File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 977.00 KB (1000448 bytes) |
Compile time: | 2018-05-10 22:48:55 |
MD5: | de225405f8e348bfbb5ba8abdc092b48 |
SHA1: | c04ad314f2a77275464fa9e516859287c9818e23 |
SHA256: | 473d50c8fbcab1a88603e67fcbf878acd761806f3c88b05195e75c2bbe8016cb |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2018-05-18 15:42:03 |
Last submission: | 2018-05-18 15:42:03 |
Filename detected: |
- success.exe (1) |
URL file hosting |
---|
hXXp://qualityoflife-lb.com/crypted/success.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-05-14 16:35:30 | [28/66] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0xc8d04 | 822784 | 19c3e1c8e7cb44218f31cc042db6e202 | 8e61991fe17d321fcfa3d80255351a1dac995ad5 |
.rsrc | 0xcc000 | 0x2b184 | 176640 | d4282a37cda1644b07fb074839f9d34e | 03814d85597edff935ebdc72fe7584ca6b284a74 |
.reloc | 0xf8000 | 0xc | 512 | e7cf008b3b9b20124dc1413088f5b1fc | c4d7877a6249cc1fb32b7ba2afcaadf5ee592ef8 |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_ICON | 0xf6a54 | 1128 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_GROUP_ICON | 0xf6ebc | 132 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_VERSION | 0xf6f40 | 580 | LANG_NEUTRAL | SUBLANG_NEUTRAL |
- API Alert
- Anti Debug
Meta Info | |
---|---|
LegalCopyright: | |
Assembly Version: | 0.0.0.0 |
InternalName: | success.exe |
FileVersion: | 0.0.0.0 |
FileDescription: | |
Translation: | 0x0000 0x04b0 |
OriginalFilename: | success.exe |
ProductVersion: | 0.0.0.0 |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
No IP detected |
URL(s) | |
---|---|
No URL found |
String too long |
---|
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD |
OtpkAH9oVDI3bbyQNY2a
lGMkX41dDMsYrx9nG539RU1m1z
Kn4saNwKYNhTI4wVle6xhUplBrR6DmR2RIR
Ubsvv9u6I52X42eaBuUagSbuxztycb
i7hqAU4D9OSIGcFzIRM3q
5nijF4FZZ081KNSbSB9MsOeFn2V3
a5kpendyagDFZH1dEZH9V8BuBq5wh1
W0qiYpPNx2eel2TpRDxbdnegm2fHJFhTOMCSoO
Translation
ZW8sL3NLlq5IpCIQKBImKGw1rSc6
V7CbzHDn7NJ18eJTJGW73AlaogV0RZBl
dHQPcrBaLFfu3OrB2sg3PxGGyJ5X9G4O1f2k
MIhYQSNjbIDqkKfZFSMLoh0XsisceRat
ypAQfHjTHkbg5aL5rjVdEpH8u0E2EW1ZqhTzHPK
nQXXwbMJosd3gZzURmJvrcBv2hRtaFRg
9ElEQ5eJdjcPfaHjZAlj
Ef582dyJSEVPfrNydhfnoWNT3DN74GP20G
6jGIPnMfoXxSrhyYrNCK063o
LegalCopyright
jy7mElSOl51C7IBOwn6qxd8prAeiRiknUO
6hu85qVFU5Jk1sUn2aqDxoW
zVpEApVZyuMWgUvL1SFAWBGFuSBvVE8
lQEg3bIKJ5ihKpgt36mAfSBVIsYHoz
SRvPglgKBtFKSfUbqjPfzQ
VarFileInfo
0RU
BJsf0ajUxoUyudQFCu69dPACnmWIbwK1l2J
xW6jUaPudBgj94SLcHmunT9rNzltz
xu8x3VQI8BoF0O2M95YqLu8bZB
RpRlVvwfTTpGSDdyXRDovOZ4m5
SXTDJQQvaQ4uwH7uS9fmZ6dDj8LaedqWNQiH
5qaK0QiouO1H0pBpZUae2t7Wt3mi8Fu04K5
VAsL9wjn1e6HlLkHIDYRQ3iCqog8iZa
IlHOiYbYe0BNr3S8zIgCZq5202LaJydkox
NpnQ48NYp8xstpZqewfvKOYWmNHiQ0yZ4xhFNm
AVuj5WSGglWp8UnPTkQmpZAJZ
zw0v59SAmpkowEImzyIW6HpkiZc9cmL0oqcd
70vXw2yJJ1dafv6is18CHQygvmtGz8bYe9Z9f
f0muY6c5zfRi1kXKD4xs6WOvanKMCVmQG5GcfYW
PqyhDxL2zcqnTxEMwAkkaAuTcoXhbUB31yW
wFGfXrC2Vo7xWzrgjQ7qzlJ
tywKzkpsk6lHZpqyyi1l
bVun3T9vYNB1wmcD6ozWdYsHSh03C5EwnrAh
BIbvQwt6CYcQEtX3MZftPB3EBO
zUHQ3T2VS3K56oh5So5xuXbgnNa0tUSIYH
qOZjWk6S083nzOhlGdIPqnQzjnvC733
JFJJLF2PALKTyqt22Ov87CxyyA
9f8qjI4xgAL7I7aG0XIyzJmPPFXxlK0d
tGwKHZ5B0FH7x0tXLPRQyOyBmWFV
E0onGhbnNYP8DCSYt8gzo
HYvAD5PJ9rCMb9WRVctDHDiqFPELIA
9QRh51A8hQdC2sLwXvlz
rercUbe5RWQLdpnXsUIonSBGSKTRog174kB6Lx
5PY592oEfRnjjXWFXYVh5nS6Bv
a9vG3ejDnxUUqwjOGg1wVhGirs
f7m7jJDwu75E55EL5u20rY
LGgJHCEKs2hHlbw4vmf8D
NOGTNVJdXTMP0xnX3e0kT7j
7q9pEWqXogH5OifCdW6xi77srab5BMtt
ofNu5EMvCSCnfBBxjrBfMuqWnbLb775F7vRlm
wvp7OVWhzZ1WhncgADUdUbBKhqdrYG
PTBXJ8Cud07U9gLmHc4JytISoQqr5aG7ta
eUXZZRlp6shDZgeYSgBJPAobVoUcflf
InternalName
vzvyuIpOS74blf19F2cNJqeCYLrJw
VS_VERSION_INFO
13j6vMoIVt6Z3SW7MK88pwXLjUOxy9uKHtmgP
9V1qrakZZDGtnkR5I2Q2PgmFSgqQW9qux
3pebMxEvaHiARPwq4mwiKPvT9E3Wkf4nh
Assembly Version
Yfj2Lbafy8b8re70ClGI2cK
ZTL7Tli8h0Tr1IZNZaQ2KPMRmfvvT2CoXXq
XRg3JIfo6IgvspPstqYPMad7LuQYVNB88GvJx
UHJfODbzsQaJMcCAKMpOHMkNgV8hM
j3dZTmv7TVxqIN2Lvqe6GgOk6X
WYLoyQGwgZlekXbC3c27yCX6aZx1wyReaG4M
mXbpasqnrDj0EEgAjazSFj4
Wg5jiMQ2ZMCxKyAzeDFHrYP
5sQ5FfbVfclB8WzZEgnYN2PVhARB5vWe1DS67H
JK7FKlZVWr8mYb8ttV89i
WrmwxPwV7NkYf3wTBLEMWJekVcEUS1o
p3RmL0Vlkc109ACG7gu7wv5KwDaa3xIs8
DOREi2w5bbuO0EMAHz4vwdhhuKBv0nqbZ
1yAPmlKqeGEYhJxBafisEoZ6MSvAXrG53Z
TrROp0rEIZyHmYKhYXYjjudYz46v5
dfbvsll5RicscipDaC5tvAtwBJn29CGihvg6
StringFileInfo
giSMubHNhjXqukbm0v9agYio5GuE30w
FileVersion
BFXB6uj99U0XFxc2CJhQWyJTwpQzVpcAgy
000004b0
ProductVersion
FileDescription
vbiabZuaOGjIIbP26gjZAPPxdn
0.0.0.0
OriginalFilename
XYYUbDYjTQpOXMTb1gAollM2TJY
jPI1h0wtLnyEZpFCnrS83N3TAETOOuIs3Y
AAnREUjwcGvf90aG1QmY
success.exe
H,y+
}t9>
gPMS>
sKK1l8
IZq
39+b
o]dL
B|wE
7KdE
~rNx
DFSeL
Cky5@_s
{]&oi
PNG
Cs2
{:
WR8
P]RP
jhO2d;
|;TL
x $-
;; 'jS
"-|f
w`#9
#sgE
,;:,
U04q
8<Of
y9
fcUA
eZ0B
wg_^
im@AD
W:lb
Y 0
6jGIPnMfoXxSrhyYrNCK063o
^(0(
0E|R
d0H2
:~*yC
fH@i
/|;V
71{r7k
SX{!
A?B4w
+RV:
v!Uf
flSg
MGc:&
V[\%Ly
B(?g
FT^
]P5[
:P #C
@amuRu
uQr:V
tjZH
4-=.!
yH<1
?[qm;Nj
m=]lX
SbM_
s{i8
L=`2
\]\
{sY9
`n N
0`{a
]$\.
p!(S
b[4j
>Xph;Nj
_mI`
v|5 K-
3?4<7
i,J
wZ\Z
lt"-
(U,I
@*\l
zpW7"
K/?!
57s{
Fu~`;Nj
A/Rd
PtE{
=;V}c
qGBT
c T>
*\x0
h3j2-U
)%)_&
+ZK_T
{.`
eSE)U
\q2g
D!nl
BX=s
|lB8s
:F[y"6
$l >m
3fgC
w kq
(KvY
SFU(
)jux
v=wF;
:2cv
7$t%
U`CW0Y
,^s|9
d5jk2f
$dHQPcrBaLFfu3OrB2sg3PxGGyJ5X9G4O1f2k
kA'J#
|Wos
%@pp9
g\A@
x8IC
i%q(
Rl#/
uJT4
,Alv&
TK!w
qao.
j5Wmp2#+
PA!gd+
eZh/
b T_
-}u.;O
0!:!
AXj*
\av7|.
hWmF
\ lQ
yMI:?Z.
}Q+e
n_?0
@nn
AH@6C
zb?l
>$P<hS
$q'AXMs
Aw8%#G\
9dz
ov&y}
>Xpp
{{hF&
V}2{W
xm-4
7)G/\{
>[p,=Vn
|7N4<
Hq-[
<Rk[;Nj
EVK-
nZ[(
xsvz&Mm
$FxZG/
9@{~@
UC>E#
q(.c
%b#$
%l-V
j\ZBHmg-
A^+1
+%e]
)QE<$
>M+g
>Yp,>Wo
kcK9V5
,Q%
}"s!ax
+>[
7ekQ
;.`I7"_
;PkO[
i|'2
:XTG
System.Security.Cryptography
*Ruq
F?x)]
f=e1
!49 yQ
GOqK
qrZ
NGh>
s|:B
1aLp
`H>(W
m0Zx
\Kdg
MlH{
7Ug1
Ol9;
<l=#c
%ed9
H9i
#1OI
]L^3
q "$
(~A!
n\mT
(+/d
cip}
IR8%F
((s`
b=(A
'vh7B\7pE
_ ?>
UnverifiableCodeAttribute
->kRzZ
1`FZ
s_0TNtq!G
CQ]~
5kP&
ynMN
w=@
`Qcy-
9ElEQ5eJdjcPfaHjZAlj
Cfh=
"Fk2
]%m-
\`TE
P{Fo
<yJ\
[S7
8+Il
>AN
k 1N
f7cr
~2]8
*0Tt<|
"2[H
L/]
[=]YP.y
,:(L
g#/l*x
mG`d
r*%w
a9t|X/j
*m6
AxF&
)lb<
bFIp
vK%M
2KkG
pgsZ
4 7
R*oE
Ql>I
DVOw[#
sst,u
=B_#
V(Z2
C'R{~}
M& ^
#t`R
>YpP
D*tgf
+,r&
tzz#
Dd9Z
B~z6
G#Is
>\%M
Q{r
uqM#7
p =7
5B.M =
[`w0E
oD)D
"4Gs
;1Z\Pn
3=t.P>
9;G>
Bho1
*b\
/99B,
Bgw_
#ZTL7Tli8h0Tr1IZNZaQ2KPMRmfvvT2CoXXq
&eaY
=Tm<
Fwww
;wA:Y
O+aU`
L?8{
yh"BI
CslC5
/;Ju
kq >D
slsN
?6r#D
[~\d
^D%n
[!D
6J,%
0vL>W
9<a1jn
$h
1^>l
6WOP
;q9I
7{^"
jJ6WS
8o&o
|ipB
x(qc
;%4
voW'MI
XHCw
6^M
{:UfW
&B_vj
i!v,
5qbD4
Uy?E
@^tc;Nj
nq1
>Wo{;Nj
Mzn:
I&cb
AevP^
M B~i
pH;y
BgwD
Acw+
N'%e
+!t<Z$
sD{9yA
C|6M
96$i
Acw4
PzaO
FrJWI
R7z Si
Q@,
>Yq\;Nj
@b?0
HKDq
o-d
K Pq
Z: ~
%XRg3JIfo6IgvspPstqYPMad7LuQYVNB88GvJx
}q|<D!
E\l4s
kfoQ
.text
mMFt.
!|QP
8 OE
Ciz,
/k({
.'41
^:J:d
Y{*jg
J!q
}$7
aVIt
>B%
vPV>
DiznBcw
aY;8
!<4
:rNO
j0tY
_;~$
5J8Z
?]qW
Gh L
YyBs&
b7+^
;']}
vwkb
!p3RmL0Vlkc109ACG7gu7wv5KwDaa3xIs8
_a}c9Xrr
K|*Xl
(JY@
*Ji<
t`/{
\%eI
?]sBdw
.6r/
W'YG
$k,z
\BiUy
JfE_h.
lVH]0'6
NIoms
YG6oAmU`
Q9."8
@`u%=Tn
Chw`
LLj
|tNb
:&lM
'Dw?
@Bb
i#\\
Xb-S
c'$w
.cDK
!Av@
H^(BL+
Z &&(
:?
#DcHi
v:n*!'R
T}5$
4nJ;HJ
,&e*$
\g17
/&
;(-f
P]:89
8EgG
Nf>~C
c|LO~
O`SW
O3 4
_#G
Yg7qlT7
q$rj
rBZZ
z@i3U:
M$J +
@`U4
YHyPEz
-tas
DX)[]<
Z`1O
U_oA=
v^G`
CreateDecryptor
c%MUE
B%N<
Xuk+j
hfTa
i;2A
TFQ@U5
rK*e
%gkJ
,ba$
*C7_
>bs.cb
2E-<%
(Nyzy/s
ez-P
]33=
wF=]
.ctor
XYYUbDYjTQpOXMTb1gAollM2TJY
nXGKpG
o;5*
u:NK
g0ac
y- .W
C]IY#
8YP8
\Hy9
d89j
wNCzg
S->I
C*(
g_Z'
%W,T
)_~
>Yp~
z/{6
)ZfPb
XIFX$
b'Dp
d[a"
t=Ol
nn!M
Et!TaP
2WHW
9d<D
AcT,
i"S=^k]
!iGx
)7Iz
S`VH)%
%Uxl
7~),
n;#TK
^)lVpB
R9Wl
@N)J
JN&Y[t
p ^x; "
Re5r
f9O-#
9Ey
~uI}
L9%E
1-J
YIar7
:U\Y
O-djg
+T p
8K4
{Fj2=
,k'P
'ZMo
3FBi
ZdX+<
?[r7
_C//
TA5w
sw[L
b@xf
r39;
&<XH
Pc0_
hdP(
\ =V
Tk1_
p " ""?M
NZt+pv
]aZD:!Y
a( $)
kjpD
mo4t
5oLBQ
l]rt
<]P9}
>`2R
x'"_t
@(G$2
veb<>
G%ac
s( b
AGaF
Gj]e
Be:w
ahu2$
3 <T
dov.9W
C\]RO
]0^#B2
S!!-
4,4C`\
8QcB
AduEJ
{jL2
7#S\
bI>qY
Q, $
get_Assembly
~ [[N
r~Si
Z\&yvl
5),@
[ST@
YV@1n#
?q8d
90=v
>dx;x1
O!l O
1qk\
D00_<
w J
h4p;
2ljL
*$Xo 1B
!W"7
l3BY
3]$
2M04
!&IN
=Unpg
"7K1
<QHP
1kpn
mmv!a<
]ic*
'w|C
$hB<
L0r@
rV/4
$S=4
ZKxR
=VoV:Mi
s"i3L
?\r!
xnEc
tHKm.1
8q5|
9:uR,zAz
aSYH
>P@p
;Sk Hw
^V85N|#
G6RX'
bB h
+ p'
0(/'=$
Fn%
?\N2
x^`j
U]-
#[;1
?[rY
rw`}
Lw2il
O<Im
cyrq
A[\M
QE::
>p3{D
ap;5/g
skhx
%NSqu
&58t
&-1/J
Acv
}_dA
;SCU9
<Snf=To6=Vp
{&N*
zaV+
!3pebMxEvaHiARPwq4mwiKPvT9E3Wkf4nh
mDdd
><tLpq
$'tS8
W2 d<
n4nV
{DV "i!
dX LI
BRR(P
&_uf
t}Nt
)WP=
PG
CZ:1
r&Ip
EOD@
RU'+
LH5P
r9H
vE}Ku
sTmV
System
~1;E
g +V
8 S)H
=oNU
jUT/
[UnYF"
"Z<vY
epNqE
?]s =Un.>Zq
q;1#
/m[P
]2ni
%&b@
brkE
:Q2S
0_K
n'Ae
u%)
I8|y
3 zC
J:4%M
Dmz3=Um
IV(hVX
+QU<
MethodBase
`8mt
DYA$/3qw
;!<0
yHv{
3My
0hxlN
m d=
(#2h@U"
\my!
~\#6
:v'K
g Gi
Qje4PgJ
@SJS
\e$1k
Nr5Il
O/|K
6ig<m
[ I"
!`Ve4
.IN\6
J+Y
`BrR
?[r#<Tm
+i$61&A
?d+T
u BH
@^t=
\W_2
IfGQFp
OUae
+ B~_
"Ixg
nLsZ
@^tM
<2 S
tAMVJ
bp(JS
@^tC
0 6"
(NC1
@^tT
KGuO
UcM*
OBQr
6)u^
%jlx
*qh!
yz4{h
@^tc
mXbpasqnrDj0EEgAjazSFj4
XkV
92\)
r7mV
"8=K
$S /
Y rf
ry~^
Vs&_
=y](
4G}
TbJ{A+
s1`)u
CGK2
_wPU.)
Y.7NI
3S\3:
zRj:
?K9`P
2-Lb
Fll.
u(g(
#%5X
OW$k
dw>;
]6%c
C,/<
6s~ i
y7!!
)e-~
}+wg
[r_F
=Tvmvp
?M Q
wyl*
{)lBc5
VWDd
WFg]
fT_U
S2 $
4G}[
HkP;
J *5q}
6(T)J5 afH
h6w;
sci
$Pk,}
h? 0
a5\h
UmY1
8b,Ow
|F6>e
f{cVlY-
xPr3
W]M!6#B
_CorExeMain
0$Tw
,+#O
3mIi\K
c?c
dg3")
A{)NoQI
|vd{
?"H`
w{~6
Er|,:Mi
!hmJXT
wGN:
I&D0W
'}(~
,8TrX
[^ #~~R
=E}X
'$d
G%O4
=Djk
& }]
fro$
<bK"
F?.]
_%lZ
Yfj2Lbafy8b8re70ClGI2cK
`H+mkM
&I!"
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
}rCz;
df}L
mU5$
lO-a)
z#U6
m^<g&
t`F5
cf|~[
Xu#D+e
O-2
sL2'(
;YM5
NEwX
h$PA
H>Z $
M/| fe
6=:07
BAk>
gU&&_rw
=VnZ
w*`
}KrI^n
!Vt\?9B
j)9
~)ur
V& d
@|k8z
F2 (
BsVG
'MO-
fw;oCM
8tBv
W\J%
x!D}
o?W"
OUNY
Z}Ad
;M3`
P`*4]
y]n-
DE<Ki&#
,CZ9b2w^
Aa&$
AA=p
Z*Tn@v
Adud;Nj
_/^V
iW&2
I{0a
?}AP
?cHk
ba{F{
["AGv
V211Rw7
yc_H7`e
Luwk
>XvVrb
Z`+g)
&J:X
1 VG
^<2(
;Qk0;Nj
p2r
6 U2
ze)/
/>Xp
kg 0WDysn
y-4`N
A3Q,
j$4_S
tGwKHZ5B0FH7x0tXLPRQyOyBmWFV
R:LN4sMB
*4 o
'S Un
o+Wr
CW"6
QPlW
'zhq-^
?[rx:Mi
?Zqp:Mi
-vTuF
f7m7jJDwu75E55EL5u20rY
{T0
?nn&
(XSq
n`hLpwO
ZQsXC
7NK(
Ryx*U
Z",D
9g1B
l8)'n
% Y$
<_.C
5gkM
pSPN
Y9f)pU
Ciz|e
<5)[-
aT9h]i9
A8m\
'JZ;
Bd@=
fcU{
5Jn'
n&y&
SVyf
UVy
ccaDO|
M'2lU(
`<;i
Kje*
7Sxl
C>`w
c.Cl
">@2
6JR5
/ FnMa
?]3L
S&EIt
NIk1
c`N:4
!o]_
{o}e
Sagu
`+}7,
X`:!3
en'l"&
#:=O
c6vO
nS"3
=x`y|y
#e;I
Da>:
f`]Y
TrROp0rEIZyHmYKhYXYjjudYz46v5
Yy7gMf
M6vo
88@Z*
9*e4N
:S?3
!Q^1
="9$
};:f
|Nmy
RB0SzE
YD]a
mG,ClDr4
\ tx
;LVl
@^t|;Nj
qd7|
]d _5M"d
<m_`
Q0CA
]Fd%
Cp7zo
^ D<
i9&B
~<Rl
26g8
P7)^
cot=_a
L}zi
L4HS
x.;~
ToArray
(>9
ffk
3i0j
IU1Ot!
R @Hb ,
1uTL<
.7]c
Q+!C6
D~-oMkA
s)hN
^\?Zz
]FtI
&%9]
@Wr
|}'B
1.]2
Q1W
2ev^
3i~Pv
ej Dx
=p$U
9R;L5$
^J&
3G`a
?ZqE
p1&Z
=;8>(
E%u5
?ZqG
(0Z^
;}Ybg
NH:JA
U4<3L
3G$ur~
0y{K -
?N Q
7.z^8H
tz{rL
aNu
?\r^
5n&b
pKwrth
*v1B
ZdOX
q*c'?@
t^q K
@`u:
kXoK5
I`$|
pdus
y@j-C
C8>jR6
* n
^/ k
"9a NB
;xb5)mt
~ 5u
E+I NB
06o;
Q9f8^
z-s|A
sm6'
bTQL
?%^
&7*X
F]R!%
?[rT;Nj
1ou@
C;7n
Cly
%*,"
zBHdsK
Y[NC6
F VE
Io#e
9 /t+
R=i U;
|S2=dw
l;;H
UXME
Z&xAi
6+:`?
DKk
c :=
$-]D
5Td4
fjr
DRX%
OS}R
Q5(.
dp8
_4ie
Bh!YA
G[i
+u7-#CXUh
L/ T
(&p(
SlBYB
3F4*
V>$zB
S$O\d
"1yAPmlKqeGEYhJxBafisEoZ6MSvAXrG53Z
I$hZ5
&5O6v
<)094F"`
:jF/
!Rkzo{
QzH)y%
CO!'
9@tr GRy
hDJx
/6R'
FbG
EV9Z[u
{8U^
pR?=
'XtN
?/e(
^z2d
q:W9$CSe
L:+y
z47[H
V2+q
ec8=ft
mV(s
q&MU
=X)}^
.X 7A7
pTBS]
xiB)
aWW
^Otu7W
m5G.<6
=%fM
<Sm)<Rl6
D:H;>
zumt
"*'
HY+4
CfyA`uT;Nj
D k6
e7uEX
EIHoq`
0Z v-!|
EBFs
aF:\
bv\}A&
Pn?Y}}
notr
[5/e
L4Z%W?
q<Fhl
f+ 1
BWQ|
Dro
*JfR
TULe_dr&4
;~@\
A?;U
<dR_
?lc
k[_'FW
e#w8
^<Wb
RB8"
RY7&
J.,j}
k(]c
^O(W
Bex*<Tm`>YpA?]s
l\9I
zYi@
\@j8
e\Nb
\^0)
=Un
)xx[7
4bX,)M
Qm7WD
ow64i
o~8de
*v^
oL'A
N:(v
g5V?I
xNv"
a.FS
b#vKf
w`e>
w|,w
}*X.
NJ;y
DtqD
j}M|
c"2r
/ksU
#ukfG
5{@.
0>Fw
sJ)(
/ksY
7%+@"
mvP
vD*/\2p
&6@
ds7g
Vw.0^
~zNl$
Pz08
"Vjz
Fo-*T
f)R3
dIvkF!S4
jZ8kW%
.OO
VpO2&
@:u_
-U`M
EK,?J
#F{7
v(ltp
45eIi
> SH
/`GySD_
j%nOe
d2HW
![?#DRv
P| :.
+P_i
#uY-
=77O"Y$
~~~!
`N\9
E tu
6q1M;
q:T
Yfs
F<)# v
|~-M
j,x@j
-IlD
j5.<
KE 2
pg)5*
6_P
hp;&7
R*\}
0'+L
qbNp
=)
i5Ct
B!%
i<Qc
'!=h
~II|
:KdV
bs(7'
"<|o$dL&
<{W]
0UrG
_uH/
Ltq:
()dq!*L'
>vq9
?t4B
vbiabZuaOGjIIbP26gjZAPPxdn
P)yX
V@I n^P
8]H
NEq}
Us[H
s r>
t"1FKo
qY i
f@wi
_&W)H
[d![
D!`4f
|5aE
|5^ft_
5*o:
:;J+
#nbOJ
0N|e
8RBu
-Q
`3<r
U%N.
,RsP$>
`sr%
FBe:
;C#X
6o!@
(JfJlzT
q+DWt
f@R@6
"zUHQ3T2VS3K56oh5So5xuXbgnNa0tUSIYH
RuntimeCompatibilityAttribute
9EHztP
b.:z
7TN9Zl
>Yo\;Nj
FQ'n
wu5^+l
}{P;
+A_}
Abt;Nj
8&$r
b;Q{
s&&g
1~"b
F^iND
OnN-
j/+S
BKZO=9
]9GTBV
j~Z*/
hl%gE
>V
n(wur6
N? K
7nHA
ISp=P
ohWw
~q Z.
MxE+pl
Kfm
jc1U
U3Cqc
1 [:^
G>vVc'J
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
kx
%4N;J
da/G
-*b,,(
~tIo
YntP
f7Z}
AHr<C
TfH7
M7rR
0+ $
qXcP
sNjn|z
*hM~
&z2S
UP"i
. 3
UX`
[dq'
;iSHe
L"CZ
a(p
#BJsf0ajUxoUyudQFCu69dPACnmWIbwK1l2J
4 6*
H2<5
"&SB
&=Tn
jjPv
`BUR
X3T{
RrOu
L`EM
_~O)A
^M0L
;8^S
Do{(
=Wo9<Rlo<SmU?[r
|w,4
BDmd
#]4^
ku hj
q~JF
1B][
mk1u
@sGa
u`Ff
=Umr;Nj
,CJ/
jREB1
CvnC
([a&
La`QC~
<2"fg
2V=2
nfmB
JRsS@
3 Gx
adB
{sc;
}mQK
ZQOB`%
-o$
$Oz$?`
x4uD
yw$
v0z
/c:$
OGe
'U$<
#Blob
y es
$0]Vc
8OfO)9I
x\=3r
azY"
(WEH
l49"
LtpRKR
[hzi/
/;+z
ResourceManager
{/ti
D|Z5i
,y* $
Z#3L.<D
tQ-(
Bzo3VlE
BcwS<Ql
=x6-
LyRr
m38TP
ZC^hL
4P$F
>\g8
Pjv&
>Yo9;Qk
/8Sv
pg1f
C3%z
NQh-
Mw,-M
TkJX
Acw*
Mh
64yA
0zn
A;Y-
rErX
O#p
=Un-9Rg
r 4#
u>#H
P#jl
0,{Jmm
d0J
itf0
cg ^g
^.e@_
4?6D
%?;;
i}LA
>;Er
O;p![
aW|.H
?ia>
UZ;f8
^Q\F
lQ<t
vrP^
A`ue<Ql
7/(e
,@%z
l%l)A
8[Ix
F 1&
g?:&
Bdw Adw
)0s"
An %
+tW
jgUH
3 j9<
Nyk+
Ac`^
q)e?}
nZA2
]$N
#Dt
VO][
?5/]^
2s5fc
$"W67
wvp7OVWhzZ1WhncgADUdUbBKhqdrYG
0E]Vn
byvy
m!;7A
aWbN_
U`M
Dyt
u?N^
UC*O
6UWW <
,Pa.;
^-;p
(Os@[
xL{
Type
Z}QO;
Z$Fs=%
g3SGYT
/ )5Xk
aRtB
ZPK#A
4CbSz
dZh,K&
>Yq2
m<1f
( <%@;
<Ql|<Qm9<Rn
8qf=
)#yv@t
txNc
N@|<
+4J;
m{^}
+b>m
Wo^KW
Wv/|
*';O
0\3]
1r7&
!P+
Aj1[j
R$ 7=
a;n%UT
H-ofa
Nu+}p
y[Z0
Bcw#
eH1:
=UnB;Nj
B;\3
dfT!
0cxX
r;3[
{[@Q*C
JjsA
@]zO
\]MH
tk?Y
QpSRUmSNR
gEw 'nsd
34Idy
wy*^~
GgZW8
^8)r
"P~N
f3,j#
mV.{
qJ@
G88V
4'8m
1iG,3
<*fv6
CfyC=Tm
r%Vm=
QZW@6
C8.0YOw}~
K@Ag<
pFz*
>[pP;Nj
&$/>mY
(9&]!0
^YTD
x+aw3
>Xpy;Nj
/#F,]+
oj|z
gfT
HB_P
=UodBcw
x_vf]k
mscorlib
'zoq
Aau?@]s
Z1`+
ii L
?[r"?ZqN>Zq?Bex
g2InU
5y6w
2 4<<
>YoB;Nj
e{K<M
ISM>
5+rI
ye ?IT1
~7@ji7L
#BJk
_J[&
t+Ev
BD'c|
:QUd
|,Bh~
l`(X
nR>8
O:H|
n`Lr
? l4pRA#
@?c\5
)HRt%
fC:8%
*-M2
'W3(M#
ZW7
&D@W
=oOE/
rT8G
t=}}
S<W7
]#q?
R_b
SEWS
OjLK
;QkB;Nj
}:e
ZP?a`
@X~7
Ot!(
aD ?
)"(gr
R7. o1$
$:j
yG
t6'GK
9Xh{
-bOh/
Xbzyu
g?r0
VAsL9wjn1e6HlLkHIDYRQ3iCqog8iZa
_<&4_ |
ImWn
'cl>n
<Bem
Iw%Z
4 8V
ty>;
h.R
<_*h7oh
J< R
w38;
,663
m`, @]
Mz,
N<qyx
Nf=Q
]Dr:
a3LP
|/Yw
Ma}%
I0H1
FvY
#&>L
g A(
.l:/u@
=)KO
Z|jL
:1p~
-lc
?mZ>
!ET=
RtM*
-lr
[& R
p'R;
M8ot;CcI
3^eW"~
{T3bx
ur'oL
hD|:
^0LEp1Q
rpZV
B B_H-R
?H*
XQNz
SEiM
TuT^
i\BBD
H;"1G
RN{|
FjKrW
b$fa
V|1[4{/
R]qP
a vw
$pPY
=`W&
C0=P
l\s"
,+/x
u`tD
<o_z*
^o6/
!] 1
g;3*
{t}8
&!^:C
GY=Pi|
%mf
?.=x
a vK
Ul e-
FB$x1K
>Xpc;Nj
9;-7O
Z_- ~&\
R9 hO!|
]~~ui
s9bW
m; /~
~p\
d<?o
B7(}
dcTq&w
k:0
/w%v}%b
I3+
Cixt@as
4PA?
7LjQ;
o9A9"'
w+#.
jd$_
T*@i
PjS%
,h,Z?5
`E1'
:Q /
I\p1#
M._5
?[rd?[r
R=H PU
>Yp];Nj
<gm?
MjHB
_xfN
vb 6
.uk0!0
l[;!
fQO.
Cjx.
6ufp
`HIu
Pez
hNnJ
Q1?H
!This program cannot be run in DOS mode. $
OHoQ
$@Vih
w}d2
*0u
_d-
*LNt
'\#u
}cnxm
A ;`+
6X&Z
/kRc
vv;mV $I_c
-D~@!
@^tw@_tMBex)?[r
Ln7
qt\1
!fJ}gD
=Un<;Nj
kmZ%p9
A'0@
&NpnQ48NYp8xstpZqewfvKOYWmNHiQ0yZ4xhFNm
vq{3
j{*w
?8z0
~P4t
Xuj`>f
o2Vv
[.nc>
vXO*&I
"'^y6ij
LIP<
1\~C
$1sW
5| m
XHa8U
1E,.k
Bv(i
?\rH
akUP
2 H
YE:!
)5iYw
q >`
O,\|
[xm
LE&,
)tOO
=K:_
0O)/
IU.\
"PTBXJ8Cud07U9gLmHc4JytISoQqr5aG7ta
T!EI
e_]^
)Do
Zvf+9i
Yuc$
9sh}I
>deQ~/
^+TZ
M6zR
Z~IY
fC
1~P7
&:[V
%pB:.
]-`1
[M",I6:
3XY^&Gm
hm66
~NTn
l<ZXp{
l=|xF
SO8 z
\j~*d|
e|\ij
DO|d
ktL?l7
+B= B
j-/@
lp(:
_.I9
?<f$
?#kE
j]EV
~rb
JW@]>
lW /
KW7Z
M]\i
j[w)
Z z
Q24N
wYu3
pP4m
bki#h
:`p3
" a
)W5X$
RpRG
(3SJT
=Vo`;Nj
xp=L
Bps$
k@Oz
WMBS
6Spt
'<!I
6m.i
kByd
Po$^
M{Kk
J-$Gn
61SN
w*r/
:UV
lT+/
V ic
j3=K
BO%tm
I@cU
/Utz
m{)d
1kv
/R`hU
ogD=
R(Io
[8ol
3~YN
BF1
$F\;
{+v5w|
1J_:P
Z$u\.
KCE)xO
xB |
I?RqB
Eq+_
m9"q
6kPL
5aZX
Za; ~
]:z
1le
<Sl
M)-E1
|8oXd
TI~)">
#KS
:ymCc
H7-|
lmW\
P/7'
x2r+4!wo[
=Un<
?]s5=Tn
};-8
=Un3
;qT4}oSzp
=OSo$t
xSl&
=!$Oh
k,k]y
KLwm
Uo\>
=Hp(
"n&z
Whud
Mub#^
]732n
o3Mj
ZQ{~m
;>\KB
=UnL
>|G#s
=UnN
/@&T
q7nV
=UnI
6muZ
|H~
u0lJ&
8LS`
s4bwR
1?r^
&$so
=Unz
F<|d
2U"
' E@
QHl8
k!^R
Ivjs
=Uni
v;AV&
F0a8<
(nX9"
v@]q
2|W(4
&U <
ir=;
Z)_k4
-v*6+
S)%i
F]59C
4(AW
>h;?
(_ g
%skdQ
?Z?=
2Tuw
1u
CompilationRelaxationsAttribute
KZ-b
I I8|?}
I!8p
L4)x
pG +d
,v=OT
.j x
d{? {p
y-/2
]Ti
"P|X
'j40
JR1/
:\'[a;
@_r$
gx\/
I<<~t
.l!
@_t<Sm
ky W
}tg*
&;\w
f`:
-L{8
;OjK<Tm
QX9X
y-[65
~w>'to
8CkA
M'<L
S0$D
|@xh
U?e.'i
!_z`{VBu
9-DA
nlmz>n 0
..7!5
?\qj
=Um\;Nj
UCt;a
\7IGi
~N]h
a-8l
$#pL
g'`g
fFj>n9
V G^
>Zp`Do{
?\qn
!?dAq
Qp8x
Ndfy"
G'p-e!T
{N S
8< c
km@<
YI.~"
ui}/
]s5u
3(Wv
?/5}y
K!9\\
HS}?
1>aNb-
Sj=D
H%YIn
2,ev
&QG@L
*qf=
d%8^^,
+Q[Z
p(IG
v/`
kh=2
[xnS
aY{Q
gN0"V
]~8#
omj+
o4~,J
IpHg
!Vld
d8,(2
%7ikGt}
hiav
Ir+r
F=W'5
W|j@]
5'5A
-nQ.
BkM
I(7 U
]% H`
+t#n
!Uz
"=>(
/Kx~g
6!kG
V?=r
e|%"
{{pS
m~vOqs ~
e#s0
r[<qOx
K;xA[
L%XBk
g1`^xZ
6sR'
@jlR
nwkl
j-B;
Fe0De
&I,X;
}iLR
y&K;\p
\Z
'}}lLQ
)i<pV
s;P|
]4-6q{
:P$e^
%Z.O6
>Xox
"du'S
I76b
qNm[
WU#zr
Gpzox7
/ym[Cz
@`u3=Unx;Oj
4w-}
FaQ*m
hFv`6}
JK7FKlZVWr8mYb8ttV89i
bW /j
5c0
K3r2
L9 Z
YBuj/
KuSZ
F-)/JJ
J*6-
'FIEO
dm[5o
<TqwZ
p<K|W
.aAg
Yi>^v
o8o<
U5o>
e9k36}
<h^(
r|my+
)6z!
}AA3
@j%!m
P~ #
Tbw\
9 Ke
UhqX
_b{i
:3<6e
p#,j
NU~1!
K<~
NwAK
jBy3
zus
$Zm
CgymGs
D$Q%
*:K.]
#0Xb
|n\}>q#
)W5l
HNA)
fB}{Y
3"x8
Y7Zb
+s(O
&hSe
iCN>X
!T'KX
w>jI
e$N
<Tm@;Nj
5vs8It
,'*(j
n/l@
@SxH
/QCc%
Rk"H
cw<"
o]hY
-OVt
4rx
a^tCPL
GetObject
?[r
`fZ|/
}~:0Z
hW@
UdwYNl
I)H[6
?[r6
-/q,
E]!y
<mUBq
Ak7T
+&jX
?[r@
?[rA
?[rL
lpP-
7T_o
@;?|
-Iv=
~2'n
Bgw4;Nj
~u q
zA]Mh
?[r_
CgDs
=jL0
SE6
eCsB
#A:j
?[rm
9W>q
^O`cS
}n?5
@_s*T
G2mQ9
jrQ9"O
zTn>
jETo
LhJ
Ar1j/
egC
({\
G{^/
b#'"
R3;]
jmsUD
R *=
u/t
}'GP
JD}v
oFb
9/ eO
J. :
K'}8
HB~,
/.)?&.
*#3$
6OX0I
FriuU
,RvdG&
%t"L
L4OZ
8Q8*<)%Y
NZJq
d"{C
C"b
h8T9 )
tywKzkpsk6lHZpqyyi1l
3R!!
S/|
]kBM
{f~
s[D%
?G?f>s;
~B:j
Eql}
Wu\$7p
R+1B
Ak\_
FwL>]0
FI_&4
uG;]
<&b8|
_BhsN5!,
fA
2`YoX
c<waf
q\3T
R$b:@
,p[\
6w>H
#c'>
?Zq\
@^se>Wo
?ZqT
+'E<
YoT
?Zqo
+P_9.s>
]7IO3
'ZEp
|h1F
L];n
V^ (
7~du[wp
a/*q
pv|*<
?Zqs
=Vn =VnI<Qkj;Pkl;PkK;Pl
;OjoZ
vr?*
M(r]
%w&2
&;7I
e _^
{0e:
qo>FpL
ItU^I
!Va<
MVTfH
]u4&
%ln2E#
Q&}I
Z3! 8
/n+f>(J'L
\9TG
V"fH
R:~*
?Zq)
lHah
<`0
qA*u
lW"=
sMd L
Sp'&G
`]h/
Q(Vf
x</D
N3Cf!,
?Zq4
WF1y
%~Ty
=O(
G+@e
#'_
>k7%*
Cjx,;Nj
U/z5
<}3_*
_PVL
B*B4
KrX{g
#\{
MIhYQSNjbIDqkKfZFSMLoh0XsisceRat
@gte\y
L>0$i
W:Eoi
(V7%O
Y[>}}
TuuN
r: Z
_lKQJy/
9A?@
F:R
=Tn ;Nj
wOy\
p+(A
P/@O_
2c(4
J .:
YI'd_
>.L{*
>tH<
(q^?
M y5
{N!7
b~+
8pb
ER8f
dM5w
0"0c%
W\o^
y}OY
HeGk
;Y s
=I (
loNB
|R_"l
>Wos<Tm4;Sk'8Pf
+WV3
]&8K
9[~>NVPHa%
$dfbvsll5RicscipDaC5tvAtwBJn29CGihvg6
BMXN
VR[JKZ
b2t!
Pa )
d#j~
|Fn\
UGs
Q]2_
J3>Y
V#im
20TM
zZ}[
97uL\H
cyze
fB|C
)Ha)
SH*)
rLe4:8J
J.'h
=Tnq;Nj
MzY
1+Dfw
f<oW
<w9
+y k<
U:Mi
S7*y@
;LZ #^
Z F7s
ZCR\8A
Ppdl>
22?:0
G6,6
=VnT;Nj
,a>5
K>i{[
PU\J:
9SDJ
BX@-g
gsn}
jA8E
kk$E
Dj{HBex
}XB=
H8@P@
{,Y tb
uB-s
J+ E1
iQ2{
9c5BV
#eI\
9Ha~
kGq
U8c
$hn* %
h@s%3
qN9
@Xoy
>Kr
1S4
<Wb\
o~6r
V' "
g.vp
CV}&
y up
F1;9
cgJ6nQ
>XoK
lg4F
q RE
3 Hw
Gj=96
[Z=s
/$Uj
V i
4e9U
>Xow
$3r#
FY^
yX8U
}1y
aHs
8Yejg
V^QE
8Cu}Hr9B
Q9D_
]Z,$
<G8IC
<Smp;Nj
A4sO
e;}M
Q-YZdyA
)C}u
m+)L
8Op'5!D
/ A'=
_ a(
>^K\)
0r{]_Si
4~~(D
M/ac
d W6
ku 4}
z'(;
@K25
m5Z24
q-
Bgw,
J8$|
m <Y
&Z{
H\hc`
0>X~
k7qw
W>Yp
,jb3
_MQ6
5+}<i
t*\
I,?]
QZUj
.-gbVJT
Em} Bcw
30 /9E 97+g
qE!4p
MS9y
Ea>`T>a
p!qI
b(v~
-fu'
eT+}
<}bj|
C2}=
bE5l
glEU `
lax}(
f?\r
o([4lr
) <O
%E0
vIRA=i
5TIf
6i*'H'
Z;ZzG
J QH
6 Ni
0G[w
ClyjW
+mhb
) ph*
$<TF
VkPj
cd3I
{ ^
43M>
9&,n"
}Zi&
+Z#
F`Zhf
]MM:
e0hy
.2P#
X<]5&
NaN1I
wJXHv
KM[ "n
&{Q@G
='U`
Bdw-
Cgy(;Nj
Bdw*
Pgu5
Cfy+@_u
08
o(]1.;
@|On7
PVk~
9JZqy
mIxGE
uCiE
n9Z(/X
p!}%Sg
"3%P`T
OtpkAH9oVDI3bbyQNY2a
Sm\O
gs
Vo>/X
@_rW
-Fo/
1?%y
>YqBBdw
,T:y
9f8qjI4xgAL7I7aG0XIyzJmPPFXxlK0d
j?U]%
BN1""
A* ?
o}i_
b'5\1-Z
Ov0
HiIsJLAY
=/J
c0$ J
X5*QS
K!XD
H_g\
zjfr}_
}uW#
9)NJ
kk 8
f.~tu7
y*K|
<QlN;Nj
>C D
.[G=
-b+}|
set_IV
Uu58
s/(k
4!SU
)^
C8Ne
wP8L
G;Z2A
a@M-
%$+\
%tqm
ow,
;D&<
]pX!`
l8f/
<_;5
2GIJ
Qlhy
+5T?
j2*2Ow
zYJn
uvy*
cnE?_&)MR
GTqx
0~"
\T)22
3A"\U1
eJM?n:o2}
uvy4
*8u
\vU&
`}-T
m5.}&
\-H m
:~NCB/>
LEFQiW
,L%~<{
Ir'
)T=X
s}1 waI
~IcR>
cADb
<?n
SF?W
i=*6
K{EPW
x&Vl
9p`>8
Y5{
OU7:
O\>
)@L`
?a_9
%:a#
q[ qRL,
Z*rX
,;&XW
J[^y
3|Jd
>XpPc
)ctys
P',m
(Sw3
)$<~
`jg.-z
/@Vx
/P`?
Bb(l0V
?]f4
q(?M
eYt7
+H<[
vYi' E$E
6:$15H
48NQ
=Xo?;Nj
` w"+
+k74|
'(%FC(V
,Nrm
F81yn8.
t }`
?[q <Qk
z*gZ^
*jB3
f:u ,
qjBd<#;)
=R-V
(a.p
(;d]
|c)flym
BG >
`wlU
:q7V
FW/U
>Xo|>Yo
;W~
d}Gf
djG=Nt@s
H|7-
8 ]m
-kfgz
$,\S
vlPb
?4J>
g:e 1
/k6^`
vN(FR
6r)\
03]C
'AN9t
[z(9
lFu0
p=h8
L==d2^
jNG:
@,#
o+Qo\h
#uu/
[Fi
$FiJ8
o.\:~
*N({
6NW'
cB-%)
Uy%[
Y?Lj
F|\Y
y%MV
ur^-
dH:%
LOD
][Ol
3&YB
NAZpH
_gV O
zpL
b}G
=UnD
/wd$
|ufXV
_ Ne
b=l2
jU>'/=
a-Sl
_IpL
8W4?4{38
PSMwF
Jz#
HKDaZ
E3O^b*
U<Ql
N`H'
(%y$
HG$n
&7E V
=/MMs
5i;
,?k1
|A<[
0K9
zC?W
5@w Y
._+y
1 c@
b57U>
4>w+J
@e`Qi
K@7?F
B`t]
*a9
lQ6O
Dj{
;N
v1lb
7e">
@"i2"
Y4P5M
M)Wmk
V T$NN
g/2a|xp
*v)2
@^t(;Nj
HQm
+6@tRg
\~]NZ
8% n
Cgg1
cA|{
Dj{(
0%0G
OTY/
wU]b
*3Fe
QN[
+^vv)
nonH)
t[<{
Hw>
L-"
&H 9
RMT<
1YM9!=
'^;3
>YpkJ
]aY)
2/*QS
c()[
/ '^v}h
h Vy
Dj,5
jw`#9G
<+D`
nR*C5G(
V1'F
L=\6
Ha,/
>YoJ:Mi
NxeLX
8?'
ntx
]v!N
|lJO
JT3S
Pt &%
%x$X$
r-BL
BHd<
XXgU
kQ3C
#`D j
b~ $H
y:ah
0E(^
D-s\
=R[2
s F(
_6>g;
.IQ}
1wo?
B.8{
-}l
@yh3
dc"k
{Wu$U
1t^
O%wz
~A[k
,<P5*8L
%FE)
JcUz
gk9
%#%b
H 7
PZUl
zpBa
0'%
6VD}
qQGt
m0e2
|h9>Y
_&51
e)P8
Swcd
uYEA
@`sAct
?K)Y
; :.
_Kr$ec
j xI%
/4Tk
=m}DA
RLV"
BcRNp
"W2k'
mVK
SX"f
s/f*
n3b|
)HDiY
z#x5
&) }
M 0!M5v
o h3
vrN@%'~r
,sc +
}p_Z
;`%
&A9
=Und;Nj
}Jubl
|f8|!(
F'%"
U{t%
3K9 j
-0,jA
zYq4
6S<G
"1$$
=VoT;Nj
Z>ppm
CseWc
doAW
:Ep
]*K X
l6a#r
$PKt)a
)7#{
=Wn:;Nj
3(xZQ7
C(
QO*'F
]GZLf
KmJ7
C4`:
~77
5@)&
W{YM
t"]s
z D!
s5(P`
u-u;:
wX&
#oa
vLU{#
m( V
OPR
@_t]=Vo
FS48H
/(O8
Zxj~73
9Cs@
t3$]
'B`b@
pCR"
8'j.]
+-A!
)#RK
Y\55^
EB3M
<Fc"
@`sbEs|
+l/T
1>^e
YEG@c
X~ VP
:cp_C
k*LO
^0{@
s6l5
sfhr|D
yb*0y
{pH2
m'mx
=E51
@+$5
" uh9
jFQN
]]z
=Wow>Wo
3ZvS
]/cI
ScFr
}$`p{j
:@'sm
\M,1p
'nY"
u5[k
4Pf
o <9
b&z
6Xnjp
[**Y
U->M
{pHq
p$I"
DFD
A!rD 9
,38 V
Jj!,
09;e
<eW
vWiF;I
QV+Y
#a,1
!!B$
#^C[
BJw\Cl
5YJS
!`i:>
8 `+{
&O[ h
Cky<>Xo
|g~L+`
L(9\n
"@];j
9Eh2
+}"U
PBS~
B|,4zT
G*Z[X
z1e0
A`ub>YqW
z'hX
*IV|
ypX|
Zif
<+~R$
/S,J
tvw3
17 X
4C>B
TuNM
ypXf
l1>=(:#F
]5C^P_x
% w&
J*EO
d B$
n{a|C
C-%>
bzq'
+8:)[
Z!vIBOqz
?;*9
pmL,
" vI
TWa8
R%@{Sa?#
|>p''
}nHG
5PP
8 =0w
/ YQ
jfLL
DN<n/t)
J'|9v
U4lp
@^t'
>oc8
l"7bZ
+-MZ
0XMg
}:8I3t
V YI
P`}%
LGgJHCEKs2hHlbw4vmf8D
R4TY4F
;(9|
6rPl
v8\A
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PA
;oM2V
\lO#N
/[;p
lB"(
+fr/
?\rrGt
?%V_
6~<9
:2|;
1*u
aQ/$
|5bTA%
?[rH;Nj
IOn=
?]s1<Ql
/F_`
"<5,BG.z
tB:w&
tx)b
_/)
isVse
cIa(
\XXlu
_/>
tzC(
7{wB
dBg
^4;'?k
q7,C
qu2i
?:rb
('$(X
ra'U
dFWf
k bm
AddRange
#_er
"[ z
N0]yl
?;zhHZMMyb
)e!E
-UUr$l
g*}m.
UjVF
:P.wPyD
x8i[4
GwH
hV5u
! J
~Xu,
h2 3
\?E~
>o~7E
8><#
0! k
71I7
O$9O
%?{K
d4b
z/,9
&#+=
^6Td
BscjU
'ntW
3P\
.6.K
8/eG;x,[
<;x$[
]P:I
7"ma
!G?LG_
' enc
/m^
')7s
*CYQmG
KI/q(z
4Yh P
2%d8
tG<E12
jJuwA}Y
>q K1
\z,*`
c1|v
t_7L
AL}ak+S^j
FhLatQ
$!"~
.rDve
Z@->|
[s.~
g=F=9^
hU*~
=D\t
7 +-^D
ZW8sL3NLlq5IpCIQKBImKGw1rSc6
Op.#+
b=;<
\?;H,h2c
cih
n+/,
Zn2F7
/O'c;
=Wo`;Nj
f8=uF
6Asb/N]22
Q0
Vzur
!Hwy
zU/{
&6L s
=Unb
@,C;
.[ U
O}YR
?Ww7
@,Jvc
OpGG
;Z[<
kZ14N
#JWr;4(
+ <v
IL%_
yKZj
Y/nA
Pz:5
n_1i
i t
}<`M
Oek
boQV
:BzzH
%whNA
44)8
AevZ
%R tz
(dyZ
:|}`*8
P*]|'_
xr,
Z&5
8qH
e*1s-
5_vP
xL2{/
p"[.'
xkfs
@71vf
HhU-"
}$G}
}9>}
AVuj5WSGglWp8UnPTkQmpZAJZ
$CMKG
{Byl
UmV<^
;/#?
E(^T
*'=V
37>uDn
fZuHQ
7JZ
yN I
/,+ZKF
44)]
Aev#
f,Ca
OBc!k
Aev>
NL%
R+D)
PISP
*!%JM:
!;Yw
Aev7
Gd[\
4LPe
#bMB
=)&7
oQUCM
v8Nh
@`sTH|
c?Rm
~E"v
KBmR
?1zkH
W#<
35
5`Vm
\;SoCx
N.E
-E+
]hV
qQU
bYwgp#
=Tn5<RlX=Wo
Nycr
y"eN
n@d5
s3X)k
?%B
deVb
)U7v
@+P
k"~
|T!J
;q*4
=Nu
7/ )
>?t.
2 pR
T4I(
CNZI
qJWH3
\PFy
!q Q
kw l
HJ;*I
atp&
rN4s(
.+lP
P!$U
CDky
<vmO
"MU4
,FWJ,
3Ett
GokS
[D 6Vf
U5D*
ir7a
-)d,
-{3$1
+V"4t
i%7"Y
:qRw}
ANvVR
|fkj
.@`t
je63
PPdL
c>A/k
-g@v
)uD\K
@;jEQL
qFUA
^ALC
>$m3
UK+$
X:B_t
`&,;
J!lx{
P" B>
(LgBx
b;qa
<y\\
1'B}[
BICs
bHLg
Kf&#fa[
-Tqb
`/Ob
T/SaP`
`]^
-h!G
&>KXr
?]q+>Zpv=Vn
9YbH
f{Q# 9
d%?;
>5U-
]W=e
5,n<%
YXtx
P#XD,
;-~'
zYsX
,D!B
in~EHB#
M<;H
gf2q
i@~]
U<MNu
t.&
NGPinA
_71W
11sUp
'py*
$mE(#l7
B(Y*
]_=s
UBbb
^bJs!
{7T
]sfz
^Ql@
>YqT;Nj
T5pV&
tbo p
q$8:
E4A~
Dmz(
}:/
, #;
[^U\
?%%+
^ 4-
1S+:O
yxb+
z Wb
D<)D
6~H-l
,N?&
Nm",
-zoX
QBDT
Y!8*lV
<Rm
X;s[
@%h
dq@QSfn
"nH}
V-6r
6!aP
/d%s
PCl/&
]F8"z
)MNU $
@bt
op_LessThan
.q'z
k>$r
5El@'z
>ZpL;Nj
jl.I
~q\5
*4sw]
/-p
(+)-
Tf@e
N1zs^
F^*}Ne,9
0+?Ti
i,[
X<Mn
<V4i
6 J
mJMZ
Q7dl
HpC{_LH
Zn3Wp O
VPi~
@btX
gcZ'
K;Nj
Db0Z
JF@C#
';me
rR>g
&qZ
B1'?
TYqc
a_sn
xikx
r$x
1?T;
K-8@
:iQZ
@niuB
: ru&
38?bx
nu[R
'KUa
GZw#
hXk
!6cb
mBIe
{ To
3\|T
V; (
Dj{jHv
h]o;
{U1R
[Wr=T
|\ 3
f3i-
"yl\
\_f)
x(qAP:L
x!2x[
Ws&P
M:|\
\|A
GNK(
=TmP;Nj
1ZG:
0]MN3
9e8wa
~`M*
rt>a
|i 4C
-FWL
"%U|:
IW.#
XM6ix
Q.Fw
~hK7
C13D,
s4w.1
<;ze
Qk+?
tp][
g3+:
{+Er
x.QU
*JPz
Dh5T
HMH}
[GO{K
=Xo<;Nj
List`1
A<b8
tK0y
L`\RF
"EXCfF
jd!oO
C X
f>TC~:#;
cn
5K?s
^>4786
!Hl@
:>Zr
pxaB
'b g
K)MJI
AyH#
$BMF
a+TZF}
8u(Y
9mO2
$ _S
=J]4
(-PF>|
84s]
SkipVerification
yS&i?
z7"c8
@iu?k
n_L*
2Qe
>Zq;Bey
E;4 2+9=
&LUt
q}O`
gk(W
WDK P%
@_t7;Nj
_a!Pf
~HI=3
m;gg
m`
(".}${
/ktF^
An:4i
GF6
8I4q
CI+6
CO ((S\C!
8_J=
evN0
6\$K
d+}2
)D7/
';Nj
yBwc
xyf=
vY$X t[
EJDm
^1 h
IDATx
CMmu
W Qk
4q</
Fba
o?y3
KAEB{+
dA \
pRp+}
ow7^
Acw>:Mi
`.rsrc
}jPSu
yc%]
%?}V
y9pES~
f79g_
YgT}
[!:RK
e^:u#
5Svf6Nb5]
A0}4|H
)ru[
|82x}
Xd&:
aQq@ !
Z *x
kG^?
v!>"0
i"7S
Uwsd
[21
]x=#
;Pkm
:#-D
~q;3
hJR2
=Up(>Vq
v-&KLhdk{~q'
U,}~
k0n:
&@aj
"qTz
G6jY
Q 1a\+
bf94O'
Uu.
w#7p
hyS(
S-=9
4b_J
O9W8U^
h58=
0"
}z$^f
n|cw
99!|h>
~#m%3
,a)&-
w0\[
_u
CP9xu
G ?6S
\D)2
a FW
E &g
@[x
y@v"
'+0
rakIf@T{
"\6+
|Q*I
XJC
lvlK%
&*k_7
a"zr8
r61BB
D&Fz
DC?e
x9(
~6[/
+":O
[ :3
)op{
T2eL
W&sl
REjl
#*]^W
v1=$
]Gw?
D[ F
M"mmwu
P:<'T1
LE:-D
=;gx
yzf
!3U!X
_G+?L
SymmetricAlgorithm
(=YeE
vr_i
|8F'
=m{@
Q >^P
]XHI
~+*
=4_V
W}Jv
6pOMr^
Jsa$c
)/dJ|r
en8&xQ
^'S
mb3t
}Y,Q
?/th
QR8T%
F7%0?,.
?F6b
B"o_~
TransformFinalBlock
c&q_]
M<Zy
B5Ue
Dv0gz
? D
trh)
ub}W
{-=p
'Pw_
L{EUG
WH/D
Nt6]
:FXaAke
^h]yMn
si0
>Zp#?\q
Ym0
%1%8g
CBY_P
tWbdq
$uCaZ
x 9R
<9_o&
:0|b?VO
'|(c
bOr`
gfF:
?Zq[<Ql
\+k"b
|Hf:
R$O&
1]YR
C y
Z@XA
ZRU y
K $3
Ay*ov
&Q>]
nX$o
<Tm}<Ql
%13
og`}
IHDR
ko=s
get_Now
'oe
p_tH}
)C;J
Plzv
^6p
fK0s7
S(i5
E\-8
.a*D
Fgyg~
?\rzBcw
|96~
RDVE
}wN=
T QJ
LU:g
|@eK!
~ qeR
Yo7w
coT
Xl$,
)]6O
*9|W
/dAlVP\~#
2kZ8U
DE 7
[v)c
mI~~
^r>^
P! #
$EZ_
6Fd^t
<{D)
7JF8
Fkt-K
E Pr
+J~}
x"
c4?P
4Sh
v $X
K;o\C
jh !
OIC?m
l n c
05_67
iQqg
A&$g
,CC
hgc;
Y GA
E)|'
m@"$
a mVb
W&[.: ?}
pOA_3
]Mv4
Ia!0
=Xoh;Nj
TuYpx
~]\;b@
jQB
%$R{
s H\
k[^Z
Q-P%B
ixT$
4@u_
-CqPK
f;2E
|8[B
L8`+YUQ
<pUK
Eq[b
"@9i
cByg
39?,bMjJ
=M`7q
_{?nK
{cv
Q.A]
MZ7Ov
#Strings
<Q@Me
@ o
AY(l$
<bv:NWJ
2YZF
Zu1o
A)K+
N)^0)
+QCo
#2nA
MW+$.
Sv[
?d' .
3|al
Vf+U
FW})p
hf>WQ 8IQ
4Jga
xl`3c_
>Xp=UnkW
&|::
aJ*j
T#|cn,
=l}c
!7ek
:4-h`
C;\p
&0cP
0M"7
mkNG
&0j0
:v@-(
NkkJ
:ew>
6o_
i&&,
&epC'
U`gKe
9[3m3~&u`
3AZp
g/>Q
oP,bz
cI_ >_
IpTV
&RAk
l&$O
U"K_
pKPW
![C~uPSQ
$;&2
alwezx
}Hue
.$_e
]c>9>
t- g
BC|`|
zsc(
%jhb
{1y+q
Q45]
!x-3j
0oIbw=M*
?;u7
wI%S
:*[K
S_>,
:5v|
c@Rm
^0sAx)!
OwCDQ;
I.c&
.N)6Y
5Dh
=<Ys
)m8
g)e6
be-14M
W4V<G
&"#'>AR//3
]ep$`
}%*e
tndPMw
p?Ie
*<t=
,WZ]
Aau
,T F
H!2<
Ej(i8
giSMubHNhjXqukbm0v9agYio5GuE30w
-FU}
|?0.'
w~)-
6 2: *
O_dd
g; *
$bVun3T9vYNB1wmcD6ozWdYsHSh03C5EwnrAh
X>]KrA
c cA
o~K<
ijRAl
z$E&0
6*f-
f@6MV
b%<Qg7
Ipa}t
Y+yG{
5J@6
1k;IH
ny1\
QL8)
Wqsl
[T}C
zvSi
ihsq
iSVb
9B{Z8
o^ rknv@
[W= `e
eN(g}
veC*C
g=Rr
PuLH
ruk~!
)Yi$
r:aT%
!IvN
Xbkl/
Itx c
n/d{
J8I
"v#U
9Xl&zi
Ecii
kn^0u
fM7D
!7.Qy
VWjd
U+tV
9B"mBm0
>s(}(
[3nnd
CkyF?[p
Mk64
#V'
|#GR
7+ b
Ly]S7
zYP
3% _d
>UCa
6Y~
~2jO
Uns.
dbc3
t=BFW
/2d
4G>6g0'
%\D(
ZKa$
')~{4
me;.
7kri
SyEAMz
G Xfj5
!~[
5T|:L
$C'E_
P f
z]z%3
W7q"
w8f)=
^tv,
by#S
mv8g
c<N|+
flA|
h1'@Iye
_n I
@#],
`>3J
&?4
P/ }
g{D#aw
SE|
2 )'
zOue\y
lF"/
9H8U
2*h_
G~eS
Gc<+%
5Hh[
I9e
XX +Sr`Od
4 k;
Ow]o/:
?\rt>Zp
~5_5
\{iT
Sk!-
hY,MJ
f{k@h~
,'Q1
jhbZ
Xt@n
vRp`9
$+Pv
lA.=J
RL?u
<EJC
kJw`.
~sWx
F.l
@2k
\R`
/?OT
snP*
_}|y
L%Kw
#"tW
*Slh
7GbtB
\0W
;I-|
Pa^
66#c*B
~O6*jv
s+n a
(I&^;
}\0
nCf0
tL:{,Oc
p2\,
Z%N!
I'qFT
V2x/
2my?
xbHS
xv k
aGP
5e
yH{l
!WD
9?@R
S GEm
UHJfODbzsQaJMcCAKMpOHMkNgV8hM
@Zy
$g$Lx
&W0qiYpPNx2eel2TpRDxbdnegm2fHJFhTOMCSoO
~oOo
qcl
kSU-
'Qy:
XLN
B GGWu
ZIT
`_n1
OIxw
4{mZ"
?\rU;Nj
=Vn0
?\s`
25T&
)>pPT
D4^d@
@wlfUz
px@7
LGZb.
2(&h;
bN~p
u ,wd
Cgys
CkU-
Eq|'
K_mj
FCp9c
:Z[f
>Zp;Nj
4uU>j^
F.MT
YI-GW
[6GP
~UO#b
%;'
ixKO
=cZx
44-t
L/PF
5C^H
OX3
q%
<RlE
~rg =
bj3d
>Yp\Bew
f%SV
iBa~
$g<O(
H N
Cgy5
dYF3
Xk<Q
i@C5
-"ix
G5%i./
=VnP
HaJY
^zxu
OIv
9%}Sz
EtCQ
xo^`
-[$S
fKzKd
5I!g
w;<
] -
6D@N
^{i $
0< Z
M, a
FLp^
{m=.|
Z &w_|
~%RK@;
?8-N
|Q)N!
~?b*($Vuh
_ VD
9Py#
36U*!
NBBJj
dlTjC
I0FJP
{=q5y
Uau:R
91$)
Ikpn
%0".
:$&v
LwbN
AbteDn{
cnqE`
+g(F=
|a5;
Rl r
3[ 0_
-Jm7K
S,3\
8E{20
D7|"w
A`uMCgy%Em}
}y#i
O:WKm6
xrol`#
][W
9^}9P
b"7~
b}[!u
~:>Vl
a)qY
{3tC
ut%5?CYV
F*A)
Wb\G)
s K
?kFV
Q*CxC
jr'*
Z?;
3P;l
AppDomain
gQ^a
Ms6]t
^Y%TN
C1 T/:W
-fL4
!H\8[;
p
{}F#
e~nI]
eK>4
,6=d
(=ApJF
F3LGV
>?G
Aw1jT
gtsL
Jjgl
auQ'
'X+[
$]+
hUI1
<<.:)
w.?K[
I'L
{s4;m
C7~;
,0(x$&I
BEM}
me&{
-hK
AavE@^t
mk?u2
jyXhPi`
~p93
0Y>/
I/,%_
SK ]
Bmiu
</K]
]H$c
A#n<
bx ?
$5pb
5;)d
zSUz
sT}*
R*0
abw)
ir 5'
&D;
=Vo0Cgy
Kpwll
1H5S
Q!ko
<RmW<Sm#
f%|o
3j"V2
Bev8
VC:#
oet
_m_
N2+~
<x<X
8?<:
vnK{?
v<+do
o<^>
#p:t
@7(]_Vo
";V5[
( /A
^ePr
We
u1|=,
0l>\v
|-c
`!>Z
?]qb
|:X b
<Rm{=Uo!
l-aJ
{;<a
Ga >w;
ht9X
X G$]9
*,/Y
^tk?
*ay2
`6Sl
}jns
xO +C_7
H3n*
XppU7
dg$m
a%M1
]l0
sU/kj
? _T
gbF9
X%[
[)[
ya.~l%5
a`y,
y~3z&
64ktki
MaiK
`T+d-Y9K
=D'
\N?kc
|u)j
',*={r(=<p
9 U
>YoX
=@6j
9Zy
I*5m
&R^"F,~4$
.P8{
p$2>|
>tH
WtZ:
KV3
L1PFI
DiE@cc
q@"z
=~6RJ
<Sms
ykgJ
_)IL\
3^A,4
Whv;?
v N6
_h%o
oM']
@.reloc
wP-YiN]0
.p&O
.E]?^+
8 A+
~SjF5
WB5Y1
yX_v
, rz
oQPa
C2Yid(
xp2%`*
To&":ViY
\coh
{z\gA
>YoH
oH^-b
G8r-8G^
uX<r^
|j"<;
)Iwl
Dnz
? !K
C@g(L
0;*
Dnz2
tv9r
t)W6
VXg""
.OI#
K3Gy
<%j`
^X0fy
uN<7y
cG@^v
%]Xbv
!!yW
J2Ft
p3Mj
~DZ
hcdc:
|uR(`gs
yM0,t
qQ\p+
z_)Fd
i=y^
~eu
sS:6
44B
we$S
W"Ju>
Vx+_Q
P{%V
g n5
-ZkY
k&AUt
zTdt
&{6H1
eF"=
gjUh
f, v
0p3r
)Ri
^|Rg-
fKV
_1'y
?IqA
=Vn{R
$Fo3
Wed k
$bF
^}&p
]/p`2
gf~0m
41~<
(^M-
|7UE
=DT?
]-\uT
@^tD;Nj
Em}
BsB6y
g ~l
~7zx.
R6YLz
ylvQSG
Em}!
'5HB3
n )I
l4 p
\SMhY
[{O*P
N8l5
T"_
E{gpj
6A-L
-8k(k
piZF
uNVMaE
6et$wy
5K`
m{MI
w<}<
zdegaq
OD7E
,C:0 4j
% ,!
5d:Ty
Dt#,j6
3Xn/]X
Jg^i
)\Wg
-34
"~>Qd
G\[qm
W67
csEZ
V <u
pS7=
NZ))
v[.E8
/j3\&
s3;A
+HbF
S 87
S@H?
WiL<}
"keW
Y?"Q:o
InCgA
J `&:[\
-qZ
>Wou<Rl
U:-
w".S
i5P_~
cWg`
\>YG{*m
1YW:H
0UO_w
c]P8gm
WaS
H|b[
.HZ&
)t4u
uX<B
P{C-Z
N>'*
$i=R
LWz==
hn19-
&LJ
bz'O
zA&!p
>Yp`;Pk
HO D<
&vqF
ByvEC~D
x 1Vx
*H$L:
|"^6
m 1vq
Bfv\Eo{
^rzs
gZ]mQ'
iJU-O
isXuY/H
3zuH3
S{~a54 Q
wIdr(c
).SB
NXl)
zl`"
ts.&
m*> -
KX4A
,J+pE
@'{u
"`"
VU4xZ
[DbL
+3?
~ tz}
4bS[
F*U/h
*?-%j-&
[$]/
*|sk
q4](
!F5j[
vjWz
9oYW*E
=UnI>XpB>Xp0?Zq
tYE3
fX9$
_c\v!%TLx
^xB~
}GQA
ZWDhM
fVZn
p xp
_[h{
?\q`
=XoNM
7zX=
\aXaA
v3u6L
JtTf
*{ih
?\qR
;bTs
5nc7
Ta.l
He}'"$R
h;DQ
?\qB
oxBg
w%-u
%q*{?
IZul
Y" m
iB $
8Z9@
6$v4
X-=~
TR\K
?\q<
I>@&
Aex
R")J )
~.m"
DmzT;Nj
u{~-
7#Pc
-I[t
XH9Kiz
CfQx
;Njm<Rl
r4?1
Z\uX& `
~L8k,=B
(:,mx=C
ct,t
&>#P
o,KMJ0
v*7{m
ijvF
7'jm
B7w=
<M s
&,8u
Wm[Su
~TR-
&dv:
2m^$
}u9$=
Bzl$zU
!EX
4av]2
:Be
#Ia(
Ri5gT
O=eH
Y{<9
YM+T
04-;
TS=i
E@H
?6Cbw.9fu?=&
xZ=|0
+hmE
wK4;
m( nG
>]]3
b+Nk&
^^_)
CXM+
j20c
dEQ#
p-SL
%|d4
{!hd
(@b)I
*>m,
>GDm
?\ru;Oj
){T2Q
vUux
j#?}
>0^G
7GNy
Mra
|E]GOT
|?_r
>Vc>
Cng"
<RlF;OjQ;Ok06Hb
Q,M}p
"%X
0bQt6a
QJTyM
'`sA
N+wW8
}?s4
tux?
3KdC
.38<~
WZ/)
-(blZ
MjB
E ln
4Vt0
W1n\
WxmQH
NpUY7
*g\-z#
1\Qf
p$\\
*!mp
L,p
%0\Y
b1p~
]"BmA
33._
:t8P?
gy-b
{_e9
I^}#
qIN6
,B\]
A9i/
A`u
?\qX;Nj
@op]=r
9)%
?,"Ly
>YqO
~p79
{K*B
gYmt
}k5)
w-V
$Tq\
=UnZV
,Iix
zT:!
>YqW
Z`W2
~26j
(5g_=
@^teW
&3h)
>Yqa
wP~/
}L_|
mT@jqd
/Spe
Dh.~
M1Ju=
H 5F
BYw}
L% [H
Tg^d
9Yl9
Q/g
wbTI
'h-LtZ]D
Er|Adu
;857(xg
Ojl ]
>~l;
>Yq,
@9MW
{uV`l
o1>|
KOvd=I
c}>@>
<{J~6
7GCT[
u2
6=ho
>Yq9
)%U(
VSO!
-&O
$`{s
c) Z
!Z|A
T\*q
- XOR
ZqX
Y>eE
lb9V
+::[L@jHKu
+>MGt
zP=s
w_Xz
cUd^
g8v>e
^Xm\k\
IdKJ
<m}
3UPh,
RHd*
AMZ.
:_.O
.#a4
Bdw
.U?`
g b_Y
/"+1
*2_0N
V>A*
7b]V
a/f5
'#XWC
0(L0Y5
`un9
'kb4
w;Au
~t+%
&G0K1
O/5pY
v<l1T
?^r?
XesQT
4>EB
] L3
Zh_P3
B{?|
(!ec
SRvPglgKBtFKSfUbqjPfzQ
-Y!<
?.+8
:]00
HPRqX
Y430
XdKH
,+=N
&m5g
i T
\|A1
i (;
^ YEKtR
l2Is1
c*we
JTg*7
Xc%vc
k5%F
9)!Z
M:f8
Xf|Anf
?]s2;Pk
4|=
PkC3
snVa(
\+LG~
EA\j
e O)
,QSV9;
.z&7
#Hh7Q
!;}
Uc^'ktfdA5
K';E@K
nyJ*Y
zy"V
%L?Hs
?QKz
[Uau
6M7+wV
}S
Zm mw
u2ZK33
m9*1
>[p^Cix
sLk#
,\n?
z*ln
?%n9
9f|)_
_]|GO
QJ&v
'bz,
-{B~
Z`p3
BC+7
zpZ_.
5#5$
}m.6=^
WI3)
4?N[
>8R`z
+%
MIG.8:
v9.
gr J
PFmi
]s<B&
"db6B
qHsZ
82X g
%`|:T
i? 8
>Yp}Bex
Jnu`
j~3O'm
0oq'
B1`B
`fMS
DuEC
B ?nB
T!}B
q Q]
{0)c
kzBt9f
F8:TyH
]ib
]?{m
LOX^$
y)<L
|#Cp
mmz/
|u+[L@
\@f
bo.0
DRm=`
Y[Vk
KPbc
;Pk
AL2o
?]qQCly
I<2(
Igs*
^n`L
_}8r
AKc.b|
I^c
{lTt{
hY6y
@Odi])
-au<
sqYw
EQC=v
8MbbY
L7m.n
;vF
qR:OH
vs[\J
uYWiP
"s>-
">O0&_
;_D7}
?f*M
m,ly
*>X:@4X
s*GV5pp
0XE,
I>>_@
H `#6
7YNU0
Uddib
|w}tBMf
~!0zG
)&q{
=)'LG
0}uR[
BsDA
311
D?)iy
o l7
K3)c
*RoNn|G
,oR~'q
;Fu
*b$3
`D2&xK
N.u
mktx
+G*V
lOt nan
S9n:
RVC`G(-
51Bg
CyVj
BOgM
sE :J.
y bH
!P:*
CVR`
Er|"<Sl
HIGu}
KOl`
\o2
3Y&j
5y[p2b
u-|:9
hXnH
?=0_?
8bvO
fiE1
x K;
W_#=
![%a
4yf*D
s5
bP|7
dMn4
FR]\
PD'\^y\J
p7J
Ad^
2A& z
u$x:
DTZT
0ey+g
@/0>u
^ZK5xEq
<>iO
{*1_E
pjA6
/8J!\rT
i3 @
H.EG
[t6x
TOt;
:0
Bz2h
mTh1
>BI-
[[Pb
XfH:?
Vu\#4#"
:(v9
BRiEx
q^P8
OU==G
<W&3
m3ET
OzYs
< lu
TK`n
h:9_
T'/#d
pR(%
'Q('
PTpb
n{ZfD
UZfh
OcAG/
k:f8
( p7
lH uR
Jplr
V?d}L
7jG<
(hES
{A ?vy
,zFc
cB72
q9rv
2l}-#
Dx=|
JZn2e
3Au
w9=!
Kbw'
FVaa
i%6c
\-pEUF*w
_kJ.*
dHYt
$GCv
+B%@
y2B
n!S
9e<~J
fh8 |
'_4fm
w^#1
JC L
pKn0
n,%,i
KM70
#K]J!
BR*L1
f4{Z
OcgR
iM9L6Qn6:
n{6A
_uj:
5kaIh
ISP+
nl>f8
=Wpp?]s
-nEn
z>"2
%$-
Le (
:>l N
eP!
Gtw\m
KGcU
RijndaelManaged
9"L|Ah}
v318
[B)*
=|:7
XiDdR
Cgy;Ok
4oCm
a =tvc
4fuz
9k/=
C<.m
]da[
GqE?
6dc<
$H^p3
V:Y4
@_tx
svQ7)it
.bVbt
?xBh
z4^{
Bdwn=Vo
q%i4
ywfI
]_D
<<rDq
rb5
Uc0H
UM]ZW
Y SB_
<4_
M/_cO
>YJ1
&QK1YU
6r[h
E{-I:
hcF2
@_tJ
~+FaI
AbvL
wFY,
P<4ucHY
ah28z
--s]|
+ =M)
) `U
Z3\
@_t8
`+3;
vT$
n6<e>
qk6F3
L@V
$qdL
-|;C@
Abv(
_}dF
s~wU
n^8P
s:]|
@_t$
@_t"
o:h<
jD|R
9o3
7Rxsk{
eCP)W
QD=e#Q^
m~8~%&
WWt>
@_t
:'1L
w9Y2O(
z]S6}
%Q&9F
G@O]g
;MN~_V\
<Rmv=Vo
((xz'J
B8y s{
!Zu(=Q
A&>o
%(Qf!
Jv%L
p^y
\v/Jm{
cc?{
qGmBQ
pT;Q
l+o.Tj
%^I8
d'*4O
*G '
%HoA
*T:
Ax i
I4Ed2;pt>
:Vi`e
'>[K!
]S}u
t/#
8qF^9
dJL%
eCl]
RS!K
sj]@xz
/w3z
v Ff?
.\`M
tQ=A5>
[N \M
'Tm]
:VZ
Invoke
<Ql5
bU{Y
jKF%
=UnT;Nj
AT^sB +
Eln[
G;tu
AcwEFo~
>&L[l
7Vg/
2s58
5Qr.[.
Ql$7
JYD3
4U4S
en r
6s)T
,11m
%7=3
wm9n~
/M{o2
G| d
">E9
:Pi Fq
_7Rz
`88ID
<wN9f`
&kW0
O jX
d+w%J
!*T
g8#f
?taa
9t'S~
jt0m
+y`
5cN
{Od<
n?\d
)`lHc2
j8g)
S dv7
Fs}OCgx
?uzb1
?^r?\qW=Vn
R:'O~9[
ib=#
urOZ
~nLU
OMEb
'~6
O<*w
z9@D
d|f(c
!%4e
7:s<+I
LwC4dV
>YoB:Mi
9gtk
)}5
a+<7
B.Lx
i9D#
C -T
]Al+
_6s]B
:"Bmu
@XqI
5EIe
:)s@%
pt
]160
\ Cc
E(\
Bbec
x{^{`Z
2zr(by
%*8C
?Qqz
])u
&o)u
6 abS
AjZ2#
xorQm5
;cVs
ue4R
Y.CY
nz'
yV#,U
W[3`
8f5;
HDg
?W x
"w<1
C+0a
OVE%c6
p_HA
"U/
)N'_
l6}B8
9tX7;
UV(K
;peI
M8B$
=qMMK
X *w^
3/_R)
(pjP
:I|[
=Woo
b~%sxf^
kJQO
N8hR
8[5W-
un3v
*cS[
<W]
!x*#
=Wo~
Z}|9$n
) $=
9S=#o*
6&S@Hz
>P_?u~
<Rm
Z j
Gwbw9B
m S3
fyq_d
vslR@'
h%Pd
LQ>!
jv||o
=WoQ
4\5"
lc+d
(,J%i
Y(v(d
-"+
BaDT
.uva
J %
zfJ7A
n~a#+
3,93M
qH* 9
D0kL
EB[ uJ
vE_
E{Q%#
=VnwAav
1_9{
u]cj.Tb:
#r4+_d~
Giub[
CfN~
g=@9
kfEl
Z k(8
;QlZ
[6nj
`FT
>WJ
0F`}P
h.c!
} 5B
=m`#
D%G!
\#u
-9:R
Z7%v
(!Fz
=H!
f=`
>J[/=
HU0d
0NK/y
R$RE
)KQw
g+g&G
!9V1qrakZZDGtnkR5I2Q2PgmFSgqQW9qux
k0YE4n[t
%PEY
@`s]Q
}:Hs
X@!
m45|
M8qnD
Zqm6
b!R|x
t8ys
F3jKd
O*TV dd
|o#q
8*0r
=Zs
hUDWwY
+|Mp
9_,O
_b!I
yn"
c YR
?HiE
/s(W
?\ro;Nj
@|1#
3cc
Gi06
=Wnq;Nj
}1~
W\T
m?y
fI\u
_oi/
*!QY
g|Z;
o*ow
.B)i
[$TlZ4
V^VK
`t+
`n]k#
\h4T
D<,e
-m{]
k@#w
IT7"]
kdc>
A5`]
waQ1
*PR)
cW<1
] #F
4fmgZwy
|pND.
En#jT
iyE=
r+8
*uGB
bc/q\q
*"lW
*I`u
Mz[ 7
hn%q
|{Z"
iS)r
jM/o
Oyt#;
mbq-p
)kG2
3v(cu
hs N}"
-TW Bk
&$t:
Ret<
/[X<4
>Zqf;Nj
R<bV
jMHf
: 4{
:=t>$
Sp0b
:Cfp
UEY\t
"j-0
"&eZ
{PL=
FzDE
^g':
<l3
`P\"h
3q-|
Y"Z#
Ik63
V f
cl3
K7(6
mGi
@`sm
=XoxM
ox~s
cRru$
9m?T
ZW~@
V_PL
7^zz
`R$s
8BSX
p#&_
@`sU
%9["
'H,
amCN
7Ao~
ZR\j
%w'}
unxot
N.zm
bsn
.(0D
KY9p
{Z,
@`s1
=WnS;Ok
{?Z
2mp_
3($;
@`s#
?^r`?^r
|m>>
A.t4
(C^#
,Gh
T F3_
(Fx3
;-hF9
r7d)
e^$]
{g!
BcwX;Pk
d6^5
o,2%"d
W('g
xb:o
BfvO
AgPcC_
BfvH
BfvI
~&ha
>Xpd;Nj
=D41
q8W:5?
>jlG
t-<
I R0
R@%O
v }K
H2uh
`>mE
nG|0
BUVo
;r9zS
IBT.d
%:8!
Xr#W`
z_ TZ
ymyxY
0[s"A
`V(`
C$qb
Q+{owZ-
CF'_O$
S`.
A?2_
Ft!+d<
<WmE
Q?n
30AE:"
Y2?]Cz_P~
&_bZ
(v*dM
]K0N
Bfv/
;<rZ
H|C;
*+?w
B+UQE
p<q@n
\13)
J&1KX`c"
<1xJ
"N[d
0\ w
!'xS
wX7
9E[$
:l7
NgY1
R$22e
wj-8Vg
?\ri;Nj
m`6&a
hX8b
[c 6
aihg
umT4
FS;5[
=4/N
o@}1
p2R
ZYTH
B{)uK
vRI
!~&i
AFx\S
E"- [J
D@U\
<3{B
qSas
=CO`
[IL$"
wkmUg
L28I
> vJ
Je3%
?[ryBfx
-#V~
g[yn>y
N2D0j
3ZHE^
EI'r
v ,@
&;K%G
k06
D}K'
F} A
}q)qht
a &
ye8
UBhH
/|W&i
tMv6=
_/WP
&Zio
2l l
v/j.D
q)0
"_U[/
8hKz
6HBk8
@at`
zMQO
wYZ*
:ktpW_
Vh5L
kJPeO
6/(n
BE
S1%^
VoLm
#E:
yF4i
pbX9Mc
AbtA
En~ ;Nj
e.]<\eA
=[oI
G7'H
hDxd
kT;\
g{.PK%bb+
AbtX
w &_
3Z]!
/yn*>
Abtc
@at&
HG;=A
v^-e
agQ8
a\?9M:
Z>!9
khz?
Zt{:#b#
@at;
i?1O
dmd[r
'7:N
y1.~4
e6E(
.$(^*
b9ct
@7it>
QMJ+v
|m_}H
f53@\
pm-Y
]P]
N?|T
S'|o
]N
,1/H
U2 $
+;^W4
&PsR
Sq6c
vkn\_N
Z 5)Izkm
;: O
dwa!
)ER
@w%}
j^UvE
r=#\
uD^V
i'z2
qa8
4PL
tqL#
. +A$i
*tE2=
zU_B+7[
3Lx
>) x
|']h)
w/i@
~ Vd
a*#F
*w2@
n{|'
>Yqh;Nj
>[q%;Nj
}4LwT
MT^o
UlU?
4Oc
{sZS
DJ/w
Z5uFN3
4j]E+
clj#
I&F'@C
d&CG
k=N|
0OC2*
&hcZ
",mF
F8kW#
:A,n{2
]Bxj.GT3lof
6$W#
Rgu?
$?|!
_b=W-
@&=`M
##r6b
4R"_b
{o'@$(r
;}| c
- 4p$
at '
\ 0v^qf'
W,t,
!/]e
[b5gyy>,
b8XO
@\x J
Q*@qC('mFm
. ]q
Bgv4>Zp
1S_>
<U)2
,-;n&
Hj~Vn2p
1AF$
`+}$
<`rY
HD0P
?h.N
`WpFU
Hc-o
uXspC
9!N"xj
cJ b
=BjS
s-J[S1&
K)p\y2
P0o9T
D") #V
r2[
n!8~
OFz!&
@_shM
AAz'
@;p/,f
&[%Us
(g2h
VEM.
O!)8
r|I95
ZQ8wh
G =B
~"3D
WT6#
& C?<}
3? }
<R{0
R1Md
-g\N
FBYH
oiXy
R# F
Oo{.bs
t#Jq
=:G'M
)L^a
x4LY
Z0zU!
UquI>
eI~A
9~8-
WzpL,
ap Mt_"b
U$Q)
->N
;9y L
N2d&03
C1>=
bi}
*|t
=Wo{;Nj
8|Y.
?tq_,
;wx7
<k{x
{%/_Ig
{J>q
{=C
Q;=!6
2r%2I<c
L8dt
]a/P!6K
b4<<
Y:~*
e_Os
:Wm}
.v=PjZb
$%"^
%2f
+"U}+
2 l7?
>ZpO
}9r2
E^&;
>Zp5
>Zp6
KFJ=
lZ5
91zM1
nV|6
N=Nx<(
1=%h:
xYmo
}OWn)
wgu
N3@=
+)&g)
wFGfXrC2Vo7xWzrgjQ7qzlJ
,.`Ap
X3H
$tU4K
j k{
"s:`
FM!\
1S}SD
P/Wu
Q1&.1"
V3"(
6IN3
5wre
IO%M
Ol$-N
gH-/
=xwL
@th_
~14w
]pX
@]s8
$<?8
5m=Lq
*uId
@]s6
ygn:
y*pz
&![%
\0Cd
#7Z+
3 [r
Z8EH
Tc)#
2wCX
UVf.
m=*H
9b!
Exception
go ;
(.$1
%@+9n
MQw0
UI.2K
G"&0,q
,l:S
pUTF
jlLY8G
*zk&
B-Po
@]sv
BS*d
vncq
l,}
@]sJ
@]sK
[gyo
~R)&
*Dxin
9ChZ
TUf!
A^RX
\8T`A
DZ=L
3Y*
k >
q^e<
YgST
N^pA
eYZo
i 9i/
(r6z
<;&$;L0
bFlqRH
\/2!
@^s4
6fIW@
@^s0
oeD`
|[tw
|ua2#H
3)d(3_
*E=R
XGpJ
EHp
J9|
;x+H
rG@@
6 _@
5 {\1
YBs\
>x4s
6oYZ
j Yu
jSVbIB
:gLj
)_'I
!S GwEj
tN>3
~pyC
M]\d
<jdK
3a7
@`uC
e$V;b
^Z%1
_@,4
K;9
N7of
^^[w)p
QFIJ
/H) b
+/xq$
I?y-
n,7ABf
>Xo ;Nj
2',FV
)-#c{l
0m`Zq
/> P+
g.e
WN.T~=,
MNUa
FXQ~
/bD,
zQLKaK
Ep]T%
lq J#
?|zn
=XLN
])%$Zq7,
Actu
:dB^
aFT'
;7\=
A%jH
`'+e
n 3
1CYa
.[IX
CWd
~4K!
/9eH
a5kpendyagDFZH1dEZH9V8BuBq5wh1
*M,-9
#j2^
\<t
k1Zn
KVlA
F)~~
emZ'
M#R&
Bfxw
NeUZe_|G;e
3DjD
Act<
.{Yl
W8pW
hhDS
Emuu
- &
Act(
']
c p\
%tdU
i%y9`]YE
*L*?
A$4
Qfg}F
EPnXg7
D,`s=
ua%5T
blPI
Bfx
H1h:<K
Bfx=
<;u>
>{M6e
~xj&5
n>_:
Bfx0
iRy<
7W>|
LO-t01xi
A?jT\&
{5>e ?
vBl'
ZT
$Uy`~~
dHd 8
Epeo+B
|f_n
A0wM
p>$!
i %<
<:P 6
OlW[
q'k41e
54Am
u5)B|
sgli
bJIRU(
B^x'
R`}L
N@_
, g-#
T _J
YYbC
?{ov;
"a+=
yj#
G3B$^
%=Vo
U_ e%
?62-
(7R"
!0F^w
=SjJ
'_H8
!O,X]
.zZz
9/ 9H
n+2
qoTyf
[!4w
V,e"
$_R
>:r?
:$NYM
FNE
e>AxdZL
qB-]P
+=H|jx\7
'Y&&
>k+
m;V$
|0<U
wzyy
A9(:/p
XEVN
aIfT
@]s+>Wo`>Xp[Abv
<#L=k
Y~[JH
R*U'
SfpSYM
exMu
>X. }
+Q8:Q
> 2Dx*x
^ZIo
Yh:N
,(ta
zEsaWg
JPJ}
Wf9
*;l^!
O2T\
C`"
!{,.
M ~f
SkJIx
Ibn<
5?e[
7q?X'
cVB*
5W*F
wVB
TB#|w
\ -/
QRNK}
Fhog
_t3X'
rwi9
_j4S
Upl`
iQ"x
quM%C
?}<_
W+vD
:~j>/
:I%PZ
Ts) Z!
@eCS~
Q~7rK
ftrs
,W y
Ba B
.f1
9]!P
@EC>6?\
,.\}
pryxK
@CoS
@jx?
2=og(
! ;{
dF;f
,Acu
Gr >?H
:GJk
4U(`
9lDI
)n -
\4\w
B,b3x
N0b
k[TF
sF<Pm
Wy8o
y=c(
Q <)\CZ
"n%Vr
!wC,
s?u<(E{3
6.gP
:nPU
hr9q9a5
@btN>Xo
9V[a
zAwC
F ^H
!1Y4
_MAn
d=Sd
_N[c
GW9:
&y(LhG
0_iZO
lvQ9
=Umk;Nj
DSZ
TM,)
WWX_
eKNy
Kh;>
{,\
x"*p
o|cx
. +4Y
HNWL
v%&d
?[r
rgd_
G~![
MEt3
Dk{<;Nj
Wqel
oYFn
D3\Q
w&H
NH%0
q[%b
Y / ,Lx
Y+{
RN&Ub
z KGI!
sd6>0
x>#7
c(VX
4]g
N;;y
is(efS
<`l^
]k/
@T,Az
*^Q'
S''A
5$'0&
k[Q_{
MD>/B
<wrO
uI>M
Xgm1
"mni
1em$W
%`]Y
v_K,\
{D R
Ho+{
JaDx
D$C)
L_W`,
$\)m 5
_&kL
{jKl
%iUR!
-F66
=Vn0;Nj
eRwl
kaLyl
X E
pj%R
> BK1
*_/#j@
r3`A
B+pf
tB@=?>
fV m
+syro?
mudB
{u P
$fBG
0kBX_
SK?=M{
WO`
1(u-
ghT
>VnQ!
ghF
AddMilliseconds
7r +
#:c@.
WF1M(
kGKYw
7=v[!!>
]y;X
^_uy
E0onGhbnNYP8DCSYt8gzo
8Im8
e tS
)UzQ&A5WnX
T'k
rcvoWb
F G`
S&qm
#b|`
=Vo5
LT^&kR
rR (
#^W_a
TArQa
\+,r
WHP'
XtJw
#eep
,jJJ
?58AM\
4`81R
RyT=
,iaU
?ryn
r1h.W
=Voj:Mi
gCAsyr
ja5a
Yn33
{ao|
|z?
PpPI
>[p*L
rumb}
EuN2L[
Z||u s
#y:d
hT9=m
N)#
XNd]
4MR
9*s+
C}em
yhGvEv
}1vD
NWJ|h
E* M-~:3
1o@5
XYz\
"%5$
Q2u?
<'Sf
.lBK
HF@j
LN!)
v.A
C>]]
&bHG
?ZqwAau5Ciz
!,X\z
~/%S%
R) Mm
`S>{
Vsyz
i&M6&
jbk}
<5f<ms
}>j/
]d9Y 5
"+B<
0A@(K7q3
O'j 6<
Vj,C
T@d
!LV.T
>!R3F
4`1{
tg)
#Mu<
QX.=
#8hc
T!% F{
*B:}
t-]=C
B ?0G
[/@jE
'ypAQfHjTHkbg5aL5rjVdEpH8u0E2EW1ZqhTzHPK
"gQ&
n)/L
~a~^
zcY'
>}~
fGp"j
Z{_)q;
{x=P
cpw.)*sz
PG?'
Y~Vq
tORl&J
XIoc8
i4Q
c(g!
0cG
=-|i
n+K(J
>Zqo
]J-n
o`4^+
R x"_D
%^Pn
e`v|
&3Um
VA)v
y-<
v6l:[yk;
!8zv
u"'
wzT$
>pDSJ;
9\_T
VujP*da
Dq ~
!#Gc!O
4G]:]
3)D;
s.42
,YR?S
z3h~
VdR??j*
Bfv~V
Bhw?
(.U
8/4hk
zW#O
|\bG&
! FZ9
>WpmGt
Bhw,
7y8a
n8O,
U#pL
lj ]
yHt b
@N,<
j9M>
C?
Pg`Y
&_!v6
CP%z
eKm
|w7Kn
)orZ
4P2<
86+LG
"zllu
Bhw
r>)
$aM:
"TSI
~q~1B
22$~n_:x
rN*
l4Lq
\4Ak
SLY
/I[
"B[.
IT;"p
qU$1
\;F[s
@Y]_
'lzl1-
g=qv\
HUc2
v:lw
bY]D
7rG&
pl ]
N~sN
m+sH
fQ>-
~[[
N>W5
>< d
I@6"
*N7O
l)V!
@Xg1
6\%?Z
Rdka
T5]*
n$ul B
B ..
WFb:
1,"|U"
<Tm>@_t
pZ'd
0V^TW
System.Security
>Y Fw 6
Cly$;Nj
mzPg
u^U_
)RY4)
xUj3
?dQQ
hc#z
QFfs
3.
eV@t
}U\Q
85(F
01Cb
M9<\5^b
]z`{
>Wox:Mi
Zj N
P(bUP
5e|p dO
ry1/RU3%
BD1dP
tA5?
aG:X
)|CY
gURr
$$i6
1\)*
B^zv
KyhL
7_<[
&&Ex]$2\
|.~F
wU""
o,\M
Bdw6>Wp
8Y'X (
al@V
=~fs
[}xr
$Zw`\
p#;t
_xmK
]<@
i`q(
XYoR
/}8&!
ub;fV
HV>d7
LFCb?
IKcb
/={g
AmH%
.dQ
=rze<(p
;Rt|
?]suJ|
7@l?
`|]rn
pY<I
\#|z
q;;M
CgxC
M3q`
'\_Oi
7#uw
M. 5
?]st@]s
2HG3
oWd.~
3Vn!p
`02P
v[Rrdor
j;V`xy
h7rN
]h12(
~L2h
WZXMM:
Yxct
get_CurrentDomain
Y"L3BTM2
vls iZ
"mb(
[: X
W8 Z2
w;Nj
,V]6
#'e]
Tc=2
9$[f
L !\
EH=t
{u6W'
O4D'
{1F
Yw%c
D(|a
8*r@
g 4Vf|
L!H
UGP+TEn
UdI
)Zt&
D"
"v2(
,D/%
)y2h
hm6V
D`X)
\%/>i
<Rlx;Pkg;NjY;Oj%<Rl
$i02
asF#
Qt"lR
E!EU&
&+/Nn
??@Y
KAE9
|y2^5
C<^~
*>Yi{
"eRN
33s!P
pmfnw
kkWo
Sy-"q
Dt2
Qa5g
%,Q
;wC[
=WoT
`O w
*@\C
GV-:
"rL
q5^k
(NiW^0
CMO!
aid`
rj6K/
Zzb0
2 ~}
L1ka
9i8%
h(Sp
=Wo,
efa]XZl
~o{
V7CbzHDn7NJ18eJTJGW73AlaogV0RZBl
00aa
%zQi
p?]]
c(U@xVi
|V>'
t/YMO
{8R[3
&4B
@d ^
iZrE[
o,d/
4{sT
P`4C
4^ *
@%x!T*O
v8 lg
3&9Z
An]_
qxu?v m
yj2B!
`n{r6
*E&d
}mAz
E-F
nNjH
^jGf
=UmlBfv
P}r<$
E}c)
BIbvQwt6CYcQEtX3MZftPB3EBO
0_e*
^%e
([jt
m=n8
-Z u18
=Wo<
`]D?v
$Je#
k\5%
Qk9]
fZW
Adu^@_s
EcPb
an^Ch
.SI3@
Hlu[*|^?
zel@
bVtI
8J{U
f/y|&@G
7}tl
L)kW
ZWUd
|ckTb
\9n
'jU?p
sUa
'vig
aHTYYq
aStP(Z
c+8r
?p H
v+Z:#
,~4N
u}Hpz
va=
HAtl
Re2s
InM o
O[6%
WQ`w
(hlV/
0I:y
HK
g<^s
=#M,
0dB
w']Q
/zAS8W N
[Gh
VZx\
}JH0
4,F
DialogResult
V?``#
_Ry,
!p9`K
>Zp :Mi
2/>!
xk>:
$" o
!D4'
ew 2
,sE}6(
.~:[W
kNSU
[(w<
.2zC
,Krl
uU/,
}Kwp
*iKQ
>a( l
WVr
N*M#E
Ta[+
`*f!
Zm 7r<
QU/
pG}TMQ=
R&Nk
V?8/3
\r:G
gl %
5gu7
WwA$
EtP
W:7 Ip
^~X(
r6kv
If?W\
dIJQ
t1'
,20@
?y7-y9;
J^Nf
6?6.
?L
;'0%S
C_h)
.S}2
AHaj
cb~ W QL
C+xZ
(q?bu
hb rc
z3.1
ei 4
Ghm9hC
x Y2u
$|8(
%{sN
D<}k
o;dA
x%gw'#yf
R+6:
;$Mc
J+r0
e?PP
-qQ_k
'!5\0
G-]]
.Qs%
"I %
oXfD#
90`0f}z
w<`J
2?E
0:G
lg=m
3Icj
pHvZ
>Xp
U)O?
<npD
70QVH
FbK1
av(HePf
?]r#
>Zp1<Qk
/$^B
Qu!N8]S
;Ic/
jNyK
n.4Ix
r1yI
^& G~8~
N)D^P
z6GV
xi'
8V(
?ZqA?\r
/ }]
du T8
R#*B}
Lc2a
8}'_
CkY-
{6}
'9jr
h21T
1,%W
GmL#!d
]Q>&
1"^LL
h*Zt
?]r,
M-@)
LYRw
3@!G
2YE|
#LO&
,E*I
?%>a
6Q[`
dJ[1
T?-wA$A0
R~!*_
(>bH
O&--;
U}MQz9
r!}o
!_Y'
*D]x
vEM=
wd!9w|h
KY5
(u*d_
x9,x<0(
uPA
f%k:9
9:9`
Bcw ?Zq
ni>|
wV'h
x=>A
>Xp*
rX
LhB8
3Bfy
-`B2
!&9U
k6j~
7;26w
5IXS
i;A\
#*[80
Q!r
8nt
dI-a
f6<1
VA`W
F%>>
oX:1O
~?}c
st P
lJnPd
?]qr
=5g}#
oMdU
Pb^|
[ HAv
TCJn
FAM.
.,!\#
+^nh\
V&+C
p5X5
{,^J
_J"AGA
~8LM
#D5I
C(?.Q
KU?Z9
6GN<Gj
Show
@^iN
N{MV
@1u+d
Zm F
("v
ASy)
f&_~Lg
@W.3l
(5<i
.s6n
7D;3
T{BA
g0Qu
jFF
z;fH
%13j6vMoIVt6Z3SW7MK88pwXLjUOxy9uKHtmgP
-mVo
kwd\{
%EI9
"yy4
f(W-
1o2&
h6v6
U5"C
Y Iv
>UIf
L9wy
CR !
)[e"u$
HTI
b!e"
O{~G
# Z
$1UB
zH`w
-fXr
K7.
Y&.v
t7b"
M|k>Ls:U
[}UO
A(T)
q8w'g3z
|+tq
OLu|h
zk ,=dV
P5Im$
21S%^
Ci{
m=T
=*7f1
Fu~4Cjy
)X56
%EIF
WrapNonExceptionThrows
mjyWb'
`IjD
YHyf
Ifb^2
*.7\e
RuntimeTypeHandle
:,Zn
BzO)2
_H5Z
N?#S
p}L`
f~up
Cgy(;Oj
spi
A4+M1
a_#Y
,[4i
%>4UR
LG\oM
o7S-
kqb
qv/>]
@nNl
17\s
4_z5
'#c}
<Iur
3*G !=
z7zc
%]8pha
Z1Hm
7~1z|
{@A:}5
BN6
"/>e3
wqoH
N#SI
bo9&
9cE>~jJ'DSi
a K57
LJ3"
3 5d?8
hyw<
cmwP
c].m
-+:J
| xY
+Rys{
New
/)Ak*
n3Q E
#C7,O
mr3r
G[}<,f
ecB_
iAtr
NbHI!!
kQZE
~B{8
J?>Xn
6'A)0$
u({T
MH2;
` n+
_;ssG
[+`63e
/LMnS
$N~W
sG8dd<
Acw,;Nj
XA+7
xu8x3VQI8BoF0O2M95YqLu8bZB
>ZqY
1pD2
Fl'
ActWAev
<Tn%:Mi
C?gL;)
/%}7
xMBff
#&[!GD
Abu0
q'c*G
qi2X
4>K
>o0I;
<Tmj;Nj
72x'
\1>58JE[
8ZGC
]qtM
pgQG
U?vxy`
0p
Mk'`
Q<q@D
89lh
`<:<
lGOeN
o[]h
>kUJ
Fq@]
4<!y
" ZD
O=rK
+-xv
'B[o
pnNJ
/-Q{.
OcX
+&:
=Ipz
(r@N ;
#.{-
Eqtz\
' %9q
SfH\0imR
E8U;
dd
^EP{g
9Q+c1c
Euq"
_68<V=w
^rQq%
{Q9`
B@3P^
e%;/jWy
0=~DD
c ZW
^^vy
gGEC>
W,a|kf
U]=i6
{kW-
Bdw';Oj
JO6S
o;Oj
`"sq
Dv"G
uOj&
pakB
XW3?
j F g/
5%1"
[al R
=":6
5fwE
9o}cP
=Vn];Nj
`!JXD
e' W,
fC_s
e=0B
}39A
"y/"|Y2
6Ja8Y
6NN:
aVXZKU
J1["
{2BL
hj[i
lT&m
0x~z
7e. uI
)c<7
6Xfw :
3raW
Jx31
.R:qH
KObc
xkX.n
ipQ*
BP,'=
_6b-
mP3-
n@)3q
:U.(mY
*v06
P&a&
}r7a
?[rg=Tn
2)N/1
3Vn
r/lk
5sN:
pRv7
|_p0
[^}_
I+eb
;PXuvU
eloz\4n
|TV$
Y@3w
u#&z
?]qj
w^es
?@;
v"T*
-B
dz++
r>'
6D<7
8D&>
"@paQYh
5nijF4FZZ081KNSbSB9MsOeFn2V3
ta"i#
gg[%
-$IU
@X^n
Abu\;Nj
f"GE
v|Uv
1kb>lZ
w2?8~
1M,
r.?|
v-)m
bn{M
h4qy
W+xF6
UG 6xd!p
3<~ 2
=Uny=Un
Z~%Z[
y\Zj
"8s9i1V3<
<\i`g
<n#<
;V i
@;_,4K
;|V4
&d:
+r@f
~xnV
Es}#P
[ T7
>ZpkGw
/a *
<Rl|;QlF;Qm
HH-i
<F2T
h3p5Ci.
o(DytSW
31P4
\|s+
ExX
0>J0jwc
!OP.)
A\"[,
3MOxj}
K!5v
`l&j
G#ZV@Y
8#!n
gB.uMx
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
q>ZuM6
=,".
#\{{y
"]k{f
*VBj
e`:M\
z =3
9WLsR
z)HB+
_Q
JAU
W9*M
vtU
@qAj
mK]K
k.,<
x*E,
+&!)\
V#`a
^?p4
2O#$x|KO
vJEZ3
oZ+6
/^^; {
|qY<
7U9W<
{%#f
#TnO
<\;N
\:9X
2exo
>$v
cU%u
uvHM
IU {
? .I
ix/1Q
)\:
T\4_
AY1f=
M/%A
6 u>`
&ebC
JuI/
7Aoy
MNO"
Yo*
07>X
?&F2$E
Qa\;
te%b
We[9
<6m{
1ET
-74y
RJ)
2sIJx
"x-v
Pq' ~P
+If%
'lX!
6jI"s A
b#W]
f? N<
1w+v
LhlGw
>XoL;Nj
,G+I
L1lD
in^Y
l-pe
J>3|
bI2{
(S&w
|pbF
xSDQ
1JS+#
-3Oi$
?]qP=Un
ah?
("WS
38BQ
"8g-
/t ;r#?
=VoX;Nj
RZMC5k_H
h]z=!W
pVwM
=3gm
&+d`
W!XBg6
!35,A
=Tn"
[;po
6FJN}f
A`u}<Rl
TY||
v||2
cs*^
3DP0
=TnX
:u'.0<
:k0'E
@yCAF9
vKM2
}*Y4
7I *J
BhxL;Nj
V+s<
PZ2&9
lhF
o`-;i
,eYN
OV,t
=Tnz
Q()"G!
Sy\!
X/?i
X`ZU
$wf(b
1C`$f=,S
NQ[\f
*IO|
RtA
]LU4`
lK(.(
,~X)
HI'h
& Zb
7P3W
F1ze
9uc&8
@q|R
bj8Zm
i8()7
|rJLk
#y:' D
IBmS
:7w`:=
~X$i
SIxN
glIU-6)C2
"l\x
9i#
a u5
{zJN
+`hz6
e D<Q
qEp?A%
|m`G
#=sp
*Pwh
B]X@
[2Yw
>ZSx
@FeI
H/6fe
Pj7
2G-_
u&h[
uCD
@_t>Xpj;Nj
-JyP
y;Nj
LQ)A4
J8V4
pnaMJ
Sh~R
$ OtZ6u
.KK~
&.V\P
v4Fm
U^;
:C4LW
=Unv;Nj
|sc7J
sM`Gmr
GxMh
ICryptoTransform
wJ)U
`v #
h"i
AZ|#
>,Nc
-_&
`)th
'nku>B
8f.9F$@
eB1\JV8;
(9&{
dO\
cxVx
9;l|(
x*3L
Ex>L
`L4r9
AauE:Mi
QC-tP
!9Wn0p
ph |
hRw{
?[r}
?ZqdAcv
3YMI
P* +JEUn
~G2@E
1+r2
NG^>Hz
y> y|F{
A W\
u2_[|
xE"8E
lX1m
jd)6
/t>2
$*C{
q3O
hl/3
?q&)]
7e"`M
p",5Q
VIQt
Dj{
d<QE
ph)
lz!2
w (\
qZiZ
XIIh
s_nV
eZ@,
0@9(
y8,d
z{b/
h[ QW
4fUn.
( ^;
i@Pu
Ckxs
deg$
TgVI
S 'tv
@|m!G
:2KF
!4"Q
e"qd
E) Z
nQ*S
a3q.
jO:
!mkYoN
>Yp@;Nj
smB
Jl;P
qCf0
+8+s
TL{{
|;K2
j5][
c2eQA0
=WohO
iK4
}{}l+c&
#XXE"
6$_/
>[q\
qKu'
[fR
/4-
tmOc@
<Sn_=Uo
3+ @
Dj{4>Vo
bw3j(i
=?xW
ygfF}
efR6yvW+
'+fT''P$
@^s`;Nj
zr\#
fM`g66
gM>lD
pL%l}
2TU;
@*Y8
}`G"a9j
MessageBox
&5sQ5FfbVfclB8WzZEgnYN2PVhARB5vWe1DS67H
1YC3}
YGl+
CRNvG
>Wp{
Dj$<b
2q)r
Vs@X
xyy}
<Sl$;Nj
{{?
>Yp<;Nj
n#;_J
Dk|V;Ok
K>{G
;qY<
B97d
LV~<~
x+mP
o&5"
;<HO8
U03c
=p'R
Ob
+Ge"
s8r=
B$aD=
.CV/
OPiW/
YLr!
]tf=$
]""3\
.>5(
]^jd
l)-f
I3l
t(sj
|U)?
g&$4
o:Q2
:S
fC]A
gKt^
\pU
p LT8
};Pk
ubCs
<3`s_!<<
*[e/zI
mg%7W
~K[#O
&&iG
W>9@Y
w\>;
Load
_b!R
#n#c
mC!K
phR!
yG5*]L} ]6
/# i
U)O
, Z
Bx~
5.q
=J 5
*Q"pP
1c_9Wc
|Mxf~
Rmp
[K,I
vd$J
JZ=v[
Srp
2R &
jUBb|
F7s*
"J<0
&FDr
[SS9
8"c4
4yT}
Z7hA
#WyC
(UKj`
,<{,
z jG
?]sp?Zq
*!K_
5VAP
iT[ ?
0p@9
k!O092
'sDo',<
7IK
^O#
t5~P
rWO
Wy%7t)
H('b{`
~S>lC
n >_l
URXb
k>N`
S9z*
gq7s@
DjpF
&R.'
3P7
u%~%
9_&x
[@Nz6
QDV 9
G~u42^
4tv7
f&U
i){,`
.|$7
?]qL@_rw;Nj
=Tng@^t
v@Hr
#? |
-GEt
"Fp
<{T\^
iEi}6
(n?3
|iX(
Y#^5
o{r_
%>Wo
*1k]
I`'K
!P6Y
[st!
pGH
E"<-
K$Q5ji
W<$F
qxBI[
8x<e
@guf
Assembly
Adu!
-qID
2 92
U|#}
<8>f
)W8^
Adu0
A]BD
t OK
u0M8
w Lz^
G/K+
"jPI1h0wtLnyEZpFCnrS83N3TAETOOuIs3Y
?]rZ:Mi
9.A*
d#2@
6rj
AduL
P! t,
N#F"xd TA
QY)9
K<&_s
^D=b
JbbR
`tPU
"tR~
.rZE
uj/]y
.04h*
+q"L
.YTNA
} -b
9'k
rK$cM
]c*+9
b^y-w
q\fZ]
a!G
8judIQ
Z{ zB
ed(n
;#xZ
m} m(
lg1:
>Wp<;Nj
Adu}
[aea
4:`Gk
8xpK$
Xy[eu
nDfh
J!F^o*
Em}(;Nj
S$Y`
{jl|
Bfv^
=WnnP
PJ]
0}JU
Z@M^
?C-
Ebhj`
X0p)
%_rI
fpz.k6!
x2.|T
2~+L
Mi5
u@<P
J(r+
Y5d=y=M
Nh5yeQH{
9_1~)
?Lc\
-I>]-
v<|z
T"&Q'
}>rq
{`Z0
Xk:
1SK\
$|<#X=
lA$^9
bkJ7v
.KbV
0"wL.
uvEo
TO=HE
F/,{
60IK
WdG[
LuL
>Em
ZQe
SBWk9
XB.={
fn<N_I5T^
tTfeg
m_22F~_
YU*T
<.>P
C2:tku
)aRAi
p\Envz
5jIW
:)O%~(
I Wz
V%Oo
JE!$
P#V,
_!c&
D;w/
V9zLKQ3
[*XS
2o$15
$^XA
!sd
^MR
8|6i
X hrh\f
U#8Zb
?\r^:Mi
O/lw\
_B2
Z`m1s
<QnL<So
jp<h
-zx%
+@/:.
Qp'X
FL
boEG
w4 1
+|{|
N.i]*'c
',5>
.e@@
TN*T
CrN\
~cI$
=~ R
;3,|K
F~L5
ul*7
^FwK-J
>YpK>Zq$?\r
XfR&>(
O~L
t8F
Y%TPb
)s;).6
H77)
JzP6
5hg
E~ ?=
rETy T
Y7JV
v3D@>
A@Yk
>ZpP;Nj
5<ge
j_-
yn+h
}J}"
2.rt
D|hrx
w.m>
|NZ-
MMD]
o&E2
.xs`-q2Z8O
I?yH^
Ep|4@]s
8XTH
+45;
U3}OJ
v Y\
d_=^aBe~
$WYLoyQGwgZlekXbC3c27yCX6aZx1wyReaG4M
5PY592oEfRnjjXWFXYVh5nS6Bv
avat3O%
&&3xl
'&Vji6
~![@
8hA=
`"ZN
6+#Y2
k$x'
fE2Lv
i>(N]
=CA9
o*0;
_xvK"13
r@;KV
UiY7
[0Di
+>r_:>
%G"
srP7
R'}j
a.q
ei#a
{>vm}
]:4P
J C
jggtb3
I.vGf
do R8
UdF
s#s5
FY^;
s$l$
MxXCwy}
P+N"
Q) RS
+`Mw9)
`SrC
7}Wx
E1m
ywiO~
jPX |
?[rg:Mi
H d-
F2PN
?|pW
xKVb
?Zqt:Mi
{Ay_
nD>Z
jnFs?_xz
e5JXs
}[j
Di{7:Mi
m+A
H:V?
8t0m
PY j0
wHK
WP R
m=%{Ae
?2eI
=Unw:Mi
EDBt
<TmlZ
rNNiD~]
%RL(
'jD/M
?ne
(]BOt
Bfv4
Ctkfo/=T53
/?K"
Q?L#
h/JF
zi"Z
;?pXSL
oD r
+;P
,.J46
gt8KT
&5yK(
6BNn
D#\u
h|l4
ws>F
ze*c
a5+x
)aRX
iv>$A
7=3
.P$pb
JY$Xk
jTts:
S6%
{NB@
q4y8
bod y
GCjD+
AduK
z,H8<
4lKv
8 ap3
#U%]
k da
RJKL
IIs3
*5BVH
I/(e
%N}S!
uL5qU;
QqCj.
GE%+
;G,)
Qd2 W6
r>VD
Q8+T
CB EU`
gG-a
FT5yv
LS<\
yg(A
OAOXM
#){\l#
r}tD1
FDXl
Vd~46}
{no9
=Wn7=Wn6=UnO<UmO<TmM<Rl4=Wo
cfI4*N
@_tfBdw
h @#
H 7-g
@`uzA`uHBex
AJ
s?Z=
~{>w
)]CQ
0Y/y
L->b
} ]0
7!j!w
Bgx
]D^d
?\q8@_r
CE_>p
-N>1
n }8
e[8
}@2d
V[U8
\ !
nV>R
WO@y
smN\
=\8m[`
tk[O
g{n;
&EoQTW
/J)
;DJn
A9'_
lKRK.HD
1 f5
6M,,
2&I]
@btq
y~=v
7Tuc
wd :
{:-x
-SlA
(B-
*n$$
KdD8
$SXTDJQQvaQ4uwH7uS9fmZ6dDj8LaedqWNQiH
h=!n
HkKSq
"1<
9eK!
Adu
3Sl
cL;9z
?[r6=Un
0bHi
B>^G
Yt)
Sp|O
ct%z[$
qm}y
rr4M
C+9iU
e,E2
QBFY'-
m/9L~
c~ob
lv3q
P.Ur
ylb~
VpL+
wl{F
+Y$og
jP<5b6*
wK^H
jaI
t66u
kn=S\BM
@$4=
.a[~
c[/!%
dGbP2xeC
#5qaK0QiouO1H0pBpZUae2t7Wt3mi8Fu04K5
^#
Gk)>
=UmD:Mi
q/*
V?>D
I p^
Qj,KgZ
wR$j2
Ho3
=~;4
Kruq
b9Mf
7]9c
<SmY
7$h@_
kom*
, 8L
_m8%n)c
Gz !
:e[[
3H:Dt
^?ro
<Sm~
/7D$
K(<
vGzZ
Cwzd
F?7W
{N$K
!Ym{
mGno
yB[-
cuLt
]hXKa
:!oV
'{>!
K9 Q
<Tm:I
rcH\
lV0v
M '.
<Sm.
AsF26
9TW
+DLAoI
>Z%'
Aav(?Zqb?[r
w/Wq
]NL6
!={/-'
v< t
u8/@
{a z.J
OXB_
?Z<R
BG!2
B9>Y
K1&
\]LV
?]q<Rl
}<N1k
^?Lv
wrd3
naDT
,(Zv`
f'P
X4$b
16<du
`dEt
1]MqrQ
*<Eji5
]sq
4"gf
Z"NYg
:9BE<X
9>J
+Zt+
31/C
?]s6
MV[}
~IHb?
4 K
^86%
/<.!
7q9pEWqXogH5OifCdW6xi77srab5BMtt
)p!IJ
kB][QeJ
`)_XRL
H.W9
s~=?
ry=8
<6c
Hwa5+
e< Z'
k<eZ5
AUou
E*xn>
)>M}
EK.Q=2
jeK
,}f
kD[]
Au2j_E
S)Ys
a^E=u
m<Yr
l' 2
$B)=
g"sXx
.GcV]
XY|
J2 4
;@pH{
U4yR
hm3?
Dx1s
H%W"
b@%'
;#btz
@k[c
j1`H
s8Sy
KqY N
bh_o
;g#R
YCu9
"w#+
x^B7?
8 1pTT
6;"^vQK
ENLj
\vu{
CI:-
yB,v
,PS+
{$+)t
mbtE
aHmR
Qk\!
J} 3
I'sRp
,:T,
k&HW
9b,N
rJl^
fz/W
>Yo<;Nj
1"S9
lVNm
FX!{
x8%`3
Av2K
<(]U
3?M*o7
34LZ$
74w^
vfY6^
S}b DF
dpeA h
7ovVT
,lJ!
* 2:
96-V
\DYJ
:x|a{x
ONV=
Z+ n
N~k
@_tXBcws?Zq
ZW M
^j,u
=Wn ;Pk
=@jYL%
kC#>
d~/Fny
Z= CN;
"eOt
NWl#w
;[ y
M67!V]
P?gjs
|a3#$8
>'$/
@I?]
`CG<i"
V DA
Soiz
|1J$G
+ng~
97<z
DaK(
F*:IT
?jxOf
Z{2^$D
()Fu
MGs+
/'bux
j0OO
FxSF
s-lr
HP9
Ep:z
!9Ig?
yw?j
\DEj
x1pF
hlIeo(Z-
_&=Kb=
IQ v
iA%]
~YD:
BE_}
c\Nzq
XGui|60Y
UjxR
SA|s
wvq@NDg
Y9RG
oM?i
"[L
<m}
Yb$Xtn
j&$Jt
i0$#b!b
qY_'
NJw`
QwINj
Aev"
x4\$`
*V#<
Mt.k
D4W'f
Z/6
#omj
`SSb-y
DmzDFs}
r=gN
FSG)Z`
G\:9I
'k:kg
Qekf6
FD3BShQ
XY-N
#4=l
a.;LZ
DxP{
HQ+H
b^JZ,
PO1,
3uKC=+
kvUp
]<H6
BYg@
9Q38
@n@v
;Pkp<Rl
a#"Qc`
*8Q!"j^'
\,4O
>Yo(;Nj
LW0@
a53GC~
G)/S
Abt
2OAR
#Lb2"m
ssb?sEt
`~ST
soZ`
s}P=
>9 J
4\&d
XBMgk
>APb
?H#
u4N3
X =(
uW(
gNgc
}54v
jA"|
Y`<b
?fWq
?\sk;Nj
G}MPNV
(1}B
tb4[
fJ+R-
W!t}`
wqhwY
Pmfg'
+?q6y
7xy{V
8@!g -E
K%\>Y5
nsH)
lz;S=
,)REj(c.
f0muY6c5zfRi1kXKD4xs6WOvanKMCVmQG5GcfYW.resources
@Iaj_
&Yq
0s*gU
L#9
g"tI
+"t
&q!g
B~^L
7 #Z
$uz9
u*a=`
\o&3
j:rT
Obro
70=:
P%EP
Ba'"&s
]'uqPj'
*J>
BbI
X|rf
6RUCn
cTLZ,O
(FQW
hl\L
6Kb/Z
L>}K
koQzS
@^t;Ok
P/}\ OB
c!"
LR4Fi
i\H[
Eqp7W
aT;s
-vJ`
WM)6
"D}c
8V&k
>Yo0;Nj
zx\
~aO+
l K0
ERT
'B Y
`B`?
=[;m
ZM4d
l`+"y
\h9|v)
g+A:
aXG:
UATLM
j_I.W
(H":
Su)
T`1_
{^#;
-)Ep
\G)
GZ6+
$%f
jK<
{)Dk
cUTa
>Wpg;Nj
1<4'
4t;5
R6D^
V^P`V
J[Av
C2z?
~Xhp
$B#<u
9._@iM
px~F
?^r">Zpp<Sl
GOen
fa;n
0jX@M
JA,'
^g1g
a2tVK2
nQXXwbMJosd3gZzURmJvrcBv2hRtaFRg
{nib
'JQ<
2 V,
VK6}*
:\D6
=:_i
e/{}
|G-V
;xQ
`Uis
A:I/
oP;CM
I7m
t 0E#
29< -OU
!_lm
22Z,
?*Z
Ec,~]Y
H=J
p?U9
f}JC+
pwAUf
GDo+
az:
0jf#
vzvyuIpOS74blf19F2cNJqeCYLrJw
d57v
@at
No&7
>XpO>Xp
^ezB
6}#+
a'A4
-;y?
Q8OnI
f[;!
x&k
0)n!
#PqyhDxL2zcqnTxEMwAkkaAuTcoXhbUB31yW
~P\d
$cjw
5-+F
WXaJh
H]e&p
Z6j<
=)-e
T_P J
EvV8
C,lgA
c[Bw
G@
nzd-/tH~
0O`e
(A#v
X xnU
OIg;
@bt?
=)-C
E9gU$^
Zt1u
Y:pp
7tz`
I^nLj
F G
oeS\
V60]
System.Resources
^uzA
\w0I{
u/;
<d/>
k4QD
Bn<$
P0-W+
sTw49
YzJkW
kEGFG
0t]C
XH"j=7
uqQh
61R;
VP>8$
m8G.
{|gL
}aBc&
I$8F3
O}JfM
gOa{})
zZ{\&>/
Kze#LT\ K
Aav7;Ok
LzU&<
^KwQ
W&KT3
nf*/
d&/s
1 )k9
xhA v
b*>c
heLm[
\`ME
1^">
4s0E
8o .
"*i]9:
6J5|*
Y1^3"X
JLQ0
MWkXx
skez`
m7,~
fp "~0
W?RS
{&=x
P#<x5
(;BA
&Rv#
: -3
:k9B
**cs
"H(
SB @1
{~e
)>.t
(o1&3e
Ev9
sna0
oYpZ
Urc3
i|.I
a%w>
OnS
T D@
Hv0P
zoJ\
zCGw?O
E%r*%
b4tU
lTTM8Z
Tqi!k
0^,E
d{DX^}f
. b0cD
4wrfAo
<c5DWGU}
^?Bwv
xg>?0
:>xw
F=p
5s~A
l3>v
$wJ
[U+
lf,f
Un/n
kJW&
_FN`Oo
_X!]E
dGK$-
c! e87G
z^@8
_&gK
R3.O5@s
<Ios+.s
xT c4L
%w.TS
'\Ef
}9Fy
!yt%L%!K
VS3Y
b(q7
=6LxR
3G]8
]09*qJ$z
`7d!(UD-
JIcD
g6Ut
#-gG"
MRCJi
8p;&
hKJ(<*
&\w0
]3'm
,eK^|
*Jc5
#;_r
uPmJ
@wTX
NKcV
R k|
.y~W{
hIaK
$1{9i
5; =
_iKe
Z7OM
b;9(
dLF8<
>'"s
$jw
62rcB-
!n?a
8Dt:
241C1r
zR\/
=h$g
N'Sj
<.:k
*cx>
CSd
XXJ*
w[e
E2`C
pcRn
;\4W
-]7;~
b}"Q
yBD7
}K\3
_U`>
+|gc
,k$] P
=a$T
lzc,
0-EW$Y
qF<XB8
o]!X
rckmf
y~}1
C:]#<
2c4
y3-
x8/%
{<0?
l<Ql
5*?a
YiMk0g
6Ge
GF=
r`$=
`lR7Y
4].B
?[r};Pk
9)Ae
=SD
/c-apk
iF$@-,
!\.<1
m/?T
;7=@
R329
5'V)7
,)>}
sv)<
1CE{
mr-<+
bA^4y
m z$0
UrF
M5K/?
O_?
(ni
>XpYBgw
y25@
</rh
3U7{
2n1B
<NYs
j;L^
:K p
WA(t
8%(6
@$Q"j|
`xR"#
%`rz
_E-N
{P<%5xm
tu"[D Xn
EW zZ
7Eim
,'
M9qv
Zxu4
(1s
Z*= 8iq
Q}`
d-|C
=}pr
i\&w
]E'I
lvrC7
] {*^
w3(qi
m @s
cO=j
,?To
wG!?
p<Di8
mx5[
6=/Z
?]shAcv4Em}
$kmc
MDN:f5
z:Fy
-%7M
PsYU
AhqO
DiTP
|s/
-:*/
5Zd)
YuY
LHst~
k.6+
'[O3
ty.R
J:ets
/n[/
$afR
i,u/
[ rd
7ol
`^'U
I7T|
o 34
bRkk
[l|: DI
>Q2
$qoU<*
odnj
Y M-
!]D&
U}xo
z~~M
]jiz
ff*#
-V/B!
(5gc
u&nP2
ZW7i
> ]f[
i27j
fkK<
Ys0%
x4xh>
dAy^
i)A#
G3Ut
8hYH
h/Zh!6
^D5
s<H!
#yQv
}y8\(
cerR
L f-
mJc ^
a-qL
x6M$a
NK+A
E b:~
g58
"'R$c
F,{!
"Eh5v
"&K3 \
;Qh+3
2IwR
2vJw
W~^P
?D5
M# =-
'9#x
vjx^
&&9t
=.Vo
aU,/
Eyr_
KKvw
SE!
x;8ua
[7T<
}7e`
nbt^f
]-mN
HN51X"t
Er 2
Ny65
l`pR
8S UT
i>uB
gtO
\-/c
P&&Y
9d7'
VL\!|
T7%:
%S,?
F&]\8
PgWo6
/#[K
R6FV
;D'N5R
)=h(
E%/t
>ZpJCky!Cky
JjK
c RO
8=++
H3XA
|uH2k
;y_K
~q4`
d)#"
O=z>
Svk0
QvZ]v\i
_6N
0:~9
<TmhFs}
?^r{=Um
'i(Su
8yGO
<Rli>\q
uR]
.Qhnvy
W&|m
q_r =
aM;MF
a)>>
Vd$ZW
S]V 7
MFT~
]pgS
\?\,\)o
^'}(
>nc7
^RBe
s,H
,hdU
<+m
LYpi
U+rq
JoPsS
mr </6
@_tVChz8Fq
F)\K
r=0&P
fCG4
kn_=
ki^lM
nrUf
;=Nk,
S7lA?+U
`;k6)
5G1&=
3c~J+HX
U,EU
JtwE
s`AR
w!ml%5
:M~
K{:
&'1}
zEwR
K;cA0
uUx
i<sH
Abv Gr
W`Ua
2Gr
3j8phg
c2yC
dhokl<x~Cs
i|}k
h)A
!%x"QL
khW
&(O!
s:j'
@`s`;Pk
~2ke;q$$x
PFnN
`RUh
3lxZr5<;
,}w(
LxS
[|TA
(a&B*T
1K |
*4 T
Uq)I
*R#w
WRg\
U#G5
Me![
ebO4/
Cfye;Nj
&G|w
2nS7
{/UAi
\lKF
N'~"
Qv=
5>0
3EF?&
q3B
-wNI}
uaZhtJ
td )!
7"$J
@_P*m
Sk>ATK
5\my
X#'?w
Q$H?h:ph
JVn ?'
LrJ2f
("
xy^c
Hi`
KUh>
skZ8c|+
~'u|
w]!6
RpRlVvwfTTpGSDdyXRDovOZ4m5
2p}:Zp
3<g3
\V BC:>
7P]4
5>]B
WF&3
_eMp#
V?-@
2/L*9U
C0Uw
%R{g
Lb@'A
7/%f
@ Jh
V|tyl
#Mnyyn
[U ?
"3f'
}oH4
&,t?
XAmg}b
?[ro?Zq$
bJSt
kY7G]
WqTu
(BS
v2.0.50727
,NvU/A
D?S$
IL^
8\FI
u}\d
oD&a
N}VZz
@_sK
.|]`
lPa r
9:agT
p8U7:@02
=Vou^
[sQ!d
}zb%
B g
"g]e
6z:R
uW.1
_h E
tSn
XTA|
x]&f
`.pA
#yc5S/
@#<K`?
Z( d
}|s_c\
T)rx
="@l
-$YM
939T=
_N2{
(_w!
fKsTu
\\l}
Z( R
XDbz
)v.2
fr~M
+?k:h
%oymM%
HdBg
f;?*
=?sS
kN}r
aj(cDVv
_yKbJ
Uy*`
?cqwf
E`~
LXs
*Y2dD
gjd8
0<ci
GS$/8
K}|A2
PsEe
kytp
Ael<
a 1L
) To
;H^w
Y3I!1
ma_
i&@9
P>o|T7r7
#w"0w
qnN)8
ES/7
Hk^ GM
wf$3
@M37li
U?X{
zxz*PH
!DOREi2w5bbuO0EMAHz4vwdhhuKBv0nqbZ
H7@[
,V
";^
u}M"z
V_@Y
3|WU+
H5S"
]uT]
B*=s
C(T[
Y]_M
_Av=
"-B(f
RT#h
gYd@
JRIf
kP'-6c
ceC<mxJ#
knb~
yF|I
%1"Zl
L9\d
0G1\
kcl
?\re:Mi
[!$R
57521
-Y~
!-)C
xh`+
Snq
.%Xf
=Wo};Nj
y1-m(
ac@f
elfj
1mO
(0-J
bIJ6
:ueo
mXbM$
]gVb
BE!w
qz)N
EGK6k
Z]p[
u&',
40Q
$PId
:UT20
oyP"q
!+C'v
GcYI
7Z57
}KW
/{ p
B*eJ
7m8E_
`x^T~
sbOCn
-_>g
*%/|
":ud
'_RWu
5?s6
n4 H
ZHsQ\
cf2V
>G`BC
oUr
'`_>
xnq
UH648
+!,?
`u-Q!Y
,7f]
%\z,/
MrS+.
5N#E
d'tP
KH-*
S* -
-Sxl.]
tv`-
Sb0S
&rercUbe5RWQLdpnXsUIonSBGSKTRog174kB6Lx
C'?`
K=*+
u%>W0
r`fmm
~/V:
vc}
(j 9
^>etsq
.8&M
wFh~?
KU,oLeLLN
^H^*
Y>L-a
uBwqJG'
WQw~
3rL?
ydV
@2z|=
KGe#F<
ilS2~
|q/wY>
02W$
T628
L ]p
^wu.
d$7&;(
c2VP
.d[xJD
C91/
,{oCv
A]$4
J|6vMW
4<Lx~
lK>_o
Cw[4{L
m4U5
YC%:5
&t{n`
jnBv-HO) ]
m1oO
$Ft8
Eut8O
?[raL
`X$
ycw
fl-G
+q5 y
de26
@ t_:
u2f}u`&I
>+y Q=
F; >{
NW3v
g[c?
%LJDA
0lDS
aL7&
7I>g
o>V&
b,@:
!|%Fk
CF4S
s<;e
O |2
'SF<
5NT4<
R xG
[LE{J0
N_X'
El|H=Tn
9EszJS
eSSr
Z F{
Ckx_
D&7U'
b#$
7 /
d>c6
}IIS
6PF
\y0y
K/tV{
_?LT'
C8hU
6WgN
iCq
`XH
#j5
"&Zb
+^ %K
2)vP:5K6M,
}<zu'2
<RmhXi
Fhv~\
5mFI
>F
Hn`}
$a"A /
/lM
ZD^2V
/IFt
8.e3
sHe&
]/O`
:h1;%
cg/U{
^j(4
u0$0
5M|
/K=!(
Qt<U
+d
"kT1Q
%R|a
Yw)c
#1k=8{
i5wIm
2QXH!
8my=
,*(6
N#*(
N@VVs
YF&-
Gqos
-I@:
>n]&
VN5CW
K.R&Q
u>$W
FQtt
(eD5
Er| ;Nj
HA=)
_5=R
Y @
@_t5?\s
NC4I
IAfI*L
ag9~
l|;LG]zM(
?Zr8
3Vv>
F~T m~m_
F6$Q9r68
JY,*t
lK7T
<N0*-
GuqVE!
'=!0
?^r<<Sl
Cl9N^
S7`V>5
@pJ4Xw;
X}x$}
e^DO
9 !.20_CG
W71x9q$C
|UD+
y}R+
7J
k7-F!
'K3y
jBY*
o~sP
5x5j
iD+i
lW'n
6vY#P
5B1?V
?<n
pq,O&Hg
>)nI6
T}8
A|ro=
+vAR;
7jI~
}6o
buK\
,-,"ZMH
6 c9
%X@5q*
Q`BIH
Y3%WN
Aau^@_tH
{VHn
m@^i|
kU#z
p-?8
*a_g
buKt
kpSo
=9[Xh
NN|
Rf)<
ASZ3
YOJn
X|SP
!JB-
VqLuhsD"S\
z)RW
|xgE
0:2,
L)}:S
H?[gxp
me=X
>v]~-
TGX
+y >
xL~m
6#]<
npEf
3U%
j<?
lV:H
C S4
ud7y
L(U%
P2Mko
@w};
q~J\L
pNz0
l5jk9
pys :
tRjE
,l_r
vn9Dj
%=e6
Bex Dj{N=Tn
>Yo?;Nj
0vv 2d
OX|{
" $'
)6bR
I8"@
6?:e
m6*%
^5hmSQ
_0e.lwZ3
`4d'
k5l8<$
S-C
K.E,+
]S@[
7._W~
tP`B
]r/(T
^|%>
I<+h
TMSC
+ijq
@b/T
YCWqR=F
dPEZ
|Nf%b
iv?o
~M6h
/tCE
+Y6/f
OWVr
/ZA*
X38z
k|7c
:/5Vq
oik2
UQ3t5
U2<_W$KrVuu
[9$"
c(M(:
x7^nJ
6%bd
Sw5^
Xu}
osvuY1
$FV*d
oW[y
n\~?
(IK]
8#"c
it o>
i`C*~Dp
oD$a
\'>h
A+z]I
5*C0
f +n
qO1
q_Ol
7O 5
vg0X
#wv
fg/QK`z
l\~$!
JYN)
D)Q~
3[ 0
pqVW
WrmwxPwV7NkYf3wTBLEMWJekVcEUS1o
zwkvT
{vES
f"J|d
,3\d4
]p)3
M`s
e76W
c0m S
L8%%k2
@x/"
'/y*]
O?6s
?e3(_
"#L[t-2h
=QHQ
#T8a]
^G ,
/X4&
`[9J
$"Q}
]Y,{R
;lEx
@N>3
DateTime
v1J
KbAV
<zR/
S6%H
|Y1d
)R>+
=U
E~Uj
jX#up
x`Rt
IqB@
Xt`
]3f
y L
^;na
G51!U-
an3<
a'bH
RGI
z+`@/
z, s
* DFe
yP+[(S~l
^sfA
G*7V~
3?gcG
]Co
i/ I
>;k[p
x\M
@ 8|1
Qz`
pH^>Xg
tTW6
vj_a
Tiq_
u4P
D'Z
="6K
J$x=
V`>0
>e'
|G/
@_5{
_Wq
(H`G
rKOk\*
.{}
t1k,
>?-/@
LM_X
"{P
]bB7
H!S'B,
`6#N
lH h
,Dfqy8
>Xpb;Nj
"e??c
>Zpy
PgrV(
`l J
~H'u
` [g
l|I]
|WDR}
Ki"1f
Fe.v|R
|,.7
:v=
9a H
/'Jfh
T R ?<]s
um?2
Okk!
>U];
5"V7
&PD|C4m
Q g
,p|jb
Aav,
3,>}
s-=|
(Gdm
;"ek
Pnn|
%"r]
<Tmr
U!D7
Hz/i
v{ x
w^JA
`1(tT
_+AZ
Ra$^
gt&
^b-p
^2-'\F
n~{~b2
i+)Rp
3u~?
yNZ[
`fJN
,0t8
cBGG
k0'R
Y0pP
B\b
9h3G
NMjZ
" V{
*pB&
AoQ-hB
7D|\
wz}[W
;Ojo<Tm
br
9K`+
Lx^/
2}[c5
VEbn#8
[?}EYW
O2Dr
iiitG
Qgh2
D9\U=Yc
+}#J
1U$+
.}kI|
}2^gk
{tvx
`>.b&61o
/` >
=p011/
6bZ
ILi#H\
i{CC#9Z
*}Q6
S&&J
v;S^;
`#`@
*X^|m
|xY1
60 C
VD 7n
km:1"
!145q?
"jy7mElSOl51C7IBOwn6qxd8prAeiRiknUO
XN;*
@!B NE
`1Yk
UKQp
K-3qiE
>i0A
eNju
Ug \
-|9p
X iY
BUpg
xZ\ME
G_|X
!U7<e>
nniu
6 yy
XuoM
R=$
_!Hx
h@<4
}6%{
!N_\
%5n5
VBj/
Y(=/
kR$7d]
7V(
~(.R
`<oRrr
rN.e"
Cg"T
!] {dB8p%
PVg)
3\$b\7
.[ 'c
WoHU
7B`id@
L@+-X
OA5o
3W)0
KO.3g
&L".7
|<U<4it?
6\=
14XJ
XdH4
@]s,
80^Z
nJ8
Idn.V
hydl*
#\9^)
kAX8y
& i)
n 3Pp6
*;Pk
kex67
b~^3
2^6u
[scmi
wm~C
j<u]
Os"m
;Pjv=Wn
W98"G!Y
%1&UG
"wY0
M'&;
s*l
b&CT9 B
=Vnya
fa1J
Dn|=}*B
Cgy8;Nj
Q=:o
n(TYd9
@^s!
Zyz0
zVpEApVZyuMWgUvL1SFAWBGFuSBvVE8
FzCnv
QQy (
5z95
AcuQAcu
9=L Y
;RwaN
sc~!
;B)y8KL
>cia
@^s
/Lp[
AguG
A>8#
k(@"
;\@]
2T4_
+sv+
&w?M
;-ZN
</>h
~/u
d.A%:
YLdf
9ry_-
Rq%;0
OJM]/
Dm@|L
|2t?
}6J^
duU`
f9[_dCfK
.p
>o?$
>Yp&;Nj
|I9(
4)f(
Abv);Pk
(Dyh
05!`
GCf$hT[
JVYYY
e}@3
OS_
CBlu
4Dc^
k:ah
\xVl
uQYd
^Xe}
wls_
=KrAH<
+0f\q
k\''
$ ;;Jok
:;yk
a&{
{,d1@.
pH-n
_7vZ
$cCtu
O zK
H,dL9
A9H#
\V2@
B>H}
a")f
m.D4#gr
}KbwE
L[1G
;!>+/
'<w,
x)Iw
1Flc
X|MC
k-ifnx`
6.O`Z
NG9@1$
0!+.
7 -
!|Ow
m}|@
2hX
c'U(
%UV~
?-!N@
n`^-w
z`E9
0%T3
W9a!
sGT2
y.OY
A_KUOqD
)[_pC
2>}p
i3w-
}fOnZ
AbvfDj{
dJha
2_F&
PuRk
N'/`
`T F
Z9DY
!]%&
|qm`
>rs@
CgyC;Pk
56ww1
{n_
Q0+:
~(I
' t
C}!f
JS^e
(D!a
v.QE
2N80
!Ct56
jNgH
Um|~"+
tkl
jdl<
t4'7L
/?Wf}J
^3:.?
_o^1?
BKM=
i6 G
)`Ti
(6L8
vmyu
L?WD
~t5!g
Q {X
>Ypo;Nj
h7B3
System.Reflection
7Mgx
o5o
m1;I'
(npt
:OBM
3vId
)j.}
|ER7
Iy_\
2 V|
lsx^a
6 h
f= +
CJIC
eK#!
M(`:!z"?
&hJ{*
Pz!4I
zp*[
c ~c
[o_o;d
mW$l
dcJd
hpuT
hy.YG
HICBj
"+R:
{)Kh
@^trK
aVNDI
'jF?
}zSI
uO3#
`C7/
4g2{
k5pw
F1k8
fQ)jF
pY^
u e~
Tj`0
Yx4
[Y;f
y(a^'
=Vos=TnL<Sm
EfAx"5
{M9
1lcg
13WE
%n\>i\
%Ngl
Peur
GD _4
a73
)dC3
qw@C?V
kYek
lQEg3bIKJ5ihKpgt36mAfSBVIsYHoz
>VL\h%"
uLoq
c0GE6A
/Siz
awEU
`{p\
Mi7@(?
:9&
;HRo
pbFu
rim6
v\k=
C 6b,O
2*B13
J\NZ
v AogI
D:6n
Y,^Z>(
$Vn_
:7]-"8G
0zeH
8kc$
fJ^9
U_\8]L
3=:78
L>P;
/1Gz
Q.FIC
'1xs
<86@
Z@*fE
6G{v &P
uav
Yfvk
H"'r
Ohy&
1dF
TJrO_Em
AGNF
w9p
%b5N+
4BV(
w0gw4
0 T@
E @1'
v f)
:!Ja
HR+:;
;^]`
@Ymn
~}*;J
t a@
Y}_Jm
@^sj@_t
@^tuHw
uSW2
` ]Bt
b\<K[
H&j>w$
pWt
[F_<o
/2{(
62Un
@`uz
.dmOc
V8=w
q|q{
@_s@;Nj
b}%ZM7&ni6
2KNW
^D)M-
*eus
0/=wD
z:D6Um
7 a/X
@^s8
rMR!
P,230
'bq[$
z/ix
(Zi
bd50m
W4/!,
X /s
[2Ui
& X:MT6#
@asD;Nj
c7L[
PMYn
A`V!A$6 1
E|VM
O7c+$
S]X>
/d$=
_^'Tx
,qFk,p
Bfv0
7,F;
g,,b
!e\G
%0D5
0Uh
6s[B
cF4e
e=Ab
@^s(
,yvWu
$-6C
E~Hnj
zhtnp~e
I?egBr
K a{
lwt(-|
!&D
A`uR<Sm
:O|a]&
#Mbb9
sJ':
hcSBa
W7w}3
#"-M
5^ p
(> g
-Eg`})
FQct
k(O
St!b
] 4L
3H1
}*&[
qi{:
y(1H)Z
mscoree.dll
6pg;
(rys(}
aPU|Z
:# $
)G3J
&yd
@*hX
E;o20v
F29NV)
7~nU
*0,;
VLzG
M'sc
Bo:=
aq<0
yd$9#
e6~[
t\>gP
mncH
o3IF
iR'Z
E0[x
1p!M*
W?`?
vmu`n
P/\Q
7M6pr
2 3,w+
CgyhBcwDAau
EE(z
9/f"zOM.
:Lb
=WoxJ{
TGs
,e r
0g/3
a[:u!
!'rx
`}(
RM|[
iB7do
s_OV;
zJ:^/
!+xd
UWwh
_a0;;^
axk.
t@4a
co+M
T>Yc7
=Vnv;Nj
amoD
l2y
fK
AI0px
"$+Ru
8e!L
iM`';ka
trL
K4`x
mRO:
39t-Y
FM.-
2H|G
}b(
F-VzB
1]}6
=Wo0Gv
'3dX.
@'l8[
IwZ 6
+_i
Zig=
AQVv
)`wT`
|wzk
^NiBi
;l{bQ
= HTt
cYFaE
$-Kv
YgvFn*<
>Wo<;Nj
jPX.wK
&VyI
Cli#
h hH
@^sv
'{zyQqs
jApi
y15|u7
v)j]<
,9
{Xke
NR[H
;Nj
V$,F
,"v\KVi
= o,V
'^vA
pgqt
1m4M
2NA:K[
tJ&N
+i`
2yOw;
<Rl(
L]f1u
?3A6
kHTq yYR-
t,^X
Nh<l
.10
Lgd9
,~1'
JFJJLF2PALKTyqt22Ov87CxyyA
{819
$rEO
=Vog
zytl0
BCh8
TD+JF
0@_[
=Voo
/rX;
1B q
ge 9
X&y
D)J<
\^WE
_;@I
CkTN
ZA&7HF
Ovv4
mL.I
gb3Rw
N>Bmc
=VoH
NOGTNVJdXTMP0xnX3e0kT7j
)K}]f
g `}
=VoT
3Vr#
S_4I?[O
tYds/
d5k.
/(I&
+^7?
.k!hH
>Wo@;Nj
UgNXR
X{W"
} ~x
Tb3dV
(3n-P
92q|
nhQ
=Vo<
C%vHjo^
\sd
2[Ha
X}W!$
\".M
~Wnu54
')2F
DIe
J"( r[
,yO
)!3J
u;%d
\Kp?
Y1`Wrw
cUfgZB
)R[
Lnh
s&o\2
uDfG)
DLlZzB
@_u;Nj
ec]fa
e3Eg
m.cs-
a8t3
^$:k
9X{)vK
l;a3u[
?]iA]a
--gn
\[%8
u9zg&2
l:A*[3
K~l=b
e?@:
1qzf
4M"zf
Aeu*
E#i>
cBr}U<;rh/
-yBPo
hYmm
@`u
KbJA
B#n-
`u5V
xz0Yk
+^:$'
Y&p
935'
F@_"
f)"?
\ ^_
Q>k
_M{C
ybvj
{h{%D`
:!aR
U% f|
System.Collections.Generic
.ig7~lu
u~T@R
P;j6y
_]KZ
Y |W
D&a[1/
IX'
a[flRA
2iu5V<
sFHw
HcI"
hRHo|=
}rXK=
p/p5
%gTg>
{V_( o?
,o`W
=$}k
#73U
%/F}
}PRvCj
/)'Q
Cew#jWA
rt02#
M, 2
Fj }#
u #bS
j3;
.jSt
TAFc\
zt}8
-(UA
n7_ul
ijqH?
lo 5
,)#}
Urk:
Ky]`
z&M\p
,=O
+Mcu
?_rS
aq @o
l1wkxk
@P-B7]g
qWRSFt}
~{^
Eo!1
)MMv
$!n3j
[Q=p
s@ Ca;JD
~{w
| (
lZUD
EqXv
s0O6
V+y[
CN-V
Ucj6{
AZca
EcUT
os[ek_0
/00|
fw<`AV
Xp(v
>BYLI9DP
7 DF
M3~u
'9-f
o?%f
3k
d7p@Y
Y,{$iO
v }@
Ob?
@as<
@as=
,k
q@"gm&
)\}R
ZU
oCV
?[r4
H4/S
fVCd'
ikq_
u^DJ
*[%F
-y2Kld
Fu?Y
>h Y
P .l
Y5|s
7fd$
* Pu
Ih#G
!V8_
%70vXw2yJJ1dafv6is18CHQygvmtGz8bYe9Z9f
P!I:
QzNg
"/?h
mR
?\qH;Nj
#|dr"
:II!
ZsuW
%\KAv
Jw}=
~dy0
L@x
nI v@
5f=m/
9`U.8
c\=
?WPLx
mRj
FnfeH
BD4=%
_MXp
5^l8`
6Iu'd
(D,u*
$@Z)1-"
]/V.
*}n
:w[MTR
uq )
/GVv
vMk
DDBx
^hep>
"&CH
1^+(su
;!;,
/9||]
T{fx+
vf7{
gmO^
9^508~ou
s.mI%
'#Rj<
?[r%
t_Xn
(M5eI
LKH
wOTJ
%U-K
OM_yo
$10V
d>d;>
MnV
Yr#p
ZEF\
.J5~ rE't2K
O8u/
x)h/3)e
H'q[
|PU/
<-!8
\v\"%
(vC8
~$kv"
E"D
Phe>b
NMW+7V;
a-8Ho
rK-^RS
XW<1
GUNGU
^%SR
0'|
Y }+
h6=d
#7k1
65hFa
>WoT
>WoL
w6#
C0md6DZ
sy$p
Xd&
1NsT
W9@e
K.eb
i2&r
!.)ER
I!=mO
!F%S
,Qo~
NsG7
/Z~aw
y
sN h
88Z-
ivhq
Bw*l8c
]QKl
GN#v
Di{);Nj
mnBr"
vUU$
Lx*v
MPH0
=UnT>Xpy<Um
KC,9!3
%^ah
oq$=~p
;K1c
cLD0
OQ1K
HnsiN
7Z8*em?
lN;wE
d&HL
EYG@
u-[
.JMw`'
\nz?)|G
^3pGa
u"h
i<B5!O
C[]]
!+wP1
~/UID
dahXq
EYGg
^E{^
swO=
u!k@
aVxK
^fU[
x]61Y
xz }
Gyu_
k9Kg
>ZpT;Nj
97,8:
JEr}
<[6r
'iE*
{VSW
$Of
C99Y
m9!3J
cJGd
{afw
!PK$ho
<^$|
Fv3n
fkC$
@bg3
Wg4L
gkz&
_s;
@1PG
HD?Li
.A-vyI
Bg(LWe
. "M,
V83j
S-/%
Q{tZ
9}}#;-mF
xz &
F'RVbt
/AV)
Cjx&
rl9Yy
'V{[
AM 0
5<rG
?Vj
p;4/
Bfx2
EAft
DCUV
@atP;Qk
^{b9
ay)(R
*vt"1
?\r^=Tn
B&=f8
_+&C
VB2 _nG
,nQnn
,Tg,
/-3Fm
=m-{
`X|"
c"F:%vu
(oRigj
qg,u
Qm%]
y!;//
/kYn
7{h#
g8aWx
%*O0
q^ *O
%YmQ
{fD~
:HJ26
sRs2
BOM$&CFx
!WqIl
G{v~m)
!UjWuG
b:xK
}vaA=
Tn C+
#$o
40?
clt#
d/`."
"BFXB6uj99U0XFxc2CJhQWyJTwpQzVpcAgy
6:_c
get_EntryPoint
0o,q?
`1]e
j3dZTmv7TVxqIN2Lvqe6GgOk6X
;Z3o
pHYs
<~+FHTb
qdbC
CO=
8pw#(
9I \
J![
$USS
bbvz}
90yy
cHpuf
<zjh
kj0V"
!j6R
Oy\+qo
> -3
fu;K
qE z~X
)dob
O--i
0TF4
h3m
_m|r
Q+E;"
Nm-.c
7mb)'
{B
?[r\CfyPBex,
5=+]
_mFV;
92ws
?NT%
'Qx4
P,{E
DxB<
MlRO0.b
d8{A
p4>a
|4%>
#Z:w
,|>?
/nI;J
?l_p
[L9k
*DFT
/1+W
5:$H
WKnK"Lcnnb?c
6Tvdq
<Rl9R
#@]ba/9p
!h8
{f-vi
!Y3%T
J1*Z
pP6U#
?\s:=Vo
mXS8
uC}h
?\r)
6u&
Lweu
Tj1:
E"ANnC
:qd^
v3t e
XO#
Zjv!~
?\r
?\r
&'A~5
Pe!ng
]7U]
D5e"
X ,G
Bex:
x;3I
ioO$
0!/+
2'y'
4X\k
p5C3
Wc9x#W
?\r\
?\rY
Dg?# h
F_2
*p{6Y
\N'Y2nc7%
j)W
J~`~
f i|
/7@r
b3!a
wyIC;
"b!U
S.F
Y=;0X
wFEF
: :j|8C
,=Me
tWRI
eU 2U3
at>i
Qp%Jp
G +x
}|@D
3}aF
|Qj,
(<Mn
~M<e
m*tq
pS&
CndY
sR;y
6]3VK
sfEOz
v^<=
:wv:
AQI3
4m148
Z: |
9X/(
5K_
2O)=G
_s2F@@
Mt[m
E|/z
13R ?@
pq'Ik
`gKe
5'#@
bS{6#
b/[w
w<vX
W/6r
0*EoH
|QFr/
W"?,
)8]x`
'D(
SnZg
;jd!hxR
]!\K2%
%$ @
1?
{*A
Y))q|!a
F'Z'r;u
V0qa
"2F>
43QJJ
jP&p
+=EO
+'P{-s
KE@\
?aNW
fF>=
gQmg
a9vG3ejDnxUUqwjOGg1wVhGirs
K+s'
Aau;
CjxxM
YD. ).R
i5&Q
]JY]
1 @
#NSS']{cq
E{/B
fnoT`W
~.H?&
so3QS[
dlOM-
L6&?
Ce!;
",8g
Vd$W
x!M:z%
~#ISm
#H9S
r@<q
{(%n
5>c?4
{W0
=fy=K
=V5+
,+"M8xY
S0gX
5OiuM
<TnJ?]s
ID"]P
<\x,6
cWIe
-!y_
qN}9P
VyY:p
\Q' ?b
Aau+
]l3.
>XoY>Wo
7L\f
3A]b
HMC
H^d8r:Wa
,4T
07hS;D
Or.6
(5Dp
QJEbmI
w/M#
bs>m8
V&5w
y6}r]
h;n*&
(5 |
|AmS
cw ]
W-~%
%DM
-8zC
Pt!
m=MCR{
=z9:
:A?|Z
z &K
~@]f
qZMa'^s
G#YC>
1o=+
oqN\
B,;b
"Dlc
'a4Pa
5*5y
w=&qp
9[{6
Man;
P-?qC$
(PWAu$
/@L 1
K!ap
[^)L
eo0y^
y]]s
8y)n
rAs`
)J#
P<f0
+B&";d%
/G5w
h=|=e.
=$ZT
r*sj
7Rx
\& *
@F S
>Zq<
z9U.Fd
`3-?
W74j
|g,9^
%zZ
8;yH
'm.9
dC_%
} 0u
rPj6
Y4q=
~6!T
kgZ_
{O 1
{h-'
=/[q@#
2};VyBcw
r~Bm}
fSi
HZ0y
aEs=
(4?.
r$e!
.3-U
d=j
O7.!
^zr1[Ol
RSLe
=Wn1<Tm
pjr
!Oi|m
#Xb
u,ZS
]7 eJ
7_izZ97
CT
r(Z
"Lq[
/Qt#$u
RewVkof
Chw)?[qo:Mi
ip< ^_s
E-0G
^HPT
$,HY
M%V2
=}=e
YAvbG
<MU+{
[aL08
yV@S
Z`sp
84Bb
rt~6
t|fK e
ITOA
)x.
a[JMZ
nx(ZWK
!8M1[7
Pw'9
}r",
` 0Q
\J`se
N.#s
qOZjWk6S083nzOhlGdIPqnQzjnvC733
fg}C
@^tZAav
FW&v
20;H
,?
T*P
>7jr
)Q$>M
+.1.
.g=G>~
fsh).4
',o
#oP'
0CUf
R293
9Ri)
Z2<V<Y
Zl_va,
De3.
<FR5
`f!#
rHh\n
vAB\u"
saXW
' !fiqe
Qa81c
?Tj
" @ `
SN]<
S[r
a558
TLkj
U!vjHEn
Bgw1=Wn
.O]<v9P=Ggdk
RfU82\K
A"2cY
6`JS
.9
Ak;F+
|3HHHP
3"q<
Y Y=`0[
!Z5#
l`1-
`hh7\BwI
TCavGeU
0f^2
>Zqv
ko'
a]f0e
>go<
bKc
%wHW
"70'Z
-a .
;MGY
Q<zP C
T|F^:
POFU
LBE58
j'?=
m!}\p
9|/
na$3#
1'F|
L@yL
&!/LQv.B
HvhE.
UXYE
0&Bc
d1OE
!^c
<TmL;Nj
rwZW
^gP#
VC4 Y
oW/p
#;Y;w
L|fS(
7 Q#GS
1OS8
q(si
W/|2
72 Z
*152
uE`3Y
AAnREUjwcGvf90aG1QmY
|0;[
5+$I[
mOU7
!WR KFj
>+I(
F=pAd
g(VC
e<F?
li\+
X0ET
[sDkn
3EH
\` (
1 .cMi
/-eSXw
EqsI
Gp |
?Zqg:Mi
qG/&
iP<
yMR"%
QX5?
"KxQ
IX1v3
uh"S `
|{Y(
B"h`
v^z\
G7VnL
Soj~=]
*x Q
F4a
>Yqw>Xpk?\re@^t_?]s>Abv
#_
8 w1
q;4:
w?29
if?0
dG'o_
dZ@3j
jxO)k
? _3
y@&o
p <cP
rmPC
/!|8]
ye,?
[Wgp
Y239
9DG+-
)cN-
dd` `
!}IC
vaz"
4o@L
Ks9
R)Qf0Hp
yB!O
|b6V
>ZqZ
R5`XW4
k+elq
_8 =
pUS>
lphN
&qbH
\u(y-
/@)J
Qr+:
b. ~K
U2-p
,`qwH
4bg;
i#5NA
_XAf
L{u !
z<\TH
2M%l
qoVU
,w{\R
"s"i
Qs#V
>O(]
7^,l
=Y[^(
zj?kZ
"IlHOiYbYe0BNr3S8zIgCZq5202LaJydkox
%c_F0
*Y}yt
zv@I
'9a\
:ZVB
7-$XZ
j+:
cp \+y6
['j|
#qa/
nenO
:9Zv
?C)gK
emQ(
X KW
_/`M
K%72|
-H`HM +,
Hb?dw
eI-ji_
w}Iy
F@^
F>(B
0NL
)c19
'h^bm
CA|Uf
P)m|
,{U>
@:3hh
e+8L
ktd
ssWc
5gY
Z?uhQM
YV]}
z-6W
y'bf
!wa"
Vn9eA
(|pD
Kj<%
:N,J>H
;mB|
G`M-
x\t
!cni.
kr-[
-ehAL
7]7P
Vw76
N!LbZM~
|%He
RP)l
yk"~
2qAE
9=mxQ2
_$]9
9k.j
]59
TP75
r Yu
lM^!
&W'p
#6 t3
e~Ff
`?{
`c;Uz
&<S\e~
\J.a
:pU2w
}4<e
r6'.
[j}dc-
_#h`j
&fo}S
m``h
( u9
2n I
VT }
`hSb
0<yT*
SQ |
*wJH]
$eHP
V;AU
T<p-
Dr+M
s`D[<
"\@S2
e<~R
I>{>
u6&
wC*:>v
oAT]
cOM,x
~'iq
DDf~
+S >V
$/\g
7&I5K%
77r
xW*(
RzB]
^^<U-%S+
y}"
`{YyO
\xB}q
GP2Y
RI&+
/[gT
XA<1
ByU}
>Yp
;SIJ
Crc$
>Zp~
@S5A-
.U{D/
9-*g
:Z{"
dD,/
~k%v@
{CO
oqyjT
^"4s
v2?J06?\
( maH
UJks
?lJ2
%7<k
VBI2K
Nbg{a
B!J8yOZ(
>Yp3
>YpN
aG#R}
M>NM
:1:{
LTcnk
Q-z+
b-\K
8GBz
$AMO
lwL-
?_r\
Rk2w
Y]>/
?\q>=Xo}<Rl
';T((
>Yph
@Ase["
set_Key
>Yp`
O8`b*r
>Ypz
H''6
[BPD
flf0K
vuzT
`YzC[
TPT`
kZK\
`W& qM
BSJB
=< g
fS7I
#D=v
3v1S
7(R=G
c|84
TWzEh
dlMJ
8d^$4
Ci:x
Nd>
0H0}X
dqN9
NRt(
btm,
4(Cc
-}x'
e!zp
IzC-
`vse-
zJVf
yh:YH
>pN]M
69wc
F-J\x
7)}JQ
K)S}
!aof
[zmU
jo><
59k/
.)V v
PFQx
ULe
s(4
w|hF
success
%HVC
YR<s7
~h|y-TY2H
aEJi|
T@A`
|{=]>
) @W
7i,b
q0y!
(>^!
/ Aa
{,A-gS
?^rl=Un
l 3l
EscIp
{ eV/
y ](
FHxXr
4h$EF_
+QpX
<,ON
!{o#1o
1Dig
oOkx
GUQSf2J
!%hD
SKpY
B=p,x
ka9<
aM<x
2T1Y# 9i
p.=&
X22h
o{P&
OpL1_
1+w
P!5*
v$s
7d!d
jp%b
qG%-
}>t"[c
g&^!
5p2j
t!tDv
8/6v
R2 #
?+ym
R\*$
)I/r
M5A@
&oCrM
<v A
'`UP
$>m{
QPWx2
W"D%l^
n>feP
\~XC
X[9m
]+?>
;l5b
q"*92
Z>[
7w@o
k>'
|_/53
6M.yy
K)h
59Z1GK
]3<
ECw`
h$i{?
.0*
El}h]
WA<2
7/KS
>QIu
oO4_
>!"
kPE=n
~BOI
Q4xy
#9av
JBU
HwAe
4a%t
` R8
:{s(
5"ny
?]q#
je2=5W.
3M _
v\%{
B/CF
!rE'Fq
n9js
;GU\
u4y\HJ
ZIN$
k*j6
;Hl'
im66
"&9~E
h9]
@H%r
F+I{
Hc}'K
s= i
:H9i
X]f\
?i OW]
d<C
?<NEz
Fy4.M
?\rsCiz
t, pa
Y#9w
8 p"
lHvV
|,;[
x2` 637)*
U+wP$
s%_
Lq;|
JvX;@A
_$-V
&AN8
cs@m
<Smz;Nj
6uT@
_?mi
kiWta
gv8L[J
Cas'H
bmVA
Mc#h
FK*a'
D<T?< O
Ea
get_Message
;Pk
,3DZ
q*Rz
j[H0
>[q1
6
8<!Q
La;P
!%PH
COA,1
Tk;;J
jYfp
d2E
%\3n
s!6K
@GC^
\Q@h(*
mbw
$zw0v59SAmpkowEImzyIW6HpkiZc9cmL0oqcd
=rnep
>{?
_[:W
_*)Jb
)fJ<
$9PEh
B8^R
mg 9>q
IEND
^h8p
Fv**
|4T{
-m7vy9
%1ZB
k%9! /
9xGu
*}t>
0T/?
@as:
P< c"-1
z`/
PP%R
zw:
x0gs
>J^DLK
UcR>H@H
#GUID
|u6Gj
wE/
zGmm
/;8g
.Q!:
-LmR
.%qC
$xt*
G:Ga
mC3E
~<Tm-2~
=WKA
AM|C
)wBq
u,b<*
Z2eWy*%
l^!8V
)bFn
h\P~
S>DQs
H0|Y
5J_S
N #<+
W T8
+Jk|
VvJZ
Y=RW
>Xpo
}Dub
R'v6RN
@D!d
@Ih
y4 jG
:(M].
=na
z[@U
u`5w1
@as+
^oYn't\
$w"`
Rm4
05D:
D/9i
T^Q
&'o4]~
hu0E
M:@f
.wVIp
8Io
"rx
Rvh'U
U2+0
CGA 3
uajQ
#Np+
isC1
;AgD
A? {a
U-B_
N[[$]
QA1
C;3R]
aUgQo
N4 "u4
Wg5jiMQ2ZMCxKyAzeDFHrYP
l#2L;
@_t3@`tnAau~>Xp
tB@3
1FNcg_0
Y[Uk
f3]
;72'
)u u
oZhF
=P#N
MGf\
lm@>
Rjl#
iH1-
SZljpap
2`Z
enWVb
;; ags
A.z@
kP~_
5pBw
_`i+
W] NG
PsE}]_
;Qk=;Nj
r%X!
}dJ*{
2spZSH
5[)70"D
@ 8~
7oH5
.q34
f!R
Z/!v
&2q
8LVFb
JC+
F3[[#
o$Yb
#j1n
7/lT
;s*!
O;["v
]}S
r%XH
ZO$a
W-
Vlm{G
O=.
|l*{
Q8SI
b J,T
rrx
)j^9`
>z-7u
$h5u/
K1]`
%dY
j]J|
f|
?#R7
">+@
3t2t
KLxI
G Uhq
:$f&
L:;\
&I9_
"2B8
UQ|)
N=x+
'l8K`G`V
7KWjf
><7IHr
L #0
l'2I
$/z
_4r},=-
OXr
)f<Y(
+ufX
^6[m]
L<rA
nkb+
c"W
63fK
6!w1U
TW"Y
=Q6~
oQ8;
OxqR
sp?u
dB-1
mj:0
i+a-)
>XpL
<QmX<Rn
b\J&
^?N9L%
Xij/
>XpW
`vl0
%sbl
6kpR
uTW?
>Xp\
>Xp]
AcuBR
_<"d
N{Yy4
>Xp`
s-QvODG50
>Xpk
c$m.
.zf
&bv
ecEig
9p 3
Chz
8lvA
h=k~
<WHr0
g:
SQYVH
zm9
J~A2
<RlE;Nj
.h,u
2 ? A
;omz
k2"^
Chz#
CSV!
*pHj
5X].
- a
e)o2
(x&?
xLUV
hmF2_0
#IeQT1E
}h+y
@asm]
lGMkX41dDMsYrx9nG539RU1m1z
nQ=v
A&H6
=UnP
PX&#C3
0:*`jr
D(tDMx
Dw$i
*|u>
)"E4
ZD><
uK5)N
mR9H
iiz?
'S<N
Pc_184
tnrnL=L
#!V
?\>{
MT_=
Iu|/!
9GDaV
Sr 4
=VnU;Nj
AYLfL
' =;
o]zf
: ?@
LVI[
=UnJ
RZK#
L#71O
Ks$b
YoFk
&GjXB
Acu8
e_3
u( V
.nH?
:r,w`7^
2rBm&d
HG<:
lonV
nlA|
Ou"G70
#GG@
&@uK
4O`f
LG_L#
~bev
x|UD
N%C
YC$>
FUix
S\CP3
Zk[0>`9!
{%l;
J<5/
KDsOG
ROur*
o.m{9
$F
1tQpq
6eRs
=v}&m
VW
*.T<n3
%*qM
@(J'
igY4"a
&a8~
_7S~
kJ>bC-=
f0$b
:V$h%D
on6[
|U"C
H\ B
Acu,
# 30
d?pM
`^(L=jm
e:2\a
%ofNu5EMvCSCnfBBxjrBfMuqWnbLb775F7vRlm
n;"c1 "G)
2*CoA
[7_F
]=?x2/
6@ k
vblZv!
Aj`"
Cixo<Rl9g
mF%M
2I68
u3Bh
@V&C!A
Be8?Zx
]Ym]
Cgy
NN8.
n }
} cl
BN=K
jcs
*nC>}^q
!w_
YJ5
Y? V
kR i
^.8;
\ |Q
U;#?
dUTN
'\o@
l1-)?:
)PNuq
7ONi
v,,)
p+Q$
0+Hn
My v;
4{<4N
wQ>.
IZg6D
Dl$X)
}QuI
{\Ua
X'n6
jaM(
rZdd
?]s\
@]sm<Rl
?]sZ
TiJr
Object
xu[."\
y{i?
j$e[?$
Tz%T
KF}(
!Z X
:Ni#
1HWh
sPY9
93 ?
?]s;
t}1y
eQ9/
9IDAT
|S*N
sB1ag
GzPtN
6hu85qVFU5Jk1sUn2aqDxoW
:yqM]
3y~3
YG9c
z[+
3[KU
*)
(jylZ[M
O-k~
Cixb>Zq
E6xo,
lU r
V ;
&_+
N>Q]yw
MethodInfo
KJzb%
1P-5
/Ma`7c
$imB
7@)y
ESp
*+lZD
' Q%
!AcT6_
G?Wb
"lC{0
##Iu
}+yO*
JyKD
05{Y#
19td
P5;|Z)
L*fe
$Jw5
tSghk
x?e)
E%tK
"zlQ|
k1oYV
$K`NI
}W9o
a:7
>uUa<
@]s0;Nj
$j[y
%04X
fE,6
jOXO
G-%&
XqFX)
& ^]l
314W
4<INg
#8k2
@^r|
>Wo<
\BqZ'
PG~]
Y4P
`Hh^%jhjt
?[ro;Nj
HJoJI
bHY%
9N e
=\Ow
HYvAD5PJ9rCMb9WRVctDHDiqFPELIA
pN!.
<zB!A8
b}@U
& ~(
ER)Q
4koR
uum
c?M
[&L]t)
@Om;
q.0V
>IOkr
-A+%
C>J
7~)N+A
HRq[
eV|
j8Gg
y%PQ
u.kH
?\qT;Nj
0x?9
+x@,
t1*)
ZNzF
DI~
tG[i
a Q~
# k`
Yo+i
6?fn
]K-Xg
jJ 5
@`sd=Vn
z?Ou
^YZ;
udVy
eBTt
fT >
;/^F
pT~]
&YI
aWTg`
<_e1
XJ{
{B}2
B*.$
6S[m~
&Pcl.v
Ow$)h
zYa"
g-88
=Vn>
@Q27
CNM
u\z)
mO\I
sfS$
;`zA,g
<`mT.c
8 <W
Ce)4J<
:/U:
;Pli<Rn
$Lj{
#f F]
fR80
7 vzf
pbs9
5=NR
#q{4
BD@,
&489+
xMS|e
2F~.
iL:)[
Q^#>
/nx%O
|wS
):( -
@_sL
bW-6/
Bfy\A`u@A`u@A`u Aau A`u A`u El|
/:n5
2kCGI;GC
oQT_tn
-uL?N
f~J-&
eZ6k.
i7hqAU4D9OSIGcFzIRM3q
8 \|hit
$9*Y
5SNNv
6*5L$!
;8n7
J,K>
Ux01o
x(mr
UtV4D
-E/
VH5Aq
_ _}
ki]?6
A+)
M8ilU
fX:MRI}3
;,JP
F$&
7N}u
]C9{sL
Ra`#
4u4BB
<Rl)
,dT:|jK
/ pn
gJZa
e6@
&ExE
~; l\{1
WZ#`1
h6(\
(f#p
OVZg
pE3iQj;
w]?'
ggP:w
4]..
x%3H
]N,C
j<\lP
968}
/aJlF&7
O8
Klv^
F;se
VL8v
yn{4+
v,AB
~^K;
yffR[
U&3<
}k2g
@[2*Z
j$T_
,n4
9H r&
8xAN
8}4[CU"
(_eo
%p*=
4!?A
xW6jUaPudBgj94SLcHmunT9rNzltz
[ux`1
x9x0W
^$&v
3\T?
5 ?n1
O{dD
4\F'
c{s8
=Q4k
Q^c.
t'q9
'{ v
e\{h(uK
w1.+^
e,+be
D$0P
rAI#]
ks0f
5FN>f
^R1$
\'G
DuHJ
`H|2Z
Hp%2
nLkxG
Or]U
?DGk
,s7q+P
2VV
\/*:
>Woo
)Uni
rm3>
gcoA
/4 QY
lcl]
$VdI
%9 lM
),a?
Qlz)
\X~Q
^ =F $
*}z
zhftc
}<H
vNNz
4.4@
rOjC
Gu{TL
@1=)
^a>@
oe{&
b2_G"
' )i
-q/Q
rx:!
23<f#
Ec*s
hL7E
V;EO
;C8FI>'
.BZD
3"NW|%
/nXA?
RH`h
qk<_g
75| 3
/1H.
oe{X
7TSS
|;v
ChzJ=Un
|ef$
34 tZ
?Ot"a
yh_4L
2G$q
v|f&B
#/vZ
eUXZZRlp6shDZgeYSgBJPAobVoUcflf
$hN4
GetTypeFromHandle
z*Dg
_?KiI
[k,
(XMN
Cv+I
x>}!@
Y]=}W
8,,i)L01
5f9h
5Ip
A^ J
!nZ)
6RkEx7
!/^t
P {`
o>:
^7=L
nBh,[
- T1
yqr%
@('(
J\#FNo
2gB 2e
&;;]
39)c
PJpeZ^y
EHo*
>5Z'
Nd2
61E"*t
}W2<
]xr0p
BgwhEq|
NQTR
cxS+
h@+Q
)x+;q*
WJh.
YSD3f
!g]
{ qw&b
]Cy~
6/`'
d=YS
Xv TZ
[Bbl
Dj#H
j'y)
&5!d
{a&y
li5S
L~1;
Ciz$
us%w W
rr#
*h)e'
|?j4
Ip#q
yeE_
|EWJ
Y!->
1%z2f
wWu
(O=,K
uJ^a
|tI{"
]Uh
O@"f,
!K]_
TZ\;
PtK)
nr3)
x"-#
-$2j
Em}7<Sm
X:&n=
>[pT;Nj
j[ai
System.Runtime.CompilerServices
0#>|
_NXu
PM6=h
#CEA
HyGs
jtKA
HC_.M#
2r@)
Z'_D
FqdN
?K)
"11e7
AA{
;93|
R]s
)dL8
,Qg)]x
b(bpx
R0MuA$
C$[Z
99pEPn
EmD.
qfz)
VM5El
F~u@.
_)Wr
8Inz
L0#C
.n9,MA
s'~RC
x~xA?t!B
u"E2
@L 1:
?7 +b
g4&WF
F$_n
kwd'
})~is
+he{\
=WoH;Nj
hJ"1]5
System.Windows.Forms
24P)|VF
I]VK
^ .
:C5X
TQL9A
U~'%
1EQ
^H@i
yR:&
%R x
G!YX
UfeO1
\[g
=]E,
<f:4)
e`Jy<
Q?`m
I|KE
<Tn
rhjL`
_XlDi
n|v`Ma
y$u8
oF!z
ts-@h(q
$:td
cj vZ
W+eu)
n*F
zaZj
j:`B
32$G3
d)h
Fac9
1bbC
V,p}
?r7Jr
gJq9
>Zq-
C1ER&
G?e47
>Zq)
}CSA!
YQnF
R8K|
YJG}<
Y>Yz
9Uf=
Q%uwiPN
a;Olp
"Ef582dyJSEVPfrNydhfnoWNT3DN74GP20G
>Zq
>Zq
&Wii
qtFu@
jO^g
/zGU
U \3
0X/q
hSO=
LIr
?qv|
[hm 10
y,Z0l/
ngom
nRV>w
lwoy
6]8*
A`uwV
8Xe3
VBvO
6]8!
Gq}Z
xm/J
ION7T
c'Dz
>Zq@
)Uklt=
gKdtp
?#57
-pjk\
(Rlu
2)kD
b 1
8Oe+@_tdY
,. ;Q
+QQh
%7ZsI$&
TeDmyy
vw5O
Uuy(
QRtY
R/{
#F/C4
I"Rp
|7"`
1n1~
H<0L
UN#9
)LI ];
FGxa
PB9z
c{ D!
?z# 3
_xaJ]
\/1}
4->8
K -
H]d
:u5#"l
lJh
Rh:n
h;B1>
M.\aV
_ x":
zuyY
GRyI7
=j1
y9d
(@Gs
oQe
1"$>
/Efi
vHgm
z!jj
W*tv6
bWMx
fEEC
$ Fa:
n^}k
Ttu)
EF5y
#_*Gb
Gy_^uwA
\sLM
4N4
(]'e
Kod
z lQ8%
@; 6
q+;I
{jg4
(ri
!vuO
4vN]yBVH
El|>:Mi
YW.wq
Aat[Abt
Bnyc
<NcBgx
p641
xsb4
{E'0Z'
1a6U
r\m.
y#la
wqqY
|o(irfI
5#g{F
@$AZB0
\`[M
D;Ok
R+h-
c@wZi
|#8d
9?B
]].G 5
#UY*
L) [
p$,fK
&QGJk
.s{J5x
+?'"
u\/uUG (
/y'Q|$
! HNd
I>z[S
J<=n
5eG" @z
2H<c
IEnumerable`1
!";;}
WWdz
*YtxJ=
>]J,&
wBwn,
|dNl
h{mk
|wU
Aau<Sm
C5Ux
i4}o9
0V5 rn
5*ldTL
jqr}
FpS[*R
O]M4
|v$G!
q8}1d
jMXYH
nE2j
a3me
7)FU
;)Bc
vlt
y\/V
L_*"
9>V
:.mL
=7 7
DX`E
LX_(i
~Kzi
Oirb
AHE((
@_t+;Nj
x0nT
EE3y
![r,
\P +
(U]*Tyyg
Dl|(
gr`Dle
.qbt
?s[
eQ}xW
Y~q0)
"KJ`
2\B$S
vd=<DP
zEQ]
f-yGMt
-}Z@
-/y{%>
_9>bX
cN^
E-~(
xI6 J
i62s
Zl{sDo
Qz[r
J\RC
MB(Rk@
~/r$r
!7V{ta6
F}a>
9`C&
>ZqB:Mi
<+0\ID
]P<Ag
P(J%"
"_=mhB-;
)\g`
*[F*
I4%>
m(1*
~\g'
9gD1+
+ZhN
(srk/ .
=/LY
"';m
4 e*
@_s?
Ukku
@_s4
P8mZ
nh9Z
lI_(
X>R}
3=vkIr
`Tu1
'(,hc
2syW
*~ v
iX1x.
S+"!
R[ [P
\u#Z
rHb
UFT;5
EW{>
4ag_
)*3h
wY_ISFF
z{gy
]oH+S
/1KB
khNkX
y::K6
yF1a
;wS.
UTP}
V%*U
?[9h
]/a
$Q8@lT
UE!}
=)
&rO
W6%k
/% V
uNca+
)eP`
L% ,w
lcn0
d9N?
Y]o-
tJZ)N
u)tt
c:Z*.azi
GTe@
n6?q
"O K
jG15
E 0
CL7S
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05b_64 | Seven05b_64 | VirtualBox | 2018-05-18 15:38:36 | 2018-05-18 15:41:32 | 176 |
23 Behaviors detected by system signatures
Collects information to fingerprint the system
Severity: High
Confidence: High
Installs itself for autorun at Windows startup
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Foster Wheeler Ltd
- data: C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\Foster Wheeler Ltd.exe
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\hvhyukghb
- data: cmd /c type C:\Users\Seven01\AppData\Local\Temp\hvhyukghb.txt | cmd
- file: C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe
Retrieves Windows ProductID, probably to fingerprint the sandbox
Severity: High
Confidence: Very High
Checks the CPU name from registry, possibly for anti-virtualization
Severity: High
Confidence: Very High
Checks the system manufacturer, likely for anti-virtualization
Severity: High
Confidence: Very High
Creates a copy of itself
Severity: High
Confidence: Very High
- copy: C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\Foster Wheeler Ltd.exe
Harvests credentials from local FTP client softwares
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
- file: C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
- file: C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
- key: HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
Harvests information related to installed instant messenger clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
- key: HKEY_CURRENT_USER\Software\Paltalk
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Attempts to remove evidence of file being downloaded from the Internet
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\Foster Wheeler Ltd.exe:Zone.Identifier
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: ygyuig.exe(2728) -> ygyuig.exe(2976)
Deletes its original binary from disk
Severity: High
Confidence: Very High
Creates RWX memory
Severity: Medium
Confidence: Medium
A process attempted to delay the analysis task.
Severity: Medium
Confidence: Very High
- Process: ygyuig.exe tried to sleep 716 seconds, actually delayed analysis time by 0 seconds
Reads data out of its own binary image
Severity: Medium
Confidence: Low
- self_read: process: A5t.exe, pid: 2564, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 2564, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 2564, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 2564, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 2564, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 2944, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 2944, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 2944, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 2944, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 2944, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 200, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 200, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 200, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 200, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 200, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 2752, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 2752, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 2752, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 2752, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 2752, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 1880, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 1880, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 1880, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 1880, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 1880, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 2768, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 2768, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 2768, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 2768, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 2768, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 1004, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 1004, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 1004, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 1004, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 1004, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 1252, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 1252, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 1252, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 1252, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 1252, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 1784, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 1784, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 1784, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 1784, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 1784, offset: 0x00001fd4, length: 0x00000200
- self_read: process: A5t.exe, pid: 1564, offset: 0x00000000, length: 0x00001000
- self_read: process: A5t.exe, pid: 1564, offset: 0x00000080, length: 0x00000200
- self_read: process: A5t.exe, pid: 1564, offset: 0x00000178, length: 0x00000200
- self_read: process: A5t.exe, pid: 1564, offset: 0x00001fb8, length: 0x00000200
- self_read: process: A5t.exe, pid: 1564, offset: 0x00001fd4, length: 0x00000200
A process created a hidden window
Severity: Medium
Confidence: Very High
- Process: success.exe -> "cmd"
- Process: ygyuig.exe -> "cmd"
Drops a binary and executes it
Severity: Medium
Confidence: Medium
- binary: C:\Users\Seven01\AppData\Local\Temp\A5t.exe
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- get_no_useragent: HTTP traffic contains a GET request with no user-agent header
- suspicious_request: http://checkip.dyndns.org/
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x000c8e00, virtual_size: 0x000c8d04
Attempts to connect to a dead IP:Port (1 unique times)
Severity: Low
Confidence: Very High
- IP: 192.168.56.1:80
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05b_64 | Seven05b_64 | VirtualBox | 2018-05-18 15:38:36 | 2018-05-18 15:41:32 | 176 |
11 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\success.exe.config C:\Users\Seven01\AppData\Local\Temp\success.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Local\Temp\success.exe.Local\ C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows C:\Windows\winsxs C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\System32\l_intl.nls C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll \Device\KsecDD C:\Users\Seven01\AppData\Local\Temp\success.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI C:\Windows\System32\tzres.dll C:\Windows\Globalization\it-it.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Users\Seven01\AppData\Local\Temp\it-IT\success.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\success.resources\success.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\success.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\success.resources\success.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\Globalization\it.nlp C:\Users\Seven01\AppData\Local\Temp\it\success.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\success.resources\success.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\success.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\success.resources\success.resources.exe C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll C:\Windows\Globalization\en-us.nlp C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe \Device\NamedPipe\ C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2496.13272265 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2496.13272265 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2496.13272296 C:\Windows\System32\Branding\Basebrd\Basebrd.dll C:\Windows\Branding\Basebrd\basebrd.dll C:\Windows\Globalization\Sorting\sortdefault.nls C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe" C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe.config C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe.Local\ C:\Users\Seven01\AppData\Roaming C:\Users\Seven01\AppData\Roaming\Microsoft\Windows C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs C:\Users\Seven01\AppData\Roaming\Microsoft C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.INI C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\success.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\success.resources\success.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\success.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\success.resources\success.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\success.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\success.resources\success.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\success.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\success.resources\success.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\hvhyukghb.txt C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2728.13274406 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2728.13274406 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2728.13274406 C:\Users\Seven01\AppData\Local\Temp\reg.* C:\Users\Seven01\AppData\Local\Temp\reg C:\ProgramData\Oracle\Java\javapath\reg.* C:\ProgramData\Oracle\Java\javapath\reg C:\Windows\System32\reg.* C:\Windows\System32\reg.COM C:\Windows\System32\reg.exe C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI C:\Windows\System32\wbem\wbemdisp.tlb C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL C:\Windows\SysWOW64\stdole2.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll C:\Windows\Globalization\en.nlp C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\ C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\Foster Wheeler Ltd.exe C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\Foster Wheeler Ltd.exe:Zone.Identifier C:\Users\Seven01\AppData\Local\Temp\tmpG397.tmp C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources\2LW2Y3MMSMHQGWQIE802UVCH9KO9UDYA1IHJP84T.resources.exe C:\Users\Seven01\AppData\Local\Temp\A5t.exe C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\* C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\logins.json C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.INI C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini \??\MountPointManager C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies C:\Users\Seven01\AppData\Local\Microsoft\Windows\History C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.INI C:\Program Files (x86)\Common Files\Apple\Apple Application Support\plutil.exe C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\logins.json C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini C:\Program Files (x86)\Mozilla Firefox\nss3.dll C:\Program Files (x86)\Postbox\nss3.dll C:\Program Files (x86)\Mozilla Thunderbird\nss3.dll C:\Program Files (x86)\SeaMonkey\nss3.dll C:\Program Files (x86)\Flock\nss3.dll C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\UCBrowser\* C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini C:\Users\Seven01\AppData\Roaming\Thunderbird\signons.sqlite C:\Users\Seven01\AppData\Roaming\Thunderbird\logins.json C:\Storage\ C:\mail\ C:\Users\Seven01\AppData\Local\VirtualStore\Program Files\Foxmail\mail\ C:\Users\Seven01\AppData\Local\VirtualStore\Program Files (x86)\Foxmail\mail\ C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini C:\Users\Seven01\AppData\Roaming\The Bat! C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini C:\Users\Seven01\AppData\Roaming\Postbox\signons.sqlite C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx C:\Windows\SysWOW64\wshom.ocx C:\ProgramData\DynDNS\Updater\config.dyndns C:\Users\All Users\AppData\Roaming\FlashFXP\3quick.dat C:\ C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml C:\Users\Seven01\AppData\RoamingSmartFTPClient 2.0FavoritesQuick Connect*.xml C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\ C:\Users\Seven01\AppData\Local\Temp\Ftplist.txt C:\Program Files (x86)\jDownloader\config\database.script C:\Windows\sysnative\wbem\WmiPrvSE.exe \??\PIPE\samr C:\Windows\sysnative\wbem\repository C:\Windows\sysnative\wbem\Logs C:\Windows\sysnative\wbem\AutoRecover C:\Windows\sysnative\wbem\MOF C:\Windows\sysnative\wbem\repository\INDEX.BTR C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\WMIDataDevice C:\Users\Seven01\AppData\Local\Temp\A5t.exe.config C:\Users\Seven01\AppData\Local\Temp\A5t.exe.Local\ C:\Users\Seven01\AppData\Local\Temp\A5t.config C:\Users\Seven01\AppData\Local\Temp\A5t.INI C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start.* C:\Windows\SysWOW64\shell32.dll C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000012.db C:\Users\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb C:\Windows\symbols\dll\System.pdb C:\Windows\dll\System.pdb C:\Windows\System.pdb C:\Users\Seven01\AppData\Local\Temp\A5t.PDB C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb C:\Windows\symbols\exe\ConsoleApp1.pdb C:\Windows\exe\ConsoleApp1.pdb C:\Windows\ConsoleApp1.pdb C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb C:\Windows\symbols\dll\mscorlib.pdb C:\Windows\dll\mscorlib.pdb C:\Windows\mscorlib.pdb C:\Windows\System32\it-IT\werui.dll.mui C:\Windows\System32\werui.dll C:\Windows\System32\it-IT\DUser.dll.mui C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui C:\Windows\Fonts\staticcache.dat C:\Windows\win.ini C:\Windows\System32\uxtheme.dll.Config C:\Windows\System32\uxtheme.dll C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2 C:\Windows\System32\it-IT\erofflps.txt C:\Users\Seven01\AppData\Local\Temp\ C:\Users\Seven01\AppData\Local\Temp\WERC4D1.tmp C:\Users\Seven01\AppData\Local\Temp\WERC4D1.tmp.WERInternalMetadata.xml C:\Windows\System32\drivers\*.mrk C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_* C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a5f31e2 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a5f31e2\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERE682.tmp C:\Users\Seven01\AppData\Local\Temp\WERE682.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a33519f C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a33519f\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERFFC7.tmp C:\Users\Seven01\AppData\Local\Temp\WERFFC7.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0ab76cf7 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0ab76cf7\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER1A35.tmp C:\Users\Seven01\AppData\Local\Temp\WER1A35.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a2b8784 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a2b8784\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER3629.tmp C:\Users\Seven01\AppData\Local\Temp\WER3629.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_07f3a23f C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_07f3a23f\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER5579.tmp C:\Users\Seven01\AppData\Local\Temp\WER5579.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_077fc1dd C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_077fc1dd\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0ad7dd35 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0ad7dd35\Report.wer
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\success.exe.config C:\Users\Seven01\AppData\Local\Temp\success.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\System32\l_intl.nls \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol23.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\System32\tzres.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll \Device\NamedPipe\ C:\Windows\Branding\Basebrd\basebrd.dll C:\Windows\Globalization\Sorting\sortdefault.nls C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe.config C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\System32\wbem\wbemdisp.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll C:\Windows\SysWOW64\stdole2.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx C:\Windows\SysWOW64\wshom.ocx C:\Windows\sysnative\wbem\WmiPrvSE.exe \??\PIPE\samr C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\WMIDataDevice C:\Users\Seven01\AppData\Local\Temp\A5t.exe.config C:\Users\Seven01\AppData\Local\Temp\A5t.exe C:\Windows\SysWOW64\shell32.dll C:\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000012.db C:\Users\desktop.ini C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Roaming C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft C:\Users\Seven01\AppData\Roaming\Microsoft\Windows C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb C:\Windows\symbols\dll\System.pdb C:\Windows\dll\System.pdb C:\Windows\System.pdb C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb C:\Windows\symbols\exe\ConsoleApp1.pdb C:\Windows\exe\ConsoleApp1.pdb C:\Windows\ConsoleApp1.pdb C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb C:\Windows\symbols\dll\mscorlib.pdb C:\Windows\dll\mscorlib.pdb C:\Windows\mscorlib.pdb C:\Windows\System32\it-IT\werui.dll.mui C:\Windows\System32\werui.dll C:\Windows\System32\it-IT\DUser.dll.mui C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui C:\Windows\Fonts\staticcache.dat C:\Windows\win.ini C:\Windows\System32\uxtheme.dll.Config C:\Windows\System32\uxtheme.dll C:\Windows\System32\it-IT\erofflps.txt C:\Users\Seven01\AppData\Local\Temp\WERC4D1.tmp C:\Users\Seven01\AppData\Local\Temp\WERC4D1.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERE682.tmp C:\Users\Seven01\AppData\Local\Temp\WERE682.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERFFC7.tmp C:\Users\Seven01\AppData\Local\Temp\WERFFC7.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER1A35.tmp C:\Users\Seven01\AppData\Local\Temp\WER1A35.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER3629.tmp C:\Users\Seven01\AppData\Local\Temp\WER3629.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER5579.tmp C:\Users\Seven01\AppData\Local\Temp\WER5579.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml
Write Files
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe C:\Users\Seven01\AppData\Local\Temp\hvhyukghb.txt C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\Foster Wheeler Ltd.exe C:\Users\Seven01\AppData\Local\Temp\tmpG397.tmp C:\Users\Seven01\AppData\Local\Temp\A5t.exe C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat \??\PIPE\samr C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\WMIDataDevice C:\Users\Seven01\AppData\Local\Temp\WERC4D1.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a5f31e2\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERE682.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a33519f\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERFFC7.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0ab76cf7\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER1A35.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0a2b8784\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER3629.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_07f3a23f\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER5579.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_077fc1dd\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_a5t.exe_fcf1331fa1dcd21ee445bf76285165bd7c718ce_0ad7dd35\Report.wer
Delete Files
C:\Users\Seven01\AppData\Local\Temp\success.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2496.13272265 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2496.13272265 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2496.13272296 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2728.13274406 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2728.13274406 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2728.13274406 C:\Users\Seven01\AppData\Local\Temp\Foster Wheeler Ltd\Foster Wheeler Ltd.exe:Zone.Identifier C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe C:\Users\Seven01\AppData\Local\Temp\WERC4D1.tmp C:\Users\Seven01\AppData\Local\Temp\WERC4D1.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERE682.tmp C:\Users\Seven01\AppData\Local\Temp\WERE682.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERFFC7.tmp C:\Users\Seven01\AppData\Local\Temp\WERFFC7.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER1A35.tmp C:\Users\Seven01\AppData\Local\Temp\WER1A35.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER3629.tmp C:\Users\Seven01\AppData\Local\Temp\WER3629.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER5579.tmp C:\Users\Seven01\AppData\Local\Temp\WER5579.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\success.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4c4c47a4\416241a4 HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7e5b0b3a\38c1333 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|success.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|success.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|success.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7e5b0b3a\5ab73485 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ygyuig.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|ygyuig.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|ygyuig.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|ygyuig.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\hvhyukghb HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\535ea7aa\1168d3aa HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\AppID\ygyuig.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\8188F324 HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_CURRENT_USER\Software\Classes\WinMgmts HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_CURRENT_USER\Software\Classes\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default) HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\410 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\10 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ygyuig_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_CURRENT_USER HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\System\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Foster Wheeler Ltd HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\13ab09c1\13882b6c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\13ab09c1\1100918d HKEY_CURRENT_USER\Control Panel\International HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it-IT_b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\1c4dd593 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it_b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\4deb99ab HKEY_LOCAL_MACHINE\Software\Policies HKEY_CURRENT_USER\Software\Policies HKEY_CURRENT_USER\Software HKEY_LOCAL_MACHINE\Software HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\ygyuig.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1 HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions HKEY_CLASSES_ROOT\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\410 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\10 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default) HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites HKEY_CURRENT_USER\Software\Paltalk HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FTP Commander HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC HKEY_CURRENT_USER\SOFTWARE\Vitalwerks\DUC HKEY_CURRENT_USER\Software\DownloadManager\Passwords HKEY_USERS\S-1-5-20_Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\Software\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\# HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\# HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\# HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994ad04-93ef-11d0-a3cc-00a0c9223196} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eCDInWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eHeadphoneWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eMicInWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerTopo HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31e60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\#eSpeakerWave HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{C2D43895-0262-4873-A789-C2F96D24B693} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{684BB8B6-2793-49A5-8012-E0A941B4B4DF} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{5F6D61D9-D207-449A-BD48-652A5D1F25BE} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{29898C9D-B0A4-4FEF-BDB6-57A562022CEE} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{E43D242B-9EAB-4626-A952-46649FBB939A} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANBH HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#NDISWANIPV6 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{8E301A52-AFFA-4F49-B9CA-C79096A1A056} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{DF4A9D2C-8742-4EB1-8703-D395C4183F33} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\#{eeab7790-c514-11d1-b42b-00805fc1270e}&asyncmac HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{83da6326-97a6-4088-9453-a1923f573b29}\00000006 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Pnp\{71d10298-bdb9-4dcd-a87a-eec6137ab254}\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Properties\{8c7ed206-3f8a-4827-b3ab-ae9e1faefc6c} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\# HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\Properties HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceHandlers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyCacheDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\SW#{eeab7790-c514-11d1-b42b-00805fc1270e} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyHwIdKey HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroup HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\Software\Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\system\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32 HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009 HKEY_PERFORMANCE_TEXT\Counter HKEY_PERFORMANCE_DATA\238 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\A5t.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\63fc17e7\5b5a3ba7 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\A5t.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory HKEY_CLASSES_ROOT\Directory HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler HKEY_CLASSES_ROOT\Folder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler HKEY_CLASSES_ROOT\AllFilesystemObjects HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|A5t.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|A5t.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|A5t.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\CLR20r3 HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_CURRENT_USER\Keyboard Layout\Toggle HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\A5t.exe
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\hvhyukghb HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\8188F324 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Foster Wheeler Ltd HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040520160406\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016040820160409\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\ygyuig.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\##?#STORAGE#Volume#{35122303-fb0b-11e5-b945-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ServiceParameters HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{69AD4AEE-51BE-439B-A92C-86AE490E8B30}\LoadUserSettings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_CAFE&SUBSYS_00000000&REV_00\3&267A616A&0&20\Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMVBOX_CD-ROM_____________________________1.0_____\5&106AF171&0&1.0.0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_00000000&REV_01\3&267A616A&0&09\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&0\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2F42C713&0&1\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{6994AD04-93EF-11D0-A3CC-00A0C9223196}\##?#HDAUDIO#FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034#4&31E60982&0&0001#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_8384&DEV_7680&SUBSYS_83847680&REV_1034\4&31E60982&0&0001\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#PCI#VEN_8086&DEV_100E&SUBSYS_001E8086&REV_02#3&267a616a&0&18#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#*ISATAP#0001#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_AGILEVPNMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_L2TPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANBH#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIP#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_NDISWANIPV6#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPPOEMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_PPTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#ROOT#MS_SSTPMINIPORT#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{ad498944-762f-11d0-8dcb-00c04fc3358c}\##?#Root#SYSTEM#0000#{ad498944-762f-11d0-8dcb-00c04fc3358c}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ClassGUID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Phantom HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ContainerID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Capabilities HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Legacy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\ConfigFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\DeviceInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\HardwareID HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CompatibleIDs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{cac88484-7515-4c03-82e6-71a87abac361}\##?#SW#{eeab7790-c514-11d1-b42b-00805fc1270e}#asyncmac#{cac88484-7515-4c03-82e6-71a87abac361}\#\Control\Linked HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceHandlers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\LastUpdateTime HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyCacheDate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters\DeviceGroup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{1D11B68C-3611-45AD-A3A9-DF5BEF6A3827}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{5A4B1C7F-0474-4F5A-AD71-412EF0F51D47}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{AB8C10DB-938A-46E7-81A7-3B33DEC13555}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{F0CE0BE7-6BC7-49B5-8E71-F5FEEA56D0B1}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_PERFORMANCE_TEXT\Counter HKEY_PERFORMANCE_DATA\238 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57
Write Keys
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\hvhyukghb HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ygyuig_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\ygyuig_RASAPI32\FileDirectory HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Foster Wheeler Ltd HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
Delete Keys
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\CustomPropertyHwIdKey
Mutexes
Global\CLR_CASOFF_MUTEX Global\.net clr networking Local\_!MSFTHISTORY!_ Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5! Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies! Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5! Local\!IETld!Mutex Local\c:!users!seven01!appdata!roaming!microsoft!windows!ietldcache! Global\e76bb364-5aa0-11e8-8646-0800274633c1 Local\MSCTF.Asm.MutexDefault1 Global\ed154924-5aa0-11e8-8646-0800274633c1 Global\f0c7ceb6-5aa0-11e8-8646-0800274633c1 Global\f4c69f88-5aa0-11e8-8646-0800274633c1 Global\f90cf6e6-5aa0-11e8-8646-0800274633c1 Global\fd619c60-5aa0-11e8-8646-0800274633c1 Global\01bfcb42-5aa1-11e8-8646-0800274633c1
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW kernel32.dll.InitializeCriticalSectionAndSpinCount kernel32.dll.IsProcessorFeaturePresent msvcrt.dll._set_error_mode msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z kernel32.dll.FindActCtxSectionStringW kernel32.dll.GetSystemWindowsDirectoryW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap mscorwks.dll._CorExeMain mscorwks.dll.GetCLRFunction advapi32.dll.RegisterTraceGuidsW advapi32.dll.UnregisterTraceGuids advapi32.dll.GetTraceLoggerHandle advapi32.dll.GetTraceEnableLevel advapi32.dll.GetTraceEnableFlags advapi32.dll.TraceEvent mscoree.dll.IEE mscoreei.dll.IEE mscorwks.dll.IEE mscoree.dll.GetStartupFlags mscoreei.dll.GetStartupFlags mscoree.dll.GetHostConfigurationFile mscoreei.dll.GetHostConfigurationFile mscoreei.dll.GetCORVersion mscoree.dll.GetCORSystemDirectory mscoreei.dll.GetCORSystemDirectory_RetAddr mscoreei.dll.CreateConfigStream ntdll.dll.RtlUnwind kernel32.dll.IsWow64Process advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddVectoredContinueHandler kernel32.dll.RemoveVectoredContinueHandler advapi32.dll.ConvertSidToStringSidW shell32.dll.SHGetFolderPathW kernel32.dll.GetWriteWatch kernel32.dll.ResetWriteWatch kernel32.dll.CreateMemoryResourceNotification kernel32.dll.QueryMemoryResourceNotification kernel32.dll.QueryActCtxW kernel32.dll.GetVersionExW kernel32.dll.GetFullPathNameW ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 ole32.dll.CoGetContextToken advapi32.dll.CryptAcquireContextA advapi32.dll.CryptReleaseContext advapi32.dll.CryptCreateHash advapi32.dll.CryptDestroyHash advapi32.dll.CryptHashData advapi32.dll.CryptGetHashParam advapi32.dll.CryptImportKey advapi32.dll.CryptExportKey advapi32.dll.CryptGenKey advapi32.dll.CryptGetKeyParam advapi32.dll.CryptDestroyKey advapi32.dll.CryptVerifySignatureA advapi32.dll.CryptSignHashA advapi32.dll.CryptGetProvParam advapi32.dll.CryptGetUserKey advapi32.dll.CryptEnumProvidersA mscoree.dll.GetMetaDataInternalInterface mscoreei.dll.GetMetaDataInternalInterface mscorwks.dll.GetMetaDataInternalInterface mscorjit.dll.getJit kernel32.dll.GetUserDefaultUILanguage kernel32.dll.SetErrorMode kernel32.dll.GetFileAttributesExW mscoreei.dll.LoadLibraryShim culture.dll.ConvertLangIdToCultureName kernel32.dll.lstrlen kernel32.dll.lstrlenW mscoree.dll.ND_RI4 mscoreei.dll.ND_RI4 bcrypt.dll.BCryptGetFipsAlgorithmMode kernel32.dll.GlobalMemoryStatusEx kernel32.dll.VirtualProtect kernel32.dll.GetEnvironmentVariableW kernel32.dll.SwitchToThread kernel32.dll.CloseHandle kernel32.dll.GetCurrentProcessId advapi32.dll.LookupPrivilegeValueW kernel32.dll.GetCurrentProcess advapi32.dll.AdjustTokenPrivileges kernel32.dll.OpenProcess psapi.dll.EnumProcessModules psapi.dll.GetModuleInformation psapi.dll.GetModuleBaseNameW psapi.dll.GetModuleFileNameExW kernel32.dll.GetProcAddress kernel32.dll.DebugActiveProcess kernel32.dll.WaitForDebugEvent kernel32.dll.ContinueDebugEvent kernel32.dll.DeleteFileA advapi32.dll.SetKernelObjectSecurity advapi32.dll.GetKernelObjectSecurity ntdll.dll.NtSetInformationProcess ntdll.dll.NtProtectVirtualMemory kernel32.dll.GetModuleFileNameW shfolder.dll.SHGetFolderPathW kernel32.dll.MoveFileW kernel32.dll.LocalFree kernel32.dll.CreatePipe kernel32.dll.DuplicateHandle kernel32.dll.GetStdHandle kernel32.dll.GetCurrentDirectoryW kernel32.dll.CreateProcessW kernel32.dll.GetFileType kernel32.dll.GetConsoleCP kernel32.dll.GetACP kernel32.dll.UnmapViewOfFile kernel32.dll.GetConsoleOutputCP kernel32.dll.WriteFile ole32.dll.CoUninitialize kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx advapi32.dll.EventUnregister kernel32.dll.SetThreadUILanguage kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle kernel32.dll.CopyFileExW kernel32.dll.IsDebuggerPresent kernel32.dll.SetConsoleInputExeNameW ntdll.dll.NtQueryInformationProcess kernel32.dll.GetTempPathW kernel32.dll.CreateFileW kernel32.dll.GetFileSize kernel32.dll.ReadFile kernel32.dll.VirtualAllocEx kernel32.dll.GetThreadContext kernel32.dll.Wow64GetThreadContext ntdll.dll.NtUnmapViewOfSection kernel32.dll.ResumeThread kernel32.dll.SetThreadContext kernel32.dll.Wow64SetThreadContext kernel32.dll.WriteProcessMemory kernel32.dll.ReadProcessMemory kernel32.dll.TerminateProcess uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptCreateHash cryptsp.dll.CryptDestroyHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam ole32.dll.CreateBindCtx ole32.dll.CoGetObjectContext sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW sechost.dll.LookupAccountSidLocalW cryptsp.dll.CryptGenRandom ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree ole32.dll.CoCreateInstance ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult rpcrtremote.dll.I_RpcExtInitializeExtensionPoint ole32.dll.MkParseDisplayName oleaut32.dll.#2 oleaut32.dll.#6 kernel32.dll.GetThreadPreferredUILanguages kernel32.dll.SetThreadPreferredUILanguages kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetSystemDefaultLocaleName ole32.dll.BindMoniker sxs.dll.SxsOleAut32RedirectTypeLibrary advapi32.dll.RegOpenKeyW advapi32.dll.RegEnumKeyW advapi32.dll.RegQueryValueW sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid sxs.dll.SxsLookupClrGuid oleaut32.dll.#9 oleaut32.dll.#4 oleaut32.dll.#283 oleaut32.dll.#284 mscoreei.dll._CorDllMain mscoree.dll.GetTokenForVTableEntry mscoree.dll.SetTargetForVTableEntry mscoree.dll.GetTargetForVTableEntry mscoreei.dll.GetTokenForVTableEntry mscoreei.dll.SetTargetForVTableEntry mscoreei.dll.GetTargetForVTableEntry kernel32.dll.GetLastError kernel32.dll.LocalAlloc oleaut32.dll.VariantInit oleaut32.dll.VariantClear oleaut32.dll.#7 kernel32.dll.CreateEventW kernel32.dll.SetEvent ole32.dll.CoWaitForMultipleHandles ole32.dll.IIDFromString kernel32.dll.LoadLibraryA wminet_utils.dll.ResetSecurity wminet_utils.dll.SetSecurity wminet_utils.dll.BlessIWbemServices wminet_utils.dll.BlessIWbemServicesObject wminet_utils.dll.GetPropertyHandle wminet_utils.dll.WritePropertyValue wminet_utils.dll.Clone wminet_utils.dll.VerifyClientKey wminet_utils.dll.GetQualifierSet wminet_utils.dll.Get wminet_utils.dll.Put wminet_utils.dll.Delete wminet_utils.dll.GetNames wminet_utils.dll.BeginEnumeration wminet_utils.dll.Next wminet_utils.dll.EndEnumeration wminet_utils.dll.GetPropertyQualifierSet wminet_utils.dll.GetObjectText wminet_utils.dll.SpawnDerivedClass wminet_utils.dll.SpawnInstance wminet_utils.dll.CompareTo wminet_utils.dll.GetPropertyOrigin wminet_utils.dll.InheritsFrom wminet_utils.dll.GetMethod wminet_utils.dll.PutMethod wminet_utils.dll.DeleteMethod wminet_utils.dll.BeginMethodEnumeration wminet_utils.dll.NextMethod wminet_utils.dll.EndMethodEnumeration wminet_utils.dll.GetMethodQualifierSet wminet_utils.dll.GetMethodOrigin wminet_utils.dll.QualifierSet_Get wminet_utils.dll.QualifierSet_Put wminet_utils.dll.QualifierSet_Delete wminet_utils.dll.QualifierSet_GetNames wminet_utils.dll.QualifierSet_BeginEnumeration wminet_utils.dll.QualifierSet_Next wminet_utils.dll.QualifierSet_EndEnumeration wminet_utils.dll.GetCurrentApartmentType wminet_utils.dll.GetDemultiplexedStub wminet_utils.dll.CreateInstanceEnumWmi wminet_utils.dll.CreateClassEnumWmi wminet_utils.dll.ExecQueryWmi wminet_utils.dll.ExecNotificationQueryWmi wminet_utils.dll.PutInstanceWmi wminet_utils.dll.PutClassWmi wminet_utils.dll.CloneEnumWbemClassObject wminet_utils.dll.ConnectServerWmi oleaut32.dll.#500 oleaut32.dll.SysStringLen kernel32.dll.RtlZeroMemory kernel32.dll.RegOpenKeyExW advapi32.dll.GetUserNameW kernel32.dll.GetComputerNameW mscoree.dll.ND_RI2 mscoreei.dll.ND_RI2 rasapi32.dll.RasEnumConnectionsW rtutils.dll.TraceRegisterExA rtutils.dll.TracePrintfExA sechost.dll.OpenSCManagerW sechost.dll.OpenServiceW sechost.dll.QueryServiceStatus sechost.dll.CloseServiceHandle ws2_32.dll.WSAStartup ws2_32.dll.WSASocketW ws2_32.dll.setsockopt ws2_32.dll.WSAEventSelect ws2_32.dll.ioctlsocket ws2_32.dll.closesocket advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.CreateFileMappingW kernel32.dll.MapViewOfFile kernel32.dll.VirtualQuery kernel32.dll.ReleaseMutex advapi32.dll.CreateWellKnownSid kernel32.dll.CreateMutexW kernel32.dll.WaitForSingleObject kernel32.dll.OpenMutexW kernel32.dll.GetProcessTimes ws2_32.dll.WSAIoctl kernel32.dll.FormatMessageW rasapi32.dll.RasConnectionNotificationW advapi32.dll.RegOpenCurrentUser advapi32.dll.RegNotifyChangeKeyValue sechost.dll.NotifyServiceStatusChangeA winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser kernel32.dll.ResetEvent iphlpapi.dll.GetNetworkParams dnsapi.dll.DnsQueryConfig iphlpapi.dll.GetAdaptersAddresses iphlpapi.dll.GetIpInterfaceEntry iphlpapi.dll.GetBestInterfaceEx ws2_32.dll.inet_addr ws2_32.dll.getaddrinfo ws2_32.dll.freeaddrinfo ws2_32.dll.WSAConnect ws2_32.dll.send ws2_32.dll.recv ws2_32.dll.shutdown kernel32.dll.GetModuleHandleW user32.dll.DefWindowProcW gdi32.dll.GetStockObject user32.dll.RegisterClassW user32.dll.CreateWindowExW user32.dll.SetWindowLongW user32.dll.GetWindowLongW kernel32.dll.GetCurrentThread kernel32.dll.GetCurrentThreadId user32.dll.CallWindowProcW user32.dll.RegisterWindowMessageW dwmapi.dll.DwmIsCompositionEnabled ntdll.dll.NtQuerySystemInformation kernel32.dll.CreateDirectoryW kernel32.dll.CopyFileW advapi32.dll.RegSetValueExW kernel32.dll.DeleteFileW kernel32.dll.GetModuleFileNameA kernel32.dll.MoveFileExW kernel32.dll.CreateIoCompletionPort kernel32.dll.PostQueuedCompletionStatus ntdll.dll.NtQueryInformationThread ntdll.dll.NtGetCurrentProcessorNumber kernel32.dll.RtlMoveMemory shell32.dll.ShellExecuteEx shell32.dll.ShellExecuteExW kernel32.dll.FindFirstFileW kernel32.dll.FindClose kernel32.dll.GetExitCodeProcess kernel32.dll.GetSystemTimeAsFileTime user32.dll.SetWindowsHookExW user32.dll.GetLastInputInfo user32.dll.GetSystemMetrics setupapi.dll.CM_Get_Device_Interface_List_Size_ExW mlang.dll.#112 wininet.dll.FindFirstUrlCacheEntryA setupapi.dll.CM_Get_Device_Interface_List_ExW user32.dll.GetClientRect user32.dll.GetWindowRect kernel32.dll.SetFileInformationByHandle user32.dll.GetParent ole32.dll.OleInitialize ole32.dll.CoRegisterMessageFilter user32.dll.PeekMessageW user32.dll.IsWindowUnicode user32.dll.GetMessageW user32.dll.TranslateMessage user32.dll.DispatchMessageW urlmon.dll.CreateUri kernel32.dll.InitializeSRWLock kernel32.dll.AcquireSRWLockExclusive kernel32.dll.AcquireSRWLockShared kernel32.dll.ReleaseSRWLockExclusive kernel32.dll.ReleaseSRWLockShared wininet.dll.FindNextUrlCacheEntryA advapi32.dll.AddMandatoryAce user32.dll.WaitMessage urlmon.dll.CreateIUriBuilder urlmon.dll.IntlPercentEncodeNormalize wininet.dll.FindCloseUrlCache cryptsp.dll.CryptAcquireContextA cryptsp.dll.CryptReleaseContext ole32.dll.CoRevokeInitializeSpy comctl32.dll.#388 ole32.dll.CLSIDFromProgIDEx kernel32.dll.GetVolumeInformationA vssapi.dll.CreateWriter advapi32.dll.LookupAccountNameW samcli.dll.NetLocalGroupGetMembers samlib.dll.SamConnect rpcrt4.dll.NdrClientCall3 rpcrt4.dll.RpcStringBindingComposeW rpcrt4.dll.RpcBindingFromStringBindingW rpcrt4.dll.RpcStringFreeW rpcrt4.dll.RpcBindingFree samlib.dll.SamOpenDomain samlib.dll.SamLookupNamesInDomain samlib.dll.SamOpenAlias samlib.dll.SamFreeMemory samlib.dll.SamCloseHandle samlib.dll.SamGetMembersInAlias netutils.dll.NetApiBufferFree ole32.dll.CoCreateGuid ole32.dll.StringFromCLSID propsys.dll.VariantToPropVariant wbemcore.dll.Reinitialize wbemsvc.dll.DllGetClassObject wbemsvc.dll.DllCanUnloadNow authz.dll.AuthzInitializeContextFromToken authz.dll.AuthzInitializeObjectAccessAuditEvent2 authz.dll.AuthzAccessCheck authz.dll.AuthzFreeAuditEvent authz.dll.AuthzFreeContext authz.dll.AuthzInitializeResourceManager authz.dll.AuthzFreeResourceManager rpcrt4.dll.RpcBindingCreateW rpcrt4.dll.RpcBindingBind rpcrt4.dll.I_RpcMapWin32Status advapi32.dll.EventWrite kernel32.dll.RegCloseKey kernel32.dll.RegSetValueExW kernel32.dll.RegQueryValueExW wmisvc.dll.IsImproperShutdownDetected wevtapi.dll.EvtRender wevtapi.dll.EvtNext wevtapi.dll.EvtClose wevtapi.dll.EvtQuery wevtapi.dll.EvtCreateRenderContext rpcrt4.dll.RpcBindingSetAuthInfoExW rpcrt4.dll.RpcBindingSetOption ole32.dll.CoCreateFreeThreadedMarshaler ole32.dll.CreateStreamOnHGlobal advapi32.dll.RegCreateKeyExW kernelbase.dll.InitializeAcl kernelbase.dll.AddAce sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.IsThreadAFiber kernel32.dll.OpenProcessToken kernelbase.dll.GetTokenInformation kernelbase.dll.DuplicateTokenEx kernelbase.dll.AdjustTokenPrivileges kernel32.dll.SetThreadToken kernelbase.dll.CheckTokenMembership kernelbase.dll.AllocateAndInitializeSid ole32.dll.CLSIDFromString oleaut32.dll.#285 oleaut32.dll.#12 oleaut32.dll.#286 oleaut32.dll.#17 oleaut32.dll.#20 oleaut32.dll.#19 oleaut32.dll.#25 ole32.dll.CoRevertToSelf advapi32.dll.LogonUserExExW sspicli.dll.LogonUserExExW authz.dll.AuthzInitializeContextFromSid ole32.dll.CoGetCallContext ole32.dll.CoImpersonateClient advapi32.dll.OpenThreadToken oleaut32.dll.#8 ole32.dll.CoSwitchCallContext oleaut32.dll.#287 oleaut32.dll.#288 oleaut32.dll.#289 ntmarta.dll.GetMartaExtensionInterface fastprox.dll.DllGetClassObject fastprox.dll.DllCanUnloadNow oleaut32.dll.#290 wmi.dll.WmiQueryAllDataW wmi.dll.WmiQuerySingleInstanceW wmi.dll.WmiSetSingleItemW wmi.dll.WmiSetSingleInstanceW wmi.dll.WmiExecuteMethodW wmi.dll.WmiNotificationRegistrationW wmi.dll.WmiMofEnumerateResourcesW wmi.dll.WmiFileHandleToInstanceNameW wmi.dll.WmiDevInstToInstanceNameW wmi.dll.WmiQueryGuidInformation wmi.dll.WmiOpenBlock wmi.dll.WmiCloseBlock wmi.dll.WmiFreeBuffer wmi.dll.WmiEnumerateGuids propsys.dll.PSCreateMemoryPropertyStore propsys.dll.PSPropertyBag_WriteDWORD ole32.dll.CoGetApartmentType ole32.dll.CoRegisterInitializeSpy comctl32.dll.#236 ole32.dll.CoGetMalloc propsys.dll.PSPropertyBag_ReadDWORD comctl32.dll.#320 comctl32.dll.#324 comctl32.dll.#323 comctl32.dll.#328 comctl32.dll.#334 advapi32.dll.InitializeSecurityDescriptor advapi32.dll.SetEntriesInAclW advapi32.dll.SetSecurityDescriptorDacl comctl32.dll.#332 comctl32.dll.#386 advapi32.dll.IsTextUnicode comctl32.dll.#338 comctl32.dll.#339 shell32.dll.#102 ole32.dll.OleUninitialize advapi32.dll.CheckTokenMembership mscoree.dll.DllGetClassObject mscoreei.dll.DllGetClassObject diasymreader.dll.DllGetClassObjectInternal wer.dll.WerReportCreate wer.dll.WerReportSetParameter wer.dll.WerReportAddFile wer.dll.WerReportSetUIOption wer.dll.WerReportSubmit wer.dll.WerReportAddDump wer.dll.WerReportCloseHandle user32.dll.LoadStringW advapi32.dll.RegGetValueW user32.dll.GetProcessWindowStation user32.dll.GetThreadDesktop user32.dll.GetUserObjectInformationW sensapi.dll.IsNetworkAlive rpcrt4.dll.NdrClientCall2 user32.dll.CharUpperW werui.dll.WerUICreate werui.dll.WerUIStart ole32.dll.CoInitialize dui70.dll.InitProcessPriv comctl32.dll.LoadIconWithScaleDown ntdll.dll.RtlRunEncodeUnicodeString ntdll.dll.RtlInitUnicodeString ntdll.dll.RtlRunDecodeUnicodeString dui70.dll.InitThread duser.dll.InitGadgets user32.dll.RegisterMessagePumpHook dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z duser.dll.CreateGadget duser.dll.SetGadgetMessageFilter duser.dll.SetGadgetStyle dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z duser.dll.InvalidateGadget dui70.dll.CreateDUIWrapper dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z shell32.dll.ExtractIconExW comctl32.dll.TaskDialogIndirect uxtheme.dll.IsThemeActive duser.dll.SetGadgetRootInfo uxtheme.dll.IsAppThemed uxtheme.dll.GetThemeAppProperties xmllite.dll.CreateXmlReader xmllite.dll.CreateXmlReaderInputWithEncodingName uxtheme.dll.OpenThemeData uxtheme.dll.GetThemeMargins uxtheme.dll.GetThemeFont uxtheme.dll.GetThemeColor uxtheme.dll.GetThemeMetric duser.dll.SetGadgetParent duser.dll.GetDUserModule duser.dll.FindStdColor duser.dll.AttachWndProcW kernel32.dll.InterlockedPopEntrySList kernel32.dll.InterlockedPushEntrySList kernel32.dll.InterlockedCompareExchange comctl32.dll.RegisterClassNameW duser.dll.GetGadgetRect duser.dll.GetGadgetRgn duser.dll.GetGadgetTicket gdi32.dll.GetLayout gdi32.dll.GdiRealizationInfo gdi32.dll.FontIsLinked gdi32.dll.GetTextFaceAliasW gdi32.dll.GetFontAssocStatus advapi32.dll.RegQueryValueExA gdi32.dll.GdiIsMetaPrintDC dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z uxtheme.dll.EnableThemeDialogTexture dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z comctl32.dll.HIMAGELIST_QueryInterface comctl32.dll.DrawShadowText comctl32.dll.DrawSizeBox comctl32.dll.DrawScrollBar comctl32.dll.SizeBoxHwnd comctl32.dll.ScrollBar_MouseMove comctl32.dll.ScrollBar_Menu comctl32.dll.HandleScrollCmd comctl32.dll.DetachScrollBars comctl32.dll.AttachScrollBars comctl32.dll.CCSetScrollInfo comctl32.dll.CCGetScrollInfo comctl32.dll.CCEnableScrollBar comctl32.dll.QuerySystemGestureStatus uxtheme.dll.#49 uxtheme.dll.CloseThemeData dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ uxtheme.dll.GetThemeBool duser.dll.GetGadgetFocus uxtheme.dll.GetThemeBackgroundContentRect uxtheme.dll.GetThemeTextMetrics uxtheme.dll.GetThemePartSize uxtheme.dll.GetThemeTextExtent uxtheme.dll.GetThemeBackgroundExtent duser.dll.SetGadgetFocus duser.dll.DUserSendEvent duser.dll.SetGadgetRect comctl32.dll.SetWindowSubclass comctl32.dll.DefSubclassProc dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ uxtheme.dll.#47 duser.dll.ForwardGadgetMessage oleaut32.dll.SysAllocString oleaut32.dll.SysFreeString uxtheme.dll.BufferedPaintInit uxtheme.dll.BeginBufferedPaint uxtheme.dll.BufferedPaintRenderAnimation uxtheme.dll.BeginBufferedAnimation uxtheme.dll.IsThemeBackgroundPartiallyTransparent uxtheme.dll.DrawThemeParentBackground uxtheme.dll.DrawThemeBackground uxtheme.dll.DrawThemeText uxtheme.dll.EndBufferedAnimation uxtheme.dll.GetThemeTransitionDuration uxtheme.dll.GetBufferedPaintDC uxtheme.dll.GetBufferedPaintTargetDC uxtheme.dll.EndBufferedPaint uxtheme.dll.GetThemeInt duser.dll.DUserPostEvent duser.dll.DisableContainerHwnd uxtheme.dll.BufferedPaintUnInit werui.dll.WerUIUpdateUIForState duser.dll.DeleteHandle duser.dll.DetachWndProc comctl32.dll.RemoveWindowSubclass dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ uxtheme.dll.BufferedPaintStopAllAnimations dui70.dll.??1CCBase@DirectUI@@UAE@XZ uxtheme.dll.DrawThemeParentBackgroundEx uxtheme.dll.GetThemeEnumValue user32.dll.MsgWaitForMultipleObjects winhttp.dll.WinHttpOpen winhttp.dll.WinHttpSetTimeouts winhttp.dll.WinHttpSetOption winhttp.dll.WinHttpConnect winhttp.dll.WinHttpOpenRequest winhttp.dll.WinHttpSetStatusCallback winhttp.dll.WinHttpGetDefaultProxyConfiguration winhttp.dll.WinHttpGetProxyForUrl winhttp.dll.WinHttpSendRequest ws2_32.dll.GetAddrInfoW ws2_32.dll.#2 ws2_32.dll.#21 ws2_32.dll.#9 ws2_32.dll.FreeAddrInfoW ws2_32.dll.#6 ws2_32.dll.#5 ws2_32.dll.WSARecv ws2_32.dll.WSASend winhttp.dll.WinHttpReceiveResponse winhttp.dll.WinHttpQueryHeaders winhttp.dll.WinHttpReadData ws2_32.dll.#22 winhttp.dll.WinHttpCloseHandle ws2_32.dll.#3 advapi32.dll.IsValidSid advapi32.dll.GetLengthSid advapi32.dll.CopySid advapi32.dll.RegisterEventSourceW advapi32.dll.ReportEventW advapi32.dll.DeregisterEventSource werui.dll.WerUITerminate duser.dll.FindGadgetFromPoint werui.dll.WerUIDelete duser.dll.DUserFlushMessages duser.dll.DUserFlushDeferredMessages dui70.dll.UnInitThread user32.dll.UnregisterMessagePumpHook dui70.dll.UnInitProcessPriv dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ advapi32.dll.DuplicateToken oleaut32.dll.#200
Execute Commands
"cmd" "C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe" reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "hvhyukghb" /d "cmd /c type "C:\Users\Seven01\AppData\Local\Temp\hvhyukghb.txt" | cmd" C:\Users\Seven01\AppData\Local\Temp\A5t.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ygyuig.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start dw20.exe -x -s 596 dw20.exe -x -s 588 dw20.exe -x -s 592 dw20.exe -x -s 600
Started Services
Nothing to display
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05b_64 | Seven05b_64 | VirtualBox | 2018-05-18 15:38:36 | 2018-05-18 15:41:32 | 176 |
1 HTTP Request(s) detected
http://checkip.dyndns.org/
- Hostname: checkip.dyndns.org
- IP Address: 131.186.113.136
- Port: 80
- Count: 1
GET / HTTP/1.1 Host: checkip.dyndns.org Connection: Keep-Alive