
r%Y)
qEhU
H3Wv
&V|
_ =~@
~XC8
D%yv
~d&Q
L[.J
CO(D'5
bQW)
^+ 5^A
4?}sh
BzLm
f&)y
2xjg
L(25d
#l 3{|
})j[DP|
NE|P
}[ U
# lv
vM:DLF
W Z}e
;U57~
>T_j
h^ q
[^u>
._IUy
vo%<L
E}x
C{1PP?
f gN
9x1PX
f_H
:aAa
:lv6
\@; D
k}CD
na(Y
-rD<
fEdZ
't%hOi
84 !
U= \=hZ:
74/`
cXGK
N^N\N/N
B`- v
;d_B*
u_0
=Yy4c45
F$>!x
a+{/)
ea7x|
I;HL
71&I
c)M&
"%Z{
oM1P
7Ol{
yOv@
)6ie
"uEsc$%a
:*!a
~X^c
Gf%`
:7oz
vlm\]
ox-{{
FSN,N[NnNiN#N)NRNuN]N%N1N,NvNnN>N
GZhR
j]kX
jF[4
_g%9
.F?VrZ(du
_`>A
I5nH
e9}
[}i"N
\'n0
/p,=
AB[e
+2+x
J'.'
jep^KLB
scU
t]2(
*3Esf
J>&Mn<q
0 ;F
wE.}
JwXpz
*Kkm
=& AOA
UZIX,Y
tw`/X
Ta9/
#LD:
PK_ D B
29i+m
, [h
On50
N!NcN
ID1oG
44BU
pp|V
Sgx%
={nS
3Nvr`a
hI%= P
Z3 VQ7
@,lL
-OR8:OR
s+@<
!Pv
aPZ
2QU\
T;3"n
[&h=
jc26~
"Ra`
Kp#HQ
nKt9buqVL5cQiTpkU0w
69(
|rqf
58"m
X4 ^l$X-
%3l~Z
UXLZf
L5sYz>
O3Dl
bh~
H"rd
tcZp
)QK,
P 8Z
3PGR,
pIPi
]+ r
C"$T
:k#*B
{AMP
ShHq
%:kx`G
WdV]
2Ml4
#W#I
QvD:^
I]u#
38f\2
HVK4
zm\%se
s74zkUV)#-
,h3^R9
kwY"
mNgw
kj.c 7
MQLT
iI|f
qJ;
8|QT
@>A
mA`p
n@@h0
3 5|
p~i>
C z:i1L|D
?3:S
{qk!$J?
04g
rg8h
hyps
<Kcv
q>{C
vqMMb
h,$9
TB>C_
K;~
p(G0
C`{~
v]?}
r*:xO
]0t:
a)Y&c
V1vI
}vtx@|l
$Nv6
|-/C
% @| N
<m[G
->ef
#VE}84-
irB]
-H87
n5QM
fj<bq
lcc
Z}_"G
">7k
?}AD
H[/"
0;`)@
FUnc
egdab
^@twxc-
qf`"
tU<m
^9gs
kNvK
4h~eS
|9FO!
Ss$20
sXWz
_DG
EOpW] I
B%81`[
E I=
cd
p*u>
-,#kO
[C M
u<G~
CzJ
NpgL
<@wq
!w:wh%
4yfZ}
!GEb
.!?~6
);zH7
N&a
rZSc
:FX#jl
Microsoft.VisualBasic
972/9E"
yL<i]r
(I2;G
5AMJ
_`Q<s9tl
[Hb/[
~V Hek
P(jZ
=zh;
NeNFN'NbNZN1N-N~N5N_N.N?NON7N\NsNHNkNuN
&tH!
jH`U
X9OPp+
mk.`
O|a_q
4U,~
^2Rln
d#sZ
ey_s
% </df
(=G?
!q9M
-OQ>O
.n"H
$c$SMC[
CP#@
Q]!RWk
v\zZ'
l-e3
$L"d
:|?+e
,0/Uw|z
> ? r=
[r;F
.s}
5 ca
mTCRH
#['l
~82%
w f?
rE-x
8<P*M
[\I%
|MYD
bQOcT
/5eb
'Z`kI
HoN
Kx6d
0FN:NVNlNlNjNgN
3hq0'+
dHJ(
V"28!|+Q
y,Z''u
(Jsy
9 @m6
@Pn
1zEh
EnG1
uw"{
o2o(
)RG^r3
!D *
yy#O7f
000U
G3rq/ )m
/u^y
wa9s
Vqp4
w{mvz(
- h
Ci;>
N6NMN?N)N
0*0p
SIkZ
"9]5
_hVu,
)rBw
MPWk
[g8G
Q,)
'RR
j>7|;
8Mu
m@4c
oX E*
_}:^=
.f'O=
Yw5p
C- +d
U)Cbt
r4U./
,{TqK
Yc#5
e'cAh
n 1g
P7 8'
_WoO
&bUi$
U!:*
feNNj3j
-7o%
jFv.M{A
v-:^
c )Nu
pcE4
Lk+
PbxP?
lMxJ
]& Ax|I
9K_^%
*q:nj
4|]\h
I>#(
G?:'
v30=
S_juD
AE[oDy
E *_`u
x"Ei
4_<MN
A""9
|W1[
lSD'ci
kCpDD
}OM/
?qNM
x>:j `
;h@.
CC$e
\KK<n
JMxU
yoH
MkgY
.>hN
$;5C
,DqO
`3ZV/y3
UxKq
a:3r
,);5
rYx<,
k#MN9
zD*[
iz&i&>
Thread
/^\/#
om_".x
bKQ
q$d2?
\8[D#
HcTe
6-(8
={CG
lfy.
X-|q
/[Q
z;AiG
G4q! ^
[`va
eSeb1>
N6NMN1N\N^N
sfLp,
E~,/xm
WQjE
2:>Q)_O>
$!`W
aMaB
S4J
~ c]@
* H
9\~L
a!.r
s \
?w`/
D^njq
N*M0
985e J
o8 pO V
Y`Un
W(VT
2dKu{
-Z>e
frt<>
K8kz
QQr'
6bcM
N`N1N9N|NgN
"dke
<ye*+
UWFP
S}18
),,Q
ze!+k
dWqHm
)%e
x8kDEV\
L2\7@&
5(<x
=Thq(
TCZL
Jf\&
@KF1
8O* 3
u$a~m
;MDW
`E|d$Mm
C?+?;6Y
N~x/e
B^Y}
PC'u
[ EcN
uU5
d4ckV
+ +"qL
C9K
T*ct
NW8=
>p="
A l
A Y
vZDG){N
"; v_
l$NL
x0NM
8;Yx
*,S5
c"/ L^Q:j
'A{RL]
7*:>V
ut/)
L=M1
%05T
xf9efso!
D{?w&
R*k>
c[j^
oew:.
'y8?
M{&Md
&s MN
OszUD
4a_
RJX82 C@
-E Y
7]9&
q 8X
o%fnl^
,hy>^
6n\n
/WuF$
Jv8wV
>@/}9
'"8 6H
2{f=U
%mray
nNNa<9
E26I
d4.s
n@ ,
~=OIH
%%3\O
a3dd
e[g`k
}4}}
u$CO.
Q @]
+RIO
wgw4
/j"-r|
ml f5
\MPs
22G"
buYL
Sj[Ia
fBM~
AG7Z
z8 l
ww w
U"hK
fy4h
rTmq
_!iPe#
\H:x
#
)Om1[
3cn>
5Cwuj
"TRo9
=%\Xt64_a]+"S
\G7)N
V \
7k86
/cK/
YQ<U
u+VS
P ]J
S(y_C3
/P~5
x+1Iy
UI5Q
/Jm>
mVTb
|S[Z
! Z
r1v[
[M6DR
>PI9
xX/`
* *F
a~`
`!"L
E5%KY
]w`PT`RN
]Xg\
Mf15
mDa8
c9g+
4=("
-dme
nc@z
5%q)
iH'/
DSJZp3
nKzr=
Ba}E
3Q}R
|yP~
zkw&e
Vy9lg
tk*k
WaPt&
}0PY3Q
|Q|gZvAg}
gims
E\m0
dwY5
2IoX
get_CurrentThread
9FJ/
qncZ
:]6(Fr
E%z{I:
YifmI>
Ivv/MD_-
v6"J
!^Sg21
tFvU
^4>C
&&9>L
d(MMv(
!o:s$
CQX+
m5 +
c(m-
ll@H
d'<
%=wm
8 Fb
\x3
I0>^I
H&Gn7
c!k~_
#R!D
r#yD
5BUU
[7"1:=
[ht'\
OCV<E
GQc0
Xd2
eu)
_!UD+`
5Kn+w
%.Y
]kjM
p#q
0xcT
Ov}/@
ckQG
1E!j
ZaMv
/%'+c0
yj4m
zI\
$y[
i*-m j
54gZ?B
b=%
]+3yR
]{ K
v4T_
oyu^s?v
_ (v[
B_Xw@
g7Ll
?S7S
' @U
Ow?p
Bxs7
3MFC
Q/N`
t;s=
624l
HK[ET
U7@W
\I40
7QVj
9TS/|
m I
?W=]L
UV 9%#
>k{]
fw> z
\ t#d
d5/b
d+Lp
3pr
P +J
XRt}=~U
rxm7
'#v
$)s8
r<UN
eA3!
'WIF
Mp^E
laRiW
DS|\p
ZCRH
bM L
4{_A
\]b
,k(&
xEs"
0tA I
NsNvN
\=6p
5PD\
i6yBh
}Ld]
Attribute
zx]s
_SL]
#mUfm
x ]h
#-V{
h#1"1
cxsw
TGB4:V
bVdm
h+J"
b'|m
wJ n
f:MQ
gT83
nZ;v
0aG]
>m/
6#=}
c vjc
_zW$
i \CU
,kg
L(Dg[
{:JZgi
~Z.a
VPz0
gaX9 C
oyf?
:Gi%
js;.
5 "`tE
G6:\
P|5T
TE#x
-0b7
[F)BuT\t7?
,N)
lVZj
3r[Bf
9//p"
^7@|
SpNN8
v8BO
7tk}
=rum?
!#G$
%_Qr`
&L
oE^-
/0l4V
:mty
s |h<
N|$i!
zJ3=MA
/EF)
SrEk
(ogf
hp/x
^M]B
hi-
4t4i
-?`uph
-PI,
dY)k
g1V3}
Mt%W
!vxB
vm&q
SyTo
t0Y4t
dral
MR4Z/Cw
1FN:NVNlNlNjNgN
e+n=
q!reSS
9mmNPQ;
r]T8
Rl_'
]l-w
gaR'
Y^+O
_`}b\
Mv,u
\PXU
be #
U=#V
uHU(<
Zeq&
U ..
yeqtmu
>rsUO
[X%
Z6U2
M?Lq
U:_N
/qwv
ew;65
{t) 4
R*+x
:]|i
"ff5
6!H-K
0%) Ano
Z<0Vo
nM!S
2#Iw
Sw Cv
2(X{6
4k`&
Nz5HeO
BzNx
je>
2AW&
1ehO
W'\|
C8]9
_bJy
TESN#Y
N{:[K{
G(("&
9+g N
SA`=
Ge{g
L 3Kc
-FBc
ew2l
E_: Ql
f=|la
R9.g
lxNm
2?|=
g)y1
gLAT
Bdd-
NoN%NXN NBN
x :`u
;k~]
xb:zt
=%R]
c?>y
%8 +
tf]2}
=DjFS
\tXy
B(v[6
;!43
#F`B
r%9k'
iKq
zyf*
cQe
? u)
QP_j
P ~m<
?ROR
RFN/=q
-digj
pr#q&
oG6.+&
5i.[
|rxT
gf>N
Xjx~
QFmDQ
wavO
g:X}
Uc1T\
xj:Y
GL)P.]*a
S/4
)^,.
A@O;
W kN-
Xs4;
XKoG
}-fB
k\EIQ
WMcM
1Pf
TYkpa7
W|~{6
855"4
g|I`y
b7 B
`#%A
A# }
Mo-%/
dq'u,
F="E~>
aIhM
J !i
,2| o
7:~I\
lB
Z*g`XdU%-
b<dl
|}XZ
:%"~
ejf@
#>gj}
!bdj
{TZ
t38F
36e"
' IR;
MvOg,
rTVU
aaw4
\1vcuE
0I<8B
jWFC?
wf?v^
7)e[
+e9z
Hh #
GUB 5
->A'
`k${
ofT
CS ;
eZzW[
3z<B
UTOT
YekZ
-AG{
eCt(
TIgn
_MGq2
EOy(
T >2;
M4{^G
dzbsO
):u?^
823}
<d~c
:2ZBm
O2Z@
qVzH
2qGWR
] lZu[I
J^NZI
c1Q~
a-g=
&'S!
/t`,@
'^8
RR4*
er!~
bvzK
}?p
zM C
XO+Q
GC0`
73Lv}.
]QQy
Wx=q=
LMke
~n=<
\ :N^F[
$DvP
y>4Z
4BO;
xY%g
|4LLJR
%7?"
:&w
+CDG
7^m
;=TC`J
>iui
/_G
wAZm
&V5e
c Mp
ow1;*_
?W4iN
c3S"
?gmmGs
2* TZ
T{ BW3'
#J 0
]CZxE
$oe\}K
sPI5lY
*%{!
= &x
|[vP
Dq5d
1*tq
G?Dv
_M_#
s?3E|
1| 5
&9#9%
QBrV
a#--H
=>$M
d.Zdk~
*Bn>,
6s/j
BHAZ
~},2
/"'AE
Heq_At
8:' ,
(G3~g++
LnOe4/
M|4/
9lZ/
A[Di*
Gy_\
w3u+
wehK
V60
EUwG
o3ux
WoWR,
?}Pm
Ol")
'^b:
|VY %u
G.=1
+o|=
Z4tV
A Z[
Tv+wjn
_! Y
P W]
<rY^
{HE#V%
djk
EV~=
k` )
i3 R
,"Bm
%xxo<
FLfaI
f- U
Y-d!
p<dh
}Hw-
#,sH
p 3F7A0
BtGt
f;Au
>O36n
"`mG
:0Y2
arDa
IDM
(&\T
1ujH
CH&.
SAk@V
N#Cx
;.'`
^cI5
!%:r
GQ%p
3Tx
+2H&
)$T\
4'R=,
>l22{
;%FK!9'
SV<p^ s
[Uf<
l%hG
Nw(X
9 m
@eUPqH
++Fl
['4QM
GNu@
} 1Z]
Zj9Q
=g'Y$
vk7l
VyEu
VMmk
VIm=,
8yGi
)w{=Hoq
Un)D
&69#
/HF+
U4` V
}%z>0
5c]C
:FPv
,xC^
K2rF
0C^0
`yMU
u!9
t)*xR6
o&VG
w-'umC-@
ZxZ~6x
~I"B
v t]
p2C;
WxS:
G[9DvO@
Tf#W
]/\]
_t:c
j.=9
Gkf^T
eB'1L~
iK}8
u07;LE
a7AYpO{
m/.f
mmNa
I7E l
| $u
TS %A1n
ifP *
f%t">
9-YW5i
~Rr$
aKiK%3
U=B&
]`
UcM
Y7 p
?D$ .yRA
u:v@$)
1#x(
N|N_N
l/5<M
[3<W
XzYG
nRbxi
unY
g4ZO
/k0B
K Yaw
ybBK
\AcY
tpgj
_8Xi
*[M[z .|
V \!
c Ta
ViN'
rzd+
oOg;\
UDz!9R
2n4l`m
:uj5]
g;^5Zp
qf<?2A
m9."
O?K(
,NY|!T
]IhH
b$0{K
xP+V|E
GetHINSTANCE
a{j@
A%"T}M.
W^ p
N*ON
w I
AR<C
os"
u!->X
JWtd
Xea]&
LvW C
0uBr
STSJ
a[`o
.BFj
\Ctb
dHp&
U N~
C:5y
F},]
OiQL
/ Io
'h`}
yx_J
8hh?
6$D*8
W '\
\k0L
uvk~
jT_,
%\|'
Fp\Ln
] 3F+
kuE@
8pW
PDN#
:S}N
KnGi
[{3
SO|rd
XTko
< f_V
}08Z
-{N0
NM*~
5(U
,I=*
]^~7
<3eRxO=
.x0P
LD5tO
O2yD
uaNu
+$C"
6Ma3
%$b9
F`b-
#<e{^Zz
7 %
&f /
*}W1
<F_$
VT)9
6-*+B
p|1N
_ud6#
B'0<
,uu5
g`q>=
yH<ko
b=fkCr
k_2
<^Hn
C6i
u --_
rv^0
'J)Y-O
&v !-<
,"0~
8;|HF
![d9
c:_e
0A+?
IPv\
>"*<
/2Q_
{ Q
:?JL
tdPH
SMs
U LQ
JgP^
's.bW;gf
CZt L
+.RA W
l6{0
_@d%
bn
(zL @7
g@h]
d-2]
0Y2J
C&AC0
IA$8
Oc,
%!AC
y. J
wpTL
"a|rU
qA+=w
h0`AKS
PxxB
K-Y_
&G5k
3WI?
z}C
39w(V
Kheq }3
:i_Z_
@r%
r&9'
lr0V~
A= 3(
EvZH
mRxA
,CyM
\J6&
fs>m-
2EM?
\d}+
3/EM
N7N NUN;
{Am +0
LD".
;1tJ
4 7hq
MHE%]
hKn0R
htO7
S})8
N_N&N
hz ,
mz4d
1X#^7
`rNW
z`-g`a3
~+`9
Vkz8
={CoQ
;:d^hp&
vR.:
V]+%SQ
^{ph
"] ;
%T$q
'ItXZ
4{T]s
JyJ4
\;27
1'dQ
3E[x
0_!2
]Vj,
a)*`'
9 Zq
\c=U
[I~<
YG6pL
r!qe
#lPF
aHcC
$te/BK
+by>
ZG[Y
h_fZ
WvAd
8j#le
0hEi
cF-Wjk
*V.
ZD&:Z-
`6GQ7
Ypr|
uy4j^
"OWu
?+D`
e3`Q
25e(Y
<bZH?
<Mb!
FOS}
SBd{
s{2z
j 0VGE
~+Us
tnj6
_/5
>>I%w
nPzt>^
mw1,
Rb|esL
BM`;Cx!
Jm"ZJ
pv&7
NcN6N
`d3tAZ
oGrU
&fZ{H
z6Cr
CpTMg '
ZY!
`7 ra+
4jyj
/PJ[~
-18j
Yb:ST
11(L
A8hl
5-o
pU?2
C ^\l
G]?Gm
Owtkw
cTW
J[Pj
r[ab
FB8"
ITuz:
b,iY
>yM1
MSuD
;#d#T
,bYx
`(:!n
^}!hER
VC'h
pFmH
,uFm
]E t
Dn <
}OyI
uiq9N
RA>Y
&x;&
h$s
=7w
d9g.&
<#BC
z!`
zx.HF6
oDp#
nCC)~
mjxoj
O#UJE
A3X@
wB1U
!bO~
G wPb
?5`
Q G;Y
oA
`A[X
(XOLw<
65B_|
cY?
u 34
AAvS
86fm!z6
5k//
dhId
.&"6lW
32K&_
,3#TS)J
lGhr
+4E?
C%w+
<9c
Cx]R
!Kw~
XZW\{
N>S<
.pBT4
]g&X)
NRGIRMn*
R:
E+N
h tAB
itL 5
c206pg
oDxo
cG2g
cx? \
81HMMISa
yD&0Y
(?fk?ia
o>_9
/%g1>%
DW(!
8u%b
>r:&RRiQiw
#>AW
\\#n
!4. Z3
q9#(e
*K4#u
P4KD)
}@ kJ2f
rm/A5
^#=d
Mjn|
:tk-
c^iJi
> @Y_j3
R^??!\%k
Qx/G
\ykOv
OSzi
p;P
:AM9
[425
pWC)
xMoV3
VE`n
T#?
aoUe7A
i #+
Wj\S
Hm$BV
Hz!T,
w`zQ:
bKJ"
D'Rj
-E,y
IDAT
o DO
M)I 7
(rc8
7rEH
Rd$<
j qU
#7Jl
deB]
;0F)c
-xXK
t[7:
i!.}
ts9
?!KB
wBFh)t
yfis
!k
vcc_H
&%/ ~
x'*W
[">
4 y!
Dy`R
IK93
0[6!D
dtnvKa4
E (>
}=!'U
\.lt
`( ^
Pq^o
|N5.
\3`ws2
P;9qw
X-govY/D4
c`4A
13qDj
>$GOA
5e#.
CUWb^J
hbXI
sW`J
X@e"
NSNRNbN
ZP,u
F)|kb
sc4Eq
2vX:
F?DZ
Cq p
;|ebr
Wr W
0!=_@
1M7sCE
\#J)
$tkO
kLqe
jJxc
=]2Yue
UN27
[*P
]*qF^
"X9#
{~_o
Futw
$mk-_
G^Xv
,u9E5
'%&W`m
]"hH
EPR)0
/ibT
7D7D
_, d
Nd{7
1pS
?,W*
Td>K;
kY+M/
fLCjA
S;Ysc
(zZSIoYqa0KsVxGziqU9dxSXLS5O2mInBVpo0VuR8
Q2_,a
cs Z
G)%y
E=,;
3v);
Ii-S
*SkGN
Q{x!
dNs,
C|d-
Bq]<e
frZJ
F#tw#
t#:p
doTw
c@nVX
XQD|Q
6eFsNj
^oSI
Z(Gq
77%{i
b$Qm
gFZP|
PDJ_}
DG-P
b'&#
cHjUx\pQ
'; z
PbV 9
bbbz
}7pF]%
4PO0
LNwr
d q0
|0DW
mU)P'
>dKx
f-t8
xl&2
N]N^N9N
*UCu
;OAx
6w1c
27/p
!}:5
hitB
x|s|
)lKhjT
(f)uX|(
3F"#
.HwJDp
sBj
j|1|
'b9W
JzXz
39S
*3#|1
g$=K
.0,e
s5-W
&Y6s
iPo`
/ S
[5ra
T4$wn
TG t8
%g@+B~KT
UCD`j83
Y E!
m3e
o#nR
@@!GV
Wip%
z_ `
`;:\m
V/(
;Zw&
f9.B
%=;Y
gtdZ
q|fT<
||OUI
hsj-
4m)#
P(?X
n(-2
j6GW
i~\r
Id>]
.Y&m
U[\.k
Q4@n
='E
{ 1R
{y .4O
*7DE
(iCg
)17!
IO_Wz
tm!r
9i!#f
AssemblyProductAttribute
|7N5
4)W3a
&Yn*V
mg$/
6/ IK
|IV
~ ~[
yS*b#$zv
>X5
,pDR=.
^){P
JU=DC
s|>L
6 WV8
@BgY
M3)c>
8I!"
kxe
*?Ll
EBT|
ZYhYh
_xo
$LH2
seeWheq
St7L
EhnG
op_o
%1/L
}OQ
ZY-f
\,&M
76X;
{IV[
6aCjy
TfW0#`
wv=E=h^@;
0"d1
N&NMNDNXNCNkNgN#N
r:eM
h6n
dER$
/"cg
<\"$
V}RVi
d K5
4g?\
j\d1
;*Nf
YT2v
#gHl
E2_
u6!(
[bb
'=C$
2^Q]
g'o+-$
BM`}VE
oN)A.
H=>>
AWQV8n
5g3L^
Cg0(
QEZ"
.P4G
?1IS
GG98
nCGUT
Z7^H
qZT?
J+Qy
={: '
'0<D6|
N7
mvf78
zy}Tv
9WcSd
U$2Ee
gK}v9
^XS]
b?D/
-+Rm
cRsQ;$
4* d
5Uth)
P#gQuU
Liqb-
G_9B
t(aI2)
>_e"
Im 4Ua
>+$A2
h[IX
8I@tl
lCnJ
4\UaN
hI=O
y ww)U=E
g)6f@
7Gla]`
l{'+
"vfV1
4q-0
z_d
LawEL
XF<I
b`2t
S `G
2a!0c
'0 *
/0l!
=W+s
`,|Z
"V{W_
sy*9
`Hz3A
p D"
8g"':
+H^(
$6:oF?
b~N3
v$bD
``LI
3sS)
jhi2xI
V 3y
ISHu-
Y>5
> oZ,1wF
G_LG
$(|iX
{.@z
Kqd@
af'
Ljg/0!
3RT
rifh
PUW)8S
rE<\5
z:JH(-@,
!8[[
<ZyT
aCQA L+
=''J
kOx,
t+V@
8c6.K
Rh{f*,
)@"vy
[KIB
k\\q
}9&k>
i va
Iu+}
oQX{
=CnN
RE1!
)mFV
1 cJ2|
i>nP
KL+X0
<d{KTXW
[5rw
Jk9 lo
(b$f+
{!~( E
LQtB
& ,;
FDL&
1SaU
]s/oX
mC+D
%JM lF
\kRH=
4r04
z68.
Cu-t
3#61
l2zy
w|6s
j("f
D\#>
sfgN
#jQI
DcF-
;qSt
PgR$,
ez0b
R]UZ
SmLZ
ib1e
x )+x
wE3/
gwY&W
pLD`
YPBPp
sk%D
'hEJ+
W+yr
9wUR+
<[WU
&gOt
xF8'-uQ
EHa0#
Yt!+
.*1S
._{w@3
hc-7j
l60'
;JA|
hS3{
F J)
Z|\'
,\F[&
6an(#
bBw'
9 C<fr
4qx+2h
&<. 7
T! i
1A+k
$vby
](bo=Z:O
iy?P
ejy[R
L-i/
<EU(
z*'^Bo
p{y.
.mmI
8wFX
75fN
io d?c
=uDO
;u'T
o\b%
ph\O
;S-dh5^
|tU)'r
Him
2y/3'
uZ!O
,hP'
Oab.P
Vb!e
<boE
~- &$N
L{ rR
|Jy=%A
1Y0H
3dZr
r}zF
?mggW
7A43
<!\]o
]+2l
#~ '=
W[t3
GU)fDk&
yv_i
,=-v
Jg-/$qQ>
ig]u
zR-NO
<2B2
J L+
y410
sS5\yF
IFM=
@nXj3z
PpPV
dM(k
{uFU
$b+t1
'?]_
j\hEk
n;C ErC
((J|
vi0d63%
0 hw #
K/^{l
20NJ
5u*Gcn
y}@"
v0gK
OXs7y
":d2
f R>
8*X6&
$ ]^4
uhVY*
gULInm
:e
fwf
6HQ~
%[B
Qcmi
W }@_
@T^O$'
14I{U
^*HZ1
}:by'
3\F
jR ,
L)q}
qOV
\U)F%
`GXyO
E]{*
Srj4
E Xj
ejl
loo
LD*':
ns]>
K0x>YM+
8 *
qy= %G-
u{"DNVJ[
#W(R
&\\"
sr{O
aLJ\!Va"
1@t?
@z3?
18uu
^79+
d O7
).: U#
nc*D
a=a
-q |
1.HlMG
TzTz7NP
;JT[l
CXwWt
{7}L
/@_k
X. 3f
E[)p
`k40?b7
/)BTAQ
CNU
;_ ~/
oTF
^0um
Ft]mv4)s)
W Pp
'l M
,#a?t
QWL&x0s
@S#o
QNem/
% RW
62yf
F!NdN
*Xp`
N^N NWN'N7N N
S MQz
',Dj~
GlSCZxxv4c7NQjgF1w
)US~
kM
DKQ{
System.Windows.Forms
F,#&
9>+7
McS`
D)`V
C$5/
UoSR
4=6pi
*o!4i
0;H ~~
Sc-;
a$@4b
F RK
Of<2"
2`$\
5XNsbG
"i&*
TZ>p
ZMYe
%=4) X
yU.;
W]1A
W>br
owm\Y
$$L!
`+Zo
d% J
`Wf/b
k 5R
5Z4
7k<b
i"x{
_[^@f0
IVmF
+O
%Ef'
GetMethod
qI%h
"O-Z}
8,VB
g{.:
pLyw
R\VO~
4}p
q5AIqw
jyNo
V"xp
Kd4CY
N{N N
pC9
xiM;7
ht*Po
-<:D
Nly h
%>C38>
}J`
`)cS
Hew
<LL9
':j5w
8mU
.3~/
VcxB
lA}W;h
+Q=:
vd5G
Yi8E
%pU@
qg%r
N N N N N3N
? r8~
J>gr
4-=(
>m 8
XR`c,k
Bgak
ZQE;
,k(}
R\u:9
@*eH
1[~D
}b?W
F<+ 81^
71?x
,+sF
$ku?8=
3dIz?
TG_ z
Y^q3
U@R#
oGpq
kS k
*c|z0
q.K1
@B@\
nx+x
N<0T8
90`G
^$mP
35eM
!N*V
.xY0
82*0
H;-*
xf3
vE6R#
+?sC
u|M;]
L_mE
9w >7E
]iu{4!l
uq4%
"I{!
g%*o
XSsD
%Az3
v6/{
2GaY
:(WGv!
ConfusedByAttribute
s>!
Kk7!
FwM`
'h1?
w8V?
0d9m:
c** 1OP;
rV*%
,NxJ
byvMG
^O-r
NFN^NPN!NKN
UEYG
Lg62
Py
$fgg
im2^
WcZuB
R`;a
/K-6
7\H|
N+Vi
;*T(
C01"^\
O%kH
"LM
la bx
gx lv
~AlJ
\_,Xq
;zApn
`|l4N
8::_
(3 "
rQYB
.$,3eP
2H#
Aktq
Q6AF
[j,:
Gz1k2
I_Z
geuf
$G&\P
ce 9
t</~
eh;9;aK
c<P|
Rm3F
0"L_N
a?C:
IYXXr
NL)?
}4d<J
$ym2
m;r|
40'F
nv\.B
5o+s
w eX_:
B*)
P:[B
Np1}
lVHi
PV|"
^=1>Q
(ra6
B%`O
Kg({
G!h5m
cNgGB
n88X
TD q
{~(m{
+E9
yyS4
lK0s
NlN N-NENbNbN
^s94
m)iN
by#8
Sqq
UU]F
*[=
,'ox
&uzp]
0(b/&
EJ{i
=U+//
p-[s
x INpf
IY-L
Vu 7
NsN?N(N"NZNxN+N
7Yiox
(DN N
m4am
w4lZ
8VHd
C#jz[SY
?5@>
4R(
fp5W
t vh
p{HS
@4KFrR!
/ eHB
`V=6[Z
D<"q
wF'X.x
UD~xC
**![k-_
K^1N+
I/%O3
98pD
`T>~
'oI|#
Rlo:Y
:e>$K
ZxBh N
B=Lc
@; W
9~zm.
?7%S
\w ^b
=+Jw
%DF{
Ch5m
-fkyK
^ t<
hi+iI
K1B#
f-rZ
2:3//
JG{n|L#
.hF]
DXb
DU /
6,>G
XiXu
({x|
/*If
C~Lx
qg9#
W5K(:lv
' >t1
8=RO
Hy8&m
System.Security
(Adf
%W#L
lo-R
1E K3
M#K
<jV9
u.PU
& 37
^1"ZF
'"ap
U(J4
t)~M
qQ>(B|[>J
JuOn
wk V
VMD(z
c$_"r
%9i(K3
%CH
:(QKZ
LA x@
!Hj
+82Tj
MSJfZ
>ql/
'moD
<aN!
rsk>d
ue-5
] p3-xYW
;>Tl
aM^9
5^ [
*8mMY8f
B2)#x
S'8i
CG{X >
:,\E
?&kz
vgSER
V*eE
#}[f
s AO
)]$Ht6F
hy S
rlM]!*
]`0l`
,Iy
1z\.
IJ;ST
vkIgT
HeX*
co N
3OL
n#$?
GY\K
P%7m&
\BR1k
n(oq
t(- p
@ZUg
I BL
6;y;lFf
CN 5J
sWIf
v--s
Y(L52
RQ\_&"
huL/t
Oa|
*]0$5
Z7mU
DY5;
{y5 L>
FT53
p?bgP
q4xK
Kxl_0
6>5yF
Y_~L
4(-:
K $a
se_Y
Vc
P:C>)
Tr-I
z6 ~r
+4f3
k@c9
YC,u;
gufFy
uTR
r'1F
C;&U/
C4 V
Ez
c>vsk$S
#@V1N
6hkp
';;N_
Dkh|
/6r^P
CFNHs
@Mr
LZjwe
tu W
Fz)7Lq
fjQ3U
rHcT
M#$@
gRg)f
yY7&
wk!]:
C: ~
z5xJ'^
ve92
'L`c
K%)l
y(wv
=~uB
e~#
Mi E
LEuF$p'&B~
*kdD
m11.
Krmw1
gv2b
=7WX
~e}#*4
if[<
JP?$
U ^Nt
3WQ'K?
]6b<[
3Qe70r
@K<zd
AA X{
)'_ }QG
sxoH
?P.x
kTb8
Qf>)
0b1VHEVYjpubkgxvjLW
ZGD9z
]<@s
Kw3P9
J| ~X
IA s~x
{W}Q
~[vo
HKEK
A]{B;2
d:0@t
>fK'
, KA#
SyAB
f"bbkB
nRi=f0
yandKhp(
:des
=/p #
ng^"2
(9 ]
rMAz
gV$l
O+9&
l$W2
`Q 7
HoArI
!Tmav
d9I"
V9z
;H-I
Pq}YC=.
&ya_
lbL*j+
W7@b
6o:.H
@z,%
CU]4
lnf=s
=H8:
o[o@#
Z%F[zB
aq,h(
)-zC3
NVN7NtN
&\<
KLKZ
Hp;/
P\Uv
x0H
H[4D
1o{T ?2
6@ /
^.\i(
?$l'x
:W}KR
uIU>X0
h}^y
MCq P
7 %)
ho'u
+h# R
h:d{
anit
e8e
#Blob
W+.rNr<
(~0b`
/Xu8B|
QyX}
i%6%J
nPa%P
Y@R3
L]BY>1
r_(3
Q%Clz
+fxY
KEuu
0hz 4z
" c_R
M oK#
Y*Ce~,
]Z*/Ny
%4A4
iwq9
N NqN
lFn;
Y&C@
aU{F
Dfp%
A x(
Ako8]U
EHh"
s,OS9
)N0,z3
rm|w
{1}J
t:+Z/
6CcN BN
Z3xs
( I:@
7;\L
kvq%Z}
h vdi
_<xe
pyuJ
@ tR
tAHE
}73/M
9 ?78P
bE,"VY
'*tR
(&#Zf
JxML
8>3
#p{7D
M5HD
p[.v#O
HEi@a
Jx a
jZ.2d.
:6C$
X*0If
P|A
5\A/
WY 1 b0
0RJg
^9g
RipH
UZ`^mP
Q d$
H# 9
spj8
5T[z
<-k+|#J
D `&
>SB<
c?ya
gOUe,
4'Vf
B,//
%C:$
AB=h(
@tG
9K|*
OHsWV
+`ag
~g&7
5oTR>
*M2a
-.!o
o ~#
[+j`
P]Q,
/J#
G>S9&u
:U(a
'Z2
1#StZ
VXR[
z{ud
p =M
\|nB
YJ2se x
? }c
%>p6
x2~)
eP'y6
@$ u
Degg
\Y+"
^w)
~/En
(% P&h
3KA'
>X29
a!$#B
$c=!?
?!TdCG
|^s=v0z
tbBb
eo[6
[0k;
GCQ/
|x`K
L<C
.:BlS
qMhcs
Z.cW
ImAa"u
T Bm
JoNzj!
f18W=ap
S@KDr
b\(r
-R;/J
iJBP
_!e>uZ
]@?#^
' MG
a=yn'P8
rYC
&n&}
_) 4y
jn2s
SZ39
dT5g
N/JIa
p Ns
oI[8
222C
`_ks
=BfS
=IX5A
yc6:k
n:71
w D
S<$l}+
@{n+SQ
F L_D
Zdv=
$np.
AQ[&\1
I>W'
3>}B
Rp+
cYn7r
X4;;
=&m}
l n]
%KmQ
U}?x
kB`'
0dp|
<"5{
Dh *
y'p[m
c3]c
/r
-$7~
fTgEi2
0IBhZf(
qdVdi,F
'LCX
7-5{`
>AJ~
Tt&Y
CS+G
ak%N
KvbXp
rp09I
)OKs
`v#S
%t\Y
3:H
5w*p&`
o7mv
MK9N
a{
G$f$
]8;'
&`bH
abv8t
3chS
'_5lX}
vY>h
E9$p+
O(67(6
DialogResult
,qzN7
^Co}
,Y~wy
q q,-
7Dsh
c\V`i
vhAG
tD Q2B6
*Wdy
:Op\
l6 H
/&+0
;sKQ
Ki2\6,G t5y
$5'(}(I
!1w+
9 iP7(
R=HL
[$})\
|,O>q
&0F2
(8,w
fO=#
hwQ(+
Xjcg`3
^ we
&S53
$gBm
-0lkV4
V42|
]|a-
|$936
/%e3
!J-$
Ad
#EQ[8
2>f#~ ?h
4a.X
1v0A
}~x4
[V.o
Ji6f
S; >
6r}36{>$
zAIh
. !9
\2H
]LlX
2u@{om
4%T(
-41*t|
`+pP
MZ \
6A\
Npgu
NJpO 7V
hxP Ku^.
^;^ 5d
h;/zC
0vT
M,:-
tZR(
Et=\
.Ll8~
h,f
k 4 am
|hph
Z w-
f~e^
W/%s&
,.B.BB,S
/!|$
NU<
MX@8
kPY6
C5]
hcS
.R&Q
qk/E7^4
{&'{
<X"!
(HW
}%?w
3xb <
l_Fe~K
z7HG
gd-}V
Nfm
+1Z4
%)pu
UF0$
o4H,x
-*'vt
P&C`[
8 V~cR
*3q=
Hq,=
*'+
B0ne_485
aJ@F-oQC_
<<h_
Ht@wB
F_&f
] %1
`|.c
pZ^K|[
9l x
]YRuSl+
bb7</
kntfm
jpFR O
l@0f
?4x8
P<r
8 #w
*C+H
:AP7
/Jkd
)?o="
(#t_0
vSN.
(JRU)
!? U
57,^
0/k!
J|>0
AtnI
,->Y
Jzw{
eNka
yP w
K/hs2
d,UH
iytl
qOUI-
FHQSW
&zROy
E^.dM
Yp{p
QQ).r
9^TK9l
ewHD
N\SW6b
H3"m
A+ykx
@Tu^
JM]`
hu9T
'b wV
i!2^
p1
' oPCc
jePI
Wm0bHbf
F%9 P@
S1>c
u A
G1zQ
7(/)
D fq
}7{Z
F+S
wo?Ay
|TczB
o?5
s1Sd
GOtq
z@V4
]%MN}
V'6)
O[~w
, x
YTj
X+oK
2.p=
ybaY
hkV=
E' L
<9G-
8'{~
M5_N
_[=s
Mg&
V t#
$#,y
$WCg
>voE
K~I;m^<Q
.6K}
kt5Jk
#+ xN3
]rVg
Y|3aK<E
'3 c(E
0[U/
\L 9+
E)&5
Za3ot
1E[$hzw
#$j3
Y"+^w
iF_HG
e.tr
n_v
hU"
Sf W4
D?$,
{:B;j
5`Ct8
<zE&_
\?#"i
8R9u}
$& '
Do1L !
PAX
rLoy\
R`M3t
*\Z]
^y+X1
16q]R<
J'ctq
":.Y
uiO,|E
>4/>
"E]/
5)yZD
Hxhf
-h#
DY#m
!QRv
C+bC(
%8UI
*Xf:
n'AU
*q4I
|l!x
^t/c
ffKOt'
|o6;
XU2`
\K"#S
AkxJ
-I;7P46
Z ]*
]/5}o
S^Y.
{.\^
O61|
;w$?
eg/(
i3C:
xx^{J
Y8<6
7y:n
\d Q
,C]3
};f)}B7
=q%I'
G|7
SnoS
1RZ2D
&>"z
trzz
Gu)5,~>
R{ p
Dt)u
Pjz3kG
s9#9
KzX'
yfuD
/*Ac
;a zZ
JF0V
)U}7,
yMaj[N m
D2T0
BM|[
G u;
^_K
198<K
Gl6%
2hZj
lct@
[*T#
B&xG
\$ Y
/'W4
4t_=
m.:%
g%v%.
~HOB
f`("*Q
U<!0O
'c*+
2$JJ
A'F!
>UbQO
!91c~
:0og%2?y@
U<6]
t_z+5
&FmPe
Zf6D
Z ?@'
e k`
HAf.Ya`
|CiS
uP2lc
X:^5
fiM(
$wTu
twIg
q 9fN
z+[5
s.6B
" h|
koQU
80ls w
x~9AS
yE|!
]/h
O~l
by zr
_!QcYz
20H&
jg}+
rN?/
_s m7
Wl^{
faj%
)& h
ppA3vA
f?h-
0kP}
jM@R
G0*U
}h4_
loX.
#zxA
r!sapQ
Al&l
a:KhSq|
lQvP3\
'\Su8q3
D<Q4
6$<:
dpM|X / =
"`Ap(
:u2]
%A?X G
;Gd Z#
e(B93
[Y -\
@gl
>_?
t:Vb
/O+B=
CQv_m7Y
ff%Yc
7M;oe
:I*o
wQ)j
JQym
&j7o
~ann
0 X'
H6E7
wyl
~w{1
['%`x
yk0Gc
~M149
zQ49
Xsd*+
"jnNI
(#M;
lNkU(
G72`
;2<&
WVx3$
: 51h*
QfQO
YcaU
$x?^`3e
SWpP
2>^
.[%:
x@RA
n*6o=
5i#G
^.EO
xv<
5m^w
.#4l
B?5X
/S1
5_Ng
c=n8
IMa9"
h KZ;
!,~s
L'7NV
=XQT;g
(o@S
=-2"
*%%K
QIhh
`.8 !
.vW6
j#%3
o'P,
vEeW
"VhI
GXq
Xj4h
"K"C
Qu)r&
R-Gys
j#%>
hZ=t
Rw\)
(ZFpK228LaCxTrZkZ7mmgcbFDKJIb8Ean5auYuaFh
./=x[
)z_%
@*WB
B+Y&
qum`
&3!Ao
G|p[
v?Tp
O6&V
/ Q|
@u!3(
IH0DP
{HCPSN
y{MO)
49nkv
6w ^
Z=,V
{-ks
CWi+h
UqIH-
r:ax
5_:A\
;[^1
#wf&
05Z"
E! 4 (
P=4
@ ?=F
[s,`
(\^B/a
I-y R
N|NON
5V#|
SeVx\
wK/
RV &
)x5
D Pj
`:z
r]=`>
4bN0NJN*NdNxNEN-N%NpN
^]E{v
kp:X
}[>|[
,CZ
cF36
HuKU
d u~
Gy
[;'s
WstB8
_g RL
Eq'<\.
~"IJ^
BjU
SsUa
;+iq
gW;.
;^9Q
t,GGp
,u\%
ytvK
:K{}k
! w{
Y:-eK
7.\&
4U,w
>1Cx
oE&e
_Zp<a
Uj6A
@ X{;Y
1jjg
]ID|
[ Jl
(l!7
mq:tT
BLx4f|
@X5b
jU M1
3@L=
0:(1
xxz n
`*E]<
j'=<
<| K
yay`N!
']9r
`weR
kH:m
E bA\
49zO
W.~
pa""j
m.N E
`Esd
bLM6h
j[arr
KIwm
V|tk
P;Cw|
_lWC
'=8_|heZe
6Q4
sG`;
ycCG
>% 77
gl~zV9
o_h >
<Q5x}M
V,9y
"%V2P
T("!.
$p/OZ)
IvLx
<a+]9
$7a9
Rfwu
V4?5
8H0}E
[;B 64
\X{s
PE<
qi2~
fu)_
X`D5HW
<[aM;M
0'p(
f,d-_b7
l{J
o/[*$
KF]
e] ~p
8T7"
l.i/A
.V&b&
b+.c
^~(u
9P@)
g50+
r9$n.*M
wL L#
#:Xdu:mGD
xjYQ
*N?@
BMn
HGj#
\*BaQ
2=+lp
"\ui6H
Vq$d
VirtualProtect
<% p
%m Lbg
~!sC|u~
o>ba
T0 1
IQG-
pvOV
KkBx
Tf=4
G?$/Ao
(>GP
NMM*
] 7(c~
.H&
agpE
?2As
x<0T
R,xS
"[%D
h\85
- 4M
)bpLA
cjar
'.TB,a8
\S7\k
*1Q2
@? [
9|ao
gFAg
j+8|4
F)96D
A=Pw
dvT"q1B
J4<R
/:HR
7<bm
"Xv ^Q
Xc=2B
O?+*
}m@
Mlg
kZB5)z
q?CL
9/o
m;P
2VeK
i BU
<6!U
*) \eu
3<tN>
NJNi
G/h>
g)kR
;~mh
0Ra -
2^:M
Ij0\
Dof[
c}jQO
`6_g
0W%jY]
D1[y
=Kjg
?rom
:<6u
i6igw
nw=%
9FLwF
pI)WP
=E, #!
?NYw5;$
3F}*
P0[l=
uDFiY
W[i+
0W1ywd a
UF-ThdO
i%tY
HzI+]
57uIU
ByuC;
k2(y'
)xlv
fgbA
v?w{
@nk9
'V,2d
Id`LI
f@^ mIT
N7!@
lHy
6vTT
&2Vo
f;dR
]eS&
ybDv
#,+'O:
Cc6w
T7rN
Z;!K
.j{c
j2NnB
rB+{cy
@GW8
:RA`
E[Na
oqI;\
h@!++
Jk6@
Gw3;
j=eA
_\)x
Fbmx
|@QXYl
?L5q
|`DDH
nSvy
QsjQ)]
3[R5
rZ}0z
qM%6
/` !
u 0^y
lk5_.
=Yp=
X"f@A
AF|g
F&B{
Vl['
he*V
|soM
NfN-NkNrNjN]N
9W B
J/Q)
30hB-
NWN N[NxNJN
}"U
ag'4
>A!g
B Q"
K Jv&
~p!-
_#! v
zldY
1: /!}
AOo$u
U|hd
I+W(s
SN
C}8~
3'L'
;iRC
,Fc&
ePv wT
;/TM?
qJtSt
$|f
Mzjp
^z)q
A4"
_b+_
&.nq
<&SjV
+|G]oC
(5r%
w 6/
y1=+{eg
6){CC
5dF:
\z 5
NFi%
2~q8
e(2
Mx"1
!}Y
2 e~
yf{|8Te
wKip
/>}C
&Y9_
g2n"
gj\1%
dO"Jtg/
{pyS
wG~7
O</,
S[,'
3#JW
!cNn
q]/J
@,iV5
[ZfU@
1L}D%
C Lry
Bqv/H
j*
4|X-
)7-:
VJ :
Lv1h
+ Bc(S
_yVs
M yeF
yf4M
Pb{~
u<`z
7"f@.
" {\
FT'=
J#5d
{DqDH
}JUz
HUmp
6F[J
j" r
=GvF
T561
+r@z
W0W$
+g@h
[P B C
xgID| j
3%~]
'Ao\
zq+%
v4io
RdNn/w
NEN~N NKN N+N^N*N;NsN
9M 0
;&Nn
MGL0U
9dk.K4
bB !
/az0T8TqR
7|DYJ
Y8sT
]D9R
gP7[
s5ci
f pC
KjA>
1k`3
{A&3 0
.;|O\'L
qf"}
c a
[Za
>5<q
%-"N
KNZf
ZF&V
WZkO
{%#5
\*9`
EJdg*
PTVb
{l<L
t:{+
W %.QP
UR{w/j;
*S~W
s{<s
J_mx k
!)g0
hx 0 1@[
h-}=
x[iT
R@eS
oeyL
\ `&
@0)/
=i>")qi*
KDqq
d b~
(LixN
KW!(h
Cd{?
MIj9(<
\O5}
@ZLT
'w$
;b5 n{w
.ocBk
YA207 Q
x,2[
+W C
O2NtA
w.d BL
Kf4o
59MP
-'5
M N
5=qB?
.vkd^
q=iV
K,:I
wi;
V56C
R/ k/!+
(>nq
b2mO
_Q 9
*)i|
UbKE
&}8:
y;<"
Ydx_`
|O2r&U
>CyLW"Z
NSNqNZNTN\N
v!L'
_w-7
( {m
'gdE
jwP7
DM/C
*1N/N N
]zwwf
Ow7x
@u`a
y_R
&C:]`
d)'l
[M=a
]Gga
NDN/N
C 7r
#8G7b
{Z4|
(Dj6
HrMt
mF^>T
24iE
(K0C }T
ParamArrayAttribute
%sl^
&">Yo
D{ v
Kko
d_KD
u1 p
J 7j
*QG.
9i\ Wf
+$
@`NHPy
p^?]
l$)`
?#H0hh
L/c|
M-~c
R3`A
4>dt6DiL
?#sR
1c)!
}>'
R-7 )
}TO%
r?75
mX,.
Cfed
>$vY
:R&(
y6 |
t~ D
)hM4
DY!|
3>9p
:2Y>o3
YT:/,
k!U b9
txsp
~hcQ
j6P7
AgFV
vU?d
&HxbJ
~e!@
;w[{p=
/>!A
f$Vul
3nOE0s
&^{ U
Jkn-
OznX
B8W<
U*u!9J
>.)C
FWs3
;^3{
vA
n9-
V#(b
h<9S
c%vr@
"GcS
f37U
:?tA
'\nGWSm%
=xcPc
{nNi
%SAN
Lv,S
l%OGI^
X]) /EZy$
>ex:VqC
' P{<
C+Jh
4zB41oN
bs|O
`% )
Fxqb_
qU(L
v=#V
Dz5+
(e{Vt
EU`S
%4b2
%#v-f
n049
Ewpx
vT*)
{y\A
p"v\
J!6_
Z>a,
ww
'T0}v
Lk@}k
E
z]8Dr
t*Te
B>kr1
HL!n
avtv
i#2c
2@WN
l0Z[
hY~C
8 ,4`
wo`k
tC+]_Y
ojO 8
bp_K3/
"tZ.MB
IT.ce
] O]
VmG;
5Vz
B:=u+
{T M
$\pH
"~3X
L11V6YW
FpZEy
" /o
-k'_
QsY|
A]t:
^ sq
DM/i
Fa^)
q6n}
'_8
v .S
,way
}dVg
a' X
EP%tR
#zJ[G
C{8H
X*eL
kTW8$
~?=.[}&
G&%!
q=Qx
-MY
'1Yla+hS
oD'1a8b
iccF
Ktn!
pvPu
sXP%
|}`q
QW<6
+l}6
l:c *@
~D##
[:Cb
*m#549
ou
!DvK
C=bX
lM0
-} B
8?ysW
YY3g
4jwV
".j=
&;Di
n63DaA
+"$ v
S;*5
I^qI
?k`et
UInt32
W"w<
Sf3Ou
$st?
Q*z#z
]/jA
>5Lb
$=vj
%^!Psm
5j@
Q|n9t`
1.lk
nbs)
o*3vz
0h8
m;'(
mS`b2
KWR-}C
C x=
Y,Tv
rJ '[<
XD^<+&`1
%'I'
Xnewri
E3cz
z=Vl
ZzyM
,o9K
A4)Ax+
g4t4
)=(93
ubo _
"(}NP
@C-]
sDo[
I[?@
-m0j
"W$Z
%=;mzV
Di RUu
HkMeN
-6q%M
@TU[
nG1'/
?>LS\U
~lL}x H=
'o<KJ
N+ut
vH!!b
L_<6
z)7z
|e;E
}_}[,
Ar}S
l!w.)
mMu:
2J /
Ymp#
}?&%
exKF
0Y/0(
Y~uP
=O]>
\4QH8
p\!,A
qbO?
d .0H.q
G<|rA
.4IiWzy
->m
3NXj
@TDV
(F_ Z
hRw#
M}D!/
7~b\
h.MAC
WNTsB
!V"H(8
8j~Z
#A1%AjRfC
*I4%|C
W`a2D
AssemblyTitleAttribute
5TTy
:+@'
jlc4
*@/+
gD[{sgD
A qZ
WI>2
_xzF
Cp/R
`v G
!?d
)$>D
C b}
{=3
Q>p`
&rt:
E}'p
+hyzY
YI32
<U@6s
NaNAN
S4}:
r7dy
q\|D
U[Gp
SL8L
>B #
^~wT
rx MV
jzePKYy
MemberInfo
&K-h^''
z*9
&Sy<
n+S'
g/oOo
|*/K
/ETq
0?B~#; zi
g}c-F
!`Izkk3
*ZNwo
.F"{$
X}y*
#V!)2T
/>u
r}80
7~nc
^\4^^-M
wCnL(
p |k
$CLn
q E}}
tB*rn0
"2^w
|Uf>Rw
Z&/r
""r.
|VxeM
$L+,
s.x+
Q!]<
l2mS
e 8.AC*
y5pG
2|.6)
1,;D8
"L ~
GAuT
_Lh1!
d} O
6# )
r]Cn
V zP
a2b6(
?b*.-
,KD;J~./
M s
J!I`
&+H00A%
(,,
|B&UV
+e7l
r} K `b
<m\OCK
iz"G
i3P@
#Iu=9
R35jY
It4
4]5nZ
Z Vn
lsJ~9
$2f?B
"e=0
1o"/
O 6
fbKh
4&H[
p@1(
bh2d
9oXmnInG
_|"'
rZD5
&7V&
WP"+
m~-o
:&pdk
q*0.
yBz;
Q}) Vn
%FAHp?*7+
++>m
1 rj
}~y;SH
{A<f*g
}X E
/kT{
A5"h
LtmY
`3V4!
B#yJ
F+P8
IuX<
1Q'c(
H<)[
-rs;x
4Ajf5
: E
tq/)
v"V_
v6=<*[
jntL
HREJ
VNQ@
/%'1f]*
'yE `
9r"x[
|O&Q$_"
uz F
o~qO
29|S!
qPPj
xN\(
7mr}
eSks
GsN[
[)?
1[Z[=
K#EoR,yo
}80`
P7cx
EsyU
8L xu
g>VU
9Tv_
F %&
r>T|
fFj
1x~P7
9SeXf
-i&A
("Rur7
rq l0
bz0!
YP$Z"O
Q};
I&CI
mg5DlB
yl50
o|2r
di2
Q Z-l
,4q7;gA
G| =_
roNw
<0v=a
&kkreZ
dR'3
B?{$
vs/r
]t];
CA5]
.52L
Jznd
13BJ
M }P
%Ci)
mTxVV
^tDQ
|qGX5
x0JDr
,04j-b
!:cH
X. K
R >
k?{v
a_t C
WrapNonExceptionThrows
Ze\y
N/J^
_G-CB2
u^X
v$@0
jK{+
M`P2
:KH7
1,; X
N3N>NlNJNXNbNtNTN
;UZ]#V
)2{9B
gHlX
6aIT
/^C;
7QAFd
Kly^
24/1
YS;Qvv
NwNlN3NfNUN NSN[NbNaN^NMN4N N5N1N
')JYy
63Hh
w1q)
*QG;
rB t
aj e
q5_E
_'VA
hx^v
ls(
[%P
I-HA
2q`O;
.9Ny^
:\5]
Hj<K
j@:5(
5, N
Ib*{L%
KC-%N
PBxy
pf1_e*r
}<=
get_Chars
,m|l
e5z]
qMd /
MgRZ
](7^
":5a
D]s`L7@u
-1-%
O [.
SCwC
5lRN
g e[.
2TJh;mnf
WR9`!
\c}U
Y%G9
{4ZB.
R2A>
Shl8 0
Ha (M
..C*
tX Dc
$=/H7
5WMR
];7Om
KyHt
e{?
ph D
(=,
l> 1
wQJ3
Mw|<
ote(B
+<^x7v[
'^/O
Px~&C83
BI)4
E4.'
j yv
tz7
#e,Eq6
QoAyT
'O_R
_ 0Shcyp
NcvtV
v!r : M
MNI61
5;lK
T-g t
)o-"
:pQB{
=HJ!
{1nAB6
|]e)
;1'$-
<lC
ZfrD
E hQ
e(7B
MessageBox
COcp 2
WQ-n7
-hIy
O/f
`5! `
$`s@`
19QN
DyuT
5gI/
djcd
Oq Z1
N!Bwj
i,+"@ir
{;X?b^
6XSxR
j yM
t""0
Glw&2W
lR qJ
o^zM
ELxV
v}/P
L_N NBNlNeNnN
8J.=
`D 3
yERfI
OVf
dI%_
Z4Qs
Cq'b
?hx_U
)o-x
"`]x
uPY
ai-~
G&#>
{G'u@
vDu-@(
)0m X
<syhE]
aGS
$r l
{gI~
7\P A
w' G
'dV5
{z=hn
f=:@
r:B
:CGYm
oc8e
)_gM
((=h
3+[(C
}{`t2
"puf#
.x> `
lK+"
6M#\r
,,|~
f)m
k"N0i
Tqf;
+]4q
\0kOX
1vyu#
t!lQ
Gl g
En'2
8v#6S
j&RC
N%N{NTNoN}N
" l<
OkF6
Q-(,A
t%3*3
hDKm
7Ulf
FgTC:
TnIrL/hf
=/?z
r%E2i
*]Nn
O.3J
*j L9
9*c=#9
w_s+ _
IE!
r1xE
Ozv5]W
[(`l
\-m=
(XF*
o|,<;
<CUB
n%ca
EGad^
&"u|
o!d W
q$8g
?pbmq?
aBmX&
gCDV
.0jUL
3sp%
!;rN`
Q#?/
TGPo
@qGs
<&]I
jOR2
#A !D~
SF#-
#qzD^nU
fWv7
ZzVH
%p>>
$@0?2C
Jg([
(`!'
APaU
gCU2[
DBWk
k%W AOW
X.^Fx
x$.<
$C
Dt0,@
_kUK
#c3gN
@y:[
m)h0*
P!H+%
kQL3?
xFW!
$Qu|x
!U~da
;F)^
~3*!
N#2
qKUhz[QA
(cm
F+21W
2~l
7!##q
{G?,
_8WL
}>%|
"Ft
XD1=
zIWc
bS"z
4\*{
9 Sp
H,@<1
_MVg7
gTa/
\s%9
h?nNl
|w\#
QrAU
Q`j$
U6$%
;DnM
OrM*
Ywq"]
N?<m
?biy
xW }
Tr`
d_M^
{*p@
,5WVY3M
,7Ey
J5 ~%
~7.s
+Xxk~
f=|)
Yg[Xy6
w{|E
,<vZSJ
8p0e
5|E#H
hu-|
Ag?d)
0Pu@
/kTzu
pyT7
yS W
*8e!
Vg!/
-S&.g
i_ac[Ih
x8GqU
9EDg
mpq3
BAq%
K= Y qQ
e^k?O
V~}
iq9h=
ParameterizedThreadStart
]'4g
b[M2
94[/V
kO.
hrQ4
Py&aI
8xmL
*f$
"o[e
RN4
b\|Q
?~e|
0W9j
dJRE
wj e
&+AR
,2 '
"zMo>A
E_;W
lUG_
HhK!
`)L
gseW
es (
U,*@
@h"
"|'}
"u1N8C
7';
A-"vM
$)T6v
3t .
71m~
4%]L
x`wO
?'W?h
w4U7 E
6_ |
/Xc4/x
P0wu
? qh\1y
} |K
a">j
NDda
h W@}
07W<
KZ'QP
w4 J
UKaR
- <1
t2?@
oMhX
l)@4
8)a8.
'x:<l
T%:>
h a;
yI\D
U;/YZ7
Y]U4
\$Mb]K
Sjo1
w Mc
j5t(u
Akr9v
:Dr?
NIT_}
`/t2
<%7C
a5c#
j7T/
Uv+\
H*YO*
/s k
A:9>
LTq*
|966E
l!Pb
37Kaka |
>Y7M
9J!
`nf +
4mD1a)
5Ds0
e@ K
]KMS
l7"|<
ai.z^
0/X@
w WHYFj
B(@x
3c<W
Rs|;
k#eSZ
J=:T
]5V>
sG{
0$<F
t]\Y
_bfu:
{z98
#Jx
^iX"_
S"G]"
N9N7N^NUNxN6N&N^NhNoN
)-kC
YtER
x; p
7i\}
gB-_
'r';
u$5
-!7C
_44 1
HZ(P
f%UE=M
jDpN
b_A+
-FHw
>qp$
HkU4
;!;KRN(
Rhu^
<du
6rGz
n$Eu
1evf
k UW
{H_~B
~3UL
_?r
p$R
k CB*
vk_/
ynad
[Ic7
f E#
h'bi
nwFb
,@|#
[hTA
enf*i
Kj
/ccD
)=Ks
iVsR
%rB
r!h]T m
B xW$
Interaction
I#l
gqN}._F`,
<]d_
fo2AH
Pqc.
]/lD
g:Rw
h 8$
|yzC
{) <-
5/D{B
g>^@
> =I
96)?_
R,S
mar`
tUf:x
w# k
zUKv
Wsr)
LXfz
C{&
3%[)
>0P
<@3l
Ie q
R`g'
.;kv
}2!'
8#>3
rN3^
|O}
f8Y:%
}lmL\= h
d~xA
tG-A
D{V/
;3}i#t
Y2] g<Y
);\9
s6"p
1cfD
s]Ia
8Q f>i
QmWj#
mMg"
56@
K0N'N N&NYN_N{NLN-N
Kk~e(=Y
P H>
%6X5
?>:T
< }*4
3^E?
*c$R
EWrz
nj 2YOb
1[b%0
x$/3
cOYvcss
C!'GS
.sT=
|t`>
\ n
){ys
z^yb
$m8
fx _
TC H
We<gaM
4KZ=
FT?f
cEu0
,Ri-
Y y3
3E`3
$qh#q
/']0
t(H
;sZl_
Qe\w
'5Z?
RV{#
x[h
T!^,
zb9/
mx95
q,lvu
IE=q
J PH
OvD$
>p!z
a?1n
N 8cTJN{
|,{U
M "$
"Vl:
@~WO
Ggwj
2)Ge
H2)"`
qNIj-
8~bv
%NKlF
m&}f&
'jsV
LNO3
KpIL8
]Ula
1Yw`q
.3sY;<
w4r'O
"o)5
V*#i
|y ba\
!2B0
Ar&%JKA6
y}.=
$@{D_
`;I~
2; }
EC.B%
etcx1
'0Xd
p{t2
~gxq
85Rp
35Nf
IDAT9
#g5y
k/}xS
+Wi c
k!/"k
'028
X^rR
iC(E
MgeNn
EO1{
! /<
OB:v#PT.
J2I!
E~2)
IP/)
'4siiP
O\{-
W_s(
@`Z?
,{ F5o
@P%g
#K%P
"0]G
v? 0
Z9oH&
!)h[M
;^n
J~L%
g7MB
@M!au
nV*g
ZT=D=
.x~M({rf[
E0ab
{1 l
TS b
MU|O
$ha/K
Q4H*
<#TX>
)W)8
fp5
HinN
hl|:
iw*'3
d_hV
QE7 x
VQcO
`_S}&
Vxd;
)tL*
jHla
C"0G
{sSL
K&_J8
\zd]
['PF
qGT I
Py:8UKD
[$p#Lz$K
Q5V P
k:!M
^qrx<
[*jj
[k\e<
!4,^
'&Iv
UY,^s_
rvT0d
fImv
Nhi&,
6=]8
edN #
~p$
I6A
|@/j1
w%X|
EE23
Et{.
+sv
TV9i
F. y)X611
Rt(h
1$Qsu
4h<.y2
c0!E
n?/.C[w
,y_=
[~~_
&F~
R^X`
l{s~x
olJ7
O k2
!M|@t
5pzl
oV:\
Ue)i
z_>F
\f F
/esq
(",;
hm=R`
W{o'
mY'n
y%-O
"G?q
r/!y+
/7hY
.cctor
5@$%
`X5y
4CyC
b'8~l
Ur][
' Y|aG"
+q|s
=ty'U
K0w3q
@5zX
!FDQ
;GAV
PZwb
$KEk
`Tmn
A8wU
2^>|
6+:]t
+r!4
`DSo
Gf {
2|OG
FbU3
QBxW
e6&V
rrA}}
z7dS}d
&j:qi
Lro7B2
%}z{
V@6 }
eJ~i
%j' }
vZ@]
edOl
-C`rJ]
_$`A
<$>H
T !sx
T!^*
17 m
t2'i
2 f~
aCa2{
-?[3
E{O3*
N[fi|
9.<(
/8T?
gA
n=n6x
wv
5GoL
5QyB
%5mH'
qmb
0QO
:}!J
mul-
:[ge
lk*z
?!I^
l1vq
Mx|/B]g
[ _D|j
Ytm;4
_? >E
| [C
q>W#
:zD;/X
Z* X(
va3t
+Q}<
);zJ
dy7rk
,ch1
f_+
System.Reflection
Xnou
@*Frl
h&k
LHjd
C>u<
Tuzkq
c#T7
Q .
S\#S
k[$O
j+>0
\Tk|
FWjf
&?&|
bs#0pc$w
?b`$A
%aWh&
U8>vd=
_T F
dnc
("<SI
<FE;
}Wf%
Uvp4
, QT
*k Ti
lfM
e%{)Z
8 &n
7nR{2
cG/y
1lc
@DHj!
%x%s
A`C#
8Z4x
2lgG
No0n`
y{+/
#Q)Y
:2MIhS
o ?#
5, ?
no`RZ
B 3j
pOQz
tME Y
YD ^
|oT*s
9Rm1
GetMethods
"X.j
Hx&8
J~K8
`_3uQ
2.d^$k
M+e|L
MwJT
a:d?
=f;%
WT{h*
]Ep'Gq
VnZ^
RNc])P
Fv @
~T1
>d/<t} W3
9XL|
/`TgV
@ R-
U9i8
wr$i
Z]3y
9Z\N<
Xp{hu
d(xMJnZT
]myycU
u" Z
?34Ueo
v~u;
oRef8
@vYr
Qs@%
cD~
]iBm#
*1 y
@#/s
LXN}Z
@=^X
xm&W
?{_
vVD&
o0FP
9U_G
'44vUo
!F 0
6l}
;MHD
pKaa
Klz ;z
Cd
y-*P)?
a oz
N|NSN_N'N5N
P*1G
]1e;
*a!q
AssemblyDescriptionAttribute
!J,{' U
78 2l
(xtg1
l0*Jq
aN,H
0*-z
jEJa(B
]dWa
X*"#y
lK%
szrF
Tt1i88
UUp;
Q,QL+
hej ^/
_G$b
P7F W
i;Ied
5{j
=W,Wu8
jY5O6
/2K9
<Y9^
SG2?
,'3xC
@Rhx
EVL6
][lLQ
3ulz
T !pE
N?NqN
AEL0
9U*[
Pz H
8Ol ,
})JVC
_Mqr
x18
ZC0h
'B?*Q
vKg
|C/
yAS>*n{
O5l}
!J,+
sIR`(kv
\V*?
8[H7
CJnQ2n
1-(p
w9c z
W )W
vwp(
@?h3
$^A-
h2Y9
>q9[
XJj]C
k.]:
lQ}.
[]Ec1E
e?0~.
|E; A
Q?/A&,i
oTBJ
m= 8
(Ofir
Q`g*i4
&4aG
N5kMP
],Z?"
u"+C
E V4 |
`g p
d!
VafL
SW2J
^}c7
|k>VW
BAC\C
(n1
\dW
0<1?
iDe}
_0KjSp
N]:n
NYN#N
8mg#
&)S>
WFSPb
%(f!R
9ig'
MwLs
hP|
k=x%
b>cd
&7#wP
^z50
cC6SJLB
&W`y
e 7O
R| S
!X(\
.31X
^y:h
9aljg
rFH;
s`:>yh+@u
'Kq?
{O=N
.W;G,
(;G[
7HQ$
Gw.F
!!qD
14VQ
O#]F
{+>9Dg!
YTz
HqI8
/{ZW$j
oYvw
l;UkR
D@DK
.r"e-ytc
="YH
[VcM~
dsr>
Y.o|
F{4=
5L<w
?Od
0]XG
*G9r
h ~!T
3ul8
7c$#
F9 &
`C("!
K `W
x c *
ObxY~ A
M-!<
F(1I
Kv<>
6ay z]
JY?)
tfxn
o}#]^
OO\p
r9{}
va _
&eT"qj]
c6|ql
&}x
Fi&hD
qyj~xZ
zCSm9uwM
4EVO
Ib&#} O.
BJ43
>dR
Z%`
n0go
!T,n
dc'(
pl-
oU,S
t@K4-r
U+w,
:xJd
W>Mt8
cH%V
)**/
P>wQ
;J7Y
^LCB
5de~
oQ+=
z0s`^
c xU
x3%+3
tCS#
`6Kv
,SP+
H>W9
zki2
']4^<
2Uq3C
cER\
m>Wk
n.zO~
0?.<d
pfE6S
a/
(BMUiA
TSp\&
O:K
?NG:
2l@F
m;{N
<x)K
hZ`iH
LnB|
ng;9N
H9N~N}N:N3N NZN
-8R;V
!MM C
d5>e]
QTo ul@h
bzF5u
j$F`
6PnF
.-9^
G`q1
A]PM|
s q^~hmq
6&eP/
4G`S
66m%qZ
1aB[6
vL.`
$QyH*
FL_
Q_hZ
U;+4K
&0#Xn
O&oE_Y
WCTG
U~y|
H5W`
Co37A
jYhK
"~7'
g4};
~d4n
@"y[g
o_MV
`'fu
\^/<
*q2u
qa^3
^C^
lVNX
6%$
ofQ
T#Vq`&5
9*C}
,8+iFU
p3lyU,[!5
- ,[
l?e,
;SRL-
T9g4c
2/Hn
y4%h
KT
Ch=X
zA17
RUHp
m`)Y
L0LY
rmY>,yD!
7SFT
br%
a-MI%
c\?a'?
q6Y
aT^8G
C##mp
IIlh+
fH(
r&k*
NrN1L
jevaW%
zc1
Ggl5
zAjY
[QT*{
6,6<
~pog
g[B-
-kK~D
N6NfN
ispH
=ey9")
B,<lL
h;Oi
\7&FM<
u.Xd
, U;
Y&Y;
7zG0;
ygUQ
'X96
9COh
\&&m9
tmvPf{u
0Ep,I
I[8xj:S}QxJ
KGvc
;BlI
7Dh&
y Z8
p0H$
YAYD]U
sfz
_hEW
!w4&
!Skj
"@Yd
EQbO
C&6m4
83,fP
[nUM
zOs{
!E ~
:fScRV
o{P<
}9k+
PXz3
e9zq;%
aPha
o-92
\?7%$
Bh~$W
!a].
!KTQE
9nk8
}q/ZA
cFX]<L
n3J"
p=Ho
0elw
*Ig<c
.%\>
ni361]A
M|]8^y9
KM!'
&4$E~
kOOd
F^Px
gl $!
SCXE
4y5^
FT+o
"H7$
IShp
'Z'!
c44:
*nV5
mv |
x%S8
vUL
m%=.Z
*B!]
>]q8
Cv% c
Hd^'G
g_pI
P:<J
h|&S
'&=_8n
A9NoD
4pgE
Gq[O
e~'r&J1I
N=NeNcN-NkNjN
u??^ED|o
bCz)s
M@TN W
5IU0,
{X;3
B})Pu
*U/7
6: q
Cdh4Q
OGv./UxDE
gt\$2
s@T3
{TE V
a}6b v
(L^J
}AP,^}-<
ZZwRW
;s*
!Q*}
5 kv
p1NL
'}-
@dku
}g^{
,O0?t
3Sd}
.`&U
?6<
5hWq?C
5!Zx
Mo)
]_vQY
Nb 2
@YPuI
+Zhtz
|9]I
!ps_b
7{P9
Bx'5
mg.
;}$,
.>yB
P&NK
kUBy
i~G3
c,qF
xJY@
qhJbX
PB6{X/
b Hx
P`=H
5&jl>
wulf
~1S&
-5~I)
+y}V4
X4 C7(
!,m)a(
MSAe|3
$P@Q&
aVBV
a@H!
q(*t
*s~3e
q!z
bb24
jA"T
UVE
#fwE
nhu-
6zs%=!l
oINW
BkA:
Y*n:
4fpWbutbqehD5pSVRd
&p 2
@kv?
d?i~?Y
0L{h
]P:B
v,\E
>jaTT
=+ bU
n 2
=R,:
NT8Ov
};R0
2:QBe
GmZR"
ad?t
;@]S
Pv3U
%WAJ
'98'
Y Q#'()
eYh#
ZN"Y
2m[G
\As;
"oDf
_ Rd
An b
o$ e
1GYO
fin~
\9jJ
yRzpc
B=!8
\l1B
vmr
NW7U
4QJ
'\hq
U:gNc
!Z9'
vWwHF
rB ,Evq
BlP;lV
,no 0
Q{ $
TO
bgCZ
\'D#
@+<Q
,DJc
umlXa
1 64
8>fA
(! rL"
qTx(
T<V} ;
Ez UQ
G_B`
^,ayd
y`lSJviok
P0As
B}|x-
NfNUNmNXNnN
yIbp
|;K
OH$
-.v_
/Et
$CHu
BsQn
mMF
ob4+
E5*>
o*~c
@NIT
'P 2r
< >Y
{q@i0
"w?,V!
}6#u
G^@n
,$s4
\ppG
[)H=
l_;J;o
6-"VH
7eM g)Zh
!`V?
`n~)
mpVu
?[Yj
}_~<
[mJ G
|/<<_`
+Vw?
.~Oo)
1"{y;
^t6 &L
dfZ3
t6I\[
{t(
vZw/$
xv-s
"`$_
Crxb
B^_
<uG7
&9y
bG1q
qt =
0qo'
7Et0
6 w
m6zs3 j
NnNx
L$y)l
DvK{
&.z9pe
6*N;C
q# gH
'-]Q
d)lf
:nH)
2=FK
JVn}
Q=uG
#?EN
sPG1
SBuj
2#rX
;P>S
@gU
WOPrd
1 vT
~y_m
O&(3
FsOn
C7wGa
Ps LPk
)U4
Mx=
!v[A\,v
!^$X8
[%`y
l|PT
k@A*
-&|l,
j/p{V}
Wv^o
/ORG
z1 4
'J*@
;;S!
%/v%
(?z60
(Jk\A
dIH
Qj "d
1a@J
s'6l
]jw&:
K7/yH^
o|i%
j2eW
JV9v
"1c$
qrHf
Z lz
*1?{z
`a77!
Mcx+Nm[
gq~2
ykHifI
n~Lzl];]K
dt[X
aO<J
-Pcd#t
HD$<
oJ ,
Z!&o
FEA7-o2&
*H/Fu3o
N7NfNoNP
5,VF
.%4j|of7
Y, D
(;lcS
_WaM
&@DL^
<w9b
(@G~
(0ul, M%V
eb{)
035*
ScnX
7l_u
N:0E
jzv:q#
7utK
qonYc0
gpxd
K)e2
:Qsd
TWy'
d\*
-L2/
0wL\c
}` =
[o2
KrVw|
e'{5
F QM
!/J0v
-v//!H
8Zr5n
OAw|
xPE!
aoJj
6*[L
V3s1
xEZ;
uip|Y
FBrw
LX:)
u,0S
SHO\wf
e $c
~z-r
NC0W
6p4q
78B<9
l`PL Y
c o(
H(?D/#
|#Zsu
0~A3,
"}3^
qHD#%+
Q)45
CcV(t
({ uY^
a9(}
M8pF
}4*rR
? W>$j
R"*N
jB\/(!<
]n -
)jgJE
\})f
^Kw#_M9
ZK-W2
c e]4
L|+G]
K%</>h
Ar)~
$<l~.
d\q
b o5
\N^-
hI~a
S:.,
Lu60?
t4KB
s2h^
9U&A
P\th>!
t{.r
O1OotD
hlp<oT
>6}#
Fyaf
ah9#4
}mlQ
P ~k
c!-m
(>Io
,hZ"
_29r
}{d1(
A15-
eD-A
n?qL
Sw#8
Jv^ h
dmJF
sPHp
<E7:
~Wa{
:3 gR
9MQ@
^b!Eek&
ko1v
6EC{
CN_L
S)"j
%E3z
E0l;|N{
F6$n|
Q3{)
MyN`L
>a: W
k_4G=jO
B^Xf*W
_1? h
vK17
&s~b7C
qWKj
xiKOr
s >"
_C5uY
H%m?
ogiw
6QIC
jVX Q
I|4(
Uef:
Copy
)d 'tbl5K
hue"
sgs!^{zm,W
a7V&'
AssemblyFileVersionAttribute
@`9
KRtG
I[S8
U#E0
m;@g<
}? 4
wHCw>
]aZ'
k^Qzd"
R,'M*
beY$
sr4U2Qm1GQLsNeZohE
AW+6L
}))>
q K9)
xVIU*:
YJ$w;)J
e-:+
dYc,
;,Z>
O\!M
3!V^
2M9_
C$`U
u~W}
4RE/
V.r,
u@ff
A4[[
:,*r
Fh/_|Hy
%6@<o
n{(WG
;7u$^
%qA<q
Ah?J
8$<:
"4z<PfqA
g]GblYl
u/;9
sBd&
j'O#v
Y io
*QS^
i o5
`+@B
^szV
D$W%
5~ p`'O
O|[0
)=b O`C
a_|.H *2
x*OK
c yG4!
K{7w
FEe=
Lv#a
TObj4iN
uI 3
ov'X
oN~>
VN+e}
&yO/
>52{
N' nV
MSi|
%3w v
$I=n
0ibHy
*-~
Hfy=
xsqH
,"rw
z1Ex
;nog
koJ
#{-
x|jB|
]0wB
{3o=
lOG~b
4 i6
7<ga
5;#
8 g
ooS,
9 ;h
s_4y
jK a]
Cc-Yj
v"/[
'h~l
Va0A
?-?[Y
wl1"
z d!
)FF
|*O;3
k>NK
6U-y
<]}v
t|-A
4|JY
/Q>_
:sT`F
AiR+
"1MW b[
@/wx
H ~U
L<m'(
Xle
il!
G8j9
U@3ug
[;l>
8l@^
2)\'
[:|{<=Z
`-VT
MIsk
W:sWf4
F)YP
:[]H
Y?#2
Ra&_
;Y V
;encu
9hal
bp'
O1q9
{hO0
\x:j
sQ#el
->Ex<n
Ik$A
,ie9
ZKIJ
m~R`9
~1Wy
CvXp
++(c
dsy-(a
v{dx
N+\q
yh+Sp
K3gp
z9{U|9
#\w t
Md%1
7 Lk
XKnpT
$F&C
r@AHq
tgDc
m0o[3
pa&@
16FWz
: v,
NM
"r :
Ud`=
T0]-
b?") ,
}!+;
C >3
7JI@
uS>m%
~V:m
u8D\
bALr
zDT7
|g;d
9HnA
@;(6#
#(CV
<;_/*K
(Y/0o
Pp|
s||;;
rDPk
9F,Ek1R
Q#X\
1@p<
Bp8.
R:HFv
(7W=Z
`7hR
#P(%)
J>GS;
"*,7
NXNON-N NdNWN;NQN(N#NkNON
Z Q.
eX2BP
6Ka9
N,fl
+Q\5
q}xe
Ob u
&B {8
/5h~
A-bG
o,lxy)
vmL7G
NF?
u*u&
R0h(
t^ #@
i&=>
$ 9n
]BFy
<t6B
=XcY
$7OR
jYLH.
oe.P
hIaC
#;",
!tt]3/~
Fm,NSs
0q4.Rw?
;bt5L
!,>'
Nf8K
`O& >
V&#4
o ~Ja
^wrp M
i2v"
[ 4@
%L9U|
Ii7u[%
+ /">
e^rLV}
9+h<b
&u&1
E7jo
"kVy
n{+ko[
^h&0%y
T_D2
?y^
GWD\
+o|R
6 Hl
c.Uz
cAiB
{wOR
5ft%o
Ig@[
Fl2X
L}^|
2U}T
% `c
?],W
l3m^XU
BRXf
~?u:
~pmI
b<UB
F5 &
I @
-k-a
&eg)yuy
|-Ty
PoJ
_Pz5'g
gsB'&
To u
_7a0
1; 6
Hr#3,
4?Y6Y
6ny.
bOX'F2
41/M
w/vO
@ 0 [
^f0v
' })
L[#)+
\ws2
&% e
N}~}&
B_= "t
uDy@#\
) O*)`
RBv
=ET@.
X$$|S
U]7U
xyS<<
#L`9~
42kbVp
;)]0
\0o\
)_(&
]6.7
ZVNC
3,mD
EgX8Z
sSr
qFl&
c]AM
9B[;
'VzH;' hybA
*{J;
P<Ss\
gaB38
\G ,
4_/^
,4a
3B
p!=|
M;kW
A]w#Gw
V^r?
" Yu:
uc:<4
8=^FM~
PMR
&J Cc
+RjlJ*l
TA]e
f ^H<
C{"e
h% _
vE g
}5vitJf`
Auz6=
L8/?,
|H\x
JNsK
Gw>m
.=,_
\1Ps
fp,D;
7Tal8
&sdiE
3BbH
oQ/#
AK&)
(5Y'7~
V/a-
lc8ZOm>.]h
Um@{
o Y<
L2J<
uX~V`K
TfQs0hq
Okg>
%9C[*
XBk2
-rt/
7X!!
U;p2
- H1OVXG
.*_3I
HRZ=
o~T*gp
]EPN_ .
~d%m
@+]6J~
yM39
S]5p
4 I-L
] gkNM
1Mva\\
3haD
usP>
|IZJ
|H#0
`:{W
q.vQ>
N0NoN+N/N*N4NCN.N
/ f@
csYUOh
/]Ge
_A@Y|
MIKP
M^M;
~ws^9
@C)RY
_ =8
nB?7Y
P6[k4
M-2 h
Q>z7
|43?R
}.M
hc)]
qv]N
k< /
lR!/z
H9S:
r,U8 k
]ReJ
o?XdtlT
& P0
|vVB
4PT&
*m #}
reK
,=lW?
A>Y1
Vx t
w}wkF
:4w,
HoX;
G t
F }\
*dj#
h gT
z4ni
dcS0
F uJ
JSz^9qP
BZ=+
-%q/
aOM)
Dg _i
diZg
]Jo{F
yeuG
eF)8
E(]u
[$ns
J(O%
fSEg
swuA
r}2^w
D 8~
D)81
PfQCpQ9) r
5W&K
H.B4
,Ygm
k4^A
{D[w
*xn
a0p8Q
LB.e
<~59R
be<;XY
toPZ
aZ'e
x-(|
O9~ !
7^G,
?9iSz
e&,@t
* $a
2e$*]
V{SqV@
dh&,I(
7eY[
(v@
CG C
kR$c
x)}b
K5`=
^@62
4s-RV
;"'~
^g(~ <
gk- j
Riak
i-9
mOv(
-Zd:
|/yT
TO(*4G
R:EQ
[=&
F:U/
iF
r2i%
3zQC
zK2#
jj{`
tI p_r
7a*'4Q
;6^wA8
:7#Fa#
>e!p
Th%z-
JL2N~
ts M#y
X53j7
1W-cb40
.^X+
<4t};8
gS'r
Qx$cK
DhF
0X?=
eo-a
Un+@
.m)A
B!X>|
^QgY*
}"hhU
GXF^*
eL=a
3ty
v:>}
4`>3
( jp
F<$N(
|W{!"
-XB<
xY|/
W 96
u9\3
9qNn
@p(A
4o+|
;kM=
**Z'u
S$x{
u?7dZ^
?hmuy
*Ogn
_ )8
}T" |$Ht
j:HN@-
VD%[
\b r
"Be"
sVwt
7=d?
R_p%
vjO2"
uJh}.
8 ak
`Pto
{1b*
'I/_
1v0u
d5S[2
uI9?|T
`3k!
`!BR
YrWi
YL(lL
"1.| R
'M ~i
&NrJ
62Lm
uk V1
nE_2
W1=F
t3w2
[ ot
"!TI~
aXI
+/b}m
{SUF
;, t
t="sz
m/ ^cR^
'I/g
UFkNow\
!nq.0
+Z]X
M2C.f
]I!
@dzy
0-`@
^~/&~\
r#F
esKM=
q <!
.n_V
L2e2\
'z#ai
R4~G
LY3Ax
&S8u
WJ "
]I!a
NHD:
(]wuh
tVjW
lW~
"+R!
]X% '
\BnP
/{P0
:fvU\&
&~AL
[.F2Y'
b .:A
7fsr4
Nn]Y
?km@
@cEq
jMg
d!nkwpll
~'.<x
] @$t
9&~
:FYX
+ sZ'S
FailFast
5j=<?j
vRa \^t
NeRz
2Fz+^
.|ry<b
C9zDl
lni
"Y;_
<S_m
RpjSx
{91Q5
}Wys?
[OH11
cCh@p&
ybgJf51
pn^l
IxZ7V
7t0F
8]f4
B,NI
nRAA
CB\v
5s];u
]kBE
hO:_
~@!fy
Xc B
lUs-0
=W<W
'QbB
vU &
LPF$
t,Y.+
+#.Gj
AssemblyCopyrightAttribute
[GpCS!\
{*H,@S
Sw#'5
#&kD
0mEk
;*sUg
5TfPYz
xa"K.+mn
]"#q
3~D\
[am~
;f >
&,9\
cl Rh
yo$v
cmaxv"l
e ^H
3v6~e
|G/6
lp )
Lvyz
M '3>
U[45
6Hr1e
* h
gvBgJ
K m^
rVtLj
5v _
Jg:_)
,U4v
Kcz[
]\"`
Tx %
pExy
lO%SRX
!H1`
p-DF6X4F/%
lP3eh
M fo?
U}ht
[ju_
,d@X
k/E)
nC^UJ
|q25T
ay^=a
DNSG&i
R7I]
Ql ?
2*FY
391 "
ttOo
8!NV
2bMf
Q]\c4
+a` 'W
{gS,
CMur
dMK'
p0j_
N\k>
v81[
.7Ft
)? c
\;~[
63M$ e
<C}DF
5K'=
6BXiA
X :e
Q'?N{i
KY<a=
jB9$|
z,c#
mz^KY
3c~@
+KK
YN pT
]_3F
AHGg
!.T6 =
U( 8
DO^
ZLETbV"
8I7
yB_(
R[NIS
p3j^B
k+k8
9i:
A:P3
2PiQ
G(#1
Kr0T
5)`N
6;Xs
0dRa
6KSk<
r}h@'|
s9MN+5
q@u7
N,Li@U
"s,g
hi{#gc@.
2M 2P
: J}h,
H4A{y
5*Gec
I)9 `
awA')6
a=MA
Debugger
;PT1_
j}3M
{,!N
%_2D^VT
HkUoNg
r^)&'
c<9`gUe
V3#&
\H*M
;/,R
@cG8
vE@l
\b#a7
owSh'
L],Ov
WgGZJ p
s4P~
?Xyfi
PfoA
T4;i
TAdu
`.rsrc
4/H}
Ic0U\
4JU@WA
1ZA}:Or
R|nE
Q3L
k31"
BYbim
I}t(ct
\'~(
8@=S
J>-gC
b0^mN
Gn_P
U3ca
HMh+,
>-~y
CY>D
"qlT
m'$d
^~
0cQcq9B
y BuQ9
6$bg
ob^#
6d~2x
A}RtU
r OSu0
v?`EX
ubr4
-<V1
WM v
, VDh
R.RL
va%]mQ'
6.INT
_VsE
R)FX
q[ y
I7QC
C[fVd
%-tp&.
*ZVE]
?{[&
<*k
kxL
i ){
?"f
ChY-
>VZ?
Iw }
>.Rjwg
NFNpNKNQN NSNlN-N]N
J)+F
-R5&
#+#Bq
Y ^L
\\n
*@8jjq
N#yPh
gZZ,O
i'TO@Mj
I[*N
\fqD
7D|Tqtn
v2.0.50727
B-^#
qglo
w<]
5u'1
'O3ea
BNiSA
,hyv
nSF$
L]o?T
N,d,
[%M;0
!+'t
GR i
2P~-1
B N
gYY<z4
4 F#
V <C]
yd-]
opnV
hW0
nFB-
I4RUA
6GvU
<n( g
OAP _
l/`F
34h+
mO4F
_?rF
ULYu
R+w[
Lx K
jUNHX
4 u9
}-+6
p; m-
&Oq1eW
k[P
hhV2 ;
%G9T9
\oHwn]@
q+2uO
%`it
Q}05
z7Y|\`
e$ty
dWr.j 6
#_ =
Z{-$
Ho]?G
e:A4
v:aD@=
.5,[p
=fgv
0VY*
[7+#,
a4K26(
2@}#
XLR
]?J
G2X s
dxq`8hIEh
UkX4S
6 37
_-X}
zkY}
`&`6
Ih-}
IiR$
Gb,6
y U8jox
~S#
YZm3
Y8J
hk@^
{I'Z
SJbA
">oO
cW:*u
DT1W
#Gk3
jD2j
KDMV
[o0iJ
;DWb
.P}'
kV58
%`h:@P
4XZ-
`uIc
*)' q{
y6p0
ey%y
q@-1
=E0a
h41rtVF
gb,[
P{{R
|)/{n
xTP=
:5Y
sF9 3
'dUr
#3c/'
78^
I+NZ
]~=
1Zy4m
]>L~
&okKzBr>8
93,kQJ%
9|t
K0Lr54.c
5IfN
7q/07%
&#xiu
zgjzc'
!oRk
FtZQ
Bh;hxs
NY
0.B]
.m44
b))Mr
@ f&?
U6Oq
^g9kY!}
1F3X
j]0TwL
jW h
J;<`u
Jdf(k
f oMS}<
3)p%
g5H^
=lv5
PM]<
| &d
/ uy
[C-h!=
;a"<W
||vl
7`J49
ps\
Yy6Vu
MrCS
D:2!
r7tY
ozx
|XTLb!dd
4 (
^Yk~
d$im
c4 qS8
Vu1 o3
{m=%?
C4D)@W
?Vj>
qk.K^w a
,{5:
_r0KL
0C~z
DUm;eQ
O\BX
(xTt5
YBFXZ
:X^c
EG*&
yh:(
;G3H
/(pc
'a l
"A&~-
j2L+
:P<)
:rqk
4}8U
h r(
{?!c&b
T+;!}
EV65
Z;|,
.(2dMlx
&/xe
C&]c
N,Ls
$<U9
s~a,
k4l
q7l]
Yd#V
4PSe
X,
Tf.?
izO)2!A
+on>cbM
& f-
c2-:pi
UPcm
@#u }
R@m[a
xCYk
fkx
Mc7i
VqM5
Jje,`u
vlw{\A
q[6`
xg3.
$;;`
]L]E
p6'
"<.S
{GI}
G_Ye
> y_
wU.C
6l &5
1Vhq
B4k2
Z7[049
>6^ g
Goa,
i3e'2
^7oh`
' )N
6I<2
Py8&
fN~V
= ~>2
I BZ
`CpxM
Cb?]
Q*JR
A x5
&o fD
U::C
x%_6
{!)J(H
rqa&
8[k
j,jo
:JaA
],C1
bR-p
?L_ f
+d*!
h486
6_ta
Tro^
etwY
?k)u
X+h
agvy
fyPyO
jzlx
d\GmT5
-^C$
hl`
Jbc+
j|vj
>aD/
^ ]]
tY
4c<\Z
=8"@d'
IMPG\
= czp|
l/(.
!\Zc
?-;6
fw _
8(?l
"l%l
>3vZ
eQ :
&HYLc
_CL
qphX
6zG
$pU{
Olay3n
>+J|'
)B 0/
U<_Zf
K`M5Z!
OImS^"
AUQ$R
kAlH
(F ~
oejG
V'^;D
(F g>1
Jvbv
1_y!Z
h:\,]
TY8Zg
7@`h
X)HG
^pO8a%
Y}&O
=?s
uyW
?u*Y
$NloZY
&wj9
XlvZ
N[zG
M Ry: @
WB1{
Yx'J0:
z)Iv
bPY
pB^D)
xu*K `
A Od
Q&#M
VG_Q
9|h(*
c:K
{UCm
rd/xCM
#cKy
|Jd< <2
N}lS
]QAT
[UC|\
n> f
i5fL
!9V#
qOT5
BwiX
FMNL
oaxfv
TbC
9{Zn
K@zu
=U=*
50+
d I !
/W*V
?#Pq
?"7"
Yn'T
,86Jh
n[O"
s7xc
K&LI
6]]
%JVd
it)K
u1q!
F Vp
;#Cj
~d{~
-M#i
#)"y
BDtO
@"nY
QY/Xd
* y
>'C[
c%P<
I(JX
90Sg@
SeGa
}i;Ws
)"BZsr
Equals
uv#<
SdRx
bgG|
xB-
GE4@l
m-Vy
Zdi$ s
6G*S
3fUQnB
h` \O
Oa41
1/f`N
Ak*x
Yks+qs>
!hji
)7S_
g hMl
qR W1;7-
C}=@}
V?b)
%l8oR
1p^w
n\b
gj\^
sgPG2
dPP6
!mbs[
/ x.
!@)(_
]w]H
Ew_p
@` .
5x6*
frs(
dP P?
+6NR2%$
uZ9V
=VP!\
pV')
P0E8
oWXEs
8Sy[
a1;J
Uyh>
P *d
A< l
~ f@
p6JPP
H'Odt4O
2g08
2z;>L
_9'\
Y*w0S'
_o 4R0
QPg&
bHwz
=Q:L_d
n)#(Wt
} mO
$:GN
>4hjDU
,K :
xnQ#4N
,nry
} Ij
E]d(
MiT[
.Py!f
C}vf
#`6vH
A94W.
J]qO
JQ;F[cTG
)r e
NbN%NMN]N1N/N%N N^NiN
tN'k
BS7v
^8~E
ucw`
>ie?
0(lx
eSS@
bHwA
3&Ud%
-<S<
gbfeTa
8dT,
hv5`
| l|
*Tm@
$p}J
N4N.NLNyN NwN
Zc3Z
u4!>)
_sp,
1oP
"AFW
{V_3TT
F*N3J
YT 9
w$;^
_cu^N
xaq.
S\@7/|
2]N$
Q kr
lKKG2J
k94%J
dq>in
=Rwl
59%c
vk|R
.S1
iwfc{
%q 1)
llU(
? 2ic8)
%*?|
5SIr
7*r*
@5uN
aq/x
`%Kv
>; o
A t:
}@W)
lSFq
>K f
; 5y
'UtW)k
*}
siA)LA
c+61e
\KDY
Qn!$P
[%H1
U'uy
6R1]
jvL:
NoWB
cQ|l
)Pz\rUN
T1\
H)L ||>-N
9[W]r
u|y{8
$p?_
_OWpc
KZ5(
l @L?
^[Xq
db9
erx!
h*.^@
+ z
kk>5
RwU#U
\tx
?`d+
yo&
*gl3%
E E!
A(}
',/U
@iv\
G^.)
[ <B
Zh#5
~4_ 0
o-LD
k/$8
pv5W
.}MY/
f5U6m
JMj1
E@]'n
D}Y8
Q^]L8,
GKGk
? 2&W
MT;l
NT,Pk
;RC xX ,
[zms
UA_c
8MC\
]*Lj
D8ZK,
[<vO[
7S1m(
sm1j
R_ak
^ C4
C\ |
dmE=5<
G8m6_#
2p @
e})m
E_FP
TA:T
n`b(
q9}4
UX_BO%
XYfL
-y?)
yhN;4
y4ke
, ?ke
<\}
\$qo
{%HC
K'"g7
7 wd
^GI9dLK
IDFx
+,k(,>W)h
BGPo
5h/U
LG9"
Y$#X 2M
w94=
q4/P
y4k}
6TT?
Av [
d z%
vQM}
:CF&
9tGS6YTXpTPVDe
CxR
mc+x
[ERd
6Xeos
-f6V
:'5N'
yBliGvTcq
P1J/
]:Q7
8?8!4
m&;x
Y")
F#OY
D^ n
(@z.1
r<5pH
#xKZS
AzAB0
c$OJ
0$(P
@Ur*
,<.]
V I{
O&t6
P&oM
"5`.
Gbf\
k1}O~
h|W_K
guS7CS,!
6"!
]{We
;=0^4
"?J&%
jTOJ
0yyfA5k,
1Gv
#:3Z
+rzI
A`Z{
x*v2,H#
Ba G
,;a9
i#"s}"
:6f+
4q.[
0r[ N
'w?<1`
bdnq*
QH(q
GGS\
:<-m
;Ko}
#oEz
osy1
9_^?
+G*I
e(j9
{;m Jh
cPr
8un9 sB
-Xq4QC
)jCS
:aNe
PQ\0
YmK'k
Sfn
]o@2
i45C
&9%~o|
Iccp
Pp_M
KW@z
tL:"(
f=+"IW
DhR<
Jj=8
S?}\wj
! oJ
6.Qf
>:eM
Qo&:0
ha]EfnJ
F%7Cac3
T7YF
h+i3
^OE({
yw}Q
-W{
^QWDBBR
P "J
=drwH*
ij
=S'(L
c4G
WF8-
>C~[
A*B$
aXOu!
"I 9
jho"m
12P5/,q
XIlB
{$#?
5\o8
G ?W
5<Hw
tx@3
:lae
qA '
W 7u,
UesW
AW `^nhh,
0P A
fImu
31%r
x82D8
|<W
pX&X
'%\~
o;n
Mg9
"'+l+
sc`F
Q ,H
~@HC
[hA
/Y
ic>gu
/* Jo%}!>-
kjE6
V~ew
Sp.Z
^Qmc
v|'o(b
p:(%u
Bp<X
ZNAv]
iE3a#
DpF[
skfL
Rbx=
gR;>
t8m*
S"{&
@WE
3x'M
S_s&
xv1&
<Hx,;
C s(y
|jFz
%#sm
% Oxt
:-,X
d@"\P
$(s#V|
tFN2
'$\q
?T[>+
4V&V
C Go
AJ.Jm
ez++~
:3"st
f*wMWR
WRh =H
s du
G)0N
\'>6
WaE
W,K]
c?XV^s
Pa@y+J+:
4j`M
h*N<
!xQU
>}FH
DK?F8
E v)G
[9IO
sK>5[
}g&Yg~
uk17
h|f>w?
0EZG#
E |n>j
!)Ht h
zF:&
fg[M
8Pb ~,
!3Ty
,G%k>6
Babf
(o,_k
tFNv
> z1h
Sleep
Cw !
/F4T
=[d^
`SO}
% j
VW0 I
[v,p
i]My
[{34,{.`Z
Ul5#
E:lY
PZD;:
>J,
}h#}
8hPC
xR,#}
FN>Ihf
1;KamD
gH;p
_ ?$J
D@E[
=sUZ
w s6
l[ ,
N,N`N4NgN!N,N
XUz{Z z
15_OF@
B{iV{
r'h-N
W OD
YOoL
z7>9
cj93O
_P`W
U%ey
f!Gs5
vDJ+`
Pmx$
>v2(
=\^D
nh,R
O[v[B
)]sFv
bABU
ry19+w$
OB/ }
fzl,
69t}i`
4hdm6
b ~{*
qni
d 2,
dLq 8
uE^+^*
,D f
l3](
\dCdW
$5}n
v>4,m
"o|s
u1jo
IpDmo
1E7V
k$-~K
OP?Su
T,e)
Ot8~
t>ivb]Z^
_T4*
d 2E
c9RF2Qe
1z)tak
w s{
2P70
\@7D
P<'6
i+%~a
u Y'
B0LpDD
cm k
}k{y
DDNw
g: 92^
SqV[
y`S$
A$$2{;W;s
BXfH
9?Vl55
PwK/d
I|bMn%
:8'h
Q;eg
9M#?
0<oi
wA.
l|Ii
5m#J
P]h')
.zJY
G bn
6tWwZ
}Bq](X
BEB.2
Rv=oV
L~PB
$p_x
&hl|
oj{g=
3k$2
F9F|d:
QB2{/
Tn@lif
M~ .k
K, &
s KRCs
#>ik
#I\o;
z<$\
f;32NF
IS)&
Vp5T
m"Ox
>j^8
5Dk]
8[g R
;<.c
Zl8c
s9IHE%+^
+|<|^?
gq V
ka#+b
rW,;e
@gP(
?>W
NJ-
Va]@W
JL~}
*rX8
+&~QE
!PM4
Npdc_
vs/c
Vtaa2
zis&
2??Y
0Pm4
rb0N
UmL|
EiTo
ny@U /
k8n<
#qe%?
" hz
cAc0
iF8I
yJew
pK(QI
\LYU
!b^7K
{X=?
}Wg{
VX>x
[pfY
9l
CKT/4S
=\bx
))&g
Q &
=PGMM<| +D
9nXs
W7 h
i-|Ls
c'0q
3s g
w6W$
+p ((
T4)B
YfBb{2
W('[
}uR1
c++T
he5ZnE
+778OQC
Rl5yR
b#u/
Txp
aG;b"
vK]5
d%pQ
Kt-bW
g; <
/sFt
g<-<
1{V}E:
L/m]s
)s,Sw
"!*Y
6AP"<
:3GP
x*9|
K/joy
~KL0
=%@
]`;,
pl3oQwj
T1 5
'wW
YO e
\:(A<`=V
)myj
v0]&j'
R+~K
tZg$
z$~>_
Q3ha
,Dh8
d-\/
r87R
Sm^NC=
GB+j!N
KOHN
:pIp
Qbv,
k7<
asA$4
)R]c
u\E6
j@/J bt
{_~es
|,sj
wNWf
`w; ]
,UW(!"
QI6i
w* i
m/1{a
4XlX
E1"dY:
m@xo
E(zG
6bZ%
3 Ru
!m\W
Kpv|!
^2t(
^klY]
_pe7
ik.&
8,vR
L<0P
c]Q'o
rrf^*F
k_dAt
X~Pt0@
\H1-
m(.
N,NiN_NhN"Y
C>\d
L)>M
rX=
3!O!
^$}NE
nB8v
E}m6
]NVB]sx2o
<awl
wh_t
9=0
l9r^_-
Vznp>
c0V
to^)Q
}rqe
<blj
$2HW
zzX4
%4V;
Uiyywg
oPS%
2)9U
94<
6,C{7
ei@nt
?D)q
~8xJu
h+|s
gr94
77<`
qv+s
\Y0^i
KD'b
URK#
SPt,
98&^
1p`MO
,}hD
~\ d
PB@7Z G
`Gv>M
mA<1
cc?@N`
IR{q
CmB)
!y.?
S\Fc
l=?
ZIFc
& @Ws32
Jt#3
xZ_dh
HX}d
D;?M/
^.^;W
VC cz+
PTEn
mLyMb
}Gdq
hz
v2Z]
9jTpn>-
nD[y
Y* S
{U?-
^a2v
%L V
H|D}9
#S* 5
TS},D
X8{C(6c
NlNLN)N
eP/
G(1:B
K@B
x]';
NGNCNQNANANuN
QI4!
8~**
0:u"
|dH
k;e,
vvE$
qlxdyb
<0QPR
0hJl
@VGe
LqC
Gnd*
##S1
O2Y~=
:S<<
0+oZ
JV?+
.{o_
5U.I
>hAA
x@unT
%[C:
f#wr4H
&g?a
nmX$
$U_3
yk#J
z OM
2,9>G
;J1p
mXx.s
._
Zy/"
;Dz-1`7)
HX<
q7-<
P3f:\
g!]F
0w[
*> f
BkkD
}*b^
^-o\
mi }
[<ajE
uOZH+
E0z(U
s+-quR
-6i&
d,!!a
=E_b
)OMI{
e<Rav
7|G4
aP .
`<N1$Z
hKf`
N %lzW
R t'l
u!/&
nn6T
}HaO
5 } j
UEh!
F\^c
Bt=!
uV Q
Xbc"&
k 8'
!'oo~
tj.C
F72e
4$OAh5
rY}|
"'@|
fa1n
2nCIk
Zd%|
%PRq
~$X;
w_r*
i+NM q
w~0%[
%H^p5
HolY
e uDf
k~F<
P%d1".t
Wx=WR
#4{IP:W
FQ 7R
TjM&`yy
35kX
uMd
,mjd
Q}0G
x`YE
cX;Y
3(Q-
NC*k
fV ')
3Cl[
fm/r
*hY
M4Otzlf-
%RqeD
94>wA1B
aCAW(
Txwsk
?L!{
if5I
TF?[
V5~:
3&q L
= zhn ^
3 2F
2!GQ
i0bD
QqmQ
b3zp
,G& x
;F?pA
n,f5!
|@ E$(M
),27
C|_
gs-
P7RX
`-AT
=iX{y
x9r%
*ZA;
w&'dA
a 'F
@64w'w
}k@#
z#bW
"S);
NkM1J
:|@Nd
#LjSEn;l
$'Nh
i^%x
ZUYc
,)6x`
XRCR !
\A=d
"_r^]
g%dP
+dVF
pswP6
OJOE
lq[
EOS
.}+mCW
Y'o0
S~x)&
z:zn
o84MS
5WG%
ontm
A$$ ll
U_ @
b)dZ
?xw8
h9Rp
}iZL
Y`l'/
%]B#
get_Name
\4 RnC7r
>1Y<
G BDV
@vr3
h9Rd
Q+k?Q
MN2_^
&0%t
]E2'
r-1
ltko
EXMMH=
~O6`
+VEd
u\\@
i7E<
ZA}r
HZVv?
a")S
32&f*
K!u
Z6+
\l8r.
gb M_
2~m
] ^c
=osG
TjR
J{}TV
_6n?
v}!
SaJ~
=_C_F
-&0?(
V3LY
=y8s
Dj~b
oF1w
;$L
G^Gp
|W)C
Cql@
Lt*ow0&B
nPwyy
.s%e
-tq0
e x9
u29WjS x
Y_QW
0}5(i
Tl.
PK 1
Jt[w
]XrD
;iFf
Z@Xw
3n0+
gnQH
.TL
y-RR'
!f9N&
T Ig
7y^p
L)"
}Ft`
]-<
96Je
:BX(
v!:$
'*dfX
40F}
B*$X
ArX)d6+
*s9`
cj+O
!WT\
7qK#
*`(Q
Z7 &
)u5\
'VVWY4
aO_]
jf \
Exception
{*LRs
Q7hp|
YNf!Y
n3>NE
#E"
]*3E
2Y|.
7f1
:ioLy
6`W
P/eVj
Mur/
RX a]
.Z]h
j`a;
,T^{
NOt'<Z
uQh$
mJvo
xo]5
-^"i4
Ag&dD
b82g
o$a9
DH'q
G-cA;vC4
d v;
`b<]
U[K2)
">c^q>
fLNUx%
&;UP
^jsUQ
H4Pz
y+ /
> HQ
#p5 L
0&Ui
O,V7
@wCEsFA
E2.('
d#2 :w
MX k
:rX.
{#%G
r=F
8ss3
o 2{I56*
Nf~\
h( 8
QvSH
0~rC]
] Fb-
?2@]
) {Z
-.Ku
ItmF
AIEn
Mdcgh
4Ta
<j+q
x#Ru
+Cw~
&xG .
,j)
<I'd
3,D:
~KB4a
/p#
y<-@X
7QFK
h<uZ
Y2!3
f O _
A9) T$
eg1tW
%b^jz
qJ <
Kn$H}_
&1[s
}!XH
pKr
~S'U
J`~n
cn5hR
i?8R
(HV3dP
psw}}
5iV:<V>
N>N NQN`N]NCN
?(x3&j
QgD=]q
IsLogging
;o #
.{4O~
$0nbdP
2!Zn
>s'^#
dQ;:3C
s{*
Z9cy$
NjN{NbNvN9NKN
y4 s f
z\vg
/ sQ
29uOY
IQMeE^
ml?I
ep[&
"A< D6
H:s|?
H6NtN&N
6I$Z-
k?z|
v[9K
5=zsJ
nIj'
,H {
_~o%a
Jkb1
^A<>-
6-Lb
q9\$
A<)
2Y o
12-'
RuntimeTypeHandle
]'tE
N;NFNaG
6r a
'+.%
NYE
4Z3_
:Ir
TeFph=NBa
>CuI
'c_,F4
Xd9T6
BTH%
#`nM
mlHB
xfHq
,n>e
Q#^,
CB\P
J{_Mv
T3s!
^$9=`
8 @`
`PR1
4 yq
d@7q
$g$6
Xks:
ZBTb
03Iq
VnOv
s (*W
|ECn#
Pq!U
mQTR
s{]O
dWGY
KxS0
(~p_
T2AE
,]@,l&
aXs:2
KrI]f
l)a-7}
3iXZ
_vB@
]XQ9
2~c io
YOi`
)9@!
*nS
0+e(
Y~?N
kernel32.dll
.zC>
5v,qM
W;J'y
kC^T
@+)e
M#|O
<35z~
osX@
Ph@
S`734
I(*2a
l98
KG8|
COo4
Z~T$
[T {
iEBC
FNW|
W=28
?_U{%|
G]C!
$I3g
VI+"
SuGrt
q\8Z#
}71{A
%;)\
zmL>
N[NFNNN;NCNrN,N
d >-
iMwE
X*qK
YOi
WNBb
@;|s
l_B`
YBa~
W(~B
JJ;n,
-GJPv
] (O
8<}*mX
Z@i7
7yaU.
SEX`
m5q4 F
Ul7L
Y rq
Pe\zsQ
,98L
2l@h
<JQhY
7mgP
jubf
dS#2
Z,|'
*r6O@
D.*]
X-PJ
+AMV
p*zN
<Q>@
W 1
pQ1+
&*A)
YEHsF
^#8
MR`<
u8%\F
;@ M
JylF
}?.-
zGp~
hEF:
*|S*
+H,&_
EE(H
Q0BvhuU6gTbUHApwB
H_b{
M#-[v
a(:
b|az>
\MS
O| |o
8,O
ew(+@
GWY<
I w
Oh2-
a`8.[
~UY)4
c^0d5G
G2=#
~Ff+ e6
Y/\;
}7NA
Bp F,L
%S52
XgTx
^DTV
"eW
foA}
l%Lu
d30I
wj/3d
*Ful
A]MY
Y[J)
*"4
+6Ud_
{$?VSy
TE7Z
E`(?g
H ^6
7B9Lnu5l
Eq~{
dt6i
07]'e;d
!t7
x7ep
-G#_
EDtJ
Xvxb
EHe6
}$E9&>
5`4z
*aG
w><+
`+-\
3e<v
K7 >!
M4px
NSNcNfNMN N+NnNG
q[Ec
q5`C
KP i /e
JK i
m%y#
D8?6
>ES$
+RZS
i ,LI4
OH=fF
](sl
B%>z^
o(=4
xj
Kj:D2
Td|
d%biD
l &k
N#q7
nO|&7
2#/F
|Cf%Z
b`{(g
{?aFW}
FB_VJ
ye0g^
=iFq
4@>JP$
$,D/
i{XM"
,%t
kR)s
u}
x6`cC
@^Pm
kJK'
m% 6;'
lnG'
Y_n@
WLVm(
mIZ
P\e.
6(wG
v)2
pDNi
s]jnn
}6P=
]E S
/TDk
rKd w
d? XA
EoL
+5Q)
Z3
6D N
WnKT
xJk,
xKI5k2\
Uy~H%W
t 1fv
^ *'
]n'7
vT';h'
?/FF
m".:
+'rDBG
NIT/
o?.{@)W,1
J(j|
:Zbn
z"n %
9HuM!
5nCP
rLhP
dw=1
S!c6
."BT
::Vkfj
S}Li
kIc:KA
zZlV?
X((/
Zva+
, I
7+p9ma
h( ~
H "
uk6E
midE
vd@!?
3({<
!Ow\
=Q
#L$&
2sH4
j~%l
'2d; b
BI2X@
=.h!
l^V4G
P' rp
b\d7
.kac3
~ *CX
Ga0T
$/$
g7Sl
{7v0
s"XL`6`p
Yc3Yv
nc86
=`:#
&>_
Y!v+
4yu^<E@
k?1Uti5?
V[V4"z
=3!^i
.P^]
YO!h
)L)5!
L;+T
~J4F
~(,%
%e)0k
6hHu
^("hm
(b7U-J
sLJQ
dC[ p
Ekhu
MAFf
_P|*
a-KH
ECDo
,D8l72
1) 7
#&I
f}G;
(6gn*
6A$:X
'EX_[
?9z;
GQx7K#
C-'m)o
NANAN
6VH+~g
.Pgv% lx
.%Rjr
s ~(
Wg6
,)BE
:cXP
2{>6
sa9L
>"LT
k<A{
*~1
Xoz6
XcA9N
fkMw
hb>v
O03S
1r+x
^C;OK
+W+=0
`\q
Z<'=
j>\C-
9.6|?g:E
S ,{
\MFA_
GAF ^
KI0d
2? Z'
{Nf/
F~%gv
(QtU
<9ak
]riC
Q(_o
5<4P
I5UlR
Y< y
b'cW'
Uv3=
N 5(7
kd-5aO8
[VRH2
^f1I
gPevs
^`>{
>ww$OG
MM2c
c T:
j]O g
f #
NF>9XH
QP{)
6qa<
.3.\
FP|H2
UjS`
EPNmd-
.-QfR
lyw!
^D `
~/G[8B
,:+SM
Wt)t
5W= |
Pi];53
y2jW
j(_"
DbR>
mEk2
wc)z'#
O 9hY
7VL
ZUw*i`P8
0WX G
X,?~
z=z2
m\pli
K&n7
zgaa
A_?1
`[K-
\ r"
cK#@
N#N=N
lFM O
tF F
8 X.
k$PR
VQ<1$?
;0j
N|*i
/+i&
,^s3}I
(B~
_v^
6l%-Y
X>b_uja
Od '
{r `
N N%N;NvNgNgNaN`NAN|N NDN*NaN1N
C,P^
}rJ:3
_, "
_o?:)
']\Y
b }]
'GnX
Od 3
w$dF
tWu@
|,n$8
7iP$
FCVU
=<1
F+zAS
:QOR
oLD&^
$.K`
8bRhe
S`1.O
aXs#O
N'#N
NQUf
mA7d
Environment
2&`Y^
z, s
vc~%j
u^Za
T]Fg|2
$Bor
#4R$
xSKB{g
>BtM
M^?:
YM|K
C#T#p
F P&C
3mDg-
cG%a
1 Lj&&
5 8
=_uN
xY$|
y#=(
+idP_"A
jcn\
?%!
w /c~
IJ!
@QJS
1[Y2
E)DGU
OHQ.y
Su4!w
CT$_
vf 6*
_%FK
o-^:0T
t"B&JG
<(IJ~y
X0o
!%Wi
WTwF
UUH(M0
T`9S
3 KK
QuTD
_v*V
[5?Q6Kq
Wmlo
k6cE|5
stb'{K
ZP9om
.oQ`
| )b
V.pw%
P%..]z
B97b&%Z
6? Z ~
FIi
C`48
Ccdc
V=CC
frg\
kA1 &z{B
sO,,%&
o W
Mjg0
8PMS\
1 |$
R\h1
\fp
qYjq
a?Am/Z2q$
}0y|
=%Lvt
CnTg
?\yzZ
/ PF7
2kL3
!1g?
3 3
k<$1
`$mT"
Z$B?
\=OZx+h
?Y^!Zj
ru9'
^PR4
* >I
>b<
xrvh
+P2h
k( (O\
NIN}NsN$NsN+NsNFNWN N5N
86kI
a/ $G
?/+
<zU %
Rslt
*AFn
n+:3I
#$g!
8R 6%$
M2@^
-F+oh
*74LXMqN
&.'w
x`)y
VyB@
Q8Lv
ES0Z
#XZWU
P.6dX[
-p,9[
BX"V
F6"1
?7.k
wcIR'
(7F>U<
~ W
2U 9
n CC
8 lrH
,NE]
g7rj
@h1T
Jq0c
[t6rc
b=0+
d=YI
cirW
lK?
fhAc<
8.$h
4?Vo
nz_P
6"SBl
{xk
\:st
KrA7
e~"j
_I:3
J*z
U1J+
Kc$n
A{0d
FR83h
5e(G
X}%G
jhFXz
=ZKO
<@U,
i+iz
7OK B
Cgv!Oo
$h~)
U<pE
<^ $
. hK\
@Oxx
jo=sK
]9Vor
"D=g
5"@"
uX9:3
2 A
rC}
WJXJ
DEg[
d<EL
q jK
l!adz $
wbSN
d=Ex
Z_|uG
-a %?S
O~>L
5Mmc
jy S
wt)j
8\C)
?8;i*{
)XO-
PG3
Ij]I
hlvZai
JNpJ1
@eO
G"V
5%
DVH@@
;q-w
a9% S
aB.U
z[Y/
r\3Z96
?Z<!P
b&Z#
U7b`
rd'n
LjH|J
||/#
an`]X
QeM~{
'HUNNB.
Cs)[
{ 9%
]50{"
g?1D
'kBC
<1i'h
^M<)P
>N=2
P0`K
jQ @
-:c{j
X.[a
8=K}
T>0Ps
>ZDI
/QIq
l3:7;2
SJ0g
R_U+
!-vWk
K< W
;Du:kZ
.N;n^Q
XLv7`
e]I6
s-VIl
k|n<
rC}w
T > d
U]=l
@NtG
Fq"Z
VcN?
VMRP
@hiw
pWzm`
24.4
~'RK
7]M<7
_ %K
S t
>CK4
q.Ba'
R|TV
+j&=H
UJC
B4--
9nIv3
$Q\^
]yXUD
1f/B)
1S! g
_ }Q
htCYa
u3|M
F~-^q
DkgV
1=}D
QB #r?
qk J
w-AXN_
@Qrl
arY 2
|yrf
[#=P
sax|
! Di[,%0
tn[P
W:a#4Om
zGV4
T>^u
Z[L!
!=4
RBF
5_<1)A
n<.i
W|q
;&(b)
)zLl
'yJ2k
<B (
Cf{.
\h"O
RC6i
mlJn
uWDt+
C2AD
KEFk
N<P.X
,Av+|
]-ZB
cp#
.ROSc/
'$jyP0'T
uLal
KPBV
Hs)^
m. >5
n*$hO
nyN3V=
k\jO/J(Kjt
ed,t
9.Ua
8B$Q)
VL 7
})^g
F/dA
[> Y
:w{
R`7
li V
%Abx}
)k=Y
P.;\
/qg:
vHxO>
+TQ{E{
<.2r
V?HR
^uz~
OSqu?
0k]Cua
(c@(
#\`0
I*C>
n!h(
Ko|H\=:
R<K\!
R >>
B~K}
#Od^
6G,o?fV
,+L$c
@xc_i
s69#[,
)JHL
K:n#
Aa_kY
uN|s
M[sN
}8qf
N+N?N:NdN3N
[Kl-
;=HT
L;j"*
tBt+Hk
i0@@
zR,d
2r!mpf
n6_e
c9;h2
g[X\
""p->
xVMr}
L\H
YV|6
Dy 7n
cqIr
,[x1i
HE8~
g@LE
9pfgw
~dx=
b?9q
> e%
iM\s>\
^s]UBc
&=9y
.t9;
*&!y
EC!
<psN
yz}gW
2>cuf
w,nc
kl3w0)
)3>
Xzszc
'lRBsd
A \@
Z4}a
K+qB
get_Length
o,0Ue
hy Vik
aT.M
:~\i
.W%5
z WTu)
9OxV
CtJDs
>|[.
5UtH
Q6:h
Ha %
77Et5U;
LTgC^
*B F
Ey}]
`N3b`
ru'*z
/A1{
xIiY
R; G
XBcv
Bvk3
1R[}u9
8>$>
{F-4"`
7b=UwA
`vc@
UkVj
O?*}
Ggi
<R P~
:]i
::SU=7
~_Lz
QUmA
#oHTR
hMMh
ctB
)jY|^
`l|R
gG*]&RW
5XX\U
z<we
al)k
#@\Z-
}b)7
k>33[
|np"
kN{,
n*O"
D:!$
>Ya)Z X
l%$-^U
Xt|ET}
ez9e
!0Jj
\R@p#
V)Ih
6O[
4{\
3BkbqvmW
h<O3
9jb&o
DdoA
+E $
t1E
(Ka,J
t mL-
Qmk6
3.4=
;Ez}
8U{,
^d%d
:.+i
~b4?
\WoU
:"e
u}xmCpb
0J6x
,$N@
T#;X
s1e~].
d I.
wK7d
48
MB]M
6l=!
1=gr*# R
pc3^G
~JO
7P;)
.lJJ
%*wJ
e68+t
fe
!B#mnT
$a"
^?tT&
$vm@
~za3Q=Le
=Sv:
kOb4
6Nzl
F#<<
Sgu
_<(1O
["!W
c8Bk
9+cP
j`5Acm
OQ9B
= 6
cUf$o
j;Da
1i? 9
%'Z.;
^\<I
@s'v
iV@}
szGY
xqV }ac
05?6
$d*;CO{
A.Vg
f?w(
Exw0y
g`6
G[Tg
5qj
G[\<
D]|3
(_%(
5p6(
r^
ixR>
Y3 $rKx
on0e
aH#93
[/\Z
}zZz=e

:?V.PO
G^mw
m_Y6y
Et_f
_N`9
!~ZT
r]?8Z
J?XO
.k*-7B
kXO l
t.G#U
3dSV
2pbK
cVFB
;^YF
QI2R
b/(0 w{
,5WM
k`8jF
x {u
nHfl
)[Da
ejnm
WieP
sFo^
N.NANXNYN~N4N
tC=5
N#_GU5_
|(`A
Z_)
I{-]
&.Q!
M5
ZY9*
J(#
:R\"
.= 8q
^\Kn
|uw({
Kx7SS
`Qlu
mVvn
+4)@
#&{Jb[
}AVp
@nzpG%9o
O^ w
X.Os
~iZx&
p(T
aNx
R8e~JfrE
h1
e)+Z
{cuN"_
?svy
Q 24
- KP
zV b
Hsqk
av"R
[_@ ]
scPU
xxc9
vh(0
7J>\
cbt1H
02O
&fC6
CallByName
bQwc
;/;5
q1cEu
0 oc
N f2 XS .4
}W3d
; YU
8m/D
mU|;
&azo
`x_g
86La
I*L.
"!V$
'5v?_1[y
F X_
B"&7
rR^\
2?<L
|]` $
"WO#
e {3^
%^6_
7:he
VO2D
43VK
-:l
TS>zL
j~Rz
uy3 g
0lBj
,`T!
H2f{7 7
<z$~t
2 r:
w/&~
901w
C3~
GuQA
WM#Q
"{G.
akmC
]
kvI.\~
N]NKNcNYN1N NON
^R/#G
z ,7
qp5s
/yW}u
Ld2n
$hwI
i9#Sg<"
wo~VL
uX>F
s3| %.{ L
{_2Y&
Ka]y>
7e R
!dI
w-g#!
!cA1
_E%t
Ga26
vLB`T
&fCC
c= Z
]PK"
# ^j
{ Z0
CV3Y
y6r
](E8
9irY
otGI
G8]A
w$=s
coN[&
/l8A
Start
pCo +
tq1s
< 3
/GXN
.:O@
)A;A8bq
9~[G
Aa:M
0:>b
<-:yZ
1m_I
~aAXX
+A?V"I
'Tli.
t27s
><,M
@PFL
As%
, MV
5Y0L
(AXA
KvVM
j*,^~
fb^ t
Vo\Ok
{nc
,<TR8w<
4s'M
T) c
wFy
B-K`
0v'@
HQJ}
^j -
dlf1
yE)%
ZVyWls7
m$k
R@Y0[
M._j
4@/YnW6
O|ft
wpP4?
@Mi|
<GA
3/55V
?m %
Y,UU
+ N3N NjN9N
K3x^@
Q tK
zn1
Eb@;;
CSPcdI
k+~g
O\]f[Il}
2Nq=
ASFL
QAZzx
"tU%
2 jS
DU=H
n4rs
pHYs
rWlD
GtUS
d>m"
?Rx#
A}U&}
Bo=5K
K"L!
D U?8
E;I{
I`GWC!
D}g];Y0J
\8 I
2RAe
g"XR
l; ;4
K_'
7AZ1
#<@u
Ny@-
)elSoXCS
8Kr
QGtn
-x
Htwy<
NV0z{j(mkF
HNk'
EwMo
+E/]?"8
1?t5
K gL
l/k%=
o'x<
/ s9R
Z'BiC;
fT~}
U^ Z
k !Z/z
q 46
+4L
:Tj?
r#9_N
W T%W$
=ZdH
G~3X
yYmK
K7R
s!
/#SL
=l(A}9!
D)Hx
c~s,
A+5<X
?-'[
|{]Y
q7{M
G/xT
JYe
5cKl
}tUF
c61#
"'h!
R,@uB
8{O=
p#~
ZJ=P
E}J$)tDB7
f]}5
Lgx6
LdF3
&[-
E GV
(T<p
5u1#B
.tha/
{:6f]
:4G-
s/ }
=#gk
>cVD
ts|~
xrU$
S1{w
6"ATj
uKy
%;G`
#TSXY
f~O9m
eq`(
9'kK\
xO+{vd($
mA n%
0$&#
ea` 0
B]4I
Ui_^
d'Y"
P>XJ{}>M
50G:9
N NbN]NqN%N
LvRN(
R%Dj
b;?\q
S?jB<8
-YF%
{3|$t
` >
,ig!
.o37
/E:@
'y{=
b2%gG
G:!G
boA
e3@V
N!T+
.X+b
w FR
MS)E
61Lb
Byte
jCmo
@fLcr
3rq+
*&k-
s&SwWg
J U
V|A1
= |f
7sb@"
y[k+]w
J$FLR
q)vG
!sBEr
~.l{
g4lY
!XT(
lt(
AtH2}5
jkK
U2/
kE]X
K NC<
Cg~C
Tz\2
7w t
=uPY
'0Dm1
&bd6Tt(
IW Z
W I,,
\Mx5
6~^3
U<Vu
=< \#F
S<8I
L-qJ5~:
sO,0
LZg
X1*N$:
[*~
mZ V
;Ac`
:B 6
ul`/
w%Bt
' p
rb:u
,I ]v!w
{#u
n^=O
Jkn$
0(:>
P|Ei
9I-vO
7*o
com(
qz_,V
J1iF
lnO(-
]D7:m
q,x
]8oM
.'.a
L?7s
U2\Y
3< O
qA[f
=!RqG{
a"-&
h8)pC6
lFDi
8>W t
^fWz
oOX= F o
Xl`(
+Z b
7LrqEB
#FR ^_(lB
i_*iC
ucP<M
Q:i.
!:5g
~sVTc
o%wI
K`DR
QeD+Cz
4nfQ
4;1N
CC"O
Ote5k
ur/5
C ZlT
NQNpNzN'N^NYN&N
JL&L<
@DIF "d
548>
@(id
uAc}
-PBD
!RBa
=1gIf
E?cC
z|<C
b5{D
'Rr
U f
^Qv Jn
f&0i}
X$UW
8]0w!
}'jh
vj _
/yJb
783K
@ya|
fFHi
ObfY
3WJk
Ql/)D*NH
d[8}
M/79
]tN=/
k! Q
9_mj
B ut
P Tz
uB3W
/h~6!0
|O?
Yt><%
eO"`Iw
{<}:X
dY$z<z
k&V\
-X4-O
:Qut
1"j<
!C%F
"YkH
%7:
g@;CP
!,Sv.M
8M ?
)J`(A
"dk7
QkBo
?60zn~?
||NpN
n+>\5A 1
6 N/N_N,NIN[N
uS:6}
l^<aA
<x=j
B|OV
)tjX
K zZ
cKh?P
.resources
AU&SJ
p8Fieb
$r&A
|X4'
dOzI
QrpC
-}Bv
/j-E
|.J|
mp(Y
z>{z
N/NFNIN(NlN
R!v 9
Gs ZP
b&l=l
V *T
ow *
XG[#
Abqt
cmCv 6
s~GY <
| VD]b
bwg4
F3 D
?tN4
s[M*
:(;o
1J2>
GgD`
=utH+F
!e6;T
,-VL
G.Ws{y
thb&
N7N;N
b %S
0>7b$
joDoCq
8R4dX
;OwfP[
lL1Y
h2p&&
lnp00Vv6
0^1]M
_>B"[}
wcsI
4$0<
VM^l
SI &
fq {
C[47
Z`V&
%z7x]
B]$[uV
q,7'
RrCc.5
i ^j19
ae8A
(NPQ
"{^
sqk|
E@*Y
c4u7?
=Ct$
/Vf3
3?fl
|6([
7I~|
V2b" B2
%)o~P>
e }^V
H[*q
l@pI
6D k
8??5
bcpKcb1
}`f{Q
?|H-z
fw6)
P3 j
I"b)Wn
hGm `&z_
]R#o
.XjB>B
76c;
:KD)
u|D7J;
w`p\S
W_Ag,
64NIYcn>b
O7f*l
0`_W&
M&"Z
G=>I
oh}
dT/:E^
YOe=
<Na?"1
K9QK
QpQM+=h/
ySc83)
^<FQ
/25kV
GuYX
;%$4}
4d&zx
:!! x
g55V
U'(t
J_9;
"{
H[*>
*ykp
XTOo76
? iN
<Y`-
;p=!vn
vT:,
tt0f^
t;]
^'3+
oEF:
'r$`:
O$#r,
*0@_Z
mO(?
BRR"
i~.
3H7xv
3P-a
wQLm#
%P>?
0sA
bdu#
J4w6
(\ =
3=DE
;\:I
{wHM
Lp\[
hq;d
jOl8
zBjMT
4|*r`<
k,.cL
L [e
s-`z
L[$&}GrD
3|[Z
[d:yU
0L2e
|J3K
S3g:
-t.UF
/M%/
\96
e]]m P
t\r9nr
%^E.C
lt:e
~V9U?l
tw"
e|%3
[)x<'
/O\o
eT~ Wp
-62l S
=)D6
tCRk
4(S
DZJ0
u6vJ,
}omD
{2BTk
vYz
luxRH
Zk/y
$:Q
0_FZ
zR[4
7Gle
avC 8
;k M
%;1*
w(Ow"
X<JJ
Fa5
jrhn
k1j!M+
,b{N
w ?+
E n f+
f7A0*r
frWLI
};e4d}U]
/HcZ
s`o$@
i,fq
Iok[
:QA`
fZRX
>U`pe%
U $r
@xOW
O9Xd
@UO~
C O}
=1u]
'gx{
j06?
b7mFf`
@[Gw
[*FR
zBN.
HkN?
Ht]9
UX(
> oJ
h;W"
!K4#o
6n }
-7 { '&
HNL/
WLXO
b,nhRq
k/Pk|
|E$'
S#_p
-7l8
:oiLp}
+f{e
~}$
Y!C=
Jt1
uq%
<WXF
f M3
u?Y,
%(.!
~q03
!=W9G0d
sV"~
li+Z
Y'P$
*I_7
WOa'
dyRG|w
)QXF
ukZ4
'+cK
/S ,
.!4P
x6 7
F TF
?acH
4Khi
|!&$
86wtp
_Q1
p^.C6
r)R9
9W|{.a
!62P
T mI
%^<W?
ePJN~
rwJUeVa3nLFCZ
SL(]
?bWg
R}du
D]jz
D3w+
5eKod
nZ9er
3)DM
N@/Wm
{W<h
,VI>
gIas
N6NHNTN
`tgp,
kus
Cn[B
{WQ#
Od8a
]<-x
C!yd
VrOM
-TG 5
b ld
X LO
ka7Y
)3Kd
8#3/9
|[?k`y
=Ymx'-^
Hgd*
&-8NF
cwF2
h<t2h
}Xx~
lM.}
)lj[07
7 5hyWsT
h[@C
tnLa
w8e>
<OYQ
&-^#
>, !
;'1nQj
u:K/!F
Waa[q{
'\kG
pA"M
1YICb
28Ti
w(DT
z^nur
1=K<
7P{*
5Tvi<
ELf3Z
aHmrAx
LG=n
Q~e<bf6] H
*RDE
a rca]]
XiM.E
FsC,v
Y/H/A
Tm O\
y/71
?j,A{!
GVnc
RB^2%>
`|Ge$8
X#]-
{ /
Z@" .'m
l3cM
O!Xl
;ii8
"IC
`%?w
}32[C
-:\b("
6w0!H
U.>$
czD>2
PuI;
~O \
uEuh
ja<V
x4`/(
fXmc
PocF
^ `
XtyG
nG:o
;(2i
iYVK_M
$d<Xw
oAp\n
]I15ea
><^-
]=,y
q'UV/
~&<0@Y$
q!Cj
tK?y
U<M\
,}bJ
1[}R
Rqfpg
Q6e
xJ\!HR
$V][+ai
"_\<
?ky+
ZAlX
y0}jo
Vy HG
Mk1X
;qR_Z
m_:t
g<Wq
WK(k
z/LC
L!T8
]UQ?
W(y
+% b
"ahX!*
zN{aE
zW#
hb:n
}\j:
}3sG
dJ4MNSy
pMZ"
@>/ ol
CfPY+
"@&}
6L-7PB
TEy}j
ZLsQ
x2iXO
$WWx
:$e\-w
|"crg
'eAE
yu?J)
0-_7<
j(c1
$9~mV
ss%Uz<
,) <
0|,'
o(m=
Ag~h
#O_KNf
acE{
0ny!
_s'g
v-\,_
"@xJF
|} w}
(`O{
Ui{$
iYE$/q
b$3k
P|bg
RR:3
#nibq
uV q
oOYm
5w"1
?XLS
7M%l
+e'ei
Ca%P
z'_?izA0
;R<q
lUVa
R5q'
q-Pv
Vih
W)&Yv
x14t
<>?w
+\9zdVI
b!
dW`y
mrobD
J6Ek
~+i P
_"L`F
+q;
@Gc;S
+j:k
`?RU2
B%SJ
>lu@
k-|6}
y: ^
lo 8
[sc.
8/tCB
u+;M
~+?J
K>" !L
0*tX
k#)T
P VC
@FU=U
Yh )
&5^Q
& 6~
3j*B
C i\f
8&b&
j7aQ
b8@7
;cAu
<j>j
uZRsj
##elV
4VP+
[i"`
0P|
:#C`
#'t7H
$?Z:
.o<e
MH6>I'
u,,7
uvSs
`hal<aX
oJ+-
mLf
;-@n
K7e=H
;) L=B
C,)
4*D-
FI"z2
5OG
xa}
&i Bz
{i5_{
^4Di1pi
~anF
,MA"
HRu,
l_iF
[4&4
Uo&cT
`U2l
NVz_
,Eqf
M>#D
0!l&
vIc4F
%TTT
}"n|
-,.
v\E.?
cc_ag
}Lc7
tF|<<
jUJl
jy-
s> l0
dUhC
!S4y
s,V
,Tk@
sZ*x
aI$3
]M*O*V
GoZB
_6!8
nWX^Z0
C0y3*
-XG
/=;>
)W!
T ys
kf E^
7BIiz
b\k"
XO 5
|]9n
7N^Ysx%
Z=+e2
3Ukq~
,5p\
;Z`U
(1!Y
Nl`&!
#`Z9
=4Kke`?2o
&XTCic
Ej ^
R7*|EN`l
Qp(&
\Q7y
5DIQOX3NWnsIsF4krk
,UHq
6%e)k
a%WM
XMo+
~/'5
]Dpyi
n]bf
>wx1Im
d%@x
~OEZ
P+u=<z
6vF8
]#(K
OX{5`
0U!=0
{aEB
r(,
OsN
(17{&
dCx8/
L0 E
A=z=t
<_a
]@2M
#5.#;>>%
K`(L0s
5I.OO
L_Y8
*s</J
]FbA
+`9}
p~;'a
En=8Z
2jww
-?X|}
| nV
uhk[F8
R04e9s
[gm%Z
o('Oi
z^rI
{u9Q
'/"+
avB
_C!x
J4$2
P=6$
ADFh
2afsJ
^dVY
7r>.
})zmP
ael!
v=C>
y7B'
Y#,GV
T\)|
=8}R
M =~
M,{-
2XRE
o)`J
=2gQ
5.-e
4X.Z
?PT
(cA*#
W\dz
{bq)
$I*<
wr_2
FW?d}1
R45b
R`.dp
Gi{z}
?-S 6
C;H~
viD rX
yC p'
N-rv
iO~nU
|M/A
W/aS
R>21
rlW#
170|
op_Equality
ZV=K
,t k9
spY~X
A[~Q0j
2 r;
WYt~
{jb J
dWP
{~!2z3
=giQ
d*Fr*
2S<qJ
kGn&
(s\P
GZil
'u~{
wGlk
qfz3
Xe$"H
9%Msz
EKY
] Q
m:-9
NZGu
~+MH
/ K#@)2
N~NPN/N
3'S_KI
Y8h,
YrDu
-S }?p
l+v
a;'r#w
_9tl
'~"q
ziD1
q|h#
;85Y
a8v!u
&$98
GAe_
p!Ss
E-]'
`"Iz
| Ftq
CXLo
L V >
%]4{r_X
vUpImw
WjsNc
Q&M
0 #jm
z1y
A:.h
.:#{Hh
.c;;L
fbh*
y"P
BqmZ*
\ f^e*
/D-I/
i{q{
M*<8
<s! Ew
[Rc
+o0z
EK $
!f{+
1l
RP-,
F^8&
7]\/
<wP7
,N1Y$w
145
)_~GiWR
\OpX
ZBw|
m6^a
FYV0M74N
XM@,
$c .
p +
%Vq[
{L4G
TWM+
| S7
b));
<G|d
qW Aw
? 05
@a=Y
PBPC
_gJ{o
FGaG
&wq"
cw[Z
Kn=k
^tl?=
p;o2N
c|MqT
jJI]
cRnJ1
%K\CT
YVuGL
{'0~
)[k
Yw5WBL
HTPj
da 4
Mq]61
lHI5
/IeH
~meER
|uIn
p1}d
m0;%
aBE
hS^-
Omh<
XkI%
_ g7VV
yS>C
e>KRFt
zX]S
Xs3K
Kdy-
MQ$C
Y' #
jk+n=
0Tep
=x_B
Wm~Wr
TgH5
A]^DI
#} N
2YQ)
7w 4^
`gje
/{ oo
u`V"D`
1#vHI
p^ t6
\`.7
s Hs
/O{Y
get_Message
')f~
\YDR_
jVmH
9^p
vB%"
l i8M
I}e;
`wpdj+'
*" Bl
=zAv|#c
>sd*
yVb
PNaV
@KZ(H
,NE[w
t8Z"O
r'c_
=7?7
t00I
/,Hq
L@GN8*
$%"#I
v/ l
JDR
|o#1+
(bE&h-
Ze4F
{Ql@
fc4p
(\=l
+C|[.
)\T[E
l&S-9
a 4
|CEI
X}D{
3Z5-
X 3[
X`%g7=;?
% e*!7x
""[6
5?E1Z
$'dK V
rx@nL}A
p\W]
@ ha
6 C\
qudB
_ 8V*n
TX%`
6S1^"Q
L Cf
w ,<$
^b3
4hP=^
CSXT
;w5s0
th}
S9R%
Xsnak
@1lb
=HCb
F_Qx
R }
s'?bR
R+V%
McN9
f!;'
:ez3
}Ih#
i9MWThG
Vh6w
-;BK
Bg!l
"sZD
Nm|O
TkN(<
:6V^
+Dz,
y i"
FG k
LMYY
?r[!
zj|WJ
%|$#->
rHhn
m ~l
'9Q3L
?\eC
]zzr
\ Yl
7y$HN
u# <
I1D=y
^7f!
}E6#
|3P
raP}
jzo@u!
XWM:
_?:
`Nm!
:Yp)Ww>0W
."L
9 <)
_4?]
}=6j
n]6J
BSJB
u[|{
WpD6
ATeUE
@5H`
$* w
}q7+j
j h3of
\ST/
P:.}
Xv'y
r'f\
hV!)
7G#oiii
ZR" .??
<"O~
% RT
j*S8
f{ n,M
=}'lm:b!O
hE.o
ihI]
LdZ' ]
B2 5+
LqX
(k;}
731#po
@ 8n
=zik
TG?(
pu%s
uhL!
8*4
Fi'J
Si4*2ua
6gS1
e<@$,
7|$O
(9F(
Pg~a
D=(Xp
NfN8NtNHN?N6N
.$P]
gTLS
m$nGg9
*/+):
BH5D
yO y
IntPtr
8sW[|
v.g.
]4`R
U-n*
8 xQ
h# .B
;'ws
MXd&
1P a
I@l3e;
&@w
rK"6
^EEFA
Vd?X"4
Q1r>
6s*}
x% 0
]rQ3F
!H#cb
\(HG)
y:VQV
Yn4>
V.10Q?<
:Jk<A
\.tu
=kb&
[C( u
X EG
;Ge9Tf 5B
Gj%H
l2Tu
ZjKx
?LY+
aq .
Vj#FL
uKbzG>
Ob v^(k
R9_B
w2Q?T
AC 4
oe?I
/j~E0
P+~S
Q4nZ
+\km
_N L
C/gQT
.($w&*
LHG %
9X0d?
EDoB
D,+i0
9H2:
NdNRN
<"Y&
) %^
J?\@
K$#+5
z(<6
<W"6` k
s5EE
r0 '
;9q5j
4?::
yeQ<j
:=#C
$Gz>
t+'IH$
8=<C
wMG4
yCv>
D|n&e`O
((ev~+Y
j!rj
@V4q
TmuC
s%.X
y1A0
SU)v
9g=/
Eb^~
QdnEW
CBLBh!b8p
O@LE
vu?:
)I/M
5#DC
)x+C
;L`g
s(8b
>n;R
9jSX
WJ;i
&m4O
D96W
EV#>e
S7yN
$l.x
-!Xn
;P@
*VSOU
H`3i
6f~H?(
=_%
;*C0
vQ}k
AECr
+H <
D'TW
`Mx3
[Mvu
HHF%u*
BC mow
=+(>
^:_4s
@V4r
:q}q
Dy#|$%
8'`=
CUKB
.ses
!K&0I
kufZy
z \<
/3P/
`/+u
EaT{
JmN}
_5+
< @7
IE4'HfL
Ky ]O
@u1b
'J`l7z
pT_
;rP#k1l
o<~w
D`VW
Y:y
sWUN
uc~7
3"sx
WUU5Ho}*
QZDIS
*,RV
:lS
F@d3
.!N+
:LU4
0hFx
"`m{X
apJZ
wJ;m
O\k!
\dz4
amaj
LO{z
@*CK
g$#4g&
/O&jO
>e`u
6oyH
"_R8
KD?,
r803
|6 Pu
`%=
Emx@
{1cn
a{Wx
r7]\
k<KS
c`L[z
Dh L
A#t( X
)Tj>4
.rJE
g6K,
}_l
4& _
X~76-
fnafZ
I@(Z
mZ h
kK-4
jO b
s)V3H0
&}]`*
|!av?
WQid"
c9fF
qU}GW6
z--m
GU2Z'
Rv6!
2 #m<
W9t
_10R
<y59
Ai/JJ)
jlKLy
y1=<%
|1b]
U e{+
]ABj~T
Bnk05L
SQp
!F- AB
F s
?3[M
-025h
q~\6
Fk8zjr
k'uHW
YA[4k
}(#U(
/J4cYo
F: I
-282u
[7N;
3iNZb
%0aX
_t ?
@.1[iY~
j (
pX3u
`*o%
"(_&Z
3tuD-
?ea
rc Ai
+`C
wo38
E#_5
b*/[
J/O6\
CallType
!=reS
eiC<
5,7R32
Bq>t_
9 ia
UTq
gDhB
y<dgF
R_* ;
^Yq\
]dc(SW
qM@GK
eLD8/
iS(,
*P&d
6QX]
^9Fnc
1w:t:
X$<r
K -_
(?g]
ft{]
:V*v)
0l<:
olB6
1m.P
htTt@
#}y
Y#c9
S^9r
s e
(zcB2
Rv6W
]l%]
#{o{
pi_m
#m;^B
fZ o
-ej9
XW8-w,
x;x8
Bghg
\XPmyE
;G<!
,??n
R|0
j~J*_
P~#4
0)O9s6u
B SN
F aK;l8
gXfK
Cx\>
S3 |
"V8 ]
uGHK
`!!3
T+`9
m+lQ=
m7${d
5: <
3Fg
5R[(
@!5|e
"(UQ98n,I
4! b
9x_l
J7`A
9>
A%`$(
Gh~;
x=F.
GL +"
oo/Di
2;Fo
}YRe
[McU9
x^FZ
@ [{
$z]{
"SAF
JVA<
9)|T^
A[)b
mSb >
{8+l
eO{@
1D1"
UGBe
IEND
J1\c?
R6U=
aKt`
7<Do[@~^ Iz.
!YMX
XzUxE
;3x
f|3h
AyGy
lE\Lph9d{
'LU4
7f_
f[==zn
_epB
q6Ra fG5#g
mVUd
[K:
$b v
tmd{7
Ptlr
2D @
u${B
. bXm
U6DC
Nq9?_
0saK @
QLA.
1)WJ
8~:L
5vd W
$Jvj
L'0
fgnS
5 T,b
[ &F
2p.8
Qc N
m50EBoHtzIrd
m@#
kf{|
#"O
&4)E
VqHF
9z54E3
BbIX
u`Hn
) EW
b!3hcx
i~X!
z6R"Ma
tB@J
fW6]-x9{
,}WW(
uFNL
.fkA
W$oC|<T
/(a$
3*;i
"o 9x
/b '
YJ~}
3)_f
K&q}
"=]1
tz%R
c]Gft
gS0dv
e&8Jz
p9M=
bAQq
3F"DXD
^crR
VjhZ~
CobV
G(|A
.<8'x
< xYa
dS0R
4X%V
kU
Qpq@
N ]
/ ]F!
g$^
5aU;
; gH
[w*ze
&Q7f
bM_%
Z,cv
'@9S
N.DCa
xJVT
3+!n/
W3AWHT
78=}
?^*9
FY'
v*H~
q`4.+8
Q<_]
YceC
td?jj
u*Qz
KeEQ
X'si
Ubu:
v858B2'wj
<jEFo'
!mAL>
Tv3Ir
[wFF
-O;r
),z%W,sx
{,Xf& ],
tg1.j
2R*R
a*q(
fT"S
LFT#~L
q! s
VhK|
{/!ZB
S@4
0oWT
B:TY
,vL |
%!We
&cK^
X Cl
Fk$^
LN_3
+=n
zKi*
LI1
tg4J
*l&KK
6d*,
k<C
za=w
]zeg
L`{'
Ss7%R
0[&A
V8\5{
Z0Sr
z6md
WL v
v{CI
!%q6<}
Hvd_h8j
g![^
B($=j
RuXm
YwF&J
h[Z-
&2i
NK2Sq\l
TYRB
6$nX
feW.
oD3w
dNt\
O>$J
_(2N
^ r+h
ETwRS
}4,vG
4WKP~H
j$3Cc
$X3u
( U]
:JYt;
ASrB
JfMK
]w8o
Q[>HH
}'nX
" @Y
%*9,
5(p)0
y @0
Q :v
/ /w$
H$5W
>sAX
"mu#V
%b(?
bM2y
>- vT0
fF9"X
(RxZM'
X"8\
o,Y
!(/'`
- I\~
+t1(
4""+
U(O2
R+Apy
jy 5
rNSx
$3Spe
\; '
cU\
T e
st.L
_Lcd
RHLAR
#0g
6k >
.Gb Q+XP
=iM t;c
MjW\]
)+Ja-;
l}2y
v#:(>j
P~{5
Wt/GD
u;cJ
i({J&
.lC`
Q`)8
^o_PNr
nRwT
WM?$E5
3TdIgM=
:~UiT
)D;nU1
wWX&sU"
Y?d:
CuMA
=7SF`
x=O,$v1
*[H&{Z
d1:y$
'amJ|2Ok
T9>I
0`CLk
:TK
m#D]
;(@F
w{#
9KE=(A@ wZ\
h[?=_
k48oa
z:X=1
\}_D
G2 T
0=fY6
~DI"@[
*w 5
+nP%
{P[I
m@O2
.vhi
70nE8
$W45
:4~
B>jwv
R*5M
I6yx
O]d3`
=/?v
x(>6Ux"
DRrRN
R(*7L8mg
fP&S
t? .w
*S z
{NOxU
W1E?
c< L
&#7Bds
MY*ha-
N/Z
7GM&
4}{y2
I%:bD
{ WQ
v;^G
*+8~/
Zw[8
Q )/
OeJB
ohW Z
D(qb-
e)0Z
_wlO
T3<IT
W#c7
Dc`+qX
Y .W;'
3mg\
(+2s
c_B
R
]8dv
<AL7
\VIP3;
"{.c
UQ7J_
h-zi@7#s(I
*!<6AoC
f(w&0
TNbc;
6u A
- !G-
]:z*
'%ZzU
hp:n@
7b^{
q0_#
%%^4
W%j
v! i
String
| R)
@nS@Fn~
m6hbHwYv7VdLU7dlq
egU$
\z2A
3LI%
,>lF!([
,FGw
kr%r a
`78A
< gS
h1Eh
EPm-
v:tJ
wT 9
gW4`
dEfw
Fk|?
"* x
v\>H
.VD?
vHX*H
"=r
xm2Q
,W+ =
Dfd fH
pV1{8
+yd;{c
J-{G
w~()
Y=ZA5#
fE'!
8T4]F
!%hc0
[}%^e
:=X,>
)_ q
"%V_ u
~"p<
qi;Y
= f:Sn
&{C(
CE.?
&FmD
m'yh
7-VF
B:qE
*@6K
.6kxzT
,vA'
3xs#
b$2WWL_
= MbY(
Ylu:
XYU@
yKkR
]G[}
u=k@#
FHQc
z]KM
f3p"
(tcK,o"
EKwD)O
`yl Q
|@<e
>=6A
BGwa8
KG1{
hiwxY Qi
?!m!
lld@
hT[hB
4i{;
dh\RRM
N Lf
;$on
pP(g
YaqjM
( dh`
,,^1
{bCdH_
J0!fT
;8f]g
d$h~
HB9
&{6,
nVeQ
K51P
`n9{u <i
aB}tz
R5Vo
%upMW
m)q
OiN;
*P6
5pbt
Ibr
sJA(
VBWF
! pT
u|.|4
PWr&
>eV(
D`:![
eBoD
b{:W
#8? +
[] 2#
$q+h
|0X.j
!o0"
Qm2'
*REM
%mR3O=
X.>?
\*-G"
V+gr
`eR0
N;6-
FPZG[
y m
os6F
J+TJ
nc}&
ih.2
B D
lwtV;R
nhz)
u9fu5J?
{=#v
8Y#h5$Q*
)W1PS
MPkH z
ry"@
eK.x5{o
Di+SX
d+Y\l
x7t T
I^+~
1Ob
0KRE
`*nj"
,.'n
x:z 2
L}1e)
zx)(Vm2
Sjx(
l'P,
3'WW
t}I/>OE
NR$[/
l~yY
dK/N
;{g5
;{c
xRb|
P@i2
5(?U
\vcU
Sj$Wd
M3YO
X;"^sZ
A -`
Pqq8
j $,
K-Y.
F7|L
f_j0
^q*V
~2d.
,b ?5@
z!3f
a@5j
4<&"f]
)}ZV
3
GVA&^+
f[@*'`-F.y
oC%y
PW >
n.z'm
nd#r7\e
RO1XM
*Zm&
\xA]}
c6~}
RfTO=
5 X15_
DBS|
plp
|) _
3RaE
590~Q
JD~6d;t
FLj70EC
KM1@
GD|u
wBS+
#SKjCT@\S
J oV
/6W@1
fq,H
H#=D
AB :
?YOK
%pL
K0<B
8Ykv3
s{mH
Dw[!
r4"-
E k&K
b*as
y3mR
'}, ;
$s`O
[D%u
#y_H
6B}0[
0or-
NbN6N.N"N"NrN\N|N#N(N
'-yV
B8ZhkGlMUuPfZo
d95S
,4Yi,b
Lc84
)*}+
f Y TFx$\
JGv&
C1oH
]7 `>
GIj
~0{0
z"4S
R >j
CX2B
ganP
P>Th74
,)8Ym7nv
q1l3
owH?
Object
.7t2J
'7R7sB
,b8c
@nrr)'k*
+`"q
2X:V
,eu|
BPdM
c1O
91[|&v
)),
[V#Y
VnW?
x])m
tW U3T
n~A)I
*51r
Yoir~
\9=wu7
3[Ko
%G
5K0n
^)e`
/0Hk
nQsq
V|^<
'q=QOd
+.Mc
ZK~K
yOsc
sHg&
^}>w
8<t<
l:dyM
d @"
IDI_[
g+2 =?
mFQu
?/5d
|%>
t\F66b8H
/F(s
PR k
0orY
zBYCK
I}xI
c2c,
>i*
)p&}
XF.a
T^;@ &UU
gY h%e
fH6*
~iZo(
+$,BW
lm['
ogG)wys
);89p
gu > qnU5@
.:ub
$)\`D
{SqJ
q-T@
i AG^
kW {
Uw`?
Rt"|
<F<Bd
*x(LA
Bt#L
+t %
/"h/
w{/
b T|
VrCo;gM"Z%
<:)ri
U8`{
uu b/>
!Kf
=*/;z
k?/bc
L-:k
_c|J
4q7''
Kj%$
-Axd1U
0$d
/Z)s
;Y+wq
Xs"$d
hB$m
9]Pj
} '
)Xr/
)q<Z[
rd<o
b:n|N
AZ6F
`VLN
SNT/M
?Q"FqC
V9
=E-T
z/9b
vHuaO
]Y%"
<4Q{
Cov_1
:tCs
b]6A>
f'2w
OB1~
I`<4
:"G4
G[V+
,
FG! Bh
R> j
`u aR
CG9b
Q@ X
`us5
%Z28
^9>e
$?5E
0[N%
hob0
F&3<?
j l5
=A n
y)_#
OW}:a
MB:J
'pOn +
"I 6
w>%X>
get_Module
"y_;
@ed_
2_@I;d
>Cvh
Di'
h79x
FH+g
&z .
p omD
% (B
}F&aT ~
%Rge}
wBs3.
FYP\
Fg&"
Yw`^m
J @)
&!]8
UDfP
{{+
79Q _
+mqb&
l7#=
Cl/@
}(L/K
\DE;
)!~
<bFMC
ZHtF
o;Hia1
d% W
!S;%Qs
OF<:I}
%1sZ
)hw_m
Y;6|E
G %>
X924l
e^+A
kvml
l~1(
31yuYC
#P o
.[z%
eEfeG
b6Zf0
K aH
&/om
.\C
(ZnqSj8TTpgOuIE5IYBC88ojd9GAgFFuR3CpEyHiG
)p/k
MgLf
!M 7
B& L
@^{+
y3*xU
P'sIs
n>}
Fm0l
a)P&S
a`Y\
)geJ
aUS|U]
zl~8
2n-3
9;{$]
,:Y5
k< 72 =
[.&I
BwJq
<f5FM
~7c
''sj
x;C
l9SJQ
+ H'y6
I$Ip
vW,!
5P> i
y%3c
7 Dz@
~I0b~
%O& *pN6T
EUu^
H1c
JLl~
yMj5]};
D;6
P'Thc
5Js`
] -
Uy i
z$bL
-`T6G
GJLb
IZsE
rvxX t
p%5_0
$goW
6[ETH
;/^E
j!L9
/%?Z
:Ltc
vgl?
M P3a
JMf
z,m2
_|N6'L
P%:F
-rY(Y
h8<_
m{7U
@{`m
UaQ;
63<6
cYC<
.+}.i
{/MJ
Ko`9
Yp/0_
J[{4X
RfJL
'-(U
fsQsb
*Jn{
B;o]
Z}@d
V( x
4,~c
PRFg~
y!]_(
x3` 9
N-P0
r2\a
s'Gz
^'Z{
Em[
.R<"
2$Az
_)zJ
A&c]
N N'NJNyN
Zh18
e_xp0~
M`Y"
i@#1
tu]2\
3#)2F
?(L[
Pui%a
dsmX
7za:
F :
a27D
System.Threading
M[+DA
7BQy
c#Ioi
`YK@5)n
g "F
cEn1Z
Q;l%9
]fgA
3Ub
8L )ja
N^wZ
+?|v
n,dg
e{R[
%.r,
? `g
CU=X
;*4_}
YI`_
ju<xQ7E
>uu`
')20l
|5h^(
IR)a
fn*J
8w}O
jaiRXmA
".[&r
M+ap
6T+b
T\k
-!H
RgLx
y VF
ki6L
\!P(
umUG
hbEIj
|D1
m/B'
"!,j L
fGmN
OwQ"IM
=)]
X,GA
f?JY
xe`~
)ASk]C
y MQ
EAt~
eM~m
B%o4
A!~C$J-k
;WV*r
m $#
Rs4EIQ
3;gFV
%B7>
@^&
]zcD
ON]6
6l(m
' 44
93;S
y7;:
R>rVI
m1\ #
IQKp^
syX4G
k6`e;1
*o3~
k5$2$
A4M^J
LS|1
2t(l
@ga;
NUNKNaNZN"N
:FzE{@M
-Tj4
v;2`y
UFck
W+QGK
rNU]
o@ >K;4
P)k j
pYsT@
W bkg`
5 &^
;aj_
hww]
U?<h
, 5@
S]M<
Qd2|
_!Fv{
2Uc6C
Wh{5
}2_Q
B sy
HfiT
B uA&'
&}~@4
@~15
IqUt
/ap*
bsog
:$U*s
COa$
AJre)e
wAC6
A2_\
~,gs6_Q
|6%dLo d
174Y
D'qU
ny{NFr
4b1
9QIw
($G|
dx[[
%%i-
))&9
!4.y#
zEM/
1_'_
NnNMN`N8NsJ
g4rb
da{Q
BNG@
x=#
^ a+
Xv_;P
4 ?
B"s nV
i%VD
xW&r
<z2,A
\HLd
})V
j[)x
Xr0{
Fln=2
VfS*
Lp-A
yX9z
vU~.
'M1!=s
q}X39.
P
ln>r~l
m{P@6
y/nk
@<0UD
5gVDIeN91X
0~?J
6^Yg^n
EQwP
Z&X0
jy`N
#|o
O2t7 f
6[E]
z3~d-
H rX
<[w
zAN&{
xG*
9oS1
FKWy
:TI[
-;><O
t 5Y
$k0 E
.9gC
d]4A
NWNfN0N
U %jS}R
}_}[
}-I.
P!q>
orn>
NBis
`<WL
,Vcv
urX @zv
rIIYYn
wZ#TIT
*0M[19
pV14?
cfZ@
8Y,k
E2 d
uH}9
NINaNYNmN7N
_i{f
=B1W
t[+e
]["i)
)Jpr
jU1t
[*\=p
D8Q$)
,-g6
S3"LJ
Ru^+)EGi
.h\C
?!"
=7Vt
UCM@
R'v;
(xpe
BoPuu
P7aA
tu+j
^2^A
L^sJ
!8v@c
v7)|
Mr2<
cem#
kT!
8NEz9s
NXNtN
oyt>x8
aO~
)70{
%_&{K
6S MK+
#} CSi
@=J
P5ob
; 2F
<2tpu
@u_J
)l+7
D'.@
VwCB
Le8V
Hbc)Uo
L>fj
)U{}
[VSO
!J#6e
w~Tt?7
&JI;
lB)!(
(82v;
l(4%
y~IVy
-=y N
3!~$
n!s1
x@-dW
PxO'
)w'
!El"
s@=
C6m_
Lc*T
'p#q
=&`
9 j)
&4xq
GetTypeFromHandle
8L=iUm
D-5e
'-n
j>j>
"-sikd
{401
7q}k
pJ6f
^wi 4.
p:p`
XP[-
24 W
;qR`
.Zwi"
u`:E
XCMU
DtFY
O5?`*C
8@ O^
~>B1
|K0}
T3/9D]
n/\P|
&O<{ts
-U3 s
j ]'
xp#l$
wdBEp
-H5$
A+q
gN{o
zcI"
~&(7a
J8&%
C,nFmI
&:esz
g5+1
BR_s
u^R~
!8]qA
JDi
z %s
*FON
qYM<
r$o-
$15^_
y0; l!
JRFh
=P$(m_I
2}d
x@k1
nmi_
s[ D
1g.1
ps~e
*b0P'
!i4c
s_ld
NqO h
~ouHg
^jD\
1/4"
G*k!
[3W `Y
F>|G
"4j<
[FvO
36`mU
*Lt_
H-.Z.
zq K
b)]`
gmRc
V?qo
N&9(
d _F
fv2$Y]<b
Ue 3
)KlO
i:Ht;
r^r8
wKLFz
)[LE
t1xPK
U;=^
xQ8R
I*~9s
System.Runtime.InteropServices
~v1$[
U5-rT
d`Bg
^JLDh
a?}3N
;5s6
`dt9
*abna']
PHz
;QgU
)#<\|X
(Lj!
@B36
;_'lGoN25w
e#UTNu)d
Adp`#
>`n+B
QL3
D<2
RxU-AI
](>g
Y5Qn
f,Ss
r"&G
AITG
;_xb
C %s
T f<
Zf:
f\L"
wE2
mb$}E
\wA
[O#K6 S]
A6^x
uxPk
q+*C
FT-*x^~
A:)I
\vVvx
Kl(*V
V5oR
~CP/
B"t`v
ZlYu
System.Runtime.CompilerServices
a9Cm
;}C>
xQOeq(
jcq'
J!wC|
Y1AG
w G1
j237 R
e4 En
7>Am
20]G@
y[5&C
Y9=Z
v.8p
;#wf
lkD<
jLk/rY$NJ
+1r+
w1A"
A"'a
u&1a
k\]v
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
" WV`
:qxC
tDA]
[mRE
P+b)
#KqebMp
/I9
80 Q+5K
7 ,q
J *
;/3>
X`xG
amYz-VM
Qq(
da$
9]g(t
de;L
Eahn
L4dF
(@Mr&[
8j(Ym
U*}^
AD)#
uVx`r[>;~
1CW5vJ
N9S1~
Z56,y
Sxu|
0g1$
B!=q
p}?s
NW%S
`M),
2 .t{
+5K&
lxq#
DP(Y
``hV
| ,c
=* S
P-#v
p!"J
@uB#
w"xr
DDg
#qL;
8>2-
#c&%
Wo<{
d20wj/
N'@^Hf
1B!
^%)
$B6BH8
ta6
1]-(j
X0#oi
1]K
z`7Z
GjL]
s;i&
Q8_5 5
P_f%
YBWr
]|>Js
D:D#
OR@R<
C`~2
#30&
=\#{
(8Td
&T1S
eL 7
+YY^E
L373
b !"
lCz *7\
SQLZQREvuGlI2
{3yMv%
ps@
,*g>
lML$
\p)H=
b&
(dI|
`G(!
k ?%F
ePt*
N8WQ
/h6x
'zBYBf&;I
u\1ok
<e2P
pt3p>S
y'f}t
DzV*f
% kFQ,Gh%
Z?:{
{{&m
"tk[
84~V
NB @
w<c0
/l*R
8E{]
]Wb(!w
Izh+J+
H7)D
1v.*
g2 H
~`n+.|
NPGf
(V)d9
|$Mo
MAu"/*
p`vpr
igu+=
2 cHDcf@
eM8`0
4b!#p
Z8H[[
)XW|
j|@<
'Hmtg%z
C|%i<
d,R\
kO>H
}*;1
fi=sS
N=0.
?RpK
pVQ4
$C4bA
~jUa
Wa*i
m46I
gy~j
L#llu D
A| S
&sr1
B]m;
^D:)
ZeWH
.`)m0
?nW_
^V^y
nZ7wvr9
qlNE
e(e
fUd-
k#h.G|
:-# <
uD!1
QKG *
xA9h
hk<,
l0llW
"1o;b
-nxy
=G=$V
g,d1
,z[X
(=gG
A\L
-[}
mj2&.
a X3
,Y T
Gx/t
1%n)
L'4x
,iPO
KE{N
& Ii
Xn.G
E/rMOd
+CNkSB1;
Nis7
PB9W
j4ep
A>,t
C2B&:
eDQHv
8WNaI
PZ u
Z JI
"hF?r$
{T!)B
88=bK'
mCb!
1`D#
!%Tb
(_%}
i^9~
%y$`
3u[e
7? eea
J]J3U
qEsz,j
jUPv
isZhL
*0r
d$y[k
Q)Q{U7
z46e
!M]v
Y;QB
PSu^
b EI
$k=S:
"0v]}
K;UzU^B2
t|Pm
:PA l
g, [m
Qq?C
RCDN
qAUu
uv[La
CBM!
@;1
d'A{q
7O1O
9d"LSq
G<J+E
't@h})w
W4 6
rj'(Z
N^U7
;;*6
1N^<_
.[x9X
#Qhu
h!I
ea>k
^ed;
![^<*
`],c
$(B.??B
h2r/|
nJo\
rD0m
*TEW
9.Ho
=`6]\
MJ<u
;s#Un
C$T Q
v&NEPD
So`(
G. g
oh lH
[/1+
pE1 =B2
B*(P
|:zl
dS0q
eD6Q ^?KHgP
d/JX
lrMPZw
b5y]
4;Gu4
/@3a
@1{&
H*+N5
vn#
<[c:K
99]@
zKez
{@!=^QV.
NbNaN
=F2dfAk
R8}$
N8NoN+N
ud\(B@
&d_D4L
[E@A
&'P:
&v&N
~[[[
5$ O
Lak\
.>x]WAk
{xTgf
NANuN@N
@L=L
pZ yV
3@,w
4(/b\
OBUD
5&C
<qQ|
n|yz
?[\A
4PdT
SlW0L
CuH&a
{p>
B 8M
n_yA
q<(3
kj =u
@TGz~
d=f\q
Z[ph
pgqg
[`} ,
23z'H x
2 ;p
z$_g
f "=
BrO[
%0e!
-`A?
<AB^
><ip:
!eZ 'Zg
'-D(C
PM!;
YE&iW'
=Gn
p%`6
KGau/R
CL
F"Xu
VuQ";
`4h,a
'#6"
d d^=
!("o
7Z/dp+
hM x
L vm
iN\H
iv"/
;7<Y
?!t+
lh `e
zZ[
zp )$F
F2.
K&X{
BtBa
7PM(
t!+K
Dh
gu
Dg-`
+<"`
F@E8
I l,
P&M
E~V_ Z
35m#
0 )H
!Y6aL$
}2(\
PEy+`
6k?u
1 Y
o:u%H
Jt^Q! W"
-oNSF$z
[k$"
4R+>
yO&
"= Mw
K R$
z3b.
&?r'
IO^&
H|^T
cRb:
l=~r
_e={B
, ,m
K 00l$Y
RDae
U7cd
SHqIU-
Jb#U
(Y"
Y4F/
\`)m4y
?~o-
CCJ8G
g.w pJ
|@W
1HMk
H*Xb
+eA>F
Pj2~
8qC
Rw2E
doxj
E%WO
'J{'
J*=SL
{e(S;
{^P&
HEfa
TBg3U
V\nr
n+FII
.~dy
bktP
a'+tGnw:
,+%D
J #
4+w~
s75_f
f.8a"
H'L;t
V=Y(C
P"(wWH
|>WS
@^ID(pN
eA W
~]qr.
~VG/
/ =S1
pxqK
x_Eq
#%F:
08|72z'/hH5
CS K
:/ g"
~/P
d/9A
s?v)
b\Yki,
R*Vf
G 8q
{i_p
' y%
?g;OPL
q`7qQUhh)
!scP
G1jI
j0v?
Bw~r
!p3{.7
AW%|
M^mSr
?d[P#:
h'*+Y
d.]b
erR7
%WHZ
]A):
-=a[
IQzyjsC 8
t?[s
-pih
zp&9
CjqY}g
KLC!z
Tmw{
# E!X,
`DkuF
\nWc83
ZYQn
>D6 e
~_FS'
?.qS
MN04oq>
|B.~
FD z
g+QE
c=9IG
>ULe
"Yc=
6V{U
XHzL
e*sa
%}v`
ZT)Z
c@9n
*kne
r~QxA
Frk U
nCU\
6l+aI$H
lM8'>
ub@>}
U&1R
HL^[
6T;H6
X^({
wW -
GI}
^E A
tr?Y
EJii
_P8\
y$?t
$) ;i[
c$n7
i3NQ
hO;k58
RTf
U (
=w>6,g
~3 !
s}_
TQ!/
yhuPt
LB 4
1|V<^
*%Bg
MAQs
wd&n
o[O$@|
npo%
UvBT
vll p
6az8
lib Q
6u^2
bvEs
-.\;
G @
JT B
c7NC
o* g
l$VV
AX,U
|vYk
.cPcv(z
UODp3rpClLp
7c
-~r_
\',!
Ey&s
V30j
51ca6
vv)Tz
#@fGJ
DL|0
q9PJ
1M1M
&c8y)n
?&+{
?rK@A
AKp4B
#?,J{b
_+M$(
hDVD
_1=]y}
vjMb
dGodU
3Bc-{
+_yCA
EvmSfa2
OREW +*k
D.(J
hSmw;E
xi.e
(it6
E!!/
WjtH
+(r&xG
H/_8
G+iR
S|o{$
f IH2
'i*L
2S1|m
%!du
30>~
V>w{
f NN
:sJj
7Vv i
B=6*
/,O.
y)?\
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03_64 Seven03_64 VirtualBox 2018-04-14 14:52:47 2018-04-14 14:55:49 182

15 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03_64 Seven03_64 VirtualBox 2018-04-14 14:52:47 2018-04-14 14:55:49 182

11 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\btC.exe.config
C:\Users\Seven01\AppData\Local\Temp\btC.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\btC.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\btC.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Users\Seven01\AppData\Local\Temp\it-IT\btC.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\btC.resources\btC.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\btC.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\btC.resources\btC.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\btC.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\btC.resources\btC.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\btC.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\btC.resources\btC.resources.exe
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\msvcrt.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\ggsT.exe
\Device\NamedPipe\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2340.27655843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2340.27655843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2340.27655890
C:\Windows\System32\Branding\Basebrd\Basebrd.dll
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\ggsT.exe"
C:\Users\Seven01\AppData\Roaming\ggsT.exe.config
C:\Users\Seven01\AppData\Roaming\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\ggsT.exe.Local\
C:\Users\Seven01\AppData\Roaming\ggsT.INI
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\btC.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\btC.resources\btC.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\btC.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\btC.resources\btC.resources.exe
C:\Users\Seven01\AppData\Roaming\it\btC.resources.dll
C:\Users\Seven01\AppData\Roaming\it\btC.resources\btC.resources.dll
C:\Users\Seven01\AppData\Roaming\it\btC.resources.exe
C:\Users\Seven01\AppData\Roaming\it\btC.resources\btC.resources.exe
C:\Users\Seven01\AppData\Roaming\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\it\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\it\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\Update.txt
C:\Users\Seven01\AppData\Local\Temp\1099718948.xml
\Device\NamedPipe
C:\Users\Seven01\AppData\Local\Temp\1252040376.xml
C:\Users\Seven01\AppData\Local\Temp\498097471.xml
C:\Users\Seven01\AppData\Roaming\eTMMY.exe
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll
\??\MountPointManager
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2660.27657531
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2660.27657531
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2660.27657531
C:\Users\Seven01\AppData\Local\Temp\schtasks.exe
C:\Users\Seven01\AppData\Local\Temp\schtasks.exe.*
C:\ProgramData\Oracle\Java\javapath\schtasks.exe
C:\ProgramData\Oracle\Java\javapath\schtasks.exe.*
C:\Windows\System32\schtasks.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\Tasks
C:\Windows\sysnative\Tasks\*
C:\Windows\sysnative\Tasks\Adobe Flash Player Updater
C:\Windows\sysnative\Tasks\Update\Update
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\*.*
C:\Windows\SysWOW64\ui\SwDRM.dll
C:\Windows\SysWOW64\schtasks.exe
C:\Windows\sysnative\Tasks\Update
C:\Windows\sysnative\Tasks\Update\
\Device\LanmanDatagramReceiver
C:\Windows\SysWOW64\shdocvw.dll
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Users\Seven01\AppData\Roaming\
C:\Users\Seven01\AppData\Roaming\*.*
C:\Users\Seven01\AppData\Roaming\ui\SwDRM.dll
C:\Windows\SysWOW64\net.exe
C:\Windows\SysWOW64\net1.exe
C:\Windows\Temp\fwtsqmfile00.sqm
C:\Windows\SysWOW64\netsh.exe
C:\Windows\SysWOW64\it-IT\netsh.exe.mui
C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\ProgramData\Microsoft\Network\
C:\ProgramData\Microsoft\Network\Downloader\
C:\Windows\sysnative\tzres.dll
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\it-IT\sc.exe.mui
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
\??\PIPE\samr
C:\DosDevices\pipe\
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\*
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
C:\Users\Seven01\AppData\Roaming\eTMMY.exe.config
C:\Users\Seven01\AppData\Roaming\eTMMY.exe.Local\
C:\Users\Seven01\AppData\Roaming\eTMMY.INI
C:\Users\Seven01\AppData\Local\Temp\170401536.xml
C:\Users\Seven01\AppData\Local\Temp\329645784.xml
C:\Users\Seven01\AppData\Local\Temp\1716263706.xml
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\90e27466c5b95ff431a99d3481615164.exe
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\ntdll.DLL
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\System32\tzres.dll
C:\Users\Seven01\AppData\Local\Temp\1229163999.xml
C:\Users\Seven01\AppData\Local\Temp\1437883044.xml
C:\Users\Seven01\AppData\Local\Temp\1648046143.xml
C:\Users\Seven01\AppData\Local\Temp\23487450.xml
C:\Users\Seven01\AppData\Local\Temp\149537844.xml
C:\Users\Seven01\AppData\Local\Temp\1453879295.xml
C:\Users\Seven01\AppData\Local\Temp\1412547054.xml
C:\Users\Seven01\AppData\Local\Temp\1277439905.xml
\Device\Http\Communication
C:\Windows\System32\p2pcollab.dll
C:\Windows\System32\qagentrt.dll
C:\Windows\System32\dnsapi.dll
C:\Windows\System32\DHCPQEC.DLL
C:\Windows\System32\napipsec.dll
C:\Windows\System32\it-IT\napipsec.dll.mui
C:\Windows\System32\tsgqec.dll
C:\Windows\System32\EAPQEC.DLL
C:\Windows\System32\it-IT\eapqec.dll.mui
C:\Windows\SysWOW64\it-IT\P2PNETSH.DLL.mui
C:\Windows\Temp
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp
C:\Windows\ServiceProfiles
C:\Windows\ServiceProfiles\NetworkService
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
C:\Windows\ServiceProfiles\LocalService
C:\Windows\sysnative\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime
C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
C:\Windows\sysnative\Tasks\Microsoft\Windows\RAC\RacTask
C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
C:\Windows\sysnative\LogFiles\Scm\fca58fb2-231f-4daa-bca0-77602b638485
C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
C:\Windows\sysnative
\??\SPDevice
C:\Windows\sysnative\spp\plugin-manifests-signed\sppwinob-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppwinob.dll
C:\Windows\sysnative\spp\plugin-manifests-signed\sppobjs-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppobjs.dll
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
C:
\??\PhysicalDrive0
\??\pci#ven_8086&dev_100e&subsys_001e8086&rev_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{c2d43895-0262-4873-a789-c2f96d24b693}
\??\root#*isatap#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{684bb8b6-2793-49a5-8012-e0a941b4b4df}
\??\root#*isatap#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{5f6d61d9-d207-449a-bd48-652a5d1f25be}
\??\root#ms_agilevpnminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{29898c9d-b0a4-4fef-bdb6-57a562022cee}
\??\root#ms_l2tpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{e43d242b-9eab-4626-a952-46649fbb939a}
\??\root#ms_ndiswanbh#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanbh
\??\root#ms_ndiswanip#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanip
\??\root#ms_ndiswanipv6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanipv6
\??\root#ms_pppoeminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8e301a52-affa-4f49-b9ca-c79096a1a056}
\??\root#ms_pptpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{df4a9d2c-8742-4eb1-8703-d395c4183f33}
\??\root#ms_sstpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{71f897d7-eb7c-4d8d-89db-ac80d9dd2270}
\??\root#system#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
\??\sw#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{78032b7e-4968-42d3-9f37-287ea86c0aaa}
\??\PIPE\lsarpc
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\btC.exe.config
C:\Users\Seven01\AppData\Local\Temp\btC.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
\Device\NamedPipe\
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Roaming\ggsT.exe.config
C:\Users\Seven01\AppData\Roaming\ggsT.exe
C:\Users\Seven01\AppData\Roaming\eTMMY.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\Tasks\Update\Update
C:\Windows\SysWOW64\cmd.exe
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\schtasks.exe
\Device\LanmanDatagramReceiver
C:\Windows\SysWOW64\shdocvw.dll
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Users\Seven01\AppData\Roaming\
C:\Windows\SysWOW64\net.exe
C:\Windows\SysWOW64\net1.exe
C:\Windows\Temp\fwtsqmfile00.sqm
C:\Windows\SysWOW64\netsh.exe
C:\Windows\SysWOW64\it-IT\netsh.exe.mui
C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\Windows\sysnative\tzres.dll
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\it-IT\sc.exe.mui
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
\??\PIPE\samr
C:\Windows\sysnative\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
C:\Users\Seven01\AppData\Local\Temp\1099718948.xml
C:\Users\Seven01\AppData\Local\Temp\1252040376.xml
C:\Users\Seven01\AppData\Local\Temp\498097471.xml
C:\Users\Seven01\AppData\Roaming\eTMMY.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\90e27466c5b95ff431a99d3481615164.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\System32\tzres.dll
C:\Users\Seven01\AppData\Local\Temp\170401536.xml
C:\Users\Seven01\AppData\Local\Temp\329645784.xml
\Device\Http\Communication
C:\Windows\System32\DHCPQEC.DLL
C:\Windows\System32\napipsec.dll
C:\Windows\System32\it-IT\napipsec.dll.mui
C:\Windows\System32\tsgqec.dll
C:\Windows\System32\EAPQEC.DLL
C:\Windows\System32\it-IT\eapqec.dll.mui
C:\Windows\SysWOW64\it-IT\P2PNETSH.DLL.mui
C:\Users\Seven01\AppData\Local\Temp\1716263706.xml
C:\Users\Seven01\AppData\Local\Temp\1229163999.xml
C:\Users\Seven01\AppData\Local\Temp\1437883044.xml
C:\Users\Seven01\AppData\Local\Temp\1648046143.xml
C:\Users\Seven01\AppData\Local\Temp\23487450.xml
C:\Users\Seven01\AppData\Local\Temp\149537844.xml
C:\Users\Seven01\AppData\Local\Temp\1453879295.xml
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\LogFiles\Scm\994c86ad-a929-4b2c-88a0-4e25a107a029
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\046fbef8-2dd6-4a92-a08e-608464edcc44
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Windows\sysnative\LogFiles\Scm\5c0aeeea-c154-45be-8499-bea5f11baff6
C:\Windows\sysnative\LogFiles\Scm\a7c73732-9f11-4281-8d19-764d4ec9d94d
C:\Windows\sysnative\LogFiles\Scm\ac4e5acf-89f7-4220-ba21-81ee183975e2
C:\Windows\sysnative\LogFiles\Scm\be669c13-8165-4536-96d0-6d6c39292aae
C:\Windows\sysnative\LogFiles\Scm\c016366b-7126-46ca-b36b-592a3d95a60b
C:\Windows\sysnative\LogFiles\Scm\ca4b8ff2-a4d2-4d88-a52e-3a5bdaf7f56e
C:\Windows\sysnative\LogFiles\Scm\fb3c354d-297a-4eb2-9b58-090f6361906b
C:\Windows\sysnative\LogFiles\Scm\fca58fb2-231f-4daa-bca0-77602b638485
C:\Windows\sysnative\LogFiles\Scm\fdd56c73-f0d5-41b6-b767-6effd7966428
C:\Users\Seven01\AppData\Local\Temp\1412547054.xml
C:\Windows\sysnative
C:\Windows\sysnative\spp\plugin-manifests-signed\sppwinob-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppwinob.dll
C:\Windows\sysnative\spp\plugin-manifests-signed\sppobjs-spp-plugin-manifest-signed.xrm-ms
C:\Windows\sysnative\sppobjs.dll
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
\??\pci#ven_8086&dev_100e&subsys_001e8086&rev_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{c2d43895-0262-4873-a789-c2f96d24b693}
\??\root#*isatap#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{684bb8b6-2793-49a5-8012-e0a941b4b4df}
\??\root#*isatap#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{5f6d61d9-d207-449a-bd48-652a5d1f25be}
\??\root#ms_agilevpnminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{29898c9d-b0a4-4fef-bdb6-57a562022cee}
\??\root#ms_l2tpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{e43d242b-9eab-4626-a952-46649fbb939a}
\??\root#ms_ndiswanbh#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanbh
\??\root#ms_ndiswanip#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanip
\??\root#ms_ndiswanipv6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\ndiswanipv6
\??\root#ms_pppoeminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8e301a52-affa-4f49-b9ca-c79096a1a056}
\??\root#ms_pptpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{df4a9d2c-8742-4eb1-8703-d395c4183f33}
\??\root#ms_sstpminiport#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{71f897d7-eb7c-4d8d-89db-ac80d9dd2270}
\??\root#system#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac
\??\sw#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{78032b7e-4968-42d3-9f37-287ea86c0aaa}
\??\PIPE\lsarpc
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui

Write Files

C:\Users\Seven01\AppData\Roaming\ggsT.exe
C:\Users\Seven01\AppData\Local\Temp\Update.txt
C:\Users\Seven01\AppData\Local\Temp\1099718948.xml
\Device\NamedPipe
C:\Users\Seven01\AppData\Local\Temp\1252040376.xml
C:\Users\Seven01\AppData\Local\Temp\498097471.xml
C:\Users\Seven01\AppData\Roaming\eTMMY.exe
C:\Windows\sysnative\Tasks\Update\Update
\Device\LanmanDatagramReceiver
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\Temp\fwtsqmfile00.sqm
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
\??\PIPE\samr
C:\Users\Seven01\AppData\Local\Temp\170401536.xml
C:\Users\Seven01\AppData\Local\Temp\329645784.xml
C:\Users\Seven01\AppData\Local\Temp\1716263706.xml
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\90e27466c5b95ff431a99d3481615164.exe
C:\Users\Seven01\AppData\Local\Temp\1229163999.xml
C:\Users\Seven01\AppData\Local\Temp\1437883044.xml
C:\Users\Seven01\AppData\Local\Temp\1648046143.xml
C:\Users\Seven01\AppData\Local\Temp\23487450.xml
C:\Users\Seven01\AppData\Local\Temp\149537844.xml
C:\Users\Seven01\AppData\Local\Temp\1453879295.xml
C:\Users\Seven01\AppData\Local\Temp\1412547054.xml
C:\Users\Seven01\AppData\Local\Temp\1277439905.xml
\Device\Http\Communication
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
\??\SPDevice
\??\PIPE\lsarpc

Delete Files

C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2340.27655843
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2340.27655843
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2340.27655890
C:\Users\Seven01\AppData\Local\Temp\1099718948.xml
C:\Users\Seven01\AppData\Local\Temp\1252040376.xml
C:\Users\Seven01\AppData\Local\Temp\498097471.xml
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2660.27657531
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2660.27657531
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2660.27657531
C:\Windows\sysnative\Tasks\Update\Update
C:\Users\Seven01\AppData\Local\Temp\170401536.xml
C:\Users\Seven01\AppData\Local\Temp\329645784.xml
C:\Users\Seven01\AppData\Local\Temp\1716263706.xml
C:\Users\Seven01\AppData\Local\Temp\1229163999.xml
C:\Users\Seven01\AppData\Local\Temp\1437883044.xml
C:\Users\Seven01\AppData\Local\Temp\1648046143.xml
C:\Users\Seven01\AppData\Local\Temp\23487450.xml
C:\Users\Seven01\AppData\Local\Temp\149537844.xml
C:\Users\Seven01\AppData\Local\Temp\1453879295.xml
C:\Users\Seven01\AppData\Local\Temp\1412547054.xml

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\btC.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30b60c51\5efe5c9a
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|btC.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|btC.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|btC.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\65767ce9\2dd67ebe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\65767ce9\c1a617b
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ggsT.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|ggsT.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|ggsT.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|ggsT.exe
HKEY_CURRENT_USER\di
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\ggsT.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\922F4745
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_CURRENT_USER\Software\Classes\AppID\schtasks.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\cmd.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\schtasks.exe
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\DynamicInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\shdocvw.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\eTMMY.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net1.exe
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\DynamicInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\netsh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Triggers
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileMinMemory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\PerfMMFileName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\BackupRestore\FilesNotToBackup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_metadata
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\BITS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobInactivityTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TimeQuantaLength
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobNoProgressTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobMinimumRetryDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TransferBufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackBegin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackEnd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackDuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TestFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\ForceFileFlush
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\UseLmCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\IGDSearcherDLL
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2085F28-FEB7-404A-B8E7-E659BDEAAA02}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2085F28-FEB7-404A-B8E7-E659BDEAAA02}\TreatAs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\DynamicInfo
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\BITS\Throttling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileChunk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileWriteBuffer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StateIndex
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BackupRestore\FilesNotToBackup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_LOG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_BAK
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\BITS Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Triggers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST
HKEY_USERS\S-1-5-20
HKEY_USERS\S-1-5-20\Control Panel\International
HKEY_USERS\S-1-5-20\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eTMMY.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|eTMMY.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|eTMMY.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|eTMMY.exe
HKEY_CURRENT_USER\Environment
HKEY_CURRENT_USER\Environment\SEE_MASK_NOZONECHECKS
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_CURRENT_USER\Software\90e27466c5b95ff431a99d3481615164
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER\Software\90e27466c5b95ff431a99d3481615164\[kl]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\DisabledComponents
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iphlpsvc\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\config\Connectivity_Platform_Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\7F06864B
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NapAgent\LocalConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enable Tracing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Tracing Level
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79617
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\PlumbIpsecPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79619
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79621
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79623
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\UI
HKEY_CURRENT_USER\Software\Classes\AppID\netsh.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F6C4EC9A
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\PeerDist
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PolicyProvider
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\PeerDist
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\PolicyRefreshInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\CryptoAlgo
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Protocol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Protocol
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Download
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Download
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Discovery
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Discovery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Upload
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Upload
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\UtilityIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\UtilityIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Peers\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Peers\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\SecurityManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\BlockSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\NumBlocksPerSegment
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\SecurityManager\Restricted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted\Seed
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CacheMgr\Republication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CacheMgr\Publication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HandleMgr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HandleMgr
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HostedCache\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Connection
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HostedCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ServerRole
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ClientAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousUploads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingOffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\DoNotUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CooperativeCaching
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CooperativeCaching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DiscoveryManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\RepubQuorumSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\MinBackoffWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\DiscoveryProviderDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Roaming
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\ForceRoamingDetect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshDllName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshProcName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-20\Environment
HKEY_USERS\S-1-5-20\Volatile Environment
HKEY_USERS\S-1-5-20\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_USERS\S-1-5-19
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-19\Environment
HKEY_USERS\S-1-5-19\Volatile Environment
HKEY_USERS\S-1-5-19\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\sppsvc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ServiceSessionId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\EnableTestVolumeIntervals
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLActivationInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleTolerance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PublisherPolicyChangeTime
HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
HKEY_LOCAL_MACHINE\System\Setup\Status
HKEY_LOCAL_MACHINE\SYSTEM\Setup\Status\AuditBoot
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Reboot.SL_BRT_COMMIT
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\InactivityShutdownDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\KeepRunningThresholdMins
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\taskhost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\SystemCritical
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\svchost.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\w32time
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogEntries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\RefreshSettingsFlags
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\TimeProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\InputProvider
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\TimeProviders
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PhaseCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\UpdateInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FrequencyCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PollAdjustFactor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LargePhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\SpikeWatchPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\HoldPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MinPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\AnnounceFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LocalClockDispersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxNegPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPosPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxAllowedPhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\TimeJumpAuditOffset
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\TimeProviders\NtpClient
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\W32Time\Parameters
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\TimeProviders\NtpClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\AllowNonstandardModeCombinations
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\CompatibilityFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMinutes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMaxTimes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\LargeSampleSkew
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\NtpServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollTimeRemaining
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Virtualization\VML
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rpc\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider\Parameters\IPC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup
HKEY_USERS\.DEFAULT\Control Panel\International
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wersvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_CURRENT_USER\di
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\922F4745
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater\Id
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Triggers
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\LogFileMinMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\First Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\Last Help
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_metadata
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobInactivityTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TimeQuantaLength
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobNoProgressTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\JobMinimumRetryDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TransferBufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackBegin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackEnd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\SleepAtCallbackDuration
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\TestFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\ForceFileFlush
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\UseLmCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\IGDSearcherDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileChunk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StatefileWriteBuffer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StateIndex
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{659CDEA7-489E-11D9-A9CD-000D56965251}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03CA98D6-FF5D-49B8-ABC6-03DD84127020}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D18AD12-BDE3-4393-B311-099C346E6DF9}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4991D34B-80A1-4291-83B6-3328366B9097}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}\Triggers
HKEY_USERS\S-1-5-20\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Triggers
HKEY_CURRENT_USER\Environment\SEE_MASK_NOZONECHECKS
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER\Software\90e27466c5b95ff431a99d3481615164\[kl]
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\DisabledComponents
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\config\Connectivity_Platform_Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\p2pcollab.dll,-8042
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dnsapi.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enable Tracing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Tracing Level
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Friendly Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-100
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-101
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Version
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-102
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Vendor Name
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Info Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Config Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Validator Clsid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Registration Date
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Component Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\PlumbIpsecPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F6C4EC9A
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\PolicyRefreshInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\CryptoAlgo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\BlockSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\NumBlocksPerSegment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted\Seed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ServerRole
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ClientAuth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\TransportDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousUploads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingOffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingDownloads
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\DoNotUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\RepubQuorumSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\MinBackoffWindow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\DiscoveryProviderDllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\ForceRoamingDetect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshDllName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshProcName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\179b8a65-b0f6-41d9-acea-12006ef9b32a\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\ManifestFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Modules\c42d83ff-5958-4af4-a0dd-ba02fed39662\PluginFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/bios/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\ModuleId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/windowsfunctionality/agent/7.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/flags/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/hwid/4.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/phone/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/pkey/2005\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/vmd/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:rm/algorithm/volume/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/eul/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/pkc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/rac/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/payloadhandler/spc/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/licenseacquisition/sequence/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/TaskScheduler/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Plugins\Objects\msft:spp/volume/services/kms/licenserenewal/1.0\IsService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\EnableTestVolumeIntervals
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLActivationInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\VLRenewalScheduleTolerance
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PublisherPolicyChangeTime
HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
HKEY_LOCAL_MACHINE\SYSTEM\Setup\Status\AuditBoot
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\InactivityShutdownDelay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\KeepRunningThresholdMins
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityParam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\ImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\AuthenticationCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\CoInitializeSecurityAppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DeferredCoInitializeSecurityServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService\SystemCritical
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogEntries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FileLogSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\RefreshSettingsFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpServer\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\DllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\VMICTimeProvider\InputProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PhaseCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\UpdateInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\FrequencyCorrectRate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\PollAdjustFactor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LargePhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\SpikeWatchPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\HoldPeriod
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MinPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\AnnounceFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\LocalClockDispersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxNegPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxPosPhaseCorrection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\MaxAllowedPhaseOffset
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Config\TimeJumpAuditOffset
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\AllowNonstandardModeCombinations
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\CompatibilityFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMinutes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\ResolvePeerBackoffMaxTimes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\EventLogFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\LargeSampleSkew
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Parameters\NtpServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollTimeRemaining
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\WerSvcGroup
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceMain
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ServiceTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Parameters\ServiceDllUnloadOnStop

Write Keys

HKEY_CURRENT_USER\di
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update\Update\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC119130-A529-4457-88FE-FBF15C010732}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6D7B88D-9C49-4FEB-A98A-A26428C8FEAA}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{740722A5-EC73-4CF2-978E-36647B729C20}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927ED4DC-ADF6-425A-AD6B-E23BD93FD777}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE953F1B-7ACA-431E-93D0-E1BCE08CF75C}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8349B91E-629E-4722-A113-510B026C2620}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AC7C83E-5EDE-4395-9CD9-742016DCDC12}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E21C3552-BC12-45A7-BE1F-1B78611E88E3}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75F7D537-96DE-4131-9A30-5BDB554FE619}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83A0FD01-58E6-4165-B9D8-27DFB44DB7D9}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{545BAA2F-8F01-4B0F-B8D3-ECB48F6501F3}\DynamicInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1B21BECF-4F49-4740-AEA6-66DDACEE4F88}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Performance\PerfMMFileName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72B176E0-4222-482E-AEAF-EFD2CEB5E239}\DynamicInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_LOG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_BAK
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\BITS Writer
HKEY_CURRENT_USER\Environment\SEE_MASK_NOZONECHECKS
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\90e27466c5b95ff431a99d3481615164
HKEY_CURRENT_USER\Software\90e27466c5b95ff431a99d3481615164
HKEY_CURRENT_USER\Software\90e27466c5b95ff431a99d3481615164\[kl]
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\LanguageList
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-100
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-101
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-103
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\dhcpqec.dll,-102
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-1
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-2
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-4
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\napipsec.dll,-3
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-100
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-101
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-102
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\tsgqec.dll,-103
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-100
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-101
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-102
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\7F06864B\@%SystemRoot%\system32\eapqec.dll,-103
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\ServiceSessionId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\TimeProviders\NtpClient\SpecialPollTimeRemaining

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
90e27466c5b95ff431a99d3481615164
Global\.net clr networking

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.VirtualProtect
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
kernel32.dll.GlobalMemoryStatusEx
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtProtectVirtualMemory
kernel32.dll.GetSystemInfo
kernel32.dll.VirtualQueryEx
kernel32.dll.ReadProcessMemory
msvcrt.dll.memcmp
kernel32.dll.WriteProcessMemory
ntdll.dll.NtQuerySystemInformation
kernel32.dll.GetModuleFileNameW
shfolder.dll.SHGetFolderPathW
kernel32.dll.CopyFileW
kernel32.dll.LocalFree
kernel32.dll.CreatePipe
kernel32.dll.DuplicateHandle
kernel32.dll.GetStdHandle
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.CreateProcessW
kernel32.dll.GetFileType
kernel32.dll.GetConsoleCP
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.GetConsoleOutputCP
kernel32.dll.WriteFile
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.SetThreadUILanguage
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
ntdll.dll.NtQueryInformationProcess
kernel32.dll.GetTempPathW
kernel32.dll.CreateFileW
kernel32.dll.LocalAlloc
mscoree.dll.ND_RU1
mscoreei.dll.ND_RU1
advapi32.dll.LsaClose
advapi32.dll.LsaFreeMemory
advapi32.dll.LsaOpenPolicy
advapi32.dll.LsaLookupSids
kernel32.dll.DeleteFileW
kernel32.dll.SetFileAttributesW
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
advapi32.dll.RegSetValueExW
kernel32.dll.ReleaseMutex
kernel32.dll.CreateMutexW
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.RtlMoveMemory
shell32.dll.ShellExecuteEx
shell32.dll.ShellExecuteExW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
comctl32.dll.#386
ole32.dll.CoWaitForMultipleHandles
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
comctl32.dll.#321
cryptsp.dll.CryptReleaseContext
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
sspicli.dll.GetUserNameExW
wbemcore.dll.Reinitialize
pcwum.dll.PerfDeleteInstance
pcwum.dll.PerfStopProvider
advapi32.dll.WmiNotificationRegistrationW
wtsapi32.dll.WTSQueryUserToken
ole32.dll.CLSIDFromString
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzInitializeContextFromSid
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeContext
authz.dll.AuthzFreeResourceManager
oleaut32.dll.#8
oleaut32.dll.#2
oleaut32.dll.#9
ole32.dll.CoCreateGuid
oleaut32.dll.#6
oleaut32.dll.#7
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
qmgr.dll.ServiceMain
advapi32.dll.SetEntriesInAclW
ws2_32.dll.#115
ws2_32.dll.WSASocketW
ws2_32.dll.WSAIoctl
ws2_32.dll.#111
bitsigd.dll.InitializeEx
upnp.dll.DllGetClassObject
upnp.dll.DllCanUnloadNow
rpcrt4.dll.RpcStringBindingComposeA
rpcrt4.dll.RpcBindingFromStringBindingA
rpcrt4.dll.RpcStringFreeA
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.I_RpcExceptionFilter
sechost.dll.OpenSCManagerA
sechost.dll.OpenServiceA
sechost.dll.StartServiceA
rpcrt4.dll.RpcBindingFree
ws2_32.dll.#116
advapi32.dll.LogonUserW
sspicli.dll.LogonUserExExW
wtsapi32.dll.WTSEnumerateSessionsW
wtsapi32.dll.WTSFreeMemory
advapi32.dll.QueryAllTracesW
vssapi.dll.CreateWriter
ole32.dll.CoRegisterClassObject
iphlpapi.dll.GetAdaptersAddresses
user32.dll.SendMessageTimeoutA
kernel32.dll.GetStartupInfoW
kernel32.dll.WaitForSingleObject
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
kernel32.dll.GetModuleHandleW
user32.dll.GetClassInfoW
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.DefWindowProcW
user32.dll.GetAsyncKeyState
kernel32.dll.GetExitCodeProcess
user32.dll.RegisterWindowMessageW
user32.dll.GetKeyState
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
user32.dll.GetSystemMetrics
gdi32.dll.GetStockObject
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
user32.dll.CallWindowProcW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
ole32.dll.OleInitialize
ole32.dll.CoRegisterMessageFilter
user32.dll.PeekMessageW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
ws2_32.dll.WSAStartup
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
advapi32.dll.CreateWellKnownSid
kernel32.dll.OpenMutexW
kernel32.dll.GetProcessTimes
ws2_32.dll.inet_addr
ws2_32.dll.WSAConnect
kernel32.dll.FormatMessageW
user32.dll.GetKeyboardState
user32.dll.MapVirtualKeyA
user32.dll.GetForegroundWindow
user32.dll.GetWindowThreadProcessId
user32.dll.GetKeyboardLayout
user32.dll.ToUnicodeEx
kernel32.dll.GetProcessWorkingSetSize
kernel32.dll.SetProcessWorkingSetSize
ws2_32.dll.shutdown
user32.dll.GetWindowTextLengthA
user32.dll.GetWindowTextA
advapi32.dll.RegCreateKeyExW
rasmontr.dll.InitHelperDll
nshwfp.dll.InitHelperDll
dhcpcmonitor.dll.InitHelperDll
wshelper.dll.InitHelperDll
nshhttp.dll.InitHelperDll
fwcfg.dll.InitHelperDll
authfwcfg.dll.InitHelperDll
ifmon.dll.InitHelperDll
netiohlp.dll.InitHelperDll
whhelper.dll.InitHelperDll
hnetmon.dll.InitHelperDll
rpcnsh.dll.InitHelperDll
dot3cfg.dll.InitHelperDll
napmontr.dll.InitHelperDll
nshipsec.dll.InitHelperDll
p2pnetsh.dll.InitHelperDll
wlancfg.dll.InitHelperDll
peerdistsh.dll.InitHelperDll
cryptsp.dll.CryptEnumProvidersW
user32.dll.LoadStringW
sechost.dll.QueryServiceConfigW
httpapi.dll.HttpInitialize
userenv.dll.RegisterGPNotification
userenv.dll.UnregisterGPNotification
gpapi.dll.RegisterGPNotificationInternal
bcryptprimitives.dll.GetHashInterface
bcryptprimitives.dll.GetCipherInterface
mprmsg.dll.MprmsgGetErrorString
oleaut32.dll.#500
httpapi.dll.HttpTerminate
gpapi.dll.UnregisterGPNotificationInternal
comctl32.dll.#388
advapi32.dll.EventWrite
advapi32.dll.EventEnabled
ntdll.dll.ZwQueryInformationProcess
ntdll.dll.NtQuerySection
ntdll.dll.LdrProcessRelocationBlock
sppwinob.dll.SppPluginInitialize
sppwinob.dll.SppPluginShutdown
sppwinob.dll.SppPluginCreateInstance
sppwinob.dll.SppPluginCanUnloadNow
sppobjs.dll.SppPluginInitialize
sppobjs.dll.SppPluginShutdown
sppobjs.dll.SppPluginCreateInstance
sppobjs.dll.SppPluginCanUnloadNow
advapi32.dll.NotifyServiceStatusChangeW
setupapi.dll.SetupDiGetClassDevsW
setupapi.dll.SetupDiEnumDeviceInfo
setupapi.dll.SetupDiGetDeviceRegistryPropertyW
setupapi.dll.SetupDiDestroyDeviceInfoList
wintrust.dll.WinVerifyTrust
setupapi.dll.SetupDiEnumDeviceInterfaces
setupapi.dll.SetupDiGetDeviceInterfaceDetailW
kernel32.dll.GetSystemFirmwareTable
ole32.dll.CoInitializeSecurity
w32time.dll.SvchostEntry_W32Time
w32time.dll.SvchostPushServiceGlobals
dsrole.dll.DsRoleGetPrimaryDomainInformation
dsrole.dll.DsRoleFreeMemory
sspicli.dll.LsaRegisterPolicyChangeNotification
w32time.dll.TimeProvClose
w32time.dll.TimeProvCommand
w32time.dll.TimeProvOpen
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.#23
ws2_32.dll.#21
ws2_32.dll.#2
vmictimeprovider.dll.TimeProvClose
vmictimeprovider.dll.TimeProvCommand
vmictimeprovider.dll.TimeProvOpen
ws2_32.dll.GetAddrInfoW
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.WSAAddressToStringW
ws2_32.dll.#3
sspicli.dll.LsaUnregisterPolicyChangeNotification
wersvc.dll.ServiceMain
wersvc.dll.SvchostPushServiceGlobals
advapi32.dll.RegGetValueW

Execute Commands

"cmd"
"C:\Users\Seven01\AppData\Roaming\ggsT.exe"
C:\Users\Seven01\AppData\Roaming\eTMMY.exe 
schtasks.exe  /Delete /TN "Update\Update" /F
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1099718948.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1252040376.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\498097471.xml"
netsh firewall add allowedprogram "C:\Users\Seven01\AppData\Roaming\eTMMY.exe" "eTMMY.exe" ENABLE
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\170401536.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\329645784.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1716263706.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1229163999.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1437883044.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1648046143.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\23487450.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\149537844.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1453879295.xml"
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1412547054.xml"
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\sc.exe start w32time task_started
taskhost.exe $(Arg0)
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k WerSvcGroup
schtasks.exe  /Create /TN "Update\Update" /XML "C:\Users\Seven01\AppData\Local\Temp\1277439905.xml"

Started Services

SSDPSRV
W32Time

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03_64 Seven03_64 VirtualBox 2018-04-14 14:52:47 2018-04-14 14:55:49 182

1 Host(s) detected

IP Address Hostname Reverse DNS
212.83.167.116 France 212-83-167-116.rev.poneytelecom.eu.

Host(s) by Country

Hosts Country 1
1 France France