- C:\Users\user\AppData\Local\Temp\msvcr100.dll
- C:\Windows\System32\msvcr100.dll
- C:\Windows\system\msvcr100.dll
- C:\Windows\msvcr100.dll
- C:\ProgramData\Oracle\Java\javapath\msvcr100.dll
-
- C:\Windows\System32\wbem\msvcr100.dll
- C:\Windows\System32\WindowsPowerShell\v1.0\msvcr100.dll
- C:\Program Files\Microsoft Network Monitor 3\msvcr100.dll
- C:\Program Files (x86)\Universal Extractor\msvcr100.dll
- C:\Program Files (x86)\Universal Extractor\bin\msvcr100.dll
- C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\msvcr100.dll
- C:\Python27\msvcr100.dll
- C:\Python27\Scripts\msvcr100.dll
- C:\tools\sysinternals\msvcr100.dll
- C:\tools\msvcr100.dll
- C:\tools\IDA_Pro_v6\python\msvcr100.dll
- \Device\KsecDD
- C:\Windows\System32\mscoree.dll.local
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
- C:\Windows\Microsoft.NET\Framework\*
- C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
- C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
- C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
- C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
- C:\Users\user\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Program Files\Microsoft Network Monitor 3\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Program Files (x86)\Universal Extractor\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Program Files (x86)\Universal Extractor\bin\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Python27\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Python27\Scripts\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\tools\sysinternals\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\tools\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\tools\IDA_Pro_v6\python\api-ms-win-appmodel-runtime-l1-1-0.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll
- C:\Windows\System32\MSVCR120_CLR0400.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll
- C:\Users\user\AppData\Local\Temp\fe3658635c66bb8b0981fe3f73cebf1b229ed661.exe.config
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll.aux
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\OLEAUT32.dll
- C:\Windows\assembly\pubpol20.dat
- C:\Windows\assembly\GAC\PublisherPolicy.tme
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\_\v4.0_0.0.0.0__461d39c4a423da0b\_.dll
- C:\Windows\assembly\GAC_MSIL\_\0.0.0.0__461d39c4a423da0b\_.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\oleaut32.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5aac750b35b27770dccb1a43f83cced7\System.Windows.Forms.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5aac750b35b27770dccb1a43f83cced7\System.Windows.Forms.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\52cca48930e580e3189eac47158c20be\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\52cca48930e580e3189eac47158c20be\System.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\646b4b01cb29986f8e076aa65c9e9753\System.Drawing.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\646b4b01cb29986f8e076aa65c9e9753\System.Drawing.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\Tombolas\v4.0_1.9.2.1440__461d39c4a423da0b\Tombolas.dll
- C:\Windows\assembly\GAC_32\Tombolas\1.9.2.1440__461d39c4a423da0b\Tombolas.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\mscorrc.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\mscorrc.dll.DLL
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\en\mscorrc.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\en\mscorrc.dll.DLL
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
- C:\Windows\System32\tzres.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
- C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll
- C:\Windows\System32\en-US\tzres.dll.mui
- C:\Windows\Microsoft.Net\assembly\GAC_32\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\da36abbea6ef456f432434d4d8d835c1\PresentationFramework.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\da36abbea6ef456f432434d4d8d835c1\PresentationFramework.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_32\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\WindowsBase.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\32512bd09e2231f6eebb15fc17e3ad79\WindowsBase.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\32512bd09e2231f6eebb15fc17e3ad79\WindowsBase.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\55560c2014611e9119f99923c9ebdeef\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\55560c2014611e9119f99923c9ebdeef\System.Core.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\System.Xaml.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\416ba33cb980d07643e82c4c45bd5786\PresentationCore.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\416ba33cb980d07643e82c4c45bd5786\PresentationCore.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Input.Manipulations.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ReachFramework.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\PresentationUI.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\System.Printing.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\MSVCR120_CLR0400.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\SHLWAPI.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.INI
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\VERSION.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.INI
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.INI
- C:\Windows\Microsoft.Net\assembly\GAC_32\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.INI
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.INI
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d86b080a37c60a872c82b912a2a63dac\System.Xml.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d86b080a37c60a872c82b912a2a63dac\System.Xml.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\46957030830964165644b52b0696c5d9\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\46957030830964165644b52b0696c5d9\System.Configuration.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\e7044d177c8e852b85908d2702898ec8\System.Transactions.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\e7044d177c8e852b85908d2702898ec8\System.Transactions.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll.config
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.CSharp\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.INI
- C:\Users\user\AppData\Local\SystemCache
- C:\Users\user\AppData\Local
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\*
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4dfa27fdd6a4cce26f99585e1c744f9b\System.Management.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4dfa27fdd6a4cce26f99585e1c744f9b\System.Management.ni.dll.aux
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\secur32.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\bcrypt.dll
- C:\Users\user\AppData\Local\Battle.net\*
- C:\Users\user\AppData\Local\Chromium\User Data\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Caps\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\EVWhitelist\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\PepperFlash\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\pnacl\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\SwiftShader\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCDM\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.28b9ef5a#\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.INI
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\*
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.INI
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.INI
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\crypt32.dll
- C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data
- C:\Users\user\AppData\Local\Google(x86)\Chrome\User Data\*
- C:\Users\user\AppData\Roaming\Opera Software\*
- C:\Users\user\AppData\Local\MapleStudio\ChromePlus\User Data\*
- C:\Users\user\AppData\Local\Iridium\User Data\*
- C:\Users\user\AppData\Local\7Star\7Star\User Data\*
- C:\Users\user\AppData\Local\CentBrowser\User Data\*
- C:\Users\user\AppData\Local\Chedot\User Data\*
- C:\Users\user\AppData\Local\Vivaldi\User Data\*
- C:\Users\user\AppData\Local\Kometa\User Data\*
- C:\Users\user\AppData\Local\Elements Browser\User Data\*
- C:\Users\user\AppData\Local\Epic Privacy Browser\User Data\*
- C:\Users\user\AppData\Local\uCozMedia\Uran\User Data\*
- C:\Users\user\AppData\Local\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\*
- C:\Users\user\AppData\Local\CatalinaGroup\Citrio\User Data\*
- C:\Users\user\AppData\Local\Coowon\Coowon\User Data\*
- C:\Users\user\AppData\Local\liebao\User Data\*
- C:\Users\user\AppData\Local\QIP Surf\User Data\*
- C:\Users\user\AppData\Local\Orbitum\User Data\*
- C:\Users\user\AppData\Local\Comodo\Dragon\User Data\*
- C:\Users\user\AppData\Local\Amigo\User\User Data\*
- C:\Users\user\AppData\Local\Torch\User Data\*
- C:\Users\user\AppData\Local\Yandex\YandexBrowser\User Data\*
- C:\Users\user\AppData\Local\Comodo\User Data\*
- C:\Users\user\AppData\Local\360Browser\Browser\User Data\*
- C:\Users\user\AppData\Local\Maxthon3\User Data\*
- C:\Users\user\AppData\Local\K-Melon\User Data\*
- C:\Users\user\AppData\Local\Sputnik\Sputnik\User Data\*
- C:\Users\user\AppData\Local\Nichrome\User Data\*
- C:\Users\user\AppData\Local\CocCoc\Browser\User Data\*
- C:\Users\user\AppData\Local\Uran\User Data\*
- C:\Users\user\AppData\Local\Chromodo\User Data\*
- C:\Users\user\AppData\Local\Mail.Ru\Atom\User Data\*
- C:\Users\user\AppData\Local\BraveSoftware\Brave-Browser\User Data\*
- C:\Users\user\AppData\Local\Microsoft\Edge\User Data\*
- C:\Users\user\AppData\Local\NVIDIA Corporation\NVIDIA GeForce Experience\*
- C:\Users\user\AppData\Local\Steam\*
- C:\Users\user\AppData\Local\CryptoTab Browser\User Data\*
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\*
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\*
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\*
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\*
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\*
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\cookies.sqlite
- C:\Users\user\AppData\Roaming\Waterfox\*
- C:\Users\user\AppData\Roaming\K-Meleon\*
- C:\Users\user\AppData\Roaming\Thunderbird\*
- C:\Users\user\AppData\Roaming\Comodo\IceDragon\*
- C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\*
- C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHaw\*
- C:\Users\user\AppData\Roaming\Moonchild Productions\Pale Moon\*
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll
- C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml
- C:\Users\user\AppData\Roaming\FileZilla\sitemanager.xml
- C:\Users\user\AppData\Local\Temp\fe3658635c66bb8b0981fe3f73cebf1b229ed661.exe.Local\
- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
- C:\Users\user\AppData\Roaming\Telegram Desktop\tdata\*
- C:\Users\user\AppData\Local\NordVPN
- C:\Users\user\AppData\Local\Temp\%USERPROFILE%\AppData\Roaming\OpenVPN Connect\profiles\*ovpn
- C:\Users\user\AppData\Local\Temp\%USERPROFILE%\AppData\Local\ProtonVPN\*ovpn
- C:\Users\user\AppData\Roaming\discord\Local Storage\leveldb\*.log
- C:\Users\user\AppData\Roaming\discord\Local Storage\leveldb\*.ldb
- C:\Users\user\AppData\Roaming\*
- C:\Users\user\AppData\Roaming\Adobe\*
- C:\Users\user\AppData\Roaming\Adobe\Acrobat\*
- C:\Users\user\AppData\Roaming\Adobe\Flash Player\*
- C:\Users\user\AppData\Roaming\GHISLER\*
- C:\Users\user\AppData\Roaming\Hex-Rays\*
- C:\Users\user\AppData\Roaming\Hex-Rays\IDA Pro\*
- C:\Users\user\AppData\Roaming\Identities\*
- C:\Users\user\AppData\Roaming\Identities\{70D464B9-E6BE-4D71-B0C3-BC4DF2DDB7BC}\*
- C:\Users\user\AppData\Roaming\JetBrains\*
- C:\Users\user\AppData\Roaming\JetBrains\dotPeek\*
- C:\Users\user\AppData\Roaming\JetBrains\PrivacyPolicy\*
- C:\Users\user\AppData\Roaming\JetBrains\Shared\*
- C:\Users\user\AppData\Roaming\JustDecompile\*
- C:\Users\user\AppData\Roaming\JustDecompile\Analytics\*
- C:\Users\user\AppData\Roaming\JustDecompile\AssemblyLists\*
- C:\Users\user\AppData\Roaming\JustDecompile\banners\*
- C:\Users\user\AppData\Roaming\JustDecompile\DownloadedPlugins\*
- C:\Users\user\AppData\Roaming\Macromedia\*
- C:\Users\user\AppData\Roaming\Macromedia\Flash Player\*
- C:\Users\user\AppData\Roaming\Media Center Programs\*
- C:\Users\user\AppData\Roaming\Microsoft\*
- C:\Users\user\AppData\Roaming\Microsoft\AddIns\*
- C:\Users\user\AppData\Roaming\Microsoft\CLR Security Config\*
- C:\Users\user\AppData\Roaming\Microsoft\Credentials\*
- C:\Users\user\AppData\Roaming\Microsoft\Crypto\*
- C:\Users\user\AppData\Roaming\Microsoft\Document Building Blocks\*
- C:\Users\user\AppData\Roaming\Microsoft\Excel\*
- C:\Users\user\AppData\Roaming\Microsoft\HTML Help\*
- C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\*
- C:\Users\user\AppData\Roaming\Microsoft\MMC\*
- C:\Users\user\AppData\Roaming\Microsoft\Network\*
- C:\Users\user\AppData\Roaming\Microsoft\Network Monitor 3\*
- C:\Users\user\AppData\Roaming\Microsoft\Office\*
- C:\Users\user\AppData\Roaming\Microsoft\Outlook\*
- C:\Users\user\AppData\Roaming\Microsoft\Proof\*
- C:\Users\user\AppData\Roaming\Microsoft\Protect\*
- C:\Users\user\AppData\Roaming\Microsoft\Speech\*
- C:\Users\user\AppData\Roaming\Microsoft\SystemCertificates\*
- C:\Users\user\AppData\Roaming\Microsoft\Templates\*
- C:\Users\user\AppData\Roaming\Microsoft\UProof\*
- C:\Users\user\AppData\Roaming\Microsoft\Windows\*
- C:\Users\user\AppData\Roaming\Microsoft\Word\*
- C:\Users\user\AppData\Roaming\Mozilla\*
- C:\Users\user\AppData\Roaming\Mozilla\Extensions\*
- C:\Users\user\AppData\Roaming\MPC-HC\*
- C:\Users\user\AppData\Roaming\Nektra\*
- C:\Users\user\AppData\Roaming\Nektra\SpyStudio\*
- C:\Users\user\AppData\Roaming\Notepad++\*
- C:\Users\user\AppData\Roaming\Notepad++\plugins\*
- C:\Users\user\AppData\Roaming\Notepad++\themes\*
- C:\Users\user\AppData\Roaming\NuGet\*
- C:\Users\user\AppData\Roaming\PhrozenSoft\*
- C:\Users\user\AppData\Roaming\PhrozenSoft\PVTUploader\*
- C:\Users\user\AppData\Roaming\SpyStudio\*
- C:\Users\user\AppData\Roaming\Sun\*
- C:\Users\user\AppData\Roaming\Sun\Java\*
- C:\Users\user\AppData\Roaming\Telerik\*
- C:\Users\user\AppData\Roaming\Telerik\Installer\*
- C:\Users\user\AppData\Local\*
- C:\Users\user\AppData\Local\Adobe\*
- C:\Users\user\AppData\Local\Adobe\Acrobat\*
- C:\Users\user\AppData\Local\Adobe\Color\*
- C:\Users\user\AppData\Local\Adobe\Updater6\*
- C:\Users\user\AppData\Local\Application Data\*
- C:\Users\user\AppData\Local\Apps\*
- C:\Users\user\AppData\Local\Apps\2.0\*
- C:\Users\user\AppData\Local\CrashDumps\*
- C:\Users\user\AppData\Local\Downloaded Installations\*
- C:\Users\user\AppData\Local\Downloaded Installations\rohitab.com\*
- C:\Users\user\AppData\Local\ElevatedDiagnostics\*
- C:\Users\user\AppData\Local\Google\*
- C:\Users\user\AppData\Local\Google\Chrome\*
- C:\Users\user\AppData\Local\History\*
- C:\Users\user\AppData\Local\IsolatedStorage\*
- C:\Users\user\AppData\Local\IsolatedStorage\vxvfkc4q.mdp\*
- C:\Users\user\AppData\Local\JetBrains\*
- C:\Users\user\AppData\Local\JetBrains\dotPeek\*
- C:\Users\user\AppData\Local\JetBrains\Installations\*
- C:\Users\user\AppData\Local\JetBrains\Shared\*
- C:\Users\user\AppData\Local\JetBrains\Transient\*
- C:\Users\user\AppData\Local\Macromedia\*
- C:\Users\user\AppData\Local\Macromedia\Flash Player\*
- C:\Users\user\AppData\Local\Microsoft\*
- C:\Users\user\AppData\Local\Microsoft\Credentials\*
- C:\Users\user\AppData\Local\Microsoft\Event Viewer\*
- C:\Users\user\AppData\Local\Microsoft\Feeds\*
- C:\Users\user\AppData\Local\Microsoft\Feeds Cache\*
- C:\Users\user\AppData\Local\Microsoft\FORMS\*
- C:\Users\user\AppData\Local\Microsoft\Internet Explorer\*
- C:\Users\user\AppData\Local\Microsoft\Media Player\*
- C:\Users\user\AppData\Local\Microsoft\Office\*
- C:\Users\user\AppData\Local\Microsoft\Outlook\*
- C:\Users\user\AppData\Local\Microsoft\TaskSchedulerConfig\*
- C:\Users\user\AppData\Local\Microsoft\Windows\*
- C:\Users\user\AppData\Local\Microsoft\Windows Mail\*
- C:\Users\user\AppData\Local\Microsoft\Windows Media\*
- C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\*
- C:\Users\user\AppData\Local\Microsoft Help\*
- C:\Users\user\AppData\Local\Mozilla\*
- C:\Users\user\AppData\Local\Mozilla\Firefox\*
- C:\Users\user\AppData\Local\Mozilla\updates\*
- C:\Users\user\AppData\Local\Nektra\*
- C:\Users\user\AppData\Local\Nektra\SpyStudio.exe_Url_rygq0eutckqdy0dml2kxedg4n3budkiv\*
- C:\Users\user\AppData\Local\NuGet\*
- C:\Users\user\AppData\Local\NuGet\Cache\*
- C:\Users\user\AppData\Local\pip\*
- C:\Users\user\AppData\Local\pip\cache\*
- C:\Users\user\AppData\Local\Programs\*
- C:\Users\user\AppData\Local\Programs\Common\*
- C:\Users\user\AppData\Local\RefSrcSymbols\*
- C:\Users\user\AppData\Local\rohitab.com\*
- C:\Users\user\AppData\Local\rohitab.com\API Monitor\*
- C:\Users\user\AppData\Local\SymbolSourceSymbols\*
- C:\Users\user\AppData\Local\SystemCache\*
- C:\Users\user\AppData\Local\Telerik_AD\*
- C:\Users\user\AppData\Local\Telerik_AD\TelerikWebInstaller.exe_StrongName_b0w3bkrwawn555ncrf1zoel0avt30orv\*
- C:\Users\user\AppData\Local\Temp\*
- C:\Users\user\AppData\Local\Temp\JetBrains\*
- C:\Users\user\AppData\Local\Temp\WPDNSE\*
- C:\Users\user\AppData\Local\Temporary Internet Files\*
- C:\Users\user\AppData\Local\VirtualStore\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofec\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnid\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflc\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjp\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\odbfpeeihdkbihmopkbjmoonfanlbfcl\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapac\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhilaheimglignddkjgofkcbgekhenbh\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnnegphlobjdpkhecapkijjdkgcjhkib\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemg\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cgeeodpfagjceefieflmdfphplkenlfk\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pdadjkfkgcafgbceimcpbkalnfnepbnk\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mgffkfbidihjpoaomajlbgchddlicgpn\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aodkkagnadcbobfpggfnjeongemjbjca\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimn\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hmeobnfnfcmdkdcmlblgagmfpfboieaf\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdo\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnm\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai\*
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaoc\*
- C:\Users\user\AppData\Roaming\Armory\*.wallet
- C:\Users\user\AppData\Roaming\atomic\*
- C:\Users\user\AppData\Roaming\Binance\*app-store*
- C:\Users\user\AppData\Local\Coinomi\Coinomi\Cache\*
- C:\Users\user\AppData\Local\Coinomi\Coinomi\db\*
- C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets\*
- C:\Users\user\AppData\Roaming\Electrum\wallets\*
- C:\Users\user\AppData\Roaming\Ethereum\wallets\*
- C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\*
- C:\Users\user\AppData\Roaming\Exodus\*.json
- C:\Users\user\AppData\Roaming\Guarda\*
- C:\Users\user\AppData\Roaming\com.liberty.jaxx\*
- C:\Users\user\Documents\Monero\wallets\*
- C:\Windows\sysnative\wbem\WmiPrvSE.exe
- C:\Windows\inf\disk.inf
- C:\Windows\sysnative\DriverStore\en-US\disk.inf_loc
- C:\Windows\inf\disk.PNF
- C:\Windows\inf\oem16.inf
- C:\Windows\sysnative\DriverStore\en-US\oem16.inf_loc
- C:\Windows\sysnative\DriverStore\en\oem16.inf_loc
- C:\Windows\inf\oem16.PNF
- \??\PIPE\samr
- C:\Windows\sysnative\wbem\repository
- C:\Windows\sysnative\wbem\Logs
- C:\Windows\sysnative\wbem\AutoRecover
- C:\Windows\sysnative\wbem\MOF
- C:\Windows\sysnative\wbem\repository\INDEX.BTR
- C:\Windows\sysnative\wbem\repository\WRITABLE.TST
- C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
- C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
- C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
- \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
- \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
- \??\ide#diskvbox_harddisk___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- \??\WMIDataDevice
- C:\
- C:\Windows\sysnative\VBoxDispD3D.*
- C:\Windows\sysnative\Branding\basebrd\basebrd.dll
- C:\Windows\Branding\Basebrd\basebrd.dll
- C:
- C:\Windows\sysnative\tzres.dll
- \??\PIPE\wkssvc
- \??\PIPE\srvsvc
- C:\DosDevices\pipe\
- \??\PHYSICALDRIVE0
- \??\ide#cdromvbox_cd-rom_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
- \??\CDROM0
- \??\PIPE\lsarpc
- C:\Windows\sysnative\OemInfo.Ini
- C:\Windows\sysnative\OemLogo.Bmp
- Show More 469
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
-
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index20
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\TZI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\MUI_Display
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\MUI_Std
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\MUI_Dlt
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\InstallPath
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\67658C14
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductName
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CSDVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\LogConf\ForcedConfig
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\DeviceDesc
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\LocaleName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\FriendlyName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Mfg
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\##?#PCI#VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00#3&267a616a&0&10#{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\DeviceInstance
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\LocalService
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\ServiceParameters
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\RunAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\ActivateAtStorage
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\ROTFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\AppIDFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\LaunchPermission
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\AuthenticationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\RemoteServerName
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\SRPTrustLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\PreferredServerBitness
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\LoadUserSettings
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InprocServer32\Synchronization
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="Cimwin32A"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
- HKEY_CURRENT_USER\Control Panel\International\LocaleName
- HKEY_CURRENT_USER\Control Panel\International\sCountry
- HKEY_CURRENT_USER\Control Panel\International\sList
- HKEY_CURRENT_USER\Control Panel\International\sDecimal
- HKEY_CURRENT_USER\Control Panel\International\sThousand
- HKEY_CURRENT_USER\Control Panel\International\sGrouping
- HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
- HKEY_CURRENT_USER\Control Panel\International\sCurrency
- HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
- HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
- HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
- HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
- HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
- HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
- HKEY_CURRENT_USER\Control Panel\International\sShortTime
- HKEY_CURRENT_USER\Control Panel\International\s1159
- HKEY_CURRENT_USER\Control Panel\International\s2359
- HKEY_CURRENT_USER\Control Panel\International\sShortDate
- HKEY_CURRENT_USER\Control Panel\International\sYearMonth
- HKEY_CURRENT_USER\Control Panel\International\sLongDate
- HKEY_CURRENT_USER\Control Panel\International\iCountry
- HKEY_CURRENT_USER\Control Panel\International\iMeasure
- HKEY_CURRENT_USER\Control Panel\International\iPaperSize
- HKEY_CURRENT_USER\Control Panel\International\iDigits
- HKEY_CURRENT_USER\Control Panel\International\iLZero
- HKEY_CURRENT_USER\Control Panel\International\iNegNumber
- HKEY_CURRENT_USER\Control Panel\International\NumShape
- HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
- HKEY_CURRENT_USER\Control Panel\International\iCurrency
- HKEY_CURRENT_USER\Control Panel\International\iNegCurr
- HKEY_CURRENT_USER\Control Panel\International\iCalendarType
- HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
- HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
- HKEY_PERFORMANCE_TEXT\Counter
- HKEY_PERFORMANCE_DATA\238
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sCountry
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sList
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sDecimal
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sThousand
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sGrouping
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sNativeDigits
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sCurrency
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sMonDecimalSep
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sMonThousandSep
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sMonGrouping
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sPositiveSign
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sNegativeSign
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sTimeFormat
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sShortTime
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\s1159
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\s2359
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sShortDate
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sYearMonth
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sLongDate
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCountry
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iMeasure
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iPaperSize
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iDigits
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iLZero
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iNegNumber
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\NumShape
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCurrDigits
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCurrency
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iNegCurr
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCalendarType
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iFirstDayOfWeek
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iFirstWeekOfYear
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation
- HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
- HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
- HKEY_USERS\.DEFAULT\Control Panel\International\sList
- HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
- HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
- HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
- HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
- HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
- HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
- HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
- HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
- HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
- HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
- HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
- HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
- HKEY_USERS\.DEFAULT\Control Panel\International\s1159
- HKEY_USERS\.DEFAULT\Control Panel\International\s2359
- HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
- HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
- HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
- HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
- HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
- HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
- HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
- HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
- HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
- HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
- HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
- HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
- HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
- HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
- HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
- HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\MEMORY MANAGEMENT\PagingFiles
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DisableAutoDaylightTimeSet
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl\AutoReboot
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\Identifier
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosDate
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
- Show More 419
- \??\PIPE\samr
- C:\Windows\sysnative\wbem\repository\WRITABLE.TST
- C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
-
- C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
- C:\Windows\sysnative\wbem\repository\INDEX.BTR
- \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
- \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
- \??\WMIDataDevice
- \??\PIPE\wkssvc
- \??\PIPE\srvsvc
- \??\PHYSICALDRIVE0
- \??\CDROM0
- \??\PIPE\lsarpc
- Show More 10
- kernel32.dll.FlsAlloc
- kernel32.dll.FlsGetValue
- kernel32.dll.FlsSetValue
- kernel32.dll.FlsFree
- kernel32.dll.VirtualProtect
-
- kernel32.dll.GlobalAlloc
- kernel32.dll.GetLastError
- kernel32.dll.Sleep
- kernel32.dll.VirtualAlloc
- kernel32.dll.CreateToolhelp32Snapshot
- kernel32.dll.Module32First
- kernel32.dll.CloseHandle
- kernel32.dll.LoadLibraryA
- kernel32.dll.VirtualFree
- kernel32.dll.GetVersionExA
- kernel32.dll.TerminateProcess
- kernel32.dll.ExitProcess
- kernel32.dll.SetErrorMode
- kernel32.dll.RaiseException
- kernel32.dll.MultiByteToWideChar
- kernel32.dll.lstrlenA
- kernel32.dll.InterlockedDecrement
- kernel32.dll.GetProcAddress
- kernel32.dll.FreeResource
- kernel32.dll.SizeofResource
- kernel32.dll.LockResource
- kernel32.dll.LoadResource
- kernel32.dll.FindResourceA
- kernel32.dll.GetModuleHandleA
- kernel32.dll.Module32Next
- kernel32.dll.GetCurrentProcessId
- kernel32.dll.SetEndOfFile
- kernel32.dll.GetStringTypeW
- kernel32.dll.GetStringTypeA
- kernel32.dll.LCMapStringW
- kernel32.dll.LCMapStringA
- kernel32.dll.GetLocaleInfoA
- kernel32.dll.HeapFree
- kernel32.dll.GetProcessHeap
- kernel32.dll.HeapAlloc
- kernel32.dll.GetCommandLineA
- kernel32.dll.HeapCreate
- kernel32.dll.DeleteCriticalSection
- kernel32.dll.LeaveCriticalSection
- kernel32.dll.EnterCriticalSection
- kernel32.dll.HeapReAlloc
- kernel32.dll.HeapSize
- kernel32.dll.GetCurrentProcess
- kernel32.dll.UnhandledExceptionFilter
- kernel32.dll.SetUnhandledExceptionFilter
- kernel32.dll.IsDebuggerPresent
- kernel32.dll.GetModuleHandleW
- kernel32.dll.WriteFile
- kernel32.dll.GetStdHandle
- kernel32.dll.GetModuleFileNameA
- kernel32.dll.WideCharToMultiByte
- kernel32.dll.GetConsoleCP
- kernel32.dll.GetConsoleMode
- kernel32.dll.ReadFile
- kernel32.dll.TlsGetValue
- kernel32.dll.TlsAlloc
- kernel32.dll.TlsSetValue
- kernel32.dll.TlsFree
- kernel32.dll.InterlockedIncrement
- kernel32.dll.SetLastError
- kernel32.dll.GetCurrentThreadId
- kernel32.dll.FlushFileBuffers
- kernel32.dll.SetFilePointer
- kernel32.dll.SetHandleCount
- kernel32.dll.GetFileType
- kernel32.dll.GetStartupInfoA
- kernel32.dll.RtlUnwind
- kernel32.dll.FreeEnvironmentStringsA
- kernel32.dll.GetEnvironmentStrings
- kernel32.dll.FreeEnvironmentStringsW
- kernel32.dll.GetEnvironmentStringsW
- kernel32.dll.QueryPerformanceCounter
- kernel32.dll.GetTickCount
- kernel32.dll.GetSystemTimeAsFileTime
- kernel32.dll.InitializeCriticalSectionAndSpinCount
- kernel32.dll.GetCPInfo
- kernel32.dll.GetACP
- kernel32.dll.GetOEMCP
- kernel32.dll.IsValidCodePage
- kernel32.dll.CompareStringA
- kernel32.dll.CompareStringW
- kernel32.dll.SetEnvironmentVariableA
- kernel32.dll.WriteConsoleA
- kernel32.dll.GetConsoleOutputCP
- kernel32.dll.WriteConsoleW
- kernel32.dll.SetStdHandle
- kernel32.dll.CreateFileA
- ole32.dll.OleInitialize
- oleaut32.dll.#15
- oleaut32.dll.#23
- oleaut32.dll.#24
- oleaut32.dll.#16
- oleaut32.dll.#411
- oleaut32.dll.#9
- oleaut32.dll.#8
- oleaut32.dll.#6
- oleaut32.dll.#2
- kernel32.dll.IsProcessorFeaturePresent
- cryptbase.dll.SystemFunction036
- uxtheme.dll.ThemeInitApiHook
- user32.dll.IsProcessDPIAware
- mscoree.dll.CLRCreateInstance
- advapi32.dll.RegOpenKeyExW
- advapi32.dll.RegQueryInfoKeyW
- advapi32.dll.RegEnumKeyExW
- advapi32.dll.RegEnumValueW
- advapi32.dll.RegCloseKey
- advapi32.dll.RegQueryValueExW
- kernel32.dll.InitializeCriticalSectionEx
- kernel32.dll.CreateEventExW
- kernel32.dll.CreateSemaphoreExW
- kernel32.dll.SetThreadStackGuarantee
- kernel32.dll.CreateThreadpoolTimer
- kernel32.dll.SetThreadpoolTimer
- kernel32.dll.WaitForThreadpoolTimerCallbacks
- kernel32.dll.CloseThreadpoolTimer
- kernel32.dll.CreateThreadpoolWait
- kernel32.dll.SetThreadpoolWait
- kernel32.dll.CloseThreadpoolWait
- kernel32.dll.FlushProcessWriteBuffers
- kernel32.dll.FreeLibraryWhenCallbackReturns
- kernel32.dll.GetCurrentProcessorNumber
- kernel32.dll.GetLogicalProcessorInformation
- kernel32.dll.CreateSymbolicLinkW
- kernel32.dll.EnumSystemLocalesEx
- kernel32.dll.CompareStringEx
- kernel32.dll.GetDateFormatEx
- kernel32.dll.GetLocaleInfoEx
- kernel32.dll.GetTimeFormatEx
- kernel32.dll.GetUserDefaultLocaleName
- kernel32.dll.IsValidLocaleName
- kernel32.dll.LCMapStringEx
- kernel32.dll.GetTickCount64
- advapi32.dll.EventRegister
- mscoree.dll.#142
- mscoreei.dll.RegisterShimImplCallback
- mscoreei.dll.OnShimDllMainCalled
- mscoreei.dll.CLRCreateInstance
- clr.dll.SetRuntimeInfo
- clr.dll.DllGetClassObjectInternal
- mscoree.dll.CreateConfigStream
- mscoreei.dll.CreateConfigStream
- shlwapi.dll.UrlIsW
- kernel32.dll.GetNumaHighestNodeNumber
- kernel32.dll.GetSystemWindowsDirectoryW
- advapi32.dll.AllocateAndInitializeSid
- advapi32.dll.OpenProcessToken
- advapi32.dll.GetTokenInformation
- advapi32.dll.InitializeAcl
- advapi32.dll.AddAccessAllowedAce
- advapi32.dll.FreeSid
- kernel32.dll.AddSIDToBoundaryDescriptor
- kernel32.dll.CreateBoundaryDescriptorW
- kernel32.dll.CreatePrivateNamespaceW
- kernel32.dll.OpenPrivateNamespaceW
- kernel32.dll.DeleteBoundaryDescriptor
- kernel32.dll.WerRegisterRuntimeExceptionModule
- mscoree.dll.#24
- mscoreei.dll.#24
- ntdll.dll.NtSetSystemInformation
- kernel32.dll.SortGetHandle
- kernel32.dll.SortCloseHandle
- kernel32.dll.GetNativeSystemInfo
- mscoree.dll._CorExeMain
- mscoree.dll._CorImageUnloading
- mscoree.dll._CorValidateImage
- ole32.dll.CoInitializeEx
- mscoree.dll.GetProcessExecutableHeap
- mscoreei.dll.GetProcessExecutableHeap
- oleaut32.dll.#17
- oleaut32.dll.#20
- oleaut32.dll.#77
- cryptsp.dll.CryptAcquireContextW
- cryptsp.dll.CryptImportKey
- cryptsp.dll.CryptExportKey
- cryptsp.dll.CryptCreateHash
- cryptsp.dll.CryptHashData
- cryptsp.dll.CryptGetHashParam
- cryptsp.dll.CryptDestroyHash
- cryptsp.dll.CryptDestroyKey
- oleaut32.dll.SysStringByteLen
- clrjit.dll.sxsJitStartup
- clrjit.dll.getJit
- kernel32.dll.LocaleNameToLCID
- kernel32.dll.LCIDToLocaleName
- kernel32.dll.GetUserPreferredUILanguages
- kernel32.dll.GetTimeZoneInformation
- kernel32.dll.GetDynamicTimeZoneInformation
- nlssorting.dll.SortGetHandle
- nlssorting.dll.SortCloseHandle
- shell32.dll.SHGetFolderPathW
- ole32.dll.CoTaskMemAlloc
- ole32.dll.CoTaskMemFree
- kernel32.dll.GetFileMUIPath
- kernel32.dll.LoadLibraryExW
- kernel32.dll.FreeLibrary
- user32.dll.LoadStringW
- kernel32.dll.LocalAlloc
- msvcr120_clr0400.dll.??2@YAPAXI@Z
- user32.dll.SetProcessDPIAware
- kernel32.dll.GetEnvironmentVariableW
- shlwapi.dll.PathAppendW
- shlwapi.dll.PathCombineW
- kernel32.dll.VerSetConditionMask
- kernel32.dll.VerifyVersionInfoW
- kernel32.dll.LoadLibraryW
- dwrite.dll.DWriteCreateFactory
- gdi32.dll.GdiEntry13
- advapi32.dll.EventWrite
- advapi32.dll.EventUnregister
- version.dll.GetFileVersionInfoSizeW
- version.dll.GetFileVersionInfoW
- version.dll.VerQueryValueW
- cryptsp.dll.CryptAcquireContextA
- cryptsp.dll.CryptReleaseContext
- kernel32.dll.CompareStringOrdinal
- kernel32.dll.GetFullPathNameW
- kernel32.dll.GetModuleFileNameW
- kernel32.dll.GetFileAttributesExW
- kernel32.dll.SetThreadErrorMode
- kernel32.dll.CreateFileW
- kernel32.dll.GetFileSize
- mscoreei.dll._CorDllMain
- mscoree.dll.GetTokenForVTableEntry
- mscoree.dll.SetTargetForVTableEntry
- mscoree.dll.GetTargetForVTableEntry
- cryptsp.dll.CryptGenRandom
- ole32.dll.CoCreateGuid
- ws2_32.dll.WSAStartup
- ws2_32.dll.WSASocketW
- ws2_32.dll.setsockopt
- ws2_32.dll.WSAEventSelect
- ws2_32.dll.ioctlsocket
- ws2_32.dll.closesocket
- ws2_32.dll.WSAConnect
- ws2_32.dll.send
- ws2_32.dll.recv
- kernel32.dll.CreateDirectoryW
- user32.dll.GetSystemMetrics
- user32.dll.GetDC
- gdi32.dll.GetDeviceCaps
- user32.dll.ReleaseDC
- secur32.dll.GetUserNameExW
- advapi32.dll.GetUserNameW
- kernel32.dll.CreateEventW
- kernel32.dll.SetEvent
- ole32.dll.CoWaitForMultipleHandles
- ole32.dll.IIDFromString
- ole32.dll.CoGetClassObject
- sechost.dll.LookupAccountNameLocalW
- ole32.dll.CoCreateFreeThreadedMarshaler
- ole32.dll.CoGetContextToken
- advapi32.dll.LookupAccountSidW
- sechost.dll.LookupAccountSidLocalW
- ole32.dll.NdrOleInitializeExtension
- ole32.dll.CoGetMarshalSizeMax
- ole32.dll.CoMarshalInterface
- ole32.dll.CoUnmarshalInterface
- ole32.dll.StringFromIID
- ole32.dll.CoGetPSClsid
- ole32.dll.CoCreateInstance
- ole32.dll.CoReleaseMarshalData
- ole32.dll.DcomChannelSetHResult
- rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
- ole32.dll.CoGetObjectContext
- wminet_utils.dll.ResetSecurity
- wminet_utils.dll.SetSecurity
- wminet_utils.dll.BlessIWbemServices
- wminet_utils.dll.BlessIWbemServicesObject
- wminet_utils.dll.GetPropertyHandle
- wminet_utils.dll.WritePropertyValue
- wminet_utils.dll.Clone
- wminet_utils.dll.VerifyClientKey
- wminet_utils.dll.GetQualifierSet
- wminet_utils.dll.Get
- wminet_utils.dll.Put
- wminet_utils.dll.Delete
- wminet_utils.dll.GetNames
- wminet_utils.dll.BeginEnumeration
- wminet_utils.dll.Next
- wminet_utils.dll.EndEnumeration
- wminet_utils.dll.GetPropertyQualifierSet
- wminet_utils.dll.GetObjectText
- wminet_utils.dll.SpawnDerivedClass
- wminet_utils.dll.SpawnInstance
- wminet_utils.dll.CompareTo
- wminet_utils.dll.GetPropertyOrigin
- wminet_utils.dll.InheritsFrom
- wminet_utils.dll.GetMethod
- wminet_utils.dll.PutMethod
- wminet_utils.dll.DeleteMethod
- wminet_utils.dll.BeginMethodEnumeration
- wminet_utils.dll.NextMethod
- wminet_utils.dll.EndMethodEnumeration
- wminet_utils.dll.GetMethodQualifierSet
- wminet_utils.dll.GetMethodOrigin
- wminet_utils.dll.QualifierSet_Get
- wminet_utils.dll.QualifierSet_Put
- wminet_utils.dll.QualifierSet_Delete
- wminet_utils.dll.QualifierSet_GetNames
- wminet_utils.dll.QualifierSet_BeginEnumeration
- wminet_utils.dll.QualifierSet_Next
- wminet_utils.dll.QualifierSet_EndEnumeration
- wminet_utils.dll.GetCurrentApartmentType
- wminet_utils.dll.GetDemultiplexedStub
- wminet_utils.dll.CreateInstanceEnumWmi
- wminet_utils.dll.CreateClassEnumWmi
- wminet_utils.dll.ExecQueryWmi
- wminet_utils.dll.ExecNotificationQueryWmi
- wminet_utils.dll.PutInstanceWmi
- wminet_utils.dll.PutClassWmi
- wminet_utils.dll.CloneEnumWbemClassObject
- wminet_utils.dll.ConnectServerWmi
- kernel32.dll.GetThreadPreferredUILanguages
- kernel32.dll.SetThreadPreferredUILanguages
- kernel32.dll.GetSystemDefaultLocaleName
- oleaut32.dll.SysStringLen
- kernel32.dll.RtlZeroMemory
- ole32.dll.CoUninitialize
- oleaut32.dll.#500
- oleaut32.dll.#283
- oleaut32.dll.#284
- oleaut32.dll.#149
- bcrypt.dll.BCryptGetFipsAlgorithmMode
- cryptsp.dll.CryptGetDefaultProviderW
- kernel32.dll.GetCurrentThread
- kernel32.dll.DuplicateHandle
- user32.dll.GetKeyboardLayout
- kernel32.dll.IsWow64Process
- kernel32.dll.ExpandEnvironmentStringsW
- kernel32.dll.FindFirstFileW
- kernel32.dll.FindClose
- kernel32.dll.FindNextFileW
- kernel32.dll.UnmapViewOfFile
- oleaut32.dll.#200
- kernel32.dll.LocalFree
- crypt32.dll.CryptUnprotectData
- kernel32.dll.FormatMessageW
- advapi32.dll.LookupPrivilegeValueW
- advapi32.dll.AdjustTokenPrivileges
- ntdll.dll.NtQuerySystemInformation
- gdiplus.dll.GdiplusStartup
- user32.dll.GetWindowInfo
- user32.dll.GetAncestor
- user32.dll.GetMonitorInfoA
- user32.dll.EnumDisplayMonitors
- user32.dll.EnumDisplayDevicesA
- gdi32.dll.ExtTextOutW
- gdi32.dll.GdiIsMetaPrintDC
- gdiplus.dll.GdipCreateBitmapFromScan0
- gdiplus.dll.GdipGetImagePixelFormat
- gdiplus.dll.GdipGetImageGraphicsContext
- gdiplus.dll.GdipSetInterpolationMode
- gdiplus.dll.GdipSetPixelOffsetMode
- gdiplus.dll.GdipSetSmoothingMode
- gdi32.dll.GetCurrentObject
- gdiplus.dll.GdipGetDC
- gdi32.dll.BitBlt
- gdiplus.dll.GdipReleaseDC
- gdiplus.dll.GdipDeleteGraphics
- gdiplus.dll.GdipGetImageEncodersSize
- gdiplus.dll.GdipGetImageEncoders
- gdiplus.dll.GdipSaveImageToStream
- windowscodecs.dll.DllGetClassObject
- kernel32.dll.WerRegisterMemoryBlock
- oleaut32.dll.#10
- user32.dll.GetKeyboardLayoutList
- vssapi.dll.CreateWriter
- advapi32.dll.LookupAccountNameW
- samcli.dll.NetLocalGroupGetMembers
- samlib.dll.SamConnect
- rpcrt4.dll.NdrClientCall3
- rpcrt4.dll.RpcStringBindingComposeW
- rpcrt4.dll.RpcBindingFromStringBindingW
- rpcrt4.dll.RpcStringFreeW
- rpcrt4.dll.RpcBindingFree
- samlib.dll.SamOpenDomain
- samlib.dll.SamLookupNamesInDomain
- samlib.dll.SamOpenAlias
- samlib.dll.SamFreeMemory
- samlib.dll.SamCloseHandle
- samlib.dll.SamGetMembersInAlias
- netutils.dll.NetApiBufferFree
- ole32.dll.StringFromCLSID
- oleaut32.dll.#4
- oleaut32.dll.#7
- propsys.dll.VariantToPropVariant
- wbemcore.dll.Reinitialize
- wbemsvc.dll.DllGetClassObject
- wbemsvc.dll.DllCanUnloadNow
- authz.dll.AuthzInitializeContextFromToken
- authz.dll.AuthzInitializeObjectAccessAuditEvent2
- authz.dll.AuthzAccessCheck
- authz.dll.AuthzFreeAuditEvent
- authz.dll.AuthzFreeContext
- authz.dll.AuthzInitializeResourceManager
- authz.dll.AuthzFreeResourceManager
- rpcrt4.dll.RpcBindingCreateW
- rpcrt4.dll.RpcBindingBind
- rpcrt4.dll.I_RpcMapWin32Status
- kernel32.dll.RegCloseKey
- kernel32.dll.RegSetValueExW
- kernel32.dll.RegOpenKeyExW
- kernel32.dll.RegQueryValueExW
- wmisvc.dll.IsImproperShutdownDetected
- wevtapi.dll.EvtRender
- wevtapi.dll.EvtNext
- wevtapi.dll.EvtClose
- wevtapi.dll.EvtQuery
- wevtapi.dll.EvtCreateRenderContext
- rpcrt4.dll.RpcBindingSetAuthInfoExW
- rpcrt4.dll.RpcBindingSetOption
- ole32.dll.CreateStreamOnHGlobal
- advapi32.dll.RegCreateKeyExW
- advapi32.dll.RegSetValueExW
- kernelbase.dll.InitializeAcl
- kernelbase.dll.AddAce
- sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
- kernel32.dll.IsThreadAFiber
- kernel32.dll.OpenProcessToken
- kernelbase.dll.GetTokenInformation
- kernelbase.dll.DuplicateTokenEx
- kernelbase.dll.AdjustTokenPrivileges
- kernelbase.dll.AllocateAndInitializeSid
- kernelbase.dll.CheckTokenMembership
- kernel32.dll.SetThreadToken
- ole32.dll.CLSIDFromString
- oleaut32.dll.#19
- oleaut32.dll.#25
- oleaut32.dll.#285
- advapi32.dll.RegOpenKeyW
- oleaut32.dll.#12
- authz.dll.AuthzInitializeContextFromSid
- oleaut32.dll.#286
- ole32.dll.CoGetCallContext
- ole32.dll.CoRevertToSelf
- advapi32.dll.LogonUserExExW
- sspicli.dll.LogonUserExExW
- ole32.dll.CoImpersonateClient
- advapi32.dll.OpenThreadToken
- ole32.dll.CoSwitchCallContext
- oleaut32.dll.#287
- oleaut32.dll.#288
- oleaut32.dll.#289
- ntmarta.dll.GetMartaExtensionInterface
- fastprox.dll.DllGetClassObject
- fastprox.dll.DllCanUnloadNow
- oleaut32.dll.#290
- devobj.dll.DevObjCreateDeviceInfoList
- devobj.dll.DevObjGetClassDevs
- devobj.dll.DevObjEnumDeviceInterfaces
- devobj.dll.DevObjGetDeviceInterfaceDetail
- cfgmgr32.dll.CM_Connect_MachineA
- cfgmgr32.dll.CM_Disconnect_Machine
- cfgmgr32.dll.CM_Locate_DevNodeW
- cfgmgr32.dll.CM_Get_DevNode_Registry_PropertyW
- cfgmgr32.dll.CM_Get_Child
- cfgmgr32.dll.CM_Get_Sibling
- cfgmgr32.dll.CM_Get_DevNode_Status
- cfgmgr32.dll.CM_Get_First_Log_Conf
- cfgmgr32.dll.CM_Get_Next_Res_Des
- cfgmgr32.dll.CM_Get_Res_Des_Data
- cfgmgr32.dll.CM_Get_Res_Des_Data_Size
- cfgmgr32.dll.CM_Free_Log_Conf_Handle
- cfgmgr32.dll.CM_Free_Res_Des_Handle
- cfgmgr32.dll.CM_Get_Device_IDA
- cfgmgr32.dll.CM_Get_Device_ID_Size
- cfgmgr32.dll.CM_Get_Parent
- oleaut32.dll.#26
- oleaut32.dll.#40
- devobj.dll.DevObjDestroyDeviceInfoList
- wmi.dll.WmiQueryAllDataW
- wmi.dll.WmiQuerySingleInstanceW
- wmi.dll.WmiSetSingleItemW
- wmi.dll.WmiSetSingleInstanceW
- wmi.dll.WmiExecuteMethodW
- wmi.dll.WmiNotificationRegistrationW
- wmi.dll.WmiMofEnumerateResourcesW
- wmi.dll.WmiFileHandleToInstanceNameW
- wmi.dll.WmiDevInstToInstanceNameW
- wmi.dll.WmiQueryGuidInformation
- wmi.dll.WmiOpenBlock
- wmi.dll.WmiCloseBlock
- wmi.dll.WmiFreeBuffer
- wmi.dll.WmiEnumerateGuids
- devobj.dll.DevObjEnumDeviceInfo
- setupapi.dll.CM_Open_DevNode_Key_Ex
- devobj.dll.DevObjGetDeviceProperty
- user32.dll.MonitorFromWindow
- user32.dll.MonitorFromRect
- user32.dll.MonitorFromPoint
- user32.dll.EnumDisplayDevicesW
- user32.dll.GetMonitorInfoW
- dxgi.dll.DXGIReportAdapterConfiguration
- setupapi.dll.SetupDiGetClassDevsW
- setupapi.dll.SetupDiEnumDeviceInterfaces
- setupapi.dll.SetupDiGetDeviceInterfaceDetailW
- setupapi.dll.SetupDiDestroyDeviceInfoList
- gdi32.dll.D3DKMTOpenAdapterFromDeviceName
- gdi32.dll.D3DKMTQueryAdapterInfo
- gdi32.dll.D3DKMTGetDisplayModeList
- gdi32.dll.D3DKMTCloseAdapter
- wintrust.dll.WinVerifyTrust
- winbrand.dll.BrandingLoadString
- security.dll.InitSecurityInterfaceW
- cryptsp.dll.SystemFunction035
- schannel.dll.SpUserModeInitialize
- ntdll.dll.RtlInitUnicodeString
- ntdll.dll.RtlFreeUnicodeString
- ntdll.dll.NtSetSystemEnvironmentValue
- ntdll.dll.NtQuerySystemEnvironmentValue
- ntdll.dll.NtCreateFile
- ntdll.dll.NtQueryDirectoryObject
- ntdll.dll.NtQueryObject
- ntdll.dll.NtOpenDirectoryObject
- ntdll.dll.NtQueryInformationProcess
- ntdll.dll.NtQueryInformationToken
- ntdll.dll.NtOpenFile
- ntdll.dll.NtClose
- ntdll.dll.NtFsControlFile
- ntdll.dll.NtQueryVolumeInformationFile
- netapi32.dll.NetGroupEnum
- netapi32.dll.NetGroupGetInfo
- netapi32.dll.NetGroupSetInfo
- netapi32.dll.NetLocalGroupGetInfo
- netapi32.dll.NetLocalGroupSetInfo
- netapi32.dll.NetGroupGetUsers
- netapi32.dll.NetLocalGroupGetMembers
- netapi32.dll.NetLocalGroupEnum
- netapi32.dll.NetShareEnum
- netapi32.dll.NetShareGetInfo
- netapi32.dll.NetShareAdd
- netapi32.dll.NetShareEnumSticky
- netapi32.dll.NetShareSetInfo
- netapi32.dll.NetShareDel
- netapi32.dll.NetShareDelSticky
- netapi32.dll.NetShareCheck
- netapi32.dll.NetUserEnum
- netapi32.dll.NetUserGetInfo
- netapi32.dll.NetUserSetInfo
- netapi32.dll.NetApiBufferFree
- netapi32.dll.NetQueryDisplayInformation
- netapi32.dll.NetServerSetInfo
- netapi32.dll.NetServerGetInfo
- netapi32.dll.NetGetDCName
- netapi32.dll.NetWkstaGetInfo
- netapi32.dll.NetGetAnyDCName
- netapi32.dll.NetServerEnum
- netapi32.dll.NetUserModalsGet
- netapi32.dll.NetScheduleJobAdd
- netapi32.dll.NetScheduleJobDel
- netapi32.dll.NetScheduleJobEnum
- netapi32.dll.NetScheduleJobGetInfo
- netapi32.dll.NetUseGetInfo
- netapi32.dll.NetEnumerateTrustedDomains
- netapi32.dll.DsGetDcNameW
- netapi32.dll.DsRoleGetPrimaryDomainInformation
- netapi32.dll.DsRoleFreeMemory
- netapi32.dll.NetRenameMachineInDomain
- netapi32.dll.NetJoinDomain
- netapi32.dll.NetUnjoinDomain
- wkscli.dll.NetWkstaGetInfo
- cscapi.dll.CscNetApiGetInterface
- kernel32.dll.GetDiskFreeSpaceExW
- kernel32.dll.GetVolumePathNameW
- kernel32.dll.Thread32First
- kernel32.dll.Thread32Next
- kernel32.dll.Process32First
- kernel32.dll.Process32Next
- kernel32.dll.Heap32ListFirst
- kernel32.dll.GlobalMemoryStatusEx
- kernel32.dll.GetSystemDefaultUILanguage
- oleaut32.dll.#150
- wtsapi32.dll.WTSEnumerateSessionsW
- winsta.dll.WinStationEnumerateW
- advapi32.dll.CreateWellKnownSid
- winsta.dll.WinStationFreeMemory
- wtsapi32.dll.WTSQuerySessionInformationW
- winsta.dll.WinStationQueryInformationW
- wtsapi32.dll.WTSFreeMemory
- powrprof.dll.PowerDeterminePlatformRole
- Show More 581
- HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
- HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
-
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
- HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
- HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fe3658635c66bb8b0981fe3f73cebf1b229ed661.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
- HKEY_CURRENT_USER\Software\Microsoft\Fusion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
- HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
- HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
- HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index20
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.0.0.___461d39c4a423da0b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.0.0.___461d39c4a423da0b
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.1.9.Tombolas__461d39c4a423da0b
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.1.9.Tombolas__461d39c4a423da0b
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\TZI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\Dynamic DST
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\MUI_Display
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\MUI_Std
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time\MUI_Dlt
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationFramework__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationFramework__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.WindowsBase__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.WindowsBase__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xaml__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xaml__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationCore__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationCore__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.UIAutomationTypes__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.UIAutomationTypes__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Input.Manipulations__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Input.Manipulations__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.UIAutomationProvider__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.UIAutomationProvider__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.ReachFramework__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.ReachFramework__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationUI__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationUI__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Printing__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Printing__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\Software\Microsoft\Net Framework Setup\NDP\v4\Client
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\InstallPath
- HKEY_LOCAL_MACHINE\Software\Microsoft\Avalon.Graphics
- HKEY_CURRENT_USER\Software\Microsoft\Avalon.Graphics
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.ServiceModel__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.ServiceModel__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.IdentityModel__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.IdentityModel__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.SMDiagnostics__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.SMDiagnostics__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.ServiceModel.Internals__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.ServiceModel.Internals__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data.SqlXml__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data.SqlXml__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Transactions__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Transactions__b77a5c561934e089
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.EnterpriseServices__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.EnterpriseServices__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
- Policy\Standards
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\.NETFramework\XML
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\XML
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Microsoft.CSharp__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Microsoft.CSharp__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
- HKEY_CLASSES_ROOT\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default)
- HKEY_CURRENT_USER\Software\Classes
- HKEY_CURRENT_USER\Software\Classes\AppID\fe3658635c66bb8b0981fe3f73cebf1b229ed661.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
- HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
- HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\67658C14
- HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
- HKEY_CLASSES_ROOT\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
- HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
- HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
- HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
- HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
- HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductName
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CSDVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Web.Extensions__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Web.Extensions__31bf3856ad364e35
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Web__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Web__b03f5f7f11d50a3a
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
- HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
- HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
- HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Namespaces
- HKEY_USERS\S-1-5-20_Classes
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\LocalServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalServer32\ServerExecutable
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppID
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LocalService
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\DllSurrogate
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RunAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ActivateAtStorage
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\ROTFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AppIDFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LaunchPermission
- HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\AuthenticationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\RemoteServerName
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\SRPTrustLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\PreferredServerBitness
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\LoadUserSettings
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Elevation
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVBOX_HARDDISK___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\Properties
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&2617AEAE&0&0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_2829&SUBSYS_00000000&REV_02\3&267A616A&0&68\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HTREE\ROOT\0\ClassGUID
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Capabilities
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\ConfigFlags
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\LogConf
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\LogConf\ForcedConfig
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\DeviceDesc
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\LocaleName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\FriendlyName
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVBOX_HARDDISK___________________________1.0_____\5&33D1638A&0&0.0.0\Mfg
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Phantom
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Driver
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Type
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000003\00000000\Data
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\DeviceDesc
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Mfg
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Capabilities
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\ConfigFlags
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\LogConf\ForcedConfig
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Service
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{1ca05180-a699-450a-9a0c-de4fbe3ddd89}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\##?#PCI#VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00#3&267a616a&0&10#{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\#
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\##?#PCI#VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00#3&267a616a&0&10#{1ca05180-a699-450a-9a0c-de4fbe3ddd89}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\##?#PCI#VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00#3&267a616a&0&10#{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\DeviceInstance
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{1ca05180-a699-450a-9a0c-de4fbe3ddd89}\Properties
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Type
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_80EE&DEV_BEEF&SUBSYS_00000000&REV_00\3&267A616A&0&10\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}\00000002\00000000\Data
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\LocalService
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\ServiceParameters
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\RunAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\ActivateAtStorage
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\ROTFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\AppIDFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\LaunchPermission
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\AuthenticationLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\RemoteServerName
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\SRPTrustLevel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\PreferredServerBitness
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{653C5148-4DCE-4905-9CFD-1B23662D3D9E}\LoadUserSettings
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\#
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\Properties
- HKEY_LOCAL_MACHINE\HARDWARE\ACPI\FADT
- HKEY_LOCAL_MACHINE\HARDWARE\ACPI\FADT\VBOX__
- HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\SYSTEM\Setup
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
- HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
- HKEY_LOCAL_MACHINE\Software\Classes
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
- HKEY_LOCAL_MACHINE\system\Setup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{03C7CC0E-7BA8-419A-97FE-A9C01F4C21DD}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{33BA5F3E-D522-4790-9606-996791BE526A}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{424FB2AE-F997-4143-8C27-9CA8AB4B394D}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B9DE0FC4-7656-434B-89A3-4D7E60FF294B}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
- HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
- HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cimv2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cimv2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
- HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
- HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
- HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
- HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
- HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
- HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
- HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\CIMV2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\CIMV2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter
- HKEY_CLASSES_ROOT\CLSID\{04788120-12C2-498d-83C1-A7D92E677AC6}\InProcServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InprocServer32\(Default)
- HKEY_CLASSES_ROOT\CLSID\{04788120-12C2-498d-83C1-A7D92E677AC6}\LocalServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\InprocServer32\Synchronization
- HKEY_CLASSES_ROOT\CLSID\{04788120-12C2-498d-83C1-A7D92E677AC6}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04788120-12C2-498D-83C1-A7D92E677AC6}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="Cimwin32A"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
- HKEY_CURRENT_USER
- HKEY_CURRENT_USER\Control Panel\International
- HKEY_CURRENT_USER\Control Panel\International\LocaleName
- HKEY_CURRENT_USER\Control Panel\International\sCountry
- HKEY_CURRENT_USER\Control Panel\International\sList
- HKEY_CURRENT_USER\Control Panel\International\sDecimal
- HKEY_CURRENT_USER\Control Panel\International\sThousand
- HKEY_CURRENT_USER\Control Panel\International\sGrouping
- HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
- HKEY_CURRENT_USER\Control Panel\International\sCurrency
- HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
- HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
- HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
- HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
- HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
- HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
- HKEY_CURRENT_USER\Control Panel\International\sShortTime
- HKEY_CURRENT_USER\Control Panel\International\s1159
- HKEY_CURRENT_USER\Control Panel\International\s2359
- HKEY_CURRENT_USER\Control Panel\International\sShortDate
- HKEY_CURRENT_USER\Control Panel\International\sYearMonth
- HKEY_CURRENT_USER\Control Panel\International\sLongDate
- HKEY_CURRENT_USER\Control Panel\International\iCountry
- HKEY_CURRENT_USER\Control Panel\International\iMeasure
- HKEY_CURRENT_USER\Control Panel\International\iPaperSize
- HKEY_CURRENT_USER\Control Panel\International\iDigits
- HKEY_CURRENT_USER\Control Panel\International\iLZero
- HKEY_CURRENT_USER\Control Panel\International\iNegNumber
- HKEY_CURRENT_USER\Control Panel\International\NumShape
- HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
- HKEY_CURRENT_USER\Control Panel\International\iCurrency
- HKEY_CURRENT_USER\Control Panel\International\iNegCurr
- HKEY_CURRENT_USER\Control Panel\International\iCalendarType
- HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
- HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
- HKEY_PERFORMANCE_TEXT\Counter
- HKEY_PERFORMANCE_DATA\238
- HKEY_LOCAL_MACHINE\SYSTEM
- HKEY_LOCAL_MACHINE\SOFTWARE
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfPath
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InfSection
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\InstalledDisplayDrivers
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.MemorySize
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.ChipType
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\HardwareInformation.DACType
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SecurityProviders
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Name
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Comment
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Capabilities
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\RpcId
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Version
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\Type
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\credssp.dll\TokenSize
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextLockCount
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\UserContextListCount
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sCountry
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sList
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sDecimal
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sThousand
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sGrouping
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sNativeDigits
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sCurrency
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sMonDecimalSep
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sMonThousandSep
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sMonGrouping
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sPositiveSign
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sNegativeSign
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sTimeFormat
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sShortTime
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\s1159
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\s2359
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sShortDate
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sYearMonth
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\sLongDate
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCountry
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iMeasure
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iPaperSize
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iDigits
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iLZero
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iNegNumber
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\NumShape
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCurrDigits
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCurrency
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iNegCurr
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iCalendarType
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iFirstDayOfWeek
- HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Control Panel\International\iFirstWeekOfYear
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Plus! ProductId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\CurrentType
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemPartition
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PriorityControl\Win32PrioritySeparation
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseInfo\FilePrint
- HKEY_USERS\S-1-5-18
- HKEY_USERS\.DEFAULT\Control Panel\International
- HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
- HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
- HKEY_USERS\.DEFAULT\Control Panel\International\sList
- HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
- HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
- HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
- HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
- HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
- HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
- HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
- HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
- HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
- HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
- HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
- HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
- HKEY_USERS\.DEFAULT\Control Panel\International\s1159
- HKEY_USERS\.DEFAULT\Control Panel\International\s2359
- HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
- HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
- HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
- HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
- HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
- HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
- HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
- HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
- HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
- HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
- HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
- HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
- HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
- HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
- HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
- HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\MEMORY MANAGEMENT\PagingFiles
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TimeZoneInformation
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation\DisableAutoDaylightTimeSet
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl\AutoReboot
- HKEY_LOCAL_MACHINE\HARDWARE\Description\System
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\Identifier
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosDate
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
- Show More 754
- \Device\KsecDD
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
- C:\Windows\System32\MSVCR120_CLR0400.dll
- C:\Users\user\AppData\Local\Temp\fe3658635c66bb8b0981fe3f73cebf1b229ed661.exe.config
-
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
- C:\Windows\assembly\pubpol20.dat
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5aac750b35b27770dccb1a43f83cced7\System.Windows.Forms.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\52cca48930e580e3189eac47158c20be\System.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\52cca48930e580e3189eac47158c20be\System.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\646b4b01cb29986f8e076aa65c9e9753\System.Drawing.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\646b4b01cb29986f8e076aa65c9e9753\System.Drawing.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5aac750b35b27770dccb1a43f83cced7\System.Windows.Forms.ni.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
- C:\Windows\System32\tzres.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
- C:\Windows\System32\en-US\tzres.dll.mui
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\da36abbea6ef456f432434d4d8d835c1\PresentationFramework.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\32512bd09e2231f6eebb15fc17e3ad79\WindowsBase.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\55560c2014611e9119f99923c9ebdeef\System.Core.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\55560c2014611e9119f99923c9ebdeef\System.Core.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\32512bd09e2231f6eebb15fc17e3ad79\WindowsBase.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\416ba33cb980d07643e82c4c45bd5786\PresentationCore.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\416ba33cb980d07643e82c4c45bd5786\PresentationCore.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\da36abbea6ef456f432434d4d8d835c1\PresentationFramework.ni.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d86b080a37c60a872c82b912a2a63dac\System.Xml.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d86b080a37c60a872c82b912a2a63dac\System.Xml.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\46957030830964165644b52b0696c5d9\System.Configuration.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\46957030830964165644b52b0696c5d9\System.Configuration.ni.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\e7044d177c8e852b85908d2702898ec8\System.Transactions.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\e7044d177c8e852b85908d2702898ec8\System.Transactions.ni.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll.config
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4dfa27fdd6a4cce26f99585e1c744f9b\System.Management.ni.dll.aux
- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4dfa27fdd6a4cce26f99585e1c744f9b\System.Management.ni.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll
- C:\Windows\Microsoft.Net\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
- C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
- C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data
- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\jdm2a1on.default\cookies.sqlite
- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
- C:\Windows\sysnative\wbem\WmiPrvSE.exe
- C:\Windows\inf\disk.PNF
- C:\Windows\inf\oem16.PNF
- \??\PIPE\samr
- C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
- C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
- C:\Windows\sysnative\wbem\repository\INDEX.BTR
- \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
- \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
- \??\ide#diskvbox_harddisk___________________________1.0_____#5&33d1638a&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
- \??\WMIDataDevice
- C:\Windows\Branding\Basebrd\basebrd.dll
- C:
- C:\Windows\sysnative\tzres.dll
- \??\PIPE\wkssvc
- \??\PIPE\srvsvc
- \??\PHYSICALDRIVE0
- \??\ide#cdromvbox_cd-rom_____________________________1.0_____#5&106af171&0&1.0.0#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
- \??\CDROM0
- \??\PIPE\lsarpc
- C:\Windows\sysnative\OemInfo.Ini
- C:\Windows\sysnative\OemLogo.Bmp
- Show More 79
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
-
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
- Show More 2