MalScore
100/100
MalFamily
Barys

bossemmy.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 21/65 Related 2243
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 964.00 KB (987136 bytes)
Compile time: 2018-05-08 03:51:54
MD5: febed648257274d46d864132745b6a05
SHA1: f199589f8f94d68580e6d7b72276a10e25cbfece
SHA256: 6beb034f6513c4863c309e1d09169341bef118754332087d4eb59f545edf3e85
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-05-18 15:57:03
Last submission: 2018-05-18 15:57:03
Filename detected: - bossemmy.exe (1)
URL file hosting
hXXp://qualityoflife-lb.com/crypted/bossemmy.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-05-09 15:54:36 [21/65] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xd8044 885248 f4e82293ccad07c3bfb086bdcbc34ad8 582eac782adb667d2647d39e644368a5b7c637a0
.rsrc 0xdc000 0x18948 100864 a3ca6af3445a0abaa77bb62c0601e400 e55dcd341c3e8c921dbed66609ee489574f55886
.reloc 0xf6000 0xc 512 4e5258d872ab972e056e51b3124f2700 9dcd613ed31fa24facdd51f52d8a71c42ce072b6
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0xf4248 1128 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0xf46b0 76 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0xf46fc 588 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: bossemmy.exe
FileVersion: 0.0.0.0
FileDescription:
Translation: 0x0000 0x04b0
OriginalFilename: bossemmy.exe
ProductVersion: 0.0.0.0
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
String too long
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
6VCa5xBjdWSYzMqM6Oh1t
lOTxxJw5HG4o6jyD1VPVzKU2dqZK
RD29vqx2NtjiEY5kF8VxLhrT6FETg8
bossemmy.exe
InternalName
tA4WuvTwm9F7Q37rdGQvIX0JJgh
7IEKzoIR3lnXNCeeELesQXXM
muTGREDJXXR4FyaNJ79N6UioGpPBSTF
bdQRyOVDDFXaUeZOOJ9dE9Ci4Mf
0kiEAS7nwmuhoPwGbSU7Fg
qlECATdwnAYJCbJFjcNcED
Translation
tbgykUPN8WOzNtPDOrH4gWz9
LegalCopyright
yw2rx4iF2EkxIyWIDPyRMokC70j
)Oqt
wyiVuKyM74pxbPI0nf9WUV
dBMLJIRjQFcOuYsPV47ilFqffeIl
aOWeB6SxhrB3j3qKfR6YSVv8D
bpMyYgC1ul4wzUWX9IkbxAEiltANtAGAfzXv
6XAtMQKi3CWIJ6hG6no5TuQ5yCUuM5hAm837J
4v2x7woLsydLXfxVBOFUkfI2pg
rlRlogHOfXkC1lRwWG8UczRm9J6bsjLNJ2x
um4cX3MT9e1WsXN6E1CY
jHnMjAMEw3HWYc2nUADesKfo7
V1ZcuJptYJpHVqKBGmNtrM0
yYogpjVhcaoT1rM7qtsh2IKns
bJVaJo2QiZSxP9CRZGdSQ4B
kyJPn6KaBqsbnE09X46LRiwlszng
IunMgNxT1TjwlUouhg2zA5qXvJXQifgEz6
Y48U60A9mfOraDIiFctgtWAk7O33MS
7w9RZn3i0j2u6v4WRhpNuD
OneLIMG01yP9e0puT3wyTgL3
qVsVCdVDRUYZCcRX37ERem13z60YUYxJ
UBgYTePRIW2C4eAETBqcQQpjTNnLt
IzriTTDDj6m8kDraAKnV
KUMXCq7EPuGxOjTqcs5kBlp1Gajs4CEUogeYwy
jHfepFO229r1rQKgAOA8ady97CmhA
daCwsoYpqx38arFyFGgRZdHotBD2E
N6cwoXj1tWdxkcyJnYuEvrRN2
mfX4dgHoZlT6sRvtdUumZP7hfx8Li
212D2bqnH4HcnS7HpOq2oHd6p
KBvUjuRUD4NzolFIiD89mnNnX012pdH5
x1jpA3O4piFW05TgQhWor0AG4HQrtVSMR5
iIrEtuuVbPxQSYIOPAkhQP
e34NbX8CUgZRVraF0fM5ak2M81edviFZK
4YDc4Yyz4rEyJmFda4PM4
6AKtZS4OlgriQ3fHQb6wQW3zwj3n
ldwuF8gHF1mRUopOo1pn262iXXFkGTo
dKiwbHb7nrUXi1IzJ7ErS6TBeHIwGbs
W526rMeKN9sL8mkDHAGHB2OBHQh
K2h7qp9RtioE7PFFoswGBHKmnGUaYu
jL5S0pPGuMoRyjkjeHm8Ntl
un4iUJ3mCMyM3mWVz1aHUUs
j35JAg8N7IS6eREDJqmX2wYbgOWedFlI
d09sFjnFrIDq5lH3SkuMYCB4nwQ4
PHUtELATQKPQmJ9gNTVJKwHG6VUFxN9Ct3m2C
7clbFdwhvvIiray0tmWy2OQhxHdx76apJ
0.0.0.0
OriginalFilename
Qc9rx0njH2c5l1ZaXXW9juHVYv4gu8
LWOGDtzQWfq3fk2Y2HCl
VarFileInfo
TGdb6GkZJKOhrLDfNag2AudziFAO
VS_VERSION_INFO
89JkQdbQ1CYMSOTPnRBZ
ZtEngnW8FkhgxYBGeuCNSD82EfGzl20iqukK
80tGJNYA7jZjW8XoPKvUJ17y9
yDmsDNkFrtJbAx6B0lUxip3Xn3
Assembly Version
9v9bNGbSLnrqcKqX1mDiSzGEIr3bF
I7oabjXYjMovgtYolCQ3X4YvMdSe3pSpDG
CWLMer12BAJYsR9DM2FnTXqt0ULVnnAqVBkL4ws
mh3D1DQZ88miInXUJQpGPFt7ktv
lkb6eRz87kXLLvJdZMyaIEr59WCqR
j4j95mL1FI3Qmf6gzEi2Jiy7EiiTSi2CG5I
caHKMig8XP831sy0lVUL7L6RR1ZfIzKEDZC
4lKMcruYdrvGNQkM0vJH0IRTfla6oeQ
qCE3c2vEleaNWUONnzeBf0Z8t7alnbyO
pxQmxBzc0gQS4d2TeSCKJZKc
Px6lw0KI8LayKuHTvMxHCt3
rgLZi9HPBzdsXXLe3RaPEpTyDcSeSoya
LwaMPcDNY8wGNcFGmN0FyMdd8UpjJuEx
Jv1xni9WaRb20lJ8V9CGRjSg4RZMvZB74d
aKwI03DkP2eaTdGxMmIz
ijytLoSQ5HQZEQqn3YNpgtLqZywuC
6T590JfnCeYepLJsfJF2hV2IwVPsL79qmqAAoiF
43ikVQcJpHaRtCgsiZNDfsf8S
StringFileInfo
yNOubBTEIGbaB7bTSd8clusjOg
nF7HVw0Qiy0jH35mzB6wqGgCMV0faYHVYe2
FileVersion
pfOS8V5Npm6qj610TZjpRC
nfT4J6o3v8vwX3XpDb8tuwJNeLDoiurzeMRw
TFS69fyxnx8RTQ1ZjTFFVN
000004b0
ProductVersion
FileDescription
nPqR17YTzDY8SDmUMNHHVn5e
2O4ewtnQsUBPXnNM0KjhmXFQ5SpzGHQ7GTBm
2Akh62mkP0FBvapHh6dLZPoUHEHn28
l7Z0oLel8CNN9dzAfCBB5Zgp54SrDqm
svMCdwta08cKl3Sumb7zSXVONFosxgC8w
3PHOfW20m52Ik1qx2952E
tjFADfaBBVxoV68wnDthc8ZsbNb
QG2Zjvmw5nGh5UvjyBKe
y7xzOPcdhokpAEVZditpSyUBlfjUGoCTHi4i
4H(&
Q: C
v!b)~
%0xo
+F:
iy-C
$_@ZN9
<#ZM8
7a*x
WE O
xHiYJs
$W`c
pJk=
. Xo
(,79
P^6/
XL&ZMD
@P>
/]AL
4yv)
)'tV
!\|ZZD
1}]0w
$?qg
-M6Q /
+[=}k
*oy_
hHXZ
!MDi
dSBq
+Q$}Pv
DP < `Pe
@ 2o
444R444
Tf>Z
X"!Y^
<tTa
>I)*
s2:a(
UnverifiableCodeAttribute
7;P-|
yf0`
>90C
4440444>444B444E444OHCAkIFJ
IPAf/
0jG&e
H2oO
/*Zb
T[7y
UB; v
0*Vi
v&o?A
J +<
#B)q
UR9 Z
}lE{
"ohI
1dn%
r9_j
\,3
}P33{
P?[x
\OyBSrXm
Is)Q
d|V.`
#LA9t
3N%M
6FF}
DEPCN
BhI'>
H z%
X\ b
vd#o
0v0;
"z?>
444 ^`oC
nh{Y
zH^?
`ft7
kJq7
6o(,
Fh$]
i>`A
p!(9
PIA(
`,(_
/D``;de
]8wKe
_Sd3
, Kn
j2."_e
M'l$
0D`v
1G/
2S.@
EgXL
TD>-
C.oe
444q444:444
]`rp
\^3Jq
# }As
E(=i
*<z3.V[
ba+#v
Ap?
mh&F-
ZhkO
8V U
tTw
r7'@
t%Uw
n!=:
eekL
m9VS
CYN=
Q'&]
"!X:
-]S
9fL^
{InNaF
=?P ==HhQLF
*#-A
s#fr
Q;B:
L [0
%!Dy
W3$\s
|*;N
8;(;#
m>9|$
F6 R~
D(@m|
80d?7
@w)q*|
K0W~
Yb<3
jK=2(
k1]
I\]XC[
W&Co#
db~a
HJ9f
5KY4
)wk
V\qd
Kn@i
Z7T+/*
&[cc
O-oy
c [h
!D50
/}",
\+[h`z
q@.?FW
Px6lw0KI8LayKuHTvMxHCt3
gijD
1Z?T
:h-F
#iN.
(DeL1
1H(6X
dPs-f
> $Gm
g@e$
NLV^bB
-z5Q
JksD
]\aU
gpN
.v*N<
-k\-
l !4
m Tj
Ir+~^|
HClc^
8Pw1
% *E\
Vn(j
$_K,
f(I^
en7]i
)gJ.
444+444W444
aa/!
iimv+gF
V@b_
VbmW
8Re^
<+lf'
_s?d
(/>u
n4hs
)(0]
Yil]
;>S KCRA.6]
ylt|U
5[L
a57#
cjM[
.Xb|rE
v_$f
]o.J
~ \A
(:f/J
%/_GtQ w
A7J
s|ol
"RvS
a"s>
Ta\H
/v(!
3`HTC
4zqy;
o!Zf
+kp>@
rM}<
p)rOp
!R2r
"{S
.R./%>9
C Xg
;E
Ed~:^
wS: \@.
SC_F
7h0B
PhF:
==z}
FziI=
K3!<w
NQ=\H<
_sP%
WY48
\F$R
<t+2}
!J?
a7R|=|
nw|no
1r@A
LH
|6cZ4
C[Yy
I<<=
mANc
KE(?
$Z&0
Gv&Nd4* C#
6=q3
W*<"(
1J-I
$?1"
edQtX
z9Mw7&[
Wb:_
P+G n
.<5t
^q_V
ymC>
vphIv
A^"E*]
vvT
'W9T
wyiVuKyM74pxbPI0nf9WUV
]?*c
YVVQhf`
Xb)Q29
dK{XEW
v+&+
ps~TuH
lRn^
Q<{_M
*QOWre
n Vs7
KE(j
N[T2
u|'!@
#RXWf
a=@)
l%p|!
O"X(
dH3vp
A1YpR<
$?bA
rKOp
$EI,
fp2Z
{w;v
,u"]
RG^n
sGWBya!
B`E_:
{ls|
E`e$
miwZo[7
&:={
X-_I
444-^[Ynxuf
QQPC
R79"
r)h o1
lV>[
%f&\
$JUIB
(b10V
4#f-
5D/g
Ch4~
<K-p
?[BQ
444"444)444#444
MB{WH
M|lZ$!
p9>f
VrmGE
%]@eHd
i#G=j\&
U*Er
8Q%w
b[B@
:"0
qA$
<\8a
"?0S
w(d "
7wr!
Nij6s
9>U4444
oClk
:u:t
:CVE
*Yrh)/}
TFR<"
8_R]
FXCaTd
mtApo
+ck`p-
o$S:
kjUq
:8IJ444
444 EFLTwte
*;xaZ
k|R}
;:Ds
rrcF
S+^+a
8d9L
YyI:+
ZZbX
ZYZ
loj%@H
,e@q
y'jB
(<u]
9h)y
Bi55c
^R'
UF!$
T+h
Q}\v[kpv
#bZw
% r,B
01
^]Hd
yk*u
Il5z
ukjIU
Tp }i
`zdb
p_b4
+J|Y( =
+t+9
C5W
|pg`
H|Xq
M HLk
Frl?z<
P0rg
9J9<
Z)?b
H2o V
-vJ71
'008
L{ 2
rdZ3H
[\m>?;9
pA#e
tTLj
A((k
\`y>
xa [
[whhk
.text
3K0
W`H>!&
G wg
OPfus
);Eai
1w<
}uAz
sx kJS
GetObject
4\o
'`?7
rSq
/)@v
G%oVH$
e2/V
O?7_j
I_F!D
9a&f
#,?uORn
"YFU
z4 @
L</"C
LMJVO
f:DV
R,VE
s/wq
1v%"~
/LJ
C-@S
;+6x
=r-1W
\C|et
f]?Q
.="q
mOSJ0Z
MtTx
v3D3
>TV6
jf-A!
;Lum
'4
/[EYX
NB}c{
Tn[x
444W444,444
YAi$G
t%%-
LSYB
0gu~
`CZ'q
sKv)
Cxee
"\e1
:m-AW
9 (nB
/BD0Vy
# j2o
Rn3d?
tBgQ
\!D
5v"'
a^%z* X%
J|G_Z
q%nH
7[im~.
k+ET(M`
Ykc}
J3X#
9IR#
!XA^
q`\4
#[.,
gx.>6(j
(TW{
%9qVd
L\I,
E) %u
t8se~
R?&]u
8Jbk3c
13F&//<
{,r3
B2N
4443`[O
XA/%9ZNX{
,RM !
rnu0
9/-,@
l;M=
h{o]
L;T!3
MM_u
4#EC
o1<t
"h=s
<N@}
bQipM
JVAN?
444 444
0o_)\>?
F&%/
CreateDecryptor
MBQ;
B)sp
aqUe
ccnG
!BJ5
(8RHq
^:"S
lY+)
zoX3
1`Eq6
fgxX%%3
$]lf
OdZ35
=F^A
=>_a
BvBUcr
DbC2
n3 M
gwy
=wYvO U
]8b?
*@.9}
=P S
>h\G
:ki 3+:
zs;?
$]l8
M^czho
IMCiZn
R^aC
stK*
L[ o
3+?oCW
n@iPH
x5 ^
\#*~
\a b
,>1D
8 pT@K
2V[PY
YrtQ
)]^%
2!b9&
:Ox2
<1+D
cdu\
euhDW
sf`'
J~|.
+<t1-^]
1/01
J=eaq
A;J [@
| pU-
tB.
2Z]o
uu5[(
b3.j
#I!ae
YxZJ
N3PGzn9
n;)
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
a.M5
Ff+Gr
q! d
^ERjC
o j+
DX6H_Xt4}Rk5
u AM}
9vV^
L/@~
B[X3
~_=0
ag&e
|.,B
:U^(
F|Xg>;q
F)U
1<N
#se"
Y4k+
pqDA
WB#W
s+\30
>t v
tAWr
6<yQNI
00bA
D>6BWQ
^qBF
S)&M&
@vj
Ih'Ifq0
fT<P<
Dh\p
)X/NA
*2 [
6d)^
a!4}(
2:S`
MvT$X
s~5&C
@lp.
`_O
>LC\
TD02
kW\
;&HM{
444e444
^6%/J
444VNRe?.5T
HH&w
1Se+dx
d8&|
?kKX
Lf)FB!
V\}i@
_G^'
,Fb|
bxx7
q vuNP
N:Ys@
Q1X1[
;ZcEb _
2_KP
L}:r
bV#:
"x1jpA3O4piFW05TgQhWor0AG4HQrtVSMR5
hkado
Naa 2@
uJ)5
qH8I'
L!j^
YPZt
(z.K
UoVL
m3YI
{LJv
t8 P
/}}N
7IH3
@c { F
sUbA
e01r./?
t~bW
xE,e
,L*y)
!b7r
E n_ZaL
AXyf1
'</(
DI?#
N>m
LPku
z:0^7
Yr@~{
Suw{
x=_c
TyYM
xftnV
fbu_
0H}
JQKEy
vf MZ
pVU1
[ir+
1~
@c;q{b#
21k W
#5M!
444U444
8RcR
,8UQ!
E>G
{ HO
AY=AkHm
UgDpz
?
_nUh
\+Q.w
]vLzj
kASJ
8>xd
h"AU
: 8
s SQ
a>UT
`+Qh^D
dBMLJIRjQFcOuYsPV47ilFqffeIl
t$lm
*l[M
cnBdoM'%kP
5L>v
5Fm[
KN 7
)A_%
j<*&U&
B:qd[i
G=_O
*X?\
3Ii][S
-0m
System
c_Xz
5#f'
tQv9
`5m)
.Q)q
xj|
$/Kb
^)mB>
:( i
t J
N|?B
$WQ'8
&A3L?Q
[DpFne
J^ib
lWb%
@"by
6W=R*
ayZ `
CUdjT_
YtXk}!
444 444 LN[DA@G
i$KK
_{6^t=J{
]D n
.puX
yYFk_|
hvKHU
brPU
A tc
TFS69fyxnx8RTQ1ZjTFFVN
ve-pX
MethodBase
>ZO,
444,444
2SO
1xx
JpON\]`
6myB^J\
uBJx
kPXw
P5ptV 2
Y"S
b( .g~
K- =u
y%^%
?p'*E
U0R
\,s\
R !$
Aeg5
=Z]E
^v&O-
/U|6
4T}1H
^Y^ 73?
DCa<
NWi@
bPJ#o
g}L#
m`"d
FCGG|
}'!Z
{43I]
+ aG A
}9SF
~86
e#uA
c^ZB
'GH>
.3g6
#rlRlogHOfXkC1lRwWG8UczRm9J6bsjLNJ2x
#p`d
FTpi
Av70
Zm &
z68gn
"-41>
XOhg
|RO=
CShy@
Q9{1
r Cx
^e;rL7
fO}4^
=ni`3
Q$I
Fp!}
_7=
07j6
V;|x
0=YL=
{$ER'*|e
pCX[
6\{dC1QZP
f%6XD
sFBz$6
@A_;
2{c%
,vA
A jC
{k3g
{;yd
`4bQl[Vx
6~CC
L[!
nGZ$
fB42
cjj2
X9a2
`*_&
Zm=N
qYL,<M
5S)4
}o\M
y:v1
I2=Oe
{8Lu
Eb0[al
Ap5'JP
GA_m
(=H35Q
_uv@\f
):AE
'O%m
;lP[
=z78
]o e
+9 >
]vIl
`7xd
bb%4
4W&6
[5zn
B5B<
F|;8
4yov
m;Vf6
A j%
3*fN
D7w/
N ;p
f>,l"
+Ro;
%q)~O
~:>s
_CorExeMain
Y:ian
Q.rc
ZY)6
444 cahTf[B
*<?
YT]V
&;E
+48)
444 444 444
$r>#u
U94`
F+$'^
KL ^J
h2!i
,]\
ZMG9qp
}!hU
C:Xq
X enC
<I!{R
{L:^
T]a}
zcEHM
w"pH6
fP.[
L$~bF
-&;@
D! -
%Kd% #;I
444 444 444 444 444
NNS!
w&?<D
]2O6[
UY3'
5O!4ddE
$}v"
.[_+
>~\(R
9QTh
=|dEj
EggN/kIj
:6D fP
212D2bqnH4HcnS7HpOq2oHd6p
7JW7
tK{~
C =p7`
hld4r
PT.F
MVq)
DCD3
(z m
-'{Z
gp%/
n5Fq
}uH "G5N8
1 A_
I9-:
444.444=444Q444H444.444
q/,h
@wA[E
rn"=
ms(*
}~w}]
I"0b
gGYcT
G+8<
@1'Z
p>.l
TA1?
@;9T
@[ |t 5
Dh!v
H}U<
Gz#P5,
M}>'
_ Jp
'7Eo
y+i(X
s[Qg
|vOw
)Zy!
or9x
ABr?
OE;
]~,Ss
;?r;
=w}g
444 @ALZ
#9A %T
3+v`
+iz
&rBo3
;'}7
gN._[A
l:l`
m!hl0*
C0qS
U.aR2
KT<vE
4442LNYh./?
([p"a
!tG!
88[-$
wSo|%
d>zI
PHAU
tU@>
71Wv
c/h?
*)*a
~s G
Y/k'
|Z/'
qsDc
kZu$
5~)"
ge6m
jP22
Fj =
X!)R
> ;U
A4.Z\
G.u=1
tQ#< %
ZsEDK
Kmq,E
rRZ^.
sQ\J2[
2{+~
5aj6U
C )<
MEqE
)'SX
K ;f
e[=3
@DAq $
j`I%
W[iF
bs0,
.Q s
>&}O@w
-!Fp
/4q&
c2KXw
6]~<
I,RR
S ?_
dq|/v
pQ@ B
FArm
_Hl>
:Pe~ZSP
3{ U:A
oouJ
e@:n
|%so>O
t mD
79io){
_Y%`
?Z X
Yv& D
k}|q
_T.f
4!a6
qROL)G
TWHd i0
=g!}[
;!/&
2pgf3
b]*j
X_`
a9!),
"OPW
eZJ2+
LbR56
444s444&444
- )T5m
ZPt '=}S
.Js^I
BZ+"
Jk5&
<g!S
?"K]Yk
r6r
":a?
5l8@
rX_.
E2=v
Nv u
42crf_
{$b
c&v`
7v&]
|Wca
J\s'
E$x,
A&`J4
c`_M
444t444M4446444*444$444"444
/%['
fS_u
=^;&'
444 ABM
u,=}
{$bD
5JjC
9b>q
PaX
sDqkHo
'<zF
cw'P
$Q!b
%_ *
?0Q
H cN&
Y2U\ J
zQQr
~ (mK
`v{X
FH!*
LES+
8 ;p.
i] 5.9
Y48U60A9mfOraDIiFctgtWAk7O33MS
5h\d
C$0,
"]^F
kQ,nx
i;|)
J"EL
Y Wk
IOwG
)_ZK{J
oce
0<Q)n
q?aA
!24X
$Pm}
x$R`/ri
>H>
P^Wj
gQ?+_M k
O.mS
hiu)wp\
a"wf
%*0
|dnfS{
Ak6YVlO
aOT9
'F=hY
BP o
@KQL
#}s0
-b[8:
(9^=e
~J$G
3*D8i
# 1IE
q{,v U
V<'4
n NL
Y-K^
444#@?JQ::D
>uL1
1=;i
_):@
c%s"H
90<
I|6r
h=|^
} 3N
}( 0T
6?n&
~)9Dnj
?%1d
umDg:
cQ;p
5wk
444>YY\
P-2 "^;
jB}T C2
Z &k
cFB9Y
CBSs
[.z3R
aru1
E&.V
l_>y
)M(g\
9hMQ=
fKk^j
57Tw
S~+g*
Xk1
ES;P V
rJad
'$U>
? TU%;Q
444 @;A
Rm91
c .Mc
}f<t_
_<M[
?H>^
X/!Tg
otNY|
n$
=Tg?e
j.O$l
2%?Oj\{%
6o%M
jscoD
}(nt
;\B}x
F|ah
%E/t"
ar(#
~;K+
11LB
da<n
Ob*EI
h*,4
444 444 444
}X DH
444w444(444
^z=9 P
I D^U
!i>^t
#^,R
"?4)
8hDLW
PhuK%
EZv
p{q
&w[n7/jZ
LNA=
R78
y lo>
~ LH
aKwI03DkP2eaTdGxMmIz
xB(QwK
vl1
| &[
Tj}s`v
H-*j
1@};
iY8+
%nd<pj:
IH!+ <
b;iA
K%nb
0}d,
H}%Y
W<`Oj"
'&kt
'b8z
z7'
.qbgh
|v(@
y8mKAe
w4+t
<u';
O)@|asU;
9f=qA
6%{V
OQoK/
v\|
.Ey .vX
&V{?Ao
Qzxix
?Vr:
<g 3
E@ ~K
b|KAKT
1 g
P%:?
L+.;
I >1y f)
.#dK
;O`:b
{ vq
gh&t
^IU6<l ^
ay-Hm
c7
}0m-
)X)L
4444444 444
;Ds-
z#Xn,
o6 '
q{ nC
\S72xp@M
4z;a3
Xyq#lV#
h9%}Zp$
sJ\K
(ycE
Ve$0
o38CplH5)
2b A
Oyw+o
444f444 444
%Zj'
sxw/
Y{?8+%
v<U#n
d|Id
HEg>y
1|%z
|-$A
lc"-7
(2;
_B3@
rrxIU
;~sx3
E5P/
bFMW
/JntD
raxE
d6WW
3 48
YaxUM
.2Z3
k{o$
)C L
{lz%
%'&T
<@2"
Ik>
`jAi
@}'>I
2D+aN
Tn)\~
d6#i
SRY)ig
.r o
cndB
2` 9
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PAV
+{Y(
{~iB
q=d@
j5.&
b${ <6
~wx
hq}-
G[C!
tL h]
%(9a
/w]cu
7gi[kY
U>~o
Cvk7
/"q6w
CA$E
97"E[:
Lkwr
:( p|.r
Z-H-
IYQ?
^HP_'[*X
wp:$F
j`"h
3C T
QADt
ZB8g
R^Lvn$
<MFV
JEkJ?
4h#n
=>q3;
xBA"
#mK
$&8;ROY
%(9&
<xvU
-pwZ
WWn`
J2mP
$<S^-o
444 \_oI(/N
#@ i
O"l?
>& b
6),v
n RU
>*!s
ww|FE?I
AR~cN
yVwh
g*KM
-zgH
RuntimeCompatibilityAttribute
ppG"
?JugT
WAc'
Jn53
)&{
o^El
.&~w
&ZbU
}B5Z
."CE
2 2ka
:vFH
444`444:444
s*d>5
a{+A
HYs%
CFJF
Q7Uqyy
)v_
t"l
BL d!
mxD$
444 LO_5opf
*c%W
3q{8
KJd
BPQ1
kBXg
3XP*
L\M1
{$}Y
B=<?
1xyD
cZI
f 8
4ofy*
O,m?
;F:?
;(!]
4+Y/(
~:~T
]Ka6
j^Y\
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hp'cj
xJ19
}lV*
xq(TN
y)v>
5t6/rB
n]]FP+
n09R)+
|$Xz
[2'g
S -Q}
sks'
?zp3
|4>
w>.m
/ 8n
-Gb;
X>rc20n
5L^-
roxj J
c`# =
e_!qiH
(|\S
|,*,s
qAu`
UlL5
>&rY
V]-#Rkl
p$vB
MV#
Mfh
/R@m
&|J"c(
tll2
:j?jX
.\yC
2-53#4=j
6V22$
W@v$
E 84
[HBO
^dN '
/ v*~^zq
m~wI
p~5&j
&V Us
444s444I444'444
&;@pG
uP'8
N~I0-
/EUD
SU]d
0PeF
m4x*
A(oa1 e8
v0pE
G4nW
-1$
'dzg
1nZGGj
j!)
;|p}
O$5VU;
vcSJo
nrPe
A-BV
B,'
D-dMC
?4P*
f5TV
AIsV
Q+@br
C?9eG
3M,s,
GQ>v
>z2u
muTGREDJXXR4FyaNJ79N6UioGpPBSTF
HHX[13F
K&e"
444}SUdy
./-;
#Blob
Iz2XwX
~"5M
m{&*.
lptyy)
&YE%}
CfC)
Z(v@
yry[
*n#7
ip+8
b$aDF&*f
f D
&HPvX=M
EGQne
"&(j
e<"O
/6YN-4S
HQn9
$l;T
{{<D
h.%}t
%kS@b6
3+!P
444 yxz1
]cybom
Oy.M
xd`a>
v&kL
444[444
(WEc
F@?_
h|<'!
&Z{1{S
5)0w
HV(hHB
/1j05
dh5B
444 444
Csl
+'YO"F
W>v
cIv[
AW*'
rgLZi9HPBzdsXXLe3RaPEpTyDcSeSoya
=Wzl
b{Jb
K$_3a
JTL
*6_c
C ;AGF6C
BRx}
#m>ee
bYw`
>vV)
YGzwH
H /y['
H>p
m4{
eR:]'
[ P*X
)k
/j86
8BGy
86|!
r :@
Lfq$
v2Lm
F?QG
D;%e
R(,U;7b
04_:
$}H
g*n1
?'Q4
.tU:
g4aV
=~Qo
} .m[n ]
?=|L
/Rgk
W}\_O
Khl%
@wR6.
mJNnq
B+{N>4
:O{C
,]s<
ZkW?
]]cu444'444 444
DG$%
^ADm
dft#
5L=P
!5\D
hK'"
BU w
LY,
|H|v
zsuJ
|v}b
9;bXKl;Y
c.`/
X@-Yb
R(~
pp%J3
T*n{
/|ef
Q9o/r
tBb8q
):}y
2&l4
}Z S
+Xs
#},:
}'}r
wDWJ
cW@z;
GO>C
oo1Y
iLN}s
P '0EX]
{VC{
vC=&9ta
"Nrt
RQE 6
z eC7
Ug4V
k G$`
u >x
v5ehv
lR#n(F
K%M V*
?$sW
BKF'
YXYp]j
Y,5@
A5o+
gonn
Ci_Kl
E:
Q5.=
V[q$
/)y4
1p7U
[Q[N
[v''
p\+~
O~h,
Uh/&
xLc
H_3(
n:jd
iIGg*]pm
{0|Z
cNck r
dF]
W v~P
*'P9
eu4kd
& \G
'F$u0
XG9
?Ft|
bK]fI
6eWRz
ada]
FCI(Q
jDlE
Ed@N
&$.J
-_]9
{8'
:b-M
zXkL
>wQ0
^(_H
t4mA'
;;LFua4
ATt
^FS;hwi
r:I=
wPD4
_"/N
@aV)M
4VB;
pvzp
MCeb
444)444 444
{}r5
IG`,
Tn`|
/4RP
* `:
-;S7
V /,g
6.`ZN
)YU`3D
H (G
AMHw
$#vO
RD,4
\9Hv
lY 0
To p
m#{$
9q{p
p T^_
] 1RvD
mscorlib
( ]@
i QQ 4
jCU
n[8`>
444H444
h] X
s\it
6/g2$V
0o;>
j#xB
mn$x@E
""DS
\'B\c]h
0t@y
5_6}
[xh`
^cN5
LML~
1G\0S
h5kGBB_
Ne:)
|DZf
+Rg 2u
#I4
VF'q
+= Y
1J'w
8[Ml
Fe t
Gr*&
oYZu
vL)(
lFTz
foZn
{-AI6
*C^(
O\5c
mE!j
*p+7
`='[ X
Oy};r
vXSRhq
&@DQ
'PD`
j=*s
[)?f
olnM
444 444!mhf
A$wr
'|]e
RLXC "2
_ a]
RuntimeTypeHandle
3ZpS
!(w G//
KV/^
A=9$D
[Bq[
|3ER*
zQ%&E
jv&
xF,%
.q?z
Xd_|L
st2
c9|WvQ
iIrEtuuVbPxQSYIOPAkhQP
92Uj,R
5EA>_
to 1
WF{u
]d A
ONWT
o~5Vh2
''*'4
W 8L
xAk
o9jLw
3?uh
f'`c
wTX^
k1CA
>:{5
} y,
56FOxfA
uLS?
P E 0
\f*{a
u4r.
MfF-w
B24I
"~R3)E
\_~C
M0bm
h4]q
#F`I_
R{,
-F"N
xb[U
`qR_
58zP
444#444G444{444
k6]#U$
dNx_
]$@Yq
(uP$
K-0~
a#WI
n<?<M
H (Tz
p>Y0
B$5-
M6CLC
C}TH
i}nxw
8l7b
Q$74jx
-T
JBTf
444v444a444J4442444
~"*
V8q6
a+-Ab!l
4sZ5
[2st
VES!
=b'#<
((V
c@1e
$e-f
<$Uj
N:beW
j%hd']A'O+Y;!
XzCgJ
{_T&y
^<6.
*Yx4
"tHv,
!Q-;
CUD{
zo`<
=Yh1
H^#L
JfL4
^@;{
/gN5
UTXk
!\_
2u'j/
,G=3
VjN_v QnE1
1p5vkv\q
TeU(
Qmtsm
`".V7
/>\-Wl
\Qp3
Z~Hp
r*mJL
7rF|$
sV/A
G;viW
kM3
2fI^
IvW&
N x!
)L0t<
X:3r
q' /
#'|Z
B?S2
h/=M
Tr$J
x3N|
G$'>
!This program cannot be run in DOS mode. $
d7N4
k_+N
DS )
I]+ CtG
#!Rs
3ozt
'{F4o
0 0 Z
{ M1
3<Rq
.2Vwa
r|~
444l444g444`444N444=444*444
Oj;&
s>e{
5qy
r]<@
k;y< r
njcw(
,> 3
v$1i
f<Q+
t#F0
z/F[Z
u@TV!~'
BJM
)8FA
-(?8
=<>`
rih
94ps
tN`=I
*M+g
J3z
NanR
pS;m
h}WL
/Hss
Jb F_rB
&d"n
]%ZB
_4)<
/ _
U9Wxu
6VCa5xBjdWSYzMqM6Oh1t
Ty`
9y\c
[!Jw5
mi)1
V .$H
(AMGw6}6
\bp. IyQA
*C13
u6L! rRG\\Q^
U7SK
^{(J
.o1^zU
Gax{
S+Ga
r+ G
O.k3D
lE \
h05B
WZl1&,K
u#C(
\-*
!-ZX
#Q&,
^bvZh
mHhwSg
2I&%
cF+pxgp/
d.-V
k\C.
^#/_
=$)<>
HO@*
e`J#` %
zor">
b[<L
W43T
_Y!r
}hND@
LyP%
+muJxj
^]i7444
nS&~
s_4
6J5Hp0
mLob_
nY^^<2
Li'gkDps
11wx
m5I
?IxP
Q~o
2;{S`-
~d5w>
iBfR
z=K7wd
&U*y
9EsK
[e/8
(9bJX
}V`>G
V?vp{
/JFh$
sy 3$
92|yHo4k*i
HR@l
zTjza
{&Em#
eTJ
rXdT
SH|u
7U 9|
`xq_+\
TW6<%
/+I1
<[ 5f
%~#=
=n y6';=
[zey
_Nc6y
444 ><H
Ms`Slt
40 D%
aht2n
=}:cv
l\m\P@t
kl*E
%HcB
EEk|
)ZX\
iN>Bn&
# }9
R{fi
7(uDM8ZQn
F*<$Wi
#0/d.
c"YgQ
.,ld
YCOt
:)A)X 2|
lx{h
B][
5 ~X
BY\O
f5 E
444g444 444
PyXz
*&@GT
(; j
O %A
_ vW
K"k<
o <Q
\>yrP
@ew`
x9[^
*I8M/
1_[_
6'A
.Z(<
#Y e
K"xDz
r{$z;
xsq[
%i-y
tW/;4
?,aw
V&.tN&
K,,"
Z[8`V
!GsV
-5y=M
1xbw
e!Q`
x1q@aQ
i`|md6W-
B"S'T
zG%
fd3s
G V b
@2kHNv
Vn[3
k'ORbn
$( &
?:kP
dLwv
b2={
_4aw
`9Y1
~UvMe\6
set_Key
*q.\
^25v
NJ0"
~tViN
|yd,
"Q(GF
@A#B
1O0*~
:!5f
?%sz2K}
IcmS<
e|Mw
-SyrB
-0z'
ypk$)/2S
L*K!
a8 l
/qV=
h0gM
pi ii,
?}*y
|]):
"H|h
"x}
FSW+
O4D
6|'Fqw
MethodInfo
o/D9B
tT'e
rVTX
L l1T}7
a+Ar
.]$
+ #
s~iW
CompilationRelaxationsAttribute
VR^$zrR
x1Sz
p+^yn
Rg]3
c S#
STaP444
`t`sV+
xFjb
M5{j
444o444(444
}#@;
9?/"[
%&d(
m5j&
XRaBc;
e9O{
*`1g
yHLH
Drl-/
/G@)W,&|
444e444"444
O A3
v>H -x
Yj6
r1eL
id7E0|
kyJPn6KaBqsbnE09X46LRiwlszng
I"/H
-3pOG1
Yg(
7>7`x
.#ub
'Ur?L/4
SSWd
-BQ{
DFV[444*444
FuyI
szPD
ex3
jcal
8OE.
Yr!E
M re
4,5j
LZ`bVk9Vo
cvsU[
Bu_S
nGO6
?!S
aNWnS
EO>3
6NhP
GW[VT
444'444HNMSm444
* 3V
5~u :
=<tt
'<b5A
`iE|
YZhp
%~3<[
^)IY
_N@S\
*vB
=m| (
vT;
1#J6
wM{Dj
4aPN {E&E
)[7.@
urv$:71
^^ha
o4}wd
}s;:=b4
W+bk
-V!
p+QZ[
i}Ku*
edu/
%ai3s
' )uB
[ oO-(
B kA\
wF)qu
g)}[
P ]4>
sk7K
)X-e
eB3w
mg Y_%Y$
^b(|
PQa{
p+X-pj
+mo6[
v`@j
Ps9Qx
XEuG
:yKm
\t4b
<D{S}
hcw9
oll8
ns7D
o=iL*
@pxK\R
aNS G
*5v'
AEnV
{IsF'
j{O,
$:J7
.S
?nyj
;`1V
US`r$!&
m!<
HS-
M[}a
{.!H
;0'8BG
%y'0d
*| f=
R2Yz
tLtM
7+rE
: Rc
qjMrU
444;444 444
!@<-
wW1i
8j41i
UrG?
x" 5=
v@eP
b3**d
`~lq_
*9kV
jX`]
tRVum
K "A
]O)J
/AEH
l}WJO
Uo!ZkZbo
>wgp
]PB.U
ed6 Y
mnx$*(2
_~v`
,Pu>D
N{yF0
"s{KK
!Kl8
_R~'8
YlA=%
sUpZs
S*bS
/YuX
d]KZ#
ZlKz
Fg Y}
);"-
46GMEH[
cxY$
X! U D
[@1jg
:\ld3
Ba;B
|E?-
z;{5De
|Rn!
&jtc
Y<!|
Y-;q7j
wRr |>
K2h7qp9RtioE7PFFoswGBHKmnGUaYu
:U_.LZ
& g
SD#G
wvV
F'L>
f$R1
Rk"\
>l)i
@ky&
Eca
z)i|
8cI2
y}>
4lNN
npe7
%z.O^!
#|RH#1
444N444&444
6SNzc
G%Q7
_~d_D
W#A/
E7!p
Sa(T
I568
QMQr
nA8v
m_4}
5_U{
{.Zq
STyu
Ev'd
+H:axJ
rkMl
E]J<
Ig
3}cWx
vxUC
8(<h
5![}
#$V
U 8il*x;
QR4G8
e?tTi
s R
W#8|
Show
Ui5
g y9
O (#G
)K jY
}F}!p
[>y
nb2c
:r$
@Y,J
BR"}+<
nwKoI
4Cg'
c BS
G<Rc
#)tL
b1Kw
RcYEqaJ
##VG
!1b
yaP3
|~_1
~bsV
b5:
}K(%
O&+}
X =$u.y
-9H=
Ftkl@
x~v*
x8
{'D
ES@nop
H` ||\
i'<N
=K$t
vjY+
*U2LL[
`e&PB
m O{
m`+cb
$ )7}#
>L9ix
=NH3#V
}* L
b$JZd
OKld
:r>$
(DNVr
NK8E
l2v_
4He9x
uXa6
Frn>V
i*Z,
ZMW=E
wm79n
444 \`o46;T
f9B66m
|PP}a
ToArray
M8sL
lR q0c
_)"qG#
|c>{
+'E0
1 6?Y
-hv+G
A^'NJ
z9,i
1,]
6cZn
jO#`%=
kw$?=,'
pI>/r
9r (
EFSm444%444 444
+:Vb/
"&W2
"J^7W
P]X#
@fs|
;00W
>S9}
m][o4
2+2+J6
ZxT9P
<l)
g3WOC
4442444 444
iz <
H\1_)
(cu}
5}5k
Qw$d
"1wNV
444q444*444
&<<g
7d^p
rKRo
-b
jp`q
Gu>L
Q`a1
"BJvy
bes K
E=tV
V 4Y
$*9r
hahE9
mkp!M
lQ+87
dD'F
3i6s
E1M(
$ 06
CCk)uA
F?4S
k5x'
#7)d!
d 7
+7mq
DTOwz
@Jo
E2'i
_,s,?
6K`P
X4,k
2HfY
qFn3H A
j^e9
444H444!444 444
444~444I444)444
IZoih
NT *
W(byCT
G9m?
^]g2444
=VfE
5&?w
IP.9
Mn"GR
'l,#R
8!:P%
u N
6">jBI
c#<~
XFCa
=y'<
#Uh0
feup
3<<cn
s8u`
dBB; H
O]S1
@%/$B&
un<"
SF b
m SD
cT F
&|xZu
3^em
5;1|0Un
a?Qw
C37%
IyRY
p7zm
KLf
qLVb
6\EL^
uY3_`w
F 2P\
BXYth-O
x+8C
IX.$
X/|
444 444
lOTxxJw5HG4o6jyD1VPVzKU2dqZK
(Mz0
V|H
U U?
Pv~(
[; @J
g/A M
.$85
4q7
MD`
D0y
1+lW
j A)
x%"v
a%_
J#i]
h2:X\
I[Tp
rv+l
!*`>
{X]9
a$KS
(:Jt
] ]N
C~V Pl
|F5t
4448444
T-BH
W0PH
r_zJE^
#ewwL
'E2F
rv+B
4Z87c7
(!Kc
)g|R
.pFF:[9
;F>oN
]|?
W[<lC
7 V&
C]A ,"H
444/444
?;V=+
rh|V
(H wr
V2bT
/gZp+zAQI
444 BCTy
Kvb;
Pb+r]awu
P{PX
Q95]
L4+@
xx9[
xAc>?
YChM
;1';o;F
%ssQv
/8yw)
:cej%
b"?w
C n
O =Z
aOR0
-T}1
i)Veq
FGlC
t9mW
7Z<BG
FGl?
gJ.:
.xm3
#JT;
9E?'&
%O!BM
:-D1
SUd862<
="^F|
*'vuc
op4,
pU2[
ZYqxC
Bcs}
CERg{
.b*A
dr4O~
UKtWXDO uFF
;^ps z
If0/
,7/f
`} R
SJV*uq_
&A 9
?~)
_fFm^]
nRm!
q f!q
g'n@
n>9i
y,*.s
?:=O[-
9qw|
;w -<7
'ay<
QD#fCI,d
1'U$
j"!wS%
&L
Dx.4
ug'u
<_sx
5@ A
wGZD
pzGZ
!G ke
(=IIz>
mL[W
6K k
gvJsi
Nhqu1
^QhZ
_ e
NgJ@2AT
$K8cX
t6Cj
(,Y#z
&19_t
'4D
X2gA
H-f^E
Xmn%
6tPZ
m(&c
9hX I
8V8*
7LpqTsq
%!j)
%*/WR
V_A5
`^ b
ok7:
h49 v
Jb7X
El9u
+FRbb
PXLY
xg0Y
z4s$
4443444
mEPV
sHL/
ym} 6
444p444)444
+b1W
nyT}
4443444
WG:RwAK
444b444 444
43M.
W0sm
9E0b
X"$z^H_
`A*Ls
wzC=
ht1z
`ja].
| I
W&q\n1
^Ry
O6o-
dPr@
1F4r
|-2}+?B:
2VQ-
1(&
;krn
Z0m w
Y.>U
Ei<J
&kQ,
C+,<
FY,
?G"L
By`c
!,]}L;<
:LF^
3two
Q3(V
0zhy
W&>A
!<|1
%>ud+]JG
R]`=W
G}jy
FWn Q\
9Q#:oj
@QV/
8SMc|wA-
] ] \
o ;>I
PQ` CCO
J8)3|
#1pp/
F]Jj'eC
dND
E:&Ql
9 <_X
l a7(
H#eM
gLRX
[\w
C;rw
1-g(
qPJ0
pPpk
$v/HKG
Pd2c]
\oS;T
@,y;
oC4!>
ka.c
aJ" D
}u[
5vDr
^S>w
<jn4`
r>nf
!dJI
4441444
v{hFm>{
q8
set_IV
m7Jx
EkdO
#0 q
3h6
;*VQ
&ZB2
^ Wn
GxV>
j1@I
Z@{y
Qhf
R,\^m
N8d
'^9eI[
tojZT
$"}5Q
b'D;x
=mmwp
hQLU2
JZ@I
', '
5a}#
u x8
gJ26!
<$YB
_g_V
eRyl
z{[/
fgi)ylu*
P&M{
r"7Q
JJM@
fOG.%
"\._
444;`^c
yceAP1
/t=_5
vryw
ocUJ6
M iXe
=K&7
kX I
qkg>3
"` /
uG}+
RPKx
[G~*
>9y
rf5 }
~k J<
v5
L[G +7Q
]M(5z
r8%'
)uR"
2bxR
F &+7
cbQ,
DZ^i
'0]Z{
bB?F
I=Y{
% Ee-
jZ.B
(cd SY
f/
~ch[b!t
C0}Nr
2P-m
RMyJ
oR zA|T
ZUap
h%-M0
n{mc
99M?0
X3Z%
X9Qc
SO+
7q>i
VJ<G
Rl7_
Mkh(paa
YFM
P^B%
aq.0
g7VI
){&W2/
@ Wd
mNQtx
=\- X
I8kE
M},i
.3nG
hXdE
<L|(
>zc>
Q; b
444e444$444 444
{d5Rh)PUj~
D_\kd7$ZW
:~_$Z
][O"
eYxpc
NpuY
M 'f
g` h
*exH
f=)p
>(L EXB
DZ%Q
N= 7{
Mod}
NEGT
y=EeEm
'm2s
B `r
1`:3
<(H)_
B\ET~}f
AH{l
i-NG
R<nx
?>rQw
]#F~e
s'^Y
T$Iu
c(aQ
X#Gb
Q57^
r.%m-
~`gF
`,lv
KP<7
80 C
tNy*
I58Fq
ivB-
Uq.@
d^\t
Oz"}
QTO'
rJ)j]
ua wj
Z~iz
-uv2
"Y$zA
r#'h]
z2~
RNc#PHB
,@7|
N'qpM
y taOaL
n]d4oU
!q^^
GK~i?0
IKK_
B`t=
qBRK
a]i%
U2'L
{=A
D |og
d4Pz
p|wx
%D6\
^ O
0s
tM%0
F0R>i
b\?z
}{fL
\WJ]
v=H*
'F['5Q
re[Sb
v+7Y
}\%5
[ &P
$ U5
B6Uq[
O\i!8|2^
dp:d
?Vx
gm:/mhN\
H%?i
_K0K
RLNS
7mF
[R*ve
N-t3]#y2
*<Wp
Yh/aL
U<$
3KU nU
Oqr:
OH|r
qCJ<
io,#
qNv?
OU#?
48+~
9 p+
|qi
VT_Z444 444 444
P"D8
!aEa
kC{':w
<',Kf
s.$2
444R444$444 444
EdJDZ
k2`wN
qt?g
8eT#
0,he
W|Hm
Id>v{W
#4
JCF'""-
bnJAi
Y{ic
4448444
-oR*
pH*s
KlV3~/L
v[R]r
x qhQh
Xah%
(Ux
K&e_t
dBI< '
S?OV'
Jr'e#v
ct$;
?k[I*
Z+MN
V X
@I*Aka
Q:p4
A}pR
{xpq
dfu(05L
VK
nTy-
`,iNx
3}7R
C Nf
N)UCK
_68uO
dxRV
] fz
\*|,|
444:444
^o!&
p Za
=76j2
q_Nf
r(^v
J.1[q
-g"d
6 flU
ZX:J
$6 ~
)^x0
wYVV
Z\p#
gT/b,K
LLR [p
4KdR#
E+Bw
Py[)cJ
V^G{
'"Q2
6G_@>
\jG>
1S6i
u609
H<_x
9v9bNGbSLnrqcKqX1mDiSzGEIr3bF
J?WKYH@V
NrV[@,
MSdH
[Z?x
UoSU*
)kY# <b
.NQx
6_[aG
67E HDQm
hc3R
4lKMcruYdrvGNQkM0vJH0IRTfla6oeQ
EwJ}l
ZP`
tm7)
qsPFD
3qKX
@r 8
a0MJO
\<nL
[E P
-'hQ
|SvI>d
9qX$Y
POQSQP[
n*J F
pe76Tf
d7YG
& |^
LLyf
f`W!
D<<x K
w7^U+
gjwI
"q<y
H0s{
{oMt
d$IE]
l)`H
JbE`#fc
#GUID
'7FvNb
j$UPrV
YJ#tTZ$
yL0'
pfOS8V5Npm6qj610TZjpRC
V IJf
)OA$+
uU3lS>
D+\k
DmA[
ht~U
K?&oH
12OUi
1cR"
4$N_
hmY\
Wzonvl.
WIc|
O`5?/
==nf
444 c]P
C/#I
*-ExYG
{J<8Z5^
\ANm
h?)
TXSnT<
R >2
_JKn
DG0GX
"y5p '
c?P)]V
!e34NbX8CUgZRVraF0fM5ak2M81edviFZK
'3>-
3LLK%
VCnVo
444R444&444
,wga
T.SbQxk
ZmhVY
Kfhi^n
b|]
"wRqzyx
T7._M}
@eWG
pHFF
0pro=
AZ\ ;),
q" a
4G)o{
UQ'0ks
`[4w
+JN
v|u
444 pprt
{9jVAL
&t6"
isuH
uJRWe5
$btP
.E\% /
*[ m
udV^uN
|Q)C
:Brp
;bW_b
gAa
iF90
Vf/)
W5?l
b2@it
0kqT^
iy;uj
UM!n
W8*Of
m]Z
jIaI%
j"*zu
n{FoD
I3[44\
v+*Q
%t |
`z/P
Cnf7(:
2-5t;9:
i$q|[KN
f J\
n-
!8QN
kpB/
u~J
# )
j=S^
@K 0O
aQ 9r
$+[3R
1YbR
C`h^
.J W
$/`Y
:81r6
|#X*5p
Y\nnJNa-444
%mevj
8-ZH
p}^m
5Gt42
444'444
6nl\2B
y#"iY_V
R"B|
b/'3
Hqx|
BQj(
`dg
*Af^
b( :
+a<]
DTLTC
z1e}
}hb
pFN*
,t/xV
fo?a
_pp?
/;VG
DH 7LV
(OUu
2 )
9Ot=r
R:e,
" v~
2%um
MCY
%;.>k
@@/1
7O[R
*Nb.
:Ykk
8f]`
ug/h,6?
NuiV
Y5
?0D|
{x+5Qt9c
5j8_
s&s7
<% T<>
^)hu
6/TXe
^uRu
e rvK
^z' a
K:Sv
Ud4^
U6:+g
a*qi
G_5RBD&
444h444
O}c
G)A_
K(eVv
m xo
1pI0x
Pb :
`-6g
z yc
$xKy
yukN
KxNX[
(d17
Y G;s
_n3*
4$DMsq:
5 ;`
N [+
})+{
<e]
2)<u
'"td
+[.P
=T1:
=-If
o]2Fy
sMNo
SY)
hK0>
i+cGK'_
XJI`g
|S:o
!>tl.
GlC6
06 8
2)UpK
i"Q8w
z>]R
@0<R
e9^R1|
ak^@
Awtf
j/h
IWk9>\h
yd"
bJdw,
f "h
ijytLoSQ5HQZEQqn3YNpgtLqZywuC
kK1:
" -a
6#L4.^
RYxpUw
XP/v2
Pv
N]ufF
ZC_;L
o0N!
sdbv
I=y
i|A^.K
FXvE
48H3
n5Bd
.<tY
Gr{-v
R~r]
nw91 `
}EIh
%f}D
wQ)
.<ts
{Q'7T
GDUz
? 0dJUA
:j^oN
)'Es
yT?3jc5
<W1 C
d8~L
iFri^^$
2rPa
bD2;
[L>)
5?<G
ORR
UGQr
K9bYRl
1V *
CYD=
?@Ol444
gx|&I
yQpn
!XR6j
<^;{
:`J\
_}xu
H&&*
+^@}2mgc
i%>U
;`?_
J o:
&n~?
&]/e
wN9,C
G0T^Qe_
"BN
'[%-5
45D88:H
:"|_
U=So
iCiQ
t1%5
Z'JD/'U
?R}O
J bN
DGBI
\wcFh
wCAu
A G&
t\95WJ
^kM]}
]V1<
LZ>L*
]$N n
dlaV
~5-hE
75\5/
dyzv
4)YE?
FldvD
o<MD
88F
+`D?>-
,*9P
<v)m dn{
>[=
kcH[
Pb5V
444-444
wwb%
[]g`444 444 444
IrNTC
|>j0
`O'S
JNcY444
tb 8
u$'(
uY#K=
oF}G
cY '*
IHiL
f?6qO|
A47N
dBm9+3#
wpC8
Uf~&d
hV81
Qw}a]
444M444
*0 v
8{FzC
1EF^
e;@}I
'!US%
wu j
# a9
v_Xl
HhWq
bY(du
9h,
!&]Q
D#-
CLaC2
6AKtZS4OlgriQ3fHQb6wQW3zwj3n
Du(|
kT f
qcZmk
!14t*
$09=
3v~C
I6$4qw
vDm5
4447444
E5G7j
]AKP
#N$%
9;;
444X444
EFS CIe
lC2S
'0c})$
;0.e
aNNn
EHGX
)Dqg
l7Riq
6}_r9
_C1
cer?F@D
o{~k
r$GJ
G452`
sW9x
oYm>
ZU=
89JkQdbQ1CYMSOTPnRBZ
W*bYt
~lYE
;o}KB}
IerH
j])f-$L/7
C3Fd
&+VJ
GU*`
?Qy
F~4pz
=?h4
v 2;8k'QjT`
9c|@
q $aOK
[d S
%HW_
/3F4 $;
m q
z3-MZ
:wBjSo
a"*G
UYuN-
vQaQ
Ml8
?2qF2
9mp c y3
F8:VP]UQ
<5&00#
L:w'
;L?y
6R] j$(I
bI0!u
8>cQ##4
dP
)qnJRX~b?
e\J'l
U 8G
i-xJ*c
mPGF|
>C#&
n|~+
aO^7
P mr
2SC"
vI$
8y~f
AppDomain
bi#a
8NCF
wVnt
T+|9
' -Y3
LXVz
p<#-
5Q]~
NEd^
(`Uq
]!4z
]4HM
get_Assembly
n9s<l
mL&{^S;
)3)%
H M$
#%$p
oK4TB/E
K`a\=
ZROS
rk=I
+&l
}@}k{?
&Fnyp~< .
Dr=R
X^1s
:~Y)
M>5)
' s[S9
0@PG)
bossemmy
7jRX
VT[j
4'"wF
S:}2
z0:O
444P444%444
C5cyQuf
\9u:0
H!tj
33gZA
7]ib`{
C^c)
Ay$dMZ
Y (y
o"PU
!m0"
OpVm_
`4T^#lpxf
L?l[W
H+Je
X@k
"%BCy
yPO2Mv
v3.v
O}% ;
Os\
jIS
:3#h
o)PAi6er
444 FFS
a@=
Q@:f]
eo,x
26Nw
(A=}
444>444
am N
444 TXmR!&C
deq?
%fP#
Z3O82
A?ZG
8zH|
]3h"B
r>=X
XJaKk
(X^\
OHMA444
'Y#T1
wCR>G
8b!
vlkT
ujK<^
Type
PsnF0AA]#
B\ls,!
2Akh62mkP0FBvapHh6dLZPoUHEHn28
e#y7
YF-"W
Tt4#M
:J|E
dh'0
op_LessThan
Z\I5}
r QL
444@444
|Zbqi
"Ni:
Y+BR
N3r<
%f\
/MR-
SGmc
NG r
y0aA~y5
)*.a
ttCb@J
Z z5$
K[l$
]jqf
[Zc-444
1PwM
blRY`6
Hl I
9taD@
U!.X
'i+qsB
n i-
Kd8k
IGPD
GdL8d
w(yN
%_:9
3'^|
Q$-0K
444m444(444 444
IVV
+c,F
JmAQ
TJPL
c.:L
,WXE
h 5jH9
xvn<
cTxO
i,65
mIEb
kaG^
SVo/XT`YCG]
+2W&S
R>afQ
7Vue
C}.$j
OM(&
T1 x
34lh@
7N&D
)9VoY
IAVN
=$gZ
: 6
|p<1a
1>6C}
B9BtW
Bp< C(
ihqS
4448CBJ
.q}Iz
AqP7
|XL<
r(UY$/
$,C.
1x!?|
P|]H
FV n'
Y\g(toa
`P\Q
'GzXNz
uA+i
%8u#
G </
!mWf
"g:Lq
kSD5Qm
t@ ]
[~m0p
-5u*
vqs
#m*;
grXs
L PGj-
5D`gE~
'z?$
6<?|
i:Ql
F91
V'l,
vE=>
<H\[
#dXEZ?
j35JAg8N7IS6eREDJqmX2wYbgOWedFlI
>,U=
M(4
|1Kv
&1gq
Is<H
444:444v444
W+ BO^!
! '&
SLC^yy
\&q$x
3r$$
T\Gb
(Hj^
e)4To
`:ts
p3^~H
Ye~9
444O444&444 444
W)>?kh
NF t
_ SC
h>vST
~ 1Qo
SkipVerification
B)Z2
i =
EhYy
7m^*
8}}=
$eC\9
=~dy
z,h2P5
0;Jf
Z20
jn2'c
XE8.T
ZrAR
4444[WN
xD[U
: <u
@*(I`W
q lbt5Zh
YY08m
Ac Y
X37/Ig
/]ow6xb
gMhf
H \^
*2qf6W
x&%AP
}o P
Eas\
8]3vg
ex<1
:xSss
.']Vz
>q&@@
=wj_
9$]G
rC<:c
r{\T
KOf"9>Y
+P y
u*=zV
IZzi
YT1a
444j444#444
_Z$`V
}Z
:.Y
=]NY
.68Yy#
}K>
1%"P$i
$th,'vn
Vmq*H
d' [
P[x6
^5Ik*
1Fh`
_cwA
}3YS"
V {Le
Z: IN
m)0M
F$|6
oP `
u zJd
`.rsrc
Z9UR.
JKeX)
`>HC
4"E/A
w48Q
RzPcV2
s**)c
Zb7t}
"W y[3
+@m
\{+p
g$I+
V^l/
]?IW]
Y4Y=
42dsx
(uK!:`
YgTm
wG&cd{
4V6q{
R XcU
444|444S4441444
K>l7
nWVv
1$Cq
`:Y]
/uKY
R[oJ
lmsL444
N9<t
a._-
a9Bt~
;n <d
>81(
CX($
|HdE{Vz
5j #
YF4\V;
H.Cp
^MdXl
qHPXIE!gO
tfj%"
+EMc
Of /
N]C3l
O{ :
x|A^
%.-"S
7W_VM
Htuc
~3o-
qVsVCdVDRUYZCcRX37ERem13z60YUYxJ
dF{L5f
T+[!
444 ROW
dO![
G@E}t
?0neGe
bBSbS
zQE!
i+h\
'uCN
4446444 444
*-5;
eH@%l_
!{ZW
0?u
YLg;
K 5x
6%'}
* p!
n^)f9
eq ,
\Lc9
rc%
cU'JA
p3T:
o]K8
_J}%q
h-@h
6hR|
e:Yi
epC~
IZJYS
/6x>O
mh3D1DQZ88miInXUJQpGPFt7ktv
;{r
s- ]a
R7e$Xr^
If9py
]iJa?1
pxQmxBzc0gQS4d2TeSCKJZKc
75"L
49:
J?GNq
9(5aA
==I}
?K? x
XYq<
N,;(<
-PAI
I~q{#
fi2j
<|&w
&Eq4
;~Gn
6:yB
gfFo
ge bk
<w]a
ehyo
#Jl
_ZWk"
&i>h
q'El
y?B[
_;7:
|7YE; jB]
] <r1
|: B
S` O
x5g&
#_DC
A:+|
tOap
2g!$.
8PYY>X
gyZ>
U<8U
:m!n!yt
QHT.
hS -
qwAdsA
\2%;0
h,%
y!Ko
N,.
)Fe+
PpqP)V~
:J57(p
Nye
Z-VB
XCg2
1HKo
rc*|
TTd?8:Ow::K
SR#E
7)0@w
B_FM
AUt
ql f
@@6QpT
#mf>iD
Ix\--XiD
QR-x I
Vx)@G
].2p
@Ahn
M2F%<BC
&3dt
zs))oB
l-"hMMl
Pl n?
K4n
QUs
444/444 444
,5hl
pkG=
2/| 2
*32/j
B'
,@??
p8lI
h{tnI
[AQJ
9Hg@
V&+`!MM
6 R*)
IN;:GR
IA^.'
(Wbv
. qP
\pKoQ]
u;.m
h!S9
]z\[
KD{j
?#HZ%Yl
v{q/
1gJS
l*lBzn
5+F8
Ov+nX
PhV6
E ?9
\yP0
g-mx
d@0-
PU*=
) z}
nMBx
$ZtEngnW8FkhgxYBGeuCNSD82EfGzl20iqukK
XgW
:e^
(TBU
: jP
*c`il
h`u=
$z>!/
KSCm
0MWx~]
rNiA
?tlT
[Letq)
'}u E<
@|c8
-\`#
7SYZSs~
[bho
%R^D
7Ys-
L3]l
cG} /Mbf&
H9 M
H@X,o2
-<-q
I'>S
?V~3
s[NS
Kc+X
%6JS
<;Jk444#444 444
4g5R
v+Vx
#Strings
J _C
m~^`
V;NO
H 1_g,m
oRgo*W
dQ"T
<e3y
B$sE
oJCy
iis
4tNd
'rq+
*Y0Hg
L>?brxS
JIz !
rMUB
zl@k.
DZ~Jp
O> C
52m1rB
38]G*
G(V=
WAcPMua
^ -R
5S$,
.=f?I
444%444);?T1MRhM18X
7k[V]x
O;r&
]5]
4443PNJtYVQ
KZflQ(
+wO&F
NW[C
xE0Q a3
h+M&a
Rk|';
/-}^
}K1JZ
#mhAL6
i&&N
M)oW
X6x
$=bV
.I7r?
uV8|]
!q?v
=E1^
^;!j
)-vl
dI>M
444a444
8 :6u
KV+(C
21KT,uP
9KcN
<|e"
i[=?
U n\
WOb}
q[x[z
1zCc
"1W#
Sq34"$
GRaA
P)u#
sh'%
I?A>
)KKS
cl=t
5P\]{+eLY_[AVX
xF:<
6l<,
No 1uBn#
3PHOfW20m52Ik1qx2952E
s7P^G7
=}>Q
1?mK
Eo8v
`ZY\
Kob
R:v;l3A*
"2$@
s_e^>
4x=:
QUus 5
%-3"d
ouVG
Nln(
&KUMXCq7EPuGxOjTqcs5kBlp1Gajs4CEUogeYwy
9"{
R}u,?
d 3T
|hfqE
'cE\{
y?p-/
p'8F_
6t_ZR
l>OjtY
p'tg
w?I#
l2 {
;"1W_
Hk5;
=Sus
;(Q@Q
+#TxZr~
G+*5
q-k (
( MH
Zwpy
Qc7R?Ng=
3H7\
;$~?$
~nD$e
eRc"
VPYf
= ^om)I%
H^)W
'6T590JfnCeYepLJsfJF2hV2IwVPsL79qmqAAoiF
yTdi
B{#_
BX m!
bdQRyOVDDFXaUeZOOJ9dE9Ci4Mf
r/[d
;Wk?+
6Cb}
AAr$
7. =)
^WJT?G{
8Vh
ofk|
]#JJ
bZI~
GRsjY
L3,.
a`-8^C9X
F I
i(\=
Y!57^
Oqo
D,UNh
3dC1'
4v2x7woLsydLXfxVBOFUkfI2pg
<'Q^L
l8l+
O !o
{ ?9V
#/AP
YG20
4g6yq`
(ga
*kS}
K;:Z
56!vh
=RrU
444Y
9i hvI
11<~|k@
=? Lb
3nB<
,ZWrw,T
\fGe
/3G`
ykpHS|Hy
?jfO=zc
*vw+
eafD
znqq/x
#x[r|
8)Jw
AM#4
2WXz
|=^"r
lbgZ
0fi9?
FBkF(
|8q
hB Na9
7j3$
! f`
xmzB5_
{dV9
}VE
w9}mL
a O/t7
#?_^
Olh''
BADEpot
X]k*
'P='
f]Y9&zS
&%(^
z5}`
DdK9
&QxQ
\0tmB
VN@
g na
Mc&V
"B|Z
9Lvb
/[0y8
!&:G|
;Sv>
&.x8
vY-n
Js4b
XWI9
> VK
tvXOi_
0{zk
CwyD
s:<y
68L
K2F?7G"
}[8i
da~.p
XGST<9
m7m-
u]_T
VqWy
RBTe_'bP
ORb.444
Zq)
eW/*bu
Lv7r
C z1x
M [e
l"~"
yjN r
D+Wvy>a.
vZ[S
\[C;10
J#' Hd
&^<oD
CsAG
B1,
P_^*
6HMBT=5
a!l!
}zZ-Y]
hZh$
K=4F
d |7
\K2(O
WTv-
Ml!c
Lv7/
/u8^
rLtA
(k#f
q{$m
FibxU
#Rn-
+OF5
_a7@
M e
@eHSH
{)U
]A %,
=^<BRF
=?SE444
444;444
S Rd
&3oW
&H>,
@O 'w
aL'
[g]_A=G
>;$h
t-W52
0"[>
XoU
\D>xl
AOA
"aa~
@I _
9r&Z=
\u }>}
Ku&}
L| 4 ~
1"=8
ud[\I{
ZI c
)1@lX
oD<s
tc6Y,
<-l3&M1-N
mj<T
Z ^Q
2y?F9T
,}%e
GdKYrK
3dMd
B g;=
4449444
Y"`s
T, ~<
d ;'
tC!F
RsE3
/h$ 9
I#?\)Y
IA7m
]0@&
~GJu{N
pE*;
"Xj~
2qDX
1 Q4
r2K
v6\|
XJbD1
JM]Z444
YOG9
`u_;
K^`yJZj
zJvn
PUDWsBjd
67_L
qR_z BZ
jL5S0pPGuMoRyjkjeHm8Ntl
Y IX3
e!-4=n
)X.O
x5=~s
|Wq;
:OGP
"m O.MS(
liH}a
B"Wr
vq I
L'MC#
4&JAL
=l@x
AM d
w[quhgE
(z*e
OF>!
GXrb
$ 3
+ben+,~
J02ja
$[ _
Vfq
28+3
~S.2H
s}"JN
6D+ 'A
"BA.
~.p,
Krn3
p"} )
<JI*
,G:)-
YFg^f
axh. =
D:XU
CnI5%5
B;@"
p:A<
j~hKy
$/[y
ur ?
C.C\0
:B/f`
|+y|
~n|a
w<sT-
JAJ`
Wvtk
!=yI
@8:UQ@
d io
x@<~
Vsn
_pg_
9l; -:n
L wJ
444u4448444
4440444
NdcQ
8b)Ev
#'j *
#_+AS
7P!
rgAh
,0L*
YWt;
G0a
{V=HQ
\(O]
zb)
%8R+
FOP:6
!/r~
]mw5
System.Security.Cryptography
& 9t
h 8g
K/nK
1H5m
'+=e-->
{we`
8pF
,o.^_
7,]P
l( 9j1
0yIu9r)
C*pGZ@.
,kZl
. 6O\
FN\y^
i- !
3[ysQ
Z \N
g6J H
o?"\
V3l<
yA$
@hju
/j]0
"NSdk
QIhLL
W^1?
WScy
-4SaJE8
.-"a
K}:o
CD{+
xQh)
&Tmq
}<C
;*7Q
@4E
3e}!D
.ctor
cEp}S
+>id
b'>N
LMw]!&
mscoree.dll
#^2
iEA>
y!}d,D~w
%@9Z_l
sxh!IE
;!<s
oMuM
LFm~
v!Z!
)t|*
SKT |
PC^NAm
"C^0
M`DMW
&eg0h
S.Zj
L(7
J$u(
edu
`e r
{yJq
,1u
Lb48
,X V
]t8&
WYb}
[jG|
Q,~
9#99
k9oq
*hRML4)
%lw>C$>=;+
kP|r<
\;XL `
%7FUcd8)
U/GO
q'?]
Mq;&Q
^0ZR$+
WUgk
QX^Z
M(a$
L3"zm
6i;A
B{ley|$Ze@
@.reloc
b y#
as?'X
~. ,%!
YoI<
fNV\8k
a'ow
D7g&
#caHKMig8XP831sy0lVUL7L6RR1ZfIzKEDZC
V=e )
^k8"CP
WVa @BSw
h~^
7IEKzoIR3lnXNCeeELesQXXM
9M$)
{ ;oP
~IJ
icCW
?z9rVn
iD=s
Y$+O
O;Llm
xx%w&
lngVm
O_
W)Tv
(AI!
tRHd
BAL2444
zU6[
7|p
9)Vg
444h444!444
NlZR
[ t@P
)(W2t
l [>Z7
}AodE@
$bpMyYgC1ul4wzUWX9IkbxAEiltANtAGAfzXv
N&2i
`60:
-5B4
0RD}
(LQ#
z 7Eb
>7!,|
444@444
Ev< %
:\+^
V}{F
FSL^M
\7&~
*^o)Q
$11I-
Gi5!oG
> ]UyQ
3q7 h
(w-6ca
=>G><;D
Md8^
p( q
444<444
89eX
RL;u-
ii?a
o#e
0O=tF
)znA
L;53
%cdC
; |P
4Ge/5A)dA
PSc&<
!kg.
Ed=sH
hAkK=
K8WJ
Dk.H
h/\@:
444*444>444McbdhWWZ
(1jv
bLxy3=d
^qp>'
-HJq
s4D#
3IH+F[
NMWS
HPXX-aX
F}K`
%uv^_
Ci :d
A;J\
^V,
X)$
Ska[I
q`Ewn
qN[/
v( ?1
5Aj4
k-+z
?)sGa<
Ctbg
^*^E
LV4O
DZfF
{@D
gu e
&a z
?APv307*444
kemyT
rn_k,
o`"hU
"egH
VWlu
i$!:
p 0o
)wbX
!Oru
MO[9
vFE|4s
"N(]Uh
rCB(
vu9n
'A ?|8
,Tj~]E
oNl
4Bv'
4GUb
vJB=y
gS,p
wC0N1,i1
;V~h0
jjv!+*@
%6XAtMQKi3CWIJ6hG6no5TuQ5yCUuM5hAm837J
~t6-
866>
P0?F+Q+*
j@bvaV
1Tbi
$?}~
*m&S
r/
%B8Yu
4"w0
kE5;
pKw
6|$2
so-3
9Zqub
22P@
vw|G444
9)kd
R^@fb
.ND6
n++'O|
y%CR
} d0
j3mdD
+xO_u2
GDT@
8#U*
k}XfAcq
$a=?
)*.DF
KNFe
7kI/
M:ZksD
j'xxj =
\f>n
7C!6b3
f( M
gdeu
rSW.
!r%"
_&u#
Naz{
$>C+
eE2H(
A|Z#s
i[pH
H@^@
:v,a
#2M(<
2Q47
8 &
2!B#
/VJA
/9D <|G&
444+444 444
-">U
~#CsB/
k-_e
\Ix!c
44/b
i#@kx
WT/5
pI?)a`
eixQ$$2
!w/PW
(X8
PA5mt
8_Ka
coY
6{b\D
AC+# |"
_[hW
8RDO
7_yJ
/K4@
D6tE,
+h:
p~jk
D8 '
>;**
444-RPQLB:4
c`Od
0)pqt@
aK&@
>`}w_
bw H
vj)1
8VU.
tYT}
WUk{8&<D
|POF!v$wD
"u ;
-9VEw
P#5U
&-Bo
uJ@N
E<ew`$
fSmR
S0J6
F+`
]CDh
{z~^
- Z6<h
O4t3
6ei|
7b\2u<
_qW_8
DK;\
$ |h
gUJ`
'P9i
C$u2
Ctjr
5`}
w:)$
RI/n
$XcEG
uXS}
C{,gvm
=_[B4t
&>#Y
qEj
~WJ|
o@&{
_2t
xe@D
LL4|
!G5Ff
\mtxo
aP n
'yk%
>eZuyG
7*/lL
CW z
]#/R
5g3A
IC]n
AS$.
RiU
.><j?
.V!t
vW@)2P
w)8;x/I
oG);
- EI
.sC[
uy Q
%/B?_
LwaMPcDNY8wGNcFGmN0FyMdd8UpjJuEx
-Vk.@
X$V
2qF#
;GBcS]
444 444
fRF1
vs=Hk
S[Z-q~y
S}q|
}XT_
"jPze
|2-#
1-x-
+E![n
pdFu(
=/0#P!m$MZ
+.
=.J&X
:;WI
-fD(
MZS;88
C 1!:j2
9ty29/
BOpTb
; %GZ
B[i.
`>UQ
{boi'+Y4]
tYx<
^7wb
=)9
d2km
}%qO
*)IJ
~FUQWl
a,/e
CGiKl
} 2iC
Iz44
hEBm
9+oPj
YrEw
#7Mz
Vz(8
B Q^L
{&dr
6Fawq
h4~LI
f0QJ
Xh<c4^@Y`
Rf |
1BdJtG3
s3Th
Q!E^
+,3
[5?j
ze\k
.3G MPdQ*%2
5= Y
CK(Vu
2,,$
ym(F
ZxNr
ume?@`
*}K7
|]H+
/Vi[
j3I5
..7j
p9!H
R bc
r/)G
>vlZ
&'Wt
sz<K
444q444'444 444
78GS58H
\p`,
! #w
S}"v\q
|<3U
i6|tjq
PO){)
zw@}
]D^\1
/>/{
8 R/?
)[IG#5
D.!6
(QV3-DM:
A ~
/g_S
7T.t
;Z!)(
`YI@L
IDN
(.D>S|
/5>Y *k
a+c_
O@/UA
G=yC
4wi"N
l00H
7(xS
t&A
IfT4 B
`^fEqm^
BHP/
Lj:.
Wiq+\C
a &l
444^444!444
bt>v+
ya W
gDRxR
5$MZ
\n[w
@AZF
L&j/
b1JD[V
$6]{r
G>U
Bv!U4A
piD|\
c.^e
gT:J
3 g^\z
DM L3+
444PBG]
})kLJ
LqY
,0o1r
\< @
I.P7T
h# +K
5>gn
s5QZ
L *L
k>wq
KV=
pW|-
oaR)
CPe~
Vj `06
ji{Qw
W.L[
j\~v
b/Kp>
~t+;
~Av!&
b2C;
-FYI
YpFe
9p{\
lr# Q
GxFjo
him
fq+w
444b444#444
5p3`
VyAt
A:w}c/
F[!N
?,kch[
YUrJ:-
^rD@
\D5F$J
4(B*
UXB~
it3N
{%qb
bllQ
}]Id
)k+t
-Q}5
v9}J%
*"BMc
s(9o
U}Z
}*%$M
<(iV
?ZO
,~)p
9L ,az
:UWP
fAQh|
hf_a
_ cr
-')1
`n_gF<
j.9.
(s8<
s~hf
%@9n
aEpu
e1Da
lU*JG
P Rw
klzNZQ@
;B='l
tVP >
A%WR8
zuEi
&n>)
=Lj;
4444444
r9F<
Dp`D6
QJ&C
y;Li
m { 8 K(
']}J
0)!v
<"-8
%)8N
rKA Q
Q,~U
;zZL
EXHY
e;,cVw
I4 w
Qn~TH
9_Pl\
|g:W"l
:KtR
\T][
;1P4C
5g"-
xpvr
DhfT
|^SLi
Zbt
$ xE6
t@Do
|sS}T
G[K e5K[LG
9YT!
,w-"Z
.uty
#q!SU
QJ<=
JLf
:g-I
t\+4
HH#
^G{u
,`Hu{k
e.8
tPdF
2-Hk
p0KZMW
Oqd[b
%52x
444s4440444
-eo]
c6:
Y1xW
$a`B
)jTb
Ft<y
%^,0:
444G444
9Y$Ld
ns[
m9O;w
K y
yqgV
+t|r~
gfQR
Bi[[
WFA-
;~~N
, B,V
&#
/6ix
MZ.g{
Gl[h
+DCU
xe$L
444*444I444Y444C444+444
(])ut
g=3O
m":
oW,.
2<_
gdOl
+lT
/2p0^
m:_a\
D%AJ
;S-G
p@"Q
X3^hnb
w4!'^
[=<M@
?z?9pB
G.'j
K&.YS
x8Bb
@B1LvP
W }
mjy%+
K`?&$G
Xs4
#Nyv'
(5l_
udvj
CsA4
Tn5unv
Ig I ,;:
C 0/
a\QNZ
-jJH
GIp,
d,fG)!
*^(Z
.V[@
vWY:
8:=!O
CT/`
IS*>
{PNM
z55m^
A<,LU/|6
/p 6V j~e
Rtp~
j&F7
/XKQ9
!JXA#
V>spZ
^/-W2
er[
.p V
A$X)
v=\
pv"Y
VMr'[
%u@S
FxXE
w!=
kQKL
`gvV
x K?
D|Y"
M%*5
M$"F
B\Y
l *
Vd[6
3k@J
J3V%-X
tfNq
BiRA
cI[u:/:
(+62
I9zsm
- P;Fh<
PhO2
[KP2
{PN.
hJ\u
"<H&
1bC*?
WcVV
vAzJ
NYK/u
444%444;VUZfHGL
4448444 444
o54]"$
_uzL|7
\%uT{
J~j71v.
a~eR
$aJps
M_:g
7z")Q<,
WIMCJ:
7[&O
o^mX
$.N2_
I8 Ar
A_}Pc
@^ B
B1QSA
0B<X&
|R78
"\RD
w*@u
bk$vD$
&YDq
6xo[
444$4444444?4442444
4P47
|.8h
rS*:u
tR[&
Y$H^
#hJ.
&:>W
MX1YI
t{HW
6aXP
lo)N
/ eT
Y=9:
X-;J
B`bG
[%,BG
R(b
F FU
|7rH
.M|*
W526rMeKN9sL8mkDHAGHB2OBHQh
?9hj
{O{C
[7 CLc
un4iUJ3mCMyM3mWVz1aHUUs
.{>S
o5K%W
.M=\cy
4441444 444
>uxT^L
m+l[K.
1FE0
_i[
|*yM
X^E0
t872
TS?x
v{y>]4
z_V{
2 S"
uX,k7
]j1e
?^i~
w %x
;~29
Pdp"
JKwY
*8bB4
8Y*
n/CK
]W}}
_fyS
&<1W
<gFm
J?9
LQ b
!rzGM
i.M6
&=|R
c[w
Tk-'4
|^ ?
NJi/
4,{v
#:0 t
u5lE
444/PPTl'(6
no{K &B
`5Yv
9Fo{
dRL/
'qDq
GO E
444y444>444
~yS$
8aUo]
'rXf
vlfD
"tC>
`5YQ
n`k{9
bjgg
\%|d
F*Em
<\LE
mdW
:6uE
v}^D
]|:S
Y>$yXE#
pU{R
TAfe
HFHn[#
G>LBy
FEH]ieM
RijndaelManaged
-\ xEX
h%0n
Gh'U
e5xuH4&7
H>VqLnMRGr
444G444$444
vRG)
z A
V j
ljs]
Mru.
tjFADfaBBVxoV68wnDthc8ZsbNb
Q FJ
LCs.
M]gM
>>[c
mwuV
-]n{j
444z444?444
ka=H
w 2U*
#>joZ~
{TMo
f~mJ
1B .
!U *
!F]2
)QK8
FI)hc
n)4{
ow=jmMy
lglV
A];oLM
CJN%
.~ob
Dw%8
6xp:
.#^H6
y@DC
YL )
}+
$2O4ewtnQsUBPXnNM0KjhmXFQ5SpzGHQ7GTBm
lO&M
>u0L
=ANP
{J\`
Tb!S
*B@?
Z+i_
a,Q2N
*A)?'&r
%1V 0
lx0Oz
N6xQUbh(%
x9 G
!Md1
[MsN
3] W,~
;] 4
444)444 444
V|,%:
'V&"
v\-Kc
*>./(
)bY,
m]W@
`4Bo
NN]O}sK
+ja.z
HIhz
V&0
n~\^
UBgYTePRIW2C4eAETBqcQQpjTNnLt
}a~o
J?8!w
$70:j
{43U
LYu
Byc3
v;Csml
$ ;W
fP:rG
TLsjK1
07F/
7x%_ut
y+2f
a,mhB
~.b1E
@G5gS
T ;
&M4Z=u
veL~
RB*h
_U(D
w"7p
cdl6
r{AB
a2@J
8"|7.
`6W"
P[e2
=Ri
K` 9
X|i:
KJ[h
9Khg
%GsA
^M/\
.7sb
OtnD
&YO9
E0&}
wGd
W7FA
5I*/y
g ]|
o=1 f
c7G,
`j"[
[*^8T
N=uMU
V'4h$
\ X$
w0q!
n@S6
EfR
K@Gr
n+Zt
pt"
08@1
Qe=f
\I|e
2DX-
g7wB).C
j05>
$,z#(R-
:iYJ
:dNpB
gG9x
izth
/O@n
YRxi
.(_T
k0{=
\Jyyp
?Wmn #
/ c ,
Fc^l.
?*h!
X'|=m}
rU!m
s \ Y
~iM d
Z'7x
+"i]
ss H
444^444
It"Jj%
d '
Uu"~y
9|?
1m[!5w
RKOC
.*-S
-KH1
hS/}
w%0xH@B
`bY.+
oH7P
z*nf
o?C>
YXa~444'444 444
>'M^|
@$Mm
mE[S6c
vd,|
]Jy_
EcwJ
e0x2
<pp+
`0Tx)(H3
@1I8:
|Uv$
~-NE
(*TF
B@P^UI8
444xOQ`
_XQ1.
ES;Du
nb 3
m7[ze
[T{*
vx$I
9HX#
)K4 #:
?VLU
9;}V%S
~}^<j
J[I-E
Zb'OH
!VV_
tsVO]
58j_
-2hNI
6a?i
UXL%>
neD
,z d
Q*D
~K?2
5U)?
]7(~
f{1cHq
]Zxq
3 _N
Fhtf
~pV1
!s[+
[6nd
gC%$
,"Z=
^RRg
6GHtS
=H{=
Q_9;
wI<@
]{E
m|??J;nB
=9EG
=!KX%X>
I(GN
l =f
BBem
zy@I][0
_] :
7Ms}
RXq& "5
S?.\]r
#I\@
b|dy2
444=444
}xu=
{H:^
8?_
6x\/Ha
Sql(
(e=Mh
d\N
-@Y`I
CR%DT
W z[
(":Z
:J "
8cTLu
^E}tu
QfRM
vj$J/&C
6~&B
X[I Ch
=:R )
R79}
t5dbe
UwiD
nmuY.*+
;!h)
6=HsXw
%^A!Q
-dne7a
8 iYe
scqg
W3
~^e]
T#>n
:9/])
tk*
<`U5
Uo__?
#Gc2
!svMCdwta08cKl3Sumb7zSXVONFosxgC8w
Xgp"
WOTI
'NHY
KJ} (r0u
{6\0
*fb_+
%MJ^
qm3?
EO?]U
*bJzd@@
H4D
&-fm;
]7s}o
} H 5
8H-H
h%vJ
u^2c
#D`^q
$v <
/8
l#
#:zv
8.qP
eJMb
}#"}t
M;=:
@| <L^Np<
:E *
|+P3
Ua/_W
"/S)
"Hc%
_^vLs
^?-j
21@?444
P]j.
`:0 y
^ I<@v^
@nrxC
Zwo
v(1"3
Xa,=
eixG
tS%]
\VV\E
kYS
)pD=
yCTI
)e4 Z
h?CJ
hWuc
"E6 `
'*zjL&
e3/,
Ii3Kq
444'444,444#444
7kE8
n| k$?
w=vk?uIH
sLM=+
e`z1
uZ#U
/=Z.
wuw d
_b5V
&Jgb{
2fT()
C?gJ
^/:]P
n7'q
B$-x
-A*e
e#z^v$
e si
7WHJ
~:`]
<:{l
f]xG
x=_-wh
s7Az
(.}ZP
xKqn
-}p,yvQ
W<My5
XKKr%
Ym@|
%TYL
@l[Wn
;)Mb
)tV 3n
:(tJ
*f*]
l ,X
Z_~"
lmGr
t}eJ[
R#k~
r0i\
oyf
W9jQ
lK4[
F~:+
V?{e
Q(OGOK>
l&dg
61C
Fa R
r2f&md
5<zK
e;;!
=! n
a]Rh
mJfhu
MvGa
z^|p#
ap A
H|Cw
d3*xS
Ftj
7 zy
Sk #
V.Ww
<diB
pt5{Z
M<n)BL
8Ye4
MgJ5g
~~e$
'NZX
gxQ\
6 &}
LwXC
JKZI/4H
_I3Ch
_UrW
H?k1
k+> o
[&!Do4$~
xQ*s
DqR^
* ER
<K=-
T5Y;
q2])
0XdN
yRFG:
zrl,
$Z :y|
444&444
lzU^
]-Uy
HtM3m
>DF$
Q&3u
]e4u
%>D{
?%YIw
O.q2
SB*4
{=hB
qYY7*
QuxP
{ZvX
$c @
3 ,|$8
V2;~
c E@,Q,
o 2
`w=^by
444O444*444
QC`h)
qif^+j
aP##
B4{
FGJ^Q
8 c
0U\r
xyIz
/;Ay
%C{8_
O~7x
_ICn
'052
N$n
v>,M
=rCB
Zzv@uOJ
444Q444
901\
(G:8KL
o !9
%whT
7wh-/D
Gdg}S
og gZ
V7 A
V_Z~)OG
}TPz
fA {
YUYH444
;xm"
_]d>
t5t`
s\,&
v=l9_u
Z&g
D.-s
>8FF
| =
]a*;3
kmN5|6
U9FT
Lp 4b
]#cI
8hKQ
0)Zb
#$b!
444Z444
3Q*)G
/g]
9}Z8
Iko2
_p<}
74@Q
9ZF2o
^\ B
/mm.
'j$|
'1$(
3(L8<
Pjs8ves
Lzc
H"p=
4446444
i\)7
8`k!
k^p)
(T ]9J8O
m ]
_<r
GX0/
okdt
h
/uGBTS
9QH@
FDhS
ZPd*
8G_
q R7
8j b
-%f@
fWhT
LPj}kb
rljB
fMwhp
A!f
Y+{g
z_wy
rlj\
7'Uj
-a`*
WaDe
Vd7]
/:Bm
_! $
/vHM
Q%yV
UWZ Q(
j|{[
H 3=$
P/Tq
(lkI
F,2h
1*/"
l LO7
|'[*G;f1
w;E!
444k444J444;444+444
w T2
Q;5i3
@?X`,8
rX:
rSN<
!.48&
.G'G
3c m
0 ;u
zWgj
ve?hI
jW{}Lo
%)th
u I~
l(w?
m .N
_]J=
444=444
T5yr
I*<
3>c=I
qKW v
n8q`_T
b kW
IH<>
i.Q%p
,Ebs
&{Bu
N\Qf
O%6AY}@Tb=
PbN2N
0YCg
G"HF
X&US
:AMS
7 4J$
YJ6Y
=(us
0/7M
`br'CFXxTS_
[Zj_\
3v2'
R "hR
im}?
I'Hvi(
{c7/
v2+Ge&O
.1f:g
_Q..
w;5Oyd;
O yX
yu zx
S1Bb<-
us {-Z
>(U
3mb-
-' y
!37
I;@?
z.u[W
CYSL
qtSD0T
, sP
1)fE:
q [o
.Obl
43ikVQcJpHaRtCgsiZNDfsf8S
oRk
hg`,#
1]L|i0
Y}3
"|ari;
H#S
a=}XF
9{ p
TGbtX}
XFAPq
C^&e
DD13
qoly
C G|@_
@ b"
`w@{
kV'5X
: pu
Z4 J
u]W+
fBRm
)B73^
`P;5
I} 4-d
5~42
&E6c
o4s{
oo_u"
#3f>
s1rY
444u444<444
BMQ]g
444 urri
W<n\FX/
Y0vq`
RRZ<
aMgL
&-UK
{uDA
E<zp
a C4w
ku2%
BaFl
444I444
2;{F
9c!J?%
g3|v
P& b
>n;z
k!w+
i@G/
'{ V
444#IJXH<<G
oN?
#h1
$MO
lz 5
^1`oC
~Nc;2
:1Z7
vfg/
XA\9
]B=]P'B
12cI
cjc,O_
+-Py=
QyA!
)q+"
Uk`\-,%
rmI}RC
Ah3Q
sry(
P7~s
|nb{ Q
??xZm
t,_F
JZVF
9_._
T t"&
bK7F
dB\efl
+.L_
C&J
/5y:B
AKDv=
s{R6"{
&!LZ-e,
%*H5
Xw7
@cIM
RP2|p>?
&^cbo
4V}
faca
;wxN
u<0{/
D &T
'j777>
81C!
]Nk$
|fzd
RM S7
Na@(
c#cny
Y[{1
^rpI
_Uj
_ewHc
444s444$444
["YW
"-V?
YF_3
INW>4
eH"ID
{e
88\C{
"q^y
/Z_.H
tZZo
A0hb
`^5q'
cOTA
+1 m
5L
apS%
Exception
6.nt_`
JqSSR
MJ<F*
uuj)
"|;Q/bR
&zJZ
*7[;n
KMze
d,9
%0bf
Vk-d
T3'A;
8F\
<X&D
OneLIMG01yP9e0puT3wyTgL3
( +{
g t
TD;H:
|)t@
h*.t_
Sm7U
5#SkEIJ
$a7&
{8E+
g:wp
)+;y10A(444
Ic8
$ilS
Bu u
e+`"L P
\^kB444!444 444
m5IdI7\PW
U,2/
/.L
B,A7
CFx
^ %t
liC({
W:1#D
wP5H1
* !60
,<;]
!SM~_
"qi4
#wA{
444 7<W
_fbkt
8Z#(
ufWD
>-J]
Rw@WP"
Z]tC^O
c*c-A
z]Bktv
B;ne0
MOPSA
*c<\|A
4aT,B
x)tbY
8T=P
'nM@E|
t qI
(cw6W
:qY-
j^ f
vA\'N
Ihu^?3
_\Ol;
4/ 7o
o",
NS*u
'=]%NoN
<{{p
HbR
|cNY
oQAt]K/
o6oU9,
{V?W
J/mY"
}d5te
R\5}
x@^]6qU
<f[3J
@Q-TZQW>y.
#|s{
iiZ3%
H8X\
G: R2
J\O|S
n/_1
2'bq
XP?K
4J#})X
-9%u
Fe]'G
%'/S
7YsrE
9HT5%p{
U (c
ZXL/
WU v
an`EBp
%z7PAI
PKA]
@` v
5ra;
I7#b
v/sx^
FHU4s
hYt]
gi R
ZFUx}G
q@?t
FwW-B1]s
=]|d
iyEg$
pttg<
'sPimS
[!/hS
!3 z
Z|e#
F u_<
Um =
cEmt
D7p
.q*^8
c'k4,_
0$C&w
PC$;e]
ly "
!'-?
zznn
s mK
.(FD
?{*
!@bo
4uSY
/)M*B{v+~3
9: E18/[/t`X
ogln
{X,t[2
%]$"?
P_Ax?
=joj4
"MaV
F;%(
3X
~1jG Ce
b@Q-A
dl d
AT?!
444Y444
jz>OS-n
ccdvOH1
rdWN
)($#|*
$K~u
f"qQ
o8%0
<m7?
A p(\*R
1#U}v
,_)$
+<h8
YHeb
1c zQ#
i&c'!JN
Kb3B
'0hX
cXmT
p$Zq0C8
;*mvz4M
Q1rpo
r\IW
_$PM
9%#j
Kz8AP
Jb_x
?2h(%5
'Q .
cFfeo
*[F
1G}
FRf1\
nou4851
vrn0
h$
x63'
[jR7
DvxHE
k<Sw
7|CK^
|LdI
i|(lz
AZZ*
;q1|x
eYbv
\q5'
txCU{
2,sd
r9qz
Sdh=
"aXx]
o"39
]T{\
2mQk
444 444 444 444
Gp]@
444 b[Xn
#Ff.>%%*
yDmsDNkFrtJbAx6B0lUxip3Xn3
dMMT
w l8
H3//B
4a+l
#-uD
/gdvW &j
HXJ}}1Hj
tTIE
\v@E
""4:v"2 u|T
ENaW
#F!T?S
wEk_
-hnV
/71z63
st"
37KVV)N
~6;M5
1>E.<
P]W0~z
PJ| 3
( 8N
+ 5D
J6*#
nVL`o
;%D }
d(|yCcfK
_ci/>6
0Co&
1 jv
o aC
)(R`
"=''
a5#
g &&
Pg.}
|t]zx
444 444
ouah`
sWM
S,N"
TH!1
+ <V
=M@
$g$4
tI5
7mnd^
}W\@I
IY@U4
v%W$w
I0.\a
ysGp
B,<{m
Xpn O
t(k
qC`S
zl:0a
:/S7
6soC
% OQ
\$&^
+d}&
Jj7VPE
q 9h
9m!
56s n
IBvt
bTZw
Z:T>BQJ
}9w_M]E%b
K#Rk
-NXJY
lx\84
p v Z
{/q
[!~*
~dV&
L1bb
Q(4w
|) `
444 444 444 444 444
=A+i
'AN
xoe.
'i o*"
,rKz qE
$` tP
;ff%
;}74
')j#E
'Yn6
tnw)
z0T
Jt")
Ixx/
};A:c
9.Uz-I
SB a
JLv'
t]Q~8
W@r T
{69'
ldf5Xf
#.*U
Nr /
yr`+
N&:q
tV iE
V"cv
G+[H1
;\#<
X $y
TE@1yWVT
dkNj
gC)e
Rf;g
/8w+X J
w!;
nN
\ ^#C
_/vi
gG#E
ls{;%
AR/s$
Z#ze
|FK
6pN5
Px8y
cA4~
9s2u
]J 2
6NEnf
'5o,
rGkj
W LO
t"(^
CfJ#
TB FDI1jL
CC 1
VA4@h[
S-'-
efoY444!444 {|
MmET
Lq>AW6
V=V"M
/Fc!x
Ecs*
? Af
s!\
$}nA
MJTi.}Q
KcvA
hF'
_fY~H
~x
:~X,
zqNF
0?j[
oyeH
</e4
JvQQ
SCbF7 Q
LN-
SE9qC5V
D^b
sY <&+
y@gH
4a[C
usfP@'
e?\W
8mPeFF`2kt
p@(B
>BjBF
!adSJ
R_<D
X'6"
DPc1c
\ TM
t/(Re
k!Gj
v2nX
a_D}
e\jZ
} ND
P^ }
Q>$B#4
)[1S9x
.\:(3
.2-`A
xk<"
$];Y9
hzB5
CW
5]U~
.V[
^V4Uo
mih$
Z dQ^
g`) S
_OL:
C).I
krk4
V1 .
=5W6W
$hlz
Ti2]4
44SU
(&s;k%
5x,2Jp]
Wx&Q
1qf-%
0)K F
?ih`C&"
h ~-
(YQ!
J|K6
y2`gO
0Hz(
C)VZ
H9urNa
dtn6
4LlCS5c
Z/pV
~j 0
9Jw2Td
B3cw
a"[xX
444\444
d+SQ[e
d>"!
RXLF[o
!zM
}fw
P{GV
*e5K
r$T&
T6d;8U
S 1
jhI@N
$X *
<U Q
=L![
mHYd.
K@ w+
5c#Ca
$U*;
##D7
:_sf
a(bH
i@J{ 7
']W[
gfW]
Cd$x
iP)j
=ns ~
iHY
f $h
AWn|5\
=zWK
iuy_
y59k
\7fg<
- #[
*:x]o
=ZEp(2
5tGNNN
t!7u
tb&f
p=xL
WY^l
$9->
UfP(e
^Efy
DfvD
tmtQ?m
7^| Gw
oeFk
NmFj
Sr2f
|cH=
l1a^
0|@9y
'L8rM
ct|Z~
f>"(
}$2fUj
)|+
.BeC
?*q7w
i:%@
N[s L
nE]Xd
y@/4
( :{
ODHc
PFF
*Uob*q
R B_
vdi
Mjl`
P J-'
T|a
/5#n
5+{}
D`;7
8=>.0l
(hVH
= /D
DateTime
K";nV
>@}#
P&%R
vH=)o06
)f F
HKfs
(%iU
x_<#
A903
Y }q!T
H)K~
|/y',
O1$,
]"RZ
Ek>X
4@D
(B mWo
}jqt
:&W8
Uid?
B@Y2
(? 1=
XwS_
A5QWw
kBVQ8
{w:'
oXuQ
q@dM
y7&r
]tCJ
O490
R\|w fY
btsn
1#]L(e{
-mv6%
hNvi}
yfwX
?]Sp
nGxa2
F;pU
HcK)#
jS^C
(XsA
Th&?
JL\x,/C;444
@5L\$
444u444*444 444
E"z
usv&@
-C3IO
8N* QD
]{f{
GU81
t"9hp!
]W.Q
,M '
h?baG<!H
O$cO
Nf6Y
=d0s
]TyAF
boC~
DSE{
'E$%
444 444'ie\
x]j^
Xo(5)
UPo.
System.Security
TWRn
N.^_k
7/I0L
sb<yE
JQ m
" a6
Rff
t!Er
{5-8$
a]Y`}
uc2'P:
*z[rE
444K444
aMi_^Z
5a?wFf
`"P(
OY>+
.5S4
SItT
}Jp~9
UA,RXdl
%b3z
-l g
nTL,
726Z
65Prj
7:L&41>
2m</
$JT'
?CX1444
{k4y
& E!yu
Fi W
=f5_8
MRpR
FyZI
f("
RKVA
Nu4.
x0G0y
A<+;
E }f
v%
%fx#~
jF 5Q
&zIH_
rpS
4442444
/AGGie
60w
mNP)
YD4,}
UV>$J
>L8d+
rA&9
,9pG
TDg1
3 k_
fx&p
\fV(`
@7 g
AddRange
6zK+
e?`s
u |tE
e?@
/2I
J3AH
Ow\K
xO&b
$[34Vg
a:*Y
444d444#444 444
j*Dif
zdx,s~
List`1
8ahZ
K7tj
PsOY
4`3!I
IAb@8E4
?<Jf
BU n@
8#}*(
$#1
:NHER5
&Zm&
T~AO
get_CurrentDomain
_l~` N
y0[
4}!&
W|6mM
BFkT
>3zN
BXQ5!}}*
&^)4p
L4cU
1 U*
In..
C[=^
444T444
S]F&3
Sp22!
}3^<[
Ng}o
8w=%
w n6B
jj.x
Ze=;
<='j
bs U
@Cas
3?:
zc:r
444 []nR
$(:~
Pd&P
z_{c
^2$
444 uw
spQ](m
#[!
1NfzP
B ri
LFsK
zo2
,F@.
;PIr>
qMo'
g e]
eckk
&VI
dk!Kv
"Jv1xni9WaRb20lJ8V9CGRjSg4RZMvZB74d
Lw;
FE>?
,`Jg
CK*#
Ht 4
bmehM}
T"(K
uF7*
CNM6
NjoW
L+6J
ps^/
'GsEX
\Hx*
RJMB
2<*($
tdw(
W06L
hh.P/
<Z?/D
5Uka
Jm x"l
hwAC%*
kUJY
(PZ i
&bmW
.p<z
LLKw*o
cD;7_
v's
F_RVG
E@?q C0
mE;/
}0i;v
+RI5
L}!<
I0X''
:w(J
U H}k
?Xb
42"PW
c<!d
r%M
')Ur
Kb 0
>wsA
N6cwoXj1tWdxkcyJnYuEvrRN2
+MK4
444 <;F
-y]a|
zI6l
P+<
eKH"
7w9RZn3i0j2u6v4WRhpNuD.resources
p$yf
#HH
aE|K(_-
OwyAx
af4`
9R/![
QiG@
dr6DbE
ij6
{1n,R
m"38
I3tI
y'NQ
$3T2
Z R!
GDg
O<2.
9(LZB
xb[r
@]\^
XWJ~
MT }
[g:M
^m@<8
h"}5
Z_rq5 Wj
6'8&
r213E
w.9)q
^[L'
f0!#
rD`
G>
Sb#J
f# s
ou+6f
@WJ6
.Q )
}u>H
X!n=
@B-b
c@['
ZKyO
.A mu{C
d BM{=ku2
:Y,l
jc~
~~oRN
}YhW
+e(
z4}_
\fe<
RJt@N
_bO!-
PkKZ
x4HA
F& e
G$61C
?o!_
vN7"
}ueK
~/E
9j/(
$/zZfa
Hg}^j$
ySq;a
q# f
|*!c=T/
5b!1MF
cN?Lq
XX`r444'444 444
_:R6
mP,w
Y)SQe
DialogResult
z*1"
[z3A
]^No
cTj ]
>(#l
#boWv_
3Rhh
}J}
!;\E3
l& e
'zX?
a| R
`)l$
444H444)QUj
liQ3<
0=dwn
( "NB
iUy
444 NP_z
CEs0
/|be
g9v
[,2n N
/sIE y
;*grM
pE;w
Y@17
u=s3
+b_
oDpN
Y( !
-HN`
~l!=
L=Gs
%$=E
DZph'
];gw
#Ci!
qf+H
?zqna
@0wU
KqC5
FWRy
}_c8
*3&)
cnBK
&/zkp
WP^T
s;tF
*,]3
'3'
C#r\
2zTG
yYvkf
@}W!
OXHK
]SLK
e?Pt
ihJN
Y+Z}
444q4440444
oY%P
-1E?+*8
?3[}.
FQ
U&s7
'+LsH1
&aWBY]l
J!|5
Y+2 }}
kmWw
4443444
]zk<l
R4C
kd}t
Y4 [
1m!^
Z:cw
R$ v
l&zEK8'
7:L;--@
aOWeB6SxhrB3j3qKfR6YSVv8D
\\r-
A Vk
o0>D
wg(9C
\B:I
gN t
:<*l
p"#g<}t@J%Rm}
X3vi\
nE}
fRsO
A\IK
9'r+
! h<
u:RN
\fKl
p-|i]
<53V
t6o
A>Cd444"444
IiUK
J: 6
\qfHn
gM?:k
@G'F
k7hM
NT~Q
xlj*
iY=J
kvn##
l\&l
GBW)
@r!\uy
'pfX
5ZI>
!(>,:
"%-'
v H,
}3bA<g/
HG(T]
nj9s
5yMD
\<+
GDBV
(I)Acz
#U@K%a
{ueu
+\\j
dM j
j%MrJ14
<,GYK
Pb%)
-K9E=
6t J%
KDZ-bB
I!Ju
.-n
kf&b
KN$o
kSY+
Y]pi
.QI o
lXU
O@ha
1EVW
mI0z
ToC t
~" R)
X-3'
r&MTt
MC$g
hp,$
=)NN9
t<k[
cGg&&
An8z
pl"@
F>dl
J !pr
Q-;l
ZbjRU
hI#
"5\t<,g"
,.wF
pEs;
~3}@2Zx
LQ~x
&=)(
||d[x
`hh7
4SF#
{c\]
%qx
r~?;
XXbV444
VNFv`X
tqG7U'
b32>Z&O
5"g$
8X%~_
wLO"
Cs:E
^l?z"
Ci"l~
OSd+QF9
3zzt
=98?
Ze'a_%
UU.f
lQ}5N0
X-^C
Y|W$l=
dkdK
4tss
_Uh
%](jW
IgXc
Rc 6'
RqS/
. UW
t;W_
b&zD-N
L I>
Ni!h
NgS*
E( p
.0uR
wFQ'
ww D
|PE0
9,_5
"wJ
W9
M58
_lSi[
E[vW7
>Lgf
yS7h
6/#z
pMd.
3mD V _
+V)I
Nw 4s
#u/H
'j!\AS
4xw/~H
`"^K
tG)d
X xy1
[c_"%
h #5
;yol
.r#t
w>e
Eau'_
K>ZD
hid8
<]z\A
uL\
7vs~
Invoke
Y7SV
=Z[w
j[
WrapNonExceptionThrows
*"R&
<6Y
@(dk
h> e
VVa9
`,->j
YI`
'MNs
4uW
f$KR
%ZZ3?
"{T]i
o1]k
TQFR
yaA>5
9hti
`=W_
ohP=a
%G`.F
m wm
Mx&&2
k,u%o
GF-o
i-kE
gAGk
%IUN
M_J!
^=Ss
IB2i
>:G0m
2|pgt6
]'=I
&n/?d
;(Y|
Wu@;
)&`Xc
|lMNqPj4 ]Y
dy3CC)/
_;uF
Tr1C+
[LA\
c6?C
Km!
vrp/
Hf*xx
&AK\
NG DwH#P
9IS-
z<6l
LWWV
zU}kR
WSImZ
%H)';\
)Y3-s
,jDN
Bd=O]
nP4i
2w)0I
<70'
w"?7
twd%
;B 73?d)
jG.E
JjMs
DZQg
>*Sq
YaS]
8"@>
$%s{-
<Ho0
[? q
y6cA
U/=!.Wi
]jaj
$N~b
qDc9
1CNqGF
v5Be
L3"*F
.HMR
ttj
uDD@
Q{)*
I2S3[
[dJ?:Q;
+tb6
CFIo
Y~"z
O0`%K
$Be/2
dea9
<\oO,
PQCsk
k*VZ
n#7C[.
444 JBLatpc
HS7c
) q r
444v444=444
V4h(
A`7g
("\@[
O8pA+
\Id\
(~@r
FXs|7
t~pB
K1T<0
G?r!
C#_8*~
pd 1iD
K\~{<kx
rm~y
[^nOO
*FDR
#>x
tW:u
=\._P
1tp/
*=^40
ILX%P
F"EV
3%<l
?#vu
u5^c nW
Y70p
=nWr
iVafRu>
nlHc
&G/E0
_C,-
/|8U
b$%y
wz|)
Zyvj
s 7H
o&\J
:519
w4tS &w
2wj;
kD<L
b8Rt
n[e/
C*q1
=?F/
BWB;.
?p}>
AQdG
:GavSA
{( ?
LO`/444
N.iW
a ,Y
t+eD
(Rbhg
V#X
R8>}
0FD
qvqj:U
-8'G
m~K67
4 E<
Nb9<
e:;*
s[u{
*s|*Y
H!H^N
]mMxQP
T '+
kvpZ\
BN47
K 1*"
&n b
i 0G
{0 '
7=Ei/
oD>
Gaz3
rs{:444
!5d:
xU
oVxs
Meq.
54d xi
> QC
i@uJ.'
} m
U>;5
qiJ3
(jx0
FBJ$ytf
mlt~
444S444
L3T&
NlwF
{h)j
f%&dI
*eqI
dHNM
b wf
\_VU
1Ml^
S`[c
444F444
K1H _
\jm|
]^ #
"c H
e!nGW
81Ek
)$\g.
S% [
{ cm
];a!
fy_-K
vNhL
Z R.OE
~X{>
5)-9
>@=
444 444 444 444
dc03s
L84
Tz,
i@M/
\@[%tk
rwH'
"I7oabjXYjMovgtYolCQ3X4YvMdSe3pSpDG
</N<C
&M9n
TfuR
AJ6o
b4S[
:$`O
<w$ID"
(Kk$
lm\F
evk{
jL_i1">
@&29
Evx
o+jE$
a$zA
km}c
2z]8
_4n7
>>gK
444"444<SU`
63.^
\}7 W
(Jd
][+'
'86K<&
j\Yd
>Es1
4443DEPwC>A
X?ln2g
#Cg'
;l</
>[f^+Q+
fwbl
0okt
aFKP
%,~6G
|~)c
fsx /
2Ntr@v
^^N
N6VU
AD~{g
n=euW
I.+MJc
y"-v
O5-s
JKB`
&/hn
1yJn
^D?2
'BcL
RV6,vn
Ogt?,U
\ 3i
| wB
V)-b
\w[ks# !B5)
`o-*
tI3O
TOnS
%3^B$
wa6R
7b#^E
,3iEZ
@%A0
vzE\
:at
Vn:
Hi9
GJ\|ADW'444
4Tu
)hk"
-ms0
!RRQ
PhY
kGkx
@71g
NnjT
) &e
H116
1'[4
5 7/
B.|9
`1k*V
QRpP;}
a(fo
'sgb
43&
~&Zc
@lq9[
.WG>
qVo/
6QMDIk
$b3yd*
zff/>T
uydM+
7#\7
B(]
|9~S
F8Fn
NcDP=
CLjN
>8A3
zjQg1
y\[qA
bo"_?Fu
qG"7
~]O@"
LE4qv
f%3YeZZ/|
b }
Z%\
iLI8
[Cv}
'u+m+U3
-p,"
{ID5
bY2)
ug%"
9 | 'y
If7N
YAKw
>KwAO
O[g
[>_&
[Y6f
)%U5
pZkF
V01O5
uudj
3fh x
NVni
G&|Ht z
6c"ka
J=
txj'5
~ jY
xKp $
LdSK
Ma,zy
.cb
S^XNFa:
jQ#
>j>)d
^n\i<F
i`=C
6me
Af2
]p]G"
YiLd
$[D8
Pnp]
shyfH
cpd9
+aT(A"
w;P.
9RKh(
CFawQI
v ZT
!)=n
%O;4n
$S#Y
2@Ws
O,.cb
aT=a[*
+ LN
^K+
Xh_`l
444w444.444
=N"z:lg
1XzM
CNt>
j|8.
L+/`
{9?T
Cn`{o
@vit
Sn*.
Gli-
Q9xC
QG2Zjvmw5nGh5UvjyBKe
0PHH
444y4441444
kl)e]
W9s6h
)K+0
A508
<z$GN
)%A/X.
cy+D,
'/dXm
iSY<
c"3/
UWaY444,444
}7B`
oTiF
zn[s
r0T+)
Gd8
@rVel"
;er>V
68cs
}?u0
Oe!BJ
>.]{
RE<b
g7a8X
)
fP/a
4443444 444
Alk
oXY` o6
=c'S7
sAk'
tc!]
# -&
v]"
swlP7
1hVm
doj3
HR2;
W nnr
Z%N)}3
L#0{p$\{
jzXR
7_Uvw
"i.
A{7K
C=5P
\Ki
e)D3
FD(
P>#{.F
]M&Jg
$)}#e
u+s
ui#G
h_C%
4Ynb
eFd_
x\Y t3
444 UVbb
O#Mln[>3:
r:8`
I"l@
kY|L
D+He
\!Nl
ckHP5
04yZ
8NC0
| Zj+
#j7'9
<oh@
q#I~
l~m>
ICryptoTransform
4$R]
xGpJ
Z*~hsF
FCO5444
J%a6
s$nK
}VaG
Yk!.c
lQZ`
d%-)
GOB#A
>I|ms|=
RRu=r
wPjC
Yxgd
I91EX
0*ND
~V9QSA
E u@
x{Dt
?>YTVF
!QuB
0?]G
%= BZ1
46EN*-B
Pqa;S
*qN(
9hC`
=@g]\
EcETW
5SAf
>{?c1U
=gO%\
XN&J
fQJ>
m 8N|K
8 .I
\Kqa2p
vG B
_ K^^
u|=Q
Ap2
~~5C
`Tr!
!'arV,
LGiv
|*/n
b]1
%](F
-M24
9:Kn90.
g8~s
kfkT
%zxY^
s&'J
9y$s
w |$
Y^t&
7F3|
ca~W
9D>U
q{ui
Se>_zel<Xl
7eu?lr
mH>.
c G(
#V_t
zFhy
"_Ll
zC)7m
;(T
8YVJ6
Y2Kt@@
wQ4EJ
b|!v
)%v|
LT7N
&4F8
S$0
(k4*
BKdF
YL>EE
Jjd?ou
. UK
^hQ@
8\$ep
n}~\7
Fed@Z
ewVi
p&wg
d>o>zC#
Pd${~
ON1(
'~M;
FDVv%F
awn[
7) b
\aso
S'Q]
[{L
-
g,@}%
EQ&
}tGQ
D SS
=)qA
l]w6
?:KY
7~`!@M
%l&
QPo[
B3z;
./]E.
2+cm
x=JC
V8nS%
K:2$
BYNk.
he}%
14
GsMQ#
HJui
KBvUjuRUD4NzolFIiD89mnNnX012pdH5
M$j P{
.=\
H[cR
q33LN
v>I/
1bgnlV
-#efM
]7Gp
^d::i
mlv%
y1TM
aTGk
<Rc;
x H*
E]lE
W! n_U
WOi
%xbao
444 HB>
444k444'444
}>:G
S6|n1
7s%*/
*&/
ML 3=
0w =t
lx>D
Y)7yIy
7x0q
MMnT
:&'>
444]444
_x&r3U
yr0XMh
u^pL
0Vo$
eJQ!5s
G5"m
c7<<7Zb%
(vONB
~"4V
v|6uJj
3/dxQ
:0HYc
*u P
7<CWR`8
oZ7@p,]
b~Kd
O w3N
`y+;i
k?T0
0m ~
Z]i1444
X]0h
3w;M\
444C444
7`
`L'd
brYvE
=|+V
@D|Z
~:x;oT
U XY
vP 0H
/P/4
oy{+
N`z
MessageBox
)j U
&!7.#
,N.Hf
GAW
?yX
M.(,
n/`'
n^eyBBO"
~O^O
F We
_\cv +
;MN*
+Pcv
Q\HN
tw,I$
q e
sLw
6DW?
~ A"
5>?i
,aI
Y`V'F
wsgi
k4rEx
pp#d
QEd|
444~444(444
`Ap
IP+m
k![!
,A5P
9t =
t$o-
_;#v<b
99*-;
)8up^2
n^X~
3|q;
V^3 g
m {D
O.l$
o(-a`
u-~-
HKR'1Y
WTfl
dp|'xs
^Y"oO1!
o8n5)
\DfY
vW/t
Assembly
z:e &
ZB9Vn
."$9
yRI!FR
W< L
wMUp4E
;-b)
Q ,7
`nW x
O$O\
./1d
DvPB
!~O;!
]QL-!+W/
='#tf
444#ZUY
#! O`
C*|;,.
`~03
fRw
C1ek1r
!@-LV
01jG
7;/.M
. dl
z[w '
vRV0
Eju
#25@o
$iQV`I?
gnW.
ct;y
I ^+
nwcD
5 },T%;
<S!l2
e9dZ
GA 5K
i +f
uK.)$I
.K.S
4nqz
q3$[
O`sm
D _b
=O0P
t3/|
i-RT
7p^(F
q+}
W \vu/
JPfPi
ldwuF8gHF1mRUopOo1pn262iXXFkGTo
Dn!9
Yl}:
.Gi
>;aI
~[ U
8OXt
yba"2<
ffne444#444 444
J1#/uZ
ciH
? C&
'Q<t
kWoG
P3L I
Brct
O[B5
. if
uTE}
`=0g
@.M
M%|
"#!o
B NhR%a
Dn!w
PRZW
8Z+[
444 []f
c___
5wjO
/oL
L{PW
V2W8
4ih *
/[(C
.kVq
%Wbd
oa|r
]bx$!#:
#s8h_
]>JQ
(j~`O{
kGL\
&Buz
TPeS
\t#*{
444j4448444
\X?N
*?)UX
`@K$
,zWY"M
(Ycb
'm Jw%
jPCv
+vm 89
p%*v
&2>%n
[ODW
p*WzN
IGF*%
F0vN
_s-n
IX6D
kOPHw
y~~@o
HHUi444!444
_83X
a0"r@w
1 fu
4Zbv
R<(w,p
7b wj
3fAc
]_iB
L)JT
Yb *v
1x,pG;i(
*ga@$
s:sV
5r d1#
s,4c
Pi1;
2_k8
D&[eY~
*O;R
[Q\S8.
Zk;
JnNi
) QXV!
JLN3z
Wsrr
hq||
du5 jQ>
)[#]
ezE9
aQ*Jj
vpEbZ'h
x3##
-#5+
fi$3
.SI(
>;.'K
Uv;-|J
VHp>
B- ?}+w>
R #I7o
M6_s
31{3IE
M+q
Ts2`
t wu
5I1_
{U8~
DW_&
s< 48
r8~Qo
WbH|
MX|c
}SHo^
Fb02
;(y,|
t/Vr
C]I3 \T@
[#S'
S8D
Ymj5@
eCe+$
0$f<
;i--8
kNK1F
.-/FV%M_:
sy s
L3LI
n''a^
9A_>
"^L6
q069
QTgJ-1H
,=,J
$D`i
n\PKi`X
1_(
/~ xa
Jn6F
0e
3o/ {
VN* t&
<l#h(U4C
0mT2
UZ>#-B
/FV
^y3/d
;[Z,
X{>w
j=!u
{|~({
ajg|
H[V\H
':5^
t-G
!C4`
Ktoz!
uRv
GC>o
)2;x
1*hl
~;O@R
=6.IK
a{i@b
9};A
wEsR
23|s:[
s`bm
[F ,
H .)J
pHbw
J7lx
<t[j0a&re
={xq8
+$_k
x!y"
be#x
*[~cv
)cHL7
#P8z
7wP>
_q7W
444K444+444
)R\Ey0
ve`J
CFE/
?koU
kwkX[
H<\%
444,444 444
0gp&
C?I@
rf5
G##M
$, ;cM
U{YRj
^_jG
S"|
^i`v2|N
ZcNW
444/444
u <
444p444J444+444
j^jD
y~dc
C;ah
)%t6
M)(;
_)}3
]@`=S
M)(A
Uj Em>
p^AYH
M4UF
n 5n/{
<a';
4445444
b.`?
F$w.
8&9y~
ql7G
32 =
CrvN
wI,\
A@O
IV;v
7ynC
VptE
+H P Fx
l#KN
:ZLcOS%
'"E& N
u*iR
{#,?
444k444%
{^n=
'H`>
3 zX+
R!W2
444m444$444
s>z/
q 4[p
y8H_
tILQ
9us2
'C|$q
HImK
s"=v
$i_)
O|z>
.dH
[4?f`
JVls
FKkfX5
L]@u
PTWBCy
.(54c?
sIk,
,?Z cN
?'TO
LqK[
vkwo
F:9Sc
1 /j
^KK3
<7:P@
&%{AU
dd7%
7,xq)
444=444rCBE
,_Y{
06*g
_&<zXF
E KXp
=)ws
z> F
%XZO
R@"'H
M @3'
V "H
4V :
&Lp
#}'O 4
@yV*^
a\q0
444 @DWR
]c)H
{S/5[
9`'C
5_~
XxY<*q
444 NSlS!'F
h?Po
7~T ,
hNJ[
ck@z
, 2t
7xiP
}Lu|
(dr@
V5
fhN|
jxM#
n\,u
.iAP@
okO
TN.
#n-h
my;-k#
.mU-
Cx(?
E}A;
_83rx
`bat
{T'
3b8G
Qn6=
d9CtyJ*i
1/PEc
~PG&B
"d*Q
444)444B444_444g444C444'444
Ms=
4445444 444
z:/M
JVU
Q#
=FT
yPIHfl
C {|]
5!A
N\g
QV (
Object
6A=|
3ihk
'<"&
%wKR^
<Y93
pG0
fw =1p
EaaP
9k r
>r |
|pFu
.k_I.
7V>n
.Y) N
W|N~
>oA.
OF)6'%|ol
'(K!
91 (M
I+f<3
EB`?
SyDa-
%t~]
I]a ;
N5S7,
?BV+s
p+ZO
bQRY
4440444
L81s
E5Ayd
i:el
k%e]K
eIU
6Bvc
3/tV
kLdo
|8}k
Ae
UroOh
444`444
444EOJA
0N9!m
@:KC
$}M47c
xg-D|
<o {
eU<~k
%9qpG
s N,
sG\+
0LFq
wSFoH
i70}
Ig>"w
W;4i
b] ~
/H9?}u
t|M>5N
444L444
TS=
Rae
V ]{
/ac$"u
(3&
WY O6V
4}oEJ
<=Rq
+ze
tf~j
~t Nj
dUyJ
KBG`
Jz&b
6etn_
zgqcQk
eOJOv
VrOn+WF
XfG%
_v?7
g+PLuE
4s68
3|Rb
4`9q
mRrLc
<;FL444
q4`,Vo
i4d1
tXji
K3r=v
3>`{Y
dd,>
Ry,`
S (}
%}_P
`E/l
a}8wE
wN `?^
'D `O4
NnfG
444y444,444 444
EI+.
:=PFH@7
S3D[m
o\Ei
\"q a=
0qG
XYq
v[!O
0N$)
m{_]
X6z:q
0Kze
>I5K
/Oi*
`>RL3
= (M:&V
_^kK
>x:Z
/MVT(K
g |)
_&)$v
cAdh
C<u@
|J 4'}
oCdm
dzA M
>Yb#
x^tAK
CBTS
A}L*
ps *
Q<R*
=n)6
j'e7d
444P444
-a)$}t^(
n#t<
YCua
># ~
:H_o
1jo5
~/uo%
i^[,
V 5!fgb
dvT}
Btr<
BvH@!
( 7G
bE/M#
iz8u
$]Nx
E6g6
yAH<~"
0^mOE
J.l%
/vYk
E% bq
#Iz0=L
dm%V
X;rm
[,cMr
NP`Z
2(^
UAiW
5@kn
D!/
L kix
DK+I
ezjZ5
444e444$444
TNwNdzE}l
'e"I
6 <z
< $W
MkHL
4KM17Jo
<9Qi
srK
p@ )
u%)b<
Q|'J
d8`f1
t3tL
2 WFq
PDeH
53&?
u_+l
|j1h
_g:E
?RUP=
H*mm
!T{i
=N.2,"g
5b<vAq
+&!-
Y,|_
KXgc
z `_
:JfWU
a Bc
tF 9
Og /w5(
~,5s
.82{
hy]_PO
)P)F*
h00aW
!7%
A7c"
Yz nMq
rN5,
NFofR
a95Q
1?Mx
d=~J
2 8k
&R /
9+Y!
444 miW
=6En
"zV9
4445444
TGdb6GkZJKOhrLDfNag2AudziFAO
.q?7W
v g`
r Gh&
;n%x
>8@1;
'*I
$w4pOT
[)0Q
5:QuO~
QUhMm
#Pf@
?Gh0G
[#Q4
TcF2
A2?-
/Yt3
^z.]P
Pe*S
4&%$x
iyNwqF
]wAG\
E+1!\D
tkFT
&qEZ
|Qy{
RT5q^
GC<;
:hD@
P+'n
p~2&
{6{
D0d:
X"j7
\=n*
i}VZ
EfI1'
Xzg
]I:Gg
iYO!
PI}d
ej.
"{^M"
}.W>XR
Vl2\5
Tkv-
fe"C
444 OKM
gGc"
]sJ:xy
BJ*VL
+Zaj
9I]4
ep K.V
iI5e
h~~Xf
bmvwB
'v ([
Apk)e 7
>#^91
j6 Y
O6xu&@
jp+a
l#Ms3
CeeK
p7<
]`=b
D$PL
3pI
2,`]
`&$Q
L#bTo
:P;;P7&
4[m&
,,8@
z{ c
3!I
DCON
-B6 n
e.Kk>cJ
v*b8
_P.
Ci!Rc
Y-tq;
bi.g O
ICE8B=9
SPr@
s:1>F
2e#f"K
4442444a444}TTW
i~R5
)o,hj
PFG5W
L,+U
Y-SR
:>AWq
aWO8r
7 Vr
nd6P
kT4^q
p3pI
HMO]
?O0Dl
&>V(r
@m?"
/%02
q@?R
_.z:o
Jnmg
`ja/
[JfE
o?fyd
aT;E
zuVL
fIo@
m9bm
_bq **:
*v~P
[+ku
E9S}
TVbj444!444 444
: K
P:t
Q* Sd
|87J
444R444 444
xj^zX,h
ONn/
zH;;p
*o0p*
nw2 B
Pf!f
//,X
ez&\
Gr d;
b|2+
OE>
]s>Bi
':O@
< ``b
, Tp,^
~wXR
\R*} (
}7c^
0L#T
DKAL
{QyRB}
c+9L
H"J2
&H e
6X'X
>5/
T`1&
:Ua"=
],Dc
se{.Y
$a od
O-eeA
6$Cl
:MZb$_
y2R#
444r444$444
5KH&
:Ikw4
a5C
@XHU:
444b
b(]*i
zwse
kHv
*G\o
H]_:
WD'L6
6Cvn
d09sFjnFrIDq5lH3SkuMYCB4nwQ4
]n p
;N*6E
N2ZP
GyJ(
|+gMD
bCEP
f5 `
]JkA
x3lA
444T
BJ(|:
z?J[
a'AX
XWZ_2?
444$
[o2Z
~Ns8;
ERNC
V[>V
-]+f
C:!<
4441
*:|rJLM
<5EE
i^+]
&4?Y
*N6qG8Mb
6[g?
HB*zSVx
:t6=.V
BTm=
444
444
444
!DJ_
&csy_
U4lH:
tL$.
X+Y
JvK+
74tk
E U_>
O_*
|]p[
hvj
jj^b
r4kVH
EVB[
pxcs$
?812
p$)gb
lS!,T
H8CjX
~-ihY
m)Zh
8
I^o8 IF
T8ok
?MbYv`
K4K>
D >V
6M8/~
~O<A
<Soy
I!a'.
Q:sJ
Z#Y;Z$
_B ~
~7b2
)J3{
-Z%_"
|[B)
um
nX=
QjO)
D"[2,80
4f]R
J--B
( ^]
lI9B
\[-Y
System.Resources
=}\n
qZ:B
q=XG0
QMLWs
p| <Q&
zuuG
klKL
mBoLFEAy
b% u
2/ca
O 5Q
en:*
4443444
;~N'
WH|j8
o0&:
n#7r
@Evy
G:W
CGKCgLW
Kb_la A
|SIP
T#Aq
/GGl
dT"a^
G[{P
t|-
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
MSU `#kBy
nt@UY
[)oy/
zO O
%M\^
m|Jp3
a7W
&2N @
GL*^
y"W1N>Zd
Smt)
<[!@
K@!I
QC^h
?;kz=
P]|8
gisL444
3' w<
h<z#('d
2=$cr
)Q9D
HR9d
h7)zJd
Z8D9
7_z$
rn(Ug
ACd6
&o~
6IKF@}
ResourceManager
x ri
|g+WO
nxuKR]o
-;N
6?>R
u;e.
gO\
Q (c
6LDo}
#XY
8;Ws
_&08
MW^'
63tS
?aD7
Q . #)
gY Y
=J1^
m?E:
T,NY~
wO0=
@V%tR
R #.
(6U
_'AT
\Cbt
Br0C0
C*P<(
pP<`,{z
R8HH
x8q
+7 e*a
bJVaJo2QiZSxP9CRZGdSQ4B
?<-9
>6R_
:]O=
T\ev
}V#{
m_:+2
,[vSp
Xf.l
: 4CK
'2WI
[Goa
7NiAiO
h_jI
-}Lp
@s]\
,rm2
D>wx
_}Pt
RnR+
Ih+p
O\4O/~
(9 H
Ia&;
)T9:gr
F"h\
w]vv
Lp=3
U4{?
8eW
tUPer
T9,Q
eA\,
S2M
/Z1zWrPH
I-4m
we0P
vTAh
E0~J
:N1[
`nY;wb
O, s5o
F&9s
/7=WU
!Zg@
"m$(
R):NR
C<aQ
Y3?h
H[M#
z]?
5l}D
L#5T
@wTe
{b`{
J ^ eV
bLxo
'f
IL]D444
6s>'
gjjg
p ?3
]R%{C
^[-
L^SDQ
N:$X&
Gi2KJr@
-$B4L
u.y@f
e@,`
gq?b(
E`|v
W.C
444 88I
7C8<
}Kf{*.W
3/EZ`
y:3h?z
riwv
X}A#
I>jE*
`(hU>
78`#8N
'WnZ*k
IMyO
JE/B
.gtU;1
GB7E|
).$S
KW04D
PYi|w
!5?J
A 'a
!?
{<Py
\|VX
%MdZ
")hhj
6I1
|VQAI
%EKx"hz9
j{+PWI
9-9 C
}|Ur
MoFp
7PB$
f#~CJ>
/Ps#/'Z
7FH'
H ~]
CD%=6
WNSe=)
IvJJF
l/-v
SuS+
Pt;-
_<3;
? 8l
y6[o@
cj6c
Bdvo
444N444'acqE"(D
yNN# |
hql6fXnRc{
~H{R
}t>
8OO$p
q\i$>
'o,XMR
u&!(
/H8W
08S=
rxAKG
;aESgL
(3Y;8
k26Evkywm
-`A{
p!UgY
UL]\
b( :
444 ^bs,=?V
2ia|'
_g56
BI(:
-T 3
Dh.Px;R
)<^b
,NfRY
[&-,
|}JF
>-`O;
I zj$
jY`RDx
@xRh-
y+15
Wu
0jb[X
pD+C
8;Ago
_C K<
?MIC
1R-
&^Gf/,
4447idY
MreD
8M m
#tCROR
%q7uB
uos!QO
o.bF
0ZaIL
]T](b
; zm
)aO:
|[3s
#t50
%j9H
t+g Ug
iwIk
:(.B
%D2&N
(R;:-
D\2z
uW*(
h3K]tO4
0X?p
c||O
z'rq
>i<D
Y(9f
OI.:_
3i/
2|U3
# ~U(H
444+444
l2wY
"y$t
"/gW
Jr@7
8Fs@
.QC/?
7 {N"
(xWNjR
K9d7
~\-fO
ZuZE
}ga6
_q3"
w18A
gMQ`v
h >4
Q|I*A
JEXnB
fw B
* V9Y_
Y~8Ks ^
rnpw
Otrb8
1\UNP
ROpa
_UX2
UMIo)
2*a@
RpiI
L>OiD
MdDT}%\
48M&
zij{
N9}&]j
8(W+
#F HA
>VEM
mLDM \?
MvSdE
b6 ;Y
5"Me
{gFRN
j zVO}
MMxE
s'b%4
R6)|F
s$hRvPf
ezC h
@s0ufct
B'W> ,
X[Tw}
%w>
>ge%w
*'HlRa.N9ST
D [@
xF/v
<*3L
a x{
=9JmZ
H~UgLk
=b#T
~P3f
d[wE
8bzvM-
Kejn+i
94mL
:* lu
7'R<
z|)&/
u Vt.8V
"1q#wG
C,VM
I.0L
U812
V %R3
"N C'*
P)`$x
q Dr
xbQ]
2D}k G
Y`pDx
-Pr[
{dG)VkD
Q/Yd
YmW#
J~/lj
Cn4
N9l5
=.Ps,
qB1og{
XMQs9
ns:_K|
CQcUc
j3:L
Tosg,s
S} a
NQoz
YTgv
T\_S
uR6 T
Pl6r
X+[|
v^pz
c%.)
Z5rr
Ee<5
yNOubBTEIGbaB7bTSd8clusjOg
(>O)
444g444#444
d8#{
:x-w
6MWAL
D6-L
D'DH
"qUT<2
JFRg$ 5
&"@]e
pZ~l
wd${
444 IDF
r28cd!
M}x(
oIms
`4g+%
NwZu
[<Vo
[Lln
kuP4k
\MK
mrNU
=VmwC
7 @]Gb
\To'
fn+ t
<Olb&^
(\Y N
t7E#q
System.Reflection
_\1)
$n(.
/W(>_
^P k
crW^
a3Ta
/E
'qJHS
_=P@
>HL_
#].
0nSkOb
mhX!
d7n&
*?I <o
h(?
@DWC444
n:!?
ktD[1
Qg}l
'Ih[U
a"%O
+4`3
~EDQ
oP2{sh
>QfG
n {y
%,N
aqG1+
wQ-\
p5K'
i|},
RpQ\
6WTN
Px%G@"
%=5
vT-43:)
a6drw
sc.j4>Y21A
VQBV
rT}]
KE?
'H}0
M`nR
:A^2
31M
#\C`
/'J\t
# fo
aFC:
ROSW
GOEs
FDRt
>r$s
ja<
h\t`
;BEZ
'1/~`9
5DJG
.XE
lkb6eRz87kXLLvJdZMyaIEr59WCqR
0 hvF
c }(
Mq^!A
iFXL ))
s zC
rFLV
KF8
<a_
++
kkuk%"0
GB2
pW@U
74"F
_bm[444
#:jG
i?~2
1fW8&
t);-
y7A'/]UH
5!i`C
JjX
en8g
-.0lBUz
M'?-
;7_-
N@Yg
XC`g
F;4H
4445ied
`zVi
|'{"O
*^e,
D3f
gf~x+
DH+]
5r+-
t)lxXOS
?g@]O
AddMilliseconds
H/EW
glkP
rO> M
q54!
v2.0.50727
/~~M
GFq&
s"zq5
thjg
444 444 444 444
9wd~sHmG
&2O
zCx|
>N6(
V0I^
}lNe:
]"1 $g
z B\
=D-L
Pl36=w
* nB
mc}eVa
Q!7Y
`0vr
hOUr
)G%
( 30
C>GevJ
-h$M
bA >h
EeJ`
e/Er
mR.B
mIo7.
k:'%u
OaW42sI
jbjjy
#JWp
2 G~-D%
0_BZ
Q}0^
[P~h`
88'o`
!T(=
Gr ^
b $0"Rk
~oA5
Nw}^
E\]N
*Gj
\uh
r!GI
K+$B
[.B@
p?z\
=>M.'(:
4)
q~a-gj
]&8KD
`0Z&H
d<|f
0x^\KM
2<hs_
SymmetricAlgorithm
444q444.444
e }&
TX~q
NAWR
<fcn
444!4446444I444H4448444#444
lx: T^/
t=I
W|T^
rQ8(
J~
\ndR
+*Z f
i$^~
.q"H
^6Gr
~ls- -
4j8._
D :
>/Z}
&ljH
9-CJ3
Q6/P
qX t{
S~LhQ
D,
%)/XB
Oq9+
'G7
`Lu;
?]vDnbx
t[N{
W#wd
'Nr^0
3V p
I6eAE
`Ie(
HEP FFSH
QHFyk
v7b(
Q-@`
Yh-w
sI)L
Cba"
!.Y?
(BlJ
>hnE
A/B]
tZ R
iCPb
DU c
ngIf
If5
\T&}4LEa
Q1dXd
=b>'
jXNU
XPM#
3*&X
JD c
I5^%
f_fW
UWK?F
p.GA
O~'m
TXX,
)]h<
xx[)
@gVT
6k<
iZ1I
`am,444
UWK?5
E-($
z&Q
_Zd5
Wi)
{S]_6I?
MEhDtM
M2)U
{zRI
<]^|
1q c
{^ga
=S#IYE
3A*|
Ls9 yV
[u\
zBF#
<J6:y
.2QH
U"q
jw7&5R
S> q
947K
\J E?N
U.F"
,U.h
(%oa}J
.w]U{
- O(
ToDv
Z{Y5v
BA{O
qmqKr
HP,
=?81
M -(
R-yc
A>G0
Gu6c
ty_O>
TransformFinalBlock
.S
%`LI
oT4
NQr{
'\s$
Vdq4
`VW]?
BM` Q
bw=[
9F}k
|fAf
bM6(
LNF9<
M(7A
#(R_'
v^_)Z1
UAr?
\~lGo|
~C1\
svxb
WlTS
2aH|N
l6i$
sp{Z
q{|,E
Mr H,Y
}!q8
+sWn
9'Vx
ZYv_|
p~6_
I Qx
BVfu
s?.5P
<F7]@
444t444!
8p=
4J*y
WCuw
]y(i
/|sh
TNIW
oU%U
!8mMFY
9D6,
[h-]v
>t7L
0kiEAS7nwmuhoPwGbSU7Fg
71LIvR
%IC3
l((q
q7SR
^Wt
QJr{
y4Dz
s:T
Z7_=
MKVi
i{F\
UMIZ
8MPQD
~L`Wn&
fwUF
G$*a
civk
"C6l
S7V~
Mx/3R ]Z`
Zu\]
Wu7^!6Z
V7^|
f%e $
iR#'
%Kd'y'
mh7^
Kf`n
ak0`V+
+6Tn
%q.d
S &jC
&op,L
9 CUY
System.Runtime.CompilerServices
QX!c
19fdI
~d:wI
E?i%
7M-0
~es
,>!9i
444(>ASh.,6
) MA
*o3u
IBCQD?7
jilO444
)@^M
444p444+444 444
Ff]r
5ao~
%>|I
Mz6E
qZG6F
K&bF
]4je
YOg}m
WtL2
g!
>j90
]4_1L
Qb|&P
_Ikt
8-9/
h J?
0hF
x1H8
<MT\ x
yN`I
Z!0
zt7j
CQ6d
%:_Y'
Pc-6
DvG-
o ~> 7
[!kS:
w*Ns
.,%J5
! 3{qm5Y
)S[2
}S+!7
HfEX
P5V-
) ZB
HsW
: (
09Jz
T (z
L!k}
h>.E
GFKo444$444
oQI,
ucw1
ijEY
^J)O
/&+x
LRjY
\f"!S,
um4cX3MT9e1WsXN6E1CY
3(QrG\
L;4s
Qh*;
SLSo
tG0ciw
L-W }
!9{N
=4Z*
<4j
Cs7GJP
~|K ]
CV[4
YUe]
~QZ$
`w#1
3;"%
| 4+b{
do@,
()\=
:}Qq
uc,N
,ULDm
:pt
N !5
R6 6
w8zk
kkkm
.kyf
JcqK
izS|?
/<hj
t]&
Ifu%
8'h'
W)?Z
JG"W
Wc{rL
'NO.
@!~
`[0<E
FSI
y,ZNC4
]'{U)
B<-1<
{0~wS-
z&4w>Oj
!{abgV
Z~j?
5~zY
R f
U2%[
HUs"
cb/u
!y5V
0z o]
6#]x
K)%/%
gq\^&
&QW!-X
_}WU;
!0UDt
c8cB
H/([
.{hKV{!
<l(Y
l6 /
juXo
3(?D
bYlr
n8\\
DGT?<;C
#,&4
rwmk
444s444)444 444
f.{F
|-UE
D)(G^?"8
L6sXW
hai8
emIu
Ea{
j1#K
v ;pN.{
iQW_%
@b ?"
FNB2
Z9 6J
i}\&e,
/X*tW
)PK,;)
XuDo
k,;+!
H*XU
|D*T
"6w.
H2E5
0JbF
}L/_
V^@r
s| ,
'RtH
d&y`o
& ]+2
KK\?
LsaXq^
.<;3
g;h
444x444^444<444
"Xq
AiN}
- n3
9B|?
CHHx
G{~+
HTA5
^7\
S@Rn
)ubZ
qP~@
|$ L7v]
ui!`3
72!y
iM\#eX
ADH 7L<
?P'r
*my(*
69P_
}]l=}
F> r
H j;u
vB~d
". .
3I:{
4v|
/)"w7
1VCI
&5BKD
XXxrZF
%3zW?
/*`{g
"6v
`$?-
6 DDx
7 >"
ab%Z\m0,
WYL3
Hs%-
RLPx
{m;QY
2fSG
rrra444
u}zZ]l
"Sc&
+xW*
M 5
0p!<%
HT3!
444k444#
3p=4
Rd ik
9DFB
$3o"
[oDO
wrc.
f <=
F9!(k
_.kk
EGNx
1H[ >
P?9s
BwL]
IrFx-
bV` 48U
BFZr``[
0x+Vo
M9Hy
};bQgC
UGhT
f2pw
X0Hp
h.d[h
3[ !
<:I6
eyAtO*?E\
asy*
H[y2
NiNHt
1&c|a
l7Z0oLel8CNN9dzAfCBB5Zgp54SrDqm
ZJ.^J
ZYCx
m"jy
"#:*f
}:,/,
Vv"{
444 444 444 444
U/BZ
Ii2!
>| B
mRCk&x
pK/.
EM\X
:L(=
ak2d
<h z
\y,/k
eT#"!
w" c
Z_lw
u}B.vf
*r>~
Z(F,
VI|h
xL]TmB3
uKe1
SL}8
lSJH]c#
w=5aXK
+1zI&
%_/q
[]RQ
)< S
444g444;444!444
Hwqa
C>y
^=:`8
qM|m
.J#0
?5vk
444E444
0.@
;8*5
9B4
Z+' _
MT%[
5 U
B ~
]2"5@
XNwBt
~Q8<w
978Z
})fLa'
Y'xsN+
$k$5t
GM(a
O>K\uB
Z^H*
4441444
=PAy*
s(0y
3H"j'1r8K)>K
!-/P
3ICxz
89ec;
hr;Nc
$$g]
/^e!
8-&6< %
S4r0
%=-8
I SB
9XcY
n!^G
()gO
F<4 2
<O<!
L 0Z
e w
t]bo
2,QkN
N3u0P
=1~5`x.#
QBEK
tv<
+We
%8J|f
_3q$
<}xN
3x 6#O)
Y\iT444%
"lR8
U "]
{)h<q
*L5>a
NmNE?
L#lJ
2h~`
N\sV}[
9GXoX
Z]rK
,tGn
KC3>6ss
!E*=
#@":
WUEm
j5b:
?l_v6_
=+WV?^
$7
ccpK
}|(^
g|W3
zW{<-
0,7O
ku?{
zwhi
\^jCC</
hA m
))
!a*>
Th+Sr|K9+
{vpt
#*D@
FI[C444
Hm_!
aP?4&<
XfI
+E(irZ
0{Ip
6o&i
-V,6
+\ck
??; 5
(wGB
.%!z
Kw$C
`ANT>
q0U5
nR'p^7
x&U5
\F =
iep2*"
O5y5Y?
>+q
cI6J
bV36
F f %
Dak5
V I+
YpAw
y 8h jW
b9ePJ
/I%W
J2vy
XDAG
~;[nn<AT
;}"a
~g`Z
} O6B
R <
&}JO
%8jv
|kRB
m?%f
1(Arqw
aJ\%A\
6`?8
BrD`$^
-9Mo
UXs
}mkQ%
0z+T2ot
qCE3c2vEleaNWUONnzeBf0Z8t7alnbyO
!#v~
`$`Y
plVr3}%-
:D]E+$
VA5#*W
i-s
#npRWlR
vJ L 10
b_$
444O444
LDWN
<l y
Cj5j$/
}F!zu
th~e9
%: P
~9S=
]X`Ex=J
\'+*1
!m1w[
3)o1
*OqNVG
Y&\UID
UsX.`
}n2|
fU;H6
)a [Sp
5_Z]
#LJd
x<IMQ
(*oh
UJ+p
{%S b
3~y3
+H
15ZJ
+.;Q
AdaT2c
BR h
CB*e
Q702
!(nm
^WT1
8%sJl
|(Tjk
7rQ_782
w xO
:UMh
:(Pm
/yo>-
,+2KG
@v1~P
MGcKg
"fR>oF
q-GZ
U|Pb
]^]$
0JGA
@<A j
FDou+
>bUj
0|\
$x=yg
?BTD444
&vU>_
I5My7V
p:4V
lj:`B`
j 7n
O~t)
444 QJSg
l+UZ
fJ~G";d
3Ux)+
g:bu
@Y*D.
yd?m
!f^V
!pnxKP
*C:@
O[\O
6IPR
Z|6C
=-RK1
_Q8=
_t}k
5 (
(/(r
RmFa
qF o
v_|&7c7?7
UH&H9
7!*6
5-x
)RPkIBqf w u7
0?zi
5i_}P
Q,9y
l'_5
444)444
mA1{
=,u
mC;9
U3,r
M|>f
~e6Y
rr 9
](Ta
4Kr@5
OS)
DU_-$2
ick
~w".
\jY
eNOH#{
4Ig'
p.&<
`,:R0
Mp"_
1/7Py!
8*wwsc
# /3
Q &i
[3/
/O\6
p"#q
>%Y4+
/0 4
7>'.
uE*#
x A6#
'}l:&*
=*(Wj
444 444 444 444 444 444
>B35~
@E8y
~Vc+
e.kg
<PCV
_iU^j
e^=+
*DgN
3x %
jig?Of
wZ&x
R%'#
1e[_
LdB3
@UY'p@~Q
3 fn
444t444$444
:onBt
2hey
:qZz
$\_#
@{ T
zGbb
N^g%a
_7ZuM
444t444l444k444c444A444"444 444
meTJ
|Z^`~f
%OPD&
444l444%444
99cZ
!a;!d
S<K#
m3F}2
7Pcr7_8
"@eDqX
tTeZ,aS
|m'6
:1Dx
Q$9
Yf.@
`acd
vMUwD
@ f0t[#Xm
KKX5`\B
jUQC
OL^x%
N/j q
T_+ka
0?a?"
r% 8
okfNE=S
444O444+444
^IRy1
\jC
=ZMx
6fC
/PU%
#6B^_
lllm444'
b[mAX
)6*E0H2}
>}:Q
$S0W
7%($$
I){t
4RkY5
;:vA
-w/}
j0
'I,\
3\w
<+K x
at2s
^y2F
get_Now
J,>+
}Zo'
444W444!444
#R::v,
>efU
CO,_
iaHnW
et\
n|*5
VY-2U
oWW!
w|K<
5WE0
T=ft
'~?`
T !H
utc RE
4;`y
CWzo
u;?N
[O gP
T2mF(
HFp/
#Ua}Is
$LR]^
Fr#(
5 xbb
Am:d
@8B5
{xB
)N'*d
fFU7
zUVX
3s$`
rQU`NBr
I=9V
9 B\
}9Rk
J)7K
P,''
\f}8
O|]1
<"2N
M"%I!
jJSj
GFLM
p3 wt52
o74W
d.I#
k)z@Y
xT'o
4^{`
mkt$K?0
88ScAC
`U[R
ZX;_C
)dC@
kGdhYr
~qc9
CV:'[
)<^O
t"PT
~^q#
"Gb6
B<>:DA=
Mxz,=
O`.j
JWRh
)R.!@J3
CDNE
F( L
A_-Q
y\M
Tme=r
:]E[
V 1<c
Z 6~
<_#2
f Au
4444444
Zl~T
85tz$
~h:z
x_ !
Nx(=
>=(W
:`T[
0 F&
V1ZcuJptYJpHVqKBGmNtrM0
}[ m4
=d%f!
T-|\[(
u\8,
oSue
1)Arr
oF O
zfmv
0S=
vDh[
EV`Lp
j*(+
xylw
444G4441<A]
Rldu
<>hzV
H:k(u
bu+Z_
bTb>
nx[
:o:R_1
Y@GE
]xZRNR
1e9 |
(zTJ
"`d\
%]Nr
f\i3c4
{79I_=?
/ `mB
/[ b
CU(y
H sKWZW4X
L o
j?kWES
BY ^m
Il5g
10S~
dO }
(qn$xJ
l~)%
g\jV
z)sU
X32>1
@=Dv444&444
!quR:,
6Y7{
~8^#
zZaNhEg1
I,PN
IM.u
~ov
UXkk444#444 444
x%[s
<;!W
sn9Q
;]#8
P>*N? [
{:z
lihFI
qsu],NMl
I{\sD
>%ah
Ee-tf
iX#jB
D=S]
CGD/
qR6*A
h|Q0
%wDId
y_T-
b|rX
S3k2
??21
6Q*s
-OI$v0
#6K7
z ueY
*P>-
*-/O
KrH-
Qc9rx0njH2c5l1ZaXXW9juHVYv4gu8
ijn.
I^:d
O"ry
mwk6
]60v
J;&O
ly9wA
AVWsq
Xy<^&
*!Xq
qzz&
O29|iv
h vZ
V[r 79M
j75%
eULO
O&Uv
?,E
@k[[
,6?N
v4v\v
QRmE~k
l$gB9
]8X-O
EKO
l-A*v
vc87
JupT
\Y}
4_%
D)2Y
\$kc`
omUeFdb>
X?fX
Ly#g>
4-*vK
1Go%
I/d{f
q\ps
s/F
\8lZ`w
Vv C3
4/k5
OQ7'
Px?w#B
<WDn
ku9E
l 9M
{iA*XV
@\C5
fj?BTP
'CWLMer12BAJYsR9DM2FnTXqt0ULVnnAqVBkL4ws
5 "(
x3yC
T 6k
djP1 J
wH#Og
g a.=bB
m[1zs
^\EK
Nj*6
9Fyo
_b6r
[\ b
!3M#`
AONPT
.!1 *j
FZsw8
A;w:
$(9
.{hE%
f{lwI`
6:OqKNa::>P
h`L'
L9 _
- ^Ui
<`&r
hk|q
?H:;s.p
',Wlk
Oz
\[mH
D*u?y
m6*
RM|r
Gw}F
nI^R
nPlZ,
KOG0E
Aw!
y\>4
I'(^
c"ux,
*>ME
In^
E?8T
N='hE
R%6('
). kN|
xdL -d
0@VE
eFP1
pT/=6 8J
444 mo{/$(>
0u
p})t
ZDW9
e>.
bWjM?In.
it#.
[)~_k6
1?6]p
Z\hV16P
XmLO
dOEX
*8 E
1N='
)f
#.?T HO3
6.q^
?VGq
h$?b
mR$y
2z X4
Yah'W
'"o
s ~
t3WId
{bE
-PL5
I&|{6
j!1~
{kiq
XmZ>b
3{sm
8NeG
E8[9
lSrE=r
^ ZS
1;/O
]g`C
i#{SB
444/444 444
Ss0P
F5U|p
:r%s
6eVwV
;;KW
RJ7R(C
PX^::jL
444~4440444 444
Bt;y
6}I7N_c
j7mf
WcZ?
9)l?
b:+q
&^\t
wN!.
ZVa4
E8[r
tX_i
6kS
DdJE
"OX5
dg>@
nJ:q
SjDI
N[`1m
Z^r`
CRcq
y ~*c
gyFG
4YDc4Yyz4rEyJmFda4PM4
cFaj
KT sI
GF 9>SL
/k7u
s'S
bXzf@
,~db
Y dn
8q;+
:K\\
C7L2v
ckVp
pf*mpc
Ght
)jhh/K
xo[
/WXn
b=<N
<0-(
F"s>
OM[.
@ dE
) !=]
6b .
F9OM
R"":
>[97F
Z10
9S~,
(j1|
b!i~
A_ o
S??q
H#Ng
qT(E
_\;T
get_EntryPoint
oi^R5
~^n@
waY;A!^
E]P3
3zH
zpZC
/ni
KEai
gI-A
HoB<
oG{5(
NNxm
T0@>
b'}C#D
s\[$
=1M\[
( O0
g0Hg1
/`Zu
;/A
fyVI
t hP
[9``
M{T@h
sv,O3
[^Jkj
of0!
r9a)
y9Y ~)
%~oG
pwO _
l @H
D+]T+B
'.xt
t=`A
-~p68l
Y&0
5'W'
0!v3
r@<g
O3 ,
#]gi
Cmr>
,{P
9-P!
O_TZl,WHd
t/&6
499o
/(5
yCV<
,)HG
#EH[
444:444
D}H:
*=4G
r@^S0
xhx3
r R$.
}i%lJ
IK0y
>D/\94
s !2
GXs0
N&'O
/85}{
H$O'
_46w
b}nC
P ;y
; y
v ,O}
444 444 444 444
CF
+5o5n
Y&V
System.Collections.Generic
444g444
_^-S
/1zz
4442414{BBH
~;d'
r[}L
',CQ
9[p6M
LWJ*
xFcs
>V`e
X_B@
{1?1s
O^b-
o+^/
#. Q
b_/(
_^v
tA4WuvTwm9F7Q37rdGQvIX0JJgh
{euo
S9Hl(
.?AA!
j];E
WZ2r
g'n
[M= `
h"A(
mQNk
u>#){
- p^)`
Z)fi
xoFs
MaOD
'Ru$1
@jU!
U`UA
DW@S|[t
?\MXV
[Ve
:-Q`1
qG
LN%Se
%2LD
D- S
" )
@;Vp'
-&).
fmFEad
A, t
fj.
'2Xk]
%w u
\a<m
-"Me
B&J3
F Jz3
s$(T
Tx$s
}SwE
"o:u
l?9)C
J2*Y
OS0}h
~ %bZ
!VL;'
T<l(
C/~
eeD]po
9,ufg
!7clbFdwhvvIiray0tmWy2OQhxHdx76apJ
|YA"#
Ypf=
:XNXd
6'& R
Hp-~
G 65
-N^w
t1E
gvd4
t9_X
<" y
";j
U,sI
aj*W|WG
*fkz
Xyla
H)yc
eIO(
6mXTz
GF!,
1n.)
wPyX
$88
='*J8
tYz.
PP<g
.vYt'
J]# "
i??Gn( x/
Eu%
2i jv
j,I
VI@|
tB0v_}N<
2@ 1
ksa
\(le!
"Dn8
: v b\
8 BA
7y*T
wWtLP
9jvBC
Xs&qi
O!{d]
\!]4
4444444 444
cgU2S
*$$;ap
n~'H
-"FXS
Y]:-
fjzBz
6P
G#C.
^uJZ
.=TZ
Nm/:
=XX*
TYN5
~qbgl
TC'^
p\U*6
Rn?}
SEZo
rB|0O:V
"8,A
*H<7
5ni}W
+ R c
S;o5!V
v0,"_z5
Il7G
JE ^)
HCRq
CX^
!U}qB
JX*j[ 02
oYxH,#
n'r|
A3[ J
F)2B
444+444 444
jg O
@| 6
]*8r
CNz)
{I #,-
*os
k|uF&Q
h8}/
d/"/
@ ot
QJ4V
:"d|
8, ;
}KDW
5*Qo
ruIe+
F-Hd%q
*osI
SOP\
2ud
4442444 444
jDD"
uz^
~Ks!7G
@ o1
F{zi
208)
444+444=4449444,444
{ fdE
kfH*(
0i>R?
PH.h
'=gEx
VUbdADSN444A4444444*444!444
W#H##
U1xx
NMDAgt_
)lG4 B
y3<H
-/j`
t}Q
G0E"
#gWi
a#7=
8p n
@\M*
Y}(2
x}WU
V\"8gn
2@,>6
iFHe|
otKO
Yjx!
444->=Fk857
G`_s
$)> 54Gx
ViIf
Fxx-
:(%~d
0 g"
i@@MQ"
+Y1d
%PHUtELATQKPQmJ9gNTVJKwHG6VUFxN9Ct3m2C
a!8s
]mLUS
w| &Mi
%G 2
eUm#=Z
N H$
5h#9_
6TD*
/i O`
444?444
92?;
g,-PE
P{4\
lT94
Z*g
mNF)
$c0z>
$_-'
p^Rl
5[%_(
`67&l
?]mj
;/;,
IKU'
3"jWU
E>x8!
OqDg
OlQu
`G0y
l^|
VX=G
*:g/>-;
}sH(
BJOB/
s+wK
rn1&
wk87a
`)YK
/vb j
}py}
6;iW
69;8
nR?
?z3r
6Rz<
VCV|
E(b<f
sbpM
yupj2
>78,p!
%!Ng
LLvmnb
yD8
4lwQ
V,8yj
tP`@D
kwfCBm
tzDN
Q{ti
4d B
a$wN
#M r
B7U8
CxlK
dKiwbHb7nrUXi1IzJ7ErS6TBeHIwGbs
]huoT
; 5-
2;Y^
t~@q
WAm<Y
8 )JY
AN~~W
.~MZ
j_(7
sjxd
xI1&
0{VK=-
jF3M
efnW444
C!( AB
71[]"
{Jz_$
CB.O
i"aU
Qy31
B_b
zKW:D
wtm4xD
}P A
7rtV
UXk$7
U[#,-E
XC J
9iV8
c w>Y7
tX R
M`e64ma
MB v
~o~D4
_U%lr
,+x1
~)t+M
Ko l]q9
?f)C
4WvR
p7]<3
U;JV
8'fg
c}2*
VE{H
Ix>cS"
&pJWW
{:b@
.Xep
Jpi~
b]<Md]
fv2} v
%-1W
ngr{
s8|x
mq.m
NSk6'.N
!.3S
.QF-
'/oO[6
x&!8
}D L
%;;='D{
=_wV
DEPr444'444
\xR
x* j
Ip60
FbYL
b]No
"lsY
*zLj
Mr[yg
{PP4
S6)+JSl
dXN4Yso
Z\3n
=DSr
Y-h
E<B2
zxX&
nu;9
)[ t
4p(7
sYBy
]+q4
I1Kr/?
8^S|
K@Y|
fl>b
dz\GP
evne
*~Pg
_aNk#y^
9{UOSI
Nf-G
ZsKj
: 0]3e
:<@@
$^)P
IgU
1d'm
Y_M'
)ob-zU4=
pm Al
Q<C6
WXeY
~~g3
CD%
]_zk
=~LJ
,2Lm`
JpSw-^
Nxl_
qc sz64
+Oop7
m|H
D L0k
nWr
i(/
Ler-
n0=7E
8Qr"
M7H\i
ZP58
4440a^aTWX`
I3kn
oxCg
B/ir]
.9l; ^
]H3Tc
I]n:q
r<8W'tl.
Zl!Q
7o. 73
'7k|6
X09p
bBAo
444;79Fl9<K
CTjx
nG
$c`m
~H9F
ZN pa1ta
c <.
-NJn
sJnf
F;y*
[ t|
Jj`D
^ "qB
444*444
!oWg
-Nb/
2.v>
.:l:
xtd_
iP==
1wfO
G4%
qDSJ|`9
*Ny5
:Pux F
"cs K
jjPh
{s9hP
n A1
)3>
W"?/
5F|X
tf W
(]D
Z)`E
i #s
!u3U
/nvP
,+$
Okw
5t!
9*o[nKg
sp;\
D#uh
&@aO&P
@E ,
>OS`g#
GnLo
0?Nc
kvzh
(xyLUT
|+D<
-@:J$
]Tb|
H#qx
gK}V1
)! /
m' L0?
Lv)]
<kT>:|
qS8
NRiu:>R4444
`vR9
K#6Z
2H8CA
m`CE
6=`BG
P MH\C
XDjO
4;;:S
l*_!?%q
+}4m
'jBs
A\&^
kRQP
JI'
sKFg
4448444 444
S4lDU
xUSU.
.Gwv
VWb=]l
Rms%|]
3)xy
< /$
GBiy?
]x3#w<
J|oM
-slC
`\*=
==J+444
444 _]Y
NBsM
u?@'9
~L~$
MTC$ 8
~3gg
$~3Sf
Pmb
4gmP
8yj9
'by$}
wi\M
_ q#k
k7~B
Z "-
s}GQ
"^"yL7=}
rZ;A
i0B7
444k444%444
w yS
KQ|b
x!HX
A+Q>9I
y}qz
aI'"$3
Q68J
#ya C
444 egu(b\O
0Y`E
YV-
mMY'
4\ R5
yk}}c
JRQe
I7Iv
#f<t
1gja
i;Ur%J
444N444
/z $A
h69Fh
p@q+i
C }
@) P;O]]
TBeA
49Tu`ao;EJ_!444
W~BF
(gtz
i&~= *;S6
7rS#
@bq'
pw1
$y7xzOPcdhokpAEVZditpSyUBlfjUGoCTHi4i
0- Yf:(
gV-8
hf^z
40$Q
>*Xc
444 444!SS_V79F
B>)B
Gp]Gp
>= y
(UI|
|s#?eC
76=762,}EC?
`cdT
:dlK
/;Y)
zfK`
;7+O
mrb#
F|H
@ l
+anI
x% (
k"hrc
Bd|0
TalJ
TPOe
su^]~
^E2/`
O'R#[h
[^hN
88\F
VT$~
Ho{2
I+z(
D&W)d$
#s q%
{L)G
/jo?c
F!][yS
qo="\G
\zIa.!
C\+<We
= XG
FA1/
p)
;fx)j
Ez#y
c=5C5
l,&g
FrT"
U k$
mfX4dgHoZlT6sRvtdUumZP7hfx8Li
!@ d
444V444
WxhS
;Ih
M9o
yu9u
c6BC
*ugM
Es!g
)$~2
j!2E6h
uxj|
V4wU
u )u
RVh9444
sZFR
^y8 [9\
U@^m
" |[~w
s ]f
hw2 @
444J444
DX[ZD
zu}z
-s$>
3iyl
`aly444.
< <|
0b21
L>q#
.O<
w ;w
/?}d
=Z{bxJ
S (<
>C`R:
!Qbu
X:sk!
Ect:
?VK*
NW;U
T-l`
(/[d
444&38QgAAT
@6 7
$]}0
#NkY
!?Xc
+p$h
m!_
8k?v
80tGJNYA7jZjW8XoPKvUJ17y9
g]J{vs|
444b444
+`Z2j
Nv<Y
u41<
%a((
hV{"
YR^L
}Ep
,Cag
=RO$
>y6{
Pi&E
OKI2
:$TM
wo5
*mrk
] JIWX
3W qO
3TcsR pa
4cl)
\E`X(E!^s]
#P]F
wioZV
I*SG5
b|,
>GxpX
^1o$!
n5^n`
9OoiW
x 15
#<.;(
0#wK;
;H15
DM:R;u
RITPH?-
;.m5
o;]q
hV~?W5
>Zko
z X
hE3D
];+D
}_+
e`d3[
UAFd
MB+m
itM0:|
|GO}#
HD;,
zXaBE
H~Oe9
%***Qx
5en!
zL X
zYFp
.1~_x
&<fL
n%l
u>C(cG
nwp
uYQ5
@H#
tQ-D
cN}'
0^{d|
}m
OB_u
444i444&444 444
ud,x$
(2m+_
BYFBel
h~-)
[mI"
dp#u
D}^v
0:@(
a&O\
L9 PI
w[>qh
-eZj
q24 v
Ku+`
Ny,AZ
1?wqT
Y"eu
dc}Z
+=bw
WY\
^o`
m$WyQv
&Nw9
r8(2[
tbgykUPN8WOzNtPDOrH4gWz9
XRXG
5|y;g
K O6
ju #$Q
3-AY
h77?0+
v%\G
cAu:
q.4S
p9Ea
_ X]K
KZ=C
{`d(
T` -FJ
&CSh
:my 9
m>F,
p{Z}
L-7%c5
\{&1
;. =Q/+
WzU
;V)
A%N]W5a
6(+&
p2[M
Cer ez
s9g:
*&0/U
Hz&B
F?k
bAWo
*W%N
#hIK
7 rrwG Q
q1E:
=!,~8
^%hb
yqB9v?
FnT8
[b7S
`P|;X
-)0SQ
a'"g
T-OZ
MeP4
?*a21
M-{?G
WIqH
z(YM7
^MbR})
@ Kb
444 PJP
\S1!
D= j
hN{'M
PUi8444
444 444 >?LV=>L
Tb#[o/
/%L
_O #
1 T6
X 96^
F??
NNrRd[*
hlW$
DD`m/
P~-\
U<?
<<f
ZRQf
HBM#
cnZ
g?@,
;"x.
Hw1
w fY
|B_u>
m u4
W-F*q
y#{f
Bvr%
w%RTk
@<$x
qw9u
)_^
yR!1[
4447SRU
z:\Hd
H~jW
444A444
444g444$444 444
c-=6
*^oM
; R^T
VX n2*o
%pCq
@<$F
444 444
1WS']
@p@]z
H1|h
k[d[W r<
&^kE
T,%}
EKF@X
NaX'
e}R*z2
[nSC
)3D:@
sl{z
RVpH8
c'/]
TAe h
flrj*I
2 A?[
'g*cfQ
o:kR2
X;MY
s_Op
g.Yz
|.o<>
|`#3g
0e'BR
e`bAk
9|;S
wDm5v
%'v
7K'h9
-}yR
[+Gcs@
5t^ x
6![K
G <K
^B3u
Z6Jtq
MX4I
x/Ib&
z&X-K
{dEl
:hM[
WmMT
G'.8
)cbI6
UsM(
3;Xg
D'm[
*%GZ
G0~(
U)4G
SlkJ<
ipk>
OZZ
V!E1
Hkh !
8i,b
eub,
tV `|
UTo{x
Z :-
G=h!\]
qczL
fhrs[Y\(&%(
kWQI
u$ P
XRMAf
pGkr
aY}KM*
MCI
_kk#ehax5/
f5|G6
g<0j
f1 U
$/ K
2 O
{OXF
tTT=
eKlZ
xB0uy
!F^4
fJ0N+
get_Message
V\R1
OZr.
C[28
t7HeW
E;=T
Q7G 6
GF%*
unpH]
N%fp
l!*
/Jg
apNV
B /jF
SGdV
i`OwO_lh
bV[xJ;8
9_B=(
IdGgC
Q-^7 l
[fiT]A
Z@>]
(Ff6
(lUR
O>C%J
.P7@
T'hE<
P/bM
{VxU
dxD@K(
e|pe
66Bu444#444
pEBBe
y;CY
WSY?YVO
VRJl
Xc3U
?w~n
q/W!
^MQh
wRsW
O!(s
r nq
gw$:
aQl3
=3q(
VTYx444(444 444
F;}(`<[
H-Y6
Zf@*.
FS# bG
X2B'
5Z e
n5+)
64 m
75/{zo
_)c
* NG
:xTp
6MP
y}w`
ikz PMX
H JA
YZb2444
5%oD
4}A
1ugs
B8JF
?{B{
ie[;kvj
TUe]
C+3.
Nbc,
BSJB
DfIgK:
Nc1$
tY.e
l:\
VwXUY
oVx K
LEK+KDA
Dmy>
4%_-
eMWn
8D'7
> `N
?uH
~>FY
/$F0k
#jZ{
x=Uq
h|4
'ZrA!
R.$T
{6$N8^
SU`ePR_bHJT
;MX-OX^b
Mn*IsT
.nN@
iy#O
,CFX
~deI
$Wa#0u
z5M~ d
VYiv444#444 444
|\0'M
,^tm y
\Q$l
<=JJ#"1
<m]7a
y; t
Lx3t
^\ [
sCom
i l-<Lp|
CFFb
d8 5/
&5h!\
[^jN
~js/
|g% 5"
nYlrM
/ RG-k;.
zt0v
' UAR
J0lB
\k&b
D]t+XX
- Q|
PUSN
Q ax3!
GwY V
/S%}
YbG7
= gZ
(*;959P
c)>2
ck?"
2!h-
%I%!
:%|B
;ewv
Vz6J
ypCd
2fx'
H~pXB
1n;lB
xCG_2
F'<#y
R]:S
mPtO
ATMu
Mviy
8HltY
ke1
NOV^
!iw,
qu,+
?"u
ke'
`(No~
%SQ
_PF%
at~Pe
&k04
JEv|
'<7N
j} .
,e l
%&Bwf
0qL
m1\\
lJ9:
.IOz
6e\0i
knL)
5Air
=R"S
-bZS
UG.%
ug]n
{hBRe
A =4P
@Li`
M 2X
}sDZ
T|H
%D8h1L6p
A7!
=(jD,P.@Fm
bv<3
B(}5
444]
@1TI
kmjW
`f'G
444{444-444 444
F] 3k&R
H(4N
Q!KZ
+g[P
ga1i_
{_f(
aLb3
dI)'k%
y6`\
9YUr
;UT/
n(Zu
$HtF
-)PA
wslc
]UK2
G{<t
MAtU
Qf"~k#
L]Pc
e(yZ
Qg<k
RD29vqx2NtjiEY5kF8VxLhrT6FETg8
Rdtr
79DR
F$dX3*x]
o9R2
Z5HE
u{y*uK
0(f\
7XY:
GK]=A
312'
>$*SEm"
B5/f
sf Q
xFIw;
.UZ9yqP
1| A
ia Zsin
'q?V
[&RC
Z:?~
.zw?
_+*
!?_V
oZUm
bO)&.
"5eL
GH+-
:>Q8%&6
za^=
&8+v
#KNS
444-444
qpX3Q
=iV#%
S0G'
i=_\
):qn
L]*,F0
Xy1)+
3kd7p{
^D9"rVjCn
1EOd
h7?z
=_kt
h8 !g
,5)e
-,0C
cR6
\v`H
V\^
PZg)
Qh("=
qpZ,my
AgML
WT,w
mMFQ!
-W;T
R1_7L
ikxk$)C
oJ 3
k%]N%
m;Ya2 [
6AxJ0h
!dPJ
|qcM\
}~v<7
)SUD
rz!c
8R4A
2A P
H)@m
tMDB
X]~#
mh rj
'52O
|* X
* y
k^ky=
EH,=
@AI>USS
6na8U
F7<q@<)a
@{Ch
~f8`rd Wo~
%},q|y
agvm1
$l _
NS)8~
NuX
AqrZ"
)9'!
#\w6
'73
4Mcy
rc#d
^s$N
=:S1
-X/%Z
@8M0
vg }O
aI3>
yB~
24=t
p>8%I-
wA/h
q2a2
G]^>
F1F
EFS/
kV9B
+KH
f~*QJ
'yGl
X2yE
1qD!
1sVb
yA<D
W%`xg
si7
gF<?
h-A~U[
*h)5w{>
W[3Z|
TZil2F
<Mj1$M
A8@7H
tw@%
;>ucn
7%I0
xuL%
<,Vi)$
Yq-8
'6%Sz
r ]?JMoT
"T(
WDo7I
ocwp
iFK4
Inw}
4y6.`
@VXX3[rx
f@s:
k f?
CLHV
ed:L
>%zj
*0JE=*L^
F/-U
xmMr
buBOY
h$ZKA
K Cp5qe(
8[d=0
vA5|
J[v@
"@ln
| XZo
EGu]
pB*?
J%Yb!q
"iCE
3 xY%
0hL.4
RP~l
%$qY\
,L:R
rQG"c
!T1l+
:lw6
JfX`
BM'5
7pGOhu:8
Dd-]
Gl8r
SBar'KP
eTwgi~ !C
VNrc!r
aV;
[A#
8dfu
v'RiI5
lJqV
E4 {"
8+lT<7p
TW"g
]~i]I
bbk%k&[<J
{ANL
}% n^bT
4447HJR
.R?}R
((jk
usAh
6]N8
||^.V
hpmr
9fcA%
;xnv
p12&KX%a v
>L1
KnaZ
q&%Q
))UP
C++wK
mS #'*
H L
.tgdZ
x9 1
.A23
J;1>5RC
=yz8dc
ih}{
wl8SP{^
adS
doSn
"q3A
HN`
B_Ytp
@46L
` &h-<T
}+RQt
( 'Q
l-[\Y
vC7
{ib[
'y$B
Ap;Cak
}8'V_
L'<!
Wo]=
5s{A`
Zv!
E&F
6< /
,Tu$
?t`i
xnz!
Yyi_zSGV
>[z 0
ee@5
#WW n1
eA11|'1a
FXX i!
) x<
LqSu
yG#|
Bt~wn
H O(Y
";B+
X |^NvVu
we>(
Qklr
Yh9j
@1?_
4P -
rI>g
ZBpI
p _I
mtG[* k
C =%
{ZHj
sd!>
Rp6<
d`8j
"!9|
T%eq
FFDj
wC>)
E-35
{-l!
M*B;
acs.KI`b
i"U5
7qH.F
RcMy2l
>EB!
tVJl,
a+=q
}M1fo
*=i9
yt$1
8A):@
Bk^,
,~$|
6E_
fcm.
g$<a
C{{w
PUN!u
% |
(#ju\O
n8|R:
fMCB
}"MPj
yJs
s&D53?4
`UC(s
i=KAZ((
K+'+
I]f.
*F8~
!2>n
oRoB
}d Q^'
`D,P
JBE+
PPJ$
Load
Bs d
fX4N
A[ -
+B>-{
fv;F
R Ng
V>L`t
:8X
U`v+
YO 5pk
;T_*o8}gS
9G(v
COp
+[E2E
>j6wP
(*v;
<Y9qS/
O:#u
$BZp
.JnUlC
9 {Zh
444 444#77=S)(,
i`iy
8OrF
8rJk+
h',J
444]444@444'444
.?QDj
Z3(p
cN`|L%
YXT;_
%6Ff)
nw4<
,h-`
KdOz
36GAHD?
U=EI
444'HGNT54;
s/~g
1S^R
)lM|x
.DsY
VERh
;2^>=/MT
[~0h
Hp[s
@CC?
hjL[z
.+jd
=9:[^e
|!"v
J~AO'
n+YC
U F-
N \:c
</ ?
OO5)
1"XL}
] )
Z:'
aewa
cp@(
>H]k
ys*xek
==H~"%8lDJkOFFS&.4M
+o7f
pe`cA
7-sf
dGGq
3nn9
}xw
"/.p
K; C/'
]G,J
EnZ@
J n
( UB9f
f3@."w
;p)
srfx
R}?$
444@BDQ
ch*<
=;so}
bTRN
,l*W.
"%;p
}0#?$Q
to11
}xwZ
fn5u
/<8&
#\Rw
%\}}
(;rV'
~739
$SGq
70X-
homF
8(KE
xc;o
mj]m
"AoW&
tttb444 444
7(=X
pQ5e?
x&#o
x=P3;V
-Hs)
"7A*
V>hi
ynNm
-xY
Ej~u
9VDY
p-:4
K[D
}+WE
T7Ff
!hc
! {'
"JsN
4:U+
*'Zh
o%XD
~+VO
+"wx
_Z)Z
L"vD
d&:E
>'w
jHfepFO229r1rQKgAOA8ady97CmhA
#d~\I
r@$b
kW S
z<RU
4vAL
AiIi!
D@$E
g|Y@
ADQf444#444 444
/aS
ct4f
@@Q
b![w
ljp SPE
%E_h
,]el
qpWs}
7u,F
TWqzS
]c@l
444W444
p7t+
v5X~
!QK `
Ip"~
'|o,
{h#oE<K
(Uh5
"5gc
.=
X_T"
O!nY
/L~w
E}M 5h
\"62
v5Jj[
.8G;
5B/#
~o$^/~=
%TXj
9b7Y
8'|l
!dR
Bsq
,pJf
dUl3
OcW
H{ir:
s ~
'Ap/
#5="Lg
444t444(444 444
1r|`
." j!
LWOGDtzQWfq3fk2Y2HCl
*) +DB
H &j
:HP`
=xtL
jKg)
>+Mu
U=fi
;NRk8
P sAN
Fu*2XA
:#O.
9N["*
hKcZ
S#Wx|
f2^$
NI0.B
8e"~<
444s444"444
ej &
Zb>W
mCJN`
vc'
JX_y!
Rdyf<Q
JtQO
A\7
1p48$
lzvj
qqxD5&
444 sqwE
NW[{ij
bS+
ht-q
KL;Wz
yw2rx4iF2EkxIyWIDPyRMokC70j
XrYSi&=
4t;Xr"Q.=
{{lA
zF=
:gM$
-uzYoJ'
"A!#1
N[ &
1o1U
cm3
i-E&
o(zRHJN
L \
Ys1J
(%Ti12l
R+j=
_^^N
eeyCu
buhy
VbP
-iwj0
!D,,
kB%d
r7k.V?
y6rY@
FYiku
/b9
TQsw
ahcq
89Lm34D
lQ)q
"|}
Fse)
j5f{
!v@~s
n|Eq
$[
xvxf
@ ng#
:<Q"B@Sq*,?
[c6t
8*xrN
-fUs
fblH
qEc_:
PJW K
KiV
c-98
#.y
]/8]
7'<gt
2mOqT
t[ $E
444<444g444
~@3+
:oM5
||5>
)QMYO
bH[I
K; M
q Xs%f[Z
hF^"S)
=4Q:
`$31
S6T>q
M] 9-
[)%m
qC7A
%0(
h|FN
aG?h
fB 8q
jQ8J#
?9kj
27(:
"Xm$
K2W+@
D$^EG
Vy2%
444D444
/~l7
'8i@
i[,hN
mf6K
`)OJ
^Wx*|dD$
Q]xk
^Cnm}
y] 2
y<(@-
]AVG
Tp<M
fJhae
E-D_B9
xHn$
lU=>
85+>
/n9'
74,
mGU9A
[%c`
QD,G
mWyA
SY|`
? ,0(
x`vU0
444+444?444T444h444p444s444w444x444|FHT
vaMk]
fUY.
,<#-
~eOF
e1,fB}w
z)Ap)1 \
|J}*
KHXX(
8+PN
Z/)X
;q"`T
Ww5U]
CIw(
444<4444PPYmnld
Aj*slj
FSfe
kl/,W9?
CliX
'5Qe
+M? ]w
_.0i
YW(,
,*2E]
gLo["TU
o-`e
kl;W
#Qs}
c)P]
J'v8
I@Z
q3c=
I,qJ
_YW!
!Z9L
inFF
F#|q
QRS?
>3 dubRN
t.{.|
q<bX~
=Zv]
2 K7Q
cHN
jFt
'm!M?
#":
^M]_
bfF8o
=4wP
6+t_
!&u=
ciYoq
5YN%:g
mx
7W $
444;444
VwC0
xz~l
&DW9
S~Y=h
z oe
(JftC
u];8C
Kx)H`
; p91
DU^M[
6vz/
nU)*
x/xC
*e\X3
rR
*@Y%
d* l9^
Bu5
^|yCq
C`#Z
> ^u Y
Y8$)
DP9G-\
pCAr
M~nH
~7:u
qG.+9
8Yi*#
Ww!
X}@7
ECsvs
"skR>
GetTypeFromHandle
^uBQ
Jn h
VqD
;3)W)N
)R*I
Q%~1
8u4nT
<1 :Ra
=*jt
'5
4biq
,*.7"]
av9dsZr
&O#PB
6|CY
i"5Cw
7g>7
>NUPG
9<~P
444c444!444
HqwG
9P])
e@Q}
Bl#|
]#:t
M]0,
Nh^?
BwSxY
# +2%
Ht[d
E"E=
h4K
=z}e2
NU !
GHR@EC?
H5ei
2?^'
z I/x
~+jqy
}X+#
e7jA&
8oY7
71YO
!nZZ
2 }T
;N~D#'
4443444 444
MOuS
444 444 444 444 444
\!
YlP%(
-VON
IGQS444
"RW]
> |h
*)GyC
"lx\
/Q!.(
:0^w
^7F3UJ
Us._
(\iM
HFP:444
)[7
9)Q
dZ C
M18G
efE}
-\I;y?
lCZ 8
N9qB
&4*uY
kaD
7g{
Xnf_
4qx<k
="?+
[4]#
Ap &u
/zMwq
c9`"
'E 4Q
p1\G
oyJ h
:M`y!
QN@b
Xxx9
% RR
f#E,c
M( A
Vr"_
)j|lu6
tAm$8
e6g?,
:rgF
0WW'
[1(|
(hw>G
[`2!
%< .o
^$ E
CY _
MZ *D
Eg7F6
*0'.`
T~ <Y
;;\|
ub,>H
AZZ
4bi<
g?N q
K9t4
IZ,O
`En+
"YMn=
GaqYG
J&;/
SfNK
|A /
f*Ey
ND^d
,$uf
"IunMgNxT1TjwlUouhg2zA5qXvJXQifgEz6
444Y4440444
j _C*
IzriTTDDj6m8kDraAKnV
$nfT4J6o3v8vwX3XpDb8tuwJNeLDoiurzeMRw
ZCt!
7A0]4
E"%e
.BG4
mnYL
}&0"t
-2q
d93R
zuHz
W)BW<
]N# -
IqnM
^<%z
System.Windows.Forms
SN[<
i-E[+
c u W
)7%a.
gt9;w
dW\R
K3b[
#j4j95mL1FI3Qmf6gzEi2Jiy7EiiTSi2CG5I
Y[;A
P+z`
'JM\
P"R
"8A1
9H 6b
3t@9
fL(uR{
6M`l
dQn?
O;C1
N:F 8
z ?
rG<wu
MS*O(t
0&D7
V`&/
l ~E
|Q0YB
m7Nu)x
@Mq\
USuK
A~9 j
S7 Je
? ;:}N
21t'
444Z444!nnx]
}7 G
2g@`j
{;Xq
GeA\
>?dk
er^S
CuTU
{d\
*3t
e"[8|y
6?93
\]UT
gd28
da2;
444_444
rNzQV
}}TOE
iKVsd[
VX A
+F&x
`b/+
y=:J6
AY[^0
|h.S*
5|d:t6
~oF2
f}KE
#do<
0Cnoaz
4;q*
#N4d
B|Z<
'hI;
'q;G
C8*76
O|;v
?_g7
w|m/#
SnOi
Z8c%w?
`<BiP
'%6m
'c b
nk]k
<-D*
08
0x1W
JD|~
UCMIi
rKA
@?S)`
3 o
[R!2
+ar=k
~rdc
2l-{H
;_04
S=G:
ZZEG
D3oC
Mh@?R[
sMqN
$Z :
E@C~444(444 444
V-rD
KW!F
k;k}
Zw|
C29Ki
fgjq
sb<2v
-A)'
-dWH@
l6C-
2S3i
@#4
RV-s%
:]c
OoIg
e9Al
NE#-
CBM$
mhU?us
0C,*
d.8W
<#(bM$j
+4EfP
444X4440444
7@{6(
l"2x
#nF7HVw0Qiy0jH35mzB6wqGgCMV0faYHVYe2
(Q t2
A#5l?
@.71
{%]K
D};4
^E>X
YoJ71*
s'YZK
" R?
t%oR
&jooWS
pl'b
+ X$
M< h
aD&^
I3!es
'EN{
s
(-?/
2!JI<Z
(qAw_
RLA=
['050
8)+
Y'!^Giy
444 444 444 444 444
J f=2
k [*
Vg(V
wwNm!G
}I+"Y4
uku1,]
]M5d
/hOk_.
5mUInX
CrI:
>dc^OoM
:}#-
H!&6
&Jn6
3MA[
7U/$vM
0=Z
yYogpjVhcaoT1rM7qtsh2IKns
;3M
3.\<
WL @
e-?k
\DO&>
.$*f1.
IEnumerable`1
HG@[
B>.N<
3e=fb
444c444&444 444
M[[_
"@Pz
Pn s
5I.\
$4"d
bmH;
?7 4nWp
H/>6
W"el
|O@e3d'
E!8TQ$
Cj(.
}+vI
o~
LWxoP
!2G*
H!,e
ILpc
l[K<
?4OwY
-w U!
g f
w8YNo
* $9f.q@
EXj8c>
7{
_$W;
)m*,
MC\n/*
KFBu!
en<e1I
?H Z
:H>Kk
]yGG
\RQ(
t7
Dd|a
Y^q8
VPX$
qEme
444n4448444
0p*Y~
( wG
444v444<444
GY\j+s
e1R/
}IVK2
o(H8Z
!&sd
_B`N
6fWk
~]DW6
(c`aP
\}Sz
$8$F
?%X~
+Zh$
Q5C;
&^Ja
bblw
;#Z:+
"h?b
444O
="#
Dz<6\
XHzq
@-_%
! bb
=S0>
J;t1J
mAeS
.`1]
<ph_
tAa^
bzC{
L[];
]elV
C]*Hf
$"2
6*bT
-u!!
;OinK
3~Hw
bU t
H`(O""
egn-
+c\f
070XRnAMc
KVP?
@<"R
wFUu
{sDU
M#+U
#XOL
D's
SrjD
pvoq
}.Tb
"p{1n
[\>(
HuN7
sFBu
9qew+.v
&w '
/7"$4
pf5s
_!lt
Ut>'
d~#pA
H9FS
w#_Y
JcF,
e{ L
!Ig
0#FU
1H<A
l#{q
A# H
WfO<
XtVs
r._s
`T"j
]dYc
o`CP
N @B
6Q3g
_xn$
ptV-i
>?cq
uRQ,s
e,+c`
~ Vw}
Ifm
N@H f
(*8I?k
,-e.
L) :
`f &
k)y~
JlH
@9F=
iq 8
it2ko
wpn~
}6AN
P= hn
[RBR
[ddV
-0B%
; &
n`9I
nPqR17YTzDY8SDmUMNHHVn5e
_ffN
C|o0
1:xi{*}s
FO!F
^BIf
lp^
\f;Y{
E# i
\?yD
7o*SYAz
444 QLZ/7;O
tqt&!$:
&*S c=,
1~yQ
cWHz
S>! D
~t'
#i$l6T[X
u H&*&D
4445
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02_64 Seven02_64 VirtualBox 2018-05-18 15:55:16 2018-05-18 15:58:38 202

22 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02_64 Seven02_64 VirtualBox 2018-05-18 15:55:16 2018-05-18 15:58:38 202

10 Summary items with data

Files

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe.config
C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe
C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Local
C:\Users\Seven01\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
\Device\KsecDD
C:\Users\Seven01\AppData\Local\Temp\bossemmy.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\System32\tzres.dll
C:\Windows\Globalization\it-it.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources\bossemmy.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources\bossemmy.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\Globalization\it.nlp
C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources\bossemmy.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources\bossemmy.resources.exe
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe
\Device\NamedPipe\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2308.19245218
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2308.19245218
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2308.19245265
C:\Windows\System32\Branding\Basebrd\Basebrd.dll
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe"
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe.Local\
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
C:\Users\Seven01\AppData\Roaming\Microsoft
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.INI
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources\bossemmy.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources\bossemmy.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources\bossemmy.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources\bossemmy.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.exe
C:\Users\Seven01\AppData\Local\Temp\iygihy.txt
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2620.19247234
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2620.19247234
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2620.19247234
C:\Users\Seven01\AppData\Local\Temp\reg.*
C:\Users\Seven01\AppData\Local\Temp\reg
C:\ProgramData\Oracle\Java\javapath\reg.*
C:\ProgramData\Oracle\Java\javapath\reg
C:\Windows\System32\reg.*
C:\Windows\System32\reg.COM
C:\Windows\System32\reg.exe
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\
C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc
C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe
C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe:Zone.Identifier
C:\Users\Seven01\AppData\Local\Temp\tmpG868.tmp
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe
C:\Users\Seven01\AppData\Local\Temp\H68.exe
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\*
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\logins.json
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.INI
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
\??\MountPointManager
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.INI
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\plutil.exe
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\logins.json
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini
C:\Program Files (x86)\Mozilla Firefox\nss3.dll
C:\Program Files (x86)\Postbox\nss3.dll
C:\Program Files (x86)\Mozilla Thunderbird\nss3.dll
C:\Program Files (x86)\SeaMonkey\nss3.dll
C:\Program Files (x86)\Flock\nss3.dll
C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\UCBrowser\*
C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\Seven01\AppData\Roaming\Thunderbird\signons.sqlite
C:\Users\Seven01\AppData\Roaming\Thunderbird\logins.json
C:\Storage\
C:\mail\
C:\Users\Seven01\AppData\Local\VirtualStore\Program Files\Foxmail\mail\
C:\Users\Seven01\AppData\Local\VirtualStore\Program Files (x86)\Foxmail\mail\
C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini
C:\Users\Seven01\AppData\Roaming\The Bat!
C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini
C:\Users\Seven01\AppData\Roaming\Postbox\signons.sqlite
C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\SysWOW64\wshom.ocx
C:\ProgramData\DynDNS\Updater\config.dyndns
C:\Users\All Users\AppData\Roaming\FlashFXP\3quick.dat
C:\
C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
C:\Users\Seven01\AppData\RoamingSmartFTPClient 2.0FavoritesQuick Connect*.xml
C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
C:\Users\Seven01\AppData\Local\Temp\Ftplist.txt
C:\Program Files (x86)\jDownloader\config\database.script
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository
C:\Windows\sysnative\wbem\Logs
C:\Windows\sysnative\wbem\AutoRecover
C:\Windows\sysnative\wbem\MOF
C:\Windows\sysnative\wbem\repository\INDEX.BTR
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
C:\Users\Seven01\AppData\Local\Temp\H68.exe.config
C:\Users\Seven01\AppData\Local\Temp\H68.exe.Local\
C:\Users\Seven01\AppData\Local\Temp\H68.config
C:\Users\Seven01\AppData\Local\Temp\H68.INI
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start.*
C:\Windows\SysWOW64\shell32.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000015.db
C:\Users\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start
C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb
C:\Windows\symbols\dll\System.pdb
C:\Windows\dll\System.pdb
C:\Windows\System.pdb
C:\Users\Seven01\AppData\Local\Temp\H68.PDB
C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb
C:\Windows\symbols\exe\ConsoleApp1.pdb
C:\Windows\exe\ConsoleApp1.pdb
C:\Windows\ConsoleApp1.pdb
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\
C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp
C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml
C:\Windows\System32\drivers\*.mrk
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_*
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_08fe76d0
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_08fe76d0\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp
C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_05aa92f3
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_05aa92f3\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp
C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_096ed1e0
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_096ed1e0\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp
C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0b5ef7e6
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0b5ef7e6\Report.wer
C:\Windows\assembly\GAC_32\System.Windows.Forms\2.0.0.0__b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\assembly\GAC_32\System\2.0.0.0__b77a5c561934e089
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089
C:\Windows\assembly\GAC_32\System.Drawing\2.0.0.0__b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9859a6e0562f64eacfb8ad76f260a2d6\Accessibility.ni.dll
C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.INI
C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp
C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_03031736
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_03031736\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp
C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_072337fd
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_072337fd\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp
C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_036b5096
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_036b5096\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp
C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0a77696d
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0a77696d\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp
C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_060f87b3
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_060f87b3\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp
C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_047fa1c3
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_047fa1c3\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_09efbc5f
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_09efbc5f\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp
C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0607d74a
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0607d74a\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp
C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_04eff263
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_04eff263\Report.wer

Read Files

C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe.config
C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol21.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\System32\tzres.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll
C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll
\Device\NamedPipe\
C:\Windows\Branding\Basebrd\basebrd.dll
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe.config
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll
C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini
C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt
C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini
C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\SysWOW64\wshom.ocx
C:\Windows\sysnative\wbem\WmiPrvSE.exe
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
C:\Users\Seven01\AppData\Local\Temp\H68.exe.config
C:\Users\Seven01\AppData\Local\Temp\H68.exe
C:\Windows\SysWOW64\shell32.dll
C:\
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000015.db
C:\Users\desktop.ini
C:\Users
C:\Users\Seven01
C:\Users\Seven01\AppData
C:\Users\Seven01\AppData\Roaming
C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini
C:\Users\Seven01\AppData\Roaming\Microsoft
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb
C:\Windows\symbols\dll\System.pdb
C:\Windows\dll\System.pdb
C:\Windows\System.pdb
C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb
C:\Windows\symbols\exe\ConsoleApp1.pdb
C:\Windows\exe\ConsoleApp1.pdb
C:\Windows\ConsoleApp1.pdb
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb
C:\Windows\symbols\dll\mscorlib.pdb
C:\Windows\dll\mscorlib.pdb
C:\Windows\mscorlib.pdb
C:\Windows\System32\it-IT\werui.dll.mui
C:\Windows\System32\werui.dll
C:\Windows\System32\it-IT\DUser.dll.mui
C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui
C:\Windows\Fonts\staticcache.dat
C:\Windows\win.ini
C:\Windows\System32\uxtheme.dll.Config
C:\Windows\System32\uxtheme.dll
C:\Windows\System32\it-IT\erofflps.txt
C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp
C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp
C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp
C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp
C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9859a6e0562f64eacfb8ad76f260a2d6\Accessibility.ni.dll
C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp
C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp
C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp
C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp
C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp
C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp
C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp
C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp
C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml

Write Files

C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe
C:\Users\Seven01\AppData\Local\Temp\iygihy.txt
C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe
C:\Users\Seven01\AppData\Local\Temp\tmpG868.tmp
C:\Users\Seven01\AppData\Local\Temp\H68.exe
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
\??\PIPE\samr
C:\Windows\sysnative\wbem\repository\WRITABLE.TST
C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
C:\Windows\sysnative\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
\??\WMIDataDevice
C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_08fe76d0\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_05aa92f3\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_096ed1e0\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0b5ef7e6\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_03031736\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_072337fd\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_036b5096\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0a77696d\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_060f87b3\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_047fa1c3\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_09efbc5f\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0607d74a\Report.wer
C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_04eff263\Report.wer

Delete Files

C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2308.19245218
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2308.19245218
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2308.19245265
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2620.19247234
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2620.19247234
C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2620.19247234
C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe:Zone.Identifier
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe
C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp
C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp
C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp
C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp
C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp
C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp
C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp
C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp
C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp
C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp
C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp
C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp
C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml
C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp
C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml

Keys

HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bossemmy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\53cbe261\3448e062
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\9622af9\2ea3dcf5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|bossemmy.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|bossemmy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|bossemmy.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\9622af9\2a895943
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fuguyih.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|fuguyih.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|fuguyih.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|fuguyih.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\iygihy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\222261a\f3721b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\fuguyih.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\5F48F05
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_CURRENT_USER\Software\Classes\WinMgmts
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\410
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\fuguyih_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Omnicare Inc
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\62ed7031\40e0b0fd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\62ed7031\1ffddffc
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it-IT_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\1c4dd593
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\4deb99ab
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1
HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine
HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
HKEY_CLASSES_ROOT\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\410
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\10
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
HKEY_CURRENT_USER\Software\Paltalk
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FTP Commander
HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC
HKEY_CURRENT_USER\SOFTWARE\Vitalwerks\DUC
HKEY_CURRENT_USER\Software\DownloadManager\Passwords
HKEY_USERS\S-1-5-20_Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\H68.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\63fc17e7\5b5a3ba7
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\H68.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
HKEY_CLASSES_ROOT\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|H68.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|H68.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|H68.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\CLR20r3
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\OfflineMode
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\WaitOnStart
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\iygihy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\5F48F05
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Omnicare Inc
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\OfflineMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\WaitOnStart

Write Keys

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\iygihy
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\fuguyih_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileDirectory
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Omnicare Inc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation
HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog

Delete Keys

Nothing to display

Mutexes

Global\CLR_CASOFF_MUTEX
Global\.net clr networking
Local\_!MSFTHISTORY!_
Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5!
Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies!
Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5!
Global\411a6ca0-5aa3-11e8-b448-080027839166
Local\MSCTF.Asm.MutexDefault1
Global\4720fe16-5aa3-11e8-b448-080027839166
Global\4f020382-5aa3-11e8-b448-080027839166
Global\5645adba-5aa3-11e8-b448-080027839166
Global\5b45fc84-5aa3-11e8-b448-080027839166
Global\6011d792-5aa3-11e8-b448-080027839166
Global\6461b858-5aa3-11e8-b448-080027839166
Global\68038d74-5aa3-11e8-b448-080027839166
Global\6c320d4e-5aa3-11e8-b448-080027839166
Global\70d56062-5aa3-11e8-b448-080027839166
Global\74a6e486-5aa3-11e8-b448-080027839166
Global\78bb2a82-5aa3-11e8-b448-080027839166
Global\7ce74802-5aa3-11e8-b448-080027839166

Resolved APIs

advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
kernel32.dll.FlsAlloc
kernel32.dll.FlsFree
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
advapi32.dll.EventRegister
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll._CorExeMain
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll._CorExeMain
mscorwks.dll.GetCLRFunction
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.IEE
mscoreei.dll.IEE
mscorwks.dll.IEE
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
kernel32.dll.QueryActCtxW
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
ole32.dll.CoGetContextToken
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
mscoree.dll.ND_RI4
mscoreei.dll.ND_RI4
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.VirtualProtect
kernel32.dll.GetEnvironmentVariableW
kernel32.dll.SwitchToThread
kernel32.dll.CloseHandle
kernel32.dll.GetCurrentProcessId
advapi32.dll.LookupPrivilegeValueW
kernel32.dll.GetCurrentProcess
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.OpenProcess
psapi.dll.EnumProcessModules
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.GetModuleFileNameExW
kernel32.dll.GetProcAddress
kernel32.dll.DebugActiveProcess
kernel32.dll.WaitForDebugEvent
kernel32.dll.ContinueDebugEvent
kernel32.dll.DeleteFileA
advapi32.dll.SetKernelObjectSecurity
advapi32.dll.GetKernelObjectSecurity
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtProtectVirtualMemory
kernel32.dll.GetModuleFileNameW
shfolder.dll.SHGetFolderPathW
kernel32.dll.MoveFileW
kernel32.dll.LocalFree
kernel32.dll.CreatePipe
kernel32.dll.DuplicateHandle
kernel32.dll.GetStdHandle
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.CreateProcessW
kernel32.dll.GetFileType
kernel32.dll.GetConsoleCP
kernel32.dll.GetACP
kernel32.dll.UnmapViewOfFile
kernel32.dll.GetConsoleOutputCP
kernel32.dll.WriteFile
ole32.dll.CoUninitialize
kernel32.dll.CreateActCtxW
kernel32.dll.AddRefActCtx
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
kernel32.dll.GetCurrentActCtx
advapi32.dll.EventUnregister
kernel32.dll.SetThreadUILanguage
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.CopyFileExW
kernel32.dll.IsDebuggerPresent
kernel32.dll.SetConsoleInputExeNameW
ntdll.dll.NtQueryInformationProcess
kernel32.dll.GetTempPathW
kernel32.dll.CreateFileW
kernel32.dll.GetFileSize
kernel32.dll.ReadFile
kernel32.dll.VirtualAllocEx
kernel32.dll.GetThreadContext
kernel32.dll.Wow64GetThreadContext
ntdll.dll.NtUnmapViewOfSection
kernel32.dll.ResumeThread
kernel32.dll.SetThreadContext
kernel32.dll.Wow64SetThreadContext
kernel32.dll.WriteProcessMemory
kernel32.dll.ReadProcessMemory
kernel32.dll.TerminateProcess
uxtheme.dll.ThemeInitApiHook
user32.dll.IsProcessDPIAware
cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
ole32.dll.CreateBindCtx
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ole32.dll.MkParseDisplayName
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
ole32.dll.BindMoniker
sxs.dll.SxsOleAut32RedirectTypeLibrary
advapi32.dll.RegOpenKeyW
advapi32.dll.RegEnumKeyW
advapi32.dll.RegQueryValueW
sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid
sxs.dll.SxsLookupClrGuid
oleaut32.dll.#9
oleaut32.dll.#4
oleaut32.dll.#283
oleaut32.dll.#284
mscoreei.dll._CorDllMain
mscoree.dll.GetTokenForVTableEntry
mscoree.dll.SetTargetForVTableEntry
mscoree.dll.GetTargetForVTableEntry
mscoreei.dll.GetTokenForVTableEntry
mscoreei.dll.SetTargetForVTableEntry
mscoreei.dll.GetTargetForVTableEntry
kernel32.dll.GetLastError
kernel32.dll.LocalAlloc
oleaut32.dll.VariantInit
oleaut32.dll.VariantClear
oleaut32.dll.#7
kernel32.dll.CreateEventW
kernel32.dll.SetEvent
ole32.dll.CoWaitForMultipleHandles
ole32.dll.IIDFromString
kernel32.dll.LoadLibraryA
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
oleaut32.dll.#500
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
kernel32.dll.RegOpenKeyExW
advapi32.dll.GetUserNameW
kernel32.dll.GetComputerNameW
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
rasapi32.dll.RasEnumConnectionsW
rtutils.dll.TraceRegisterExA
rtutils.dll.TracePrintfExA
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.QueryServiceStatus
sechost.dll.CloseServiceHandle
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.GetProcessTimes
ws2_32.dll.WSAIoctl
kernel32.dll.FormatMessageW
rasapi32.dll.RasConnectionNotificationW
advapi32.dll.RegOpenCurrentUser
sechost.dll.NotifyServiceStatusChangeA
advapi32.dll.RegNotifyChangeKeyValue
winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser
kernel32.dll.ResetEvent
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
ws2_32.dll.inet_addr
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
ws2_32.dll.WSAConnect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.shutdown
kernel32.dll.GetModuleHandleW
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
user32.dll.RegisterClassW
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
user32.dll.CallWindowProcW
user32.dll.RegisterWindowMessageW
dwmapi.dll.DwmIsCompositionEnabled
ntdll.dll.NtQuerySystemInformation
kernel32.dll.CreateDirectoryW
kernel32.dll.CopyFileW
advapi32.dll.RegSetValueExW
kernel32.dll.DeleteFileW
kernel32.dll.GetModuleFileNameA
kernel32.dll.MoveFileExW
kernel32.dll.CreateIoCompletionPort
kernel32.dll.PostQueuedCompletionStatus
ntdll.dll.NtQueryInformationThread
ntdll.dll.NtGetCurrentProcessorNumber
kernel32.dll.RtlMoveMemory
shell32.dll.ShellExecuteEx
shell32.dll.ShellExecuteExW
kernel32.dll.FindFirstFileW
kernel32.dll.FindClose
kernel32.dll.GetExitCodeProcess
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
user32.dll.GetSystemMetrics
kernel32.dll.GetSystemTimeAsFileTime
setupapi.dll.CM_Get_Device_Interface_List_ExW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetLastInputInfo
user32.dll.GetParent
ole32.dll.OleInitialize
ole32.dll.CoRegisterMessageFilter
user32.dll.PeekMessageW
user32.dll.IsWindowUnicode
user32.dll.GetMessageW
user32.dll.TranslateMessage
user32.dll.DispatchMessageW
user32.dll.WaitMessage
mlang.dll.#112
wininet.dll.FindFirstUrlCacheEntryA
kernel32.dll.SetFileInformationByHandle
urlmon.dll.CreateUri
wininet.dll.FindNextUrlCacheEntryA
wininet.dll.FindCloseUrlCache
ole32.dll.CoRevokeInitializeSpy
comctl32.dll.#388
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptReleaseContext
ole32.dll.CLSIDFromProgIDEx
kernel32.dll.GetVolumeInformationA
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
rpcrt4.dll.NdrClientCall3
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventWrite
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CreateStreamOnHGlobal
advapi32.dll.RegCreateKeyExW
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.IsThreadAFiber
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernel32.dll.SetThreadToken
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.CheckTokenMembership
ole32.dll.CLSIDFromString
oleaut32.dll.#285
oleaut32.dll.#12
oleaut32.dll.#286
oleaut32.dll.#17
oleaut32.dll.#20
oleaut32.dll.#19
oleaut32.dll.#25
ole32.dll.CoRevertToSelf
advapi32.dll.LogonUserExExW
sspicli.dll.LogonUserExExW
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.CoImpersonateClient
advapi32.dll.OpenThreadToken
oleaut32.dll.#8
ole32.dll.CoSwitchCallContext
oleaut32.dll.#287
oleaut32.dll.#288
oleaut32.dll.#289
ntmarta.dll.GetMartaExtensionInterface
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
oleaut32.dll.#290
wmi.dll.WmiQueryAllDataW
wmi.dll.WmiQuerySingleInstanceW
wmi.dll.WmiSetSingleItemW
wmi.dll.WmiSetSingleInstanceW
wmi.dll.WmiExecuteMethodW
wmi.dll.WmiNotificationRegistrationW
wmi.dll.WmiMofEnumerateResourcesW
wmi.dll.WmiFileHandleToInstanceNameW
wmi.dll.WmiDevInstToInstanceNameW
wmi.dll.WmiQueryGuidInformation
wmi.dll.WmiOpenBlock
wmi.dll.WmiCloseBlock
wmi.dll.WmiFreeBuffer
wmi.dll.WmiEnumerateGuids
propsys.dll.PSCreateMemoryPropertyStore
propsys.dll.PSPropertyBag_WriteDWORD
ole32.dll.CoGetApartmentType
ole32.dll.CoRegisterInitializeSpy
comctl32.dll.#236
ole32.dll.CoGetMalloc
propsys.dll.PSPropertyBag_ReadDWORD
comctl32.dll.#320
comctl32.dll.#324
comctl32.dll.#323
comctl32.dll.#328
comctl32.dll.#334
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.SetEntriesInAclW
advapi32.dll.SetSecurityDescriptorDacl
comctl32.dll.#332
comctl32.dll.#386
advapi32.dll.IsTextUnicode
comctl32.dll.#338
comctl32.dll.#339
shell32.dll.#102
ole32.dll.OleUninitialize
advapi32.dll.CheckTokenMembership
mscoree.dll.DllGetClassObject
mscoreei.dll.DllGetClassObject
diasymreader.dll.DllGetClassObjectInternal
wer.dll.WerReportCreate
wer.dll.WerReportSetParameter
wer.dll.WerReportAddFile
wer.dll.WerReportSetUIOption
wer.dll.WerReportSubmit
wer.dll.WerReportAddDump
wer.dll.WerReportCloseHandle
user32.dll.LoadStringW
advapi32.dll.RegGetValueW
user32.dll.GetProcessWindowStation
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationW
sensapi.dll.IsNetworkAlive
rpcrt4.dll.NdrClientCall2
user32.dll.CharUpperW
werui.dll.WerUICreate
werui.dll.WerUIStart
ole32.dll.CoInitialize
dui70.dll.InitProcessPriv
comctl32.dll.LoadIconWithScaleDown
ntdll.dll.RtlRunEncodeUnicodeString
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlRunDecodeUnicodeString
dui70.dll.InitThread
duser.dll.InitGadgets
user32.dll.RegisterMessagePumpHook
dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ
dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ
dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z
dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z
dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ
dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z
dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ
dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ
dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ
dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ
dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ
dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z
dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z
duser.dll.CreateGadget
duser.dll.SetGadgetMessageFilter
duser.dll.SetGadgetStyle
dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z
dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ
dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z
dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z
dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z
dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z
dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z
duser.dll.InvalidateGadget
dui70.dll.CreateDUIWrapper
dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z
shell32.dll.ExtractIconExW
comctl32.dll.TaskDialogIndirect
uxtheme.dll.IsThemeActive
duser.dll.SetGadgetRootInfo
uxtheme.dll.IsAppThemed
uxtheme.dll.GetThemeAppProperties
xmllite.dll.CreateXmlReader
xmllite.dll.CreateXmlReaderInputWithEncodingName
uxtheme.dll.OpenThemeData
uxtheme.dll.GetThemeMargins
uxtheme.dll.GetThemeFont
uxtheme.dll.GetThemeColor
uxtheme.dll.GetThemeMetric
duser.dll.SetGadgetParent
duser.dll.GetDUserModule
duser.dll.FindStdColor
duser.dll.AttachWndProcW
kernel32.dll.InterlockedPopEntrySList
kernel32.dll.InterlockedPushEntrySList
kernel32.dll.InterlockedCompareExchange
comctl32.dll.RegisterClassNameW
duser.dll.GetGadgetRect
duser.dll.GetGadgetRgn
duser.dll.GetGadgetTicket
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
gdi32.dll.GetTextFaceAliasW
gdi32.dll.GetFontAssocStatus
advapi32.dll.RegQueryValueExA
gdi32.dll.GdiIsMetaPrintDC
dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z
dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z
uxtheme.dll.EnableThemeDialogTexture
dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z
dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z
comctl32.dll.HIMAGELIST_QueryInterface
comctl32.dll.DrawShadowText
comctl32.dll.DrawSizeBox
comctl32.dll.DrawScrollBar
comctl32.dll.SizeBoxHwnd
comctl32.dll.ScrollBar_MouseMove
comctl32.dll.ScrollBar_Menu
comctl32.dll.HandleScrollCmd
comctl32.dll.DetachScrollBars
comctl32.dll.AttachScrollBars
comctl32.dll.CCSetScrollInfo
comctl32.dll.CCGetScrollInfo
comctl32.dll.CCEnableScrollBar
comctl32.dll.QuerySystemGestureStatus
uxtheme.dll.#49
uxtheme.dll.CloseThemeData
dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z
dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ
uxtheme.dll.GetThemeBool
duser.dll.GetGadgetFocus
uxtheme.dll.GetThemeBackgroundContentRect
uxtheme.dll.GetThemeTextMetrics
uxtheme.dll.GetThemePartSize
uxtheme.dll.GetThemeTextExtent
uxtheme.dll.GetThemeBackgroundExtent
duser.dll.SetGadgetFocus
duser.dll.DUserSendEvent
duser.dll.SetGadgetRect
comctl32.dll.SetWindowSubclass
comctl32.dll.DefSubclassProc
dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ
uxtheme.dll.#47
uxtheme.dll.BufferedPaintInit
uxtheme.dll.BeginBufferedPaint
uxtheme.dll.BufferedPaintRenderAnimation
uxtheme.dll.BeginBufferedAnimation
uxtheme.dll.IsThemeBackgroundPartiallyTransparent
uxtheme.dll.DrawThemeParentBackground
uxtheme.dll.DrawThemeBackground
uxtheme.dll.DrawThemeText
uxtheme.dll.EndBufferedAnimation
uxtheme.dll.GetThemeTransitionDuration
uxtheme.dll.GetBufferedPaintDC
uxtheme.dll.GetBufferedPaintTargetDC
uxtheme.dll.EndBufferedPaint
oleaut32.dll.SysAllocString
oleaut32.dll.SysFreeString
duser.dll.ForwardGadgetMessage
uxtheme.dll.GetThemeInt
duser.dll.DUserPostEvent
duser.dll.DisableContainerHwnd
uxtheme.dll.BufferedPaintUnInit
werui.dll.WerUIUpdateUIForState
duser.dll.DeleteHandle
duser.dll.DetachWndProc
comctl32.dll.RemoveWindowSubclass
dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z
dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z
dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ
dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ
uxtheme.dll.BufferedPaintStopAllAnimations
dui70.dll.??1CCBase@DirectUI@@UAE@XZ
uxtheme.dll.DrawThemeParentBackgroundEx
uxtheme.dll.GetThemeEnumValue
user32.dll.MsgWaitForMultipleObjects
winhttp.dll.WinHttpOpen
winhttp.dll.WinHttpSetTimeouts
winhttp.dll.WinHttpSetOption
winhttp.dll.WinHttpConnect
winhttp.dll.WinHttpOpenRequest
winhttp.dll.WinHttpSetStatusCallback
winhttp.dll.WinHttpGetDefaultProxyConfiguration
winhttp.dll.WinHttpGetProxyForUrl
winhttp.dll.WinHttpSendRequest
ws2_32.dll.GetAddrInfoW
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#9
ws2_32.dll.FreeAddrInfoW
ws2_32.dll.#6
ws2_32.dll.#5
ws2_32.dll.WSARecv
ws2_32.dll.WSASend
winhttp.dll.WinHttpReceiveResponse
winhttp.dll.WinHttpQueryHeaders
winhttp.dll.WinHttpReadData
ws2_32.dll.#22
ws2_32.dll.#3
winhttp.dll.WinHttpCloseHandle
advapi32.dll.IsValidSid
advapi32.dll.GetLengthSid
advapi32.dll.CopySid
advapi32.dll.RegisterEventSourceW
advapi32.dll.ReportEventW
advapi32.dll.DeregisterEventSource
werui.dll.WerUITerminate
duser.dll.DUserFlushMessages
duser.dll.DUserFlushDeferredMessages
dui70.dll.UnInitThread
user32.dll.UnregisterMessagePumpHook
dui70.dll.UnInitProcessPriv
dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ
dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ
dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ
werui.dll.WerUIDelete
advapi32.dll.DuplicateToken
duser.dll.FindGadgetFromPoint
shlwapi.dll.PathIsDirectoryW

Execute Commands

"cmd"
"C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe"
reg  add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "iygihy" /d "cmd /c type "C:\Users\Seven01\AppData\Local\Temp\iygihy.txt" | cmd"
C:\Users\Seven01\AppData\Local\Temp\H68.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start 
dw20.exe -x -s 604
dw20.exe -x -s 680
dw20.exe -x -s 596
dw20.exe -x -s 592
dw20.exe -x -s 624
dw20.exe -x -s 600
dw20.exe -x -s 644

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02_64 Seven02_64 VirtualBox 2018-05-18 15:55:16 2018-05-18 15:58:38 202

1 HTTP Request(s) detected

http://checkip.dyndns.org/
  • Hostname: checkip.dyndns.org
  • IP Address: 162.88.100.200
  • Port: 80
  • Count: 1

GET / HTTP/1.1
Host: checkip.dyndns.org
Connection: Keep-Alive

#infosec #automation

TheSystem Itself @ 2018-05-18 15:57:19

Detected family: #Barys

TheSystem Itself @ 2018-05-18 16:08:03