File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 964.00 KB (987136 bytes) |
Compile time: | 2018-05-08 03:51:54 |
MD5: | febed648257274d46d864132745b6a05 |
SHA1: | f199589f8f94d68580e6d7b72276a10e25cbfece |
SHA256: | 6beb034f6513c4863c309e1d09169341bef118754332087d4eb59f545edf3e85 |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2018-05-18 15:57:03 |
Last submission: | 2018-05-18 15:57:03 |
Filename detected: |
- bossemmy.exe (1) |
URL file hosting |
---|
hXXp://qualityoflife-lb.com/crypted/bossemmy.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-05-09 15:54:36 | [21/65] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0xd8044 | 885248 | f4e82293ccad07c3bfb086bdcbc34ad8 | 582eac782adb667d2647d39e644368a5b7c637a0 |
.rsrc | 0xdc000 | 0x18948 | 100864 | a3ca6af3445a0abaa77bb62c0601e400 | e55dcd341c3e8c921dbed66609ee489574f55886 |
.reloc | 0xf6000 | 0xc | 512 | 4e5258d872ab972e056e51b3124f2700 | 9dcd613ed31fa24facdd51f52d8a71c42ce072b6 |
PE Resources | |||||
---|---|---|---|---|---|
Name | Offset | Size | Language | Sublanguage | Data |
RT_ICON | 0xf4248 | 1128 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_GROUP_ICON | 0xf46b0 | 76 | LANG_NEUTRAL | SUBLANG_NEUTRAL | |
RT_VERSION | 0xf46fc | 588 | LANG_NEUTRAL | SUBLANG_NEUTRAL |
- API Alert
- Anti Debug
Meta Info | |
---|---|
LegalCopyright: | |
Assembly Version: | 0.0.0.0 |
InternalName: | bossemmy.exe |
FileVersion: | 0.0.0.0 |
FileDescription: | |
Translation: | 0x0000 0x04b0 |
OriginalFilename: | bossemmy.exe |
ProductVersion: | 0.0.0.0 |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
No IP detected |
URL(s) | |
---|---|
No URL found |
String too long |
---|
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX |
6VCa5xBjdWSYzMqM6Oh1t
lOTxxJw5HG4o6jyD1VPVzKU2dqZK
RD29vqx2NtjiEY5kF8VxLhrT6FETg8
bossemmy.exe
InternalName
tA4WuvTwm9F7Q37rdGQvIX0JJgh
7IEKzoIR3lnXNCeeELesQXXM
muTGREDJXXR4FyaNJ79N6UioGpPBSTF
bdQRyOVDDFXaUeZOOJ9dE9Ci4Mf
0kiEAS7nwmuhoPwGbSU7Fg
qlECATdwnAYJCbJFjcNcED
Translation
tbgykUPN8WOzNtPDOrH4gWz9
LegalCopyright
yw2rx4iF2EkxIyWIDPyRMokC70j
)Oqt
wyiVuKyM74pxbPI0nf9WUV
dBMLJIRjQFcOuYsPV47ilFqffeIl
aOWeB6SxhrB3j3qKfR6YSVv8D
bpMyYgC1ul4wzUWX9IkbxAEiltANtAGAfzXv
6XAtMQKi3CWIJ6hG6no5TuQ5yCUuM5hAm837J
4v2x7woLsydLXfxVBOFUkfI2pg
rlRlogHOfXkC1lRwWG8UczRm9J6bsjLNJ2x
um4cX3MT9e1WsXN6E1CY
jHnMjAMEw3HWYc2nUADesKfo7
V1ZcuJptYJpHVqKBGmNtrM0
yYogpjVhcaoT1rM7qtsh2IKns
bJVaJo2QiZSxP9CRZGdSQ4B
kyJPn6KaBqsbnE09X46LRiwlszng
IunMgNxT1TjwlUouhg2zA5qXvJXQifgEz6
Y48U60A9mfOraDIiFctgtWAk7O33MS
7w9RZn3i0j2u6v4WRhpNuD
OneLIMG01yP9e0puT3wyTgL3
qVsVCdVDRUYZCcRX37ERem13z60YUYxJ
UBgYTePRIW2C4eAETBqcQQpjTNnLt
IzriTTDDj6m8kDraAKnV
KUMXCq7EPuGxOjTqcs5kBlp1Gajs4CEUogeYwy
jHfepFO229r1rQKgAOA8ady97CmhA
daCwsoYpqx38arFyFGgRZdHotBD2E
N6cwoXj1tWdxkcyJnYuEvrRN2
mfX4dgHoZlT6sRvtdUumZP7hfx8Li
212D2bqnH4HcnS7HpOq2oHd6p
KBvUjuRUD4NzolFIiD89mnNnX012pdH5
x1jpA3O4piFW05TgQhWor0AG4HQrtVSMR5
iIrEtuuVbPxQSYIOPAkhQP
e34NbX8CUgZRVraF0fM5ak2M81edviFZK
4YDc4Yyz4rEyJmFda4PM4
6AKtZS4OlgriQ3fHQb6wQW3zwj3n
ldwuF8gHF1mRUopOo1pn262iXXFkGTo
dKiwbHb7nrUXi1IzJ7ErS6TBeHIwGbs
W526rMeKN9sL8mkDHAGHB2OBHQh
K2h7qp9RtioE7PFFoswGBHKmnGUaYu
jL5S0pPGuMoRyjkjeHm8Ntl
un4iUJ3mCMyM3mWVz1aHUUs
j35JAg8N7IS6eREDJqmX2wYbgOWedFlI
d09sFjnFrIDq5lH3SkuMYCB4nwQ4
PHUtELATQKPQmJ9gNTVJKwHG6VUFxN9Ct3m2C
7clbFdwhvvIiray0tmWy2OQhxHdx76apJ
0.0.0.0
OriginalFilename
Qc9rx0njH2c5l1ZaXXW9juHVYv4gu8
LWOGDtzQWfq3fk2Y2HCl
VarFileInfo
TGdb6GkZJKOhrLDfNag2AudziFAO
VS_VERSION_INFO
89JkQdbQ1CYMSOTPnRBZ
ZtEngnW8FkhgxYBGeuCNSD82EfGzl20iqukK
80tGJNYA7jZjW8XoPKvUJ17y9
yDmsDNkFrtJbAx6B0lUxip3Xn3
Assembly Version
9v9bNGbSLnrqcKqX1mDiSzGEIr3bF
I7oabjXYjMovgtYolCQ3X4YvMdSe3pSpDG
CWLMer12BAJYsR9DM2FnTXqt0ULVnnAqVBkL4ws
mh3D1DQZ88miInXUJQpGPFt7ktv
lkb6eRz87kXLLvJdZMyaIEr59WCqR
j4j95mL1FI3Qmf6gzEi2Jiy7EiiTSi2CG5I
caHKMig8XP831sy0lVUL7L6RR1ZfIzKEDZC
4lKMcruYdrvGNQkM0vJH0IRTfla6oeQ
qCE3c2vEleaNWUONnzeBf0Z8t7alnbyO
pxQmxBzc0gQS4d2TeSCKJZKc
Px6lw0KI8LayKuHTvMxHCt3
rgLZi9HPBzdsXXLe3RaPEpTyDcSeSoya
LwaMPcDNY8wGNcFGmN0FyMdd8UpjJuEx
Jv1xni9WaRb20lJ8V9CGRjSg4RZMvZB74d
aKwI03DkP2eaTdGxMmIz
ijytLoSQ5HQZEQqn3YNpgtLqZywuC
6T590JfnCeYepLJsfJF2hV2IwVPsL79qmqAAoiF
43ikVQcJpHaRtCgsiZNDfsf8S
StringFileInfo
yNOubBTEIGbaB7bTSd8clusjOg
nF7HVw0Qiy0jH35mzB6wqGgCMV0faYHVYe2
FileVersion
pfOS8V5Npm6qj610TZjpRC
nfT4J6o3v8vwX3XpDb8tuwJNeLDoiurzeMRw
TFS69fyxnx8RTQ1ZjTFFVN
000004b0
ProductVersion
FileDescription
nPqR17YTzDY8SDmUMNHHVn5e
2O4ewtnQsUBPXnNM0KjhmXFQ5SpzGHQ7GTBm
2Akh62mkP0FBvapHh6dLZPoUHEHn28
l7Z0oLel8CNN9dzAfCBB5Zgp54SrDqm
svMCdwta08cKl3Sumb7zSXVONFosxgC8w
3PHOfW20m52Ik1qx2952E
tjFADfaBBVxoV68wnDthc8ZsbNb
QG2Zjvmw5nGh5UvjyBKe
y7xzOPcdhokpAEVZditpSyUBlfjUGoCTHi4i
4H(&
Q:C
v!b)~
%0xo
+F:
iy-C
$_@ZN9
<#ZM8
7a*x
WE O
xHiYJs
$W`c
pJk=
. Xo
(,79
P^6/
XL&ZMD
@P>
/]AL
4yv)
)'tV
!\|ZZD
1}]0w
$?qg
-M6Q /
+[=}k
*oy_
hHXZ
!MDi
dSBq
+Q$}Pv
DP< `Pe
@ 2o
444R444
Tf>Z
X"!Y^
<tTa
>I)*
s2:a(
UnverifiableCodeAttribute
7;P-|
yf0`
>90C
4440444>444B444E444OHCAkIFJ
IPAf/
0jG&e
H2oO
/*Zb
T[7y
UB; v
0*Vi
v&o?A
J +<
#B)q
UR9 Z
}lE{
"ohI
1dn%
r9_j
\,3
}P33{
P?[x
\OyBSrXm
Is)Q
d|V.`
#LA9t
3N%M
6FF}
DEPCN
BhI'>
Hz%
X\b
vd#o
0v0;
"z?>
444^`oC
nh{Y
zH^?
`ft7
kJq7
6o(,
Fh$]
i>`A
p!(9
PIA(
`,(_
/D``;de
]8wKe
_Sd3
, Kn
j2."_e
M'l$
0D`v
1G/
2S.@
EgXL
TD>-
C.oe
444q444:444
]`rp
\^3Jq
# }As
E(=i
*<z3.V[
ba+#v
Ap?
mh&F-
ZhkO
8V U
tTw
r7'@
t%Uw
n!=:
eekL
m9VS
CYN=
Q'&]
"!X:
-]S
9fL^
{InNaF
=?P ==HhQLF
*#-A
s#fr
Q;B:
L[0
%!Dy
W3$\s
|*;N
8;(;#
m>9|$
F6 R~
D(@m|
80d?7
@w)q*|
K0W~
Yb<3
jK=2(
k1]
I\]XC[
W&Co#
db~a
HJ9f
5KY4
)wk
V\qd
Kn@i
Z7T+/*
&[cc
O-oy
c[h
!D50
/}",
\+[h`z
q@.?FW
Px6lw0KI8LayKuHTvMxHCt3
gijD
1Z?T
:h-F
#iN.
(DeL1
1H(6X
dPs-f
> $Gm
g@e$
NLV^bB
-z5Q
JksD
]\aU
gpN
.v*N<
-k\-
l !4
m Tj
Ir+~^|
HClc^
8Pw1
% *E\
Vn(j
$_K,
f(I^
en7]i
)gJ.
444+444W444
aa/!
iimv+gF
V@b_
VbmW
8Re^
<+lf'
_s?d
(/>u
n4hs
)(0]
Yil]
;>SKCRA.6]
ylt|U
5[L
a57#
cjM[
.Xb|rE
v_$f
]o.J
~ \A
(:f/J
%/_GtQ w
A7J
s|ol
"RvS
a"s>
Ta\H
/v(!
3`HTC
4zqy;
o!Zf
+kp>@
rM}<
p)rOp
!R2r
"{S
.R./%>9
C Xg
;E
Ed~:^
wS: \@.
SC_F
7h0B
PhF:
==z}
FziI=
K3!<w
NQ=\H<
_sP%
WY48
\F$R
<t+2}
!J?
a7R|=|
nw|no
1r@A
LH
|6cZ4
C[Yy
I<<=
mANc
KE(?
$Z&0
Gv&Nd4* C#
6=q3
W*<"(
1J-I
$?1"
edQtX
z9Mw7&[
Wb:_
P+G n
.<5t
^q_V
ymC>
vphIv
A^"E*]
vvT
'W9T
wyiVuKyM74pxbPI0nf9WUV
]?*c
YVVQhf`
Xb)Q29
dK{XEW
v+&+
ps~TuH
lRn^
Q<{_M
*QOWre
n Vs7
KE(j
N[T2
u|'!@
#RXWf
a=@)
l%p|!
O"X(
dH3vp
A1YpR<
$?bA
rKOp
$EI,
fp2Z
{w;v
,u"]
RG^n
sGWBya!
B`E_:
{ls|
E`e$
miwZo[7
&:={
X-_I
444-^[Ynxuf
QQPC
R79"
r)h o1
lV>[
%f&\
$JUIB
(b10V
4#f-
5D/g
Ch4~
<K-p
?[BQ
444"444)444#444
MB{WH
M|lZ$!
p9>f
VrmGE
%]@eHd
i#G=j\&
U*Er
8Q%w
b[B@
:"0
qA$
<\8a
"?0S
w(d "
7wr!
Nij6s
9>U4444
oClk
:u:t
:CVE
*Yrh)/}
TFR<"
8_R]
FXCaTd
mtApo
+ck`p-
o$S:
kjUq
:8IJ444
444 EFLTwte
*;xaZ
k|R}
;:Ds
rrcF
S+^+a
8d9L
YyI:+
ZZbX
ZYZ
loj%@H
,e@q
y'jB
(<u]
9h)y
Bi55c
^R'
UF!$
T+h
Q}\v[kpv
#bZw
% r,B
01
^]Hd
yk*u
Il5z
ukjIU
Tp }i
`zdb
p_b4
+J|Y( =
+t+9
C5W
|pg`
H|Xq
M HLk
Frl?z<
P0rg
9J9<
Z)?b
H2o V
-vJ71
'008
L{ 2
rdZ3H
[\m>?;9
pA#e
tTLj
A((k
\`y>
xa[
[whhk
.text
3K0
W`H>!&
G wg
OPfus
);Eai
1w<
}uAz
sx kJS
GetObject
4\o
'`?7
rSq
/)@v
G%oVH$
e2/V
O?7_j
I_F!D
9a&f
#,?uORn
"YFU
z4@
L</"C
LMJVO
f:DV
R,VE
s/wq
1v%"~
/LJ
C-@S
;+6x
=r-1W
\C|et
f]?Q
.="q
mOSJ0Z
MtTx
v3D3
>TV6
jf-A!
;Lum
'4
/[EYX
NB}c{
Tn[x
444W444,444
YAi$G
t%%-
LSYB
0gu~
`CZ'q
sKv)
Cxee
"\e1
:m-AW
9 (nB
/BD0Vy
# j2o
Rn3d?
tBgQ
\!D
5v"'
a^%z* X%
J|G_Z
q%nH
7[im~.
k+ET(M`
Ykc}
J3X#
9IR#
!XA^
q`\4
#[.,
gx.>6(j
(TW{
%9qVd
L\I,
E) %u
t8se~
R?&]u
8Jbk3c
13F&//<
{,r3
B2N
4443`[O
XA/%9ZNX{
,RM!
rnu0
9/-,@
l;M=
h{o]
L;T!3
MM_u
4#EC
o1<t
"h=s
<N@}
bQipM
JVAN?
444 444
0o_)\>?
F&%/
CreateDecryptor
MBQ;
B)sp
aqUe
ccnG
!BJ5
(8RHq
^:"S
lY+)
zoX3
1`Eq6
fgxX%%3
$]lf
OdZ35
=F^A
=>_a
BvBUcr
DbC2
n3 M
gwy
=wYvO U
]8b?
*@.9}
=PS
>h\G
:ki 3+:
zs;?
$]l8
M^czho
IMCiZn
R^aC
stK*
L[ o
3+?oCW
n@iPH
x5 ^
\#*~
\ab
,>1D
8pT@K
2V[PY
YrtQ
)]^%
2!b9&
:Ox2
<1+D
cdu\
euhDW
sf`'
J~|.
+<t1-^]
1/01
J=eaq
A;J [@
|pU-
tB.
2Z]o
uu5[(
b3.j
#I!ae
YxZJ
N3PGzn9
n;)
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
a.M5
Ff+Gr
q! d
^ERjC
oj+
DX6H_Xt4}Rk5
uAM}
9vV^
L/@~
B[X3
~_=0
ag&e
|.,B
:U^(
F|Xg>;q
F)U
1<N
#se"
Y4k+
pqDA
WB#W
s+\30
>tv
tAWr
6<yQNI
00bA
D>6BWQ
^qBF
S)&M&
@vj
Ih'Ifq0
fT<P<
Dh\p
)X/NA
*2[
6d)^
a!4}(
2:S`
MvT$X
s~5&C
@lp.
`_O
>LC\
TD02
kW\
;&HM{
444e444
^6%/J
444VNRe?.5T
HH&w
1Se+dx
d8&|
?kKX
Lf)FB!
V\}i@
_G^'
,Fb|
bxx7
q vuNP
N:Ys@
Q1X1[
;ZcEb _
2_KP
L}:r
bV#:
"x1jpA3O4piFW05TgQhWor0AG4HQrtVSMR5
hkado
Naa 2@
uJ)5
qH8I'
L!j^
YPZt
(z.K
UoVL
m3YI
{LJv
t8 P
/}}N
7IH3
@c{ F
sUbA
e01r./?
t~bW
xE,e
,L*y)
!b7r
En_ZaL
AXyf1
'</(
DI?#
N>m
LPku
z:0^7
Yr@~{
Suw{
x=_c
TyYM
xftnV
fbu_
0H}
JQKEy
vf MZ
pVU1
[ir+
1~
@c;q{b#
21k W
#5M!
444U444
8RcR
,8UQ!
E>G
{HO
AY=AkHm
UgDpz
?
_nUh
\+Q.w
]vLzj
kASJ
8>xd
h"AU
: 8
sSQ
a>UT
`+Qh^D
dBMLJIRjQFcOuYsPV47ilFqffeIl
t$lm
*l[M
cnBdoM'%kP
5L>v
5Fm[
KN7
)A_%
j<*&U&
B:qd[i
G=_O
*X?\
3Ii][S
-0m
System
c_Xz
5#f'
tQv9
`5m)
.Q)q
xj|
$/Kb
^)mB>
:( i
t J
N|?B
$WQ'8
&A3L?Q
[DpFne
J^ib
lWb%
@"by
6W=R*
ayZ `
CUdjT_
YtXk}!
444 444 LN[DA@G
i$KK
_{6^t=J{
]D n
.puX
yYFk_|
hvKHU
brPU
A tc
TFS69fyxnx8RTQ1ZjTFFVN
ve-pX
MethodBase
>ZO,
444,444
2SO
1xx
JpON\]`
6myB^J\
uBJx
kPXw
P5ptV2
Y"S
b(.g~
K-=u
y%^%
?p'*E
U0R
\,s\
R!$
Aeg5
=Z]E
^v&O-
/U|6
4T}1H
^Y^ 73?
DCa<
NWi@
bPJ#o
g}L#
m`"d
FCGG|
}'!Z
{43I]
+ aG A
}9SF
~86
e#uA
c^ZB
'GH>
.3g6
#rlRlogHOfXkC1lRwWG8UczRm9J6bsjLNJ2x
#p`d
FTpi
Av70
Zm&
z68gn
"-41>
XOhg
|RO=
CShy@
Q9{1
rCx
^e;rL7
fO}4^
=ni`3
Q$I
Fp!}
_7=
07j6
V;|x
0=YL=
{$ER'*|e
pCX[
6\{dC1QZP
f%6XD
sFBz$6
@A_;
2{c%
,vA
AjC
{k3g
{;yd
`4bQl[Vx
6~CC
L[!
nGZ$
fB42
cjj2
X9a2
`*_&
Zm=N
qYL,<M
5S)4
}o\M
y:v1
I2=Oe
{8Lu
Eb0[al
Ap5'JP
GA_m
(=H35Q
_uv@\f
):AE
'O%m
;lP[
=z78
]o e
+9 >
]vIl
`7xd
bb%4
4W&6
[5zn
B5B<
F|;8
4yov
m;Vf6
Aj%
3*fN
D7w/
N ;p
f>,l"
+Ro;
%q)~O
~:>s
_CorExeMain
Y:ian
Q.rc
ZY)6
444cahTf[B
*<?
YT]V
&;E
+48)
444 444 444
$r>#u
U94`
F+$'^
KL^J
h2!i
,]\
ZMG9qp
}!hU
C:Xq
XenC
<I!{R
{L:^
T]a}
zcEHM
w"pH6
fP.[
L$~bF
-&;@
D! -
%Kd% #;I
444 444444444 444
NNS!
w&?<D
]2O6[
UY3'
5O!4ddE
$}v"
.[_+
>~\(R
9QTh
=|dEj
EggN/kIj
:6D fP
212D2bqnH4HcnS7HpOq2oHd6p
7JW7
tK{~
C =p7`
hld4r
PT.F
MVq)
DCD3
(zm
-'{Z
gp%/
n5Fq
}uH "G5N8
1 A_
I9-:
444.444=444Q444H444.444
q/,h
@wA[E
rn"=
ms(*
}~w}]
I"0b
gGYcT
G+8<
@1'Z
p>.l
TA1?
@;9T
@[|t 5
Dh!v
H}U<
Gz#P5,
M}>'
_Jp
'7Eo
y+i(X
s[Qg
|vOw
)Zy!
or9x
ABr?
OE;
]~,Ss
;?r;
=w}g
444@ALZ
#9A %T
3+v`
+iz
&rBo3
;'}7
gN._[A
l:l`
m!hl0*
C0qS
U.aR2
KT<vE
4442LNYh./?
([p"a
!tG!
88[-$
wSo|%
d>zI
PHAU
tU@>
71Wv
c/h?
*)*a
~s G
Y/k'
|Z/'
qsDc
kZu$
5~)"
ge6m
jP22
Fj =
X!)R
> ;U
A4.Z\
G.u=1
tQ#<%
ZsEDK
Kmq,E
rRZ^.
sQ\J2[
2{+~
5aj6U
C )<
MEqE
)'SX
K ;f
e[=3
@DAq $
j`I%
W[iF
bs0,
.Qs
>&}O@w
-!Fp
/4q&
c2KXw
6]~<
I,RR
S?_
dq|/v
pQ@ B
FArm
_Hl>
:Pe~ZSP
3{ U:A
oouJ
e@:n
|%so>O
t mD
79io){
_Y%`
?ZX
Yv&D
k}|q
_T.f
4!a6
qROL)G
TWHd i0
=g!}[
;!/&
2pgf3
b]*j
X_`
a9!),
"OPW
eZJ2+
LbR56
444s444&444
-)T5m
ZPt '=}S
.Js^I
BZ+"
Jk5&
<g!S
?"K]Yk
r6r
":a?
5l8@
rX_.
E2=v
Nv u
42crf_
{$b
c&v`
7v&]
|Wca
J\s'
E$x,
A&`J4
c`_M
444t444M4446444*444$444"444
/%['
fS_u
=^;&'
444 ABM
u,=}
{$bD
5JjC
9b>q
PaX
sDqkHo
'<zF
cw'P
$Q!b
%_ *
?0Q
H cN&
Y2U\ J
zQQr
~ (mK
`v{X
FH!*
LES+
8 ;p.
i] 5.9
Y48U60A9mfOraDIiFctgtWAk7O33MS
5h\d
C$0,
"]^F
kQ,nx
i;|)
J"EL
Y Wk
IOwG
)_ZK{J
oce
0<Q)n
q?aA
!24X
$Pm}
x$R`/ri
>H>
P^Wj
gQ?+_M k
O.mS
hiu)wp\
a"wf
%*0
|dnfS{
Ak6YVlO
aOT9
'F=hY
BP o
@KQL
#}s0
-b[8:
(9^=e
~J$G
3*D8i
#1IE
q{,v U
V<'4
nNL
Y-K^
444#@?JQ::D
>uL1
1=;i
_):@
c%s"H
90<
I|6r
h=|^
} 3N
}(0T
6?n&
~)9Dnj
?%1d
umDg:
cQ;p
5wk
444>YY\
P-2 "^;
jB}T C2
Z &k
cFB9Y
CBSs
[.z3R
aru1
E&.V
l_>y
)M(g\
9hMQ=
fKk^j
57Tw
S~+g*
Xk1
ES;P V
rJad
'$U>
? TU%;Q
444 @;A
Rm91
c .Mc
}f<t_
_<M[
?H>^
X/!Tg
otNY|
n$
=Tg?e
j.O$l
2%?Oj\{%
6o%M
jscoD
}(nt
;\B}x
F|ah
%E/t"
ar(#
~;K+
11LB
da<n
Ob*EI
h*,4
444 444444
}X DH
444w444(444
^z=9 P
ID^U
!i>^t
#^,R
"?4)
8hDLW
PhuK%
EZv
p{q
&w[n7/jZ
LNA=
R78
y lo>
~LH
aKwI03DkP2eaTdGxMmIz
xB(QwK
vl1
| &[
Tj}s`v
H-*j
1@};
iY8+
%nd<pj:
IH!+ <
b;iA
K%nb
0}d,
H}%Y
W<`Oj"
'&kt
'b8z
z7'
.qbgh
|v(@
y8mKAe
w4+t
<u';
O)@|asU;
9f=qA
6%{V
OQoK/
v\|
.Ey.vX
&V{?Ao
Qzxix
?Vr:
<g3
E@ ~K
b|KAKT
1 g
P%:?
L+.;
I >1y f)
.#dK
;O`:b
{vq
gh&t
^IU6<l ^
ay-Hm
c7
}0m-
)X)L
4444444 444
;Ds-
z#Xn,
o6'
q{ nC
\S72xp@M
4z;a3
Xyq#lV#
h9%}Zp$
sJ\K
(ycE
Ve$0
o38CplH5)
2b A
Oyw+o
444f444 444
%Zj'
sxw/
Y{?8+%
v<U#n
d|Id
HEg>y
1|%z
|-$A
lc"-7
(2;
_B3@
rrxIU
;~sx3
E5P/
bFMW
/JntD
raxE
d6WW
3 48
YaxUM
.2Z3
k{o$
)CL
{lz%
%'&T
<@2"
Ik>
`jAi
@}'>I
2D+aN
Tn)\~
d6#i
SRY)ig
.r o
cndB
2` 9
\System.String[], mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PAV
+{Y(
{~iB
q=d@
j5.&
b${ <6
~wx
hq}-
G[C!
tL h]
%(9a
/w]cu
7gi[kY
U>~o
Cvk7
/"q6w
CA$E
97"E[:
Lkwr
:( p|.r
Z-H-
IYQ?
^HP_'[*X
wp:$F
j`"h
3C T
QADt
ZB8g
R^Lvn$
<MFV
JEkJ?
4h#n
=>q3;
xBA"
#mK
$&8;ROY
%(9&
<xvU
-pwZ
WWn`
J2mP
$<S^-o
444 \_oI(/N
#@ i
O"l?
>& b
6),v
n RU
>*!s
ww|FE?I
AR~cN
yVwh
g*KM
-zgH
RuntimeCompatibilityAttribute
ppG"
?JugT
WAc'
Jn53
)&{
o^El
.&~w
&ZbU
}B5Z
."CE
2 2ka
:vFH
444`444:444
s*d>5
a{+A
HYs%
CFJF
Q7Uqyy
)v_
t"l
BL d!
mxD$
444 LO_5opf
*c%W
3q{8
KJd
BPQ1
kBXg
3XP*
L\M1
{$}Y
B=<?
1xyD
cZI
f 8
4ofy*
O,m?
;F:?
;(!]
4+Y/(
~:~T
]Ka6
j^Y\
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hp'cj
xJ19
}lV*
xq(TN
y)v>
5t6/rB
n]]FP+
n09R)+
|$Xz
[2'g
S -Q}
sks'
?zp3
|4>
w>.m
/8n
-Gb;
X>rc20n
5L^-
roxjJ
c`# =
e_!qiH
(|\S
|,*,s
qAu`
UlL5
>&rY
V]-#Rkl
p$vB
MV#
Mfh
/R@m
&|J"c(
tll2
:j?jX
.\yC
2-53#4=j
6V22$
W@v$
E 84
[HBO
^dN '
/ v*~^zq
m~wI
p~5&j
&V Us
444s444I444'444
&;@pG
uP'8
N~I0-
/EUD
SU]d
0PeF
m4x*
A(oa1 e8
v0pE
G4nW
-1$
'dzg
1nZGGj
j!)
;|p}
O$5VU;
vcSJo
nrPe
A-BV
B,'
D-dMC
?4P*
f5TV
AIsV
Q+@br
C?9eG
3M,s,
GQ>v
>z2u
muTGREDJXXR4FyaNJ79N6UioGpPBSTF
HHX[13F
K&e"
444}SUdy
./-;
#Blob
Iz2XwX
~"5M
m{&*.
lptyy)
&YE%}
CfC)
Z(v@
yry[
*n#7
ip+8
b$aDF&*f
f D
&HPvX=M
EGQne
"&(j
e<"O
/6YN-4S
HQn9
$l;T
{{<D
h.%}t
%kS@b6
3+!P
444 yxz1
]cybom
Oy.M
xd`a>
v&kL
444[444
(WEc
F@?_
h|<'!
&Z{1{S
5)0w
HV(hHB
/1j05
dh5B
444444
Csl
+'YO"F
W>v
cIv[
AW*'
rgLZi9HPBzdsXXLe3RaPEpTyDcSeSoya
=Wzl
b{Jb
K$_3a
JTL
*6_c
C ;AGF6C
BRx}
#m>ee
bYw`
>vV)
YGzwH
H /y['
H>p
m4{
eR:]'
[P*X
)k
/j86
8BGy
86|!
r:@
Lfq$
v2Lm
F?QG
D;%e
R(,U;7b
04_:
$}H
g*n1
?'Q4
.tU:
g4aV
=~Qo
}.m[n ]
?=|L
/Rgk
W}\_O
Khl%
@wR6.
mJNnq
B+{N>4
:O{C
,]s<
ZkW?
]]cu444'444 444
DG$%
^ADm
dft#
5L=P
!5\D
hK'"
BUw
LY,
|H|v
zsuJ
|v}b
9;bXKl;Y
c.`/
X@-Yb
R(~
pp%J3
T*n{
/|ef
Q9o/r
tBb8q
):}y
2&l4
}Z S
+Xs
#},:
}'}r
wDWJ
cW@z;
GO>C
oo1Y
iLN}s
P'0EX]
{VC{
vC=&9ta
"Nrt
RQE 6
zeC7
Ug4V
kG$`
u>x
v5ehv
lR#n(F
K%M V*
?$sW
BKF'
YXYp]j
Y,5@
A5o+
gonn
Ci_Kl
E:
Q5.=
V[q$
/)y4
1p7U
[Q[N
[v''
p\+~
O~h,
Uh/&
xLc
H_3(
n:jd
iIGg*]pm
{0|Z
cNckr
dF]
Wv~P
*'P9
eu4kd
&\G
'F$u0
XG9
?Ft|
bK]fI
6eWRz
ada]
FCI(Q
jDlE
Ed@N
&$.J
-_]9
{8'
:b-M
zXkL
>wQ0
^(_H
t4mA'
;;LFua4
ATt
^FS;hwi
r:I=
wPD4
_"/N
@aV)M
4VB;
pvzp
MCeb
444)444 444
{}r5
IG`,
Tn`|
/4RP
*`:
-;S7
V /,g
6.`ZN
)YU`3D
H (G
AMHw
$#vO
RD,4
\9Hv
lY 0
To p
m#{$
9q{p
p T^_
] 1RvD
mscorlib
( ]@
i QQ 4
jCU
n[8`>
444H444
h]X
s\it
6/g2$V
0o;>
j#xB
mn$x@E
""DS
\'B\c]h
0t@y
5_6}
[xh`
^cN5
LML~
1G\0S
h5kGBB_
Ne:)
|DZf
+Rg2u
#I4
VF'q
+= Y
1J'w
8[Ml
Fe t
Gr*&
oYZu
vL)(
lFTz
foZn
{-AI6
*C^(
O\5c
mE!j
*p+7
`='[ X
Oy};r
vXSRhq
&@DQ
'PD`
j=*s
[)?f
olnM
444444!mhf
A$wr
'|]e
RLXC "2
_ a]
RuntimeTypeHandle
3ZpS
!(w G//
KV/^
A=9$D
[Bq[
|3ER*
zQ%&E
jv&
xF,%
.q?z
Xd_|L
st2
c9|WvQ
iIrEtuuVbPxQSYIOPAkhQP
92Uj,R
5EA>_
to 1
WF{u
]d A
ONWT
o~5Vh2
''*'4
W8L
xAk
o9jLw
3?uh
f'`c
wTX^
k1CA
>:{5
} y,
56FOxfA
uLS?
P E0
\f*{a
u4r.
MfF-w
B24I
"~R3)E
\_~C
M0bm
h4]q
#F`I_
R{,
-F"N
xb[U
`qR_
58zP
444#444G444{444
k6]#U$
dNx_
]$@Yq
(uP$
K-0~
a#WI
n<?<M
H(Tz
p>Y0
B$5-
M6CLC
C}TH
i}nxw
8l7b
Q$74jx
-T
JBTf
444v444a444J4442444
~"*
V8q6
a+-Ab!l
4sZ5
[2st
VES!
=b'#<
((V
c@1e
$e-f
<$Uj
N:beW
j%hd']A'O+Y;!
XzCgJ
{_T&y
^<6.
*Yx4
"tHv,
!Q-;
CUD{
zo`<
=Yh1
H^#L
JfL4
^@;{
/gN5
UTXk
!\_
2u'j/
,G=3
VjN_v QnE1
1p5vkv\q
TeU(
Qmtsm
`".V7
/>\-Wl
\Qp3
Z~Hp
r*mJL
7rF|$
sV/A
G;viW
kM3
2fI^
IvW&
N x!
)L0t<
X:3r
q'/
#'|Z
B?S2
h/=M
Tr$J
x3N|
G$'>
!This program cannot be run in DOS mode. $
d7N4
k_+N
DS )
I]+ CtG
#!Rs
3ozt
'{F4o
00 Z
{ M1
3<Rq
.2Vwa
r|~
444l444g444`444N444=444*444
Oj;&
s>e{
5qy
r]<@
k;y< r
njcw(
,>3
v$1i
f<Q+
t#F0
z/F[Z
u@TV!~'
BJM
)8FA
-(?8
=<>`
rih
94ps
tN`=I
*M+g
J3z
NanR
pS;m
h}WL
/Hss
Jb F_rB
&d"n
]%ZB
_4)<
/_
U9Wxu
6VCa5xBjdWSYzMqM6Oh1t
Ty`
9y\c
[!Jw5
mi)1
V .$H
(AMGw6}6
\bp. IyQA
*C13
u6L! rRG\\Q^
U7SK
^{(J
.o1^zU
Gax{
S+Ga
r+ G
O.k3D
lE\
h05B
WZl1&,K
u#C(
\-*
!-ZX
#Q&,
^bvZh
mHhwSg
2I&%
cF+pxgp/
d.-V
k\C.
^#/_
=$)<>
HO@*
e`J#`%
zor">
b[<L
W43T
_Y!r
}hND@
LyP%
+muJxj
^]i7444
nS&~
s_4
6J5Hp0
mLob_
nY^^<2
Li'gkDps
11wx
m5I
?IxP
Q~o
2;{S`-
~d5w>
iBfR
z=K7wd
&U*y
9EsK
[e/8
(9bJX
}V`>G
V?vp{
/JFh$
sy 3$
92|yHo4k*i
HR@l
zTjza
{&Em#
eTJ
rXdT
SH|u
7U9|
`xq_+\
TW6<%
/+I1
<[ 5f
%~#=
=ny6';=
[zey
_Nc6y
444 ><H
Ms`Slt
40D%
aht2n
=}:cv
l\m\P@t
kl*E
%HcB
EEk|
)ZX\
iN>Bn&
#}9
R{fi
7(uDM8ZQn
F*<$Wi
#0/d.
c"YgQ
.,ld
YCOt
:)A)X2|
lx{h
B][
5 ~X
BY\O
f5 E
444g444 444
PyXz
*&@GT
(; j
O%A
_vW
K"k<
o<Q
\>yrP
@ew`
x9[^
*I8M/
1_[_
6'A
.Z(<
#Y e
K"xDz
r{$z;
xsq[
%i-y
tW/;4
?,aw
V&.tN&
K,,"
Z[8`V
!GsV
-5y=M
1xbw
e!Q`
x1q@aQ
i`|md6W-
B"S'T
zG%
fd3s
G V b
@2kHNv
Vn[3
k'ORbn
$( &
?:kP
dLwv
b2={
_4aw
`9Y1
~UvMe\6
set_Key
*q.\
^25v
NJ0"
~tViN
|yd,
"Q(GF
@A#B
1O0*~
:!5f
?%sz2K}
IcmS<
e|Mw
-SyrB
-0z'
ypk$)/2S
L*K!
a8 l
/qV=
h0gM
pi ii,
?}*y
|]):
"H|h
"x}
FSW+
O4D
6|'Fqw
MethodInfo
o/D9B
tT'e
rVTX
Ll1T}7
a+Ar
.]$
+ #
s~iW
CompilationRelaxationsAttribute
VR^$zrR
x1Sz
p+^yn
Rg]3
c S#
STaP444
`t`sV+
xFjb
M5{j
444o444(444
}#@;
9?/"[
%&d(
m5j&
XRaBc;
e9O{
*`1g
yHLH
Drl-/
/G@)W,&|
444e444"444
O A3
v>H-x
Yj6
r1eL
id7E0|
kyJPn6KaBqsbnE09X46LRiwlszng
I"/H
-3pOG1
Yg(
7>7`x
.#ub
'Ur?L/4
SSWd
-BQ{
DFV[444*444
FuyI
szPD
ex3
jcal
8OE.
Yr!E
M re
4,5j
LZ`bVk9Vo
cvsU[
Bu_S
nGO6
?!S
aNWnS
EO>3
6NhP
GW[VT
444'444HNMSm444
*3V
5~u :
=<tt
'<b5A
`iE|
YZhp
%~3<[
^)IY
_N@S\
*vB
=m| (
vT;
1#J6
wM{Dj
4aPN{E&E
)[7.@
urv$:71
^^ha
o4}wd
}s;:=b4
W+bk
-V!
p+QZ[
i}Ku*
edu/
%ai3s
' )uB
[ oO-(
B kA\
wF)qu
g)}[
P ]4>
sk7K
)X-e
eB3w
mg Y_%Y$
^b(|
PQa{
p+X-pj
+mo6[
v`@j
Ps9Qx
XEuG
:yKm
\t4b
<D{S}
hcw9
oll8
ns7D
o=iL*
@pxK\R
aNS G
*5v'
AEnV
{IsF'
j{O,
$:J7
.S
?nyj
;`1V
US`r$!&
m!<
HS-
M[}a
{.!H
;0'8BG
%y'0d
*| f=
R2Yz
tLtM
7+rE
: Rc
qjMrU
444;444 444
!@<-
wW1i
8j41i
UrG?
x" 5=
v@eP
b3**d
`~lq_
*9kV
jX`]
tRVum
K "A
]O)J
/AEH
l}WJO
Uo!ZkZbo
>wgp
]PB.U
ed6Y
mnx$*(2
_~v`
,Pu>D
N{yF0
"s{KK
!Kl8
_R~'8
YlA=%
sUpZs
S*bS
/YuX
d]KZ#
ZlKz
Fg Y}
);"-
46GMEH[
cxY$
X! U D
[@1jg
:\ld3
Ba;B
|E?-
z;{5De
|Rn!
&jtc
Y<!|
Y-;q7j
wRr|>
K2h7qp9RtioE7PFFoswGBHKmnGUaYu
:U_.LZ
& g
SD#G
wvV
F'L>
f$R1
Rk"\
>l)i
@ky&
Eca
z)i|
8cI2
y}>
4lNN
npe7
%z.O^!
#|RH#1
444N444&444
6SNzc
G%Q7
_~d_D
W#A/
E7!p
Sa(T
I568
QMQr
nA8v
m_4}
5_U{
{.Zq
STyu
Ev'd
+H:axJ
rkMl
E]J<
Ig
3}cWx
vxUC
8(<h
5![}
#$V
U8il*x;
QR4G8
e?tTi
s R
W#8|
Show
Ui5
g y9
O (#G
)K jY
}F}!p
[>y
nb2c
:r$
@Y,J
BR"}+<
nwKoI
4Cg'
cBS
G<Rc
#)tL
b1Kw
RcYEqaJ
##VG
!1b
yaP3
|~_1
~bsV
b5:
}K(%
O&+}
X =$u.y
-9H=
Ftkl@
x~v*
x8
{'D
ES@nop
H`||\
i'<N
=K$t
vjY+
*U2LL[
`e&PB
m O{
m`+cb
$)7}#
>L9ix
=NH3#V
}*L
b$JZd
OKld
:r>$
(DNVr
NK8E
l2v_
4He9x
uXa6
Frn>V
i*Z,
ZMW=E
wm79n
444\`o46;T
f9B66m
|PP}a
ToArray
M8sL
lR q0c
_)"qG#
|c>{
+'E0
16?Y
-hv+G
A^'NJ
z9,i
1,]
6cZn
jO#`%=
kw$?=,'
pI>/r
9r (
EFSm444%444 444
+:Vb/
"&W2
"J^7W
P]X#
@fs|
;00W
>S9}
m][o4
2+2+J6
ZxT9P
<l)
g3WOC
4442444 444
iz <
H\1_)
(cu}
5}5k
Qw$d
"1wNV
444q444*444
&<<g
7d^p
rKRo
-b
jp`q
Gu>L
Q`a1
"BJvy
besK
E=tV
V4Y
$*9r
hahE9
mkp!M
lQ+87
dD'F
3i6s
E1M(
$ 06
CCk)uA
F?4S
k5x'
#7)d!
d7
+7mq
DTOwz
@Jo
E2'i
_,s,?
6K`P
X4,k
2HfY
qFn3H A
j^e9
444H444!444 444
444~444I444)444
IZoih
NT *
W(byCT
G9m?
^]g2444
=VfE
5&?w
IP.9
Mn"GR
'l,#R
8!:P%
uN
6">jBI
c#<~
XFCa
=y'<
#Uh0
feup
3<<cn
s8u`
dBB; H
O]S1
@%/$B&
un<"
SF b
m SD
cTF
&|xZu
3^em
5;1|0Un
a?Qw
C37%
IyRY
p7zm
KLf
qLVb
6\EL^
uY3_`w
F 2P\
BXYth-O
x+8C
IX.$
X/|
444 444
lOTxxJw5HG4o6jyD1VPVzKU2dqZK
(Mz0
V|H
UU?
Pv~(
[; @J
g/A M
.$85
4q7
MD`
D0y
1+lW
j A)
x%"v
a%_
J#i]
h2:X\
I[Tp
rv+l
!*`>
{X]9
a$KS
(:Jt
] ]N
C~VPl
|F5t
4448444
T-BH
W0PH
r_zJE^
#ewwL
'E2F
rv+B
4Z87c7
(!Kc
)g|R
.pFF:[9
;F>oN
]|?
W[<lC
7V&
C]A,"H
444/444
?;V=+
rh|V
(H wr
V2bT
/gZp+zAQI
444BCTy
Kvb;
Pb+r]awu
P{PX
Q95]
L4+@
xx9[
xAc>?
YChM
;1';o;F
%ssQv
/8yw)
:cej%
b"?w
Cn
O=Z
aOR0
-T}1
i)Veq
FGlC
t9mW
7Z<BG
FGl?
gJ.:
.xm3
#JT;
9E?'&
%O!BM
:-D1
SUd862<
="^F|
*'vuc
op4,
pU2[
ZYqxC
Bcs}
CERg{
.b*A
dr4O~
UKtWXDO uFF
;^ps z
If0/
,7/f
`} R
SJV*uq_
&A 9
?~)
_fFm^]
nRm!
q f!q
g'n@
n>9i
y,*.s
?:=O[-
9qw|
;w -<7
'ay<
QD#fCI,d
1'U$
j"!wS%
&L
Dx.4
ug'u
<_sx
5@A
wGZD
pzGZ
!G ke
(=IIz>
mL[W
6Kk
gvJsi
Nhqu1
^QhZ
_e
NgJ@2AT
$K8cX
t6Cj
(,Y#z
&19_t
'4D
X2gA
H-f^E
Xmn%
6tPZ
m(&c
9hX I
8V8*
7LpqTsq
%!j)
%*/WR
V_A5
`^ b
ok7:
h49v
Jb7X
El9u
+FRbb
PXLY
xg0Y
z4s$
4443444
mEPV
sHL/
ym} 6
444p444)444
+b1W
nyT}
4443444
WG:RwAK
444b444 444
43M.
W0sm
9E0b
X"$z^H_
`A*Ls
wzC=
ht1z
`ja].
| I
W&q\n1
^Ry
O6o-
dPr@
1F4r
|-2}+?B:
2VQ-
1(&
;krn
Z0m w
Y.>U
Ei<J
&kQ,
C+,<
FY,
?G"L
By`c
!,]}L;<
:LF^
3two
Q3(V
0zhy
W&>A
!<|1
%>ud+]JG
R]`=W
G}jy
FWn Q\
9Q#:oj
@QV/
8SMc|wA-
]] \
o ;>I
PQ` CCO
J8)3|
#1pp/
F]Jj'eC
dND
E:&Ql
9 <_X
l a7(
H#eM
gLRX
[\w
C;rw
1-g(
qPJ0
pPpk
$v/HKG
Pd2c]
\oS;T
@,y;
oC4!>
ka.c
aJ" D
}u[
5vDr
^S>w
<jn4`
r>nf
!dJI
4441444
v{hFm>{
q8
set_IV
m7Jx
EkdO
#0q
3h6
;*VQ
&ZB2
^Wn
GxV>
j1@I
Z@{y
Qhf
R,\^m
N8d
'^9eI[
tojZT
$"}5Q
b'D;x
=mmwp
hQLU2
JZ@I
', '
5a}#
u x8
gJ26!
<$YB
_g_V
eRyl
z{[/
fgi)ylu*
P&M{
r"7Q
JJM@
fOG.%
"\._
444;`^c
yceAP1
/t=_5
vryw
ocUJ6
MiXe
=K&7
kXI
qkg>3
"` /
uG}+
RPKx
[G~*
>9y
rf5 }
~k J<
v5
L[G+7Q
]M(5z
r8%'
)uR"
2bxR
F&+7
cbQ,
DZ^i
'0]Z{
bB?F
I=Y{
% Ee-
jZ.B
(cd SY
f/
~ch[b!t
C0}Nr
2P-m
RMyJ
oR zA|T
ZUap
h%-M0
n{mc
99M?0
X3Z%
X9Qc
SO+
7q>i
VJ<G
Rl7_
Mkh(paa
YFM
P^B%
aq.0
g7VI
){&W2/
@Wd
mNQtx
=\-X
I8kE
M},i
.3nG
hXdE
<L|(
>zc>
Q; b
444e444$444 444
{d5Rh)PUj~
D_\kd7$ZW
:~_$Z
][O"
eYxpc
NpuY
M 'f
g` h
*exH
f=)p
>(L EXB
DZ%Q
N= 7{
Mod}
NEGT
y=EeEm
'm2s
B `r
1`:3
<(H)_
B\ET~}f
AH{l
i-NG
R<nx
?>rQw
]#F~e
s'^Y
T$Iu
c(aQ
X#Gb
Q57^
r.%m-
~`gF
`,lv
KP<7
80 C
tNy*
I58Fq
ivB-
Uq.@
d^\t
Oz"}
QTO'
rJ)j]
uawj
Z~iz
-uv2
"Y$zA
r#'h]
z2~
RNc#PHB
,@7|
N'qpM
ytaOaL
n]d4oU
!q^^
GK~i?0
IKK_
B`t=
qBRK
a]i%
U2'L
{=A
D|og
d4Pz
p|wx
%D6\
^ O
0s
tM%0
F0R>i
b\?z
}{fL
\WJ]
v=H*
'F['5Q
re[Sb
v+7Y
}\%5
[ &P
$ U5
B6Uq[
O\i!8|2^
dp:d
?Vx
gm:/mhN\
H%?i
_K0K
RLNS
7mF
[R*ve
N-t3]#y2
*<Wp
Yh/aL
U<$
3KUnU
Oqr:
OH|r
qCJ<
io,#
qNv?
OU#?
48+~
9 p+
|qi
VT_Z444 444444
P"D8
!aEa
kC{':w
<',Kf
s.$2
444R444$444 444
EdJDZ
k2`wN
qt?g
8eT#
0,he
W|Hm
Id>v{W
#4
JCF'""-
bnJAi
Y{ic
4448444
-oR*
pH*s
KlV3~/L
v[R]r
x qhQh
Xah%
(Ux
K&e_t
dBI< '
S?OV'
Jr'e#v
ct$;
?k[I*
Z+MN
V X
@I*Aka
Q:p4
A}pR
{xpq
dfu(05L
VK
nTy-
`,iNx
3}7R
C Nf
N)UCK
_68uO
dxRV
]fz
\*|,|
444:444
^o!&
p Za
=76j2
q_Nf
r(^v
J.1[q
-g"d
6flU
ZX:J
$6 ~
)^x0
wYVV
Z\p#
gT/b,K
LLR[p
4KdR#
E+Bw
Py[)cJ
V^G{
'"Q2
6G_@>
\jG>
1S6i
u609
H<_x
9v9bNGbSLnrqcKqX1mDiSzGEIr3bF
J?WKYH@V
NrV[@,
MSdH
[Z?x
UoSU*
)kY# <b
.NQx
6_[aG
67E HDQm
hc3R
4lKMcruYdrvGNQkM0vJH0IRTfla6oeQ
EwJ}l
ZP`
tm7)
qsPFD
3qKX
@r 8
a0MJO
\<nL
[E P
-'hQ
|SvI>d
9qX$Y
POQSQP[
n*J F
pe76Tf
d7YG
&|^
LLyf
f`W!
D<<x K
w7^U+
gjwI
"q<y
H0s{
{oMt
d$IE]
l)`H
JbE`#fc
#GUID
'7FvNb
j$UPrV
YJ#tTZ$
yL0'
pfOS8V5Npm6qj610TZjpRC
VIJf
)OA$+
uU3lS>
D+\k
DmA[
ht~U
K?&oH
12OUi
1cR"
4$N_
hmY\
Wzonvl.
WIc|
O`5?/
==nf
444c]P
C/#I
*-ExYG
{J<8Z5^
\ANm
h?)
TXSnT<
R >2
_JKn
DG0GX
"y5p '
c?P)]V
!e34NbX8CUgZRVraF0fM5ak2M81edviFZK
'3>-
3LLK%
VCnVo
444R444&444
,wga
T.SbQxk
ZmhVY
Kfhi^n
b|]
"wRqzyx
T7._M}
@eWG
pHFF
0pro=
AZ\ ;),
q"a
4G)o{
UQ'0ks
`[4w
+JN
v|u
444 pprt
{9jVAL
&t6"
isuH
uJRWe5
$btP
.E\% /
*[m
udV^uN
|Q)C
:Brp
;bW_b
gAa
iF90
Vf/)
W5?l
b2@it
0kqT^
iy;uj
UM!n
W8*Of
m]Z
jIaI%
j"*zu
n{FoD
I3[44\
v+*Q
%t|
`z/P
Cnf7(:
2-5t;9:
i$q|[KN
fJ\
n-
!8QN
kpB/
u~J
# )
j=S^
@K 0O
aQ 9r
$+[3R
1YbR
C`h^
.J W
$/`Y
:81r6
|#X*5p
Y\nnJNa-444
%mevj
8-ZH
p}^m
5Gt42
444'444
6nl\2B
y#"iY_V
R"B|
b/'3
Hqx|
BQj(
`dg
*Af^
b(:
+a<]
DTLTC
z1e}
}hb
pFN*
,t/xV
fo?a
_pp?
/;VG
DH 7LV
(OUu
2)
9Ot=r
R:e,
" v~
2%um
MCY
%;.>k
@@/1
7O[R
*Nb.
:Ykk
8f]`
ug/h,6?
NuiV
Y5
?0D|
{x+5Qt9c
5j8_
s&s7
<%T<>
^)hu
6/TXe
^uRu
e rvK
^z'a
K:Sv
Ud4^
U6:+g
a*qi
G_5RBD&
444h444
O}c
G)A_
K(eVv
m xo
1pI0x
Pb :
`-6g
z yc
$xKy
yukN
KxNX[
(d17
Y G;s
_n3*
4$DMsq:
5 ;`
N [+
})+{
<e]
2)<u
'"td
+[.P
=T1:
=-If
o]2Fy
sMNo
SY)
hK0>
i+cGK'_
XJI`g
|S:o
!>tl.
GlC6
068
2)UpK
i"Q8w
z>]R
@0<R
e9^R1|
ak^@
Awtf
j/h
IWk9>\h
yd"
bJdw,
f "h
ijytLoSQ5HQZEQqn3YNpgtLqZywuC
kK1:
" -a
6#L4.^
RYxpUw
XP/v2
Pv
N]ufF
ZC_;L
o0N!
sdbv
I=y
i|A^.K
FXvE
48H3
n5Bd
.<tY
Gr{-v
R~r]
nw91 `
}EIh
%f}D
wQ)
.<ts
{Q'7T
GDUz
? 0dJUA
:j^oN
)'Es
yT?3jc5
<W1 C
d8~L
iFri^^$
2rPa
bD2;
[L>)
5?<G
ORR
UGQr
K9bYRl
1V *
CYD=
?@Ol444
gx|&I
yQpn
!XR6j
<^;{
:`J\
_}xu
H&&*
+^@}2mgc
i%>U
;`?_
J o:
&n~?
&]/e
wN9,C
G0T^Qe_
"BN
'[%-5
45D88:H
:"|_
U=So
iCiQ
t1%5
Z'JD/'U
?R}O
J bN
DGBI
\wcFh
wCAu
A G&
t\95WJ
^kM]}
]V1<
LZ>L*
]$Nn
dlaV
~5-hE
75\5/
dyzv
4)YE?
FldvD
o<MD
88F
+`D?>-
,*9P
<v)m dn{
>[=
kcH[
Pb5V
444-444
wwb%
[]g`444 444 444
IrNTC
|>j0
`O'S
JNcY444
tb 8
u$'(
uY#K=
oF}G
cY'*
IHiL
f?6qO|
A47N
dBm9+3#
wpC8
Uf~&d
hV81
Qw}a]
444M444
*0 v
8{FzC
1EF^
e;@}I
'!US%
wu j
# a9
v_Xl
HhWq
bY(du
9h,
!&]Q
D#-
CLaC2
6AKtZS4OlgriQ3fHQb6wQW3zwj3n
Du(|
kT f
qcZmk
!14t*
$09=
3v~C
I6$4qw
vDm5
4447444
E5G7j
]AKP
#N$%
9;;
444X444
EFS CIe
lC2S
'0c})$
;0.e
aNNn
EHGX
)Dqg
l7Riq
6}_r9
_C1
cer?F@D
o{~k
r$GJ
G452`
sW9x
oYm>
ZU=
89JkQdbQ1CYMSOTPnRBZ
W*bYt
~lYE
;o}KB}
IerH
j])f-$L/7
C3Fd
&+VJ
GU*`
?Qy
F~4pz
=?h4
v2;8k'QjT`
9c|@
q $aOK
[dS
%HW_
/3F4 $;
mq
z3-MZ
:wBjSo
a"*G
UYuN-
vQaQ
Ml8
?2qF2
9mp cy3
F8:VP]UQ
<5&00#
L:w'
;L?y
6R]j$(I
bI0!u
8>cQ##4
dP
)qnJRX~b?
e\J'l
U 8G
i-xJ*c
mPGF|
>C#&
n|~+
aO^7
P mr
2SC"
vI$
8y~f
AppDomain
bi#a
8NCF
wVnt
T+|9
'-Y3
LXVz
p<#-
5Q]~
NEd^
(`Uq
]!4z
]4HM
get_Assembly
n9s<l
mL&{^S;
)3)%
HM$
#%$p
oK4TB/E
K`a\=
ZROS
rk=I
+&l
}@}k{?
&Fnyp~< .
Dr=R
X^1s
:~Y)
M>5)
' s[S9
0@PG)
bossemmy
7jRX
VT[j
4'"wF
S:}2
z0:O
444P444%444
C5cyQuf
\9u:0
H!tj
33gZA
7]ib`{
C^c)
Ay$dMZ
Y(y
o"PU
!m0"
OpVm_
`4T^#lpxf
L?l[W
H+Je
X@k
"%BCy
yPO2Mv
v3.v
O}% ;
Os\
jIS
:3#h
o)PAi6er
444 FFS
a@=
Q@:f]
eo,x
26Nw
(A=}
444>444
am N
444 TXmR!&C
deq?
%fP#
Z3O82
A?ZG
8zH|
]3h"B
r>=X
XJaKk
(X^\
OHMA444
'Y#T1
wCR>G
8b!
vlkT
ujK<^
Type
PsnF0AA]#
B\ls,!
2Akh62mkP0FBvapHh6dLZPoUHEHn28
e#y7
YF-"W
Tt4#M
:J|E
dh'0
op_LessThan
Z\I5}
r QL
444@444
|Zbqi
"Ni:
Y+BR
N3r<
%f\
/MR-
SGmc
NG r
y0aA~y5
)*.a
ttCb@J
Z z5$
K[l$
]jqf
[Zc-444
1PwM
blRY`6
Hl I
9taD@
U!.X
'i+qsB
n i-
Kd8k
IGPD
GdL8d
w(yN
%_:9
3'^|
Q$-0K
444m444(444 444
IVV
+c,F
JmAQ
TJPL
c.:L
,WXE
h 5jH9
xvn<
cTxO
i,65
mIEb
kaG^
SVo/XT`YCG]
+2W&S
R>afQ
7Vue
C}.$j
OM(&
T1 x
34lh@
7N&D
)9VoY
IAVN
=$gZ
:6
|p<1a
1>6C}
B9BtW
Bp<C(
ihqS
4448CBJ
.q}Iz
AqP7
|XL<
r(UY$/
$,C.
1x!?|
P|]H
FVn'
Y\g(toa
`P\Q
'GzXNz
uA+i
%8u#
G</
!mWf
"g:Lq
kSD5Qm
t@]
[~m0p
-5u*
vqs
#m*;
grXs
LPGj-
5D`gE~
'z?$
6<?|
i:Ql
F91
V'l,
vE=>
<H\[
#dXEZ?
j35JAg8N7IS6eREDJqmX2wYbgOWedFlI
>,U=
M(4
|1Kv
&1gq
Is<H
444:444v444
W+BO^!
!'&
SLC^yy
\&q$x
3r$$
T\Gb
(Hj^
e)4To
`:ts
p3^~H
Ye~9
444O444&444 444
W)>?kh
NFt
_ SC
h>vST
~ 1Qo
SkipVerification
B)Z2
i =
EhYy
7m^*
8}}=
$eC\9
=~dy
z,h2P5
0;Jf
Z20
jn2'c
XE8.T
ZrAR
4444[WN
xD[U
: <u
@*(I`W
qlbt5Zh
YY08m
Ac Y
X37/Ig
/]ow6xb
gMhf
H \^
*2qf6W
x&%AP
}o P
Eas\
8]3vg
ex<1
:xSss
.']Vz
>q&@@
=wj_
9$]G
rC<:c
r{\T
KOf"9>Y
+P y
u*=zV
IZzi
YT1a
444j444#444
_Z$`V
}Z
:.Y
=]NY
.68Yy#
}K>
1%"P$i
$th,'vn
Vmq*H
d'[
P[x6
^5Ik*
1Fh`
_cwA
}3YS"
V{Le
Z: IN
m)0M
F$|6
oP `
u zJd
`.rsrc
Z9UR.
JKeX)
`>HC
4"E/A
w48Q
RzPcV2
s**)c
Zb7t}
"W y[3
+@m
\{+p
g$I+
V^l/
]?IW]
Y4Y=
42dsx
(uK!:`
YgTm
wG&cd{
4V6q{
RXcU
444|444S4441444
K>l7
nWVv
1$Cq
`:Y]
/uKY
R[oJ
lmsL444
N9<t
a._-
a9Bt~
;n <d
>81(
CX($
|HdE{Vz
5j#
YF4\V;
H.Cp
^MdXl
qHPXIE!gO
tfj%"
+EMc
Of /
N]C3l
O{:
x|A^
%.-"S
7W_VM
Htuc
~3o-
qVsVCdVDRUYZCcRX37ERem13z60YUYxJ
dF{L5f
T+[!
444 ROW
dO![
G@E}t
?0neGe
bBSbS
zQE!
i+h\
'uCN
4446444444
*-5;
eH@%l_
!{ZW
0?u
YLg;
K5x
6%'}
* p!
n^)f9
eq ,
\Lc9
rc%
cU'JA
p3T:
o]K8
_J}%q
h-@h
6hR|
e:Yi
epC~
IZJYS
/6x>O
mh3D1DQZ88miInXUJQpGPFt7ktv
;{r
s-]a
R7e$Xr^
If9py
]iJa?1
pxQmxBzc0gQS4d2TeSCKJZKc
75"L
49:
J?GNq
9(5aA
==I}
?K? x
XYq<
N,;(<
-PAI
I~q{#
fi2j
<|&w
&Eq4
;~Gn
6:yB
gfFo
gebk
<w]a
ehyo
#Jl
_ZWk"
&i>h
q'El
y?B[
_;7:
|7YE; jB]
] <r1
|: B
S` O
x5g&
#_DC
A:+|
tOap
2g!$.
8PYY>X
gyZ>
U<8U
:m!n!yt
QHT.
hS -
qwAdsA
\2%;0
h,%
y!Ko
N,.
)Fe+
PpqP)V~
:J57(p
Nye
Z-VB
XCg2
1HKo
rc*|
TTd?8:Ow::K
SR#E
7)0@w
B_FM
AUt
ql f
@@6QpT
#mf>iD
Ix\--XiD
QR-x I
Vx)@G
].2p
@Ahn
M2F%<BC
&3dt
zs))oB
l-"hMMl
Pl n?
K4n
QUs
444/444 444
,5hl
pkG=
2/|2
*32/j
B'
,@??
p8lI
h{tnI
[AQJ
9Hg@
V&+`!MM
6 R*)
IN;:GR
IA^.'
(Wbv
.qP
\pKoQ]
u;.m
h!S9
]z\[
KD{j
?#HZ%Yl
v{q/
1gJS
l*lBzn
5+F8
Ov+nX
PhV6
E ?9
\yP0
g-mx
d@0-
PU*=
) z}
nMBx
$ZtEngnW8FkhgxYBGeuCNSD82EfGzl20iqukK
XgW
:e^
(TBU
: jP
*c`il
h`u=
$z>!/
KSCm
0MWx~]
rNiA
?tlT
[Letq)
'}u E<
@|c8
-\`#
7SYZSs~
[bho
%R^D
7Ys-
L3]l
cG} /Mbf&
H9M
H@X,o2
-<-q
I'>S
?V~3
s[NS
Kc+X
%6JS
<;Jk444#444444
4g5R
v+Vx
#Strings
J_C
m~^`
V;NO
H 1_g,m
oRgo*W
dQ"T
<e3y
B$sE
oJCy
iis
4tNd
'rq+
*Y0Hg
L>?brxS
JIz!
rMUB
zl@k.
DZ~Jp
O>C
52m1rB
38]G*
G(V=
WAcPMua
^ -R
5S$,
.=f?I
444%444);?T1MRhM18X
7k[V]x
O;r&
]5]
4443PNJtYVQ
KZflQ(
+wO&F
NW[C
xE0Qa3
h+M&a
Rk|';
/-}^
}K1JZ
#mhAL6
i&&N
M)oW
X6x
$=bV
.I7r?
uV8|]
!q?v
=E1^
^;!j
)-vl
dI>M
444a444
8 :6u
KV+(C
21KT,uP
9KcN
<|e"
i[=?
U n\
WOb}
q[x[z
1zCc
"1W#
Sq34"$
GRaA
P)u#
sh'%
I?A>
)KKS
cl=t
5P\]{+eLY_[AVX
xF:<
6l<,
No 1uBn#
3PHOfW20m52Ik1qx2952E
s7P^G7
=}>Q
1?mK
Eo8v
`ZY\
Kob
R:v;l3A*
"2$@
s_e^>
4x=:
QUus 5
%-3"d
ouVG
Nln(
&KUMXCq7EPuGxOjTqcs5kBlp1Gajs4CEUogeYwy
9"{
R}u,?
d 3T
|hfqE
'cE\{
y?p-/
p'8F_
6t_ZR
l>OjtY
p'tg
w?I#
l2 {
;"1W_
Hk5;
=Sus
;(Q@Q
+#TxZr~
G+*5
q-k (
( MH
Zwpy
Qc7R?Ng=
3H7\
;$~?$
~nD$e
eRc"
VPYf
=^om)I%
H^)W
'6T590JfnCeYepLJsfJF2hV2IwVPsL79qmqAAoiF
yTdi
B{#_
BX m!
bdQRyOVDDFXaUeZOOJ9dE9Ci4Mf
r/[d
;Wk?+
6Cb}
AAr$
7.=)
^WJT?G{
8Vh
ofk|
]#JJ
bZI~
GRsjY
L3,.
a`-8^C9X
FI
i(\=
Y!57^
Oqo
D,UNh
3dC1'
4v2x7woLsydLXfxVBOFUkfI2pg
<'Q^L
l8l+
O !o
{ ?9V
#/AP
YG20
4g6yq`
(ga
*kS}
K;:Z
56!vh
=RrU
444Y
9i hvI
11<~|k@
=? Lb
3nB<
,ZWrw,T
\fGe
/3G`
ykpHS|Hy
?jfO=zc
*vw+
eafD
znqq/x
#x[r|
8)Jw
AM#4
2WXz
|=^"r
lbgZ
0fi9?
FBkF(
|8q
hBNa9
7j3$
!f`
xmzB5_
{dV9
}VE
w9}mL
a O/t7
#?_^
Olh''
BADEpot
X]k*
'P='
f]Y9&zS
&%(^
z5}`
DdK9
&QxQ
\0tmB
VN@
gna
Mc&V
"B|Z
9Lvb
/[0y8
!&:G|
;Sv>
&.x8
vY-n
Js4b
XWI9
>VK
tvXOi_
0{zk
CwyD
s:<y
68L
K2F?7G"
}[8i
da~.p
XGST<9
m7m-
u]_T
VqWy
RBTe_'bP
ORb.444
Zq)
eW/*bu
Lv7r
Cz1x
M [e
l"~"
yjNr
D+Wvy>a.
vZ[S
\[C;10
J#'Hd
&^<oD
CsAG
B1,
P_^*
6HMBT=5
a!l!
}zZ-Y]
hZh$
K=4F
d |7
\K2(O
WTv-
Ml!c
Lv7/
/u8^
rLtA
(k#f
q{$m
FibxU
#Rn-
+OF5
_a7@
Me
@eHSH
{)U
]A%,
=^<BRF
=?SE444
444;444
S Rd
&3oW
&H>,
@O 'w
aL'
[g]_A=G
>;$h
t-W52
0"[>
XoU
\D>xl
AOA
"aa~
@I _
9r&Z=
\u}>}
Ku&}
L| 4~
1"=8
ud[\I{
ZIc
)1@lX
oD<s
tc6Y,
<-l3&M1-N
mj<T
Z ^Q
2y?F9T
,}%e
GdKYrK
3dMd
B g;=
4449444
Y"`s
T,~<
d;'
tC!F
RsE3
/h$ 9
I#?\)Y
IA7m
]0@&
~GJu{N
pE*;
"Xj~
2qDX
1 Q4
r2K
v6\|
XJbD1
JM]Z444
YOG9
`u_;
K^`yJZj
zJvn
PUDWsBjd
67_L
qR_z BZ
jL5S0pPGuMoRyjkjeHm8Ntl
Y IX3
e!-4=n
)X.O
x5=~s
|Wq;
:OGP
"m O.MS(
liH}a
B"Wr
vq I
L'MC#
4&JAL
=l@x
AMd
w[quhgE
(z*e
OF>!
GXrb
$ 3
+ben+,~
J02ja
$[ _
Vfq
28+3
~S.2H
s}"JN
6D+ 'A
"BA.
~.p,
Krn3
p"} )
<JI*
,G:)-
YFg^f
axh. =
D:XU
CnI5%5
B;@"
p:A<
j~hKy
$/[y
ur ?
C.C\0
:B/f`
|+y|
~n|a
w<sT-
JAJ`
Wvtk
!=yI
@8:UQ@
d io
x@<~
Vsn
_pg_
9l;-:n
L wJ
444u4448444
4440444
NdcQ
8b)Ev
#'j*
#_+AS
7P!
rgAh
,0L*
YWt;
G0a
{V=HQ
\(O]
zb)
%8R+
FOP:6
!/r~
]mw5
System.Security.Cryptography
& 9t
h8g
K/nK
1H5m
'+=e-->
{we`
8pF
,o.^_
7,]P
l( 9j1
0yIu9r)
C*pGZ@.
,kZl
. 6O\
FN\y^
i- !
3[ysQ
Z \N
g6J H
o?"\
V3l<
yA$
@hju
/j]0
"NSdk
QIhLL
W^1?
WScy
-4SaJE8
.-"a
K}:o
CD{+
xQh)
&Tmq
}<C
;*7Q
@4E
3e}!D
.ctor
cEp}S
+>id
b'>N
LMw]!&
mscoree.dll
#^2
iEA>
y!}d,D~w
%@9Z_l
sxh!IE
;!<s
oMuM
LFm~
v!Z!
)t|*
SKT|
PC^NAm
"C^0
M`DMW
&eg0h
S.Zj
L(7
J$u(
edu
`er
{yJq
,1u
Lb48
,XV
]t8&
WYb}
[jG|
Q,~
9#99
k9oq
*hRML4)
%lw>C$>=;+
kP|r<
\;XL `
%7FUcd8)
U/GO
q'?]
Mq;&Q
^0ZR$+
WUgk
QX^Z
M(a$
L3"zm
6i;A
B{ley|$Ze@
@.reloc
b y#
as?'X
~.,%!
YoI<
fNV\8k
a'ow
D7g&
#caHKMig8XP831sy0lVUL7L6RR1ZfIzKEDZC
V=e)
^k8"CP
WVa @BSw
h~^
7IEKzoIR3lnXNCeeELesQXXM
9M$)
{ ;oP
~IJ
icCW
?z9rVn
iD=s
Y$+O
O;Llm
xx%w&
lngVm
O_
W)Tv
(AI!
tRHd
BAL2444
zU6[
7|p
9)Vg
444h444!444
NlZR
[ t@P
)(W2t
l[>Z7
}AodE@
$bpMyYgC1ul4wzUWX9IkbxAEiltANtAGAfzXv
N&2i
`60:
-5B4
0RD}
(LQ#
z7Eb
>7!,|
444@444
Ev<%
:\+^
V}{F
FSL^M
\7&~
*^o)Q
$11I-
Gi5!oG
>]UyQ
3q7h
(w-6ca
=>G><;D
Md8^
p( q
444<444
89eX
RL;u-
ii?a
o#e
0O=tF
)znA
L;53
%cdC
; |P
4Ge/5A)dA
PSc&<
!kg.
Ed=sH
hAkK=
K8WJ
Dk.H
h/\@:
444*444>444McbdhWWZ
(1jv
bLxy3=d
^qp>'
-HJq
s4D#
3IH+F[
NMWS
HPXX-aX
F}K`
%uv^_
Ci :d
A;J\
^V,
X)$
Ska[I
q`Ewn
qN[/
v( ?1
5Aj4
k-+z
?)sGa<
Ctbg
^*^E
LV4O
DZfF
{@D
gu e
&a z
?APv307*444
kemyT
rn_k,
o`"hU
"egH
VWlu
i$!:
p 0o
)wbX
!Oru
MO[9
vFE|4s
"N(]Uh
rCB(
vu9n
'A ?|8
,Tj~]E
oNl
4Bv'
4GUb
vJB=y
gS,p
wC0N1,i1
;V~h0
jjv!+*@
%6XAtMQKi3CWIJ6hG6no5TuQ5yCUuM5hAm837J
~t6-
866>
P0?F+Q+*
j@bvaV
1Tbi
$?}~
*m&S
r/
%B8Yu
4"w0
kE5;
pKw
6|$2
so-3
9Zqub
22P@
vw|G444
9)kd
R^@fb
.ND6
n++'O|
y%CR
} d0
j3mdD
+xO_u2
GDT@
8#U*
k}XfAcq
$a=?
)*.DF
KNFe
7kI/
M:ZksD
j'xxj=
\f>n
7C!6b3
f( M
gdeu
rSW.
!r%"
_&u#
Naz{
$>C+
eE2H(
A|Z#s
i[pH
H@^@
:v,a
#2M(<
2Q47
8&
2!B#
/VJA
/9D <|G&
444+444 444
-">U
~#CsB/
k-_e
\Ix!c
44/b
i#@kx
WT/5
pI?)a`
eixQ$$2
!w/PW
(X8
PA5mt
8_Ka
coY
6{b\D
AC+# |"
_[hW
8RDO
7_yJ
/K4@
D6tE,
+h:
p~jk
D8'
>;**
444-RPQLB:4
c`Od
0)pqt@
aK&@
>`}w_
bwH
vj)1
8VU.
tYT}
WUk{8&<D
|POF!v$wD
"u ;
-9VEw
P#5U
&-Bo
uJ@N
E<ew`$
fSmR
S0J6
F+`
]CDh
{z~^
- Z6<h
O4t3
6ei|
7b\2u<
_qW_8
DK;\
$ |h
gUJ`
'P9i
C$u2
Ctjr
5`}
w:)$
RI/n
$XcEG
uXS}
C{,gvm
=_[B4t
&>#Y
qEj
~WJ|
o@&{
_2t
xe@D
LL4|
!G5Ff
\mtxo
aPn
'yk%
>eZuyG
7*/lL
CW z
]#/R
5g3A
IC]n
AS$.
RiU
.><j?
.V!t
vW@)2P
w)8;x/I
oG);
-EI
.sC[
uyQ
%/B?_
LwaMPcDNY8wGNcFGmN0FyMdd8UpjJuEx
-Vk.@
X$V
2qF#
;GBcS]
444444
fRF1
vs=Hk
S[Z-q~y
S}q|
}XT_
"jPze
|2-#
1-x-
+E![n
pdFu(
=/0#P!m$MZ
+.
=.J&X
:;WI
-fD(
MZS;88
C1!:j2
9ty29/
BOpTb
;%GZ
B[i.
`>UQ
{boi'+Y4]
tYx<
^7wb
=)9
d2km
}%qO
*)IJ
~FUQWl
a,/e
CGiKl
} 2iC
Iz44
hEBm
9+oPj
YrEw
#7Mz
Vz(8
BQ^L
{&dr
6Fawq
h4~LI
f0QJ
Xh<c4^@Y`
Rf |
1BdJtG3
s3Th
Q!E^
+,3
[5?j
ze\k
.3GMPdQ*%2
5= Y
CK(Vu
2,,$
ym(F
ZxNr
ume?@`
*}K7
|]H+
/Vi[
j3I5
..7j
p9!H
Rbc
r/)G
>vlZ
&'Wt
sz<K
444q444'444 444
78GS58H
\p`,
!#w
S}"v\q
|<3U
i6|tjq
PO){)
zw@}
]D^\1
/>/{
8 R/?
)[IG#5
D.!6
(QV3-DM:
A ~
/g_S
7T.t
;Z!)(
`YI@L
IDN
(.D>S|
/5>Y*k
a+c_
O@/UA
G=yC
4wi"N
l00H
7(xS
t&A
IfT4B
`^fEqm^
BHP/
Lj:.
Wiq+\C
a &l
444^444!444
bt>v+
yaW
gDRxR
5$MZ
\n[w
@AZF
L&j/
b1JD[V
$6]{r
G>U
Bv!U4A
piD|\
c.^e
gT:J
3 g^\z
DM L3+
444PBG]
})kLJ
LqY
,0o1r
\<@
I.P7T
h# +K
5>gn
s5QZ
L *L
k>wq
KV=
pW|-
oaR)
CPe~
Vj `06
ji{Qw
W.L[
j\~v
b/Kp>
~t+;
~Av!&
b2C;
-FYI
YpFe
9p{\
lr#Q
GxFjo
him
fq+w
444b444#444
5p3`
VyAt
A:w}c/
F[!N
?,kch[
YUrJ:-
^rD@
\D5F$J
4(B*
UXB~
it3N
{%qb
bllQ
}]Id
)k+t
-Q}5
v9}J%
*"BMc
s(9o
U}Z
}*%$M
<(iV
?ZO
,~)p
9L ,az
:UWP
fAQh|
hf_a
_ cr
-')1
`n_gF<
j.9.
(s8<
s~hf
%@9n
aEpu
e1Da
lU*JG
P Rw
klzNZQ@
;B='l
tVP>
A%WR8
zuEi
&n>)
=Lj;
4444444
r9F<
Dp`D6
QJ&C
y;Li
m { 8 K(
']}J
0)!v
<"-8
%)8N
rKA Q
Q,~U
;zZL
EXHY
e;,cVw
I4 w
Qn~TH
9_Pl\
|g:W"l
:KtR
\T][
;1P4C
5g"-
xpvr
DhfT
|^SLi
Zbt
$xE6
t@Do
|sS}T
G[K e5K[LG
9YT!
,w-"Z
.uty
#q!SU
QJ<=
JLf
:g-I
t\+4
HH#
^G{u
,`Hu{k
e.8
tPdF
2-Hk
p0KZMW
Oqd[b
%52x
444s4440444
-eo]
c6:
Y1xW
$a`B
)jTb
Ft<y
%^,0:
444G444
9Y$Ld
ns[
m9O;w
K y
yqgV
+t|r~
gfQR
Bi[[
WFA-
;~~N
,B,V
&#
/6ix
MZ.g{
Gl[h
+DCU
xe$L
444*444I444Y444C444+444
(])ut
g=3O
m":
oW,.
2<_
gdOl
+lT
/2p0^
m:_a\
D%AJ
;S-G
p@"Q
X3^hnb
w4!'^
[=<M@
?z?9pB
G.'j
K&.YS
x8Bb
@B1LvP
W }
mjy%+
K`?&$G
Xs4
#Nyv'
(5l_
udvj
CsA4
Tn5unv
Ig I ,;:
C 0/
a\QNZ
-jJH
GIp,
d,fG)!
*^(Z
.V[@
vWY:
8:=!O
CT/`
IS*>
{PNM
z55m^
A<,LU/|6
/p6V j~e
Rtp~
j&F7
/XKQ9
!JXA#
V>spZ
^/-W2
er[
.p V
A$X)
v=\
pv"Y
VMr'[
%u@S
FxXE
w!=
kQKL
`gvV
x K?
D|Y"
M%*5
M$"F
B\Y
l *
Vd[6
3k@J
J3V%-X
tfNq
BiRA
cI[u:/:
(+62
I9zsm
- P;Fh<
PhO2
[KP2
{PN.
hJ\u
"<H&
1bC*?
WcVV
vAzJ
NYK/u
444%444;VUZfHGL
4448444 444
o54]"$
_uzL|7
\%uT{
J~j71v.
a~eR
$aJps
M_:g
7z")Q<,
WIMCJ:
7[&O
o^mX
$.N2_
I8 Ar
A_}Pc
@^ B
B1QSA
0B<X&
|R78
"\RD
w*@u
bk$vD$
&YDq
6xo[
444$4444444?4442444
4P47
|.8h
rS*:u
tR[&
Y$H^
#hJ.
&:>W
MX1YI
t{HW
6aXP
lo)N
/ eT
Y=9:
X-;J
B`bG
[%,BG
R(b
F FU
|7rH
.M|*
W526rMeKN9sL8mkDHAGHB2OBHQh
?9hj
{O{C
[7 CLc
un4iUJ3mCMyM3mWVz1aHUUs
.{>S
o5K%W
.M=\cy
4441444 444
>uxT^L
m+l[K.
1FE0
_i[
|*yM
X^E0
t872
TS?x
v{y>]4
z_V{
2S"
uX,k7
]j1e
?^i~
w %x
;~29
Pdp"
JKwY
*8bB4
8Y*
n/CK
]W}}
_fyS
&<1W
<gFm
J?9
LQ b
!rzGM
i.M6
&=|R
c[w
Tk-'4
|^?
NJi/
4,{v
#:0t
u5lE
444/PPTl'(6
no{K &B
`5Yv
9Fo{
dRL/
'qDq
GOE
444y444>444
~yS$
8aUo]
'rXf
vlfD
"tC>
`5YQ
n`k{9
bjgg
\%|d
F*Em
<\LE
mdW
:6uE
v}^D
]|:S
Y>$yXE#
pU{R
TAfe
HFHn[#
G>LBy
FEH]ieM
RijndaelManaged
-\ xEX
h%0n
Gh'U
e5xuH4&7
H>VqLnMRGr
444G444$444
vRG)
zA
V j
ljs]
Mru.
tjFADfaBBVxoV68wnDthc8ZsbNb
Q FJ
LCs.
M]gM
>>[c
mwuV
-]n{j
444z444?444
ka=H
w 2U*
#>joZ~
{TMo
f~mJ
1B.
!U *
!F]2
)QK8
FI)hc
n)4{
ow=jmMy
lglV
A];oLM
CJN%
.~ob
Dw%8
6xp:
.#^H6
y@DC
YL)
}+
$2O4ewtnQsUBPXnNM0KjhmXFQ5SpzGHQ7GTBm
lO&M
>u0L
=ANP
{J\`
Tb!S
*B@?
Z+i_
a,Q2N
*A)?'&r
%1V 0
lx0Oz
N6xQUbh(%
x9 G
!Md1
[MsN
3] W,~
;] 4
444)444444
V|,%:
'V&"
v\-Kc
*>./(
)bY,
m]W@
`4Bo
NN]O}sK
+ja.z
HIhz
V&0
n~\^
UBgYTePRIW2C4eAETBqcQQpjTNnLt
}a~o
J?8!w
$70:j
{43U
LYu
Byc3
v;Csml
$ ;W
fP:rG
TLsjK1
07F/
7x%_ut
y+2f
a,mhB
~.b1E
@G5gS
T ;
&M4Z=u
veL~
RB*h
_U(D
w"7p
cdl6
r{AB
a2@J
8"|7.
`6W"
P[e2
=Ri
K`9
X|i:
KJ[h
9Khg
%GsA
^M/\
.7sb
OtnD
&YO9
E0&}
wGd
W7FA
5I*/y
g ]|
o=1 f
c7G,
`j"[
[*^8T
N=uMU
V'4h$
\ X$
w0q!
n@S6
EfR
K@Gr
n+Zt
pt"
08@1
Qe=f
\I|e
2DX-
g7wB).C
j05>
$,z#(R-
:iYJ
:dNpB
gG9x
izth
/O@n
YRxi
.(_T
k0{=
\Jyyp
?Wmn #
/ c,
Fc^l.
?*h!
X'|=m}
rU!m
s \ Y
~iM d
Z'7x
+"i]
ssH
444^444
It"Jj%
d '
Uu"~y
9|?
1m[!5w
RKOC
.*-S
-KH1
hS/}
w%0xH@B
`bY.+
oH7P
z*nf
o?C>
YXa~444'444 444
>'M^|
@$Mm
mE[S6c
vd,|
]Jy_
EcwJ
e0x2
<pp+
`0Tx)(H3
@1I8:
|Uv$
~-NE
(*TF
B@P^UI8
444xOQ`
_XQ1.
ES;Du
nb3
m7[ze
[T{*
vx$I
9HX#
)K4#:
?VLU
9;}V%S
~}^<j
J[I-E
Zb'OH
!VV_
tsVO]
58j_
-2hNI
6a?i
UXL%>
neD
,z d
Q*D
~K?2
5U)?
]7(~
f{1cHq
]Zxq
3_N
Fhtf
~pV1
!s[+
[6nd
gC%$
,"Z=
^RRg
6GHtS
=H{=
Q_9;
wI<@
]{E
m|??J;nB
=9EG
=!KX%X>
I(GN
l =f
BBem
zy@I][0
_]:
7Ms}
RXq& "5
S?.\]r
#I\@
b|dy2
444=444
}xu=
{H:^
8?_
6x\/Ha
Sql(
(e=Mh
d\N
-@Y`I
CR%DT
Wz[
(":Z
:J"
8cTLu
^E}tu
QfRM
vj$J/&C
6~&B
X[I Ch
=:R)
R79}
t5dbe
UwiD
nmuY.*+
;!h)
6=HsXw
%^A!Q
-dne7a
8 iYe
scqg
W3
~^e]
T#>n
:9/])
tk*
<`U5
Uo__?
#Gc2
!svMCdwta08cKl3Sumb7zSXVONFosxgC8w
Xgp"
WOTI
'NHY
KJ}(r0u
{6\0
*fb_+
%MJ^
qm3?
EO?]U
*bJzd@@
H4D
&-fm;
]7s}o
} H5
8H-H
h%vJ
u^2c
#D`^q
$v<
/8
l#
#:zv
8.qP
eJMb
}#"}t
M;=:
@| <L^Np<
:E *
|+P3
Ua/_W
"/S)
"Hc%
_^vLs
^?-j
21@?444
P]j.
`:0y
^ I<@v^
@nrxC
Zwo
v(1"3
Xa,=
eixG
tS%]
\VV\E
kYS
)pD=
yCTI
)e4 Z
h?CJ
hWuc
"E6 `
'*zjL&
e3/,
Ii3Kq
444'444,444#444
7kE8
n|k$?
w=vk?uIH
sLM=+
e`z1
uZ#U
/=Z.
wuw d
_b5V
&Jgb{
2fT()
C?gJ
^/:]P
n7'q
B$-x
-A*e
e#z^v$
e si
7WHJ
~:`]
<:{l
f]xG
x=_-wh
s7Az
(.}ZP
xKqn
-}p,yvQ
W<My5
XKKr%
Ym@|
%TYL
@l[Wn
;)Mb
)tV 3n
:(tJ
*f*]
l,X
Z_~"
lmGr
t}eJ[
R#k~
r0i\
oyf
W9jQ
lK4[
F~:+
V?{e
Q(OGOK>
l&dg
61C
Fa R
r2f&md
5<zK
e;;!
=!n
a]Rh
mJfhu
MvGa
z^|p#
ap A
H|Cw
d3*xS
Ftj
7 zy
Sk#
V.Ww
<diB
pt5{Z
M<n)BL
8Ye4
MgJ5g
~~e$
'NZX
gxQ\
6 &}
LwXC
JKZI/4H
_I3Ch
_UrW
H?k1
k+> o
[&!Do4$~
xQ*s
DqR^
* ER
<K=-
T5Y;
q2])
0XdN
yRFG:
zrl,
$Z :y|
444&444
lzU^
]-Uy
HtM3m
>DF$
Q&3u
]e4u
%>D{
?%YIw
O.q2
SB*4
{=hB
qYY7*
QuxP
{ZvX
$c @
3 ,|$8
V2;~
c E@,Q,
o 2
`w=^by
444O444*444
QC`h)
qif^+j
aP##
B4{
FGJ^Q
8 c
0U\r
xyIz
/;Ay
%C{8_
O~7x
_ICn
'052
N$n
v>,M
=rCB
Zzv@uOJ
444Q444
901\
(G:8KL
o !9
%whT
7wh-/D
Gdg}S
oggZ
V7 A
V_Z~)OG
}TPz
fA{
YUYH444
;xm"
_]d>
t5t`
s\,&
v=l9_u
Z&g
D.-s
>8FF
| =
]a*;3
kmN5|6
U9FT
Lp 4b
]#cI
8hKQ
0)Zb
#$b!
444Z444
3Q*)G
/g]
9}Z8
Iko2
_p<}
74@Q
9ZF2o
^\ B
/mm.
'j$|
'1$(
3(L8<
Pjs8ves
Lzc
H"p=
4446444
i\)7
8`k!
k^p)
(T ]9J8O
m ]
_<r
GX0/
okdt
h
/uGBTS
9QH@
FDhS
ZPd*
8G_
qR7
8j b
-%f@
fWhT
LPj}kb
rljB
fMwhp
A!f
Y+{g
z_wy
rlj\
7'Uj
-a`*
WaDe
Vd7]
/:Bm
_!$
/vHM
Q%yV
UWZ Q(
j|{[
H 3=$
P/Tq
(lkI
F,2h
1*/"
lLO7
|'[*G;f1
w;E!
444k444J444;444+444
wT2
Q;5i3
@?X`,8
rX:
rSN<
!.48&
.G'G
3cm
0 ;u
zWgj
ve?hI
jW{}Lo
%)th
uI~
l(w?
m.N
_]J=
444=444
T5yr
I*<
3>c=I
qKWv
n8q`_T
bkW
IH<>
i.Q%p
,Ebs
&{Bu
N\Qf
O%6AY}@Tb=
PbN2N
0YCg
G"HF
X&US
:AMS
7 4J$
YJ6Y
=(us
0/7M
`br'CFXxTS_
[Zj_\
3v2'
R "hR
im}?
I'Hvi(
{c7/
v2+Ge&O
.1f:g
_Q..
w;5Oyd;
O yX
yu zx
S1Bb<-
us {-Z
>(U
3mb-
-'y
!37
I;@?
z.u[W
CYSL
qtSD0T
, sP
1)fE:
q [o
.Obl
43ikVQcJpHaRtCgsiZNDfsf8S
oRk
hg`,#
1]L|i0
Y}3
"|ari;
H#S
a=}XF
9{p
TGbtX}
XFAPq
C^&e
DD13
qoly
CG|@_
@b"
`w@{
kV'5X
: pu
Z4J
u]W+
fBRm
)B73^
`P;5
I}4-d
5~42
&E6c
o4s{
oo_u"
#3f>
s1rY
444u444<444
BMQ]g
444urri
W<n\FX/
Y0vq`
RRZ<
aMgL
&-UK
{uDA
E<zp
aC4w
ku2%
BaFl
444I444
2;{F
9c!J?%
g3|v
P& b
>n;z
k!w+
i@G/
'{ V
444#IJXH<<G
oN?
#h1
$MO
lz 5
^1`oC
~Nc;2
:1Z7
vfg/
XA\9
]B=]P'B
12cI
cjc,O_
+-Py=
QyA!
)q+"
Uk`\-,%
rmI}RC
Ah3Q
sry(
P7~s
|nb{ Q
??xZm
t,_F
JZVF
9_._
Tt"&
bK7F
dB\efl
+.L_
C&J
/5y:B
AKDv=
s{R6"{
&!LZ-e,
%*H5
Xw7
@cIM
RP2|p>?
&^cbo
4V}
faca
;wxN
u<0{/
D &T
'j777>
81C!
]Nk$
|fzd
RM S7
Na@(
c#cny
Y[{1
^rpI
_Uj
_ewHc
444s444$444
["YW
"-V?
YF_3
INW>4
eH"ID
{e
88\C{
"q^y
/Z_.H
tZZo
A0hb
`^5q'
cOTA
+1m
5L
apS%
Exception
6.nt_`
JqSSR
MJ<F*
uuj)
"|;Q/bR
&zJZ
*7[;n
KMze
d,9
%0bf
Vk-d
T3'A;
8F\
<X&D
OneLIMG01yP9e0puT3wyTgL3
(+{
gt
TD;H:
|)t@
h*.t_
Sm7U
5#SkEIJ
$a7&
{8E+
g:wp
)+;y10A(444
Ic8
$ilS
Bu u
e+`"LP
\^kB444!444 444
m5IdI7\PW
U,2/
/.L
B,A7
CFx
^ %t
liC({
W:1#D
wP5H1
* !60
,<;]
!SM~_
"qi4
#wA{
444 7<W
_fbkt
8Z#(
ufWD
>-J]
Rw@WP"
Z]tC^O
c*c-A
z]Bktv
B;ne0
MOPSA
*c<\|A
4aT,B
x)tbY
8T=P
'nM@E|
t qI
(cw6W
:qY-
j^ f
vA\'N
Ihu^?3
_\Ol;
4/7o
o",
NS*u
'=]%NoN
<{{p
HbR
|cNY
oQAt]K/
o6oU9,
{V?W
J/mY"
}d5te
R\5}
x@^]6qU
<f[3J
@Q-TZQW>y.
#|s{
iiZ3%
H8X\
G: R2
J\O|S
n/_1
2'bq
XP?K
4J#})X
-9%u
Fe]'G
%'/S
7YsrE
9HT5%p{
U (c
ZXL/
WU v
an`EBp
%z7PAI
PKA]
@` v
5ra;
I7#b
v/sx^
FHU4s
hYt]
giR
ZFUx}G
q@?t
FwW-B1]s
=]|d
iyEg$
pttg<
'sPimS
[!/hS
!3 z
Z|e#
F u_<
Um =
cEmt
D7p
.q*^8
c'k4,_
0$C&w
PC$;e]
ly"
!'-?
zznn
smK
.(FD
?{*
!@bo
4uSY
/)M*B{v+~3
9: E18/[/t`X
ogln
{X,t[2
%]$"?
P_Ax?
=joj4
"MaV
F;%(
3X
~1jG Ce
b@Q-A
dl d
AT?!
444Y444
jz>OS-n
ccdvOH1
rdWN
)($#|*
$K~u
f"qQ
o8%0
<m7?
Ap(\*R
1#U}v
,_)$
+<h8
YHeb
1c zQ#
i&c'!JN
Kb3B
'0hX
cXmT
p$Zq0C8
;*mvz4M
Q1rpo
r\IW
_$PM
9%#j
Kz8AP
Jb_x
?2h(%5
'Q .
cFfeo
*[F
1G}
FRf1\
nou4851
vrn0
h$
x63'
[jR7
DvxHE
k<Sw
7|CK^
|LdI
i|(lz
AZZ*
;q1|x
eYbv
\q5'
txCU{
2,sd
r9qz
Sdh=
"aXx]
o"39
]T{\
2mQk
444 444 444 444
Gp]@
444b[Xn
#Ff.>%%*
yDmsDNkFrtJbAx6B0lUxip3Xn3
dMMT
wl8
H3//B
4a+l
#-uD
/gdvW&j
HXJ}}1Hj
tTIE
\v@E
""4:v"2 u|T
ENaW
#F!T?S
wEk_
-hnV
/71z63
st"
37KVV)N
~6;M5
1>E.<
P]W0~z
PJ| 3
( 8N
+ 5D
J6*#
nVL`o
;%D}
d(|yCcfK
_ci/>6
0Co&
1 jv
o aC
)(R`
"=''
a5#
g&&
Pg.}
|t]zx
444 444
ouah`
sWM
S,N"
TH!1
+<V
=M@
$g$4
tI5
7mnd^
}W\@I
IY@U4
v%W$w
I0.\a
ysGp
B,<{m
Xpn O
t(k
qC`S
zl:0a
:/S7
6soC
% OQ
\$&^
+d}&
Jj7VPE
q9h
9m!
56sn
IBvt
bTZw
Z:T>BQJ
}9w_M]E%b
K#Rk
-NXJY
lx\84
pvZ
{/q
[!~*
~dV&
L1bb
Q(4w
|) `
444 444444444 444
=A+i
'AN
xoe.
'i o*"
,rKz qE
$` tP
;ff%
;}74
')j#E
'Yn6
tnw)
z0T
Jt")
Ixx/
};A:c
9.Uz-I
SB a
JLv'
t]Q~8
W@r T
{69'
ldf5Xf
#.*U
Nr /
yr`+
N&:q
tV iE
V"cv
G+[H1
;\#<
X $y
TE@1yWVT
dkNj
gC)e
Rf;g
/8w+X J
w!;
nN
\ ^#C
_/vi
gG#E
ls{;%
AR/s$
Z#ze
|FK
6pN5
Px8y
cA4~
9s2u
]J 2
6NEnf
'5o,
rGkj
W LO
t"(^
CfJ#
TB FDI1jL
CC 1
VA4@h[
S-'-
efoY444!444{|
MmET
Lq>AW6
V=V"M
/Fc!x
Ecs*
? Af
s!\
$}nA
MJTi.}Q
KcvA
hF'
_fY~H
~x
:~X,
zqNF
0?j[
oyeH
</e4
JvQQ
SCbF7 Q
LN-
SE9qC5V
D^b
sY <&+
y@gH
4a[C
usfP@'
e?\W
8mPeFF`2kt
p@(B
>BjBF
!adSJ
R_<D
X'6"
DPc1c
\TM
t/(Re
k!Gj
v2nX
a_D}
e\jZ
}ND
P^ }
Q>$B#4
)[1S9x
.\:(3
.2-`A
xk<"
$];Y9
hzB5
CW
5]U~
.V[
^V4Uo
mih$
ZdQ^
g`)S
_OL:
C).I
krk4
V1 .
=5W6W
$hlz
Ti2]4
44SU
(&s;k%
5x,2Jp]
Wx&Q
1qf-%
0)K F
?ih`C&"
h ~-
(YQ!
J|K6
y2`gO
0Hz(
C)VZ
H9urNa
dtn6
4LlCS5c
Z/pV
~j 0
9Jw2Td
B3cw
a"[xX
444\444
d+SQ[e
d>"!
RXLF[o
!zM
}fw
P{GV
*e5K
r$T&
T6d;8U
S 1
jhI@N
$X*
<U Q
=L![
mHYd.
K@ w+
5c#Ca
$U*;
##D7
:_sf
a(bH
i@J{ 7
']W[
gfW]
Cd$x
iP)j
=ns~
iHY
f $h
AWn|5\
=zWK
iuy_
y59k
\7fg<
- #[
*:x]o
=ZEp(2
5tGNNN
t!7u
tb&f
p=xL
WY^l
$9->
UfP(e
^Efy
DfvD
tmtQ?m
7^| Gw
oeFk
NmFj
Sr2f
|cH=
l1a^
0|@9y
'L8rM
ct|Z~
f>"(
}$2fUj
)|+
.BeC
?*q7w
i:%@
N[s L
nE]Xd
y@/4
(:{
ODHc
PFF
*Uob*q
R B_
vdi
Mjl`
P J-'
T|a
/5#n
5+{}
D`;7
8=>.0l
(hVH
= /D
DateTime
K";nV
>@}#
P&%R
vH=)o06
)f F
HKfs
(%iU
x_<#
A903
Y }q!T
H)K~
|/y',
O1$,
]"RZ
Ek>X
4@D
(B mWo
}jqt
:&W8
Uid?
B@Y2
(?1=
XwS_
A5QWw
kBVQ8
{w:'
oXuQ
q@dM
y7&r
]tCJ
O490
R\|w fY
btsn
1#]L(e{
-mv6%
hNvi}
yfwX
?]Sp
nGxa2
F;pU
HcK)#
jS^C
(XsA
Th&?
JL\x,/C;444
@5L\$
444u444*444 444
E"z
usv&@
-C3IO
8N* QD
]{f{
GU81
t"9hp!
]W.Q
,M '
h?baG<!H
O$cO
Nf6Y
=d0s
]TyAF
boC~
DSE{
'E$%
444 444'ie\
x]j^
Xo(5)
UPo.
System.Security
TWRn
N.^_k
7/I0L
sb<yE
JQ m
" a6
Rff
t!Er
{5-8$
a]Y`}
uc2'P:
*z[rE
444K444
aMi_^Z
5a?wFf
`"P(
OY>+
.5S4
SItT
}Jp~9
UA,RXdl
%b3z
-lg
nTL,
726Z
65Prj
7:L&41>
2m</
$JT'
?CX1444
{k4y
& E!yu
FiW
=f5_8
MRpR
FyZI
f("
RKVA
Nu4.
x0G0y
A<+;
E}f
v%
%fx#~
jF 5Q
&zIH_
rpS
4442444
/AGGie
60w
mNP)
YD4,}
UV>$J
>L8d+
rA&9
,9pG
TDg1
3 k_
fx&p
\fV(`
@7 g
AddRange
6zK+
e?`s
u|tE
e?@
/2I
J3AH
Ow\K
xO&b
$[34Vg
a:*Y
444d444#444 444
j*Dif
zdx,s~
List`1
8ahZ
K7tj
PsOY
4`3!I
IAb@8E4
?<Jf
BUn@
8#}*(
$#1
:NHER5
&Zm&
T~AO
get_CurrentDomain
_l~` N
y0[
4}!&
W|6mM
BFkT
>3zN
BXQ5!}}*
&^)4p
L4cU
1 U*
In..
C[=^
444T444
S]F&3
Sp22!
}3^<[
Ng}o
8w=%
wn6B
jj.x
Ze=;
<='j
bs U
@Cas
3?:
zc:r
444[]nR
$(:~
Pd&P
z_{c
^2$
444 uw
spQ](m
#[!
1NfzP
B ri
LFsK
zo2
,F@.
;PIr>
qMo'
g e]
eckk
&VI
dk!Kv
"Jv1xni9WaRb20lJ8V9CGRjSg4RZMvZB74d
Lw;
FE>?
,`Jg
CK*#
Ht 4
bmehM}
T"(K
uF7*
CNM6
NjoW
L+6J
ps^/
'GsEX
\Hx*
RJMB
2<*($
tdw(
W06L
hh.P/
<Z?/D
5Uka
Jm x"l
hwAC%*
kUJY
(PZi
&bmW
.p<z
LLKw*o
cD;7_
v's
F_RVG
E@?qC0
mE;/
}0i;v
+RI5
L}!<
I0X''
:w(J
U H}k
?Xb
42"PW
c<!d
r%M
')Ur
Kb 0
>wsA
N6cwoXj1tWdxkcyJnYuEvrRN2
+MK4
444 <;F
-y]a|
zI6l
P+<
eKH"
7w9RZn3i0j2u6v4WRhpNuD.resources
p$yf
#HH
aE|K(_-
OwyAx
af4`
9R/![
QiG@
dr6DbE
ij6
{1n,R
m"38
I3tI
y'NQ
$3T2
Z R!
GDg
O<2.
9(LZB
xb[r
@]\^
XWJ~
MT }
[g:M
^m@<8
h"}5
Z_rq5 Wj
6'8&
r213E
w.9)q
^[L'
f0!#
rD`
G>
Sb#J
f# s
ou+6f
@WJ6
.Q)
}u>H
X!n=
@B-b
c@['
ZKyO
.A mu{C
dBM{=ku2
:Y,l
jc~
~~oRN
}YhW
+e(
z4}_
\fe<
RJt@N
_bO!-
PkKZ
x4HA
F& e
G$61C
?o!_
vN7"
}ueK
~/E
9j/(
$/zZfa
Hg}^j$
ySq;a
q# f
|*!c=T/
5b!1MF
cN?Lq
XX`r444'444 444
_:R6
mP,w
Y)SQe
DialogResult
z*1"
[z3A
]^No
cTj ]
>(#l
#boWv_
3Rhh
}J}
!;\E3
l& e
'zX?
a|R
`)l$
444H444)QUj
liQ3<
0=dwn
( "NB
iUy
444 NP_z
CEs0
/|be
g9v
[,2n N
/sIEy
;*grM
pE;w
Y@17
u=s3
+b_
oDpN
Y( !
-HN`
~l!=
L=Gs
%$=E
DZph'
];gw
#Ci!
qf+H
?zqna
@0wU
KqC5
FWRy
}_c8
*3&)
cnBK
&/zkp
WP^T
s;tF
*,]3
'3'
C#r\
2zTG
yYvkf
@}W!
OXHK
]SLK
e?Pt
ihJN
Y+Z}
444q4440444
oY%P
-1E?+*8
?3[}.
FQ
U&s7
'+LsH1
&aWBY]l
J!|5
Y+2 }}
kmWw
4443444
]zk<l
R4C
kd}t
Y4 [
1m!^
Z:cw
R$ v
l&zEK8'
7:L;--@
aOWeB6SxhrB3j3qKfR6YSVv8D
\\r-
A Vk
o0>D
wg(9C
\B:I
gNt
:<*l
p"#g<}t@J%Rm}
X3vi\
nE}
fRsO
A\IK
9'r+
! h<
u:RN
\fKl
p-|i]
<53V
t6o
A>Cd444"444
IiUK
J: 6
\qfHn
gM?:k
@G'F
k7hM
NT~Q
xlj*
iY=J
kvn##
l\&l
GBW)
@r!\uy
'pfX
5ZI>
!(>,:
"%-'
v H,
}3bA<g/
HG(T]
nj9s
5yMD
\<+
GDBV
(I)Acz
#U@K%a
{ueu
+\\j
dM j
j%MrJ14
<,GYK
Pb%)
-K9E=
6t J%
KDZ-bB
I!Ju
.-n
kf&b
KN$o
kSY+
Y]pi
.QI o
lXU
O@ha
1EVW
mI0z
ToC t
~" R)
X-3'
r&MTt
MC$g
hp,$
=)NN9
t<k[
cGg&&
An8z
pl"@
F>dl
J!pr
Q-;l
ZbjRU
hI#
"5\t<,g"
,.wF
pEs;
~3}@2Zx
LQ~x
&=)(
||d[x
`hh7
4SF#
{c\]
%qx
r~?;
XXbV444
VNFv`X
tqG7U'
b32>Z&O
5"g$
8X%~_
wLO"
Cs:E
^l?z"
Ci"l~
OSd+QF9
3zzt
=98?
Ze'a_%
UU.f
lQ}5N0
X-^C
Y|W$l=
dkdK
4tss
_Uh
%](jW
IgXc
Rc 6'
RqS/
. UW
t;W_
b&zD-N
L I>
Ni!h
NgS*
E( p
.0uR
wFQ'
ww D
|PE0
9,_5
"wJ
W9
M58
_lSi[
E[vW7
>Lgf
yS7h
6/#z
pMd.
3mD V _
+V)I
Nw 4s
#u/H
'j!\AS
4xw/~H
`"^K
tG)d
Xxy1
[c_"%
h#5
;yol
.r#t
w>e
Eau'_
K>ZD
hid8
<]z\A
uL\
7vs~
Invoke
Y7SV
=Z[w
j[
WrapNonExceptionThrows
*"R&
<6Y
@(dk
h> e
VVa9
`,->j
YI`
'MNs
4uW
f$KR
%ZZ3?
"{T]i
o1]k
TQFR
yaA>5
9hti
`=W_
ohP=a
%G`.F
m wm
Mx&&2
k,u%o
GF-o
i-kE
gAGk
%IUN
M_J!
^=Ss
IB2i
>:G0m
2|pgt6
]'=I
&n/?d
;(Y|
Wu@;
)&`Xc
|lMNqPj4]Y
dy3CC)/
_;uF
Tr1C+
[LA\
c6?C
Km!
vrp/
Hf*xx
&AK\
NG DwH#P
9IS-
z<6l
LWWV
zU}kR
WSImZ
%H)';\
)Y3-s
,jDN
Bd=O]
nP4i
2w)0I
<70'
w"?7
twd%
;B 73?d)
jG.E
JjMs
DZQg
>*Sq
YaS]
8"@>
$%s{-
<Ho0
[?q
y6cA
U/=!.Wi
]jaj
$N~b
qDc9
1CNqGF
v5Be
L3"*F
.HMR
ttj
uDD@
Q{)*
I2S3[
[dJ?:Q;
+tb6
CFIo
Y~"z
O0`%K
$Be/2
dea9
<\oO,
PQCsk
k*VZ
n#7C[.
444JBLatpc
HS7c
)qr
444v444=444
V4h(
A`7g
("\@[
O8pA+
\Id\
(~@r
FXs|7
t~pB
K1T<0
G?r!
C#_8*~
pd 1iD
K\~{<kx
rm~y
[^nOO
*FDR
#>x
tW:u
=\._P
1tp/
*=^40
ILX%P
F"EV
3%<l
?#vu
u5^c nW
Y70p
=nWr
iVafRu>
nlHc
&G/E0
_C,-
/|8U
b$%y
wz|)
Zyvj
s 7H
o&\J
:519
w4tS &w
2wj;
kD<L
b8Rt
n[e/
C*q1
=?F/
BWB;.
?p}>
AQdG
:GavSA
{( ?
LO`/444
N.iW
a,Y
t+eD
(Rbhg
V#X
R8>}
0FD
qvqj:U
-8'G
m~K67
4 E<
Nb9<
e:;*
s[u{
*s|*Y
H!H^N
]mMxQP
T '+
kvpZ\
BN47
K 1*"
&n b
i0G
{0 '
7=Ei/
oD>
Gaz3
rs{:444
!5d:
xU
oVxs
Meq.
54d xi
> QC
i@uJ.'
} m
U>;5
qiJ3
(jx0
FBJ$ytf
mlt~
444S444
L3T&
NlwF
{h)j
f%&dI
*eqI
dHNM
bwf
\_VU
1Ml^
S`[c
444F444
K1H _
\jm|
]^ #
"cH
e!nGW
81Ek
)$\g.
S% [
{ cm
];a!
fy_-K
vNhL
Z R.OE
~X{>
5)-9
>@=
444 444 444444
dc03s
L84
Tz,
i@M/
\@[%tk
rwH'
"I7oabjXYjMovgtYolCQ3X4YvMdSe3pSpDG
</N<C
&M9n
TfuR
AJ6o
b4S[
:$`O
<w$ID"
(Kk$
lm\F
evk{
jL_i1">
@&29
Evx
o+jE$
a$zA
km}c
2z]8
_4n7
>>gK
444"444<SU`
63.^
\}7 W
(Jd
][+'
'86K<&
j\Yd
>Es1
4443DEPwC>A
X?ln2g
#Cg'
;l</
>[f^+Q+
fwbl
0okt
aFKP
%,~6G
|~)c
fsx/
2Ntr@v
^^N
N6VU
AD~{g
n=euW
I.+MJc
y"-v
O5-s
JKB`
&/hn
1yJn
^D?2
'BcL
RV6,vn
Ogt?,U
\ 3i
| wB
V)-b
\w[ks#!B5)
`o-*
tI3O
TOnS
%3^B$
wa6R
7b#^E
,3iEZ
@%A0
vzE\
:at
Vn:
Hi9
GJ\|ADW'444
4Tu
)hk"
-ms0
!RRQ
PhY
kGkx
@71g
NnjT
)&e
H116
1'[4
5 7/
B.|9
`1k*V
QRpP;}
a(fo
'sgb
43&
~&Zc
@lq9[
.WG>
qVo/
6QMDIk
$b3yd*
zff/>T
uydM+
7#\7
B(]
|9~S
F8Fn
NcDP=
CLjN
>8A3
zjQg1
y\[qA
bo"_?Fu
qG"7
~]O@"
LE4qv
f%3YeZZ/|
b }
Z%\
iLI8
[Cv}
'u+m+U3
-p,"
{ID5
bY2)
ug%"
9| 'y
If7N
YAKw
>KwAO
O[g
[>_&
[Y6f
)%U5
pZkF
V01O5
uudj
3fh x
NVni
G&|Ht z
6c"ka
J=
txj'5
~ jY
xKp $
LdSK
Ma,zy
.cb
S^XNFa:
jQ#
>j>)d
^n\i<F
i`=C
6me
Af2
]p]G"
YiLd
$[D8
Pnp]
shyfH
cpd9
+aT(A"
w;P.
9RKh(
CFawQI
v ZT
!)=n
%O;4n
$S#Y
2@Ws
O,.cb
aT=a[*
+ LN
^K+
Xh_`l
444w444.444
=N"z:lg
1XzM
CNt>
j|8.
L+/`
{9?T
Cn`{o
@vit
Sn*.
Gli-
Q9xC
QG2Zjvmw5nGh5UvjyBKe
0PHH
444y4441444
kl)e]
W9s6h
)K+0
A508
<z$GN
)%A/X.
cy+D,
'/dXm
iSY<
c"3/
UWaY444,444
}7B`
oTiF
zn[s
r0T+)
Gd8
@rVel"
;er>V
68cs
}?u0
Oe!BJ
>.]{
RE<b
g7a8X
)
fP/a
4443444 444
Alk
oXY` o6
=c'S7
sAk'
tc!]
# -&
v]"
swlP7
1hVm
doj3
HR2;
Wnnr
Z%N)}3
L#0{p$\{
jzXR
7_Uvw
"i.
A{7K
C=5P
\Ki
e)D3
FD(
P>#{.F
]M&Jg
$)}#e
u+s
ui#G
h_C%
4Ynb
eFd_
x\Y t3
444UVbb
O#Mln[>3:
r:8`
I"l@
kY|L
D+He
\!Nl
ckHP5
04yZ
8NC0
| Zj+
#j7'9
<oh@
q#I~
l~m>
ICryptoTransform
4$R]
xGpJ
Z*~hsF
FCO5444
J%a6
s$nK
}VaG
Yk!.c
lQZ`
d%-)
GOB#A
>I|ms|=
RRu=r
wPjC
Yxgd
I91EX
0*ND
~V9QSA
E u@
x{Dt
?>YTVF
!QuB
0?]G
%= BZ1
46EN*-B
Pqa;S
*qN(
9hC`
=@g]\
EcETW
5SAf
>{?c1U
=gO%\
XN&J
fQJ>
m 8N|K
8.I
\Kqa2p
vGB
_ K^^
u|=Q
Ap2
~~5C
`Tr!
!'arV,
LGiv
|*/n
b]1
%](F
-M24
9:Kn90.
g8~s
kfkT
%zxY^
s&'J
9y$s
w|$
Y^t&
7F3|
ca~W
9D>U
q{ui
Se>_zel<Xl
7eu?lr
mH>.
cG(
#V_t
zFhy
"_Ll
zC)7m
;(T
8YVJ6
Y2Kt@@
wQ4EJ
b|!v
)%v|
LT7N
&4F8
S$0
(k4*
BKdF
YL>EE
Jjd?ou
. UK
^hQ@
8\$ep
n}~\7
Fed@Z
ewVi
p&wg
d>o>zC#
Pd${~
ON1(
'~M;
FDVv%F
awn[
7) b
\aso
S'Q]
[{L
-
g,@}%
EQ&
}tGQ
D SS
=)qA
l]w6
?:KY
7~`!@M
%l&
QPo[
B3z;
./]E.
2+cm
x=JC
V8nS%
K:2$
BYNk.
he}%
14
GsMQ#
HJui
KBvUjuRUD4NzolFIiD89mnNnX012pdH5
M$j P{
.=\
H[cR
q33LN
v>I/
1bgnlV
-#efM
]7Gp
^d::i
mlv%
y1TM
aTGk
<Rc;
xH*
E]lE
W! n_U
WOi
%xbao
444HB>
444k444'444
}>:G
S6|n1
7s%*/
*&/
ML 3=
0w=t
lx>D
Y)7yIy
7x0q
MMnT
:&'>
444]444
_x&r3U
yr0XMh
u^pL
0Vo$
eJQ!5s
G5"m
c7<<7Zb%
(vONB
~"4V
v|6uJj
3/dxQ
:0HYc
*u P
7<CWR`8
oZ7@p,]
b~Kd
Ow3N
`y+;i
k?T0
0m ~
Z]i1444
X]0h
3w;M\
444C444
7`
`L'd
brYvE
=|+V
@D|Z
~:x;oT
UXY
vP 0H
/P/4
oy{+
N`z
MessageBox
)j U
&!7.#
,N.Hf
GAW
?yX
M.(,
n/`'
n^eyBBO"
~O^O
F We
_\cv +
;MN*
+Pcv
Q\HN
tw,I$
q e
sLw
6DW?
~ A"
5>?i
,aI
Y`V'F
wsgi
k4rEx
pp#d
QEd|
444~444(444
`Ap
IP+m
k![!
,A5P
9t=
t$o-
_;#v<b
99*-;
)8up^2
n^X~
3|q;
V^3g
m{D
O.l$
o(-a`
u-~-
HKR'1Y
WTfl
dp|'xs
^Y"oO1!
o8n5)
\DfY
vW/t
Assembly
z:e &
ZB9Vn
."$9
yRI!FR
W< L
wMUp4E
;-b)
Q ,7
`nWx
O$O\
./1d
DvPB
!~O;!
]QL-!+W/
='#tf
444#ZUY
#!O`
C*|;,.
`~03
fRw
C1ek1r
!@-LV
01jG
7;/.M
.dl
z[w '
vRV0
Eju
#25@o
$iQV`I?
gnW.
ct;y
I ^+
nwcD
5 },T%;
<S!l2
e9dZ
GA 5K
i +f
uK.)$I
.K.S
4nqz
q3$[
O`sm
D _b
=O0P
t3/|
i-RT
7p^(F
q+}
W \vu/
JPfPi
ldwuF8gHF1mRUopOo1pn262iXXFkGTo
Dn!9
Yl}:
.Gi
>;aI
~[ U
8OXt
yba"2<
ffne444#444444
J1#/uZ
ciH
? C&
'Q<t
kWoG
P3L I
Brct
O[B5
.if
uTE}
`=0g
@.M
M%|
"#!o
B NhR%a
Dn!w
PRZW
8Z+[
444 []f
c___
5wjO
/oL
L{PW
V2W8
4ih*
/[(C
.kVq
%Wbd
oa|r
]bx$!#:
#s8h_
]>JQ
(j~`O{
kGL\
&Buz
TPeS
\t#*{
444j4448444
\X?N
*?)UX
`@K$
,zWY"M
(Ycb
'm Jw%
jPCv
+vm 89
p%*v
&2>%n
[ODW
p*WzN
IGF*%
F0vN
_s-n
IX6D
kOPHw
y~~@o
HHUi444!444
_83X
a0"r@w
1 fu
4Zbv
R<(w,p
7b wj
3fAc
]_iB
L)JT
Yb *v
1x,pG;i(
*ga@$
s:sV
5r d1#
s,4c
Pi1;
2_k8
D&[eY~
*O;R
[Q\S8.
Zk;
JnNi
) QXV!
JLN3z
Wsrr
hq||
du5 jQ>
)[#]
ezE9
aQ*Jj
vpEbZ'h
x3##
-#5+
fi$3
.SI(
>;.'K
Uv;-|J
VHp>
B- ?}+w>
R #I7o
M6_s
31{3IE
M+q
Ts2`
t wu
5I1_
{U8~
DW_&
s< 48
r8~Qo
WbH|
MX|c
}SHo^
Fb02
;(y,|
t/Vr
C]I3\T@
[#S'
S8D
Ymj5@
eCe+$
0$f<
;i--8
kNK1F
.-/FV%M_:
sy s
L3LI
n''a^
9A_>
"^L6
q069
QTgJ-1H
,=,J
$D`i
n\PKi`X
1_(
/~ xa
Jn6F
0e
3o/ {
VN* t&
<l#h(U4C
0mT2
UZ>#-B
/FV
^y3/d
;[Z,
X{>w
j=!u
{|~({
ajg|
H[V\H
':5^
t-G
!C4`
Ktoz!
uRv
GC>o
)2;x
1*hl
~;O@R
=6.IK
a{i@b
9};A
wEsR
23|s:[
s`bm
[F,
H .)J
pHbw
J7lx
<t[j0a&re
={xq8
+$_k
x!y"
be#x
*[~cv
)cHL7
#P8z
7wP>
_q7W
444K444+444
)R\Ey0
ve`J
CFE/
?koU
kwkX[
H<\%
444,444444
0gp&
C?I@
rf5
G##M
$,;cM
U{YRj
^_jG
S"|
^i`v2|N
ZcNW
444/444
u <
444p444J444+444
j^jD
y~dc
C;ah
)%t6
M)(;
_)}3
]@`=S
M)(A
Uj Em>
p^AYH
M4UF
n 5n/{
<a';
4445444
b.`?
F$w.
8&9y~
ql7G
32=
CrvN
wI,\
A@O
IV;v
7ynC
VptE
+H P Fx
l#KN
:ZLcOS%
'"E&N
u*iR
{#,?
444k444%
{^n=
'H`>
3 zX+
R!W2
444m444$444
s>z/
q 4[p
y8H_
tILQ
9us2
'C|$q
HImK
s"=v
$i_)
O|z>
.dH
[4?f`
JVls
FKkfX5
L]@u
PTWBCy
.(54c?
sIk,
,?ZcN
?'TO
LqK[
vkwo
F:9Sc
1/j
^KK3
<7:P@
&%{AU
dd7%
7,xq)
444=444rCBE
,_Y{
06*g
_&<zXF
EKXp
=)ws
z>F
%XZO
R@"'H
M @3'
V "H
4V:
&Lp
#}'O 4
@yV*^
a\q0
444 @DWR
]c)H
{S/5[
9`'C
5_~
XxY<*q
444 NSlS!'F
h?Po
7~T,
hNJ[
ck@z
,2t
7xiP
}Lu|
(dr@
V5
fhN|
jxM#
n\,u
.iAP@
okO
TN.
#n-h
my;-k#
.mU-
Cx(?
E}A;
_83rx
`bat
{T'
3b8G
Qn6=
d9CtyJ*i
1/PEc
~PG&B
"d*Q
444)444B444_444g444C444'444
Ms=
4445444 444
z:/M
JVU
Q#
=FT
yPIHfl
C{|]
5!A
N\g
QV(
Object
6A=|
3ihk
'<"&
%wKR^
<Y93
pG0
fw =1p
EaaP
9k r
>r|
|pFu
.k_I.
7V>n
.Y) N
W|N~
>oA.
OF)6'%|ol
'(K!
91 (M
I+f<3
EB`?
SyDa-
%t~]
I]a ;
N5S7,
?BV+s
p+ZO
bQRY
4440444
L81s
E5Ayd
i:el
k%e]K
eIU
6Bvc
3/tV
kLdo
|8}k
Ae
UroOh
444`444
444EOJA
0N9!m
@:KC
$}M47c
xg-D|
<o {
eU<~k
%9qpG
sN,
sG\+
0LFq
wSFoH
i70}
Ig>"w
W;4i
b] ~
/H9?}u
t|M>5N
444L444
TS=
Rae
V ]{
/ac$"u
(3&
WY O6V
4}oEJ
<=Rq
+ze
tf~j
~tNj
dUyJ
KBG`
Jz&b
6etn_
zgqcQk
eOJOv
VrOn+WF
XfG%
_v?7
g+PLuE
4s68
3|Rb
4`9q
mRrLc
<;FL444
q4`,Vo
i4d1
tXji
K3r=v
3>`{Y
dd,>
Ry,`
S (}
%}_P
`E/l
a}8wE
wN `?^
'D `O4
NnfG
444y444,444444
EI+.
:=PFH@7
S3D[m
o\Ei
\"q a=
0qG
XYq
v[!O
0N$)
m{_]
X6z:q
0Kze
>I5K
/Oi*
`>RL3
= (M:&V
_^kK
>x:Z
/MVT(K
g |)
_&)$v
cAdh
C<u@
|J 4'}
oCdm
dzA M
>Yb#
x^tAK
CBTS
A}L*
ps *
Q<R*
=n)6
j'e7d
444P444
-a)$}t^(
n#t<
YCua
># ~
:H_o
1jo5
~/uo%
i^[,
V 5!fgb
dvT}
Btr<
BvH@!
( 7G
bE/M#
iz8u
$]Nx
E6g6
yAH<~"
0^mOE
J.l%
/vYk
E% bq
#Iz0=L
dm%V
X;rm
[,cMr
NP`Z
2(^
UAiW
5@kn
D!/
L kix
DK+I
ezjZ5
444e444$444
TNwNdzE}l
'e"I
6 <z
<$W
MkHL
4KM17Jo
<9Qi
srK
p@ )
u%)b<
Q|'J
d8`f1
t3tL
2WFq
PDeH
53&?
u_+l
|j1h
_g:E
?RUP=
H*mm
!T{i
=N.2,"g
5b<vAq
+&!-
Y,|_
KXgc
z`_
:JfWU
a Bc
tF 9
Og /w5(
~,5s
.82{
hy]_PO
)P)F*
h00aW
!7%
A7c"
YznMq
rN5,
NFofR
a95Q
1?Mx
d=~J
2 8k
&R /
9+Y!
444 miW
=6En
"zV9
4445444
TGdb6GkZJKOhrLDfNag2AudziFAO
.q?7W
v g`
r Gh&
;n%x
>8@1;
'*I
$w4pOT
[)0Q
5:QuO~
QUhMm
#Pf@
?Gh0G
[#Q4
TcF2
A2?-
/Yt3
^z.]P
Pe*S
4&%$x
iyNwqF
]wAG\
E+1!\D
tkFT
&qEZ
|Qy{
RT5q^
GC<;
:hD@
P+'n
p~2&
{6{
D0d:
X"j7
\=n*
i}VZ
EfI1'
Xzg
]I:Gg
iYO!
PI}d
ej.
"{^M"
}.W>XR
Vl2\5
Tkv-
fe"C
444 OKM
gGc"
]sJ:xy
BJ*VL
+Zaj
9I]4
epK.V
iI5e
h~~Xf
bmvwB
'v([
Apk)e7
>#^91
j6Y
O6xu&@
jp+a
l#Ms3
CeeK
p7<
]`=b
D$PL
3pI
2,`]
`&$Q
L#bTo
:P;;P7&
4[m&
,,8@
z{ c
3!I
DCON
-B6 n
e.Kk>cJ
v*b8
_P.
Ci!Rc
Y-tq;
bi.g O
ICE8B=9
SPr@
s:1>F
2e#f"K
4442444a444}TTW
i~R5
)o,hj
PFG5W
L,+U
Y-SR
:>AWq
aWO8r
7 Vr
nd6P
kT4^q
p3pI
HMO]
?O0Dl
&>V(r
@m?"
/%02
q@?R
_.z:o
Jnmg
`ja/
[JfE
o?fyd
aT;E
zuVL
fIo@
m9bm
_bq **:
*v~P
[+ku
E9S}
TVbj444!444 444
: K
P:t
Q* Sd
|87J
444R444 444
xj^zX,h
ONn/
zH;;p
*o0p*
nw2 B
Pf!f
//,X
ez&\
Gr d;
b|2+
OE>
]s>Bi
':O@
< ``b
, Tp,^
~wXR
\R*} (
}7c^
0L#T
DKAL
{QyRB}
c+9L
H"J2
&He
6X'X
>5/
T`1&
:Ua"=
],Dc
se{.Y
$a od
O-eeA
6$Cl
:MZb$_
y2R#
444r444$444
5KH&
:Ikw4
a5C
@XHU:
444b
b(]*i
zwse
kHv
*G\o
H]_:
WD'L6
6Cvn
d09sFjnFrIDq5lH3SkuMYCB4nwQ4
]n p
;N*6E
N2ZP
GyJ(
|+gMD
bCEP
f5`
]JkA
x3lA
444T
BJ(|:
z?J[
a'AX
XWZ_2?
444$
[o2Z
~Ns8;
ERNC
V[>V
-]+f
C:!<
4441
*:|rJLM
<5EE
i^+]
&4?Y
*N6qG8Mb
6[g?
HB*zSVx
:t6=.V
BTm=
444
444
444
!DJ_
&csy_
U4lH:
tL$.
X+Y
JvK+
74tk
E U_>
O_*
|]p[
hvj
jj^b
r4kVH
EVB[
pxcs$
?812
p$)gb
lS!,T
H8CjX
~-ihY
m)Zh
8
I^o8 IF
T8ok
?MbYv`
K4K>
D>V
6M8/~
~O<A
<Soy
I!a'.
Q:sJ
Z#Y;Z$
_B~
~7b2
)J3{
-Z%_"
|[B)
um
nX=
QjO)
D"[2,80
4f]R
J--B
( ^]
lI9B
\[-Y
System.Resources
=}\n
qZ:B
q=XG0
QMLWs
p| <Q&
zuuG
klKL
mBoLFEAy
b% u
2/ca
O 5Q
en:*
4443444
;~N'
WH|j8
o0&:
n#7r
@Evy
G:W
CGKCgLW
Kb_la A
|SIP
T#Aq
/GGl
dT"a^
G[{P
t|-
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
MSU`#kBy
nt@UY
[)oy/
zOO
%M\^
m|Jp3
a7W
&2N@
GL*^
y"W1N>Zd
Smt)
<[!@
K@!I
QC^h
?;kz=
P]|8
gisL444
3' w<
h<z#('d
2=$cr
)Q9D
HR9d
h7)zJd
Z8D9
7_z$
rn(Ug
ACd6
&o~
6IKF@}
ResourceManager
x ri
|g+WO
nxuKR]o
-;N
6?>R
u;e.
gO\
Q (c
6LDo}
#XY
8;Ws
_&08
MW^'
63tS
?aD7
Q . #)
gY Y
=J1^
m?E:
T,NY~
wO0=
@V%tR
R#.
(6U
_'AT
\Cbt
Br0C0
C*P<(
pP<`,{z
R8HH
x8q
+7 e*a
bJVaJo2QiZSxP9CRZGdSQ4B
?<-9
>6R_
:]O=
T\ev
}V#{
m_:+2
,[vSp
Xf.l
: 4CK
'2WI
[Goa
7NiAiO
h_jI
-}Lp
@s]\
,rm2
D>wx
_}Pt
RnR+
Ih+p
O\4O/~
(9 H
Ia&;
)T9:gr
F"h\
w]vv
Lp=3
U4{?
8eW
tUPer
T9,Q
eA\,
S2M
/Z1zWrPH
I-4m
we0P
vTAh
E0~J
:N1[
`nY;wb
O, s5o
F&9s
/7=WU
!Zg@
"m$(
R):NR
C<aQ
Y3?h
H[M#
z]?
5l}D
L#5T
@wTe
{b`{
J ^ eV
bLxo
'f
IL]D444
6s>'
gjjg
p ?3
]R%{C
^[-
L^SDQ
N:$X&
Gi2KJr@
-$B4L
u.y@f
e@,`
gq?b(
E`|v
W.C
44488I
7C8<
}Kf{*.W
3/EZ`
y:3h?z
riwv
X}A#
I>jE*
`(hU>
78`#8N
'WnZ*k
IMyO
JE/B
.gtU;1
GB7E|
).$S
KW04D
PYi|w
!5?J
A 'a
!?
{<Py
\|VX
%MdZ
")hhj
6I1
|VQAI
%EKx"hz9
j{+PWI
9-9 C
}|Ur
MoFp
7PB$
f#~CJ>
/Ps#/'Z
7FH'
H ~]
CD%=6
WNSe=)
IvJJF
l/-v
SuS+
Pt;-
_<3;
? 8l
y6[o@
cj6c
Bdvo
444N444'acqE"(D
yNN#|
hql6fXnRc{
~H{R
}t>
8OO$p
q\i$>
'o,XMR
u&!(
/H8W
08S=
rxAKG
;aESgL
(3Y;8
k26Evkywm
-`A{
p!UgY
UL]\
b( :
444 ^bs,=?V
2ia|'
_g56
BI(:
-T3
Dh.Px;R
)<^b
,NfRY
[&-,
|}JF
>-`O;
I zj$
jY`RDx
@xRh-
y+15
Wu
0jb[X
pD+C
8;Ago
_C K<
?MIC
1R-
&^Gf/,
4447idY
MreD
8M m
#tCROR
%q7uB
uos!QO
o.bF
0ZaIL
]T](b
; zm
)aO:
|[3s
#t50
%j9H
t+g Ug
iwIk
:(.B
%D2&N
(R;:-
D\2z
uW*(
h3K]tO4
0X?p
c||O
z'rq
>i<D
Y(9f
OI.:_
3i/
2|U3
# ~U(H
444+444
l2wY
"y$t
"/gW
Jr@7
8Fs@
.QC/?
7 {N"
(xWNjR
K9d7
~\-fO
ZuZE
}ga6
_q3"
w18A
gMQ`v
h >4
Q|I*A
JEXnB
fw B
*V9Y_
Y~8Ks^
rnpw
Otrb8
1\UNP
ROpa
_UX2
UMIo)
2*a@
RpiI
L>OiD
MdDT}%\
48M&
zij{
N9}&]j
8(W+
#F HA
>VEM
mLDM \?
MvSdE
b6;Y
5"Me
{gFRN
j zVO}
MMxE
s'b%4
R6)|F
s$hRvPf
ezC h
@s0ufct
B'W> ,
X[Tw}
%w>
>ge%w
*'HlRa.N9ST
D[@
xF/v
<*3L
a x{
=9JmZ
H~UgLk
=b#T
~P3f
d[wE
8bzvM-
Kejn+i
94mL
:* lu
7'R<
z|)&/
uVt.8V
"1q#wG
C,VM
I.0L
U812
V %R3
"N C'*
P)`$x
q Dr
xbQ]
2D}kG
Y`pDx
-Pr[
{dG)VkD
Q/Yd
YmW#
J~/lj
Cn4
N9l5
=.Ps,
qB1og{
XMQs9
ns:_K|
CQcUc
j3:L
Tosg,s
S} a
NQoz
YTgv
T\_S
uR6 T
Pl6r
X+[|
v^pz
c%.)
Z5rr
Ee<5
yNOubBTEIGbaB7bTSd8clusjOg
(>O)
444g444#444
d8#{
:x-w
6MWAL
D6-L
D'DH
"qUT<2
JFRg$ 5
&"@]e
pZ~l
wd${
444 IDF
r28cd!
M}x(
oIms
`4g+%
NwZu
[<Vo
[Lln
kuP4k
\MK
mrNU
=VmwC
7@]Gb
\To'
fn+ t
<Olb&^
(\Y N
t7E#q
System.Reflection
_\1)
$n(.
/W(>_
^P k
crW^
a3Ta
/E
'qJHS
_=P@
>HL_
#].
0nSkOb
mhX!
d7n&
*?I<o
h(?
@DWC444
n:!?
ktD[1
Qg}l
'Ih[U
a"%O
+4`3
~EDQ
oP2{sh
>QfG
n{y
%,N
aqG1+
wQ-\
p5K'
i|},
RpQ\
6WTN
Px%G@"
%=5
vT-43:)
a6drw
sc.j4>Y21A
VQBV
rT}]
KE?
'H}0
M`nR
:A^2
31M
#\C`
/'J\t
# fo
aFC:
ROSW
GOEs
FDRt
>r$s
ja<
h\t`
;BEZ
'1/~`9
5DJG
.XE
lkb6eRz87kXLLvJdZMyaIEr59WCqR
0 hvF
c }(
Mq^!A
iFXL))
szC
rFLV
KF8
<a_
++
kkuk%"0
GB2
pW@U
74"F
_bm[444
#:jG
i?~2
1fW8&
t);-
y7A'/]UH
5!i`C
JjX
en8g
-.0lBUz
M'?-
;7_-
N@Yg
XC`g
F;4H
4445ied
`zVi
|'{"O
*^e,
D3f
gf~x+
DH+]
5r+-
t)lxXOS
?g@]O
AddMilliseconds
H/EW
glkP
rO>M
q54!
v2.0.50727
/~~M
GFq&
s"zq5
thjg
444 444444 444
9wd~sHmG
&2O
zCx|
>N6(
V0I^
}lNe:
]"1 $g
z B\
=D-L
Pl36=w
* nB
mc}eVa
Q!7Y
`0vr
hOUr
)G%
( 30
C>GevJ
-h$M
bA >h
EeJ`
e/Er
mR.B
mIo7.
k:'%u
OaW42sI
jbjjy
#JWp
2 G~-D%
0_BZ
Q}0^
[P~h`
88'o`
!T(=
Gr ^
b $0"Rk
~oA5
Nw}^
E\]N
*Gj
\uh
r!GI
K+$B
[.B@
p?z\
=>M.'(:
4)
q~a-gj
]&8KD
`0Z&H
d<|f
0x^\KM
2<hs_
SymmetricAlgorithm
444q444.444
e}&
TX~q
NAWR
<fcn
444!4446444I444H4448444#444
lx:T^/
t=I
W|T^
rQ8(
J~
\ndR
+*Z f
i$^~
.q"H
^6Gr
~ls--
4j8._
D :
>/Z}
&ljH
9-CJ3
Q6/P
qXt{
S~LhQ
D,
%)/XB
Oq9+
'G7
`Lu;
?]vDnbx
t[N{
W#wd
'Nr^0
3V p
I6eAE
`Ie(
HEP FFSH
QHFyk
v7b(
Q-@`
Yh-w
sI)L
Cba"
!.Y?
(BlJ
>hnE
A/B]
tZR
iCPb
DU c
ngIf
If5
\T&}4LEa
Q1dXd
=b>'
jXNU
XPM#
3*&X
JD c
I5^%
f_fW
UWK?F
p.GA
O~'m
TXX,
)]h<
xx[)
@gVT
6k<
iZ1I
`am,444
UWK?5
E-($
z&Q
_Zd5
Wi)
{S]_6I?
MEhDtM
M2)U
{zRI
<]^|
1q c
{^ga
=S#IYE
3A*|
Ls9 yV
[u\
zBF#
<J6:y
.2QH
U"q
jw7&5R
S>q
947K
\J E?N
U.F"
,U.h
(%oa}J
.w]U{
- O(
ToDv
Z{Y5v
BA{O
qmqKr
HP,
=?81
M -(
R-yc
A>G0
Gu6c
ty_O>
TransformFinalBlock
.S
%`LI
oT4
NQr{
'\s$
Vdq4
`VW]?
BM` Q
bw=[
9F}k
|fAf
bM6(
LNF9<
M(7A
#(R_'
v^_)Z1
UAr?
\~lGo|
~C1\
svxb
WlTS
2aH|N
l6i$
sp{Z
q{|,E
Mr H,Y
}!q8
+sWn
9'Vx
ZYv_|
p~6_
I Qx
BVfu
s?.5P
<F7]@
444t444!
8p=
4J*y
WCuw
]y(i
/|sh
TNIW
oU%U
!8mMFY
9D6,
[h-]v
>t7L
0kiEAS7nwmuhoPwGbSU7Fg
71LIvR
%IC3
l((q
q7SR
^Wt
QJr{
y4Dz
s:T
Z7_=
MKVi
i{F\
UMIZ
8MPQD
~L`Wn&
fwUF
G$*a
civk
"C6l
S7V~
Mx/3R ]Z`
Zu\]
Wu7^!6Z
V7^|
f%e $
iR#'
%Kd'y'
mh7^
Kf`n
ak0`V+
+6Tn
%q.d
S &jC
&op,L
9 CUY
System.Runtime.CompilerServices
QX!c
19fdI
~d:wI
E?i%
7M-0
~es
,>!9i
444(>ASh.,6
) MA
*o3u
IBCQD?7
jilO444
)@^M
444p444+444444
Ff]r
5ao~
%>|I
Mz6E
qZG6F
K&bF
]4je
YOg}m
WtL2
g!
>j90
]4_1L
Qb|&P
_Ikt
8-9/
h J?
0hF
x1H8
<MT\ x
yN`I
Z!0
zt7j
CQ6d
%:_Y'
Pc-6
DvG-
o ~> 7
[!kS:
w*Ns
.,%J5
!3{qm5Y
)S[2
}S+!7
HfEX
P5V-
) ZB
HsW
: (
09Jz
T (z
L!k}
h>.E
GFKo444$444
oQI,
ucw1
ijEY
^J)O
/&+x
LRjY
\f"!S,
um4cX3MT9e1WsXN6E1CY
3(QrG\
L;4s
Qh*;
SLSo
tG0ciw
L-W }
!9{N
=4Z*
<4j
Cs7GJP
~|K ]
CV[4
YUe]
~QZ$
`w#1
3;"%
| 4+b{
do@,
()\=
uc,N
,ULDm
:pt
N !5
R66
w8zk
kkkm
.kyf
JcqK
izS|?
/<hj
t]&
Ifu%
8'h'
W)?Z
JG"W
Wc{rL
'NO.
@!~
`[0<E
FSI
y,ZNC4
]'{U)
B<-1<
{0~wS-
z&4w>Oj
!{abgV
Z~j?
5~zY
R f
U2%[
HUs"
cb/u
!y5V
0z o]
6#]x
K)%/%
gq\^&
&QW!-X
_}WU;
!0UDt
c8cB
H/([
.{hKV{!
<l(Y
l6 /
juXo
3(?D
bYlr
n8\\
DGT?<;C
#,&4
rwmk
444s444)444 444
f.{F
|-UE
D)(G^?"8
L6sXW
hai8
emIu
Ea{
j1#K
v;pN.{
iQW_%
@b?"
FNB2
Z96J
i}\&e,
/X*tW
)PK,;)
XuDo
k,;+!
H*XU
|D*T
"6w.
H2E5
0JbF
}L/_
V^@r
s| ,
'RtH
d&y`o
& ]+2
KK\?
LsaXq^
.<;3
g;h
444x444^444<444
"Xq
AiN}
- n3
9B|?
CHHx
G{~+
HTA5
^7\
S@Rn
)ubZ
qP~@
|$ L7v]
ui!`3
72!y
iM\#eX
ADH 7L<
?P'r
*my(*
69P_
}]l=}
F> r
Hj;u
vB~d
". .
3I:{
4v|
/)"w7
1VCI
&5BKD
XXxrZF
%3zW?
/*`{g
"6v
`$?-
6DDx
7>"
ab%Z\m0,
WYL3
Hs%-
RLPx
{m;QY
2fSG
rrra444
u}zZ]l
"Sc&
+xW*
M 5
0p!<%
HT3!
444k444#
3p=4
Rd ik
9DFB
$3o"
[oDO
wrc.
f <=
F9!(k
_.kk
EGNx
1H[ >
P?9s
BwL]
IrFx-
bV` 48U
BFZr``[
0x+Vo
M9Hy
};bQgC
UGhT
f2pw
X0Hp
h.d[h
3[ !
<:I6
eyAtO*?E\
asy*
H[y2
NiNHt
1&c|a
l7Z0oLel8CNN9dzAfCBB5Zgp54SrDqm
ZJ.^J
ZYCx
m"jy
"#:*f
}:,/,
Vv"{
444 444444 444
U/BZ
Ii2!
>| B
mRCk&x
pK/.
EM\X
:L(=
ak2d
<h z
\y,/k
eT#"!
w"c
Z_lw
u}B.vf
*r>~
Z(F,
VI|h
xL]TmB3
uKe1
SL}8
lSJH]c#
w=5aXK
+1zI&
%_/q
[]RQ
)<S
444g444;444!444
Hwqa
C>y
^=:`8
qM|m
.J#0
?5vk
444E444
0.@
;8*5
9B4
Z+'_
MT%[
5 U
B ~
]2"5@
XNwBt
~Q8<w
978Z
})fLa'
Y'xsN+
$k$5t
GM(a
O>K\uB
Z^H*
4441444
=PAy*
s(0y
3H"j'1r8K)>K
!-/P
3ICxz
89ec;
hr;Nc
$$g]
/^e!
8-&6< %
S4r0
%=-8
ISB
9XcY
n!^G
()gO
F<4 2
<O<!
L0Z
e w
t]bo
2,QkN
N3u0P
=1~5`x.#
QBEK
tv<
+We
%8J|f
_3q$
<}xN
3x 6#O)
Y\iT444%
"lR8
U "]
{)h<q
*L5>a
NmNE?
L#lJ
2h~`
N\sV}[
9GXoX
Z]rK
,tGn
KC3>6ss
!E*=
#@":
WUEm
j5b:
?l_v6_
=+WV?^
$7
ccpK
}|(^
g|W3
zW{<-
0,7O
ku?{
zwhi
\^jCC</
hA m
))
!a*>
Th+Sr|K9+
{vpt
#*D@
FI[C444
Hm_!
aP?4&<
XfI
+E(irZ
0{Ip
6o&i
-V,6
+\ck
??; 5
(wGB
.%!z
Kw$C
`ANT>
q0U5
nR'p^7
x&U5
\F =
iep2*"
O5y5Y?
>+q
cI6J
bV36
Ff %
Dak5
V I+
YpAw
y 8h jW
b9ePJ
/I%W
J2vy
XDAG
~;[nn<AT
;}"a
~g`Z
} O6B
R<
&}JO
%8jv
|kRB
m?%f
1(Arqw
aJ\%A\
6`?8
BrD`$^
-9Mo
UXs
}mkQ%
0z+T2ot
qCE3c2vEleaNWUONnzeBf0Z8t7alnbyO
!#v~
`$`Y
plVr3}%-
:D]E+$
VA5#*W
i-s
#npRWlR
vJ L 10
b_$
444O444
LDWN
<l y
Cj5j$/
}F!zu
th~e9
%: P
~9S=
]X`Ex=J
\'+*1
!m1w[
3)o1
*OqNVG
Y&\UID
UsX.`
}n2|
fU;H6
)a [Sp
5_Z]
#LJd
x<IMQ
(*oh
UJ+p
{%S b
3~y3
+H
15ZJ
+.;Q
AdaT2c
BRh
CB*e
Q702
!(nm
^WT1
8%sJl
|(Tjk
7rQ_782
w xO
:UMh
:(Pm
/yo>-
,+2KG
@v1~P
MGcKg
"fR>oF
q-GZ
U|Pb
]^]$
0JGA
@<Aj
FDou+
>bUj
0|\
$x=yg
?BTD444
&vU>_
I5My7V
p:4V
lj:`B`
j7n
O~t)
444 QJSg
l+UZ
fJ~G";d
3Ux)+
g:bu
@Y*D.
yd?m
!f^V
!pnxKP
*C:@
O[\O
6IPR
Z|6C
=-RK1
_Q8=
_t}k
5 (
(/(r
RmFa
qF o
v_|&7c7?7
UH&H9
7!*6
5-x
)RPkIBqfw u7
0?zi
5i_}P
Q,9y
l'_5
444)444
mA1{
=,u
mC;9
U3,r
M|>f
~e6Y
rr9
](Ta
4Kr@5
OS)
DU_-$2
ick
~w".
\jY
eNOH#{
4Ig'
p.&<
`,:R0
Mp"_
1/7Py!
8*wwsc
# /3
Q &i
[3/
/O\6
p"#q
>%Y4+
/0 4
7>'.
uE*#
xA6#
'}l:&*
=*(Wj
444 444444444444 444
>B35~
@E8y
~Vc+
e.kg
<PCV
_iU^j
e^=+
*DgN
3x %
jig?Of
wZ&x
R%'#
1e[_
LdB3
@UY'p@~Q
3 fn
444t444$444
:onBt
2hey
:qZz
$\_#
@{ T
zGbb
N^g%a
_7ZuM
444t444l444k444c444A444"444 444
meTJ
|Z^`~f
%OPD&
444l444%444
99cZ
!a;!d
S<K#
m3F}2
7Pcr7_8
"@eDqX
tTeZ,aS
|m'6
:1Dx
Q$9
Yf.@
`acd
vMUwD
@f0t[#Xm
KKX5`\B
jUQC
OL^x%
N/jq
T_+ka
0?a?"
r% 8
okfNE=S
444O444+444
^IRy1
\jC
=ZMx
6fC
/PU%
#6B^_
lllm444'
b[mAX
)6*E0H2}
>}:Q
$S0W
7%($$
I){t
4RkY5
;:vA
-w/}
j0
'I,\
3\w
<+K x
at2s
^y2F
get_Now
J,>+
}Zo'
444W444!444
#R::v,
>efU
CO,_
iaHnW
et\
n|*5
VY-2U
oWW!
w|K<
5WE0
T=ft
'~?`
T!H
utc RE
4;`y
CWzo
u;?N
[O gP
T2mF(
HFp/
#Ua}Is
$LR]^
Fr#(
5 xbb
Am:d
@8B5
{xB
)N'*d
fFU7
zUVX
3s$`
rQU`NBr
I=9V
9 B\
}9Rk
J)7K
P,''
\f}8
O|]1
<"2N
M"%I!
jJSj
GFLM
p3 wt52
o74W
d.I#
k)z@Y
xT'o
4^{`
mkt$K?0
88ScAC
`U[R
ZX;_C
)dC@
kGdhYr
~qc9
CV:'[
)<^O
t"PT
~^q#
"Gb6
B<>:DA=
Mxz,=
O`.j
JWRh
)R.!@J3
CDNE
F( L
A_-Q
y\M
Tme=r
:]E[
V 1<c
Z 6~
<_#2
f Au
4444444
Zl~T
85tz$
~h:z
x_!
Nx(=
>=(W
:`T[
0F&
V1ZcuJptYJpHVqKBGmNtrM0
}[ m4
=d%f!
T-|\[(
u\8,
oSue
1)Arr
oFO
zfmv
0S=
vDh[
EV`Lp
j*(+
xylw
444G4441<A]
Rldu
<>hzV
H:k(u
bu+Z_
bTb>
nx[
:o:R_1
Y@GE
]xZRNR
1e9|
(zTJ
"`d\
%]Nr
f\i3c4
{79I_=?
/ `mB
/[ b
CU(y
H sKWZW4X
Lo
j?kWES
BY ^m
Il5g
10S~
dO }
(qn$xJ
l~)%
g\jV
z)sU
X32>1
@=Dv444&444
!quR:,
6Y7{
~8^#
zZaNhEg1
I,PN
IM.u
~ov
UXkk444#444444
x%[s
<;!W
sn9Q
;]#8
P>*N? [
{:z
lihFI
qsu],NMl
I{\sD
>%ah
Ee-tf
iX#jB
D=S]
CGD/
qR6*A
h|Q0
%wDId
y_T-
b|rX
S3k2
??21
6Q*s
-OI$v0
#6K7
z ueY
*P>-
*-/O
KrH-
Qc9rx0njH2c5l1ZaXXW9juHVYv4gu8
ijn.
I^:d
O"ry
mwk6
]60v
J;&O
ly9wA
AVWsq
Xy<^&
*!Xq
qzz&
O29|iv
h vZ
V[r 79M
j75%
eULO
O&Uv
?,E
@k[[
,6?N
v4v\v
QRmE~k
l$gB9
]8X-O
EKO
l-A*v
vc87
JupT
\Y}
4_%
D)2Y
\$kc`
omUeFdb>
X?fX
Ly#g>
4-*vK
1Go%
I/d{f
q\ps
s/F
\8lZ`w
VvC3
4/k5
OQ7'
Px?w#B
<WDn
ku9E
l 9M
{iA*XV
@\C5
fj?BTP
'CWLMer12BAJYsR9DM2FnTXqt0ULVnnAqVBkL4ws
5"(
x3yC
T 6k
djP1 J
wH#Og
g a.=bB
m[1zs
^\EK
Nj*6
9Fyo
_b6r
[\ b
!3M#`
AONPT
.!1*j
FZsw8
A;w:
$(9
.{hE%
f{lwI`
6:OqKNa::>P
h`L'
L9 _
- ^Ui
<`&r
hk|q
?H:;s.p
',Wlk
Oz
\[mH
D*u?y
m6*
RM|r
Gw}F
nI^R
nPlZ,
KOG0E
Aw!
y\>4
I'(^
c"ux,
*>ME
In^
E?8T
N='hE
R%6('
). kN|
xdL-d
0@VE
eFP1
pT/=6 8J
444mo{/$(>
0u
p})t
ZDW9
e>.
bWjM?In.
it#.
[)~_k6
1?6]p
Z\hV16P
XmLO
dOEX
*8E
1N='
)f
#.?T HO3
6.q^
?VGq
h$?b
mR$y
2z X4
Yah'W
'"o
s ~
t3WId
{bE
-PL5
I&|{6
j!1~
{kiq
XmZ>b
3{sm
8NeG
E8[9
lSrE=r
^ ZS
1;/O
]g`C
i#{SB
444/444444
Ss0P
F5U|p
:r%s
6eVwV
;;KW
RJ7R(C
PX^::jL
444~4440444 444
Bt;y
6}I7N_c
j7mf
WcZ?
9)l?
b:+q
&^\t
wN!.
ZVa4
E8[r
tX_i
6kS
DdJE
"OX5
dg>@
nJ:q
SjDI
N[`1m
Z^r`
CRcq
y ~*c
gyFG
4YDc4Yyz4rEyJmFda4PM4
cFaj
KTsI
GF9>SL
/k7u
s'S
bXzf@
,~db
Ydn
8q;+
:K\\
C7L2v
ckVp
pf*mpc
Ght
)jhh/K
xo[
/WXn
b=<N
<0-(
F"s>
OM[.
@ dE
) !=]
6b .
F9OM
R"":
>[97F
Z10
9S~,
(j1|
b!i~
A_ o
S??q
H#Ng
qT(E
_\;T
get_EntryPoint
oi^R5
~^n@
waY;A!^
E]P3
3zH
zpZC
/ni
KEai
gI-A
HoB<
oG{5(
NNxm
T0@>
b'}C#D
s\[$
=1M\[
( O0
g0Hg1
/`Zu
;/A
fyVI
t hP
[9``
M{T@h
sv,O3
[^Jkj
of0!
r9a)
y9Y ~)
%~oG
pwO_
l@H
D+]T+B
'.xt
t=`A
-~p68l
Y&0
5'W'
0!v3
r@<g
O3,
#]gi
Cmr>
,{P
9-P!
O_TZl,WHd
t/&6
499o
/(5
yCV<
,)HG
#EH[
444:444
D}H:
*=4G
r@^S0
xhx3
rR$.
}i%lJ
IK0y
>D/\94
s !2
GXs0
N&'O
/85}{
H$O'
_46w
b}nC
P ;y
; y
v ,O}
444 444 444 444
CF
+5o5n
Y&V
System.Collections.Generic
444g444
_^-S
/1zz
4442414{BBH
~;d'
r[}L
',CQ
9[p6M
LWJ*
xFcs
>V`e
X_B@
{1?1s
O^b-
o+^/
#.Q
b_/(
_^v
tA4WuvTwm9F7Q37rdGQvIX0JJgh
{euo
S9Hl(
.?AA!
j];E
WZ2r
g'n
[M=`
h"A(
mQNk
u>#){
- p^)`
Z)fi
xoFs
MaOD
'Ru$1
@jU!
U`UA
DW@S|[t
?\MXV
[Ve
:-Q`1
qG
LN%Se
%2LD
D- S
" )
@;Vp'
-&).
fmFEad
A, t
fj.
'2Xk]
%wu
\a<m
-"Me
B&J3
F Jz3
s$(T
Tx$s
}SwE
"o:u
l?9)C
J2*Y
OS0}h
~%bZ
!VL;'
T<l(
C/~
eeD]po
9,ufg
!7clbFdwhvvIiray0tmWy2OQhxHdx76apJ
|YA"#
Ypf=
:XNXd
6'& R
Hp-~
G 65
-N^w
t1E
gvd4
t9_X
<" y
";j
U,sI
aj*W|WG
*fkz
Xyla
H)yc
eIO(
6mXTz
GF!,
1n.)
wPyX
$88
='*J8
tYz.
PP<g
.vYt'
J]# "
i??Gn( x/
Eu%
2ijv
j,I
VI@|
tB0v_}N<
2@1
ksa
\(le!
"Dn8
:v b\
8 BA
7y*T
wWtLP
9jvBC
Xs&qi
O!{d]
\!]4
4444444444
cgU2S
*$$;ap
n~'H
-"FXS
Y]:-
fjzBz
6P
G#C.
^uJZ
.=TZ
Nm/:
=XX*
TYN5
~qbgl
TC'^
p\U*6
Rn?}
SEZo
rB|0O:V
"8,A
*H<7
5ni}W
+ Rc
S;o5!V
v0,"_z5
Il7G
JE ^)
HCRq
CX^
!U}qB
JX*j[ 02
oYxH,#
n'r|
A3[ J
F)2B
444+444444
jg O
@|6
]*8r
CNz)
{I#,-
*os
k|uF&Q
h8}/
d/"/
@ ot
QJ4V
:"d|
8,;
}KDW
5*Qo
ruIe+
F-Hd%q
*osI
SOP\
2ud
4442444444
jDD"
uz^
~Ks!7G
@ o1
F{zi
208)
444+444=4449444,444
{ fdE
kfH*(
0i>R?
PH.h
'=gEx
VUbdADSN444A4444444*444!444
W#H##
U1xx
NMDAgt_
)lG4B
y3<H
-/j`
t}Q
G0E"
#gWi
a#7=
8pn
@\M*
Y}(2
x}WU
V\"8gn
2@,>6
iFHe|
otKO
Yjx!
444->=Fk857
G`_s
$)> 54Gx
ViIf
Fxx-
:(%~d
0g"
i@@MQ"
+Y1d
%PHUtELATQKPQmJ9gNTVJKwHG6VUFxN9Ct3m2C
a!8s
]mLUS
w|&Mi
%G 2
eUm#=Z
N H$
5h#9_
6TD*
/i O`
444?444
92?;
g,-PE
P{4\
lT94
Z*g
mNF)
$c0z>
$_-'
p^Rl
5[%_(
`67&l
?]mj
;/;,
IKU'
3"jWU
E>x8!
OqDg
OlQu
`G0y
l^|
VX=G
*:g/>-;
}sH(
BJOB/
s+wK
rn1&
wk87a
`)YK
/vbj
}py}
6;iW
69;8
nR?
?z3r
6Rz<
VCV|
E(b<f
sbpM
yupj2
>78,p!
%!Ng
LLvmnb
yD8
4lwQ
V,8yj
tP`@D
kwfCBm
tzDN
Q{ti
4dB
a$wN
#M r
B7U8
CxlK
dKiwbHb7nrUXi1IzJ7ErS6TBeHIwGbs
]huoT
;5-
2;Y^
t~@q
WAm<Y
8 )JY
AN~~W
.~MZ
j_(7
sjxd
xI1&
0{VK=-
jF3M
efnW444
C!(AB
71[]"
{Jz_$
CB.O
i"aU
Qy31
B_b
zKW:D
wtm4xD
}PA
7rtV
UXk$7
U[#,-E
XC J
9iV8
c w>Y7
tXR
M`e64ma
MB v
~o~D4
_U%lr
,+x1
~)t+M
Kol]q9
?f)C
4WvR
p7]<3
U;JV
8'fg
c}2*
VE{H
Ix>cS"
&pJWW
{:b@
.Xep
Jpi~
b]<Md]
fv2} v
%-1W
ngr{
s8|x
mq.m
NSk6'.N
!.3S
.QF-
'/oO[6
x&!8
}D L
%;;='D{
=_wV
DEPr444'444
\xR
x* j
Ip60
FbYL
b]No
"lsY
*zLj
Mr[yg
{PP4
S6)+JSl
dXN4Yso
Z\3n
=DSr
Y-h
E<B2
zxX&
nu;9
)[t
4p(7
sYBy
]+q4
I1Kr/?
8^S|
K@Y|
fl>b
dz\GP
evne
*~Pg
_aNk#y^
9{UOSI
Nf-G
ZsKj
: 0]3e
:<@@
$^)P
IgU
1d'm
Y_M'
)ob-zU4=
pmAl
Q<C6
WXeY
~~g3
CD%
]_zk
=~LJ
,2Lm`
JpSw-^
Nxl_
qc sz64
+Oop7
m|H
DL0k
nWr
i(/
Ler-
n0=7E
8Qr"
M7H\i
ZP58
4440a^aTWX`
I3kn
oxCg
B/ir]
.9l; ^
]H3Tc
I]n:q
r<8W'tl.
Zl!Q
7o. 73
'7k|6
X09p
bBAo
444;79Fl9<K
CTjx
nG
$c`m
~H9F
ZN pa1ta
c<.
-NJn
sJnf
F;y*
[ t|
Jj`D
^ "qB
444*444
!oWg
-Nb/
2.v>
.:l:
xtd_
iP==
1wfO
G4%
qDSJ|`9
*Ny5
:Pux F
"csK
jjPh
{s9hP
n A1
)3>
W"?/
5F|X
tfW
(]D
Z)`E
i #s
!u3U
/nvP
,+$
Okw
5t!
9*o[nKg
sp;\
D#uh
&@aO&P
@E,
>OS`g#
GnLo
0?Nc
kvzh
(xyLUT
|+D<
-@:J$
]Tb|
H#qx
gK}V1
)! /
m'L0?
Lv)]
<kT>:|
qS8
NRiu:>R4444
`vR9
K#6Z
2H8CA
m`CE
6=`BG
P MH\C
XDjO
4;;:S
l*_!?%q
+}4m
'jBs
A\&^
kRQP
JI'
sKFg
4448444444
S4lDU
xUSU.
.Gwv
VWb=]l
Rms%|]
3)xy
< /$
GBiy?
]x3#w<
J|oM
-slC
`\*=
==J+444
444_]Y
NBsM
u?@'9
~L~$
MTC$ 8
~3gg
$~3Sf
Pmb
4gmP
8yj9
'by$}
wi\M
_ q#k
k7~B
Z "-
s}GQ
"^"yL7=}
rZ;A
i0B7
444k444%444
w yS
KQ|b
x!HX
A+Q>9I
y}qz
aI'"$3
Q68J
#ya C
444egu(b\O
0Y`E
YV-
mMY'
4\R5
yk}}c
JRQe
I7Iv
#f<t
1gja
i;Ur%J
444N444
/z $A
h69Fh
p@q+i
C }
@) P;O]]
TBeA
49Tu`ao;EJ_!444
W~BF
(gtz
i&~= *;S6
7rS#
@bq'
pw1
$y7xzOPcdhokpAEVZditpSyUBlfjUGoCTHi4i
0- Yf:(
gV-8
hf^z
40$Q
>*Xc
444444!SS_V79F
B>)B
Gp]Gp
>= y
(UI|
|s#?eC
76=762,}EC?
`cdT
:dlK
/;Y)
zfK`
;7+O
mrb#
F|H
@l
+anI
x%(
k"hrc
Bd|0
TalJ
TPOe
su^]~
^E2/`
O'R#[h
[^hN
88\F
VT$~
Ho{2
I+z(
D&W)d$
#s q%
{L)G
/jo?c
F!][yS
qo="\G
\zIa.!
C\+<We
=XG
FA1/
p)
;fx)j
Ez#y
c=5C5
l,&g
FrT"
U k$
mfX4dgHoZlT6sRvtdUumZP7hfx8Li
!@ d
444V444
WxhS
;Ih
M9o
yu9u
c6BC
*ugM
Es!g
)$~2
j!2E6h
uxj|
V4wU
u )u
RVh9444
sZFR
^y8 [9\
U@^m
" |[~w
s]f
hw2@
444J444
DX[ZD
zu}z
-s$>
3iyl
`aly444.
< <|
0b21
L>q#
.O<
w;w
/?}d
=Z{bxJ
S (<
>C`R:
!Qbu
X:sk!
Ect:
?VK*
NW;U
T-l`
(/[d
444&38QgAAT
@6 7
$]}0
#NkY
!?Xc
+p$h
m!_
8k?v
80tGJNYA7jZjW8XoPKvUJ17y9
g]J{vs|
444b444
+`Z2j
Nv<Y
u41<
%a((
hV{"
YR^L
}Ep
,Cag
=RO$
>y6{
Pi&E
OKI2
:$TM
wo5
*mrk
] JIWX
3W qO
3TcsR pa
4cl)
\E`X(E!^s]
#P]F
wioZV
I*SG5
b|,
>GxpX
^1o$!
n5^n`
9OoiW
x 15
#<.;(
0#wK;
;H15
DM:R;u
RITPH?-
;.m5
o;]q
hV~?W5
>Zko
z X
hE3D
];+D
}_+
e`d3[
UAFd
MB+m
itM0:|
|GO}#
HD;,
zXaBE
H~Oe9
%***Qx
5en!
zL X
zYFp
.1~_x
&<fL
n%l
u>C(cG
nwp
uYQ5
@H#
tQ-D
cN}'
0^{d|
}m
OB_u
444i444&444 444
ud,x$
(2m+_
BYFBel
h~-)
[mI"
dp#u
D}^v
0:@(
a&O\
L9 PI
w[>qh
-eZj
q24 v
Ku+`
Ny,AZ
1?wqT
Y"eu
dc}Z
+=bw
WY\
^o`
m$WyQv
&Nw9
r8(2[
tbgykUPN8WOzNtPDOrH4gWz9
XRXG
5|y;g
KO6
ju #$Q
3-AY
h77?0+
v%\G
cAu:
q.4S
p9Ea
_ X]K
KZ=C
{`d(
T` -FJ
&CSh
:my9
m>F,
p{Z}
L-7%c5
\{&1
;.=Q/+
WzU
;V)
A%N]W5a
6(+&
p2[M
Cer ez
s9g:
*&0/U
Hz&B
F?k
bAWo
*W%N
#hIK
7 rrwG Q
q1E:
=!,~8
^%hb
yqB9v?
FnT8
[b7S
`P|;X
-)0SQ
a'"g
T-OZ
MeP4
?*a21
M-{?G
WIqH
z(YM7
^MbR})
@ Kb
444 PJP
\S1!
D= j
hN{'M
PUi8444
444 444 >?LV=>L
Tb#[o/
/%L
_O #
1 T6
X 96^
F??
NNrRd[*
hlW$
DD`m/
P~-\
U<?
<<f
ZRQf
HBM#
cnZ
g?@,
;"x.
Hw1
w fY
|B_u>
mu4
W-F*q
y#{f
Bvr%
w%RTk
@<$x
qw9u
)_^
yR!1[
4447SRU
z:\Hd
H~jW
444A444
444g444$444 444
c-=6
*^oM
; R^T
VX n2*o
%pCq
@<$F
444 444
1WS']
@p@]z
H1|h
k[d[W r<
&^kE
T,%}
EKF@X
NaX'
e}R*z2
[nSC
)3D:@
sl{z
RVpH8
c'/]
TAe h
flrj*I
2 A?[
'g*cfQ
o:kR2
X;MY
s_Op
g.Yz
|.o<>
|`#3g
0e'BR
e`bAk
9|;S
wDm5v
%'v
7K'h9
-}yR
[+Gcs@
5t^ x
6![K
G<K
^B3u
Z6Jtq
MX4I
x/Ib&
z&X-K
{dEl
:hM[
WmMT
G'.8
)cbI6
UsM(
3;Xg
D'm[
*%GZ
G0~(
U)4G
SlkJ<
ipk>
OZZ
V!E1
Hkh !
8i,b
eub,
tV `|
UTo{x
Z :-
G=h!\]
qczL
fhrs[Y\(&%(
kWQI
u$P
XRMAf
pGkr
aY}KM*
MCI
_kk#ehax5/
f5|G6
g<0j
f1 U
$/ K
2 O
{OXF
tTT=
eKlZ
xB0uy
!F^4
fJ0N+
get_Message
V\R1
OZr.
C[28
t7HeW
E;=T
Q7G6
GF%*
unpH]
N%fp
l!*
/Jg
apNV
B /jF
SGdV
i`OwO_lh
bV[xJ;8
9_B=(
IdGgC
Q-^7 l
[fiT]A
Z@>]
(Ff6
(lUR
O>C%J
.P7@
T'hE<
P/bM
{VxU
dxD@K(
e|pe
66Bu444#444
pEBBe
y;CY
WSY?YVO
VRJl
Xc3U
?w~n
q/W!
^MQh
wRsW
O!(s
rnq
gw$:
aQl3
=3q(
VTYx444(444 444
F;}(`<[
H-Y6
Zf@*.
FS#bG
X2B'
5Z e
n5+)
64 m
75/{zo
_)c
* NG
:xTp
6MP
y}w`
ikz PMX
H JA
YZb2444
5%oD
4}A
1ugs
B8JF
?{B{
ie[;kvj
TUe]
C+3.
Nbc,
BSJB
DfIgK:
Nc1$
tY.e
l:\
VwXUY
oVxK
LEK+KDA
Dmy>
4%_-
eMWn
8D'7
> `N
?uH
~>FY
/$F0k
#jZ{
x=Uq
h|4
'ZrA!
R.$T
{6$N8^
SU`ePR_bHJT
;MX-OX^b
Mn*IsT
.nN@
iy#O
,CFX
~deI
$Wa#0u
z5M~d
VYiv444#444 444
|\0'M
,^tm y
\Q$l
<=JJ#"1
<m]7a
y;t
Lx3t
^\ [
sCom
i l-<Lp|
CFFb
d8 5/
&5h!\
[^jN
~js/
|g%5"
nYlrM
/RG-k;.
zt0v
'UAR
J0lB
\k&b
D]t+XX
- Q|
PUSN
Qax3!
GwY V
/S%}
YbG7
= gZ
(*;959P
c)>2
ck?"
2!h-
%I%!
:%|B
;ewv
Vz6J
ypCd
2fx'
H~pXB
1n;lB
xCG_2
F'<#y
R]:S
mPtO
ATMu
Mviy
8HltY
ke1
NOV^
!iw,
qu,+
?"u
ke'
`(No~
%SQ
_PF%
at~Pe
&k04
JEv|
'<7N
j} .
,e l
%&Bwf
0qL
m1\\
lJ9:
.IOz
6e\0i
knL)
5Air
=R"S
-bZS
UG.%
ug]n
{hBRe
A =4P
@Li`
M2X
}sDZ
T|H
%D8h1L6p
A7!
=(jD,P.@Fm
bv<3
B(}5
444]
@1TI
kmjW
`f'G
444{444-444444
F] 3k&R
H(4N
Q!KZ
+g[P
ga1i_
{_f(
aLb3
dI)'k%
y6`\
9YUr
;UT/
n(Zu
$HtF
-)PA
wslc
]UK2
G{<t
MAtU
Qf"~k#
L]Pc
e(yZ
Qg<k
RD29vqx2NtjiEY5kF8VxLhrT6FETg8
Rdtr
79DR
F$dX3*x]
o9R2
Z5HE
u{y*uK
0(f\
7XY:
GK]=A
312'
>$*SEm"
B5/f
sf Q
xFIw;
.UZ9yqP
1|A
ia Zsin
'q?V
[&RC
Z:?~
.zw?
_+*
!?_V
oZUm
bO)&.
"5eL
GH+-
:>Q8%&6
za^=
&8+v
#KNS
444-444
qpX3Q
=iV#%
S0G'
i=_\
):qn
L]*,F0
Xy1)+
3kd7p{
^D9"rVjCn
1EOd
h7?z
=_kt
h8 !g
,5)e
-,0C
cR6
\v`H
V\^
PZg)
Qh("=
qpZ,my
AgML
WT,w
mMFQ!
-W;T
R1_7L
ikxk$)C
oJ 3
k%]N%
m;Ya2 [
6AxJ0h
!dPJ
|qcM\
}~v<7
)SUD
rz!c
8R4A
2AP
H)@m
tMDB
X]~#
mh rj
'52O
|* X
* y
k^ky=
EH,=
@AI>USS
6na8U
F7<q@<)a
@{Ch
~f8`rd Wo~
%},q|y
agvm1
$l _
NS)8~
NuX
AqrZ"
)9'!
#\w6
'73
4Mcy
rc#d
^s$N
=:S1
-X/%Z
@8M0
vg }O
aI3>
yB~
24=t
p>8%I-
wA/h
q2a2
G]^>
F1F
EFS/
kV9B
+KH
f~*QJ
'yGl
X2yE
1qD!
1sVb
yA<D
W%`xg
si7
gF<?
h-A~U[
*h)5w{>
W[3Z|
TZil2F
<Mj1$M
A8@7H
tw@%
;>ucn
7%I0
xuL%
<,Vi)$
Yq-8
'6%Sz
r]?JMoT
"T(
WDo7I
ocwp
iFK4
Inw}
4y6.`
@VXX3[rx
f@s:
k f?
CLHV
ed:L
>%zj
*0JE=*L^
F/-U
xmMr
buBOY
h$ZKA
K Cp5qe(
8[d=0
vA5|
J[v@
"@ln
|XZo
EGu]
pB*?
J%Yb!q
"iCE
3 xY%
0hL.4
RP~l
%$qY\
,L:R
rQG"c
!T1l+
:lw6
JfX`
BM'5
7pGOhu:8
Dd-]
Gl8r
SBar'KP
eTwgi~!C
VNrc!r
aV;
[A#
8dfu
v'RiI5
lJqV
E4 {"
8+lT<7p
TW"g
]~i]I
bbk%k&[<J
{ANL
}% n^bT
4447HJR
.R?}R
((jk
usAh
6]N8
||^.V
hpmr
9fcA%
;xnv
p12&KX%a v
>L1
KnaZ
q&%Q
))UP
C++wK
mS #'*
H L
.tgdZ
x91
.A23
J;1>5RC
=yz8dc
ih}{
wl8SP{^
adS
doSn
"q3A
HN`
B_Ytp
@46L
` &h-<T
}+RQt
( 'Q
l-[\Y
vC7
{ib[
'y$B
Ap;Cak
}8'V_
L'<!
Wo]=
5s{A`
Zv!
E&F
6</
,Tu$
?t`i
xnz!
Yyi_zSGV
>[z0
ee@5
#WW n1
eA11|'1a
FXX i!
) x<
LqSu
yG#|
Bt~wn
H O(Y
";B+
X|^NvVu
we>(
Qklr
Yh9j
@1?_
4P -
rI>g
ZBpI
p_I
mtG[* k
C =%
{ZHj
sd!>
Rp6<
d`8j
"!9|
T%eq
FFDj
wC>)
E-35
{-l!
M*B;
acs.KI`b
i"U5
7qH.F
RcMy2l
>EB!
tVJl,
a+=q
}M1fo
*=i9
yt$1
8A):@
Bk^,
,~$|
6E_
fcm.
g$<a
C{{w
PUN!u
% |
(#ju\O
n8|R:
fMCB
}"MPj
yJs
s&D53?4
`UC(s
i=KAZ((
K+'+
I]f.
*F8~
!2>n
oRoB
}d Q^'
`D,P
JBE+
PPJ$
Load
Bs d
fX4N
A[ -
+B>-{
fv;F
R Ng
V>L`t
:8X
U`v+
YO5pk
;T_*o8}gS
9G(v
COp
+[E2E
>j6wP
(*v;
<Y9qS/
O:#u
$BZp
.JnUlC
9 {Zh
444444#77=S)(,
i`iy
8OrF
8rJk+
h',J
444]444@444'444
.?QDj
Z3(p
cN`|L%
YXT;_
%6Ff)
nw4<
,h-`
KdOz
36GAHD?
U=EI
444'HGNT54;
s/~g
1S^R
)lM|x
.DsY
VERh
;2^>=/MT
[~0h
Hp[s
@CC?
hjL[z
.+jd
=9:[^e
|!"v
J~AO'
n+YC
UF-
N \:c
</ ?
OO5)
1"XL}
] )
Z:'
aewa
cp@(
>H]k
ys*xek
==H~"%8lDJkOFFS&.4M
+o7f
pe`cA
7-sf
dGGq
3nn9
}xw
"/.p
K; C/'
]G,J
EnZ@
J n
( UB9f
f3@."w
;p)
srfx
R}?$
444@BDQ
ch*<
=;so}
bTRN
,l*W.
"%;p
}0#?$Q
to11
}xwZ
fn5u
/<8&
#\Rw
%\}}
(;rV'
~739
$SGq
70X-
homF
8(KE
xc;o
mj]m
"AoW&
tttb444 444
7(=X
pQ5e?
x&#o
x=P3;V
-Hs)
"7A*
V>hi
ynNm
-xY
Ej~u
9VDY
p-:4
K[D
}+WE
T7Ff
!hc
! {'
"JsN
4:U+
*'Zh
o%XD
~+VO
+"wx
_Z)Z
L"vD
d&:E
>'w
jHfepFO229r1rQKgAOA8ady97CmhA
#d~\I
r@$b
kW S
z<RU
4vAL
AiIi!
D@$E
g|Y@
ADQf444#444 444
/aS
ct4f
@@Q
b![w
ljpSPE
%E_h
,]el
qpWs}
7u,F
TWqzS
]c@l
444W444
p7t+
v5X~
!QK `
Ip"~
'|o,
{h#oE<K
(Uh5
"5gc
.=
X_T"
O!nY
/L~w
E}M5h
\"62
v5Jj[
.8G;
5B/#
~o$^/~=
%TXj
9b7Y
8'|l
!dR
Bsq
,pJf
dUl3
OcW
H{ir:
s~
'Ap/
#5="Lg
444t444(444 444
1r|`
." j!
LWOGDtzQWfq3fk2Y2HCl
*) +DB
H&j
:HP`
=xtL
jKg)
>+Mu
U=fi
;NRk8
P sAN
Fu*2XA
:#O.
9N["*
hKcZ
S#Wx|
f2^$
NI0.B
8e"~<
444s444"444
ej&
Zb>W
mCJN`
vc'
JX_y!
Rdyf<Q
JtQO
A\7
1p48$
lzvj
qqxD5&
444sqwE
NW[{ij
bS+
ht-q
KL;Wz
yw2rx4iF2EkxIyWIDPyRMokC70j
XrYSi&=
4t;Xr"Q.=
{{lA
zF=
:gM$
-uzYoJ'
"A!#1
N[&
1o1U
cm3
i-E&
o(zRHJN
L \
Ys1J
(%Ti12l
R+j=
_^^N
eeyCu
buhy
VbP
-iwj0
!D,,
kB%d
r7k.V?
y6rY@
FYiku
/b9
TQsw
ahcq
89Lm34D
lQ)q
"|}
Fse)
j5f{
!v@~s
n|Eq
$[
xvxf
@ng#
:<Q"B@Sq*,?
[c6t
8*xrN
-fUs
fblH
qEc_:
PJW K
KiV
c-98
#.y
]/8]
7'<gt
2mOqT
t[ $E
444<444g444
~@3+
:oM5
||5>
)QMYO
bH[I
K; M
q Xs%f[Z
hF^"S)
=4Q:
`$31
S6T>q
M] 9-
[)%m
qC7A
%0(
h|FN
aG?h
fB 8q
jQ8J#
?9kj
27(:
"Xm$
K2W+@
D$^EG
Vy2%
444D444
/~l7
'8i@
i[,hN
mf6K
`)OJ
^Wx*|dD$
Q]xk
^Cnm}
y]2
y<(@-
]AVG
Tp<M
fJhae
E-D_B9
xHn$
lU=>
85+>
/n9'
74,
mGU9A
[%c`
QD,G
mWyA
SY|`
?,0(
x`vU0
444+444?444T444h444p444s444w444x444|FHT
vaMk]
fUY.
,<#-
~eOF
e1,fB}w
z)Ap)1 \
|J}*
KHXX(
8+PN
Z/)X
;q"`T
Ww5U]
CIw(
444<4444PPYmnld
Aj*slj
FSfe
kl/,W9?
CliX
'5Qe
+M? ]w
_.0i
YW(,
,*2E]
gLo["TU
o-`e
kl;W
#Qs}
c)P]
J'v8
I@Z
q3c=
I,qJ
_YW!
!Z9L
inFF
F#|q
QRS?
>3 dubRN
t.{.|
q<bX~
=Zv]
2 K7Q
cHN
jFt
'm!M?
#":
^M]_
bfF8o
=4wP
6+t_
!&u=
ciYoq
5YN%:g
mx
7W $
444;444
VwC0
xz~l
&DW9
S~Y=h
z oe
(JftC
u];8C
Kx)H`
;p91
DU^M[
6vz/
nU)*
x/xC
*e\X3
rR
*@Y%
d*l9^
Bu5
^|yCq
C`#Z
> ^u Y
Y8$)
DP9G-\
pCAr
M~nH
~7:u
qG.+9
8Yi*#
Ww!
X}@7
ECsvs
"skR>
GetTypeFromHandle
^uBQ
Jn h
VqD
;3)W)N
)R*I
Q%~1
8u4nT
<1:Ra
=*jt
'5
4biq
,*.7"]
av9dsZr
&O#PB
6|CY
i"5Cw
7g>7
>NUPG
9<~P
444c444!444
HqwG
9P])
e@Q}
Bl#|
]#:t
M]0,
Nh^?
BwSxY
# +2%
Ht[d
E"E=
h4K
=z}e2
NU!
GHR@EC?
H5ei
2?^'
z I/x
~+jqy
}X+#
e7jA&
8oY7
71YO
!nZZ
2 }T
;N~D#'
4443444444
MOuS
444444444444 444
\!
YlP%(
-VON
IGQS444
"RW]
> |h
*)GyC
"lx\
/Q!.(
:0^w
^7F3UJ
Us._
(\iM
HFP:444
)[7
9)Q
dZC
M18G
efE}
-\I;y?
lCZ 8
N9qB
&4*uY
kaD
7g{
Xnf_
4qx<k
="?+
[4]#
Ap &u
/zMwq
c9`"
'E4Q
p1\G
oyJ h
:M`y!
QN@b
Xxx9
% RR
f#E,c
M( A
Vr"_
)j|lu6
tAm$8
e6g?,
:rgF
0WW'
[1(|
(hw>G
[`2!
%< .o
^$E
CY _
MZ *D
Eg7F6
*0'.`
T~ <Y
;;\|
ub,>H
AZZ
4bi<
g?N q
K9t4
IZ,O
`En+
"YMn=
GaqYG
J&;/
SfNK
|A /
f*Ey
ND^d
,$uf
"IunMgNxT1TjwlUouhg2zA5qXvJXQifgEz6
444Y4440444
j_C*
IzriTTDDj6m8kDraAKnV
$nfT4J6o3v8vwX3XpDb8tuwJNeLDoiurzeMRw
ZCt!
7A0]4
E"%e
.BG4
mnYL
}&0"t
-2q
d93R
zuHz
W)BW<
]N# -
IqnM
^<%z
System.Windows.Forms
SN[<
i-E[+
c uW
)7%a.
gt9;w
dW\R
K3b[
#j4j95mL1FI3Qmf6gzEi2Jiy7EiiTSi2CG5I
Y[;A
P+z`
'JM\
P"R
"8A1
9H 6b
3t@9
fL(uR{
6M`l
dQn?
O;C1
N:F 8
z?
rG<wu
MS*O(t
0&D7
V`&/
l ~E
|Q0YB
m7Nu)x
@Mq\
USuK
A~9j
S7 Je
? ;:}N
21t'
444Z444!nnx]
}7 G
2g@`j
{;Xq
GeA\
>?dk
er^S
CuTU
{d\
*3t
e"[8|y
6?93
\]UT
gd28
da2;
444_444
rNzQV
}}TOE
iKVsd[
VX A
+F&x
`b/+
y=:J6
AY[^0
|h.S*
5|d:t6
~oF2
f}KE
#do<
0Cnoaz
4;q*
#N4d
B|Z<
'hI;
'q;G
C8*76
O|;v
?_g7
w|m/#
SnOi
Z8c%w?
`<BiP
'%6m
'c b
nk]k
<-D*
08
0x1W
JD|~
UCMIi
rKA
@?S)`
3 o
[R!2
+ar=k
~rdc
2l-{H
;_04
S=G:
ZZEG
D3oC
Mh@?R[
sMqN
$Z :
E@C~444(444 444
V-rD
KW!F
k;k}
Zw|
C29Ki
fgjq
sb<2v
-A)'
-dWH@
l6C-
2S3i
@#4
RV-s%
:]c
OoIg
e9Al
NE#-
CBM$
mhU?us
0C,*
d.8W
<#(bM$j
+4EfP
444X4440444
7@{6(
l"2x
#nF7HVw0Qiy0jH35mzB6wqGgCMV0faYHVYe2
(Q t2
A#5l?
@.71
{%]K
D};4
^E>X
YoJ71*
s'YZK
"R?
t%oR
&jooWS
pl'b
+ X$
M<h
aD&^
I3!es
'EN{
s
(-?/
2!JI<Z
(qAw_
RLA=
['050
8)+
Y'!^Giy
444 444444444 444
J f=2
k [*
Vg(V
wwNm!G
}I+"Y4
uku1,]
]M5d
/hOk_.
5mUInX
CrI:
>dc^OoM
:}#-
H!&6
&Jn6
3MA[
7U/$vM
0=Z
yYogpjVhcaoT1rM7qtsh2IKns
;3M
3.\<
WL @
e-?k
\DO&>
.$*f1.
IEnumerable`1
HG@[
B>.N<
3e=fb
444c444&444 444
M[[_
"@Pz
Pn s
5I.\
$4"d
bmH;
?7 4nWp
H/>6
W"el
|O@e3d'
E!8TQ$
Cj(.
}+vI
o~
LWxoP
!2G*
H!,e
ILpc
l[K<
?4OwY
-w U!
g f
w8YNo
* $9f.q@
EXj8c>
7{
_$W;
)m*,
MC\n/*
KFBu!
en<e1I
?H Z
:H>Kk
]yGG
\RQ(
t7
Dd|a
Y^q8
VPX$
qEme
444n4448444
0p*Y~
( wG
444v444<444
GY\j+s
e1R/
}IVK2
o(H8Z
!&sd
_B`N
6fWk
~]DW6
(c`aP
\}Sz
$8$F
?%X~
+Zh$
Q5C;
&^Ja
bblw
;#Z:+
"h?b
444O
="#
Dz<6\
XHzq
@-_%
!bb
=S0>
J;t1J
mAeS
.`1]
<ph_
tAa^
bzC{
L[];
]elV
C]*Hf
$"2
6*bT
-u!!
;OinK
3~Hw
bUt
H`(O""
egn-
+c\f
070XRnAMc
KVP?
@<"R
wFUu
{sDU
M#+U
#XOL
D's
SrjD
pvoq
}.Tb
"p{1n
[\>(
HuN7
sFBu
9qew+.v
&w'
/7"$4
pf5s
_!lt
Ut>'
d~#pA
H9FS
w#_Y
JcF,
e{ L
!Ig
0#FU
1H<A
l#{q
A#H
WfO<
XtVs
r._s
`T"j
]dYc
o`CP
N @B
6Q3g
_xn$
ptV-i
>?cq
uRQ,s
e,+c`
~ Vw}
Ifm
N@H f
(*8I?k
,-e.
L) :
`f&
k)y~
JlH
@9F=
iq 8
it2ko
wpn~
}6AN
P= hn
[RBR
[ddV
-0B%
;&
n`9I
nPqR17YTzDY8SDmUMNHHVn5e
_ffN
C|o0
1:xi{*}s
FO!F
^BIf
lp^
\f;Y{
E# i
\?yD
7o*SYAz
444QLZ/7;O
tqt&!$:
&*Sc=,
1~yQ
cWHz
S>! D
~t'
#i$l6T[X
uH&*&D
4445
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven02_64 | Seven02_64 | VirtualBox | 2018-05-18 15:55:16 | 2018-05-18 15:58:38 | 202 |
22 Behaviors detected by system signatures
Collects information to fingerprint the system
Severity: High
Confidence: High
Attempts to remove evidence of file being downloaded from the Internet
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe:Zone.Identifier
Installs itself for autorun at Windows startup
Severity: High
Confidence: Very High
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\iygihy
- data: cmd /c type C:\Users\Seven01\AppData\Local\Temp\iygihy.txt | cmd
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Omnicare Inc
- data: C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe
- file: C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe
Retrieves Windows ProductID, probably to fingerprint the sandbox
Severity: High
Confidence: Very High
Checks the CPU name from registry, possibly for anti-virtualization
Severity: High
Confidence: Very High
Checks the system manufacturer, likely for anti-virtualization
Severity: High
Confidence: Very High
Creates a copy of itself
Severity: High
Confidence: Very High
- copy: C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe
Harvests credentials from local FTP client softwares
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml
- file: C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
- file: C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
- key: HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
Harvests information related to installed instant messenger clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml
- key: HKEY_CURRENT_USER\Software\Paltalk
Harvests information related to installed mail clients
Severity: High
Confidence: Very High
- file: C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
- key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: fuguyih.exe(2620) -> fuguyih.exe(2868)
Deletes its original binary from disk
Severity: High
Confidence: Very High
Creates RWX memory
Severity: Medium
Confidence: Medium
A process attempted to delay the analysis task.
Severity: Medium
Confidence: Very High
- Process: fuguyih.exe tried to sleep 652 seconds, actually delayed analysis time by 0 seconds
- Process: WmiPrvSE.exe tried to sleep 361 seconds, actually delayed analysis time by 0 seconds
Reads data out of its own binary image
Severity: Medium
Confidence: Low
- self_read: process: H68.exe, pid: 2480, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2480, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2480, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2480, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2480, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 2728, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2728, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2728, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2728, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2728, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 2640, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2640, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2640, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2640, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2640, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 2496, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2496, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2496, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2496, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2496, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 2052, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2052, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2052, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2052, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2052, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 2668, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2668, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2668, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2668, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2668, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 1852, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 1852, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 1852, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 1852, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 1852, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 2852, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2852, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2852, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2852, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2852, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 2720, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 2720, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 2720, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 2720, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 2720, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 200, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 200, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 200, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 200, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 200, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 1980, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 1980, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 1980, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 1980, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 1980, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 1340, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 1340, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 1340, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 1340, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 1340, offset: 0x00001fd4, length: 0x00000200
- self_read: process: H68.exe, pid: 208, offset: 0x00000000, length: 0x00001000
- self_read: process: H68.exe, pid: 208, offset: 0x00000080, length: 0x00000200
- self_read: process: H68.exe, pid: 208, offset: 0x00000178, length: 0x00000200
- self_read: process: H68.exe, pid: 208, offset: 0x00001fb8, length: 0x00000200
- self_read: process: H68.exe, pid: 208, offset: 0x00001fd4, length: 0x00000200
A process created a hidden window
Severity: Medium
Confidence: Very High
- Process: bossemmy.exe -> "cmd"
- Process: fuguyih.exe -> "cmd"
Drops a binary and executes it
Severity: Medium
Confidence: Medium
- binary: C:\Users\Seven01\AppData\Local\Temp\H68.exe
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- get_no_useragent: HTTP traffic contains a GET request with no user-agent header
- suspicious_request: http://checkip.dyndns.org/
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x000d8200, virtual_size: 0x000d8044
Attempts to connect to a dead IP:Port (1 unique times)
Severity: Low
Confidence: Very High
- IP: 192.168.56.1:80
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven02_64 | Seven02_64 | VirtualBox | 2018-05-18 15:55:16 | 2018-05-18 15:58:38 | 202 |
10 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe.config C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe.Local\ C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows C:\Windows\winsxs C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\System32\l_intl.nls C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll \Device\KsecDD C:\Users\Seven01\AppData\Local\Temp\bossemmy.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol21.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI C:\Windows\System32\tzres.dll C:\Windows\Globalization\it-it.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources\bossemmy.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\bossemmy.resources\bossemmy.resources.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\Globalization\it.nlp C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources\bossemmy.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\bossemmy.resources\bossemmy.resources.exe C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll C:\Windows\Globalization\en-us.nlp C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Windows\assembly\GAC\mscorlib.resources\2.0.0.0_it-IT_b77a5c561934e089 C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Local\Temp\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe \Device\NamedPipe\ C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2308.19245218 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2308.19245218 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2308.19245265 C:\Windows\System32\Branding\Basebrd\Basebrd.dll C:\Windows\Branding\Basebrd\basebrd.dll C:\Windows\Globalization\Sorting\sortdefault.nls C:\Users\Seven01\AppData\Local\Temp\"C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe" C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe.config C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe.Local\ C:\Users\Seven01\AppData\Roaming C:\Users\Seven01\AppData\Roaming\Microsoft\Windows C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs C:\Users\Seven01\AppData\Roaming\Microsoft C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.INI C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources\bossemmy.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\bossemmy.resources\bossemmy.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources\bossemmy.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\bossemmy.resources\bossemmy.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\mscorlib.resources\mscorlib.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RunPEDll\RunPEDll.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\stub.resources\stub.resources.exe C:\Users\Seven01\AppData\Local\Temp\iygihy.txt C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2620.19247234 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2620.19247234 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2620.19247234 C:\Users\Seven01\AppData\Local\Temp\reg.* C:\Users\Seven01\AppData\Local\Temp\reg C:\ProgramData\Oracle\Java\javapath\reg.* C:\ProgramData\Oracle\Java\javapath\reg C:\Windows\System32\reg.* C:\Windows\System32\reg.COM C:\Windows\System32\reg.exe C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI C:\Windows\System32\wbem\wbemdisp.tlb C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL C:\Windows\SysWOW64\stdole2.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll C:\Windows\Globalization\en.nlp C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\ C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe:Zone.Identifier C:\Users\Seven01\AppData\Local\Temp\tmpG868.tmp C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources\I3MM3S5RFX9NVW52W48C5607KGZSIXA32HJPLGAR.resources.exe C:\Users\Seven01\AppData\Local\Temp\H68.exe C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\* C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\logins.json C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_it-IT_b03f5f7f11d50a3a C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\it-IT\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.INI C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data \??\MountPointManager C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies C:\Users\Seven01\AppData\Local\Microsoft\Windows\History C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.INI C:\Program Files (x86)\Common Files\Apple\Apple Application Support\plutil.exe C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\logins.json C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini C:\Program Files (x86)\Mozilla Firefox\nss3.dll C:\Program Files (x86)\Postbox\nss3.dll C:\Program Files (x86)\Mozilla Thunderbird\nss3.dll C:\Program Files (x86)\SeaMonkey\nss3.dll C:\Program Files (x86)\Flock\nss3.dll C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data C:\Users\Seven01\AppData\Local\UCBrowser\* C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini C:\Users\Seven01\AppData\Roaming\Thunderbird\signons.sqlite C:\Users\Seven01\AppData\Roaming\Thunderbird\logins.json C:\Storage\ C:\mail\ C:\Users\Seven01\AppData\Local\VirtualStore\Program Files\Foxmail\mail\ C:\Users\Seven01\AppData\Local\VirtualStore\Program Files (x86)\Foxmail\mail\ C:\Users\Seven01\AppData\Roaming\Opera Mail\Opera Mail\wand.dat C:\Users\Seven01\AppData\Roaming\Pocomail\accounts.ini C:\Users\Seven01\AppData\Roaming\The Bat! C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini C:\Users\Seven01\AppData\Roaming\Postbox\signons.sqlite C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx C:\Windows\SysWOW64\wshom.ocx C:\ProgramData\DynDNS\Updater\config.dyndns C:\Users\All Users\AppData\Roaming\FlashFXP\3quick.dat C:\ C:\Users\Seven01\AppData\Roaming\.purple\accounts.xml C:\Users\Seven01\AppData\RoamingSmartFTPClient 2.0FavoritesQuick Connect*.xml C:\Users\Seven01\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\ C:\Users\Seven01\AppData\Local\Temp\Ftplist.txt C:\Program Files (x86)\jDownloader\config\database.script C:\Windows\sysnative\wbem\WmiPrvSE.exe \??\PIPE\samr C:\Windows\sysnative\wbem\repository C:\Windows\sysnative\wbem\Logs C:\Windows\sysnative\wbem\AutoRecover C:\Windows\sysnative\wbem\MOF C:\Windows\sysnative\wbem\repository\INDEX.BTR C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\WMIDataDevice C:\Users\Seven01\AppData\Local\Temp\H68.exe.config C:\Users\Seven01\AppData\Local\Temp\H68.exe.Local\ C:\Users\Seven01\AppData\Local\Temp\H68.config C:\Users\Seven01\AppData\Local\Temp\H68.INI C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start.* C:\Windows\SysWOW64\shell32.dll C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000015.db C:\Users\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start C:\Windows\Microsoft.NET\Framework\v2.0.50727\VERSION.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb C:\Windows\symbols\dll\System.pdb C:\Windows\dll\System.pdb C:\Windows\System.pdb C:\Users\Seven01\AppData\Local\Temp\H68.PDB C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb C:\Windows\symbols\exe\ConsoleApp1.pdb C:\Windows\exe\ConsoleApp1.pdb C:\Windows\ConsoleApp1.pdb C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb C:\Windows\symbols\dll\mscorlib.pdb C:\Windows\dll\mscorlib.pdb C:\Windows\mscorlib.pdb C:\Windows\System32\it-IT\werui.dll.mui C:\Windows\System32\werui.dll C:\Windows\System32\it-IT\DUser.dll.mui C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui C:\Windows\Fonts\staticcache.dat C:\Windows\win.ini C:\Windows\System32\uxtheme.dll.Config C:\Windows\System32\uxtheme.dll C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2 C:\Windows\System32\it-IT\erofflps.txt C:\Users\Seven01\AppData\Local\Temp\ C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml C:\Windows\System32\drivers\*.mrk C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\*_*_*_* C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_08fe76d0 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_08fe76d0\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_05aa92f3 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_05aa92f3\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_096ed1e0 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_096ed1e0\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0b5ef7e6 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0b5ef7e6\Report.wer C:\Windows\assembly\GAC_32\System.Windows.Forms\2.0.0.0__b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\assembly\GAC_32\System\2.0.0.0__b77a5c561934e089 C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089 C:\Windows\assembly\GAC_32\System.Drawing\2.0.0.0__b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9859a6e0562f64eacfb8ad76f260a2d6\Accessibility.ni.dll C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.INI C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_03031736 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_03031736\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_072337fd C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_072337fd\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_036b5096 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_036b5096\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0a77696d C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0a77696d\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_060f87b3 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_060f87b3\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_047fa1c3 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_047fa1c3\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_09efbc5f C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_09efbc5f\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0607d74a C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0607d74a\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_04eff263 C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_04eff263\Report.wer
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe.config C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6229_none_d089f796442de10e\msvcr80.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch C:\Windows\assembly\NativeImages_v2.0.50727_32\index126.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll C:\Windows\System32\l_intl.nls \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll C:\Windows\assembly\pubpol21.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll C:\Windows\System32\tzres.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\it\mscorrc.dll C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll \Device\NamedPipe\ C:\Windows\Branding\Basebrd\basebrd.dll C:\Windows\Globalization\Sorting\sortdefault.nls C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe.config C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll C:\Windows\System32\wbem\wbemdisp.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll C:\Windows\SysWOW64\stdole2.tlb C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll C:\Users\Seven01\AppData\Roaming\Mozilla\Firefox\profiles.ini C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_it_b03f5f7f11d50a3a\Microsoft.VisualBasic.resources.dll C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\d9a485330ec2708456134e4a9712a4ab\System.Security.ni.dll C:\Users\Seven01\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini C:\Users\Seven01\AppData\Roaming\Flock\Browser\profiles.ini C:\Users\Seven01\AppData\Roaming\Flock\Browser\signons3.txt C:\Users\Seven01\AppData\Roaming\Thunderbird\profiles.ini C:\Users\Seven01\AppData\Roaming\Postbox\profiles.ini C:\Users\Seven01\AppData\Roaming\FileZilla\recentservers.xml C:\Users\Seven01\AppData\Roaming\CoreFTP\sites.idx C:\Windows\SysWOW64\wshom.ocx C:\Windows\sysnative\wbem\WmiPrvSE.exe \??\PIPE\samr C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\WMIDataDevice C:\Users\Seven01\AppData\Local\Temp\H68.exe.config C:\Users\Seven01\AppData\Local\Temp\H68.exe C:\Windows\SysWOW64\shell32.dll C:\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\cversions.1.db C:\Users\Seven01\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000015.db C:\Users\desktop.ini C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Roaming C:\Users\Seven01\AppData\Roaming\Microsoft\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft C:\Users\Seven01\AppData\Roaming\Microsoft\Windows C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb C:\Windows\symbols\dll\System.pdb C:\Windows\dll\System.pdb C:\Windows\System.pdb C:\Users\Seven01\AppData\Local\Temp\ConsoleApp1.pdb C:\Windows\symbols\exe\ConsoleApp1.pdb C:\Windows\exe\ConsoleApp1.pdb C:\Windows\ConsoleApp1.pdb C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.pdb C:\Windows\symbols\dll\mscorlib.pdb C:\Windows\dll\mscorlib.pdb C:\Windows\mscorlib.pdb C:\Windows\System32\it-IT\werui.dll.mui C:\Windows\System32\werui.dll C:\Windows\System32\it-IT\DUser.dll.mui C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_it-it_e4c79be92250cb6e\Comctl32.dll.mui C:\Windows\Fonts\staticcache.dat C:\Windows\win.ini C:\Windows\System32\uxtheme.dll.Config C:\Windows\System32\uxtheme.dll C:\Windows\System32\it-IT\erofflps.txt C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\9859a6e0562f64eacfb8ad76f260a2d6\Accessibility.ni.dll C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml
Write Files
C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe C:\Users\Seven01\AppData\Local\Temp\iygihy.txt C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe C:\Users\Seven01\AppData\Local\Temp\tmpG868.tmp C:\Users\Seven01\AppData\Local\Temp\H68.exe C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat \??\PIPE\samr C:\Windows\sysnative\wbem\repository\WRITABLE.TST C:\Windows\sysnative\wbem\repository\MAPPING1.MAP C:\Windows\sysnative\wbem\repository\MAPPING2.MAP C:\Windows\sysnative\wbem\repository\MAPPING3.MAP C:\Windows\sysnative\wbem\repository\OBJECTS.DATA C:\Windows\sysnative\wbem\repository\INDEX.BTR \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER \??\WMIDataDevice C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_08fe76d0\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_05aa92f3\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_096ed1e0\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0b5ef7e6\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_03031736\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_072337fd\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_036b5096\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0a77696d\Report.wer C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_060f87b3\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_047fa1c3\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_09efbc5f\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_0607d74a\Report.wer C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_h68.exe_387f3d693bf61385051547b48cb97a18578d563_04eff263\Report.wer
Delete Files
C:\Users\Seven01\AppData\Local\Temp\bossemmy.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2308.19245218 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2308.19245218 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2308.19245265 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.2620.19247234 C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.2620.19247234 C:\Users\Seven01\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2620.19247234 C:\Users\Seven01\AppData\Local\Temp\Omnicare Inc\Omnicare Inc.exe:Zone.Identifier C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp C:\Users\Seven01\AppData\Local\Temp\WER7B26.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp C:\Users\Seven01\AppData\Local\Temp\WER992E.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp C:\Users\Seven01\AppData\Local\Temp\WERD608.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp C:\Users\Seven01\AppData\Local\Temp\WERFB81.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp C:\Users\Seven01\AppData\Local\Temp\WER1E1D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp C:\Users\Seven01\AppData\Local\Temp\WER3F12.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp C:\Users\Seven01\AppData\Local\Temp\WER576D.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp C:\Users\Seven01\AppData\Local\Temp\WER7063.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp C:\Users\Seven01\AppData\Local\Temp\WER8E7A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp C:\Users\Seven01\AppData\Local\Temp\WERA89A.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp C:\Users\Seven01\AppData\Local\Temp\WERC327.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp C:\Users\Seven01\AppData\Local\Temp\WERDDE3.tmp.WERInternalMetadata.xml C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp C:\Users\Seven01\AppData\Local\Temp\WERF8FC.tmp.WERInternalMetadata.xml
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bossemmy.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\53cbe261\3448e062 HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\9622af9\2ea3dcf5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|bossemmy.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|bossemmy.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|bossemmy.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\9622af9\2a895943 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it-IT_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\40dcb014 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.mscorlib.resources_it_b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5e8c75c\1ffc8ca7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4ad60644\6f323003 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\235dd0a9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5d1b2185\9e47f51 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fuguyih.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|fuguyih.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|fuguyih.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Roaming|Microsoft|Windows|Start Menu|Programs|Startup|fuguyih.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\iygihy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\222261a\f3721b HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\AppID\fuguyih.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\5F48F05 HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_CURRENT_USER\Software\Classes\WinMgmts HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_CURRENT_USER\Software\Classes\TypeLib HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default) HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\410 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\10 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\fuguyih_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_CURRENT_USER HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\System\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Omnicare Inc HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\62ed7031\40e0b0fd HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\62ed7031\1ffddffc HKEY_CURRENT_USER\Control Panel\International HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it-IT_b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\1c4dd593 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_it_b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\4deb99ab HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\Software\Policies HKEY_CURRENT_USER\Software\Policies HKEY_CURRENT_USER\Software HKEY_LOCAL_MACHINE\Software HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1 HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions HKEY_CLASSES_ROOT\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\410 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\10 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default) HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites HKEY_CURRENT_USER\Software\Paltalk HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FTP Commander HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC HKEY_CURRENT_USER\SOFTWARE\Vitalwerks\DUC HKEY_CURRENT_USER\Software\DownloadManager\Passwords HKEY_USERS\S-1-5-20_Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\Software\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\Software\Classes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\system\Setup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\ProcessIdentifier HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32 HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000 HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009 HKEY_PERFORMANCE_TEXT\Counter HKEY_PERFORMANCE_DATA\238 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\H68.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\63fc17e7\5b5a3ba7 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\H68.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory HKEY_CLASSES_ROOT\Directory HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler HKEY_CLASSES_ROOT\Folder HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler HKEY_CLASSES_ROOT\AllFilesystemObjects HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\ExclusionList HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\InclusionList HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default) HKEY_CLASSES_ROOT\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|H68.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|H68.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|H68.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Windows Error Reporting HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ExcludedApplications HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DebugApplications HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Windows Error Reporting HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ExcludedApplications HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DebugApplications HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Throttling\CLR20r3 HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\dw20.exe HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90} HKEY_CURRENT_USER\Keyboard Layout\Toggle HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SystemInformation HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CEIPRole\RolesInWER HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\OfflineMode HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\WaitOnStart HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\NIUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index126\ILUsageMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index21 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\iygihy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\5F48F05 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileDirectory HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{C2D43895-0262-4873-A789-C2F96D24B693}\DhcpDomain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Omnicare Inc HKEY_CURRENT_USER\Control Panel\International\sYearMonth HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\84\MissingDependencies HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default) HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{4528B43E-8110-4BC2-9519-4704F6839CC9}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{98ED7337-6B70-4CB1-AF2E-255A91FF690F}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{9AFECCEE-F4AB-4D2A-8F19-A565C84B3A3E}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Provider HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Scope HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\Locale HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\User HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{E67713A8-22A6-4301-8DC7-EDD0251B97C7}\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension HKEY_CURRENT_USER\Control Panel\International\LocaleName HKEY_CURRENT_USER\Control Panel\International\sCountry HKEY_CURRENT_USER\Control Panel\International\sList HKEY_CURRENT_USER\Control Panel\International\sDecimal HKEY_CURRENT_USER\Control Panel\International\sThousand HKEY_CURRENT_USER\Control Panel\International\sGrouping HKEY_CURRENT_USER\Control Panel\International\sNativeDigits HKEY_CURRENT_USER\Control Panel\International\sCurrency HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep HKEY_CURRENT_USER\Control Panel\International\sMonGrouping HKEY_CURRENT_USER\Control Panel\International\sPositiveSign HKEY_CURRENT_USER\Control Panel\International\sNegativeSign HKEY_CURRENT_USER\Control Panel\International\sTimeFormat HKEY_CURRENT_USER\Control Panel\International\sShortTime HKEY_CURRENT_USER\Control Panel\International\s1159 HKEY_CURRENT_USER\Control Panel\International\s2359 HKEY_CURRENT_USER\Control Panel\International\sShortDate HKEY_CURRENT_USER\Control Panel\International\sLongDate HKEY_CURRENT_USER\Control Panel\International\iCountry HKEY_CURRENT_USER\Control Panel\International\iMeasure HKEY_CURRENT_USER\Control Panel\International\iPaperSize HKEY_CURRENT_USER\Control Panel\International\iDigits HKEY_CURRENT_USER\Control Panel\International\iLZero HKEY_CURRENT_USER\Control Panel\International\iNegNumber HKEY_CURRENT_USER\Control Panel\International\NumShape HKEY_CURRENT_USER\Control Panel\International\iCurrDigits HKEY_CURRENT_USER\Control Panel\International\iCurrency HKEY_CURRENT_USER\Control Panel\International\iNegCurr HKEY_CURRENT_USER\Control Panel\International\iCalendarType HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier HKEY_USERS\S-1-5-21-1822907384-1282624486-319450072-1000\Control Panel\International\LocaleName HKEY_PERFORMANCE_TEXT\Counter HKEY_PERFORMANCE_DATA\238 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ForceQueueMode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\ShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\DoReport HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\PCHealth\ErrorReporting\AllOrNone HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\Server\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MachineID HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultConsent HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontSendAdditionalData HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Disabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\DefaultOverrideBehavior HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Consent\CLR20r3 HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LoggingDisabled HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ConfigureArchive HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\DisableQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxQueueCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\MaxArchiveCount HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceQueue HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\QueuePesterInterval HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\SendEFSFiles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\BypassDataThrottling HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\ForceUserModeCabCollection HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerServer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseSSL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerPortNumber HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\CorporateWerUseAuthentication HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Reliability Analysis\RAC\RacWerSampleTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\RestartRunTime HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Segoe UI HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EditionID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BuildLabEx HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CSDBuildNumber HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\BIOSVersion HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\CSDBuildNumber HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\LastWatsonCabUploaded HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\WinHttpSettings HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\44D72C57 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\DisplayName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigMask HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ConfigString HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MVID HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\EvalationData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\Status HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\ILDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\NIDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\50a69a2e\2dd6ac50\7f\MissingDependencies HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\OfflineMode HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\WaitOnStart
Write Keys
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\iygihy HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\fuguyih_RASAPI32 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableFileTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\EnableConsoleTracing HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\ConsoleTracingMask HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\MaxFileSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\fuguyih_RASAPI32\FileDirectory HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Omnicare Inc HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\CheckingForSolutionDialog HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\StoreLocation HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles\FirstLevelConsentDialog
Delete Keys
Nothing to display
Mutexes
Global\CLR_CASOFF_MUTEX Global\.net clr networking Local\_!MSFTHISTORY!_ Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5! Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies! Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5! Global\411a6ca0-5aa3-11e8-b448-080027839166 Local\MSCTF.Asm.MutexDefault1 Global\4720fe16-5aa3-11e8-b448-080027839166 Global\4f020382-5aa3-11e8-b448-080027839166 Global\5645adba-5aa3-11e8-b448-080027839166 Global\5b45fc84-5aa3-11e8-b448-080027839166 Global\6011d792-5aa3-11e8-b448-080027839166 Global\6461b858-5aa3-11e8-b448-080027839166 Global\68038d74-5aa3-11e8-b448-080027839166 Global\6c320d4e-5aa3-11e8-b448-080027839166 Global\70d56062-5aa3-11e8-b448-080027839166 Global\74a6e486-5aa3-11e8-b448-080027839166 Global\78bb2a82-5aa3-11e8-b448-080027839166 Global\7ce74802-5aa3-11e8-b448-080027839166
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW kernel32.dll.InitializeCriticalSectionAndSpinCount kernel32.dll.IsProcessorFeaturePresent msvcrt.dll._set_error_mode msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z kernel32.dll.FindActCtxSectionStringW kernel32.dll.GetSystemWindowsDirectoryW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap mscorwks.dll._CorExeMain mscorwks.dll.GetCLRFunction advapi32.dll.RegisterTraceGuidsW advapi32.dll.UnregisterTraceGuids advapi32.dll.GetTraceLoggerHandle advapi32.dll.GetTraceEnableLevel advapi32.dll.GetTraceEnableFlags advapi32.dll.TraceEvent mscoree.dll.IEE mscoreei.dll.IEE mscorwks.dll.IEE mscoree.dll.GetStartupFlags mscoreei.dll.GetStartupFlags mscoree.dll.GetHostConfigurationFile mscoreei.dll.GetHostConfigurationFile mscoreei.dll.GetCORVersion mscoree.dll.GetCORSystemDirectory mscoreei.dll.GetCORSystemDirectory_RetAddr mscoreei.dll.CreateConfigStream ntdll.dll.RtlUnwind kernel32.dll.IsWow64Process advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddVectoredContinueHandler kernel32.dll.RemoveVectoredContinueHandler advapi32.dll.ConvertSidToStringSidW shell32.dll.SHGetFolderPathW kernel32.dll.GetWriteWatch kernel32.dll.ResetWriteWatch kernel32.dll.CreateMemoryResourceNotification kernel32.dll.QueryMemoryResourceNotification kernel32.dll.QueryActCtxW kernel32.dll.GetVersionExW kernel32.dll.GetFullPathNameW ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 ole32.dll.CoGetContextToken advapi32.dll.CryptAcquireContextA advapi32.dll.CryptReleaseContext advapi32.dll.CryptCreateHash advapi32.dll.CryptDestroyHash advapi32.dll.CryptHashData advapi32.dll.CryptGetHashParam advapi32.dll.CryptImportKey advapi32.dll.CryptExportKey advapi32.dll.CryptGenKey advapi32.dll.CryptGetKeyParam advapi32.dll.CryptDestroyKey advapi32.dll.CryptVerifySignatureA advapi32.dll.CryptSignHashA advapi32.dll.CryptGetProvParam advapi32.dll.CryptGetUserKey advapi32.dll.CryptEnumProvidersA mscoree.dll.GetMetaDataInternalInterface mscoreei.dll.GetMetaDataInternalInterface mscorwks.dll.GetMetaDataInternalInterface mscorjit.dll.getJit kernel32.dll.GetUserDefaultUILanguage kernel32.dll.SetErrorMode kernel32.dll.GetFileAttributesExW mscoreei.dll.LoadLibraryShim culture.dll.ConvertLangIdToCultureName kernel32.dll.lstrlen kernel32.dll.lstrlenW mscoree.dll.ND_RI4 mscoreei.dll.ND_RI4 bcrypt.dll.BCryptGetFipsAlgorithmMode kernel32.dll.GlobalMemoryStatusEx kernel32.dll.VirtualProtect kernel32.dll.GetEnvironmentVariableW kernel32.dll.SwitchToThread kernel32.dll.CloseHandle kernel32.dll.GetCurrentProcessId advapi32.dll.LookupPrivilegeValueW kernel32.dll.GetCurrentProcess advapi32.dll.AdjustTokenPrivileges kernel32.dll.OpenProcess psapi.dll.EnumProcessModules psapi.dll.GetModuleInformation psapi.dll.GetModuleBaseNameW psapi.dll.GetModuleFileNameExW kernel32.dll.GetProcAddress kernel32.dll.DebugActiveProcess kernel32.dll.WaitForDebugEvent kernel32.dll.ContinueDebugEvent kernel32.dll.DeleteFileA advapi32.dll.SetKernelObjectSecurity advapi32.dll.GetKernelObjectSecurity ntdll.dll.NtSetInformationProcess ntdll.dll.NtProtectVirtualMemory kernel32.dll.GetModuleFileNameW shfolder.dll.SHGetFolderPathW kernel32.dll.MoveFileW kernel32.dll.LocalFree kernel32.dll.CreatePipe kernel32.dll.DuplicateHandle kernel32.dll.GetStdHandle kernel32.dll.GetCurrentDirectoryW kernel32.dll.CreateProcessW kernel32.dll.GetFileType kernel32.dll.GetConsoleCP kernel32.dll.GetACP kernel32.dll.UnmapViewOfFile kernel32.dll.GetConsoleOutputCP kernel32.dll.WriteFile ole32.dll.CoUninitialize kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx advapi32.dll.EventUnregister kernel32.dll.SetThreadUILanguage kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle kernel32.dll.CopyFileExW kernel32.dll.IsDebuggerPresent kernel32.dll.SetConsoleInputExeNameW ntdll.dll.NtQueryInformationProcess kernel32.dll.GetTempPathW kernel32.dll.CreateFileW kernel32.dll.GetFileSize kernel32.dll.ReadFile kernel32.dll.VirtualAllocEx kernel32.dll.GetThreadContext kernel32.dll.Wow64GetThreadContext ntdll.dll.NtUnmapViewOfSection kernel32.dll.ResumeThread kernel32.dll.SetThreadContext kernel32.dll.Wow64SetThreadContext kernel32.dll.WriteProcessMemory kernel32.dll.ReadProcessMemory kernel32.dll.TerminateProcess uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptCreateHash cryptsp.dll.CryptDestroyHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam ole32.dll.CreateBindCtx ole32.dll.CoGetObjectContext sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW sechost.dll.LookupAccountSidLocalW cryptsp.dll.CryptGenRandom ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree ole32.dll.CoCreateInstance ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult rpcrtremote.dll.I_RpcExtInitializeExtensionPoint ole32.dll.MkParseDisplayName oleaut32.dll.#2 oleaut32.dll.#6 kernel32.dll.GetThreadPreferredUILanguages kernel32.dll.SetThreadPreferredUILanguages kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetSystemDefaultLocaleName ole32.dll.BindMoniker sxs.dll.SxsOleAut32RedirectTypeLibrary advapi32.dll.RegOpenKeyW advapi32.dll.RegEnumKeyW advapi32.dll.RegQueryValueW sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid sxs.dll.SxsLookupClrGuid oleaut32.dll.#9 oleaut32.dll.#4 oleaut32.dll.#283 oleaut32.dll.#284 mscoreei.dll._CorDllMain mscoree.dll.GetTokenForVTableEntry mscoree.dll.SetTargetForVTableEntry mscoree.dll.GetTargetForVTableEntry mscoreei.dll.GetTokenForVTableEntry mscoreei.dll.SetTargetForVTableEntry mscoreei.dll.GetTargetForVTableEntry kernel32.dll.GetLastError kernel32.dll.LocalAlloc oleaut32.dll.VariantInit oleaut32.dll.VariantClear oleaut32.dll.#7 kernel32.dll.CreateEventW kernel32.dll.SetEvent ole32.dll.CoWaitForMultipleHandles ole32.dll.IIDFromString kernel32.dll.LoadLibraryA wminet_utils.dll.ResetSecurity wminet_utils.dll.SetSecurity wminet_utils.dll.BlessIWbemServices wminet_utils.dll.BlessIWbemServicesObject wminet_utils.dll.GetPropertyHandle wminet_utils.dll.WritePropertyValue wminet_utils.dll.Clone wminet_utils.dll.VerifyClientKey wminet_utils.dll.GetQualifierSet wminet_utils.dll.Get wminet_utils.dll.Put wminet_utils.dll.Delete wminet_utils.dll.GetNames wminet_utils.dll.BeginEnumeration wminet_utils.dll.Next wminet_utils.dll.EndEnumeration wminet_utils.dll.GetPropertyQualifierSet wminet_utils.dll.GetObjectText wminet_utils.dll.SpawnDerivedClass wminet_utils.dll.SpawnInstance wminet_utils.dll.CompareTo wminet_utils.dll.GetPropertyOrigin wminet_utils.dll.InheritsFrom wminet_utils.dll.GetMethod wminet_utils.dll.PutMethod wminet_utils.dll.DeleteMethod wminet_utils.dll.BeginMethodEnumeration wminet_utils.dll.NextMethod wminet_utils.dll.EndMethodEnumeration wminet_utils.dll.GetMethodQualifierSet wminet_utils.dll.GetMethodOrigin wminet_utils.dll.QualifierSet_Get wminet_utils.dll.QualifierSet_Put wminet_utils.dll.QualifierSet_Delete wminet_utils.dll.QualifierSet_GetNames wminet_utils.dll.QualifierSet_BeginEnumeration wminet_utils.dll.QualifierSet_Next wminet_utils.dll.QualifierSet_EndEnumeration wminet_utils.dll.GetCurrentApartmentType wminet_utils.dll.GetDemultiplexedStub wminet_utils.dll.CreateInstanceEnumWmi wminet_utils.dll.CreateClassEnumWmi wminet_utils.dll.ExecQueryWmi wminet_utils.dll.ExecNotificationQueryWmi wminet_utils.dll.PutInstanceWmi wminet_utils.dll.PutClassWmi wminet_utils.dll.CloneEnumWbemClassObject wminet_utils.dll.ConnectServerWmi oleaut32.dll.#500 oleaut32.dll.SysStringLen kernel32.dll.RtlZeroMemory kernel32.dll.RegOpenKeyExW advapi32.dll.GetUserNameW kernel32.dll.GetComputerNameW mscoree.dll.ND_RI2 mscoreei.dll.ND_RI2 rasapi32.dll.RasEnumConnectionsW rtutils.dll.TraceRegisterExA rtutils.dll.TracePrintfExA sechost.dll.OpenSCManagerW sechost.dll.OpenServiceW sechost.dll.QueryServiceStatus sechost.dll.CloseServiceHandle ws2_32.dll.WSAStartup ws2_32.dll.WSASocketW ws2_32.dll.setsockopt ws2_32.dll.WSAEventSelect ws2_32.dll.ioctlsocket ws2_32.dll.closesocket advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.CreateFileMappingW kernel32.dll.MapViewOfFile kernel32.dll.VirtualQuery kernel32.dll.ReleaseMutex advapi32.dll.CreateWellKnownSid kernel32.dll.CreateMutexW kernel32.dll.WaitForSingleObject kernel32.dll.OpenMutexW kernel32.dll.GetProcessTimes ws2_32.dll.WSAIoctl kernel32.dll.FormatMessageW rasapi32.dll.RasConnectionNotificationW advapi32.dll.RegOpenCurrentUser sechost.dll.NotifyServiceStatusChangeA advapi32.dll.RegNotifyChangeKeyValue winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser kernel32.dll.ResetEvent iphlpapi.dll.GetNetworkParams dnsapi.dll.DnsQueryConfig iphlpapi.dll.GetAdaptersAddresses iphlpapi.dll.GetIpInterfaceEntry iphlpapi.dll.GetBestInterfaceEx ws2_32.dll.inet_addr ws2_32.dll.getaddrinfo ws2_32.dll.freeaddrinfo ws2_32.dll.WSAConnect ws2_32.dll.send ws2_32.dll.recv ws2_32.dll.shutdown kernel32.dll.GetModuleHandleW user32.dll.DefWindowProcW gdi32.dll.GetStockObject user32.dll.RegisterClassW user32.dll.CreateWindowExW user32.dll.SetWindowLongW user32.dll.GetWindowLongW kernel32.dll.GetCurrentThread kernel32.dll.GetCurrentThreadId user32.dll.CallWindowProcW user32.dll.RegisterWindowMessageW dwmapi.dll.DwmIsCompositionEnabled ntdll.dll.NtQuerySystemInformation kernel32.dll.CreateDirectoryW kernel32.dll.CopyFileW advapi32.dll.RegSetValueExW kernel32.dll.DeleteFileW kernel32.dll.GetModuleFileNameA kernel32.dll.MoveFileExW kernel32.dll.CreateIoCompletionPort kernel32.dll.PostQueuedCompletionStatus ntdll.dll.NtQueryInformationThread ntdll.dll.NtGetCurrentProcessorNumber kernel32.dll.RtlMoveMemory shell32.dll.ShellExecuteEx shell32.dll.ShellExecuteExW kernel32.dll.FindFirstFileW kernel32.dll.FindClose kernel32.dll.GetExitCodeProcess setupapi.dll.CM_Get_Device_Interface_List_Size_ExW user32.dll.GetSystemMetrics kernel32.dll.GetSystemTimeAsFileTime setupapi.dll.CM_Get_Device_Interface_List_ExW user32.dll.GetClientRect user32.dll.GetWindowRect user32.dll.GetLastInputInfo user32.dll.GetParent ole32.dll.OleInitialize ole32.dll.CoRegisterMessageFilter user32.dll.PeekMessageW user32.dll.IsWindowUnicode user32.dll.GetMessageW user32.dll.TranslateMessage user32.dll.DispatchMessageW user32.dll.WaitMessage mlang.dll.#112 wininet.dll.FindFirstUrlCacheEntryA kernel32.dll.SetFileInformationByHandle urlmon.dll.CreateUri wininet.dll.FindNextUrlCacheEntryA wininet.dll.FindCloseUrlCache ole32.dll.CoRevokeInitializeSpy comctl32.dll.#388 cryptsp.dll.CryptAcquireContextA cryptsp.dll.CryptReleaseContext ole32.dll.CLSIDFromProgIDEx kernel32.dll.GetVolumeInformationA vssapi.dll.CreateWriter advapi32.dll.LookupAccountNameW samcli.dll.NetLocalGroupGetMembers samlib.dll.SamConnect rpcrt4.dll.NdrClientCall3 rpcrt4.dll.RpcStringBindingComposeW rpcrt4.dll.RpcBindingFromStringBindingW rpcrt4.dll.RpcStringFreeW rpcrt4.dll.RpcBindingFree samlib.dll.SamOpenDomain samlib.dll.SamLookupNamesInDomain samlib.dll.SamOpenAlias samlib.dll.SamFreeMemory samlib.dll.SamCloseHandle samlib.dll.SamGetMembersInAlias netutils.dll.NetApiBufferFree ole32.dll.CoCreateGuid ole32.dll.StringFromCLSID propsys.dll.VariantToPropVariant wbemcore.dll.Reinitialize wbemsvc.dll.DllGetClassObject wbemsvc.dll.DllCanUnloadNow authz.dll.AuthzInitializeContextFromToken authz.dll.AuthzInitializeObjectAccessAuditEvent2 authz.dll.AuthzAccessCheck authz.dll.AuthzFreeAuditEvent authz.dll.AuthzFreeContext authz.dll.AuthzInitializeResourceManager authz.dll.AuthzFreeResourceManager rpcrt4.dll.RpcBindingCreateW rpcrt4.dll.RpcBindingBind rpcrt4.dll.I_RpcMapWin32Status advapi32.dll.EventWrite kernel32.dll.RegCloseKey kernel32.dll.RegSetValueExW kernel32.dll.RegQueryValueExW wmisvc.dll.IsImproperShutdownDetected wevtapi.dll.EvtRender wevtapi.dll.EvtNext wevtapi.dll.EvtClose wevtapi.dll.EvtQuery wevtapi.dll.EvtCreateRenderContext rpcrt4.dll.RpcBindingSetAuthInfoExW rpcrt4.dll.RpcBindingSetOption ole32.dll.CoCreateFreeThreadedMarshaler ole32.dll.CreateStreamOnHGlobal advapi32.dll.RegCreateKeyExW kernelbase.dll.InitializeAcl kernelbase.dll.AddAce sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW kernel32.dll.IsThreadAFiber kernel32.dll.OpenProcessToken kernelbase.dll.GetTokenInformation kernelbase.dll.DuplicateTokenEx kernelbase.dll.AdjustTokenPrivileges kernel32.dll.SetThreadToken kernelbase.dll.AllocateAndInitializeSid kernelbase.dll.CheckTokenMembership ole32.dll.CLSIDFromString oleaut32.dll.#285 oleaut32.dll.#12 oleaut32.dll.#286 oleaut32.dll.#17 oleaut32.dll.#20 oleaut32.dll.#19 oleaut32.dll.#25 ole32.dll.CoRevertToSelf advapi32.dll.LogonUserExExW sspicli.dll.LogonUserExExW authz.dll.AuthzInitializeContextFromSid ole32.dll.CoGetCallContext ole32.dll.CoImpersonateClient advapi32.dll.OpenThreadToken oleaut32.dll.#8 ole32.dll.CoSwitchCallContext oleaut32.dll.#287 oleaut32.dll.#288 oleaut32.dll.#289 ntmarta.dll.GetMartaExtensionInterface fastprox.dll.DllGetClassObject fastprox.dll.DllCanUnloadNow oleaut32.dll.#290 wmi.dll.WmiQueryAllDataW wmi.dll.WmiQuerySingleInstanceW wmi.dll.WmiSetSingleItemW wmi.dll.WmiSetSingleInstanceW wmi.dll.WmiExecuteMethodW wmi.dll.WmiNotificationRegistrationW wmi.dll.WmiMofEnumerateResourcesW wmi.dll.WmiFileHandleToInstanceNameW wmi.dll.WmiDevInstToInstanceNameW wmi.dll.WmiQueryGuidInformation wmi.dll.WmiOpenBlock wmi.dll.WmiCloseBlock wmi.dll.WmiFreeBuffer wmi.dll.WmiEnumerateGuids propsys.dll.PSCreateMemoryPropertyStore propsys.dll.PSPropertyBag_WriteDWORD ole32.dll.CoGetApartmentType ole32.dll.CoRegisterInitializeSpy comctl32.dll.#236 ole32.dll.CoGetMalloc propsys.dll.PSPropertyBag_ReadDWORD comctl32.dll.#320 comctl32.dll.#324 comctl32.dll.#323 comctl32.dll.#328 comctl32.dll.#334 advapi32.dll.InitializeSecurityDescriptor advapi32.dll.SetEntriesInAclW advapi32.dll.SetSecurityDescriptorDacl comctl32.dll.#332 comctl32.dll.#386 advapi32.dll.IsTextUnicode comctl32.dll.#338 comctl32.dll.#339 shell32.dll.#102 ole32.dll.OleUninitialize advapi32.dll.CheckTokenMembership mscoree.dll.DllGetClassObject mscoreei.dll.DllGetClassObject diasymreader.dll.DllGetClassObjectInternal wer.dll.WerReportCreate wer.dll.WerReportSetParameter wer.dll.WerReportAddFile wer.dll.WerReportSetUIOption wer.dll.WerReportSubmit wer.dll.WerReportAddDump wer.dll.WerReportCloseHandle user32.dll.LoadStringW advapi32.dll.RegGetValueW user32.dll.GetProcessWindowStation user32.dll.GetThreadDesktop user32.dll.GetUserObjectInformationW sensapi.dll.IsNetworkAlive rpcrt4.dll.NdrClientCall2 user32.dll.CharUpperW werui.dll.WerUICreate werui.dll.WerUIStart ole32.dll.CoInitialize dui70.dll.InitProcessPriv comctl32.dll.LoadIconWithScaleDown ntdll.dll.RtlRunEncodeUnicodeString ntdll.dll.RtlInitUnicodeString ntdll.dll.RtlRunDecodeUnicodeString dui70.dll.InitThread duser.dll.InitGadgets user32.dll.RegisterMessagePumpHook dui70.dll.?GetClassInfoPtr@CCBase@DirectUI@@SGPAUIClassInfo@2@XZ dui70.dll.?GetFactoryLock@Element@DirectUI@@SGPAU_RTL_CRITICAL_SECTION@@XZ dui70.dll.??0CritSecLock@DirectUI@@QAE@PAU_RTL_CRITICAL_SECTION@@@Z dui70.dll.?ClassExist@ClassInfoBase@DirectUI@@SG_NPAPAUIClassInfo@2@PBQBUPropertyInfo@2@IPAU32@PAUHINSTANCE__@@PBG_N@Z dui70.dll.??0ClassInfoBase@DirectUI@@QAE@XZ dui70.dll.?Initialize@ClassInfoBase@DirectUI@@QAEJPAUHINSTANCE__@@PBG_NPBQBUPropertyInfo@2@I@Z dui70.dll.?Register@ClassInfoBase@DirectUI@@QAEJXZ dui70.dll.?IsGlobal@ClassInfoBase@DirectUI@@UBE_NXZ dui70.dll.?GetName@ClassInfoBase@DirectUI@@UBEPBGXZ dui70.dll.?GetModule@ClassInfoBase@DirectUI@@UBEPAUHINSTANCE__@@XZ dui70.dll.??1CritSecLock@DirectUI@@QAE@XZ dui70.dll.??0CCBase@DirectUI@@QAE@KPBG@Z dui70.dll.?Initialize@CCBase@DirectUI@@QAEJIPAVElement@2@PAK@Z duser.dll.CreateGadget duser.dll.SetGadgetMessageFilter duser.dll.SetGadgetStyle dui70.dll.?OnPropertyChanging@Element@DirectUI@@UAE_NPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?HandleUiaPropertyChangingListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@@Z dui70.dll.?HandleUiaPropertyListener@Element@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?DirectionProp@Element@DirectUI@@SGPBUPropertyInfo@2@XZ dui70.dll.?OnPropertyChanged@CCBase@DirectUI@@UAEXPBUPropertyInfo@2@HPAVValue@2@1@Z dui70.dll.?SetFontSize@Element@DirectUI@@QAEJH@Z dui70.dll.?SetWidth@Element@DirectUI@@QAEJH@Z dui70.dll.?SetHeight@Element@DirectUI@@QAEJH@Z dui70.dll.?EndDefer@Element@DirectUI@@QAEXK@Z dui70.dll.?OnGroupChanged@Element@DirectUI@@UAEXH_N@Z duser.dll.InvalidateGadget dui70.dll.CreateDUIWrapper dui70.dll.?SetNotifyHandler@CCBase@DirectUI@@QAEXP6GHIIJPAJPAX@Z1@Z shell32.dll.ExtractIconExW comctl32.dll.TaskDialogIndirect uxtheme.dll.IsThemeActive duser.dll.SetGadgetRootInfo uxtheme.dll.IsAppThemed uxtheme.dll.GetThemeAppProperties xmllite.dll.CreateXmlReader xmllite.dll.CreateXmlReaderInputWithEncodingName uxtheme.dll.OpenThemeData uxtheme.dll.GetThemeMargins uxtheme.dll.GetThemeFont uxtheme.dll.GetThemeColor uxtheme.dll.GetThemeMetric duser.dll.SetGadgetParent duser.dll.GetDUserModule duser.dll.FindStdColor duser.dll.AttachWndProcW kernel32.dll.InterlockedPopEntrySList kernel32.dll.InterlockedPushEntrySList kernel32.dll.InterlockedCompareExchange comctl32.dll.RegisterClassNameW duser.dll.GetGadgetRect duser.dll.GetGadgetRgn duser.dll.GetGadgetTicket gdi32.dll.GetLayout gdi32.dll.GdiRealizationInfo gdi32.dll.FontIsLinked gdi32.dll.GetTextFaceAliasW gdi32.dll.GetFontAssocStatus advapi32.dll.RegQueryValueExA gdi32.dll.GdiIsMetaPrintDC dui70.dll.?GetPICount@ClassInfoBase@DirectUI@@UBEIXZ dui70.dll.?GetByClassIndex@ClassInfoBase@DirectUI@@UAEPBUPropertyInfo@2@I@Z dui70.dll.?OnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z dui70.dll.?CreateAccNameLabel@HWNDHost@DirectUI@@IAEPAUHWND__@@PAU3@@Z uxtheme.dll.EnableThemeDialogTexture dui70.dll.?OnMessage@HWNDHost@DirectUI@@UAE_NIIJPAJ@Z dui70.dll.?CreateHWND@CCBase@DirectUI@@UAEPAUHWND__@@PAU3@@Z comctl32.dll.HIMAGELIST_QueryInterface comctl32.dll.DrawShadowText comctl32.dll.DrawSizeBox comctl32.dll.DrawScrollBar comctl32.dll.SizeBoxHwnd comctl32.dll.ScrollBar_MouseMove comctl32.dll.ScrollBar_Menu comctl32.dll.HandleScrollCmd comctl32.dll.DetachScrollBars comctl32.dll.AttachScrollBars comctl32.dll.CCSetScrollInfo comctl32.dll.CCGetScrollInfo comctl32.dll.CCEnableScrollBar comctl32.dll.QuerySystemGestureStatus uxtheme.dll.#49 uxtheme.dll.CloseThemeData dui70.dll.?PostCreate@CCBase@DirectUI@@MAEXPAUHWND__@@@Z dui70.dll.?IsContentProtected@Element@DirectUI@@UAE_NXZ uxtheme.dll.GetThemeBool duser.dll.GetGadgetFocus uxtheme.dll.GetThemeBackgroundContentRect uxtheme.dll.GetThemeTextMetrics uxtheme.dll.GetThemePartSize uxtheme.dll.GetThemeTextExtent uxtheme.dll.GetThemeBackgroundExtent duser.dll.SetGadgetFocus duser.dll.DUserSendEvent duser.dll.SetGadgetRect comctl32.dll.SetWindowSubclass comctl32.dll.DefSubclassProc dui70.dll.?GetHWND@HWNDHost@DirectUI@@UAEPAUHWND__@@XZ uxtheme.dll.#47 uxtheme.dll.BufferedPaintInit uxtheme.dll.BeginBufferedPaint uxtheme.dll.BufferedPaintRenderAnimation uxtheme.dll.BeginBufferedAnimation uxtheme.dll.IsThemeBackgroundPartiallyTransparent uxtheme.dll.DrawThemeParentBackground uxtheme.dll.DrawThemeBackground uxtheme.dll.DrawThemeText uxtheme.dll.EndBufferedAnimation uxtheme.dll.GetThemeTransitionDuration uxtheme.dll.GetBufferedPaintDC uxtheme.dll.GetBufferedPaintTargetDC uxtheme.dll.EndBufferedPaint oleaut32.dll.SysAllocString oleaut32.dll.SysFreeString duser.dll.ForwardGadgetMessage uxtheme.dll.GetThemeInt duser.dll.DUserPostEvent duser.dll.DisableContainerHwnd uxtheme.dll.BufferedPaintUnInit werui.dll.WerUIUpdateUIForState duser.dll.DeleteHandle duser.dll.DetachWndProc comctl32.dll.RemoveWindowSubclass dui70.dll.?OnUnHosted@HWNDHost@DirectUI@@MAEXPAVElement@2@@Z dui70.dll.?MessageCallback@HWNDHost@DirectUI@@UAEIPAUtagGMSG@@@Z dui70.dll.?HandleUiaDestroyListener@Element@DirectUI@@UAEXXZ dui70.dll.?OnDestroy@HWNDHost@DirectUI@@UAEXXZ uxtheme.dll.BufferedPaintStopAllAnimations dui70.dll.??1CCBase@DirectUI@@UAE@XZ uxtheme.dll.DrawThemeParentBackgroundEx uxtheme.dll.GetThemeEnumValue user32.dll.MsgWaitForMultipleObjects winhttp.dll.WinHttpOpen winhttp.dll.WinHttpSetTimeouts winhttp.dll.WinHttpSetOption winhttp.dll.WinHttpConnect winhttp.dll.WinHttpOpenRequest winhttp.dll.WinHttpSetStatusCallback winhttp.dll.WinHttpGetDefaultProxyConfiguration winhttp.dll.WinHttpGetProxyForUrl winhttp.dll.WinHttpSendRequest ws2_32.dll.GetAddrInfoW ws2_32.dll.#2 ws2_32.dll.#21 ws2_32.dll.#9 ws2_32.dll.FreeAddrInfoW ws2_32.dll.#6 ws2_32.dll.#5 ws2_32.dll.WSARecv ws2_32.dll.WSASend winhttp.dll.WinHttpReceiveResponse winhttp.dll.WinHttpQueryHeaders winhttp.dll.WinHttpReadData ws2_32.dll.#22 ws2_32.dll.#3 winhttp.dll.WinHttpCloseHandle advapi32.dll.IsValidSid advapi32.dll.GetLengthSid advapi32.dll.CopySid advapi32.dll.RegisterEventSourceW advapi32.dll.ReportEventW advapi32.dll.DeregisterEventSource werui.dll.WerUITerminate duser.dll.DUserFlushMessages duser.dll.DUserFlushDeferredMessages dui70.dll.UnInitThread user32.dll.UnregisterMessagePumpHook dui70.dll.UnInitProcessPriv dui70.dll.?Release@ClassInfoBase@DirectUI@@UAEHXZ dui70.dll.?GetGlobalIndex@ClassInfoBase@DirectUI@@UBEIXZ dui70.dll.??1ClassInfoBase@DirectUI@@UAE@XZ werui.dll.WerUIDelete advapi32.dll.DuplicateToken duser.dll.FindGadgetFromPoint shlwapi.dll.PathIsDirectoryW
Execute Commands
"cmd" "C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe" reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "iygihy" /d "cmd /c type "C:\Users\Seven01\AppData\Local\Temp\iygihy.txt" | cmd" C:\Users\Seven01\AppData\Local\Temp\H68.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fuguyih.exe C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Start dw20.exe -x -s 604 dw20.exe -x -s 680 dw20.exe -x -s 596 dw20.exe -x -s 592 dw20.exe -x -s 624 dw20.exe -x -s 600 dw20.exe -x -s 644
Started Services
Nothing to display
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven02_64 | Seven02_64 | VirtualBox | 2018-05-18 15:55:16 | 2018-05-18 15:58:38 | 202 |
1 HTTP Request(s) detected
http://checkip.dyndns.org/
- Hostname: checkip.dyndns.org
- IP Address: 162.88.100.200
- Port: 80
- Count: 1
GET / HTTP/1.1 Host: checkip.dyndns.org Connection: Keep-Alive