Analysis

Category Package Started Completed Duration Options Log
FILE Extraction 2019-08-13 15:46:59 2019-08-13 15:51:04 245 seconds Show Options Show Log
procmemdump = 1
import_reconstruction = 1
procdump = 0
route = internet
2019-08-13 16:47:00,000 [root] INFO: Date set to: 08-13-19, time set to: 15:47:00, timeout set to: 200
2019-08-13 16:47:00,046 [root] DEBUG: Starting analyzer from: C:\exrhhyewq
2019-08-13 16:47:00,046 [root] DEBUG: Storing results at: C:\fOcJxESUJT
2019-08-13 16:47:00,062 [root] DEBUG: Pipe server name: \\.\PIPE\xFpBNAZ
2019-08-13 16:47:00,062 [root] INFO: Analysis package "Extraction" has been specified.
2019-08-13 16:47:02,012 [root] DEBUG: Started auxiliary module Browser
2019-08-13 16:47:02,012 [root] DEBUG: Started auxiliary module Curtain
2019-08-13 16:47:02,012 [modules.auxiliary.digisig] DEBUG: Checking for a digitial signature.
2019-08-13 16:47:03,197 [modules.auxiliary.digisig] DEBUG: File is not signed.
2019-08-13 16:47:03,197 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2019-08-13 16:47:03,197 [root] DEBUG: Started auxiliary module DigiSig
2019-08-13 16:47:03,213 [root] DEBUG: Started auxiliary module Disguise
2019-08-13 16:47:03,213 [root] DEBUG: Started auxiliary module Human
2019-08-13 16:47:03,213 [root] DEBUG: Started auxiliary module Screenshots
2019-08-13 16:47:03,229 [root] DEBUG: Started auxiliary module Sysmon
2019-08-13 16:47:03,229 [root] DEBUG: Started auxiliary module Usage
2019-08-13 16:47:03,229 [root] INFO: Analyzer: DLL set to Extraction.dll from package modules.packages.Extraction
2019-08-13 16:47:03,229 [root] INFO: Analyzer: DLL_64 set to Extraction_x64.dll from package modules.packages.Extraction
2019-08-13 16:47:03,290 [lib.api.process] INFO: Successfully executed process from path "C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe" with arguments "" with pid 420
2019-08-13 16:47:03,290 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:47:03,290 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:47:03,290 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:47:03,290 [lib.api.process] INFO: 32-bit DLL to inject is C:\exrhhyewq\dll\HwRqvw.dll, loader C:\exrhhyewq\bin\jzciJjf.exe
2019-08-13 16:47:03,415 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:47:03,415 [root] DEBUG: Loader: Injecting process 420 (thread 264) with C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:03,415 [root] DEBUG: Process image base: 0x00400000
2019-08-13 16:47:03,431 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:03,431 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x004ED000 - 0x77110000
2019-08-13 16:47:03,431 [root] DEBUG: InjectDllViaIAT: Allocated 0x164 bytes for new import table at 0x004F0000.
2019-08-13 16:47:03,431 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-13 16:47:03,431 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:03,431 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 420
2019-08-13 16:47:05,444 [lib.api.process] INFO: Successfully resumed process with pid 420
2019-08-13 16:47:05,444 [root] INFO: Added new process to list with pid: 420
2019-08-13 16:47:06,130 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:47:06,130 [root] DEBUG: Process dumps disabled.
2019-08-13 16:47:06,130 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:47:06,130 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:47:06,552 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-13 16:47:06,552 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:06,566 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:06,566 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:06,566 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:06,566 [root] DEBUG: WoW64 detected: 64-bit ntdll base: 0x77110000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7716124a, Wow64PrepareForException: 0x0
2019-08-13 16:47:06,566 [root] DEBUG: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x230000
2019-08-13 16:47:06,566 [root] DEBUG: Debugger initialised.
2019-08-13 16:47:06,566 [root] DEBUG: CAPE initialised: 32-bit Extraction v2 loaded in process 420 at 0x747e0000, image base 0x400000, stack from 0x186000-0x190000
2019-08-13 16:47:06,566 [root] DEBUG: Commandline: C:\Users\user\AppData\Local\Temp\"C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe".
2019-08-13 16:47:06,582 [root] DEBUG: AddTrackedRegion: EntryPoint 0x1948, Entropy 5.440585e+00
2019-08-13 16:47:06,582 [root] DEBUG: AddTrackedRegion: Region at 0x00400000 size 0x1000 added to tracked regions.
2019-08-13 16:47:06,582 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:47:06,582 [root] INFO: Monitor successfully loaded in process with pid 420.
2019-08-13 16:47:07,051 [root] DEBUG: AddTrackedRegion: Region at 0x00240000 size 0x6000 added to tracked regions.
2019-08-13 16:47:07,051 [root] DEBUG: ProtectionHandler: Address: 0x00240000 (alloc base 0x00240000), NumberOfBytesToProtect: 0x6000, NewAccessProtection: 0x20
2019-08-13 16:47:07,051 [root] DEBUG: ProtectionHandler: New code detected at (0x00240000), scanning for PE images.
2019-08-13 16:47:07,051 [root] DEBUG: DumpPEsInRange: Scanning range 0x00240000 - 0x00246000.
2019-08-13 16:47:07,065 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x240000-0x246000.
2019-08-13 16:47:07,065 [root] DEBUG: DumpPEsInRange: Scanning range 0x00240000 - 0x00246000.
2019-08-13 16:47:07,065 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x240000-0x246000.
2019-08-13 16:47:07,065 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x00240000, TrackedRegion->RegionSize: 0x6000, thread 264
2019-08-13 16:47:07,065 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xe0, Size=0x0, Address=0x00240000 and Type=0x1.
2019-08-13 16:47:07,176 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 264 type 1 at address 0x00240000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:07,176 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x00240000
2019-08-13 16:47:07,176 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xe0, Size=0x4, Address=0x0024003C and Type=0x1.
2019-08-13 16:47:07,176 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 264 type 1 at address 0x0024003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:07,176 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0024003C
2019-08-13 16:47:07,176 [root] DEBUG: ProtectionHandler: Breakpoints set on executable region at: 0x00240000.
2019-08-13 16:47:07,190 [root] DEBUG: DLL loaded at 0x74970000: C:\Windows\system32\SXS (0x5f000 bytes).
2019-08-13 16:47:07,440 [root] DEBUG: ProtectionHandler: Address 0x00240000 already in tracked region at 0x00240000.
2019-08-13 16:47:07,456 [root] DEBUG: ProtectionHandler: Address: 0x00240000 (alloc base 0x00240000), NumberOfBytesToProtect: 0xa000, NewAccessProtection: 0x20
2019-08-13 16:47:07,456 [root] DEBUG: ProtectionHandler: Increased region size at 0x00240000 to 0xa000.
2019-08-13 16:47:07,456 [root] DEBUG: ProtectionHandler: New code detected at (0x00240000), scanning for PE images.
2019-08-13 16:47:07,456 [root] DEBUG: DumpPEsInRange: Scanning range 0x00240000 - 0x0024A000.
2019-08-13 16:47:07,456 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x240000-0x24a000.
2019-08-13 16:47:07,456 [root] DEBUG: DumpPEsInRange: Scanning range 0x00240000 - 0x0024A000.
2019-08-13 16:47:07,456 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x240000-0x24a000.
2019-08-13 16:47:07,456 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x00240000, TrackedRegion->RegionSize: 0xa000, thread 264
2019-08-13 16:47:07,456 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xe0, Size=0x0, Address=0x00240000 and Type=0x1.
2019-08-13 16:47:07,456 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 264 type 1 at address 0x00240000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:07,471 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x00240000
2019-08-13 16:47:07,471 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xe0, Size=0x4, Address=0x0024003C and Type=0x1.
2019-08-13 16:47:07,471 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 264 type 1 at address 0x0024003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:07,471 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0024003C
2019-08-13 16:47:07,471 [root] DEBUG: ProtectionHandler: Breakpoints set on executable region at: 0x00240000.
2019-08-13 16:47:08,377 [root] DEBUG: DLL loaded at 0x74960000: C:\Windows\system32\VERSION (0x9000 bytes).
2019-08-13 16:47:08,377 [root] DEBUG: DLL unloaded from 0x00400000.
2019-08-13 16:47:08,424 [root] DEBUG: Allocation: 0x00510000 - 0x00517000, size: 0x7000, protection: 0x40.
2019-08-13 16:47:08,424 [root] DEBUG: AddTrackedRegion: Region at 0x00510000 size 0x7000 added to tracked regions.
2019-08-13 16:47:08,424 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x00510000, TrackedRegion->RegionSize: 0x7000, thread 264
2019-08-13 16:47:08,424 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x00240000 to 0x00510000.
2019-08-13 16:47:08,424 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xe0, Size=0x0, Address=0x00510000 and Type=0x1.
2019-08-13 16:47:08,424 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 264 type 1 at address 0x00510000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:08,424 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x00510000
2019-08-13 16:47:08,424 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xe0, Size=0x4, Address=0x0051003C and Type=0x1.
2019-08-13 16:47:08,424 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 264 type 1 at address 0x0051003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:08,424 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0051003C
2019-08-13 16:47:08,424 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x00510000 (size 0x7000).
2019-08-13 16:47:13,868 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:47:13,868 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x004AD073 (thread 264)
2019-08-13 16:47:13,868 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x0051003C.
2019-08-13 16:47:13,868 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header too big: 0x18cde9 (at 0x0051003C).
2019-08-13 16:47:13,868 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x004AD073 (thread 264)
2019-08-13 16:47:13,884 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x00510000.
2019-08-13 16:47:13,884 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x00510000 and Type=0x0.
2019-08-13 16:47:13,884 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x510000: 0x41.
2019-08-13 16:47:13,884 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:13,884 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x00510000 (thread 264)
2019-08-13 16:47:13,884 [root] DEBUG: ShellcodeExecCallback: Breakpoint 2 at Address 0x00510000 (allocation base 0x00510000).
2019-08-13 16:47:13,884 [root] DEBUG: ShellcodeExecCallback: Debug: About to scan region for a PE image (base 0x00510000, size 0x7000).
2019-08-13 16:47:13,884 [root] DEBUG: DumpPEsInRange: Scanning range 0x00510000 - 0x00517000.
2019-08-13 16:47:13,884 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x510000-0x517000.
2019-08-13 16:47:13,930 [root] DEBUG: DumpMemory: CAPE output file C:\fOcJxESUJT\CAPE\420_8409118001372213282019 successfully created, size 0x7000
2019-08-13 16:47:13,946 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\420_8409118001372213282019
2019-08-13 16:47:13,946 [root] DEBUG: ShellcodeExecCallback: successfully dumped memory range at 0x00510000 (size 0x7000).
2019-08-13 16:47:13,946 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x510000 - 0x517000.
2019-08-13 16:47:13,946 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 0 address 0x00510000.
2019-08-13 16:47:13,946 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 264.
2019-08-13 16:47:13,946 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 1 address 0x0051003C.
2019-08-13 16:47:13,946 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 264.
2019-08-13 16:47:13,946 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 2 address 0x00510000.
2019-08-13 16:47:13,946 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 264.
2019-08-13 16:47:13,946 [root] DEBUG: set_caller_info: Adding region at 0x00510000 to caller regions list.
2019-08-13 16:47:15,973 [root] DEBUG: Allocation: 0x04300000 - 0x08300000, size: 0x4000000, protection: 0x40.
2019-08-13 16:47:15,973 [root] DEBUG: AddTrackedRegion: Region at 0x04300000 size 0x4000000 added to tracked regions.
2019-08-13 16:47:15,973 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x04300000, TrackedRegion->RegionSize: 0x4000000, thread 264
2019-08-13 16:47:15,973 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x00510000 to 0x04300000.
2019-08-13 16:47:15,973 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xe0, Size=0x0, Address=0x04300000 and Type=0x1.
2019-08-13 16:47:15,973 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 264 type 1 at address 0x04300000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:15,973 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x04300000
2019-08-13 16:47:15,973 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xe0, Size=0x4, Address=0x0430003C and Type=0x1.
2019-08-13 16:47:15,973 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 264 type 1 at address 0x0430003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:15,973 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0430003C
2019-08-13 16:47:15,973 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x04300000 (size 0x4000000).
2019-08-13 16:47:15,973 [root] DEBUG: DLL loaded at 0x75E70000: C:\Windows\syswow64\shell32 (0xc4a000 bytes).
2019-08-13 16:47:16,020 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,020 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x04300000.
2019-08-13 16:47:16,020 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x04300000 and Type=0x0.
2019-08-13 16:47:16,020 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x4300000: 0x0.
2019-08-13 16:47:16,020 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:16,020 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,020 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x04300000.
2019-08-13 16:47:16,020 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x04300000 already exists for thread 264 (process 420), skipping.
2019-08-13 16:47:16,020 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x4300000: 0x0.
2019-08-13 16:47:16,020 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:16,020 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,020 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x04300000.
2019-08-13 16:47:16,036 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x04300000 already exists for thread 264 (process 420), skipping.
2019-08-13 16:47:16,036 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x4300000: 0x0.
2019-08-13 16:47:16,036 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:16,036 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,036 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x04300000.
2019-08-13 16:47:16,036 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x04300000 already exists for thread 264 (process 420), skipping.
2019-08-13 16:47:16,036 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x4300000: 0x0.
2019-08-13 16:47:16,036 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:16,036 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x0430003C.
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:16,036 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x0430003C.
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:16,036 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x0430003C.
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:16,036 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0051037B (thread 264)
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x0430003C.
2019-08-13 16:47:16,036 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:16,052 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x00510C6E (thread 264)
2019-08-13 16:47:16,052 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x04300000.
2019-08-13 16:47:16,052 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x04300000 already exists for thread 264 (process 420), skipping.
2019-08-13 16:47:16,052 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x4300000: 0xd0.
2019-08-13 16:47:16,052 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:16,052 [root] DEBUG: DLL loaded at 0x74AF0000: C:\Windows\system32\apphelp (0x4c000 bytes).
2019-08-13 16:47:16,068 [root] DEBUG: DLL unloaded from 0x00400000.
2019-08-13 16:47:16,098 [root] INFO: Announced 32-bit process name: JJB-175325-_33001.exe pid: 2228
2019-08-13 16:47:16,098 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:47:16,098 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:47:16,098 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:47:16,098 [lib.api.process] INFO: 32-bit DLL to inject is C:\exrhhyewq\dll\HwRqvw.dll, loader C:\exrhhyewq\bin\jzciJjf.exe
2019-08-13 16:47:16,098 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:47:16,098 [root] DEBUG: Loader: Injecting process 2228 (thread 1040) with C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:16,098 [root] DEBUG: Process image base: 0x00400000
2019-08-13 16:47:16,098 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:16,098 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x004ED000 - 0x77110000
2019-08-13 16:47:16,098 [root] DEBUG: InjectDllViaIAT: Allocated 0x164 bytes for new import table at 0x004F0000.
2019-08-13 16:47:16,114 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-13 16:47:16,114 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:16,114 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2228
2019-08-13 16:47:16,114 [root] INFO: Announced 32-bit process name: JJB-175325-_33001.exe pid: 2228
2019-08-13 16:47:16,114 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:47:16,114 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:47:16,114 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:47:16,114 [lib.api.process] INFO: 32-bit DLL to inject is C:\exrhhyewq\dll\HwRqvw.dll, loader C:\exrhhyewq\bin\jzciJjf.exe
2019-08-13 16:47:16,114 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:47:16,114 [root] DEBUG: Loader: Injecting process 2228 (thread 1040) with C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:16,114 [root] DEBUG: Process image base: 0x00400000
2019-08-13 16:47:16,114 [root] DEBUG: InjectDllViaIAT: Modified EP detected, rebasing IAT patch to new image base 0x00400000 (context EP 0x004ACED9)
2019-08-13 16:47:16,114 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:16,114 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2019-08-13 16:47:16,114 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\HwRqvw.dll.
2019-08-13 16:47:16,114 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2228
2019-08-13 16:47:16,114 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 420).
2019-08-13 16:47:16,130 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:47:16,130 [root] INFO: Notified of termination of process with pid 420.
2019-08-13 16:47:16,130 [root] DEBUG: Process dumps disabled.
2019-08-13 16:47:16,130 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:47:16,145 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:47:16,145 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:16,177 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-13 16:47:16,177 [root] DEBUG: WoW64 detected: 64-bit ntdll base: 0x77110000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7716124a, Wow64PrepareForException: 0x0
2019-08-13 16:47:16,191 [root] DEBUG: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x1c0000
2019-08-13 16:47:16,191 [root] DEBUG: Debugger initialised.
2019-08-13 16:47:16,191 [root] DEBUG: CAPE initialised: 32-bit Extraction v2 loaded in process 2228 at 0x747e0000, image base 0x400000, stack from 0x186000-0x190000
2019-08-13 16:47:16,191 [root] DEBUG: Commandline: C:\Users\user\AppData\Local\Temp\C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe".
2019-08-13 16:47:16,191 [root] DEBUG: AddTrackedRegion: EntryPoint 0x1948, Entropy 5.440585e+00
2019-08-13 16:47:16,191 [root] DEBUG: AddTrackedRegion: Region at 0x00400000 size 0x1000 added to tracked regions.
2019-08-13 16:47:16,207 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:47:16,207 [root] INFO: Added new process to list with pid: 2228
2019-08-13 16:47:16,207 [root] INFO: Monitor successfully loaded in process with pid 2228.
2019-08-13 16:47:16,207 [root] DEBUG: Allocation: 0x001D0000 - 0x001D7000, size: 0x7000, protection: 0x40.
2019-08-13 16:47:16,207 [root] DEBUG: AddTrackedRegion: Region at 0x001D0000 size 0x7000 added to tracked regions.
2019-08-13 16:47:16,207 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x001D0000, TrackedRegion->RegionSize: 0x7000, thread 1040
2019-08-13 16:47:16,223 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xcc, Size=0x0, Address=0x001D0000 and Type=0x1.
2019-08-13 16:47:16,223 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 1040 type 1 at address 0x001D0000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:16,223 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x001D0000
2019-08-13 16:47:16,223 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xcc, Size=0x4, Address=0x001D003C and Type=0x1.
2019-08-13 16:47:16,223 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 1040 type 1 at address 0x001D003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:16,223 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x001D003C
2019-08-13 16:47:16,223 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x001D0000 (size 0x7000).
2019-08-13 16:47:16,628 [lib.api.process] WARNING: Unable to find process dump for process 420.
2019-08-13 16:47:16,628 [root] INFO: Process with pid 420 has terminated
2019-08-13 16:47:21,542 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:47:21,542 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x004AD073 (thread 1040)
2019-08-13 16:47:21,542 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x001D003C.
2019-08-13 16:47:21,559 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header too big: 0x18cde9 (at 0x001D003C).
2019-08-13 16:47:21,559 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x004AD073 (thread 1040)
2019-08-13 16:47:21,559 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x001D0000.
2019-08-13 16:47:21,559 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x001D0000 and Type=0x0.
2019-08-13 16:47:21,559 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x1d0000: 0x41.
2019-08-13 16:47:21,559 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:21,559 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D0000 (thread 1040)
2019-08-13 16:47:21,559 [root] DEBUG: ShellcodeExecCallback: Breakpoint 2 at Address 0x001D0000 (allocation base 0x001D0000).
2019-08-13 16:47:21,559 [root] DEBUG: ShellcodeExecCallback: Debug: About to scan region for a PE image (base 0x001D0000, size 0x7000).
2019-08-13 16:47:21,573 [root] DEBUG: DumpPEsInRange: Scanning range 0x001D0000 - 0x001D7000.
2019-08-13 16:47:21,573 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x1d0000-0x1d7000.
2019-08-13 16:47:21,573 [root] DEBUG: DumpMemory: CAPE output file C:\fOcJxESUJT\CAPE\2228_10101946202172213282019 successfully created, size 0x7000
2019-08-13 16:47:21,605 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_10101946202172213282019
2019-08-13 16:47:21,621 [root] DEBUG: ShellcodeExecCallback: successfully dumped memory range at 0x001D0000 (size 0x7000).
2019-08-13 16:47:21,637 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x1d0000 - 0x1d7000.
2019-08-13 16:47:21,637 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 0 address 0x001D0000.
2019-08-13 16:47:21,637 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1040.
2019-08-13 16:47:21,651 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 1 address 0x001D003C.
2019-08-13 16:47:21,667 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1040.
2019-08-13 16:47:21,667 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 2 address 0x001D0000.
2019-08-13 16:47:21,667 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1040.
2019-08-13 16:47:21,684 [root] DEBUG: set_caller_info: Adding region at 0x001D0000 to caller regions list.
2019-08-13 16:47:23,711 [root] DEBUG: Allocation: 0x03E00000 - 0x07E00000, size: 0x4000000, protection: 0x40.
2019-08-13 16:47:23,711 [root] DEBUG: AddTrackedRegion: Region at 0x03E00000 size 0x4000000 added to tracked regions.
2019-08-13 16:47:23,711 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x03E00000, TrackedRegion->RegionSize: 0x4000000, thread 1040
2019-08-13 16:47:23,711 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x001D0000 to 0x03E00000.
2019-08-13 16:47:23,711 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xcc, Size=0x0, Address=0x03E00000 and Type=0x1.
2019-08-13 16:47:23,711 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 1040 type 1 at address 0x03E00000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:23,711 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x03E00000
2019-08-13 16:47:23,711 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xcc, Size=0x4, Address=0x03E0003C and Type=0x1.
2019-08-13 16:47:23,711 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 1040 type 1 at address 0x03E0003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:23,711 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x03E0003C
2019-08-13 16:47:23,711 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x03E00000 (size 0x4000000).
2019-08-13 16:47:23,726 [root] DEBUG: DLL loaded at 0x75E70000: C:\Windows\syswow64\shell32 (0xc4a000 bytes).
2019-08-13 16:47:23,726 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,726 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,726 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x03E00000 and Type=0x0.
2019-08-13 16:47:23,743 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,743 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,743 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,743 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,757 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1040 (process 2228), skipping.
2019-08-13 16:47:23,757 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,757 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,757 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,757 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,773 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1040 (process 2228), skipping.
2019-08-13 16:47:23,773 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,773 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,773 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,773 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,773 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1040 (process 2228), skipping.
2019-08-13 16:47:23,773 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,773 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,773 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,789 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x03E0003C.
2019-08-13 16:47:23,789 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:23,789 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,789 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x03E0003C.
2019-08-13 16:47:23,789 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:23,789 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,789 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x03E0003C.
2019-08-13 16:47:23,789 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:23,789 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D037B (thread 1040)
2019-08-13 16:47:23,805 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x03E0003C.
2019-08-13 16:47:23,805 [root] DEBUG: PEPointerWriteCallback: candidate pointer to PE header zero.
2019-08-13 16:47:23,805 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,805 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,805 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1040 (process 2228), skipping.
2019-08-13 16:47:23,821 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,821 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,821 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,821 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,821 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1040 (process 2228), skipping.
2019-08-13 16:47:23,821 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,821 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,821 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,821 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,821 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1040 (process 2228), skipping.
2019-08-13 16:47:23,821 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,835 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,835 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,835 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03E00000.
2019-08-13 16:47:23,835 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1040 (process 2228), skipping.
2019-08-13 16:47:23,835 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3e00000: 0x0.
2019-08-13 16:47:23,835 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:23,851 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,851 [root] DEBUG: PEPointerWriteCallback: Breakpoint 1 at Address 0x03E0003C.
2019-08-13 16:47:23,851 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 1 within Context, Size=0x2, Address=0x03E000E8 and Type=0x1.
2019-08-13 16:47:23,851 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 3 within Context, Size=0x4, Address=0x03E000F8 and Type=0x1.
2019-08-13 16:47:23,851 [root] DEBUG: PEPointerWriteCallback: set write bp on AddressOfEntryPoint at 0x03E000F8.
2019-08-13 16:47:23,851 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,851 [root] DEBUG: MagicWriteCallback: Breakpoint 1 at Address 0x03E000E8.
2019-08-13 16:47:23,851 [root] DEBUG: GetHookCallerBase: thread 1040 (handle 0xcc), return address 0x001D1739, allocation base 0x001D0000.
2019-08-13 16:47:23,851 [root] DEBUG: MagicWriteCallback: Not in a hooked function, setting callback in enter_hook() to catch next hook (return address 0x001D0000).
2019-08-13 16:47:23,851 [root] DEBUG: MagicWriteCallback: Magic value not valid NT: 0xc0 (at 0x03E000E8).
2019-08-13 16:47:23,851 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,851 [root] DEBUG: MagicWriteCallback: Breakpoint 1 at Address 0x03E000E8.
2019-08-13 16:47:23,868 [root] DEBUG: GetHookCallerBase: thread 1040 (handle 0xcc), return address 0x001D1739, allocation base 0x001D0000.
2019-08-13 16:47:23,868 [root] DEBUG: MagicWriteCallback: Magic value not valid NT: 0xb1c0 (at 0x03E000E8).
2019-08-13 16:47:23,868 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,868 [root] DEBUG: AddressOfEPWriteCallback: Breakpoint 3 at Address 0x03E000F8.
2019-08-13 16:47:23,868 [root] DEBUG: GetHookCallerBase: thread 1040 (handle 0xcc), return address 0x001D1739, allocation base 0x001D0000.
2019-08-13 16:47:23,868 [root] DEBUG: AddressOfEPWriteCallback: Magic value not valid NT: 0xb1c0 (at 0x03E000E8).
2019-08-13 16:47:23,868 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,868 [root] DEBUG: AddressOfEPWriteCallback: Breakpoint 3 at Address 0x03E000F8.
2019-08-13 16:47:23,868 [root] DEBUG: GetHookCallerBase: thread 1040 (handle 0xcc), return address 0x001D1739, allocation base 0x001D0000.
2019-08-13 16:47:23,868 [root] DEBUG: AddressOfEPWriteCallback: Magic value not valid NT: 0xb1c0 (at 0x03E000E8).
2019-08-13 16:47:23,868 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,882 [root] DEBUG: AddressOfEPWriteCallback: Breakpoint 3 at Address 0x03E000F8.
2019-08-13 16:47:23,882 [root] DEBUG: GetHookCallerBase: thread 1040 (handle 0xcc), return address 0x001D1739, allocation base 0x001D0000.
2019-08-13 16:47:23,882 [root] DEBUG: AddressOfEPWriteCallback: Magic value not valid NT: 0xb1c0 (at 0x03E000E8).
2019-08-13 16:47:23,882 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x001D09D0 (thread 1040)
2019-08-13 16:47:23,882 [root] DEBUG: AddressOfEPWriteCallback: Breakpoint 3 at Address 0x03E000F8.
2019-08-13 16:47:23,882 [root] DEBUG: GetHookCallerBase: thread 1040 (handle 0xcc), return address 0x001D1739, allocation base 0x001D0000.
2019-08-13 16:47:23,882 [root] DEBUG: AddressOfEPWriteCallback: Magic value not valid NT: 0xb1c0 (at 0x03E000E8).
2019-08-13 16:47:23,882 [root] DEBUG: ProcessImageBase: Modified entry point (0x0000FFEF) detected at image base 0x00400000 - dumping.
2019-08-13 16:47:23,930 [root] DEBUG: ApiReader: module list size: 21
2019-08-13 16:47:23,930 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\ntdll.dll
2019-08-13 16:47:23,930 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll
2019-08-13 16:47:23,946 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll
2019-08-13 16:47:23,946 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\user32.dll
2019-08-13 16:47:23,976 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\gdi32.dll
2019-08-13 16:47:23,976 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\lpk.dll
2019-08-13 16:47:23,976 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\usp10.dll
2019-08-13 16:47:23,976 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msvcrt.dll
2019-08-13 16:47:23,992 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\advapi32.dll
2019-08-13 16:47:24,007 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\sechost.dll
2019-08-13 16:47:24,007 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\rpcrt4.dll
2019-08-13 16:47:24,007 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\sspicli.dll
2019-08-13 16:47:24,007 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\cryptbase.dll
2019-08-13 16:47:24,007 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\ole32.dll
2019-08-13 16:47:24,023 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\shlwapi.dll
2019-08-13 16:47:24,039 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\psapi.dll
2019-08-13 16:47:24,055 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msvbvm60.dll
2019-08-13 16:47:24,055 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\oleaut32.dll
2019-08-13 16:47:24,055 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\imm32.dll
2019-08-13 16:47:24,069 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msctf.dll
2019-08-13 16:47:24,085 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\shell32.dll
2019-08-13 16:47:24,085 [root] DEBUG: DumpCurrentProcessFixImports: Instantiating PeParser with address: 0x00400000.
2019-08-13 16:47:24,085 [root] DEBUG: DumpCurrentProcessFixImports: Module entry point VA is 0x0000FFEF.
2019-08-13 16:47:24,085 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_133084517224471513282019
2019-08-13 16:47:24,101 [root] DEBUG: DumpCurrentProcessFixImports: Module image dump success C:\fOcJxESUJT\CAPE\2228_133084517224471513282019
2019-08-13 16:47:24,101 [root] DEBUG: DumpCurrentProcessFixImports: Warning - Unable to find IAT in scan, import reconstruction failed.
2019-08-13 16:47:24,101 [root] DEBUG: AddTrackedRegion: EntryPoint 0xffef, Entropy 7.497508e+00
2019-08-13 16:47:24,101 [root] DEBUG: AddTrackedRegion: Region at 0x00400000 size 0x1a67f added to tracked regions.
2019-08-13 16:47:24,101 [root] DEBUG: ProtectionHandler: Address: 0x00401000 (alloc base 0x00400000), NumberOfBytesToProtect: 0x1967f, NewAccessProtection: 0x20
2019-08-13 16:47:24,101 [root] DEBUG: NewThreadHandler: Address: 0x0040FFEF.
2019-08-13 16:47:24,101 [root] DEBUG: DumpPEsInRange: Scanning range 0x00400000 - 0x0041A67F.
2019-08-13 16:47:24,117 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x400000
2019-08-13 16:47:24,117 [root] DEBUG: DumpPEsInRange: PE image at 0x00400000, dumping
2019-08-13 16:47:24,117 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2019-08-13 16:47:24,117 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x00400000.
2019-08-13 16:47:24,117 [root] DEBUG: DumpProcess: Module entry point VA is 0x0000FFEF.
2019-08-13 16:47:24,117 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_37120205424471513282019
2019-08-13 16:47:24,132 [root] DEBUG: DumpProcess: Module image dump success - dump size 0x21c00.
2019-08-13 16:47:24,132 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x400001-0x41a67f.
2019-08-13 16:47:24,132 [root] DEBUG: DumpPEsInTrackedRegion: Dumped 1 PE image(s) from range 0x00400000 - 0x0041A67F.
2019-08-13 16:47:24,132 [root] DEBUG: NewThreadHandler: Dumped module at 0x00400000.
2019-08-13 16:47:24,132 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x400000 - 0x41a67f.
2019-08-13 16:47:24,132 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2640.
2019-08-13 16:47:24,132 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03E00000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:47:24,148 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03E000E8 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:47:24,148 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:47:24,148 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (3) at 0x03E000F8 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:47:24,148 [root] DEBUG: DLL loaded at 0x74980000: C:\Windows\system32\mscoree (0x4a000 bytes).
2019-08-13 16:47:24,148 [root] DEBUG: ProcessImageBase: Modified image detected at image base 0x00400000 - new entropy 3.074454e+00.
2019-08-13 16:47:24,148 [root] DEBUG: ApiReader: module list size: 22
2019-08-13 16:47:24,148 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\ntdll.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\user32.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\gdi32.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\lpk.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\usp10.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msvcrt.dll
2019-08-13 16:47:24,164 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\advapi32.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\sechost.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\rpcrt4.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\sspicli.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\cryptbase.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\ole32.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\shlwapi.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\psapi.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msvbvm60.dll
2019-08-13 16:47:24,180 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\oleaut32.dll
2019-08-13 16:47:24,194 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\imm32.dll
2019-08-13 16:47:24,194 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msctf.dll
2019-08-13 16:47:24,194 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\shell32.dll
2019-08-13 16:47:24,194 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\mscoree.dll
2019-08-13 16:47:24,210 [root] DEBUG: DumpCurrentProcessFixImports: Instantiating PeParser with address: 0x00400000.
2019-08-13 16:47:24,210 [root] DEBUG: DumpCurrentProcessFixImports: Module entry point VA is 0x0000FFEF.
2019-08-13 16:47:24,210 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_123697018324471513282019
2019-08-13 16:47:24,210 [root] DEBUG: DumpCurrentProcessFixImports: Module image dump success C:\fOcJxESUJT\CAPE\2228_123697018324471513282019
2019-08-13 16:47:24,210 [root] DEBUG: DumpCurrentProcessFixImports: Warning - Unable to find IAT in scan, import reconstruction failed.
2019-08-13 16:47:24,210 [root] DEBUG: ProcessImageBase: Modified image detected at image base 0x00400000 - new entropy 3.074454e+00.
2019-08-13 16:47:24,210 [root] DEBUG: ApiReader: module list size: 22
2019-08-13 16:47:24,226 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\ntdll.dll
2019-08-13 16:47:24,226 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll
2019-08-13 16:47:24,226 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll
2019-08-13 16:47:24,226 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\user32.dll
2019-08-13 16:47:24,226 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\gdi32.dll
2019-08-13 16:47:24,226 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\lpk.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\usp10.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msvcrt.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\advapi32.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\sechost.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\rpcrt4.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\sspicli.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\cryptbase.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\ole32.dll
2019-08-13 16:47:24,242 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\shlwapi.dll
2019-08-13 16:47:24,257 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\psapi.dll
2019-08-13 16:47:24,257 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msvbvm60.dll
2019-08-13 16:47:24,257 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\oleaut32.dll
2019-08-13 16:47:24,257 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\imm32.dll
2019-08-13 16:47:24,257 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\msctf.dll
2019-08-13 16:47:24,257 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\shell32.dll
2019-08-13 16:47:24,257 [root] DEBUG: Module parsing: \Device\HarddiskVolume2\Windows\SysWOW64\mscoree.dll
2019-08-13 16:47:24,257 [root] DEBUG: DumpCurrentProcessFixImports: Instantiating PeParser with address: 0x00400000.
2019-08-13 16:47:24,273 [root] DEBUG: DumpCurrentProcessFixImports: Module entry point VA is 0x0000FFEF.
2019-08-13 16:47:24,273 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_185683153924471513282019
2019-08-13 16:47:24,273 [root] DEBUG: DumpCurrentProcessFixImports: Module image dump success C:\fOcJxESUJT\CAPE\2228_185683153924471513282019
2019-08-13 16:47:24,273 [root] DEBUG: DumpCurrentProcessFixImports: Warning - Unable to find IAT in scan, import reconstruction failed.
2019-08-13 16:47:24,273 [root] DEBUG: AddTrackedRegion: EntryPoint 0x4c37e, Entropy 6.238785e+00
2019-08-13 16:47:24,289 [root] DEBUG: AddTrackedRegion: Region at 0x03D10000 size 0x4c400 added to tracked regions.
2019-08-13 16:47:24,289 [root] DEBUG: ProtectionHandler: Address: 0x03D12000 (alloc base 0x03D10000), NumberOfBytesToProtect: 0x4a400, NewAccessProtection: 0x20
2019-08-13 16:47:24,289 [root] DEBUG: ProtectionHandler: New code detected at (0x03D10000), scanning for PE images.
2019-08-13 16:47:24,289 [root] DEBUG: DumpPEsInRange: Scanning range 0x03D10000 - 0x03D5C400.
2019-08-13 16:47:24,303 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x3d10000
2019-08-13 16:47:24,319 [root] DEBUG: DumpPEsInRange: PE image at 0x03D10000, dumping
2019-08-13 16:47:24,319 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2019-08-13 16:47:24,335 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x03D10000.
2019-08-13 16:47:24,335 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_102231236824471513282019
2019-08-13 16:47:24,335 [root] DEBUG: DumpPE: PE file in memory dumped successfully - dump size 0x5dc00.
2019-08-13 16:47:24,335 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x3d557ae
2019-08-13 16:47:24,335 [root] DEBUG: DumpPEsInRange: PE image at 0x03D557AE, dumping
2019-08-13 16:47:24,351 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2019-08-13 16:47:24,351 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x03D557AE.
2019-08-13 16:47:24,351 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_176820848724471513282019
2019-08-13 16:47:24,351 [root] DEBUG: DumpPE: PE file in memory dumped successfully - dump size 0x4200.
2019-08-13 16:47:24,351 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x3d557af-0x3d5c400.
2019-08-13 16:47:24,367 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x03D10000.
2019-08-13 16:47:24,367 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x3d10000 - 0x3d5c400.
2019-08-13 16:47:24,367 [root] DEBUG: set_caller_info: Calling address 0x085FED2C in stack (advapi32::RegQueryInfoKeyW)
2019-08-13 16:47:24,367 [root] DEBUG: set_caller_info: Adding region at 0x08500000 to caller regions list.
2019-08-13 16:47:24,367 [root] DEBUG: set_caller_info: Adding region at 0x01DB0000 to caller regions list.
2019-08-13 16:47:24,367 [root] DEBUG: set_caller_info: Adding region at 0x00540000 to caller regions list.
2019-08-13 16:47:24,367 [root] DEBUG: DLL loaded at 0x744C0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x7b000 bytes).
2019-08-13 16:47:24,367 [root] DEBUG: Allocation: 0x08800000 - 0x089D0000, size: 0x1d0000, protection: 0x40.
2019-08-13 16:47:24,381 [root] DEBUG: AddTrackedRegion: Region at 0x08800000 size 0x1d0000 added to tracked regions.
2019-08-13 16:47:24,381 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x08800000.
2019-08-13 16:47:24,381 [root] DEBUG: FreeHandler: Address: 0x08800000.
2019-08-13 16:47:24,381 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x8800000 - 0x89d0000.
2019-08-13 16:47:24,414 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x21aea88, AllocationBase 0x400000.
2019-08-13 16:47:24,414 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x21aeb30, AllocationBase 0x1d0000.
2019-08-13 16:47:24,414 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x1db0590, AllocationBase 0x3e00000.
2019-08-13 16:47:24,414 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x1db0638, AllocationBase 0x400000.
2019-08-13 16:47:24,414 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x21af940, AllocationBase 0x3d10000.
2019-08-13 16:47:24,428 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x21afd18, AllocationBase 0x8800000.
2019-08-13 16:47:24,428 [root] DEBUG: DropTrackedRegion: removed pages 0x8800000-0x89d0000 from tracked region list.
2019-08-13 16:47:24,428 [root] DEBUG: Allocation: 0x08990000 - 0x08991000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,428 [root] DEBUG: AddTrackedRegion: Region at 0x08990000 size 0x1000 added to tracked regions.
2019-08-13 16:47:24,444 [root] DEBUG: AddTrackedRegion: Region at 0x00080000 size 0x1392 added to tracked regions.
2019-08-13 16:47:24,444 [root] DEBUG: ProtectionHandler: Address: 0x00081388 (alloc base 0x00080000), NumberOfBytesToProtect: 0xa, NewAccessProtection: 0x40
2019-08-13 16:47:24,444 [root] DEBUG: ProtectionHandler: New code detected at (0x00080000), scanning for PE images.
2019-08-13 16:47:24,444 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x00081392.
2019-08-13 16:47:24,444 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x81392.
2019-08-13 16:47:24,460 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x00081392.
2019-08-13 16:47:24,460 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x81392.
2019-08-13 16:47:24,460 [root] DEBUG: AddTrackedRegion: Region at 0x00080000 size 0x13aa added to tracked regions.
2019-08-13 16:47:24,460 [root] DEBUG: ProtectionHandler: Address: 0x000813A0 (alloc base 0x00080000), NumberOfBytesToProtect: 0xa, NewAccessProtection: 0x40
2019-08-13 16:47:24,460 [root] DEBUG: ProtectionHandler: New code detected at (0x00080000), scanning for PE images.
2019-08-13 16:47:24,460 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813AA.
2019-08-13 16:47:24,460 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813aa.
2019-08-13 16:47:24,460 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813AA.
2019-08-13 16:47:24,460 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813aa.
2019-08-13 16:47:24,460 [root] DEBUG: AddTrackedRegion: Region at 0x00080000 size 0x13c2 added to tracked regions.
2019-08-13 16:47:24,460 [root] DEBUG: ProtectionHandler: Address: 0x000813B8 (alloc base 0x00080000), NumberOfBytesToProtect: 0xa, NewAccessProtection: 0x40
2019-08-13 16:47:24,476 [root] DEBUG: ProtectionHandler: New code detected at (0x00080000), scanning for PE images.
2019-08-13 16:47:24,476 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813C2.
2019-08-13 16:47:24,476 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813c2.
2019-08-13 16:47:24,476 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813C2.
2019-08-13 16:47:24,476 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813c2.
2019-08-13 16:47:24,476 [root] DEBUG: AddTrackedRegion: Region at 0x00080000 size 0x13da added to tracked regions.
2019-08-13 16:47:24,492 [root] DEBUG: ProtectionHandler: Address: 0x000813D0 (alloc base 0x00080000), NumberOfBytesToProtect: 0xa, NewAccessProtection: 0x40
2019-08-13 16:47:24,506 [root] DEBUG: ProtectionHandler: New code detected at (0x00080000), scanning for PE images.
2019-08-13 16:47:24,506 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813DA.
2019-08-13 16:47:24,506 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813da.
2019-08-13 16:47:24,523 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813DA.
2019-08-13 16:47:24,523 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813da.
2019-08-13 16:47:24,523 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 11.
2019-08-13 16:47:24,523 [root] DEBUG: AddTrackedRegion: Region at 0x00080000 size 0x13f2 added to tracked regions.
2019-08-13 16:47:24,523 [root] DEBUG: ProtectionHandler: Address: 0x000813E8 (alloc base 0x00080000), NumberOfBytesToProtect: 0xa, NewAccessProtection: 0x40
2019-08-13 16:47:24,523 [root] DEBUG: ProtectionHandler: New code detected at (0x00080000), scanning for PE images.
2019-08-13 16:47:24,523 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813F2.
2019-08-13 16:47:24,523 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813f2.
2019-08-13 16:47:24,538 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x000813F2.
2019-08-13 16:47:24,538 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x813f2.
2019-08-13 16:47:24,538 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 12.
2019-08-13 16:47:24,538 [root] DEBUG: AddTrackedRegion: Region at 0x00080000 size 0x140a added to tracked regions.
2019-08-13 16:47:24,553 [root] DEBUG: ProtectionHandler: Address: 0x00081400 (alloc base 0x00080000), NumberOfBytesToProtect: 0xa, NewAccessProtection: 0x40
2019-08-13 16:47:24,553 [root] DEBUG: ProtectionHandler: New code detected at (0x00080000), scanning for PE images.
2019-08-13 16:47:24,553 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x0008140A.
2019-08-13 16:47:24,553 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x8140a.
2019-08-13 16:47:24,553 [root] DEBUG: DumpPEsInRange: Scanning range 0x00080000 - 0x0008140A.
2019-08-13 16:47:24,553 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x80000-0x8140a.
2019-08-13 16:47:24,569 [root] DEBUG: DLL loaded at 0x73F10000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks (0x5ab000 bytes).
2019-08-13 16:47:24,569 [root] DEBUG: DLL loaded at 0x73E70000: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80 (0x9b000 bytes).
2019-08-13 16:47:24,585 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1340.
2019-08-13 16:47:24,601 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03E00000 already exists for thread 1340 (process 2228), skipping.
2019-08-13 16:47:24,601 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03E000E8 already exists for thread 1340 (process 2228), skipping.
2019-08-13 16:47:24,601 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 1340 (process 2228), skipping.
2019-08-13 16:47:24,601 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (3) at 0x03E000F8 already exists for thread 1340 (process 2228), skipping.
2019-08-13 16:47:24,601 [root] DEBUG: Allocation: 0x0028A000 - 0x0028B000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,601 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 13.
2019-08-13 16:47:24,601 [root] DEBUG: AddTrackedRegion: Region at 0x00280000 size 0xb000 added to tracked regions.
2019-08-13 16:47:24,601 [root] DEBUG: Allocation: 0x00282000 - 0x00283000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,615 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00280000, size: 0xb000.
2019-08-13 16:47:24,615 [root] DEBUG: DLL loaded at 0x74970000: C:\Windows\system32\profapi (0xb000 bytes).
2019-08-13 16:47:24,648 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2648.
2019-08-13 16:47:24,678 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03E00000 already exists for thread 2648 (process 2228), skipping.
2019-08-13 16:47:24,694 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03E000E8 already exists for thread 2648 (process 2228), skipping.
2019-08-13 16:47:24,694 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03E00000 already exists for thread 2648 (process 2228), skipping.
2019-08-13 16:47:24,694 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (3) at 0x03E000F8 already exists for thread 2648 (process 2228), skipping.
2019-08-13 16:47:24,694 [root] DEBUG: DLL loaded at 0x72EF0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni (0xaf8000 bytes).
2019-08-13 16:47:24,694 [root] DEBUG: Allocation: 0x004F2000 - 0x004F3000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,694 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 14.
2019-08-13 16:47:24,694 [root] DEBUG: AddTrackedRegion: Region at 0x004F0000 size 0x3000 added to tracked regions.
2019-08-13 16:47:24,694 [root] DEBUG: set_caller_info: Adding region at 0x08990000 to caller regions list.
2019-08-13 16:47:24,694 [root] DEBUG: DLL unloaded from 0x751B0000.
2019-08-13 16:47:24,710 [root] DEBUG: DLL loaded at 0x74C70000: C:\Windows\system32\CRYPTSP (0x16000 bytes).
2019-08-13 16:47:24,710 [root] DEBUG: DLL loaded at 0x74C30000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2019-08-13 16:47:24,710 [root] DEBUG: Allocation: 0x004F3000 - 0x004F4000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,710 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 15.
2019-08-13 16:47:24,710 [root] DEBUG: AddTrackedRegion: Region at 0x004F0000 size 0x4000 added to tracked regions.
2019-08-13 16:47:24,710 [root] DEBUG: Allocation: 0x0066B000 - 0x0066C000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,710 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 16.
2019-08-13 16:47:24,726 [root] DEBUG: AddTrackedRegion: Region at 0x00660000 size 0xc000 added to tracked regions.
2019-08-13 16:47:24,726 [root] DEBUG: Allocation: 0x00667000 - 0x00668000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,726 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00660000, size: 0xc000.
2019-08-13 16:47:24,740 [root] DEBUG: Allocation: 0x004F4000 - 0x004F7000, size: 0x3000, protection: 0x40.
2019-08-13 16:47:24,740 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 17.
2019-08-13 16:47:24,740 [root] DEBUG: AddTrackedRegion: Region at 0x004F0000 size 0x7000 added to tracked regions.
2019-08-13 16:47:24,740 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x004F0000, TrackedRegion->RegionSize: 0x7000, thread 2640
2019-08-13 16:47:24,740 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x03E00000 to 0x004F0000.
2019-08-13 16:47:24,740 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:47:24,740 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:47:24,740 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xfc, Size=0x0, Address=0x004F4000 and Type=0x1.
2019-08-13 16:47:24,740 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2640 type 1 at address 0x004F4000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:24,756 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x004F4000
2019-08-13 16:47:24,756 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xfc, Size=0x4, Address=0x004F003C and Type=0x1.
2019-08-13 16:47:24,756 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2640 type 1 at address 0x004F003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:24,756 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x004F003C
2019-08-13 16:47:24,772 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x004F4000 (size 0x3000).
2019-08-13 16:47:24,803 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:47:24,803 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73F4D4C4 (thread 2640)
2019-08-13 16:47:24,819 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x004F4000.
2019-08-13 16:47:24,819 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x004F4000 and Type=0x0.
2019-08-13 16:47:24,819 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x4f4000: 0xfe.
2019-08-13 16:47:24,819 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:24,835 [root] DEBUG: Allocation: 0x004FC000 - 0x004FD000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,835 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 18.
2019-08-13 16:47:24,835 [root] DEBUG: AddTrackedRegion: Region at 0x004F0000 size 0xd000 added to tracked regions.
2019-08-13 16:47:24,835 [root] DEBUG: DLL loaded at 0x73E10000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit (0x5b000 bytes).
2019-08-13 16:47:24,913 [root] DEBUG: Allocation: 0x0AC20000 - 0x0AC21000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,913 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 19.
2019-08-13 16:47:24,913 [root] DEBUG: AddTrackedRegion: Region at 0x0AC20000 size 0x1000 added to tracked regions.
2019-08-13 16:47:24,927 [root] DEBUG: Allocation: 0x0AC30000 - 0x0AC31000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:24,960 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 20.
2019-08-13 16:47:24,974 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x1000 added to tracked regions.
2019-08-13 16:47:24,974 [root] DEBUG: Allocation: 0x0AC31000 - 0x0AC43000, size: 0x12000, protection: 0x40.
2019-08-13 16:47:24,990 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 21.
2019-08-13 16:47:24,990 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x13000 added to tracked regions.
2019-08-13 16:47:24,990 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x0AC30000, TrackedRegion->RegionSize: 0x13000, thread 2640
2019-08-13 16:47:24,990 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x004F0000 to 0x0AC30000.
2019-08-13 16:47:24,990 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:47:24,990 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:47:24,990 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xfc, Size=0x0, Address=0x0AC31000 and Type=0x1.
2019-08-13 16:47:24,990 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2640 type 1 at address 0x0AC31000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:24,990 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x0AC31000
2019-08-13 16:47:25,006 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xfc, Size=0x4, Address=0x0AC3003C and Type=0x1.
2019-08-13 16:47:25,006 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2640 type 1 at address 0x0AC3003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:25,006 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0AC3003C
2019-08-13 16:47:25,006 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x0AC31000 (size 0x12000).
2019-08-13 16:47:25,006 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E3E57D (thread 2640)
2019-08-13 16:47:25,022 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC31000.
2019-08-13 16:47:25,022 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x0AC31000 and Type=0x0.
2019-08-13 16:47:25,022 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac31000: 0x85.
2019-08-13 16:47:25,022 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:25,022 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E3E0C2 (thread 2640)
2019-08-13 16:47:25,022 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC31000.
2019-08-13 16:47:25,022 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x0AC31000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:47:25,022 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac31000: 0x85.
2019-08-13 16:47:25,038 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:25,052 [root] DEBUG: set_caller_info: Adding region at 0x0AC30000 to caller regions list.
2019-08-13 16:47:25,069 [root] DEBUG: Allocation: 0x004F7000 - 0x004F8000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:25,069 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x004F0000, size: 0xd000.
2019-08-13 16:47:25,115 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 22.
2019-08-13 16:47:25,115 [root] DEBUG: AddTrackedRegion: Region at 0x0AC50000 size 0x758000 added to tracked regions.
2019-08-13 16:47:25,115 [root] DEBUG: ProtectionHandler: Address: 0x0AD5E000 (alloc base 0x0AC50000), NumberOfBytesToProtect: 0x64a000, NewAccessProtection: 0x40
2019-08-13 16:47:25,115 [root] DEBUG: ProtectionHandler: New code detected at (0x0AC50000), scanning for PE images.
2019-08-13 16:47:25,115 [root] DEBUG: DumpPEsInRange: Scanning range 0x0AC50000 - 0x0B3A8000.
2019-08-13 16:47:25,115 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0xac50000
2019-08-13 16:47:25,115 [root] DEBUG: DumpPEsInRange: PE image at 0x0AC50000, dumping
2019-08-13 16:47:25,131 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2019-08-13 16:47:25,131 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x0AC50000.
2019-08-13 16:47:25,131 [root] DEBUG: DumpProcess: Module entry point VA is 0x00000000.
2019-08-13 16:47:25,256 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_191751481625471513282019
2019-08-13 16:47:25,256 [root] DEBUG: DumpProcess: Module image dump success - dump size 0x755a00.
2019-08-13 16:47:25,286 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 256, VirtualSize and SizeOfRawData are zero.
2019-08-13 16:47:25,302 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 718, RVA 0x2a082a14 and size 0x1001.
2019-08-13 16:47:25,302 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 1166, RVA 0x7e260058 and size 0x100.
2019-08-13 16:47:25,302 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 29956, RVA 0x6f040028 and size 0xa000365.
2019-08-13 16:47:25,302 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 16, RVA 0xa581b06 and size 0x736f0206.
2019-08-13 16:47:25,302 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 5, RVA 0x2a8e7b02 and size 0x20a0400.
2019-08-13 16:47:25,302 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 13 of 28422, RVA 0xc5517205 and size 0x1336de0a.
2019-08-13 16:47:25,318 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0xac50001-0xb3a8000.
2019-08-13 16:47:25,318 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x0AC50000.
2019-08-13 16:47:25,318 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0xac50000 - 0xb3a8000.
2019-08-13 16:47:25,334 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 23.
2019-08-13 16:47:25,334 [root] DEBUG: AddTrackedRegion: Region at 0x0AC50000 size 0x759000 added to tracked regions.
2019-08-13 16:47:25,334 [root] DEBUG: ProtectionHandler: Address: 0x0B3A8000 (alloc base 0x0AC50000), NumberOfBytesToProtect: 0x1000, NewAccessProtection: 0x40
2019-08-13 16:47:25,349 [root] DEBUG: ProtectionHandler: New code detected at (0x0AC50000), scanning for PE images.
2019-08-13 16:47:25,349 [root] DEBUG: DumpPEsInRange: Scanning range 0x0AC50000 - 0x0B3A9000.
2019-08-13 16:47:25,349 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0xac50000
2019-08-13 16:47:25,365 [root] DEBUG: DumpPEsInRange: PE image at 0x0AC50000, dumping
2019-08-13 16:47:25,365 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2019-08-13 16:47:25,365 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x0AC50000.
2019-08-13 16:47:25,365 [root] DEBUG: DumpProcess: Module entry point VA is 0x00000000.
2019-08-13 16:47:25,459 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_19159142325471513282019
2019-08-13 16:47:25,473 [root] DEBUG: DumpProcess: Module image dump success - dump size 0x755a00.
2019-08-13 16:47:25,473 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 256, VirtualSize and SizeOfRawData are zero.
2019-08-13 16:47:25,490 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 718, RVA 0x2a082a14 and size 0x1001.
2019-08-13 16:47:25,490 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 1166, RVA 0x7e260058 and size 0x100.
2019-08-13 16:47:25,490 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 29956, RVA 0x6f040028 and size 0xa000365.
2019-08-13 16:47:25,490 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 16, RVA 0xa581b06 and size 0x736f0206.
2019-08-13 16:47:25,506 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 5, RVA 0x2a8e7b02 and size 0x20a0400.
2019-08-13 16:47:25,506 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 13 of 28422, RVA 0xc5517205 and size 0x1336de0a.
2019-08-13 16:47:25,520 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0xac50001-0xb3a9000.
2019-08-13 16:47:25,520 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x0AC50000.
2019-08-13 16:47:25,520 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0xac50000 - 0xb3a9000.
2019-08-13 16:47:25,520 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 24.
2019-08-13 16:47:25,536 [root] DEBUG: AddTrackedRegion: Region at 0x0AC50000 size 0x79c000 added to tracked regions.
2019-08-13 16:47:25,536 [root] DEBUG: ProtectionHandler: Address: 0x0B3A9000 (alloc base 0x0AC50000), NumberOfBytesToProtect: 0x43000, NewAccessProtection: 0x40
2019-08-13 16:47:25,536 [root] DEBUG: ProtectionHandler: New code detected at (0x0AC50000), scanning for PE images.
2019-08-13 16:47:25,536 [root] DEBUG: DumpPEsInRange: Scanning range 0x0AC50000 - 0x0B3EC000.
2019-08-13 16:47:25,536 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0xac50000
2019-08-13 16:47:25,536 [root] DEBUG: DumpPEsInRange: PE image at 0x0AC50000, dumping
2019-08-13 16:47:25,536 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2019-08-13 16:47:25,552 [root] DEBUG: DumpProcess: Instantiating PeParser with address: 0x0AC50000.
2019-08-13 16:47:25,568 [root] DEBUG: DumpProcess: Module entry point VA is 0x00000000.
2019-08-13 16:47:25,630 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_90637876025471513282019
2019-08-13 16:47:25,630 [root] DEBUG: DumpProcess: Module image dump success - dump size 0x755a00.
2019-08-13 16:47:25,661 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 256, VirtualSize and SizeOfRawData are zero.
2019-08-13 16:47:25,677 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 718, RVA 0x2a082a14 and size 0x1001.
2019-08-13 16:47:25,677 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 1166, RVA 0x7e260058 and size 0x100.
2019-08-13 16:47:25,677 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 29956, RVA 0x6f040028 and size 0xa000365.
2019-08-13 16:47:25,677 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 16, RVA 0xa581b06 and size 0x736f0206.
2019-08-13 16:47:25,677 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 1 of 5, RVA 0x2a8e7b02 and size 0x20a0400.
2019-08-13 16:47:25,677 [root] DEBUG: TestPERequirements: Possible PE image rejected due to section 13 of 28422, RVA 0xc5517205 and size 0x1336de0a.
2019-08-13 16:47:25,707 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0xac50001-0xb3ec000.
2019-08-13 16:47:25,723 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x0AC50000.
2019-08-13 16:47:25,723 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0xac50000 - 0xb3ec000.
2019-08-13 16:47:25,723 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-13 16:47:25,740 [root] DEBUG: DLL loaded at 0x0AC50000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni (0x79c000 bytes).
2019-08-13 16:47:25,755 [root] DEBUG: DLL loaded at 0x73C80000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni (0x188000 bytes).
2019-08-13 16:47:25,770 [root] DEBUG: DLL loaded at 0x71B70000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni (0xbde000 bytes).
2019-08-13 16:47:25,770 [root] DEBUG: Allocation: 0x004F8000 - 0x004FA000, size: 0x2000, protection: 0x40.
2019-08-13 16:47:25,770 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x004F0000, size: 0xd000.
2019-08-13 16:47:25,818 [root] DEBUG: Allocation: 0x087A0000 - 0x087A1000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:25,818 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 25.
2019-08-13 16:47:25,848 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x1000 added to tracked regions.
2019-08-13 16:47:25,864 [root] DEBUG: Allocation: 0x0AC43000 - 0x0AC44000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:25,880 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 26.
2019-08-13 16:47:25,895 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x14000 added to tracked regions.
2019-08-13 16:47:25,927 [root] DEBUG: Allocation: 0x0065A000 - 0x0065B000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:25,927 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 27.
2019-08-13 16:47:25,927 [root] DEBUG: AddTrackedRegion: Region at 0x00650000 size 0xb000 added to tracked regions.
2019-08-13 16:47:25,941 [root] DEBUG: set_caller_info: Adding region at 0x00280000 to caller regions list.
2019-08-13 16:47:25,941 [root] DEBUG: Allocation: 0x00652000 - 0x00653000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:25,973 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00650000, size: 0xb000.
2019-08-13 16:47:26,036 [root] DEBUG: Allocation: 0x0AC44000 - 0x0AC47000, size: 0x3000, protection: 0x40.
2019-08-13 16:47:26,036 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 28.
2019-08-13 16:47:26,036 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x17000 added to tracked regions.
2019-08-13 16:47:26,052 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x0AC30000, TrackedRegion->RegionSize: 0x17000, thread 2640
2019-08-13 16:47:26,066 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x0AC30000 to 0x0AC30000.
2019-08-13 16:47:26,066 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:47:26,066 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:47:26,082 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xfc, Size=0x0, Address=0x0AC44000 and Type=0x1.
2019-08-13 16:47:26,098 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2640 type 1 at address 0x0AC44000, size 0 with Callback 0x747e7620.
2019-08-13 16:47:26,098 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x0AC44000
2019-08-13 16:47:26,098 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xfc, Size=0x4, Address=0x0AC3003C and Type=0x1.
2019-08-13 16:47:26,098 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2640 type 1 at address 0x0AC3003C, size 4 with Callback 0x747e7280.
2019-08-13 16:47:26,098 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0AC3003C
2019-08-13 16:47:26,098 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x0AC44000 (size 0x3000).
2019-08-13 16:47:26,098 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E2C6C2 (thread 2640)
2019-08-13 16:47:26,098 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC44000.
2019-08-13 16:47:26,098 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x0AC44000 and Type=0x0.
2019-08-13 16:47:26,098 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac44000: 0x8b.
2019-08-13 16:47:26,098 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:26,114 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E2C6C6 (thread 2640)
2019-08-13 16:47:26,130 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC44000.
2019-08-13 16:47:26,130 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x0AC44000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:47:26,130 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac44000: 0x8b.
2019-08-13 16:47:26,130 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:26,144 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E25F60 (thread 2640)
2019-08-13 16:47:26,144 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC44000.
2019-08-13 16:47:26,144 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x0AC44000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:47:26,144 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac44000: 0x8b.
2019-08-13 16:47:26,144 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:47:26,176 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x0AC44000 (thread 2640)
2019-08-13 16:47:26,176 [root] DEBUG: ShellcodeExecCallback: Breakpoint 2 at Address 0x0AC44000 (allocation base 0x0AC30000).
2019-08-13 16:47:26,223 [root] DEBUG: ShellcodeExecCallback: Debug: About to scan region for a PE image (base 0x0AC30000, size 0x17000).
2019-08-13 16:47:26,223 [root] DEBUG: DumpPEsInRange: Scanning range 0x0AC30000 - 0x0AC47000.
2019-08-13 16:47:26,223 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0xac30000-0xac47000.
2019-08-13 16:47:26,239 [root] DEBUG: DumpMemory: CAPE output file C:\fOcJxESUJT\CAPE\2228_3835739232672213282019 successfully created, size 0x17000
2019-08-13 16:47:26,239 [root] INFO: Added new CAPE file to list with path: C:\fOcJxESUJT\CAPE\2228_3835739232672213282019
2019-08-13 16:47:26,239 [root] DEBUG: ShellcodeExecCallback: successfully dumped memory range at 0x0AC30000 (size 0x17000).
2019-08-13 16:47:26,239 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0xac30000 - 0xac47000.
2019-08-13 16:47:26,239 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 0 address 0x0AC44000.
2019-08-13 16:47:26,253 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1040.
2019-08-13 16:47:26,269 [root] DEBUG: Error 31 (0x1f) - ClearDebugRegister: Initial GetThreadContext failed: A device attached to the system is not functioning.
2019-08-13 16:47:26,269 [root] DEBUG: ClearThreadBreakpoint: Call to ClearDebugRegister failed.
2019-08-13 16:47:26,269 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 2640.
2019-08-13 16:47:26,269 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1340.
2019-08-13 16:47:26,286 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 2648.
2019-08-13 16:47:26,286 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 1 address 0x0AC3003C.
2019-08-13 16:47:26,286 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1040.
2019-08-13 16:47:26,286 [root] DEBUG: Error 31 (0x1f) - ClearDebugRegister: Initial GetThreadContext failed: A device attached to the system is not functioning.
2019-08-13 16:47:26,286 [root] DEBUG: ClearThreadBreakpoint: Call to ClearDebugRegister failed.
2019-08-13 16:47:26,286 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 2640.
2019-08-13 16:47:26,286 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1340.
2019-08-13 16:47:26,286 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 2648.
2019-08-13 16:47:26,286 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoint 2 address 0x0AC44000.
2019-08-13 16:47:26,301 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1040.
2019-08-13 16:47:26,301 [root] DEBUG: Error 31 (0x1f) - ClearDebugRegister: Initial GetThreadContext failed: A device attached to the system is not functioning.
2019-08-13 16:47:26,301 [root] DEBUG: ClearThreadBreakpoint: Call to ClearDebugRegister failed.
2019-08-13 16:47:26,301 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 2640.
2019-08-13 16:47:26,301 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 1340.
2019-08-13 16:47:26,301 [root] DEBUG: ClearBreakpoint: About to call ClearThreadBreakpoint for thread 2648.
2019-08-13 16:47:26,301 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:47:26,316 [root] DEBUG: DLL loaded at 0x74950000: C:\Windows\system32\bcrypt (0x17000 bytes).
2019-08-13 16:47:26,364 [root] DEBUG: Allocation: 0x00646000 - 0x00647000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:26,364 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 29.
2019-08-13 16:47:26,364 [root] DEBUG: AddTrackedRegion: Region at 0x00640000 size 0x7000 added to tracked regions.
2019-08-13 16:47:26,410 [root] DEBUG: Allocation: 0x0064A000 - 0x0064B000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:26,410 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 30.
2019-08-13 16:47:26,410 [root] DEBUG: AddTrackedRegion: Region at 0x00640000 size 0xb000 added to tracked regions.
2019-08-13 16:47:26,426 [root] DEBUG: Allocation: 0x00647000 - 0x00648000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:26,426 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00640000, size: 0xb000.
2019-08-13 16:47:26,426 [root] DEBUG: DLL loaded at 0x73AE0000: C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni (0x19b000 bytes).
2019-08-13 16:47:26,487 [root] DEBUG: DLL loaded at 0x74940000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2019-08-13 16:47:26,503 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2944.
2019-08-13 16:47:26,503 [root] DEBUG: DLL loaded at 0x74EB0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2019-08-13 16:47:26,535 [root] DEBUG: DLL loaded at 0x71B30000: C:\Windows\system32\wbem\wbemdisp (0x31000 bytes).
2019-08-13 16:47:26,565 [root] DEBUG: DLL loaded at 0x71AD0000: C:\Windows\system32\wbemcomn (0x5c000 bytes).
2019-08-13 16:47:26,598 [root] DEBUG: DLL loaded at 0x75D00000: C:\Windows\syswow64\WS2_32 (0x35000 bytes).
2019-08-13 16:47:26,598 [root] DEBUG: DLL loaded at 0x75130000: C:\Windows\syswow64\NSI (0x6000 bytes).
2019-08-13 16:47:34,398 [root] INFO: Stopped WMI Service
2019-08-13 16:47:34,398 [root] INFO: Attaching to DcomLaunch service (pid 564)
2019-08-13 16:47:34,476 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:47:34,476 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:47:34,476 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:47:34,476 [lib.api.process] INFO: 64-bit DLL to inject is C:\exrhhyewq\dll\wexpbM.dll, loader C:\exrhhyewq\bin\JjsuVYzF.exe
2019-08-13 16:47:34,490 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:47:34,522 [root] DEBUG: Loader: Injecting process 564 (thread 0) with C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:47:34,538 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 568, handle 0x84
2019-08-13 16:47:34,538 [root] DEBUG: Process image base: 0x00000000FFA10000
2019-08-13 16:47:34,538 [root] DEBUG: InjectDllViaIAT: Not a new process, aborting IAT patch
2019-08-13 16:47:34,538 [root] DEBUG: InjectDll: IAT patching failed, falling back to thread injection.
2019-08-13 16:47:34,553 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:47:34,553 [root] DEBUG: Process dumps disabled.
2019-08-13 16:47:34,553 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:47:34,553 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:47:34,553 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:34,599 [root] WARNING: Unable to place hook on LockResource
2019-08-13 16:47:34,615 [root] WARNING: Unable to hook LockResource
2019-08-13 16:47:34,631 [root] DEBUG: Debugger initialised.
2019-08-13 16:47:34,647 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 564 at 0x00000000719E0000, image base 0x00000000FFA10000, stack from 0x00000000022B6000-0x00000000022C0000
2019-08-13 16:47:34,663 [root] DEBUG: Commandline: C:\Windows\sysnative\svchost.exe -k DcomLaunch.
2019-08-13 16:47:34,677 [root] DEBUG: AddTrackedRegion: EntryPoint 0x246c, Entropy 3.671080e+00
2019-08-13 16:47:34,677 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFA10000 size 0x1000 added to tracked regions.
2019-08-13 16:47:34,677 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:47:34,694 [root] INFO: Added new process to list with pid: 564
2019-08-13 16:47:34,694 [root] INFO: Monitor successfully loaded in process with pid 564.
2019-08-13 16:47:34,710 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2019-08-13 16:47:34,710 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2019-08-13 16:47:34,724 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:47:38,796 [root] INFO: Started WMI Service
2019-08-13 16:47:38,796 [root] INFO: Attaching to WMI service (pid 2128)
2019-08-13 16:47:38,796 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:47:38,796 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:47:38,796 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:47:38,796 [lib.api.process] INFO: 64-bit DLL to inject is C:\exrhhyewq\dll\wexpbM.dll, loader C:\exrhhyewq\bin\JjsuVYzF.exe
2019-08-13 16:47:38,796 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:47:38,796 [root] DEBUG: Loader: Injecting process 2128 (thread 0) with C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:47:38,796 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2084, handle 0x84
2019-08-13 16:47:38,796 [root] DEBUG: Process image base: 0x00000000FFA10000
2019-08-13 16:47:38,796 [root] DEBUG: InjectDllViaIAT: Not a new process, aborting IAT patch
2019-08-13 16:47:38,796 [root] DEBUG: InjectDll: IAT patching failed, falling back to thread injection.
2019-08-13 16:47:38,796 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:47:38,796 [root] DEBUG: Process dumps disabled.
2019-08-13 16:47:38,812 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:47:38,812 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:47:38,812 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:38,812 [root] WARNING: Unable to place hook on LockResource
2019-08-13 16:47:38,812 [root] WARNING: Unable to hook LockResource
2019-08-13 16:47:38,812 [root] DEBUG: Debugger initialised.
2019-08-13 16:47:38,812 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 2128 at 0x00000000719E0000, image base 0x00000000FFA10000, stack from 0x00000000016B6000-0x00000000016C0000
2019-08-13 16:47:38,812 [root] DEBUG: Commandline: C:\Windows\sysnative\svchost.exe -k netsvcs.
2019-08-13 16:47:38,812 [root] DEBUG: AddTrackedRegion: EntryPoint 0x246c, Entropy 3.657648e+00
2019-08-13 16:47:38,828 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFA10000 size 0x1000 added to tracked regions.
2019-08-13 16:47:38,828 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:47:38,828 [root] INFO: Added new process to list with pid: 2128
2019-08-13 16:47:38,828 [root] INFO: Monitor successfully loaded in process with pid 2128.
2019-08-13 16:47:38,828 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2019-08-13 16:47:38,828 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2019-08-13 16:47:38,828 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:47:40,839 [root] DEBUG: DLL loaded at 0x74930000: C:\Windows\system32\wbem\wbemprox (0xa000 bytes).
2019-08-13 16:47:40,855 [root] DEBUG: DLL loaded at 0x719C0000: C:\Windows\system32\wbem\wmiutils (0x17000 bytes).
2019-08-13 16:47:40,871 [root] DEBUG: DLL loaded at 0x000007FEF9E80000: C:\Windows\system32\VSSAPI (0x1b0000 bytes).
2019-08-13 16:47:40,871 [root] DEBUG: DLL loaded at 0x000007FEFB270000: C:\Windows\system32\ATL (0x19000 bytes).
2019-08-13 16:47:40,871 [root] DEBUG: DLL loaded at 0x000007FEF9E60000: C:\Windows\system32\VssTrace (0x17000 bytes).
2019-08-13 16:47:40,903 [root] DEBUG: DLL loaded at 0x000007FEFA870000: C:\Windows\system32\samcli (0x14000 bytes).
2019-08-13 16:47:40,903 [root] DEBUG: DLL loaded at 0x000007FEFB820000: C:\Windows\system32\SAMLIB (0x1d000 bytes).
2019-08-13 16:47:40,917 [root] DEBUG: DLL loaded at 0x000007FEFAC20000: C:\Windows\system32\netutils (0xc000 bytes).
2019-08-13 16:47:40,934 [root] DEBUG: DLL loaded at 0x000007FEFB0D0000: C:\Windows\system32\es (0x67000 bytes).
2019-08-13 16:47:40,964 [root] DEBUG: DLL loaded at 0x000007FEFB840000: C:\Windows\system32\PROPSYS (0x12c000 bytes).
2019-08-13 16:47:40,996 [root] DEBUG: DLL loaded at 0x000007FEF9540000: C:\Windows\system32\wbem\wbemcore (0x12f000 bytes).
2019-08-13 16:47:40,996 [root] DEBUG: DLL loaded at 0x000007FEF94D0000: C:\Windows\system32\wbem\esscli (0x6f000 bytes).
2019-08-13 16:47:41,012 [root] DEBUG: DLL loaded at 0x000007FEF9A00000: C:\Windows\system32\wbem\FastProx (0xe2000 bytes).
2019-08-13 16:47:41,012 [root] DEBUG: DLL loaded at 0x000007FEF9980000: C:\Windows\system32\NTDSAPI (0x27000 bytes).
2019-08-13 16:47:41,012 [root] DEBUG: DLL unloaded from 0x000007FEF9540000.
2019-08-13 16:47:41,028 [root] DEBUG: DLL loaded at 0x000007FEFA0A0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2019-08-13 16:47:41,059 [root] DEBUG: DLL loaded at 0x747D0000: C:\Windows\system32\wbem\wbemsvc (0xf000 bytes).
2019-08-13 16:47:41,073 [root] DEBUG: DLL loaded at 0x71920000: C:\Windows\system32\wbem\fastprox (0x96000 bytes).
2019-08-13 16:47:41,089 [root] DEBUG: DLL loaded at 0x71900000: C:\Windows\system32\NTDSAPI (0x18000 bytes).
2019-08-13 16:47:41,105 [root] DEBUG: DLL loaded at 0x000007FEFCAC0000: C:\Windows\system32\authZ (0x2f000 bytes).
2019-08-13 16:47:41,121 [root] DEBUG: CreateThread: Initialising breakpoints for thread 668.
2019-08-13 16:47:41,121 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-13 16:47:41,121 [root] DEBUG: DLL loaded at 0x000007FEF97C0000: C:\Windows\system32\wbem\wmiutils (0x26000 bytes).
2019-08-13 16:47:41,137 [root] DEBUG: DLL loaded at 0x000007FEF90B0000: C:\Windows\system32\wbem\repdrvfs (0x73000 bytes).
2019-08-13 16:47:41,151 [root] WARNING: File at path "C:\Windows\sysnative\wbem\repository\WRITABLE.TST" does not exist, skip.
2019-08-13 16:47:41,151 [root] DEBUG: DLL loaded at 0x000007FEFCB00000: C:\Windows\system32\Wevtapi (0x6d000 bytes).
2019-08-13 16:47:41,167 [root] DEBUG: DLL unloaded from 0x000007FEFCB00000.
2019-08-13 16:47:41,448 [root] DEBUG: DLL loaded at 0x000007FEF80F0000: C:\Windows\system32\wbem\wmiprvsd (0xbc000 bytes).
2019-08-13 16:47:41,463 [root] DEBUG: DLL loaded at 0x000007FEFA0C0000: C:\Windows\system32\NCObjAPI (0x16000 bytes).
2019-08-13 16:47:41,510 [root] DEBUG: DLL loaded at 0x000007FEF2DA0000: C:\Windows\system32\wbem\wbemess (0x7e000 bytes).
2019-08-13 16:47:41,526 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2376.
2019-08-13 16:47:41,526 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-13 16:47:41,573 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2200.
2019-08-13 16:47:41,573 [root] DEBUG: DLL unloaded from 0x0000000076FF0000.
2019-08-13 16:47:41,588 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2436.
2019-08-13 16:47:41,588 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-13 16:47:41,635 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1396.
2019-08-13 16:47:41,667 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2816.
2019-08-13 16:47:41,667 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2796.
2019-08-13 16:47:41,683 [root] DEBUG: CreateThread: Initialising breakpoints for thread 332.
2019-08-13 16:47:41,683 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1308.
2019-08-13 16:47:41,713 [root] DEBUG: DLL loaded at 0x718A0000: C:\Windows\system32\SXS (0x5f000 bytes).
2019-08-13 16:47:41,776 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1436.
2019-08-13 16:47:41,792 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2120.
2019-08-13 16:47:41,792 [root] DEBUG: CreateThread: Initialising breakpoints for thread 928.
2019-08-13 16:47:41,854 [root] DEBUG: DLL loaded at 0x71860000: C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni (0x3a000 bytes).
2019-08-13 16:47:41,854 [root] DEBUG: DLL loaded at 0x60350000: C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers (0x15000 bytes).
2019-08-13 16:47:41,869 [root] DEBUG: Allocation: 0x08991000 - 0x08992000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:41,901 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 31.
2019-08-13 16:47:41,901 [root] DEBUG: AddTrackedRegion: Region at 0x08990000 size 0x2000 added to tracked regions.
2019-08-13 16:47:41,917 [root] DEBUG: Allocation: 0x0B8A0000 - 0x0B8A1000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:41,917 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 32.
2019-08-13 16:47:41,917 [root] DEBUG: AddTrackedRegion: Region at 0x0B8A0000 size 0x1000 added to tracked regions.
2019-08-13 16:47:41,963 [root] DEBUG: Allocation: 0x0B8A1000 - 0x0B8A2000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:41,963 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 33.
2019-08-13 16:47:41,979 [root] DEBUG: AddTrackedRegion: Region at 0x0B8A0000 size 0x2000 added to tracked regions.
2019-08-13 16:47:41,994 [root] DEBUG: Allocation: 0x004FA000 - 0x004FB000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:42,009 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x004F0000, size: 0xd000.
2019-08-13 16:47:42,072 [root] DEBUG: DLL loaded at 0x000007FEFA1E0000: C:\Windows\system32\wbem\ncprov (0x16000 bytes).
2019-08-13 16:47:42,134 [root] DEBUG: Allocation: 0x004FB000 - 0x004FC000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:42,134 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x004F0000, size: 0xd000.
2019-08-13 16:47:42,213 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 2132
2019-08-13 16:47:42,243 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:47:42,243 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:47:42,243 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:47:42,243 [lib.api.process] INFO: 64-bit DLL to inject is C:\exrhhyewq\dll\wexpbM.dll, loader C:\exrhhyewq\bin\JjsuVYzF.exe
2019-08-13 16:47:42,290 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:47:42,338 [root] DEBUG: Loader: Injecting process 2132 (thread 2156) with C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:47:42,338 [root] DEBUG: Process image base: 0x00000000FF330000
2019-08-13 16:47:42,384 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:47:42,384 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00000000FF38F000 - 0x000007FEFF430000
2019-08-13 16:47:42,431 [root] DEBUG: InjectDllViaIAT: Allocated 0x238 bytes for new import table at 0x00000000FF390000.
2019-08-13 16:47:42,431 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-13 16:47:42,431 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:47:42,431 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 2132
2019-08-13 16:47:42,447 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:47:42,447 [root] DEBUG: Process dumps disabled.
2019-08-13 16:47:42,447 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:47:42,447 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:47:42,447 [root] INFO: Disabling sleep skipping.
2019-08-13 16:47:42,463 [root] WARNING: Unable to place hook on LockResource
2019-08-13 16:47:42,463 [root] WARNING: Unable to hook LockResource
2019-08-13 16:47:42,477 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-13 16:47:42,477 [root] DEBUG: Debugger initialised.
2019-08-13 16:47:42,493 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 2132 at 0x00000000719E0000, image base 0x00000000FF330000, stack from 0x0000000000280000-0x0000000000290000
2019-08-13 16:47:42,493 [root] DEBUG: Commandline: C:\Windows\sysnative\wbem\wmiprvse.exe -secured -Embedding.
2019-08-13 16:47:42,525 [root] DEBUG: AddTrackedRegion: EntryPoint 0xa9b4, Entropy 5.871801e+00
2019-08-13 16:47:42,525 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FF330000 size 0x1000 added to tracked regions.
2019-08-13 16:47:42,525 [root] DEBUG: CreateThread: Initialising breakpoints for thread 924.
2019-08-13 16:47:42,525 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:47:42,525 [root] INFO: Added new process to list with pid: 2132
2019-08-13 16:47:42,525 [root] DEBUG: CreateThread: Initialising breakpoints for thread 764.
2019-08-13 16:47:42,525 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1428.
2019-08-13 16:47:42,525 [root] INFO: Monitor successfully loaded in process with pid 2132.
2019-08-13 16:47:42,665 [root] DEBUG: DLL loaded at 0x000007FEFCF50000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2019-08-13 16:47:42,665 [root] DEBUG: DLL loaded at 0x000007FEFC190000: C:\Windows\system32\ntmarta (0x2d000 bytes).
2019-08-13 16:47:42,665 [root] DEBUG: DLL loaded at 0x000007FEFE860000: C:\Windows\system32\WLDAP32 (0x52000 bytes).
2019-08-13 16:47:42,993 [root] DEBUG: DLL loaded at 0x000007FEFE400000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2019-08-13 16:47:42,993 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2344.
2019-08-13 16:47:43,023 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-13 16:47:43,071 [root] DEBUG: DLL loaded at 0x000007FEF9D50000: C:\Windows\system32\wbem\wbemprox (0xf000 bytes).
2019-08-13 16:47:43,071 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1628.
2019-08-13 16:47:43,118 [root] DEBUG: DLL loaded at 0x000007FEFC8F0000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2019-08-13 16:47:43,118 [root] DEBUG: DLL loaded at 0x000007FEFC5F0000: C:\Windows\system32\rsaenh (0x47000 bytes).
2019-08-13 16:47:43,148 [root] DEBUG: DLL loaded at 0x000007FEFD000000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2019-08-13 16:47:43,507 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2756.
2019-08-13 16:47:43,539 [root] DEBUG: DLL loaded at 0x000007FEFA0A0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2019-08-13 16:47:43,585 [root] DEBUG: DLL loaded at 0x000007FEF97C0000: C:\Windows\system32\wbem\wmiutils (0x26000 bytes).
2019-08-13 16:47:46,207 [root] DEBUG: DLL loaded at 0x000007FEF2BA0000: C:\Windows\system32\wbem\cimwin32 (0x1fa000 bytes).
2019-08-13 16:47:46,207 [root] DEBUG: DLL loaded at 0x000007FEF4570000: C:\Windows\system32\framedynos (0x4c000 bytes).
2019-08-13 16:47:46,207 [root] DEBUG: DLL loaded at 0x000007FEFAFA0000: C:\Windows\system32\WTSAPI32 (0x11000 bytes).
2019-08-13 16:47:49,108 [root] DEBUG: DLL loaded at 0x0000000073AA0000: C:\Windows\system32\WMI (0x3000 bytes).
2019-08-13 16:47:49,201 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1328.
2019-08-13 16:47:50,138 [root] DEBUG: DLL loaded at 0x71750000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni (0x104000 bytes).
2019-08-13 16:47:50,278 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1728.
2019-08-13 16:47:50,341 [root] DEBUG: Allocation: 0x7EF30000 - 0x7EF80000, size: 0x50000, protection: 0x40.
2019-08-13 16:47:50,543 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 34.
2019-08-13 16:47:50,559 [root] DEBUG: AddTrackedRegion: Region at 0x7EF30000 size 0x50000 added to tracked regions.
2019-08-13 16:47:50,684 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x7EF30000.
2019-08-13 16:47:50,684 [root] DEBUG: Allocation: 0x7EF30000 - 0x7EF31000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:50,809 [root] DEBUG: AllocationHandler: Previously reserved region 0x7EF30000 - 0x7EF80000, committing at: 0x7EF30000.
2019-08-13 16:47:50,809 [root] DEBUG: Allocation: 0x7EF30000 - 0x7EF31000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:50,917 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x7EF30000, size: 0x50000.
2019-08-13 16:47:50,934 [root] DEBUG: Allocation: 0x7EF20000 - 0x7EF30000, size: 0x10000, protection: 0x40.
2019-08-13 16:47:51,058 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 35.
2019-08-13 16:47:51,058 [root] DEBUG: AddTrackedRegion: Region at 0x7EF20000 size 0x10000 added to tracked regions.
2019-08-13 16:47:51,167 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x7EF20000.
2019-08-13 16:47:51,183 [root] DEBUG: Allocation: 0x7EF20000 - 0x7EF21000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:51,292 [root] DEBUG: AllocationHandler: Previously reserved region 0x7EF20000 - 0x7EF30000, committing at: 0x7EF20000.
2019-08-13 16:47:51,323 [root] DEBUG: Allocation: 0x0028B000 - 0x0028C000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:51,433 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 36.
2019-08-13 16:47:51,447 [root] DEBUG: AddTrackedRegion: Region at 0x00280000 size 0xc000 added to tracked regions.
2019-08-13 16:47:51,558 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2632.
2019-08-13 16:47:52,181 [root] DEBUG: DLL loaded at 0x6A310000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils (0x9000 bytes).
2019-08-13 16:47:52,305 [root] DEBUG: Allocation: 0x0B8D0000 - 0x0B8D1000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:52,322 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 37.
2019-08-13 16:47:52,430 [root] DEBUG: AddTrackedRegion: Region at 0x0B8D0000 size 0x1000 added to tracked regions.
2019-08-13 16:47:52,447 [root] DEBUG: Allocation: 0x0B8D1000 - 0x0B8D2000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:52,572 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 38.
2019-08-13 16:47:52,572 [root] DEBUG: AddTrackedRegion: Region at 0x0B8D0000 size 0x2000 added to tracked regions.
2019-08-13 16:47:52,680 [root] DEBUG: Allocation: 0x0B8D2000 - 0x0B8D3000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:52,680 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 39.
2019-08-13 16:47:52,884 [root] DEBUG: AddTrackedRegion: Region at 0x0B8D0000 size 0x3000 added to tracked regions.
2019-08-13 16:47:52,884 [root] DEBUG: Allocation: 0x0B8D3000 - 0x0B8D4000, size: 0x1000, protection: 0x40.
2019-08-13 16:47:52,976 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 40.
2019-08-13 16:47:52,976 [root] DEBUG: AddTrackedRegion: Region at 0x0B8D0000 size 0x4000 added to tracked regions.
2019-08-13 16:47:53,071 [root] DEBUG: set_caller_info: Adding region at 0x0B8D0000 to caller regions list.
2019-08-13 16:47:53,273 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2444.
2019-08-13 16:47:53,913 [root] DEBUG: DLL unloaded from 0x000007FEF9540000.
2019-08-13 16:47:54,288 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1960.
2019-08-13 16:47:54,957 [root] DEBUG: set_caller_info: Adding region at 0x004F0000 to caller regions list.
2019-08-13 16:48:02,821 [root] DEBUG: DLL unloaded from 0x0000000073AA0000.
2019-08-13 16:48:04,506 [root] DEBUG: DLL unloaded from 0x751B0000.
2019-08-13 16:48:26,548 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1336.
2019-08-13 16:48:26,579 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-13 16:48:27,016 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1132.
2019-08-13 16:48:27,608 [root] DEBUG: CreateThread: Initialising breakpoints for thread 648.
2019-08-13 16:48:27,905 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 1996
2019-08-13 16:48:27,921 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:48:27,921 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:48:27,921 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:48:27,921 [lib.api.process] INFO: 64-bit DLL to inject is C:\exrhhyewq\dll\wexpbM.dll, loader C:\exrhhyewq\bin\JjsuVYzF.exe
2019-08-13 16:48:28,092 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:48:28,108 [root] DEBUG: Loader: Injecting process 1996 (thread 2032) with C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:48:28,201 [root] DEBUG: Process image base: 0x00000000FF330000
2019-08-13 16:48:28,201 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:48:28,279 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00000000FF38F000 - 0x000007FEFF430000
2019-08-13 16:48:28,279 [root] DEBUG: InjectDllViaIAT: Allocated 0x238 bytes for new import table at 0x00000000FF390000.
2019-08-13 16:48:28,374 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-13 16:48:28,374 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:48:28,388 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 1996
2019-08-13 16:48:28,436 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:48:28,436 [root] DEBUG: Process dumps disabled.
2019-08-13 16:48:28,483 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:48:28,483 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:48:28,575 [root] INFO: Disabling sleep skipping.
2019-08-13 16:48:28,622 [root] WARNING: Unable to place hook on LockResource
2019-08-13 16:48:28,622 [root] WARNING: Unable to hook LockResource
2019-08-13 16:48:28,638 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-13 16:48:28,638 [root] DEBUG: Debugger initialised.
2019-08-13 16:48:28,670 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 1996 at 0x00000000719E0000, image base 0x00000000FF330000, stack from 0x00000000001C0000-0x00000000001D0000
2019-08-13 16:48:28,670 [root] DEBUG: Commandline: C:\Windows\sysnative\wbem\wmiprvse.exe -Embedding.
2019-08-13 16:48:28,717 [root] DEBUG: AddTrackedRegion: EntryPoint 0xa9b4, Entropy 5.871801e+00
2019-08-13 16:48:28,717 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FF330000 size 0x1000 added to tracked regions.
2019-08-13 16:48:28,795 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:48:28,795 [root] INFO: Added new process to list with pid: 1996
2019-08-13 16:48:28,809 [root] INFO: Monitor successfully loaded in process with pid 1996.
2019-08-13 16:48:29,138 [root] DEBUG: DLL loaded at 0x000007FEFCF50000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2019-08-13 16:48:29,154 [root] DEBUG: DLL loaded at 0x000007FEFC190000: C:\Windows\system32\ntmarta (0x2d000 bytes).
2019-08-13 16:48:29,232 [root] DEBUG: DLL loaded at 0x000007FEFE860000: C:\Windows\system32\WLDAP32 (0x52000 bytes).
2019-08-13 16:48:29,901 [root] DEBUG: DLL loaded at 0x000007FEFE400000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2019-08-13 16:48:29,917 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3004.
2019-08-13 16:48:29,996 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-13 16:48:30,089 [root] DEBUG: DLL loaded at 0x000007FEF9D50000: C:\Windows\system32\wbem\wbemprox (0xf000 bytes).
2019-08-13 16:48:30,105 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1276.
2019-08-13 16:48:30,276 [root] DEBUG: DLL loaded at 0x000007FEFC8F0000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2019-08-13 16:48:30,276 [root] DEBUG: DLL loaded at 0x000007FEFC5F0000: C:\Windows\system32\rsaenh (0x47000 bytes).
2019-08-13 16:48:30,355 [root] DEBUG: DLL loaded at 0x000007FEFD000000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2019-08-13 16:48:31,384 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1092.
2019-08-13 16:48:31,650 [root] DEBUG: DLL loaded at 0x000007FEFA0A0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2019-08-13 16:48:32,164 [root] DEBUG: DLL loaded at 0x000007FEF97C0000: C:\Windows\system32\wbem\wmiutils (0x26000 bytes).
2019-08-13 16:48:37,046 [root] DEBUG: DLL unloaded from 0x000007FEFE320000.
2019-08-13 16:48:37,187 [root] DEBUG: DLL loaded at 0x000007FEF9C50000: C:\Windows\System32\perfos (0xb000 bytes).
2019-08-13 16:48:39,589 [root] DEBUG: DLL loaded at 0x000007FEF9910000: C:\Windows\system32\wbem\wmiprov (0x3c000 bytes).
2019-08-13 16:48:39,823 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1924.
2019-08-13 16:48:39,823 [root] DEBUG: DLL unloaded from 0x000007FEFB0D0000.
2019-08-13 16:48:39,871 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:48:39,996 [root] DEBUG: Allocation: 0x0AC47000 - 0x0AC48000, size: 0x1000, protection: 0x40.
2019-08-13 16:48:40,042 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 41.
2019-08-13 16:48:40,088 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x18000 added to tracked regions.
2019-08-13 16:48:40,183 [root] DEBUG: Allocation: 0x0B8E0000 - 0x0B8E1000, size: 0x1000, protection: 0x40.
2019-08-13 16:48:40,213 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 42.
2019-08-13 16:48:40,213 [root] DEBUG: AddTrackedRegion: Region at 0x0B8E0000 size 0x1000 added to tracked regions.
2019-08-13 16:48:40,213 [root] DEBUG: set_caller_info: Adding region at 0x0B8E0000 to caller regions list.
2019-08-13 16:48:40,230 [root] DEBUG: Allocation: 0x087A1000 - 0x087A2000, size: 0x1000, protection: 0x40.
2019-08-13 16:48:40,230 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 43.
2019-08-13 16:48:40,244 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x2000 added to tracked regions.
2019-08-13 16:48:40,276 [root] DEBUG: Allocation: 0x0AC48000 - 0x0AC49000, size: 0x1000, protection: 0x40.
2019-08-13 16:48:40,322 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 44.
2019-08-13 16:48:40,322 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x19000 added to tracked regions.
2019-08-13 16:48:55,907 [root] DEBUG: Allocation: 0x0AC49000 - 0x0AC4A000, size: 0x1000, protection: 0x40.
2019-08-13 16:48:55,907 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 45.
2019-08-13 16:48:55,954 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x1a000 added to tracked regions.
2019-08-13 16:48:55,954 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3008.
2019-08-13 16:49:00,961 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1016.
2019-08-13 16:49:01,134 [root] DEBUG: DLL loaded at 0x71650000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni (0xf1000 bytes).
2019-08-13 16:49:01,180 [root] DEBUG: Allocation: 0x00283000 - 0x00284000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:01,226 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00280000, size: 0xb000.
2019-08-13 16:49:01,259 [root] DEBUG: DLL loaded at 0x71110000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni (0x536000 bytes).
2019-08-13 16:49:01,305 [root] DEBUG: Allocation: 0x00665000 - 0x00666000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:01,305 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00660000, size: 0xc000.
2019-08-13 16:49:01,351 [root] DEBUG: DLL loaded at 0x74A40000: C:\Windows\system32\rasapi32 (0x52000 bytes).
2019-08-13 16:49:01,368 [root] DEBUG: DLL loaded at 0x74A20000: C:\Windows\system32\rasman (0x15000 bytes).
2019-08-13 16:49:01,382 [root] DEBUG: DLL loaded at 0x74A10000: C:\Windows\system32\rtutils (0xd000 bytes).
2019-08-13 16:49:01,398 [root] DEBUG: Allocation: 0x0B8E1000 - 0x0B8E2000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:01,398 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 46.
2019-08-13 16:49:01,398 [root] DEBUG: AddTrackedRegion: Region at 0x0B8E0000 size 0x2000 added to tracked regions.
2019-08-13 16:49:01,414 [root] DEBUG: DLL loaded at 0x74BF0000: C:\Windows\system32\mswsock (0x3c000 bytes).
2019-08-13 16:49:01,414 [root] DEBUG: DLL loaded at 0x74BE0000: C:\Windows\System32\wshtcpip (0x5000 bytes).
2019-08-13 16:49:01,430 [root] DEBUG: DLL loaded at 0x74A00000: C:\Windows\System32\wship6 (0x6000 bytes).
2019-08-13 16:49:01,493 [root] DEBUG: Allocation: 0x0B8E2000 - 0x0B8E3000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:01,493 [root] DEBUG: DLL unloaded from 0x74A20000.
2019-08-13 16:49:01,493 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 47.
2019-08-13 16:49:01,493 [root] DEBUG: AddTrackedRegion: Region at 0x0B8E0000 size 0x3000 added to tracked regions.
2019-08-13 16:49:01,539 [root] DEBUG: DLL loaded at 0x710B0000: C:\Windows\system32\winhttp (0x58000 bytes).
2019-08-13 16:49:01,555 [root] DEBUG: DLL loaded at 0x71060000: C:\Windows\system32\webio (0x4f000 bytes).
2019-08-13 16:49:01,555 [root] DEBUG: DLL loaded at 0x71040000: C:\Windows\system32\IPHLPAPI (0x1c000 bytes).
2019-08-13 16:49:01,555 [root] DEBUG: DLL loaded at 0x73AA0000: C:\Windows\system32\WINNSI (0x7000 bytes).
2019-08-13 16:49:01,585 [root] DEBUG: DLL loaded at 0x71030000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes).
2019-08-13 16:49:01,617 [root] DEBUG: DLL loaded at 0x71010000: C:\Windows\system32\dhcpcsvc (0x12000 bytes).
2019-08-13 16:49:01,617 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:49:01,648 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-13 16:49:01,664 [root] DEBUG: DLL loaded at 0x71000000: C:\Windows\system32\credssp (0x8000 bytes).
2019-08-13 16:49:01,680 [root] DEBUG: DLL unloaded from 0x74C70000.
2019-08-13 16:49:01,680 [root] DEBUG: DLL loaded at 0x75A10000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2019-08-13 16:49:01,694 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1928.
2019-08-13 16:49:01,773 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:49:01,819 [root] DEBUG: Allocation: 0x0064B000 - 0x0064C000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:01,882 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 48.
2019-08-13 16:49:01,928 [root] DEBUG: AddTrackedRegion: Region at 0x00640000 size 0xc000 added to tracked regions.
2019-08-13 16:49:01,960 [root] DEBUG: DLL loaded at 0x74B50000: C:\Windows\system32\DNSAPI (0x44000 bytes).
2019-08-13 16:49:01,976 [root] DEBUG: DLL loaded at 0x70FF0000: C:\Windows\system32\rasadhlp (0x6000 bytes).
2019-08-13 16:49:04,332 [root] DEBUG: DLL loaded at 0x70FB0000: C:\Windows\System32\fwpuclnt (0x38000 bytes).
2019-08-13 16:49:04,861 [root] DEBUG: Allocation: 0x0065C000 - 0x0065D000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:04,861 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 49.
2019-08-13 16:49:04,861 [root] DEBUG: AddTrackedRegion: Region at 0x00650000 size 0xd000 added to tracked regions.
2019-08-13 16:49:05,970 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1148.
2019-08-13 16:49:05,970 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2412.
2019-08-13 16:49:05,984 [root] DEBUG: Allocation: 0x087A2000 - 0x087A3000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:05,984 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 50.
2019-08-13 16:49:05,984 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x3000 added to tracked regions.
2019-08-13 16:49:06,032 [root] DEBUG: Allocation: 0x0AC4A000 - 0x0AC4D000, size: 0x3000, protection: 0x40.
2019-08-13 16:49:06,032 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 51.
2019-08-13 16:49:06,032 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x1d000 added to tracked regions.
2019-08-13 16:49:06,032 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x0AC30000, TrackedRegion->RegionSize: 0x1d000, thread 2640
2019-08-13 16:49:06,032 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x0AC30000 to 0x0AC30000.
2019-08-13 16:49:06,032 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:49:06,032 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2944.
2019-08-13 16:49:06,032 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2632.
2019-08-13 16:49:06,032 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2444.
2019-08-13 16:49:06,032 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1960.
2019-08-13 16:49:06,062 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1148.
2019-08-13 16:49:06,062 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2412.
2019-08-13 16:49:06,095 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:49:06,095 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2944.
2019-08-13 16:49:06,095 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2632.
2019-08-13 16:49:06,095 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2444.
2019-08-13 16:49:06,095 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1960.
2019-08-13 16:49:06,109 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1148.
2019-08-13 16:49:06,109 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2412.
2019-08-13 16:49:06,109 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xfc, Size=0x0, Address=0x0AC4A000 and Type=0x1.
2019-08-13 16:49:06,109 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2640 type 1 at address 0x0AC4A000, size 0 with Callback 0x747e7620.
2019-08-13 16:49:06,109 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x0AC4A000
2019-08-13 16:49:06,109 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xfc, Size=0x4, Address=0x0AC3003C and Type=0x1.
2019-08-13 16:49:06,109 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2640 type 1 at address 0x0AC3003C, size 4 with Callback 0x747e7280.
2019-08-13 16:49:06,109 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0AC3003C
2019-08-13 16:49:06,109 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x0AC4A000 (size 0x3000).
2019-08-13 16:49:06,109 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E24318 (thread 2640)
2019-08-13 16:49:06,109 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC4A000.
2019-08-13 16:49:06,109 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x0AC4A000 and Type=0x0.
2019-08-13 16:49:06,109 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac4a000: 0x68.
2019-08-13 16:49:06,109 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:49:06,109 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E25F60 (thread 2640)
2019-08-13 16:49:06,109 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC4A000.
2019-08-13 16:49:06,109 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x0AC4A000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:49:06,109 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac4a000: 0x68.
2019-08-13 16:49:06,125 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:49:06,125 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E25F64 (thread 2640)
2019-08-13 16:49:06,125 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0AC4A000.
2019-08-13 16:49:06,125 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x0AC4A000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:49:06,125 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xac4a000: 0x68.
2019-08-13 16:49:06,125 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:49:06,141 [root] DEBUG: DLL loaded at 0x70FA0000: C:\Windows\system32\shfolder (0x5000 bytes).
2019-08-13 16:49:06,141 [root] DEBUG: Allocation: 0x0AC4D000 - 0x0AC4E000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,141 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 52.
2019-08-13 16:49:06,141 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x1e000 added to tracked regions.
2019-08-13 16:49:06,141 [root] DEBUG: Allocation: 0x087A3000 - 0x087A4000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,187 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 53.
2019-08-13 16:49:06,187 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x4000 added to tracked regions.
2019-08-13 16:49:06,187 [root] DEBUG: Allocation: 0x0AC4E000 - 0x0AC4F000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,187 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 54.
2019-08-13 16:49:06,187 [root] DEBUG: AddTrackedRegion: Region at 0x0AC30000 size 0x1f000 added to tracked regions.
2019-08-13 16:49:06,296 [root] DEBUG: Allocation: 0x0C770000 - 0x0C771000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,296 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 55.
2019-08-13 16:49:06,296 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x1000 added to tracked regions.
2019-08-13 16:49:06,296 [root] DEBUG: Allocation: 0x0C771000 - 0x0C772000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,312 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 56.
2019-08-13 16:49:06,328 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x2000 added to tracked regions.
2019-08-13 16:49:06,344 [root] DEBUG: DLL loaded at 0x60340000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\culture (0x8000 bytes).
2019-08-13 16:49:06,359 [root] DEBUG: DLL unloaded from 0x60340000.
2019-08-13 16:49:06,375 [root] DEBUG: set_caller_info: Adding region at 0x0C770000 to caller regions list.
2019-08-13 16:49:06,375 [root] DEBUG: Allocation: 0x087A4000 - 0x087A5000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,375 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 57.
2019-08-13 16:49:06,375 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x5000 added to tracked regions.
2019-08-13 16:49:06,391 [root] DEBUG: Allocation: 0x087A5000 - 0x087A6000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,391 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 58.
2019-08-13 16:49:06,391 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x6000 added to tracked regions.
2019-08-13 16:49:06,391 [root] DEBUG: Allocation: 0x004FD000 - 0x004FE000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,391 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 59.
2019-08-13 16:49:06,391 [root] DEBUG: AddTrackedRegion: Region at 0x004F0000 size 0xe000 added to tracked regions.
2019-08-13 16:49:06,421 [root] DEBUG: DLL loaded at 0x70520000: C:\Windows\SysWOW64\ieframe (0xa80000 bytes).
2019-08-13 16:49:06,469 [root] DEBUG: DLL loaded at 0x704E0000: C:\Windows\SysWOW64\OLEACC (0x3c000 bytes).
2019-08-13 16:49:06,469 [root] DEBUG: DLL loaded at 0x76CA0000: C:\Windows\syswow64\iertutil (0x1fb000 bytes).
2019-08-13 16:49:06,500 [root] DEBUG: DLL loaded at 0x70340000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32 (0x19e000 bytes).
2019-08-13 16:49:06,546 [root] DEBUG: Allocation: 0x0C772000 - 0x0C773000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,546 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 60.
2019-08-13 16:49:06,546 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x3000 added to tracked regions.
2019-08-13 16:49:06,594 [root] DEBUG: DLL loaded at 0x70310000: C:\Windows\system32\MLANG (0x2e000 bytes).
2019-08-13 16:49:06,625 [root] DEBUG: DLL loaded at 0x75600000: C:\Windows\syswow64\WININET (0xf5000 bytes).
2019-08-13 16:49:06,655 [root] DEBUG: DLL loaded at 0x74F40000: C:\Windows\syswow64\urlmon (0x136000 bytes).
2019-08-13 16:49:06,655 [root] DEBUG: DLL loaded at 0x75790000: C:\Windows\syswow64\CRYPT32 (0x11d000 bytes).
2019-08-13 16:49:06,655 [root] DEBUG: DLL loaded at 0x755F0000: C:\Windows\syswow64\MSASN1 (0xc000 bytes).
2019-08-13 16:49:06,703 [root] DEBUG: DLL loaded at 0x70300000: C:\Windows\system32\vaultcli (0xc000 bytes).
2019-08-13 16:49:06,733 [root] DEBUG: DLL unloaded from 0x75C10000.
2019-08-13 16:49:06,937 [root] INFO: Announced starting service "VaultSvc"
2019-08-13 16:49:06,937 [root] INFO: Attaching to Service Control Manager (services.exe - pid 460)
2019-08-13 16:49:06,937 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:49:06,937 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:49:06,937 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:49:06,937 [lib.api.process] INFO: 64-bit DLL to inject is C:\exrhhyewq\dll\wexpbM.dll, loader C:\exrhhyewq\bin\JjsuVYzF.exe
2019-08-13 16:49:06,937 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:49:06,937 [root] DEBUG: Loader: Injecting process 460 (thread 0) with C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:49:06,937 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 1896, handle 0x84
2019-08-13 16:49:06,937 [root] DEBUG: Process image base: 0x00000000FFA10000
2019-08-13 16:49:06,937 [root] DEBUG: InjectDllViaIAT: Not a new process, aborting IAT patch
2019-08-13 16:49:06,953 [root] DEBUG: InjectDll: IAT patching failed, falling back to thread injection.
2019-08-13 16:49:06,953 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:49:06,953 [root] DEBUG: Process dumps disabled.
2019-08-13 16:49:06,953 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:49:06,953 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:49:06,953 [root] INFO: Disabling sleep skipping.
2019-08-13 16:49:06,967 [root] WARNING: Unable to place hook on LockResource
2019-08-13 16:49:06,967 [root] WARNING: Unable to hook LockResource
2019-08-13 16:49:06,967 [root] DEBUG: Debugger initialised.
2019-08-13 16:49:06,983 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 460 at 0x00000000719E0000, image base 0x00000000FFA10000, stack from 0x0000000001056000-0x0000000001060000
2019-08-13 16:49:06,983 [root] DEBUG: Allocation: 0x0C773000 - 0x0C774000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:06,983 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3036.
2019-08-13 16:49:06,983 [root] DEBUG: Commandline: C:\Windows\sysnative\services.exe.
2019-08-13 16:49:06,983 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 61.
2019-08-13 16:49:06,983 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:49:06,983 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x4000 added to tracked regions.
2019-08-13 16:49:06,983 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2364.
2019-08-13 16:49:07,015 [root] DEBUG: AddTrackedRegion: EntryPoint 0x13310, Entropy 6.073540e+00
2019-08-13 16:49:07,015 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFA10000 size 0x1000 added to tracked regions.
2019-08-13 16:49:07,015 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:49:07,015 [root] INFO: Added new process to list with pid: 460
2019-08-13 16:49:07,015 [root] INFO: Monitor successfully loaded in process with pid 460.
2019-08-13 16:49:07,015 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2019-08-13 16:49:07,015 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2019-08-13 16:49:07,015 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:49:07,217 [root] DEBUG: DLL unloaded from 0x000007FEFE8C0000.
2019-08-13 16:49:08,059 [root] INFO: Announced 64-bit process name: lsass.exe pid: 2532
2019-08-13 16:49:08,059 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:49:08,059 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:49:08,059 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:49:08,059 [lib.api.process] INFO: 64-bit DLL to inject is C:\exrhhyewq\dll\wexpbM.dll, loader C:\exrhhyewq\bin\JjsuVYzF.exe
2019-08-13 16:49:08,107 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\xFpBNAZ.
2019-08-13 16:49:08,107 [root] DEBUG: Loader: Injecting process 2532 (thread 2568) with C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:49:08,107 [root] DEBUG: Process image base: 0x00000000FF1A0000
2019-08-13 16:49:08,107 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:49:08,107 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00000000FF1AC000 - 0x000007FEFF430000
2019-08-13 16:49:08,107 [root] DEBUG: InjectDllViaIAT: Allocated 0x2a4 bytes for new import table at 0x00000000FF1B0000.
2019-08-13 16:49:08,107 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-13 16:49:08,107 [root] DEBUG: Successfully injected DLL C:\exrhhyewq\dll\wexpbM.dll.
2019-08-13 16:49:08,154 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 2532
2019-08-13 16:49:08,200 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-13 16:49:08,200 [root] DEBUG: Process dumps disabled.
2019-08-13 16:49:08,200 [root] DEBUG: Import reconstruction of process dumps enabled.
2019-08-13 16:49:08,200 [root] DEBUG: Full process memory dumps enabled.
2019-08-13 16:49:08,200 [root] INFO: Disabling sleep skipping.
2019-08-13 16:49:08,216 [root] WARNING: Unable to place hook on LockResource
2019-08-13 16:49:08,216 [root] WARNING: Unable to hook LockResource
2019-08-13 16:49:08,216 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-13 16:49:08,232 [root] DEBUG: Debugger initialised.
2019-08-13 16:49:08,246 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 2532 at 0x00000000719E0000, image base 0x00000000FF1A0000, stack from 0x00000000000D4000-0x00000000000E0000
2019-08-13 16:49:08,246 [root] DEBUG: Commandline: C:\Windows\sysnative\lsass.exe.
2019-08-13 16:49:08,279 [root] DEBUG: AddTrackedRegion: EntryPoint 0x1850, Entropy 3.682657e+00
2019-08-13 16:49:08,279 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FF1A0000 size 0x1000 added to tracked regions.
2019-08-13 16:49:08,309 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-13 16:49:08,309 [root] INFO: Added new process to list with pid: 2532
2019-08-13 16:49:08,309 [root] INFO: Monitor successfully loaded in process with pid 2532.
2019-08-13 16:49:10,009 [root] DEBUG: DLL unloaded from 0x751B0000.
2019-08-13 16:49:38,167 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 460).
2019-08-13 16:49:38,184 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1748.
2019-08-13 16:49:38,184 [root] INFO: Notified of termination of process with pid 2532.
2019-08-13 16:49:38,198 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 2532).
2019-08-13 16:49:38,276 [root] DEBUG: Allocation: 0x0C774000 - 0x0C775000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,276 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 62.
2019-08-13 16:49:38,276 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x5000 added to tracked regions.
2019-08-13 16:49:38,276 [lib.api.process] WARNING: Unable to find process dump for process 2532.
2019-08-13 16:49:38,276 [root] INFO: Process with pid 2532 has terminated
2019-08-13 16:49:38,355 [root] DEBUG: Allocation: 0x0C775000 - 0x0C776000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,355 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 63.
2019-08-13 16:49:38,355 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x6000 added to tracked regions.
2019-08-13 16:49:38,417 [root] DEBUG: Allocation: 0x0C776000 - 0x0C777000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,417 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 64.
2019-08-13 16:49:38,417 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x7000 added to tracked regions.
2019-08-13 16:49:38,433 [root] DEBUG: Allocation: 0x0C777000 - 0x0C778000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,433 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 65.
2019-08-13 16:49:38,433 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x8000 added to tracked regions.
2019-08-13 16:49:38,448 [root] DEBUG: Allocation: 0x0C778000 - 0x0C77A000, size: 0x2000, protection: 0x40.
2019-08-13 16:49:38,448 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 66.
2019-08-13 16:49:38,448 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0xa000 added to tracked regions.
2019-08-13 16:49:38,448 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x0C770000, TrackedRegion->RegionSize: 0xa000, thread 2640
2019-08-13 16:49:38,448 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x0AC30000 to 0x0C770000.
2019-08-13 16:49:38,448 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:49:38,448 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2944.
2019-08-13 16:49:38,464 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2632.
2019-08-13 16:49:38,464 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2444.
2019-08-13 16:49:38,464 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1960.
2019-08-13 16:49:38,464 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1924.
2019-08-13 16:49:38,510 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1148.
2019-08-13 16:49:38,510 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2412.
2019-08-13 16:49:38,510 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:49:38,526 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2944.
2019-08-13 16:49:38,542 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2632.
2019-08-13 16:49:38,542 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2444.
2019-08-13 16:49:38,558 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1960.
2019-08-13 16:49:38,558 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1924.
2019-08-13 16:49:38,558 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1148.
2019-08-13 16:49:38,558 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2412.
2019-08-13 16:49:38,558 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xfc, Size=0x0, Address=0x0C778000 and Type=0x1.
2019-08-13 16:49:38,558 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2640 type 1 at address 0x0C778000, size 0 with Callback 0x747e7620.
2019-08-13 16:49:38,558 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x0C778000
2019-08-13 16:49:38,558 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xfc, Size=0x4, Address=0x0C77003C and Type=0x1.
2019-08-13 16:49:38,558 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2640 type 1 at address 0x0C77003C, size 4 with Callback 0x747e7280.
2019-08-13 16:49:38,558 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x0C77003C
2019-08-13 16:49:38,558 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x0C778000 (size 0x2000).
2019-08-13 16:49:38,558 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-13 16:49:38,558 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E2C6C2 (thread 2640)
2019-08-13 16:49:38,573 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0C778000.
2019-08-13 16:49:38,573 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x0C778000 and Type=0x0.
2019-08-13 16:49:38,573 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xc778000: 0x45.
2019-08-13 16:49:38,573 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:49:38,573 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E2C6C6 (thread 2640)
2019-08-13 16:49:38,573 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0C778000.
2019-08-13 16:49:38,573 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x0C778000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:49:38,588 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xc778000: 0x45.
2019-08-13 16:49:38,588 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:49:38,588 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73E25F60 (thread 2640)
2019-08-13 16:49:38,588 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x0C778000.
2019-08-13 16:49:38,588 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x0C778000 already exists for thread 2640 (process 2228), skipping.
2019-08-13 16:49:38,588 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xc778000: 0x45.
2019-08-13 16:49:38,588 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-13 16:49:38,588 [root] DEBUG: Allocation: 0x087A6000 - 0x087A7000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,588 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 67.
2019-08-13 16:49:38,605 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x7000 added to tracked regions.
2019-08-13 16:49:38,621 [root] DEBUG: Allocation: 0x0C77A000 - 0x0C77B000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,635 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 68.
2019-08-13 16:49:38,635 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0xb000 added to tracked regions.
2019-08-13 16:49:38,635 [root] DEBUG: Allocation: 0x00653000 - 0x00654000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,635 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00650000, size: 0xb000.
2019-08-13 16:49:38,730 [root] DEBUG: Allocation: 0x0C77B000 - 0x0C77C000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,730 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 69.
2019-08-13 16:49:38,730 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0xc000 added to tracked regions.
2019-08-13 16:49:38,760 [root] DEBUG: Allocation: 0x0C77C000 - 0x0C77D000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,760 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 70.
2019-08-13 16:49:38,760 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0xd000 added to tracked regions.
2019-08-13 16:49:38,808 [root] DEBUG: Allocation: 0x0C77D000 - 0x0C77E000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,808 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 71.
2019-08-13 16:49:38,808 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0xe000 added to tracked regions.
2019-08-13 16:49:38,822 [root] DEBUG: Allocation: 0x0C77E000 - 0x0C77F000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:38,822 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 72.
2019-08-13 16:49:38,822 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0xf000 added to tracked regions.
2019-08-13 16:49:38,869 [root] DEBUG: DLL loaded at 0x702D0000: C:\Windows\SysWOW64\wshom.ocx (0x21000 bytes).
2019-08-13 16:49:38,885 [root] DEBUG: DLL loaded at 0x702B0000: C:\Windows\SysWOW64\MPR (0x12000 bytes).
2019-08-13 16:49:38,901 [root] DEBUG: DLL loaded at 0x70280000: C:\Windows\SysWOW64\ScrRun (0x2a000 bytes).
2019-08-13 16:49:38,917 [root] DEBUG: DLL loaded at 0x70270000: C:\Windows\SysWOW64\VERSION (0x9000 bytes).
2019-08-13 16:49:38,947 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1584.
2019-08-13 16:49:39,026 [root] DEBUG: Allocation: 0x0C77F000 - 0x0C780000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,042 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 73.
2019-08-13 16:49:39,042 [root] DEBUG: AddTrackedRegion: Region at 0x0C770000 size 0x10000 added to tracked regions.
2019-08-13 16:49:39,056 [root] DEBUG: Allocation: 0x08992000 - 0x08993000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,072 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 74.
2019-08-13 16:49:39,072 [root] DEBUG: AddTrackedRegion: Region at 0x08990000 size 0x3000 added to tracked regions.
2019-08-13 16:49:39,104 [root] DEBUG: Allocation: 0x0B840000 - 0x0B841000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,119 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 75.
2019-08-13 16:49:39,151 [root] DEBUG: AddTrackedRegion: Region at 0x0B840000 size 0x1000 added to tracked regions.
2019-08-13 16:49:39,151 [root] DEBUG: set_caller_info: Adding region at 0x0B840000 to caller regions list.
2019-08-13 16:49:39,167 [root] DEBUG: Allocation: 0x0B841000 - 0x0B842000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,167 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 76.
2019-08-13 16:49:39,167 [root] DEBUG: AddTrackedRegion: Region at 0x0B840000 size 0x2000 added to tracked regions.
2019-08-13 16:49:39,213 [root] DEBUG: Allocation: 0x0B8E3000 - 0x0B8E4000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,213 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 77.
2019-08-13 16:49:39,213 [root] DEBUG: AddTrackedRegion: Region at 0x0B8E0000 size 0x4000 added to tracked regions.
2019-08-13 16:49:39,259 [root] DEBUG: Allocation: 0x0B8D4000 - 0x0B8D5000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,259 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 78.
2019-08-13 16:49:39,259 [root] DEBUG: AddTrackedRegion: Region at 0x0B8D0000 size 0x5000 added to tracked regions.
2019-08-13 16:49:39,276 [root] DEBUG: CreateThread: Initialising breakpoints for thread 972.
2019-08-13 16:49:39,322 [root] DEBUG: Allocation: 0x0B842000 - 0x0B843000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,322 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 79.
2019-08-13 16:49:39,338 [root] DEBUG: AddTrackedRegion: Region at 0x0B840000 size 0x3000 added to tracked regions.
2019-08-13 16:49:39,431 [root] DEBUG: Allocation: 0x087A7000 - 0x087A8000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,447 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 80.
2019-08-13 16:49:39,447 [root] DEBUG: AddTrackedRegion: Region at 0x087A0000 size 0x8000 added to tracked regions.
2019-08-13 16:49:39,447 [root] DEBUG: Allocation: 0x0B843000 - 0x0B844000, size: 0x1000, protection: 0x40.
2019-08-13 16:49:39,447 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 81.
2019-08-13 16:49:39,447 [root] DEBUG: AddTrackedRegion: Region at 0x0B840000 size 0x4000 added to tracked regions.
2019-08-13 16:50:01,224 [modules.auxiliary.human] INFO: Found button "OK", clicking it
2019-08-13 16:50:01,770 [root] DEBUG: DLL unloaded from 0x710B0000.
2019-08-13 16:50:03,674 [root] INFO: Announced 64-bit process name: taskhost.exe pid: 1488
2019-08-13 16:50:03,737 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-13 16:50:03,739 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2019-08-13 16:50:03,739 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2019-08-13 16:50:03,740 [lib.api.process] INFO: 64-bit DLL to inject is C:\exrhhyewq\dll\wexpbM.dll, loader C:\exrhhyewq\bin\JjsuVYzF.exe
2019-08-13 16:50:03,769 [root] ERROR: Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 831, in run
    handler.start()
  File "C:\Python27\lib\threading.py", line 745, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 831, in run
    handler.start()
  File "C:\Python27\lib\threading.py", line 745, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2019-08-13 16:50:03,839 [root] ERROR: Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 718, in run
    res = proc.inject(INJECT_QUEUEUSERAPC, interest)
  File "C:\exrhhyewq\lib\api\process.py", line 571, in inject
    ret = subprocess.call([bin_name, "inject", str(self.pid), str(thread_id), dll, str(INJECT_QUEUEUSERAPC)])
  File "C:\Python27\lib\subprocess.py", line 522, in call
    return Popen(*popenargs, **kwargs).wait()
  File "C:\Python27\lib\subprocess.py", line 709, in __init__
    errread, errwrite)
  File "C:\Python27\lib\subprocess.py", line 957, in _execute_child
    startupinfo)
WindowsError: [Error 8] Not enough storage is available to process this command
Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 718, in run
    res = proc.inject(INJECT_QUEUEUSERAPC, interest)
  File "C:\exrhhyewq\lib\api\process.py", line 571, in inject
    ret = subprocess.call([bin_name, "inject", str(self.pid), str(thread_id), dll, str(INJECT_QUEUEUSERAPC)])
  File "C:\Python27\lib\subprocess.py", line 522, in call
    return Popen(*popenargs, **kwargs).wait()
  File "C:\Python27\lib\subprocess.py", line 709, in __init__
    errread, errwrite)
  File "C:\Python27\lib\subprocess.py", line 957, in _execute_child
    startupinfo)
WindowsError: [Error 8] Not enough storage is available to process this command
2019-08-13 16:50:06,180 [root] ERROR: Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 831, in run
    handler.start()
  File "C:\Python27\lib\threading.py", line 745, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 831, in run
    handler.start()
  File "C:\Python27\lib\threading.py", line 745, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2019-08-13 16:50:09,016 [root] DEBUG: DLL unloaded from 0x751B0000.
2019-08-13 16:50:09,681 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2800.
2019-08-13 16:50:09,684 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-13 16:50:09,762 [root] DEBUG: DLL unloaded from 0x000007FEF9D50000.
2019-08-13 16:50:29,835 [root] INFO: Analysis timeout hit (200 seconds), terminating analysis.
2019-08-13 16:50:29,835 [root] INFO: Created shutdown mutex.
2019-08-13 16:50:30,854 [lib.api.process] INFO: Successfully received reply to terminate_event, pid 2228
2019-08-13 16:50:30,854 [root] INFO: Terminate event set for process 2228.
2019-08-13 16:50:30,854 [root] INFO: Terminating process 2228 before shutdown.
2019-08-13 16:50:30,854 [root] INFO: Waiting for process 2228 to exit.
2019-08-13 16:50:30,900 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 2228).
2019-08-13 16:50:30,901 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1040.
2019-08-13 16:50:30,915 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2944.
2019-08-13 16:50:30,920 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2632.
2019-08-13 16:50:30,924 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2444.
2019-08-13 16:50:30,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1960.
2019-08-13 16:50:30,934 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1924.
2019-08-13 16:50:30,937 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1148.
2019-08-13 16:50:30,940 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2412.
2019-08-13 16:50:30,944 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1584.
2019-08-13 16:50:30,950 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 972.
2019-08-13 16:50:30,976 [root] ERROR: Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 732, in run
    dump_file(file_path)
  File "C:\exrhhyewq\analyzer.py", line 160, in dump_file
    sha256 = hash_file(hashlib.sha256, file_path)
  File "C:\exrhhyewq\lib\common\hashing.py", line 17, in hash_file
    buf = f.read(BUFSIZE)
MemoryError
Traceback (most recent call last):
  File "C:\exrhhyewq\analyzer.py", line 732, in run
    dump_file(file_path)
  File "C:\exrhhyewq\analyzer.py", line 160, in dump_file
    sha256 = hash_file(hashlib.sha256, file_path)
  File "C:\exrhhyewq\lib\common\hashing.py", line 17, in hash_file
    buf = f.read(BUFSIZE)
MemoryError
2019-08-13 16:50:31,855 [root] INFO: Waiting for process 2228 to exit.
2019-08-13 16:50:32,855 [root] INFO: Waiting for process 2228 to exit.
2019-08-13 16:50:33,859 [root] INFO: Waiting for process 2228 to exit.
2019-08-13 16:50:34,859 [lib.api.process] INFO: Successfully terminated process with pid 2228.
2019-08-13 16:50:34,859 [root] INFO: Waiting for process 2228 to exit.
2019-08-13 16:50:35,859 [lib.api.process] INFO: Successfully received reply to terminate_event, pid 2132
2019-08-13 16:50:35,859 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 2132).
2019-08-13 16:50:35,859 [root] INFO: Terminate event set for process 2132.
2019-08-13 16:50:35,859 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2756.
2019-08-13 16:50:35,859 [root] INFO: Terminating process 2132 before shutdown.
2019-08-13 16:50:35,859 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1328.
2019-08-13 16:50:35,859 [root] INFO: Waiting for process 2132 to exit.
2019-08-13 16:50:35,859 [root] DEBUG: Terminate Event: CAPE shutdown complete for process 2132
2019-08-13 16:50:36,859 [lib.api.process] INFO: Successfully received reply to terminate_event, pid 1996
2019-08-13 16:50:36,859 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 1996).
2019-08-13 16:50:36,859 [root] INFO: Terminate event set for process 1996.
2019-08-13 16:50:36,859 [root] DEBUG: Terminate Event: CAPE shutdown complete for process 1996
2019-08-13 16:50:36,859 [root] INFO: Terminating process 1996 before shutdown.
2019-08-13 16:50:36,880 [root] INFO: Shutting down package.
2019-08-13 16:50:36,900 [lib.api.process] WARNING: Unable to find process dump for process 2228.
2019-08-13 16:50:36,910 [lib.api.process] WARNING: Unable to find process dump for process 564.
2019-08-13 16:50:36,930 [lib.api.process] WARNING: Unable to find process dump for process 2128.
2019-08-13 16:50:36,960 [lib.api.process] WARNING: Unable to find process dump for process 2132.
2019-08-13 16:50:36,970 [lib.api.process] WARNING: Unable to find process dump for process 1996.
2019-08-13 16:50:36,990 [lib.api.process] WARNING: Unable to find process dump for process 460.
2019-08-13 16:50:36,992 [root] INFO: Stopping auxiliary modules.
2019-08-13 16:50:37,012 [root] INFO: Finishing auxiliary modules.
2019-08-13 16:50:37,012 [root] INFO: Shutting down pipe server and dumping dropped files.
2019-08-13 16:50:37,012 [root] WARNING: File at path "C:\fOcJxESUJT\debugger" does not exist, skip.
2019-08-13 16:50:37,012 [root] WARNING: Monitor injection attempted but failed for process 1488.
2019-08-13 16:50:37,022 [root] INFO: Analysis completed.

MalScore

10.0

Malicious

Machine

Name Label Manager Started On Shutdown On
target-01 target-01 ESX 2019-08-13 15:46:59 2019-08-13 15:51:04

File Details

File Name JJB-175325-#33001.exe
File Size 966656 bytes
File Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 6a237f3a634fe7697150c1aceb4849e8
SHA1 466eddb76b322d5252689ebd5de8e3b37adbde9e
SHA256 2274f0b2e9370ac7e7e7777c34766c09b09ef528fbbf6a6b04e1291e69ff6bd6
SHA512 b6b121a08d95c6b8741e10d292b0e8e63ae94120b4d27d8160c64caf1833eb369c943fdd2a3d785466c4d939dc65b75b27cbaf79b5e48f6a3a9d5f468fd40198
CRC32 04BE684F
Ssdeep 12288:44IitFNVMfBetcCzJ4iQSYPSYA3ekunqAI+jeXBaG02d3L:44IidVUeuCHQSASe03
TrID
  • 88.6% (.EXE) Win32 Executable Microsoft Visual Basic 6 (82067/2/8)
  • 4.8% (.EXE) Win32 Executable (generic) (4508/7/1)
  • 2.1% (.EXE) OS/2 Executable (generic) (2029/13)
  • 2.1% (.EXE) Generic Win/DOS Executable (2002/3)
  • 2.1% (.EXE) DOS Executable Generic (2000/1)
ClamAV None matched
Yara None matched
CAPE Yara None matched
Resubmit sample

Signatures

Behavioural detection: Executable code extraction
SetUnhandledExceptionFilter detected (possible anti-debug)
Yara rule detections observed from a process memory dump/dropped files/CAPE
Hit: PID 420 trigged the Yara rule 'embedded_win_api'
Hit: PID 420 trigged the Yara rule 'shellcode'
Hit: PID 420 trigged the Yara rule 'HeavensGate'
Hit: PID 2228 trigged the Yara rule 'shellcode'
Guard pages use detected - possible anti-debugging.
Dynamic (imported) function loading detected
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: OLEAUT32.dll/OleLoadPictureEx
DynamicLoader: OLEAUT32.dll/DispCallFunc
DynamicLoader: OLEAUT32.dll/LoadTypeLibEx
DynamicLoader: OLEAUT32.dll/UnRegisterTypeLib
DynamicLoader: OLEAUT32.dll/CreateTypeLib2
DynamicLoader: OLEAUT32.dll/VarDateFromUdate
DynamicLoader: OLEAUT32.dll/VarUdateFromDate
DynamicLoader: OLEAUT32.dll/GetAltMonthNames
DynamicLoader: OLEAUT32.dll/VarNumFromParseNum
DynamicLoader: OLEAUT32.dll/VarParseNumFromStr
DynamicLoader: OLEAUT32.dll/VarDecFromR4
DynamicLoader: OLEAUT32.dll/VarDecFromR8
DynamicLoader: OLEAUT32.dll/VarDecFromDate
DynamicLoader: OLEAUT32.dll/VarDecFromI4
DynamicLoader: OLEAUT32.dll/VarDecFromCy
DynamicLoader: OLEAUT32.dll/VarR4FromDec
DynamicLoader: OLEAUT32.dll/GetRecordInfoFromTypeInfo
DynamicLoader: OLEAUT32.dll/GetRecordInfoFromGuids
DynamicLoader: OLEAUT32.dll/SafeArrayGetRecordInfo
DynamicLoader: OLEAUT32.dll/SafeArraySetRecordInfo
DynamicLoader: OLEAUT32.dll/SafeArrayGetIID
DynamicLoader: OLEAUT32.dll/SafeArraySetIID
DynamicLoader: OLEAUT32.dll/SafeArrayCopyData
DynamicLoader: OLEAUT32.dll/SafeArrayAllocDescriptorEx
DynamicLoader: OLEAUT32.dll/SafeArrayCreateEx
DynamicLoader: OLEAUT32.dll/VarFormat
DynamicLoader: OLEAUT32.dll/VarFormatDateTime
DynamicLoader: OLEAUT32.dll/VarFormatNumber
DynamicLoader: OLEAUT32.dll/VarFormatPercent
DynamicLoader: OLEAUT32.dll/VarFormatCurrency
DynamicLoader: OLEAUT32.dll/VarWeekdayName
DynamicLoader: OLEAUT32.dll/VarMonthName
DynamicLoader: OLEAUT32.dll/VarAdd
DynamicLoader: OLEAUT32.dll/VarAnd
DynamicLoader: OLEAUT32.dll/VarCat
DynamicLoader: OLEAUT32.dll/VarDiv
DynamicLoader: OLEAUT32.dll/VarEqv
DynamicLoader: OLEAUT32.dll/VarIdiv
DynamicLoader: OLEAUT32.dll/VarImp
DynamicLoader: OLEAUT32.dll/VarMod
DynamicLoader: OLEAUT32.dll/VarMul
DynamicLoader: OLEAUT32.dll/VarOr
DynamicLoader: OLEAUT32.dll/VarPow
DynamicLoader: OLEAUT32.dll/VarSub
DynamicLoader: OLEAUT32.dll/VarXor
DynamicLoader: OLEAUT32.dll/VarAbs
DynamicLoader: OLEAUT32.dll/VarFix
DynamicLoader: OLEAUT32.dll/VarInt
DynamicLoader: OLEAUT32.dll/VarNeg
DynamicLoader: OLEAUT32.dll/VarNot
DynamicLoader: OLEAUT32.dll/VarRound
DynamicLoader: OLEAUT32.dll/VarCmp
DynamicLoader: OLEAUT32.dll/VarDecAdd
DynamicLoader: OLEAUT32.dll/VarDecCmp
DynamicLoader: OLEAUT32.dll/VarBstrCat
DynamicLoader: OLEAUT32.dll/VarCyMulI4
DynamicLoader: OLEAUT32.dll/VarBstrCmp
DynamicLoader: ole32.dll/CoCreateInstanceEx
DynamicLoader: ole32.dll/CLSIDFromProgIDEx
DynamicLoader: SXS.DLL/SxsOleAut32MapIIDOrCLSIDToTypeLibrary
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: USER32.dll/MonitorFromWindow
DynamicLoader: USER32.dll/MonitorFromRect
DynamicLoader: USER32.dll/MonitorFromPoint
DynamicLoader: USER32.dll/EnumDisplayMonitors
DynamicLoader: USER32.dll/GetMonitorInfoA
DynamicLoader: kernel32.dll/NlsGetCacheUpdateCount
DynamicLoader: VERSION.DLL/VerQueryValueA
DynamicLoader: VERSION.DLL/GetFileVersionInfoSizeA
DynamicLoader: VERSION.DLL/GetFileVersionInfoA
DynamicLoader: kernel32.dll/GetCalendarInfoW
DynamicLoader: kernel32.dll/RtlMoveMemory
DynamicLoader: kernel32.dll/EnumUILanguagesA
DynamicLoader: kernel32.dll/GetTickCount
DynamicLoader: kernel32.dll/Sleep
DynamicLoader: USER32.dll/GetCursorPos
DynamicLoader: USER32.dll/EnumWindows
DynamicLoader: kernel32.dll/SetErrorMode
DynamicLoader: kernel32.dll/SetLastError
DynamicLoader: kernel32.dll/VirtualAllocEx
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: shell32.DLL/ShellExecuteW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/UnmapViewOfFile
DynamicLoader: kernel32.dll/VirtualAllocEx
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/TerminateProcess
DynamicLoader: kernel32.dll/VirtualProtectEx
DynamicLoader: kernel32.dll/CreateProcessInternalW
DynamicLoader: kernel32.dll/GetTempPathW
DynamicLoader: kernel32.dll/GetLongPathNameW
DynamicLoader: kernel32.dll/GetFileSize
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: ntdll.dll/NtProtectVirtualMemory
DynamicLoader: kernel32.dll/GetCommandLineW
DynamicLoader: ntdll.dll/NtGetContextThread
DynamicLoader: ntdll.dll/NtSetContextThread
DynamicLoader: ntdll.dll/NtResumeThread
DynamicLoader: kernel32.dll/GetExitCodeProcess
DynamicLoader: kernel32.dll/IsTNT
DynamicLoader: kernel32.dll/IsProcessorFeaturePresent
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: kernel32.dll/GetTickCount
DynamicLoader: kernel32.dll/Sleep
DynamicLoader: USER32.dll/GetCursorPos
DynamicLoader: USER32.dll/EnumWindows
DynamicLoader: kernel32.dll/SetErrorMode
DynamicLoader: kernel32.dll/SetLastError
DynamicLoader: kernel32.dll/VirtualAllocEx
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: shell32.DLL/ShellExecuteW
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/UnmapViewOfFile
DynamicLoader: kernel32.dll/VirtualAllocEx
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/TerminateProcess
DynamicLoader: kernel32.dll/VirtualProtectEx
DynamicLoader: kernel32.dll/CreateProcessInternalW
DynamicLoader: kernel32.dll/GetTempPathW
DynamicLoader: kernel32.dll/GetLongPathNameW
DynamicLoader: kernel32.dll/GetFileSize
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: ntdll.dll/NtProtectVirtualMemory
DynamicLoader: kernel32.dll/GetCommandLineW
DynamicLoader: kernel32.dll/RaiseException
DynamicLoader: kernel32.dll/GetLastError
DynamicLoader: kernel32.dll/IsBadReadPtr
DynamicLoader: kernel32.dll/VirtualProtect
DynamicLoader: kernel32.dll/GetProcAddress
DynamicLoader: kernel32.dll/GetModuleHandleA
DynamicLoader: kernel32.dll/MultiByteToWideChar
DynamicLoader: kernel32.dll/lstrlenA
DynamicLoader: kernel32.dll/WideCharToMultiByte
DynamicLoader: kernel32.dll/lstrlenW
DynamicLoader: kernel32.dll/GetModuleFileNameW
DynamicLoader: kernel32.dll/GetModuleFileNameA
DynamicLoader: kernel32.dll/LoadLibraryA
DynamicLoader: kernel32.dll/FreeResource
DynamicLoader: kernel32.dll/SizeofResource
DynamicLoader: kernel32.dll/LockResource
DynamicLoader: kernel32.dll/LoadResource
DynamicLoader: kernel32.dll/FindResourceA
DynamicLoader: kernel32.dll/Module32Next
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/Module32First
DynamicLoader: kernel32.dll/CreateToolhelp32Snapshot
DynamicLoader: kernel32.dll/GetCurrentProcessId
DynamicLoader: kernel32.dll/CreateFileA
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: kernel32.dll/VirtualAlloc
DynamicLoader: kernel32.dll/VirtualFree
DynamicLoader: kernel32.dll/HeapFree
DynamicLoader: kernel32.dll/GetProcessHeap
DynamicLoader: kernel32.dll/FreeLibrary
DynamicLoader: kernel32.dll/HeapAlloc
DynamicLoader: kernel32.dll/HeapReAlloc
DynamicLoader: kernel32.dll/GetCommandLineA
DynamicLoader: kernel32.dll/DeleteCriticalSection
DynamicLoader: kernel32.dll/LeaveCriticalSection
DynamicLoader: kernel32.dll/EnterCriticalSection
DynamicLoader: kernel32.dll/HeapCreate
DynamicLoader: kernel32.dll/Sleep
DynamicLoader: kernel32.dll/ExitProcess
DynamicLoader: kernel32.dll/WriteFile
DynamicLoader: kernel32.dll/GetStdHandle
DynamicLoader: kernel32.dll/HeapSize
DynamicLoader: kernel32.dll/TerminateProcess
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/UnhandledExceptionFilter
DynamicLoader: kernel32.dll/SetUnhandledExceptionFilter
DynamicLoader: kernel32.dll/IsDebuggerPresent
DynamicLoader: kernel32.dll/GetConsoleCP
DynamicLoader: kernel32.dll/GetConsoleMode
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: kernel32.dll/TlsGetValue
DynamicLoader: kernel32.dll/TlsAlloc
DynamicLoader: kernel32.dll/TlsSetValue
DynamicLoader: kernel32.dll/TlsFree
DynamicLoader: kernel32.dll/InterlockedIncrement
DynamicLoader: kernel32.dll/SetLastError
DynamicLoader: kernel32.dll/GetCurrentThreadId
DynamicLoader: kernel32.dll/InterlockedDecrement
DynamicLoader: kernel32.dll/FlushFileBuffers
DynamicLoader: kernel32.dll/SetFilePointer
DynamicLoader: kernel32.dll/SetHandleCount
DynamicLoader: kernel32.dll/GetFileType
DynamicLoader: kernel32.dll/GetStartupInfoA
DynamicLoader: kernel32.dll/RtlUnwind
DynamicLoader: kernel32.dll/FreeEnvironmentStringsA
DynamicLoader: kernel32.dll/GetEnvironmentStrings
DynamicLoader: kernel32.dll/FreeEnvironmentStringsW
DynamicLoader: kernel32.dll/GetEnvironmentStringsW
DynamicLoader: kernel32.dll/QueryPerformanceCounter
DynamicLoader: kernel32.dll/GetTickCount
DynamicLoader: kernel32.dll/GetSystemTimeAsFileTime
DynamicLoader: kernel32.dll/InitializeCriticalSectionAndSpinCount
DynamicLoader: kernel32.dll/GetCPInfo
DynamicLoader: kernel32.dll/GetACP
DynamicLoader: kernel32.dll/GetOEMCP
DynamicLoader: kernel32.dll/IsValidCodePage
DynamicLoader: kernel32.dll/CompareStringA
DynamicLoader: kernel32.dll/CompareStringW
DynamicLoader: kernel32.dll/SetEnvironmentVariableA
DynamicLoader: kernel32.dll/WriteConsoleA
DynamicLoader: kernel32.dll/GetConsoleOutputCP
DynamicLoader: kernel32.dll/WriteConsoleW
DynamicLoader: kernel32.dll/SetStdHandle
DynamicLoader: kernel32.dll/GetLocaleInfoA
DynamicLoader: kernel32.dll/LCMapStringA
DynamicLoader: kernel32.dll/LCMapStringW
DynamicLoader: kernel32.dll/GetStringTypeA
DynamicLoader: kernel32.dll/GetStringTypeW
DynamicLoader: kernel32.dll/SetEndOfFile
DynamicLoader: kernel32.dll/CreateThread
DynamicLoader: kernel32.dll/GetCurrentThread
DynamicLoader: kernel32.dll/TerminateThread
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: mscoree.dll/_CorExeMain
DynamicLoader: mscoree.dll/CLRCreateInstance
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: mscoree.dll/
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: mscoreei.dll/RegisterShimImplCallback
DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
DynamicLoader: mscoreei.dll/SetShellShimInstance
DynamicLoader: mscoreei.dll/OnShimDllMainCalled
DynamicLoader: mscoreei.dll/CLRCreateInstance
DynamicLoader: kernel32.dll/GetModuleFileNameW
DynamicLoader: kernel32.dll/GetModuleFileNameA
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: kernel32.dll/GetModuleHandleA
DynamicLoader: kernel32.dll/CreateFileA
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
DynamicLoader: mscoreei.dll/_CorExeMain
DynamicLoader: SHLWAPI.dll/UrlIsW
DynamicLoader: kernel32.dll/GetCurrentPackageId
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/InitializeCriticalSectionAndSpinCount
DynamicLoader: kernel32.dll/IsProcessorFeaturePresent
DynamicLoader: msvcrt.dll/_set_error_mode
DynamicLoader: msvcrt.dll/?set_terminate@@YAP6AXXZP6AXXZ@Z
DynamicLoader: msvcrt.dll/_get_terminate
DynamicLoader: kernel32.dll/FindActCtxSectionStringW
DynamicLoader: kernel32.dll/GetSystemWindowsDirectoryW
DynamicLoader: mscoree.dll/GetProcessExecutableHeap
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
DynamicLoader: mscorwks.dll/SetLoadedByMscoree
DynamicLoader: mscorwks.dll/_CorExeMain
DynamicLoader: mscorwks.dll/GetCLRFunction
DynamicLoader: ADVAPI32.dll/RegisterTraceGuidsW
DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
DynamicLoader: ADVAPI32.dll/GetTraceLoggerHandle
DynamicLoader: ADVAPI32.dll/GetTraceEnableLevel
DynamicLoader: ADVAPI32.dll/GetTraceEnableFlags
DynamicLoader: ADVAPI32.dll/TraceEvent
DynamicLoader: mscoree.dll/IEE
DynamicLoader: mscoreei.dll/IEE_RetAddr
DynamicLoader: mscoreei.dll/IEE
DynamicLoader: mscorwks.dll/IEE
DynamicLoader: mscoree.dll/GetStartupFlags
DynamicLoader: mscoreei.dll/GetStartupFlags_RetAddr
DynamicLoader: mscoreei.dll/GetStartupFlags
DynamicLoader: mscoree.dll/GetHostConfigurationFile
DynamicLoader: mscoreei.dll/GetHostConfigurationFile_RetAddr
DynamicLoader: mscoreei.dll/GetHostConfigurationFile
DynamicLoader: mscoreei.dll/GetCORVersion_RetAddr
DynamicLoader: mscoreei.dll/GetCORVersion
DynamicLoader: mscoree.dll/GetCORSystemDirectory
DynamicLoader: mscoreei.dll/GetCORSystemDirectory_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream
DynamicLoader: ntdll.dll/RtlUnwind
DynamicLoader: kernel32.dll/IsWow64Process
DynamicLoader: kernel32.dll/GetSystemWindowsDirectoryW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: kernel32.dll/SetThreadStackGuarantee
DynamicLoader: kernel32.dll/FlsSetValue
DynamicLoader: kernel32.dll/FlsGetValue
DynamicLoader: kernel32.dll/FlsAlloc
DynamicLoader: kernel32.dll/FlsFree
DynamicLoader: kernel32.dll/AddVectoredContinueHandler
DynamicLoader: kernel32.dll/RemoveVectoredContinueHandler
DynamicLoader: ADVAPI32.dll/ConvertSidToStringSidW
DynamicLoader: shell32.DLL/SHGetFolderPathW
DynamicLoader: kernel32.dll/FlushProcessWriteBuffers
DynamicLoader: kernel32.dll/GetWriteWatch
DynamicLoader: kernel32.dll/ResetWriteWatch
DynamicLoader: kernel32.dll/CreateMemoryResourceNotification
DynamicLoader: kernel32.dll/QueryMemoryResourceNotification
DynamicLoader: mscoree.dll/_CorExeMain
DynamicLoader: mscoree.dll/_CorImageUnloading
DynamicLoader: mscoree.dll/_CorValidateImage
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: kernel32.dll/QueryActCtxW
DynamicLoader: ole32.dll/CoGetContextToken
DynamicLoader: kernel32.dll/GetVersionEx
DynamicLoader: kernel32.dll/GetVersionExW
DynamicLoader: kernel32.dll/GetVersionEx
DynamicLoader: kernel32.dll/GetVersionExW
DynamicLoader: kernel32.dll/GetFullPathName
DynamicLoader: kernel32.dll/GetFullPathNameW
DynamicLoader: ADVAPI32.dll/CryptAcquireContextA
DynamicLoader: ADVAPI32.dll/CryptReleaseContext
DynamicLoader: ADVAPI32.dll/CryptCreateHash
DynamicLoader: ADVAPI32.dll/CryptDestroyHash
DynamicLoader: ADVAPI32.dll/CryptHashData
DynamicLoader: ADVAPI32.dll/CryptGetHashParam
DynamicLoader: ADVAPI32.dll/CryptImportKey
DynamicLoader: ADVAPI32.dll/CryptExportKey
DynamicLoader: ADVAPI32.dll/CryptGenKey
DynamicLoader: ADVAPI32.dll/CryptGetKeyParam
DynamicLoader: ADVAPI32.dll/CryptDestroyKey
DynamicLoader: ADVAPI32.dll/CryptVerifySignatureA
DynamicLoader: ADVAPI32.dll/CryptSignHashA
DynamicLoader: ADVAPI32.dll/CryptGetProvParam
DynamicLoader: ADVAPI32.dll/CryptGetUserKey
DynamicLoader: ADVAPI32.dll/CryptEnumProvidersA
DynamicLoader: CRYPTSP.dll/CryptAcquireContextA
DynamicLoader: CRYPTSP.dll/CryptImportKey
DynamicLoader: CRYPTSP.dll/CryptExportKey
DynamicLoader: CRYPTSP.dll/CryptCreateHash
DynamicLoader: CRYPTSP.dll/CryptHashData
DynamicLoader: CRYPTSP.dll/CryptGetHashParam
DynamicLoader: CRYPTSP.dll/CryptDestroyHash
DynamicLoader: CRYPTSP.dll/CryptDestroyKey
DynamicLoader: mscorjit.dll/getJit
DynamicLoader: kernel32.dll/IsWow64Process
DynamicLoader: kernel32.dll/lstrlen
DynamicLoader: kernel32.dll/lstrlenW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: kernel32.dll/GetUserDefaultUILanguage
DynamicLoader: bcrypt.dll/BCryptGetFipsAlgorithmMode
DynamicLoader: kernel32.dll/SetErrorMode
DynamicLoader: kernel32.dll/GetFileAttributesEx
DynamicLoader: kernel32.dll/GetFileAttributesExW
DynamicLoader: kernel32.dll/GetEnvironmentVariable
DynamicLoader: kernel32.dll/GetEnvironmentVariableW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: ole32.dll/CreateBindCtx
DynamicLoader: ole32.dll/CoGetObjectContext
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: ole32.dll/NdrOleInitializeExtension
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/MkParseDisplayName
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/GetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/SetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/LocaleNameToLCID
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/LCIDToLocaleName
DynamicLoader: kernel32.dll/GetSystemDefaultLocaleName
DynamicLoader: ole32.dll/BindMoniker
DynamicLoader: SXS.DLL/SxsOleAut32RedirectTypeLibrary
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyW
DynamicLoader: ADVAPI32.dll/RegQueryValueW
DynamicLoader: SXS.DLL/SxsOleAut32MapConfiguredClsidToReferenceClsid
DynamicLoader: SXS.DLL/SxsLookupClrGuid
DynamicLoader: kernel32.dll/ReleaseActCtx
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: mscoreei.dll/_CorDllMain_RetAddr
DynamicLoader: mscoreei.dll/_CorDllMain
DynamicLoader: mscoree.dll/GetTokenForVTableEntry
DynamicLoader: mscoree.dll/SetTargetForVTableEntry
DynamicLoader: mscoree.dll/GetTargetForVTableEntry
DynamicLoader: mscoreei.dll/GetTokenForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/GetTokenForVTableEntry
DynamicLoader: mscoreei.dll/SetTargetForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/SetTargetForVTableEntry
DynamicLoader: mscoreei.dll/GetTargetForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/GetTargetForVTableEntry
DynamicLoader: kernel32.dll/GetLastError
DynamicLoader: kernel32.dll/LocalAlloc
DynamicLoader: OLEAUT32.dll/VariantInit
DynamicLoader: OLEAUT32.dll/VariantClear
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/CreateEvent
DynamicLoader: kernel32.dll/CreateEventW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/SwitchToThread
DynamicLoader: kernel32.dll/SetEvent
DynamicLoader: ole32.dll/CoWaitForMultipleHandles
DynamicLoader: ole32.dll/IIDFromString
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: kernel32.dll/LoadLibrary
DynamicLoader: kernel32.dll/LoadLibraryA
DynamicLoader: kernel32.dll/GetProcAddress
DynamicLoader: wminet_utils.dll/ResetSecurity
DynamicLoader: wminet_utils.dll/SetSecurity
DynamicLoader: wminet_utils.dll/BlessIWbemServices
DynamicLoader: wminet_utils.dll/BlessIWbemServicesObject
DynamicLoader: wminet_utils.dll/GetPropertyHandle
DynamicLoader: wminet_utils.dll/WritePropertyValue
DynamicLoader: wminet_utils.dll/Clone
DynamicLoader: wminet_utils.dll/VerifyClientKey
DynamicLoader: wminet_utils.dll/GetQualifierSet
DynamicLoader: wminet_utils.dll/Get
DynamicLoader: wminet_utils.dll/Put
DynamicLoader: wminet_utils.dll/Delete
DynamicLoader: wminet_utils.dll/GetNames
DynamicLoader: wminet_utils.dll/BeginEnumeration
DynamicLoader: wminet_utils.dll/Next
DynamicLoader: wminet_utils.dll/EndEnumeration
DynamicLoader: wminet_utils.dll/GetPropertyQualifierSet
DynamicLoader: wminet_utils.dll/Clone
DynamicLoader: wminet_utils.dll/GetObjectText
DynamicLoader: wminet_utils.dll/SpawnDerivedClass
DynamicLoader: wminet_utils.dll/SpawnInstance
DynamicLoader: wminet_utils.dll/CompareTo
DynamicLoader: wminet_utils.dll/GetPropertyOrigin
DynamicLoader: wminet_utils.dll/InheritsFrom
DynamicLoader: wminet_utils.dll/GetMethod
DynamicLoader: wminet_utils.dll/PutMethod
DynamicLoader: wminet_utils.dll/DeleteMethod
DynamicLoader: wminet_utils.dll/BeginMethodEnumeration
DynamicLoader: wminet_utils.dll/NextMethod
DynamicLoader: wminet_utils.dll/EndMethodEnumeration
DynamicLoader: wminet_utils.dll/GetMethodQualifierSet
DynamicLoader: wminet_utils.dll/GetMethodOrigin
DynamicLoader: wminet_utils.dll/QualifierSet_Get
DynamicLoader: wminet_utils.dll/QualifierSet_Put
DynamicLoader: wminet_utils.dll/QualifierSet_Delete
DynamicLoader: wminet_utils.dll/QualifierSet_GetNames
DynamicLoader: wminet_utils.dll/QualifierSet_BeginEnumeration
DynamicLoader: wminet_utils.dll/QualifierSet_Next
DynamicLoader: wminet_utils.dll/QualifierSet_EndEnumeration
DynamicLoader: wminet_utils.dll/GetCurrentApartmentType
DynamicLoader: wminet_utils.dll/GetDemultiplexedStub
DynamicLoader: wminet_utils.dll/CreateInstanceEnumWmi
DynamicLoader: wminet_utils.dll/CreateClassEnumWmi
DynamicLoader: wminet_utils.dll/ExecQueryWmi
DynamicLoader: wminet_utils.dll/ExecNotificationQueryWmi
DynamicLoader: wminet_utils.dll/PutInstanceWmi
DynamicLoader: wminet_utils.dll/PutClassWmi
DynamicLoader: wminet_utils.dll/CloneEnumWbemClassObject
DynamicLoader: wminet_utils.dll/ConnectServerWmi
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: OLEAUT32.dll/SysStringLen
DynamicLoader: kernel32.dll/ZeroMemory
DynamicLoader: kernel32.dll/ZeroMemoryA
DynamicLoader: kernel32.dll/RtlZeroMemory
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/GetUserName
DynamicLoader: ADVAPI32.dll/GetUserNameW
DynamicLoader: kernel32.dll/GetComputerName
DynamicLoader: kernel32.dll/GetComputerNameW
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/GetModuleHandle
DynamicLoader: kernel32.dll/GetModuleHandleW
DynamicLoader: kernel32.dll/GetProcAddress
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: GDI32.dll/GetStockObject
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/GetWindowLong
DynamicLoader: USER32.dll/GetWindowLongW
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/GetCurrentThread
DynamicLoader: kernel32.dll/DuplicateHandle
DynamicLoader: kernel32.dll/GetCurrentThreadId
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/CallWindowProc
DynamicLoader: USER32.dll/CallWindowProcW
DynamicLoader: USER32.dll/RegisterWindowMessage
DynamicLoader: USER32.dll/RegisterWindowMessageW
DynamicLoader: kernel32.dll/GetCurrentProcessId
DynamicLoader: kernel32.dll/GetCurrentProcessIdW
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: ntdll.dll/NtQuerySystemInformation
DynamicLoader: ntdll.dll/NtQuerySystemInformationW
DynamicLoader: kernel32.dll/CreateIoCompletionPort
DynamicLoader: kernel32.dll/PostQueuedCompletionStatus
DynamicLoader: ntdll.dll/NtQueryInformationThread
DynamicLoader: ntdll.dll/NtQuerySystemInformation
DynamicLoader: ntdll.dll/NtGetCurrentProcessorNumber
DynamicLoader: kernel32.dll/GetSystemTimeAsFileTime
DynamicLoader: kernel32.dll/GetACP
DynamicLoader: kernel32.dll/UnmapViewOfFile
DynamicLoader: kernel32.dll/GetCurrentProcess
DynamicLoader: kernel32.dll/GetCurrentProcessW
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: kernel32.dll/GetFileAttributesEx
DynamicLoader: kernel32.dll/GetFileAttributesExW
DynamicLoader: kernel32.dll/CreateFile
DynamicLoader: kernel32.dll/CreateFileW
DynamicLoader: kernel32.dll/GetFileType
DynamicLoader: kernel32.dll/GetFileSize
DynamicLoader: kernel32.dll/ReadFile
DynamicLoader: mscoree.dll/ND_RI2
DynamicLoader: mscoreei.dll/ND_RI2_RetAddr
DynamicLoader: mscoreei.dll/ND_RI2
DynamicLoader: rasapi32.dll/RasEnumConnections
DynamicLoader: rasapi32.dll/RasEnumConnectionsW
DynamicLoader: rtutils.dll/TraceRegisterExA
DynamicLoader: rtutils.dll/TracePrintfExA
DynamicLoader: sechost.dll/OpenSCManagerW
DynamicLoader: sechost.dll/OpenServiceW
DynamicLoader: sechost.dll/QueryServiceStatus
DynamicLoader: sechost.dll/CloseServiceHandle
DynamicLoader: WS2_32.dll/WSAStartup
DynamicLoader: WS2_32.dll/WSASocket
DynamicLoader: WS2_32.dll/WSASocketW
DynamicLoader: WS2_32.dll/setsockopt
DynamicLoader: WS2_32.dll/WSAEventSelect
DynamicLoader: WS2_32.dll/ioctlsocket
DynamicLoader: WS2_32.dll/closesocket
DynamicLoader: kernel32.dll/GetComputerName
DynamicLoader: kernel32.dll/GetComputerNameW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/ConvertStringSecurityDescriptorToSecurityDescriptor
DynamicLoader: ADVAPI32.dll/ConvertStringSecurityDescriptorToSecurityDescriptorW
DynamicLoader: kernel32.dll/LocalFree
DynamicLoader: kernel32.dll/CreateFileMapping
DynamicLoader: kernel32.dll/CreateFileMappingW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/MapViewOfFile
DynamicLoader: kernel32.dll/UnmapViewOfFile
DynamicLoader: kernel32.dll/VirtualQuery
DynamicLoader: kernel32.dll/ReleaseMutex
DynamicLoader: ADVAPI32.dll/CreateWellKnownSid
DynamicLoader: ADVAPI32.dll/CreateWellKnownSidW
DynamicLoader: kernel32.dll/CreateMutex
DynamicLoader: kernel32.dll/CreateMutexW
DynamicLoader: kernel32.dll/WaitForSingleObject
DynamicLoader: kernel32.dll/OpenMutex
DynamicLoader: kernel32.dll/OpenMutexW
DynamicLoader: kernel32.dll/CloseHandle
DynamicLoader: kernel32.dll/OpenProcess
DynamicLoader: kernel32.dll/OpenProcessW
DynamicLoader: kernel32.dll/GetProcessTimes
DynamicLoader: kernel32.dll/GetProcessTimesW
DynamicLoader: WS2_32.dll/ioctlsocket
DynamicLoader: WS2_32.dll/WSAIoctl
DynamicLoader: kernel32.dll/FormatMessage
DynamicLoader: kernel32.dll/FormatMessageW
DynamicLoader: WS2_32.dll/WSAEventSelect
DynamicLoader: rasapi32.dll/RasConnectionNotification
DynamicLoader: rasapi32.dll/RasConnectionNotificationW
DynamicLoader: ADVAPI32.dll/RegOpenCurrentUser
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: sechost.dll/NotifyServiceStatusChangeA
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegNotifyChangeKeyValue
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: winhttp.dll/WinHttpGetIEProxyConfigForCurrentUser
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ADVAPI32.dll/RegDeleteTreeA
DynamicLoader: ADVAPI32.dll/RegDeleteTreeW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: NSI.dll/NsiAllocateAndGetTable
DynamicLoader: CFGMGR32.dll/CM_Open_Class_Key_ExW
DynamicLoader: IPHLPAPI.DLL/ConvertInterfaceGuidToLuid
DynamicLoader: IPHLPAPI.DLL/GetIfEntry2
DynamicLoader: IPHLPAPI.DLL/GetIpForwardTable2
DynamicLoader: IPHLPAPI.DLL/GetIpNetEntry2
DynamicLoader: IPHLPAPI.DLL/FreeMibTable
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: NSI.dll/NsiFreeTable
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: kernel32.dll/ResetEvent
DynamicLoader: winhttp.dll/WinHttpDetectAutoProxyConfigUrl
DynamicLoader: kernel32.dll/GlobalFree
DynamicLoader: WS2_32.dll/getaddrinfo
DynamicLoader: WS2_32.dll/
DynamicLoader: kernel32.dll/LocalFree
DynamicLoader: IPHLPAPI.DLL/GetNetworkParams
DynamicLoader: DNSAPI.dll/DnsQueryConfig
DynamicLoader: IPHLPAPI.DLL/GetAdaptersAddresses
DynamicLoader: IPHLPAPI.DLL/GetIpInterfaceEntry
DynamicLoader: IPHLPAPI.DLL/GetBestInterfaceEx
DynamicLoader: kernel32.dll/LocalAlloc
DynamicLoader: IPHLPAPI.DLL/GetAdaptersAddresses
DynamicLoader: WS2_32.dll/inet_addr
DynamicLoader: WS2_32.dll/getaddrinfo
DynamicLoader: WS2_32.dll/freeaddrinfo
DynamicLoader: IPHLPAPI.DLL/GetAdaptersAddresses
DynamicLoader: WS2_32.dll/WSAConnect
DynamicLoader: WS2_32.dll/send
DynamicLoader: WS2_32.dll/setsockopt
DynamicLoader: WS2_32.dll/recv
DynamicLoader: shfolder.dll/SHGetFolderPath
DynamicLoader: shfolder.dll/SHGetFolderPathW
DynamicLoader: mscoreei.dll/LoadLibraryShim_RetAddr
DynamicLoader: mscoreei.dll/LoadLibraryShim
DynamicLoader: culture.dll/ConvertLangIdToCultureName
DynamicLoader: MLANG.dll/
DynamicLoader: WININET.dll/FindFirstUrlCacheEntryA
DynamicLoader: kernel32.dll/SetFileInformationByHandle
DynamicLoader: shell32.DLL/SHGetFolderPathW
DynamicLoader: vaultcli.dll/VaultEnumerateVaults
DynamicLoader: USER32.dll/GetLastInputInfo
DynamicLoader: kernel32.dll/GlobalMemoryStatusEx
DynamicLoader: kernel32.dll/FindFirstFile
DynamicLoader: kernel32.dll/FindFirstFileW
DynamicLoader: kernel32.dll/FindClose
DynamicLoader: ADVAPI32.dll/RegQueryInfoKey
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyEx
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ole32.dll/CLSIDFromProgIDEx
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: USER32.dll/SetWindowsHookEx
DynamicLoader: USER32.dll/SetWindowsHookExW
DynamicLoader: USER32.dll/SetClipboardViewer
DynamicLoader: USER32.dll/SetClipboardViewerW
DynamicLoader: ole32.dll/OleInitialize
DynamicLoader: ole32.dll/OleGetClipboard
DynamicLoader: kernel32.dll/GlobalLock
DynamicLoader: kernel32.dll/GlobalUnlock
DynamicLoader: kernel32.dll/GlobalFree
DynamicLoader: USER32.dll/SendMessage
DynamicLoader: USER32.dll/SendMessageW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: USER32.dll/GetClientRect
DynamicLoader: USER32.dll/GetWindowRect
DynamicLoader: USER32.dll/GetParent
DynamicLoader: ole32.dll/CoRegisterMessageFilter
DynamicLoader: USER32.dll/PeekMessage
DynamicLoader: USER32.dll/PeekMessageW
DynamicLoader: USER32.dll/IsWindowUnicode
DynamicLoader: USER32.dll/GetMessageW
DynamicLoader: USER32.dll/TranslateMessage
DynamicLoader: USER32.dll/DispatchMessageW
DynamicLoader: USER32.dll/WaitMessage
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: WS2_32.dll/
DynamicLoader: kernel32.dll/GetTempPath
DynamicLoader: kernel32.dll/GetTempPathW
DynamicLoader: ole32.dll/CoGetObjectContext
DynamicLoader: kernel32.dll/RegCreateKeyExW
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: wbemsvc.dll/DllGetClassObject
DynamicLoader: wbemsvc.dll/DllCanUnloadNow
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: kernel32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/RegCloseKey
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/GetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/SetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/LocaleNameToLCID
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/LCIDToLocaleName
DynamicLoader: kernel32.dll/GetSystemDefaultLocaleName
DynamicLoader: WMI.DLL/WmiQueryAllDataW
DynamicLoader: WMI.DLL/WmiQuerySingleInstanceW
DynamicLoader: WMI.DLL/WmiSetSingleItemW
DynamicLoader: WMI.DLL/WmiSetSingleInstanceW
DynamicLoader: WMI.DLL/WmiExecuteMethodW
DynamicLoader: WMI.DLL/WmiNotificationRegistrationW
DynamicLoader: WMI.DLL/WmiMofEnumerateResourcesW
DynamicLoader: WMI.DLL/WmiFileHandleToInstanceNameW
DynamicLoader: WMI.DLL/WmiDevInstToInstanceNameW
DynamicLoader: WMI.DLL/WmiQueryGuidInformation
DynamicLoader: WMI.DLL/WmiOpenBlock
DynamicLoader: WMI.DLL/WmiCloseBlock
DynamicLoader: WMI.DLL/WmiFreeBuffer
DynamicLoader: WMI.DLL/WmiEnumerateGuids
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/StringFromCLSID
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: kernel32.dll/RegCreateKeyExW
DynamicLoader: kernel32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/RegCloseKey
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: wbemsvc.dll/DllGetClassObject
DynamicLoader: wbemsvc.dll/DllCanUnloadNow
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: sechost.dll/LookupAccountSidLocalW
HTTP traffic contains suspicious features which may be indicative of malware related traffic
get_no_useragent: HTTP traffic contains a GET request with no user-agent header
suspicious_request: http://checkip.amazonaws.com/
Performs some HTTP requests
url: http://checkip.amazonaws.com/
Looks up the external IP address
domain: checkip.amazonaws.com
Behavioural detection: Injection (Process Hollowing)
Injection: JJB-175325-_33001.exe(420) -> JJB-175325-_33001.exe(2228)
Executed a process and injected code into it, probably while unpacking
Injection: JJB-175325-_33001.exe(420) -> JJB-175325-_33001.exe(2228)
Sniffs keystrokes
SetWindowsHookExW: Process: JJB-175325-_33001.exe(2228)
A process attempted to delay the analysis task by a long amount of time.
Process: JJB-175325-_33001.exe tried to sleep 2506 seconds, actually delayed analysis time by 0 seconds
Process: WmiPrvSE.exe tried to sleep 1203 seconds, actually delayed analysis time by 0 seconds
Attempts to repeatedly call a single API many times in order to delay analysis time
Spam: JJB-175325-_33001.exe (420) called API GetLocalTime 65020 times
Checks the CPU name from registry, possibly for anti-virtualization
Harvests credentials from local FTP client softwares
file: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml
file: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
file: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\*.xml
file: C:\Users\user\AppData\Roaming\FTPGetter\servers.xml
file: C:\Users\user\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
file: C:\cftp\Ftplist.txt
key: HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
Harvests information related to installed mail clients
file: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
key: HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Collects information to fingerprint the system

Screenshots


Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
N 52.55.255.113 [VT] United States

DNS

Name Response Post-Analysis Lookup
checkip.amazonaws.com [VT] A 52.55.255.113 [VT]
A 52.44.169.135 [VT]
CNAME checkip.check-ip.aws.a2z.com [VT]
CNAME checkip.us-east-1.prod.check-ip.aws.a2z.com [VT]
A 18.205.71.63 [VT]
A 3.224.145.145 [VT]
A 18.204.189.102 [VT]
A 34.196.181.158 [VT]

Summary

C:\Windows\Globalization\Sorting\sortdefault.nls
\Device\KsecDD
C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe.cfg
C:\Windows\sysnative\C_932.NLS
C:\Windows\sysnative\C_949.NLS
C:\Windows\sysnative\C_950.NLS
C:\Windows\sysnative\C_936.NLS
C:\Users\user\AppData\Local\Temp\varieteterlafay
C:\Windows\System32\mscoree.dll.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe.Local\
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
C:\Windows
C:\Windows\winsxs
C:\Windows\Microsoft.NET\Framework\v4.0.30319
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\user\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\user\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index149.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI
C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe
C:\Users
C:\Users\user
C:\Users\user\AppData
C:\Users\user\AppData\Local
C:\Users\user\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
C:\Windows\System32\l_intl.nls
C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI
C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
C:\Windows\Globalization\en-gb.nlp
C:\Windows\Globalization\en-us.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.INI
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.INI
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\oleaut32.DLL
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\System32\tzres.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Globalization\en.nlp
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\%insfolder%\%insname%
C:\Users\user\AppData\Local\Google\Chrome\User Data\
C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Windows\assembly\GAC_32\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\0.0.0.0_en-US_461d39c4a423da0b
C:\Windows\assembly\GAC_MSIL\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\0.0.0.0_en-US_461d39c4a423da0b
C:\Windows\assembly\GAC\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\0.0.0.0_en-US_461d39c4a423da0b
C:\Users\user\AppData\Local\Temp\en-US\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.exe
C:\Users\user\AppData\Local\Temp\en-US\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
C:\Windows\assembly\GAC_32\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\0.0.0.0_en_461d39c4a423da0b
C:\Windows\assembly\GAC_MSIL\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\0.0.0.0_en_461d39c4a423da0b
C:\Windows\assembly\GAC\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\0.0.0.0_en_461d39c4a423da0b
C:\Users\user\AppData\Local\Temp\en\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.dll
C:\Users\user\AppData\Local\Temp\en\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.dll
C:\Users\user\AppData\Local\Temp\en\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.exe
C:\Users\user\AppData\Local\Temp\en\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources\VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources.exe
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\user\AppData\Local\Microsoft\Windows\History
C:\Users\user\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\user\AppData\Local\Temp\vaultcli.dll
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\plutil.exe
C:\Users\user\AppData\Local\Tencent\QQBrowser\User Data
C:\Users\user\AppData\Local\Tencent\QQBrowser\User Data\Default\EncryptedStorage
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\user\AppData\Local\Yandex\YandexBrowser\User Data
C:\Users\user\AppData\Local\360Chrome\Chrome\User Data
C:\Users\user\AppData\Local\Iridium\User Data
C:\Users\user\AppData\Local\Comodo\Dragon\User Data
C:\Users\user\AppData\Local\MapleStudio\ChromePlus\User Data
C:\Users\user\AppData\Local\Chromium\User Data
C:\Users\user\AppData\Local\Torch\User Data
C:\Users\user\AppData\Local\7Star\7Star\User Data
C:\Users\user\AppData\Local\Amigo\User Data
C:\Users\user\AppData\Local\BraveSoftware\Brave-Browser\User Data
C:\Users\user\AppData\Local\CentBrowser\User Data
C:\Users\user\AppData\Local\Chedot\User Data
C:\Users\user\AppData\Local\CocCoc\Browser\User Data
C:\Users\user\AppData\Local\Elements Browser\User Data
C:\Users\user\AppData\Local\Epic Privacy Browser\User Data
C:\Users\user\AppData\Local\Kometa\User Data
C:\Users\user\AppData\Local\Orbitum\User Data
C:\Users\user\AppData\Local\Sputnik\Sputnik\User Data
C:\Users\user\AppData\Local\uCozMedia\Uran\User Data
C:\Users\user\AppData\Local\Vivaldi\User Data
C:\Users\user\AppData\Local\CatalinaGroup\Citrio\User Data
C:\Users\user\AppData\Local\liebao\User Data
C:\Users\user\AppData\Local\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer
C:\Users\user\AppData\Local\QIP Surf\User Data
C:\Users\user\AppData\Local\Coowon\Coowon\User Data
C:\Users\user\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\user\AppData\Roaming\Flock\Browser\profiles.ini
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_en-GB_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_en-GB_b03f5f7f11d50a3a
C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_en-GB_b03f5f7f11d50a3a
C:\Users\user\AppData\Local\Temp\en-GB\Microsoft.VisualBasic.resources.dll
C:\Users\user\AppData\Local\Temp\en-GB\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll
C:\Users\user\AppData\Local\Temp\en-GB\Microsoft.VisualBasic.resources.exe
C:\Users\user\AppData\Local\Temp\en-GB\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources\8.0.0.0_en_b03f5f7f11d50a3a
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources\8.0.0.0_en_b03f5f7f11d50a3a
C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources\8.0.0.0_en_b03f5f7f11d50a3a
C:\Users\user\AppData\Local\Temp\en\Microsoft.VisualBasic.resources.dll
C:\Users\user\AppData\Local\Temp\en\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.dll
C:\Users\user\AppData\Local\Temp\en\Microsoft.VisualBasic.resources.exe
C:\Users\user\AppData\Local\Temp\en\Microsoft.VisualBasic.resources\Microsoft.VisualBasic.resources.exe
C:\Users\user\AppData\Local\UCBrowser\*
C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini
C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini
C:\Users\user\AppData\Roaming\K-Meleon\profiles.ini
C:\Users\user\AppData\Roaming\Mozilla\icecat\profiles.ini
C:\Users\user\AppData\Roaming\Comodo\IceDragon\profiles.ini
C:\Users\user\AppData\Roaming\Moonchild Productions\Pale Moon\profiles.ini
C:\Users\user\AppData\Roaming\Waterfox\profiles.ini
C:\Users\user\AppData\Local\falkon\profiles\profiles.ini
C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
C:\Storage\
C:\mail\
C:\Users\user\AppData\Local\VirtualStore\Program Files\Foxmail\mail\
C:\Users\user\AppData\Local\VirtualStore\Program Files (x86)\Foxmail\mail\
C:\Users\user\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
C:\Users\user\AppData\Roaming\Pocomail\accounts.ini
C:\Users\user\AppData\Roaming\The Bat!
C:\Users\user\AppData\Roaming\Postbox\profiles.ini
C:\Users\user\AppData\Roaming\Claws-mail
C:\Users\user\AppData\Roaming\Claws-mail\clawsrc
C:\Users\user\AppData\Local\Temp\Folder.lst
C:\Users\user\AppData\Roaming\Trillian\users\global\accounts.dat
C:\Users\user\AppData\Roaming\Psi\profiles
C:\Users\user\AppData\Roaming\Psi+\profiles
C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\user\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini
C:\Users\user\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\SysWOW64\wshom.ocx
C:\FTP Navigator\Ftplist.txt
C:\Users\All Users\AppData\Roaming\FlashFXP\3quick.dat
C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\*.xml
C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\
C:\cftp\Ftplist.txt
C:\Users\user\AppData\Roaming\FTPGetter\servers.xml
C:\Program Files (x86)\jDownloader\config\database.script
C:\Users\user\AppData\Local\Google\Chrome\User Data
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable
C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer
C:\Users\user\AppData\Local\UCBrowser\
C:\Users\user\AppData\Roaming\Mozilla\Firefox\
C:\Users\user\AppData\Roaming\Postbox\
C:\Users\user\AppData\Roaming\Thunderbird\
C:\Users\user\AppData\Roaming\Mozilla\SeaMonkey\
C:\Users\user\AppData\Roaming\Flock\Browser\
C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\
C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\
C:\Users\user\AppData\Roaming\K-Meleon\
C:\Users\user\AppData\Roaming\Mozilla\icecat\
C:\Users\user\AppData\Roaming\Moonchild Productions\Pale Moon\
C:\Users\user\AppData\Roaming\Comodo\IceDragon\
C:\Users\user\AppData\Roaming\Waterfox\
C:\Users\user\AppData\Roaming\qrpxulmj.q1s.zip
C:\Users\user\AppData\Roaming\qrpxulmj.q1s\*
C:\Users\user\AppData\Local\Temp\log.tmp
C:\Windows\sysnative\cscsvc.dll
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\discache.sys
C:\Windows\sysnative\drivers\en-US\discache.sys.mui
C:\Windows\sysnative\drivers\en\discache.sys.mui
C:\Windows\sysnative\drivers\netbt.sys
C:\Windows\sysnative\drivers\en-US\netbt.sys.mui
C:\Windows\sysnative\drivers\en\netbt.sys.mui
C:\Windows\sysnative\vmstorfltres.dll
C:\Windows\sysnative\tcpipcfg.dll
C:\Windows\sysnative\en-US\tcpipcfg.dll.mui
C:\Windows\sysnative\drivers\fvevol.sys
C:\Windows\sysnative\drivers\en-US\fvevol.sys.mui
C:\Windows\sysnative\drivers\nsiproxy.sys
C:\Windows\sysnative\drivers\en-US\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\en\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\http.sys
C:\Windows\sysnative\drivers\en-US\http.sys.mui
C:\Windows\sysnative\drivers\hwpolicy.sys
C:\Windows\sysnative\drivers\en-US\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\en\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\tssecsrv.sys
C:\Windows\sysnative\drivers\en-US\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\en\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\pacer.sys
C:\Windows\sysnative\drivers\en-US\pacer.sys.mui
C:\Windows\sysnative\drivers\mountmgr.sys
C:\Windows\sysnative\drivers\en-US\mountmgr.sys.mui
C:\Windows\sysnative\drivers\RDPCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\volmgrx.sys
C:\Windows\sysnative\drivers\en-US\volmgrx.sys.mui
C:\Windows\sysnative\drivers\afd.sys
C:\Windows\sysnative\drivers\en-US\afd.sys.mui
C:\Windows\sysnative\FirewallAPI.dll
C:\Windows\sysnative\en-US\FirewallAPI.dll.mui
C:\Windows\sysnative\drivers\RDPENCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPENCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPENCDD.sys.mui
C:\Windows\sysnative\rascfg.dll
C:\Windows\sysnative\en-US\rascfg.dll.mui
C:\Windows\sysnative\drivers\RDPREFMP.sys
C:\Windows\sysnative\drivers\en-US\RdpRefMp.sys.mui
C:\Windows\sysnative\drivers\en\RdpRefMp.sys.mui
C:\Windows\sysnative\clfs.sys
C:\Windows\sysnative\en-US\clfs.sys.mui
C:\Windows\sysnative\wbem\Logs\
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
C:\Windows\Temp
C:\Windows\Globalization\Sorting\sortdefault.nls
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\user\AppData\Local\Temp\JJB-175325-_33001.exe.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch
C:\Users\user\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config
C:\Users\user\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch
C:\Windows\assembly\NativeImages_v2.0.50727_32\index149.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
C:\Windows\System32\l_intl.nls
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9e0a3b9b9f457233a335d7fba8f95419\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\dbfe8642a8ed7b2b103ad28e0c96418a\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3afcd5168c7a6cb02eab99d7fd71e102\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\08d608378aa405adc844f3cf36974b8c\Microsoft.VisualBasic.ni.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\bf7e7494e75e32979c7824a07570a8a9\CustomMarshalers.ni.dll
C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\wminet_utils.dll
C:\Windows\System32\tzres.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bc09ad2d49d8535371845cd7532f9271\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\461d3b6b3f43e6fbe6c897d5936e17e4\System.Xml.ni.dll
C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\user\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\user\AppData\Roaming\Flock\Browser\profiles.ini
C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini
C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini
C:\Users\user\AppData\Roaming\K-Meleon\profiles.ini
C:\Users\user\AppData\Roaming\Mozilla\icecat\profiles.ini
C:\Users\user\AppData\Roaming\Comodo\IceDragon\profiles.ini
C:\Users\user\AppData\Roaming\Moonchild Productions\Pale Moon\profiles.ini
C:\Users\user\AppData\Roaming\Waterfox\profiles.ini
C:\Users\user\AppData\Local\falkon\profiles\profiles.ini
C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\user\AppData\Roaming\Postbox\profiles.ini
C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\user\AppData\Roaming\CoreFTP\sites.idx
C:\Windows\SysWOW64\wshom.ocx
C:\FTP Navigator\Ftplist.txt
C:\Users\user\AppData\Roaming\qrpxulmj.q1s.zip
C:\Windows\sysnative\cscsvc.dll
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\discache.sys
C:\Windows\sysnative\drivers\en-US\discache.sys.mui
C:\Windows\sysnative\drivers\en\discache.sys.mui
C:\Windows\sysnative\drivers\netbt.sys
C:\Windows\sysnative\drivers\en-US\netbt.sys.mui
C:\Windows\sysnative\drivers\en\netbt.sys.mui
C:\Windows\sysnative\vmstorfltres.dll
C:\Windows\sysnative\tcpipcfg.dll
C:\Windows\sysnative\en-US\tcpipcfg.dll.mui
C:\Windows\sysnative\drivers\fvevol.sys
C:\Windows\sysnative\drivers\en-US\fvevol.sys.mui
C:\Windows\sysnative\drivers\nsiproxy.sys
C:\Windows\sysnative\drivers\en-US\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\en\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\http.sys
C:\Windows\sysnative\drivers\en-US\http.sys.mui
C:\Windows\sysnative\drivers\hwpolicy.sys
C:\Windows\sysnative\drivers\en-US\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\en\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\tssecsrv.sys
C:\Windows\sysnative\drivers\en-US\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\en\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\pacer.sys
C:\Windows\sysnative\drivers\en-US\pacer.sys.mui
C:\Windows\sysnative\drivers\mountmgr.sys
C:\Windows\sysnative\drivers\en-US\mountmgr.sys.mui
C:\Windows\sysnative\drivers\RDPCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\volmgrx.sys
C:\Windows\sysnative\drivers\en-US\volmgrx.sys.mui
C:\Windows\sysnative\drivers\afd.sys
C:\Windows\sysnative\drivers\en-US\afd.sys.mui
C:\Windows\sysnative\FirewallAPI.dll
C:\Windows\sysnative\en-US\FirewallAPI.dll.mui
C:\Windows\sysnative\drivers\RDPENCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPENCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPENCDD.sys.mui
C:\Windows\sysnative\rascfg.dll
C:\Windows\sysnative\en-US\rascfg.dll.mui
C:\Windows\sysnative\drivers\RDPREFMP.sys
C:\Windows\sysnative\drivers\en-US\RdpRefMp.sys.mui
C:\Windows\sysnative\drivers\en\RdpRefMp.sys.mui
C:\Windows\sysnative\clfs.sys
C:\Windows\sysnative\en-US\clfs.sys.mui
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\user\AppData\Roaming\qrpxulmj.q1s.zip
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-GB
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-GB
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000809
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
DisableUserModeCallbackFilter
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Codepage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\936
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VBA\Monitors
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\JJB-175325-_33001.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT\UserEra
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\International\Calendars\TwoDigitYearMax
HKEY_CURRENT_USER\Control Panel\International\Calendars\TwoDigitYearMax
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v2.0.50727
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\JJB-175325-_33001.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-120665959-548228820-2376508522-1001
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\GACChangeNotification\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\53d498f7\3fc7d248
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscorjit.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Web__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\JJB-175325-_33001.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\356E510D
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_CURRENT_USER\Software\Classes\WinMgmts
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\809
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\9
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.CustomMarshalers__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualC__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.ni.dll
HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\wminet_utils.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.Management.ni.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\JJB-175325-_33001_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\FileDirectory
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\EnableFileTracing
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\FileTracingMask
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\EnableConsoleTracing
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\ConsoleTracingMask
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\MaxFileSize
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-0c-29-f8-d7-43
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.0.0.VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources_en-US_461d39c4a423da0b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4e737d0e\56d38e7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-120665959-548228820-2376508522-1001\Installer\Assemblies\C:|Users|user|AppData|Local|Temp|JJB-175325-_33001.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|user|AppData|Local|Temp|JJB-175325-_33001.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|user|AppData|Local|Temp|JJB-175325-_33001.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-120665959-548228820-2376508522-1001\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\culture.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.0.0.VQQQIDULPBMLSWBHBWPIBPUOWMZVOWNXYFKOJAIX_20190718094011775.resources_en_461d39c4a423da0b
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\4e737d0e\faf6b28
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
\xeb\x9f\x98\xc8\x83EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
\xeb\x9f\x98\xc8\x83EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
\xeb\x9f\x98\xc8\x83EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_en-GB_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\610b1085
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.VisualBasic.resources_en_b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6d5fb745\15f61caa
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1
HKEY_CURRENT_USER\Software\IncrediMail\Identities
HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine
HKEY_CURRENT_USER\Software\RimArts\B2\Settings
HKEY_CURRENT_USER\Software\OpenVPN-GUI\configs
HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
HKEY_CLASSES_ROOT\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\809
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\9
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites
HKEY_CURRENT_USER\Software\DownloadManager\Passwords
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVMware_Virtual_SATA_Hard_Drive__________00000001#6&158e87a7&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVMware_Virtual_SATA_Hard_Drive__________00000001#6&158e87a7&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVMware_Virtual_SATA_Hard_Drive__________00000001#6&158e87a7&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_94_-_INTEL(R)_XEON(R)_CPU_E3-1270_V5_@_3.60GHZ\_0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT12
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_94_-_INTEL(R)_XEON(R)_CPU_E3-1270_V5_@_3.60GHZ\_1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LocationInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LocationInformation
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Power\PowerRequestOverride
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Power\PowerRequestOverride\Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnablePrivateObjectHeap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ContextLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ObjectLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6A7AE7C1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Control Panel\International
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\Identifier
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MMCSS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MMCSS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MMCSS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MMCSS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MMCSS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000809
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
DisableUserModeCallbackFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\936
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStart
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\GCStressStartAtJit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\VersioningLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\LatestIndex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\NIUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index149\ILUsageMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\7950e2c5\83\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\183e33de\83\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib,2.0.0.0,,b77a5c561934e089,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\mscorjit.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064\7a\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\475dce40\2d382ce6\85\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\19ab8d57\1bd7b0d8\87\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2dd6ac50\163e1f5e\80\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\424bd4d8\1c83327b\86\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\41c04c7e\7f3b6ac4\78\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3ced59c5\1b2590b1\7c\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\c991064\2bd33e1c\79\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\30bc7c4f\3f50fe4f\88\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3f50fe4f\6f1da7aa\88\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\3cca06a0\6dc7d4c0\7b\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\6dc7d4c0\a5cd4db\7e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\1c22df2f\4f99a7c9\2e\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\f6e8397\46ad0879\6f\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\2b1a4e4\38a3212c\44\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\24bf93f6\455bab30\6e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\4f99a7c9\53bea2b0\2e\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualBasic,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Web,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Remoting,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\356E510D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\109d7e79\357ee49a\44\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\3d590c3f\59f3b67b\82\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\357ee49a\7d2df0ec\41\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\CustomMarshalers,2.0.0.0,,b03f5f7f11d50a3a,x86
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.VisualC,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\CustomMarshalers.ni.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\5a8de2c3\2b1a4e4\47\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\73843e06\43a920ef\66\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\141dfd70\6b79efab\43\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript,8.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install,2.0.0.0,,b03f5f7f11d50a3a,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\wminet_utils.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.Management.ni.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\159a66b8\424bd4d8\87\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ConfigString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MVID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\EvalationData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\ILDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\NIDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\6faf58\19ab8d57\86\MissingDependencies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\Modules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\SIG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\75638fee\7566cac\84\LastModTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml,2.0.0.0,,b77a5c561934e089,MSIL
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\EnableFileTracing
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\FileTracingMask
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\EnableConsoleTracing
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\ConsoleTracingMask
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\MaxFileSize
\xe7\xb3\xa0\xc8\x9aEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\JJB-175325-_33001_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Library
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\IsMultiInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\First Counter
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\CategoryOptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\FileMappingSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking\Performance\Counter Names
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\culture.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
\xeb\x9f\x98\xc8\x83EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
\xeb\x9f\x98\xc8\x83EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
\xeb\x9f\x98\xc8\x83EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
\xeb\x9f\x98\xc8\x83EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
\xe7\xb3\xa0\xc8\x9aEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
\xe8\x80\x88\xc7\xbcEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\Class
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVMware_Virtual_SATA_Hard_Drive__________00000001#6&158e87a7&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LocationInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LocationInformation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnablePrivateObjectHeap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ContextLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ObjectLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6A7AE7C1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_U