MalScore
100/100
MalFamily
Malicious

chidi.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 15/68 Related 2060
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 510.50 KB (522752 bytes)
Compile time: 2017-05-08 04:54:22
MD5: e1cbec9e98c2a7d81ba5b493f3a49a5d
SHA1: 32e57ea2d2e96460fa1b24102c02d3b5b55f3d1f
SHA256: 1e4c33de19175c6d8de56e70c101bd4636275e7608287bac15981ea074a5c046
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 #~H)k .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-02-15 11:48:04
Last submission: 2018-02-15 11:48:04
Filename detected: - chidi.exe (1)
URL file hosting
hXXp://prosciuttiamo.it/ice/chidi.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-02-15 05:41:08 [15/68] VirusTotal
PE Sections 4 suspicious
Name VAddress VSize Size MD5 SHA1
#~H)k 0x2000 0xd614 55296 1711dc7602589910c084a41c676b94d1 1f50db5dde1c9b1e74620e44a2a481ee7904507f
.text 0x10000 0x3dcc8 253440 7a5ca8c217062b700a4aacb81fc8bdd2 46d977f0df3b0596ac990fe7457e86de330d924e
.rsrc 0x4e000 0x33a38 211968 dad99728b9b0bcf3c7dcdca472b1c5ca adbc77a606db294fe83bfa9169616bdeef3e7e27
.reloc 0x82000 0xc 512 4e4a67c1ffad72c688ad19cfcdc4fd13 d14eeb3fb7574ba336983085b070684b350f4b1d
0x84000 0x10 512 da8c3884b98792b6bef8967fcff539d0 68e0303f596b209249acb6097527889af6738d8b
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x4e130 209740 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x8147c 20 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x81490 952 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x81848 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2017 Duke Energy Corp
Assembly Version: 0.0.0.0
InternalName: chidi.exe
FileVersion: 6.8.19.2
CompanyName: Duke Energy Corp
Comments: ibadaqayubowigar
ProductName: cobas TaqScreen West Nile Virus Test
ProductVersion: 6.8.19.2
FileDescription: cobas TaqScreen West Nile Virus Test
Translation: 0x0000 0x04b0
OriginalFilename: chidi.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
KERNEL32.dll
mscoree.dll
IP Found
6.8.19.2
URL(s)
No URL found
chidi.exe
Assembly Version
$#)(-,0/1/43536373
VarFileInfo
5cfddfdd-005c-7d
Comments
5c5503e3-1b66-5711
5c5503e3-1b66-5710
5c5503e3-1b66-5713
5c5503e3-1b66-5712
5c5503e3-1b66-5715
5c5503e3-1b66-5714
5c5503e3-1b66-5717
5c5503e3-1b66-5716
5c5503e3-1b66-5719
5c5503e3-1b66-5718
5c5503e3-1b66-5731
5c5503e3-1b66-5730
5c5503e3-1b66-5737
5c5503e3-1b66-5736
5c5503e3-1b66-5735
5c5503e3-1b66-5734
cobas TaqScreen West Nile Virus Test
InternalName
FileDescription
2017 Duke Energy Corp
5c5503e3-1b66-5742
FileVersion
5c5503e3-1b66-576
Copyright
5c5503e3-1b66-5743
VS_VERSION_INFO
Translation
OriginalFilename
StringFileInfo
000004b0
5c5503e3-1b66-5732
6.8.19.2
0.0.0.0
5c5503e3-1b66-571
5c5503e3-1b66-570
5c5503e3-1b66-573
5c5503e3-1b66-572
5c5503e3-1b66-575
5c5503e3-1b66-574
5c5503e3-1b66-577
%q^
5c5503e3-1b66-579
5c5503e3-1b66-578
5c5503e3-1b66-5724
5c5503e3-1b66-5725
5c5503e3-1b66-5726
5c5503e3-1b66-5727
5c5503e3-1b66-5720
5c5503e3-1b66-5721
5c5503e3-1b66-5722
5c5503e3-1b66-5723
5c5503e3-1b66-5744
5c5503e3-1b66-5745
5c5503e3-1b66-5728
5c5503e3-1b66-5729
5c5503e3-1b66-5740
5c5503e3-1b66-5741
LegalCopyright
CompanyName
5c5503e3-1b66-5739
ProductName
Duke Energy Corp
5c5503e3-1b66-5738
ibadaqayubowigar
5c5503e3-1b66-5733
ProductVersion
D0@N
oJP
la|4
Kk+.]
2L]1
?GW-
df\LQe
Ect#M
KA!U
8\R:
RiqU
]9>vba+XRX0wW`({[H-hb<:M*
43NU
|Y@DS}
AS>md)o'kCL([OVX0,rNEpX""
!}V@
PNG
*a"8*
?n|o
Yc"cuIv/
z%Sc
x ]:
ys
ObjectHandle
jQ <L
BsND
tS7<
c p1
Zw$]
HpKI
f]Ch8
8+7,%a,qGf!zHpeOJ{x3L7dT#
1Zeg3
NR+r^LO
W*YN
ResolveEventHandler
rz{u
x58l
get_Height
j|o~Y
sLIbQ
ivjzzzf
Kju+q;e
c<Kk
tQ#_G3
`z,?
S b
bS[DC
$/5~voD/O(mv8:corH\dI7qN"
L[o|TBas
X#fxG
b|5[9!eE
1 s Tk
*m5
NxeX]
?s`}G
+F4u
UH&=
n-O[
!++.
TB(F
cT]
B}G.Z
Hd#k
tNuk!
1Km7
c~fi
P5>iPy
:7sk
3l=*
&``
= < < < < < < < < < < < < < < <
R~XI
c"e6%"</*i<2wfQ$9mMY+coY:
Au?>
tY *
n3h:
Version
$a_:
zCb<
RiMm
{c@9
*5 5
!TAO
X (+
oWa4F
hS{@
4 2<8
n*rYe
set_EnabledCalc
;gI 4
{v93
YE:WZ
6Imh4
5fATM
Fgn49
u>~i
N'Mx
4^U
:g&4
kB^
'4' ga
O!PgAY
;;ZX
l5d: <
8/yS
y]0<
.: ^
//5WO
ControlStyles
a;wO
cf<m
Y HD
i E!
Marshal
7Dy<M
vC<Tm;
<d^Pj
Dp|>
4.N
~ v#;
C0cy
a?h?
?>t
^wp>
8#;)
\D'f
[bK_
_lN 0
|;lv
W2~'
}RaZ
_KtS
PDm`
|6e*
Ii|r8wW
p)r6<
I Il8
VqW?R#6-d$JX/Alq&>"u+8Kn'
(07v
*in:t
CWE]
}Q{8
op_Explicit
RuntimeFieldHandle
Q#5|;d7f#qo&l?";70^T>wjG"
d/tx
0)J)
NBF0
xl?fw
'^9H5
}IDAThC
lC2b
7%MoapX)Q<\u:h{?9+Pauw8V"
H6:C
mo?G
CznWDb{s|WO[cx\qL*!VcRPf
-v5>:
cq``
xx0
/Xl]
j TvdZK@Phcht<8CfC)UWGF1%
{'5 j
JC@C
[}*:0
)',eL^<
)-
[e+Tz
?E f;7
ZXJX*V
YI&
spy2
8B$|
ZXJX*J
=r<.
UiQn/b,k@08aNrM7C+s_8yTW
z=04~ b;%qLdm[JaGu=^-o}j$
EndInvoke
i!gH
q#sU
MT~H
|o}~
fTyE
2gi
pGSC
;k6)
Tx?i': '$)!j{jYl6-t =Rn4"
s5qZ[
%/ ,T
GuLN>*0AJe-I3rv!C9'JN1k"5
wq|I
55TR`%
;'Sf
pt^@
G0zX
9M1[
G]S\
7 dV
(neU
s4&=
-/R]0
-xb#
c`|j#"
Qi]^/
qlG"+;
%#} !
<]G
.D0|5
$g__{
.=#>
)7 D%
`!nq;+?sN 8h/2otBqI 9U,3/
9zlt
PO")
1I`f
u3#~(o*lt6d/MY80Td-(9Pa2#
t*{V}QZ'EvK~ewmhL#YmCL-X!
k0'/
=}L;=1
1 A`f
OZ2|
?J&s
set_Alignment
20Q^!
`M|0D
AssemblyCompanyAttribute
eF`P
O 0F
(NH
c I@T0
$8Im
E`>0
oe~F
;4,5
f!.S
8R).g
^<eg uv"
6^}jC
#s5@w|Rd,k"
IL8$
!`oz#,
"OF/
G 2uR
E9U?
}wG<&?0'dS;?;"3e>Oz\2Zhc"
~UD}
352
D#m/;ccM1?=)nRd,h/if:n;`
}l"2
Z6'Y
M>e)EFXu,m[[=oDg09<?5jBX!
L7xdC
Oe4t
zWgI7
ZuPQ
Th0?
Enumerable
g sb
;?g13k
BNza
|+}-
AppDomain
'</z
f %2
q g;
<#vN
HV
Ow\$
}|o9
#1aeG
|v@
a3{;
get_CurrentDomain
,MHm
i+?M
r*NO
TcXm
|%U^
]f_&j
j`?A
'gUp%
|i]6
?V_KS
f2so
hh<3
K=-W
kg U
_ww%
KF=}{t#vqP&5,v~d&(%P[7G{$
8)809
pAB^
FiZzY|
=$sq
eu%S
Kp{NJEI86K#,r[B[-l?{fbai"
)r^^
#\v&_C9zb}&u%^daOP7G)Yh"$
B<*X
L:-Rpo
U/~5O
=Y]7W
Jnwj
rSg|+%
*`,D:Hy
AssemblyTrademarkAttribute
XOTw
b!y<c{
Ae^G
?!{#r7IdIyd1|JX+Lg_7]qJx!
e/H2
{_@D
Gc*l
O>T a
eDp[.
LOic!"
^?Y9
=}%/'
f1{
]cFP$
Y-kr
ZB 7
q_<9
$xqC
$QJb9
]=\#
R( 4
<}
36
uAdX
",uY6/
get_TabPages
SVq+
aiV^J
#P&=
#Blob
Control
?9O#72F7hJv\n9czYfELho6B
2Edf2
GetFunctionPointerForDelegate
RnXS
]ysB
3&IQ@}1
I5J6
b?OkpDU
3zC "D
~xs 1
{dFDp
mRm
zn}CL
d6F\
t%7~5Qv`6o\7w|'Y,mk1Egc}'
$[P(8v;@ldPm]S(6I_aVtaNh!
75Vr
mJM=
6xC_
1e[%
Qa6S
_OEuQ
d|pFF
mpkC
ZiX
BindingFlags
6 >
Ng0X
Z{c3
_O#LG
Type
^k$r`-[
|9g S.9
B #D=
z;K{
w4s
?pooYHX$2P5*T(H;+XSM&-kF#
n2j-5
/8<($ZkBvcE5eLbL=GtyR^OP'
j%~%
WlNGU2v>;G(nYs>}C7@1<#(0
q;sU
3(!N6i
!Wvuj'
Re}=
, iH~
2"{ i5d9n~C*ulIDR^F_b"Wc&
7pO,
@C4
6xf|
LF {
,Q]mg
0kIv)
C['
H}%r
.q{#x
ycRm
=orh
p+($
U!QVA
*:'WhWFdonDmAgIr5:Lgw mW+
Cursor
N/AM
03<e*x)a
>hf2X
@,/Y
RN~VtC
jO6u
]fZ|
MhnUu
Jz?[
0:FK
?zmD
u p4
lp.QU_w
Char
7yyp
*'~]p
U=LH
}}Gy
/Zu#
ocUI
bLu\
tL37
bd?$Z7Y'`\eiFU3?1pxltfZ"!
DO#[Z2\'EJNtWIumjsdWG"t!!
<,H
R5AT
s/a!
4/g<
GetValue
'=qQ 2
rsEM
j0>)i
B}1[
/Ge
eD3D
v<kYMP3n$?#*-nb61/oI1PH?%
w.Es
s"0}a
G83-
+Z:VRc
j2Vs
k"k
et-_ ~
get_X
get_Y
0BI=37
] .M
#UU V
O$S
;Q^|0<K)/x&eaGfgj<?%L6R{(
A,[h
K $B
fZoq
s27W
XyWz
K}:=
L(Syd
n9jCEB:^hl(6(*34&+Db(hUj=
i' )
E{*]
VirtualProtectEx
c VH
8:W&
get_FullyQualifiedName
^D%<
QaU#]
n1Se
ILr)
rqoQL*H!sP5$6F,CJ^/n$@l%&
q1"DV
K^DvY`
[`JA
M)V&
^ %DWDT
J*,
ISynchronizeInvoke
*I"qg
f6NE2j
vnNp7V4AO="`Ee;t@ynOb+>g!
`<'nF
)&l$)c
t5EV
Q{=W
"]8x
E)E
z- i
Q@s6s
( #w\
: )RV
)$ u
poT"y
WYgzT
/LfR
o/e|!
d=gE
} X97FCfpb<Bgy)>#DA+/4eB,
$AFGc
IiF#)
$@~8ZI|qUO
?ZA^
HIB#5T7-Ls;L|8~\J=?{Jt* $
?5_P
9|;zI
Jj?#
myO
N7T]
Uc?T
g @
}*R53
l qS
/ {R
5X;h~
.text
ut93
hFOjz
_ yU2
6!(C
.'`.1
GetString
3s/7th
5[N~1
_ g+
CNWl
*"#N
C544
Ha3!M
wEnZ
rj| r3
>XhY
k"wZ}
x)z/ft*>3+K>put2PP*2GH11%
smg}>
aGWI
uT]M
W#yT%
?_?;
g#w7mo
cqa|
f c
c{ =
object
j]7R
BG)u
0mm[
e~2R
#g/0/
X]t:P"<-I;v;Py=#<{Ha$+:[%
5[WS*[
bvFv%
EaxQN
>m$8
nDDB:EBzt
D+n9DS
BH$$M
-6_Pz
,j/gL
q@5Zg 6Dq^*:m"%dycy3yw'Y'
YXAC
<}(,
=>E^m~S$g5~U7q!~L7q5qP'&#
Gt!1t)1xp
>%B!
[{zq
G ey7<Z
/VXD
8M62
RgP,><Ckc+*sbc'\,,nR:/Hy)
oCV .j
~ ~p
OxyU
n6m
0 VV
7`j,
s3MT
c{APM
v%<2
NQ<,
*]Do CbqbQ=sj2a[I6XkN=\,#
CI0):
jF]W
i|E#
:4Uw/
&]SZ
.l/
YW+L6
oE< '
}CL=56pY,Q(?ud2dx:kLPL_j#
Wv }j
!6p#|
'A)2H
. Y#H\%
(1i8}
wEl?zt
c9m'
;MJV4
=jdT-S
|+f 8
a 5+^qh:"!F`/XRGdD`f2e&H!
t>u|
6>D?
yG Uz
dO9zcM5y@oLc0\NK5MfyJG'j!
UJ`X
p8D|
Iq *
"L/{
v^Tz4U
*>Ln
"Z5\W
ADJ@B
W10{*
3oq3
3>w@
[698
a+ji\
9I@,
@ "4
Wklm
(& 2
?T[{
yRpvP
n >U
3M{r
U1tN?j
Mu;4;-`
yT>lC
`.rsrc
= .b
xphB-I
m\Mm
~s\f,
D8}V
(rHt
%w.S
b%=,
72p``d
-s=N
pSlS
0ToW
,O$8\
s"$;
Ct,
G!Y,/
get_Default
dS\asd#c~lp{X_Y0!Lt7/Qh0!
7i48
XPI<#
6aP^
kernel32.dll
ob_i
result
' Oq
Jrkd
~)q@
(dX:
+U\$UL3=DN@B)W6R!64K=Q__%
8 ~da
Q K:Z5m
-J*
Q3;P
:CUT
"l_["Xgl/ZFlS6IG|J+2![L}!
:E']b
$.\g
r3nh
aK}x
cVE#c9N
t3f[>
spad4
9%~.tx
m!jYJ
X[|g u
Z$|B
OH k
Uk5wO"
T'Cu
Ddm3
-21t
J0_}43Bo}nY=8O$a>$^lG{OG'
k#s\T
9|tE
M`xP
l~_#Zm
c*8>T
6e*.
HhW^
z@VM
TBS
yw:gb
ef%vbsE
Ck:2
d6P}s&sREW]]+^O_"v?n4s@U%
5=]Q
(ax2
4`_-
3(LYq/P3#41<7>+kZ(Q=s1N<)
HUK).
7XuP
"'#1SI
F=@?e
\N@=
\,yrp
7)+P
EK*uU?I,cveG&2kqu/&`,@[J)
~qz?
J]Rj
.H\/c"`
}2Zy
6IR>G'm}xp5"j97o;A%[d~Z@'
"O}P
_UE*
nR5z
s$DW
Hz@'m
-4l*W
f[-[z
>ub8
FH4Xdg
uc+f
KAu:
MouseEventArgs
T>dFxY
:~~6
S5+m
J&x/
e+Z('
[PaW
VHG%-
9Ei6
73J$7+
_Kiw
@}3ae
|N?^
%WW
05y:O
h<?r
n4uN
Y)Acv
O va0
Qb.
b998ce88-ca91-6d.Resources.resources
LB5XI{
vNf
-jE8
'XLz
}W]lZ:F~+0x\!(m<f~Nqh&7(#
<,*HE
0.z?
2-fA
axGB
_ u\d
q:_U
Cl"{]
Ug\6
59$<nUOM~\
(
(r1[^
b*HIl
jV9bp
q!\c
f8c<
a\#BP
HU=VepQPy8/!$<$+!eq%'hT*!
Lur=
jU9O
#[ZK
hwNeF
eA}q K
qGJSDcI
6 d+R
FB'hV:nrW2|xgo18!R[!:+61&
1JU"L0=d{J%;3[k#d94oVs4+,
0_do
]*nN^Ufn//3nTXZ~W>>5f(kz!
HP7s,
TGZ[?
9gLJ
(3gb19N5[f+?WU5Hae'DSw7v"
[k^-
PlhL
2P ?T
X >4
XJX*V
qID^
){=6sqa
UQwu
d:V?
/cDDk!O"9|/j61*08aUN)z\w#
!<M i7r~
m>4 NX$
o-eE
Write
DE|)
OnMouseMove
/AL$
atJ#)
9@FbIcNe
o-vMw
+<F6
^!mr
ET<'
}@d8!3uKD4h0,oMn<kSZou2T&
get_Assembly
3,Dr*?YgJNlCDYr74K>ke"HU0
SjG^2mOgH'/BOq(#$c\Hxc\k"
;4wF
}:[i#
KOZC0
bvf< T
,wj.
x|*X
K $^
#d..
-y,x
m[$T
e5e1W
Ay< 4-4g|2"Fo%9~p&oDD1T*
f^zy
g[T/
7 kb
^&^Ik
yEW4a
(^8
XJ[0
_t3t4e~
aJ:jk
paHB
k"
7lmz
-.nA`U
DI?
"mTeD
/~ZDA
NPI&|"92Bj6d>PR1>Dd461*^+
&/?[
nHJuN5^Q%WZDrG\6q}i-nnK3"
System.IO
&s"
WrapNonExceptionThrows
8%gv
+f4wcd-I
(rD6Y
pH.C
'w_J
)H0H
=]TMVr
*Dcna
"?+X
L Uq
; CAU
t]*`
Console
fB(;:
(d<1
2mU&
ajc<
Y |'h
i7WQN7vvo_kv%{Gk'Vpfh+Nw'
;-DT~
d[t\
4,D);;Wc?mkXk{/!)c\-i:|V"
bRQh
==z9$
#efes
-Zn
=lP$
SQi1
GpGZ
a&J:
#9&3
K`(;1t
bzF:R
J>lgx
$s"FC
-*+St%C}l2r!{b-X6$ZwT#{2"
xl,X
m+)i}b
YWECW
as%0I
Qqzx
GF{
7EXg
=^l3[
[ cK
@-Jl
6E@
IHDR
q&Dj!I
bRa$
1QI:
D `k
o</,
J1w/Y?b,0,u\M_X7R+pwS(Q{+
k'}"}!DO~j#C\94&$7>o]T/:'
hQUo
OBC,6" J-{k,uV9voP09*usY
Sak,a(
|Cl&MKXjv4P+0=NdLCJBdX,`"
2eO%)L
)hf1
v^pT7
xgz/i
hIh/1
bS G
)A/zEZdAAO:YHqQU_*Q@4d,?#
@+1v
'*)]
^1 @uq
[Zyi^
[ fa
5{wn
_|aC
uxTi]M
c$-0e<9(<Nu!uORLu\/9)FSu#
F&y.
[nO)2,
n}aew*
System
EventArgs
uD)|
5wQu{"%
` n.
<\>MO
se-W
E(Ii
&P2R
D3 U
[ Ap)\
\2,CO3"9i9[Q5db,?Nck<1TQ"
tU!+uI#mTw2\[*R&"z^a{2gb
Safi
:":~A
T|3w
_7Jt
v2\vN
S{Lq8
>pT/
]h57F#hvq6%k:Js?GC2(ew]6
YGx'
3Ld-
K!U+M
H\>.
Pi, P
j0m`
Hhrkj
jPW_
JgU;
CreateInstance
w9I
aFhA
=5GY?Rw)>J$1%cy41*W8'G'(,
vM2k
rLx
v;/|
'9,I
XMEe~<
Yh>X
C4I
d:}"
MethodBase
#Strings
~j(W;wb3ramO6xe?J<( 4_ne!
i)Y+
>(`
{E&L
[KiW
>${|?
System.Collections
$eUG
+}kiz^
ZXM(!
V #Z~
NK#j
:6aP
V<;Ct
Bu(e
Sdb(
9KM7
k}W[
rdLQr2+
ya<n
|9AM
-gXQ
/?C1o
ui{
.E2G
?ry<
Q?{_
TWY?
'9X{`
IETd
'SF
?S)P#
2Zne:
Environment
r [I
get_EnabledCalc
NnE
@Gg~(
VirtualProtect
j{$$$>
uxXzG
P_G
0 6r
|!/bl
_ Yw
GLsE
J7W^.
?GIW
f0aE=
oC~[Z
W!|s
`SgKKa
h48`
#,Sk
9swW
$20O
gt~&
get_EntryPoint
u.)sk72
:~mS
_U@x
r#Nu
annT
8!%8
la9Cl5p(R6:nU]UjB?$qUIl6
=3su
p !'hCe*
.279
>%4y#C>oAvRNf5eCYY2^x9gs"
~o (
J/C
u&[LI
]P>RC1
:0 (
>uk
dG~J97
.JHr\
u0Nk
GetType
u5a)FX
m-N)
2]`LX
{^k
\MBtD/
tV|]
ZnK;C
add_AssemblyResolve
QnA<
IDAThC
1+]Z
p4yI$-$3;Y hvA]m#-V!dCK2(
s 9O
# 0y
T4Sm[%
[#x D
MQ\CJm
| .{
:Np~
4E,fw
swE|z
i$$GL
'mpc
set_OverIndex
KchC*F
u'%w
aA|$
0*6Z
l?Fc%J
SIeG
z?u P
5*.]&=
q[+=
%ym&LeEEC"p#&_T03sXG&'r>+
d ?vaScj
9IAZ:E
"J^-
aDYi
A}]v
6E(
jb^t
3^+N
?1cc
QXTw^FzxZ npe](W3Um,G@k9!
-7iW
TabControl
xXv(w
"i{x
* r
l)/9
f"> b`
*d Y
'{}K
_yRs
m]KZ
$|gMeN9zo4n]_c!OqyadWBu0"
OX?1
v*_8vL
rGj@
2R9z_J
?^`B
kBf%v8RT $[dEx#09@KS0="W%
R)'0@
#-J}D=
R Y"
8\ G
=L
7K `
{` >
Color
Kn6|
4< +
:|5#of>T`H:%oq^bayS\;MWS
!dde+$R}COLr_Y*5$b*!27P6&
iUL'
Intern
c">m
]4'%^
[o8u
?k [
*m9?
)+boD=R8S]lV^=f5DD<ju'G~+
#_!s
*$U*
\W92[q
U 'm
set_BackColor
Ki f?
!iig
|efp
=Gv?
TcB4)
-W[G[
4vZ*
S|=&
M+ 8
get_UTF8
1ts;m
C }#^A)FodD*[X/Q(@POOlr["
_&]V
get_Width
+#^c!_
Xny>
,&r$
(#CWt)q)*(%iwz~$8Dp|FXWY)
Je aZ/y
NEw
[uti
@:8xB
d'{`
ZX {`
t ~i+ >
Bz`
Za]F{f<qS,y}82y2%6WGMfQ
OK K
rC}6
.x1x
get_Revision
8M7xUh"
[GW8+
;FnG5/
U@6'
i7sB
l4VGn`z
ts8g
6~.m
X%R>)aP
d%Q-
x<-A
&4o=
29V6J6
System.Runtime.InteropServices
3V5Z
d l
Q'N
PD}h
X*%Q
!5kb
U>n |
L~"%
c-K.
1[ERZ
=[
3%j:
A}]qmzD9=Uvd8A/_Qb=LcUml
SE>2
F@m<
Rwc'
QmrP
>_Tg
wb"}#
D@NN
@%:<5
s;RC%
.Ss-
3n%/
rH@Ow#-;&Acdn-|4vaU6[QJK#
ywKS
k*YG
{""A
Kr Fz .
3~F
zO1pV'Z7:TMnH-b>O@Vl7I)T"
v[*]jOW_<>d&//+xfV#VRShU"
u];-
= "b
6Rg8$C)9Z,QHANBi'dsz@4&"&
&YS(7:3M$H#?0@j0`<bob"o:*
A%U*
V pc
9$ C
Y_V'
D/T=p<
y}ui
,oAZ
System.Core
a)~_
tVEq*8 +ezmq7mA{v:gvS|~?
PHf=~
-PKN
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
[OJm=
Qk PW
_~@^
>D%
NLdJ
w[[v
Delegate
X]> #
P,O`
<p't{
9H\KVvh;
7zW>
oIKA\
IXxAQ9w1J=:8^3-C8?h*bn@0#
?o=0W(a
Hh`F6
#"P%
$U.x
"8|qd}
74$w
)YPpK
??-Q
Q;A%zl
2N>Y
INg rV
X +4(+
.mL0+
$4a2d78df-2af0-42c0-a6ab-a776438b6f2e
H>>!
L2 \
ED}]cj
p,V6$r(
EwkE(
&a/Q
qo lZ
rPsncn
WuSK
ModuleHandle
F T0
CI6|
v> F{
R$f+
J0m]C@7
]F,lP
F><]
Yw+a
2:&1@+`)'|<rc?!exn7-53Ct!
-*34
<T]9p&
ng],
0!t|.
;k$2
@0Re
fbzNM
xEG1o
{m79 L\4W
3OXRV;
v8+Y[
P uu
I6& =_
Ky4.
( e
#]:~
XnD,
2h(5G
&;Jxj
fwgB;
&#BE
mTm{D9\xVK?ipwfwr=sm|jy]!
W? z>
Zaw0
set_DoubleBuffered
Q=%Lz
sot#
2915 SWs5
get_Length
6{mkl
paMe
mk@s\
ltT.
f3n)
A7$ K
J*'8
7tz
oT<[B
x: 0
\MA>
pr[M
t\nad,9
!`LlS
-V;]AQ
|Lks
w#N%C
|^s&N!
?Tgu&
Bi/
Lwx={
'hgS
F<2@PRH(8#@WyWv:UP&v%D*{$
3'7i^Nx
\Gkx
9sZ{?)o
7R|G
<C+<I
-X#Y|
*(#6
)pQ:
#_&^
Va@T
eiZD
qW6.
U>q
[i=f
L@6O
5geuR
liFT$
7' Kd
w#=s
tH DR:
QV)s
ValueType
bAZ<:
pQ@c
G,E!
GuidAttribute
aecz-?S`gXg1*-Ozv9<pT[u5!
uyPv8
zE6*
Yb](
=G0R
r^hl
c5.!T
? 6t"
f0"#w,!
_oDAED`JhbTN7-[F}(<qS"Vt#
j{j!,
&F^h^R{
J&Ncg|
{.n<
6U#\
x WT
.)jO
[hln9
IM%)WG_;v@j+Cn")[ld|yZ`(!
K'-+
Q6j)D
:5g2
v+)D
0\N-
R}x?A
get_Count
SR|h
nAH`
M KI
U/X]
dD6on
D&LxMB
58rw
System.Runtime.Remoting
8p|7
zjgu
?R6G
oUX'
;U{y
7zaC2yBN(^Oi%s `,M!0906 $
D:*'
eFgda)
*f:?$3K
%agb
GetField
BUP5
/oj,
e./d+
jVb=S
b{
F9nIlaaXc3H=7bHs=!Goxt2;%
EmO&
_ qu=)
qN+j
9x I
[V+b
"u+m
i,@j
m4$T_vUj(iK4@>H}T@+=!gjT#
sl~D
Z>yy
|^\&Uwz
si2
@s
I<R]
q/&lk
lYX7Xj
3F}/TJeu
~1gf
mGG`
Y]hI!}
UInt32
]UU4W
r?3
A_nU5
>:#o
btyb
Wsl*
Ll66t
yY6l&
f349'h
get_Version
c<vS
n~Z!R
ICustomAttributeProvider
"&)8vEm{WD1Wcff&|TKZHw@h#
:FkG-
ToString
]W(v!
9Zu
SO/>j
zTzY W4
KC|K
%c ~Q>
zNT{
aMlR
AV4C
p!"1
neM
b?c)x[
Hj?U
7Rf&
v. qr
fxk6
2*dH)
5NP>
0%SU
X
3rR
we#
a]U!ir
.& h
DyU^
cFq4
A DK
8+#{
!,R0)
|KkS
ServiceBase
b%"5
J/8<?5
'\@",0<OK5Z?Y?3Fh/gz)D]\
N_/O
s_=(
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
S?k=a
K",D
8o7}OxYdq[]?~5HTAIq<z\P(#
V\ct
DF>(D6 ?Ii!DO{NB2`(!}I[E+
IBSv
k"g7k!
Lmpx
%,TLk
03>K
gTkqz
nH)R9
zomG
Q4?_
AssemblyTitleAttribute
fj/~
'[(s
Hr L
[gaa
^cKdv*A^<shsxc-8wM(Zw%Tf#
AFNb=
=pMz
{+@p
0hA 6
eh7@
jwV z
P S7;
abu])k
#& C
vW"Y
C8V\#c
Z;.z
\(,#
v/6FE4A
UDz
}xGE
Q>I)Q
dU|`U
!3yMQ>
1&:,|w{
-@cPV
ZwvU
#{qV
ZXo+
H:HX8
|v:<
kxOZe
$AWE
YtuD
}IL{
0~@$(
PG:L
eC`>
w xg
w&1v
FbGc
6jU
eJD#
G\%5
Rn]R
}<=K
uc2/
Wd@_
BdQS5<a#p(alUlfWj8ghH9n}!
Jle)
kX &
TX-^E(
m"E6&
Data
^6iun
j c!
-6m:
L!D`
#nub
zo_1
|I ^XT
Enabled
.Jrp
^ nO
T",w
C#u*
Lu)\
M:pj8~
m}Ri
|-}|
d/Qe:U}
Y*?YF;7?yi_fx5YzCAR[pi[x$
x@x'P
4{m-
cuoN
[>>`6,W^
GI{l
LrFa
KjrS
*N]L
pHYs
.ctor
3{bz
#P_+
`S&/
,Z!9
7.!J#
L&UB
A<&)
get_SelectedIndex
=2\=
'ay
QYjz
get_Message
Container
$p&
[S28P
BY<p
eET~l=5Vi+!J*-CFZ-#=^4~V"
5b%a
WgNh
Xb'-b
H$-Y
~1/7
*|kUi
Main
yt%}8)Al,fB&(TcBu!~G!3oY"
Wu&;
#]:r[
39Et
*XW
g>]MZ4Dd:N^2wVvr~(rhU*5*"
H0d5
Invoke
Mw2f
eQ>%
.A!*
ZXJX*
q@"%
_EEZ2v ^y\3CrK>a07/eA~Am$
S; Lz~__Q
p "`6)
Y*
f}'!
lH(m
#a"U
e78 PW9u|b96hz<AYyZJ_,(("
t\XG
L/<W
X->2
V5t1
| gR
!dTO
Efd2F21vkS%$@-w:mnW3Rs14$
L ,e
[.Wv
{?<
88Jd
>3w3/
>^Z5
f7&+
+#nXMv
\gTv@ ]T
Ri~1
pKe]U>
U:3.
%C N
aH-TU
tak2
BP^+
M;n
!]f6
9?$1<vAM!
CMDu
gSA6
|Q*/I
Module
<y'w
;jzq
KBA
.EV 4~
Array
|m`z
emA;
h!{7{/
]8E^
[Z
"2f%3;:6*[J%+M3-x<NCzAAg"
#-5j
}8"/
j!:
Y+X;^g<
@.reloc
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
f/}wfi
-^$rJ 1y<
W\SF9)
&rV_
1A\!
]'.c
8%dm
E!Qt
4ZX?
#R%gr
eU?(
u2w;
;p &{
.@SyQU
TabSizeMode
d}';`o
Byte
get_Chars
u'Zn
~aYmo("EM%,a]zh:$TCt?^,k!
#AW<
z}%P
\)eh"N
@d#PE/[I8*x'<V<}H%`vqQAG!
e{?
0F5$
y]q:
~yY
2U $#md7
Mw+R%7P(<;eE0);Br0j@}[S\#
<.!Z
oTc}E
!g}(l
1`6m
c|i_H
;,^e
5{rF
/J9$
a%Q&
y\(67
!T Zn
N^(($
u9:
^s '
uJ$a
xT{\
K2 s
m1p~pXP
J#%J
jH'r
!':]
2i).2
Wyc*
')KOw
heY+
TR!C
?45
P ?lP
M_cr
-zu?6_
A 0E
A@Dwe
2Fd)
YrFW
D{A}
PC/[x
x"&o
- O1
uuFq
"vHL
8 uK7
PRl\
b^*d
KOkV
get_Location
M#0SC $7
z543 i
vwgc
o1NY
z_Q7
6iN?
jg,I4
S^zI<`yrt4=!8jx}4>E?'F'V!
{*HcA
xA2b
\-|='U
"j0)
E%m4
}QW!
)8?
m6ta
FreeHGlobal
bK?y
IKV
ndDjX@s2gG"$G_P a4vFOV|_4
M $ b.
8uyT
\ {|q
g+Kk
it;8t
-kL-jPT-%/E`T"^/;se`RH]\"
|G;E
jVkMM
,K\}
3mTZ
V|W3
'4>3VS+
B\o}l
Zk*}
'd#C
IList
"p:nm
+ IWl
e44
Xli
"KM!x
li4`*
, J!
{7-*9
`X}w
a{F>
RuntimeCompatibilityAttribute
'KsM
] }i
f0/;
+R(+
U/LT6
x8@
LbafI{
\'An
S&!Zv6aj/-q)6:3Ox<aD<$Lg#
Assembly
S3b+Yz[N
fBI
yR`5
]*V[%
!d<
&i CP
( G/
(nj#
a:Hq
^ 3
IDisposable
i3k]K
5DF\M
a,<{Y
UGT)n
kRd?
r1nR
2Iay
,#z (
:Ey'
5MI ^
[}(M
q9JV
%mVa
AqrdJ
vW/
]yt#
30"*
2 n'p
Invalidate
y( i
>7R#
?n*jZ
uzg{
M$]P
`C H
;K-p
mW1Dg
>i7V
-Vv2
\/$A
\_nU
X.N'1
Size
r?_mF
%2s}
@ O
5Eit<
'IwrC
nd)gOh
NewGuid
iSGr
]K_
U9 cre
{?P{
set_AutoScaleMode
V*Gl
fZ-l
u&f{
I8sN
@K
:;}z!%
<iOQ
$* PP,
5a<\>@[X"\vVi?mlO[N3Jf{e#
7},9
_`3jU
it(M
u5#"
C2.b|[f
c?)u
a $}
:X}-
O)aMn
6]Kll +
aP1z
*BE.
j9!g\w3k
_k@q
W<i)l%
$ '9
K];l
qzh:
IContainer
> |/i]{WG
~ H,
?b%{f
'A{j
R:VN
v<O:
TEU&
m1O\
Y>g4[i:0Dx,i-SVLj/-a]!XM
;$vr<1MrEc &H'#^(c!u`%u}$
jufu
.q_n
r7|q
]ah1
$\&U 2
STm
-K.I
R p!
yDpK
dqrR
c"Nv
AE4gh]T*iV#'U%m'5z4X16`L(
ISerializable
:l I
X&r2!Bj
huN~7l
(f"G
8?'
W/ Zd
_ tcL
9i3W
l1l$ DU)&|NeQD?, hh\$7[P
qv~y
|fgXo22lCXp07,[pR@x)KxKi&
)K?&V
ok2
mf+6[
Opmo
$JxC
Z(1
V1'y73&:
0$H .g
v4.7
r-mnn
{_u?`
> hX
%7&sD
R$r$
tP X&
pP$G
- <m8
F@_L
DL!_E
rH3J
e w=
e=8JZ:1ysS%8qg+L:5cH{I,/'
?Q`w
#Lyy
}c"~
iG}9"
l-`Q
vK3wM
get_OverIndex
r\ Kl,B
:vI<
A+D!
*}_I+
RNZ_ppD(&
"~q13
lfRcn
&48m
Sf.)L
g""*
q ~G
-'aX
|Y{P
LY4w
7B#dR
Z7t2,
VS ^-
KVjX}
n@T2
nyO/
w~J~
TF8*
` A;W
bXE
[M "
xrjr*
/f3*
.u`
fVwf
1'}$.
v 3G
,&#
0.vG~h+
b\3G8^kRp% 5/FL7GT%},,$5%
ContainerControl
iQ$s+,8spL%)v7[Dd@B+NMsT)
[2 \W
5=s+
^eI@@
V.f
}Ud1
W73SWw
_i+x
PM@!d*6 Ue>7@F)OCgV_^oQ9$
iQqv
f] &
mE~f
C&S{
o@PCOQFhk);%hH<3MMn@:mH*%
}\-'
`m-
vZ5\9
O#}j
ReadByte
W5L#
M_I}
4RR^
VCgux
NnX5Wf<-D"A<DSSX|vzGSe~$"
*V!u
+ BM
`54o
joa4
fAvj
3F1764884A245F1B3FA91DEC2E25339F23787561
IE[C
} Q2
m~0(A4
QAu+X>
B=+1]T&>7
H.<N
TWf`
VP~N
6B&$h
a?US
Roci
IComparable
W[{48&
7gYyRd
_|S
?fWr*
Z;fs
k!*;
v'p'p'p'p'p'p'p'p'p'p'p'p'p'p'p'
%z=a
9KY`B
r+EqV
AllocHGlobal
n(iG
1na5l
I#l9
A3$j
AssemblyCopyrightAttribute
)L6
y^^@orJ!?;,)my?^0-^m>~8_"
+ rD
0x/VMj|y<!-O>hRm~Md,Al~O"
)UGwN
@/T3
6QQHJ
)}dE^7yNn'| Ie,9LBq:DZuP
kJoS
w_P8
mg,'
Y7{a
~V-^61v4o>"qOocdNqutY %B$
`{w}
-n6a
\|k|E@3=9kf}/aFz7, #:3:-0
lEOi3
NQ`91"vk
g2vy&
+J=b"O
*m"B
Xh@?
0Td`
-> :
(o.s
#l,.=
dbMU
[JY_
; e.TitK
(x2;
0YX'
C6.:
>#gmKx
`$7\z vqpO
]LrX
) #!Km4
)Zilj
'=>L
|Nr+
acy/4?8bN'a+c:k>&Dr269&Q"
Te`;
|+i'
{V]<
D\c|
$m F1?
MM)E
bY~fG$ EjF@F|D$=Xk%PPDP5'
CGbZ
t} o
!^@:i
: Jh
qq[a
*:oC7!Av
us7J
z'N$'Hi8U1^UipDY:-Dd*A#"&
8!od4
yEfZ
g9:B
zmeV
rz y
q ~
i4Y;
_e'
)tHB%
oV"u
%ZEc
fh|
m2(n;
3qd}+G
{>?~`M
YCVcu`
#q=e
O3+VgE
4*s5j
ControlEventArgs
px/@
RX^z
mFH1Mi/?'+D# 04 f9rw=dW#
gr I
}<I]?8F>N~?JXIQO`HMO~S5',
1<f c
s4q-
iAlS
Tb#=
5*>nfKv(lr[
d>G}Z
hJzAHg=+v7-)n(!Yq&#@\ hy!
set_Enabled
|wXl
N,U
} QK
7ek;[
zYG08
Read
x6vI
&!2O
M{-(
}gk8
wbsi
6%H.A
SGQu
+LM$:
!VBhFma
;%"-
\ +P
[+ ">
4r<Q
XLk
:UYiQ]2sUl `=X:WY{5_n6$r
[ 9H
@#4g +
k8zRg
_l8A
ko>*1s$X-)S19s]jf"+YAHM;!
sQnuw($AM<O$'V92B~kJh^NG#
9&I^q
get_Value
jRz+:
>jX^
H o^
?,F3
}:z1
g]E!
e %560
\Du7W
j5lon<
BewB
JeS<
6W&A
7oo1
Fv
~ YLd
kU@X
SxaH
rtsp
(CPZ
mEd$
v-IJD
gAMA
\`RY
{7rYPN
S@*:
yxVw
hq4I
4F=S
jMJf u
<eZ]q
-O7N
+=bN
IEnumerable
*'S9U'M~?-jr7>VWZ"]j)a6D$
AutoScaleMode
N9fV
.;uf
*MW<
*BPcX
r@q\
PA +C
X>s!
MarshalByRefObject
taiE
J~p(
gY'f <
DT.(
\fP7
.cctor
AsyncCallback
gtOc7Z8a;M|(%mCvYs@=gc]^"
2wnL
mscorlib
QqPt
ha\%>/
<0W<="
rGvN
&t(.?
Qq2J
V u
EmL<B
6QPIc:
oaB7
YhcNf
.]$`-
i]Ub;,DB ~RU,LY-2!t~<LY}$
r<Aw
DYpR7
NLws
zL+v
4 $LE
d8_X'
OqeH^5?K8 zl4ON &++'@:~+*
vivd?
={(q5
),Tj
]=:V
Jkky
$*W(
var^,
Hg'l
6z|?
zS3
TA)j)0y
9eH
7s|J
>:B7
BFt@
w('=
Guid
{k>`J4
yy:ru
]Y#n9K
QpZW
ju?]
-@[5=p
ucRwM
&9K1
&gc\
sAK7G>
I3g/#Tm\e3BO(T2Mjd$<QKiy#
SUwE
~%6sA
[|UC
RO WAl'R+!S"LHvJm|nyy"Z"
Qa-C&
MrZ}
=oj:)h
_KmQ
"0.e}
qI)%6
=`kS
% I
I HT
j&,}
System.Reflection
gd6p
$|te
GrlAC"N XbZUap<QEa:xg)Yd%
xUH]V
RuntimeTypeHandle
mPmD
2H((
l+:'y,9VvMiM`ynd};322QKv!
Db8/
sc).
F$>P
BvMWA
(;7{
IdGB
[o<Q
68 !J
BW"
6CBh
E~_0
DdM#
bF4m\cb7kUwr26;PqC)a^dB<"
|}*$3
BI8u
?X\I,
QdiZ
GR+
G2@D
NWb+
`Bl9
sender
R6{+E ONIyv`sDj\$b@&)"BE
sk6C1f
m .s
\1CQ>h
#q`R
?Z_
U:Z(
j [b R"
}y^X$+\c}[&NT44c\wU^n`yK"
v8 u
pM4U
yt`3
l*z6f%^Ps8y_85N0Q;Ov>,0 ,
Append
!%+2m
2Jk<
'|D{|*
smFKA
System.ServiceProcess
op_Equality
\IDAThC
Ex;L
N5;%
H?GhGXNnm49He=kQAP<`s[D"%
7 a]
k>r8#
8h_"
V7_,
-^>E
Uo0#
g )!
mG-&
}D'Ds}S
FbfA
{ uOe
I8lW
v0-T`
2 n
"{YQB]'
j-YV
yA;/@ W
T|b
V,V0,M>]Fud_XWXe>iBuG,v*$
7c@A
$?DMDN
n2|1
l1 M.
?DdL|JkRV)}v<-uyf^aB%t$v
F:@V
~WcU
^Zn1
'[/*
AssemblyDescriptionAttribute
]j&'|
.g?j
6c9m
V2&j
c>IWQ6<m0:6qEqv$RB?'=M+\)
;+0n
,<(U
8W+j(
F\Sx
XuZ[
v};/
n9k
rm>)V
;'H:
22+U'
RvQT
j^7g59)MH,&h90\FP[Bfj0u,)
P.)4
8emar(b
bg54
+Nu\
61qzL
v ZRmS
T 6C
]L e
+Ok!\@xSajz+<J[Vl6yOc^k]!
7A#1;P(
iJZ#
mYqq
N`C$r:_+&NK]SZ^Y;i?m^uV<
} <j
a c9
rJVC
fC|x
+\tT
G=Nd
TGM1mXJFY=:AQ1F2Z`H"'/;'!
i]:&^
rk +
kzmc5
>i)"
h`zBk3=S8CT$y(xp+;$&+yhE
K,-q
_"U]6*^d
HHtZZ
AZq5
SW|g*
b4Z^;
rR=*
I|Rua
30D_
-+X[
U4U1
5LNK
Ms^L
>aA_;
86C:
:Psi
QpAg^
BtV|
Kfen
`tqQ8
R?
BH55=
YJQ9/`
=_Du
,
10tqjEHXmO8S4!#46ne)soM$
OUB0
<| Y
;B"z
WxI qL@~2
^kmx%
0`XK
Ua'L-
-[n3N
"0 8
pKs|
%ro0/
@E h
'Z3m
4PAA
mscoree.dll
!This program cannot be run in DOS mode. $
g~]7?1>_z
9H@ !z
callback
Fjcjz(^
V:4
^uV;N
f5X~'wmJ<
g^[ ,N
tsA.g
=<s
qTy?
R+3(
Su'q;
Mw"5U/]JIk:1xn>(]!Iua3uN#
NOoO
Dispose
<AN:
3=GUWH
1dS"=Y
0B7.W
q]miAw
)/X?f
+=Q<
79,KM&_1$pdxv;M!XvOX5Y^;"
#$F>
7}qs
"^j"
k7#'U(
=1eA
R*^z}V
l()y[
%VTyn
4E2BE99140D24066CADC84F74FA899FEE5976B68
7D7"*}Fa
2M 3
-4b[#?
ICloneable
Q6[
h<U`p
xGi_
3{pC
g&@*
z%k?
HESFu:
#<!
e h4
=Xjq
y@)>
:'TpV
,[=b
w!ueR^bi:4dJp'X"]CmO!z,k$
VB8%
9M`x
n U
n?Bz
$a;^
W Jg
{C^N
}F+y
.W )5 L~t
~oT|
$|<}
3WrW#"
2/# e
W>ZRHu
U\hW
KeYr /
sW]9
M\J3f
rIDAThC
\'(E'3Gh2!2A@M\;d{$^bS5M)
_`v|
JjA%x4[0U?$&P*8I=A-?Ll"J!
|V95
zIDAThC
V' tg
Ye_{8
[-q9
%EI
:5Ps
fzLM
$opbrVrEz]p=_x-1!_$W9Kvc!
3'S]O
(!',D
4?b^
<,y*
t '?
U 1{C
O\j
VEAK
9eqt,
:1sI
\=#3=
>d DY
)fY
TcRD
H3'i
=N}vI
!a8j
BSJB
JwbU
."m
{H`
l2;R
8j^rn
#Qc2@#jML{VW?}>+-?I<F\JZ"
z5 w
@87c
:^(G %
\\+LOp
{PyX,,q[23]A9[ZfWVgOex&s"
A;6t
C hN
2 /
kG!U
/G 0
.P%p
Zr}^&K
V8
IV2F
`6R)q(
%{2*
get_ModuleHandle
U:],
I7U.Z
xD"9j
MhuK#K:7
Ej/U8c5(>pD01SD>~}1j@<F@
~zdYl
]KY0
r1=
kv3zTt_
|5od
:y^N
VKpX
xf%L
1[\(
IntPtr
qf:@
tYRp
s|]v
kGVm
c!G~
P$- #
dm7h
MIR
KJJW
D,rzr
5 Lc
Uf&aA
#>|2y
hr]5
2vj*ll
o? B!RI1(/
)@]B
/YTPwZ
I2x;
T#q
|hT
#;~ U
_AppDomain
$!f/~@/R8m //&,#,eE9-HFI6
QJr|l
a "K
"}gi
MIGs
3MV+
9JUt
c ;
'SoCu,w
`a(I
Mh8c
m.kn
X_VR
`IDAThC
=)^x
3&[S
{ rz
$|Ioa
v+|f
System.Linq
3}rr
*k ( +
Z-&Y
1v|A
i>[K
Ars}f
UN]6$
E?H;
C708234F139063BBE3CBE2208BB6ACFACBC50333
InvalidOperationException
<w p
mja
hH=*|
$~K*T:
y5/CcW=2Z'WMu/Kd65In@REW$
6H04Gxkfw,+T[$v@-3&V_>6I#
LWh[
h!Do
mU ~
SKbQ
v%p%p%p%p%p%p%p%p%p%p%p%p%p%p%p%
JAjr
Xc{H#
_\Ow
/zC.
js7F
",nO
PeIJNaE^%pF91l8E14a}N\qM#
*R 7
WRQbs-
kaN*
RMN6
Zn9do
+6C
w63p
5f8S
moF9l5I/W
y&QR
-&>&
syo_
zWw>
z)[5K=
M)=3rJ((r(/Oj7AhW$qiA66u0
"nDt
'I2?|
)=I*
y%w``
BlockCopy
}W1 W
~6Q4
/Ri-f$a\}PK4`0o-x=%@v#Y:$
ZDnbU
\-_-@>
\]!E
2c1R
M!*"
4.-d
g^Jw
xu)-
K-4t$
OpbN
}U&[G]
}GU[>2KV
Mw;9
/C)}]r|G0Tu9ck}u;q(t9rT^!
>+>fy>-q\[#)*,c+vcC`-~a3!
V+4r
h u%
'56W
Pos ,
=gV&%
~.NQ
!6g
*&P
dI4'
k$C5
hmAN
?_mT
r XAx
zCvCff
;/F~|z
17?F
EAKcy
'lG-s
1L7E
3 H
qP2|
(a)%H
;?o=
N!j=J*?mo
aC"c
E6p>*9
h)b7i++^L["N;znE>1/<i*^3"
1Yp'L
yd Cc
0riz
C yny
B"}_s!=L
*IKU
kp,sq
RF so
}v>((8
OgGl
-A Q<Y
fk0&.\6@
Qd#Y
b+ u
RS
K(c#nQ%wWr*H8,>p-;B\ 5~=$
Cy:O
1j4XlH/eV*OuZ/h_to:$p'Pd!
1p7'
I3`3
K|cP
d$2
(E
yKj]
-Rgd
08,r
w&`ps
_43Wd
60Uo
SrotO
<J E
18={:
QT7A
|HD
$(2f
:CsR6
D?^
#TNS
U*du
pgeN4
n<P5
LLsM
Y{K
Y/*Kb
CompilationRelaxationsAttribute
`1A[?a
X=/3(6*#/1+S\ji~:zREFn7["
AKaE\o;r{u 3
GD|+
TabPageCollection
Zs7?
T`x<
9YKY
Y#>(
3#:`]eOz<J0//Ekn=,&PRo\(
@9C|
FO$
BIL8V
MemoryStream
H XR
}G~I
4 }5<
^8WrTo
;>~I
1R+r
Nc .N
ResolveEventArgs
tw*HK
0 G;
R1 W
M5{z
0ZTD
stCK
:\B=6:
r}5
8wot
Bs.q
TA$@F
ysb+]
&W3 )
OnControlAdded
vzT7
Oz]Wxy7
Mq45
U]"|
U"{c
/n e
$`u'
Mv +
i)3J
koqR
5Vlv
C t*U
A82 B
+u~3
IB<p
S`7X"2S
^R+s
zr5q
FUnm
7M)-
8?*U
XO.V
P*e'h
#='4
dMm
n?-
EeO2
L'N7
#@si,OX%B`U;5*ulvNudeh{n
d(0Z
'`EkVJ
?sI_
7!s"u
,uT?
9dCfn
$#p`
]}GZ
&'c&
06>W
`c~$OCtsr9L,2%9?&o(zfTJ2!
IEND
vT9(
(/C0YE
~~bN&8
V[&)9p0Gvm>Skr3|?6U>2&l"
dRx0Jy!
k r.B
Ls:T
L"Fu
P(+V(7
,+p#6
si'
=ML!!
KiV
%HQ0
E&_
ZD1S
.ake
c gg
=>~%0)
gHl#
F\J%
QnK;
5y4;
'O16
oa?F
iR?$rl
.*;#
829CnF!3!)Q'?~'i*O8rF'R:$
ruI;)sNn
\GJ`
7fjK#
lF3
eGj1
3]n$
)+M${
|\JW|3
' DC
8f5U
a,p^

=e;3k
,wc~
Mutation
3vW\
s1}D}@n?jFr2|]uE\7Y81n3i$
X4i*+
]6_8O6ZQ*a%vohPRS8w/*1bu$
Rectangle
Y`q
kL;9
f/?S`
~, d
get_White
mJ^G{g@;)8vJi+dmLav6 B-1!
^6}(
kwwI
\O`y
%xwO
_ Q
nO\YV
4\6yl
Zv9`
nwmc{
];Tk
M'S4^
Concat
)w6:$
StringBuilder
,J^lb
7WYd
kHvL
' 8W~5
?<iQ]
,B_ l
W/g@
LaD4e
@/}H
u9<5=
,$oCh
4WQ<
*pb;
esIQ:
K)nAG#
}("
dAYM(
{IXf
pG7;
:}*g2&%-(`> 4
MKv.h
w[E"Nr>=";X[VbJ~c:C,P]R7"
zB&v
,v9s
^oEPQ
pa 0{
>VmT
get_Hand
k3bkf
lng7
,YxB
d(a
bDJ47FR_H<,SU#A=hX`[CMw]
03vaYu`{bBH"gzPR93*w,7+:%
:t\hJr
71'O
(>C2
[] +\R
b!+T
x+cT3T4%s@8$Zz_"=A5+nQ,%6
C-X5
SZ{Lv
ltdi
ZWSx
|:>f
B`n
sRGB
J>M?
qgM7t
hg26
AssemblyFileVersionAttribute
&k7u
System.Text
6(Y
9Bjf
(nc V+w
)BXN
PWh+V
`V/i+]
K (.
:VUd<F
w0c=4X
hLlI
2>[OZ`
_PWK
g zq
^X9[
Mu9ni
9 kw
Lp{xq
%~4LNb1^
na@9
4^1ZN
e|:z
2 fY_P
g[~[
( WN
+HXL
\ 2#
YMpK`_
GetElementType
ywQ\
I6y2
yQ*E
}rx.
v~O]q
C{Jv;
|qSB
\Q~kC
SWW8Q
1'O8
\K:R+
(+
FRt.G 5
vxU4
8,<7
TJt-`
GTH\J
7gTX
b\\>
lldLL"#
* [Y
i26"Y
XK^t
VSJ'
Z hS
a45o
>%#4
Nuj^$=IS#EC*D9<|d*0vCjR^'
KlGd
%:trw
aD?=iI#T>^7Ez\uMEd#ac8n0+
hI}/
WI'
;kj$}c
~>-AQEgS)M947FK=PZE\Yu'H'
;_'n
(x|
# fG
ncr,3
z W'
+ $%
kiy>
IQ H;
f1O^s
QA^A
h/?u
{4$k
{xj4R
'}](
{|n &*{
m4Mb
`zQ[q
^Oz7
RgZ4<
q(0`
o?L
{]Kz
Z)LF
FieldInfo
Font
f%
w/Z:76S0BO'!?^+#,ZrwOrzu$
>ol<
Sn l
pxlH2
,~mI
[!Ks%
!b8D]
^)H~
0
5QN$
Jp|k
^ (Z
'^S9C^
wD _g
h1EF
hPA$
F7$8
;#/Q
fTEQ
g]8`
String
p4wjR
"3+Gjd@oOMrO%^O]JW,OM0n4$
_CorExeMain
-#xKL
Wj!2
-<fo
5v>y
N,f+
+XUHF
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
[kuF{
sK6l<
YA1\
H}2R
gr=dA^ E
RJ%3
IM(2%N]!
Wg6rK
Hwu>
D35R
,T\O
'AE;D
p\K*
"yA^
Ji1c@
M^7,U(
InitializeArray
}/+6
\]Py
gj-I
7wY,y
!^cM?(Kc[c;f^\Bc=<XgRz'@"
u q<
\h)t
mit6E
*C!c
7eXk
AL[z%
Ve/d
r_^fXF%)"A7Xs@,H[XZnV\^K%
l*,9mB^VrQB9n,3q_^&tkjDw#
bfZ8
o^d%%
KeyI0
QPr{q((3#
pEOh
KZ,n
wQt*
ToArray
M}.f
4GXpo
K91t.
n\ x,t,
L *4
eA3h
OnCreateControl
]o&`#_K}bV";c$T-]0W@o\?I$
tgV<
h?CH
%I
f J9
P}-Y
0zk.
ffzO
nO=`k,z
4D{G1^
9gTN
<m9M
&v{3X
Ca<)
=Rh3
VPS}#
#=2
8 JP
JZ"'
j:V!
|Oys(
>&&rQE<
WzdeOE!N)>Q?w70&WQucJc'y!
5G| &w
PcC
>Y=N
C /q
get_Hovering
h-^-
JZ/iq^ft
VL^Y
E{a<T]
jt&
z:
13N+k
LxdD
[p:^
bG0i
r,N]
(ES2F
mgZ/
ZFK\u
Load
w<-s1N+
i.u.
L.e8L$
pE||f
~#{x
]C;cFG
ejz5
kf8L
System.Drawing
#<;<
r#j>/W
#L-g"
;=Z*M
W?#
I(:B>
b>Aoe
get_FullName
TA
~RW>
!sJ(
wIDAThC
[Qyd
UUaU
"]>=`z[
;yl]
'!M|K
BeginInvoke
ZxB2Ox
DGaI
r5!K
ArZ; ^
~OWi
n J#
&NUEk
W!(D-
,q &,I
GGF1
lan.
&#c|/M
xY:25
=?O,
W_]y
l+Hmh\
>(f<
O#k5
G+4]
pOh-
gW f6A
=TT6
"<?r(x
C&}(
5j04
dPQ
B4m5
p?01
Ksmdw}
=CXj2
nYad
k%Y~7
s}v0h+Z4'1=)$hN"a@Q88|_,#
K ]
L3b b
4sEK,
)--K/
vBAy X
KUe_
Ri.Z5
=miBx
K8j9
RuntimeHelpers
g#k_S"@II3jUkFZ;)V@axq]'$
|=TM
2Ioz$
oG ]
k?*S
V#79
aa:Fz
:i>Y(c^N2!([@VLu{3s\P+6r"
;[C9
^8|8
A%l-
C R1H+
UserControl
KSV}
#LcZ
v|D"
get_Enabled
r,IEQ
g0#%p
z$PQw77Ke"?:l6?1@zWEy{;N$
H#p
dvXb
Lp RI
e~zU]kK*dKxB&5}8 hVx8#~l+
s]7$
.C3h
koVG
a@'6
4=SM
5Zd^
>d|Sy
,Hnm]
dfBs
&hTins
PijU{
Object
/o?`
(1s
cp3ChO
,ix
>aM,8
5gN
=/to*
0zcLU
ComVisibleAttribute
q&y5
b%VwlB_
wQ IKu*
ZJ-?D%
`3b{Jw4T5>'I>wq]+qu7x'b(%
t(0\^~?
8U|g
4[F8<>cRH>|nr3IF:'"MQem5#
r 3C0~c
nw+p+p+p+p+p+p+p+p+p+p+p+p+p+p+p+
y ?
Z1'%
? A"
Q=MY
6.y3
^|* "
G ^V
a8n 1
fu 7
\sK_KA"p1L!KU9J8sfwG\Y2j'
3o$q
tb*Y
uRXI
/#C7
W2|ilj
4a+ZCv`(
O'/
3?a
U" M
cw^
R@a~
OK8Rd';g78C{_;AZ>_vVt'b
E9Gj
qI8$
9>`u~
n\W6T
<Ckh
o'dM
xn{w
LH=e
F? 9
AssemblyConfigurationAttribute
sAe5
Rwdci4Ig?N#EWme3"lFF)*(cI
t!ea
b5HB
MethodInfo
r^!t~Ro
f :G
.Sk(A
' 2
ER3m
-KI Hb
XUx|8cTP\uX'=U(05#K$p@-B"
wKIn
ZkOA
gET%-,
OnMouseLeave
p6 my
1.0.0.0
x >
og5JA5
']/7
}]2i
05 N
}10
-41m[J
F!U"
1n'U
V] 5B
P|d
7+vOY
) $EIrq@
L"v:
w EH
D.?Z
2"gc
09[~ShG
ZTjC
9 Zs \2A?\'
m[%
zs\%KT
dfdge
y)cZ a
Stream
R+?l(
v aL
,uV5? W
M6u(eu
*:TDQRO
-zBs
LE&: q
Zh5 }P
=_I"
djH<
Tu-"?d;
pAN
#/y($m-
wgti
hWg6a
)UqR9H
qSVWVJ
UTAD
FCbv
8o3n
=elu0
k$:s
T7#v=(!NZ@ dc"q97E4aMWP\#
Qql9j&_WmTG$TTz=v,2C<@L0
D~iK
A6 4
CreateInstanceAndUnwrap
vZDP
;aSkV;[PS#eSL>kSvA"W|a]W!
))?u3/lJS#o;%*yNy?dJEE[#'
fM=
3uUc$:-OG+] 8FBAEgo&-!M&*
y\kv
Y4yN
NJB^
jVr.
$kkP{:i
:`=[vY
##W8
get_Control
| Iv
(D62
XQUV
2flC~
qXI e*M7{
Confuser.Runtime
F+5d
}(@h
<c5}H
i'YKR{
r/Bhr
gP9W4H%g7W780>]&:;ypPK<;'
PK:m
zQAL&
O =_se
" `N
X\HV
?v{G
@hIX
kr~ah
Z'Dm
"2/LO
TiB
<pwqe
Ki`N
"fwG
I.?C
IBP=N
(Fyf[m
3L]7\
B9pH
jZzk
f\!k
u>J0_X)ZUc^7}2K''A!"cU>$(
op3%
RSE4Q
!vQJ+dR
aT!3
FJ#
w1w[
D9At0
]P$nz{u#I
d-DP
c5CE
BHCy
EQOz
(@ +{g
o&HT
IY@]|NVDeV6E%wd:)aXXc9*}'
;3a<
i,_E
D4Se
set_ServiceName
.#Li
Gd5{TIte44AIN;3b pFR!(9z)
CC6pD
HVm
|NS*
%'\R
<,FBx
&wX
-s:cdz<sX7V&0iTYZ1&=IPPa
14n3
kHz@
L_yU
ZfR$b
HkF3
j{ON]
Uz<m
..P9P
6V`C
NG&A*
zej
XR,<0
*lC&
m!*a=j
CN}|
8:Tk
]Tx|
J!/it
D8.#_
HFD
d~e5
Zos}
1]>O
iv
_lOWw
_+fxhM[
G*v Q
T=j)
%Lv`
Jp`fW
;nTD
/wgnj02ykkL
rmf^
^`0x/w*AY@4#r5dXN&6fbtQI
cIv=
!Fe~
F&*Ib
1^Z3Jr
6<lA
set_ItemSize
K{}w
I|/"H1T
is1m
(*6*
/ hPD:
'k$)S=1NdHbl\u|A?wi8(3"&%
TFm^
Ut-OmC
usu/
s-0y
+M,g
?v{6
0@OpV(
#v~0#_
"-T6
h.F+
G}<\!"r`$"\?OTD\%hD3J,2\%
<Se5
vT*z+
l/)u
m}9A'jlz0docI3AI\VzaDF";
ubpeY
M`YM
lZ29
nuzn%
z~&S
(#t=
o~b zh
:d|M
o3@v
ohI,
GetHINSTANCE
59rf
FIz.Lf
ga]C
r+[e
7cZKZ
Buffer
/TS
a o
iy0Z]
gw4Ii
7\.N4
,*9:PV
DR}sM-
"lW'
:V}@D
o|AL
j1$_
@?/s
w=Yaq
2-uL
C q{
_"8
-VTy
uu@7
@_8a
%"lR
~zv(
[Vs$B?5_
p )
:&]_
%I(FJ
p-eK*
;w1t
maf"
4>;lJx
C?]e
li$0
Jtm#
9<68y
rM!u
46o5=i
Y,lqHu1
Dg+^
$5W5&l
cnim&
SL#Y
xU ^
9N%t
|6Z8
lyc7
x*aD
c{:Wln
%ozfNJ<u>3jOX56Y(`?w{w:d'
(L62+P
?Hg,
eJ h
L%oB
VTmb
orfcQ
cY1;hME
6KQ|
/vp@
G.G{"
$# ;
u K
_KmUX;
r^U-
5VErr
t|/9
d>;r
)~D6
.[U#
eAU'}
O/LG
ue\
S-A,
X bVW
>gjV
J0Q3
mq "
F|s
Kj$g
J %[W
+dd
5vC]
rA+<
VpT1
D]Xq
*x13
[~TsV
P2[T;
-:Ym%B
gNFs|
J22[
k~qcX|8>,{h|Kv($XSOa3hV$!
~vW x
t/!n
X,E|
L."6
Copyright
N 5N
mG@M
}T1F
r<"'
ArgumentNullException
YVh[
rlO)
_wjh
%b{h
08hf
get_Major
(^OSby
aXqR
~*_ +z
<%M0
!aB,
v)%8]Y
+_)R
w`I7
c@#?o6Idsr-J34*3|0+HC\gU%
o1)v
(&]W
Point
_ )-
,J(+
YvU*
7$@0li\
tkNJ
;:rO
m-Zok
";,')
<N\
v2.0.50727
Z6UI
;LBQ{KE
`w*@\
}yrL
0N{D1
|"`&
#Txc=D
G1Gv'
f5v"
v@J~|
}28+i
D3W r
8&zg+C'UUd)mIrHsdrU_c(<i#
/m$_
j Fc|TH~-PJkC4~@zT+sP(=5
2,]2
ZG5z6
[)h'%Yc/kDuT6cCHSspb{9sg#
t>i
D/+g
1Qe,
r|z/
2)?"+6F
Bu5j
I_}P
%;zmT
68D7
ZH,M
I">
-W,h
i$r}
-(F* p[ZpR
^iZ6
3gS`
bg6d
ukK2
BjRG
Exception
t6XQ
2xu1
D$^H
wpicR_
er<bf
W"AS
qtX
m?w
T%{E
eDL__w
nl" {
B/K*
9eSI)3
L.OnI
r<)K2
/~Z Yl
Jze<
Rd T
9T-'(
F3FpI6_kXm_!f?vp=g(-t'(00
Ei}]uC
A'H"
wcK~
VQhC
GetTypeFromHandle
IAsyncResult
2C0-9
*,~
] rv
USjQ
!J_)
' 4S
+ ,W
qwhF
L#7m
x c;
V%Q;
I/nF
e x#_r
vaq:
Hy,~
5n9,+
Q)T%
GetDelegateForFunctionPointer
s~"G)+(
L;Nc
87s9Y
/}$
l'Z|
.FDuX
/pC;
3 r
e`{Z
2DG}
.Vp5#
H& $
fowK
P@IpVFk$
gm9d
QDgv
G3sT6
Shu95iQ
d"XYNfF!NN<!^Z144Mt!]dVa
jo&d
TxeB
|3f#
yvIa
/`Da<
}m]
>Ug~
?[:P[
1?mx
;n>
bTt)
{e@|
Bdjx\
*vp(?7s% 8Vj$e0^{5a<d4X,$
>Fm^
2s0z
x(N${
$ + D U k v
E(aO
System.Runtime.Serialization
@CMLa]$
g%g{
Kmu)
`z9K
2)z3
8^Q]9:
NXd6
6\s[`
S)k4
4kip*aHX>+b$U4b5$22MnLz+#
pw?t
#Mj~
F D
}qN~ OM#fo
@1fm
S4X/\
~IDAThC
0w14
hF?q>4
gVD,CU
*D}?
u,PCX#ju
-5_oM8~*
2FY9
Ks0^
XK(.
F{2c
}nhz
{e*lB
0%(/
}</>:f-TJx`M/V0qKeej*J}+#
| JV
Gzy[~
7se&
(Yo<
X]P"Q
J`*)
Math
V#K#
Y;JW"~d_*IXPbTDk~I<|L^r{!
s&S*pnK s"s9$tA5G|H$|\0J#
QYl\FI$/6%)slk[$?o;y!0`4-
r4z}x
b:0]0
>mWFPZ+ u#
\xN T
]J z
?L2K
a ?~
\ i9
#^'6
t7)=?
KZ
z mh
b^p2P
WENS
S;2&
$|MJt:
&Rno
FB'V
$4?"
w1 P
+s~aYu
VbQQ
!O@O
4J"e"9][JqR2;NqQAQLWbp)&#
<?S[
O[1!z[
System.Runtime.CompilerServices
hH_"
-*vi
46E!
!TvSn
v[O1
SuppressIldasmAttribute

JIDAThC
yAr?
Tjd^a
`O;G
L >q
PON:s
E[|c
H}9,aUW
2?06}
':0@
ZWdC[
xd {
H TY
%+(
YlEmj?/OB_!-|Hk!`T{4O$Yg6
x"fL7AL|ZL}7"{o#aPSvt_DF#
.Pl2,
YmJl
&eaD@[;7eJ
3LL^
4^ [\[`
FHQwf
t#:Y
Knws=
NGA'FA !
1w %
d`VB=k
-d)-T
;"6<f
TVP^F5
[?Lm9D5v&LHuSWtbeQ[b<\b*$
p_T4G
A[d`
|IDAThC
HzbO@?
T{pd
Aidbe
\V%H
Sp.$H:H
buH?
M vY
[KqS
S x
&J!{6Te3kE&z9>j1'yMw*6=-"
/p *
}oT
]7[p
a~IcVVRZeSML0shce;\i`}i[
mPZ,
rE=7~
RT}+
2a=9
set_Font
= < < < < < < < < < < < < < < <
Q<f
,/N;jx
Oy'Il
p !U,
=[[%In
ebRy:
d'0z
Q*Y|M
.+ gV|(I
A('J3 ?h
":F@]
5.3>
Y%~?w
}(~P(
ILqG
1vPY
aA-VA
3wUT
o|@U
ZaUe
+"UkV
.pMc
v M0zlq
dV<qAG
V-:Q
S|X3
NCnI
5mv (
c!p+B
ZU;M
(kR
tbOd
).H
2G8e
U$4)
Zi3V
q-J^
V4vu
!%p-
QpX'
4:{D
vnxtDm|6
#5g *
S*d<
ol$
s"z{
26Fs
12:n
AssemblyProductAttribute
LOww<
_cp|
uQE
8c|x
LBgV
89UIDc
u@Hf!
B~ /Wy
Qbx4'P=
'G#SR
F3f}
j7&udD%B<HQ=&kF<UZd_n(\}'
on^Y
<Module>
HZ/`
Y+@g,
h^kp~
p&[Q
7Wk
*]G
=VH
Sfd*
3.9
{WX[l|r]MP9V>HuslX:El^Yk
3: `
W<CW
ez"DY"{860ml1WHzJ~+XFn=m
m!~B
"9sA
X;At
MulticastDelegate
.SQ)
H:Xp
lIP7
Ez)Z4
#t:Y
0< H4
G,D0ACg5ir9[ju*MSd:#b7Pf#
hIDAThC
!m_pData
K`<E
!7Vxd=bnNZCn#hi)!K&\mHG"(
g !W]'MZ
D,n[_N
%U?E
value
+?<k
xP"X'
N;*"
oJ0a
2018
6|#;
Yb:=
'KXz
E"3%
^jy C
_DIM$
qJHO
@OnCj?M3'`X<Mq"2QwSxNLx*$
lV[B
$n=|
nA;*
3j 6
g1,6
NF:-
;9}?
/AIqr
OnMouseUp
~]Mjc<>kS^ocG{zi(K:RPzj>
pS,M'
i^V5
:IF2
dE!:+w.
%0RF$
.Bj`
lc?jB
W q^
C'di
Ac!S
.Fl+s
4g14
Y;E\-;
[\`hj
6D HYWg=d-)@9s5c<wM2IM95(
&bYK
aBu
\K_&,
mL~q)~T
CO c
1{ZY
%5+W
#GUID
) Zg
v^`>
/LS l
\I`#(#
set_SizeMode
QR ,
,4FR
cfzT
e[[g
KJ*
uR%^
W_:<x
:)=w3.x
T#^/
Q'mT
3@M+J
yIDAThC
8r>r
JERs6<|
>lgoM"eN3aswW^zOhS4)umzr
mEs|
P8:>g&
==3M4
]Uh.Y
Fhsa1'#^N}^;F6jOAx)cik4|&
$ Grh$
t!q"
f#>V
%e[
yE8;}
[bHw
8S$bq!x,9U`7Wz>W6s-azHdp#
GHI'
09$@W
u%?p
`]u
-{]eU
R]jW
Xm"
')66
X +U
QSN[hN
Iyg{t
dfen
Nullable`1
$frN;
_#T>
o^Y~J0>ciFD ZTQ<\7Ov_zA(&
w7X^LP9Zxn`:wZ6n]C!f;_98"
F2K"
QO|G)j\v4|,JZ,X/`]uGD6<7$
dU^
FjH
5b-'
}x-g|y
IQYa
{Re(
+Gm
)m04;kpT1c(!%XY3g!?#|3eU!
j YQVYV8S<#G|$|Ka)l4Jn<31
`! o
*_1G!
rBw%1
:cF]
R[]@
get_HasValue
kd9B
/S{D,X[k/0N\);M'B-'HYOjp"
|Mh
jH"W
QsTr
^#>=4
W1 w
oT ^
<?&(@)7`
""7{
lPKy
kic
.t.7
J.zq3
p9M{
Cq
Encoding
:Hz4
]v<p
mk$O
+*J
VOqi
GbtG
cYIgp
m1h-n
OK0w
2FH[
p8){f
DL_'
j{'|
Eyid
IEnumerable`1
[<>NK 7
{MCbT5>W+eCf*O7JkAK@!xXC#
1dY:
n[tF
ShG1
'[^U
[ERK
get_Module
tlI]
c"A|R
TabAlignment
JAs[
OVnO
Y *gd
j@q~
9~ zsY
-+S ccWs
|b<yV_a
}N!n
Tk(X
Ev{2
rN:s
yk93
m_1C
uC|N
;{y'>Dvb:X4`ij4aSnT`1"z#
d9s
H-V/G=?mg$5[<RI?QLNa(aA*!
<RbihY
,RN-)
}0-^
]A0~)J}o+s]@[4,,L@R1r'L$*
+|%l
= N'
Cursors
{,/k
G&Qj4CD
l JP
0QWaY
Yd( @s
get_Size
lmDk
xIDAThC
^3893c)Y}{['Xy&'#<)~_vL{&
IPKsz
/RYl
N BN
DR')H!]
{kIq
,}u|
3Q1-#
O;1{
Zln
% 72P
&3)D
;2=h
System.ComponentModel
Ark.exe
H{t<s
04VR
VPue
;`.R0
`N{uk
(zb
]%Kn
436534A617CD86B8557AEAA31D433ECFF38B112F
v]'
O^t*@
L^<6
'b?(EWa?_UA4*^APRsBg"P l"
|UdkV
Q%*1
Qvs+TR
u_~ 9fB
~26 U}
^ 4
!X1H7GMi
DisplayNameAttribute
b\4C
& Ml
]S_|
rq ;
) }"d
IW+WI
*8 q
L=%
C92E
VI:I
^13(jaF$\d+1u+U,%nz{Vn4I+
e~\N
C648C0E55DD0A71600A3C979FEC05C180303B2F7
5SXB
EaWP#
M5dF
7QmI
Upoz
<no]
I({Y
OZe&w
$+9'o
awM]
ySwr
F;*~
U?0^
v+}}
owo
Gk1t
5YKY`
f_GLa1\D6!{V37`n9^PXL:*'!
System.Collections.Generic
kWme;
lGTD
Kd(i
XE11Q^\BjCLPCFW`_'+V[w'h
UDG:
H$
bI-LUJO0PbVFBgh[Zp/G7cS@'
7_--
o+`q?N80:v!s,/] 7`%;g)YN4
FD}|5>)\y}~!WUa#2x]`Le\t
' yh
<=,0
ce8l
FaQp0r
lT4f
]J-QH
;o1w
System.Windows.Forms
set_Cursor
)GB\
)i9t`/bf^Fa%'?r+aw"lhF)="
i8'
>3j O
6MIJ
oQy[X#7XP1>*R({nIbK?;'v%&
P^@^
vc h
3/ Q
7 K<
iPDA
vvAY0f06rsVSId^! (l=u9Qc)
:`3V|
F2r6K
XZDml7X&U/"c0&DRhD$QF*BU)
wG h
0)_
{Af=
WriteLine
=@bF
System.Drawing.Bitmap
Contains
<T| 6e
+H,?
!<XPHX
DJ3mM
}}oKcd
8"|S
gpLe
HJyN
IDAThCc``
={'rX
$X ,
SetStyle
8jN-
=B/f
v9qjG7];QNE"\?MWU'>J;BcZ'
blqv
9a_1
5M%Y4M
|TCe58M2
disposing
F;8M
4Y3.
h2"k
m'
qm(j1-
cC][
y4GM
3#Q5
ssmw
(8p\O
uum,
I,mR
_Maz
!dZx
.CKP4
U_d]?Rw
!,OD3X
<4p#H
A_QR
}tI
/@7;
\d4]%#_-+JoU%*>z[)lO\CQ`%
1r8K
GetTabRect
VY|'
RZ4!<n
Cfb
@Wv wT
]"A$W
- JwM
wZ M
gj)h
0Q;}vG:ft-KDM-T0+F]+CeOS%
{ o'
3=(0
y?6o
rzNA)rw7^TjDhAnHj9K'u+ER"
ezhy
\Tz1ykQ}2d`3zFTTCR#}5c?0$
CO<2
1t>2
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04b_64 Seven04b_64 VirtualBox 2018-02-15 11:47:04 2018-02-15 11:49:58 174

9 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven04b_64 Seven04b_64 VirtualBox 2018-02-15 11:47:04 2018-02-15 11:49:58 174

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\chidi.exe.config
C:\Users\Seven01\AppData\Local\Temp\chidi.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\chidi.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\chidi.config
C:\Users\Seven01\AppData\Local\Temp\chidi.INI
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\20008c75bb41e2febf84d4d4aea5b4e8\System.ServiceProcess.ni.dll
C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.INI
C:\Users\Seven01\AppData\Local\Temp\92d863a2-56eb-4d97-93b2-bb960eb5c440.dll
C:\Users\Seven01\AppData\Local\Temp\92d863a2-56eb-4d97-93b2-bb960eb5c440\92d863a2-56eb-4d97-93b2-bb960eb5c440.dll
C:\Users\Seven01\AppData\Local\Temp\92d863a2-56eb-4d97-93b2-bb960eb5c440.exe
C:\Users\Seven01\AppData\Local\Temp\92d863a2-56eb-4d97-93b2-bb960eb5c440\92d863a2-56eb-4d97-93b2-bb960eb5c440.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1\System.Core.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.INI
C:\Users\Seven01\AppData\Local\Temp\chidi.exe:Zone.Identifier
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Ark.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Ark.resources\Ark.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\Ark.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\Ark.resources\Ark.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\Ark.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\Ark.resources\Ark.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\Ark.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\Ark.resources\Ark.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Local\Temp\shell32.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe
\??\MountPointManager
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2348.21675468
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2348.21675468
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2348.21675531
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe.Local\
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows
C:\Users\Seven01\AppData\Roaming\Microsoft
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.INI
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\4ddee51a-5195-4ef3-b945-00a5a040c597.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\4ddee51a-5195-4ef3-b945-00a5a040c597\4ddee51a-5195-4ef3-b945-00a5a040c597.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\4ddee51a-5195-4ef3-b945-00a5a040c597.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\4ddee51a-5195-4ef3-b945-00a5a040c597\4ddee51a-5195-4ef3-b945-00a5a040c597.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe:Zone.Identifier
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\Ark.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\Ark.resources\Ark.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\Ark.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it-IT\Ark.resources\Ark.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it\Ark.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it\Ark.resources\Ark.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it\Ark.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\it\Ark.resources\Ark.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\shell32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2540.21680546
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2540.21680546
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2540.21680546

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\chidi.exe.config
C:\Users\Seven01\AppData\Local\Temp\chidi.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\20008c75bb41e2febf84d4d4aea5b4e8\System.ServiceProcess.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\fbc05b5b05dc6366b02b8e2f77d080f1\System.Core.ni.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe

Write Files

C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe

Delete Files

C:\Users\Seven01\AppData\Local\Temp\chidi.exe:Zone.Identifier
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2348.21675468
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2348.21675468
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2348.21675531
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe:Zone.Identifier
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2540.21680546
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2540.21680546
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2540.21680546

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chidi.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3035fc5a\375c7a1a
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|chidi.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|chidi.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|chidi.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.ServiceProcess__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.ServiceProcess,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.3.5.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Core,3.5.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\337da671\3850e7bd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\337da671\1b71387b
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Namespaces
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\index
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\index.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Templates|index.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Templates|index.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Templates|index.exe

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5fcea75a\3c9c8d7b\67\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3c9c8d7b\46b95040\6c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.ServiceProcess,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\7ac727df\7b5311d7\61\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7b5311d7\1b0ed4d\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Core,3.5.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles

Write Keys

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\index

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
kernel32.dll.GetFullPathNameW
kernel32.dll.GetVersionExW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.VirtualProtect
kernel32.dll.GlobalMemoryStatusEx
ole32.dll.CoCreateGuid
kernel32.dll.GetStdHandle
kernel32.dll.CloseHandle
kernel32.dll.DeleteFileW
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
gdiplus.dll.GdiplusStartup
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.GetMonitorInfoA
user32.dll.EnumDisplayMonitors
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipLoadImageFromStream
windowscodecs.dll.DllGetClassObject
kernel32.dll.WerRegisterMemoryBlock
gdiplus.dll.GdipImageForceValidation
gdiplus.dll.GdipGetImageType
gdiplus.dll.GdipGetImageRawFormat
gdiplus.dll.GdipGetImageWidth
gdiplus.dll.GdipGetImageHeight
gdiplus.dll.GdipGetImageEncodersSize
kernel32.dll.LocalAlloc
gdiplus.dll.GdipGetImageEncoders
kernel32.dll.RtlMoveMemory
kernel32.dll.LocalFree
gdiplus.dll.GdipSaveImageToStream
oleaut32.dll.#8
oleaut32.dll.#9
oleaut32.dll.#10
gdiplus.dll.GdipCreateBitmapFromStream
gdiplus.dll.GdipBitmapLockBits
gdiplus.dll.GdipBitmapUnlockBits
kernel32.dll.SwitchToThread
gdiplus.dll.GdipDisposeImage
shfolder.dll.SHGetFolderPathW
kernel32.dll.CopyFileW
shell32.dll.ShellExecuteEx
shell32.dll.ShellExecuteExW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
comctl32.dll.#386
ole32.dll.CoUninitialize
ole32.dll.CoRevokeInitializeSpy
comctl32.dll.#388
oleaut32.dll.#500
advapi32.dll.RegSetValueExW
kernel32.dll.DeleteAtom
comctl32.dll.#321
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.GetProcAddress
kernel32.dll.CreateProcessW
ntdll.dll.NtAlertResumeThread
ntdll.dll.NtGetContextThread
ntdll.dll.NtReadVirtualMemory
ntdll.dll.NtSetContextThread
ntdll.dll.NtWriteVirtualMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.VirtualFreeEx
kernel32.dll.VirtualProtectEx
kernel32.dll.Wow64GetThreadContext
kernel32.dll.Wow64SetThreadContext
ntdll.dll.ZwUnmapViewOfSection

Execute Commands

C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe 
"C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Templates\index.exe"

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-02-15 11:48:05

Detected family: #Malicious

TheSystem Itself @ 2018-02-15 12:04:02