- C:\Users\user\AppData\Local\Temp\45b63e00c568632d21828d652ee538085ad64e11.exe
- C:\Users\user\AppData\Local\Temp
- C:\Users\user\AppData\Local\Temp\_MEI22722
- C:\Users\user\AppData\Local\Temp\_MEI22722\VCRUNTIME140.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\_bz2.pyd
-
- C:\Users\user\AppData\Local\Temp\_MEI22722\_cffi_backend.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_decimal.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_hashlib.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_lzma.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_queue.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_socket.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_ssl.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\bcrypt
- C:\Users\user\AppData\Local\Temp\_MEI22722\bcrypt\_bcrypt.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\brotli
- C:\Users\user\AppData\Local\Temp\_MEI22722\brotli\_brotli.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat\bindings
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat\bindings\_rust.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\libcrypto-1_1.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\libssl-1_1.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\python3.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\python310.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\select.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\unicodedata.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard\_cffi.cp310-win_amd64.pyd
- C:\Windows\sysnative\tzres.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard\backend_c.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\base_library.zip
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi\cacert.pem
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi\py.typed
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\INSTALLER
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE.APACHE
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE.BSD
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\METADATA
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\RECORD
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\WHEEL
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\top_level.txt
- C:\Users\user\AppData\Local\Temp\_MEI22722\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\bcrypt\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\brotli\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat\bindings\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard\*
- C:\Users\user\AppData\Local\Temp\_MEI22722\ucrtbase.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\VERSION.dll
- C:\Windows\sysnative\version.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\api-ms-win-core-path-l1-1-0.dll
- C:\Windows\sysnative\api-ms-win-core-path-l1-1-0.dll
- C:\Windows\system\api-ms-win-core-path-l1-1-0.dll
- C:\Windows\api-ms-win-core-path-l1-1-0.dll
- C:\ProgramData\Oracle\Java\javapath\api-ms-win-core-path-l1-1-0.dll
- C:\Windows\sysnative\wbem\api-ms-win-core-path-l1-1-0.dll
- C:\Windows\sysnative\WindowsPowerShell\v1.0\api-ms-win-core-path-l1-1-0.dll
- C:\Program Files\Microsoft Network Monitor 3\api-ms-win-core-path-l1-1-0.dll
- C:\Program Files (x86)\Universal Extractor\api-ms-win-core-path-l1-1-0.dll
- C:\Program Files (x86)\Universal Extractor\bin\api-ms-win-core-path-l1-1-0.dll
- C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\api-ms-win-core-path-l1-1-0.dll
- C:\Python27\api-ms-win-core-path-l1-1-0.dll
- C:\Python27\Scripts\api-ms-win-core-path-l1-1-0.dll
- C:\tools\sysinternals\api-ms-win-core-path-l1-1-0.dll
- C:\tools\api-ms-win-core-path-l1-1-0.dll
- C:\tools\IDA_Pro_v6\python\api-ms-win-core-path-l1-1-0.dll
- C:\Windows\sysnative\en-US\KERNELBASE.dll.mui
- C:\Windows\Fonts\staticcache.dat
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Users\user\AppData\Local\Temp\imageres.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\imageres.dll
- C:\Windows\sysnative\imageres.dll
- \Device\KsecDD
- Show More 73
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
-
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\EnableAnchorContext
- Show More 22
- C:\Users\user\AppData\Local\Temp\_MEI22722\VCRUNTIME140.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\_bz2.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_cffi_backend.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_decimal.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_hashlib.pyd
-
- C:\Users\user\AppData\Local\Temp\_MEI22722\_lzma.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_queue.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_socket.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_ssl.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\bcrypt\_bcrypt.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\brotli\_brotli.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat\bindings\_rust.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\libcrypto-1_1.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\libssl-1_1.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\python3.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\python310.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\select.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\unicodedata.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard\_cffi.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard\backend_c.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\base_library.zip
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi\cacert.pem
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi\py.typed
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\INSTALLER
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE.APACHE
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE.BSD
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\METADATA
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\RECORD
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\WHEEL
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\top_level.txt
- Show More 26
- kernel32.dll.InitializeCriticalSectionEx
- kernel32.dll.FlsAlloc
- kernel32.dll.FlsSetValue
- kernel32.dll.LCMapStringEx
- gdi32.dll.GetLayout
-
- gdi32.dll.GdiRealizationInfo
- gdi32.dll.FontIsLinked
- advapi32.dll.RegOpenKeyExW
- advapi32.dll.RegQueryInfoKeyW
- gdi32.dll.GetTextFaceAliasW
- advapi32.dll.RegEnumValueW
- advapi32.dll.RegCloseKey
- advapi32.dll.RegQueryValueExW
- gdi32.dll.GetFontAssocStatus
- advapi32.dll.RegQueryValueExA
- advapi32.dll.RegEnumKeyExW
- uxtheme.dll.ThemeInitApiHook
- user32.dll.IsProcessDPIAware
- dwmapi.dll.DwmIsCompositionEnabled
- comctl32.dll.RegisterClassNameW
- kernel32.dll.SortGetHandle
- kernel32.dll.SortCloseHandle
- uxtheme.dll.EnableThemeDialogTexture
- uxtheme.dll.OpenThemeData
- uxtheme.dll.GetThemeBool
- gdi32.dll.GdiIsMetaPrintDC
- ole32.dll.CoInitializeEx
- ole32.dll.CoUninitialize
- cryptbase.dll.SystemFunction036
- ole32.dll.CoRegisterInitializeSpy
- ole32.dll.CoRevokeInitializeSpy
- uxtheme.dll.BufferedPaintInit
- uxtheme.dll.BufferedPaintRenderAnimation
- uxtheme.dll.BeginBufferedAnimation
- uxtheme.dll.IsThemeBackgroundPartiallyTransparent
- uxtheme.dll.DrawThemeParentBackground
- uxtheme.dll.DrawThemeBackground
- uxtheme.dll.GetThemeBackgroundContentRect
- uxtheme.dll.DrawThemeText
- uxtheme.dll.EndBufferedAnimation
- uxtheme.dll.CloseThemeData
- uxtheme.dll.BufferedPaintStopAllAnimations
- uxtheme.dll.BufferedPaintUnInit
- Show More 38
- C:\Users\user\AppData\Local\Temp\_MEI22722\base_library.zip
- C:\Users\user\AppData\Local\Temp\_MEI22722\bcrypt\_bcrypt.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\bcrypt
- C:\Users\user\AppData\Local\Temp\_MEI22722\brotli\_brotli.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\brotli
-
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi\cacert.pem
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi\py.typed
- C:\Users\user\AppData\Local\Temp\_MEI22722\certifi
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat\bindings\_rust.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat\bindings
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography\hazmat
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\INSTALLER
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE.APACHE
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\LICENSE.BSD
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\METADATA
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\RECORD
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\top_level.txt
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info\WHEEL
- C:\Users\user\AppData\Local\Temp\_MEI22722\cryptography-41.0.1.dist-info
- C:\Users\user\AppData\Local\Temp\_MEI22722\libcrypto-1_1.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\libssl-1_1.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\python3.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\python310.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\select.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\unicodedata.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\VCRUNTIME140.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard\backend_c.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard\_cffi.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\zstandard
- C:\Users\user\AppData\Local\Temp\_MEI22722\_bz2.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_cffi_backend.cp310-win_amd64.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_decimal.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_hashlib.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_lzma.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_queue.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_socket.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722\_ssl.pyd
- C:\Users\user\AppData\Local\Temp\_MEI22722
- Show More 35
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
-
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\45b63e00c568632d21828d652ee538085ad64e11.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\EnableAnchorContext
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
- Show More 38
- C:\Users\user\AppData\Local\Temp\45b63e00c568632d21828d652ee538085ad64e11.exe
- C:\Windows\sysnative\tzres.dll
- C:\Users\user\AppData\Local\Temp\_MEI22722\python310.dll
- C:\Windows\sysnative\version.dll
- C:\Windows\sysnative\en-US\KERNELBASE.dll.mui
-
- C:\Windows\Fonts\staticcache.dat
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\sysnative\imageres.dll
- \Device\KsecDD
- Show More 4
- CicLoadWinStaWinSta0
- Local\MSCTF.CtfMonitorInstMutexDefault1