paladin316

Exes_e0b6bbd9bc80c81573743aba3a1494ba_png_2019-06-27_18_30.json

Jun 27th, 2019
2,251
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 174.67 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Malicious"
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Exes_e0b6bbd9bc80c81573743aba3a1494ba.png"
  7. [*] File Size: 487424
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. [*] SHA256: "3c28e0ea1590a299b036aa07fa7175a252bf506cc69843021747c906dad1b6bc"
  10. [*] MD5: "e0b6bbd9bc80c81573743aba3a1494ba"
  11. [*] SHA1: "4987e7b22170e272232b5ad4935212da4b24f009"
  12. [*] SHA512: "cbacf11bc04099ccbb9c540b4145568ebda3d49b7f053d90f993bf9e29f07950942f032d7bd092adaabebabe6be89a19fe890005957f06fa34c7adc9a4f42715"
  13. [*] CRC32: "8CF55557"
  14. [*] SSDEEP: "12288:pzf3B2gRyEsyG8kx1P1fHaKWjZXJwuxHqoKu:5B2g3sqkD1fHaKWjZucv"
  15.  
  16. [*] Process Execution: [
  17. "Exes_e0b6bbd9bc80c81573743aba3a1494ba.png",
  18. "cmd.exe",
  19. "powershell.exe",
  20. "cmd.exe",
  21. "sc.exe",
  22. "cmd.exe",
  23. "sc.exe",
  24. "cmd.exe",
  25. "sc.exe",
  26. "cmd.exe",
  27. "sc.exe",
  28. "cmd.exe",
  29. "powershell.exe",
  30. "Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe",
  31. "cmd.exe",
  32. "powershell.exe",
  33. "cmd.exe",
  34. "sc.exe",
  35. "cmd.exe",
  36. "sc.exe",
  37. "svchost.exe",
  38. "services.exe",
  39. "mscorsvw.exe",
  40. "mscorsvw.exe",
  41. "mscorsvw.exe",
  42. "mscorsvw.exe",
  43. "mscorsvw.exe",
  44. "mscorsvw.exe",
  45. "mscorsvw.exe",
  46. "mscorsvw.exe",
  47. "mscorsvw.exe",
  48. "mscorsvw.exe",
  49. "mscorsvw.exe",
  50. "mscorsvw.exe",
  51. "mscorsvw.exe",
  52. "mscorsvw.exe",
  53. "mscorsvw.exe",
  54. "mscorsvw.exe",
  55. "mscorsvw.exe",
  56. "mscorsvw.exe",
  57. "mscorsvw.exe",
  58. "mscorsvw.exe",
  59. "mscorsvw.exe",
  60. "mscorsvw.exe",
  61. "mscorsvw.exe",
  62. "mscorsvw.exe",
  63. "mscorsvw.exe",
  64. "mscorsvw.exe",
  65. "mscorsvw.exe",
  66. "mscorsvw.exe",
  67. "svchost.exe",
  68. "svchost.exe",
  69. "svchost.exe",
  70. "sppsvc.exe",
  71. "svchost.exe",
  72. "WmiPrvSE.exe",
  73. "svchost.exe",
  74. "svchost.exe",
  75. "WerFault.exe",
  76. "wermgr.exe",
  77. "WerFault.exe",
  78. "wermgr.exe",
  79. "taskhost.exe",
  80. "sc.exe",
  81. "svchost.exe",
  82. "explorer.exe",
  83. "WMIADAP.exe"
  84. ]
  85.  
  86. [*] Signatures Detected: [
  87. {
  88. "Description": "At least one process apparently crashed during execution",
  89. "Details": []
  90. },
  91. {
  92. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  93. "Details": [
  94. {
  95. "IP": "23.12.41.9:80"
  96. }
  97. ]
  98. },
  99. {
  100. "Description": "Creates RWX memory",
  101. "Details": []
  102. },
  103. {
  104. "Description": "Possible date expiration check, exits too soon after checking local time",
  105. "Details": [
  106. {
  107. "process": "cmd.exe, PID 2136"
  108. }
  109. ]
  110. },
  111. {
  112. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  113. "Details": [
  114. {
  115. "ioc": "v2.0.50727"
  116. },
  117. {
  118. "ioc": "ontract.v10.0.dll"
  119. }
  120. ]
  121. },
  122. {
  123. "Description": "A process created a hidden window",
  124. "Details": [
  125. {
  126. "Process": "Exes_e0b6bbd9bc80c81573743aba3a1494ba.png -> cmd"
  127. },
  128. {
  129. "Process": "Exes_e0b6bbd9bc80c81573743aba3a1494ba.png -> cmd"
  130. },
  131. {
  132. "Process": "Exes_e0b6bbd9bc80c81573743aba3a1494ba.png -> cmd"
  133. },
  134. {
  135. "Process": "Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe -> cmd"
  136. },
  137. {
  138. "Process": "Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe -> cmd"
  139. },
  140. {
  141. "Process": "Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe -> cmd"
  142. }
  143. ]
  144. },
  145. {
  146. "Description": "Drops a binary and executes it",
  147. "Details": [
  148. {
  149. "binary": "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe"
  150. }
  151. ]
  152. },
  153. {
  154. "Description": "The binary likely contains encrypted or compressed data.",
  155. "Details": [
  156. {
  157. "section": "name: .rsrc, entropy: 7.39, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0002d000, virtual_size: 0x0002ca80"
  158. }
  159. ]
  160. },
  161. {
  162. "Description": "Queries information on disks, possibly for anti-virtualization",
  163. "Details": []
  164. },
  165. {
  166. "Description": "Sniffs keystrokes",
  167. "Details": [
  168. {
  169. "SetWindowsHookExW": "Process: explorer.exe(1884)"
  170. }
  171. ]
  172. },
  173. {
  174. "Description": "Attempts to stop active services",
  175. "Details": [
  176. {
  177. "servicename": "WinDefend"
  178. }
  179. ]
  180. },
  181. {
  182. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  183. "Details": [
  184. {
  185. "Process": "mscorsvw.exe tried to sleep 3480 seconds, actually delayed analysis time by 0 seconds"
  186. },
  187. {
  188. "Process": "sppsvc.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  189. },
  190. {
  191. "Process": "WmiPrvSE.exe tried to sleep 960 seconds, actually delayed analysis time by 0 seconds"
  192. }
  193. ]
  194. },
  195. {
  196. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  197. "Details": [
  198. {
  199. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 12703096 times"
  200. }
  201. ]
  202. },
  203. {
  204. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  205. "Details": [
  206. {
  207. "modified_name": "svchost.exe",
  208. "modified_path": "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe",
  209. "original_name": "svchost.exe",
  210. "original_path": "C:\\Windows\\system32\\svchost.exe"
  211. }
  212. ]
  213. },
  214. {
  215. "Description": "Creates a hidden or system file",
  216. "Details": [
  217. {
  218. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2277db3.TMP"
  219. },
  220. {
  221. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2273511.TMP"
  222. },
  223. {
  224. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index15f.dat"
  225. },
  226. {
  227. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index15e.dat"
  228. },
  229. {
  230. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index160.dat"
  231. },
  232. {
  233. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index161.dat"
  234. },
  235. {
  236. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index162.dat"
  237. },
  238. {
  239. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index163.dat"
  240. },
  241. {
  242. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index164.dat"
  243. },
  244. {
  245. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index165.dat"
  246. },
  247. {
  248. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index166.dat"
  249. },
  250. {
  251. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index167.dat"
  252. },
  253. {
  254. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index168.dat"
  255. },
  256. {
  257. "file": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index169.dat"
  258. }
  259. ]
  260. },
  261. {
  262. "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
  263. "Details": []
  264. },
  265. {
  266. "Description": "File has been identified by 16 Antiviruses on VirusTotal as malicious",
  267. "Details": [
  268. {
  269. "FireEye": "Generic.mg.e0b6bbd9bc80c815"
  270. },
  271. {
  272. "APEX": "Malicious"
  273. },
  274. {
  275. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  276. },
  277. {
  278. "Invincea": "heuristic"
  279. },
  280. {
  281. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.gc"
  282. },
  283. {
  284. "Trapmine": "malicious.high.ml.score"
  285. },
  286. {
  287. "Jiangmin": "Pack.Mal.AntiVM"
  288. },
  289. {
  290. "Webroot": "Trojan.Dropper.Gen"
  291. },
  292. {
  293. "Endgame": "malicious (high confidence)"
  294. },
  295. {
  296. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  297. },
  298. {
  299. "Microsoft": "Trojan:Win32/MereTam.A"
  300. },
  301. {
  302. "Acronis": "suspicious"
  303. },
  304. {
  305. "Cylance": "Unsafe"
  306. },
  307. {
  308. "AVG": "FileRepMalware"
  309. },
  310. {
  311. "Paloalto": "generic.ml"
  312. },
  313. {
  314. "CrowdStrike": "win/malicious_confidence_90% (D)"
  315. }
  316. ]
  317. },
  318. {
  319. "Description": "Checks the version of Bios, possibly for anti-virtualization",
  320. "Details": []
  321. },
  322. {
  323. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  324. "Details": []
  325. },
  326. {
  327. "Description": "Creates a copy of itself",
  328. "Details": [
  329. {
  330. "copy": "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe"
  331. }
  332. ]
  333. },
  334. {
  335. "Description": "Attempts to disable Windows Defender",
  336. "Details": []
  337. },
  338. {
  339. "Description": "Collects information to fingerprint the system",
  340. "Details": []
  341. }
  342. ]
  343.  
  344. [*] Started Service: [
  345. "WerSvc",
  346. "W32Time"
  347. ]
  348.  
  349. [*] Executed Commands: [
  350. "\"C:\\Windows\\System32\\cmd.exe\" /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  351. "cmd /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  352. "\"C:\\Windows\\System32\\cmd.exe\" /c sc stop WinDefend",
  353. "cmd /c sc stop WinDefend",
  354. "\"C:\\Windows\\System32\\cmd.exe\" /c sc delete WinDefend",
  355. "cmd /c sc delete WinDefend",
  356. "C:\\Windows\\system32\\cmd.exe /c sc stop WinDefend",
  357. "C:\\Windows\\system32\\cmd.exe /c sc delete WinDefend",
  358. "C:\\Windows\\system32\\cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  359. "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe",
  360. "powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  361. "sc stop WinDefend",
  362. "sc delete WinDefend",
  363. "C:\\Windows\\system32\\svchost.exe",
  364. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
  365. "C:\\Windows\\system32\\svchost.exe -k LocalServiceAndNoImpersonation",
  366. "C:\\Windows\\system32\\sppsvc.exe",
  367. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  368. "taskhost.exe $(Arg0)",
  369. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  370. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  371. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {A77D01E6-0EDB-4F86-964A-D4AFBDF99430} -Comment \"Dependency Analyzer\"",
  372. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {B90CD4F3-8837-4E88-B30B-FA46E2F96CCF} -Comment \"Dependency Analyzer\"",
  373. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {7BC658C5-1B70-40DF-8E84-C1D038678FA0} -Comment \"Dependency Analyzer\"",
  374. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {CCB709EE-B4CC-45FF-A024-F704E18CBC8B} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\AddInSideAdapters\\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll\"",
  375. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {72174C53-70DD-4DF0-9E70-63FF7D432D9E} -Comment \"Dependency Analyzer\"",
  376. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {556043C5-8B19-4E62-8F8F-E6B5235377B1} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\AddInSideAdapters\\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll\"",
  377. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {4772CF34-863D-4B66-BB1E-1586BA06421D} -Comment \"Dependency Analyzer\"",
  378. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {4E3C3ACC-AD78-4F13-9063-A03EAB2B4ADA} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\AddInSideAdapters\\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll\"",
  379. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {96DFF0F0-028A-4B64-8E45-8FD9CBAA5CC6} -Comment \"Dependency Analyzer\"",
  380. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {7E61ED20-4619-46B0-AF0B-C28A714386AD} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\AddInSideAdapters\\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll\"",
  381. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {AA7A3E4A-378A-4393-A034-BB5F51231C9B} -Comment \"Dependency Analyzer\"",
  382. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {7C082D41-6682-4C11-B654-738BB1B95C2D} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\AddInViews\\Microsoft.Office.Tools.v9.0.dll\"",
  383. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {3AE23E99-D7FD-406B-A437-34344CE6A25B} -Comment \"Dependency Analyzer\"",
  384. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {D66AA8AA-EA82-4CD9-8715-0616FBD12A65} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\AddInViews\\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll\"",
  385. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {E6F77928-5478-4D5C-ADBA-38022E1A9612} -Comment \"Dependency Analyzer\"",
  386. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {40615AFB-AFB3-48F2-B50F-A3520F2AE65D} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\AddInViews\\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll\"",
  387. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {DF731495-8EF3-43EA-825D-3D2EDAEFBABF} -Comment \"Dependency Analyzer\"",
  388. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {BC9F88B7-E038-4C1E-9695-B15CF5C4BDD4} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\Contracts\\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll\"",
  389. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {B0178BFE-8A76-4ED0-B52F-058BD95E0E0F} -Comment \"Dependency Analyzer\"",
  390. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {5A1A88A0-83AC-4E50-A334-0CB00438434A} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\Contracts\\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll\"",
  391. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {D4E4255E-3F4E-4FC6-A440-B9EF9341A27E} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\Contracts\\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll\"",
  392. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {ECCD61FF-AED9-494A-AFC0-193348B58A93} -Comment \"Dependency Analyzer\"",
  393. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {67A94996-4001-4AE8-9A3D-3EC5219E0D00} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\Contracts\\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll\"",
  394. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {DDD75712-E8E0-4E9C-822D-50E446130940} -Comment \"Dependency Analyzer\"",
  395. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {03B2578E-E795-49EA-8581-A3E6340B4515} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\Contracts\\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll\"",
  396. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {70231502-4139-4BC3-B7FD-212DA83B0915} -Comment \"Dependency Analyzer\"",
  397. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe -UseCLSID {F062D3E1-B267-4EFE-A1AC-D0CEB51C8461} -Comment \"Compile worker for C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTA\\Pipeline.v10.0\\HostSideAdapters\\Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll\"",
  398. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  399. "C:\\Windows\\system32\\WerFault.exe -u -p 3060 -s 368",
  400. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\"",
  401. "C:\\Windows\\system32\\WerFault.exe -u -p 1316 -s 288",
  402. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\""
  403. ]
  404.  
  405. [*] Mutexes: [
  406. "Local\\ZoneAttributeCacheCounterMutex",
  407. "Local\\ZonesCacheCounterMutex",
  408. "Local\\ZonesLockedCacheCounterMutex",
  409. "Global\\CLR_CASOFF_MUTEX",
  410. "Global\\838B6C9EB27932960",
  411. "DBWinMutex",
  412. "Local\\WERReportingForProcess3060",
  413. "Global\\\\xe5\\x88\\x90\\xc2\\x89",
  414. "Global\\\\xed\\x9c\\x90\\xc7\\x93",
  415. "WERUI_APPCRASH-a468bbd7f9d5bc71a51824c4153e31390dce9f",
  416. "Local\\WERReportingForProcess1316",
  417. "Global\\\\xe5\\x88\\x90\\xc2\\x8c",
  418. "Global\\ADAP_WMI_ENTRY",
  419. "Global\\RefreshRA_Mutex",
  420. "Global\\RefreshRA_Mutex_Lib",
  421. "Global\\RefreshRA_Mutex_Flag",
  422. "Global\\\\xed\\x95\\xb0\\xc7\\xa0",
  423. "WERUI_BEX64-40c9bd36c65451fafb0fe7d6967ae2b451a6f19"
  424. ]
  425.  
  426. [*] Modified Files: [
  427. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
  428. "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_e0b8bbd9bc80c81793943aba3a1494ba.exe",
  429. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  430. "\\??\\PIPE\\srvsvc",
  431. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\AQPYM2WTCC9KPX3OGW4X.temp",
  432. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2277db3.TMP",
  433. "C:\\Windows\\SysWOW64\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  434. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\BIM5K3OD9AE8YZW0ZTB1.temp",
  435. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
  436. "C:\\Users\\user\\AppData\\Roaming\\diskram\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  437. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\GUC1QUMW973WTZD4FEEJ.temp",
  438. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2273511.TMP",
  439. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  440. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  441. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen_service.lock",
  442. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen_service.log",
  443. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngenservicelock.dat",
  444. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngenrootstorelock.dat",
  445. "C:\\Windows\\Microsoft.NET\\ngenservice_pri3_lock.dat",
  446. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\696F3DE637E6DE85B458996D49D759AD",
  447. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7396C420A8E1BC1DA97F1AF0D10BAD21",
  448. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  449. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\F90F18257CBB4D84216AC1E1F3BB2C76",
  450. "\\??\\SPDevice",
  451. "\\??\\PIPE\\wkssvc",
  452. "C:\\Windows\\sysnative\\winevt\\Logs\\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx",
  453. "C:\\Windows\\sysnative\\winevt\\Logs\\Microsoft-Windows-WER-Diag%4Operational.evtx",
  454. "C:\\Windows\\sysnative\\winevt\\Logs\\Microsoft-Windows-Fault-Tolerant-Heap%4Operational.evtx",
  455. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP5787.tmp\\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll",
  456. "C:\\Windows\\assembly\\GACLock.dat",
  457. "C:\\Windows\\assembly\\ngenlock.dat",
  458. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index15f.dat",
  459. "C:\\Windows\\assembly\\temp\\Q9RFL4KAPF",
  460. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\858a16566417324d7113703e9d9a220f\\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.ni.dll",
  461. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  462. "\\??\\PHYSICALDRIVE0",
  463. "\\??\\CDROM0",
  464. "\\??\\WMIDataDevice",
  465. "\\??\\PIPE\\lsarpc",
  466. "C:\\BVTBin\\Tests\\installpackage\\csilogfile.log",
  467. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP64B6.tmp\\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll",
  468. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index160.dat",
  469. "C:\\Windows\\assembly\\temp\\7PDRUIN1L4",
  470. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\aa8c5b1ed8c1befde1f41b7cd4886163\\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.ni.dll",
  471. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP9914.tmp\\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll",
  472. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index161.dat",
  473. "C:\\Windows\\assembly\\temp\\9433GOHN4L",
  474. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\a00f92391877dd945e4a4639788c20c4\\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.ni.dll",
  475. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPA28A.tmp\\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll",
  476. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index162.dat",
  477. "C:\\Windows\\assembly\\temp\\6CQWLLURSD",
  478. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\768fc8d43917315c6e1ea9a91b5295a8\\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.ni.dll",
  479. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPB140.tmp\\Microsoft.Office.Tools.v9.0.dll",
  480. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index163.dat",
  481. "C:\\Windows\\assembly\\temp\\8TRRW7TXOX",
  482. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.Office.To#\\09c86f6b3ef36b680afe553f4bb7182d\\Microsoft.Office.Tools.v9.0.ni.dll",
  483. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\696F3DE637E6DE85B458996D49D759AD",
  484. "C:\\Windows\\Temp\\CabE7C1.tmp",
  485. "C:\\Windows\\Temp\\TarE7C2.tmp",
  486. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7396C420A8E1BC1DA97F1AF0D10BAD21",
  487. "C:\\Windows\\Temp\\Cab7490.tmp",
  488. "C:\\Windows\\Temp\\Tar7491.tmp",
  489. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP7F7F.tmp\\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll",
  490. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index164.dat",
  491. "C:\\Windows\\assembly\\temp\\YLLDZM42I4",
  492. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\4b3742b9ce5a12286a9e50f48e6dbbb2\\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.ni.dll",
  493. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPAB01.tmp\\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll",
  494. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index165.dat",
  495. "C:\\Windows\\assembly\\temp\\UKJBZ34RFZ",
  496. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\7ccd189d94efd1491116295d6fb86584\\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.ni.dll",
  497. "C:\\Windows\\Temp\\CabCD9D.tmp",
  498. "C:\\Windows\\Temp\\TarCD9E.tmp",
  499. "C:\\Windows\\Temp\\CabF0E4.tmp",
  500. "C:\\Windows\\Temp\\TarF0F5.tmp",
  501. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPF22E.tmp\\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll",
  502. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index166.dat",
  503. "C:\\Windows\\assembly\\temp\\6QG4LWWMB1",
  504. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\d22de3f4c42430a9421588d3b2c0de6f\\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.ni.dll",
  505. "C:\\Windows\\Temp\\WER2C6.tmp.appcompat.txt",
  506. "C:\\Windows\\Temp\\WER7F7.tmp.WERInternalMetadata.xml",
  507. "C:\\Windows\\Temp\\WERA5A.tmp.hdmp",
  508. "C:\\Windows\\Temp\\WER1B52.tmp.mdmp",
  509. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\\WER2C6.tmp.appcompat.txt",
  510. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\\WER7F7.tmp.WERInternalMetadata.xml",
  511. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\\WERA5A.tmp.hdmp",
  512. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\\WER1B52.tmp.mdmp",
  513. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\\Report.wer",
  514. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\\Report.wer.tmp",
  515. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP2C76.tmp\\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll",
  516. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index167.dat",
  517. "C:\\Windows\\assembly\\temp\\319WLI7L9N",
  518. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\8cace01bdef1fa3c1deb129b0c201333\\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.ni.dll",
  519. "C:\\Windows\\Temp\\CabA6E6.tmp",
  520. "C:\\Windows\\Temp\\TarA6E7.tmp",
  521. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERD9EC.tmp.appcompat.txt",
  522. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE75B.tmp.WERInternalMetadata.xml",
  523. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE817.tmp.hdmp",
  524. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERF595.tmp.mdmp",
  525. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\\WERD9EC.tmp.appcompat.txt",
  526. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\\WERE75B.tmp.WERInternalMetadata.xml",
  527. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\\WERE817.tmp.hdmp",
  528. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\\WERF595.tmp.mdmp",
  529. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\\Report.wer",
  530. "C:\\Windows\\Temp\\CabE5A4.tmp",
  531. "C:\\Windows\\Temp\\TarE5A5.tmp",
  532. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPE931.tmp\\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll",
  533. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index168.dat",
  534. "C:\\Windows\\assembly\\temp\\E0RKAJIMRM",
  535. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\f475ddf8555a053a766081058e4df1ec\\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.ni.dll",
  536. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPFA26.tmp\\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll",
  537. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index169.dat",
  538. "C:\\Windows\\assembly\\temp\\DM4PAMQBYW",
  539. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\10544e726a20c09e227a1c906be47b69\\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.ni.dll",
  540. "C:\\Windows\\Temp\\Cab4808.tmp",
  541. "C:\\Windows\\Temp\\Tar4818.tmp",
  542. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\\Report.wer.tmp",
  543. "C:\\Windows\\Temp\\CabC72B.tmp",
  544. "C:\\Windows\\Temp\\TarC72C.tmp"
  545. ]
  546.  
  547. [*] Deleted Files: [
  548. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2277db3.TMP",
  549. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.160.36142562",
  550. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.160.36142562",
  551. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.160.36142578",
  552. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\BIM5K3OD9AE8YZW0ZTB1.temp",
  553. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1764.36145234",
  554. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1764.36145234",
  555. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1764.36145250",
  556. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2273511.TMP",
  557. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2572.36125796",
  558. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2572.36125796",
  559. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2572.36125796",
  560. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngenserviceclientlock.dat",
  561. "C:\\Windows\\Microsoft.NET\\ngenservice_pri0_lock.dat",
  562. "C:\\Windows\\Microsoft.NET\\ngenservice_pri1_lock.dat",
  563. "C:\\Windows\\Microsoft.NET\\ngenservice_pri2_lock.dat",
  564. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2488.36326625",
  565. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2488.36326625",
  566. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2488.36326640",
  567. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1816.36327281",
  568. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1816.36327281",
  569. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1816.36327296",
  570. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.204.36327828",
  571. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.204.36327843",
  572. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.204.36327843",
  573. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP5787.tmp",
  574. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index15e.dat",
  575. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\858a16566417324d7113703e9d9a220f",
  576. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#",
  577. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP5787.tmp\\Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll",
  578. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1696.36328906",
  579. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1696.36328921",
  580. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1696.36328921",
  581. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1832.36330500",
  582. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1832.36330515",
  583. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1832.36330515",
  584. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP64B6.tmp",
  585. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index15f.dat",
  586. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\aa8c5b1ed8c1befde1f41b7cd4886163",
  587. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP64B6.tmp\\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll",
  588. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1624.36332281",
  589. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1624.36332281",
  590. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1624.36332296",
  591. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1200.36342156",
  592. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1200.36342171",
  593. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1200.36342171",
  594. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP9914.tmp",
  595. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index160.dat",
  596. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\a00f92391877dd945e4a4639788c20c4",
  597. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP9914.tmp\\Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll",
  598. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1432.36345687",
  599. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1432.36345703",
  600. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1432.36345703",
  601. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2520.36347203",
  602. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2520.36347203",
  603. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2520.36347218",
  604. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPA28A.tmp",
  605. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index161.dat",
  606. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\768fc8d43917315c6e1ea9a91b5295a8",
  607. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPA28A.tmp\\Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll",
  608. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1340.36348109",
  609. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1340.36348109",
  610. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1340.36348125",
  611. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.476.36350921",
  612. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.476.36350921",
  613. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.476.36350937",
  614. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPB140.tmp",
  615. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index162.dat",
  616. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.Office.To#\\09c86f6b3ef36b680afe553f4bb7182d",
  617. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.Office.To#",
  618. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPB140.tmp\\Microsoft.Office.Tools.v9.0.dll",
  619. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2696.36351875",
  620. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2696.36351875",
  621. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2696.36351890",
  622. "C:\\Windows\\Temp\\CabE7C1.tmp",
  623. "C:\\Windows\\Temp\\TarE7C2.tmp",
  624. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3020.36353125",
  625. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3020.36353125",
  626. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3020.36353140",
  627. "C:\\Windows\\Temp\\Cab7490.tmp",
  628. "C:\\Windows\\Temp\\Tar7491.tmp",
  629. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP7F7F.tmp",
  630. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index163.dat",
  631. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\4b3742b9ce5a12286a9e50f48e6dbbb2",
  632. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP7F7F.tmp\\Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll",
  633. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1596.36377796",
  634. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1596.36377796",
  635. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1596.36377796",
  636. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2004.36407828",
  637. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2004.36407828",
  638. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2004.36407859",
  639. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPAB01.tmp",
  640. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index164.dat",
  641. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\7ccd189d94efd1491116295d6fb86584",
  642. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPAB01.tmp\\Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll",
  643. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2836.36415828",
  644. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2836.36415828",
  645. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2836.36415843",
  646. "C:\\Windows\\Temp\\CabCD9D.tmp",
  647. "C:\\Windows\\Temp\\TarCD9E.tmp",
  648. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1196.36421656",
  649. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1196.36421656",
  650. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1196.36421671",
  651. "C:\\Windows\\Temp\\CabF0E4.tmp",
  652. "C:\\Windows\\Temp\\TarF0F5.tmp",
  653. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPF22E.tmp",
  654. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index165.dat",
  655. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\d22de3f4c42430a9421588d3b2c0de6f",
  656. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPF22E.tmp\\Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll",
  657. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2596.36426359",
  658. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2596.36426375",
  659. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2596.36426390",
  660. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1100.36435218",
  661. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1100.36435218",
  662. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1100.36435234",
  663. "C:\\Windows\\Temp\\WER2C6.tmp",
  664. "C:\\Windows\\Temp\\WER2C6.tmp.appcompat.txt",
  665. "C:\\Windows\\Temp\\WER7F7.tmp",
  666. "C:\\Windows\\Temp\\WER7F7.tmp.WERInternalMetadata.xml",
  667. "C:\\Windows\\Temp\\WERA5A.tmp",
  668. "C:\\Windows\\Temp\\WERA5A.tmp.hdmp",
  669. "C:\\Windows\\Temp\\WER1B52.tmp",
  670. "C:\\Windows\\Temp\\WER1B52.tmp.mdmp",
  671. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_mscorsvw.exe_a468bbd7f9d5bc71a51824c4153e31390dce9f_cab_007eb4ad\\Report.wer.tmp",
  672. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP2C76.tmp",
  673. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index166.dat",
  674. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\8cace01bdef1fa3c1deb129b0c201333",
  675. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAP2C76.tmp\\Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll",
  676. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1384.36448906",
  677. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1384.36448921",
  678. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1384.36448921",
  679. "C:\\Windows\\Temp\\CabA6E6.tmp",
  680. "C:\\Windows\\Temp\\TarA6E7.tmp",
  681. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2164.36450062",
  682. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2164.36450062",
  683. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2164.36450078",
  684. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERD9EC.tmp",
  685. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERD9EC.tmp.appcompat.txt",
  686. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE75B.tmp",
  687. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE75B.tmp.WERInternalMetadata.xml",
  688. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE817.tmp",
  689. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE817.tmp.hdmp",
  690. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERF595.tmp",
  691. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERF595.tmp.mdmp",
  692. "C:\\Windows\\Temp\\CabE5A4.tmp",
  693. "C:\\Windows\\Temp\\TarE5A5.tmp",
  694. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPE931.tmp",
  695. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index167.dat",
  696. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\f475ddf8555a053a766081058e4df1ec",
  697. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPE931.tmp\\Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll",
  698. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2096.36486234",
  699. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2096.36486281",
  700. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2096.36486312",
  701. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3452.36500218",
  702. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3452.36500234",
  703. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3452.36500250",
  704. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPFA26.tmp",
  705. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\index168.dat",
  706. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Microsoft.VisualStu#\\10544e726a20c09e227a1c906be47b69",
  707. "C:\\Windows\\assembly\\NativeImages_v2.0.50727_64\\Temp\\ZAPFA26.tmp\\Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll",
  708. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3640.36501531",
  709. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3640.36501546",
  710. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3640.36501578",
  711. "C:\\Windows\\Temp\\Cab4808.tmp",
  712. "C:\\Windows\\Temp\\Tar4818.tmp",
  713. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3912.36504921",
  714. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3912.36504921",
  715. "C:\\Windows\\sysnative\\config\\systemprofile\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3912.36504937",
  716. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_40c9bd36c65451fafb0fe7d6967ae2b451a6f19_cab_0832bbc7\\Report.wer.tmp",
  717. "C:\\Windows\\Temp\\CabC72B.tmp"
  718. ]
  719.  
  720. [*] Modified Registry Keys: [
  721. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  722. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  723. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender",
  724. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware",
  725. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
  726. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring",
  727. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection",
  728. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnRealtimeEnable",
  729. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection",
  730. "DisableNotifications",
  731. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  732. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
  733. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  734. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  735. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  736. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3",
  737. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3\\Scenario",
  738. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3\\Status",
  739. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\2\\Status",
  740. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3\\ImageList",
  741. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64\\2\\ImageList",
  742. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64\\2\\Status",
  743. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll\\0\\ImageList",
  744. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Applications.AddInAdapter.v9.0.dll\\0\\Status",
  745. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll\\0\\ImageList",
  746. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll\\0\\Status",
  747. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll\\0\\ImageList",
  748. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Office.Excel.AddInAdapter.v9.0.dll\\0\\Status",
  749. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll\\0\\ImageList",
  750. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInSideAdapters/Microsoft.VisualStudio.Tools.Office.Word.AddInAdapter.v9.0.dll\\0\\Status",
  751. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInViews/Microsoft.Office.Tools.v9.0.dll\\0\\ImageList",
  752. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInViews/Microsoft.Office.Tools.v9.0.dll\\0\\Status",
  753. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInViews/Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll\\0\\ImageList",
  754. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInViews/Microsoft.VisualStudio.Tools.Applications.Runtime.v10.0.dll\\0\\Status",
  755. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInViews/Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll\\0\\ImageList",
  756. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/AddInViews/Microsoft.VisualStudio.Tools.Applications.Runtime.v9.0.dll\\0\\Status",
  757. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll\\0\\ImageList",
  758. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Applications.Contract.v10.0.dll\\0\\Status",
  759. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll\\0\\ImageList",
  760. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Applications.Contract.v9.0.dll\\0\\Status",
  761. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll\\0\\ImageList",
  762. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Office.Contract.v10.0.dll\\0\\Status",
  763. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll\\0\\ImageList",
  764. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/Contracts/Microsoft.VisualStudio.Tools.Office.Contract.v9.0.dll\\0\\Status",
  765. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/HostSideAdapters/Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll\\0\\ImageList",
  766. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\C:/Program Files (x86)/Common Files/Microsoft Shared/VSTA/Pipeline.v10.0/HostSideAdapters/Microsoft.VisualStudio.Tools.Applications.HostAdapter.v10.0.dll\\0\\Status",
  767. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SoftwareProtectionPlatform\\ServiceSessionId",
  768. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.100\\CheckSetting",
  769. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.101\\CheckSetting",
  770. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0\\CheckSetting",
  771. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\\CheckSetting",
  772. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.101\\CheckSetting",
  773. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103\\CheckSetting",
  774. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100\\CheckSetting",
  775. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102\\CheckSetting",
  776. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.104\\CheckSetting",
  777. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
  778. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
  779. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\WHCIconStartup",
  780. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.bmp\\OpenWithProgids\\Paint.Picture",
  781. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.cab\\OpenWithProgids\\CABFolder",
  782. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.contact\\OpenWithProgids\\contact_wab_auto_file",
  783. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.css\\OpenWithProgids\\CSSfile",
  784. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.csv\\OpenWithProgids\\Excel.CSV",
  785. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dib\\OpenWithProgids\\Paint.Picture",
  786. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dll\\OpenWithProgids\\dllfile",
  787. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.doc\\OpenWithProgids\\Word.Document.8",
  788. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docm\\OpenWithProgids\\Word.DocumentMacroEnabled.12",
  789. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docx\\OpenWithProgids\\Word.Document.12",
  790. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dot\\OpenWithProgids\\Word.Template.8",
  791. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotm\\OpenWithProgids\\Word.TemplateMacroEnabled.12",
  792. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotx\\OpenWithProgids\\Word.Template.12",
  793. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dwfx\\OpenWithProgids\\Windows.XPSReachViewer",
  794. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.easmx\\OpenWithProgids\\Windows.XPSReachViewer",
  795. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.edrwx\\OpenWithProgids\\Windows.XPSReachViewer",
  796. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.emf\\OpenWithProgids\\emffile",
  797. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.eprtx\\OpenWithProgids\\Windows.XPSReachViewer",
  798. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\OpenWithProgids\\exefile",
  799. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.fon\\OpenWithProgids\\fonfile",
  800. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.gif\\OpenWithProgids\\giffile",
  801. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm\\OpenWithProgids\\ChromeHTML",
  802. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids\\ChromeHTML",
  803. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ico\\OpenWithProgids\\icofile",
  804. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ini\\OpenWithProgids\\inifile",
  805. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jfif\\OpenWithProgids\\pjpegfile",
  806. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpe\\OpenWithProgids\\jpegfile",
  807. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpeg\\OpenWithProgids\\jpegfile",
  808. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpg\\OpenWithProgids\\jpegfile",
  809. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jtx\\OpenWithProgids\\Windows.XPSReachViewer",
  810. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.lnk\\OpenWithProgids\\lnkfile",
  811. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mht\\OpenWithProgids\\mhtmlfile",
  812. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mhtml\\OpenWithProgids\\mhtmlfile",
  813. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.msg\\OpenWithProgids\\Outlook.File.msg.15",
  814. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ocx\\OpenWithProgids\\ocxfile",
  815. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.odt\\OpenWithProgids\\Word.OpenDocumentText.12",
  816. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.otf\\OpenWithProgids\\otffile",
  817. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.png\\OpenWithProgids\\pngfile",
  818. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pot\\OpenWithProgids\\PowerPoint.Template.8",
  819. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potm\\OpenWithProgids\\PowerPoint.TemplateMacroEnabled.12",
  820. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potx\\OpenWithProgids\\PowerPoint.Template.12",
  821. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppam\\OpenWithProgids\\PowerPoint.Addin.12",
  822. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsm\\OpenWithProgids\\PowerPoint.SlideShowMacroEnabled.12",
  823. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsx\\OpenWithProgids\\PowerPoint.SlideShow.12",
  824. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppt\\OpenWithProgids\\PowerPoint.Show.8",
  825. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptm\\OpenWithProgids\\PowerPoint.ShowMacroEnabled.12",
  826. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptx\\OpenWithProgids\\PowerPoint.Show.12",
  827. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ps1xml\\OpenWithProgids\\Microsoft.PowerShellXMLData.1",
  828. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rle\\OpenWithProgids\\rlefile",
  829. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rtf\\OpenWithProgids\\Word.RTF.8",
  830. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.scf\\OpenWithProgids\\SHCmdFile",
  831. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.search-ms\\OpenWithProgids\\SearchFolder",
  832. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.shtml\\OpenWithProgids\\ChromeHTML",
  833. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldm\\OpenWithProgids\\PowerPoint.SlideMacroEnabled.12",
  834. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldx\\OpenWithProgids\\PowerPoint.Slide.12",
  835. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sys\\OpenWithProgids\\sysfile",
  836. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tif\\OpenWithProgids\\TIFImage.Document",
  837. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tiff\\OpenWithProgids\\TIFImage.Document",
  838. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttc\\OpenWithProgids\\ttcfile",
  839. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttf\\OpenWithProgids\\ttffile",
  840. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.txt\\OpenWithProgids\\txtfile",
  841. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.vsto\\OpenWithProgids\\bootstrap.vsto.1",
  842. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wdp\\OpenWithProgids\\wdpfile",
  843. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wmf\\OpenWithProgids\\wmffile",
  844. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlam\\OpenWithProgids\\Excel.AddInMacroEnabled",
  845. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xls\\OpenWithProgids\\Excel.Sheet.8",
  846. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsb\\OpenWithProgids\\Excel.SheetBinaryMacroEnabled.12",
  847. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsm\\OpenWithProgids\\Excel.SheetMacroEnabled.12",
  848. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsx\\OpenWithProgids\\Excel.Sheet.12",
  849. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlt\\OpenWithProgids\\Excel.Template.8",
  850. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltm\\OpenWithProgids\\Excel.TemplateMacroEnabled",
  851. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltx\\OpenWithProgids\\Excel.Template",
  852. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xml\\OpenWithProgids\\xmlfile",
  853. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xps\\OpenWithProgids\\Windows.XPSReachViewer",
  854. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xsl\\OpenWithProgids\\xslfile",
  855. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.zip\\OpenWithProgids\\CompressedFolder",
  856. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{945a8954-c147-4acd-923f-40c45405a658}.check.42\\CheckSetting",
  857. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WINEVT\\Publishers\\{945a8954-c147-4acd-923f-40c45405a658}\\Enabled",
  858. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\ILUsageMask",
  859. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NIUsageMask",
  860. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8",
  861. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\DisplayName",
  862. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\SIG",
  863. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\Status",
  864. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\LastModTime",
  865. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\InvertDependencies",
  866. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  867. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7",
  868. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\DisplayName",
  869. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\SIG",
  870. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\Status",
  871. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\LastModTime",
  872. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\InvertDependencies",
  873. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  874. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6",
  875. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\DisplayName",
  876. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\SIG",
  877. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\Status",
  878. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\LastModTime",
  879. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\InvertDependencies",
  880. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  881. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5",
  882. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\DisplayName",
  883. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\SIG",
  884. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\Status",
  885. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\LastModTime",
  886. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\InvertDependencies",
  887. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  888. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\505c41c7\\18407c1\\53",
  889. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  890. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\505c41c7\\18407c1\\53",
  891. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  892. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\505c41c7\\18407c1\\53\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  893. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\172a6d0a\\5f403964\\b0",
  894. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\505c41c7\\18407c1\\53",
  895. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\30bc7c4f\\3f50fe4f\\90",
  896. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0",
  897. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0\\DisplayName",
  898. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0\\Status",
  899. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0\\MVID",
  900. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0\\ConfigString",
  901. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0\\ConfigMask",
  902. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0\\ILDependencies",
  903. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\172a6d0a\\5f403964\\b0\\NIDependencies",
  904. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index15f",
  905. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index15f\\NIUsageMask",
  906. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index15f\\ILUsageMask",
  907. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\LatestIndex",
  908. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\SystemStoreChangeId",
  909. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4",
  910. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\DisplayName",
  911. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\SIG",
  912. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\Status",
  913. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\LastModTime",
  914. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\InvertDependencies",
  915. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\InvertDependencies\\794b0063\\27dee8be\\ae",
  916. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\19ab8d57\\1bd7b0d8\\8f\\InvertDependencies\\30bc7c4f\\3f50fe4f\\90",
  917. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\19ab8d57\\1bd7b0d8\\8f\\InvertDependencies\\794b0063\\27dee8be\\ae",
  918. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5b43ba09\\4355c2d6\\7e\\InvertDependencies\\794b0063\\27dee8be\\ae",
  919. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\6dc7d4c0\\a5cd4db\\87\\InvertDependencies\\794b0063\\27dee8be\\ae",
  920. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\61b2c30f\\70d479e\\b3",
  921. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\61b2c30f\\70d479e\\b3\\DisplayName",
  922. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\61b2c30f\\70d479e\\b3\\SIG",
  923. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\61b2c30f\\70d479e\\b3\\Status",
  924. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\61b2c30f\\70d479e\\b3\\LastModTime",
  925. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\61b2c30f\\70d479e\\b3\\InvertDependencies",
  926. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\61b2c30f\\70d479e\\b3\\InvertDependencies\\794b0063\\27dee8be\\ae",
  927. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\c991064\\2bd33e1c\\81\\InvertDependencies\\794b0063\\27dee8be\\ae",
  928. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1",
  929. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\DisplayName",
  930. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\SIG",
  931. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\Status",
  932. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\LastModTime",
  933. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\InvertDependencies",
  934. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\InvertDependencies\\794b0063\\27dee8be\\ae",
  935. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\InvertDependencies\\794b0063\\27dee8be\\ae",
  936. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\InvertDependencies\\794b0063\\27dee8be\\ae",
  937. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0",
  938. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\DisplayName",
  939. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\SIG",
  940. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\Status",
  941. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\LastModTime",
  942. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\InvertDependencies",
  943. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\InvertDependencies\\794b0063\\27dee8be\\ae",
  944. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\InvertDependencies\\794b0063\\27dee8be\\ae",
  945. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\794b0063\\27dee8be\\ae",
  946. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\794b0063\\27dee8be\\ae",
  947. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\505c41c7\\18407c1\\53\\InvertDependencies\\794b0063\\27dee8be\\ae",
  948. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\InvertDependencies\\794b0063\\27dee8be\\ae",
  949. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\794b0063\\27dee8be\\ae",
  950. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae",
  951. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae\\DisplayName",
  952. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae\\Status",
  953. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae\\MVID",
  954. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae\\ConfigString",
  955. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae\\ConfigMask",
  956. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae\\ILDependencies",
  957. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\794b0063\\27dee8be\\ae\\NIDependencies",
  958. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index160",
  959. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index160\\NIUsageMask",
  960. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index160\\ILUsageMask",
  961. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\b50d826\\39ee39d6\\ae",
  962. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\b50d826\\39ee39d6\\ae\\DisplayName",
  963. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\b50d826\\39ee39d6\\ae\\SIG",
  964. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\b50d826\\39ee39d6\\ae\\Status",
  965. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\b50d826\\39ee39d6\\ae\\LastModTime",
  966. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\b50d826\\39ee39d6\\ae\\InvertDependencies",
  967. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\b50d826\\39ee39d6\\ae\\InvertDependencies\\30c713cc\\b50d826\\ad",
  968. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\696e98a8\\5621414f\\ad",
  969. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\696e98a8\\5621414f\\ad\\DisplayName",
  970. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\696e98a8\\5621414f\\ad\\SIG",
  971. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\696e98a8\\5621414f\\ad\\Status",
  972. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\696e98a8\\5621414f\\ad\\LastModTime",
  973. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\696e98a8\\5621414f\\ad\\InvertDependencies",
  974. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\696e98a8\\5621414f\\ad\\InvertDependencies\\30c713cc\\b50d826\\ad",
  975. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\InvertDependencies\\30c713cc\\b50d826\\ad",
  976. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\InvertDependencies\\30c713cc\\b50d826\\ad",
  977. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\InvertDependencies\\30c713cc\\b50d826\\ad",
  978. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\InvertDependencies\\30c713cc\\b50d826\\ad",
  979. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\InvertDependencies\\30c713cc\\b50d826\\ad",
  980. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\30c713cc\\b50d826\\ad",
  981. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\30c713cc\\b50d826\\ad",
  982. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\505c41c7\\18407c1\\53\\InvertDependencies\\30c713cc\\b50d826\\ad",
  983. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\InvertDependencies\\30c713cc\\b50d826\\ad",
  984. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\InvertDependencies\\30c713cc\\b50d826\\ad",
  985. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\30c713cc\\b50d826\\ad",
  986. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad",
  987. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad\\DisplayName",
  988. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad\\Status",
  989. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad\\MVID",
  990. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad\\ConfigString",
  991. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad\\ConfigMask",
  992. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad\\ILDependencies",
  993. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30c713cc\\b50d826\\ad\\NIDependencies",
  994. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index161",
  995. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index161\\NIUsageMask",
  996. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index161\\ILUsageMask",
  997. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7ecb7908\\a57652a\\ac",
  998. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7ecb7908\\a57652a\\ac\\DisplayName",
  999. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7ecb7908\\a57652a\\ac\\SIG",
  1000. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7ecb7908\\a57652a\\ac\\Status",
  1001. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7ecb7908\\a57652a\\ac\\LastModTime",
  1002. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7ecb7908\\a57652a\\ac\\InvertDependencies",
  1003. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7ecb7908\\a57652a\\ac\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1004. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5eb5da09\\60f328e1\\ab",
  1005. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5eb5da09\\60f328e1\\ab\\DisplayName",
  1006. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5eb5da09\\60f328e1\\ab\\SIG",
  1007. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5eb5da09\\60f328e1\\ab\\Status",
  1008. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5eb5da09\\60f328e1\\ab\\LastModTime",
  1009. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5eb5da09\\60f328e1\\ab\\InvertDependencies",
  1010. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5eb5da09\\60f328e1\\ab\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1011. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1012. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\4c502bfe\\5b540d10\\b6\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1013. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1014. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1015. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1016. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1017. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1018. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\505c41c7\\18407c1\\53\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1019. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\5f403964\\690f05a5\\b8\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1020. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\27dee8be\\45d0e051\\b4\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1021. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\110db8ad\\7ecb7908\\ac",
  1022. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac",
  1023. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac\\DisplayName",
  1024. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac\\Status",
  1025. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac\\MVID",
  1026. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac\\ConfigString",
  1027. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac\\ConfigMask",
  1028. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac\\ILDependencies",
  1029. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\110db8ad\\7ecb7908\\ac\\NIDependencies",
  1030. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index162",
  1031. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index162\\NIUsageMask",
  1032. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index162\\ILUsageMask",
  1033. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\791c4ec4\\7f00610c\\b1\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1034. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\505c41c7\\18407c1\\53\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1035. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\19ab8d57\\1bd7b0d8\\8f\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1036. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\6dc7d4c0\\a5cd4db\\87\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1037. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1038. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\c991064\\2bd33e1c\\81\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1039. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1040. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\350c026a\\791c4ec4\\ab",
  1041. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab",
  1042. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab\\DisplayName",
  1043. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab\\Status",
  1044. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab\\MVID",
  1045. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab\\ConfigString",
  1046. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab\\ConfigMask",
  1047. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab\\ILDependencies",
  1048. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\350c026a\\791c4ec4\\ab\\NIDependencies",
  1049. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index163",
  1050. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index163\\NIUsageMask",
  1051. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index163\\ILUsageMask",
  1052. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  1053. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\265c09da\\b55bce9\\aa",
  1054. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\265c09da\\b55bce9\\aa\\DisplayName",
  1055. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\265c09da\\b55bce9\\aa\\SIG",
  1056. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\265c09da\\b55bce9\\aa\\Status",
  1057. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\265c09da\\b55bce9\\aa\\LastModTime",
  1058. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\265c09da\\b55bce9\\aa\\InvertDependencies",
  1059. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\265c09da\\b55bce9\\aa\\InvertDependencies\\2d825c1\\265c09da\\aa",
  1060. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\505c41c7\\18407c1\\53\\InvertDependencies\\2d825c1\\265c09da\\aa",
  1061. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\7ac727df\\7b5311d7\\69\\InvertDependencies\\2d825c1\\265c09da\\aa",
  1062. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\2d825c1\\265c09da\\aa",
  1063. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\7ac727df\\7b5311d7\\69",
  1064. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\2d825c1\\265c09da\\aa",
  1065. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\7ac727df\\7b5311d7\\69",
  1066. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa",
  1067. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa\\DisplayName",
  1068. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa\\Status",
  1069. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa\\MVID",
  1070. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa\\ConfigString",
  1071. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa\\ConfigMask",
  1072. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa\\ILDependencies",
  1073. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\2d825c1\\265c09da\\aa\\NIDependencies",
  1074. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index164",
  1075. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index164\\NIUsageMask",
  1076. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index164\\ILUsageMask",
  1077. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\25016a16\\48c6af76\\b7\\InvertDependencies\\435ee1bb\\25016a16\\a9",
  1078. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\505c41c7\\18407c1\\53\\InvertDependencies\\435ee1bb\\25016a16\\a9",
  1079. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\30bc7c4f\\3f50fe4f\\90\\InvertDependencies\\435ee1bb\\25016a16\\a9",
  1080. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\435ee1bb\\25016a16\\a9",
  1081. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9",
  1082. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9\\DisplayName",
  1083. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9\\Status",
  1084. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9\\MVID",
  1085. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9\\ConfigString",
  1086. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9\\ConfigMask",
  1087. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9\\ILDependencies",
  1088. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\435ee1bb\\25016a16\\a9\\NIDependencies",
  1089. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index165",
  1090. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index165\\NIUsageMask",
  1091. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index165\\ILUsageMask",
  1092. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\dc778d4\\674fbc54\\a9",
  1093. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\dc778d4\\674fbc54\\a9\\DisplayName",
  1094. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\dc778d4\\674fbc54\\a9\\SIG",
  1095. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\dc778d4\\674fbc54\\a9\\Status",
  1096. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\dc778d4\\674fbc54\\a9\\LastModTime",
  1097. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\dc778d4\\674fbc54\\a9\\InvertDependencies",
  1098. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\dc778d4\\674fbc54\\a9\\InvertDependencies\\3a6c7cbb\\dc778d4\\a8",
  1099. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\3a6c7cbb\\dc778d4\\a8",
  1100. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\3a6c7cbb\\dc778d4\\a8",
  1101. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8",
  1102. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8\\DisplayName",
  1103. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8\\Status",
  1104. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8\\MVID",
  1105. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8\\ConfigString",
  1106. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8\\ConfigMask",
  1107. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8\\ILDependencies",
  1108. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3a6c7cbb\\dc778d4\\a8\\NIDependencies",
  1109. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index166",
  1110. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index166\\NIUsageMask",
  1111. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index166\\ILUsageMask",
  1112. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
  1113. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\ExceptionRecord",
  1114. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  1115. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
  1116. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
  1117. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
  1118. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
  1119. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
  1120. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\InvertDependencies\\57632c41\\29e89c9b\\a7",
  1121. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\57632c41\\29e89c9b\\a7",
  1122. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\57632c41\\29e89c9b\\a7",
  1123. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7",
  1124. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7\\DisplayName",
  1125. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7\\Status",
  1126. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7\\MVID",
  1127. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7\\ConfigString",
  1128. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7\\ConfigMask",
  1129. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7\\ILDependencies",
  1130. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\57632c41\\29e89c9b\\a7\\NIDependencies",
  1131. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index167",
  1132. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index167\\NIUsageMask",
  1133. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index167\\ILUsageMask",
  1134. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
  1135. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7670e6bc\\7f028a6e\\a8",
  1136. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7670e6bc\\7f028a6e\\a8\\DisplayName",
  1137. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7670e6bc\\7f028a6e\\a8\\SIG",
  1138. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7670e6bc\\7f028a6e\\a8\\Status",
  1139. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7670e6bc\\7f028a6e\\a8\\LastModTime",
  1140. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7670e6bc\\7f028a6e\\a8\\InvertDependencies",
  1141. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\7670e6bc\\7f028a6e\\a8\\InvertDependencies\\66a906a3\\7670e6bc\\a6",
  1142. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\66a906a3\\7670e6bc\\a6",
  1143. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\66a906a3\\7670e6bc\\a6",
  1144. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6",
  1145. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6\\DisplayName",
  1146. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6\\Status",
  1147. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6\\MVID",
  1148. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6\\ConfigString",
  1149. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6\\ConfigMask",
  1150. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6\\ILDependencies",
  1151. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\66a906a3\\7670e6bc\\a6\\NIDependencies",
  1152. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index168",
  1153. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index168\\NIUsageMask",
  1154. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index168\\ILUsageMask",
  1155. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
  1156. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\700244f4\\45e7f6bc\\b0\\InvertDependencies\\3762b89a\\700244f4\\a3",
  1157. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\29e89c9b\\75d60fde\\b5\\InvertDependencies\\3762b89a\\700244f4\\a3",
  1158. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\IL\\23a3725a\\3f4e5352\\4f\\InvertDependencies\\3762b89a\\700244f4\\a3",
  1159. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\181938c6\\7950e2c5\\82\\InvertDependencies\\3762b89a\\700244f4\\a3",
  1160. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3",
  1161. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3\\DisplayName",
  1162. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3\\Status",
  1163. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3\\MVID",
  1164. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3\\ConfigString",
  1165. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3\\ConfigMask",
  1166. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3\\ILDependencies",
  1167. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\NI\\3762b89a\\700244f4\\a3\\NIDependencies",
  1168. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index169",
  1169. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index169\\NIUsageMask",
  1170. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_64\\index169\\ILUsageMask"
  1171. ]
  1172.  
  1173. [*] Deleted Registry Keys: [
  1174. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  1175. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  1176. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  1177. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  1178. ]
  1179.  
  1180. [*] DNS Communications: []
  1181.  
  1182. [*] Domains: []
  1183.  
  1184. [*] Network Communication - ICMP: []
  1185.  
  1186. [*] Network Communication - HTTP: [
  1187. {
  1188. "count": 1,
  1189. "body": "",
  1190. "uri": "http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl",
  1191. "user-agent": "Microsoft-CryptoAPI/6.1",
  1192. "method": "GET",
  1193. "host": "crl.microsoft.com",
  1194. "version": "1.1",
  1195. "path": "/pki/crl/products/microsoftrootcert.crl",
  1196. "data": "GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Thu, 07 Mar 2019 06:00:16 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  1197. "port": 80
  1198. },
  1199. {
  1200. "count": 2,
  1201. "body": "",
  1202. "uri": "http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
  1203. "user-agent": "Microsoft-CryptoAPI/6.1",
  1204. "method": "GET",
  1205. "host": "crl.microsoft.com",
  1206. "version": "1.1",
  1207. "path": "/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
  1208. "data": "GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Thu, 14 Feb 2019 06:01:18 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  1209. "port": 80
  1210. }
  1211. ]
  1212.  
  1213. [*] Network Communication - SMTP: []
  1214.  
  1215. [*] Network Communication - Hosts: []
  1216.  
  1217. [*] Network Communication - IRC: []
  1218.  
  1219. [*] Static Analysis: {
  1220. "pe": {
  1221. "peid_signatures": null,
  1222. "imports": [
  1223. {
  1224. "imports": [
  1225. {
  1226. "name": "ReadFile",
  1227. "address": "0x40d008"
  1228. },
  1229. {
  1230. "name": "GetFileSize",
  1231. "address": "0x40d00c"
  1232. },
  1233. {
  1234. "name": "CreateFileA",
  1235. "address": "0x40d010"
  1236. },
  1237. {
  1238. "name": "WriteFile",
  1239. "address": "0x40d014"
  1240. },
  1241. {
  1242. "name": "MapViewOfFile",
  1243. "address": "0x40d018"
  1244. },
  1245. {
  1246. "name": "CreateFileMappingW",
  1247. "address": "0x40d01c"
  1248. },
  1249. {
  1250. "name": "GetProcAddress",
  1251. "address": "0x40d020"
  1252. },
  1253. {
  1254. "name": "LoadLibraryW",
  1255. "address": "0x40d024"
  1256. },
  1257. {
  1258. "name": "GetStringTypeA",
  1259. "address": "0x40d028"
  1260. },
  1261. {
  1262. "name": "LCMapStringW",
  1263. "address": "0x40d02c"
  1264. },
  1265. {
  1266. "name": "LCMapStringA",
  1267. "address": "0x40d030"
  1268. },
  1269. {
  1270. "name": "SetStdHandle",
  1271. "address": "0x40d034"
  1272. },
  1273. {
  1274. "name": "LoadLibraryA",
  1275. "address": "0x40d038"
  1276. },
  1277. {
  1278. "name": "GetOEMCP",
  1279. "address": "0x40d03c"
  1280. },
  1281. {
  1282. "name": "GetACP",
  1283. "address": "0x40d040"
  1284. },
  1285. {
  1286. "name": "GetCPInfo",
  1287. "address": "0x40d044"
  1288. },
  1289. {
  1290. "name": "IsBadCodePtr",
  1291. "address": "0x40d048"
  1292. },
  1293. {
  1294. "name": "GlobalFree",
  1295. "address": "0x40d04c"
  1296. },
  1297. {
  1298. "name": "SetUnhandledExceptionFilter",
  1299. "address": "0x40d050"
  1300. },
  1301. {
  1302. "name": "FlushFileBuffers",
  1303. "address": "0x40d054"
  1304. },
  1305. {
  1306. "name": "SetFilePointer",
  1307. "address": "0x40d058"
  1308. },
  1309. {
  1310. "name": "GetLastError",
  1311. "address": "0x40d05c"
  1312. },
  1313. {
  1314. "name": "GetFileType",
  1315. "address": "0x40d060"
  1316. },
  1317. {
  1318. "name": "GetStdHandle",
  1319. "address": "0x40d064"
  1320. },
  1321. {
  1322. "name": "SetHandleCount",
  1323. "address": "0x40d068"
  1324. },
  1325. {
  1326. "name": "GetEnvironmentStringsW",
  1327. "address": "0x40d06c"
  1328. },
  1329. {
  1330. "name": "GetEnvironmentStrings",
  1331. "address": "0x40d070"
  1332. },
  1333. {
  1334. "name": "WideCharToMultiByte",
  1335. "address": "0x40d074"
  1336. },
  1337. {
  1338. "name": "FreeEnvironmentStringsW",
  1339. "address": "0x40d078"
  1340. },
  1341. {
  1342. "name": "FreeEnvironmentStringsA",
  1343. "address": "0x40d07c"
  1344. },
  1345. {
  1346. "name": "GetModuleFileNameA",
  1347. "address": "0x40d080"
  1348. },
  1349. {
  1350. "name": "UnhandledExceptionFilter",
  1351. "address": "0x40d084"
  1352. },
  1353. {
  1354. "name": "HeapSize",
  1355. "address": "0x40d088"
  1356. },
  1357. {
  1358. "name": "IsBadWritePtr",
  1359. "address": "0x40d08c"
  1360. },
  1361. {
  1362. "name": "HeapReAlloc",
  1363. "address": "0x40d090"
  1364. },
  1365. {
  1366. "name": "VirtualAlloc",
  1367. "address": "0x40d094"
  1368. },
  1369. {
  1370. "name": "VirtualFree",
  1371. "address": "0x40d098"
  1372. },
  1373. {
  1374. "name": "HeapCreate",
  1375. "address": "0x40d09c"
  1376. },
  1377. {
  1378. "name": "IsBadReadPtr",
  1379. "address": "0x40d0a0"
  1380. },
  1381. {
  1382. "name": "CloseHandle",
  1383. "address": "0x40d0a4"
  1384. },
  1385. {
  1386. "name": "HeapDestroy",
  1387. "address": "0x40d0a8"
  1388. },
  1389. {
  1390. "name": "GetCurrentProcess",
  1391. "address": "0x40d0ac"
  1392. },
  1393. {
  1394. "name": "GetStringTypeW",
  1395. "address": "0x40d0b0"
  1396. },
  1397. {
  1398. "name": "MultiByteToWideChar",
  1399. "address": "0x40d0b4"
  1400. },
  1401. {
  1402. "name": "HeapAlloc",
  1403. "address": "0x40d0b8"
  1404. },
  1405. {
  1406. "name": "RtlUnwind",
  1407. "address": "0x40d0bc"
  1408. },
  1409. {
  1410. "name": "GetModuleHandleA",
  1411. "address": "0x40d0c0"
  1412. },
  1413. {
  1414. "name": "GetStartupInfoA",
  1415. "address": "0x40d0c4"
  1416. },
  1417. {
  1418. "name": "GetCommandLineA",
  1419. "address": "0x40d0c8"
  1420. },
  1421. {
  1422. "name": "GetVersion",
  1423. "address": "0x40d0cc"
  1424. },
  1425. {
  1426. "name": "ExitProcess",
  1427. "address": "0x40d0d0"
  1428. },
  1429. {
  1430. "name": "RaiseException",
  1431. "address": "0x40d0d4"
  1432. },
  1433. {
  1434. "name": "HeapFree",
  1435. "address": "0x40d0d8"
  1436. },
  1437. {
  1438. "name": "TerminateProcess",
  1439. "address": "0x40d0dc"
  1440. }
  1441. ],
  1442. "dll": "KERNEL32.dll"
  1443. },
  1444. {
  1445. "imports": [
  1446. {
  1447. "name": "DestroyWindow",
  1448. "address": "0x40d0e4"
  1449. },
  1450. {
  1451. "name": "GetWindowTextA",
  1452. "address": "0x40d0e8"
  1453. },
  1454. {
  1455. "name": "GetDlgItem",
  1456. "address": "0x40d0ec"
  1457. },
  1458. {
  1459. "name": "EnableMenuItem",
  1460. "address": "0x40d0f0"
  1461. },
  1462. {
  1463. "name": "DrawMenuBar",
  1464. "address": "0x40d0f4"
  1465. },
  1466. {
  1467. "name": "SetFocus",
  1468. "address": "0x40d0f8"
  1469. },
  1470. {
  1471. "name": "SendDlgItemMessageA",
  1472. "address": "0x40d0fc"
  1473. },
  1474. {
  1475. "name": "DefMDIChildProcA",
  1476. "address": "0x40d100"
  1477. },
  1478. {
  1479. "name": "GetMenu",
  1480. "address": "0x40d104"
  1481. },
  1482. {
  1483. "name": "GetSubMenu",
  1484. "address": "0x40d108"
  1485. },
  1486. {
  1487. "name": "SendMessageA",
  1488. "address": "0x40d10c"
  1489. },
  1490. {
  1491. "name": "PostMessageA",
  1492. "address": "0x40d110"
  1493. },
  1494. {
  1495. "name": "DefFrameProcA",
  1496. "address": "0x40d114"
  1497. },
  1498. {
  1499. "name": "GetClientRect",
  1500. "address": "0x40d118"
  1501. },
  1502. {
  1503. "name": "GetWindowRect",
  1504. "address": "0x40d11c"
  1505. },
  1506. {
  1507. "name": "MoveWindow",
  1508. "address": "0x40d120"
  1509. },
  1510. {
  1511. "name": "GetWindowTextLengthA",
  1512. "address": "0x40d124"
  1513. },
  1514. {
  1515. "name": "PostQuitMessage",
  1516. "address": "0x40d128"
  1517. },
  1518. {
  1519. "name": "LoadIconA",
  1520. "address": "0x40d12c"
  1521. },
  1522. {
  1523. "name": "LoadCursorA",
  1524. "address": "0x40d130"
  1525. },
  1526. {
  1527. "name": "RegisterClassExA",
  1528. "address": "0x40d134"
  1529. },
  1530. {
  1531. "name": "MessageBoxA",
  1532. "address": "0x40d138"
  1533. },
  1534. {
  1535. "name": "CreateWindowExA",
  1536. "address": "0x40d13c"
  1537. },
  1538. {
  1539. "name": "ShowWindow",
  1540. "address": "0x40d140"
  1541. },
  1542. {
  1543. "name": "UpdateWindow",
  1544. "address": "0x40d144"
  1545. },
  1546. {
  1547. "name": "GetMessageA",
  1548. "address": "0x40d148"
  1549. },
  1550. {
  1551. "name": "TranslateMDISysAccel",
  1552. "address": "0x40d14c"
  1553. },
  1554. {
  1555. "name": "TranslateMessage",
  1556. "address": "0x40d150"
  1557. },
  1558. {
  1559. "name": "DispatchMessageA",
  1560. "address": "0x40d154"
  1561. },
  1562. {
  1563. "name": "SetWindowTextA",
  1564. "address": "0x40d158"
  1565. }
  1566. ],
  1567. "dll": "USER32.dll"
  1568. },
  1569. {
  1570. "imports": [
  1571. {
  1572. "name": "GetStockObject",
  1573. "address": "0x40d000"
  1574. }
  1575. ],
  1576. "dll": "GDI32.dll"
  1577. },
  1578. {
  1579. "imports": [
  1580. {
  1581. "name": "GetOpenFileNameA",
  1582. "address": "0x40d160"
  1583. },
  1584. {
  1585. "name": "GetSaveFileNameA",
  1586. "address": "0x40d164"
  1587. }
  1588. ],
  1589. "dll": "comdlg32.dll"
  1590. }
  1591. ],
  1592. "digital_signers": null,
  1593. "exported_dll_name": null,
  1594. "actual_checksum": "0x00085ff6",
  1595. "overlay": null,
  1596. "imagebase": "0x00400000",
  1597. "reported_checksum": "0x00085ff6",
  1598. "icon_hash": null,
  1599. "entrypoint": "0x00407eb3",
  1600. "timestamp": "2019-06-27 10:13:21",
  1601. "osversion": "4.0",
  1602. "sections": [
  1603. {
  1604. "name": ".text",
  1605. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  1606. "virtual_address": "0x00001000",
  1607. "size_of_data": "0x0000c000",
  1608. "entropy": "6.47",
  1609. "raw_address": "0x00001000",
  1610. "virtual_size": "0x0000be25",
  1611. "characteristics_raw": "0x60000020"
  1612. },
  1613. {
  1614. "name": ".rdata",
  1615. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1616. "virtual_address": "0x0000d000",
  1617. "size_of_data": "0x00002000",
  1618. "entropy": "4.33",
  1619. "raw_address": "0x0000d000",
  1620. "virtual_size": "0x00001e0a",
  1621. "characteristics_raw": "0x40000040"
  1622. },
  1623. {
  1624. "name": ".data",
  1625. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1626. "virtual_address": "0x0000f000",
  1627. "size_of_data": "0x0003b000",
  1628. "entropy": "6.05",
  1629. "raw_address": "0x0000f000",
  1630. "virtual_size": "0x0003bbc8",
  1631. "characteristics_raw": "0xc0000040"
  1632. },
  1633. {
  1634. "name": ".rsrc",
  1635. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1636. "virtual_address": "0x0004b000",
  1637. "size_of_data": "0x0002d000",
  1638. "entropy": "7.39",
  1639. "raw_address": "0x0004a000",
  1640. "virtual_size": "0x0002ca80",
  1641. "characteristics_raw": "0x40000040"
  1642. }
  1643. ],
  1644. "resources": [],
  1645. "dirents": [
  1646. {
  1647. "virtual_address": "0x00000000",
  1648. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1649. "size": "0x00000000"
  1650. },
  1651. {
  1652. "virtual_address": "0x0000e640",
  1653. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1654. "size": "0x00000064"
  1655. },
  1656. {
  1657. "virtual_address": "0x0004b000",
  1658. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1659. "size": "0x0002ca80"
  1660. },
  1661. {
  1662. "virtual_address": "0x00000000",
  1663. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1664. "size": "0x00000000"
  1665. },
  1666. {
  1667. "virtual_address": "0x00000000",
  1668. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1669. "size": "0x00000000"
  1670. },
  1671. {
  1672. "virtual_address": "0x00000000",
  1673. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1674. "size": "0x00000000"
  1675. },
  1676. {
  1677. "virtual_address": "0x00000000",
  1678. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1679. "size": "0x00000000"
  1680. },
  1681. {
  1682. "virtual_address": "0x00000000",
  1683. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1684. "size": "0x00000000"
  1685. },
  1686. {
  1687. "virtual_address": "0x00000000",
  1688. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1689. "size": "0x00000000"
  1690. },
  1691. {
  1692. "virtual_address": "0x00000000",
  1693. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1694. "size": "0x00000000"
  1695. },
  1696. {
  1697. "virtual_address": "0x00000000",
  1698. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1699. "size": "0x00000000"
  1700. },
  1701. {
  1702. "virtual_address": "0x00000000",
  1703. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1704. "size": "0x00000000"
  1705. },
  1706. {
  1707. "virtual_address": "0x0000d000",
  1708. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1709. "size": "0x0000016c"
  1710. },
  1711. {
  1712. "virtual_address": "0x00000000",
  1713. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1714. "size": "0x00000000"
  1715. },
  1716. {
  1717. "virtual_address": "0x00000000",
  1718. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1719. "size": "0x00000000"
  1720. },
  1721. {
  1722. "virtual_address": "0x00000000",
  1723. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1724. "size": "0x00000000"
  1725. }
  1726. ],
  1727. "exports": [],
  1728. "guest_signers": {},
  1729. "imphash": "04db1e6ce3faf3176a7e60a381423311",
  1730. "icon_fuzzy": null,
  1731. "icon": null,
  1732. "pdbpath": null,
  1733. "imported_dll_count": 4,
  1734. "versioninfo": []
  1735. }
  1736. }
  1737.  
  1738. [*] Resolved APIs: [
  1739. "advapi32.dll.CryptAcquireContextA",
  1740. "cryptsp.dll.CryptAcquireContextA",
  1741. "kernel32.dll.VirtualAlloc",
  1742. "ntdll.dll.memcpy",
  1743. "kernel32.dll.GetCurrentProcess",
  1744. "kernel32.dll.CloseHandle",
  1745. "advapi32.dll.OpenProcessToken",
  1746. "advapi32.dll.GetTokenInformation",
  1747. "kernel32.dll.Wow64EnableWow64FsRedirection",
  1748. "advapi32.dll.RegCloseKey",
  1749. "advapi32.dll.RegCreateKeyW",
  1750. "advapi32.dll.RegOpenKeyExW",
  1751. "advapi32.dll.RegSetValueExW",
  1752. "shell32.dll.ShellExecuteA",
  1753. "ole32.dll.OleInitialize",
  1754. "cryptbase.dll.SystemFunction036",
  1755. "uxtheme.dll.ThemeInitApiHook",
  1756. "user32.dll.IsProcessDPIAware",
  1757. "ole32.dll.CreateBindCtx",
  1758. "ole32.dll.CoTaskMemAlloc",
  1759. "propsys.dll.PSCreateMemoryPropertyStore",
  1760. "propsys.dll.PSPropertyBag_WriteDWORD",
  1761. "ole32.dll.CoGetApartmentType",
  1762. "ole32.dll.CoRegisterInitializeSpy",
  1763. "ole32.dll.CoTaskMemFree",
  1764. "comctl32.dll.#236",
  1765. "oleaut32.dll.#6",
  1766. "ole32.dll.CoGetMalloc",
  1767. "propsys.dll.PSPropertyBag_ReadDWORD",
  1768. "propsys.dll.PSPropertyBag_ReadGUID",
  1769. "comctl32.dll.#320",
  1770. "comctl32.dll.#324",
  1771. "comctl32.dll.#323",
  1772. "advapi32.dll.RegEnumKeyW",
  1773. "advapi32.dll.OpenThreadToken",
  1774. "ole32.dll.StringFromGUID2",
  1775. "apphelp.dll.ApphelpCheckShellObject",
  1776. "ole32.dll.CoCreateInstance",
  1777. "urlmon.dll.CreateUri",
  1778. "kernel32.dll.InitializeSRWLock",
  1779. "kernel32.dll.AcquireSRWLockExclusive",
  1780. "kernel32.dll.AcquireSRWLockShared",
  1781. "kernel32.dll.ReleaseSRWLockExclusive",
  1782. "kernel32.dll.ReleaseSRWLockShared",
  1783. "comctl32.dll.#328",
  1784. "comctl32.dll.#334",
  1785. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  1786. "oleaut32.dll.#2",
  1787. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  1788. "shell32.dll.#102",
  1789. "propsys.dll.PSPropertyBag_ReadStrAlloc",
  1790. "comctl32.dll.#332",
  1791. "ole32.dll.CoInitializeEx",
  1792. "comctl32.dll.#386",
  1793. "advapi32.dll.InitializeSecurityDescriptor",
  1794. "advapi32.dll.SetEntriesInAclW",
  1795. "ntmarta.dll.GetMartaExtensionInterface",
  1796. "advapi32.dll.SetSecurityDescriptorDacl",
  1797. "advapi32.dll.IsTextUnicode",
  1798. "comctl32.dll.#338",
  1799. "comctl32.dll.#339",
  1800. "ole32.dll.CoUninitialize",
  1801. "sechost.dll.ConvertSidToStringSidW",
  1802. "profapi.dll.#104",
  1803. "propsys.dll.#430",
  1804. "advapi32.dll.RegGetValueW",
  1805. "ole32.dll.CoTaskMemRealloc",
  1806. "propsys.dll.InitPropVariantFromStringAsVector",
  1807. "propsys.dll.PSCoerceToCanonicalValue",
  1808. "propsys.dll.PropVariantToStringAlloc",
  1809. "ole32.dll.PropVariantClear",
  1810. "ole32.dll.CoAllowSetForegroundWindow",
  1811. "shell32.dll.SHGetFolderPathW",
  1812. "advapi32.dll.SaferGetPolicyInformation",
  1813. "ntdll.dll.RtlDllShutdownInProgress",
  1814. "comctl32.dll.#329",
  1815. "ole32.dll.OleUninitialize",
  1816. "ole32.dll.CoRevokeInitializeSpy",
  1817. "comctl32.dll.#388",
  1818. "oleaut32.dll.#500",
  1819. "advapi32.dll.CryptImportKey",
  1820. "advapi32.dll.CryptEncrypt",
  1821. "cryptsp.dll.CryptImportKey",
  1822. "cryptbase.dll.SystemFunction040",
  1823. "cryptbase.dll.SystemFunction041",
  1824. "cryptsp.dll.CryptEncrypt",
  1825. "advapi32.dll.UnregisterTraceGuids",
  1826. "comctl32.dll.#321",
  1827. "kernel32.dll.SetThreadUILanguage",
  1828. "kernel32.dll.CopyFileExW",
  1829. "kernel32.dll.IsDebuggerPresent",
  1830. "kernel32.dll.SetConsoleInputExeNameW",
  1831. "kernel32.dll.SortGetHandle",
  1832. "kernel32.dll.SortCloseHandle",
  1833. "shell32.dll.#66",
  1834. "comctl32.dll.#385",
  1835. "comctl32.dll.#336",
  1836. "comctl32.dll.#333",
  1837. "linkinfo.dll.IsValidLinkInfo",
  1838. "propsys.dll.#417",
  1839. "propsys.dll.PSGetNameFromPropertyKey",
  1840. "propsys.dll.PSStringFromPropertyKey",
  1841. "propsys.dll.InitVariantFromBuffer",
  1842. "oleaut32.dll.#9",
  1843. "propsys.dll.PropVariantToGUID",
  1844. "linkinfo.dll.CreateLinkInfoW",
  1845. "user32.dll.IsCharAlphaW",
  1846. "user32.dll.CharPrevW",
  1847. "ntshrui.dll.GetNetResourceFromLocalPathW",
  1848. "srvcli.dll.NetShareEnum",
  1849. "cscapi.dll.CscNetApiGetInterface",
  1850. "slc.dll.SLGetWindowsInformationDWORD",
  1851. "shlwapi.dll.PathRemoveFileSpecW",
  1852. "linkinfo.dll.DestroyLinkInfo",
  1853. "propsys.dll.PropVariantToBoolean",
  1854. "cryptsp.dll.CryptAcquireContextW",
  1855. "cryptsp.dll.CryptGenRandom",
  1856. "cryptsp.dll.CryptReleaseContext",
  1857. "advapi32.dll.GetSecurityInfo",
  1858. "advapi32.dll.SetSecurityInfo",
  1859. "advapi32.dll.GetSecurityDescriptorControl",
  1860. "advapi32.dll.RegQueryInfoKeyW",
  1861. "advapi32.dll.RegEnumKeyExW",
  1862. "advapi32.dll.RegEnumValueW",
  1863. "advapi32.dll.RegQueryValueExW",
  1864. "shlwapi.dll.UrlIsW",
  1865. "kernel32.dll.InitializeCriticalSectionAndSpinCount",
  1866. "msvcrt.dll._set_error_mode",
  1867. "msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z",
  1868. "kernel32.dll.FindActCtxSectionStringW",
  1869. "kernel32.dll.GetSystemWindowsDirectoryW",
  1870. "mscoree.dll.GetProcessExecutableHeap",
  1871. "mscorwks.dll.DllGetClassObjectInternal",
  1872. "mscorwks.dll.GetCLRFunction",
  1873. "advapi32.dll.RegisterTraceGuidsW",
  1874. "advapi32.dll.GetTraceLoggerHandle",
  1875. "advapi32.dll.GetTraceEnableLevel",
  1876. "advapi32.dll.GetTraceEnableFlags",
  1877. "advapi32.dll.TraceEvent",
  1878. "mscoree.dll.IEE",
  1879. "mscorwks.dll.IEE",
  1880. "mscoree.dll.GetStartupFlags",
  1881. "mscoree.dll.GetHostConfigurationFile",
  1882. "mscoree.dll.GetCORSystemDirectory",
  1883. "ntdll.dll.RtlVirtualUnwind",
  1884. "kernel32.dll.IsWow64Process",
  1885. "advapi32.dll.AllocateAndInitializeSid",
  1886. "advapi32.dll.InitializeAcl",
  1887. "advapi32.dll.AddAccessAllowedAce",
  1888. "advapi32.dll.FreeSid",
  1889. "kernel32.dll.SetThreadStackGuarantee",
  1890. "kernel32.dll.FlsSetValue",
  1891. "kernel32.dll.FlsGetValue",
  1892. "kernel32.dll.FlsAlloc",
  1893. "kernel32.dll.FlsFree",
  1894. "kernel32.dll.AddVectoredContinueHandler",
  1895. "kernel32.dll.RemoveVectoredContinueHandler",
  1896. "advapi32.dll.ConvertSidToStringSidW",
  1897. "kernel32.dll.FlushProcessWriteBuffers",
  1898. "kernel32.dll.GetWriteWatch",
  1899. "kernel32.dll.ResetWriteWatch",
  1900. "kernel32.dll.CreateMemoryResourceNotification",
  1901. "kernel32.dll.QueryMemoryResourceNotification",
  1902. "kernel32.dll.GlobalMemoryStatusEx",
  1903. "oleaut32.dll.#149",
  1904. "kernel32.dll.GetUserDefaultUILanguage",
  1905. "ole32.dll.CoGetContextToken",
  1906. "kernel32.dll.GetVersionExW",
  1907. "kernel32.dll.GetFullPathNameW",
  1908. "kernel32.dll.SetErrorMode",
  1909. "kernel32.dll.GetFileAttributesExW",
  1910. "version.dll.GetFileVersionInfoSizeW",
  1911. "version.dll.GetFileVersionInfoW",
  1912. "version.dll.VerQueryValueW",
  1913. "kernel32.dll.lstrlen",
  1914. "kernel32.dll.lstrlenW",
  1915. "mscoree.dll.ND_RI2",
  1916. "kernel32.dll.lstrcpy",
  1917. "kernel32.dll.lstrcpyW",
  1918. "version.dll.VerLanguageNameW",
  1919. "kernel32.dll.GetCurrentProcessId",
  1920. "advapi32.dll.LookupPrivilegeValueW",
  1921. "advapi32.dll.AdjustTokenPrivileges",
  1922. "kernel32.dll.OpenProcess",
  1923. "psapi.dll.EnumProcessModules",
  1924. "psapi.dll.GetModuleInformation",
  1925. "psapi.dll.GetModuleBaseNameW",
  1926. "psapi.dll.GetModuleFileNameExW",
  1927. "kernel32.dll.GetExitCodeProcess",
  1928. "ntdll.dll.NtQuerySystemInformation",
  1929. "user32.dll.EnumWindows",
  1930. "user32.dll.GetWindowThreadProcessId",
  1931. "kernel32.dll.WerSetFlags",
  1932. "kernel32.dll.SetThreadPreferredUILanguages",
  1933. "kernel32.dll.GetThreadPreferredUILanguages",
  1934. "kernel32.dll.GetUserDefaultLocaleName",
  1935. "kernel32.dll.GetEnvironmentVariableW",
  1936. "advapi32.dll.CryptReleaseContext",
  1937. "advapi32.dll.CryptCreateHash",
  1938. "advapi32.dll.CryptDestroyHash",
  1939. "advapi32.dll.CryptHashData",
  1940. "advapi32.dll.CryptGetHashParam",
  1941. "advapi32.dll.CryptExportKey",
  1942. "advapi32.dll.CryptGenKey",
  1943. "advapi32.dll.CryptGetKeyParam",
  1944. "advapi32.dll.CryptDestroyKey",
  1945. "advapi32.dll.CryptVerifySignatureA",
  1946. "advapi32.dll.CryptSignHashA",
  1947. "advapi32.dll.CryptGetProvParam",
  1948. "advapi32.dll.CryptGetUserKey",
  1949. "advapi32.dll.CryptEnumProvidersA",
  1950. "cryptsp.dll.CryptHashData",
  1951. "cryptsp.dll.CryptGetHashParam",
  1952. "cryptsp.dll.CryptDestroyHash",
  1953. "cryptsp.dll.CryptDestroyKey",
  1954. "mscoree.dll.GetTokenForVTableEntry",
  1955. "mscoree.dll.SetTargetForVTableEntry",
  1956. "mscoree.dll.GetTargetForVTableEntry",
  1957. "culture.dll.ConvertLangIdToCultureName",
  1958. "ole32.dll.CoCreateGuid",
  1959. "kernel32.dll.CreateFileW",
  1960. "kernel32.dll.GetConsoleScreenBufferInfo",
  1961. "kernel32.dll.LocalFree",
  1962. "kernel32.dll.LocalAlloc",
  1963. "mscoree.dll.ND_RI4",
  1964. "advapi32.dll.DuplicateTokenEx",
  1965. "advapi32.dll.CheckTokenMembership",
  1966. "kernel32.dll.GetConsoleTitleW",
  1967. "mscorjit.dll.getJit",
  1968. "kernel32.dll.SetConsoleTitleW",
  1969. "kernel32.dll.SetConsoleCtrlHandler",
  1970. "kernel32.dll.CreateEventW",
  1971. "ntdll.dll.WinSqmIsOptedIn",
  1972. "kernel32.dll.ExpandEnvironmentStringsW",
  1973. "shfolder.dll.SHGetFolderPathW",
  1974. "kernel32.dll.SetEnvironmentVariableW",
  1975. "kernel32.dll.GetACP",
  1976. "kernel32.dll.UnmapViewOfFile",
  1977. "kernel32.dll.GetFileType",
  1978. "kernel32.dll.ReadFile",
  1979. "kernel32.dll.GetSystemInfo",
  1980. "kernel32.dll.VirtualQuery",
  1981. "secur32.dll.GetUserNameExW",
  1982. "advapi32.dll.GetUserNameW",
  1983. "kernel32.dll.ReleaseMutex",
  1984. "advapi32.dll.RegisterEventSourceW",
  1985. "advapi32.dll.DeregisterEventSource",
  1986. "advapi32.dll.ReportEventW",
  1987. "kernel32.dll.GetLogicalDrives",
  1988. "kernel32.dll.GetDriveTypeW",
  1989. "kernel32.dll.GetVolumeInformationW",
  1990. "kernel32.dll.GetCurrentDirectoryW",
  1991. "kernel32.dll.GetLastError",
  1992. "kernel32.dll.GetStdHandle",
  1993. "kernel32.dll.GetConsoleMode",
  1994. "kernel32.dll.SetEvent",
  1995. "kernel32.dll.FindFirstFileW",
  1996. "kernel32.dll.FindClose",
  1997. "mscoree.dll.DllGetClassObject",
  1998. "diasymreader.dll.DllGetClassObjectInternal",
  1999. "kernel32.dll.GetConsoleOutputCP",
  2000. "gdi32.dll.TranslateCharsetInfo",
  2001. "kernel32.dll.SetConsoleTextAttribute",
  2002. "kernel32.dll.WriteConsoleW",
  2003. "mscoree.dll.CorExitProcess",
  2004. "mscorwks.dll.CorExitProcess",
  2005. "mscorwks.dll._CorDllMain",
  2006. "kernel32.dll.CreateActCtxW",
  2007. "kernel32.dll.AddRefActCtx",
  2008. "kernel32.dll.ReleaseActCtx",
  2009. "kernel32.dll.ActivateActCtx",
  2010. "kernel32.dll.DeactivateActCtx",
  2011. "kernel32.dll.GetCurrentActCtx",
  2012. "kernel32.dll.QueryActCtxW",
  2013. "netutils.dll.NetApiBufferFree",
  2014. "crypt32.dll.CryptProtectData",
  2015. "kernel32.dll.IsProcessorFeaturePresent",
  2016. "ntdll.dll.RtlUnwind",
  2017. "mscoree.dll._CorExeMain",
  2018. "mscoree.dll._CorImageUnloading",
  2019. "mscoree.dll._CorValidateImage",
  2020. "cryptsp.dll.CryptExportKey",
  2021. "cryptsp.dll.CryptCreateHash",
  2022. "kernel32.dll.SwitchToThread",
  2023. "sechost.dll.LookupAccountNameLocalW",
  2024. "advapi32.dll.LookupAccountSidW",
  2025. "sechost.dll.LookupAccountSidLocalW",
  2026. "sspicli.dll.GetUserNameExW",
  2027. "shlwapi.dll.PathFindFileNameW",
  2028. "mscorsvc.dll.CorGetSvc",
  2029. "advapi32.dll.StartServiceCtrlDispatcherW",
  2030. "kernel32.dll.VerSetConditionMask",
  2031. "kernel32.dll.VerifyVersionInfoW",
  2032. "advapi32.dll.RegisterServiceCtrlHandlerExW",
  2033. "advapi32.dll.SetServiceStatus",
  2034. "advapi32.dll.OpenSCManagerW",
  2035. "advapi32.dll.OpenServiceW",
  2036. "advapi32.dll.ChangeServiceConfigW",
  2037. "advapi32.dll.CloseServiceHandle",
  2038. "mscoree.dll.CorIsLatestSvc",
  2039. "msidle.dll.#8",
  2040. "wtsapi32.dll.WTSQuerySessionInformationW",
  2041. "wtsapi32.dll.WTSFreeMemory",
  2042. "wtsapi32.dll.WTSEnumerateSessionsW",
  2043. "winsta.dll.WinStationEnumerateW",
  2044. "advapi32.dll.CreateWellKnownSid",
  2045. "rpcrt4.dll.RpcStringBindingComposeW",
  2046. "rpcrt4.dll.RpcBindingFromStringBindingW",
  2047. "rpcrt4.dll.RpcStringFreeW",
  2048. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  2049. "rpcrt4.dll.NdrClientCall3",
  2050. "rpcrt4.dll.I_RpcExceptionFilter",
  2051. "rpcrt4.dll.RpcBindingFree",
  2052. "winsta.dll.WinStationFreeMemory",
  2053. "powrprof.dll.CallNtPowerInformation",
  2054. "advapi32.dll.QueryServiceConfig2W",
  2055. "advapi32.dll.CreateRestrictedToken",
  2056. "mscoree.dll.GetCORRootDirectory",
  2057. "advapi32.dll.CreateProcessAsUserW",
  2058. "oleaut32.dll.BSTR_UserSize",
  2059. "oleaut32.dll.BSTR_UserMarshal",
  2060. "oleaut32.dll.BSTR_UserUnmarshal",
  2061. "oleaut32.dll.BSTR_UserFree",
  2062. "oleaut32.dll.VARIANT_UserSize",
  2063. "oleaut32.dll.VARIANT_UserMarshal",
  2064. "oleaut32.dll.VARIANT_UserUnmarshal",
  2065. "oleaut32.dll.VARIANT_UserFree",
  2066. "oleaut32.dll.LPSAFEARRAY_UserSize",
  2067. "oleaut32.dll.LPSAFEARRAY_UserMarshal",
  2068. "oleaut32.dll.LPSAFEARRAY_UserUnmarshal",
  2069. "oleaut32.dll.LPSAFEARRAY_UserFree",
  2070. "ole32.dll.CoInitializeSecurity",
  2071. "fntcache.dll.ServiceMain",
  2072. "fntcache.dll.SvchostPushServiceGlobals",
  2073. "ssdpsrv.dll.ServiceMain",
  2074. "ssdpsrv.dll.SvchostPushServiceGlobals",
  2075. "firewallapi.dll.IcfChangeNotificationCreate",
  2076. "firewallapi.dll.IcfChangeNotificationDestroy",
  2077. "firewallapi.dll.IcfAddrChangeNotificationCreate",
  2078. "advapi32.dll.RegCreateKeyExW",
  2079. "advapi32.dll.RegNotifyChangeKeyValue",
  2080. "iphlpapi.dll.GetAdaptersAddresses",
  2081. "mswsock.dll.WSPStartup",
  2082. "wship6.dll.WSHOpenSocket",
  2083. "wship6.dll.WSHOpenSocket2",
  2084. "wship6.dll.WSHJoinLeaf",
  2085. "wship6.dll.WSHNotify",
  2086. "wship6.dll.WSHGetSocketInformation",
  2087. "wship6.dll.WSHSetSocketInformation",
  2088. "wship6.dll.WSHGetSockaddrType",
  2089. "wship6.dll.WSHGetWildcardSockaddr",
  2090. "wship6.dll.WSHAddressToString",
  2091. "wship6.dll.WSHStringToAddress",
  2092. "wship6.dll.WSHIoctl",
  2093. "wshtcpip.dll.WSHOpenSocket",
  2094. "wshtcpip.dll.WSHOpenSocket2",
  2095. "wshtcpip.dll.WSHJoinLeaf",
  2096. "wshtcpip.dll.WSHNotify",
  2097. "wshtcpip.dll.WSHGetSocketInformation",
  2098. "wshtcpip.dll.WSHSetSocketInformation",
  2099. "wshtcpip.dll.WSHGetSockaddrType",
  2100. "wshtcpip.dll.WSHGetWildcardSockaddr",
  2101. "wshtcpip.dll.WSHGetBroadcastSockaddr",
  2102. "wshtcpip.dll.WSHAddressToString",
  2103. "wshtcpip.dll.WSHStringToAddress",
  2104. "wshtcpip.dll.WSHIoctl",
  2105. "iphlpapi.dll.ConvertInterfaceGuidToLuid",
  2106. "secur32.dll.InitSecurityInterfaceW",
  2107. "cryptsp.dll.SystemFunction035",
  2108. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  2109. "iphlpapi.dll.NotifyUnicastIpAddressChange",
  2110. "rpcrt4.dll.RpcStringBindingComposeA",
  2111. "rpcrt4.dll.RpcBindingFromStringBindingA",
  2112. "rpcrt4.dll.RpcStringFreeA",
  2113. "bcryptprimitives.dll.GetHashInterface",
  2114. "crypt32.dll.I_CertSrvProtectFunction",
  2115. "advapi32.dll.SetThreadToken",
  2116. "advapi32.dll.GetLengthSid",
  2117. "advapi32.dll.CopySid",
  2118. "advapi32.dll.GetSecurityDescriptorSacl",
  2119. "advapi32.dll.EventWrite",
  2120. "advapi32.dll.EventRegister",
  2121. "advapi32.dll.EventUnregister",
  2122. "advapi32.dll.EventEnabled",
  2123. "ntdll.dll.ZwQueryInformationProcess",
  2124. "ntdll.dll.NtQuerySection",
  2125. "ntdll.dll.LdrProcessRelocationBlock",
  2126. "sppwinob.dll.SppPluginInitialize",
  2127. "sppwinob.dll.SppPluginShutdown",
  2128. "sppwinob.dll.SppPluginCreateInstance",
  2129. "sppwinob.dll.SppPluginCanUnloadNow",
  2130. "sppobjs.dll.SppPluginInitialize",
  2131. "sppobjs.dll.SppPluginShutdown",
  2132. "sppobjs.dll.SppPluginCreateInstance",
  2133. "sppobjs.dll.SppPluginCanUnloadNow",
  2134. "advapi32.dll.NotifyServiceStatusChangeW",
  2135. "setupapi.dll.SetupDiGetClassDevsW",
  2136. "setupapi.dll.SetupDiEnumDeviceInfo",
  2137. "setupapi.dll.SetupDiGetDeviceRegistryPropertyW",
  2138. "setupapi.dll.SetupDiDestroyDeviceInfoList",
  2139. "wintrust.dll.WinVerifyTrust",
  2140. "setupapi.dll.SetupDiEnumDeviceInterfaces",
  2141. "setupapi.dll.SetupDiGetDeviceInterfaceDetailW",
  2142. "kernel32.dll.GetSystemFirmwareTable",
  2143. "sechost.dll.OpenSCManagerW",
  2144. "sechost.dll.OpenServiceW",
  2145. "sechost.dll.QueryServiceStatus",
  2146. "sechost.dll.QueryServiceConfigW",
  2147. "sechost.dll.CloseServiceHandle",
  2148. "advapi32.dll.IsValidSid",
  2149. "shell32.dll.SHGetFolderPathEx",
  2150. "comctl32.dll.DPA_Create",
  2151. "comctl32.dll.DPA_Search",
  2152. "comctl32.dll.DPA_InsertPtr",
  2153. "wscapi.dll.WscGetSecurityProviderHealth",
  2154. "ntdll.dll.EtwUnregisterTraceGuids",
  2155. "shlwapi.dll.#487",
  2156. "comctl32.dll.DPA_DeletePtr",
  2157. "comctl32.dll.DPA_GetPtr",
  2158. "comctl32.dll.#331",
  2159. "comctl32.dll.LoadIconMetric",
  2160. "sechost.dll.QueryServiceStatusEx",
  2161. "wkscli.dll.NetGetJoinInformation",
  2162. "ole32.dll.CLSIDFromOle1Class",
  2163. "clbcatq.dll.GetCatalogObject",
  2164. "clbcatq.dll.GetCatalogObject2",
  2165. "ole32.dll.NdrOleInitializeExtension",
  2166. "ole32.dll.CoGetClassObject",
  2167. "ole32.dll.CoGetMarshalSizeMax",
  2168. "ole32.dll.CoMarshalInterface",
  2169. "ole32.dll.CoUnmarshalInterface",
  2170. "ole32.dll.StringFromIID",
  2171. "ole32.dll.CoGetPSClsid",
  2172. "ole32.dll.CoReleaseMarshalData",
  2173. "ole32.dll.DcomChannelSetHResult",
  2174. "oleaut32.dll.DllGetClassObject",
  2175. "oleaut32.dll.DllCanUnloadNow",
  2176. "sxs.dll.SxsOleAut32MapIIDToProxyStubCLSID",
  2177. "advapi32.dll.RegQueryValueW",
  2178. "sxs.dll.SxsOleAut32MapIIDToTLBPath",
  2179. "advapi32.dll.RegOpenKeyW",
  2180. "sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid",
  2181. "sxs.dll.SxsOleAut32RedirectTypeLibrary",
  2182. "mscorwks.dll.NGenCreateNGenWorker",
  2183. "oleaut32.dll.#7",
  2184. "oleaut32.dll.#411",
  2185. "oleaut32.dll.#26",
  2186. "mscoree.dll.GetMetaDataInternalInterface",
  2187. "mscorwks.dll.GetMetaDataInternalInterface",
  2188. "cryptsp.dll.CryptVerifySignatureA",
  2189. "oleaut32.dll.#19",
  2190. "oleaut32.dll.#23",
  2191. "oleaut32.dll.#24",
  2192. "ole32.dll.CoWaitForMultipleHandles",
  2193. "kernel32.dll.LocaleNameToLCID",
  2194. "kernel32.dll.GetLocaleInfoEx",
  2195. "kernel32.dll.LCIDToLocaleName",
  2196. "kernel32.dll.GetSystemDefaultLocaleName",
  2197. "fastprox.dll.DllGetClassObject",
  2198. "fastprox.dll.DllCanUnloadNow",
  2199. "oleaut32.dll.#283",
  2200. "oleaut32.dll.#284",
  2201. "kernel32.dll.RegOpenKeyExW",
  2202. "kernel32.dll.RegQueryValueExW",
  2203. "kernel32.dll.RegCloseKey",
  2204. "oleaut32.dll.#289",
  2205. "oleaut32.dll.#287",
  2206. "oleaut32.dll.#288",
  2207. "oleaut32.dll.#290",
  2208. "oleaut32.dll.#285",
  2209. "winbrand.dll.BrandingLoadString",
  2210. "security.dll.InitSecurityInterfaceW",
  2211. "schannel.dll.SpUserModeInitialize",
  2212. "user32.dll.GetSystemMetrics",
  2213. "ntdll.dll.RtlInitUnicodeString",
  2214. "ntdll.dll.RtlFreeUnicodeString",
  2215. "ntdll.dll.NtSetSystemEnvironmentValue",
  2216. "ntdll.dll.NtQuerySystemEnvironmentValue",
  2217. "ntdll.dll.NtCreateFile",
  2218. "ntdll.dll.NtQueryDirectoryObject",
  2219. "ntdll.dll.NtQueryObject",
  2220. "ntdll.dll.NtOpenDirectoryObject",
  2221. "ntdll.dll.NtQueryInformationProcess",
  2222. "ntdll.dll.NtQueryInformationToken",
  2223. "ntdll.dll.NtOpenFile",
  2224. "ntdll.dll.NtClose",
  2225. "ntdll.dll.NtFsControlFile",
  2226. "ntdll.dll.NtQueryVolumeInformationFile",
  2227. "oleaut32.dll.#286",
  2228. "netapi32.dll.NetGroupEnum",
  2229. "netapi32.dll.NetGroupGetInfo",
  2230. "netapi32.dll.NetGroupSetInfo",
  2231. "netapi32.dll.NetLocalGroupGetInfo",
  2232. "netapi32.dll.NetLocalGroupSetInfo",
  2233. "netapi32.dll.NetGroupGetUsers",
  2234. "netapi32.dll.NetLocalGroupGetMembers",
  2235. "netapi32.dll.NetLocalGroupEnum",
  2236. "netapi32.dll.NetShareEnum",
  2237. "netapi32.dll.NetShareGetInfo",
  2238. "netapi32.dll.NetShareAdd",
  2239. "netapi32.dll.NetShareEnumSticky",
  2240. "netapi32.dll.NetShareSetInfo",
  2241. "netapi32.dll.NetShareDel",
  2242. "netapi32.dll.NetShareDelSticky",
  2243. "netapi32.dll.NetShareCheck",
  2244. "netapi32.dll.NetUserEnum",
  2245. "netapi32.dll.NetUserGetInfo",
  2246. "netapi32.dll.NetUserSetInfo",
  2247. "netapi32.dll.NetApiBufferFree",
  2248. "netapi32.dll.NetQueryDisplayInformation",
  2249. "netapi32.dll.NetServerSetInfo",
  2250. "netapi32.dll.NetServerGetInfo",
  2251. "netapi32.dll.NetGetDCName",
  2252. "netapi32.dll.NetWkstaGetInfo",
  2253. "netapi32.dll.NetGetAnyDCName",
  2254. "netapi32.dll.NetServerEnum",
  2255. "netapi32.dll.NetUserModalsGet",
  2256. "netapi32.dll.NetScheduleJobAdd",
  2257. "netapi32.dll.NetScheduleJobDel",
  2258. "netapi32.dll.NetScheduleJobEnum",
  2259. "netapi32.dll.NetScheduleJobGetInfo",
  2260. "netapi32.dll.NetUseGetInfo",
  2261. "netapi32.dll.NetEnumerateTrustedDomains",
  2262. "netapi32.dll.DsGetDcNameW",
  2263. "netapi32.dll.DsRoleGetPrimaryDomainInformation",
  2264. "netapi32.dll.DsRoleFreeMemory",
  2265. "netapi32.dll.NetRenameMachineInDomain",
  2266. "netapi32.dll.NetJoinDomain",
  2267. "netapi32.dll.NetUnjoinDomain",
  2268. "wkscli.dll.NetWkstaGetInfo",
  2269. "kernel32.dll.GetDiskFreeSpaceExW",
  2270. "kernel32.dll.GetVolumePathNameW",
  2271. "kernel32.dll.CreateToolhelp32Snapshot",
  2272. "kernel32.dll.Thread32First",
  2273. "kernel32.dll.Thread32Next",
  2274. "kernel32.dll.Process32First",
  2275. "kernel32.dll.Process32Next",
  2276. "kernel32.dll.Module32First",
  2277. "kernel32.dll.Module32Next",
  2278. "kernel32.dll.Heap32ListFirst",
  2279. "kernel32.dll.GetSystemDefaultUILanguage",
  2280. "oleaut32.dll.#8",
  2281. "oleaut32.dll.#15",
  2282. "wmi.dll.WmiQueryAllDataW",
  2283. "wmi.dll.WmiQuerySingleInstanceW",
  2284. "wmi.dll.WmiSetSingleItemW",
  2285. "wmi.dll.WmiSetSingleInstanceW",
  2286. "wmi.dll.WmiExecuteMethodW",
  2287. "wmi.dll.WmiNotificationRegistrationW",
  2288. "wmi.dll.WmiMofEnumerateResourcesW",
  2289. "wmi.dll.WmiFileHandleToInstanceNameW",
  2290. "wmi.dll.WmiDevInstToInstanceNameW",
  2291. "wmi.dll.WmiQueryGuidInformation",
  2292. "wmi.dll.WmiOpenBlock",
  2293. "wmi.dll.WmiCloseBlock",
  2294. "wmi.dll.WmiFreeBuffer",
  2295. "wmi.dll.WmiEnumerateGuids",
  2296. "oleaut32.dll.#150",
  2297. "winsta.dll.WinStationQueryInformationW",
  2298. "advapi32.dll.LookupAccountNameW",
  2299. "devobj.dll.DevObjCreateDeviceInfoList",
  2300. "devobj.dll.DevObjGetClassDevs",
  2301. "devobj.dll.DevObjEnumDeviceInfo",
  2302. "devobj.dll.DevObjDestroyDeviceInfoList",
  2303. "powrprof.dll.PowerDeterminePlatformRole",
  2304. "oleaut32.dll.#16",
  2305. "ole32.dll.StringFromCLSID",
  2306. "ole32.dll.IIDFromString",
  2307. "advapi32.dll.RegDeleteKeyExW",
  2308. "kernel32.dll.ProcessIdToSessionId",
  2309. "imm32.dll.ImmCreateContext",
  2310. "imm32.dll.ImmDestroyContext",
  2311. "imm32.dll.ImmNotifyIME",
  2312. "imm32.dll.ImmAssociateContext",
  2313. "imm32.dll.ImmReleaseContext",
  2314. "imm32.dll.ImmGetContext",
  2315. "imm32.dll.ImmGetCompositionStringA",
  2316. "imm32.dll.ImmSetCompositionStringA",
  2317. "imm32.dll.ImmGetCompositionStringW",
  2318. "imm32.dll.ImmSetCompositionStringW",
  2319. "imm32.dll.ImmSetCandidateWindow",
  2320. "mscorsec.dll.GetPublisher",
  2321. "mscoree.dll.CoInitializeEE",
  2322. "mscorwks.dll.CoInitializeEE",
  2323. "wintrust.dll.WintrustCertificateTrust",
  2324. "mscorsec.dll.CORPolicyEE",
  2325. "wintrust.dll.SoftpubInitialize",
  2326. "wintrust.dll.SoftpubLoadMessage",
  2327. "wintrust.dll.SoftpubLoadSignature",
  2328. "wintrust.dll.SoftpubCheckCert",
  2329. "wintrust.dll.CryptSIPPutSignedDataMsg",
  2330. "wintrust.dll.CryptSIPGetSignedDataMsg",
  2331. "imagehlp.dll.ImageGetCertificateData",
  2332. "user32.dll.LoadStringW",
  2333. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  2334. "ncrypt.dll.BCryptGetProperty",
  2335. "ncrypt.dll.BCryptCreateHash",
  2336. "ncrypt.dll.BCryptHashData",
  2337. "wintrust.dll.CryptSIPVerifyIndirectData",
  2338. "bcrypt.dll.BCryptOpenAlgorithmProvider",
  2339. "bcrypt.dll.BCryptGetProperty",
  2340. "bcrypt.dll.BCryptCreateHash",
  2341. "bcrypt.dll.BCryptHashData",
  2342. "bcrypt.dll.BCryptFinishHash",
  2343. "bcrypt.dll.BCryptDestroyHash",
  2344. "bcrypt.dll.BCryptCloseAlgorithmProvider",
  2345. "ncrypt.dll.BCryptFinishHash",
  2346. "cryptsp.dll.CryptSetHashParam",
  2347. "ncrypt.dll.BCryptDestroyHash",
  2348. "userenv.dll.GetUserProfileDirectoryW",
  2349. "sechost.dll.ConvertStringSidToSidW",
  2350. "userenv.dll.RegisterGPNotification",
  2351. "gpapi.dll.RegisterGPNotificationInternal",
  2352. "cryptnet.dll.CertDllVerifyRevocation",
  2353. "sensapi.dll.IsNetworkAlive",
  2354. "winhttp.dll.WinHttpOpen",
  2355. "winhttp.dll.WinHttpSetTimeouts",
  2356. "winhttp.dll.WinHttpSetOption",
  2357. "winhttp.dll.WinHttpCrackUrl",
  2358. "shlwapi.dll.StrCmpNW",
  2359. "winhttp.dll.WinHttpConnect",
  2360. "winhttp.dll.WinHttpOpenRequest",
  2361. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  2362. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  2363. "advapi32.dll.RegDeleteTreeA",
  2364. "advapi32.dll.RegDeleteTreeW",
  2365. "nsi.dll.NsiAllocateAndGetTable",
  2366. "cfgmgr32.dll.CM_Open_Class_Key_ExW",
  2367. "iphlpapi.dll.GetIfEntry2",
  2368. "iphlpapi.dll.GetIpForwardTable2",
  2369. "iphlpapi.dll.GetIpNetEntry2",
  2370. "iphlpapi.dll.FreeMibTable",
  2371. "nsi.dll.NsiFreeTable",
  2372. "winhttp.dll.WinHttpGetProxyForUrl",
  2373. "winhttp.dll.WinHttpTimeFromSystemTime",
  2374. "winhttp.dll.WinHttpSendRequest",
  2375. "ws2_32.dll.GetAddrInfoW",
  2376. "ws2_32.dll.WSASocketW",
  2377. "ws2_32.dll.#2",
  2378. "ws2_32.dll.#21",
  2379. "ws2_32.dll.#9",
  2380. "ws2_32.dll.WSAIoctl",
  2381. "ws2_32.dll.FreeAddrInfoW",
  2382. "ws2_32.dll.#6",
  2383. "ws2_32.dll.#5",
  2384. "ws2_32.dll.WSARecv",
  2385. "ws2_32.dll.WSASend",
  2386. "winhttp.dll.WinHttpReceiveResponse",
  2387. "winhttp.dll.WinHttpQueryHeaders",
  2388. "winhttp.dll.WinHttpQueryDataAvailable",
  2389. "winhttp.dll.WinHttpReadData",
  2390. "winhttp.dll.WinHttpCloseHandle",
  2391. "cryptnet.dll.I_CryptNetGetConnectivity",
  2392. "cryptnet.dll.CryptRetrieveObjectByUrlW",
  2393. "setupapi.dll.SetupIterateCabinetW",
  2394. "cabinet.dll.#20",
  2395. "cabinet.dll.#22",
  2396. "devrtl.dll.DevRtlGetThreadLogToken",
  2397. "cabinet.dll.#23",
  2398. "sechost.dll.QueryServiceConfigA",
  2399. "rpcrt4.dll.RpcEpResolveBinding",
  2400. "cryptnet.dll.I_CryptNetSetUrlCachePreFetchInfo",
  2401. "cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo",
  2402. "wintrust.dll.SoftpubAuthenticode",
  2403. "wintrust.dll.SoftpubCleanup",
  2404. "advapi32.dll.SaferiSearchMatchingHashRules",
  2405. "mscoree.dll.CoUninitializeEE",
  2406. "mscorwks.dll.CoUninitializeEE",
  2407. "wersvc.dll.ServiceMain",
  2408. "wersvc.dll.SvchostPushServiceGlobals",
  2409. "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
  2410. "faultrep.dll.WerpInitiateCrashReporting",
  2411. "wer.dll.WerpCreateMachineStore",
  2412. "userenv.dll.CreateEnvironmentBlock",
  2413. "userenv.dll.DestroyEnvironmentBlock",
  2414. "wer.dll.WerpSvcReportFromMachineQueue",
  2415. "advapi32.dll.DuplicateToken",
  2416. "wtsapi32.dll.WTSQueryUserToken",
  2417. "advapi32.dll.ImpersonateLoggedOnUser",
  2418. "advapi32.dll.RevertToSelf",
  2419. "imm32.dll.ImmDisableIME",
  2420. "wer.dll.WerpCreateIntegratorReportId",
  2421. "wer.dll.WerReportCreate",
  2422. "wer.dll.WerpSetIntegratorReportId",
  2423. "wer.dll.WerReportSetParameter",
  2424. "dbgeng.dll.DebugCreate",
  2425. "ntdll.dll.CsrGetProcessId",
  2426. "ntdll.dll.DbgBreakPoint",
  2427. "ntdll.dll.DbgPrint",
  2428. "ntdll.dll.DbgPrompt",
  2429. "ntdll.dll.DbgUiConvertStateChangeStructure",
  2430. "ntdll.dll.DbgUiGetThreadDebugObject",
  2431. "ntdll.dll.DbgUiIssueRemoteBreakin",
  2432. "ntdll.dll.DbgUiSetThreadDebugObject",
  2433. "ntdll.dll.NtAllocateVirtualMemory",
  2434. "ntdll.dll.NtCreateDebugObject",
  2435. "ntdll.dll.NtDebugActiveProcess",
  2436. "ntdll.dll.NtDebugContinue",
  2437. "ntdll.dll.NtFreeVirtualMemory",
  2438. "ntdll.dll.NtOpenProcess",
  2439. "ntdll.dll.NtOpenThread",
  2440. "ntdll.dll.NtQueryInformationThread",
  2441. "ntdll.dll.NtQueryMutant",
  2442. "ntdll.dll.NtRemoveProcessDebug",
  2443. "ntdll.dll.NtResumeThread",
  2444. "ntdll.dll.NtSetInformationDebugObject",
  2445. "ntdll.dll.NtSetInformationProcess",
  2446. "ntdll.dll.NtSystemDebugControl",
  2447. "ntdll.dll.NtWaitForDebugEvent",
  2448. "ntdll.dll.RtlAnsiStringToUnicodeString",
  2449. "ntdll.dll.RtlCreateProcessParameters",
  2450. "ntdll.dll.RtlCreateUserProcess",
  2451. "ntdll.dll.RtlDestroyProcessParameters",
  2452. "ntdll.dll.RtlDosPathNameToNtPathName_U",
  2453. "ntdll.dll.RtlFindMessage",
  2454. "ntdll.dll.RtlFreeHeap",
  2455. "ntdll.dll.RtlGetFunctionTableListHead",
  2456. "ntdll.dll.RtlGetUnloadEventTrace",
  2457. "ntdll.dll.RtlGetUnloadEventTraceEx",
  2458. "ntdll.dll.RtlInitAnsiString",
  2459. "ntdll.dll.RtlTryEnterCriticalSection",
  2460. "ntdll.dll.RtlUnicodeStringToAnsiString",
  2461. "ntdll.dll.NtOpenProcessToken",
  2462. "ntdll.dll.NtOpenThreadToken",
  2463. "kernel32.dll.CloseProfileUserMapping",
  2464. "kernel32.dll.DebugActiveProcessStop",
  2465. "kernel32.dll.DebugBreak",
  2466. "kernel32.dll.DebugBreakProcess",
  2467. "kernel32.dll.DebugSetProcessKillOnExit",
  2468. "kernel32.dll.Module32FirstW",
  2469. "kernel32.dll.Module32NextW",
  2470. "kernel32.dll.OpenThread",
  2471. "kernel32.dll.Process32FirstW",
  2472. "kernel32.dll.Process32NextW",
  2473. "kernel32.dll.SetProcessShutdownParameters",
  2474. "kernel32.dll.GetTimeZoneInformation",
  2475. "kernel32.dll.DuplicateHandle",
  2476. "kernel32.dll.Wow64GetThreadSelectorEntry",
  2477. "advapi32.dll.ControlService",
  2478. "advapi32.dll.CreateServiceA",
  2479. "advapi32.dll.CreateServiceW",
  2480. "advapi32.dll.DeleteService",
  2481. "advapi32.dll.EnumServicesStatusExA",
  2482. "advapi32.dll.EnumServicesStatusExW",
  2483. "advapi32.dll.GetEventLogInformation",
  2484. "advapi32.dll.OpenSCManagerA",
  2485. "advapi32.dll.OpenServiceA",
  2486. "advapi32.dll.StartServiceA",
  2487. "advapi32.dll.StartServiceW",
  2488. "advapi32.dll.GetSidSubAuthority",
  2489. "advapi32.dll.GetSidSubAuthorityCount",
  2490. "version.dll.GetFileVersionInfoSizeExW",
  2491. "version.dll.GetFileVersionInfoExW",
  2492. "dbghelp.dll.WinDbgExtensionDllInit",
  2493. "dbghelp.dll.ExtensionApiVersion",
  2494. "wer.dll.WerpSetDynamicParameter",
  2495. "wer.dll.WerReportAddDump",
  2496. "wer.dll.WerpSetCallBack",
  2497. "wer.dll.WerReportSetUIOption",
  2498. "wer.dll.WerpAddRegisteredDataToReport",
  2499. "wer.dll.WerReportSubmit",
  2500. "user32.dll.GetProcessWindowStation",
  2501. "user32.dll.GetThreadDesktop",
  2502. "user32.dll.GetUserObjectInformationW",
  2503. "user32.dll.CharUpperW",
  2504. "wer.dll.WerpAddAppCompatData",
  2505. "apphelp.dll.SdbGetFileAttributes",
  2506. "apphelp.dll.SdbFormatAttribute",
  2507. "apphelp.dll.SdbFreeFileAttributes",
  2508. "dbghelp.dll.MiniDumpWriteDump",
  2509. "kernel32.dll.GetLongPathNameA",
  2510. "kernel32.dll.GetLongPathNameW",
  2511. "kernel32.dll.GetProcessTimes",
  2512. "advapi32.dll.RegOpenKeyExA",
  2513. "advapi32.dll.RegQueryValueExA",
  2514. "version.dll.GetFileVersionInfoSizeA",
  2515. "version.dll.GetFileVersionInfoA",
  2516. "version.dll.VerQueryValueA",
  2517. "verifier.dll.VerifierEnumerateResource",
  2518. "ntdll.dll.NtSuspendProcess",
  2519. "ntdll.dll.NtResumeProcess",
  2520. "advapi32.dll.QueryTraceW",
  2521. "advapi32.dll.AddAccessAllowedAceEx",
  2522. "shlwapi.dll.PathIsDirectoryW",
  2523. "wer.dll.WerpGetStoreLocation",
  2524. "wer.dll.WerpGetStoreType",
  2525. "wer.dll.WerReportCloseHandle",
  2526. "user32.dll.MsgWaitForMultipleObjects",
  2527. "wer.dll.WerpFreeString",
  2528. "werui.dll.WerUICreate",
  2529. "werui.dll.WerUIStart",
  2530. "werui.dll.WerUITerminate",
  2531. "werui.dll.WerUIDelete",
  2532. "w32time.dll.SvchostEntry_W32Time",
  2533. "w32time.dll.SvchostPushServiceGlobals",
  2534. "ws2_32.dll.#115",
  2535. "ws2_32.dll.#111",
  2536. "dsrole.dll.DsRoleGetPrimaryDomainInformation",
  2537. "dsrole.dll.DsRoleFreeMemory",
  2538. "sspicli.dll.LsaRegisterPolicyChangeNotification",
  2539. "w32time.dll.TimeProvClose",
  2540. "w32time.dll.TimeProvCommand",
  2541. "w32time.dll.TimeProvOpen",
  2542. "ws2_32.dll.getaddrinfo",
  2543. "ws2_32.dll.freeaddrinfo",
  2544. "ws2_32.dll.#23",
  2545. "ws2_32.dll.WSAEventSelect",
  2546. "vmictimeprovider.dll.TimeProvClose",
  2547. "vmictimeprovider.dll.TimeProvCommand",
  2548. "vmictimeprovider.dll.TimeProvOpen",
  2549. "ws2_32.dll.WSAAddressToStringW",
  2550. "ws2_32.dll.#3",
  2551. "ws2_32.dll.#116",
  2552. "sspicli.dll.LsaUnregisterPolicyChangeNotification",
  2553. "userenv.dll.UnregisterGPNotification",
  2554. "gpapi.dll.UnregisterGPNotificationInternal",
  2555. "psapi.dll.EnumProcesses"
  2556. ]
  2557.  
  2558. [*] Static Analysis: {
  2559. "pe": {
  2560. "peid_signatures": null,
  2561. "imports": [
  2562. {
  2563. "imports": [
  2564. {
  2565. "name": "ReadFile",
  2566. "address": "0x40d008"
  2567. },
  2568. {
  2569. "name": "GetFileSize",
  2570. "address": "0x40d00c"
  2571. },
  2572. {
  2573. "name": "CreateFileA",
  2574. "address": "0x40d010"
  2575. },
  2576. {
  2577. "name": "WriteFile",
  2578. "address": "0x40d014"
  2579. },
  2580. {
  2581. "name": "MapViewOfFile",
  2582. "address": "0x40d018"
  2583. },
  2584. {
  2585. "name": "CreateFileMappingW",
  2586. "address": "0x40d01c"
  2587. },
  2588. {
  2589. "name": "GetProcAddress",
  2590. "address": "0x40d020"
  2591. },
  2592. {
  2593. "name": "LoadLibraryW",
  2594. "address": "0x40d024"
  2595. },
  2596. {
  2597. "name": "GetStringTypeA",
  2598. "address": "0x40d028"
  2599. },
  2600. {
  2601. "name": "LCMapStringW",
  2602. "address": "0x40d02c"
  2603. },
  2604. {
  2605. "name": "LCMapStringA",
  2606. "address": "0x40d030"
  2607. },
  2608. {
  2609. "name": "SetStdHandle",
  2610. "address": "0x40d034"
  2611. },
  2612. {
  2613. "name": "LoadLibraryA",
  2614. "address": "0x40d038"
  2615. },
  2616. {
  2617. "name": "GetOEMCP",
  2618. "address": "0x40d03c"
  2619. },
  2620. {
  2621. "name": "GetACP",
  2622. "address": "0x40d040"
  2623. },
  2624. {
  2625. "name": "GetCPInfo",
  2626. "address": "0x40d044"
  2627. },
  2628. {
  2629. "name": "IsBadCodePtr",
  2630. "address": "0x40d048"
  2631. },
  2632. {
  2633. "name": "GlobalFree",
  2634. "address": "0x40d04c"
  2635. },
  2636. {
  2637. "name": "SetUnhandledExceptionFilter",
  2638. "address": "0x40d050"
  2639. },
  2640. {
  2641. "name": "FlushFileBuffers",
  2642. "address": "0x40d054"
  2643. },
  2644. {
  2645. "name": "SetFilePointer",
  2646. "address": "0x40d058"
  2647. },
  2648. {
  2649. "name": "GetLastError",
  2650. "address": "0x40d05c"
  2651. },
  2652. {
  2653. "name": "GetFileType",
  2654. "address": "0x40d060"
  2655. },
  2656. {
  2657. "name": "GetStdHandle",
  2658. "address": "0x40d064"
  2659. },
  2660. {
  2661. "name": "SetHandleCount",
  2662. "address": "0x40d068"
  2663. },
  2664. {
  2665. "name": "GetEnvironmentStringsW",
  2666. "address": "0x40d06c"
  2667. },
  2668. {
  2669. "name": "GetEnvironmentStrings",
  2670. "address": "0x40d070"
  2671. },
  2672. {
  2673. "name": "WideCharToMultiByte",
  2674. "address": "0x40d074"
  2675. },
  2676. {
  2677. "name": "FreeEnvironmentStringsW",
  2678. "address": "0x40d078"
  2679. },
  2680. {
  2681. "name": "FreeEnvironmentStringsA",
  2682. "address": "0x40d07c"
  2683. },
  2684. {
  2685. "name": "GetModuleFileNameA",
  2686. "address": "0x40d080"
  2687. },
  2688. {
  2689. "name": "UnhandledExceptionFilter",
  2690. "address": "0x40d084"
  2691. },
  2692. {
  2693. "name": "HeapSize",
  2694. "address": "0x40d088"
  2695. },
  2696. {
  2697. "name": "IsBadWritePtr",
  2698. "address": "0x40d08c"
  2699. },
  2700. {
  2701. "name": "HeapReAlloc",
  2702. "address": "0x40d090"
  2703. },
  2704. {
  2705. "name": "VirtualAlloc",
  2706. "address": "0x40d094"
  2707. },
  2708. {
  2709. "name": "VirtualFree",
  2710. "address": "0x40d098"
  2711. },
  2712. {
  2713. "name": "HeapCreate",
  2714. "address": "0x40d09c"
  2715. },
  2716. {
  2717. "name": "IsBadReadPtr",
  2718. "address": "0x40d0a0"
  2719. },
  2720. {
  2721. "name": "CloseHandle",
  2722. "address": "0x40d0a4"
  2723. },
  2724. {
  2725. "name": "HeapDestroy",
  2726. "address": "0x40d0a8"
  2727. },
  2728. {
  2729. "name": "GetCurrentProcess",
  2730. "address": "0x40d0ac"
  2731. },
  2732. {
  2733. "name": "GetStringTypeW",
  2734. "address": "0x40d0b0"
  2735. },
  2736. {
  2737. "name": "MultiByteToWideChar",
  2738. "address": "0x40d0b4"
  2739. },
  2740. {
  2741. "name": "HeapAlloc",
  2742. "address": "0x40d0b8"
  2743. },
  2744. {
  2745. "name": "RtlUnwind",
  2746. "address": "0x40d0bc"
  2747. },
  2748. {
  2749. "name": "GetModuleHandleA",
  2750. "address": "0x40d0c0"
  2751. },
  2752. {
  2753. "name": "GetStartupInfoA",
  2754. "address": "0x40d0c4"
  2755. },
  2756. {
  2757. "name": "GetCommandLineA",
  2758. "address": "0x40d0c8"
  2759. },
  2760. {
  2761. "name": "GetVersion",
  2762. "address": "0x40d0cc"
  2763. },
  2764. {
  2765. "name": "ExitProcess",
  2766. "address": "0x40d0d0"
  2767. },
  2768. {
  2769. "name": "RaiseException",
  2770. "address": "0x40d0d4"
  2771. },
  2772. {
  2773. "name": "HeapFree",
  2774. "address": "0x40d0d8"
  2775. },
  2776. {
  2777. "name": "TerminateProcess",
  2778. "address": "0x40d0dc"
  2779. }
  2780. ],
  2781. "dll": "KERNEL32.dll"
  2782. },
  2783. {
  2784. "imports": [
  2785. {
  2786. "name": "DestroyWindow",
  2787. "address": "0x40d0e4"
  2788. },
  2789. {
  2790. "name": "GetWindowTextA",
  2791. "address": "0x40d0e8"
  2792. },
  2793. {
  2794. "name": "GetDlgItem",
  2795. "address": "0x40d0ec"
  2796. },
  2797. {
  2798. "name": "EnableMenuItem",
  2799. "address": "0x40d0f0"
  2800. },
  2801. {
  2802. "name": "DrawMenuBar",
  2803. "address": "0x40d0f4"
  2804. },
  2805. {
  2806. "name": "SetFocus",
  2807. "address": "0x40d0f8"
  2808. },
  2809. {
  2810. "name": "SendDlgItemMessageA",
  2811. "address": "0x40d0fc"
  2812. },
  2813. {
  2814. "name": "DefMDIChildProcA",
  2815. "address": "0x40d100"
  2816. },
  2817. {
  2818. "name": "GetMenu",
  2819. "address": "0x40d104"
  2820. },
  2821. {
  2822. "name": "GetSubMenu",
  2823. "address": "0x40d108"
  2824. },
  2825. {
  2826. "name": "SendMessageA",
  2827. "address": "0x40d10c"
  2828. },
  2829. {
  2830. "name": "PostMessageA",
  2831. "address": "0x40d110"
  2832. },
  2833. {
  2834. "name": "DefFrameProcA",
  2835. "address": "0x40d114"
  2836. },
  2837. {
  2838. "name": "GetClientRect",
  2839. "address": "0x40d118"
  2840. },
  2841. {
  2842. "name": "GetWindowRect",
  2843. "address": "0x40d11c"
  2844. },
  2845. {
  2846. "name": "MoveWindow",
  2847. "address": "0x40d120"
  2848. },
  2849. {
  2850. "name": "GetWindowTextLengthA",
  2851. "address": "0x40d124"
  2852. },
  2853. {
  2854. "name": "PostQuitMessage",
  2855. "address": "0x40d128"
  2856. },
  2857. {
  2858. "name": "LoadIconA",
  2859. "address": "0x40d12c"
  2860. },
  2861. {
  2862. "name": "LoadCursorA",
  2863. "address": "0x40d130"
  2864. },
  2865. {
  2866. "name": "RegisterClassExA",
  2867. "address": "0x40d134"
  2868. },
  2869. {
  2870. "name": "MessageBoxA",
  2871. "address": "0x40d138"
  2872. },
  2873. {
  2874. "name": "CreateWindowExA",
  2875. "address": "0x40d13c"
  2876. },
  2877. {
  2878. "name": "ShowWindow",
  2879. "address": "0x40d140"
  2880. },
  2881. {
  2882. "name": "UpdateWindow",
  2883. "address": "0x40d144"
  2884. },
  2885. {
  2886. "name": "GetMessageA",
  2887. "address": "0x40d148"
  2888. },
  2889. {
  2890. "name": "TranslateMDISysAccel",
  2891. "address": "0x40d14c"
  2892. },
  2893. {
  2894. "name": "TranslateMessage",
  2895. "address": "0x40d150"
  2896. },
  2897. {
  2898. "name": "DispatchMessageA",
  2899. "address": "0x40d154"
  2900. },
  2901. {
  2902. "name": "SetWindowTextA",
  2903. "address": "0x40d158"
  2904. }
  2905. ],
  2906. "dll": "USER32.dll"
  2907. },
  2908. {
  2909. "imports": [
  2910. {
  2911. "name": "GetStockObject",
  2912. "address": "0x40d000"
  2913. }
  2914. ],
  2915. "dll": "GDI32.dll"
  2916. },
  2917. {
  2918. "imports": [
  2919. {
  2920. "name": "GetOpenFileNameA",
  2921. "address": "0x40d160"
  2922. },
  2923. {
  2924. "name": "GetSaveFileNameA",
  2925. "address": "0x40d164"
  2926. }
  2927. ],
  2928. "dll": "comdlg32.dll"
  2929. }
  2930. ],
  2931. "digital_signers": null,
  2932. "exported_dll_name": null,
  2933. "actual_checksum": "0x00085ff6",
  2934. "overlay": null,
  2935. "imagebase": "0x00400000",
  2936. "reported_checksum": "0x00085ff6",
  2937. "icon_hash": null,
  2938. "entrypoint": "0x00407eb3",
  2939. "timestamp": "2019-06-27 10:13:21",
  2940. "osversion": "4.0",
  2941. "sections": [
  2942. {
  2943. "name": ".text",
  2944. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  2945. "virtual_address": "0x00001000",
  2946. "size_of_data": "0x0000c000",
  2947. "entropy": "6.47",
  2948. "raw_address": "0x00001000",
  2949. "virtual_size": "0x0000be25",
  2950. "characteristics_raw": "0x60000020"
  2951. },
  2952. {
  2953. "name": ".rdata",
  2954. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  2955. "virtual_address": "0x0000d000",
  2956. "size_of_data": "0x00002000",
  2957. "entropy": "4.33",
  2958. "raw_address": "0x0000d000",
  2959. "virtual_size": "0x00001e0a",
  2960. "characteristics_raw": "0x40000040"
  2961. },
  2962. {
  2963. "name": ".data",
  2964. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  2965. "virtual_address": "0x0000f000",
  2966. "size_of_data": "0x0003b000",
  2967. "entropy": "6.05",
  2968. "raw_address": "0x0000f000",
  2969. "virtual_size": "0x0003bbc8",
  2970. "characteristics_raw": "0xc0000040"
  2971. },
  2972. {
  2973. "name": ".rsrc",
  2974. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  2975. "virtual_address": "0x0004b000",
  2976. "size_of_data": "0x0002d000",
  2977. "entropy": "7.39",
  2978. "raw_address": "0x0004a000",
  2979. "virtual_size": "0x0002ca80",
  2980. "characteristics_raw": "0x40000040"
  2981. }
  2982. ],
  2983. "resources": [],
  2984. "dirents": [
  2985. {
  2986. "virtual_address": "0x00000000",
  2987. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  2988. "size": "0x00000000"
  2989. },
  2990. {
  2991. "virtual_address": "0x0000e640",
  2992. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  2993. "size": "0x00000064"
  2994. },
  2995. {
  2996. "virtual_address": "0x0004b000",
  2997. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  2998. "size": "0x0002ca80"
  2999. },
  3000. {
  3001. "virtual_address": "0x00000000",
  3002. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  3003. "size": "0x00000000"
  3004. },
  3005. {
  3006. "virtual_address": "0x00000000",
  3007. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  3008. "size": "0x00000000"
  3009. },
  3010. {
  3011. "virtual_address": "0x00000000",
  3012. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  3013. "size": "0x00000000"
  3014. },
  3015. {
  3016. "virtual_address": "0x00000000",
  3017. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  3018. "size": "0x00000000"
  3019. },
  3020. {
  3021. "virtual_address": "0x00000000",
  3022. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  3023. "size": "0x00000000"
  3024. },
  3025. {
  3026. "virtual_address": "0x00000000",
  3027. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  3028. "size": "0x00000000"
  3029. },
  3030. {
  3031. "virtual_address": "0x00000000",
  3032. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  3033. "size": "0x00000000"
  3034. },
  3035. {
  3036. "virtual_address": "0x00000000",
  3037. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  3038. "size": "0x00000000"
  3039. },
  3040. {
  3041. "virtual_address": "0x00000000",
  3042. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  3043. "size": "0x00000000"
  3044. },
  3045. {
  3046. "virtual_address": "0x0000d000",
  3047. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  3048. "size": "0x0000016c"
  3049. },
  3050. {
  3051. "virtual_address": "0x00000000",
  3052. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  3053. "size": "0x00000000"
  3054. },
  3055. {
  3056. "virtual_address": "0x00000000",
  3057. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  3058. "size": "0x00000000"
  3059. },
  3060. {
  3061. "virtual_address": "0x00000000",
  3062. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  3063. "size": "0x00000000"
  3064. }
  3065. ],
  3066. "exports": [],
  3067. "guest_signers": {},
  3068. "imphash": "04db1e6ce3faf3176a7e60a381423311",
  3069. "icon_fuzzy": null,
  3070. "icon": null,
  3071. "pdbpath": null,
  3072. "imported_dll_count": 4,
  3073. "versioninfo": []
  3074. }
  3075. }
Add Comment
Please, Sign In to add comment