Analysis

Category Package Started Completed Duration Options Log
FILE exe 2020-06-23 05:50:26 2020-06-23 05:55:51 325 seconds Show Options Show Log
route = tor
2020-05-13 09:13:35,391 [root] INFO: Date set to: 20200623T05:50:25, timeout set to: 200
2020-06-23 05:50:25,046 [root] DEBUG: Starting analyzer from: C:\tmpq_mrpfl7
2020-06-23 05:50:25,046 [root] DEBUG: Storing results at: C:\sUsoAPg
2020-06-23 05:50:25,046 [root] DEBUG: Pipe server name: \\.\PIPE\qQwmnKNu
2020-06-23 05:50:25,046 [root] DEBUG: Python path: C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32
2020-06-23 05:50:25,046 [root] DEBUG: No analysis package specified, trying to detect it automagically.
2020-06-23 05:50:25,046 [root] INFO: Automatically selected analysis package "exe"
2020-06-23 05:50:25,046 [root] DEBUG: Trying to import analysis package "exe"...
2020-06-23 05:50:25,109 [root] DEBUG: Imported analysis package "exe".
2020-06-23 05:50:25,109 [root] DEBUG: Trying to initialize analysis package "exe"...
2020-06-23 05:50:25,109 [root] DEBUG: Initialized analysis package "exe".
2020-06-23 05:50:25,234 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.browser"...
2020-06-23 05:50:25,296 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser".
2020-06-23 05:50:25,296 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.curtain"...
2020-06-23 05:50:25,375 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain".
2020-06-23 05:50:25,375 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.digisig"...
2020-06-23 05:50:25,406 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig".
2020-06-23 05:50:25,406 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.disguise"...
2020-06-23 05:50:25,406 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise".
2020-06-23 05:50:25,421 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.human"...
2020-06-23 05:50:25,421 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human".
2020-06-23 05:50:25,421 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.procmon"...
2020-06-23 05:50:25,421 [root] DEBUG: Imported auxiliary module "modules.auxiliary.procmon".
2020-06-23 05:50:25,421 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.screenshots"...
2020-06-23 05:50:25,437 [modules.auxiliary.screenshots] DEBUG: Importing 'time'
2020-06-23 05:50:25,437 [modules.auxiliary.screenshots] DEBUG: Importing 'StringIO'
2020-06-23 05:50:25,437 [modules.auxiliary.screenshots] DEBUG: Importing 'Thread'
2020-06-23 05:50:25,437 [modules.auxiliary.screenshots] DEBUG: Importing 'Auxiliary'
2020-06-23 05:50:25,437 [modules.auxiliary.screenshots] DEBUG: Importing 'NetlogFile'
2020-06-23 05:50:25,437 [modules.auxiliary.screenshots] DEBUG: Importing 'Screenshot'
2020-06-23 05:50:25,453 [lib.api.screenshot] DEBUG: Importing 'math'
2020-06-23 05:50:25,453 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2020-06-23 05:50:26,062 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2020-06-23 05:50:26,093 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2020-06-23 05:50:26,140 [modules.auxiliary.screenshots] DEBUG: Imports OK
2020-06-23 05:50:26,140 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots".
2020-06-23 05:50:26,156 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.sysmon"...
2020-06-23 05:50:26,156 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon".
2020-06-23 05:50:26,156 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.usage"...
2020-06-23 05:50:26,171 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage".
2020-06-23 05:50:26,171 [root] DEBUG: Trying to initialize auxiliary module "Browser"...
2020-06-23 05:50:26,171 [root] DEBUG: Initialized auxiliary module "Browser".
2020-06-23 05:50:26,171 [root] DEBUG: Trying to start auxiliary module "Browser"...
2020-06-23 05:50:26,171 [root] DEBUG: Started auxiliary module Browser
2020-06-23 05:50:26,171 [root] DEBUG: Trying to initialize auxiliary module "Curtain"...
2020-06-23 05:50:26,171 [root] DEBUG: Initialized auxiliary module "Curtain".
2020-06-23 05:50:26,171 [root] DEBUG: Trying to start auxiliary module "Curtain"...
2020-06-23 05:50:26,171 [root] DEBUG: Started auxiliary module Curtain
2020-06-23 05:50:26,171 [root] DEBUG: Trying to initialize auxiliary module "DigiSig"...
2020-06-23 05:50:26,171 [root] DEBUG: Initialized auxiliary module "DigiSig".
2020-06-23 05:50:26,171 [root] DEBUG: Trying to start auxiliary module "DigiSig"...
2020-06-23 05:50:26,171 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature.
2020-06-23 05:50:26,968 [modules.auxiliary.digisig] DEBUG: File is not signed.
2020-06-23 05:50:26,968 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2020-06-23 05:50:26,984 [root] DEBUG: Started auxiliary module DigiSig
2020-06-23 05:50:26,984 [root] DEBUG: Trying to initialize auxiliary module "Disguise"...
2020-06-23 05:50:26,984 [root] DEBUG: Initialized auxiliary module "Disguise".
2020-06-23 05:50:26,984 [root] DEBUG: Trying to start auxiliary module "Disguise"...
2020-06-23 05:50:27,015 [root] DEBUG: Started auxiliary module Disguise
2020-06-23 05:50:27,015 [root] DEBUG: Trying to initialize auxiliary module "Human"...
2020-06-23 05:50:27,015 [root] DEBUG: Initialized auxiliary module "Human".
2020-06-23 05:50:27,015 [root] DEBUG: Trying to start auxiliary module "Human"...
2020-06-23 05:50:27,015 [root] DEBUG: Started auxiliary module Human
2020-06-23 05:50:27,015 [root] DEBUG: Trying to initialize auxiliary module "Procmon"...
2020-06-23 05:50:27,031 [root] DEBUG: Initialized auxiliary module "Procmon".
2020-06-23 05:50:27,031 [root] DEBUG: Trying to start auxiliary module "Procmon"...
2020-06-23 05:50:27,031 [root] DEBUG: Started auxiliary module Procmon
2020-06-23 05:50:27,031 [root] DEBUG: Trying to initialize auxiliary module "Screenshots"...
2020-06-23 05:50:27,031 [root] DEBUG: Initialized auxiliary module "Screenshots".
2020-06-23 05:50:27,031 [root] DEBUG: Trying to start auxiliary module "Screenshots"...
2020-06-23 05:50:27,031 [root] DEBUG: Started auxiliary module Screenshots
2020-06-23 05:50:27,031 [root] DEBUG: Trying to initialize auxiliary module "Sysmon"...
2020-06-23 05:50:27,031 [root] DEBUG: Initialized auxiliary module "Sysmon".
2020-06-23 05:50:27,031 [root] DEBUG: Trying to start auxiliary module "Sysmon"...
2020-06-23 05:50:27,031 [root] DEBUG: Started auxiliary module Sysmon
2020-06-23 05:50:27,031 [root] DEBUG: Trying to initialize auxiliary module "Usage"...
2020-06-23 05:50:27,031 [root] DEBUG: Initialized auxiliary module "Usage".
2020-06-23 05:50:27,031 [root] DEBUG: Trying to start auxiliary module "Usage"...
2020-06-23 05:50:27,046 [root] DEBUG: Started auxiliary module Usage
2020-06-23 05:50:27,046 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2020-06-23 05:50:27,046 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2020-06-23 05:50:27,046 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2020-06-23 05:50:27,046 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2020-06-23 05:50:27,187 [lib.api.process] INFO: Successfully executed process from path "C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe" with arguments "" with pid 5112
2020-06-23 05:50:27,187 [lib.api.process] INFO: Monitor config for process 5112: C:\tmpq_mrpfl7\dll\5112.ini
2020-06-23 05:50:27,187 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:50:27,249 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:50:27,249 [root] DEBUG: Loader: Injecting process 5112 (thread 3936) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:27,249 [root] DEBUG: Process image base: 0x00400000
2020-06-23 05:50:27,249 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:27,249 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2020-06-23 05:50:27,249 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:27,265 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 5112
2020-06-23 05:50:29,265 [lib.api.process] INFO: Successfully resumed process with pid 5112
2020-06-23 05:50:30,218 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 05:50:30,218 [root] DEBUG: Dropped file limit defaulting to 100.
2020-06-23 05:50:30,234 [root] DEBUG: RestoreHeaders: Restored original import table.
2020-06-23 05:50:30,234 [root] DEBUG: CAPE initialised: 32-bit monitor loaded in process 5112 at 0x6b650000, image base 0x400000, stack from 0x126000-0x130000
2020-06-23 05:50:30,234 [root] DEBUG: Commandline: C:\Users\Rebecca\AppData\Local\Temp\"C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe".
2020-06-23 05:50:30,249 [root] INFO: Loaded monitor into process with pid 5112
2020-06-23 05:50:30,249 [root] DEBUG: OpenProcessHandler: Injection info created for Pid 5112, handle 0xbc.
2020-06-23 05:50:30,265 [root] INFO: Disabling sleep skipping.
2020-06-23 05:50:30,265 [root] DEBUG: set_caller_info: Adding region at 0x003F0000 to caller regions list (ntdll::NtAllocateVirtualMemory).
2020-06-23 05:50:30,265 [root] DEBUG: set_caller_info: Adding region at 0x01450000 to caller regions list (kernel32::GetSystemTime).
2020-06-23 05:50:30,281 [root] DEBUG: DLL loaded at 0x75B30000: C:\Windows\system32\cryptbase (0xc000 bytes).
2020-06-23 05:50:30,281 [root] DEBUG: DumpMemory: Exception occured reading memory address 0x1450000
2020-06-23 05:50:30,281 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x01450000 size 0x400000.
2020-06-23 05:50:30,296 [root] DEBUG: DumpPEsInRange: Scanning range 0x1450000 - 0x1451000.
2020-06-23 05:50:30,296 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x1450000-0x1451000.
2020-06-23 05:50:30,640 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5112_11282861123050723262020 (size 0xffe)
2020-06-23 05:50:30,656 [root] DEBUG: DumpRegion: Dumped stack region from 0x01450000, size 0x1000.
2020-06-23 05:50:30,796 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5112_20808463043050723262020 (size 0x8020)
2020-06-23 05:50:30,796 [root] DEBUG: DumpRegion: Dumped stack region from 0x003F0000, size 0x9000.
2020-06-23 05:50:30,812 [root] DEBUG: set_caller_info: Adding region at 0x005D0000 to caller regions list (ntdll::memcpy).
2020-06-23 05:50:30,843 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5112_2172523803050723262020 (size 0x1a)
2020-06-23 05:50:30,843 [root] DEBUG: DumpRegion: Dumped stack region from 0x005D0000, size 0x1000.
2020-06-23 05:50:30,859 [root] INFO: Announced 32-bit process name: AlV8bUk.exe pid: 5436
2020-06-23 05:50:30,859 [lib.api.process] INFO: Monitor config for process 5436: C:\tmpq_mrpfl7\dll\5436.ini
2020-06-23 05:50:30,859 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:50:30,875 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:50:30,875 [root] DEBUG: Loader: Injecting process 5436 (thread 5400) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,875 [root] DEBUG: Process image base: 0x00400000
2020-06-23 05:50:30,890 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,890 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2020-06-23 05:50:30,890 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,890 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 5436
2020-06-23 05:50:30,890 [root] DEBUG: DLL loaded at 0x75AE0000: C:\Windows\system32\apphelp (0x4c000 bytes).
2020-06-23 05:50:30,921 [root] DEBUG: DLL unloaded from 0x00400000.
2020-06-23 05:50:30,921 [root] DEBUG: CreateProcessHandler: using lpCommandLine: "C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe" .
2020-06-23 05:50:30,921 [root] DEBUG: CreateProcessHandler: Injection info set for new process 5436, ImageBase: 0x00400000
2020-06-23 05:50:30,921 [root] INFO: Announced 32-bit process name: AlV8bUk.exe pid: 5436
2020-06-23 05:50:30,921 [lib.api.process] INFO: Monitor config for process 5436: C:\tmpq_mrpfl7\dll\5436.ini
2020-06-23 05:50:30,921 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:50:30,937 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:50:30,937 [root] DEBUG: Loader: Injecting process 5436 (thread 5400) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,937 [root] DEBUG: Process image base: 0x00400000
2020-06-23 05:50:30,937 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,937 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2020-06-23 05:50:30,953 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,953 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 5436
2020-06-23 05:50:30,953 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x104 amd local view 0x031E0000 to global list.
2020-06-23 05:50:30,953 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x104 to target process 5436.
2020-06-23 05:50:30,953 [root] INFO: Announced 32-bit process name: AlV8bUk.exe pid: 5436
2020-06-23 05:50:30,953 [lib.api.process] INFO: Monitor config for process 5436: C:\tmpq_mrpfl7\dll\5436.ini
2020-06-23 05:50:30,953 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:50:30,968 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:50:30,968 [root] DEBUG: Loader: Injecting process 5436 (thread 0) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,968 [root] DEBUG: Error 0 (0x0) - GetProcessInitialThreadId: Remote PEB 0x7FFDA000 Local PEB 0x7FFDE000 Local TEB 0x7FFDF000: The operation completed successfully.
2020-06-23 05:50:30,968 [root] DEBUG: Error 299 (0x12b) - GetProcessInitialThreadId: Failed to read from process: Only part of a ReadProcessMemory or WriteProcessMemory request was completed.
2020-06-23 05:50:30,984 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed (SessionId=1).
2020-06-23 05:50:30,984 [root] DEBUG: Failed to inject DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:30,984 [lib.api.process] ERROR: Unable to inject into 32-bit process with pid 5436, error: 4294967281
2020-06-23 05:50:30,984 [root] DEBUG: SetThreadContextHandler: Hollow process entry point reset via NtSetContextThread to 0x000A3CA0 (process 5436).
2020-06-23 05:50:30,984 [root] INFO: Announced 32-bit process name: AlV8bUk.exe pid: 5436
2020-06-23 05:50:30,984 [lib.api.process] INFO: Monitor config for process 5436: C:\tmpq_mrpfl7\dll\5436.ini
2020-06-23 05:50:31,000 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:50:31,000 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:50:31,000 [root] DEBUG: Loader: Injecting process 5436 (thread 5400) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:31,000 [root] DEBUG: Process image base: 0x00400000
2020-06-23 05:50:31,000 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:31,015 [root] DEBUG: InjectDllViaIAT: Memory region at 0x07000000 not empty.
2020-06-23 05:50:31,015 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2020-06-23 05:50:31,015 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:31,015 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 5436
2020-06-23 05:50:31,015 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x00400000.
2020-06-23 05:50:31,015 [root] DEBUG: DumpProcess: Module entry point VA is 0x000A3CA0.
2020-06-23 05:50:31,078 [root] DEBUG: DumpProcess: Module image dump success - dump size 0x30a00.
2020-06-23 05:50:31,078 [root] DEBUG: ResumeThreadHandler: Dumped PE image from buffer.
2020-06-23 05:50:31,078 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:50:31,078 [root] DEBUG: DumpSectionViewsForPid: Shared section view found with pid 5436, local address 0x031E0000.
2020-06-23 05:50:31,078 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x31e0000
2020-06-23 05:50:31,078 [root] DEBUG: DumpSectionViewsForPid: Dumping PE image from shared section view, local address 0x031E0000.
2020-06-23 05:50:31,078 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2020-06-23 05:50:31,093 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x031E0000.
2020-06-23 05:50:31,093 [root] DEBUG: DumpProcess: Module entry point VA is 0x000A3CA0.
2020-06-23 05:50:31,093 [root] DEBUG: readPeSectionsFromProcess: Failed to relocate image back to header image base 0x00400000.
2020-06-23 05:50:31,109 [root] DEBUG: DumpProcess: Module image dump success - dump size 0x30a00.
2020-06-23 05:50:31,109 [root] DEBUG: DumpSectionViewsForPid: Dumped PE image from shared section view.
2020-06-23 05:50:31,109 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x31e0001-0x3285000.
2020-06-23 05:50:31,109 [root] DEBUG: NtTerminateProcess hook: Attempting to dump process 5112
2020-06-23 05:50:31,109 [root] DEBUG: GetHookCallerBase: thread 5384 (handle 0x0), return address 0x003F36E2, allocation base 0x003F0000.
2020-06-23 05:50:31,109 [root] DEBUG: DoProcessDump: Dumping Imagebase at 0x00400000.
2020-06-23 05:50:31,109 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2020-06-23 05:50:31,125 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x00400000.
2020-06-23 05:50:31,125 [root] DEBUG: DumpProcess: Module entry point VA is 0x0006282C.
2020-06-23 05:50:31,125 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 05:50:31,125 [root] DEBUG: Dropped file limit defaulting to 100.
2020-06-23 05:50:31,140 [root] INFO: Disabling sleep skipping.
2020-06-23 05:50:31,140 [root] DEBUG: RestoreHeaders: Restored original import table.
2020-06-23 05:50:31,140 [root] DEBUG: CAPE initialised: 32-bit monitor loaded in process 5436 at 0x6b650000, image base 0x400000, stack from 0x126000-0x130000
2020-06-23 05:50:31,140 [root] DEBUG: Commandline: C:\Users\Rebecca\AppData\Local\Temp\"C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe".
2020-06-23 05:50:31,156 [root] INFO: Loaded monitor into process with pid 5436
2020-06-23 05:50:31,171 [root] DEBUG: DLL loaded at 0x73960000: C:\Windows\system32\mscoree (0x4a000 bytes).
2020-06-23 05:50:31,187 [root] DEBUG: DumpProcess: Module image dump success - dump size 0xb8a00.
2020-06-23 05:50:31,187 [root] DEBUG: DLL unloaded from 0x76730000.
2020-06-23 05:50:31,218 [root] INFO: Process with pid 5112 has terminated
2020-06-23 05:50:31,234 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xb0 amd local view 0x68450000 to global list.
2020-06-23 05:50:31,234 [root] DEBUG: DLL loaded at 0x68450000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks (0x5b1000 bytes).
2020-06-23 05:50:31,249 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xbc amd local view 0x6B570000 to global list.
2020-06-23 05:50:31,265 [root] DEBUG: DLL loaded at 0x6B570000: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80 (0x9b000 bytes).
2020-06-23 05:50:31,281 [root] DEBUG: set_caller_info: Adding region at 0x00030000 to caller regions list (advapi32::RegQueryInfoKeyW).
2020-06-23 05:50:31,281 [root] DEBUG: set_caller_info: Adding region at 0x012F0000 to caller regions list (ntdll::RtlDispatchException).
2020-06-23 05:50:31,296 [root] DEBUG: DLL loaded at 0x75B30000: C:\Windows\system32\cryptbase (0xc000 bytes).
2020-06-23 05:50:31,296 [root] DEBUG: DumpMemory: Exception occured reading memory address 0x12f0000
2020-06-23 05:50:31,296 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x012F0000 size 0x400000.
2020-06-23 05:50:31,296 [root] DEBUG: DumpPEsInRange: Scanning range 0x12f0000 - 0x12f1000.
2020-06-23 05:50:31,296 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x12f0000-0x12f1000.
2020-06-23 05:50:31,359 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_12805254723150723262020 (size 0xfa0)
2020-06-23 05:50:31,375 [root] DEBUG: DumpRegion: Dumped stack region from 0x012F0000, size 0x1000.
2020-06-23 05:50:31,375 [root] DEBUG: set_caller_info: Failed to dumping calling PE image at 0x00030000.
2020-06-23 05:50:31,390 [root] DEBUG: set_caller_info: Adding region at 0x004B0000 to caller regions list (kernel32::FindFirstFileExW).
2020-06-23 05:50:31,484 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_15112391163150723262020 (size 0x100099)
2020-06-23 05:50:31,484 [root] DEBUG: DumpRegion: Dumped stack region from 0x004B0000, size 0x101000.
2020-06-23 05:50:31,484 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x71720000 for section view with handle 0xbc.
2020-06-23 05:50:31,500 [root] DEBUG: DLL loaded at 0x71720000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x7d000 bytes).
2020-06-23 05:50:31,500 [root] DEBUG: DLL unloaded from 0x76A30000.
2020-06-23 05:50:31,515 [root] DEBUG: DLL loaded at 0x75B40000: C:\Windows\system32\sxs (0x5f000 bytes).
2020-06-23 05:50:31,546 [root] DEBUG: DLL loaded at 0x73570000: C:\Windows\system32\shfolder (0x5000 bytes).
2020-06-23 05:50:31,546 [root] DEBUG: DLL loaded at 0x76AE0000: C:\Windows\system32\SHELL32 (0xc4c000 bytes).
2020-06-23 05:50:31,546 [root] DEBUG: DLL loaded at 0x740A0000: C:\Windows\system32\iphlpapi (0x1c000 bytes).
2020-06-23 05:50:31,562 [root] DEBUG: DLL loaded at 0x77D80000: C:\Windows\system32\NSI (0x6000 bytes).
2020-06-23 05:50:31,562 [root] DEBUG: DLL loaded at 0x74060000: C:\Windows\system32\WINNSI (0x7000 bytes).
2020-06-23 05:50:31,562 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xec amd local view 0x74560000 to global list.
2020-06-23 05:50:31,562 [root] DEBUG: DLL loaded at 0x74560000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035\Gdiplus (0x192000 bytes).
2020-06-23 05:50:31,578 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x6B360000 for section view with handle 0xec.
2020-06-23 05:50:31,593 [root] DEBUG: DLL loaded at 0x6B360000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader (0x8d000 bytes).
2020-06-23 05:50:31,656 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0xf8 amd local view 0x6F470000 to global list.
2020-06-23 05:50:31,656 [root] DEBUG: DLL loaded at 0x6F470000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec (0x13000 bytes).
2020-06-23 05:50:31,671 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x75E90000 for section view with handle 0xf8.
2020-06-23 05:50:31,687 [root] DEBUG: DLL loaded at 0x75E90000: C:\Windows\system32\WINTRUST (0x2f000 bytes).
2020-06-23 05:50:31,687 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x75D60000 for section view with handle 0xf8.
2020-06-23 05:50:31,703 [root] DEBUG: DLL loaded at 0x75D60000: C:\Windows\system32\CRYPT32 (0x122000 bytes).
2020-06-23 05:50:31,703 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x75C50000 for section view with handle 0xf8.
2020-06-23 05:50:31,703 [root] DEBUG: DLL loaded at 0x75C50000: C:\Windows\system32\MSASN1 (0xc000 bytes).
2020-06-23 05:50:31,718 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x100 amd local view 0x66130000 to global list.
2020-06-23 05:50:31,718 [root] DEBUG: DLL loaded at 0x66130000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\COMCTL32 (0x84000 bytes).
2020-06-23 05:50:31,734 [root] DEBUG: OpenProcessHandler: Injection info created for Pid 5436, handle 0x110.
2020-06-23 05:50:31,734 [root] DEBUG: DLL loaded at 0x6B2E0000: C:\Windows\system32\RichEd20 (0x76000 bytes).
2020-06-23 05:50:31,734 [root] DEBUG: DLL unloaded from 0x6B2E0000.
2020-06-23 05:50:31,781 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x118 amd local view 0x02B50000 to global list.
2020-06-23 05:50:31,781 [root] DEBUG: DLL loaded at 0x750B0000: C:\Windows\system32\VERSION (0x9000 bytes).
2020-06-23 05:50:31,796 [root] DEBUG: DLL unloaded from 0x68450000.
2020-06-23 05:50:31,812 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x114 amd local view 0x6B260000 to global list.
2020-06-23 05:50:31,875 [root] DEBUG: DLL loaded at 0x6B260000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks (0xf8000 bytes).
2020-06-23 05:50:31,921 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x6E5C0000 for section view with handle 0x114.
2020-06-23 05:50:31,937 [root] DEBUG: DLL loaded at 0x6E5C0000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture (0x8000 bytes).
2020-06-23 05:50:31,937 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x6B200000 for section view with handle 0x118.
2020-06-23 05:50:31,953 [root] DEBUG: DLL loaded at 0x6B200000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit (0x5b000 bytes).
2020-06-23 05:50:31,968 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x11c amd local view 0x6B1A0000 to global list.
2020-06-23 05:50:31,968 [root] DEBUG: DLL loaded at 0x6B1A0000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc (0x55000 bytes).
2020-06-23 05:50:32,046 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x128 amd local view 0x012D0000 to global list.
2020-06-23 05:50:32,046 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x130 amd local view 0x02B00000 to global list.
2020-06-23 05:50:32,046 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:50:32,078 [root] DEBUG: DLL loaded at 0x75BE0000: C:\Windows\system32\profapi (0xb000 bytes).
2020-06-23 05:50:32,093 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:50:32,109 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1d8 amd local view 0x672E0000 to global list.
2020-06-23 05:50:32,125 [root] DEBUG: DLL loaded at 0x672E0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f8420d8c6ede777377fcff48a4beaa2a\mscorlib.ni (0xafe000 bytes).
2020-06-23 05:50:32,156 [root] DEBUG: set_caller_info: Adding region at 0x03450000 to caller regions list (kernel32::SetErrorMode).
2020-06-23 05:50:32,171 [root] DEBUG: DLL unloaded from 0x763A0000.
2020-06-23 05:50:32,187 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x348ffff
2020-06-23 05:50:32,187 [root] DEBUG: DumpMemory: Nothing to dump at 0x03450000!
2020-06-23 05:50:32,187 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x03450000 size 0x40000.
2020-06-23 05:50:32,187 [root] DEBUG: DumpPEsInRange: Scanning range 0x3450000 - 0x3451000.
2020-06-23 05:50:32,187 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x3450000-0x3451000.
2020-06-23 05:50:32,249 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_13597052793250723262020 (size 0xffe)
2020-06-23 05:50:32,249 [root] DEBUG: DumpRegion: Dumped stack region from 0x03450000, size 0x1000.
2020-06-23 05:50:32,265 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1f0 amd local view 0x02B90000 to global list.
2020-06-23 05:50:32,296 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x02BB0000 for section view with handle 0x1f0.
2020-06-23 05:50:32,328 [root] DEBUG: DLL loaded at 0x75600000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2020-06-23 05:50:32,343 [root] DEBUG: DLL loaded at 0x75390000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2020-06-23 05:50:32,609 [root] DEBUG: set_caller_info: Adding region at 0x058C0000 to caller regions list (ntdll::NtAllocateVirtualMemory).
2020-06-23 05:50:32,609 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x58cffff
2020-06-23 05:50:32,609 [root] DEBUG: DumpMemory: Nothing to dump at 0x058C0000!
2020-06-23 05:50:32,625 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x058C0000 size 0x10000.
2020-06-23 05:50:32,625 [root] DEBUG: DumpPEsInRange: Scanning range 0x58c0000 - 0x58ce000.
2020-06-23 05:50:32,625 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x58c0000-0x58ce000.
2020-06-23 05:50:32,687 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_15296080603250723262020 (size 0xd28a)
2020-06-23 05:50:32,687 [root] DEBUG: DumpRegion: Dumped stack region from 0x058C0000, size 0xe000.
2020-06-23 05:50:32,734 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x200 amd local view 0x66B30000 to global list.
2020-06-23 05:50:32,750 [root] DEBUG: DLL loaded at 0x66B30000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0a65164b17e5c64bacdc694ea2439c43\System.ni (0x7a5000 bytes).
2020-06-23 05:50:32,750 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1f8 amd local view 0x682C0000 to global list.
2020-06-23 05:50:32,765 [root] DEBUG: DLL loaded at 0x682C0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\175df210b784212def386595c25caefb\System.Drawing.ni (0x189000 bytes).
2020-06-23 05:50:32,781 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x654C0000 for section view with handle 0x1f8.
2020-06-23 05:50:32,796 [root] DEBUG: DLL loaded at 0x654C0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\5669120680b52abf616f3876387ca2cc\System.Windows.Forms.ni (0xbdf000 bytes).
2020-06-23 05:50:33,000 [root] DEBUG: set_caller_info: Adding region at 0x02B20000 to caller regions list (ntdll::memcpy).
2020-06-23 05:50:33,000 [root] DEBUG: set_caller_info: Failed to dumping calling PE image at 0x02B20000.
2020-06-23 05:50:33,046 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x02BD0000 for section view with handle 0x1f8.
2020-06-23 05:50:33,062 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x204 amd local view 0x02DC0000 to global list.
2020-06-23 05:50:33,078 [root] DEBUG: DLL loaded at 0x75750000: C:\Windows\system32\bcrypt (0x17000 bytes).
2020-06-23 05:50:33,156 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x218 amd local view 0x66990000 to global list.
2020-06-23 05:50:33,171 [root] DEBUG: DLL loaded at 0x66990000: C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4ac828c8c4c76f3ba59f8f9c7dab1cb3\Microsoft.VisualBasic.ni (0x19b000 bytes).
2020-06-23 05:50:44,390 [root] DEBUG: DLL loaded at 0x75BD0000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2020-06-23 05:50:44,484 [root] DEBUG: DLL loaded at 0x76010000: C:\Windows\system32\CLBCatQ (0x83000 bytes).
2020-06-23 05:50:44,500 [root] DEBUG: DLL loaded at 0x76500000: C:\Windows\system32\OLEAUT32 (0x91000 bytes).
2020-06-23 05:50:44,531 [root] DEBUG: DLL loaded at 0x6B530000: C:\Windows\system32\wbem\wbemdisp (0x31000 bytes).
2020-06-23 05:50:44,546 [root] DEBUG: DLL loaded at 0x6B140000: C:\Windows\system32\wbemcomn (0x5c000 bytes).
2020-06-23 05:50:44,562 [root] DEBUG: DLL loaded at 0x76750000: C:\Windows\system32\WS2_32 (0x35000 bytes).
2020-06-23 05:50:44,578 [root] INFO: Stopping WMI Service
2020-06-23 05:50:52,249 [root] INFO: Stopped WMI Service
2020-06-23 05:50:52,437 [lib.api.process] INFO: Monitor config for process 576: C:\tmpq_mrpfl7\dll\576.ini
2020-06-23 05:50:52,468 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:50:52,484 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:50:52,484 [root] DEBUG: Loader: Injecting process 576 (thread 0) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:52,484 [root] DEBUG: Error 0 (0x0) - GetProcessInitialThreadId: Remote PEB 0x7FFDB000 Local PEB 0x7FFDF000 Local TEB 0x7FFD3000: The operation completed successfully.
2020-06-23 05:50:52,484 [root] DEBUG: Error 299 (0x12b) - GetProcessInitialThreadId: Failed to read from process: Only part of a ReadProcessMemory or WriteProcessMemory request was completed.
2020-06-23 05:50:52,484 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2020-06-23 05:50:52,500 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 05:50:52,500 [root] DEBUG: Dropped file limit defaulting to 100.
2020-06-23 05:50:52,515 [root] INFO: Disabling sleep skipping.
2020-06-23 05:50:52,515 [root] DEBUG: CAPE initialised: 32-bit monitor loaded in process 576 at 0x6b650000, image base 0x3c0000, stack from 0x1156000-0x1160000
2020-06-23 05:50:52,609 [root] DEBUG: Commandline: C:\Windows\System32\svchost.exe -k DcomLaunch.
2020-06-23 05:50:52,640 [root] INFO: Loaded monitor into process with pid 576
2020-06-23 05:50:52,640 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2020-06-23 05:50:52,656 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2020-06-23 05:50:52,656 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:54,671 [root] INFO: Starting WMI Service
2020-06-23 05:50:56,750 [root] INFO: Started WMI Service
2020-06-23 05:50:56,796 [lib.api.process] INFO: Monitor config for process 6036: C:\tmpq_mrpfl7\dll\6036.ini
2020-06-23 05:50:56,796 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:50:56,828 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:50:56,828 [root] DEBUG: Loader: Injecting process 6036 (thread 0) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:56,828 [root] DEBUG: Error 0 (0x0) - GetProcessInitialThreadId: Remote PEB 0x7FFD5000 Local PEB 0x7FFDE000 Local TEB 0x7FFDF000: The operation completed successfully.
2020-06-23 05:50:56,843 [root] DEBUG: Error 299 (0x12b) - GetProcessInitialThreadId: Failed to read from process: Only part of a ReadProcessMemory or WriteProcessMemory request was completed.
2020-06-23 05:50:56,843 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2020-06-23 05:50:56,859 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 05:50:56,859 [root] DEBUG: Dropped file limit defaulting to 100.
2020-06-23 05:50:56,859 [root] INFO: Disabling sleep skipping.
2020-06-23 05:50:56,859 [root] DEBUG: CAPE initialised: 32-bit monitor loaded in process 6036 at 0x6b650000, image base 0x3c0000, stack from 0x6c6000-0x6d0000
2020-06-23 05:50:56,859 [root] DEBUG: Commandline: C:\Windows\System32\svchost.exe -k netsvcs.
2020-06-23 05:50:56,875 [root] INFO: Loaded monitor into process with pid 6036
2020-06-23 05:50:56,875 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2020-06-23 05:50:56,875 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2020-06-23 05:50:56,906 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:50:58,906 [root] DEBUG: DLL loaded at 0x6EE20000: C:\Windows\system32\wbem\wbemprox (0xb000 bytes).
2020-06-23 05:50:58,921 [root] DEBUG: DLL loaded at 0x6F590000: C:\Windows\system32\wbemcomn2 (0x61000 bytes).
2020-06-23 05:50:58,937 [root] DEBUG: DLL loaded at 0x6E500000: C:\Windows\system32\wbem\wmiutils (0x1a000 bytes).
2020-06-23 05:50:58,953 [root] DEBUG: DLL loaded at 0x6F600000: C:\Windows\system32\VSSAPI (0x116000 bytes).
2020-06-23 05:50:58,953 [root] DEBUG: DLL loaded at 0x74230000: C:\Windows\system32\ATL (0x14000 bytes).
2020-06-23 05:50:58,968 [root] DEBUG: DLL loaded at 0x70F90000: C:\Windows\system32\VssTrace (0x10000 bytes).
2020-06-23 05:50:58,968 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x1bc amd local view 0x00560000 to global list.
2020-06-23 05:50:58,968 [root] DEBUG: DLL loaded at 0x73B00000: C:\Windows\system32\samcli (0xf000 bytes).
2020-06-23 05:50:59,000 [root] DEBUG: DLL loaded at 0x74700000: C:\Windows\system32\SAMLIB (0x12000 bytes).
2020-06-23 05:50:59,000 [root] DEBUG: DLL loaded at 0x74970000: C:\Windows\system32\netutils (0x9000 bytes).
2020-06-23 05:50:59,015 [root] DEBUG: DLL loaded at 0x74190000: C:\Windows\system32\es (0x47000 bytes).
2020-06-23 05:50:59,031 [root] DEBUG: DLL loaded at 0x747E0000: C:\Windows\system32\PROPSYS (0xf5000 bytes).
2020-06-23 05:50:59,046 [root] DEBUG: DLL loaded at 0x6EAE0000: C:\Windows\system32\wbem\wbemcore (0xf1000 bytes).
2020-06-23 05:50:59,062 [root] DEBUG: DLL loaded at 0x750B0000: C:\Windows\system32\VERSION (0x9000 bytes).
2020-06-23 05:50:59,078 [root] DEBUG: DLL loaded at 0x6E9F0000: C:\Windows\system32\wbem\esscli (0x4a000 bytes).
2020-06-23 05:50:59,093 [root] DEBUG: DLL loaded at 0x6F0C0000: C:\Windows\system32\wbem\FastProx (0xa6000 bytes).
2020-06-23 05:50:59,093 [root] DEBUG: DLL loaded at 0x6F020000: C:\Windows\system32\NTDSAPI (0x18000 bytes).
2020-06-23 05:50:59,093 [root] DEBUG: DLL unloaded from 0x6EAE0000.
2020-06-23 05:50:59,093 [root] DEBUG: DLL loaded at 0x6E580000: C:\Windows\system32\wbem\wbemsvc (0xf000 bytes).
2020-06-23 05:50:59,156 [root] DEBUG: DLL loaded at 0x6E580000: C:\Windows\system32\wbem\wbemsvc (0xf000 bytes).
2020-06-23 05:50:59,203 [root] DEBUG: DLL loaded at 0x757B0000: C:\Windows\system32\authZ (0x1b000 bytes).
2020-06-23 05:50:59,218 [root] DEBUG: DLL loaded at 0x6E500000: C:\Windows\system32\wbem\wmiutils (0x1a000 bytes).
2020-06-23 05:50:59,265 [root] DEBUG: DLL unloaded from 0x75800000.
2020-06-23 05:50:59,671 [root] DEBUG: DLL loaded at 0x6DC00000: C:\Windows\system32\wbem\wmiprvsd (0x91000 bytes).
2020-06-23 05:50:59,687 [root] DEBUG: DLL loaded at 0x6DBD0000: C:\Windows\system32\NCObjAPI (0xf000 bytes).
2020-06-23 05:50:59,703 [root] DEBUG: OpenProcessHandler: Injection info created for Pid 576, handle 0x2c8.
2020-06-23 05:50:59,718 [root] DEBUG: DLL loaded at 0x6C010000: C:\Windows\system32\wbem\wbemess (0x5b000 bytes).
2020-06-23 05:51:00,000 [root] DEBUG: DLL loaded at 0x6F0C0000: C:\Windows\system32\wbem\fastprox (0xa6000 bytes).
2020-06-23 05:51:00,109 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x2e0 amd local view 0x033D0000 to global list.
2020-06-23 05:51:00,125 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x2d0 amd local view 0x05ED0000 to global list.
2020-06-23 05:51:00,171 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x2e4 amd local view 0x6F050000 to global list.
2020-06-23 05:51:00,171 [root] DEBUG: DLL loaded at 0x6F050000: C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\aa404966f6e5a3d1f9d0fe3ba1d13ec1\CustomMarshalers.ni (0x3a000 bytes).
2020-06-23 05:51:00,187 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x73810000 for section view with handle 0x2e4.
2020-06-23 05:51:00,187 [root] DEBUG: DLL loaded at 0x6F750000: C:\Windows\system32\wbem\ncprov (0x12000 bytes).
2020-06-23 05:51:00,187 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x033E0000 for section view with handle 0x2e4.
2020-06-23 05:51:00,203 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x2f0 amd local view 0x73810000 to global list.
2020-06-23 05:51:00,343 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x2f4 amd local view 0x03410000 to global list.
2020-06-23 05:51:00,359 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x03410000 for section view with handle 0x2f0.
2020-06-23 05:51:00,421 [root] DEBUG: DLL unloaded from 0x6EAE0000.
2020-06-23 05:51:00,546 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x6B030000 for section view with handle 0x2f0.
2020-06-23 05:51:00,562 [root] DEBUG: DLL loaded at 0x6B030000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\81ab4c39c6a7c9f50721aca2db09b417\System.Management.ni (0x106000 bytes).
2020-06-23 05:51:01,031 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:51:01,218 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:51:01,281 [root] DEBUG: set_caller_info: Adding region at 0x03420000 to caller regions list (ntdll::LdrLoadDll).
2020-06-23 05:51:01,281 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x342ffff
2020-06-23 05:51:01,281 [root] DEBUG: DumpMemory: Nothing to dump at 0x03420000!
2020-06-23 05:51:01,296 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x03420000 size 0x10000.
2020-06-23 05:51:01,296 [root] DEBUG: DumpPEsInRange: Scanning range 0x3420000 - 0x3421000.
2020-06-23 05:51:01,296 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x3420000-0x3421000.
2020-06-23 05:51:01,406 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_343644968153723262020 (size 0xe5)
2020-06-23 05:51:01,437 [root] DEBUG: DumpRegion: Dumped stack region from 0x03420000, size 0x1000.
2020-06-23 05:51:01,453 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x34c amd local view 0x6F570000 to global list.
2020-06-23 05:51:01,468 [root] DEBUG: DLL loaded at 0x6F570000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils (0x1e000 bytes).
2020-06-23 05:51:01,484 [root] DEBUG: set_caller_info: Adding region at 0x03440000 to caller regions list (ole32::CoCreateInstance).
2020-06-23 05:51:01,500 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x344ffff
2020-06-23 05:51:01,500 [root] DEBUG: DumpMemory: Nothing to dump at 0x03440000!
2020-06-23 05:51:01,500 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x03440000 size 0x10000.
2020-06-23 05:51:01,500 [root] DEBUG: DumpPEsInRange: Scanning range 0x3440000 - 0x3444000.
2020-06-23 05:51:01,500 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x3440000-0x3444000.
2020-06-23 05:51:01,531 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_400306956153723262020 (size 0x3a88)
2020-06-23 05:51:01,546 [root] DEBUG: DumpRegion: Dumped stack region from 0x03440000, size 0x4000.
2020-06-23 05:51:03,234 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:51:09,359 [root] INFO: Added new file to list with pid None and path C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe
2020-06-23 05:51:16,328 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:51:16,328 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x404 amd local view 0x033C0000 to global list.
2020-06-23 05:51:16,328 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x340 amd local view 0x05860000 to global list.
2020-06-23 05:51:16,343 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x033C0000 for section view with handle 0x340.
2020-06-23 05:51:16,343 [root] DEBUG: MapSectionViewHandler: Updated local view to 0x05860000 for section view with handle 0x404.
2020-06-23 05:51:24,406 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:51:24,453 [root] DEBUG: set_caller_info: Adding region at 0x05FF0000 to caller regions list (kernel32::SetErrorMode).
2020-06-23 05:51:24,453 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x5ffffff
2020-06-23 05:51:24,453 [root] DEBUG: DumpMemory: Nothing to dump at 0x05FF0000!
2020-06-23 05:51:24,468 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x05FF0000 size 0x10000.
2020-06-23 05:51:24,468 [root] DEBUG: DumpPEsInRange: Scanning range 0x5ff0000 - 0x5ff4000.
2020-06-23 05:51:24,468 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x5ff0000-0x5ff4000.
2020-06-23 05:51:24,500 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_964014212546823262020 (size 0x377b)
2020-06-23 05:51:24,500 [root] DEBUG: DumpRegion: Dumped stack region from 0x05FF0000, size 0x4000.
2020-06-23 05:51:24,656 [root] DEBUG: DLL loaded at 0x6EE40000: C:\Windows\system32\wshom.ocx (0x21000 bytes).
2020-06-23 05:51:24,656 [root] DEBUG: DLL loaded at 0x72260000: C:\Windows\system32\MPR (0x12000 bytes).
2020-06-23 05:51:24,671 [root] DEBUG: DLL loaded at 0x6DA00000: C:\Windows\system32\ScrRun (0x2a000 bytes).
2020-06-23 05:51:24,718 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x42c amd local view 0x033C0000 to global list.
2020-06-23 05:51:24,734 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x41c amd local view 0x05870000 to global list.
2020-06-23 05:51:24,843 [root] DEBUG: DLL unloaded from 0x6E5C0000.
2020-06-23 05:51:24,906 [root] DEBUG: set_caller_info: Adding region at 0x05FE0000 to caller regions list (kernel32::SetErrorMode).
2020-06-23 05:51:24,921 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x5feffff
2020-06-23 05:51:24,921 [root] DEBUG: DumpMemory: Nothing to dump at 0x05FE0000!
2020-06-23 05:51:24,921 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x05FE0000 size 0x10000.
2020-06-23 05:51:24,921 [root] DEBUG: DumpPEsInRange: Scanning range 0x5fe0000 - 0x5fe3000.
2020-06-23 05:51:24,921 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x5fe0000-0x5fe3000.
2020-06-23 05:51:24,968 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_679392250546823262020 (size 0x2253)
2020-06-23 05:51:24,984 [root] DEBUG: DumpRegion: Dumped stack region from 0x05FE0000, size 0x3000.
2020-06-23 05:51:25,015 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x424 amd local view 0x058A0000 to global list.
2020-06-23 05:51:25,187 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x434 amd local view 0x66450000 to global list.
2020-06-23 05:51:25,187 [root] DEBUG: DLL loaded at 0x66450000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b065f84b49a27b648015c08fab8cd00e\System.Xml.ni (0x53b000 bytes).
2020-06-23 05:51:25,203 [root] DEBUG: set_caller_info: Adding region at 0x05F90000 to caller regions list (ntdll::NtQueryPerformanceCounter).
2020-06-23 05:51:25,203 [root] DEBUG: ScanForNonZero: Exception occured reading memory address 0x5f9ffff
2020-06-23 05:51:25,218 [root] DEBUG: DumpMemory: Nothing to dump at 0x05F90000!
2020-06-23 05:51:25,218 [root] DEBUG: DumpRegion: Failed to dump entire allocation from 0x05F90000 size 0x10000.
2020-06-23 05:51:25,218 [root] DEBUG: DumpPEsInRange: Scanning range 0x5f90000 - 0x5f91000.
2020-06-23 05:51:25,234 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x5f90000-0x5f91000.
2020-06-23 05:51:25,249 [root] DEBUG: DumpMemory: CAPE output file successfully created: C:\sUsoAPg\CAPE\5436_1288284504556823262020 (size 0x417)
2020-06-23 05:51:25,249 [root] DEBUG: DumpRegion: Dumped stack region from 0x05F90000, size 0x1000.
2020-06-23 05:51:25,296 [root] DEBUG: DLL loaded at 0x6F040000: C:\Windows\system32\vaultcli (0xc000 bytes).
2020-06-23 05:51:25,296 [root] DEBUG: DLL unloaded from 0x77D90000.
2020-06-23 05:51:25,390 [root] INFO: Announced starting service "b'VaultSvc'"
2020-06-23 05:51:25,390 [lib.api.process] INFO: Monitor config for process 460: C:\tmpq_mrpfl7\dll\460.ini
2020-06-23 05:51:25,421 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:51:25,437 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:51:25,437 [root] DEBUG: Loader: Injecting process 460 (thread 0) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:51:25,453 [root] DEBUG: Error 0 (0x0) - GetProcessInitialThreadId: Remote PEB 0x7FFD9000 Local PEB 0x7FFDF000 Local TEB 0x7FFD4000: The operation completed successfully.
2020-06-23 05:51:25,453 [root] DEBUG: Error 299 (0x12b) - GetProcessInitialThreadId: Failed to read from process: Only part of a ReadProcessMemory or WriteProcessMemory request was completed.
2020-06-23 05:51:25,453 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2020-06-23 05:51:25,468 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 05:51:25,468 [root] DEBUG: Dropped file limit defaulting to 100.
2020-06-23 05:51:25,484 [root] INFO: Disabling sleep skipping.
2020-06-23 05:51:25,484 [root] DEBUG: CAPE initialised: 32-bit monitor loaded in process 460 at 0x6b650000, image base 0xd00000, stack from 0x1b26000-0x1b30000
2020-06-23 05:51:25,484 [root] DEBUG: Commandline: C:\Windows\System32\services.exe.
2020-06-23 05:51:25,500 [root] INFO: Loaded monitor into process with pid 460
2020-06-23 05:51:25,500 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2020-06-23 05:51:25,500 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2020-06-23 05:51:25,500 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:51:30,000 [root] INFO: Announced 32-bit process name: lsass.exe pid: 4792
2020-06-23 05:51:30,000 [lib.api.process] INFO: Monitor config for process 4792: C:\tmpq_mrpfl7\dll\4792.ini
2020-06-23 05:51:30,078 [root] DEBUG: DLL unloaded from 0x763A0000.
2020-06-23 05:51:30,078 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpq_mrpfl7\dll\CPJiMhRK.dll, loader C:\tmpq_mrpfl7\bin\dPADHtf.exe
2020-06-23 05:51:55,296 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\qQwmnKNu.
2020-06-23 05:52:00,187 [root] DEBUG: Loader: Injecting process 4792 (thread 6104) with C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:52:00,281 [root] DEBUG: Process image base: 0x00830000
2020-06-23 05:52:06,218 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:52:06,249 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2020-06-23 05:52:12,234 [root] DEBUG: Successfully injected DLL C:\tmpq_mrpfl7\dll\CPJiMhRK.dll.
2020-06-23 05:52:18,218 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 4792
2020-06-23 05:52:18,296 [root] DEBUG: CreateProcessHandler: using lpCommandLine: C:\Windows\system32\lsass.exe.
2020-06-23 05:52:24,187 [root] DEBUG: Python path set to 'C:\Users\Rebecca\AppData\Local\Programs\Python\Python38-32'.
2020-06-23 05:52:24,546 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:52:30,203 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:52:30,281 [root] DEBUG: DLL loaded at 0x73E10000: C:\Windows\system32\WindowsCodecs (0x131000 bytes).
2020-06-23 05:52:48,328 [root] INFO: Process with pid 4792 has terminated
2020-06-23 05:52:55,406 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x478 amd local view 0x68B60000 to global list.
2020-06-23 05:52:55,453 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:53:00,187 [root] DEBUG: DLL loaded at 0x68B60000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\51fb28e8a54a8d8f6021415d47477ab4\System.Security.ni (0xb3000 bytes).
2020-06-23 05:53:36,187 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x398 amd local view 0x6AC30000 to global list.
2020-06-23 05:53:36,359 [root] DEBUG: DLL loaded at 0x75480000: C:\Windows\system32\DNSAPI (0x44000 bytes).
2020-06-23 05:53:36,468 [root] DEBUG: DLL loaded at 0x73F70000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes).
2020-06-23 05:53:40,890 [root] DEBUG: DLL loaded at 0x73F50000: C:\Windows\system32\dhcpcsvc (0x12000 bytes).
2020-06-23 05:53:40,968 [root] DEBUG: DLL loaded at 0x755C0000: C:\Windows\system32\mswsock (0x3c000 bytes).
2020-06-23 05:53:40,984 [root] DEBUG: DLL loaded at 0x75140000: C:\Windows\System32\wshtcpip (0x5000 bytes).
2020-06-23 05:53:40,984 [root] DEBUG: DLL loaded at 0x755B0000: C:\Windows\System32\wship6 (0x6000 bytes).
2020-06-23 05:53:41,000 [root] DEBUG: MapSectionViewHandler: Added section view with handle 0x4f0 amd local view 0x033C0000 to global list.
2020-06-23 05:53:41,015 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:53:41,031 [root] DEBUG: DLL loaded at 0x72290000: C:\Windows\system32\rasadhlp (0x6000 bytes).
2020-06-23 05:53:41,328 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:53:49,421 [root] INFO: Analysis timeout hit, terminating analysis.
2020-06-23 05:53:49,421 [lib.api.process] INFO: Terminate event set for process 5436
2020-06-23 05:53:49,484 [root] DEBUG: Terminate Event: Attempting to dump process 5436
2020-06-23 05:53:49,500 [lib.api.process] INFO: Termination confirmed for process 5436
2020-06-23 05:53:49,500 [root] INFO: Terminate event set for process 5436.
2020-06-23 05:53:49,500 [lib.api.process] INFO: Terminate event set for process 576
2020-06-23 05:53:49,546 [lib.api.process] INFO: Termination confirmed for process 576
2020-06-23 05:53:49,546 [root] INFO: Terminate event set for process 576.
2020-06-23 05:53:49,546 [lib.api.process] INFO: Terminate event set for process 6036
2020-06-23 05:53:49,546 [root] DEBUG: Terminate Event: Attempting to dump process 6036
2020-06-23 05:53:49,546 [root] DEBUG: DoProcessDump: Dumping Imagebase at 0x003C0000.
2020-06-23 05:53:49,562 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2020-06-23 05:53:49,562 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x003C0000.
2020-06-23 05:53:52,671 [root] DEBUG: DumpProcess: Module image dump success - dump size 0x5200.
2020-06-23 05:53:52,671 [lib.api.process] INFO: Termination confirmed for process 6036
2020-06-23 05:53:52,671 [root] INFO: Terminate event set for process 6036.
2020-06-23 05:53:58,187 [lib.api.process] INFO: Terminate event set for process 460
2020-06-23 05:53:58,187 [root] DEBUG: Terminate Event: Attempting to dump process 460
2020-06-23 05:54:00,375 [lib.api.process] INFO: Termination confirmed for process 460
2020-06-23 05:54:00,375 [root] INFO: Terminate event set for process 460.
2020-06-23 05:54:00,375 [root] INFO: Created shutdown mutex.
2020-06-23 05:54:01,375 [root] INFO: Shutting down package.
2020-06-23 05:54:01,375 [root] INFO: Stopping auxiliary modules.
2020-06-23 05:54:10,765 [root] DEBUG: ResumeThreadHandler: Dumping section view for process 5436.
2020-06-23 05:54:22,656 [lib.common.results] WARNING: File C:\sUsoAPg\bin\procmon.xml doesn't exist anymore
2020-06-23 05:54:22,656 [root] INFO: Finishing auxiliary modules.
2020-06-23 05:54:22,656 [root] INFO: Shutting down pipe server and dumping dropped files.
2020-06-23 05:54:28,234 [root] WARNING: Folder at path "C:\sUsoAPg\debugger" does not exist, skip.
2020-06-23 05:54:28,249 [root] WARNING: Monitor injection attempted but failed for process 4792.
2020-06-23 05:54:28,249 [root] INFO: Analysis completed.

Machine

Name Label Manager Started On Shutdown On
win7_4 win7_4 KVM 2020-06-23 05:50:28 2020-06-23 05:55:51

File Details

File Name AlV8bUk
File Size 753152 bytes
File Type PE32 executable (GUI) Intel 80386, for MS Windows
PE timestamp 1992-06-19 22:22:17
MD5 6b05795f7de00b9b9cf3fe9c84c62daf
SHA1 3e6aa59e8c6f128730542b23a8e877d96c7dcf36
SHA256 738067ec907f78255aef1b88b13f915ceb174d620a98f37549cc22f38e5898c6
SHA512 0b6f5aee5f25f9779c4e11e033c06f9dabc99b32eb5da7ac91dcc33c8d296feadaaa6d0eeb969bc78849484f29ae41c0cc12205f45d50fc9bc1b8f450edfd987
CRC32 0C1C74B3
Ssdeep 12288:dDRuXrEbb00e9ElcwOixtthKGc7WR5Sc7YpDqIp9fJYFdqkqweNhFHQ:hYbQhe9RKthmg5ANaFJMbFw
Download Download ZIP Resubmit sample

Signatures

Behavioural detection: Executable code extraction - unpacking
SetUnhandledExceptionFilter detected (possible anti-debug)
Yara rule detections observed from a process memory dump/dropped files/CAPE
Hit: PID 5112 trigged the Yara rule 'shellcode_patterns'
Creates RWX memory
Possible date expiration check, exits too soon after checking local time
process: AlV8bUk.exe, PID 5112
Guard pages use detected - possible anti-debugging.
A process attempted to delay the analysis task.
Process: AlV8bUk.exe tried to sleep 1556.52 seconds, actually delayed analysis time by 0.0 seconds
Dynamic (imported) function loading detected
DynamicLoader: IMM32.DLL/ImmCreateContext
DynamicLoader: IMM32.DLL/ImmDestroyContext
DynamicLoader: IMM32.DLL/ImmNotifyIME
DynamicLoader: IMM32.DLL/ImmAssociateContext
DynamicLoader: IMM32.DLL/ImmReleaseContext
DynamicLoader: IMM32.DLL/ImmGetContext
DynamicLoader: IMM32.DLL/ImmGetCompositionStringA
DynamicLoader: IMM32.DLL/ImmSetCompositionStringA
DynamicLoader: IMM32.DLL/ImmGetCompositionStringW
DynamicLoader: IMM32.DLL/ImmSetCompositionStringW
DynamicLoader: IMM32.DLL/ImmSetCandidateWindow
DynamicLoader: kernel32.dll/GetDiskFreeSpaceExA
DynamicLoader: oleaut32.dll/VariantChangeTypeEx
DynamicLoader: oleaut32.dll/VarNeg
DynamicLoader: oleaut32.dll/VarNot
DynamicLoader: oleaut32.dll/VarAdd
DynamicLoader: oleaut32.dll/VarSub
DynamicLoader: oleaut32.dll/VarMul
DynamicLoader: oleaut32.dll/VarDiv
DynamicLoader: oleaut32.dll/VarIdiv
DynamicLoader: oleaut32.dll/VarMod
DynamicLoader: oleaut32.dll/VarAnd
DynamicLoader: oleaut32.dll/VarOr
DynamicLoader: oleaut32.dll/VarXor
DynamicLoader: oleaut32.dll/VarCmp
DynamicLoader: oleaut32.dll/VarI4FromStr
DynamicLoader: oleaut32.dll/VarR4FromStr
DynamicLoader: oleaut32.dll/VarR8FromStr
DynamicLoader: oleaut32.dll/VarDateFromStr
DynamicLoader: oleaut32.dll/VarCyFromStr
DynamicLoader: oleaut32.dll/VarBoolFromStr
DynamicLoader: oleaut32.dll/VarBstrFromCy
DynamicLoader: oleaut32.dll/VarBstrFromDate
DynamicLoader: oleaut32.dll/VarBstrFromBool
DynamicLoader: USER32.dll/GetMonitorInfoA
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: USER32.dll/EnumDisplayMonitors
DynamicLoader: USER32.dll/AnimateWindow
DynamicLoader: comctl32.dll/InitializeFlatSB
DynamicLoader: comctl32.dll/UninitializeFlatSB
DynamicLoader: comctl32.dll/FlatSB_GetScrollProp
DynamicLoader: comctl32.dll/FlatSB_SetScrollProp
DynamicLoader: comctl32.dll/FlatSB_EnableScrollBar
DynamicLoader: comctl32.dll/FlatSB_ShowScrollBar
DynamicLoader: comctl32.dll/FlatSB_GetScrollRange
DynamicLoader: comctl32.dll/FlatSB_GetScrollInfo
DynamicLoader: comctl32.dll/FlatSB_GetScrollPos
DynamicLoader: comctl32.dll/FlatSB_SetScrollPos
DynamicLoader: comctl32.dll/FlatSB_SetScrollInfo
DynamicLoader: comctl32.dll/FlatSB_SetScrollRange
DynamicLoader: USER32.dll/SetLayeredWindowAttributes
DynamicLoader: kernel32.dll/FileTimeToSystemTime
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: kernel32.dll/VirtualFree
DynamicLoader: kernel32.dll/LoadLibraryW
DynamicLoader: kernel32.dll/SizeofResource
DynamicLoader: kernel32.dll/GetModuleFileNameW
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/MultiByteToWideChar
DynamicLoader: kernel32.dll/FlushInstructionCache
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/VirtualAlloc
DynamicLoader: kernel32.dll/LoadLibraryA
DynamicLoader: kernel32.dll/GetModuleFileNameA
DynamicLoader: kernel32.dll/GetModuleHandleA
DynamicLoader: kernel32.dll/VirtualProtect
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/LoadResource
DynamicLoader: kernel32.dll/FindResourceW
DynamicLoader: kernel32.dll/GetProcAddress
DynamicLoader: kernel32.dll/GetFileSize
DynamicLoader: kernel32.dll/LCMapStringW
DynamicLoader: kernel32.dll/LCMapStringA
DynamicLoader: kernel32.dll/GetStringTypeW
DynamicLoader: kernel32.dll/GetStringTypeA
DynamicLoader: kernel32.dll/HeapAlloc
DynamicLoader: kernel32.dll/GetStartupInfoW
DynamicLoader: kernel32.dll/DeleteCriticalSection
DynamicLoader: kernel32.dll/LeaveCriticalSection
DynamicLoader: kernel32.dll/EnterCriticalSection
DynamicLoader: kernel32.dll/HeapFree
DynamicLoader: kernel32.dll/HeapReAlloc
DynamicLoader: kernel32.dll/HeapCreate
DynamicLoader: kernel32.dll/Sleep
DynamicLoader: kernel32.dll/ExitProcess
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/GetStdHandle
DynamicLoader: kernel32.dll/SetUnhandledExceptionFilter
DynamicLoader: kernel32.dll/FreeEnvironmentStringsW
DynamicLoader: kernel32.dll/GetEnvironmentStringsW
DynamicLoader: kernel32.dll/GetCommandLineW
DynamicLoader: kernel32.dll/SetHandleCount
DynamicLoader: kernel32.dll/GetFileType
DynamicLoader: kernel32.dll/GetStartupInfoA
DynamicLoader: kernel32.dll/TlsGetValue
DynamicLoader: kernel32.dll/TlsAlloc
DynamicLoader: kernel32.dll/TlsSetValue
DynamicLoader: kernel32.dll/TlsFree
DynamicLoader: kernel32.dll/InterlockedIncrement
DynamicLoader: kernel32.dll/SetLastError
DynamicLoader: kernel32.dll/GetCurrentThreadId
DynamicLoader: kernel32.dll/GetLastError
DynamicLoader: kernel32.dll/InterlockedDecrement
DynamicLoader: kernel32.dll/QueryPerformanceCounter
DynamicLoader: kernel32.dll/GetTickCount
DynamicLoader: kernel32.dll/GetCurrentProcessId
DynamicLoader: kernel32.dll/GetSystemTimeAsFileTime
DynamicLoader: kernel32.dll/InitializeCriticalSectionAndSpinCount
DynamicLoader: kernel32.dll/TerminateProcess
DynamicLoader: kernel32.dll/UnhandledExceptionFilter
DynamicLoader: kernel32.dll/IsDebuggerPresent
DynamicLoader: kernel32.dll/RtlUnwind
DynamicLoader: kernel32.dll/GetCPInfo
DynamicLoader: kernel32.dll/GetACP
DynamicLoader: kernel32.dll/GetOEMCP
DynamicLoader: kernel32.dll/IsValidCodePage
DynamicLoader: kernel32.dll/HeapSize
DynamicLoader: kernel32.dll/GetLocaleInfoA
DynamicLoader: kernel32.dll/WideCharToMultiByte
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: PSAPI.DLL/GetModuleInformation
DynamicLoader: PSAPI.DLL/GetModuleBaseNameW
DynamicLoader: PSAPI.DLL/EnumProcessModules
DynamicLoader: SHLWAPI.dll/StrStrIW
DynamicLoader: SHLWAPI.dll/PathFileExistsW
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: mscoree.dll/_CorExeMain
DynamicLoader: mscoree.dll/_CorExeMain
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/InitializeCriticalSectionAndSpinCount
DynamicLoader: kernel32.dll/IsProcessorFeaturePresent
DynamicLoader: msvcrt.dll/_set_error_mode
DynamicLoader: msvcrt.dll/[email protected]@[email protected]
DynamicLoader: msvcrt.dll/_get_terminate
DynamicLoader: kernel32.dll/FindActCtxSectionStringW
DynamicLoader: kernel32.dll/GetSystemWindowsDirectoryW
DynamicLoader: mscoree.dll/GetProcessExecutableHeap
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/InitializeCriticalSectionEx
DynamicLoader: kernel32.dll/CreateEventExW
DynamicLoader: kernel32.dll/CreateSemaphoreExW
DynamicLoader: kernel32.dll/SetThreadStackGuarantee
DynamicLoader: kernel32.dll/CreateThreadpoolTimer
DynamicLoader: kernel32.dll/SetThreadpoolTimer
DynamicLoader: kernel32.dll/WaitForThreadpoolTimerCallbacks
DynamicLoader: kernel32.dll/CloseThreadpoolTimer
DynamicLoader: kernel32.dll/CreateThreadpoolWait
DynamicLoader: kernel32.dll/SetThreadpoolWait
DynamicLoader: kernel32.dll/CloseThreadpoolWait
DynamicLoader: kernel32.dll/FlushProcessWriteBuffers
DynamicLoader: kernel32.dll/FreeLibraryWhenCallbackReturns
DynamicLoader: kernel32.dll/GetCurrentProcessorNumber
DynamicLoader: kernel32.dll/GetLogicalProcessorInformation
DynamicLoader: kernel32.dll/CreateSymbolicLinkW
DynamicLoader: kernel32.dll/SetDefaultDllDirectories
DynamicLoader: kernel32.dll/EnumSystemLocalesEx
DynamicLoader: kernel32.dll/CompareStringEx
DynamicLoader: kernel32.dll/GetDateFormatEx
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/GetTimeFormatEx
DynamicLoader: kernel32.dll/GetUserDefaultLocaleName
DynamicLoader: kernel32.dll/IsValidLocaleName
DynamicLoader: kernel32.dll/LCMapStringEx
DynamicLoader: kernel32.dll/GetCurrentPackageId
DynamicLoader: kernel32.dll/GetTickCount64
DynamicLoader: kernel32.dll/GetFileInformationByHandleExW
DynamicLoader: kernel32.dll/SetFileInformationByHandleW
DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
DynamicLoader: ADVAPI32.dll/EventRegister
DynamicLoader: ADVAPI32.dll/EventSetInformation
DynamicLoader: mscoree.dll/
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: mscoreei.dll/RegisterShimImplCallback
DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
DynamicLoader: mscoreei.dll/SetShellShimInstance
DynamicLoader: mscoreei.dll/OnShimDllMainCalled
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: KERNELBASE.dll/InitializeCriticalSectionAndSpinCount
DynamicLoader: kernel32.dll/ProcessIdToSessionId
DynamicLoader: IMM32.DLL/ImmCreateContext
DynamicLoader: IMM32.DLL/ImmDestroyContext
DynamicLoader: IMM32.DLL/ImmNotifyIME
DynamicLoader: IMM32.DLL/ImmAssociateContext
DynamicLoader: IMM32.DLL/ImmReleaseContext
DynamicLoader: IMM32.DLL/ImmGetContext
DynamicLoader: IMM32.DLL/ImmGetCompositionStringA
DynamicLoader: IMM32.DLL/ImmSetCompositionStringA
DynamicLoader: IMM32.DLL/ImmGetCompositionStringW
DynamicLoader: IMM32.DLL/ImmSetCompositionStringW
DynamicLoader: IMM32.DLL/ImmSetCandidateWindow
DynamicLoader: mscorwks.dll/GetCLRFunction
DynamicLoader: mscoree.dll/IEE
DynamicLoader: mscoreei.dll/IEE_RetAddr
DynamicLoader: mscoreei.dll/IEE
DynamicLoader: SHLWAPI.dll/UrlIsW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
DynamicLoader: VERSION.dll/GetFileVersionInfoW
DynamicLoader: VERSION.dll/VerQueryValueW
DynamicLoader: mscorwks.dll/SetLoadedByMscoree
DynamicLoader: USER32.dll/GetProcessWindowStation
DynamicLoader: USER32.dll/GetUserObjectInformationW
DynamicLoader: mscorwks.dll/IEE
DynamicLoader: mscorwks.dll/GetCLRFunction
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/InitializeCriticalSectionAndSpinCount
DynamicLoader: kernel32.dll/IsProcessorFeaturePresent
DynamicLoader: kernel32.dll/GetModuleHandleA
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: kernel32.dll/GetModuleFileNameW
DynamicLoader: kernel32.dll/GetModuleFileNameA
DynamicLoader: ntdll.dll/ZwCreateSection
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/GetFileSize
DynamicLoader: kernel32.dll/MapViewOfFile
DynamicLoader: kernel32.dll/LoadLibraryExW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
DynamicLoader: mscoreei.dll/_CorExeMain
DynamicLoader: mscorwks.dll/_CorExeMain
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsW
DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
DynamicLoader: ADVAPI32.dll/GetTraceLoggerHandle
DynamicLoader: ADVAPI32.dll/GetTraceEnableLevel
DynamicLoader: ADVAPI32.dll/GetTraceEnableFlags
DynamicLoader: ADVAPI32.dll/TraceEvent
DynamicLoader: mscoree.dll/IEE
DynamicLoader: mscoree.dll/GetStartupFlags
DynamicLoader: mscoreei.dll/GetStartupFlags_RetAddr
DynamicLoader: mscoreei.dll/GetStartupFlags
DynamicLoader: mscoree.dll/GetHostConfigurationFile
DynamicLoader: mscoreei.dll/GetHostConfigurationFile_RetAddr
DynamicLoader: mscoreei.dll/GetHostConfigurationFile
DynamicLoader: mscoreei.dll/GetCORVersion_RetAddr
DynamicLoader: mscoreei.dll/GetCORVersion
DynamicLoader: mscoree.dll/GetCORSystemDirectory
DynamicLoader: mscoreei.dll/GetCORSystemDirectory_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream
DynamicLoader: ntdll.dll/RtlUnwind
DynamicLoader: kernel32.dll/IsWow64Process
DynamicLoader: kernel32.dll/GetSystemWindowsDirectoryW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: kernel32.dll/SetThreadStackGuarantee
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/AddVectoredContinueHandler
DynamicLoader: kernel32.dll/RemoveVectoredContinueHandler
DynamicLoader: ADVAPI32.dll/ConvertSidToStringSidW
DynamicLoader: SHELL32.dll/SHGetFolderPathW
DynamicLoader: kernel32.dll/FlushProcessWriteBuffers
DynamicLoader: kernel32.dll/GetWriteWatch
DynamicLoader: kernel32.dll/ResetWriteWatch
DynamicLoader: kernel32.dll/CreateMemoryResourceNotification
DynamicLoader: kernel32.dll/QueryMemoryResourceNotification
DynamicLoader: mscoree.dll/_CorExeMain
DynamicLoader: mscoree.dll/_CorImageUnloading
DynamicLoader: mscoree.dll/_CorValidateImage
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: cryptbase.dll/SystemFunction036
DynamicLoader: kernel32.dll/QueryActCtxW
DynamicLoader: ole32.dll/CoGetContextToken
DynamicLoader: kernel32.dll/GetVersionEx
DynamicLoader: kernel32.dll/GetVersionExW
DynamicLoader: kernel32.dll/GetVersionEx
DynamicLoader: kernel32.dll/GetVersionExW
DynamicLoader: kernel32.dll/GetFullPathName
DynamicLoader: kernel32.dll/GetFullPathNameW
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptReleaseContext
DynamicLoader: ADVAPI32.dll/CryptCreateHash
DynamicLoader: ADVAPI32.dll/CryptDestroyHash
DynamicLoader: ADVAPI32.dll/CryptHashData
DynamicLoader: ADVAPI32.dll/CryptGetHashParam
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptExportKey
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: ADVAPI32.dll/CryptGetKeyParam
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptVerifySignatureA
DynamicLoader: ADVAPI32.dll/CryptSignHashA
DynamicLoader: ADVAPI32.dll/CryptGetProvParam
DynamicLoader: ADVAPI32.dll/CryptGetUserKey
DynamicLoader: ADVAPI32.dll/CryptEnumProvidersA
DynamicLoader: mscoree.dll/GetMetaDataInternalInterface
DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface_RetAddr
DynamicLoader: mscoreei.dll/GetMetaDataInternalInterface
DynamicLoader: mscorwks.dll/GetMetaDataInternalInterface
DynamicLoader: CRYPTSP.dll/CryptAcquireContextA
DynamicLoader: CRYPTSP.dll/CryptImportKey
DynamicLoader: CRYPTSP.dll/CryptCreateHash
DynamicLoader: CRYPTSP.dll/CryptHashData
DynamicLoader: CRYPTSP.dll/CryptVerifySignatureA
DynamicLoader: CRYPTSP.dll/CryptDestroyHash
DynamicLoader: CRYPTSP.dll/CryptDestroyKey
DynamicLoader: mscorjit.dll/getJit
DynamicLoader: kernel32.dll/IsWow64Process
DynamicLoader: kernel32.dll/GetUserDefaultUILanguage
DynamicLoader: kernel32.dll/SetErrorMode
DynamicLoader: kernel32.dll/GetFileAttributesEx
DynamicLoader: kernel32.dll/GetFileAttributesExW
DynamicLoader: bcrypt.dll/BCryptGetFipsAlgorithmMode
DynamicLoader: kernel32.dll/lstrlen
DynamicLoader: kernel32.dll/lstrlenW
DynamicLoader: kernel32.dll/GetModuleHandle
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: kernel32.dll/GetProcAddress
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: GDI32.dll/GetStockObject
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/GetWindowLong
DynamicLoader: USER32.dll/GetWindowLongW
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/GetCurrentThread
DynamicLoader: kernel32.dll/DuplicateHandle
DynamicLoader: kernel32.dll/GetCurrentThreadId
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/CallWindowProc
DynamicLoader: USER32.dll/CallWindowProcW
DynamicLoader: USER32.dll/RegisterWindowMessage
DynamicLoader: USER32.dll/RegisterWindowMessageW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/GetCurrentProcessId
DynamicLoader: kernel32.dll/GetCurrentProcessIdW
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: ntdll.dll/NtQuerySystemInformation
DynamicLoader: ntdll.dll/NtQuerySystemInformationW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: ole32.dll/CreateBindCtx
DynamicLoader: ole32.dll/CoGetObjectContext
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: ole32.dll/NdrOleInitializeExtension
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/MkParseDisplayName
DynamicLoader: kernel32.dll/GetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/SetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/LocaleNameToLCID
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/LCIDToLocaleName
DynamicLoader: kernel32.dll/GetSystemDefaultLocaleName
DynamicLoader: fastprox.dll/DllGetClassObject
DynamicLoader: fastprox.dll/DllCanUnloadNow
DynamicLoader: ole32.dll/BindMoniker
DynamicLoader: sxs.dll/SxsOleAut32RedirectTypeLibrary
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyW
DynamicLoader: ADVAPI32.dll/RegQueryValueW
DynamicLoader: sxs.dll/SxsOleAut32MapConfiguredClsidToReferenceClsid
DynamicLoader: sxs.dll/SxsLookupClrGuid
DynamicLoader: kernel32.dll/ReleaseActCtx
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: mscoreei.dll/_CorDllMain_RetAddr
DynamicLoader: mscoreei.dll/_CorDllMain
DynamicLoader: mscoree.dll/GetTokenForVTableEntry
DynamicLoader: mscoree.dll/SetTargetForVTableEntry
DynamicLoader: mscoree.dll/GetTargetForVTableEntry
DynamicLoader: mscoreei.dll/GetTokenForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/GetTokenForVTableEntry
DynamicLoader: mscoreei.dll/SetTargetForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/SetTargetForVTableEntry
DynamicLoader: mscoreei.dll/GetTargetForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/GetTargetForVTableEntry
DynamicLoader: kernel32.dll/GetLastError
DynamicLoader: kernel32.dll/LocalAlloc
DynamicLoader: OLEAUT32.dll/VariantInit
DynamicLoader: OLEAUT32.dll/VariantClear
DynamicLoader: kernel32.dll/CreateEvent
DynamicLoader: kernel32.dll/CreateEventW
DynamicLoader: kernel32.dll/SwitchToThread
DynamicLoader: kernel32.dll/SetEvent
DynamicLoader: ole32.dll/CoWaitForMultipleHandles
DynamicLoader: ole32.dll/IIDFromString
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: kernel32.dll/LoadLibrary
DynamicLoader: kernel32.dll/LoadLibraryA
DynamicLoader: kernel32.dll/GetProcAddress
DynamicLoader: wminet_utils.dll/ResetSecurity
DynamicLoader: wminet_utils.dll/SetSecurity
DynamicLoader: wminet_utils.dll/BlessIWbemServices
DynamicLoader: wminet_utils.dll/BlessIWbemServicesObject
DynamicLoader: wminet_utils.dll/GetPropertyHandle
DynamicLoader: wminet_utils.dll/WritePropertyValue
DynamicLoader: wminet_utils.dll/Clone
DynamicLoader: wminet_utils.dll/VerifyClientKey
DynamicLoader: wminet_utils.dll/GetQualifierSet
DynamicLoader: wminet_utils.dll/Get
DynamicLoader: wminet_utils.dll/Put
DynamicLoader: wminet_utils.dll/Delete
DynamicLoader: wminet_utils.dll/GetNames
DynamicLoader: wminet_utils.dll/BeginEnumeration
DynamicLoader: wminet_utils.dll/Next
DynamicLoader: wminet_utils.dll/EndEnumeration
DynamicLoader: wminet_utils.dll/GetPropertyQualifierSet
DynamicLoader: wminet_utils.dll/Clone
DynamicLoader: wminet_utils.dll/GetObjectText
DynamicLoader: wminet_utils.dll/SpawnDerivedClass
DynamicLoader: wminet_utils.dll/SpawnInstance
DynamicLoader: wminet_utils.dll/CompareTo
DynamicLoader: wminet_utils.dll/GetPropertyOrigin
DynamicLoader: wminet_utils.dll/InheritsFrom
DynamicLoader: wminet_utils.dll/GetMethod
DynamicLoader: wminet_utils.dll/PutMethod
DynamicLoader: wminet_utils.dll/DeleteMethod
DynamicLoader: wminet_utils.dll/BeginMethodEnumeration
DynamicLoader: wminet_utils.dll/NextMethod
DynamicLoader: wminet_utils.dll/EndMethodEnumeration
DynamicLoader: wminet_utils.dll/GetMethodQualifierSet
DynamicLoader: wminet_utils.dll/GetMethodOrigin
DynamicLoader: wminet_utils.dll/QualifierSet_Get
DynamicLoader: wminet_utils.dll/QualifierSet_Put
DynamicLoader: wminet_utils.dll/QualifierSet_Delete
DynamicLoader: wminet_utils.dll/QualifierSet_GetNames
DynamicLoader: wminet_utils.dll/QualifierSet_BeginEnumeration
DynamicLoader: wminet_utils.dll/QualifierSet_Next
DynamicLoader: wminet_utils.dll/QualifierSet_EndEnumeration
DynamicLoader: wminet_utils.dll/GetCurrentApartmentType
DynamicLoader: wminet_utils.dll/GetDemultiplexedStub
DynamicLoader: wminet_utils.dll/CreateInstanceEnumWmi
DynamicLoader: wminet_utils.dll/CreateClassEnumWmi
DynamicLoader: wminet_utils.dll/ExecQueryWmi
DynamicLoader: wminet_utils.dll/ExecNotificationQueryWmi
DynamicLoader: wminet_utils.dll/PutInstanceWmi
DynamicLoader: wminet_utils.dll/PutClassWmi
DynamicLoader: wminet_utils.dll/CloneEnumWbemClassObject
DynamicLoader: wminet_utils.dll/ConnectServerWmi
DynamicLoader: wminet_utils.dll/GetErrorInfo
DynamicLoader: wminet_utils.dll/Initialize
DynamicLoader: OLEAUT32.dll/SysStringLen
DynamicLoader: kernel32.dll/ZeroMemory
DynamicLoader: kernel32.dll/ZeroMemoryA
DynamicLoader: kernel32.dll/RtlZeroMemory
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: CRYPTSP.dll/CryptGetHashParam
DynamicLoader: kernel32.dll/GetEnvironmentVariable
DynamicLoader: kernel32.dll/GetEnvironmentVariableW
DynamicLoader: ADVAPI32.dll/GetUserName
DynamicLoader: ADVAPI32.dll/GetUserNameW
DynamicLoader: kernel32.dll/GetComputerName
DynamicLoader: kernel32.dll/GetComputerNameW
DynamicLoader: kernel32.dll/CreateIoCompletionPort
DynamicLoader: kernel32.dll/PostQueuedCompletionStatus
DynamicLoader: ntdll.dll/NtQueryInformationThread
DynamicLoader: ntdll.dll/NtQuerySystemInformation
DynamicLoader: ntdll.dll/NtGetCurrentProcessorNumber
DynamicLoader: kernel32.dll/CreateDirectory
DynamicLoader: kernel32.dll/CreateDirectoryW
DynamicLoader: kernel32.dll/CopyFile
DynamicLoader: kernel32.dll/CopyFileW
DynamicLoader: ADVAPI32.dll/RegSetValueEx
DynamicLoader: ADVAPI32.dll/RegSetValueExW
DynamicLoader: kernel32.dll/DeleteFile
DynamicLoader: kernel32.dll/DeleteFileW
DynamicLoader: kernel32.dll/GetSystemTimeAsFileTime
DynamicLoader: USER32.dll/GetLastInputInfo
DynamicLoader: shfolder.dll/SHGetFolderPath
DynamicLoader: shfolder.dll/SHGetFolderPathW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: kernel32.dll/CreateFile
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: ole32.dll/CLSIDFromProgIDEx
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/FindFirstFile
DynamicLoader: kernel32.dll/FindFirstFileW
DynamicLoader: kernel32.dll/FindClose
DynamicLoader: OLEAUT32.dll/
DynamicLoader: mscoreei.dll/LoadLibraryShim_RetAddr
DynamicLoader: mscoreei.dll/LoadLibraryShim
DynamicLoader: Culture.dll/ConvertLangIdToCultureName
DynamicLoader: kernel32.dll/GetFileType
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/GetFileSize
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/GetACP
DynamicLoader: kernel32.dll/UnmapViewOfFile
DynamicLoader: vaultcli.dll/VaultEnumerateVaults
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: USER32.dll/GetDC
DynamicLoader: USER32.dll/EnumDisplayMonitors
DynamicLoader: USER32.dll/GetMonitorInfo
DynamicLoader: USER32.dll/GetMonitorInfoW
DynamicLoader: GDI32.dll/GetDeviceCaps
DynamicLoader: USER32.dll/ReleaseDC
DynamicLoader: USER32.dll/GetProcessWindowStation
DynamicLoader: USER32.dll/GetUserObjectInformation
DynamicLoader: USER32.dll/GetUserObjectInformationA
DynamicLoader: kernel32.dll/SetConsoleCtrlHandler
DynamicLoader: kernel32.dll/SetConsoleCtrlHandlerW
DynamicLoader: kernel32.dll/GetModuleHandle
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: USER32.dll/GetClassInfo
DynamicLoader: USER32.dll/GetClassInfoW
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/DefWindowProc
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: USER32.dll/MsgWaitForMultipleObjectsEx
DynamicLoader: kernel32.dll/GetCurrentProcessId
DynamicLoader: kernel32.dll/GetCurrentProcessIdW
DynamicLoader: kernel32.dll/FindAtom
DynamicLoader: kernel32.dll/FindAtomW
DynamicLoader: kernel32.dll/AddAtom
DynamicLoader: kernel32.dll/AddAtomW
DynamicLoader: mscoree.dll/LoadLibraryShim
DynamicLoader: Gdiplus.dll/GdiplusStartup
DynamicLoader: kernel32.dll/IsProcessorFeaturePresent
DynamicLoader: USER32.dll/GetWindowInfo
DynamicLoader: USER32.dll/GetAncestor
DynamicLoader: USER32.dll/GetMonitorInfoA
DynamicLoader: USER32.dll/EnumDisplayMonitors
DynamicLoader: USER32.dll/EnumDisplayDevicesA
DynamicLoader: GDI32.dll/ExtTextOutW
DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
DynamicLoader: Gdiplus.dll/GdipCreateBitmapFromScan0
DynamicLoader: Gdiplus.dll/GdipGetImageEncodersSize
DynamicLoader: Gdiplus.dll/GdipGetImageEncoders
DynamicLoader: kernel32.dll/lstrlenW
DynamicLoader: kernel32.dll/lstrlenWW
DynamicLoader: kernel32.dll/RtlMoveMemory
DynamicLoader: kernel32.dll/RtlMoveMemoryW
DynamicLoader: kernel32.dll/LocalFree
DynamicLoader: mscoree.dll/ND_WI4
DynamicLoader: mscoreei.dll/ND_WI4_RetAddr
DynamicLoader: mscoreei.dll/ND_WI4
DynamicLoader: Gdiplus.dll/GdipGetImagePixelFormat
DynamicLoader: Gdiplus.dll/GdipGetImageGraphicsContext
DynamicLoader: USER32.dll/GetDC
DynamicLoader: GDI32.dll/GetCurrentObject
DynamicLoader: Gdiplus.dll/GdipGetDC
DynamicLoader: GDI32.dll/BitBlt
DynamicLoader: Gdiplus.dll/GdipReleaseDC
DynamicLoader: USER32.dll/ReleaseDC
DynamicLoader: Gdiplus.dll/GdipSaveImageToStream
DynamicLoader: WindowsCodecs.dll/DllGetClassObject
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoGetObjectContext
DynamicLoader: kernel32.dll/FindNextFile
DynamicLoader: kernel32.dll/FindNextFileW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/LocalFree
DynamicLoader: kernel32.dll/ZeroMemory
DynamicLoader: kernel32.dll/ZeroMemoryA
DynamicLoader: kernel32.dll/RtlZeroMemory
DynamicLoader: CRYPT32.dll/CryptUnprotectData
DynamicLoader: CRYPT32.dll/CryptUnprotectDataW
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: cryptbase.dll/SystemFunction041
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: USER32.dll/SetClipboardViewer
DynamicLoader: USER32.dll/SetClipboardViewerW
DynamicLoader: ole32.dll/OleInitialize
DynamicLoader: ole32.dll/OleGetClipboard
DynamicLoader: Gdiplus.dll/GdipDeleteGraphics
DynamicLoader: kernel32.dll/GlobalLock
DynamicLoader: kernel32.dll/GlobalUnlock
DynamicLoader: kernel32.dll/GlobalFree
DynamicLoader: USER32.dll/SendMessage
DynamicLoader: USER32.dll/SendMessageW
DynamicLoader: USER32.dll/SetWindowsHookEx
DynamicLoader: USER32.dll/SetWindowsHookExW
DynamicLoader: USER32.dll/GetClientRect
DynamicLoader: USER32.dll/GetWindowRect
DynamicLoader: USER32.dll/GetParent
DynamicLoader: ole32.dll/CoRegisterMessageFilter
DynamicLoader: USER32.dll/PeekMessage
DynamicLoader: USER32.dll/PeekMessageW
DynamicLoader: USER32.dll/IsWindowUnicode
DynamicLoader: USER32.dll/GetMessageW
DynamicLoader: USER32.dll/TranslateMessage
DynamicLoader: USER32.dll/DispatchMessageW
DynamicLoader: USER32.dll/WaitMessage
DynamicLoader: kernel32.dll/GlobalMemoryStatusEx
DynamicLoader: kernel32.dll/GlobalMemoryStatusExW
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/GetCurrentProcessW
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: kernel32.dll/GetFileAttributesEx
DynamicLoader: kernel32.dll/GetFileAttributesExW
DynamicLoader: mscoree.dll/ND_RI2
DynamicLoader: mscoreei.dll/ND_RI2_RetAddr
DynamicLoader: mscoreei.dll/ND_RI2
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/LocalFree
DynamicLoader: iphlpapi.dll/GetNetworkParams
DynamicLoader: DNSAPI.dll/DnsQueryConfig
DynamicLoader: iphlpapi.dll/GetAdaptersAddresses
DynamicLoader: iphlpapi.dll/GetIpInterfaceEntry
DynamicLoader: iphlpapi.dll/GetBestInterfaceEx
DynamicLoader: kernel32.dll/LocalAlloc
DynamicLoader: iphlpapi.dll/GetAdaptersAddresses
DynamicLoader: WS2_32.dll/WSAStartup
DynamicLoader: WS2_32.dll/WSASocket
DynamicLoader: WS2_32.dll/WSASocketW
DynamicLoader: WS2_32.dll/setsockopt
DynamicLoader: WS2_32.dll/WSAEventSelect
DynamicLoader: WS2_32.dll/ioctlsocket
DynamicLoader: WS2_32.dll/closesocket
DynamicLoader: kernel32.dll/GetComputerName
DynamicLoader: kernel32.dll/GetComputerNameW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/ConvertStringSecurityDescriptorToSecurityDescriptor
DynamicLoader: ADVAPI32.dll/ConvertStringSecurityDescriptorToSecurityDescriptorW
DynamicLoader: kernel32.dll/LocalFree
DynamicLoader: kernel32.dll/CreateFileMapping
DynamicLoader: kernel32.dll/CreateFileMappingW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/MapViewOfFile
DynamicLoader: kernel32.dll/UnmapViewOfFile
DynamicLoader: kernel32.dll/VirtualQuery
DynamicLoader: kernel32.dll/ReleaseMutex
DynamicLoader: ADVAPI32.dll/CreateWellKnownSid
DynamicLoader: ADVAPI32.dll/CreateWellKnownSidW
DynamicLoader: kernel32.dll/CreateMutex
DynamicLoader: kernel32.dll/CreateMutexW
DynamicLoader: kernel32.dll/WaitForSingleObject
DynamicLoader: kernel32.dll/OpenMutex
DynamicLoader: kernel32.dll/OpenMutexW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/OpenProcess
DynamicLoader: kernel32.dll/OpenProcessW
DynamicLoader: kernel32.dll/GetProcessTimes
DynamicLoader: kernel32.dll/GetProcessTimesW
DynamicLoader: WS2_32.dll/inet_addr
DynamicLoader: bcrypt.dll/BCryptGetFipsAlgorithmMode
DynamicLoader: kernel32.dll/ResetEvent
DynamicLoader: kernel32.dll/CreateSemaphore
DynamicLoader: kernel32.dll/CreateSemaphoreA
DynamicLoader: WS2_32.dll/getaddrinfo
DynamicLoader: WS2_32.dll/freeaddrinfo
DynamicLoader: kernel32.dll/GetTempPath
DynamicLoader: kernel32.dll/GetTempPathW
DynamicLoader: kernel32.dll/FormatMessage
DynamicLoader: kernel32.dll/FormatMessageW
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
DynamicLoader: VSSAPI.DLL/CreateWriter
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ADVAPI32.dll/LookupAccountNameW
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: samcli.dll/NetLocalGroupGetMembers
DynamicLoader: SAMLIB.dll/SamConnect
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: SAMLIB.dll/SamOpenDomain
DynamicLoader: SAMLIB.dll/SamLookupNamesInDomain
DynamicLoader: SAMLIB.dll/SamOpenAlias
DynamicLoader: SAMLIB.dll/SamFreeMemory
DynamicLoader: SAMLIB.dll/SamCloseHandle
DynamicLoader: SAMLIB.dll/SamGetMembersInAlias
DynamicLoader: netutils.dll/NetApiBufferFree
DynamicLoader: ole32.dll/CoCreateGuid
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/StringFromCLSID
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: PROPSYS.dll/VariantToPropVariant
DynamicLoader: OLEAUT32.dll/
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemsvc.dll/DllGetClassObject
DynamicLoader: wbemsvc.dll/DllCanUnloadNow
DynamicLoader: authZ.dll/AuthzInitializeContextFromToken
DynamicLoader: authZ.dll/AuthzInitializeObjectAccessAuditEvent2
DynamicLoader: authZ.dll/AuthzAccessCheck
DynamicLoader: authZ.dll/AuthzFreeAuditEvent
DynamicLoader: authZ.dll/AuthzFreeContext
DynamicLoader: authZ.dll/AuthzInitializeResourceManager
DynamicLoader: authZ.dll/AuthzFreeResourceManager
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: RPCRT4.dll/RpcBindingCreateW
DynamicLoader: RPCRT4.dll/RpcBindingBind
DynamicLoader: RPCRT4.dll/I_RpcMapWin32Status
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: ADVAPI32.dll/EventRegister
DynamicLoader: ADVAPI32.dll/EventUnregister
DynamicLoader: ADVAPI32.dll/EventWrite
DynamicLoader: ADVAPI32.dll/EventActivityIdControl
DynamicLoader: ADVAPI32.dll/EventWriteTransfer
DynamicLoader: ADVAPI32.dll/EventEnabled
DynamicLoader: kernel32.dll/RegCloseKey
DynamicLoader: kernel32.dll/RegSetValueExW
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: kernel32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/RegCloseKey
DynamicLoader: wmisvc.dll/IsImproperShutdownDetected
DynamicLoader: Wevtapi.dll/EvtRender
DynamicLoader: Wevtapi.dll/EvtNext
DynamicLoader: Wevtapi.dll/EvtClose
DynamicLoader: Wevtapi.dll/EvtQuery
DynamicLoader: Wevtapi.dll/EvtCreateRenderContext
DynamicLoader: RPCRT4.dll/RpcStringBindingComposeW
DynamicLoader: RPCRT4.dll/RpcBindingFromStringBindingW
DynamicLoader: RPCRT4.dll/RpcBindingSetAuthInfoExW
DynamicLoader: RPCRT4.dll/RpcBindingSetOption
DynamicLoader: RPCRT4.dll/RpcStringFreeW
DynamicLoader: RPCRT4.dll/NdrClientCall2
DynamicLoader: RPCRT4.dll/RpcBindingFree
DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
DynamicLoader: ole32.dll/CoCreateFreeThreadedMarshaler
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CreateStreamOnHGlobal
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: KERNELBASE.dll/InitializeAcl
DynamicLoader: KERNELBASE.dll/AddAce
DynamicLoader: kernel32.dll/OpenProcessToken
DynamicLoader: KERNELBASE.dll/GetTokenInformation
DynamicLoader: KERNELBASE.dll/DuplicateTokenEx
DynamicLoader: KERNELBASE.dll/AdjustTokenPrivileges
DynamicLoader: kernel32.dll/SetThreadToken
DynamicLoader: KERNELBASE.dll/CheckTokenMembership
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: KERNELBASE.dll/AllocateAndInitializeSid
DynamicLoader: ole32.dll/CLSIDFromString
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: authZ.dll/AuthzInitializeContextFromToken
DynamicLoader: authZ.dll/AuthzInitializeResourceManager
DynamicLoader: authZ.dll/AuthzInitializeContextFromSid
DynamicLoader: authZ.dll/AuthzInitializeContextFromToken
DynamicLoader: authZ.dll/AuthzAccessCheck
DynamicLoader: authZ.dll/AuthzFreeContext
DynamicLoader: authZ.dll/AuthzFreeResourceManager
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetCallContext
DynamicLoader: ole32.dll/StringFromGUID2
DynamicLoader: ole32.dll/CoImpersonateClient
DynamicLoader: ole32.dll/CoRevertToSelf
DynamicLoader: ole32.dll/CoSwitchCallContext
DynamicLoader: ole32.dll/CoCreateGuid
DynamicLoader: kernel32.dll/ResolveDelayLoadedAPI
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: SspiCli.dll/LogonUserExExW
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: OLEAUT32.dll/
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
DynamicLoader: wbemcore.dll/Reinitialize
CAPE extracted potentially suspicious content
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Injected PE Image: 32-bit executable
AlV8bUk.exe: Unpacked Shellcode
AlV8bUk.exe: Unpacked Shellcode
Queries or connects to DNS-Over-HTTPS/DNS-Over-TLS domain or IP address
ip: 1.1.1.1
The binary contains an unknown PE section name indicative of packing
unknown section: name: CODE, entropy: 6.52, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00061a00, virtual_size: 0x00061874
unknown section: name: DATA, entropy: 5.02, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0000b000, virtual_size: 0x0000ae28
unknown section: name: BSS, entropy: 0.00, characteristics: IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x00000bf9
The binary likely contains encrypted or compressed data.
section: name: .rsrc, entropy: 7.36, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ, raw_size: 0x00041800, virtual_size: 0x00041774
Authenticode signature is invalid
authenticode error: No signature found. SignTool Error File not valid C\Users\Rebecca\AppData\Local\Temp\AlV8bUk
Behavioural detection: Injection (Process Hollowing)
Injection: AlV8bUk.exe(5112) -> AlV8bUk.exe(5436)
Executed a process and injected code into it, probably while unpacking
Injection: AlV8bUk.exe(5112) -> AlV8bUk.exe(5436)
Attempts to remove evidence of file being downloaded from the Internet
file: C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe:Zone.Identifier
Sniffs keystrokes
SetWindowsHookExW: Process: AlV8bUk.exe(5436)
Behavioural detection: Injection (inter-process)
Behavioural detection: Injection with CreateRemoteThread in a remote process
Tries to unhook or modify Windows functions monitored by Cuckoo
unhook: function_name: NtCreateSection, type: modification
Attempts to repeatedly call a single API many times in order to delay analysis time
Spam: services.exe (460) called API GetSystemTimeAsFileTime 14282739 times
Steals private information from local Internet browsers
file: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Login Data
file: C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\profiles.ini
file: C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\Profiles\48wgv2fv.default\key4.db
Installs itself for autorun at Windows startup
key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ben
data: C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe
File has been identified by 29 Antiviruses on VirusTotal as malicious
Bkav: W32.AIDetectVM.malwareB
FireEye: Generic.mg.6b05795f7de00b9b
McAfee: Fareit-FTB!6B05795F7DE0
Cylance: Unsafe
K7AntiVirus: Trojan ( 005680341 )
K7GW: Trojan ( 005680341 )
Cybereason: malicious.e8c6f1
Invincea: heuristic
BitDefenderTheta: Gen:[email protected]
F-Prot: W32/Injector.ABY.gen!Eldorado
Symantec: ML.Attribute.HighConfidence
APEX: Malicious
Kaspersky: UDS:DangerousObject.Multi.Generic
Rising: Malware.Heuristic!ET#100% (RDMK:cmRtazpl4I95cdqG9rvlBz3ce7sL)
McAfee-GW-Edition: BehavesLike.Win32.Fareit.bc
Trapmine: malicious.moderate.ml.score
SentinelOne: DFI - Suspicious PE
Cyren: W32/Injector.ABY.gen!Eldorado
Fortinet: W32/Injector.ELZG!tr
Endgame: malicious (high confidence)
Microsoft: Trojan:Win32/Wacatac.C!ml
ZoneAlarm: UDS:DangerousObject.Multi.Generic
Cynet: Malicious (score: 100)
AhnLab-V3: Suspicious/Win.Delphiless.X2066
Acronis: suspicious
ESET-NOD32: a variant of Win32/Injector.EMJE
eGambit: Unsafe.AI_Score_95%
CrowdStrike: win/malicious_confidence_80% (D)
Qihoo-360: HEUR/QVM05.1.166F.Malware.Gen
Creates a copy of itself
copy: C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe
Harvests credentials from local FTP client softwares
file: C:\Users\Rebecca\AppData\Roaming\FileZilla\recentservers.xml
file: C:\Users\Rebecca\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
file: C:\Users\Rebecca\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\*.xml
file: C:\Users\Rebecca\AppData\Roaming\FTPGetter\servers.xml
file: C:\Users\Rebecca\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
file: C:\cftp\Ftplist.txt
key: HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
Harvests information related to installed mail clients
file: C:\Users\Rebecca\AppData\Roaming\Thunderbird\profiles.ini
key: HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Anomalous binary characteristics
anomaly: Timestamp on binary predates the release date of the OS version it requires by at least a year

Screenshots


Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
Y 1.1.1.1 [VT] Australia

DNS

Name Response Post-Analysis Lookup
dutchlogs.us [VT] 5.77.32.186 [VT]

Summary

C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.ENU
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.ENU.DLL
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.EN
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.EN.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\System32\mscoree.dll.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\sxs.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\shfolder.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\user32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\iphlpapi.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\advapi32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035\GdiPlus.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscoree.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe.config
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-2.dll
C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index38e.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f8420d8c6ede777377fcff48a4beaa2a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users
C:\Users\Rebecca
C:\Users\Rebecca\AppData
C:\Users\Rebecca\AppData\Local
C:\Users\Rebecca\AppData\Local\Temp
C:\Windows\System32\l_intl.nls
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.INI
C:\Windows\assembly\pubpol224.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0a65164b17e5c64bacdc694ea2439c43\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\175df210b784212def386595c25caefb\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\5669120680b52abf616f3876387ca2cc\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4ac828c8c4c76f3ba59f8f9c7dab1cb3\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\System32\en-US\KERNELBASE.dll.mui
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\aa404966f6e5a3d1f9d0fe3ba1d13ec1\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\81ab4c39c6a7c9f50721aca2db09b417\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Users\Rebecca\AppData\Local\Temp\ben\
C:\Users\Rebecca\AppData\Local\Temp\ben
C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe
C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe:Zone.Identifier
C:\Windows\System32\tzres.dll
C:\Windows\System32\en-US\tzres.dll.mui
C:\Users\Rebecca\AppData\Local\CatalinaGroup\Citrio\User Data
C:\Users\Rebecca\AppData\Local\Yandex\YandexBrowser\User Data
C:\Users\Rebecca\AppData\Local\QIP Surf\User Data
C:\Users\Rebecca\AppData\Local\Comodo\Dragon\User Data
C:\Users\Rebecca\AppData\Local\7Star\7Star\User Data
C:\Users\Rebecca\AppData\Local\Chedot\User Data
C:\Users\Rebecca\AppData\Local\uCozMedia\Uran\User Data
C:\Users\Rebecca\AppData\Local\Orbitum\User Data
C:\Users\Rebecca\AppData\Local\Elements Browser\User Data
C:\Users\Rebecca\AppData\Local\360Chrome\Chrome\User Data
C:\Users\Rebecca\AppData\Local\CocCoc\Browser\User Data
C:\Users\Rebecca\AppData\Local\Epic Privacy Browser\User Data
C:\Users\Rebecca\AppData\Local\Chromium\User Data
C:\Users\Rebecca\AppData\Local\MapleStudio\ChromePlus\User Data
C:\Users\Rebecca\AppData\Local\Vivaldi\User Data
C:\Users\Rebecca\AppData\Local\Kometa\User Data
C:\Users\Rebecca\AppData\Local\Coowon\Coowon\User Data
C:\Users\Rebecca\AppData\Local\CentBrowser\User Data
C:\Users\Rebecca\AppData\Local\Amigo\User Data
C:\Users\Rebecca\AppData\Local\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer
C:\Users\Rebecca\AppData\Local\Torch\User Data
C:\Users\Rebecca\AppData\Local\liebao\User Data
C:\Users\Rebecca\AppData\Local\BraveSoftware\Brave-Browser\User Data
C:\Users\Rebecca\AppData\Local\Sputnik\Sputnik\User Data
C:\Users\Rebecca\AppData\Local\Iridium\User Data
C:\Users\Rebecca\AppData\Roaming\Opera Software\Opera Stable
C:\Users\Rebecca\AppData\Roaming\Moonchild Productions\Pale Moon\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Postbox\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\FTP Navigator\Ftplist.txt
C:\Users\Rebecca\AppData\Roaming\FTPGetter\servers.xml
C:\Users\Rebecca\AppData\Roaming\Waterfox\profiles.ini
C:\Users\Rebecca\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\System32\wshom.ocx
C:\Windows\System32\en-US\wshom.ocx.mui
C:\Program Files\Common Files\Apple\Apple Application Support\plutil.exe
C:\Users\Rebecca\AppData\Roaming\Trillian\users\global\accounts.dat
C:\Users\Rebecca\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\Rebecca\AppData\Local\falkon\profiles\profiles.ini
C:\Storage\
C:\mail\
C:\Users\Rebecca\AppData\Local\VirtualStore\Program Files\Foxmail\mail\
C:\Users\Rebecca\AppData\Local\VirtualStore\Program Files (x86)\Foxmail\mail\
C:\Users\Rebecca\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\*.xml
C:\Users\Rebecca\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
C:\Users\Rebecca\AppData\Roaming\The Bat!
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll.DLL
C:\Users\Rebecca\AppData\Roaming\Claws-mail
C:\Users\Rebecca\AppData\Roaming\Claws-mail\clawsrc
C:\Users\Rebecca\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
C:\Users\Rebecca\AppData\Roaming\Comodo\IceDragon\profiles.ini
C:\Program Files\jDownloader\config\database.script
C:\Users\Rebecca\AppData\Roaming\K-Meleon\profiles.ini
C:\Users\Rebecca\AppData\Local\Tencent\QQBrowser\User Data
C:\Users\Rebecca\AppData\Local\Tencent\QQBrowser\User Data\Default\EncryptedStorage
C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\Profiles\48wgv2fv.default\logins.json
C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\Profiles\48wgv2fv.default\key4.db
C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\Profiles\48wgv2fv.default\signons.sqlite
C:\Users\Rebecca\AppData\Roaming\Pocomail\accounts.ini
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b065f84b49a27b648015c08fab8cd00e\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Users\Rebecca\AppData\Roaming\Psi\profiles
C:\Users\Rebecca\AppData\Roaming\Psi+\profiles
C:\Users\All Users\AppData\Roaming\FlashFXP\3quick.dat
C:\Users\Rebecca\AppData\Local\Microsoft\Edge\User Data
C:\Users\Rebecca\AppData\Local\Temp\vaultcli.dll
C:\cftp\Ftplist.txt
C:\Users\Rebecca\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini
C:\Users\Rebecca\AppData\Local\Temp\Folder.lst
C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\
C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\*
C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Login Data
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\51fb28e8a54a8d8f6021415d47477ab4\System.Security.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.INI
C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Local State
C:\Windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\crypt32.dll
\Device\KsecDD
C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Login Data
C:\Users\Rebecca\AppData\Roaming\Mozilla\icecat\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Flock\Browser\profiles.ini
C:\Users\Rebecca\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Rebecca\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini
C:\Users\Rebecca\AppData\Local\UCBrowser\*
C:\Users\Rebecca\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d22616370e881379e5a7c30ee1e75a6\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Users\Rebecca\AppData\Local\Temp\log.tmp
C:\Windows\System32\en-US\VssTrace.DLL.mui
\??\PIPE\samr
C:\Windows\System32\wbem\repository
C:\Windows\System32\wbem\Logs
C:\Windows\System32\wbem\AutoRecover
C:\Windows\System32\wbem\MOF
C:\Windows\System32\wbem\repository\INDEX.BTR
C:\Windows\System32\wbem\repository\WRITABLE.TST
C:\Windows\System32\wbem\repository\MAPPING1.MAP
C:\Windows\System32\wbem\repository\MAPPING2.MAP
C:\Windows\System32\wbem\repository\MAPPING3.MAP
C:\Windows\System32\wbem\repository\OBJECTS.DATA
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\Temp
C:\Windows\System32\LogFiles\Scm\a1cfa52f-06f2-418d-addb-cd6456d66f43
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24308_none_5c028e37a0121035\GdiPlus.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe.config
C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\Rebecca\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index38e.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f8420d8c6ede777377fcff48a4beaa2a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
C:\Windows\assembly\pubpol224.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\0a65164b17e5c64bacdc694ea2439c43\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\175df210b784212def386595c25caefb\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\5669120680b52abf616f3876387ca2cc\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4ac828c8c4c76f3ba59f8f9c7dab1cb3\Microsoft.VisualBasic.ni.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\System32\en-US\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\aa404966f6e5a3d1f9d0fe3ba1d13ec1\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\81ab4c39c6a7c9f50721aca2db09b417\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\System32\tzres.dll
C:\Windows\System32\en-US\tzres.dll.mui
C:\Users\Rebecca\AppData\Roaming\Moonchild Productions\Pale Moon\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Postbox\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\FTP Navigator\Ftplist.txt
C:\Users\Rebecca\AppData\Roaming\Waterfox\profiles.ini
C:\Users\Rebecca\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\System32\wshom.ocx
C:\Windows\System32\en-US\wshom.ocx.mui
C:\Users\Rebecca\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\Rebecca\AppData\Local\falkon\profiles\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Comodo\IceDragon\profiles.ini
C:\Users\Rebecca\AppData\Roaming\K-Meleon\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\Profiles\48wgv2fv.default\key4.db
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b065f84b49a27b648015c08fab8cd00e\System.Xml.ni.dll
C:\Users\Rebecca\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini
C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Login Data
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\51fb28e8a54a8d8f6021415d47477ab4\System.Security.ni.dll
C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Local State
\Device\KsecDD
C:\Users\Rebecca\AppData\Roaming\Mozilla\icecat\profiles.ini
C:\Users\Rebecca\AppData\Roaming\Flock\Browser\profiles.ini
C:\Users\Rebecca\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\Rebecca\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d22616370e881379e5a7c30ee1e75a6\System.Configuration.ni.dll
C:\Windows\System32\en-US\VssTrace.DLL.mui
\??\PIPE\samr
C:\Windows\System32\wbem\repository\MAPPING1.MAP
C:\Windows\System32\wbem\repository\MAPPING2.MAP
C:\Windows\System32\wbem\repository\MAPPING3.MAP
C:\Windows\System32\wbem\repository\OBJECTS.DATA
C:\Windows\System32\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Windows\System32\LogFiles\Scm\a1cfa52f-06f2-418d-addb-cd6456d66f43
C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe
\??\PIPE\samr
C:\Windows\System32\wbem\repository\WRITABLE.TST
C:\Windows\System32\wbem\repository\MAPPING1.MAP
C:\Windows\System32\wbem\repository\MAPPING2.MAP
C:\Windows\System32\wbem\repository\MAPPING3.MAP
C:\Windows\System32\wbem\repository\OBJECTS.DATA
C:\Windows\System32\wbem\repository\INDEX.BTR
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
C:\Users\Rebecca\AppData\Local\Temp\ben\ben.exe:Zone.Identifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_CURRENT_USER
DisableUserModeCallbackFilter
HKEY_CURRENT_USER\Software\Borland\Locales
HKEY_LOCAL_MACHINE\Software\Borland\Locales
HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\diasymreader.dll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\msasn1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscorsec.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\AlV8bUk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\v2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscordacwks.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\Culture.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscorjit.dll
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlV8bUk.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v2.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-479431668-4257340731-3059248302-1002
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\60eb77ee\31125dee
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\DotNetClient\v3.5
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index224
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\AlV8bUk.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\ECB0FD17
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_CURRENT_USER\Software\Classes\WinMgmts
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM
HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\409
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\9
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.ni.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.Management.ni.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\WMIDisableCOMSecurity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ben
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
HKEY_CLASSES_ROOT\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\409
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\9
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1
HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine
HKEY_CURRENT_USER\Software\DownloadManager\Passwords
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_CURRENT_USER\Software\OpenVPN-GUI\configs
HKEY_CURRENT_USER\Software\RimArts\B2\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\MissingDependencies
HKEY_CURRENT_USER\Software\IncrediMail\Identities
HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\MissingDependencies
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableNullRecordSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{E29AC6C2-7037-11DE-816D-806E6F6E6963}
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\ProcessIdentifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ObjectName
DisableUserModeCallbackFilter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\diasymreader.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscorsec.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscordacwks.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\Culture.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscorjit.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index38e\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\74\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\780ee13f\6d\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index224
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\66\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\304b33ae\65\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\46ad1249\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\553abeb3\54\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\324708cb\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\4bf62c79\57\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\3dc46903\53\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\5086dba8\61\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\78\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\257bdb20\70\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\6f\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\12d2be49\5c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\a4\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\3e045c21\58\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\23e7306f\b5\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\6e527edf\63\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\191b956f\bb\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\ECB0FD17
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\28\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\6c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\34724983\16\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.ni.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\9e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\61f4f6f6\52\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\41a2a33b\b4\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.Management.ni.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\WMIDisableCOMSecurity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ben
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\75\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\658578aa\64\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6f06001f\475dce40\71\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\76\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableNullRecordSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{8C26D1B6-C485-43DB-8C6E-9EBF79977CC0}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{0096CAC7-A03A-47A2-9F4E-7A57014C4406}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{34175B06-4595-447A-82C4-8F30A3906562}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C1637785-412C-41B2-B0DD-0F34D54B2296}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\Scope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\Locale
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\User
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{C84FE829-9991-4EF4-BDFC-FC1B13F492BC}\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Audiosrv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent\ObjectName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ben
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
kernel32.dll.FlsAlloc
kernel32.dll.FlsGetValue
kernel32.dll.FlsSetValue
kernel32.dll.FlsFree
kernelbase.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.ProcessIdToSessionId
imm32.dll.ImmCreateContext
imm32.dll.ImmDestroyContext
imm32.dll.ImmNotifyIME
imm32.dll.ImmAssociateContext
imm32.dll.ImmReleaseContext
imm32.dll.ImmGetContext
imm32.dll.ImmGetCompositionStringA
imm32.dll.ImmSetCompositionStringA
imm32.dll.ImmGetCompositionStringW
imm32.dll.ImmSetCompositionStringW
imm32.dll.ImmSetCandidateWindow
kernel32.dll.GetDiskFreeSpaceExA
oleaut32.dll.VariantChangeTypeEx
oleaut32.dll.VarNeg
oleaut32.dll.VarNot
oleaut32.dll.VarAdd
oleaut32.dll.VarSub
oleaut32.dll.VarMul
oleaut32.dll.VarDiv
oleaut32.dll.VarIdiv
oleaut32.dll.VarMod
oleaut32.dll.VarAnd
oleaut32.dll.VarOr
oleaut32.dll.VarXor
oleaut32.dll.VarCmp
oleaut32.dll.VarI4FromStr
oleaut32.dll.VarR4FromStr
oleaut32.dll.VarR8FromStr
oleaut32.dll.VarDateFromStr
oleaut32.dll.VarCyFromStr
oleaut32.dll.VarBoolFromStr
oleaut32.dll.VarBstrFromCy
oleaut32.dll.VarBstrFromDate
oleaut32.dll.VarBstrFromBool
user32.dll.GetMonitorInfoA
user32.dll.GetSystemMetrics
user32.dll.EnumDisplayMonitors
user32.dll.AnimateWindow
comctl32.dll.InitializeFlatSB
comctl32.dll.UninitializeFlatSB
comctl32.dll.FlatSB_GetScrollProp
comctl32.dll.FlatSB_SetScrollProp
comctl32.dll.FlatSB_EnableScrollBar
comctl32.dll.FlatSB_ShowScrollBar
comctl32.dll.FlatSB_GetScrollRange
comctl32.dll.FlatSB_GetScrollInfo
comctl32.dll.FlatSB_GetScrollPos
comctl32.dll.FlatSB_SetScrollPos
comctl32.dll.FlatSB_SetScrollInfo
comctl32.dll.FlatSB_SetScrollRange
user32.dll.SetLayeredWindowAttributes
kernel32.dll.FileTimeToSystemTime
kernel32.dll.GetModuleHandleW
kernel32.dll.VirtualFree
kernel32.dll.LoadLibraryW
kernel32.dll.SizeofResource
kernel32.dll.GetModuleFileNameW
kernel32.dll.CreateFileW
kernel32.dll.MultiByteToWideChar
kernel32.dll.FlushInstructionCache
kernel32.dll.GetCurrentProcess
kernel32.dll.VirtualAlloc
kernel32.dll.LoadLibraryA
kernel32.dll.GetModuleFileNameA
kernel32.dll.GetModuleHandleA
kernel32.dll.VirtualProtect
kernel32.dll.CloseHandle
kernel32.dll.LoadResource
kernel32.dll.FindResourceW
kernel32.dll.GetProcAddress
kernel32.dll.GetFileSize
kernel32.dll.LCMapStringW
kernel32.dll.LCMapStringA
kernel32.dll.GetStringTypeW
kernel32.dll.GetStringTypeA
kernel32.dll.HeapAlloc
kernel32.dll.GetStartupInfoW
kernel32.dll.DeleteCriticalSection
kernel32.dll.LeaveCriticalSection
kernel32.dll.EnterCriticalSection
kernel32.dll.HeapFree
kernel32.dll.HeapReAlloc
kernel32.dll.HeapCreate
kernel32.dll.Sleep
kernel32.dll.ExitProcess
kernel32.dll.WriteFile
kernel32.dll.GetStdHandle
kernel32.dll.SetUnhandledExceptionFilter
kernel32.dll.FreeEnvironmentStringsW
kernel32.dll.GetEnvironmentStringsW
kernel32.dll.GetCommandLineW
kernel32.dll.SetHandleCount
kernel32.dll.GetFileType
kernel32.dll.GetStartupInfoA
kernel32.dll.TlsGetValue
kernel32.dll.TlsAlloc
kernel32.dll.TlsSetValue
kernel32.dll.TlsFree
kernel32.dll.InterlockedIncrement
kernel32.dll.SetLastError
kernel32.dll.GetCurrentThreadId
kernel32.dll.GetLastError
kernel32.dll.InterlockedDecrement
kernel32.dll.QueryPerformanceCounter
kernel32.dll.GetTickCount
kernel32.dll.GetCurrentProcessId
kernel32.dll.GetSystemTimeAsFileTime
kernel32.dll.InitializeCriticalSectionAndSpinCount
kernel32.dll.TerminateProcess
kernel32.dll.UnhandledExceptionFilter
kernel32.dll.IsDebuggerPresent
kernel32.dll.RtlUnwind
kernel32.dll.GetCPInfo
kernel32.dll.GetACP
kernel32.dll.GetOEMCP
kernel32.dll.IsValidCodePage
kernel32.dll.HeapSize
kernel32.dll.GetLocaleInfoA
kernel32.dll.WideCharToMultiByte
advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryValueExW
advapi32.dll.RegCloseKey
psapi.dll.GetModuleInformation
psapi.dll.GetModuleBaseNameW
psapi.dll.EnumProcessModules
shlwapi.dll.StrStrIW
shlwapi.dll.PathFileExistsW
mscoree.dll._CorExeMain
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._set_error_mode
[email protected]@[email protected]
kernel32.dll.FindActCtxSectionStringW
kernel32.dll.GetSystemWindowsDirectoryW
mscoree.dll.GetProcessExecutableHeap
advapi32.dll.RegQueryInfoKeyW
advapi32.dll.RegEnumKeyExW
advapi32.dll.RegEnumValueW
kernel32.dll.InitializeCriticalSectionEx
kernel32.dll.CreateEventExW
kernel32.dll.CreateSemaphoreExW
kernel32.dll.SetThreadStackGuarantee
kernel32.dll.CreateThreadpoolTimer
kernel32.dll.SetThreadpoolTimer
kernel32.dll.WaitForThreadpoolTimerCallbacks
kernel32.dll.CloseThreadpoolTimer
kernel32.dll.CreateThreadpoolWait
kernel32.dll.SetThreadpoolWait
kernel32.dll.CloseThreadpoolWait
kernel32.dll.FlushProcessWriteBuffers
kernel32.dll.FreeLibraryWhenCallbackReturns
kernel32.dll.GetCurrentProcessorNumber
kernel32.dll.GetLogicalProcessorInformation
kernel32.dll.CreateSymbolicLinkW
kernel32.dll.SetDefaultDllDirectories
kernel32.dll.EnumSystemLocalesEx
kernel32.dll.CompareStringEx
kernel32.dll.GetDateFormatEx
kernel32.dll.GetLocaleInfoEx
kernel32.dll.GetTimeFormatEx
kernel32.dll.GetUserDefaultLocaleName
kernel32.dll.IsValidLocaleName
kernel32.dll.LCMapStringEx
kernel32.dll.GetTickCount64
kernel32.dll.AcquireSRWLockExclusive
kernel32.dll.ReleaseSRWLockExclusive
advapi32.dll.EventRegister
advapi32.dll.EventSetInformation
mscoree.dll.#142
mscoreei.dll.RegisterShimImplCallback
mscoreei.dll.OnShimDllMainCalled
mscoreei.dll.GetProcessExecutableHeap
mscorwks.dll.GetCLRFunction
mscoree.dll.IEE
mscoreei.dll.IEE
shlwapi.dll.UrlIsW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerQueryValueW
user32.dll.GetProcessWindowStation
user32.dll.GetUserObjectInformationW
mscorwks.dll.IEE
ntdll.dll.ZwCreateSection
kernel32.dll.MapViewOfFile
kernel32.dll.LoadLibraryExW
mscoreei.dll._CorExeMain
mscorwks.dll._CorExeMain
advapi32.dll.RegisterTraceGuidsW
advapi32.dll.UnregisterTraceGuids
advapi32.dll.GetTraceLoggerHandle
advapi32.dll.GetTraceEnableLevel
advapi32.dll.GetTraceEnableFlags
advapi32.dll.TraceEvent
mscoree.dll.GetStartupFlags
mscoreei.dll.GetStartupFlags
mscoree.dll.GetHostConfigurationFile
mscoreei.dll.GetHostConfigurationFile
mscoreei.dll.GetCORVersion
mscoree.dll.GetCORSystemDirectory
mscoreei.dll.GetCORSystemDirectory_RetAddr
mscoreei.dll.CreateConfigStream
ntdll.dll.RtlUnwind
kernel32.dll.IsWow64Process
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.OpenProcessToken
advapi32.dll.GetTokenInformation
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.FreeSid
kernel32.dll.AddVectoredContinueHandler
kernel32.dll.RemoveVectoredContinueHandler
advapi32.dll.ConvertSidToStringSidW
shell32.dll.SHGetFolderPathW
kernel32.dll.GetWriteWatch
kernel32.dll.ResetWriteWatch
kernel32.dll.CreateMemoryResourceNotification
kernel32.dll.QueryMemoryResourceNotification
mscoree.dll._CorImageUnloading
mscoree.dll._CorValidateImage
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
kernel32.dll.QueryActCtxW
ole32.dll.CoGetContextToken
kernel32.dll.GetVersionExW
kernel32.dll.GetFullPathNameW
advapi32.dll.CryptAcquireContextA
advapi32.dll.CryptReleaseContext
advapi32.dll.CryptCreateHash
advapi32.dll.CryptDestroyHash
advapi32.dll.CryptHashData
advapi32.dll.CryptGetHashParam
advapi32.dll.CryptImportKey
advapi32.dll.CryptExportKey
advapi32.dll.CryptGenKey
advapi32.dll.CryptGetKeyParam
advapi32.dll.CryptDestroyKey
advapi32.dll.CryptVerifySignatureA
advapi32.dll.CryptSignHashA
advapi32.dll.CryptGetProvParam
advapi32.dll.CryptGetUserKey
advapi32.dll.CryptEnumProvidersA
mscoree.dll.GetMetaDataInternalInterface
mscoreei.dll.GetMetaDataInternalInterface
mscorwks.dll.GetMetaDataInternalInterface
cryptsp.dll.CryptAcquireContextA
cryptsp.dll.CryptImportKey
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptVerifySignatureA
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptDestroyKey
mscorjit.dll.getJit
kernel32.dll.GetUserDefaultUILanguage
kernel32.dll.SetErrorMode
kernel32.dll.GetFileAttributesExW
bcrypt.dll.BCryptGetFipsAlgorithmMode
kernel32.dll.lstrlen
kernel32.dll.lstrlenW
user32.dll.DefWindowProcW
gdi32.dll.GetStockObject
user32.dll.RegisterClassW
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
user32.dll.CreateWindowExW
user32.dll.SetWindowLongW
user32.dll.GetWindowLongW
kernel32.dll.GetCurrentThread
kernel32.dll.DuplicateHandle
user32.dll.CallWindowProcW
user32.dll.RegisterWindowMessageW
advapi32.dll.LookupPrivilegeValueW
advapi32.dll.AdjustTokenPrivileges
ntdll.dll.NtQuerySystemInformation
cryptsp.dll.CryptAcquireContextW
ole32.dll.CreateBindCtx
ole32.dll.CoGetObjectContext
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
cryptsp.dll.CryptGenRandom
ole32.dll.NdrOleInitializeExtension
ole32.dll.CoGetClassObject
ole32.dll.CoGetMarshalSizeMax
ole32.dll.CoMarshalInterface
ole32.dll.CoUnmarshalInterface
ole32.dll.StringFromIID
ole32.dll.CoGetPSClsid
ole32.dll.CoCreateInstance
ole32.dll.CoReleaseMarshalData
ole32.dll.DcomChannelSetHResult
rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
ole32.dll.MkParseDisplayName
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
fastprox.dll.DllGetClassObject
fastprox.dll.DllCanUnloadNow
ole32.dll.BindMoniker
sxs.dll.SxsOleAut32RedirectTypeLibrary
advapi32.dll.RegOpenKeyW
advapi32.dll.RegEnumKeyW
advapi32.dll.RegQueryValueW
sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid
sxs.dll.SxsLookupClrGuid
kernel32.dll.ReleaseActCtx
oleaut32.dll.#9
oleaut32.dll.#4
mscoreei.dll._CorDllMain
mscoree.dll.GetTokenForVTableEntry
mscoree.dll.SetTargetForVTableEntry
mscoree.dll.GetTargetForVTableEntry
mscoreei.dll.GetTokenForVTableEntry
mscoreei.dll.SetTargetForVTableEntry
mscoreei.dll.GetTargetForVTableEntry
kernel32.dll.LocalAlloc
oleaut32.dll.VariantInit
oleaut32.dll.VariantClear
kernel32.dll.CreateEventW
kernel32.dll.SwitchToThread
kernel32.dll.SetEvent
ole32.dll.CoWaitForMultipleHandles
ole32.dll.IIDFromString
wminet_utils.dll.ResetSecurity
wminet_utils.dll.SetSecurity
wminet_utils.dll.BlessIWbemServices
wminet_utils.dll.BlessIWbemServicesObject
wminet_utils.dll.GetPropertyHandle
wminet_utils.dll.WritePropertyValue
wminet_utils.dll.Clone
wminet_utils.dll.VerifyClientKey
wminet_utils.dll.GetQualifierSet
wminet_utils.dll.Get
wminet_utils.dll.Put
wminet_utils.dll.Delete
wminet_utils.dll.GetNames
wminet_utils.dll.BeginEnumeration
wminet_utils.dll.Next
wminet_utils.dll.EndEnumeration
wminet_utils.dll.GetPropertyQualifierSet
wminet_utils.dll.GetObjectText
wminet_utils.dll.SpawnDerivedClass
wminet_utils.dll.SpawnInstance
wminet_utils.dll.CompareTo
wminet_utils.dll.GetPropertyOrigin
wminet_utils.dll.InheritsFrom
wminet_utils.dll.GetMethod
wminet_utils.dll.PutMethod
wminet_utils.dll.DeleteMethod
wminet_utils.dll.BeginMethodEnumeration
wminet_utils.dll.NextMethod
wminet_utils.dll.EndMethodEnumeration
wminet_utils.dll.GetMethodQualifierSet
wminet_utils.dll.GetMethodOrigin
wminet_utils.dll.QualifierSet_Get
wminet_utils.dll.QualifierSet_Put
wminet_utils.dll.QualifierSet_Delete
wminet_utils.dll.QualifierSet_GetNames
wminet_utils.dll.QualifierSet_BeginEnumeration
wminet_utils.dll.QualifierSet_Next
wminet_utils.dll.QualifierSet_EndEnumeration
wminet_utils.dll.GetCurrentApartmentType
wminet_utils.dll.GetDemultiplexedStub
wminet_utils.dll.CreateInstanceEnumWmi
wminet_utils.dll.CreateClassEnumWmi
wminet_utils.dll.ExecQueryWmi
wminet_utils.dll.ExecNotificationQueryWmi
wminet_utils.dll.PutInstanceWmi
wminet_utils.dll.PutClassWmi
wminet_utils.dll.CloneEnumWbemClassObject
wminet_utils.dll.ConnectServerWmi
wminet_utils.dll.GetErrorInfo
wminet_utils.dll.Initialize
oleaut32.dll.SysStringLen
kernel32.dll.RtlZeroMemory
ole32.dll.CoUninitialize
oleaut32.dll.#500
kernel32.dll.RegOpenKeyExW
oleaut32.dll.#7
cryptsp.dll.CryptGetHashParam
kernel32.dll.GetEnvironmentVariableW
advapi32.dll.GetUserNameW
kernel32.dll.GetComputerNameW
kernel32.dll.CreateIoCompletionPort
kernel32.dll.PostQueuedCompletionStatus
ntdll.dll.NtQueryInformationThread
ntdll.dll.NtGetCurrentProcessorNumber
kernel32.dll.CreateDirectoryW
kernel32.dll.CopyFileW
advapi32.dll.RegSetValueExW
kernel32.dll.DeleteFileW
user32.dll.GetLastInputInfo
shfolder.dll.SHGetFolderPathW
ole32.dll.CLSIDFromProgIDEx
oleaut32.dll.#2
oleaut32.dll.#6
kernel32.dll.FindFirstFileW
kernel32.dll.FindClose
oleaut32.dll.#201
mscoreei.dll.LoadLibraryShim
culture.dll.ConvertLangIdToCultureName
kernel32.dll.ReadFile
oleaut32.dll.#204
oleaut32.dll.#203
kernel32.dll.UnmapViewOfFile
vaultcli.dll.VaultEnumerateVaults
user32.dll.GetDC
user32.dll.GetMonitorInfoW
gdi32.dll.GetDeviceCaps
user32.dll.ReleaseDC
user32.dll.GetUserObjectInformationA
kernel32.dll.SetConsoleCtrlHandler
user32.dll.GetClassInfoW
user32.dll.MsgWaitForMultipleObjectsEx
kernel32.dll.FindAtomW
kernel32.dll.AddAtomW
mscoree.dll.LoadLibraryShim
gdiplus.dll.GdiplusStartup
user32.dll.GetWindowInfo
user32.dll.GetAncestor
user32.dll.EnumDisplayDevicesA
gdi32.dll.ExtTextOutW
gdi32.dll.GdiIsMetaPrintDC
gdiplus.dll.GdipCreateBitmapFromScan0
gdiplus.dll.GdipGetImageEncodersSize
gdiplus.dll.GdipGetImageEncoders
kernel32.dll.RtlMoveMemory
kernel32.dll.LocalFree
mscoree.dll.ND_WI4
mscoreei.dll.ND_WI4
gdiplus.dll.GdipGetImagePixelFormat
gdiplus.dll.GdipGetImageGraphicsContext
gdi32.dll.GetCurrentObject
gdiplus.dll.GdipGetDC
gdi32.dll.BitBlt
gdiplus.dll.GdipReleaseDC
gdiplus.dll.GdipSaveImageToStream
windowscodecs.dll.DllGetClassObject
oleaut32.dll.#8
oleaut32.dll.#10
kernel32.dll.FindNextFileW
oleaut32.dll.#179
crypt32.dll.CryptUnprotectData
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.NdrClientCall2
cryptbase.dll.SystemFunction041
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
user32.dll.SetClipboardViewer
ole32.dll.OleInitialize
ole32.dll.OleGetClipboard
gdiplus.dll.GdipDeleteGraphics
kernel32.dll.GlobalLock
kernel32.dll.GlobalUnlock
kernel32.dll.GlobalFree
user32.dll.SendMessageW
user32.dll.SetWindowsHookExW
user32.dll.GetClientRect
user32.dll.GetWindowRect
user32.dll.GetParent
ole32.dll.CoRegisterMessageFilter
user32.dll.PeekMessageW
user32.dll.IsWindowUnicode
user32.dll.GetMessageW
user32.dll.TranslateMessage
user32.dll.DispatchMessageW
user32.dll.WaitMessage
kernel32.dll.GlobalMemoryStatusEx
mscoree.dll.ND_RI2
mscoreei.dll.ND_RI2
iphlpapi.dll.GetNetworkParams
dnsapi.dll.DnsQueryConfig
iphlpapi.dll.GetAdaptersAddresses
iphlpapi.dll.GetIpInterfaceEntry
iphlpapi.dll.GetBestInterfaceEx
ws2_32.dll.WSAStartup
ws2_32.dll.WSASocketW
ws2_32.dll.setsockopt
ws2_32.dll.WSAEventSelect
ws2_32.dll.ioctlsocket
ws2_32.dll.closesocket
advapi32.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
kernel32.dll.CreateFileMappingW
kernel32.dll.VirtualQuery
kernel32.dll.ReleaseMutex
advapi32.dll.CreateWellKnownSid
kernel32.dll.CreateMutexW
kernel32.dll.WaitForSingleObject
kernel32.dll.OpenMutexW
kernel32.dll.OpenProcess
kernel32.dll.GetProcessTimes
ws2_32.dll.inet_addr
kernel32.dll.ResetEvent
kernel32.dll.CreateSemaphoreA
ws2_32.dll.getaddrinfo
ws2_32.dll.freeaddrinfo
kernel32.dll.GetTempPathW
kernel32.dll.FormatMessageW
vssapi.dll.CreateWriter
advapi32.dll.LookupAccountNameW
samcli.dll.NetLocalGroupGetMembers
samlib.dll.SamConnect
samlib.dll.SamOpenDomain
samlib.dll.SamLookupNamesInDomain
samlib.dll.SamOpenAlias
samlib.dll.SamFreeMemory
samlib.dll.SamCloseHandle
samlib.dll.SamGetMembersInAlias
netutils.dll.NetApiBufferFree
ole32.dll.CoCreateGuid
ole32.dll.StringFromCLSID
propsys.dll.VariantToPropVariant
wbemcore.dll.Reinitialize
wbemsvc.dll.DllGetClassObject
wbemsvc.dll.DllCanUnloadNow
authz.dll.AuthzInitializeContextFromToken
authz.dll.AuthzInitializeObjectAccessAuditEvent2
authz.dll.AuthzAccessCheck
authz.dll.AuthzFreeAuditEvent
authz.dll.AuthzFreeContext
authz.dll.AuthzInitializeResourceManager
authz.dll.AuthzFreeResourceManager
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.RpcBindingBind
rpcrt4.dll.I_RpcMapWin32Status
advapi32.dll.EventUnregister
advapi32.dll.EventWrite
advapi32.dll.EventActivityIdControl
advapi32.dll.EventWriteTransfer
advapi32.dll.EventEnabled
kernel32.dll.RegCloseKey
kernel32.dll.RegSetValueExW
kernel32.dll.RegQueryValueExW
wmisvc.dll.IsImproperShutdownDetected
wevtapi.dll.EvtRender
wevtapi.dll.EvtNext
wevtapi.dll.EvtClose
wevtapi.dll.EvtQuery
wevtapi.dll.EvtCreateRenderContext
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcBindingSetOption
ole32.dll.CoCreateFreeThreadedMarshaler
ole32.dll.CreateStreamOnHGlobal
cryptsp.dll.CryptReleaseContext
kernelbase.dll.InitializeAcl
kernelbase.dll.AddAce
kernel32.dll.OpenProcessToken
kernelbase.dll.GetTokenInformation
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.AdjustTokenPrivileges
kernel32.dll.SetThreadToken
kernelbase.dll.CheckTokenMembership
kernelbase.dll.AllocateAndInitializeSid
ole32.dll.CLSIDFromString
authz.dll.AuthzInitializeContextFromSid
ole32.dll.CoGetCallContext
ole32.dll.StringFromGUID2
ole32.dll.CoImpersonateClient
ole32.dll.CoRevertToSelf
ole32.dll.CoSwitchCallContext
sspicli.dll.LogonUserExExW
"C:\Users\Rebecca\AppData\Local\Temp\AlV8bUk.exe"
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\system32\lsass.exe
Global\CLR_CASOFF_MUTEX
Global\.net clr networking
VaultSvc

PE Information

Image Base Entry Point Reported Checksum Actual Checksum Minimum OS Version Compile Time Import Hash Icon Icon Exact Hash Icon Similarity Hash
0x00400000 0x0046282c 0x00000000 0x000badb8 4.0 1992-06-19 22:22:17 a3bfafd3839d7a926bcc393a99921236 b196788ae84ca5d7e6327df18fc58a89 0ab954406964a00a463561e23b1fff82

Sections

Name RAW Address Virtual Address Virtual Size Size of Raw Data Characteristics Entropy
CODE 0x00000400 0x00001000 0x00061874 0x00061a00 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.52
DATA 0x00061e00 0x00063000 0x0000ae28 0x0000b000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5.02
BSS 0x0006ce00 0x0006e000 0x00000bf9 0x00000000 IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
.idata 0x0006ce00 0x0006f000 0x000022b0 0x00002400 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4.95
.tls 0x0006f200 0x00072000 0x00000010 0x00000000 IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
.rdata 0x0006f200 0x00073000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ 0.20
.reloc 0x0006f400 0x00074000 0x00007188 0x00007200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ 6.65
.rsrc 0x00076600 0x0007c000 0x00041774 0x00041800 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ 7.36

Resources

Name Offset Size Language Sub-language Entropy File type
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_CURSOR 0x000b6c08 0x00000369 LANG_ENGLISH SUBLANG_ENGLISH_US 0.00 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_BITMAP 0x000b81a8 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL 2.85 None
RT_ICON 0x000b8290 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US 2.75 None
RT_DIALOG 0x000ba838 0x00000052 LANG_NEUTRAL SUBLANG_NEUTRAL 2.56 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_STRING 0x000bcd94 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL 3.19 None
RT_RCDATA 0x000bd5ec 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US 7.10 None
RT_RCDATA 0x000bd5ec 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US 7.10 None
RT_RCDATA 0x000bd5ec 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US 7.10 None
RT_RCDATA 0x000bd5ec 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US 7.10 None
RT_GROUP_CURSOR 0x000bd74c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL 2.02 None
RT_GROUP_CURSOR 0x000bd74c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL 2.02 None
RT_GROUP_CURSOR 0x000bd74c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL 2.02 None
RT_GROUP_CURSOR 0x000bd74c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL 2.02 None
RT_GROUP_CURSOR 0x000bd74c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL 2.02 None
RT_GROUP_CURSOR 0x000bd74c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL 2.02 None
RT_GROUP_CURSOR 0x000bd74c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL 2.02 None
RT_GROUP_ICON 0x000bd760 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US 2.02 None

Imports

0x46f13c VirtualFree
0x46f140 VirtualAlloc
0x46f144 LocalFree
0x46f148 LocalAlloc
0x46f14c GetVersion
0x46f150 GetCurrentThreadId
0x46f15c VirtualQuery
0x46f160 WideCharToMultiByte
0x46f164 MultiByteToWideChar
0x46f168 lstrlenA
0x46f16c lstrcpynA
0x46f170 LoadLibraryExA
0x46f174 GetThreadLocale
0x46f178 GetStartupInfoA
0x46f17c GetProcAddress
0x46f180 GetModuleHandleA
0x46f184 GetModuleFileNameA
0x46f188 GetLocaleInfoA
0x46f18c GetCommandLineA
0x46f190 FreeLibrary
0x46f194 FindFirstFileA
0x46f198 FindClose
0x46f19c ExitProcess
0x46f1a0 WriteFile
0x46f1a8 RtlUnwind
0x46f1ac RaiseException
0x46f1b0 GetStdHandle
0x46f1b8 GetKeyboardType
0x46f1bc LoadStringA
0x46f1c0 MessageBoxA
0x46f1c4 CharNextA
0x46f1cc RegQueryValueExA
0x46f1d0 RegOpenKeyExA
0x46f1d4 RegCloseKey
0x46f1dc SysFreeString
0x46f1e0 SysReAllocStringLen
0x46f1e4 SysAllocStringLen
0x46f1ec TlsSetValue
0x46f1f0 TlsGetValue
0x46f1f4 LocalAlloc
0x46f1f8 GetModuleHandleA
0x46f200 RegQueryValueExA
0x46f204 RegOpenKeyExA
0x46f208 RegCloseKey
0x46f210 lstrcpyA
0x46f214 WriteFile
0x46f21c WaitForSingleObject
0x46f220 VirtualQuery
0x46f224 VirtualAlloc
0x46f228 Sleep
0x46f22c SizeofResource
0x46f230 SetThreadLocale
0x46f234 SetFilePointer
0x46f238 SetEvent
0x46f23c SetErrorMode
0x46f240 SetEndOfFile
0x46f244 ResetEvent
0x46f248 ReadFile
0x46f24c MulDiv
0x46f250 LockResource
0x46f254 LoadResource
0x46f258 LoadLibraryA
0x46f264 GlobalUnlock
0x46f268 GlobalReAlloc
0x46f26c GlobalHandle
0x46f270 GlobalLock
0x46f274 GlobalFree
0x46f278 GlobalFindAtomA
0x46f27c GlobalDeleteAtom
0x46f280 GlobalAlloc
0x46f284 GlobalAddAtomA
0x46f288 GetVersionExA
0x46f28c GetVersion
0x46f290 GetTickCount
0x46f294 GetThreadLocale
0x46f29c GetSystemTime
0x46f2a0 GetSystemInfo
0x46f2a4 GetStringTypeExA
0x46f2a8 GetStdHandle
0x46f2ac GetProcAddress
0x46f2b0 GetModuleHandleA
0x46f2b4 GetModuleFileNameA
0x46f2b8 GetLocaleInfoA
0x46f2bc GetLocalTime
0x46f2c0 GetLastError
0x46f2c4 GetFullPathNameA
0x46f2c8 GetFileAttributesA
0x46f2cc GetDiskFreeSpaceA
0x46f2d0 GetDateFormatA
0x46f2d4 GetCurrentThreadId
0x46f2d8 GetCurrentProcessId
0x46f2dc GetCPInfo
0x46f2e0 GetACP
0x46f2e4 FreeResource
0x46f2e8 InterlockedExchange
0x46f2ec FreeLibrary
0x46f2f0 FormatMessageA
0x46f2f4 FindResourceA
0x46f2f8 FindFirstFileA
0x46f2fc FindClose
0x46f308 ExitThread
0x46f30c EnumCalendarInfoA
0x46f318 CreateThread
0x46f31c CreateFileA
0x46f320 CreateEventA
0x46f324 CompareStringA
0x46f328 CloseHandle
0x46f330 VerQueryValueA
0x46f338 GetFileVersionInfoA
0x46f340 UnrealizeObject
0x46f344 StretchBlt
0x46f348 SetWindowOrgEx
0x46f34c SetWinMetaFileBits
0x46f350 SetViewportOrgEx
0x46f354 SetTextColor
0x46f358 SetStretchBltMode
0x46f35c SetROP2
0x46f360 SetPixel
0x46f364 SetEnhMetaFileBits
0x46f368 SetDIBColorTable
0x46f36c SetBrushOrgEx
0x46f370 SetBkMode
0x46f374 SetBkColor
0x46f378 SelectPalette
0x46f37c SelectObject
0x46f380 SelectClipRgn
0x46f384 SaveDC
0x46f388 RestoreDC
0x46f38c Rectangle
0x46f390 RectVisible
0x46f394 RealizePalette
0x46f398 Polyline
0x46f39c PlayEnhMetaFile
0x46f3a0 PathToRegion
0x46f3a4 PatBlt
0x46f3a8 MoveToEx
0x46f3ac MaskBlt
0x46f3b0 LineTo
0x46f3b4 IntersectClipRect
0x46f3b8 GetWindowOrgEx
0x46f3bc GetWinMetaFileBits
0x46f3c0 GetTextMetricsA
0x46f3cc GetStockObject
0x46f3d0 GetPixel
0x46f3d4 GetPaletteEntries
0x46f3d8 GetObjectA
0x46f3e4 GetEnhMetaFileBits
0x46f3e8 GetDeviceCaps
0x46f3ec GetDIBits
0x46f3f0 GetDIBColorTable
0x46f3f4 GetDCOrgEx
0x46f3fc GetClipRgn
0x46f400 GetClipBox
0x46f404 GetBrushOrgEx
0x46f408 GetBitmapBits
0x46f40c ExcludeClipRect
0x46f410 DeleteObject
0x46f414 DeleteEnhMetaFile
0x46f418 DeleteDC
0x46f41c CreateSolidBrush
0x46f420 CreateRectRgn
0x46f424 CreatePenIndirect
0x46f428 CreatePalette
0x46f430 CreateFontIndirectA
0x46f434 CreateDIBitmap
0x46f438 CreateDIBSection
0x46f43c CreateCompatibleDC
0x46f444 CreateBrushIndirect
0x46f448 CreateBitmap
0x46f44c CopyEnhMetaFileA
0x46f450 BitBlt
0x46f458 CreateWindowExA
0x46f45c WindowFromPoint
0x46f460 WinHelpA
0x46f464 WaitMessage
0x46f468 UpdateWindow
0x46f46c UnregisterClassA
0x46f470 UnhookWindowsHookEx
0x46f474 TranslateMessage
0x46f47c TrackPopupMenu
0x46f484 ShowWindow
0x46f488 ShowScrollBar
0x46f48c ShowOwnedPopups
0x46f490 ShowCursor
0x46f494 SetWindowsHookExA
0x46f498 SetWindowPos
0x46f49c SetWindowPlacement
0x46f4a0 SetWindowLongA
0x46f4a4 SetTimer
0x46f4a8 SetScrollRange
0x46f4ac SetScrollPos
0x46f4b0 SetScrollInfo
0x46f4b4 SetRect
0x46f4b8 SetPropA
0x46f4bc SetParent
0x46f4c0 SetMenuItemInfoA
0x46f4c4 SetMenu
0x46f4c8 SetForegroundWindow
0x46f4cc SetFocus
0x46f4d0 SetCursor
0x46f4d4 SetClassLongA
0x46f4d8 SetCapture
0x46f4dc SetActiveWindow
0x46f4e0 SendMessageA
0x46f4e4 ScrollWindow
0x46f4e8 ScreenToClient
0x46f4ec RemovePropA
0x46f4f0 RemoveMenu
0x46f4f4 ReleaseDC
0x46f4f8 ReleaseCapture
0x46f504 RegisterClassA
0x46f508 RedrawWindow
0x46f50c PtInRect
0x46f510 PostQuitMessage
0x46f514 PostMessageA
0x46f518 PeekMessageA
0x46f51c OffsetRect
0x46f520 OemToCharA
0x46f524 MessageBoxA
0x46f528 MapWindowPoints
0x46f52c MapVirtualKeyA
0x46f530 LockWindowUpdate
0x46f534 LoadStringA
0x46f538 LoadKeyboardLayoutA
0x46f53c LoadIconA
0x46f540 LoadCursorA
0x46f544 LoadBitmapA
0x46f548 KillTimer
0x46f54c IsZoomed
0x46f550 IsWindowVisible
0x46f554 IsWindowEnabled
0x46f558 IsWindow
0x46f55c IsRectEmpty
0x46f560 IsIconic
0x46f564 IsDialogMessageA
0x46f568 IsChild
0x46f56c InvalidateRect
0x46f570 IntersectRect
0x46f574 InsertMenuItemA
0x46f578 InsertMenuA
0x46f57c InflateRect
0x46f584 GetWindowTextA
0x46f588 GetWindowRect
0x46f58c GetWindowPlacement
0x46f590 GetWindowLongA
0x46f594 GetWindowDC
0x46f598 GetTopWindow
0x46f59c GetSystemMetrics
0x46f5a0 GetSystemMenu
0x46f5a4 GetSysColorBrush
0x46f5a8 GetSysColor
0x46f5ac GetSubMenu
0x46f5b0 GetScrollRange
0x46f5b4 GetScrollPos
0x46f5b8 GetScrollInfo
0x46f5bc GetPropA
0x46f5c0 GetParent
0x46f5c4 GetWindow
0x46f5c8 GetMessagePos
0x46f5cc GetMenuStringA
0x46f5d0 GetMenuState
0x46f5d4 GetMenuItemInfoA
0x46f5d8 GetMenuItemID
0x46f5dc GetMenuItemCount
0x46f5e0 GetMenu
0x46f5e4 GetLastActivePopup
0x46f5e8 GetKeyboardState
0x46f5f0 GetKeyboardLayout
0x46f5f4 GetKeyState
0x46f5f8 GetKeyNameTextA
0x46f5fc GetIconInfo
0x46f600 GetForegroundWindow
0x46f604 GetFocus
0x46f608 GetDlgItem
0x46f60c GetDesktopWindow
0x46f610 GetDCEx
0x46f614 GetDC
0x46f618 GetCursorPos
0x46f61c GetCursor
0x46f620 GetClipboardData
0x46f624 GetClientRect
0x46f628 GetClassNameA
0x46f62c GetClassInfoA
0x46f630 GetCapture
0x46f634 GetActiveWindow
0x46f638 FrameRect
0x46f63c FindWindowA
0x46f640 FillRect
0x46f644 EqualRect
0x46f648 EnumWindows
0x46f64c EnumThreadWindows
0x46f650 EndPaint
0x46f654 EndDeferWindowPos
0x46f658 EnableWindow
0x46f65c EnableScrollBar
0x46f660 EnableMenuItem
0x46f664 DrawTextA
0x46f668 DrawMenuBar
0x46f66c DrawIconEx
0x46f670 DrawIcon
0x46f674 DrawFrameControl
0x46f678 DrawFocusRect
0x46f67c DrawEdge
0x46f680 DispatchMessageA
0x46f684 DestroyWindow
0x46f688 DestroyMenu
0x46f68c DestroyIcon
0x46f690 DestroyCursor
0x46f694 DeleteMenu
0x46f698 DeferWindowPos
0x46f69c DefWindowProcA
0x46f6a0 DefMDIChildProcA
0x46f6a4 DefFrameProcA
0x46f6a8 CreatePopupMenu
0x46f6ac CreateMenu
0x46f6b0 CreateIcon
0x46f6b4 ClientToScreen
0x46f6b8 CheckMenuItem
0x46f6bc CallWindowProcA
0x46f6c0 CallNextHookEx
0x46f6c4 BeginPaint
0x46f6c8 BeginDeferWindowPos
0x46f6cc CharNextA
0x46f6d0 CharLowerBuffA
0x46f6d4 CharLowerA
0x46f6d8 CharToOemA
0x46f6dc AdjustWindowRectEx
0x46f6e8 Sleep
0x46f6f0 SafeArrayPtrOfIndex
0x46f6f4 SafeArrayGetUBound
0x46f6f8 SafeArrayGetLBound
0x46f6fc SafeArrayCreate
0x46f700 VariantChangeType
0x46f704 VariantCopy
0x46f708 VariantClear
0x46f70c VariantInit
0x46f71c ImageList_Write
0x46f720 ImageList_Read
0x46f730 ImageList_DragMove
0x46f734 ImageList_DragLeave
0x46f738 ImageList_DragEnter
0x46f73c ImageList_EndDrag
0x46f740 ImageList_BeginDrag
0x46f744 ImageList_Remove
0x46f748 ImageList_DrawEx
0x46f74c ImageList_Replace
0x46f750 ImageList_Draw
0x46f760 ImageList_Add
0x46f768 ImageList_Destroy
0x46f76c ImageList_Create
0x46f770 InitCommonControls
0x46f778 GetSaveFileNameA
0x46f77c GetOpenFileNameA

This program must be run under Win32
`DATA
.idata
.rdata
P.reloc
P.rsrc
Boolean
False
Integer
Cardinal
String
TObject
TObject
System
IInterface
System
TInterfacedObject
SVWUQ
Z]_^[
YZ]_^[
w;;t$
SVWUQ
Z]_^[
YZ]_^[
Uhd"@
_^[YY]
_^[Y]
YZ]_^[
_^[Y]
C<"u1S
Q<"u8S
,$YXZ
~KxI[)
BkU'9
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
_^[YY]
PPRTj
YZXtp
YZXtm1
ZTUWVSPRTj
t=HtN
Ph~;@
Uhf<@
t-Rf;
t f;J
SVWRP
Z_^[X
tVSVWU
t1SVW
t-Rf;
t f;J
kernel32.dll
GetLongPathNameA
Software\Borland\Locales
Software\Borland\Delphi\Locales
_^[YY]
FFF;M
^[YY]
odSelected
odGrayed
odDisabled
odChecked
odFocused
odDefault
odHotLight
odInactive
odNoAccel
odNoFocusRect
odReserved1
odReserved2
odComboBoxEdit
Windows
TOwnerDrawState
_^[Y]
_^[Y]
_^[Y]
Magellan MSWHEEL
MouseZ
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
TFileName
Exception
EHeapException
EOutOfMemory
EInOutError
EExternal
EExternalException
EIntError
EDivByZero
ERangeError
EIntOverflow
EMathError
EInvalidOp
EZeroDivide
EOverflow
EUnderflow
EInvalidPointer
EInvalidCast
EConvertError
EAccessViolation
EPrivilege
EStackOverflow
EControlC
EVariantError
EAssertionFailed
EAbstractError
EIntfCastError
EOSError
ESafecallException
SysUtils
SysUtils
TThreadLocalCounter
$TMultiReadExclusiveWriteSynchronizer
SWSVj
False
_^[Y]
TStrData
^[YY]
$Z_^[
$Z_^[
^[YY]
<*t"<0r=<9w9i
INFNAN
QS<$t
_^[YY]
t%HtIHtm
AM/PM
_^[YY]
SVWUQ
$Z]_^[
_^[Y]
QQQQQQSVW3
QQQQQSVW
D$PPj
D$LPj
_^[Y]
_^[YY]
TErrorRec
TExceptRec
t<HtH
$YZ^[
$YZ^[
WUWSj
YZ]_^[
_^[Y]
m/d/yy
mmmm d, yyyy
AMPM
AMPM
:mm:ss
kernel32.dll
GetDiskFreeSpaceExA
SVWUQ
(Z]_^[
SVWUQ
;w$t|
Z]_^[
;F$t=
;C$t4
_^[Y]
oleaut32.dll
VariantChangeTypeEx
VarNeg
VarNot
VarAdd
VarSub
VarMul
VarDiv
VarIdiv
VarMod
VarAnd
VarOr
VarXor
VarCmp
VarI4FromStr
VarR4FromStr
VarR8FromStr
VarDateFromStr
VarCyFromStr
VarBoolFromStr
VarBstrFromCy
VarBstrFromDate
VarBstrFromBool
TCustomVariantType
TCustomVariantType
Variants
EVariantInvalidOpError
EVariantTypeCastError
EVariantOverflowError
EVariantInvalidArgError`
EVariantBadVarTypeError
EVariantBadIndexError
EVariantArrayLockedError
EVariantArrayCreateError
EVariantNotImplError
EVariantOutOfMemoryError
EVariantUnexpectedError(
EVariantDispatchError
t?Htb
QQQQSV
Empty
Smallint
Integer
Single
Double
Currency
OleStr
Dispatch
Error
Boolean
Variant
Unknown
Decimal
ShortInt
LongWord
Int64
String
Array
ByRef
Variants
_^[YY]
_^[Y]
SVWUQ
Z]_^[
_^[Y]
False
_^[Y]
_^[YY]
$YZ^[
TAlignment
taLeftJustify
taRightJustify
taCenter
Classes
TLeftRight
Classes
TBiDiMode
bdLeftToRight
bdRightToLeft
bdRightToLeftNoAlign
bdRightToLeftReadingOnly
Classes
ssShift
ssAlt
ssCtrl
ssLeft
ssRight
ssMiddle
ssDouble
Classes
TShiftState
THelpContext
THelpType
htKeyword
htContext
Classes
TShortCut
TNotifyEvent
Sender
TObject
EStreamError
EFileStreamError
EFCreateError
EFOpenError
EFilerErrorD
EReadError
EWriteError
EClassNotFound
EResNotFound
EListError
EBitsError
EStringListError
EComponentError
EOutOfResourcest
EInvalidOperation
TList
TThreadList
TBits
TPersistent
TPersistent
Classes
TInterfacedPersistent
TInterfacedPersistent
Classes
TCollectionItem
TCollectionItem
Classes
TCollection
Classes
IStringsAdapter
Classes
TStrings
TStringsL
Classes
TStringItem
TStringList$
TStringList|
Classes
TStream
THandleStream
TFileStream
TCustomMemoryStreaml!A
TMemoryStream
TResourceStream
TStreamAdapter
TClassFinder
TFiler
TReader
EThreadX%A
TComponentNamel%A
IDesignerNotify
Classes
TComponent
TComponent
Classes
Name<
TBasicActionLink
TBasicAction
TBasicActiont(A
Classes
TIdentMapEntry
TRegGroup
TRegGroups
YZ]_^[
_^[Y]
_^[Y]
SVWUQ
u%CNu
Z]_^[
SVWUQ
$Z]_^[
Uh3-A
SVWUQ
Z]_^[
SVWUQ
Z]_^[
SVWUQ
Z]_^[
UhC0A
SVWUQ
$Z]_^[
Uh+3A
_^[YY]
Uh|4A
Uha5A
UhK6A
TIntConst
_^[Y]
_^[Y]
_^[YY]
_^[Y]
Uh*;A
;5H&A
UhP=A
Uh4AA
SVWUQ
Z]_^[
UhZDA
PhtFA
_^[Y]
UhIHA
%s[%d]
_^[Y]
W<CNu
UhtOA
PhdZA
Strings
_^[Y]
UhpRA
UhNRA
UhWUA
S$_^[Y]
^[YY]
UhmWA
UhPWA
_^[YY]
SVWUQ
SdZ]_^[
UhXXA
Uh3XA
UhTZA
Uh7ZA
SVWUQ
$Z]_^[
^[YY]
Uh\eA
_^[Y]
TPropFixup
TPropIntfFixup
_^[YY]
Owner
UhapA
_^[YY]
Uh#rA
_^[Y]
Uh/vA
C0_^[
UhWxA
Classes
_^[Y]
UhX|A
False
_^[YY]
QQQQ3
%s_%d
_^[YY]
^[YY]
QQQQQQQS
SVWUQ
Z]_^[
_^[Y]
S _^[
SVWUQ
Z]_^[
YZ_^[
SVWUQ
Z]_^[
G0_^[
;CDt:
R0_^[]
_^[YY]
TPUtilWindow
TColor
EInvalidGraphic
EInvalidGraphicOperation
TFontPitch
fpDefault
fpVariable
fpFixed
Graphics
TFontName
TFontCharset
TFontStyle
fsBold
fsItalic
fsUnderline
fsStrikeOut
Graphics
TFontStyles
TPenStyle
psSolid
psDash
psDot
psDashDot
psDashDotDot
psClear
psInsideFrame
Graphics
TPenMode
pmBlack
pmWhite
pmNop
pmNot
pmCopy
pmNotCopy
pmMergePenNot
pmMaskPenNot
pmMergeNotPen
pmMaskNotPen
pmMerge
pmNotMerge
pmMask
pmNotMask
pmXor
pmNotXor
Graphics
TBrushStyle
bsSolid
bsClear
bsHorizontal
bsVertical
bsFDiagonal
bsBDiagonal
bsCross
bsDiagCross
Graphics
TGraphicsObject
TGraphicsObject
Graphics
IChangeNotifier
Graphics
TFont
TFont
Graphics
CharsetX
Color<
Heightx
Name4
Pitch<
Style
TPenH
Graphics
Colort
Style<
Width
TBrush
TBrushH
Graphics
Color0
Style
TCanvas0
TCanvas
Graphics
Brush<
CopyMode
Font\
TProgressStage
psStarting
psRunning
psEnding
Graphics
TProgressEvent
Sender
TObject
Stage
TProgressStage
PercentDone
RedrawNow
Boolean
TRect
String
TGraphic
TGraphich
Graphics
TPicture
TPicture
Graphics
TSharedImage
TMetafileImage
TMetafile
TMetafile(
Graphics
TBitmapImage
TBitmap
TBitmaph
Graphics
TIconImage
TIcon
TIcon
Graphics
TResourceManager
^[YY]
_^[YY]
_^[Y]
^[YY]
clBlack
clMaroon
clGreen
clOlive
clNavy
clPurple
clTeal
clGray
clSilver
clRed
clLime
clYellow
clBlue
clFuchsia
clAqua
clWhite
clMoneyGreen
clSkyBlue
clCream
clMedGray
clActiveBorder
clActiveCaption
clAppWorkSpace
clBackground
clBtnFace
clBtnHighlight
clBtnShadow
clBtnText
clCaptionText
clDefault
clGradientActiveCaption
clGradientInactiveCaption
clGrayText
clHighlight
clHighlightText
clHotLight
clInactiveBorder
clInactiveCaption
clInactiveCaptionText
clInfoBk
clInfoText
clMenu
clMenuBar
clMenuHighlight
clMenuText
clNone
clScrollBar
cl3DDkShadow
cl3DLight
clWindow
clWindowFrame
clWindowText
ANSI_CHARSET
DEFAULT_CHARSET
SYMBOL_CHARSET
MAC_CHARSET
SHIFTJIS_CHARSET
HANGEUL_CHARSET
JOHAB_CHARSET
GB2312_CHARSET
CHINESEBIG5_CHARSET
GREEK_CHARSET
TURKISH_CHARSET
HEBREW_CHARSET
ARABIC_CHARSET
BALTIC_CHARSET
RUSSIAN_CHARSET
THAI_CHARSET
EASTEUROPE_CHARSET
OEM_CHARSET
Default
_^[Y]
$YZ^[
E$PVSj
YZ_^[
$Z_^[
_^[YY]
C ;C$s
TFileFormat
TFileFormatsList
QQQQSV
_^[YY]
%s%s (*.%s)|*.%2:s
%s*.%s
%s (%s)|%1:s|%s
TClipboardFormats
_^[YY]
_^[Y]
3TjdP
kD$TdP
3TjdP
kD$PdP
EMFt
?TjdR
D$LPkD$XdPV
?TjdR
D$HPkD$TdPV
|$( EMFt
^[YY]
TBitmapCanvas
TBitmapCanvasH
Graphics
Uhv B
UhT B
Uh* B
UhK#B
@pPV3
Uh%(B
Uhg+B
Uh+.B
_^[YY]
Uh73B
Uhs2B
<$BMt
Uh?5B
T]_^[
s(;~ t8
;V4tA
D$*Ph
Uh.<B
C(_^[Y]
UhIAB
\$4Vj
SVWjH
TPatternManagerSV
_^[YY]
UhIFB
TObjectListLHB
TOrderedList
TStack
Uh=JB
comctl32.dll
InitCommonControlsEx
_^[Y]
GetMonitorInfoA
GetSystemMetrics
MonitorFromRect
MonitorFromWindow
MonitorFromPoint
>(r[j
GetMonitorInfo
DISPLAY
>(r[j
GetMonitorInfoA
DISPLAY
>(r[j
GetMonitorInfoW
DISPLAY
EnumDisplayMonitors
USER32.DLL
UhUSB
IHelpSelector
HelpIntfs
IHelpSystem
HelpIntfs
ICustomHelpViewer
HelpIntfs
IExtendedHelpViewer
HelpIntfs
ISpecialWinHelpViewerPTB
HelpIntfs
IHelpManager
HelpIntfs
EHelpSystemException
THelpViewerNode
THelpManager
R(FKu
Uh5_B
Uh7`B
Uh;aB
UhMbB
_^[Y]
comctl32.dll
InitializeFlatSB
UninitializeFlatSB
FlatSB_GetScrollProp
FlatSB_SetScrollProp
FlatSB_EnableScrollBar
FlatSB_ShowScrollBar
FlatSB_GetScrollRange
FlatSB_GetScrollInfo
FlatSB_GetScrollPos
FlatSB_SetScrollPos
FlatSB_SetScrollInfo
FlatSB_SetScrollRange
Uh!gB
TSynchroObject
TCriticalSection
UhSnB
uxtheme.dll
OpenThemeData
CloseThemeData
DrawThemeBackground
DrawThemeText
GetThemeBackgroundContentRect
GetThemePartSize
GetThemeTextExtent
GetThemeTextMetrics
GetThemeBackgroundRegion
HitTestThemeBackground
DrawThemeEdge
DrawThemeIcon
IsThemePartDefined
IsThemeBackgroundPartiallyTransparent
GetThemeColor
GetThemeMetric
GetThemeString
GetThemeBool
GetThemeInt
GetThemeEnumValue
GetThemePosition
GetThemeFont
GetThemeRect
GetThemeMargins
GetThemeIntList
GetThemePropertyOrigin
SetWindowTheme
GetThemeFilename
GetThemeSysColor
GetThemeSysColorBrush
GetThemeSysBool
GetThemeSysSize
GetThemeSysFont
GetThemeSysString
GetThemeSysInt
IsThemeActive
IsAppThemed
GetWindowTheme
EnableThemeDialogTexture
IsThemeDialogTextureEnabled
GetThemeAppProperties
SetThemeAppProperties
GetCurrentThemeName
GetThemeDocumentationProperty
DrawThemeParentBackground
EnableTheming
UhtrB
TEdgeBorder
ebLeft
ebTop
ebRight
ebBottom
ToolWin
TEdgeBorders
TEdgeStyle
esNone
esRaised
esLowered
ToolWin
TToolWindow
TToolWindow
ToolWin
Uh>wB
Uh!xB
UhYxB
IShellFolder
ShlObj
UhEyB
Uh}yB
TCommonDialog
TCommonDialog
Dialogs
Ctl3D
HelpContext
OnClose
OnShow
TOpenOption
ofReadOnly
ofOverwritePrompt
ofHideReadOnly
ofNoChangeDir
ofShowHelp
ofNoValidate
ofAllowMultiSelect
ofExtensionDifferent
ofPathMustExist
ofFileMustExist
ofCreatePrompt
ofShareAware
ofNoReadOnlyReturn
ofNoTestFileCreate
ofNoNetworkButton
ofNoLongNames
ofOldStyleDialog
ofNoDereferenceLinks
ofEnableIncludeNotify
ofEnableSizing
ofDontAddToRecent
ofForceShowHidden
Dialogs
TOpenOptions
TOpenOptionEx
ofExNoPlacesBar
Dialogs
TOpenOptionsEx
TOFNotifyEx
TIncludeItemEvent
TOFNotifyEx
Include
Boolean
TOpenDialog
TOpenDialog
Dialogs
DefaultExt
FileName
Filter<
FilterIndex
InitialDir
Options
OptionsEx
Title
OnCanClose
OnFolderChange
OnSelectionChange
OnTypeChange }B
OnIncludeItemSVW
_^[Y]
_^[Y]
;Ght4
FileEditStyle
8Z|03
@\@t*U
u"Vh_
Cancel
Abort
Retry
Ignore
NoToAll
YesToAll
commdlg_help
commdlg_FindReplace
WndProcPtr%.8X%.8X
TImage
TImage
ExtCtrls
Align
Anchors
AutoSize
Centerp
Constraints
DragCursor$
DragKind
DragMode
Enabled
IncrementalDisplay
ParentShowHint
PopupMenu
Proportional
ShowHint
Stretch
Transparent
Visible
OnClickT
OnContextPopup
OnDblClick
OnDragDrop
OnDragOver
OnEndDock
OnEndDrag,
OnMouseDown
OnMouseMove,
OnMouseUp
OnProgress
OnStartDockx
OnStartDrag
TTimer
TTimer
ExtCtrls
Enabled|
Interval
OnTimer
TCustomPanel
TCustomPanel
ExtCtrls
TPanel
TPanel
ExtCtrls7
AlignH
Alignment
Anchors
AutoSize\
BevelInner\
BevelOuterD
BevelWidth
BorderWidth
BorderStylep
CaptionX
Colorp
Constraints
Ctl3D
UseDockManager
DockSite
DragCursor$
DragKind
DragMode
Enabled
FullRepaint
Locked
ParentBiDiMode
ParentBackground
ParentColor
ParentCtl3D
ParentFont
PopupMenu
ShowHintX
TabOrder
TabStop
VisibleX
OnCanResize
OnClick
OnConstrainedResizeT
OnContextPopup
OnDockDrop
OnDockOver
OnDblClick
OnDragDrop
OnDragOver
OnEndDock
OnEndDrag
OnEnter
OnExit
OnGetSiteInfo,
OnMouseDown
OnMouseMove,
OnMouseUp
OnResize
OnStartDockx
OnStartDrag
OnUnDock
TCustomRadioGroup
TCustomRadioGroup
ExtCtrls
TRadioGroup
TRadioGroup0
ExtCtrls$
Align
Anchors
BiDiModep
CaptionX
Color<
Columns
Ctl3D
DragCursor$
DragKind
DragMode
Enabled
Font<
ItemIndex
Itemsp
Constraints
ParentBiDiMode
ParentBackground
ParentColor
ParentCtl3D
ParentFont
PopupMenu
ShowHintX
TabOrder
TabStop
Visible
OnClickT
OnContextPopup
OnDragDrop
OnDragOver
OnEndDock
OnEndDrag
OnEnter
OnExit
OnStartDockx
OnStartDrag
NaturalNumber
TCanResizeEvent
Sender
TObject
NewSize
Integer
Accept
Boolean
TResizeStyle
rsNone
rsLine
rsUpdate
rsPattern
ExtCtrls
TSplitter
TSplitterH
ExtCtrls
Align
AutoSnap
BeveledX
Color
Cursorp
Constraints<
MinSize
ParentColor
ResizeStyle
Visible<
WidthX
OnCanResize
OnMoved
OnPaint
_^[Y]
_^[Y]
TGroupButton
TGroupButton
ExtCtrls
_^[Y]
_^[YY]
QdGNu
Delphi Picture
Delphi Component
TButtonLayout
blGlyphLeft
blGlyphRight
blGlyphTop
blGlyphBottom
Buttons
TNumGlyphs
TSpeedButtonActionLink
TSpeedButton
TSpeedButton
Buttons
Action
AllowAllUp
Anchors
BiDiModep
Constraints<
GroupIndex
Downp
Caption
Enabled
Glyph,
Layout<
Margin
NumGlyphs
ParentFont
ParentShowHint
PopupMenu
ShowHint<
Spacing
Transparent
Visible
OnClick
OnDblClick,
OnMouseDown
OnMouseMove,
OnMouseUp
TGlyphList
TGlyphList
Buttons
TGlyphCache8
TButtonGlyph
SVWUQ
Z]_^[
_^[Y]
_^[Y]
Y^[Y]
TOpenPictureDialog
TOpenPictureDialog
ExtDlgs
Filter
TSavePictureDialog
TSavePictureDialog
ExtDlgs
TSilentPaintPanel
TSilentPaintPanel
ExtDlgs
_^[YY]
_^[YY]
PicturePanel
PictureLabel
PreviewButton
PREVIEWGLYPH
PaintPanel
PaintBox
DLGTEMPLATE
_^[YY]
PreviewForm
Panel
Image
DLGTEMPLATE
MAPI32.DLL
TConversion
TConversionFormat
TCoolBand
TCoolBand
ComCtrls
Bitmap
BorderStyle
BreakX
ColorH
Control
FixedBackground
FixedSize
HorizontalOnlyh
ImageIndex<
MinHeight<
MinWidth
ParentColor
ParentBitmap
Visible<
Width
TCoolBands
TCoolBands
ComCtrls
TCoolBandMaximize
bmNone
bmClick
bmDblClick
ComCtrls
TCoolBar
TCoolBar
ComCtrls1
Align
Anchors
AutoSize
BandBorderStyleX
BandMaximize0
BorderWidthX
Colorp
Constraints
Ctl3D
DockSite
DragCursor$
DragKind
DragMode
EdgeBorders0sB
EdgeInner0sB
EdgeOuter
Enabled
FixedSize
FixedOrder
Font0
Images
ParentColor
ParentFont
ParentShowHint
PopupMenu
ShowHint
ShowText
Vertical
Visible
OnChange
OnClickT
OnContextPopup
OnDblClick
OnDockDrop
OnDockOver
OnDragDrop
OnDragOver
OnEndDock
OnEndDrag
OnGetSiteInfo,
OnMouseDown
OnMouseMove,
OnMouseUp
OnResize
OnStartDockx
OnStartDrag
OnUnDock
comctl32.dll
_^[Y]
;s(tT
ReBarWindow32
Uhm"C
UhD$C
Uh!&C
Uhu%C
Uhk*C
Uh+/C
_^[YY]
Uh>3C
|]_^[
R|^Y]
_^[YY]
_^[Y]
Uh7=C
TThemeServices
Theme manager
2001, 2002 Mike Lischke
^[YY]
!"#$%
Uh_IC
TCustomGroupBox
TCustomGroupBox
StdCtrls
TTextLayout
tlTop
tlCenter
tlBottom
StdCtrls
TCustomLabel
TCustomLabellKC
StdCtrls
TLabel
TLabel
StdCtrls'
AlignH
Alignment
Anchors
AutoSize
BiDiModep
CaptionX
Colorp
Constraints
DragCursor$
DragKind
DragMode
EnabledH
FocusControl
ParentBiDiMode
ParentColor
ParentFont
PopupMenu
ShowAccelChar
ShowHint
Transparent
Layout
Visible
WordWrap
OnClickT
OnContextPopup
OnDblClick
OnDragDrop
OnDragOver
OnEndDock
OnEndDrag,
OnMouseDown
OnMouseMove,
OnMouseUp
OnMouseEnter
OnMouseLeave
OnStartDockx
OnStartDrag
TDrawItemEvent
Control
TWinControl
Index
Integer
TRect
State
TOwnerDrawState
TMeasureItemEvent
Control
TWinControl
Index
Integer
Height
Integer
TButtonActionLink
TButtonControl
TButtonControl
StdCtrls
TRadioButton
TRadioButton`VC
StdCtrls*
Action
Alignment
Anchors
BiDiModep
Caption
CheckedX
Colorp
Constraints
Ctl3D
DragCursor$
DragKind
DragMode
Enabled
ParentBiDiMode
ParentColor
ParentCtl3D
ParentFont
PopupMenu
ShowHintX
TabOrder
TabStop
Visible
WordWrap
OnClickT
OnContextPopup
OnDblClick
OnDragDrop
OnDragOver
OnEndDock
OnEndDrag
OnEnter
OnExit
OnKeyDownT
OnKeyPress
OnKeyUp,
OnMouseDown
OnMouseMove,
OnMouseUp
OnStartDockx
OnStartDrag
TListBoxStyle
lbStandard
lbOwnerDrawFixed
lbOwnerDrawVariable
lbVirtual
lbVirtualOwnerDraw
StdCtrls
TLBGetDataEvent
Control
TWinControl
Index
Integer
String
TLBGetDataObjectEvent
Control
TWinControl
Index
Integer
DataObject
TObject
TLBFindDataEvent
Control
TWinControl
FindString
String
Integer<
TCustomListBox
TCustomListBox8_C
StdCtrls
TabStop
TListBoxStrings
TListBoxStrings\aC
StdCtrls
_^[Y]
UhbiC
_^[Y]
CL+D$
CL+D$
GH+D$
UhQmC
_^[Y]
Z:Pit
UhZnC
_^[YY]
BUTTON
UhMsC
_^[Y]
UhltC
_^[YY]
_^[YY]
UhEvC
_^[YY]
_^[YY]
UhPxC
Uh.xC
_^[YY]
QQQQQQSVW
@YZ^[
YZ_^[
(]_^[
!G$_^[
LISTBOX
YZ]_^[
THintAction
THintActionL
StdActns
TWinHelpViewer
_^[YY]
_^[YY]
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
_^[Y]
JumpID("","%s")
_^[YY]
_^[Y]
MS_WINHELP
#32770
TCursor
TAlign
alNone
alTop
alBottom
alLeft
alRight
alClient
alCustom
Controls
TDragObject|
TDragObjectH
Controls
TBaseDragControlObject
TBaseDragControlObject
Controls
TDragControlObject
TDragControlObjectEx
TDragDockObject
TDragDockObject
Controls
TDragDockObjectEx
TControlCanvas
TControlCanvas,
Controls
TControlActionLink
TMouseButton
mbLeft
mbRight
mbMiddle
Controls
TDragMode
dmManual
dmAutomatic
Controls
TDragState
dsDragEnter
dsDragLeave
dsDragMove
Controls
TDragKind
dkDrag
dkDock
Controls
TTabOrder
TCaption
TAnchorKind
akLeft
akTop
akRight
akBottom
Controls
TAnchors
TConstraintSize
TSizeConstraints
TSizeConstraintsH
Controls
MaxHeight
MaxWidth
MinHeight
MinWidth
TMouseEvent
Sender
TObject
Button
TMouseButton
Shift
TShiftState
Integer
Integer
TMouseMoveEvent
Sender
TObject
Shift
TShiftState
Integer
Integer
TKeyEvent
Sender
TObject
Shift
TShiftState
TKeyPressEvent
Sender
TObject
TDragOverEvent
Sender
TObject
Source
TObject
Integer
Integer
State
TDragState
Accept
Boolean
TDragDropEvent
Sender
TObject
Source
TObject
Integer
Integer
TStartDragEvent
Sender
TObject
DragObject
TDragObject
TEndDragEvent
Sender
TObject
Target
TObject
Integer
Integer
TDockDropEvent
Sender
TObject
Source
TDragDockObject
Integer
Integer
TDockOverEvent
Sender
TObject
Source
TDragDockObject
Integer
Integer
State
TDragState
Accept
Boolean
TUnDockEvent
Sender
TObject
Client
TControl
NewTarget
TWinControl
Allow
Boolean
TStartDockEvent
Sender
TObject
DragObject
TDragDockObject
TGetSiteInfoEvent
Sender
TObject
DockClient
TControl
InfluenceRect
TRect
MousePos
TPoint
CanDock
Boolean
TCanResizeEvent
Sender
TObject
NewWidth
Integer
NewHeight
Integer
Resize
Boolean
TConstrainedResizeEvent
Sender
TObject
MinWidth
Integer
MinHeight
Integer
MaxWidth
Integer
MaxHeight
Integer
TMouseWheelEvent
Sender
TObject
Shift
TShiftState
WheelDelta
Integer
MousePos
TPoint
Handled
Boolean
TMouseWheelUpDownEvent
Sender
TObject
Shift
TShiftState
MousePos
TPoint
Handled
Boolean
TContextPopupEvent
Sender
TObject
MousePos
TPoint
Handled
Boolean
TControl
TControl
Controls
Left<
Width<
Height
Cursor
HelpType
HelpKeyword
HelpContext
TWinControlActionLink
TImeMode
imDisable
imClose
imOpen
imDontCare
imSAlpha
imAlpha
imHira
imSKata
imKata
imChinese
imSHanguel
imHanguel
Controls
TImeName
TBorderWidth
TBevelCut
bvNone
bvLowered
bvRaised
bvSpace
Controls
TBevelEdge
beLeft
beTop
beRight
beBottom
Controls
TBevelEdges
TBevelKind
bkNone
bkTile
bkSoft
bkFlat
Controls
TBevelWidth
IDockManager
Controls
TWinControl
TWinControl
Controls
TGraphicControlh
TGraphicControl
Controls
TCustomControl
TCustomControl
Controls
THintWindow
THintWindow8
Controls
TDragImageList
TDragImageList
Controls
TImageList
TImageList
Controls
BlendColorX
BkColor<
AllocBy
DrawingStyle<
Height4
ImageType
Masked
OnChange
ShareImages<
Width
TDockZone
TDockTree
TMouse
TCustomListControl
TCustomListControl
Controls
TCustomMultiSelectListControl
TCustomMultiSelectListControlD
Controls
crDefault
crArrow
crCross
crIBeam
crSizeNESW
crSizeNS
crSizeNWSE
crSizeWE
crUpArrow
crHourGlass
crDrag
crNoDrop
crHSplit
crVSplit
crMultiDrag
crSQLWait
crAppStart
crHelp
crHandPoint
crSizeAll
crSize
TSiteList
_^[YY]
tPHt8
_^[Y]
S$_^[]
;B0t'
;B8t=
CQ tA
YZ_^[
YZ]_^[
YZ_^[
t%Jt?Jt[
%s (%s)
Z:Pjt
YZ]_^[
$:Cat
u$;~|u
;CLtX3
Qh_^[
YZ_^[
YZ_^[
V:P\t
GP t;
_^[YY]
CH+D$
CL+D$
;s0t=;
:_Wt+
f;Pxt
KHQRP
Ht7Ht
IsControl
_^[YY]
YZ_^[
_^[YY]
_^[Y]
8]_^[
,]_^[
YZ_^[
^[YY]
Uh$!D
RD;PD
Uhm%D
:_[up
Uh{)D
Uh}*D
Uhs+D
SVWUQ
Z]_^[
C$PVj
C$_^[
Uhi2D
:GauOFKu
_^[Y]
DesignSize
Uh15D
_^[YY]
_^[Y]
t2HtY
]_^[
UhSID
_^[Y]
_^[Y]
$Z_^[
_^[YY]
UhtMD
_^[Y]
UhFND
^[YY]
SVWUQ
Z]_^[
SVWUQ
Z]_^[
SVWUQ
Z]_^[
_^[YY]
;XDt#
SVWUQ
Z]_^[
t&j7j
YZ]_^[
YZ]_^[
YZ]_^[
t4VS
R|FOu
YZ]_^[
^[YY]
S8_^[]
UhjkD
+CH+E
+SL+U
UhgmD
UhotD
UhLtD
UhUvD
Uh[wD
UhAyD
_^[Y]
Uh|{D
f;Pht
_^[Y]
t9;wlt4
YZ_^[
;Bdt*
;Bh|3
R|_^[
^dVhp
^dVhp
_^[Y]
Y_^[]
Y[YY]
t$;C8u
QQQQSVW
;Fdu;
^[YY]
Q8FKu
;Xdt>
t#;^dt
YZ_^[
Y_^[]
^[YY]
+W$;U
+G$;E
_^[Y]
BP_^[]
USER32
WINNLSEnableIME
imm32.dll
ImmGetContext
ImmReleaseContext
ImmGetConversionStatus
ImmSetConversionStatus
ImmSetOpenStatus
ImmSetCompositionWindow
ImmSetCompositionFontA
ImmGetCompositionStringA
ImmIsIME
ImmNotifyIME
YZ_^[
Delphi%.8X
ControlOfs%.8X%.8X
USER32
AnimateWindow
TContainedAction
TContainedAction8
ActnList
Category
TCustomActionList
TCustomActionList\
ActnList
TShortCutList
TShortCutList8
ActnList
TCustomAction
TCustomActionT
ActnList
TActionLinkSV
^[YY]
u*;~8u
R0GNu
SVWUQ
Z]_^[
QLGNu
R0Z_^[
QPFOu
_^[Y]
$:Cjt_
QTGNu
R0Z_^[
Q`FOu
R0]_^[
$;Ctt?
Q\GNu
R0Z_^[
QhGNu
R0Z_^[
QlGNu
R0Z_^[
SVWQf
QpGNu
R0Z_^[
QtFOu
R0]_^[
SVWUQ
$Z]_^[
TChangeLink
TDrawingStyle
dsFocus
dsSelected
dsNormal
dsTransparent
ImgList
TImageType
itImage
itMask
ImgListl
TImageIndex
TCustomImageList
TCustomImageList
ImgList
;V4t8
;V0t8
Rd_^[
s8VV3
S0_^[]
R ;C0|
R,;C4}!
S`]_^[
Bitmap
_^[Y]
comctl32.dll
comctl32.dll
ImageList_WriteEx
EMenuError
TMenuBreak
mbNone
mbBreak
mbBarBreak
Menus
TMenuChangeEvent
Sender
TObject
Source
TMenuItem
Rebuild
Boolean
TMenuDrawItemEvent
Sender
TObject
ACanvas
TCanvas
ARect
TRect
Selected
Boolean
TAdvancedMenuDrawItemEvent
Sender
TObject
ACanvas
TCanvas
ARect
TRect
State
TOwnerDrawState
TMenuMeasureItemEvent
Sender
TObject
ACanvas
TCanvas
Width
Integer
Height
Integer
TMenuItemAutoFlag
maAutomatic
maManual
maParent
Menus
TMenuAutoFlag
Menus
TMenuActionLink
TMenuItem
TMenuItem
Menus
Action
AutoCheck`
AutoHotkeys`
AutoLineReduction
Bitmapt
Break
Caption
Checked0
SubMenuImages
Default
EnabledT
GroupIndex
HelpContext
Hinth
ImageIndex
RadioItem
ShortCut
Visible
OnClick
OnDrawItemx
OnAdvancedDrawItem
OnMeasureItem
TMenu
TMenu
Menus
Items
TMainMenu
TMainMenu
Menus
AutoHotkeys
AutoLineReduction
AutoMerge
BiDiMode0
Images
OwnerDraw
ParentBiDiMode
OnChange
TPopupAlignment
paLeft
paRight
paCenter
Menus
TTrackButton
tbRightButton
tbLeftButton
Menus$
TMenuAnimations
maLeftToRight
maRightToLeft
maTopToBottom
maBottomToTop
maNone
Menus
TMenuAnimation
TPopupMenu
TPopupMenu
Menus
Alignment
AutoHotkeys
AutoLineReduction
AutoPopup
BiDiMode
HelpContext0
Images
MenuAnimation
OwnerDraw
ParentBiDiMode
TrackButton
OnChange
OnPopup
TPopupList
TMenuItemStack
1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ
_^[YY]
f;B`t
CPPVj
Q<]_^[
SVWUQ
:X?s&
X?ENu
Z]_^[
ShortCutText
_^[Y]
_^[Y]
P?:S?u
:^8tB
:^9tg
Q<_^[
:^?t1
f;P`t
:]:tJ
Q<]_^[
@?:F?v
Q<]_^[
Q<_^[
W<CNu
Uhh)E
SpFOu
$YZ]_^[
_^[Y]
_^[Y]
SVWUQ
Z]_^[
Uhi0E
_^[YY]
Uhk1E
S0^[]
_^[Y]
_^[Y]
Ih;J4u
_^[Y]
UhU?E
Uh0?E
Sh`:E
YZ]_^[
S0_^[
S<&uO
^[YY]
TScrollBarInc
TScrollBarStyle
ssRegular
ssFlat
ssHotTrack
Forms
TControlScrollBar
TControlScrollBar
Forms
ButtonSizeX
ColorXFE
Incrementh
Margin
ParentColor<
Position<
Range
Smooth<
SizetFE
Style<
ThumbSize
Tracking
Visible
TWindowState
wsNormal
wsMinimized
wsMaximized
Forms
TScrollingWinControl
TScrollingWinControl
Forms
HorzScrollBar$GE
VertScrollBar0KE
TFormBorderStyle
bsNone
bsSingle
bsSizeable
bsDialog
bsToolWindow
bsSizeToolWin
Forms
TBorderStyle
Forms
IDesignerHookh%A
Forms
IOleForm
Forms
TFormStyle
fsNormal
fsMDIChild
fsMDIForm
fsStayOnTop
Forms
TBorderIcon
biSystemMenu
biMinimize
biMaximize
biHelp
Forms
TBorderIcons
TPosition
poDesigned
poDefault
poDefaultPosOnly
poDefaultSizeOnly
poScreenCenter
poDesktopCenter
poMainFormCenter
poOwnerFormCenter
FormsxME
TDefaultMonitor
dmDesktop
dmPrimary
dmMainForm
dmActiveForm
Forms
TPrintScale
poNone
poProportional
poPrintToFit
Forms
TCloseAction
caNone
caHide
caFree
caMinimize
Forms
TCloseEvent
Sender
TObject
Action
TCloseAction
TCloseQueryEvent
Sender
TObject
CanClose
Boolean
TShortCutEvent
TWMKey
Handled
Boolean
THelpEvent
Command
Integer
CallHelp
Boolean
Boolean
TCustomForm
TCustomForm
Forms
TForm
TForm
FormsU
ActionH
ActiveControl
Align
AlphaBlendT
AlphaBlendValue
Anchors
AutoScroll
AutoSize
BiDiMode
BorderIcons,KE
BorderWidthp
Caption<
ClientHeight<
ClientWidthX
Color
TransparentColorX
TransparentColorValuep
Constraints
Ctl3D
UseDockManagertME
DefaultMonitor
DockSite$
DragKind
DragMode
Enabled
ParentFont
Font LE
FormStyle<
Height
HelpFile$GE
HorzScrollBar
KeyPreviewT
OldCreateOrder
ObjectMenuItem
ParentBiDiMode<
PopupMenu
Position
PrintScale
Scaled
ScreenSnap
ShowHint<
SnapBuffer$GE
VertScrollBar
Visible<
Width
WindowState
WindowMenu
OnActivateX
OnCanResize
OnClickXNE
OnClose
OnCloseQuery
OnConstrainedResizeT
OnContextPopup
OnCreate
OnDblClick
OnDestroy
OnDeactivate
OnDockDrop
OnDockOver
OnDragDrop
OnDragOver
OnEndDock
OnGetSiteInfo
OnHide
OnHelp
OnKeyDownT
OnKeyPress
OnKeyUp,
OnMouseDown
OnMouseMove,
OnMouseUpX
OnMouseWheel
OnMouseWheelDown
OnMouseWheelUp
OnPaint
OnResize
OnShortCut
OnShow
OnStartDock
OnUnDock
TCustomDockForm
TCustomDockFormh`E
Forms
PixelsPerInch
TMonitor
TScreen
TScreen
Forms
TApplication
TApplicationpcE
Forms
Uh\eE
t:GNu
^[YY]
UhMiE
;S$t6
;S0t6
Uh,wE
]_^[
UhV{E
Uht~E
UhT~E
_^[Y]
_^[Y]
PixelsPerInch
TextHeight
IgnoreFontProperty
_^[YY]
S,_^[]
SVWUQ
$Z]_^[
;Cpu'
F(Z_^[
MDICLIENT
_^[Y]
_^[Y]
;ADti
f#CTf
_^[Y]
_^[YY]
t"GNu
$Z_^[
_^[YY]
_^[Y]
Y_^[]
_^[Y]
_^[Y]
_^[YY]
Ch;Ctt
Cd;Cpt
C\_^[
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
layout text
f;sDtsf
PWj W
CHYZ]_^[
RD;PD
_^[YY]
TApplication
MAINICON
XD;PHu
sx;P`u
;B0uGj
_^[YY]
vcltest3.dll
RegisterAutomation
SVWUQ
$Z]_^[
~D_^[Y]
_^[Y]
_^[Y]
_^[Y]
;{HtK
YZ_^[
Y_^[Y]
;^`u0
]_^[
^[YY]
YZ]_^[
User32.dll
SetLayeredWindowAttributes
TaskbarCreated
TCheckListBox
TCheckListBox
OnClickCheck
Align
AllowGrayed
Anchors
AutoComplete
BevelEdges\
BevelInner\
BevelOuter
BevelKindD
BevelWidth
BiDiMode
BorderStyleX
Color<
Columnsp
Constraints
Ctl3D
DragCursor$
DragKind
DragMode
Enabled
FontX
HeaderColorX
HeaderBackgroundColor
ImeMode0
ImeName
IntegralHeight<
ItemHeight
Items
ParentBiDiMode
ParentColor
ParentCtl3D
ParentFont
PopupMenu
ShowHint
Sorted`]C
StyleX
TabOrder
TabStop<
TabWidth
Visible
OnClickT
OnContextPopup
OnData
OnDataFind0^C
OnDataObject
OnDblClick
OnDragDrop
OnDragOver
OnDrawItem
OnEndDock
OnEndDrag
OnEnter
OnExit
OnKeyDownT
OnKeyPress
OnKeyUphSC
OnMeasureItem,
OnMouseDown
OnMouseMove,
OnMouseUp
OnStartDockx
OnStartDrag
TCheckListBoxDataWrapper
SVWUQ
Z]_^[
Panel1
RadioGroup1
Label1
PopupMenu1
CoolBar1
Splitter1
CheckListBox1
SavePictureDialog1
TForm1
TForm1
Unit1
FileTimeToSystemTime
kernel32
UhM%F
ELF.EX
Uh;&F
Error
Runtime error at 00000000
0123456789ABCDEF
MS Sans Serif
h3QgjW
Oh87>
OSVWj?_jr
joZj,f
Xj.^%ef
_j#Zf
jiZj!f
W%sXja)
f9K"@
PWWjoWWWW
4j"Xjs
Y%dXjr)
joX%pf
jaX%vf
PSSjUS
PVVjoVVV
HhhAh[S
t*SSV
hhAh[S
OhIH8YSV
Oj:Xj
hX7xkW
u<erf
h'A'[W
jmXj%f
V%\Xjd)
Xjs^)
%vXjm)
X%oZju)
X%.Yjy)
VMKV)
j"Y%%
Oj0Yd
j+Xjwf
js^j8
OjoXj?f
j\X%nf
PVVjoVVV
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
user32.dll
GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll
lstrcpyA
WriteFile
WaitForSingleObjectEx
WaitForSingleObject
VirtualQuery
VirtualAlloc
Sleep
SizeofResource
SetThreadLocale
SetFilePointer
SetEvent
SetErrorMode
SetEndOfFile
ResetEvent
ReadFile
MulDiv
LockResource
LoadResource
LoadLibraryA
LeaveCriticalSection
InitializeCriticalSection
GlobalUnlock
GlobalReAlloc
GlobalHandle
GlobalLock
GlobalFree
GlobalFindAtomA
GlobalDeleteAtom
GlobalAlloc
GlobalAddAtomA
GetVersionExA
GetVersion
GetTickCount
GetThreadLocale
GetSystemTimeAsFileTime
GetSystemTime
GetSystemInfo
GetStringTypeExA
GetStdHandle
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLocalTime
GetLastError
GetFullPathNameA
GetFileAttributesA
GetDiskFreeSpaceA
GetDateFormatA
GetCurrentThreadId
GetCurrentProcessId
GetCPInfo
GetACP
FreeResource
InterlockedExchange
FreeLibrary
FormatMessageA
FindResourceA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitThread
EnumCalendarInfoA
EnterCriticalSection
DeleteCriticalSection
CreateThread
CreateFileA
CreateEventA
CompareStringA
CloseHandle
version.dll
VerQueryValueA
GetFileVersionInfoSizeA
GetFileVersionInfoA
gdi32.dll
UnrealizeObject
StretchBlt
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SelectClipRgn
SaveDC
RestoreDC
Rectangle
RectVisible
RealizePalette
Polyline
PlayEnhMetaFile
PathToRegion
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipRgn
GetClipBox
GetBrushOrgEx
GetBitmapBits
ExcludeClipRect
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreateRectRgn
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectA
CreateDIBitmap
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileA
BitBlt
user32.dll
CreateWindowExA
WindowFromPoint
WinHelpA
WaitMessage
UpdateWindow
UnregisterClassA
UnhookWindowsHookEx
TranslateMessage
TranslateMDISysAccel
TrackPopupMenu
SystemParametersInfoA
ShowWindow
ShowScrollBar
ShowOwnedPopups
ShowCursor
SetWindowsHookExA
SetWindowPos
SetWindowPlacement
SetWindowLongA
SetTimer
SetScrollRange
SetScrollPos
SetScrollInfo
SetRect
SetPropA
SetParent
SetMenuItemInfoA
SetMenu
SetForegroundWindow
SetFocus
SetCursor
SetClassLongA
SetCapture
SetActiveWindow
SendMessageA
ScrollWindow
ScreenToClient
RemovePropA
RemoveMenu
ReleaseDC
ReleaseCapture
RegisterWindowMessageA
RegisterClipboardFormatA
RegisterClassA
RedrawWindow
PtInRect
PostQuitMessage
PostMessageA
PeekMessageA
OffsetRect
OemToCharA
MessageBoxA
MapWindowPoints
MapVirtualKeyA
LockWindowUpdate
LoadStringA
LoadKeyboardLayoutA
LoadIconA
LoadCursorA
LoadBitmapA
KillTimer
IsZoomed
IsWindowVisible
IsWindowEnabled
IsWindow
IsRectEmpty
IsIconic
IsDialogMessageA
IsChild
InvalidateRect
IntersectRect
InsertMenuItemA
InsertMenuA
InflateRect
GetWindowThreadProcessId
GetWindowTextA
GetWindowRect
GetWindowPlacement
GetWindowLongA
GetWindowDC
GetTopWindow
GetSystemMetrics
GetSystemMenu
GetSysColorBrush
GetSysColor
GetSubMenu
GetScrollRange
GetScrollPos
GetScrollInfo
GetPropA
GetParent
GetWindow
GetMessagePos
GetMenuStringA
GetMenuState
GetMenuItemInfoA
GetMenuItemID
GetMenuItemCount
GetMenu
GetLastActivePopup
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
GetIconInfo
GetForegroundWindow
GetFocus
GetDlgItem
GetDesktopWindow
GetDCEx
GetDC
GetCursorPos
GetCursor
GetClipboardData
GetClientRect
GetClassNameA
GetClassInfoA
GetCapture
GetActiveWindow
FrameRect
FindWindowA
FillRect
EqualRect
EnumWindows
EnumThreadWindows
EndPaint
EndDeferWindowPos
EnableWindow
EnableScrollBar
EnableMenuItem
DrawTextA
DrawMenuBar
DrawIconEx
DrawIcon
DrawFrameControl
DrawFocusRect
DrawEdge
DispatchMessageA
DestroyWindow
DestroyMenu
DestroyIcon
DestroyCursor
DeleteMenu
DeferWindowPos
DefWindowProcA
DefMDIChildProcA
DefFrameProcA
CreatePopupMenu
CreateMenu
CreateIcon
ClientToScreen
CheckMenuItem
CallWindowProcA
CallNextHookEx
BeginPaint
BeginDeferWindowPos
CharNextA
CharLowerBuffA
CharLowerA
CharToOemA
AdjustWindowRectEx
ActivateKeyboardLayout
kernel32.dll
Sleep
oleaut32.dll
SafeArrayPtrOfIndex
SafeArrayGetUBound
SafeArrayGetLBound
SafeArrayCreate
VariantChangeType
VariantCopy
VariantClear
VariantInit
comctl32.dll
ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Replace
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
InitCommonControls
comdlg32.dll
GetSaveFileNameA
GetOpenFileNameA
0(0<0T0h0|0
1e1i1m1
2&2.262>2F2N2V2^2f2n2v2~2
323:3B3J3R3Z3b3j3s3
6_6r6
6,7m7
:!:+:5:?:U:[:i:|:
;';.;8;B;L;X;c;t;z;
<&<f<|<
=3>@>s>y>
>P?X?
0r0x0
1'1/1b1
2%2.2L2R2Z2
363Z3b3h3n3
4e4p4y4
5$5+555
6#6/676
7$7=7
8F:N:
>$>5>A>
1#1:1O1
606>6R6
7<7E7w7
9=9D9d9
:K;s;z;
;'<<<
>)>3>;>A>O>j>
>R?[?
0Y2w2
5i5z5
<+<2<6<<<@<F<M<Q<k<t<}<
=2=\=j=o=
>*>w>
>X?n?v?~?
0&0.060>0F0N0V0^0f0n0v0~0
1&1.161>1F1N1V1^1f1n1v1~1
2&2.262>2F2N2V2^2f2n2v2~2
3&3.363>3F3N3V3^3f3n3v3~3
4&4.464>4F4N4V4^4f4n4v4~4
5&5.565>5F5N5V5^5f5n5v5~5
6&6.666>6F6N6V6^6f6n6v6~6
7&7.767>7F7N7V7^7f7n7v7~7
8&8.868>8F8N8V8^8f8n8v8~8
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?0?4?8?<[email protected]?D?H?L?Z?l?
0$0D0L0P0T0X0\0`0d0h0l0|0
141T1\1`1d1h1l1p1t1x1|1
2 2$2(2,2<2\2d2h2l2p2t2x2|2
3 3$3(3,3034383H3h3p3t3x3|3
4 4$4(4,4044484<[email protected]|4
6<6D6H6L6P6T6X6\6`6d6x6
7,7L7T7X7\7`7d7h7l7p7t7
8 8$8(8,808D8d8l8p8t8x8|8
9 9-959P9p9x9|9
: :,:0:L:T:X:\:`:d:h:l:p:t:
;;;C;P;U;[;
10A0L0Y0^0h0x0
111=1T1`1
1Q2^2w2
8=:A:E:I:M:Q:U:Y:]:a:e:i:m:q:u:y:}:
:M;T;
>%>->
)0f1{1
5+555
8K92:h:
<\=c=
>=?d?x?
2,2_2s2
3h4y5
8;8j8
979~9
:-:E:q:
<2=n>
?+?]?
0>0R0
2.2G2b2
5$5-5
797G7N7f7m7
8-8X8g8{8
;&<-<7<=<D<N<S<Y<^<d<i<o<v<|<
=D=M=V=\=m=x=}=
>A>d>
?&?D?
011a1u1
2 4g4
505E5P5U5Z5g5}5
6&686
7#767?7Z7m7v7
878Y8h8v8
:8:?:N:U:s:
.0?0b0|0
1 1$1(1,1014181<[email protected]\1`1d1h1l1p1t1x1|1
2 2(2,[email protected]\2d2h2p2t2|2
3$3(30343<[email protected]`3d3s3
4'414<4F4Q4[4f4p4z4
5$5)5O5n5v5~5
5 6-6V6
7.7d7q7
8B8\8
9?9q9
9!:/:4:?:E:J:U:[:`:k:q:v:
;!;&;1;7;<;G;M;R;];c;h;s;y;~;
</=;=H=Z=
> >$>(>,>0>4>8><>T>l>p>
? ?$?(?,?0?L?l?t?x?|?
1 1$1D1d1l1p1t1x1|1
3 3$3I3W3f3}3
494G4V4m4
5)575F5]5
6 6A6P6g6v6
7"717B7t7
8.8E8
$0A0y0
0,1a1}1
4!4%4)4-4145494=4A4E4I4M4Q4U4Y4]4a4e496
7)7]7v7
768S8
9$9-;1;5;9;=;A;E;I;M;Q;U;Y;];a;e;i;m;q;u;y;};
0^1u1
2-2B2G2T2t2
5*5K5a5y5~5
5B6G6a6
7%7*7/74797?7D7I7O7V7\7c7i7p7v7}7
8$8,848<8D8L8T8\8d8l8t8|8
9><g<
>d>h>l>p>t>x>
1#101B1H1a1
1,2=2
3)303P3X3\3`3d3h3l3p3t3x3
4 4$4(4,40444H4h4p4t4x4|4
5 5$5(5,5054585<[email protected]|5
6$6,6064686<[email protected]`6
8(8H8P8T8X8\8`8d8h8l8p8
9 9$9(9,90949D9d9l9p9t9x9|9
:!:Y:]:a:y:
;';+;<;L;X;\;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<r<
= =(=,=0=4=8=<[email protected]=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
>%>0>@>P>X>\>`>d>h>l>p>t>x>|>
? ?1?5?H?h?p?t?x?|?
000P0X0\0`0d0h0l0p0t0x0|0
1 [email protected]\1`1d1h1l1p1t1x1|1
3(3,3H3P3T3X3\3`3d3h3l3p3t3x3|3
4,44484<[email protected]\4`4d4p4|4
5 5(5,5054585<[email protected]}5
6:6H6L6T6X6d6h6p6t6x6|6
7 7$7(7,70747D7T7X7h7
8(888D8H8P8T8X8\8`8d8h8l8p8t8x8|8
:$:,:0:4:8:<:@:D:H:L:^;m;|;
1W2g2t2
3.4I4X4o4
5*5<5R5W5s5
6*6<6A6`6m6x6
6T7`7
9?9d9t9
;I;V;j;q;
=1=C=
1'1j1
3/464M4
6:6J6
9P:}:
<T>j>
0%0w0
0,1R1{1
1A2^2
666L6
6C7`7
7&8K8s8
9*:G:|:
;G<}<
1A2H2
2l3s3
5/5O5
7m7t7
<$<,<0<4<8<<<@<D<H<L<P<^<f<|<
=&>n>
>b?o?z?
282I2g2n2
555Q5
8J8{8
=/>Q>
>%?;?v?
%0{0a1
2?2M2[2i2
5?6C6f6j6
898}8
9 9$9(9,9
<)=<=
3#3'3+3/33373;3?3C3>4d4
4&5`5
8 8N8k8
9"9&9*9.92969:9>9B9F9J9N9R9V9
=%=N=j=q=
>'>f>k>
O0<1G1s2y2
3f4m4
;!<P<
?-?s?
00050>0D0Y0g0m0x0
2!2+282H2P2X2`2h2p2x2
3 3([email protected]`3h3p3x3
4 4([email protected]`4h4p4x4
646M6x6
7$7t7
708J8
91959H9]9
: :::B:Z:^:b:{:
;$;(;,;0;4;8;<;@;D;H;L;P;\;f;j;{;
<$<(<,<0<4<8<<<@<D<H<L<P<\<h<l<}<
= =,=9===N=V=n=
? ?,?8?<?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
:0>0B0F0J0b0p0t0|0
1<1D1H1L1P1T1X1\1`1d1h1|1
2 2$2(2,2024282<[email protected]\2`2d2h2l2p2t2x2|2
3,3<3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4$4,4044484<[email protected]`4p4
5#5'5>5L5l5t5x5|5
7(8^8
9*9:9p9z9
#030N0
1'1W1
3.434S43686s6
8S8X8
9;9f9
9.:>:P:n:
< <-<A<N<b<t<~<
0,1s1
2%242C2
324R4r4
7-8j8
<;<P<s<
?:?X?
8U9r9
9/:A:^:
;S;i;r;
<*=g=
>P?x?
3#4D4S4m4
4^5{5
696W6
???]?
4'4]4
5$5(5,5054585<[email protected]\5p5
6'6,6T6c6
>L>T?
0:0d0
4'444
4#5/5
5i6E7j7
<O=c=
>C>P>|>
>1???
0G1b1
>P?`?
1<1k1x1
2%2+2D2d2l2p2t2x2|2
5P5i5
6'626D6V6g6q6
8 8(8,8084888<[email protected]
:+:8:J:R:Z:b:l:r:z:
;2;:;B;J;R;Z;b;j;r;z;
<*<2<8<D<J<c<
<f=n=t=
>)?1?7?C?K?
0[0f0
0/1:1Z1
373C3P3b3w3
4+4P4i4
5$5,5054585<[email protected]
5_6c6g6k6o6s6w6{6
7 7.767L7T7\7d7
9Q9f9
> ?d?
0 0y0
1$1r1
4!4:4U4b4{4
7.7<7\7d7h7l7p7t7x7|7
9%[email protected]\9c9j9q9x9
: :':.:5:<:C:J:Q:X:_:f:m:t:{:
;*;/;<;A;N;S;`;e;r;w;
<&<+<8<=<J<O<\<a<n<s<
="='=4=9=F=K=X=]=j=o=|=
>#>0>D>I>
232?2G2U2]2o2
3+303I3p3
4 4$4(4,4044484<[email protected]\4`4d4h4l4p4t4x4|4
6 6/6
7'7s7
8.8;8G8T8f8s8
:(:,:0:4:8:L:_:c:s:
= =\=`=d=p=t=
>2>6>:>>>B>T>e>i>y>
?-?O?s?
040l0z0
0.161H1Z1j1
4 4/4?4
7$7`7
9&909<9
<D=x=P>Z>_>i>p>
? ?(?,[email protected]?D?L?P?X?\?d?h?p?t?|?
0*0/0<0L0X0\0d0h0l0p0t0x0|0
1"2E2h2t2
3&3.3M3U3Y3p3x3
3%4J4o4
5(5L5q5
6 6$6(6,[email protected]\6m6u6
7 7$7(7,7074787<[email protected]\7`7d7h7l7p7t7x7|7
8(8:8>8P8`8p8x8|8
9 9$9(9,9094989<[email protected]\9`9d9p9|9
:":?:G:d:l:
;";&;:;B;`;h;l;
<7<C<Y<
=9=A=_=g=
>9>A>E>[>
?D?i?
0>0f0
1E1h1x1
2 2$2(2,2024282<[email protected]\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<[email protected]\3`3d3h3l3p3t3x3|3
4!424:4R4Z4^4t4
616Z6^6
7'7C7K7O7f7j7n7
8=8b8
9<9X9
:$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
;0;8;P;s;{;
<&<D<j<r<v<
<a>k>
2G3T3
5X5g5~5
7n7;8
<o<~<
= =$=(=,=0=4=8=<[email protected]=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
<O<u<
0$0,040<0D0L0T0\0d0l0t0|0
1$1014181<[email protected]\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<[email protected]\2`2d2h2l2p2t2x2|2
3 3/3;3H3Z3g3s3z3
4&4,4H4
5 5$5(5,5054585<[email protected]\5`5d5h5
6 6$6(6,6064686<[email protected]\6
7<7D7H7^7j7
8/878N8V8Z8m8q8u8
9 9A9j9r9
:':=:b:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;p;
< <$<(<,<0<4<m<
>(?0?>?J?
1!131C1]2j2y2
<0=K=m=
;';:;B;L;`;l;p;|;
<0<H<L<\<h<
=([email protected]=D=T=d=p=t=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>p>
?_?v?
0]0o0
2?3h3
4F4q4
6$6e6o6{6
9+979D9V9{9
:&:G:S:[:c:n:
;";(;H;P;T;X;\;`;d;h;l;p;t;x;
<&<4<8<H<W<[<l<t<x<
=?=G=c=k=
>&>E>M>d>h>l>
0 0$0(0,0004080<[email protected]\0`0d0h0l0p0t0x0|0
1"101>1B1S1W1[1s1{1
2)212O2W2[2o2w2
2 3C3K3i3q3
4$4(4;4C4\4d4
636X6}6
777]7
8Q9e9p9J:k:
?5?<?U?i?{?
$0B0Q0`0o0
374i4
5+5h5
7Y8g8
= =2=B=H=h=p=t=x=|=
=r?|?
2"4)4
5"5&5*5
8+979>9H9Z9j9p9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
: ;0;<;@;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<<<N<R<d<t<
= =$=(=,=0=4=8=<[email protected]=L=X=\=m=u=
>!>%>;>C>G>[>c>
?5?=?A?T?}?
0=0E0I0`0d0h0
171\1
2:2^2
2V3Z3b3h3
4 4$4(4,4044484<[email protected]\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<[email protected]\5`5d5h5l5p5t5x5|5
6$60646<[email protected]\6`6d6h6l6p6t6x6|6
7 7$7(7,7:7>7B7F7X7j7n7
8+878M8U8Y8m8u8
:":*:F:N:R:i:m:q:
;>;c;
<8<\<
=9=`=|=
=!>%>)>0>
? ?$?(?,?0?4?8?<[email protected]?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,00040B0n0r0v0z0~0
1 10181<[email protected]\1`1d1h1l1p1t1x1|1
8a8U9
=+>H>
0X1{1]2{2
6!686q6
7H7!8>8
:#:-:h:
535B5V5^5
6;7W:7;g<
=,>V?
0#0:0
1 1(1,1014181<[email protected]\1`1d1h1l1p1t1x1|1
172C2P2b2h2
3 3$3(3,3034383<[email protected]
3(4b4m4x4
5/5;5T5z5
8J8R8p8~8
:1:b:
=$>\>
?3???I?S?X?g?y?
0$0(0,0004080<[email protected]\0`0d0h0x0
101L1P1d1
2 2$2(2,2024282<[email protected]\2`2d2
3-313D3d3l3p3t3x3|3
4 4$4(4,4044484<[email protected]
5 5$5(5,5054585<[email protected]\5w5
5$6<6X6p6
7$7(7,7074787<[email protected]
9G9K9O9T9
:e:i:m:q:x:
;q;u;y;};
<p<t<x<|<
<B=F=R=X=
=B>F>J>N>R>X>
>D?H?P?T?
0 0$0(0,0004080<[email protected]\0`0d0h0l0p0t0x0|0
0:1>1B1F1J1N1R1V1Z1^1b1f1j1n1r1v1z1~1
2"2&2*2.22262:2>2B2F2J2N2R2V2Z2^2b2p2~2
323>3Q3t3|3
4 4$4(4,4044484<[email protected]\4`4d4h4l4p4t4x4|4
6D6`6r6
7 7$7(7,7074787<[email protected]\7`7d7h7l7p7t7x7|7
9"9&9*9.92969:9>9B9F9J9N9R9V9Z9^9b9f9j9n9r9v9z9~9
:":&:*:.:2:6:H:Y:]:p:
; ;$;(;,;0;4;8;<;@;D;H;P;d;y;};
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<[email protected]=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
>">&>*>.>@>Q>U>h>x>
? ?4?D?T?\?`?d?h?l?p?t?x?|?
0"0<0^0f0
141<1T1t1|1
1H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3$3D3L3P3T3X3\3`3d3h3l3x3
4 4$4(4,4044484<[email protected]\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<[email protected]\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686\6
;<;D;H;L;P;T;X;\;`;d;h;l;p;t;
>A>P>
243n3
4e5w5
7P7]7f7o7
7"8*878>8L8W8]8v8
9(989I9V9x9
:#:>:J:R:d:
;+;0;:;@;H;
< <%<1<;<A<I<j<r<
=(=^=
>">8>@>N>`>p>y>
?3?>?G?U?h?
0$0+01090O0Z0o0y0
1#1)171=1K1V1j1{1
373G3~3
304?4~4
4n5V6
7 7d7
8K8N9l9
94:>:R:W:c:w:
=W=;>{?
4K5;6A6d6j6
7?7y7
9/<S<b<
?N?f?~?
0P0Y0z0
4.5;5J5!717
0 1H1p1`3k3y3
=>>S>e>
1w1{1
455a5
7T8d8
889f9
041F1|1
4M4V4d4
8b8l8
:3<;<N<
9F9l9w9
<3=g=
1s2Q3e3|4
315A5
9t9z9%;
474\4
555v5
;#;n;
0\0M2T2
6-6_6
5,8>8O8g8
9U:s:\;
2 4g5
9_9i9s9}9
;5;A;I;U;`;f;r;|;
<!<&<1<6<;<F<K<P<[<h<z=
>#>4>E>[>c>r>|>
???L?V?g?p?
0%03080=0G0W0b0o0
1(121<1N1c1o1
2 2$2(2,2024282<[email protected]\2`2d2h2l2p2t2x2|2
3 3,30383<[email protected]\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<[email protected]\4`4d4h4l4p4t4x4|4
5$5(5054585<[email protected]\5`5d5h5l5p5t5x5|5
60686<[email protected]\6`6d6h6l6p6t6x6|6
6g708j8
9.9B9
;L<`<t<
3+474D4V4_4d4o4t4
445M5h5
606F6J6
7,8H8
;,;V;
<N<^<
?4?O?^?
3$343]3m324O4l4
4r5'6Q6`6w6
8+8V8s8
8&9w9
:`:u;
</<X<h<
=H=e=
==>E>O>U>`>p>{>
0<0D0H0L0P0T0X0\0`0d0t0
1g1k1s1x1
1N2R2V2Z2`2
3 3$3(3,3034383<[email protected]\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484F4N4f4j4n4r4v4z4~4
5 5D5H5L5e5m5
656=6Z6f6
7-797O7t7
8 8$8(8,8084888<[email protected]^8n8r8v8
9 9$9(9,9094989<[email protected]}9
:/:7:S:[:|:
: ;>;
< <$<(<,<0<@<P<T<b<
=#='=E=M=f=
>$>H>h>p>t>x>|>
545g5
5/6l6
97:H:
;&;2;
?9?D?
0i0C1
3%4/494L4V4i4s4
7i7C8
8A9e9R:
3)4T4Y4a4f4{4
475i5
6v6Z7
8C9x9
1-1:1\1a1
9=9I9]9i9n:
<Z=j=
111M1w1
3"4u4
5 5$5(5,5054585<[email protected]\5g5s5z5
6$6.656?6F6P6X6t6
7$7;7?7M7U7r7z7
9'9T9d9p9t9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:
;,;K;
; <9<p<
>+>X>
?d?i?m?q?x?
0 0$0(0,0004080<[email protected]\0`0d0h0l0p0t0x0|0
0V1Z1^1b1f1j1n1r1v1z1~1
2"2&2*2.22262:2>2B2F2X2i2m2|2
3 3$3(3,3034383<[email protected]\3`3d3h3l3p3t3x3|3
4*424J4R4o4w4
5&5.525L5T5X5r5z5
6'6/6R6Z6
7"7=7`7
8.8Q8Y8]8y8
9.9W9[9_9
:1:9:=:T:y:
;.;:;S;_;y;
<;<G<^<j<
=$===I=b=
> >9>E>[>g>
?F?R?h?t?
0,080<0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<[email protected]|1
2 2$2(2,2024282<2L2X2\2l2t2x2|2
3$30343D3L3P3T3X3\3`3d3h3l3p3t3x3|3
5 5.5;5K5b5~5
6 6(616A6H6O6V6g6o6u6
7)7?7n7
536C6
;H;k;
<:=E=T=y=
>C>H>d>
>)?=?Q?r?y?
0T0g0
0(1q1v1
132b2
203V3
4U4i4
6>6I6V6\6g6t6
=<>L>i>
>F?S?c?}?
3A4_4
6<6R6~6
6<7F7.9=9T9h9
:z;v<
=!===`=
=+>=>[>n>
? ?7?O?a?
1/1Y1
2Z3|3
405n5}5
5T6z6
7"797\7?8
:":_:
1&1:2F2
5E8h8w8
889T9p9
:U:n:
<#<H<d<
>K>[>y>!?+?
0,1l1{1
2.2D2q2{2
3&343F3]3g3v3
6O8l8
<e=Q>
?(?U?_?j?|?
2,2s2
2Q3k3
4_5r5z5
<,=7=B=\=a=
>)>9>F>L>a>g>t>
G0Y0^0
595%6
7#7d7
<4=\>|>
465p5{5
?;?X?n?
002V2
2$3G3
8 8c8
869F9Q9
:&:5:?:D:`:p:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
<,<S<[<s<
=,=4=Q=Y=u=}=
>%>->K>S>W>k>
?#?6?>?\?d?
0&0>0g0o0
1%1-111H1P1i1q1
252^2
3:3_3
434U4}4
5<5\5d5h5l5p5t5x5|5
2 2$2(2,2024282<[email protected]\2`2d2h2l2p2t2x2|2
4/5;5H5a5m5w5
5#666H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<[email protected]\7`7d7h7l7p7t7x7|7
8 8(838=8J8O8W8a8
2X2`2h2p2x2
[email protected]\3`3d3h3l3p3t3x3|3
4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6
:`:d:h:l:p:t:x:|:
:L;\;d;l;t;|;
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<[email protected]=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>
M<b_4]Y0
`5SM(
PeRcp
`fA;V
0Z7g.
ClS^'
W'LPAD
L&7o;
krRI_?
KXS"x;
:5Y_J
Hx?/7
}-_GK
~Ih"@
9$bJ;
)@6H}
cUJ#_
'!v-W.
Tk{-&
W8Mt&z
{y;Q=
D,PADN
wxU7FGw
,X;.|I
kzMEc
R}='
zHHe{f
;l6^O%
tPxypD
9!zkb
yjw-0
vk!'F
P>&(Z
)tq1S<
"k91i
qrG-G
zJ~F5
a"t^W
@*=~?
(94%S1
v J{,\uVmW
917<C_t0
;\UAR
nN{"r
rZNt7
Q`Q8h
}2zpDUf
RW|}s
5p`Hf
,YB^|?
^'NsS
YPADX
=!>\4
YoxBl
'c4}Y
>: [I
' S[!
cEsb0{i
<px))9
.Aq#.c\9
<pUEY
6-!8OK
O.aK$}S
e%-[]U
Q|@:S
m^$K?
LH>`?
Ywxg,V
8"Z_fa
'c46kS
0o(zT
actRa
:Z;}H
xPAD:
:w[1
q/BA?
mUk{o
!p:Cz_
z)1:c
xxuN=
x)|iK
t\HzH
e?\GK5Ph
gU8Ok
oEw}y
i<3`S9
O2p}c
PADPd
Cx3;f
DU$l]
xu1da;p
aPAD&
D^dE5
peIhy
&b^Qa
u^H~T
MY)AM
PAD8f
=3C_a
Z^pYu
v9HVm
PADy0
iegsE
jRz#ti
MS[0\:3q
DUW6-
da7/I
Mo4x'I
Z0ovPr0
Q_,kD
35J8J
nhJ:y
x6t<z
l)-(x
bDMY[
z&n9~
lSHTl
{&sSZ9
C>r>]
~5J u
qIx8r
4y-~H
DSsWL<
Gti+Z
wo!3I<A
oW,+ .L(
u;$Y=
Q)0_-
x"vLF
>C,!>U
KM3AA
hCf!#
cF*A8
D&PAD
TizP:
|L-[e
j[^&uY
~Y(yo
&`B?{
s>HFP
c:NJu
V(7XJ1
&#qK^
Pg05H
I$k,}xe52
~zg<#<
;O1G8
-7uRn
L U%Y
Foe~F
wh3xo
b<QIe%
(Q6{ki-(
@$$N
j[&&Ax
Cdsbs
1=u4%
-Io^6
ufnwF
9PADi
F!=0W
J;Pm3
_[wJG
t]ONW
IDY+F
^7VYM
PADe=
=7ws3T
W\{2$.
WDwViIi
~Be`D
IAm,e
^i!|]
"SK.c
uIl`go*W
&ueHc
+3?_6
v`D;m
Q3?&~
[WDrL2
&X;c|P
[9ouwo
PAD=
H-"zM
W69Hkn
b=*Ew
\fpq46_
y-u[n
+R zm]=U
jsRa7
\i$T9
g#eA\
*&ao+K
2{zcm
5sZOh4
;NaHn
(=6M)
FXPAD
w)V/%~[
vPAD*
5no'6
u~Im5
zq:e1
A1sqW
@sr&.eG
n,u_t
7LTd?o
;1Si9
w?M+c
{q}l+
Fg??7
~}?:[:e
(@0[W+
<0Y*E
u, }pLT+
-lHwx
\3f;m
e1mon9?{
U[lWCk
I"(8Df
mnXJV
a+aD{T
_Xn,,
?*WC7w
s)rzvX
!_PAD
'T->kh
*@i~,
y6_!X
.y=%}
,}Yh"
3f&t:[
4~IP;
_K}1\
sdv7T
Hiv,Q
TpL8PAD
[As6V"
TfAAM
l6p/*
)9gO%
i=p>`s
O~O/*
8=uQ}3~
nb~*QR
Jd*Y2}|
@wES?
N]f?Q
-Sp5FM
f6vM/K
`'i9Z
b6>t0Z9
3d34+7
/OWip~q
xWzM[
=ukPAD
uY%D/
ai*k$
^}wSt
8^7R,S
}pXmt
iiTYi
PAD ?
|bp^i
,lh+y
'Z(~T
Ww51 "Ox}2w
:PADs
,\$Zq
;m#dKF2
aTPxZ3E
9)A)9*
PQ+Y=,
J*P%n
b7sjsW
Wn7JD3*
~{ X(
Dhx'M
'A6PAD
hbE^o
7_n](
!<}L5
I~ku-
vp-sU
-^c}c
AWOB/
->Gr#H
6ws(N
4WlAwx
$!RS>
.6sRCd
LkhPAD
Rwgu5
rFj%k`L
RU2 AT
ErHq{
%G{Yb
Ur\\\
KndVPAD
H;TB+D
30,c
4uM="P
kWiId
s1s|(
dP?ACB
mV%8z#
WC&8
s 1|[
{{&F5)F
OOPH+
5T~"L_
kx]03
#1(1T
S"-4G
|Ya*>
%NuX'!
i&U!~
t:pDd
bfImU
<2Qlz
h<aQw
d&{a>
XMDZw$
,R)]V
YCP^by
PADk/)q
e_-%xM
aZPADi
2&edL
AEeu+
7b.zNw
D2Z}g
AI~OB
aK8o(
TY{<;
+dA.B4
>@}dtu
Ee7fU
sPADEE3,{@a^
[925ii
PADQ:
#L[4GK&
mGBKV
MdG4]
C*LGl
:sH$G
d>4-
~!=IM4
#PADLcN
!>-[,.
!f`9q
YHPAD
bZ3LA
NswfN
8.FuK
cfULAn&U
PBkr$E
{@x*Z
tEE>]9
qY&m
m D5G<
l?z.UJ
uU>iJ
a;W~Y\=
RfTD\
(W}nv
'Ra6aP
!9p:c
[PAD(
,<2ojl
p]u~Xi
^PNK41
eTu[~
*|%!VZ
+pLT#
1/dVg
.C*.w#FC
%1In{
HuI~]
.tFwc
j)@$d
p?f^a
XNcBPN
{7J.x+WHw
F6Vw`9
K/42Q
59|0k
p?x#zkX
PADtMC
4W <7
PADAG
;yS">X)R
^=PxR;
UCl~OFw
"kp;_
t~$K?z;
"bwC(u
<%ED;
eXEXpJ
k%PAD
2:n&<
9+NR.`
)Y:#>
m\9]6
yb!7h-
!*E<>
42k32
uic^QE
*JOI4sPAD
4cw20
-ra~R
O,s4C
#ojb$
}t#:Q|
T0J4z>
dtKaVx
Gn4I_
d8?mY
VbxM=
0jE!({@Y
pC"nz
]n[8C
}~G|nS8
frc=3H
dIrp5
.6t)S
\py_K
wo b`
#Iv:Q{LQ
WHHFx'
{y7:t
<-rU;
mKlfhJ
IjgSA
$8eU)
PAD.N
>7$UaN1
ZD,6{
|L,sT\
PADxY
GSkUdK
a[@%#PJ
nAE$E
>|$[-F
Jkpcy
q4\1X
=.8\5
?W"Nw
x9$+5
!|G+
vW)Tou
'_PAD
h6. <
tNeM/%h
v/O-M
RlR',*
05/{
\6TPAD
MC$T/x8)
9(^>/Q
i6$6'
SkNE=$$\
[|(Kx
_gZK(5a
cNyWX
1M=UI
3=V>y
Fc$%5K
wPAD[hS
;d]iT
eR0|q
f*=hr
pb4XEe
XswKr
,^f"Y
cPADC-s
pt=&G
_&d_]
$PADG
?X'@>4
HSYQ<
0A$+&
fD-t>
_O?K3
DJ9`@U
Yp_xMA
c"j-:_z
n,Py!fV
4s"`;'
PAD%C
z$^;K
[A1,e
B%Ei5K.Mky
x'dc#I
=Bm=,
Tu8oIy
9C)H}\
'x~ez
lY2.#
x4ltsGR
pO\v*
ChkwayL
59!kM
Kwl7T
=N.iU\q
/+\'F
>FZ&NZ
[A_sBE;L1
\+?s^xx
2E;`X
/i,-.
ePAD2
\Xq/M
e;_We
~xHg(
#v0:H
K5xs2
WS.:Z
#*}0D=
O=Co#nbaz
&DI~T
w%&z6
U_puYJ
@3A#7
PAD+6ve,
?OsXf
6qthQt
[ uzJo(z&
;t+7(
'FB}^Q
33Tc[
wHM-f;
:r+RbK
Mr^#%W
t=Xm,
.#bb5
u/{@rq
$n) H
F)ZGE
xQp8c
ey#&"
h1M~+
k~mVQ
+%=QYP
PADMz
mFjTo0
lW<pl
s_,xDd,
&gfGr;
C2%dm
"Hd5?
4/7#6
*[)a{[
o8T3$
7c^Ln
D'p;v
8d Xt5
aAC"Nd
,>euv
3W$V4
h:W4gP
pGZEh
@@rWDUg
WG=?v
K)=nU
C3Up4;
Q8t\j
bLY7Vz
?&.}vhn
{0L:+
aX!Jl
*,D9L
Np:sP}`
C[q5:
W->_a}
q<g7<
E}au/
0S`pz8
1+Ri|t
|BAM7
[7,z4
GDzZo
5Yxy%
1+lN(
]L_88
PAD7H
q)|2r~
C>wx4X
iT5KJ
u.rX2
| b``4
%9:O(Qy
Np{E/
GK9,y
=oOA_j
>QsA<
?Gvb"
fMtXo
[o#x8O:mw
W`&Ij
0Trd$1 )T
LI0~]%g
{3-xPw
RPAD/
mdcx++
Y~D`s
f3/xI
eZNVhCC
Qr|l:
Nk"K,c
PAD[g
I$v9??
bNPAD',
t'&_K
v}!V+
7y<:):
$oW[]
|hHJL9,
/KPAD
4I6\/w
;/[Jn
r{Ztk
El"B"
5"Dzl
140Y8u4
ZPADr
D{#.<Hf
-I2{h
/<MW7
@9bwH
PADX]10
xYI\;
BdXq:
39YJl
PADW2
H7G}xT
PF7Ok
WY5"n,
:PAD+
&r{<r9
nmIa1
qF;U_
}M4t_
|1`?g!
WwQ=OCC
5G4sWt\
^Hzl)
@&5_'
/cbrj
_k,=h;
3:}9c
qIwjk/K
)k`8Vb_qj.\o:hd
PADk;
O;^ec
]bKH`G
nGaY\
+:PAD
zH-]nZ=
=SI64
PGS<Qv
3zR-k
6c!}}
lr]-%
8C/Q:
{6Dlb&
/pXyG:
b4Qa$
{/",B
*=zVu_*U
&+)ZmU
vd_g$
DkK-<
PAD6;b
#/p}=gMI
5$h)G'
I1Gtj
PADrEu*
9>6rB
bP5O(i
$?S)~
5PAD|Yp
ly&L+_
3*wqx
cjPAD
T'`<|
Vj+cg
Vn`%t0h
M+9T>p
lX^VV
:?2SDt"t
kXYNG
mb*}X
K'3A
2^uTh1
@_]=KC
$sjMAR]
/O:9.
__$6"
Go2SUp~
%]%*5#
>@]Wly
Zz(1i
mGGbS#
'0=!KaQa[
D#)/T
7/~JO
=!X#T
``"oDN
t0e./
?0=-/
)XM:W
S]'X~
`}7Fz
fLMmQ
Xda`g
";q$ec
v}<!3
9'f2=
ZC<*E/=
&Tu11
Q`MTp-l
2lPAD)
E`^2M
PAD >
j_AN0
tAO}o
yPAD&a,
'{1YK>
5!'`J
fPADw
:-VZ;
g;PAD
@~3\X
5)kI&&
.q{[R|m
SoQ_|
m94J+
iPADh}f
=oR[T
p--,E
WAv\ r
5DY,58<
P#aV$"
\8x:'
YS.*!U
n92g_
4o>e5
QaA#%
W>E>n
A:9It
;'U kxa
{k(4M
7 yPAD
idU F
B_TgLf
1=eUs
9}Dm;
_ PyE
99Pw
4^>#O
KQO/k+y
OSyms
|~ 6+
%PADGgg
<4\*=
*vU}5
-$'{C
*L|2~
HL]J&
.Nii)
W]q.0&
(B~b\
8&U)t
6k)0\
^3j:C
Rm81l
SG=Bm
st"hbuh
FXvzc9R_
1t|m%~P
G+sR%j
'#(t}
94j5b
X/^2g
HoGUo
C(|P3O
]wb;^3*&B
[EhU=
'*%l)
][*4wM
'tI\!
_4XEj
hQkfSb
->\at
scPAD
PAD7`
9l(jx*
Jn^Yv
zIlqBu
u>#3+X
pwoep
cFdRNK
&[cUnd
IXrU)
3|.7'
`r2AN1
333333333333333333
33333333?333333
33?33
33338
33333
33833
333338
33333833
33333
333838
3333339
3333333333333338
333333333333333333
334C33333338
33333
33B$3333333
34""C33333833
3B""$33333
4"*""C3338
"C3338
:*"*"$3338
"C338
"*"$33
"*:"$
"J"$3
:33:"$
"C8338
"J"C3333
3333:"$
#33338
33333
"J333333
33333:"$3333338
333333
$3333333
333333:"33333338
3333333
33333333
333333333333333333
33333333?333333
33?33
33338
33333
33833
333338
33333833
33333
333838
3333339
3333333333333338
333333333333333333
33DDDDD3333
33333333333
333333?
333333
333333
3333f3333333?
3336Dc3333338
333>fC333333
c333333
3333333333338
3333Dc3333333
3336fC3333338
333>fC333333
333>fd333333
fC33333
3333>fd333338
334C3
fC333?3
33fd3>fC333
fDFfC338
33>ffffc338
fff3333
33833
33338
3333333333338
4DF334DC33
333*C33
c33*C333
338?3
33338?383
F*F333383
"$c33333
"dc3333833
CjC338
CjC338
D*C33383
33333
3332*
C33333833?33
3333"
3333333
3334JC33333338?333
C3333333
C3333333
3333fc33333338
333333333333?
33333?
333333
333333333333333333
333333333333333333
333333333333
33333
334C33333338
33333
33B$3333333
34""C33333833
3B""$33333
4"*""C3338
"C3338
:*3:"$3338
"C333
3333:"$3333338
33333
"C333333
33333:"$3333338
333333
"C333333
333333:"C3333338
3333333
#3333333
3333333:3333333383
333333333333333333
333DDD33333?
2C4"""D338
2$B""""C38
2""333:"C8
83338
2""#33:DC8
333338
33333
333333333333333
333333DDD3
:DC33:""$8
:"C333
$334B"$3
"DDB""$3
3:"""""
333333
333333333333333333
333333333333333333
333333333333
33333
334C33333338
33333
33B$3333333
34""C33333833
3B""$33333
4"*""C3338
"C3338
:*3:"$3338
"C333
3333:"$3333338
33333
"C333333
33333:"$3333338
333333
"C333333
333333:"C3333338
3333333
#3333333
3333333:3333333383
333333333333333333
33333333
xzJjfghNMMF
_QTIcXZ
S?C<\FIx{`d
ZDH3`HM|~bh
TGJ XILTmV[
|~Ntdf
7Project1
)CheckLst
Consts
System
SysInit
"RTLConsts
5Themes
SysUtils
KWindows
UTypes
SysConst
nComCtrls
Printers
WWinSpool
^Classes
3Messages
CVariants
$VarUtils
QTypInfo
sActiveX
+Graphics
Forms
CommCtrl
FlatSB
StdActns
Clipbrd
YStrUtils
*ShellAPI
&Controls
MultiMon
vMenus
Contnrs
ImgList
EActnList
dStdCtrls
Dialogs
ExtCtrls
IDlgs
3CommDlg
(ShlObj
RegStr
?WinInet
UrlMon
WinHelpViewer
RHelpIntfs
ComStrs
ExtActns
0Mapi
ExtDlgs
Buttons
8Registry
IniFiles
CUxTheme
SyncObjs
RichEdit
ToolWin
ListActns
Unit1
TForm1
Form1
Width
Height
Caption
2jsJPdzYfH
Color
clBtnFace
Font.Charset
DEFAULT_CHARSET
Font.Color
clWindowText
Font.Height
Font.Name
MS Sans Serif
Font.Style
OldCreateOrder
PixelsPerInch
TextHeight
TPanel
Panel1
Width
Height
Caption
Panel1
TabOrder
TLabel
Label1
Width
Height
Caption
Label1
TRadioGroup
RadioGroup1
Width
Height
Caption
RadioGroup1
TabOrder
TCoolBar
CoolBar1
Width
Height
Bands
Control
CheckListBox1
ImageIndex
Width
TSplitter
Splitter1
Width
Height
TCheckListBox
CheckListBox1
Width
Height
ItemHeight
TabOrder
TPopupMenu
PopupMenu1
TSavePictureDialog
SavePictureDialog1
BTHBD
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
jjjjjj
ebutton
clock
combobox
explorerbar
header
listview
progress
rebar
scrollbar
startpanel
status
taskband
taskbar
toolbar
tooltip
trackbar
traynotify
treeview
window
jjjjj
jjjjj
jjjjj
jjjjj
jjjjj
jjjjj
jjjjj
jjjjj
jjjjj
A(A4AHAXAhA|A
BBABORT
BBALL
BBCANCEL
BBCLOSE
BBHELP
BBIGNORE
BBRETRY
BBYES
PREVIEWGLYPH
DLGTEMPLATE
DVCLAL
PACKAGEINFO
TFORM1
MAINICON
MS Sans Serif
Scroll Bar
3D Dark Shadow
3D Light
Window Background
Window Frame
Window Text=This control requires version 4.70 or greater of COMCTL32.DLL
No help keyword specified.
Button Face
Button Highlight
Button Shadow
Button Text
Caption Text
Default
Gray Text
Highlight Background
Highlight Text
Inactive Border
Inactive Caption
Inactive Caption Text
Info Background
Info Text
Menu Background
Menu Text
Silver
Yellow
Fuchsia
White
Money Green
Sky Blue
Cream
Medium Gray
Active Border
Active Caption
Application Workspace
Background
- Dock zone not found
- Dock zone has no control
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count"Unable to find a Table of Contents
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Black
Maroon
Green
Olive
Purple
Shift+
Ctrl+
(None)
Unable to insert a line Clipboard does not support Icons/Menu '%s' is already being used by another form
Picture:
(%dx%d)
Preview
Docked control must have a name%Error removing control from dock tree
&Ignore
N&o to All
Yes to &All
Enter
Space
Right
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Information
Confirm
Cancel
&Help
&Abort
&Retry
Menu inserted twice
Sub-menu is not in menu
Not enough timers [email protected] cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
Cancel
&Help
&Close
&Ignore
&Retry
Abort
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Unable to Replace Image
Invalid ImageList Index)Failed to read ImageList data from stream(Failed to write ImageList data to stream$Error creating window device context
Error creating window class+Cannot focus a disabled or invisible window!Control '%s' has no parent window
Cannot hide an MDI Child Form)Cannot change Visible in OnShow or OnHide"Cannot make a visible window modal
Menu index out of range
Error reading %s%s%s: %s
Stream read error
Property is read-only
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Stream write error
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Invalid image!Cannot change the size of an icon$Unknown picture file extension (.%s)
Unsupported clipboard format
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)+Out of memory while expanding memory stream
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
January
February
March
April
August
September
October
November
December
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
A call to an OS function failed
)Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Floating point underflow
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Write$Error creating variant or safe array
!'%s' is not a valid integer value
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow Invalid floating point operation
Floating point division by zero
Floating point overflow

Full Results

Engine Signature Engine Signature Engine Signature
Bkav W32.AIDetectVM.malwareB MicroWorld-eScan Clean FireEye Generic.mg.6b05795f7de00b9b
CAT-QuickHeal Clean McAfee Fareit-FTB!6B05795F7DE0 Cylance Unsafe
Zillya Clean AegisLab Clean Sangfor Clean
K7AntiVirus Trojan ( 005680341 ) Alibaba Clean K7GW Trojan ( 005680341 )
Cybereason malicious.e8c6f1 Arcabit Clean Invincea heuristic
BitDefenderTheta Gen:[email protected] F-Prot W32/Injector.ABY.gen!Eldorado Symantec ML.Attribute.HighConfidence
TotalDefense Clean Baidu Clean APEX Malicious
Paloalto Clean ClamAV Clean Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean NANO-Antivirus Clean SUPERAntiSpyware Clean
Avast Clean Rising Malware.Heuristic!ET#100% (RDMK:cmRtazpl4I95cdqG9rvlBz3ce7sL) Ad-Aware Clean
Emsisoft Clean Comodo Clean F-Secure Clean
DrWeb Clean VIPRE Clean TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Fareit.bc Trapmine malicious.moderate.ml.score CMC Clean
Sophos Clean SentinelOne DFI - Suspicious PE Cyren W32/Injector.ABY.gen!Eldorado
Jiangmin Clean Webroot Clean Avira Clean
Fortinet W32/Injector.ELZG!tr Antiy-AVL Clean Kingsoft Clean
Endgame malicious (high confidence) Microsoft Trojan:Win32/Wacatac.C!ml ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic Avast-Mobile Clean Cynet Malicious (score: 100)
AhnLab-V3 Suspicious/Win.Delphiless.X2066 Acronis suspicious ALYac Clean
MAX Clean VBA32 Clean Malwarebytes Clean
Zoner Clean ESET-NOD32 a variant of Win32/Injector.EMJE TrendMicro-HouseCall Clean
Tencent Clean Yandex Clean TACHYON Clean
eGambit Unsafe.AI_Score_95% GData Clean AVG Clean
Panda Clean CrowdStrike win/malicious_confidence_80% (D) Qihoo-360 HEUR/QVM05.1.166F.Malware.Gen
Sorry! No behavior.

Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
Y 1.1.1.1 [VT] Australia

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.1.5 50775 1.1.1.1 53
192.168.1.5 52876 1.1.1.1 53
192.168.1.5 54724 1.1.1.1 53
192.168.1.5 61410 1.1.1.1 53
192.168.1.5 63931 1.1.1.1 53
192.168.1.5 137 192.168.1.255 137
192.168.1.5 50775 8.8.8.8 53
192.168.1.5 52876 8.8.8.8 53
192.168.1.5 54312 8.8.8.8 53
192.168.1.5 54724 8.8.8.8 53
192.168.1.5 61410 8.8.8.8 53
192.168.1.5 63931 8.8.8.8 53

DNS

Name Response Post-Analysis Lookup
dutchlogs.us [VT] 5.77.32.186 [VT]

HTTP Requests

No HTTP requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

ICMP traffic

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No dropped Suricata Extracted files.

JA3

Source Source Port Destination Destination Port JA3 Hash JA3 Description
192.168.1.5 49175 13.107.42.23 443 3b483d0b34894548b602e8d18cdc24c5 unknown
Sorry! No dropped files.
Sorry! No CAPE files.
Process Name services.exe
PID 460
Dump Size 258048 bytes
Module Path C:\Windows\System32\services.exe
Type PE image: 32-bit executable
PE timestamp 2015-04-13 01:58:57
MD5 462cca66c806eccef84051148153bc46
SHA1 c952a2a4314a4c708471e675b39fabfd2b558aec
SHA256