Analysis

Category Package Started Completed Duration Options Log
FILE Extraction 2019-08-14 00:16:43 2019-08-14 00:21:11 268 seconds Show Options Show Log
route = internet
procdump = 0
2019-08-14 01:16:44,000 [root] INFO: Date set to: 08-14-19, time set to: 00:16:44, timeout set to: 200
2019-08-14 01:16:44,108 [root] DEBUG: Starting analyzer from: C:\nkmznsmshd
2019-08-14 01:16:44,108 [root] DEBUG: Storing results at: C:\xeiUbkq
2019-08-14 01:16:44,108 [root] DEBUG: Pipe server name: \\.\PIPE\QfJQsZQ
2019-08-14 01:16:44,108 [root] INFO: Analysis package "Extraction" has been specified.
2019-08-14 01:16:47,026 [root] DEBUG: Started auxiliary module Browser
2019-08-14 01:16:47,026 [root] DEBUG: Started auxiliary module Curtain
2019-08-14 01:16:47,026 [modules.auxiliary.digisig] DEBUG: Checking for a digitial signature.
2019-08-14 01:16:48,773 [modules.auxiliary.digisig] DEBUG: File is not signed.
2019-08-14 01:16:48,773 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2019-08-14 01:16:48,773 [root] DEBUG: Started auxiliary module DigiSig
2019-08-14 01:16:48,803 [root] DEBUG: Started auxiliary module Disguise
2019-08-14 01:16:48,803 [root] DEBUG: Started auxiliary module Human
2019-08-14 01:16:48,819 [root] DEBUG: Started auxiliary module Screenshots
2019-08-14 01:16:48,819 [root] DEBUG: Started auxiliary module Sysmon
2019-08-14 01:16:48,819 [root] DEBUG: Started auxiliary module Usage
2019-08-14 01:16:48,819 [root] INFO: Analyzer: DLL set to Extraction.dll from package modules.packages.Extraction
2019-08-14 01:16:48,819 [root] INFO: Analyzer: DLL_64 set to Extraction_x64.dll from package modules.packages.Extraction
2019-08-14 01:16:49,006 [lib.api.process] INFO: Successfully executed process from path "C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe" with arguments "" with pid 1460
2019-08-14 01:16:49,163 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:16:49,163 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:16:49,506 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:16:49,506 [root] DEBUG: Loader: Injecting process 1460 (thread 576) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:16:49,506 [root] DEBUG: Process image base: 0x01020000
2019-08-14 01:16:49,506 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:16:49,506 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:16:49,506 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:16:49,522 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 1460
2019-08-14 01:16:51,533 [lib.api.process] INFO: Successfully resumed process with pid 1460
2019-08-14 01:16:51,533 [root] INFO: Added new process to list with pid: 1460
2019-08-14 01:16:51,611 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:16:51,611 [root] DEBUG: Process dumps disabled.
2019-08-14 01:16:51,674 [root] DEBUG: WoW64 detected: 64-bit ntdll base: 0x77110000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7716124a, Wow64PrepareForException: 0x0
2019-08-14 01:16:51,674 [root] DEBUG: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0xe0000
2019-08-14 01:16:51,674 [root] DEBUG: Debugger initialised.
2019-08-14 01:16:51,674 [root] DEBUG: CAPE initialised: 32-bit Extraction v2 loaded in process 1460 at 0x747e0000, image base 0x1020000, stack from 0x1e5000-0x1f0000
2019-08-14 01:16:51,674 [root] DEBUG: Commandline: C:\Users\user\AppData\Local\Temp\"C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe".
2019-08-14 01:16:51,674 [root] DEBUG: set_caller_info: Adding region at 0x000C0000 to caller regions list.
2019-08-14 01:16:51,674 [root] DEBUG: CAPEExceptionFilter: Exception 0xc0000005 caught at RVA 0x1854 in capemon caught accessing 0x1021000 (expected in memory scans), passing to next handler.
2019-08-14 01:16:51,674 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,674 [root] DEBUG: AddTrackedRegion: GetEntropy failed.
2019-08-14 01:16:51,674 [root] DEBUG: AddTrackedRegion: Region at 0x01020000 size 0x1000 added to tracked regions.
2019-08-14 01:16:51,690 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:16:51,690 [root] INFO: Monitor successfully loaded in process with pid 1460.
2019-08-14 01:16:51,690 [root] DEBUG: set_caller_info: Calling address 0x001EF21C in stack (advapi32::RegQueryInfoKeyW)
2019-08-14 01:16:51,690 [root] DEBUG: set_caller_info: Adding region at 0x000F0000 to caller regions list.
2019-08-14 01:16:51,690 [root] DEBUG: set_caller_info: Adding region at 0x02680000 to caller regions list.
2019-08-14 01:16:51,690 [root] DEBUG: set_caller_info: Adding region at 0x004F0000 to caller regions list.
2019-08-14 01:16:51,690 [root] DEBUG: DLL loaded at 0x744C0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x7b000 bytes).
2019-08-14 01:16:51,690 [root] DEBUG: Allocation: 0x00780000 - 0x00850000, size: 0xd0000, protection: 0x40.
2019-08-14 01:16:51,690 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,690 [root] DEBUG: AddTrackedRegion: Region at 0x00780000 size 0xd0000 added to tracked regions.
2019-08-14 01:16:51,690 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x00780000.
2019-08-14 01:16:51,690 [root] DEBUG: FreeHandler: Address: 0x00780000.
2019-08-14 01:16:51,690 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x780000 - 0x850000.
2019-08-14 01:16:51,690 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a094a0, AllocationBase 0x1020000.
2019-08-14 01:16:51,690 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a7ea10, AllocationBase 0x780000.
2019-08-14 01:16:51,690 [root] DEBUG: DropTrackedRegion: removed pages 0x780000-0x850000 from tracked region list.
2019-08-14 01:16:51,690 [root] DEBUG: Allocation: 0x00810000 - 0x00811000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,690 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,690 [root] DEBUG: AddTrackedRegion: Region at 0x00810000 size 0x1000 added to tracked regions.
2019-08-14 01:16:51,706 [root] DEBUG: DLL loaded at 0x73E20000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr (0x69b000 bytes).
2019-08-14 01:16:51,706 [root] DEBUG: DLL loaded at 0x73D40000: C:\Windows\system32\MSVCR110_CLR0400 (0xd3000 bytes).
2019-08-14 01:16:51,706 [root] INFO: Disabling sleep skipping.
2019-08-14 01:16:51,706 [root] DEBUG: Allocation: 0x03CE0000 - 0x03E80000, size: 0x1a0000, protection: 0x40.
2019-08-14 01:16:51,706 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,706 [root] DEBUG: AddTrackedRegion: Region at 0x03CE0000 size 0x1a0000 added to tracked regions.
2019-08-14 01:16:51,706 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x03CE0000.
2019-08-14 01:16:51,706 [root] DEBUG: FreeHandler: Address: 0x03CE0000.
2019-08-14 01:16:51,706 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x3ce0000 - 0x3e80000.
2019-08-14 01:16:51,706 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a094a0, AllocationBase 0x1020000.
2019-08-14 01:16:51,706 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a7fc10, AllocationBase 0x810000.
2019-08-14 01:16:51,721 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a7ea10, AllocationBase 0x3ce0000.
2019-08-14 01:16:51,721 [root] DEBUG: DropTrackedRegion: removed pages 0x3ce0000-0x3e80000 from tracked region list.
2019-08-14 01:16:51,721 [root] DEBUG: Allocation: 0x03E40000 - 0x03E41000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,721 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,721 [root] DEBUG: AddTrackedRegion: Region at 0x03E40000 size 0x1000 added to tracked regions.
2019-08-14 01:16:51,721 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2320.
2019-08-14 01:16:51,721 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-14 01:16:51,721 [root] DEBUG: Allocation: 0x00292000 - 0x00293000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,721 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,721 [root] DEBUG: AddTrackedRegion: Region at 0x00290000 size 0x3000 added to tracked regions.
2019-08-14 01:16:51,721 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2380.
2019-08-14 01:16:51,736 [root] DEBUG: DLL loaded at 0x729C0000: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\045c9588954c3662d542b53f4462268b\mscorlib.ni (0x102e000 bytes).
2019-08-14 01:16:51,767 [root] DEBUG: Allocation: 0x00305000 - 0x00306000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,767 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,767 [root] DEBUG: AddTrackedRegion: Region at 0x00300000 size 0x6000 added to tracked regions.
2019-08-14 01:16:51,767 [root] DEBUG: Allocation: 0x0030B000 - 0x0030C000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,767 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,767 [root] DEBUG: AddTrackedRegion: Region at 0x00300000 size 0xc000 added to tracked regions.
2019-08-14 01:16:51,767 [root] DEBUG: Allocation: 0x00307000 - 0x00308000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,767 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,767 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00300000, size: 0xc000.
2019-08-14 01:16:51,767 [root] DEBUG: Allocation: 0x002AC000 - 0x002AD000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,767 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,767 [root] DEBUG: AddTrackedRegion: Region at 0x002A0000 size 0xd000 added to tracked regions.
2019-08-14 01:16:51,783 [root] DEBUG: DLL loaded at 0x73CC0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit (0x7d000 bytes).
2019-08-14 01:16:51,783 [root] DEBUG: DLL loaded at 0x75980000: C:\Windows\syswow64\OLEAUT32 (0x8f000 bytes).
2019-08-14 01:16:51,799 [root] DEBUG: DLL loaded at 0x72020000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System\79f6324a598a7c4446a4a1168be7c4b1\System.ni (0x99a000 bytes).
2019-08-14 01:16:51,815 [root] DEBUG: DLL loaded at 0x73B20000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c4477b3ce64d0d612d1ab0dba425b77f\System.Drawing.ni (0x194000 bytes).
2019-08-14 01:16:51,815 [root] DEBUG: DLL loaded at 0x713D0000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\05ca0ca95b6fcc0d710b63b6200cc178\System.Windows.Forms.ni (0xc4f000 bytes).
2019-08-14 01:16:51,861 [root] DEBUG: Allocation: 0x004C0000 - 0x004C1000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,861 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,861 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x1000 added to tracked regions.
2019-08-14 01:16:51,878 [root] DEBUG: set_caller_info: Adding region at 0x004C0000 to caller regions list.
2019-08-14 01:16:51,878 [root] DEBUG: Allocation: 0x0029A000 - 0x0029B000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,878 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,878 [root] DEBUG: AddTrackedRegion: Region at 0x00290000 size 0xb000 added to tracked regions.
2019-08-14 01:16:51,940 [root] DEBUG: DLL loaded at 0x71350000: C:\Windows\system32\uxtheme (0x80000 bytes).
2019-08-14 01:16:51,970 [root] DEBUG: Allocation: 0x002FA000 - 0x002FB000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,970 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,970 [root] DEBUG: AddTrackedRegion: Region at 0x002F0000 size 0xb000 added to tracked regions.
2019-08-14 01:16:51,970 [root] DEBUG: Allocation: 0x002F7000 - 0x002F8000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:51,970 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:51,970 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x002F0000, size: 0xb000.
2019-08-14 01:16:51,986 [root] DEBUG: DLL loaded at 0x748A0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32 (0x84000 bytes).
2019-08-14 01:16:52,017 [root] DEBUG: DLL loaded at 0x711B0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32 (0x19e000 bytes).
2019-08-14 01:16:52,033 [root] DEBUG: Allocation: 0x002AA000 - 0x002AB000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:52,033 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:52,033 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x002A0000, size: 0xd000.
2019-08-14 01:16:52,033 [root] DEBUG: set_caller_info: Adding region at 0x002A0000 to caller regions list.
2019-08-14 01:16:52,049 [root] DEBUG: DLL loaded at 0x74960000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting (0x12000 bytes).
2019-08-14 01:16:52,329 [root] DEBUG: Allocation: 0x004C1000 - 0x004C2000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:52,329 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:52,345 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 11.
2019-08-14 01:16:52,345 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x2000 added to tracked regions.
2019-08-14 01:16:52,377 [root] DEBUG: Allocation: 0x002F6000 - 0x002F7000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:52,377 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:52,377 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x002F0000, size: 0xb000.
2019-08-14 01:16:52,424 [root] DEBUG: DLL loaded at 0x71020000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus (0x190000 bytes).
2019-08-14 01:16:52,532 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2872.
2019-08-14 01:16:52,750 [root] DEBUG: DLL loaded at 0x70F20000: C:\Windows\system32\WindowsCodecs (0xfb000 bytes).
2019-08-14 01:16:52,953 [root] DEBUG: DLL loaded at 0x70870000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\4e69f1e7d86d79012db2d7e0dadc8880\System.Core.ni (0x6ae000 bytes).
2019-08-14 01:16:52,953 [root] DEBUG: DLL loaded at 0x70690000: C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\65f7c6dcc498c7157f0ef5b72824d60a\Microsoft.VisualBasic.ni (0x1dd000 bytes).
2019-08-14 01:16:52,984 [root] DEBUG: Allocation: 0x004C2000 - 0x004C3000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:52,984 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:52,984 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 12.
2019-08-14 01:16:52,984 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x3000 added to tracked regions.
2019-08-14 01:16:53,078 [root] DEBUG: set_caller_info: Adding region at 0x00290000 to caller regions list.
2019-08-14 01:16:53,921 [root] DEBUG: Allocation: 0x004C3000 - 0x004C4000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:53,921 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:53,921 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 13.
2019-08-14 01:16:53,921 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x4000 added to tracked regions.
2019-08-14 01:16:53,921 [root] DEBUG: Allocation: 0x004C4000 - 0x004C5000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:53,921 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:53,921 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 14.
2019-08-14 01:16:53,921 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x5000 added to tracked regions.
2019-08-14 01:16:53,921 [root] DEBUG: Allocation: 0x004C5000 - 0x004C6000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:53,921 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:53,921 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 15.
2019-08-14 01:16:53,921 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x6000 added to tracked regions.
2019-08-14 01:16:53,921 [root] DEBUG: Allocation: 0x004C6000 - 0x004C7000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:53,921 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:53,921 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 16.
2019-08-14 01:16:53,937 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x7000 added to tracked regions.
2019-08-14 01:16:53,937 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1856.
2019-08-14 01:16:53,937 [root] DEBUG: Allocation: 0x004C7000 - 0x004C8000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:53,937 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:53,937 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 17.
2019-08-14 01:16:53,937 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x8000 added to tracked regions.
2019-08-14 01:16:53,951 [root] DEBUG: Allocation: 0x004C8000 - 0x004CB000, size: 0x3000, protection: 0x40.
2019-08-14 01:16:53,951 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:53,951 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 18.
2019-08-14 01:16:53,951 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0xb000 added to tracked regions.
2019-08-14 01:16:53,951 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x004C0000, TrackedRegion->RegionSize: 0xb000, thread 576
2019-08-14 01:16:53,951 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xd0, Size=0x0, Address=0x004C8000 and Type=0x1.
2019-08-14 01:16:53,951 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 576 type 1 at address 0x004C8000, size 0 with Callback 0x747e7620.
2019-08-14 01:16:53,951 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x004C8000
2019-08-14 01:16:53,951 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xd0, Size=0x4, Address=0x004C003C and Type=0x1.
2019-08-14 01:16:53,951 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 576 type 1 at address 0x004C003C, size 4 with Callback 0x747e7280.
2019-08-14 01:16:53,951 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x004C003C
2019-08-14 01:16:53,951 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x004C8000 (size 0x3000).
2019-08-14 01:16:53,951 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x73CF1AA3 (thread 576)
2019-08-14 01:16:53,951 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x004C8000.
2019-08-14 01:16:53,951 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x004C8000 and Type=0x0.
2019-08-14 01:16:53,951 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x4c8000: 0x54.
2019-08-14 01:16:53,951 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:16:53,983 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:53,983 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 19.
2019-08-14 01:16:53,983 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x061BE000
2019-08-14 01:16:53,983 [root] DEBUG: AddTrackedRegion: GetEntropy failed.
2019-08-14 01:16:53,983 [root] DEBUG: AddTrackedRegion: Region at 0x06150000 size 0x180 added to tracked regions.
2019-08-14 01:16:53,983 [root] DEBUG: ProtectionHandler: Address: 0x06150178 (alloc base 0x06150000), NumberOfBytesToProtect: 0x8, NewAccessProtection: 0x40
2019-08-14 01:16:53,983 [root] DEBUG: ProtectionHandler: New code detected at (0x06150000), scanning for PE images.
2019-08-14 01:16:53,983 [root] DEBUG: DumpPEsInRange: Scanning range 0x06150000 - 0x06150180.
2019-08-14 01:16:53,983 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x6150000
2019-08-14 01:16:53,983 [root] DEBUG: DumpPEsInRange: PE image at 0x06150000, dumping
2019-08-14 01:16:53,983 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2019-08-14 01:16:53,983 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x06150000.
2019-08-14 01:16:53,999 [root] INFO: Added new CAPE file to list with path: C:\xeiUbkq\CAPE\1460_17130176645316014382019
2019-08-14 01:16:53,999 [root] DEBUG: DumpPE: PE file in memory dumped successfully - dump size 0x6d600.
2019-08-14 01:16:53,999 [root] DEBUG: ScanForDisguisedPE: Exception occured scanning buffer at 0x61bdfc1
2019-08-14 01:16:53,999 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x06150000.
2019-08-14 01:16:53,999 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x6150000 - 0x6150180.
2019-08-14 01:16:53,999 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:54,015 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 20.
2019-08-14 01:16:54,015 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x061BE000
2019-08-14 01:16:54,015 [root] DEBUG: AddTrackedRegion: GetEntropy failed.
2019-08-14 01:16:54,015 [root] DEBUG: AddTrackedRegion: Region at 0x06150000 size 0x1a8 added to tracked regions.
2019-08-14 01:16:54,015 [root] DEBUG: ProtectionHandler: Address: 0x061501A0 (alloc base 0x06150000), NumberOfBytesToProtect: 0x8, NewAccessProtection: 0x40
2019-08-14 01:16:54,015 [root] DEBUG: ProtectionHandler: New code detected at (0x06150000), scanning for PE images.
2019-08-14 01:16:54,015 [root] DEBUG: DumpPEsInRange: Scanning range 0x06150000 - 0x061501A8.
2019-08-14 01:16:54,015 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x6150000
2019-08-14 01:16:54,015 [root] DEBUG: DumpPEsInRange: PE image at 0x06150000, dumping
2019-08-14 01:16:54,015 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2019-08-14 01:16:54,015 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x06150000.
2019-08-14 01:16:54,015 [root] INFO: Added new CAPE file to list with path: C:\xeiUbkq\CAPE\1460_13423681595416014382019
2019-08-14 01:16:54,015 [root] DEBUG: DumpPE: PE file in memory dumped successfully - dump size 0x6d600.
2019-08-14 01:16:54,029 [root] DEBUG: ScanForDisguisedPE: Exception occured scanning buffer at 0x61bdfc1
2019-08-14 01:16:54,029 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x06150000.
2019-08-14 01:16:54,029 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x6150000 - 0x61501a8.
2019-08-14 01:16:54,029 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:54,029 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 21.
2019-08-14 01:16:54,029 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x061BE000
2019-08-14 01:16:54,029 [root] DEBUG: AddTrackedRegion: GetEntropy failed.
2019-08-14 01:16:54,029 [root] DEBUG: AddTrackedRegion: Region at 0x06150000 size 0x1d0 added to tracked regions.
2019-08-14 01:16:54,029 [root] DEBUG: ProtectionHandler: Address: 0x061501C8 (alloc base 0x06150000), NumberOfBytesToProtect: 0x8, NewAccessProtection: 0x40
2019-08-14 01:16:54,029 [root] DEBUG: ProtectionHandler: New code detected at (0x06150000), scanning for PE images.
2019-08-14 01:16:54,029 [root] DEBUG: DumpPEsInRange: Scanning range 0x06150000 - 0x061501D0.
2019-08-14 01:16:54,029 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x6150000
2019-08-14 01:16:54,029 [root] DEBUG: DumpPEsInRange: PE image at 0x06150000, dumping
2019-08-14 01:16:54,029 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2019-08-14 01:16:54,029 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x06150000.
2019-08-14 01:16:54,046 [root] INFO: Added new CAPE file to list with path: C:\xeiUbkq\CAPE\1460_21167603865416014382019
2019-08-14 01:16:54,046 [root] DEBUG: DumpPE: PE file in memory dumped successfully - dump size 0x6d600.
2019-08-14 01:16:54,046 [root] DEBUG: ScanForDisguisedPE: Exception occured scanning buffer at 0x61bdfc1
2019-08-14 01:16:54,046 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x06150000.
2019-08-14 01:16:54,046 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x6150000 - 0x61501d0.
2019-08-14 01:16:54,046 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:54,046 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 22.
2019-08-14 01:16:54,046 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x061BE000
2019-08-14 01:16:54,046 [root] DEBUG: AddTrackedRegion: GetEntropy failed.
2019-08-14 01:16:54,046 [root] DEBUG: AddTrackedRegion: Region at 0x06150000 size 0x6cd99 added to tracked regions.
2019-08-14 01:16:54,046 [root] DEBUG: ProtectionHandler: Address: 0x061BCD8E (alloc base 0x06150000), NumberOfBytesToProtect: 0xb, NewAccessProtection: 0x40
2019-08-14 01:16:54,046 [root] DEBUG: ProtectionHandler: New code detected at (0x06150000), scanning for PE images.
2019-08-14 01:16:54,046 [root] DEBUG: DumpPEsInRange: Scanning range 0x06150000 - 0x061BCD99.
2019-08-14 01:16:54,046 [root] DEBUG: ScanForDisguisedPE: PE image located at: 0x6150000
2019-08-14 01:16:54,046 [root] DEBUG: DumpPEsInRange: PE image at 0x06150000, dumping
2019-08-14 01:16:54,046 [root] DEBUG: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image.
2019-08-14 01:16:54,046 [root] DEBUG: DumpPE: Instantiating PeParser with address: 0x06150000.
2019-08-14 01:16:54,062 [root] INFO: Added new CAPE file to list with path: C:\xeiUbkq\CAPE\1460_8260636065416014382019
2019-08-14 01:16:54,062 [root] DEBUG: DumpPE: PE file in memory dumped successfully - dump size 0x6d600.
2019-08-14 01:16:54,062 [root] DEBUG: ScanForDisguisedPE: No PE image located in range 0x6150001-0x61bcd99.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: PE image(s) dumped from 0x06150000.
2019-08-14 01:16:54,062 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x6150000 - 0x61bcd99.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,062 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: ProtectionHandler: Current tracked region has already been dumped.
2019-08-14 01:16:54,076 [root] DEBUG: Allocation: 0x004CB000 - 0x004CC000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:54,076 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:54,076 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 23.
2019-08-14 01:16:54,076 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0xc000 added to tracked regions.
2019-08-14 01:16:54,108 [root] DEBUG: Allocation: 0x004CC000 - 0x004CD000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:54,108 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:54,108 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 24.
2019-08-14 01:16:54,108 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0xd000 added to tracked regions.
2019-08-14 01:16:54,154 [root] DEBUG: Allocation: 0x004CD000 - 0x004CE000, size: 0x1000, protection: 0x40.
2019-08-14 01:16:54,154 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:16:54,154 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 25.
2019-08-14 01:16:54,154 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0xe000 added to tracked regions.
2019-08-14 01:17:04,170 [root] DEBUG: DLL loaded at 0x75E70000: C:\Windows\syswow64\shell32 (0xc4a000 bytes).
2019-08-14 01:17:04,201 [root] DEBUG: DLL loaded at 0x749D0000: C:\Windows\system32\ntmarta (0x21000 bytes).
2019-08-14 01:17:04,201 [root] DEBUG: DLL loaded at 0x76EA0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2019-08-14 01:17:04,279 [root] DEBUG: Allocation: 0x004CE000 - 0x004CF000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:04,279 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:17:04,279 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 26.
2019-08-14 01:17:04,279 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0xf000 added to tracked regions.
2019-08-14 01:17:04,311 [root] DEBUG: Allocation: 0x004CF000 - 0x004D0000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:04,311 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:17:04,311 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 27.
2019-08-14 01:17:04,311 [root] DEBUG: AddTrackedRegion: Region at 0x004C0000 size 0x10000 added to tracked regions.
2019-08-14 01:17:04,372 [root] DEBUG: DLL loaded at 0x70590000: C:\Windows\system32\PROPSYS (0xf5000 bytes).
2019-08-14 01:17:04,388 [root] DEBUG: DLL loaded at 0x74AF0000: C:\Windows\system32\apphelp (0x4c000 bytes).
2019-08-14 01:17:04,388 [root] DEBUG: DLL loaded at 0x74EB0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2019-08-14 01:17:04,436 [root] DEBUG: DLL loaded at 0x6FB10000: C:\Windows\SysWOW64\ieframe (0xa80000 bytes).
2019-08-14 01:17:04,467 [root] DEBUG: DLL loaded at 0x73AE0000: C:\Windows\SysWOW64\OLEACC (0x3c000 bytes).
2019-08-14 01:17:04,497 [root] DEBUG: DLL loaded at 0x76CA0000: C:\Windows\syswow64\iertutil (0x1fb000 bytes).
2019-08-14 01:17:04,545 [root] DEBUG: DLL loaded at 0x74F40000: C:\Windows\syswow64\urlmon (0x136000 bytes).
2019-08-14 01:17:04,575 [root] DEBUG: DLL loaded at 0x75600000: C:\Windows\syswow64\WININET (0xf5000 bytes).
2019-08-14 01:17:04,592 [root] DEBUG: DLL loaded at 0x75790000: C:\Windows\syswow64\CRYPT32 (0x11d000 bytes).
2019-08-14 01:17:04,592 [root] DEBUG: DLL loaded at 0x755F0000: C:\Windows\syswow64\MSASN1 (0xc000 bytes).
2019-08-14 01:17:04,700 [root] DEBUG: DLL loaded at 0x75A70000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes).
2019-08-14 01:17:04,700 [root] DEBUG: DLL loaded at 0x75A10000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2019-08-14 01:17:04,700 [root] DEBUG: DLL loaded at 0x75D40000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2019-08-14 01:17:04,716 [root] DEBUG: DLL unloaded from 0x75E70000.
2019-08-14 01:17:04,747 [root] DEBUG: DLL loaded at 0x74950000: C:\Windows\system32\profapi (0xb000 bytes).
2019-08-14 01:17:04,857 [root] INFO: Announced 32-bit process name: schtasks.exe pid: 2868
2019-08-14 01:17:04,857 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:04,857 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:04,857 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:04,857 [root] DEBUG: Loader: Injecting process 2868 (thread 1560) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:04,857 [root] DEBUG: Process image base: 0x00630000
2019-08-14 01:17:04,857 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:04,857 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x0065E000 - 0x77110000
2019-08-14 01:17:04,857 [root] DEBUG: InjectDllViaIAT: Allocated 0x344 bytes for new import table at 0x00660000.
2019-08-14 01:17:04,857 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-14 01:17:04,857 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:04,857 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2868
2019-08-14 01:17:04,871 [root] DEBUG: DLL loaded at 0x74C70000: C:\Windows\system32\CRYPTSP (0x16000 bytes).
2019-08-14 01:17:04,871 [root] DEBUG: DLL loaded at 0x74C30000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2019-08-14 01:17:04,871 [root] DEBUG: DLL loaded at 0x74940000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2019-08-14 01:17:04,871 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2736.
2019-08-14 01:17:04,888 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-14 01:17:04,888 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x004C8000 already exists for thread 2736 (process 1460), skipping.
2019-08-14 01:17:04,888 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x004C003C already exists for thread 2736 (process 1460), skipping.
2019-08-14 01:17:04,888 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x004C8000 already exists for thread 2736 (process 1460), skipping.
2019-08-14 01:17:04,888 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:17:04,888 [root] DEBUG: Process dumps disabled.
2019-08-14 01:17:04,888 [root] INFO: Disabling sleep skipping.
2019-08-14 01:17:04,888 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-14 01:17:04,888 [root] DEBUG: WoW64 detected: 64-bit ntdll base: 0x77110000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7716124a, Wow64PrepareForException: 0x0
2019-08-14 01:17:04,888 [root] DEBUG: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x190000
2019-08-14 01:17:04,888 [root] DEBUG: Debugger initialised.
2019-08-14 01:17:04,888 [root] DEBUG: CAPE initialised: 32-bit Extraction v2 loaded in process 2868 at 0x747e0000, image base 0x630000, stack from 0xc6000-0xd0000
2019-08-14 01:17:04,888 [root] DEBUG: Commandline: C:\Users\user\AppData\Local\Temp\"C:\Windows\System32\schtasks.exe" \Create \TN "Updates\LIeDXmUzhdkSdI" \XML "C:\Users\user\AppData\Local\Temp\tmpDEAB.tmp".
2019-08-14 01:17:04,888 [root] DEBUG: AddTrackedRegion: EntryPoint 0x17683, Entropy 5.581797e+00
2019-08-14 01:17:04,888 [root] DEBUG: AddTrackedRegion: Region at 0x00630000 size 0x1000 added to tracked regions.
2019-08-14 01:17:04,888 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:17:04,904 [root] INFO: Added new process to list with pid: 2868
2019-08-14 01:17:04,904 [root] INFO: Monitor successfully loaded in process with pid 2868.
2019-08-14 01:17:04,904 [root] DEBUG: DLL loaded at 0x747D0000: C:\Windows\SysWOW64\VERSION (0x9000 bytes).
2019-08-14 01:17:04,904 [root] DEBUG: DLL unloaded from 0x00630000.
2019-08-14 01:17:05,121 [root] INFO: Stopped Task Scheduler Service
2019-08-14 01:17:05,138 [root] INFO: Started Task Scheduler Service
2019-08-14 01:17:05,184 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:05,184 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:17:05,184 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:05,184 [root] DEBUG: Loader: Injecting process 816 (thread 0) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:05,184 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 820, handle 0x84
2019-08-14 01:17:05,184 [root] DEBUG: Process image base: 0x00000000FFA10000
2019-08-14 01:17:05,200 [root] DEBUG: InjectDllViaIAT: Not a new process, aborting IAT patch
2019-08-14 01:17:05,200 [root] DEBUG: InjectDll: IAT patching failed, falling back to thread injection.
2019-08-14 01:17:05,200 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:17:05,200 [root] DEBUG: Process dumps disabled.
2019-08-14 01:17:05,200 [root] INFO: Disabling sleep skipping.
2019-08-14 01:17:05,262 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:17:05,262 [root] WARNING: Unable to hook LockResource
2019-08-14 01:17:05,293 [root] DEBUG: Debugger initialised.
2019-08-14 01:17:05,293 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 816 at 0x000000006FA20000, image base 0x00000000FFA10000, stack from 0x0000000001766000-0x0000000001770000
2019-08-14 01:17:05,293 [root] DEBUG: Commandline: C:\Windows\sysnative\svchost.exe -k netsvcs.
2019-08-14 01:17:05,309 [root] DEBUG: AddTrackedRegion: EntryPoint 0x246c, Entropy 3.672292e+00
2019-08-14 01:17:05,309 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFA10000 size 0x1000 added to tracked regions.
2019-08-14 01:17:05,309 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:17:05,309 [root] INFO: Added new process to list with pid: 816
2019-08-14 01:17:05,309 [root] INFO: Monitor successfully loaded in process with pid 816.
2019-08-14 01:17:05,309 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2019-08-14 01:17:05,309 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2019-08-14 01:17:05,309 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:07,322 [root] DEBUG: DLL loaded at 0x74EB0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2019-08-14 01:17:07,336 [root] DEBUG: DLL loaded at 0x6F9A0000: C:\Windows\SysWOW64\taskschd (0x7d000 bytes).
2019-08-14 01:17:07,539 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 2868).
2019-08-14 01:17:07,539 [root] DEBUG: DLL unloaded from 0x75140000.
2019-08-14 01:17:07,539 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 2868).
2019-08-14 01:17:07,539 [root] INFO: Notified of termination of process with pid 2868.
2019-08-14 01:17:07,586 [root] DEBUG: Allocation: 0x00FE0000 - 0x00FE1000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:07,586 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:17:07,586 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 28.
2019-08-14 01:17:07,586 [root] DEBUG: AddTrackedRegion: Region at 0x00FE0000 size 0x1000 added to tracked regions.
2019-08-14 01:17:07,601 [root] DEBUG: set_caller_info: Adding region at 0x00FE0000 to caller regions list.
2019-08-14 01:17:07,618 [root] INFO: Announced 32-bit process name: DOCUMENTS-7821.exe pid: 2968
2019-08-14 01:17:07,618 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:07,618 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:07,618 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:07,664 [root] DEBUG: Loader: Injecting process 2968 (thread 2948) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,664 [root] DEBUG: Process image base: 0x01020000
2019-08-14 01:17:07,664 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:17:07,664 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:17:07,711 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,711 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2968
2019-08-14 01:17:07,711 [root] DEBUG: Allocation: 0x00FE1000 - 0x00FE2000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:07,711 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:17:07,711 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 29.
2019-08-14 01:17:07,711 [root] DEBUG: AddTrackedRegion: Region at 0x00FE0000 size 0x2000 added to tracked regions.
2019-08-14 01:17:07,711 [root] INFO: Announced 32-bit process name: DOCUMENTS-7821.exe pid: 2968
2019-08-14 01:17:07,711 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:07,711 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:07,711 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:07,711 [root] DEBUG: Loader: Injecting process 2968 (thread 0) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,726 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2948, handle 0x9c
2019-08-14 01:17:07,726 [root] DEBUG: Process image base: 0x01020000
2019-08-14 01:17:07,726 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:17:07,726 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:17:07,757 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,757 [root] INFO: Process with pid 2868 has terminated
2019-08-14 01:17:07,757 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2968
2019-08-14 01:17:07,757 [root] INFO: Announced 32-bit process name: DOCUMENTS-7821.exe pid: 2968
2019-08-14 01:17:07,757 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:07,757 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:07,757 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:07,757 [root] DEBUG: Loader: Injecting process 2968 (thread 0) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,757 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2948, handle 0x9c
2019-08-14 01:17:07,757 [root] DEBUG: Process image base: 0x01020000
2019-08-14 01:17:07,757 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:17:07,757 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:17:07,757 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,773 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2968
2019-08-14 01:17:07,773 [root] INFO: Announced 32-bit process name: DOCUMENTS-7821.exe pid: 2968
2019-08-14 01:17:07,773 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:07,773 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:07,851 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:07,851 [root] DEBUG: Loader: Injecting process 2968 (thread 0) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,851 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2948, handle 0x9c
2019-08-14 01:17:07,851 [root] DEBUG: Process image base: 0x01020000
2019-08-14 01:17:07,851 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:17:07,851 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:17:07,851 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,851 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2968
2019-08-14 01:17:07,851 [root] INFO: Announced 32-bit process name: DOCUMENTS-7821.exe pid: 2968
2019-08-14 01:17:07,851 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:07,851 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:07,868 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:07,868 [root] DEBUG: Loader: Injecting process 2968 (thread 0) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,898 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2948, handle 0x9c
2019-08-14 01:17:07,898 [root] DEBUG: Process image base: 0x01020000
2019-08-14 01:17:07,898 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:17:07,898 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:17:07,946 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,946 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2968
2019-08-14 01:17:07,946 [root] INFO: Announced 32-bit process name: DOCUMENTS-7821.exe pid: 2968
2019-08-14 01:17:07,946 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:07,946 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:07,946 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:07,946 [root] DEBUG: Loader: Injecting process 2968 (thread 0) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,946 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2948, handle 0x9c
2019-08-14 01:17:07,946 [root] DEBUG: Process image base: 0x00400000
2019-08-14 01:17:07,946 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:17:07,946 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:17:07,946 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,960 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2968
2019-08-14 01:17:07,960 [root] INFO: Announced 32-bit process name: DOCUMENTS-7821.exe pid: 2968
2019-08-14 01:17:07,960 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:07,960 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:17:07,992 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:07,992 [root] DEBUG: Loader: Injecting process 2968 (thread 2948) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,992 [root] DEBUG: Process image base: 0x00400000
2019-08-14 01:17:07,992 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2019-08-14 01:17:07,992 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2019-08-14 01:17:07,992 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:17:07,992 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2968
2019-08-14 01:17:08,007 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:17:08,007 [root] DEBUG: Process dumps disabled.
2019-08-14 01:17:08,039 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2652.
2019-08-14 01:17:08,039 [root] INFO: Disabling sleep skipping.
2019-08-14 01:17:08,039 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x004C8000 already exists for thread 2652 (process 1460), skipping.
2019-08-14 01:17:08,039 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x004C003C already exists for thread 2652 (process 1460), skipping.
2019-08-14 01:17:08,039 [root] DEBUG: WoW64 detected: 64-bit ntdll base: 0x77110000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7716124a, Wow64PrepareForException: 0x0
2019-08-14 01:17:08,039 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x004C8000 already exists for thread 2652 (process 1460), skipping.
2019-08-14 01:17:08,039 [root] DEBUG: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x1b0000
2019-08-14 01:17:08,039 [root] DEBUG: Debugger initialised.
2019-08-14 01:17:08,117 [root] DEBUG: CAPE initialised: 32-bit Extraction v2 loaded in process 2968 at 0x747e0000, image base 0x400000, stack from 0x366000-0x370000
2019-08-14 01:17:08,117 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 1460).
2019-08-14 01:17:08,117 [root] DEBUG: Commandline: C:\Users\user\AppData\Local\Temp\"C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe".
2019-08-14 01:17:08,117 [root] DEBUG: CAPEExceptionFilter: Exception 0xc0000005 caught at RVA 0x1854 in capemon caught accessing 0x1021000 (expected in memory scans), passing to next handler.
2019-08-14 01:17:08,117 [root] DEBUG: AddTrackedRegion: EntryPoint 0x74587cef, Entropy 6.271207e+00
2019-08-14 01:17:08,117 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:17:08,117 [root] DEBUG: AddTrackedRegion: Region at 0x00400000 size 0x5a000 added to tracked regions.
2019-08-14 01:17:08,117 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:17:08,132 [root] INFO: Added new process to list with pid: 2968
2019-08-14 01:17:08,132 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,132 [root] INFO: Monitor successfully loaded in process with pid 2968.
2019-08-14 01:17:08,132 [root] DEBUG: DLL unloaded from 0x70590000.
2019-08-14 01:17:08,132 [root] DEBUG: set_caller_info: Adding region at 0x00090000 to caller regions list.
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x75140000.
2019-08-14 01:17:08,148 [root] DEBUG: DLL loaded at 0x00ED0000: C:\nkmznsmshd\dll\UPldJWKY (0xc0000 bytes).
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x749D0000.
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x00ED0000.
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x73E20000.
2019-08-14 01:17:08,148 [root] DEBUG: set_caller_info: Adding region at 0x000A0000 to caller regions list.
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x744C0000.
2019-08-14 01:17:08,148 [root] DEBUG: DLL loaded at 0x00ED0000: C:\nkmznsmshd\dll\UPldJWKY (0xc0000 bytes).
2019-08-14 01:17:08,148 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 1460).
2019-08-14 01:17:08,148 [root] DEBUG: CAPEExceptionFilter: Exception 0xc0000005 caught at RVA 0x1854 in capemon caught accessing 0x1021000 (expected in memory scans), passing to next handler.
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,148 [root] DEBUG: GetEntropy: Exception occured attempting to get PE entropy at 0x01021000
2019-08-14 01:17:08,148 [root] DEBUG: DLL unloaded from 0x00ED0000.
2019-08-14 01:17:08,148 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2320.
2019-08-14 01:17:08,164 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2380.
2019-08-14 01:17:08,164 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2872.
2019-08-14 01:17:08,164 [root] DEBUG: set_caller_info: Adding region at 0x000B0000 to caller regions list.
2019-08-14 01:17:08,164 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:17:08,164 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2736.
2019-08-14 01:17:08,164 [root] DEBUG: DLL loaded at 0x00ED0000: C:\nkmznsmshd\dll\UPldJWKY (0xc0000 bytes).
2019-08-14 01:17:08,164 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2652.
2019-08-14 01:17:08,164 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,164 [root] INFO: Notified of termination of process with pid 1460.
2019-08-14 01:17:08,164 [root] DEBUG: DLL unloaded from 0x00ED0000.
2019-08-14 01:17:08,180 [root] DEBUG: set_caller_info: Adding region at 0x00100000 to caller regions list.
2019-08-14 01:17:08,180 [root] DEBUG: DLL loaded at 0x00ED0000: C:\nkmznsmshd\dll\UPldJWKY (0xc0000 bytes).
2019-08-14 01:17:08,180 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,180 [root] DEBUG: DLL unloaded from 0x00ED0000.
2019-08-14 01:17:08,194 [root] DEBUG: set_caller_info: Adding region at 0x00110000 to caller regions list.
2019-08-14 01:17:08,194 [root] DEBUG: DLL loaded at 0x00ED0000: C:\nkmznsmshd\dll\UPldJWKY (0xc0000 bytes).
2019-08-14 01:17:08,194 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,194 [root] DEBUG: DLL unloaded from 0x00ED0000.
2019-08-14 01:17:08,194 [root] DEBUG: set_caller_info: Adding region at 0x00120000 to caller regions list.
2019-08-14 01:17:08,226 [root] DEBUG: DLL loaded at 0x00ED0000: C:\nkmznsmshd\dll\UPldJWKY (0xc0000 bytes).
2019-08-14 01:17:08,226 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:17:08,226 [root] DEBUG: DLL unloaded from 0x00ED0000.
2019-08-14 01:17:08,226 [root] DEBUG: set_caller_info: Calling address 0x0036F300 in stack (advapi32::RegQueryInfoKeyW)
2019-08-14 01:17:08,226 [root] DEBUG: set_caller_info: Adding region at 0x00270000 to caller regions list.
2019-08-14 01:17:08,226 [root] DEBUG: set_caller_info: Adding region at 0x02670000 to caller regions list.
2019-08-14 01:17:08,226 [root] DEBUG: set_caller_info: Adding region at 0x00560000 to caller regions list.
2019-08-14 01:17:08,226 [root] DEBUG: DLL loaded at 0x74440000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x7b000 bytes).
2019-08-14 01:17:08,226 [root] DEBUG: Allocation: 0x00ED0000 - 0x00FE0000, size: 0x110000, protection: 0x40.
2019-08-14 01:17:08,242 [root] DEBUG: AddTrackedRegion: Region at 0x00ED0000 size 0x110000 added to tracked regions.
2019-08-14 01:17:08,242 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x00ED0000.
2019-08-14 01:17:08,242 [root] DEBUG: FreeHandler: Address: 0x00ED0000.
2019-08-14 01:17:08,242 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0xed0000 - 0xfe0000.
2019-08-14 01:17:08,242 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a6ea48, AllocationBase 0x400000.
2019-08-14 01:17:08,242 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a6eaf0, AllocationBase 0xed0000.
2019-08-14 01:17:08,242 [root] DEBUG: DropTrackedRegion: removed pages 0xed0000-0xfe0000 from tracked region list.
2019-08-14 01:17:08,242 [root] DEBUG: Allocation: 0x00FA0000 - 0x00FA1000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,242 [root] DEBUG: AddTrackedRegion: Region at 0x00FA0000 size 0x1000 added to tracked regions.
2019-08-14 01:17:08,257 [root] DEBUG: DLL loaded at 0x73DA0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr (0x69b000 bytes).
2019-08-14 01:17:08,257 [root] DEBUG: DLL loaded at 0x73CC0000: C:\Windows\system32\MSVCR110_CLR0400 (0xd3000 bytes).
2019-08-14 01:17:08,257 [root] DEBUG: Allocation: 0x03BB0000 - 0x03C90000, size: 0xe0000, protection: 0x40.
2019-08-14 01:17:08,257 [root] DEBUG: AddTrackedRegion: Region at 0x03BB0000 size 0xe0000 added to tracked regions.
2019-08-14 01:17:08,257 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x03BB0000.
2019-08-14 01:17:08,273 [root] DEBUG: FreeHandler: Address: 0x03BB0000.
2019-08-14 01:17:08,273 [root] DEBUG: ClearBreakpointsInRange: Clearing breakpoints in range 0x3bb0000 - 0x3c90000.
2019-08-14 01:17:08,273 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a6ea48, AllocationBase 0x400000.
2019-08-14 01:17:08,273 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a6ec48, AllocationBase 0xfa0000.
2019-08-14 01:17:08,273 [root] DEBUG: DropTrackedRegion: CurrentTrackedRegion 0x2a6eaf0, AllocationBase 0x3bb0000.
2019-08-14 01:17:08,273 [root] DEBUG: DropTrackedRegion: removed pages 0x3bb0000-0x3c90000 from tracked region list.
2019-08-14 01:17:08,273 [root] DEBUG: Allocation: 0x03C50000 - 0x03C51000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,273 [root] DEBUG: AddTrackedRegion: Region at 0x03C50000 size 0x1000 added to tracked regions.
2019-08-14 01:17:08,273 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1752.
2019-08-14 01:17:08,273 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-14 01:17:08,289 [root] DEBUG: Allocation: 0x001F2000 - 0x001F3000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,289 [root] DEBUG: AddTrackedRegion: Region at 0x001F0000 size 0x3000 added to tracked regions.
2019-08-14 01:17:08,289 [root] DEBUG: CreateThread: Initialising breakpoints for thread 864.
2019-08-14 01:17:08,303 [root] DEBUG: DLL loaded at 0x71990000: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\045c9588954c3662d542b53f4462268b\mscorlib.ni (0x102e000 bytes).
2019-08-14 01:17:08,303 [root] DEBUG: Allocation: 0x0020C000 - 0x0020D000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,303 [root] DEBUG: AddTrackedRegion: Region at 0x00200000 size 0xd000 added to tracked regions.
2019-08-14 01:17:08,303 [root] DEBUG: DLL loaded at 0x744C0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit (0x7d000 bytes).
2019-08-14 01:17:08,303 [root] DEBUG: DLL loaded at 0x75980000: C:\Windows\syswow64\OLEAUT32 (0x8f000 bytes).
2019-08-14 01:17:08,319 [root] DEBUG: Allocation: 0x03CA0000 - 0x03CA1000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,335 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x1000 added to tracked regions.
2019-08-14 01:17:08,335 [root] DEBUG: Allocation: 0x03CA1000 - 0x03CB4000, size: 0x13000, protection: 0x40.
2019-08-14 01:17:08,335 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x14000 added to tracked regions.
2019-08-14 01:17:08,351 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x03CA0000, TrackedRegion->RegionSize: 0x14000, thread 2948
2019-08-14 01:17:08,351 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xd0, Size=0x0, Address=0x03CA1000 and Type=0x1.
2019-08-14 01:17:08,351 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2948 type 1 at address 0x03CA1000, size 0 with Callback 0x747e7620.
2019-08-14 01:17:08,351 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x03CA1000
2019-08-14 01:17:08,351 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xd0, Size=0x4, Address=0x03CA003C and Type=0x1.
2019-08-14 01:17:08,351 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2948 type 1 at address 0x03CA003C, size 4 with Callback 0x747e7280.
2019-08-14 01:17:08,351 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x03CA003C
2019-08-14 01:17:08,351 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x03CA1000 (size 0x13000).
2019-08-14 01:17:08,367 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744F1AA3 (thread 2948)
2019-08-14 01:17:08,367 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CA1000.
2019-08-14 01:17:08,367 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x03CA1000 and Type=0x0.
2019-08-14 01:17:08,367 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3ca1000: 0xff.
2019-08-14 01:17:08,367 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:17:08,381 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744D20FB (thread 2948)
2019-08-14 01:17:08,381 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CA1000.
2019-08-14 01:17:08,381 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03CA1000 already exists for thread 2948 (process 2968), skipping.
2019-08-14 01:17:08,381 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3ca1000: 0xff.
2019-08-14 01:17:08,381 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:17:08,381 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744D2106 (thread 2948)
2019-08-14 01:17:08,381 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CA1000.
2019-08-14 01:17:08,381 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03CA1000 already exists for thread 2948 (process 2968), skipping.
2019-08-14 01:17:08,381 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3ca1000: 0xff.
2019-08-14 01:17:08,381 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:17:08,381 [root] DEBUG: set_caller_info: Adding region at 0x03CA0000 to caller regions list.
2019-08-14 01:17:08,398 [root] DEBUG: Allocation: 0x00225000 - 0x00226000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,398 [root] DEBUG: AddTrackedRegion: Region at 0x00220000 size 0x6000 added to tracked regions.
2019-08-14 01:17:08,398 [root] DEBUG: Allocation: 0x0022B000 - 0x0022C000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,398 [root] DEBUG: AddTrackedRegion: Region at 0x00220000 size 0xc000 added to tracked regions.
2019-08-14 01:17:08,398 [root] DEBUG: Allocation: 0x00227000 - 0x00228000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,398 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00220000, size: 0xc000.
2019-08-14 01:17:08,414 [root] DEBUG: DLL loaded at 0x73050000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System\79f6324a598a7c4446a4a1168be7c4b1\System.ni (0x99a000 bytes).
2019-08-14 01:17:08,444 [root] DEBUG: DLL loaded at 0x712E0000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\4e69f1e7d86d79012db2d7e0dadc8880\System.Core.ni (0x6ae000 bytes).
2019-08-14 01:17:08,444 [root] DEBUG: DLL loaded at 0x73AE0000: C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\65f7c6dcc498c7157f0ef5b72824d60a\Microsoft.VisualBasic.ni (0x1dd000 bytes).
2019-08-14 01:17:08,460 [root] DEBUG: DLL loaded at 0x72EB0000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c4477b3ce64d0d612d1ab0dba425b77f\System.Drawing.ni (0x194000 bytes).
2019-08-14 01:17:08,460 [root] DEBUG: DLL loaded at 0x70690000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\05ca0ca95b6fcc0d710b63b6200cc178\System.Windows.Forms.ni (0xc4f000 bytes).
2019-08-14 01:17:08,476 [root] DEBUG: Allocation: 0x00216000 - 0x00217000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,476 [root] DEBUG: AddTrackedRegion: Region at 0x00210000 size 0x7000 added to tracked regions.
2019-08-14 01:17:08,492 [root] DEBUG: DLL loaded at 0x74940000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting (0x12000 bytes).
2019-08-14 01:17:08,492 [root] DEBUG: DLL loaded at 0x75E70000: C:\Windows\syswow64\shell32 (0xc4a000 bytes).
2019-08-14 01:17:08,492 [root] DEBUG: DLL loaded at 0x74970000: C:\Windows\system32\profapi (0xb000 bytes).
2019-08-14 01:17:08,506 [root] DEBUG: Allocation: 0x001FA000 - 0x001FB000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,506 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 11.
2019-08-14 01:17:08,506 [root] DEBUG: AddTrackedRegion: Region at 0x001F0000 size 0xb000 added to tracked regions.
2019-08-14 01:17:08,523 [root] DEBUG: set_caller_info: Adding region at 0x001F0000 to caller regions list.
2019-08-14 01:17:08,523 [root] DEBUG: DLL loaded at 0x72E90000: C:\Windows\system32\bcrypt (0x17000 bytes).
2019-08-14 01:17:08,538 [root] DEBUG: Allocation: 0x0021A000 - 0x0021B000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,538 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 12.
2019-08-14 01:17:08,553 [root] DEBUG: AddTrackedRegion: Region at 0x00210000 size 0xb000 added to tracked regions.
2019-08-14 01:17:08,553 [root] DEBUG: Allocation: 0x00217000 - 0x00218000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,553 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00210000, size: 0xb000.
2019-08-14 01:17:08,553 [root] DEBUG: DLL loaded at 0x74C70000: C:\Windows\system32\CRYPTSP (0x16000 bytes).
2019-08-14 01:17:08,553 [root] DEBUG: DLL loaded at 0x74C30000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2019-08-14 01:17:08,569 [root] DEBUG: Allocation: 0x03CB4000 - 0x03CB5000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:08,569 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 13.
2019-08-14 01:17:08,569 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x15000 added to tracked regions.
2019-08-14 01:17:08,601 [root] DEBUG: DLL loaded at 0x74960000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2019-08-14 01:17:08,601 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1672.
2019-08-14 01:17:08,601 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CA1000 already exists for thread 1672 (process 2968), skipping.
2019-08-14 01:17:08,601 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 1672 (process 2968), skipping.
2019-08-14 01:17:08,601 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CA1000 already exists for thread 1672 (process 2968), skipping.
2019-08-14 01:17:08,615 [root] DEBUG: DLL loaded at 0x74EB0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2019-08-14 01:17:08,648 [root] DEBUG: DLL loaded at 0x72E50000: C:\Windows\system32\wbem\wbemdisp (0x31000 bytes).
2019-08-14 01:17:08,678 [root] DEBUG: DLL loaded at 0x72DF0000: C:\Windows\system32\wbemcomn (0x5c000 bytes).
2019-08-14 01:17:08,678 [root] DEBUG: DLL loaded at 0x75D00000: C:\Windows\syswow64\WS2_32 (0x35000 bytes).
2019-08-14 01:17:08,678 [root] DEBUG: DLL loaded at 0x75130000: C:\Windows\syswow64\NSI (0x6000 bytes).
2019-08-14 01:17:08,710 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF98D0000 to caller regions list.
2019-08-14 01:17:08,726 [root] DEBUG: DLL unloaded from 0x000007FEFA1C0000.
2019-08-14 01:17:08,756 [root] DEBUG: set_caller_info: Adding region at 0x000007FEFCEF0000 to caller regions list.
2019-08-14 01:17:08,788 [root] INFO: Process with pid 1460 has terminated
2019-08-14 01:17:08,788 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF9A00000 to caller regions list.
2019-08-14 01:17:08,819 [root] DEBUG: CreateThread: Initialising breakpoints for thread 928.
2019-08-14 01:17:08,819 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:08,835 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF8070000 to caller regions list.
2019-08-14 01:17:08,865 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF94D0000 to caller regions list.
2019-08-14 01:17:08,865 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2376.
2019-08-14 01:17:11,253 [root] DEBUG: DLL unloaded from 0x000007FEF9B80000.
2019-08-14 01:17:13,763 [root] DEBUG: DLL unloaded from 0x000007FEFA1C0000.
2019-08-14 01:17:13,763 [root] DEBUG: DLL loaded at 0x000007FEFB0D0000: C:\Windows\system32\es (0x67000 bytes).
2019-08-14 01:17:13,779 [root] DEBUG: set_caller_info: Adding region at 0x000007FEFB0D0000 to caller regions list.
2019-08-14 01:17:13,888 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2736.
2019-08-14 01:17:13,888 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:13,888 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2760.
2019-08-14 01:17:13,904 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF80F0000 to caller regions list.
2019-08-14 01:17:13,920 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF4E10000 to caller regions list.
2019-08-14 01:17:13,936 [root] DEBUG: CreateThread: Initialising breakpoints for thread 856.
2019-08-14 01:17:13,936 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2764.
2019-08-14 01:17:13,936 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2716.
2019-08-14 01:17:13,936 [root] DEBUG: CreateThread: Initialising breakpoints for thread 648.
2019-08-14 01:17:13,936 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2900.
2019-08-14 01:17:13,951 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2340.
2019-08-14 01:17:13,967 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2236.
2019-08-14 01:17:13,967 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2636.
2019-08-14 01:17:13,967 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2940.
2019-08-14 01:17:13,967 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2836.
2019-08-14 01:17:13,967 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2956.
2019-08-14 01:17:13,983 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2924.
2019-08-14 01:17:13,983 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2928.
2019-08-14 01:17:13,983 [root] DEBUG: CreateThread: Initialising breakpoints for thread 736.
2019-08-14 01:17:13,983 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2916.
2019-08-14 01:17:13,983 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF90B0000 to caller regions list.
2019-08-14 01:17:13,983 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1644.
2019-08-14 01:17:13,997 [root] DEBUG: set_caller_info: Adding region at 0x000007FEFA0C0000 to caller regions list.
2019-08-14 01:17:14,013 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF97C0000 to caller regions list.
2019-08-14 01:17:14,061 [root] DEBUG: DLL unloaded from 0x000007FEF9540000.
2019-08-14 01:17:14,075 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF45C0000 to caller regions list.
2019-08-14 01:17:14,092 [root] DEBUG: DLL unloaded from 0x000007FEFB0D0000.
2019-08-14 01:17:14,092 [root] DEBUG: DLL unloaded from 0x000007FEF45C0000.
2019-08-14 01:17:14,108 [root] DEBUG: DLL unloaded from 0x000007FEF9950000.
2019-08-14 01:17:14,108 [root] DEBUG: DLL unloaded from 0x000007FEF4E10000.
2019-08-14 01:17:14,108 [root] DEBUG: DLL unloaded from 0x000007FEF94D0000.
2019-08-14 01:17:14,108 [root] DEBUG: DLL unloaded from 0x000007FEF8070000.
2019-08-14 01:17:14,122 [root] DEBUG: DLL unloaded from 0x000007FEFA1C0000.
2019-08-14 01:17:16,369 [root] INFO: Stopped WMI Service
2019-08-14 01:17:16,369 [root] INFO: Attaching to DcomLaunch service (pid 564)
2019-08-14 01:17:16,369 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:16,369 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:17:16,369 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:16,369 [root] DEBUG: Loader: Injecting process 564 (thread 0) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:16,369 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 568, handle 0x84
2019-08-14 01:17:16,369 [root] DEBUG: Process image base: 0x00000000FFA10000
2019-08-14 01:17:16,369 [root] DEBUG: InjectDllViaIAT: Not a new process, aborting IAT patch
2019-08-14 01:17:16,384 [root] DEBUG: InjectDll: IAT patching failed, falling back to thread injection.
2019-08-14 01:17:16,384 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:17:16,384 [root] DEBUG: Process dumps disabled.
2019-08-14 01:17:16,384 [root] INFO: Disabling sleep skipping.
2019-08-14 01:17:16,384 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:17:16,401 [root] WARNING: Unable to hook LockResource
2019-08-14 01:17:16,401 [root] DEBUG: Debugger initialised.
2019-08-14 01:17:16,401 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 564 at 0x000000006FA20000, image base 0x00000000FFA10000, stack from 0x0000000001D76000-0x0000000001D80000
2019-08-14 01:17:16,401 [root] DEBUG: Commandline: C:\Windows\sysnative\svchost.exe -k DcomLaunch.
2019-08-14 01:17:16,401 [root] DEBUG: AddTrackedRegion: EntryPoint 0x246c, Entropy 3.671080e+00
2019-08-14 01:17:16,401 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFA10000 size 0x1000 added to tracked regions.
2019-08-14 01:17:16,401 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:17:16,401 [root] INFO: Added new process to list with pid: 564
2019-08-14 01:17:16,401 [root] INFO: Monitor successfully loaded in process with pid 564.
2019-08-14 01:17:16,415 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2019-08-14 01:17:16,415 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2019-08-14 01:17:16,415 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:20,535 [root] INFO: Started WMI Service
2019-08-14 01:17:20,535 [root] INFO: Attaching to WMI service (pid 2656)
2019-08-14 01:17:20,535 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:20,535 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:17:20,535 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:20,535 [root] DEBUG: Loader: Injecting process 2656 (thread 0) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:20,535 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2136, handle 0x84
2019-08-14 01:17:20,549 [root] DEBUG: Process image base: 0x00000000FFA10000
2019-08-14 01:17:20,549 [root] DEBUG: InjectDllViaIAT: Not a new process, aborting IAT patch
2019-08-14 01:17:20,549 [root] DEBUG: InjectDll: IAT patching failed, falling back to thread injection.
2019-08-14 01:17:20,549 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:17:20,549 [root] DEBUG: Process dumps disabled.
2019-08-14 01:17:20,549 [root] INFO: Disabling sleep skipping.
2019-08-14 01:17:20,565 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:17:20,565 [root] WARNING: Unable to hook LockResource
2019-08-14 01:17:20,565 [root] DEBUG: Debugger initialised.
2019-08-14 01:17:20,565 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 2656 at 0x000000006FA20000, image base 0x00000000FFA10000, stack from 0x00000000015E6000-0x00000000015F0000
2019-08-14 01:17:20,565 [root] DEBUG: Commandline: C:\Windows\sysnative\svchost.exe -k netsvcs.
2019-08-14 01:17:20,565 [root] DEBUG: AddTrackedRegion: EntryPoint 0x246c, Entropy 3.657311e+00
2019-08-14 01:17:20,565 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFA10000 size 0x1000 added to tracked regions.
2019-08-14 01:17:20,565 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:17:20,582 [root] INFO: Added new process to list with pid: 2656
2019-08-14 01:17:20,582 [root] INFO: Monitor successfully loaded in process with pid 2656.
2019-08-14 01:17:20,582 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2019-08-14 01:17:20,582 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2019-08-14 01:17:20,582 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:22,609 [root] DEBUG: DLL loaded at 0x74930000: C:\Windows\system32\wbem\wbemprox (0xa000 bytes).
2019-08-14 01:17:22,625 [root] DEBUG: DLL loaded at 0x72DD0000: C:\Windows\system32\wbem\wmiutils (0x17000 bytes).
2019-08-14 01:17:22,671 [root] DEBUG: DLL loaded at 0x000007FEF9E80000: C:\Windows\system32\VSSAPI (0x1b0000 bytes).
2019-08-14 01:17:22,671 [root] DEBUG: DLL loaded at 0x000007FEFB270000: C:\Windows\system32\ATL (0x19000 bytes).
2019-08-14 01:17:22,671 [root] DEBUG: DLL loaded at 0x000007FEF9E60000: C:\Windows\system32\VssTrace (0x17000 bytes).
2019-08-14 01:17:22,687 [root] DEBUG: DLL loaded at 0x000007FEFA870000: C:\Windows\system32\samcli (0x14000 bytes).
2019-08-14 01:17:22,687 [root] DEBUG: DLL loaded at 0x000007FEFB820000: C:\Windows\system32\SAMLIB (0x1d000 bytes).
2019-08-14 01:17:22,703 [root] DEBUG: DLL loaded at 0x000007FEFAC20000: C:\Windows\system32\netutils (0xc000 bytes).
2019-08-14 01:17:22,719 [root] DEBUG: DLL loaded at 0x000007FEFB0D0000: C:\Windows\system32\es (0x67000 bytes).
2019-08-14 01:17:22,733 [root] DEBUG: DLL loaded at 0x000007FEFB840000: C:\Windows\system32\PROPSYS (0x12c000 bytes).
2019-08-14 01:17:22,766 [root] DEBUG: DLL loaded at 0x000007FEF9540000: C:\Windows\system32\wbem\wbemcore (0x12f000 bytes).
2019-08-14 01:17:22,766 [root] DEBUG: DLL loaded at 0x000007FEF94D0000: C:\Windows\system32\wbem\esscli (0x6f000 bytes).
2019-08-14 01:17:22,780 [root] DEBUG: DLL loaded at 0x000007FEF9A00000: C:\Windows\system32\wbem\FastProx (0xe2000 bytes).
2019-08-14 01:17:22,780 [root] DEBUG: DLL loaded at 0x000007FEF9980000: C:\Windows\system32\NTDSAPI (0x27000 bytes).
2019-08-14 01:17:22,796 [root] DEBUG: DLL unloaded from 0x000007FEF9540000.
2019-08-14 01:17:22,796 [root] DEBUG: DLL loaded at 0x000007FEFA0A0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2019-08-14 01:17:22,828 [root] DEBUG: DLL loaded at 0x747D0000: C:\Windows\system32\wbem\wbemsvc (0xf000 bytes).
2019-08-14 01:17:22,844 [root] DEBUG: DLL loaded at 0x72D30000: C:\Windows\system32\wbem\fastprox (0x96000 bytes).
2019-08-14 01:17:22,858 [root] DEBUG: DLL loaded at 0x72D10000: C:\Windows\system32\NTDSAPI (0x18000 bytes).
2019-08-14 01:17:22,890 [root] DEBUG: DLL loaded at 0x000007FEFCAC0000: C:\Windows\system32\authZ (0x2f000 bytes).
2019-08-14 01:17:22,890 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2640.
2019-08-14 01:17:22,890 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:22,905 [root] DEBUG: DLL loaded at 0x000007FEF97C0000: C:\Windows\system32\wbem\wmiutils (0x26000 bytes).
2019-08-14 01:17:22,921 [root] DEBUG: DLL loaded at 0x000007FEF90B0000: C:\Windows\system32\wbem\repdrvfs (0x73000 bytes).
2019-08-14 01:17:22,937 [root] WARNING: File at path "C:\Windows\sysnative\wbem\repository\WRITABLE.TST" does not exist, skip.
2019-08-14 01:17:22,937 [root] DEBUG: DLL loaded at 0x000007FEFCB00000: C:\Windows\system32\Wevtapi (0x6d000 bytes).
2019-08-14 01:17:22,967 [root] DEBUG: DLL unloaded from 0x000007FEFCB00000.
2019-08-14 01:17:23,513 [root] DEBUG: DLL loaded at 0x000007FEF80F0000: C:\Windows\system32\wbem\wmiprvsd (0xbc000 bytes).
2019-08-14 01:17:23,529 [root] DEBUG: DLL loaded at 0x000007FEFA0C0000: C:\Windows\system32\NCObjAPI (0x16000 bytes).
2019-08-14 01:17:23,561 [root] DEBUG: DLL loaded at 0x000007FEF2E80000: C:\Windows\system32\wbem\wbemess (0x7e000 bytes).
2019-08-14 01:17:23,576 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2108.
2019-08-14 01:17:23,576 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:23,638 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3032.
2019-08-14 01:17:23,654 [root] DEBUG: DLL unloaded from 0x0000000076FF0000.
2019-08-14 01:17:23,654 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1092.
2019-08-14 01:17:23,654 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:23,686 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3008.
2019-08-14 01:17:23,701 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2820.
2019-08-14 01:17:23,747 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1236.
2019-08-14 01:17:23,747 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2308.
2019-08-14 01:17:23,747 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2352.
2019-08-14 01:17:23,747 [root] DEBUG: DLL loaded at 0x72CB0000: C:\Windows\system32\SXS (0x5f000 bytes).
2019-08-14 01:17:23,747 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2344.
2019-08-14 01:17:23,858 [root] DEBUG: DLL loaded at 0x72C70000: C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\509f36ec564b9ad2bb2ffda3d4a3b5fc\CustomMarshalers.ni (0x33000 bytes).
2019-08-14 01:17:23,858 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2808.
2019-08-14 01:17:23,858 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1796.
2019-08-14 01:17:23,858 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1332.
2019-08-14 01:17:23,872 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1756.
2019-08-14 01:17:23,888 [root] DEBUG: DLL loaded at 0x72C50000: C:\Windows\Microsoft.Net\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers (0x17000 bytes).
2019-08-14 01:17:23,888 [root] DEBUG: Allocation: 0x005B0000 - 0x005B1000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:23,920 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 14.
2019-08-14 01:17:23,936 [root] DEBUG: AddTrackedRegion: Region at 0x005B0000 size 0x1000 added to tracked regions.
2019-08-14 01:17:23,936 [root] DEBUG: Allocation: 0x005B1000 - 0x005B2000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:23,936 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 15.
2019-08-14 01:17:23,950 [root] DEBUG: AddTrackedRegion: Region at 0x005B0000 size 0x2000 added to tracked regions.
2019-08-14 01:17:23,982 [root] DEBUG: Allocation: 0x0020A000 - 0x0020B000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:23,997 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00200000, size: 0xd000.
2019-08-14 01:17:24,013 [root] DEBUG: Allocation: 0x0020B000 - 0x0020C000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:24,013 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x00200000, size: 0xd000.
2019-08-14 01:17:24,075 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 844
2019-08-14 01:17:24,092 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:24,092 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:17:24,107 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:24,107 [root] DEBUG: Loader: Injecting process 844 (thread 1864) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:24,107 [root] DEBUG: Process image base: 0x00000000FFD80000
2019-08-14 01:17:24,122 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:24,122 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00000000FFDDF000 - 0x000007FEFF430000
2019-08-14 01:17:24,138 [root] DEBUG: InjectDllViaIAT: Allocated 0x238 bytes for new import table at 0x00000000FFDE0000.
2019-08-14 01:17:24,138 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-14 01:17:24,138 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:24,138 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 844
2019-08-14 01:17:24,154 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:17:24,154 [root] DEBUG: DLL loaded at 0x000007FEFA1E0000: C:\Windows\system32\wbem\ncprov (0x16000 bytes).
2019-08-14 01:17:24,154 [root] DEBUG: Process dumps disabled.
2019-08-14 01:17:24,170 [root] INFO: Disabling sleep skipping.
2019-08-14 01:17:24,200 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:17:24,216 [root] WARNING: Unable to hook LockResource
2019-08-14 01:17:24,216 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-14 01:17:24,216 [root] DEBUG: Debugger initialised.
2019-08-14 01:17:24,216 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 844 at 0x000000006FA20000, image base 0x00000000FFD80000, stack from 0x0000000000240000-0x0000000000250000
2019-08-14 01:17:24,216 [root] DEBUG: Commandline: C:\Windows\sysnative\wbem\wmiprvse.exe -secured -Embedding.
2019-08-14 01:17:24,263 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3068.
2019-08-14 01:17:24,263 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3028.
2019-08-14 01:17:24,263 [root] DEBUG: AddTrackedRegion: EntryPoint 0xa9b4, Entropy 5.870330e+00
2019-08-14 01:17:24,279 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1936.
2019-08-14 01:17:24,279 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFD80000 size 0x1000 added to tracked regions.
2019-08-14 01:17:24,279 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:17:24,279 [root] INFO: Added new process to list with pid: 844
2019-08-14 01:17:24,279 [root] INFO: Monitor successfully loaded in process with pid 844.
2019-08-14 01:17:24,293 [root] DEBUG: DLL loaded at 0x000007FEFCF50000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2019-08-14 01:17:24,293 [root] DEBUG: DLL loaded at 0x000007FEFC190000: C:\Windows\system32\ntmarta (0x2d000 bytes).
2019-08-14 01:17:24,293 [root] DEBUG: DLL loaded at 0x000007FEFE860000: C:\Windows\system32\WLDAP32 (0x52000 bytes).
2019-08-14 01:17:24,325 [root] DEBUG: DLL loaded at 0x000007FEFE400000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2019-08-14 01:17:24,325 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2688.
2019-08-14 01:17:24,325 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:24,341 [root] DEBUG: DLL loaded at 0x000007FEF9D50000: C:\Windows\system32\wbem\wbemprox (0xf000 bytes).
2019-08-14 01:17:24,357 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1360.
2019-08-14 01:17:24,357 [root] DEBUG: DLL loaded at 0x000007FEFC8F0000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2019-08-14 01:17:24,371 [root] DEBUG: DLL loaded at 0x000007FEFC5F0000: C:\Windows\system32\rsaenh (0x47000 bytes).
2019-08-14 01:17:24,371 [root] DEBUG: DLL loaded at 0x000007FEFD000000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2019-08-14 01:17:24,388 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2812.
2019-08-14 01:17:24,466 [root] DEBUG: DLL loaded at 0x000007FEFA0A0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2019-08-14 01:17:24,482 [root] DEBUG: DLL loaded at 0x000007FEF97C0000: C:\Windows\system32\wbem\wmiutils (0x26000 bytes).
2019-08-14 01:17:24,621 [root] DEBUG: DLL loaded at 0x000007FEF2C80000: C:\Windows\system32\wbem\cimwin32 (0x1fa000 bytes).
2019-08-14 01:17:24,621 [root] DEBUG: DLL loaded at 0x000007FEF4570000: C:\Windows\system32\framedynos (0x4c000 bytes).
2019-08-14 01:17:24,621 [root] DEBUG: DLL loaded at 0x000007FEFAFA0000: C:\Windows\system32\WTSAPI32 (0x11000 bytes).
2019-08-14 01:17:24,917 [root] DEBUG: DLL loaded at 0x0000000073AA0000: C:\Windows\system32\WMI (0x3000 bytes).
2019-08-14 01:17:24,917 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1784.
2019-08-14 01:17:25,292 [root] DEBUG: DLL loaded at 0x72B20000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\13f5eb7285c90c219d2be24eebb55cd9\System.Management.ni (0x123000 bytes).
2019-08-14 01:17:25,371 [root] DEBUG: CreateThread: Initialising breakpoints for thread 948.
2019-08-14 01:17:25,401 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CA1000 already exists for thread 948 (process 2968), skipping.
2019-08-14 01:17:25,433 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 948 (process 2968), skipping.
2019-08-14 01:17:25,480 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CA1000 already exists for thread 948 (process 2968), skipping.
2019-08-14 01:17:25,635 [root] DEBUG: Allocation: 0x7EF30000 - 0x7EF80000, size: 0x50000, protection: 0x40.
2019-08-14 01:17:25,683 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 16.
2019-08-14 01:17:25,744 [root] DEBUG: AddTrackedRegion: Region at 0x7EF30000 size 0x50000 added to tracked regions.
2019-08-14 01:17:25,792 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x7EF30000.
2019-08-14 01:17:25,838 [root] DEBUG: Allocation: 0x7EF30000 - 0x7EF31000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:25,869 [root] DEBUG: AllocationHandler: Previously reserved region 0x7EF30000 - 0x7EF80000, committing at: 0x7EF30000.
2019-08-14 01:17:25,901 [root] DEBUG: Allocation: 0x7EF30000 - 0x7EF31000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:25,917 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x7EF30000, size: 0x50000.
2019-08-14 01:17:26,009 [root] DEBUG: Allocation: 0x7EF38000 - 0x7EF39000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:26,056 [root] DEBUG: AllocationHandler: New allocation already in tracked region list: 0x7EF30000, size: 0x50000.
2019-08-14 01:17:26,119 [root] DEBUG: Allocation: 0x7EF20000 - 0x7EF30000, size: 0x10000, protection: 0x40.
2019-08-14 01:17:26,134 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 17.
2019-08-14 01:17:26,165 [root] DEBUG: AddTrackedRegion: Region at 0x7EF20000 size 0x10000 added to tracked regions.
2019-08-14 01:17:26,229 [root] DEBUG: AllocationHandler: Memory reserved but not committed at 0x7EF20000.
2019-08-14 01:17:26,290 [root] DEBUG: Allocation: 0x7EF20000 - 0x7EF21000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:26,338 [root] DEBUG: AllocationHandler: Previously reserved region 0x7EF20000 - 0x7EF30000, committing at: 0x7EF20000.
2019-08-14 01:17:26,384 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1856.
2019-08-14 01:17:26,400 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CA1000 already exists for thread 1856 (process 2968), skipping.
2019-08-14 01:17:26,447 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 1856 (process 2968), skipping.
2019-08-14 01:17:26,463 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CA1000 already exists for thread 1856 (process 2968), skipping.
2019-08-14 01:17:26,602 [root] DEBUG: DLL loaded at 0x72B10000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils (0xa000 bytes).
2019-08-14 01:17:26,665 [root] DEBUG: Allocation: 0x03CB5000 - 0x03CB6000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:26,711 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 18.
2019-08-14 01:17:26,727 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x16000 added to tracked regions.
2019-08-14 01:17:26,775 [root] DEBUG: Allocation: 0x03CB6000 - 0x03CB7000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:26,789 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 19.
2019-08-14 01:17:26,836 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x17000 added to tracked regions.
2019-08-14 01:17:26,884 [root] DEBUG: Allocation: 0x03CB7000 - 0x03CB8000, size: 0x1000, protection: 0x40.
2019-08-14 01:17:26,900 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 20.
2019-08-14 01:17:26,914 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x18000 added to tracked regions.
2019-08-14 01:17:26,993 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2768.
2019-08-14 01:17:27,101 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CA1000 already exists for thread 2768 (process 2968), skipping.
2019-08-14 01:17:27,118 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2768 (process 2968), skipping.
2019-08-14 01:17:27,164 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CA1000 already exists for thread 2768 (process 2968), skipping.
2019-08-14 01:17:27,446 [root] DEBUG: DLL unloaded from 0x000007FEF9540000.
2019-08-14 01:17:27,632 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1896.
2019-08-14 01:17:27,648 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CA1000 already exists for thread 1896 (process 2968), skipping.
2019-08-14 01:17:27,710 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 1896 (process 2968), skipping.
2019-08-14 01:17:27,742 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CA1000 already exists for thread 1896 (process 2968), skipping.
2019-08-14 01:17:32,000 [root] DEBUG: DLL unloaded from 0x000007FEFE320000.
2019-08-14 01:17:35,869 [root] DEBUG: DLL loaded at 0x000007FEFA1D0000: C:\Windows\System32\perfos (0xb000 bytes).
2019-08-14 01:17:35,869 [root] DEBUG: DLL unloaded from 0x0000000073AA0000.
2019-08-14 01:17:37,023 [root] DEBUG: DLL unloaded from 0x000007FEFE320000.
2019-08-14 01:17:37,865 [root] DEBUG: DLL unloaded from 0x751B0000.
2019-08-14 01:17:42,203 [root] DEBUG: set_caller_info: Adding region at 0x00200000 to caller regions list.
2019-08-14 01:17:42,233 [root] DEBUG: Allocation: 0x03CB8000 - 0x03CBA000, size: 0x2000, protection: 0x40.
2019-08-14 01:17:42,233 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 21.
2019-08-14 01:17:42,250 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x1a000 added to tracked regions.
2019-08-14 01:17:42,250 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x03CA0000, TrackedRegion->RegionSize: 0x1a000, thread 2948
2019-08-14 01:17:42,250 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x03CA0000 to 0x03CA0000.
2019-08-14 01:17:42,250 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:17:42,250 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2768.
2019-08-14 01:17:42,250 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1896.
2019-08-14 01:17:42,250 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:17:42,250 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2768.
2019-08-14 01:17:42,250 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1896.
2019-08-14 01:17:42,250 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xd0, Size=0x0, Address=0x03CB8000 and Type=0x1.
2019-08-14 01:17:42,266 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2948 type 1 at address 0x03CB8000, size 0 with Callback 0x747e7620.
2019-08-14 01:17:42,266 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x03CB8000
2019-08-14 01:17:42,266 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xd0, Size=0x4, Address=0x03CA003C and Type=0x1.
2019-08-14 01:17:42,266 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2948 type 1 at address 0x03CA003C, size 4 with Callback 0x747e7280.
2019-08-14 01:17:42,266 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x03CA003C
2019-08-14 01:17:42,266 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x03CB8000 (size 0x2000).
2019-08-14 01:17:42,280 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-14 01:17:42,280 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744E5A82 (thread 2948)
2019-08-14 01:17:42,280 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CB8000.
2019-08-14 01:17:42,280 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x03CB8000 and Type=0x0.
2019-08-14 01:17:42,280 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3cb8000: 0x0.
2019-08-14 01:17:42,280 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:17:42,280 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744C848D (thread 2948)
2019-08-14 01:17:42,280 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CB8000.
2019-08-14 01:17:42,296 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2948 (process 2968), skipping.
2019-08-14 01:17:42,296 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3cb8000: 0x0.
2019-08-14 01:17:42,296 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:17:42,296 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744D48A0 (thread 2948)
2019-08-14 01:17:42,296 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CB8000.
2019-08-14 01:17:42,296 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2948 (process 2968), skipping.
2019-08-14 01:17:42,296 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3cb8000: 0x0.
2019-08-14 01:17:42,296 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:17:47,726 [root] DEBUG: set_caller_info: Adding region at 0x000007FEF4500000 to caller regions list.
2019-08-14 01:17:57,615 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2204.
2019-08-14 01:17:57,677 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 2204 (process 2968), skipping.
2019-08-14 01:17:57,740 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2204 (process 2968), skipping.
2019-08-14 01:17:57,802 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2204 (process 2968), skipping.
2019-08-14 01:17:59,549 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2668.
2019-08-14 01:17:59,565 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:59,582 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2292.
2019-08-14 01:17:59,706 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 3040
2019-08-14 01:17:59,706 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:17:59,706 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:17:59,721 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:17:59,737 [root] DEBUG: Loader: Injecting process 3040 (thread 3024) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:59,737 [root] DEBUG: Process image base: 0x00000000FFD80000
2019-08-14 01:17:59,737 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:59,737 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00000000FFDDF000 - 0x000007FEFF430000
2019-08-14 01:17:59,753 [root] DEBUG: InjectDllViaIAT: Allocated 0x238 bytes for new import table at 0x00000000FFDE0000.
2019-08-14 01:17:59,753 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-14 01:17:59,753 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:17:59,753 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 3040
2019-08-14 01:17:59,753 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:17:59,753 [root] DEBUG: Process dumps disabled.
2019-08-14 01:17:59,769 [root] INFO: Disabling sleep skipping.
2019-08-14 01:17:59,769 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:17:59,783 [root] WARNING: Unable to hook LockResource
2019-08-14 01:17:59,783 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-14 01:17:59,783 [root] DEBUG: Debugger initialised.
2019-08-14 01:17:59,799 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 3040 at 0x000000006FA20000, image base 0x00000000FFD80000, stack from 0x0000000000260000-0x0000000000270000
2019-08-14 01:17:59,799 [root] DEBUG: Commandline: C:\Windows\sysnative\wbem\wmiprvse.exe -Embedding.
2019-08-14 01:17:59,799 [root] DEBUG: AddTrackedRegion: EntryPoint 0xa9b4, Entropy 5.870330e+00
2019-08-14 01:17:59,815 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFD80000 size 0x1000 added to tracked regions.
2019-08-14 01:17:59,815 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:17:59,815 [root] INFO: Added new process to list with pid: 3040
2019-08-14 01:17:59,831 [root] INFO: Monitor successfully loaded in process with pid 3040.
2019-08-14 01:17:59,831 [root] DEBUG: DLL loaded at 0x000007FEFCF50000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2019-08-14 01:17:59,846 [root] DEBUG: DLL loaded at 0x000007FEFC190000: C:\Windows\system32\ntmarta (0x2d000 bytes).
2019-08-14 01:17:59,846 [root] DEBUG: DLL loaded at 0x000007FEFE860000: C:\Windows\system32\WLDAP32 (0x52000 bytes).
2019-08-14 01:17:59,940 [root] DEBUG: DLL loaded at 0x000007FEFE400000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2019-08-14 01:17:59,940 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2120.
2019-08-14 01:17:59,940 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:17:59,940 [root] DEBUG: DLL loaded at 0x000007FEF9D50000: C:\Windows\system32\wbem\wbemprox (0xf000 bytes).
2019-08-14 01:17:59,956 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2772.
2019-08-14 01:17:59,956 [root] DEBUG: DLL loaded at 0x000007FEFC8F0000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2019-08-14 01:17:59,971 [root] DEBUG: DLL loaded at 0x000007FEFC5F0000: C:\Windows\system32\rsaenh (0x47000 bytes).
2019-08-14 01:17:59,986 [root] DEBUG: DLL loaded at 0x000007FEFD000000: C:\Windows\system32\RpcRtRemote (0x14000 bytes).
2019-08-14 01:18:00,003 [root] DEBUG: CreateThread: Initialising breakpoints for thread 624.
2019-08-14 01:18:00,017 [root] DEBUG: DLL loaded at 0x000007FEFA0A0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2019-08-14 01:18:00,033 [root] DEBUG: DLL loaded at 0x000007FEF97C0000: C:\Windows\system32\wbem\wmiutils (0x26000 bytes).
2019-08-14 01:18:00,517 [root] DEBUG: DLL loaded at 0x000007FEF9BA0000: C:\Windows\system32\wbem\wmiprov (0x3c000 bytes).
2019-08-14 01:18:02,842 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2564.
2019-08-14 01:18:02,858 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 2564 (process 2968), skipping.
2019-08-14 01:18:02,858 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2564 (process 2968), skipping.
2019-08-14 01:18:02,858 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2564 (process 2968), skipping.
2019-08-14 01:18:02,872 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2876.
2019-08-14 01:18:02,872 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 2876 (process 2968), skipping.
2019-08-14 01:18:02,872 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2876 (process 2968), skipping.
2019-08-14 01:18:02,872 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2876 (process 2968), skipping.
2019-08-14 01:18:02,888 [root] DEBUG: DLL unloaded from 0x751B0000.
2019-08-14 01:18:02,967 [root] DEBUG: DLL loaded at 0x72A20000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\1f56d5786274992934de0c900431c447\System.Configuration.ni (0xf0000 bytes).
2019-08-14 01:18:02,982 [root] DEBUG: DLL loaded at 0x6FF30000: C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d91f3556f8011a5d48e1448e3fa8df9e\System.Xml.ni (0x751000 bytes).
2019-08-14 01:18:03,029 [root] DEBUG: Allocation: 0x0021B000 - 0x0021C000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:03,029 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 22.
2019-08-14 01:18:03,045 [root] DEBUG: AddTrackedRegion: Region at 0x00210000 size 0xc000 added to tracked regions.
2019-08-14 01:18:03,059 [root] DEBUG: DLL loaded at 0x729C0000: C:\Windows\system32\rasapi32 (0x52000 bytes).
2019-08-14 01:18:03,075 [root] DEBUG: DLL loaded at 0x6FF10000: C:\Windows\system32\rasman (0x15000 bytes).
2019-08-14 01:18:03,107 [root] DEBUG: DLL loaded at 0x73AA0000: C:\Windows\system32\rtutils (0xd000 bytes).
2019-08-14 01:18:03,122 [root] DEBUG: DLL loaded at 0x74BF0000: C:\Windows\system32\mswsock (0x3c000 bytes).
2019-08-14 01:18:03,122 [root] DEBUG: DLL loaded at 0x74BE0000: C:\Windows\System32\wshtcpip (0x5000 bytes).
2019-08-14 01:18:03,138 [root] DEBUG: DLL loaded at 0x6FF00000: C:\Windows\System32\wship6 (0x6000 bytes).
2019-08-14 01:18:03,184 [root] DEBUG: DLL loaded at 0x6FEA0000: C:\Windows\system32\winhttp (0x58000 bytes).
2019-08-14 01:18:03,200 [root] DEBUG: DLL loaded at 0x6FE50000: C:\Windows\system32\webio (0x4f000 bytes).
2019-08-14 01:18:03,232 [root] DEBUG: DLL unloaded from 0x6FF10000.
2019-08-14 01:18:03,232 [root] DEBUG: DLL unloaded from 0x75D60000.
2019-08-14 01:18:03,247 [root] DEBUG: DLL loaded at 0x6FE40000: C:\Windows\system32\credssp (0x8000 bytes).
2019-08-14 01:18:03,247 [root] DEBUG: DLL unloaded from 0x74C70000.
2019-08-14 01:18:03,263 [root] DEBUG: DLL loaded at 0x6FE20000: C:\Windows\system32\IPHLPAPI (0x1c000 bytes).
2019-08-14 01:18:03,263 [root] DEBUG: DLL loaded at 0x6FE10000: C:\Windows\system32\WINNSI (0x7000 bytes).
2019-08-14 01:18:03,293 [root] DEBUG: DLL loaded at 0x6FE00000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes).
2019-08-14 01:18:03,325 [root] DEBUG: DLL loaded at 0x6FDE0000: C:\Windows\system32\dhcpcsvc (0x12000 bytes).
2019-08-14 01:18:03,341 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-14 01:18:03,341 [root] DEBUG: DLL loaded at 0x75A10000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2019-08-14 01:18:03,357 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1472.
2019-08-14 01:18:03,357 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 1472 (process 2968), skipping.
2019-08-14 01:18:03,357 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 1472 (process 2968), skipping.
2019-08-14 01:18:03,371 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 1472 (process 2968), skipping.
2019-08-14 01:18:03,388 [root] DEBUG: DLL unloaded from 0x6FEA0000.
2019-08-14 01:18:03,404 [root] DEBUG: DLL loaded at 0x74B50000: C:\Windows\system32\DNSAPI (0x44000 bytes).
2019-08-14 01:18:03,418 [root] DEBUG: DLL loaded at 0x74BD0000: C:\Windows\system32\NLAapi (0x10000 bytes).
2019-08-14 01:18:03,418 [root] DEBUG: DLL loaded at 0x74BC0000: C:\Windows\system32\napinsp (0x10000 bytes).
2019-08-14 01:18:03,418 [root] DEBUG: DLL loaded at 0x74BA0000: C:\Windows\system32\pnrpnsp (0x12000 bytes).
2019-08-14 01:18:03,418 [root] DEBUG: DLL loaded at 0x74B40000: C:\Windows\System32\winrnr (0x8000 bytes).
2019-08-14 01:18:03,434 [root] DEBUG: DLL loaded at 0x6FDD0000: C:\Windows\system32\rasadhlp (0x6000 bytes).
2019-08-14 01:18:03,450 [root] DEBUG: DLL loaded at 0x6FD90000: C:\Windows\System32\fwpuclnt (0x38000 bytes).
2019-08-14 01:18:03,887 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2180.
2019-08-14 01:18:05,930 [root] DEBUG: DLL unloaded from 0x000007FEFE8C0000.
2019-08-14 01:18:06,507 [root] DEBUG: Allocation: 0x001FC000 - 0x001FD000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:06,507 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 23.
2019-08-14 01:18:06,523 [root] DEBUG: AddTrackedRegion: Region at 0x001F0000 size 0xd000 added to tracked regions.
2019-08-14 01:18:06,523 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2788.
2019-08-14 01:18:06,523 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-14 01:18:06,539 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 2788 (process 2968), skipping.
2019-08-14 01:18:06,539 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2788 (process 2968), skipping.
2019-08-14 01:18:06,539 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2788 (process 2968), skipping.
2019-08-14 01:18:06,555 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2116.
2019-08-14 01:18:06,555 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 2116 (process 2968), skipping.
2019-08-14 01:18:06,555 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2116 (process 2968), skipping.
2019-08-14 01:18:06,569 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2116 (process 2968), skipping.
2019-08-14 01:18:07,895 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2584.
2019-08-14 01:18:07,911 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 2584 (process 2968), skipping.
2019-08-14 01:18:07,911 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2584 (process 2968), skipping.
2019-08-14 01:18:07,911 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 2584 (process 2968), skipping.
2019-08-14 01:18:07,927 [root] DEBUG: CreateThread: Initialising breakpoints for thread 252.
2019-08-14 01:18:07,927 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CB8000 already exists for thread 252 (process 2968), skipping.
2019-08-14 01:18:07,927 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 252 (process 2968), skipping.
2019-08-14 01:18:07,943 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CB8000 already exists for thread 252 (process 2968), skipping.
2019-08-14 01:18:07,959 [root] DEBUG: DLL loaded at 0x74AF0000: C:\Windows\system32\apphelp (0x4c000 bytes).
2019-08-14 01:18:07,973 [root] INFO: Announced 32-bit process name: reg.exe pid: 3004
2019-08-14 01:18:07,990 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:18:07,990 [lib.api.process] INFO: 32-bit DLL to inject is C:\nkmznsmshd\dll\UPldJWKY.dll, loader C:\nkmznsmshd\bin\TBNHVPB.exe
2019-08-14 01:18:08,020 [root] DEBUG: Allocation: 0x03CBA000 - 0x03CBC000, size: 0x2000, protection: 0x40.
2019-08-14 01:18:08,020 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:18:08,036 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 24.
2019-08-14 01:18:08,036 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x1c000 added to tracked regions.
2019-08-14 01:18:08,036 [root] DEBUG: Loader: Injecting process 3004 (thread 2524) with C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:18:08,036 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x03CA0000, TrackedRegion->RegionSize: 0x1c000, thread 2948
2019-08-14 01:18:08,036 [root] DEBUG: Process image base: 0x00700000
2019-08-14 01:18:08,036 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x03CA0000 to 0x03CA0000.
2019-08-14 01:18:08,052 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:18:08,052 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1672.
2019-08-14 01:18:08,052 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00752000 - 0x77110000
2019-08-14 01:18:08,052 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:18:08,068 [root] DEBUG: InjectDllViaIAT: Allocated 0x1dc bytes for new import table at 0x00760000.
2019-08-14 01:18:08,068 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2768.
2019-08-14 01:18:08,068 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-14 01:18:08,084 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1896.
2019-08-14 01:18:08,084 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\UPldJWKY.dll.
2019-08-14 01:18:08,084 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2876.
2019-08-14 01:18:08,084 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 3004
2019-08-14 01:18:08,084 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 252.
2019-08-14 01:18:08,130 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1672.
2019-08-14 01:18:08,130 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:18:08,130 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2768.
2019-08-14 01:18:08,130 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1896.
2019-08-14 01:18:08,161 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2876.
2019-08-14 01:18:08,161 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:18:08,177 [root] DEBUG: Process dumps disabled.
2019-08-14 01:18:08,177 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 252.
2019-08-14 01:18:08,177 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xd0, Size=0x0, Address=0x03CBA000 and Type=0x1.
2019-08-14 01:18:08,177 [root] INFO: Disabling sleep skipping.
2019-08-14 01:18:08,193 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2948 type 1 at address 0x03CBA000, size 0 with Callback 0x747e7620.
2019-08-14 01:18:08,193 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-14 01:18:08,193 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x03CBA000
2019-08-14 01:18:08,207 [root] DEBUG: WoW64 detected: 64-bit ntdll base: 0x77110000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7716124a, Wow64PrepareForException: 0x0
2019-08-14 01:18:08,207 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xd0, Size=0x4, Address=0x03CA003C and Type=0x1.
2019-08-14 01:18:08,207 [root] DEBUG: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x140000
2019-08-14 01:18:08,223 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2948 type 1 at address 0x03CA003C, size 4 with Callback 0x747e7280.
2019-08-14 01:18:08,223 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x03CA003C
2019-08-14 01:18:08,223 [root] DEBUG: Debugger initialised.
2019-08-14 01:18:08,223 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x03CBA000 (size 0x2000).
2019-08-14 01:18:08,223 [root] DEBUG: CAPE initialised: 32-bit Extraction v2 loaded in process 3004 at 0x747e0000, image base 0x700000, stack from 0x2e6000-0x2f0000
2019-08-14 01:18:08,240 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744F1AA3 (thread 2948)
2019-08-14 01:18:08,240 [root] DEBUG: Commandline: C:\Users\user\AppData\Local\Temp\REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System \v DisableTaskMgr \t REG_DWORD \d 1 \f.
2019-08-14 01:18:08,240 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CBA000.
2019-08-14 01:18:08,240 [root] DEBUG: AddTrackedRegion: EntryPoint 0x1bca, Entropy 1.662841e+00
2019-08-14 01:18:08,240 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x03CBA000 and Type=0x0.
2019-08-14 01:18:08,240 [root] DEBUG: AddTrackedRegion: Region at 0x00700000 size 0x1000 added to tracked regions.
2019-08-14 01:18:08,240 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3cba000: 0xff.
2019-08-14 01:18:08,255 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:18:08,255 [root] INFO: Added new process to list with pid: 3004
2019-08-14 01:18:08,255 [root] INFO: Monitor successfully loaded in process with pid 3004.
2019-08-14 01:18:08,255 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:18:08,255 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 3004).
2019-08-14 01:18:08,270 [root] DEBUG: DLL unloaded from 0x75140000.
2019-08-14 01:18:08,270 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744F1AA0 (thread 2948)
2019-08-14 01:18:08,286 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 3004).
2019-08-14 01:18:08,286 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x03CBA000.
2019-08-14 01:18:08,286 [root] INFO: Notified of termination of process with pid 3004.
2019-08-14 01:18:08,286 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2948 (process 2968), skipping.
2019-08-14 01:18:08,302 [root] DEBUG: BaseAddressWriteCallback: byte written to 0x3cba000: 0xff.
2019-08-14 01:18:08,302 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:18:08,411 [root] INFO: Process with pid 3004 has terminated
2019-08-14 01:18:08,441 [root] DEBUG: Allocation: 0x03CBC000 - 0x03CBD000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:08,457 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 25.
2019-08-14 01:18:08,457 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x1d000 added to tracked regions.
2019-08-14 01:18:08,489 [root] DEBUG: Allocation: 0x03CBD000 - 0x03CBE000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:08,489 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 26.
2019-08-14 01:18:08,489 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x1e000 added to tracked regions.
2019-08-14 01:18:08,505 [root] DEBUG: Allocation: 0x03CBE000 - 0x03CBF000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:08,519 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 27.
2019-08-14 01:18:08,519 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x1f000 added to tracked regions.
2019-08-14 01:18:08,536 [root] DEBUG: Allocation: 0x03CBF000 - 0x03CC0000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:08,552 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 28.
2019-08-14 01:18:08,566 [root] DEBUG: AddTrackedRegion: Region at 0x03CA0000 size 0x20000 added to tracked regions.
2019-08-14 01:18:08,566 [root] DEBUG: Allocation: 0x0020D000 - 0x0020E000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:08,582 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 29.
2019-08-14 01:18:08,582 [root] DEBUG: AddTrackedRegion: Region at 0x00200000 size 0xe000 added to tracked regions.
2019-08-14 01:18:08,582 [root] DEBUG: DLL loaded at 0x6EFA0000: C:\Windows\SysWOW64\ieframe (0xa80000 bytes).
2019-08-14 01:18:08,598 [root] DEBUG: DLL loaded at 0x6FD50000: C:\Windows\SysWOW64\OLEACC (0x3c000 bytes).
2019-08-14 01:18:08,598 [root] DEBUG: DLL loaded at 0x76CA0000: C:\Windows\syswow64\iertutil (0x1fb000 bytes).
2019-08-14 01:18:08,598 [root] DEBUG: DLL loaded at 0x6FBB0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32 (0x19e000 bytes).
2019-08-14 01:18:08,661 [root] DEBUG: DLL loaded at 0x6FB80000: C:\Windows\system32\MLANG (0x2e000 bytes).
2019-08-14 01:18:08,661 [root] DEBUG: DLL loaded at 0x75600000: C:\Windows\syswow64\WININET (0xf5000 bytes).
2019-08-14 01:18:08,676 [root] DEBUG: DLL loaded at 0x74F40000: C:\Windows\syswow64\urlmon (0x136000 bytes).
2019-08-14 01:18:08,691 [root] DEBUG: DLL loaded at 0x75790000: C:\Windows\syswow64\CRYPT32 (0x11d000 bytes).
2019-08-14 01:18:08,691 [root] DEBUG: DLL loaded at 0x755F0000: C:\Windows\syswow64\MSASN1 (0xc000 bytes).
2019-08-14 01:18:08,723 [root] DEBUG: DLL loaded at 0x6FB70000: C:\Windows\system32\vaultcli (0xc000 bytes).
2019-08-14 01:18:08,739 [root] DEBUG: DLL unloaded from 0x75C10000.
2019-08-14 01:18:08,786 [root] INFO: Announced starting service "VaultSvc"
2019-08-14 01:18:08,801 [root] INFO: Attaching to Service Control Manager (services.exe - pid 460)
2019-08-14 01:18:08,801 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:18:08,801 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:18:08,816 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:18:08,816 [root] DEBUG: Loader: Injecting process 460 (thread 0) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:08,816 [root] DEBUG: InjectDll: No thread ID supplied. Initial thread ID 2256, handle 0x84
2019-08-14 01:18:08,816 [root] DEBUG: Process image base: 0x00000000FFA10000
2019-08-14 01:18:08,832 [root] DEBUG: InjectDllViaIAT: Not a new process, aborting IAT patch
2019-08-14 01:18:08,832 [root] DEBUG: InjectDll: IAT patching failed, falling back to thread injection.
2019-08-14 01:18:08,848 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:18:08,864 [root] DEBUG: Process dumps disabled.
2019-08-14 01:18:08,864 [root] INFO: Disabling sleep skipping.
2019-08-14 01:18:08,878 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:18:08,878 [root] WARNING: Unable to hook LockResource
2019-08-14 01:18:08,878 [root] DEBUG: Debugger initialised.
2019-08-14 01:18:08,894 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 460 at 0x000000006FA20000, image base 0x00000000FFA10000, stack from 0x0000000001376000-0x0000000001380000
2019-08-14 01:18:08,894 [root] DEBUG: Commandline: C:\Windows\sysnative\services.exe.
2019-08-14 01:18:08,926 [root] DEBUG: AddTrackedRegion: EntryPoint 0x13310, Entropy 6.073543e+00
2019-08-14 01:18:08,926 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFA10000 size 0x1000 added to tracked regions.
2019-08-14 01:18:08,941 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:18:08,957 [root] INFO: Added new process to list with pid: 460
2019-08-14 01:18:08,957 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1272.
2019-08-14 01:18:08,957 [root] INFO: Monitor successfully loaded in process with pid 460.
2019-08-14 01:18:08,957 [root] DEBUG: DLL unloaded from 0x772F0000.
2019-08-14 01:18:08,957 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2019-08-14 01:18:08,973 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 1272 (process 2968), skipping.
2019-08-14 01:18:08,973 [root] DEBUG: InjectDll: Successfully injected DLL via thread.
2019-08-14 01:18:08,973 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 1272 (process 2968), skipping.
2019-08-14 01:18:08,973 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:08,973 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 1272 (process 2968), skipping.
2019-08-14 01:18:09,503 [root] DEBUG: DLL unloaded from 0x000007FEF9540000.
2019-08-14 01:18:10,002 [root] INFO: Announced 64-bit process name: lsass.exe pid: 2828
2019-08-14 01:18:10,002 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:18:10,002 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:18:10,002 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:18:10,017 [root] DEBUG: Loader: Injecting process 2828 (thread 332) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:10,033 [root] DEBUG: Process image base: 0x00000000FF1A0000
2019-08-14 01:18:10,065 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:10,095 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00000000FF1AC000 - 0x000007FEFF430000
2019-08-14 01:18:10,111 [root] DEBUG: InjectDllViaIAT: Allocated 0x2a4 bytes for new import table at 0x00000000FF1B0000.
2019-08-14 01:18:10,190 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-14 01:18:10,190 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:10,190 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 2828
2019-08-14 01:18:10,267 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:18:10,267 [root] DEBUG: Process dumps disabled.
2019-08-14 01:18:10,282 [root] INFO: Disabling sleep skipping.
2019-08-14 01:18:10,282 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:18:10,313 [root] WARNING: Unable to hook LockResource
2019-08-14 01:18:10,329 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-14 01:18:10,329 [root] DEBUG: Debugger initialised.
2019-08-14 01:18:10,329 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 2828 at 0x000000006FA20000, image base 0x00000000FF1A0000, stack from 0x00000000001D4000-0x00000000001E0000
2019-08-14 01:18:10,329 [root] DEBUG: Commandline: C:\Windows\sysnative\lsass.exe.
2019-08-14 01:18:10,345 [root] DEBUG: AddTrackedRegion: EntryPoint 0x1850, Entropy 3.682657e+00
2019-08-14 01:18:10,345 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FF1A0000 size 0x1000 added to tracked regions.
2019-08-14 01:18:10,345 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:18:10,345 [root] INFO: Added new process to list with pid: 2828
2019-08-14 01:18:10,345 [root] INFO: Monitor successfully loaded in process with pid 2828.
2019-08-14 01:18:11,000 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2684.
2019-08-14 01:18:11,000 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2684 (process 2968), skipping.
2019-08-14 01:18:11,016 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2684 (process 2968), skipping.
2019-08-14 01:18:11,016 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2684 (process 2968), skipping.
2019-08-14 01:18:13,043 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2580.
2019-08-14 01:18:13,043 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2580 (process 2968), skipping.
2019-08-14 01:18:13,059 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2580 (process 2968), skipping.
2019-08-14 01:18:13,059 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2580 (process 2968), skipping.
2019-08-14 01:18:15,104 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1544.
2019-08-14 01:18:15,104 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 1544 (process 2968), skipping.
2019-08-14 01:18:15,104 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 1544 (process 2968), skipping.
2019-08-14 01:18:15,118 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 1544 (process 2968), skipping.
2019-08-14 01:18:17,147 [root] DEBUG: CreateThread: Initialising breakpoints for thread 716.
2019-08-14 01:18:17,147 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 716 (process 2968), skipping.
2019-08-14 01:18:17,163 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 716 (process 2968), skipping.
2019-08-14 01:18:17,163 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 716 (process 2968), skipping.
2019-08-14 01:18:18,848 [root] DEBUG: DLL unloaded from 0x000007FEFB0D0000.
2019-08-14 01:18:19,190 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2648.
2019-08-14 01:18:19,190 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2648 (process 2968), skipping.
2019-08-14 01:18:19,206 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2648 (process 2968), skipping.
2019-08-14 01:18:19,206 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2648 (process 2968), skipping.
2019-08-14 01:18:21,250 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2392.
2019-08-14 01:18:21,250 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2392 (process 2968), skipping.
2019-08-14 01:18:21,296 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2392 (process 2968), skipping.
2019-08-14 01:18:21,358 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2392 (process 2968), skipping.
2019-08-14 01:18:23,387 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2320.
2019-08-14 01:18:23,417 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2320 (process 2968), skipping.
2019-08-14 01:18:23,417 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2320 (process 2968), skipping.
2019-08-14 01:18:23,464 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2320 (process 2968), skipping.
2019-08-14 01:18:31,217 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2844.
2019-08-14 01:18:31,451 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2844 (process 2968), skipping.
2019-08-14 01:18:31,451 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2844 (process 2968), skipping.
2019-08-14 01:18:31,624 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2844 (process 2968), skipping.
2019-08-14 01:18:33,994 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2672.
2019-08-14 01:18:34,010 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2672 (process 2968), skipping.
2019-08-14 01:18:34,026 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2672 (process 2968), skipping.
2019-08-14 01:18:34,634 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2672 (process 2968), skipping.
2019-08-14 01:18:36,802 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2460.
2019-08-14 01:18:37,006 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2460 (process 2968), skipping.
2019-08-14 01:18:37,006 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2460 (process 2968), skipping.
2019-08-14 01:18:37,177 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2460 (process 2968), skipping.
2019-08-14 01:18:40,032 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2560.
2019-08-14 01:18:40,078 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2560 (process 2968), skipping.
2019-08-14 01:18:40,095 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2560 (process 2968), skipping.
2019-08-14 01:18:40,188 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2560 (process 2968), skipping.
2019-08-14 01:18:40,312 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 460).
2019-08-14 01:18:40,359 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1996.
2019-08-14 01:18:40,375 [root] INFO: Notified of termination of process with pid 2828.
2019-08-14 01:18:40,375 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 2828).
2019-08-14 01:18:40,500 [root] DEBUG: Allocation: 0x00E70000 - 0x00E71000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:40,609 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 30.
2019-08-14 01:18:40,609 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x1000 added to tracked regions.
2019-08-14 01:18:40,625 [root] DEBUG: set_caller_info: Adding region at 0x00E70000 to caller regions list.
2019-08-14 01:18:40,796 [root] DEBUG: Allocation: 0x00E71000 - 0x00E72000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:40,796 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 31.
2019-08-14 01:18:40,812 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x2000 added to tracked regions.
2019-08-14 01:18:40,875 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1928.
2019-08-14 01:18:40,875 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 1928 (process 2968), skipping.
2019-08-14 01:18:40,891 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 1928 (process 2968), skipping.
2019-08-14 01:18:40,891 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 1928 (process 2968), skipping.
2019-08-14 01:18:41,187 [root] INFO: Process with pid 2828 has terminated
2019-08-14 01:18:41,592 [root] INFO: Announced 64-bit process name: taskhost.exe pid: 2396
2019-08-14 01:18:41,638 [root] DEBUG: Allocation: 0x00E72000 - 0x00E73000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:41,686 [lib.api.process] INFO: Option 'procdump' with value '0' sent to monitor
2019-08-14 01:18:41,686 [lib.api.process] INFO: 64-bit DLL to inject is C:\nkmznsmshd\dll\mqjWcJC.dll, loader C:\nkmznsmshd\bin\NgZZvtiw.exe
2019-08-14 01:18:42,122 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 32.
2019-08-14 01:18:42,200 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x3000 added to tracked regions.
2019-08-14 01:18:42,247 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2884.
2019-08-14 01:18:42,263 [root] DEBUG: Allocation: 0x00E73000 - 0x00E75000, size: 0x2000, protection: 0x40.
2019-08-14 01:18:42,279 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x03CBA000 already exists for thread 2884 (process 2968), skipping.
2019-08-14 01:18:42,279 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 33.
2019-08-14 01:18:42,279 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x03CA003C already exists for thread 2884 (process 2968), skipping.
2019-08-14 01:18:42,295 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x03CBA000 already exists for thread 2884 (process 2968), skipping.
2019-08-14 01:18:42,341 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x5000 added to tracked regions.
2019-08-14 01:18:42,434 [root] DEBUG: ReadConfig: Successfully loaded pipe name \\.\PIPE\QfJQsZQ.
2019-08-14 01:18:42,496 [root] DEBUG: ActivateBreakpoints: TrackedRegion->AllocationBase: 0x00E70000, TrackedRegion->RegionSize: 0x5000, thread 2948
2019-08-14 01:18:42,513 [root] DEBUG: Loader: Injecting process 2396 (thread 2208) with C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:42,513 [root] DEBUG: ActivateBreakpoints: Switching breakpoints from region 0x03CA0000 to 0x00E70000.
2019-08-14 01:18:42,513 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1672.
2019-08-14 01:18:42,513 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:18:42,513 [root] DEBUG: Process image base: 0x00000000FFC30000
2019-08-14 01:18:42,513 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2768.
2019-08-14 01:18:42,529 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1896.
2019-08-14 01:18:42,543 [root] DEBUG: InjectDllViaIAT: IAT patching with dll name C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:42,543 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2876.
2019-08-14 01:18:42,543 [root] DEBUG: InjectDllViaIAT: Found a free region from 0x00000000FFC44000 - 0x000007FEFF430000
2019-08-14 01:18:42,543 [root] DEBUG: InjectDllViaIAT: Allocated 0x238 bytes for new import table at 0x00000000FFC50000.
2019-08-14 01:18:42,559 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2116.
2019-08-14 01:18:42,559 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2019-08-14 01:18:42,575 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2584.
2019-08-14 01:18:42,575 [root] DEBUG: Successfully injected DLL C:\nkmznsmshd\dll\mqjWcJC.dll.
2019-08-14 01:18:42,575 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 252.
2019-08-14 01:18:42,591 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 2396
2019-08-14 01:18:42,607 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1272.
2019-08-14 01:18:42,621 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2684.
2019-08-14 01:18:42,621 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2580.
2019-08-14 01:18:42,621 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1544.
2019-08-14 01:18:42,621 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 716.
2019-08-14 01:18:42,638 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2648.
2019-08-14 01:18:42,638 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2392.
2019-08-14 01:18:42,653 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2320.
2019-08-14 01:18:42,653 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2844.
2019-08-14 01:18:42,653 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2672.
2019-08-14 01:18:42,653 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2460.
2019-08-14 01:18:42,668 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2560.
2019-08-14 01:18:42,668 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1672.
2019-08-14 01:18:42,668 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:18:42,684 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2768.
2019-08-14 01:18:42,684 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1896.
2019-08-14 01:18:42,684 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2876.
2019-08-14 01:18:42,684 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2116.
2019-08-14 01:18:42,684 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2584.
2019-08-14 01:18:42,684 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 252.
2019-08-14 01:18:42,700 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1272.
2019-08-14 01:18:42,700 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2684.
2019-08-14 01:18:42,700 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2580.
2019-08-14 01:18:42,700 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1544.
2019-08-14 01:18:42,700 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 716.
2019-08-14 01:18:42,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2648.
2019-08-14 01:18:42,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2392.
2019-08-14 01:18:42,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2320.
2019-08-14 01:18:42,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2844.
2019-08-14 01:18:42,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2672.
2019-08-14 01:18:42,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2460.
2019-08-14 01:18:42,730 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2560.
2019-08-14 01:18:42,730 [root] DEBUG: SetDebugRegister: Setting breakpoint 0 hThread=0xd0, Size=0x0, Address=0x00E73000 and Type=0x1.
2019-08-14 01:18:42,730 [root] DEBUG: SetThreadBreakpoint: Set bp 0 thread id 2948 type 1 at address 0x00E73000, size 0 with Callback 0x747e7620.
2019-08-14 01:18:42,730 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on empty protect address: 0x00E73000
2019-08-14 01:18:42,746 [root] DEBUG: SetDebugRegister: Setting breakpoint 1 hThread=0xd0, Size=0x4, Address=0x00E7003C and Type=0x1.
2019-08-14 01:18:42,746 [root] DEBUG: SetThreadBreakpoint: Set bp 1 thread id 2948 type 1 at address 0x00E7003C, size 4 with Callback 0x747e7280.
2019-08-14 01:18:42,746 [root] DEBUG: ActivateBreakpoints: Set write breakpoint on e_lfanew address: 0x00E7003C
2019-08-14 01:18:42,763 [root] DEBUG: AllocationHandler: Breakpoints set on newly-allocated executable region at: 0x00E73000 (size 0x2000).
2019-08-14 01:18:42,763 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744C64FA (thread 2948)
2019-08-14 01:18:42,778 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x00E73000.
2019-08-14 01:18:42,778 [root] DEBUG: ContextSetDebugRegister: Setting breakpoint 2 within Context, Size=0x0, Address=0x00E73000 and Type=0x0.
2019-08-14 01:18:42,778 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xe73000: 0x95.
2019-08-14 01:18:42,778 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:18:42,778 [root] DEBUG: CAPEExceptionFilter: breakpoint hit by instruction at 0x744C848D (thread 2948)
2019-08-14 01:18:42,793 [root] DEBUG: BaseAddressWriteCallback: Breakpoint 0 at Address 0x00E73000.
2019-08-14 01:18:42,793 [root] DEBUG: ContextSetThreadBreakpoint: An identical breakpoint (2) at 0x00E73000 already exists for thread 2948 (process 2968), skipping.
2019-08-14 01:18:42,793 [root] DEBUG: BaseAddressWriteCallback: byte written to 0xe73000: 0x95.
2019-08-14 01:18:42,793 [root] DEBUG: Terminate processes on terminate_event enabled.
2019-08-14 01:18:42,793 [root] DEBUG: BaseAddressWriteCallback: Exec bp set on tracked region protect address.
2019-08-14 01:18:42,793 [root] DEBUG: Process dumps disabled.
2019-08-14 01:18:42,825 [root] DEBUG: Allocation: 0x00E75000 - 0x00E76000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:42,841 [root] INFO: Disabling sleep skipping.
2019-08-14 01:18:42,841 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 34.
2019-08-14 01:18:42,855 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x6000 added to tracked regions.
2019-08-14 01:18:42,903 [root] WARNING: Unable to place hook on LockResource
2019-08-14 01:18:42,918 [root] WARNING: Unable to hook LockResource
2019-08-14 01:18:42,934 [root] DEBUG: RestoreHeaders: Restored original import table.
2019-08-14 01:18:42,934 [root] DEBUG: Debugger initialised.
2019-08-14 01:18:42,950 [root] DEBUG: CAPE initialised: 64-bit Extraction v2 loaded in process 2396 at 0x000000006FA20000, image base 0x00000000FFC30000, stack from 0x0000000000125000-0x0000000000130000
2019-08-14 01:18:42,950 [root] DEBUG: Commandline: C:\Windows\sysnative\"taskhost.exe".
2019-08-14 01:18:42,964 [root] DEBUG: AddTrackedRegion: EntryPoint 0x2ce0, Entropy 5.003625e+00
2019-08-14 01:18:42,964 [root] DEBUG: AddTrackedRegion: Region at 0x00000000FFC30000 size 0x1000 added to tracked regions.
2019-08-14 01:18:42,964 [root] DEBUG: ExtractionInit: Adding main image base to tracked regions.
2019-08-14 01:18:42,964 [root] INFO: Added new process to list with pid: 2396
2019-08-14 01:18:42,996 [root] INFO: Monitor successfully loaded in process with pid 2396.
2019-08-14 01:18:43,214 [root] DEBUG: DLL loaded at 0x000007FEFCF50000: C:\Windows\system32\CRYPTBASE (0xf000 bytes).
2019-08-14 01:18:43,869 [root] DEBUG: CreateThread: Initialising breakpoints for thread 576.
2019-08-14 01:18:43,869 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:18:43,869 [root] DEBUG: Allocation: 0x00E76000 - 0x00E77000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:43,885 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 35.
2019-08-14 01:18:43,885 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x7000 added to tracked regions.
2019-08-14 01:18:43,963 [root] DEBUG: Allocation: 0x00E77000 - 0x00E78000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:43,963 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 36.
2019-08-14 01:18:43,963 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x8000 added to tracked regions.
2019-08-14 01:18:43,979 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2904.
2019-08-14 01:18:43,979 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2840.
2019-08-14 01:18:44,026 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (0) at 0x00E73000 already exists for thread 2904 (process 2968), skipping.
2019-08-14 01:18:44,026 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (1) at 0x00E7003C already exists for thread 2904 (process 2968), skipping.
2019-08-14 01:18:44,026 [root] DEBUG: SetThreadBreakpoint: An identical breakpoint (2) at 0x00E73000 already exists for thread 2904 (process 2968), skipping.
2019-08-14 01:18:44,042 [root] DEBUG: DLL loaded at 0x000007FEFE400000: C:\Windows\system32\CLBCatQ (0x99000 bytes).
2019-08-14 01:18:44,213 [root] DEBUG: DLL loaded at 0x000007FEFA040000: C:\Windows\System32\wdi (0x19000 bytes).
2019-08-14 01:18:44,368 [root] DEBUG: Allocation: 0x00E78000 - 0x00E79000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:44,447 [root] DEBUG: CreateThread: Initialising breakpoints for thread 1028.
2019-08-14 01:18:44,447 [root] DEBUG: DLL loaded at 0x748A0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32 (0x84000 bytes).
2019-08-14 01:18:44,479 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 37.
2019-08-14 01:18:44,602 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0x9000 added to tracked regions.
2019-08-14 01:18:44,618 [lib.common.results] ERROR: Exception uploading file C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48 to host: 
2019-08-14 01:18:44,634 [root] ERROR: Traceback (most recent call last):
  File "C:\nkmznsmshd\lib\core\log.py", line 79, in run
    self.handle_logs()
  File "C:\nkmznsmshd\lib\core\log.py", line 61, in handle_logs
    data += buf.raw[:bytes_read.value]
MemoryError
Traceback (most recent call last):
  File "C:\nkmznsmshd\lib\core\log.py", line 79, in run
    self.handle_logs()
  File "C:\nkmznsmshd\lib\core\log.py", line 61, in handle_logs
    data += buf.raw[:bytes_read.value]
MemoryError
2019-08-14 01:18:44,680 [root] DEBUG: Allocation: 0x00E79000 - 0x00E7A000, size: 0x1000, protection: 0x40.
2019-08-14 01:18:44,680 [root] ERROR: Traceback (most recent call last):
  File "C:\nkmznsmshd\analyzer.py", line 831, in run
    handler.start()
  File "C:\Python27\lib\threading.py", line 745, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
Traceback (most recent call last):
  File "C:\nkmznsmshd\analyzer.py", line 831, in run
    handler.start()
  File "C:\Python27\lib\threading.py", line 745, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2019-08-14 01:18:55,555 [root] DEBUG: CreateThread: Initialising breakpoints for thread 3044.
2019-08-14 01:18:55,694 [root] DEBUG: AddTrackedRegion: DEBUG Warning - number of tracked regions 38.
2019-08-14 01:18:55,710 [root] DEBUG: DLL loaded at 0x000007FEF9C40000: C:\Windows\system32\radarrs (0x18000 bytes).
2019-08-14 01:18:55,851 [root] DEBUG: AddTrackedRegion: Region at 0x00E70000 size 0xa000 added to tracked regions.
2019-08-14 01:18:55,851 [root] DEBUG: DLL loaded at 0x000007FEFBB00000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\COMCTL32 (0x1f4000 bytes).
2019-08-14 01:18:55,928 [root] DEBUG: DLL loaded at 0x000007FEFD560000: C:\Windows\system32\SHELL32 (0xd88000 bytes).
2019-08-14 01:18:56,006 [root] DEBUG: DLL loaded at 0x000007FEF9910000: C:\Windows\system32\RstrtMgr (0x33000 bytes).
2019-08-14 01:18:56,023 [root] DEBUG: DLL loaded at 0x000007FEFCA70000: C:\Windows\system32\ncrypt (0x4e000 bytes).
2019-08-14 01:18:56,115 [root] DEBUG: DLL loaded at 0x000007FEFCA40000: C:\Windows\system32\bcrypt (0x22000 bytes).
2019-08-14 01:18:56,115 [root] DEBUG: DLL loaded at 0x000007FEFD100000: C:\Windows\system32\MSASN1 (0xf000 bytes).
2019-08-14 01:18:56,240 [root] DEBUG: DLL loaded at 0x000007FEF8CA0000: C:\Windows\system32\wer (0x7c000 bytes).
2019-08-14 01:18:56,319 [root] DEBUG: DLL loaded at 0x000007FEFC1C0000: C:\Windows\system32\VERSION (0xc000 bytes).
2019-08-14 01:18:56,631 [root] DEBUG: DLL loaded at 0x000007FEFB060000: C:\Windows\system32\DUser (0x43000 bytes).
2019-08-14 01:18:56,661 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2452.
2019-08-14 01:18:57,691 [root] DEBUG: DLL loaded at 0x000007FEFB7C0000: C:\Windows\system32\UxTheme (0x56000 bytes).
2019-08-14 01:18:57,739 [root] DEBUG: DLL unloaded from 0x0000000076EF0000.
2019-08-14 01:18:57,769 [root] DEBUG: DLL unloaded from 0x000007FEFB060000.
2019-08-14 01:18:57,785 [root] DEBUG: DLL unloaded from 0x000007FEFBB00000.
2019-08-14 01:18:57,848 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:18:57,848 [root] DEBUG: CreateThread: Initialising breakpoints for thread 2996.
2019-08-14 01:18:58,565 [root] DEBUG: DLL unloaded from 0x0000000076EF0000.
2019-08-14 01:18:58,565 [root] DEBUG: DLL unloaded from 0x000007FEFB060000.
2019-08-14 01:18:58,596 [root] DEBUG: DLL unloaded from 0x000007FEFBB00000.
2019-08-14 01:18:58,596 [root] DEBUG: DLL unloaded from 0x0000000077110000.
2019-08-14 01:19:11,529 [root] DEBUG: DLL unloaded from 0x000007FEF9BA0000.
2019-08-14 01:19:11,529 [root] DEBUG: DLL unloaded from 0x000007FEF97C0000.
2019-08-14 01:19:11,545 [root] DEBUG: DLL unloaded from 0x000007FEF9A00000.
2019-08-14 01:19:11,545 [root] DEBUG: DLL unloaded from 0x000007FEFA0A0000.
2019-08-14 01:19:11,545 [root] DEBUG: DLL unloaded from 0x000007FEF9D50000.
2019-08-14 01:19:11,654 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 3040).
2019-08-14 01:19:11,668 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2120.
2019-08-14 01:19:11,668 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2772.
2019-08-14 01:19:11,700 [root] DEBUG: DLL unloaded from 0x000007FEFC190000.
2019-08-14 01:19:11,700 [root] DEBUG: DLL unloaded from 0x000007FEFF190000.
2019-08-14 01:19:11,716 [root] DEBUG: NtTerminateProcess hook: Processing tracked regions before shutdown (process 3040).
2019-08-14 01:19:11,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2120.
2019-08-14 01:19:11,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2772.
2019-08-14 01:19:11,716 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 624.
2019-08-14 01:19:11,732 [root] INFO: Notified of termination of process with pid 3040.
2019-08-14 01:19:11,779 [root] INFO: Process with pid 3040 has terminated
2019-08-14 01:19:25,974 [root] DEBUG: DLL unloaded from 0x751B0000.
2019-08-14 01:19:55,161 [root] DEBUG: DLL unloaded from 0x000007FEFE8C0000.
2019-08-14 01:20:33,913 [root] INFO: Analysis timeout hit (200 seconds), terminating analysis.
2019-08-14 01:20:33,913 [root] INFO: Created shutdown mutex.
2019-08-14 01:20:34,927 [lib.api.process] INFO: Successfully received reply to terminate_event, pid 2968
2019-08-14 01:20:34,927 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 2968).
2019-08-14 01:20:34,927 [root] INFO: Terminate event set for process 2968.
2019-08-14 01:20:34,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1672.
2019-08-14 01:20:34,927 [root] INFO: Terminating process 2968 before shutdown.
2019-08-14 01:20:34,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1856.
2019-08-14 01:20:34,927 [root] INFO: Waiting for process 2968 to exit.
2019-08-14 01:20:34,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2768.
2019-08-14 01:20:34,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1896.
2019-08-14 01:20:34,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2564.
2019-08-14 01:20:34,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2876.
2019-08-14 01:20:34,927 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1472.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2788.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2116.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2584.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 252.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1272.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2684.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2580.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1544.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 716.
2019-08-14 01:20:34,941 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2648.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2392.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2320.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2844.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2672.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2460.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2560.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 1928.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2884.
2019-08-14 01:20:34,957 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2904.
2019-08-14 01:20:35,019 [root] DEBUG: Terminate Event: CAPE shutdown complete for process 2968
2019-08-14 01:20:35,940 [lib.api.process] INFO: Successfully received reply to terminate_event, pid 844
2019-08-14 01:20:35,940 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 844).
2019-08-14 01:20:35,940 [root] INFO: Terminate event set for process 844.
2019-08-14 01:20:35,940 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2812.
2019-08-14 01:20:35,940 [root] INFO: Terminating process 844 before shutdown.
2019-08-14 01:20:35,940 [root] DEBUG: Terminate Event: CAPE shutdown complete for process 844
2019-08-14 01:20:35,940 [root] INFO: Waiting for process 844 to exit.
2019-08-14 01:20:36,954 [lib.api.process] INFO: Successfully received reply to terminate_event, pid 2396
2019-08-14 01:20:36,954 [root] DEBUG: Terminate Event: Processing tracked regions before shutdown (process 2396).
2019-08-14 01:20:36,954 [root] INFO: Terminate event set for process 2396.
2019-08-14 01:20:36,954 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2840.
2019-08-14 01:20:36,954 [root] INFO: Terminating process 2396 before shutdown.
2019-08-14 01:20:36,954 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2452.
2019-08-14 01:20:36,954 [root] INFO: Waiting for process 2396 to exit.
2019-08-14 01:20:36,954 [root] DEBUG: ClearAllBreakpoints: Error getting thread context for thread 2996.
2019-08-14 01:20:36,954 [root] DEBUG: Terminate Event: CAPE shutdown complete for process 2396
2019-08-14 01:20:37,969 [root] INFO: Shutting down package.
2019-08-14 01:20:37,969 [root] INFO: Stopping auxiliary modules.
2019-08-14 01:20:37,983 [root] INFO: Finishing auxiliary modules.
2019-08-14 01:20:38,000 [root] INFO: Shutting down pipe server and dumping dropped files.
2019-08-14 01:20:38,000 [root] WARNING: File at path "C:\xeiUbkq\debugger" does not exist, skip.
2019-08-14 01:20:38,016 [root] INFO: Analysis completed.

MalScore

10.0

Malicious

Machine

Name Label Manager Started On Shutdown On
target-01 target-01 ESX 2019-08-14 00:16:43 2019-08-14 00:21:03

File Details

File Name DOCUMENTS-7821.exe
File Size 798208 bytes
File Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 1e09a996ff682c8f96fcad4e5ebe5e22
SHA1 001c6eea49802b3e685d9b85917ba6e9053165e8
SHA256 cba21a1002265fdd1da16a1fb54bdddff5edeba67abeb72643abba54116605f1
SHA512 4393e9e4317358ba4d1e6121f11404e33336c1e766c38e5a5b83ae8235b115fb12d9c590fa3fb721f86431d773afae792eba1545cac729053eb962d49fc35ac0
CRC32 A0191D11
Ssdeep 12288:lTc5UVfzfP+yJIUTZkNXCs+/KsQ1tjSYwjmU99ym:lQEfrP+yJhAys+0dwom
TrID
  • 61.7% (.EXE) Win64 Executable (generic) (27625/18/4)
  • 14.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
  • 10.0% (.EXE) Win32 Executable (generic) (4508/7/1)
  • 4.5% (.EXE) OS/2 Executable (generic) (2029/13)
  • 4.4% (.EXE) Generic Win/DOS Executable (2002/3)
ClamAV None matched
Yara None matched
CAPE Yara None matched
Resubmit sample

Signatures

Behavioural detection: Executable code extraction
SetUnhandledExceptionFilter detected (possible anti-debug)
Guard pages use detected - possible anti-debugging.
A process attempted to delay the analysis task.
Process: DOCUMENTS-7821.exe tried to sleep 620 seconds, actually delayed analysis time by 0 seconds
Process: WmiPrvSE.exe tried to sleep 602 seconds, actually delayed analysis time by 0 seconds
Dynamic (imported) function loading detected
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: MSCOREE.DLL/
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: mscoreei.dll/RegisterShimImplCallback
DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
DynamicLoader: mscoreei.dll/SetShellShimInstance
DynamicLoader: mscoreei.dll/OnShimDllMainCalled
DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
DynamicLoader: mscoreei.dll/_CorExeMain
DynamicLoader: SHLWAPI.dll/UrlIsW
DynamicLoader: KERNEL32.dll/GetCurrentPackageId
DynamicLoader: clr.dll/SetRuntimeInfo
DynamicLoader: clr.dll/_CorExeMain
DynamicLoader: KERNEL32.dll/GetCurrentPackageId
DynamicLoader: MSCOREE.DLL/CreateConfigStream
DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream
DynamicLoader: KERNEL32.dll/GetNumaHighestNodeNumber
DynamicLoader: KERNEL32.dll/FlsSetValue
DynamicLoader: KERNEL32.dll/FlsGetValue
DynamicLoader: KERNEL32.dll/FlsAlloc
DynamicLoader: KERNEL32.dll/FlsFree
DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
DynamicLoader: MSCOREE.DLL/CLRCreateInstance
DynamicLoader: mscoreei.dll/CLRCreateInstance
DynamicLoader: SHLWAPI.dll/PathFindFileNameW
DynamicLoader: KERNEL32.dll/IsWow64Process
DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: KERNEL32.dll/AddSIDToBoundaryDescriptor
DynamicLoader: KERNEL32.dll/CreateBoundaryDescriptorW
DynamicLoader: KERNEL32.dll/CreatePrivateNamespaceW
DynamicLoader: KERNEL32.dll/OpenPrivateNamespaceW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: KERNEL32.dll/DeleteBoundaryDescriptor
DynamicLoader: KERNEL32.dll/WerRegisterRuntimeExceptionModule
DynamicLoader: KERNEL32.dll/RaiseException
DynamicLoader: KERNEL32.dll/AddVectoredExceptionHandler
DynamicLoader: KERNEL32.dll/RemoveVectoredExceptionHandler
DynamicLoader: KERNEL32.dll/AddVectoredContinueHandler
DynamicLoader: KERNEL32.dll/RemoveVectoredContinueHandler
DynamicLoader: MSCOREE.DLL/
DynamicLoader: mscoreei.dll/
DynamicLoader: KERNELBASE.dll/SetSystemFileCacheSize
DynamicLoader: ntdll.dll/NtSetSystemInformation
DynamicLoader: KERNELBASE.dll/PrivIsDllSynchronizationHeld
DynamicLoader: KERNEL32.dll/AddDllDirectory
DynamicLoader: KERNEL32.dll/GetWriteWatch
DynamicLoader: KERNEL32.dll/ResetWriteWatch
DynamicLoader: KERNEL32.dll/CreateMemoryResourceNotification
DynamicLoader: KERNEL32.dll/QueryMemoryResourceNotification
DynamicLoader: KERNEL32.dll/SortGetHandle
DynamicLoader: KERNEL32.dll/SortCloseHandle
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ole32.dll/CoGetContextToken
DynamicLoader: clrjit.dll/sxsJitStartup
DynamicLoader: clrjit.dll/getJit
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/QueryThreadCycleTime
DynamicLoader: KERNEL32.dll/GetFullPathName
DynamicLoader: KERNEL32.dll/GetFullPathNameW
DynamicLoader: uxtheme.dll/IsAppThemed
DynamicLoader: uxtheme.dll/IsAppThemedW
DynamicLoader: KERNEL32.dll/CreateActCtx
DynamicLoader: KERNEL32.dll/CreateActCtxA
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: USER32.dll/RegisterWindowMessage
DynamicLoader: USER32.dll/RegisterWindowMessageW
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: KERNEL32.dll/GetModuleHandle
DynamicLoader: KERNEL32.dll/GetModuleHandleW
DynamicLoader: KERNEL32.dll/LoadLibrary
DynamicLoader: KERNEL32.dll/LoadLibraryW
DynamicLoader: USER32.dll/AdjustWindowRectEx
DynamicLoader: KERNEL32.dll/GetCurrentProcess
DynamicLoader: KERNEL32.dll/GetCurrentThread
DynamicLoader: KERNEL32.dll/DuplicateHandle
DynamicLoader: KERNEL32.dll/GetCurrentThreadId
DynamicLoader: KERNEL32.dll/GetCurrentActCtx
DynamicLoader: KERNEL32.dll/ActivateActCtx
DynamicLoader: KERNEL32.dll/GetProcAddress
DynamicLoader: KERNEL32.dll/WideCharToMultiByte
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: GDI32.dll/GetStockObject
DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
DynamicLoader: KERNEL32.dll/LocaleNameToLCID
DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
DynamicLoader: KERNEL32.dll/LCIDToLocaleName
DynamicLoader: KERNEL32.dll/GetUserPreferredUILanguages
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/GetWindowLong
DynamicLoader: USER32.dll/GetWindowLongW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: nlssorting.dll/SortGetHandle
DynamicLoader: nlssorting.dll/SortCloseHandle
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/CallWindowProc
DynamicLoader: USER32.dll/CallWindowProcW
DynamicLoader: USER32.dll/GetClientRect
DynamicLoader: USER32.dll/GetWindowRect
DynamicLoader: USER32.dll/GetParent
DynamicLoader: KERNEL32.dll/DeactivateActCtx
DynamicLoader: ADVAPI32.dll/EventRegister
DynamicLoader: USER32.dll/GetProcessWindowStation
DynamicLoader: USER32.dll/GetUserObjectInformation
DynamicLoader: USER32.dll/GetUserObjectInformationA
DynamicLoader: KERNEL32.dll/SetConsoleCtrlHandler
DynamicLoader: KERNEL32.dll/SetConsoleCtrlHandlerW
DynamicLoader: KERNEL32.dll/GetModuleHandle
DynamicLoader: KERNEL32.dll/GetModuleHandleW
DynamicLoader: USER32.dll/GetClassInfo
DynamicLoader: USER32.dll/GetClassInfoW
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/DefWindowProc
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: USER32.dll/SystemParametersInfo
DynamicLoader: USER32.dll/SystemParametersInfoW
DynamicLoader: USER32.dll/GetDC
DynamicLoader: gdiplus.dll/GdiplusStartup
DynamicLoader: KERNEL32.dll/IsProcessorFeaturePresent
DynamicLoader: USER32.dll/GetWindowInfo
DynamicLoader: USER32.dll/GetAncestor
DynamicLoader: USER32.dll/GetMonitorInfoA
DynamicLoader: USER32.dll/EnumDisplayMonitors
DynamicLoader: USER32.dll/EnumDisplayDevicesA
DynamicLoader: GDI32.dll/ExtTextOutW
DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
DynamicLoader: gdiplus.dll/GdipCreateFontFromLogfontW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: KERNEL32.dll/RegOpenKeyExW
DynamicLoader: KERNEL32.dll/RegQueryInfoKeyA
DynamicLoader: KERNEL32.dll/RegCloseKey
DynamicLoader: KERNEL32.dll/RegCreateKeyExW
DynamicLoader: KERNEL32.dll/RegQueryValueExW
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: MSCOREE.DLL/ND_RI2
DynamicLoader: mscoreei.dll/ND_RI2_RetAddr
DynamicLoader: mscoreei.dll/ND_RI2
DynamicLoader: MSCOREE.DLL/ND_RU1
DynamicLoader: mscoreei.dll/ND_RU1_RetAddr
DynamicLoader: mscoreei.dll/ND_RU1
DynamicLoader: gdiplus.dll/GdipGetFontUnit
DynamicLoader: gdiplus.dll/GdipGetFontSize
DynamicLoader: gdiplus.dll/GdipGetFontStyle
DynamicLoader: gdiplus.dll/GdipGetFamily
DynamicLoader: USER32.dll/ReleaseDC
DynamicLoader: gdiplus.dll/GdipCreateFromHDC
DynamicLoader: gdiplus.dll/GdipGetDpiY
DynamicLoader: gdiplus.dll/GdipGetFontHeight
DynamicLoader: gdiplus.dll/GdipGetEmHeight
DynamicLoader: gdiplus.dll/GdipGetLineSpacing
DynamicLoader: gdiplus.dll/GdipDeleteGraphics
DynamicLoader: gdiplus.dll/GdipCreateFont
DynamicLoader: USER32.dll/SystemParametersInfo
DynamicLoader: USER32.dll/SystemParametersInfoW
DynamicLoader: gdiplus.dll/GdipGetFamilyName
DynamicLoader: GDI32.dll/CreateCompatibleDC
DynamicLoader: GDI32.dll/GetCurrentObject
DynamicLoader: GDI32.dll/SaveDC
DynamicLoader: GDI32.dll/GetDeviceCaps
DynamicLoader: GDI32.dll/CreateFontIndirect
DynamicLoader: GDI32.dll/CreateFontIndirectW
DynamicLoader: GDI32.dll/GetObject
DynamicLoader: GDI32.dll/GetObjectW
DynamicLoader: GDI32.dll/SelectObject
DynamicLoader: GDI32.dll/GetMapMode
DynamicLoader: GDI32.dll/GetTextMetricsW
DynamicLoader: USER32.dll/DrawTextExW
DynamicLoader: USER32.dll/DrawTextExWW
DynamicLoader: GDI32.dll/GetLayout
DynamicLoader: GDI32.dll/GdiRealizationInfo
DynamicLoader: GDI32.dll/FontIsLinked
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: GDI32.dll/GetFontAssocStatus
DynamicLoader: ADVAPI32.dll/RegQueryValueExA
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: GDI32.dll/GetTextFaceAliasW
DynamicLoader: USER32.dll/MonitorFromRect
DynamicLoader: USER32.dll/GetMonitorInfo
DynamicLoader: USER32.dll/GetMonitorInfoW
DynamicLoader: GDI32.dll/CreateDC
DynamicLoader: GDI32.dll/CreateDCW
DynamicLoader: GDI32.dll/GetDeviceCaps
DynamicLoader: GDI32.dll/DeleteDC
DynamicLoader: USER32.dll/GetDoubleClickTime
DynamicLoader: gdiplus.dll/GdipCreateBitmapFromStream
DynamicLoader: WindowsCodecs.dll/DllGetClassObject
DynamicLoader: KERNEL32.dll/WerRegisterMemoryBlock
DynamicLoader: gdiplus.dll/GdipImageForceValidation
DynamicLoader: gdiplus.dll/GdipGetImageRawFormat
DynamicLoader: gdiplus.dll/GdipGetImageWidth
DynamicLoader: gdiplus.dll/GdipGetImageHeight
DynamicLoader: gdiplus.dll/GdipCreateBitmapFromScan0
DynamicLoader: gdiplus.dll/GdipGetImagePixelFormat
DynamicLoader: gdiplus.dll/GdipGetImageGraphicsContext
DynamicLoader: USER32.dll/GetSysColor
DynamicLoader: USER32.dll/GetSysColorW
DynamicLoader: gdiplus.dll/GdipGraphicsClear
DynamicLoader: gdiplus.dll/GdipCreateImageAttributes
DynamicLoader: gdiplus.dll/GdipSetImageAttributesColorKeys
DynamicLoader: gdiplus.dll/GdipDrawImageRectRectI
DynamicLoader: gdiplus.dll/GdipDisposeImageAttributes
DynamicLoader: gdiplus.dll/GdipDisposeImage
DynamicLoader: KERNEL32.dll/GetSystemDefaultLCID
DynamicLoader: KERNEL32.dll/GetSystemDefaultLCIDW
DynamicLoader: GDI32.dll/GetStockObject
DynamicLoader: GDI32.dll/GetObject
DynamicLoader: GDI32.dll/GetObjectW
DynamicLoader: KERNEL32.dll/RegEnumValueW
DynamicLoader: KERNEL32.dll/RegQueryInfoKeyW
DynamicLoader: gdiplus.dll/GdipDeleteFont
DynamicLoader: ole32.dll/CoCreateGuid
DynamicLoader: KERNEL32.dll/LCMapStringEx
DynamicLoader: gdiplus.dll/GdipCreateFontFamilyFromName
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/CompareStringOrdinal
DynamicLoader: KERNEL32.dll/SetThreadErrorMode
DynamicLoader: KERNEL32.dll/GetFileAttributesEx
DynamicLoader: KERNEL32.dll/GetFileAttributesExW
DynamicLoader: KERNEL32.dll/ResolveLocaleName
DynamicLoader: gdiplus.dll/GdipLoadImageFromStream
DynamicLoader: gdiplus.dll/GdipGetImageType
DynamicLoader: gdiplus.dll/GdipBitmapGetPixel
DynamicLoader: KERNEL32.dll/VirtualProtect
DynamicLoader: shell32.dll/SHGetFolderPath
DynamicLoader: shell32.dll/SHGetFolderPathW
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
DynamicLoader: ADVAPI32.dll/SetNamedSecurityInfoW
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: KERNEL32.dll/CopyFile
DynamicLoader: KERNEL32.dll/CopyFileW
DynamicLoader: ADVAPI32.dll/GetUserName
DynamicLoader: ADVAPI32.dll/GetUserNameW
DynamicLoader: KERNEL32.dll/SetFileAttributes
DynamicLoader: KERNEL32.dll/SetFileAttributesW
DynamicLoader: ADVAPI32.dll/LsaClose
DynamicLoader: ADVAPI32.dll/LsaFreeMemory
DynamicLoader: ADVAPI32.dll/LsaOpenPolicy
DynamicLoader: ADVAPI32.dll/LsaLookupNames2
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: KERNEL32.dll/GetCurrentProcess
DynamicLoader: KERNEL32.dll/GetCurrentProcessW
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: KERNEL32.dll/LocalFree
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/GetTokenInformationW
DynamicLoader: KERNEL32.dll/LocalAlloc
DynamicLoader: KERNEL32.dll/LocalAllocW
DynamicLoader: ADVAPI32.dll/LsaLookupSids
DynamicLoader: KERNEL32.dll/GetTempPath
DynamicLoader: KERNEL32.dll/GetTempPathW
DynamicLoader: KERNEL32.dll/GetTempFileName
DynamicLoader: KERNEL32.dll/GetTempFileNameW
DynamicLoader: KERNEL32.dll/CreateFile
DynamicLoader: KERNEL32.dll/CreateFileW
DynamicLoader: KERNEL32.dll/GetFileType
DynamicLoader: KERNEL32.dll/WriteFile
DynamicLoader: KERNEL32.dll/LocalAlloc
DynamicLoader: shell32.dll/ShellExecuteEx
DynamicLoader: shell32.dll/ShellExecuteExW
DynamicLoader: SETUPAPI.dll/CM_Get_Device_Interface_List_Size_ExW
DynamicLoader: SETUPAPI.dll/CM_Get_Device_Interface_List_ExW
DynamicLoader: comctl32.dll/
DynamicLoader: comctl32.dll/
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: KERNEL32.dll/GetCurrentProcess
DynamicLoader: KERNEL32.dll/DuplicateHandle
DynamicLoader: KERNEL32.dll/ReleaseMutex
DynamicLoader: KERNEL32.dll/CreateMutex
DynamicLoader: KERNEL32.dll/CreateMutexW
DynamicLoader: ole32.dll/CoWaitForMultipleHandles
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: ole32.dll/NdrOleInitializeExtension
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: KERNEL32.dll/DeleteFile
DynamicLoader: KERNEL32.dll/DeleteFileW
DynamicLoader: KERNEL32.dll/CreateProcess
DynamicLoader: KERNEL32.dll/CreateProcessW
DynamicLoader: KERNEL32.dll/GetThreadContext
DynamicLoader: KERNEL32.dll/ReadProcessMemory
DynamicLoader: KERNEL32.dll/VirtualAllocEx
DynamicLoader: KERNEL32.dll/WriteProcessMemory
DynamicLoader: KERNEL32.dll/SetThreadContext
DynamicLoader: KERNEL32.dll/ResumeThread
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: PSAPI.DLL/EnumProcesses
DynamicLoader: PSAPI.DLL/EnumProcessesW
DynamicLoader: USER32.dll/SetClassLong
DynamicLoader: USER32.dll/SetClassLongW
DynamicLoader: USER32.dll/PostMessage
DynamicLoader: USER32.dll/PostMessageW
DynamicLoader: USER32.dll/UnregisterClass
DynamicLoader: USER32.dll/UnregisterClassW
DynamicLoader: USER32.dll/IsWindow
DynamicLoader: KERNEL32.dll/GetProcAddress
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/SetClassLong
DynamicLoader: USER32.dll/SetClassLongW
DynamicLoader: USER32.dll/DestroyWindow
DynamicLoader: USER32.dll/DestroyWindowW
DynamicLoader: USER32.dll/PostMessage
DynamicLoader: USER32.dll/PostMessageW
DynamicLoader: GDI32.dll/RestoreDC
DynamicLoader: GDI32.dll/DeleteDC
DynamicLoader: GDI32.dll/DeleteObject
DynamicLoader: ADVAPI32.dll/EventUnregister
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
DynamicLoader: comctl32.dll/
DynamicLoader: KERNEL32.dll/CreateActCtxW
DynamicLoader: KERNEL32.dll/AddRefActCtx
DynamicLoader: KERNEL32.dll/ReleaseActCtx
DynamicLoader: KERNEL32.dll/ActivateActCtx
DynamicLoader: KERNEL32.dll/DeactivateActCtx
DynamicLoader: KERNEL32.dll/GetCurrentActCtx
DynamicLoader: KERNEL32.dll/QueryActCtxW
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
DynamicLoader: VERSION.dll/GetFileVersionInfoW
DynamicLoader: VERSION.dll/VerQueryValueW
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: SspiCli.dll/GetUserNameExW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: pcwum.dll/PerfDeleteInstance
DynamicLoader: pcwum.dll/PerfStopProvider
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: ADVAPI32.dll/WmiCloseBlock
DynamicLoader: PROPSYS.dll/PropVariantToVariant
DynamicLoader: ole32.dll/CoDisconnectObject
DynamicLoader: wbemcore.dll/Shutdown
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: ole32.dll/CoDisconnectObject
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ADVAPI32.dll/RegDeleteKeyExW
DynamicLoader: kernel32.dll/RegDeleteValueW
DynamicLoader: WTSAPI32.dll/WTSQueryUserToken
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ADVAPI32.dll/RegEnumValueW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: MSCOREE.DLL/
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: mscoreei.dll/RegisterShimImplCallback
DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
DynamicLoader: mscoreei.dll/SetShellShimInstance
DynamicLoader: mscoreei.dll/OnShimDllMainCalled
DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
DynamicLoader: mscoreei.dll/_CorExeMain
DynamicLoader: SHLWAPI.dll/UrlIsW
DynamicLoader: KERNEL32.dll/GetCurrentPackageId
DynamicLoader: clr.dll/SetRuntimeInfo
DynamicLoader: clr.dll/_CorExeMain
DynamicLoader: KERNEL32.dll/GetCurrentPackageId
DynamicLoader: MSCOREE.DLL/CreateConfigStream
DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
DynamicLoader: mscoreei.dll/CreateConfigStream
DynamicLoader: KERNEL32.dll/GetNumaHighestNodeNumber
DynamicLoader: KERNEL32.dll/FlsSetValue
DynamicLoader: KERNEL32.dll/FlsGetValue
DynamicLoader: KERNEL32.dll/FlsAlloc
DynamicLoader: KERNEL32.dll/FlsFree
DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
DynamicLoader: MSCOREE.DLL/CLRCreateInstance
DynamicLoader: mscoreei.dll/CLRCreateInstance
DynamicLoader: SHLWAPI.dll/PathFindFileNameW
DynamicLoader: KERNEL32.dll/IsWow64Process
DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: KERNEL32.dll/AddSIDToBoundaryDescriptor
DynamicLoader: KERNEL32.dll/CreateBoundaryDescriptorW
DynamicLoader: KERNEL32.dll/CreatePrivateNamespaceW
DynamicLoader: KERNEL32.dll/OpenPrivateNamespaceW
DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/GetTokenInformation
DynamicLoader: ADVAPI32.dll/InitializeAcl
DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
DynamicLoader: ADVAPI32.dll/FreeSid
DynamicLoader: KERNEL32.dll/DeleteBoundaryDescriptor
DynamicLoader: KERNEL32.dll/WerRegisterRuntimeExceptionModule
DynamicLoader: KERNEL32.dll/RaiseException
DynamicLoader: KERNEL32.dll/AddVectoredExceptionHandler
DynamicLoader: KERNEL32.dll/RemoveVectoredExceptionHandler
DynamicLoader: KERNEL32.dll/AddVectoredContinueHandler
DynamicLoader: KERNEL32.dll/RemoveVectoredContinueHandler
DynamicLoader: MSCOREE.DLL/
DynamicLoader: mscoreei.dll/
DynamicLoader: KERNELBASE.dll/SetSystemFileCacheSize
DynamicLoader: ntdll.dll/NtSetSystemInformation
DynamicLoader: KERNELBASE.dll/PrivIsDllSynchronizationHeld
DynamicLoader: KERNEL32.dll/AddDllDirectory
DynamicLoader: KERNEL32.dll/GetWriteWatch
DynamicLoader: KERNEL32.dll/ResetWriteWatch
DynamicLoader: KERNEL32.dll/CreateMemoryResourceNotification
DynamicLoader: KERNEL32.dll/QueryMemoryResourceNotification
DynamicLoader: KERNEL32.dll/SortGetHandle
DynamicLoader: KERNEL32.dll/SortCloseHandle
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ole32.dll/CoGetContextToken
DynamicLoader: clrjit.dll/sxsJitStartup
DynamicLoader: clrjit.dll/getJit
DynamicLoader: KERNEL32.dll/QueryThreadCycleTime
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
DynamicLoader: KERNEL32.dll/LocaleNameToLCID
DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
DynamicLoader: KERNEL32.dll/LCIDToLocaleName
DynamicLoader: KERNEL32.dll/GetUserPreferredUILanguages
DynamicLoader: nlssorting.dll/SortGetHandle
DynamicLoader: nlssorting.dll/SortCloseHandle
DynamicLoader: ADVAPI32.dll/ConvertSidToStringSidW
DynamicLoader: shell32.dll/SHGetFolderPathW
DynamicLoader: KERNEL32.dll/GetFullPathName
DynamicLoader: KERNEL32.dll/GetFullPathNameW
DynamicLoader: KERNEL32.dll/SetThreadErrorMode
DynamicLoader: KERNEL32.dll/GetFileAttributesEx
DynamicLoader: KERNEL32.dll/GetFileAttributesExW
DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
DynamicLoader: bcrypt.dll/BCryptGetFipsAlgorithmMode
DynamicLoader: KERNEL32.dll/GetEnvironmentVariable
DynamicLoader: KERNEL32.dll/GetEnvironmentVariableW
DynamicLoader: CRYPTSP.dll/CryptGetDefaultProviderW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptCreateHash
DynamicLoader: ole32.dll/CreateBindCtx
DynamicLoader: ole32.dll/CoGetObjectContext
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: ole32.dll/NdrOleInitializeExtension
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/MkParseDisplayName
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: KERNEL32.dll/GetThreadPreferredUILanguages
DynamicLoader: KERNEL32.dll/SetThreadPreferredUILanguages
DynamicLoader: KERNEL32.dll/LocaleNameToLCID
DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
DynamicLoader: KERNEL32.dll/LCIDToLocaleName
DynamicLoader: KERNEL32.dll/GetSystemDefaultLocaleName
DynamicLoader: ole32.dll/BindMoniker
DynamicLoader: SXS.DLL/SxsOleAut32RedirectTypeLibrary
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyW
DynamicLoader: ADVAPI32.dll/RegQueryValueW
DynamicLoader: SXS.DLL/SxsOleAut32MapConfiguredClsidToReferenceClsid
DynamicLoader: SXS.DLL/SxsLookupClrGuid
DynamicLoader: KERNEL32.dll/ReleaseActCtx
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: mscoreei.dll/_CorDllMain_RetAddr
DynamicLoader: mscoreei.dll/_CorDllMain
DynamicLoader: MSCOREE.DLL/GetTokenForVTableEntry
DynamicLoader: MSCOREE.DLL/SetTargetForVTableEntry
DynamicLoader: MSCOREE.DLL/GetTargetForVTableEntry
DynamicLoader: mscoreei.dll/GetTokenForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/GetTokenForVTableEntry
DynamicLoader: mscoreei.dll/SetTargetForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/SetTargetForVTableEntry
DynamicLoader: mscoreei.dll/GetTargetForVTableEntry_RetAddr
DynamicLoader: mscoreei.dll/GetTargetForVTableEntry
DynamicLoader: KERNEL32.dll/GetLastError
DynamicLoader: KERNEL32.dll/LocalAlloc
DynamicLoader: OLEAUT32.dll/
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/CreateEvent
DynamicLoader: KERNEL32.dll/CreateEventW
DynamicLoader: KERNEL32.dll/ReleaseMutex
DynamicLoader: KERNEL32.dll/CreateMutex
DynamicLoader: KERNEL32.dll/CreateMutexW
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: KERNEL32.dll/SetEvent
DynamicLoader: ole32.dll/CoWaitForMultipleHandles
DynamicLoader: KERNEL32.dll/LCMapStringEx
DynamicLoader: ole32.dll/IIDFromString
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: KERNEL32.dll/LoadLibrary
DynamicLoader: KERNEL32.dll/LoadLibraryA
DynamicLoader: KERNEL32.dll/WideCharToMultiByte
DynamicLoader: KERNEL32.dll/GetProcAddress
DynamicLoader: wminet_utils.dll/ResetSecurity
DynamicLoader: wminet_utils.dll/SetSecurity
DynamicLoader: wminet_utils.dll/BlessIWbemServices
DynamicLoader: wminet_utils.dll/BlessIWbemServicesObject
DynamicLoader: wminet_utils.dll/GetPropertyHandle
DynamicLoader: wminet_utils.dll/WritePropertyValue
DynamicLoader: wminet_utils.dll/Clone
DynamicLoader: wminet_utils.dll/VerifyClientKey
DynamicLoader: wminet_utils.dll/GetQualifierSet
DynamicLoader: wminet_utils.dll/Get
DynamicLoader: wminet_utils.dll/Put
DynamicLoader: wminet_utils.dll/Delete
DynamicLoader: wminet_utils.dll/GetNames
DynamicLoader: wminet_utils.dll/BeginEnumeration
DynamicLoader: wminet_utils.dll/Next
DynamicLoader: wminet_utils.dll/EndEnumeration
DynamicLoader: wminet_utils.dll/GetPropertyQualifierSet
DynamicLoader: wminet_utils.dll/Clone
DynamicLoader: wminet_utils.dll/GetObjectText
DynamicLoader: wminet_utils.dll/SpawnDerivedClass
DynamicLoader: wminet_utils.dll/SpawnInstance
DynamicLoader: wminet_utils.dll/CompareTo
DynamicLoader: wminet_utils.dll/GetPropertyOrigin
DynamicLoader: wminet_utils.dll/InheritsFrom
DynamicLoader: wminet_utils.dll/GetMethod
DynamicLoader: wminet_utils.dll/PutMethod
DynamicLoader: wminet_utils.dll/DeleteMethod
DynamicLoader: wminet_utils.dll/BeginMethodEnumeration
DynamicLoader: wminet_utils.dll/NextMethod
DynamicLoader: wminet_utils.dll/EndMethodEnumeration
DynamicLoader: wminet_utils.dll/GetMethodQualifierSet
DynamicLoader: wminet_utils.dll/GetMethodOrigin
DynamicLoader: wminet_utils.dll/QualifierSet_Get
DynamicLoader: wminet_utils.dll/QualifierSet_Put
DynamicLoader: wminet_utils.dll/QualifierSet_Delete
DynamicLoader: wminet_utils.dll/QualifierSet_GetNames
DynamicLoader: wminet_utils.dll/QualifierSet_BeginEnumeration
DynamicLoader: wminet_utils.dll/QualifierSet_Next
DynamicLoader: wminet_utils.dll/QualifierSet_EndEnumeration
DynamicLoader: wminet_utils.dll/GetCurrentApartmentType
DynamicLoader: wminet_utils.dll/GetDemultiplexedStub
DynamicLoader: wminet_utils.dll/CreateInstanceEnumWmi
DynamicLoader: wminet_utils.dll/CreateClassEnumWmi
DynamicLoader: wminet_utils.dll/ExecQueryWmi
DynamicLoader: wminet_utils.dll/ExecNotificationQueryWmi
DynamicLoader: wminet_utils.dll/PutInstanceWmi
DynamicLoader: wminet_utils.dll/PutClassWmi
DynamicLoader: wminet_utils.dll/CloneEnumWbemClassObject
DynamicLoader: wminet_utils.dll/ConnectServerWmi
DynamicLoader: OLEAUT32.dll/SysStringLen
DynamicLoader: KERNEL32.dll/RtlZeroMemory
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: KERNEL32.dll/RegOpenKeyExW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: CRYPTSP.dll/CryptHashData
DynamicLoader: CRYPTSP.dll/CryptGetHashParam
DynamicLoader: CRYPTSP.dll/CryptDestroyHash
DynamicLoader: ADVAPI32.dll/GetUserName
DynamicLoader: ADVAPI32.dll/GetUserNameW
DynamicLoader: KERNEL32.dll/GetComputerName
DynamicLoader: KERNEL32.dll/GetComputerNameW
DynamicLoader: KERNEL32.dll/GetTimeZoneInformation
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: ADVAPI32.dll/RegQueryValueEx
DynamicLoader: ADVAPI32.dll/RegQueryValueExW
DynamicLoader: KERNEL32.dll/GetModuleHandle
DynamicLoader: KERNEL32.dll/GetModuleHandleW
DynamicLoader: KERNEL32.dll/GetProcAddress
DynamicLoader: USER32.dll/DefWindowProcW
DynamicLoader: GDI32.dll/GetStockObject
DynamicLoader: USER32.dll/RegisterClass
DynamicLoader: USER32.dll/RegisterClassW
DynamicLoader: USER32.dll/CreateWindowEx
DynamicLoader: USER32.dll/CreateWindowExW
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/GetWindowLong
DynamicLoader: USER32.dll/GetWindowLongW
DynamicLoader: KERNEL32.dll/GetCurrentProcess
DynamicLoader: KERNEL32.dll/GetCurrentThread
DynamicLoader: KERNEL32.dll/DuplicateHandle
DynamicLoader: KERNEL32.dll/GetCurrentThreadId
DynamicLoader: USER32.dll/SetWindowLong
DynamicLoader: USER32.dll/SetWindowLongW
DynamicLoader: USER32.dll/CallWindowProc
DynamicLoader: USER32.dll/CallWindowProcW
DynamicLoader: USER32.dll/RegisterWindowMessage
DynamicLoader: USER32.dll/RegisterWindowMessageW
DynamicLoader: KERNEL32.dll/GetCurrentProcessId
DynamicLoader: KERNEL32.dll/GetCurrentProcessIdW
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
DynamicLoader: KERNEL32.dll/GetCurrentProcess
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: ntdll.dll/NtQuerySystemInformation
DynamicLoader: ntdll.dll/NtQuerySystemInformationW
DynamicLoader: ntdll.dll/NtQueryInformationThread
DynamicLoader: ntdll.dll/NtQuerySystemInformation
DynamicLoader: KERNEL32.dll/CreateWaitableTimerExW
DynamicLoader: KERNEL32.dll/SetWaitableTimerEx
DynamicLoader: ntdll.dll/NtGetCurrentProcessorNumber
DynamicLoader: KERNEL32.dll/GetSystemTimeAsFileTime
DynamicLoader: KERNEL32.dll/GetDynamicTimeZoneInformation
DynamicLoader: shell32.dll/SHGetFolderPath
DynamicLoader: shell32.dll/SHGetFolderPathW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: KERNEL32.dll/GetFileMUIPath
DynamicLoader: KERNEL32.dll/LoadLibraryEx
DynamicLoader: KERNEL32.dll/LoadLibraryExW
DynamicLoader: KERNEL32.dll/FreeLibrary
DynamicLoader: KERNEL32.dll/FreeLibraryW
DynamicLoader: USER32.dll/LoadStringW
DynamicLoader: KERNEL32.dll/GetACP
DynamicLoader: KERNEL32.dll/UnmapViewOfFile
DynamicLoader: KERNEL32.dll/CompareStringOrdinal
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetCurrentProcess
DynamicLoader: KERNEL32.dll/GetCurrentProcessW
DynamicLoader: ADVAPI32.dll/OpenProcessToken
DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
DynamicLoader: KERNEL32.dll/GetFileAttributesEx
DynamicLoader: KERNEL32.dll/GetFileAttributesExW
DynamicLoader: KERNEL32.dll/CreateFile
DynamicLoader: KERNEL32.dll/CreateFileW
DynamicLoader: KERNEL32.dll/GetFileType
DynamicLoader: KERNEL32.dll/GetFileSize
DynamicLoader: KERNEL32.dll/ReadFile
DynamicLoader: KERNEL32.dll/QueryPerformanceFrequency
DynamicLoader: KERNEL32.dll/QueryPerformanceCounter
DynamicLoader: rasapi32.dll/RasEnumConnections
DynamicLoader: rasapi32.dll/RasEnumConnectionsW
DynamicLoader: rtutils.dll/TraceRegisterExA
DynamicLoader: rtutils.dll/TracePrintfExA
DynamicLoader: sechost.dll/OpenSCManagerW
DynamicLoader: sechost.dll/OpenServiceW
DynamicLoader: sechost.dll/QueryServiceStatus
DynamicLoader: sechost.dll/CloseServiceHandle
DynamicLoader: WS2_32.dll/WSAStartup
DynamicLoader: WS2_32.dll/WSASocket
DynamicLoader: WS2_32.dll/WSASocketW
DynamicLoader: WS2_32.dll/setsockopt
DynamicLoader: WS2_32.dll/WSAEventSelect
DynamicLoader: WS2_32.dll/ioctlsocket
DynamicLoader: WS2_32.dll/closesocket
DynamicLoader: WS2_32.dll/ioctlsocket
DynamicLoader: WS2_32.dll/WSAIoctl
DynamicLoader: KERNEL32.dll/FormatMessage
DynamicLoader: KERNEL32.dll/FormatMessageW
DynamicLoader: WS2_32.dll/WSAEventSelect
DynamicLoader: rasapi32.dll/RasConnectionNotification
DynamicLoader: rasapi32.dll/RasConnectionNotificationW
DynamicLoader: ADVAPI32.dll/RegOpenCurrentUser
DynamicLoader: ADVAPI32.dll/RegCloseKey
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: ADVAPI32.dll/RegNotifyChangeKeyValue
DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
DynamicLoader: winhttp.dll/WinHttpOpen
DynamicLoader: winhttp.dll/WinHttpOpenW
DynamicLoader: winhttp.dll/WinHttpCloseHandle
DynamicLoader: winhttp.dll/WinHttpCloseHandleW
DynamicLoader: sechost.dll/NotifyServiceStatusChangeA
DynamicLoader: winhttp.dll/WinHttpSetTimeouts
DynamicLoader: winhttp.dll/WinHttpSetTimeoutsW
DynamicLoader: KERNEL32.dll/LocalFree
DynamicLoader: winhttp.dll/WinHttpGetIEProxyConfigForCurrentUser
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ADVAPI32.dll/RegDeleteTreeA
DynamicLoader: ADVAPI32.dll/RegDeleteTreeW
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: NSI.dll/NsiAllocateAndGetTable
DynamicLoader: CFGMGR32.dll/CM_Open_Class_Key_ExW
DynamicLoader: IPHLPAPI.DLL/ConvertInterfaceGuidToLuid
DynamicLoader: IPHLPAPI.DLL/GetIfEntry2
DynamicLoader: IPHLPAPI.DLL/GetIpForwardTable2
DynamicLoader: IPHLPAPI.DLL/GetIpNetEntry2
DynamicLoader: IPHLPAPI.DLL/FreeMibTable
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: NSI.dll/NsiFreeTable
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: KERNEL32.dll/ResetEvent
DynamicLoader: winhttp.dll/WinHttpGetProxyForUrl
DynamicLoader: winhttp.dll/WinHttpGetProxyForUrlW
DynamicLoader: KERNEL32.dll/LocalFree
DynamicLoader: IPHLPAPI.DLL/GetNetworkParams
DynamicLoader: DNSAPI.dll/DnsQueryConfig
DynamicLoader: IPHLPAPI.DLL/GetAdaptersAddresses
DynamicLoader: IPHLPAPI.DLL/GetIpInterfaceEntry
DynamicLoader: IPHLPAPI.DLL/GetBestInterfaceEx
DynamicLoader: KERNEL32.dll/LocalAlloc
DynamicLoader: IPHLPAPI.DLL/GetAdaptersAddresses
DynamicLoader: WS2_32.dll/GetAddrInfoW
DynamicLoader: WS2_32.dll/freeaddrinfo
DynamicLoader: IPHLPAPI.DLL/GetAdaptersAddresses
DynamicLoader: WS2_32.dll/WSAConnect
DynamicLoader: WS2_32.dll/send
DynamicLoader: WS2_32.dll/setsockopt
DynamicLoader: WS2_32.dll/recv
DynamicLoader: CRYPTSP.dll/CryptAcquireContextA
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: CRYPTSP.dll/CryptImportKey
DynamicLoader: CRYPTSP.dll/CryptExportKey
DynamicLoader: CRYPTSP.dll/CryptDestroyKey
DynamicLoader: KERNEL32.dll/CreateDirectory
DynamicLoader: KERNEL32.dll/CreateDirectoryW
DynamicLoader: KERNEL32.dll/CopyFile
DynamicLoader: KERNEL32.dll/CopyFileW
DynamicLoader: KERNEL32.dll/SetFileAttributes
DynamicLoader: KERNEL32.dll/SetFileAttributesW
DynamicLoader: ADVAPI32.dll/RegSetValueEx
DynamicLoader: ADVAPI32.dll/RegSetValueExW
DynamicLoader: KERNEL32.dll/DeleteFile
DynamicLoader: KERNEL32.dll/DeleteFileW
DynamicLoader: KERNEL32.dll/CloseHandle
DynamicLoader: KERNEL32.dll/GetStartupInfo
DynamicLoader: KERNEL32.dll/GetStartupInfoW
DynamicLoader: KERNEL32.dll/CreateProcess
DynamicLoader: KERNEL32.dll/CreateProcessW
DynamicLoader: USER32.dll/WaitForInputIdle
DynamicLoader: USER32.dll/WaitForInputIdleW
DynamicLoader: ADVAPI32.dll/RegSetValueEx
DynamicLoader: ADVAPI32.dll/RegSetValueExW
DynamicLoader: KERNEL32.dll/EnumCalendarInfoExEx
DynamicLoader: KERNEL32.dll/GetCalendarInfoEx
DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
DynamicLoader: KERNEL32.dll/EnumTimeFormatsEx
DynamicLoader: ADVAPI32.dll/EventRegister
DynamicLoader: KERNEL32.dll/ResolveLocaleName
DynamicLoader: MLANG.dll/
DynamicLoader: WININET.dll/FindFirstUrlCacheEntryA
DynamicLoader: KERNEL32.dll/SetFileInformationByHandle
DynamicLoader: shell32.dll/SHGetFolderPathW
DynamicLoader: vaultcli.dll/VaultEnumerateVaults
DynamicLoader: USER32.dll/GetLastInputInfo
DynamicLoader: clr.dll/CreateAssemblyNameObject
DynamicLoader: clr.dll/CreateAssemblyNameObjectW
DynamicLoader: clr.dll/CreateAssemblyEnum
DynamicLoader: clr.dll/CreateAssemblyEnumW
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
DynamicLoader: KERNEL32.dll/FindFirstFile
DynamicLoader: KERNEL32.dll/FindFirstFileW
DynamicLoader: KERNEL32.dll/FindClose
DynamicLoader: ADVAPI32.dll/RegQueryInfoKey
DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
DynamicLoader: ADVAPI32.dll/RegEnumKeyEx
DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: USER32.dll/GetSystemMetrics
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: KERNEL32.dll/LoadLibrary
DynamicLoader: KERNEL32.dll/LoadLibraryW
DynamicLoader: USER32.dll/GetClientRect
DynamicLoader: USER32.dll/GetWindowRect
DynamicLoader: USER32.dll/GetParent
DynamicLoader: ole32.dll/OleInitialize
DynamicLoader: ole32.dll/CoRegisterMessageFilter
DynamicLoader: USER32.dll/PeekMessage
DynamicLoader: USER32.dll/PeekMessageW
DynamicLoader: USER32.dll/IsWindowUnicode
DynamicLoader: USER32.dll/GetMessageW
DynamicLoader: USER32.dll/TranslateMessage
DynamicLoader: USER32.dll/DispatchMessageW
DynamicLoader: USER32.dll/WaitMessage
DynamicLoader: WS2_32.dll/shutdown
DynamicLoader: kernel32.dll/RegCreateKeyExW
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: wbemsvc.dll/DllGetClassObject
DynamicLoader: wbemsvc.dll/DllCanUnloadNow
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: kernel32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/RegCloseKey
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ADVAPI32.dll/RegOpenKeyW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/GetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/SetThreadPreferredUILanguages
DynamicLoader: kernel32.dll/LocaleNameToLCID
DynamicLoader: kernel32.dll/GetLocaleInfoEx
DynamicLoader: kernel32.dll/LCIDToLocaleName
DynamicLoader: kernel32.dll/GetSystemDefaultLocaleName
DynamicLoader: WMI.DLL/WmiQueryAllDataW
DynamicLoader: WMI.DLL/WmiQuerySingleInstanceW
DynamicLoader: WMI.DLL/WmiSetSingleItemW
DynamicLoader: WMI.DLL/WmiSetSingleInstanceW
DynamicLoader: WMI.DLL/WmiExecuteMethodW
DynamicLoader: WMI.DLL/WmiNotificationRegistrationW
DynamicLoader: WMI.DLL/WmiMofEnumerateResourcesW
DynamicLoader: WMI.DLL/WmiFileHandleToInstanceNameW
DynamicLoader: WMI.DLL/WmiDevInstToInstanceNameW
DynamicLoader: WMI.DLL/WmiQueryGuidInformation
DynamicLoader: WMI.DLL/WmiOpenBlock
DynamicLoader: WMI.DLL/WmiCloseBlock
DynamicLoader: WMI.DLL/WmiFreeBuffer
DynamicLoader: WMI.DLL/WmiEnumerateGuids
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/RegCreateKeyExW
DynamicLoader: kernel32.dll/RegQueryValueExW
DynamicLoader: kernel32.dll/RegCloseKey
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: ntdll.dll/EtwRegisterTraceGuidsW
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: ntmarta.dll/GetMartaExtensionInterface
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
DynamicLoader: CRYPTSP.dll/CryptGenRandom
DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
DynamicLoader: ole32.dll/CoGetClassObject
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/StringFromIID
DynamicLoader: ole32.dll/CoGetPSClsid
DynamicLoader: ole32.dll/CoTaskMemAlloc
DynamicLoader: ole32.dll/CoTaskMemFree
DynamicLoader: ole32.dll/CoCreateInstance
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: ole32.dll/DcomChannelSetHResult
DynamicLoader: ole32.dll/CoGetMarshalSizeMax
DynamicLoader: ole32.dll/CoMarshalInterface
DynamicLoader: ole32.dll/CoUnmarshalInterface
DynamicLoader: ole32.dll/CoReleaseMarshalData
DynamicLoader: wbemsvc.dll/DllGetClassObject
DynamicLoader: wbemsvc.dll/DllCanUnloadNow
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: kernel32.dll/RegOpenKeyExW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: OLEAUT32.dll/
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: OLEAUT32.dll/
DynamicLoader: ntdll.dll/EtwUnregisterTraceGuids
DynamicLoader: ntdll.dll/EtwUnregisterTraceGuids
DynamicLoader: CRYPTSP.dll/CryptReleaseContext
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: CRYPTBASE.dll/SystemFunction036
DynamicLoader: sechost.dll/LookupAccountNameLocalW
DynamicLoader: ADVAPI32.dll/LookupAccountSidW
DynamicLoader: sechost.dll/LookupAccountSidLocalW
DynamicLoader: RPCRT4.dll/UuidFromStringW
DynamicLoader: radarrs.dll/WdiDiagnosticModuleMain
DynamicLoader: radarrs.dll/WdiHandleInstance
DynamicLoader: radarrs.dll/WdiGetDiagnosticModuleInterfaceVersion
DynamicLoader: COMCTL32.dll/LoadIconWithScaleDown
DynamicLoader: ntdll.dll/RtlRunEncodeUnicodeString
DynamicLoader: ntdll.dll/RtlInitUnicodeString
DynamicLoader: ntdll.dll/RtlRunDecodeUnicodeString
DynamicLoader: DUser.dll/InitGadgets
DynamicLoader: USER32.dll/RegisterMessagePumpHook
DynamicLoader: UxTheme.dll/IsThemeActive
DynamicLoader: DUser.dll/CreateGadget
DynamicLoader: DUser.dll/DisableContainerHwnd
DynamicLoader: ole32.dll/CoInitializeEx
DynamicLoader: ole32.dll/CoUninitialize
DynamicLoader: ole32.dll/CoRegisterInitializeSpy
DynamicLoader: ole32.dll/CoRevokeInitializeSpy
DynamicLoader: kernel32.dll/SortGetHandle
DynamicLoader: kernel32.dll/SortCloseHandle
DynamicLoader: OLEAUT32.dll/
DynamicLoader: DUser.dll/DUserFlushMessages
DynamicLoader: DUser.dll/DUserFlushDeferredMessages
DynamicLoader: DUser.dll/DeleteHandle
DynamicLoader: USER32.dll/UnregisterMessagePumpHook
DynamicLoader: COMCTL32.dll/LoadIconWithScaleDown
DynamicLoader: ntdll.dll/RtlRunEncodeUnicodeString
DynamicLoader: ntdll.dll/RtlInitUnicodeString
DynamicLoader: ntdll.dll/RtlRunDecodeUnicodeString
DynamicLoader: USER32.dll/RegisterMessagePumpHook
DynamicLoader: USER32.dll/UnregisterMessagePumpHook
A process created a hidden window
Process: DOCUMENTS-7821.exe -> schtasks.exe
HTTP traffic contains suspicious features which may be indicative of malware related traffic
get_no_useragent: HTTP traffic contains a GET request with no user-agent header
suspicious_request: http://checkip.amazonaws.com/
Performs some HTTP requests
url: http://checkip.amazonaws.com/
The binary likely contains encrypted or compressed data.
section: name: .text, entropy: 7.90, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x000a5400, virtual_size: 0x000a5244
Looks up the external IP address
domain: checkip.amazonaws.com
Uses Windows utilities for basic functionality
command: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\LIeDXmUzhdkSdI" /XML "C:\Users\user\AppData\Local\Temp\tmpDEAB.tmp"
command: schtasks.exe /Create /TN "Updates\LIeDXmUzhdkSdI" /XML "C:\Users\user\AppData\Local\Temp\tmpDEAB.tmp"
command: REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
Behavioural detection: Injection (Process Hollowing)
Injection: DOCUMENTS-7821.exe(1460) -> DOCUMENTS-7821.exe(2968)
Executed a process and injected code into it, probably while unpacking
Injection: DOCUMENTS-7821.exe(1460) -> DOCUMENTS-7821.exe(2968)
Attempts to remove evidence of file being downloaded from the Internet
file: C:\Users\user\AppData\Roaming\newapp\newapp.exe:Zone.Identifier
Behavioural detection: Injection (inter-process)
Behavioural detection: Injection with CreateRemoteThread in a remote process
Installs itself for autorun at Windows startup
key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\newapp
data: C:\Users\user\AppData\Roaming\newapp\newapp.exe
Creates a hidden or system file
file: C:\Users\user\AppData\Roaming\LIeDXmUzhdkSdI.exe
file: C:\Users\user\AppData\Roaming\newapp\newapp.exe
Checks the CPU name from registry, possibly for anti-virtualization
Creates a copy of itself
copy: C:\Users\user\AppData\Roaming\LIeDXmUzhdkSdI.exe
copy: C:\Users\user\AppData\Roaming\newapp\newapp.exe
Attempts to disable System Restore
Harvests information related to installed mail clients
file: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
key: HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
key: HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
key: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
Collects information to fingerprint the system
Uses suspicious command line tools or Windows utilities
command: REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f

Screenshots


Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
N 34.196.181.158 [VT] United States

DNS

Name Response Post-Analysis Lookup
checkip.amazonaws.com [VT] A 52.55.255.113 [VT]
CNAME checkip.check-ip.aws.a2z.com [VT]
A 52.44.169.135 [VT]
CNAME checkip.us-east-1.prod.check-ip.aws.a2z.com [VT]
A 18.205.71.63 [VT]
A 3.224.145.145 [VT]
A 18.204.189.102 [VT]
A 34.196.181.158 [VT]

Summary

C:\Windows\System32\MSCOREE.DLL.local
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\*
C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe.config
C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR110_CLR0400.dll
C:\Windows\System32\MSVCR110_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\045c9588954c3662d542b53f4462268b\mscorlib.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\045c9588954c3662d542b53f4462268b\mscorlib.ni.dll.aux
C:\Users
C:\Users\user
C:\Users\user\AppData
C:\Users\user\AppData\Local
C:\Users\user\AppData\Local\Temp
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll
\Device\KsecDD
C:\Windows\assembly\NativeImages_v4.0.30319_32\KHGX\*
C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.INI
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\GAC\PublisherPolicy.tme
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\05ca0ca95b6fcc0d710b63b6200cc178\System.Windows.Forms.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\05ca0ca95b6fcc0d710b63b6200cc178\System.Windows.Forms.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c4477b3ce64d0d612d1ab0dba425b77f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c4477b3ce64d0d612d1ab0dba425b77f\System.Drawing.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\79f6324a598a7c4446a4a1168be7c4b1\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\79f6324a598a7c4446a4a1168be7c4b1\System.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\uxtheme.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\ahronbd.ttf
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\65f7c6dcc498c7157f0ef5b72824d60a\Microsoft.VisualBasic.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\65f7c6dcc498c7157f0ef5b72824d60a\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\4e69f1e7d86d79012db2d7e0dadc8880\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\4e69f1e7d86d79012db2d7e0dadc8880\System.Core.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
C:\Users\user\AppData\Local\Temp\en-US\KHGX.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\KHGX.resources\KHGX.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\KHGX.resources.exe
C:\Users\user\AppData\Local\Temp\en-US\KHGX.resources\KHGX.resources.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\en-US\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\en\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\en\mscorrc.dll.DLL
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Users\user\AppData\Local\Temp\en\KHGX.resources.dll
C:\Users\user\AppData\Local\Temp\en\KHGX.resources\KHGX.resources.dll
C:\Users\user\AppData\Local\Temp\en\KHGX.resources.exe
C:\Users\user\AppData\Local\Temp\en\KHGX.resources\KHGX.resources.exe
C:\Users\user\AppData\Local\Temp\en-US\fHzaVY.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\fHzaVY.resources\fHzaVY.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\fHzaVY.resources.exe
C:\Users\user\AppData\Local\Temp\en-US\fHzaVY.resources\fHzaVY.resources.exe
C:\Users\user\AppData\Local\Temp\en\fHzaVY.resources.dll
C:\Users\user\AppData\Local\Temp\en\fHzaVY.resources\fHzaVY.resources.dll
C:\Users\user\AppData\Local\Temp\en\fHzaVY.resources.exe
C:\Users\user\AppData\Local\Temp\en\fHzaVY.resources\fHzaVY.resources.exe
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll
C:\Users\user\AppData\Roaming\LIeDXmUzhdkSdI.exe
C:\Users\user\AppData\Roaming\
C:\Users\user\AppData\Local\Temp\tmpDEAB.tmp
\??\MountPointManager
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\psapi.dll
C:\Windows\sysnative\Tasks
C:\Windows\sysnative\Tasks\*
C:\Windows\sysnative\Tasks\Updates\LIeDXmUzhdkSdI
C:\Windows\sysnative\Tasks\Updates
C:\Windows\sysnative\Tasks\Updates\
C:\Windows\SysWOW64\net1.exe
C:\Windows
C:\Windows\SysWOW64\net.exe
C:\Windows\SysWOW64
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\SysWOW64\*.*
C:\Windows\SysWOW64\ui\SwDRM.dll
C:\Windows\Temp\fwtsqmfile00.sqm
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\en-US\sc.exe.mui
C:\Windows\SysWOW64\reg.exe
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\SysWOW64\en-US\reg.exe.mui
C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost
\Device\LanmanDatagramReceiver
C:\Windows\assembly\NativeImages_v4.0.30319_32\FQLQFIXENZV03e8423a#\*
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\bcrypt.dll
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
C:\Windows\Microsoft.NET\Framework\v4.0.30319\OLEAUT32.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\509f36ec564b9ad2bb2ffda3d4a3b5fc\CustomMarshalers.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\509f36ec564b9ad2bb2ffda3d4a3b5fc\CustomMarshalers.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll.config
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\13f5eb7285c90c219d2be24eebb55cd9\System.Management.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\13f5eb7285c90c219d2be24eebb55cd9\System.Management.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\oleaut32.dll
C:\Windows\System32\tzres.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll
C:\Windows\System32\en-US\tzres.dll.mui
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\1f56d5786274992934de0c900431c447\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\1f56d5786274992934de0c900431c447\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\*
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d91f3556f8011a5d48e1448e3fa8df9e\System.Xml.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d91f3556f8011a5d48e1448e3fa8df9e\System.Xml.ni.dll.aux
C:\Windows\Microsoft.Net\assembly\GAC_32\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\rasapi32.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ws2_32.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\winhttp.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\iphlpapi.dll
C:\Users\user\AppData\Roaming\newapp\
C:\Users\user\AppData\Roaming\newapp
C:\Users\user\AppData\Roaming
C:\Users\user\AppData\Roaming\newapp\newapp.exe
C:\Users\user\AppData\Roaming\newapp\newapp.exe:Zone.Identifier
C:\Users\user\AppData\Local\Google\Chrome\User Data\
C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\user\AppData\Local\Temp\en-US\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.dll
C:\Users\user\AppData\Local\Temp\en-US\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.exe
C:\Users\user\AppData\Local\Temp\en-US\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.exe
C:\Users\user\AppData\Local\Temp\en\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.dll
C:\Users\user\AppData\Local\Temp\en\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.dll
C:\Users\user\AppData\Local\Temp\en\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.exe
C:\Users\user\AppData\Local\Temp\en\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources\FQLQFIXENZVOKEBENBWPYIMKXLWZNMKPNSSTLUOS_20190716182041964.resources.exe
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\user\AppData\Local\Microsoft\Windows\History
C:\Users\user\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\user\AppData\Local\Temp\vaultcli.dll
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\plutil.exe
C:\Users\user\AppData\Local\Tencent\QQBrowser\User Data
C:\Users\user\AppData\Local\Tencent\QQBrowser\User Data\Default\EncryptedStorage
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\user\AppData\Local\Yandex\YandexBrowser\User Data
C:\Users\user\AppData\Local\360Chrome\Chrome\User Data
C:\Users\user\AppData\Local\Iridium\User Data
C:\Users\user\AppData\Local\Comodo\Dragon\User Data
C:\Users\user\AppData\Local\MapleStudio\ChromePlus\User Data
C:\Users\user\AppData\Local\Chromium\User Data
C:\Users\user\AppData\Local\Torch\User Data
C:\Users\user\AppData\Local\7Star\7Star\User Data
C:\Users\user\AppData\Local\Amigo\User Data
C:\Users\user\AppData\Local\BraveSoftware\Brave-Browser\User Data
C:\Users\user\AppData\Local\CentBrowser\User Data
C:\Users\user\AppData\Local\Chedot\User Data
C:\Users\user\AppData\Local\CocCoc\Browser\User Data
C:\Users\user\AppData\Local\Elements Browser\User Data
C:\Users\user\AppData\Local\Epic Privacy Browser\User Data
C:\Users\user\AppData\Local\Kometa\User Data
C:\Users\user\AppData\Local\Orbitum\User Data
C:\Users\user\AppData\Local\Sputnik\Sputnik\User Data
C:\Users\user\AppData\Local\uCozMedia\Uran\User Data
C:\Users\user\AppData\Local\Vivaldi\User Data
C:\Users\user\AppData\Local\CatalinaGroup\Citrio\User Data
C:\Users\user\AppData\Local\liebao\User Data
C:\Users\user\AppData\Local\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer
C:\Users\user\AppData\Local\QIP Surf\User Data
C:\Users\user\AppData\Local\Coowon\Coowon\User Data
C:\Users\user\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\user\AppData\Roaming\Flock\Browser\profiles.ini
C:\Windows\assembly\GAC_64
C:\Windows\assembly\GAC_64\Microsoft.VisualBasic.resources
C:\Windows\assembly\GAC_32
C:\Windows\assembly\GAC_32\Microsoft.VisualBasic.resources
C:\Windows\assembly\GAC_MSIL
C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.resources
C:\Windows\assembly\GAC
C:\Windows\assembly\GAC\Microsoft.VisualBasic.resources
C:\Windows\Microsoft.Net\assembly\GAC_64
C:\Windows\Microsoft.Net\assembly\GAC_64\Microsoft.VisualBasic.resources
C:\Windows\Microsoft.Net\assembly\GAC_32
C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic.resources
C:\Windows\Microsoft.Net\assembly\GAC_MSIL
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic.resources
C:\Windows\Microsoft.Net\assembly\GAC
C:\Users\user\AppData\Local\UCBrowser\*
C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini
C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini
C:\Users\user\AppData\Roaming\K-Meleon\profiles.ini
C:\Users\user\AppData\Roaming\Mozilla\icecat\profiles.ini
C:\Users\user\AppData\Roaming\Comodo\IceDragon\profiles.ini
C:\Users\user\AppData\Roaming\Moonchild Productions\Pale Moon\profiles.ini
C:\Users\user\AppData\Roaming\Waterfox\profiles.ini
C:\Users\user\AppData\Local\falkon\profiles\profiles.ini
C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
C:\Storage\
C:\mail\
C:\Users\user\AppData\Local\VirtualStore\Program Files\Foxmail\mail\
C:\Users\user\AppData\Local\VirtualStore\Program Files (x86)\Foxmail\mail\
C:\Users\user\AppData\Roaming\Opera Mail\Opera Mail\wand.dat
C:\Users\user\AppData\Roaming\Pocomail\accounts.ini
C:\Users\user\AppData\Roaming\The Bat!
C:\Users\user\AppData\Roaming\Postbox\profiles.ini
C:\Users\user\AppData\Roaming\Claws-mail
C:\Users\user\AppData\Roaming\Claws-mail\clawsrc
C:\Users\user\AppData\Local\Temp\Folder.lst
C:\Users\user\AppData\Roaming\Trillian\users\global\accounts.dat
C:\Users\user\AppData\Local\Google\Chrome\User Data
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable
C:\Users\user\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer
C:\Users\user\AppData\Local\UCBrowser\
C:\Users\user\AppData\Roaming\Mozilla\Firefox\
C:\Users\user\AppData\Roaming\Postbox\
C:\Users\user\AppData\Roaming\Thunderbird\
C:\Users\user\AppData\Roaming\Mozilla\SeaMonkey\
C:\Users\user\AppData\Roaming\Flock\Browser\
C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\
C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\
C:\Users\user\AppData\Roaming\K-Meleon\
C:\Users\user\AppData\Roaming\Mozilla\icecat\
C:\Users\user\AppData\Roaming\Moonchild Productions\Pale Moon\
C:\Users\user\AppData\Roaming\Comodo\IceDragon\
C:\Users\user\AppData\Roaming\Waterfox\
C:\Users\user\AppData\Roaming\tp1lvg4l.r4q.zip
C:\Users\user\AppData\Roaming\tp1lvg4l.r4q\*
C:\Windows\sysnative\cscsvc.dll
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\discache.sys
C:\Windows\sysnative\drivers\en-US\discache.sys.mui
C:\Windows\sysnative\drivers\en\discache.sys.mui
C:\Windows\sysnative\drivers\netbt.sys
C:\Windows\sysnative\drivers\en-US\netbt.sys.mui
C:\Windows\sysnative\drivers\en\netbt.sys.mui
C:\Windows\sysnative\vmstorfltres.dll
C:\Windows\sysnative\tcpipcfg.dll
C:\Windows\sysnative\en-US\tcpipcfg.dll.mui
C:\Windows\sysnative\drivers\fvevol.sys
C:\Windows\sysnative\drivers\en-US\fvevol.sys.mui
C:\Windows\sysnative\drivers\nsiproxy.sys
C:\Windows\sysnative\drivers\en-US\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\en\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\http.sys
C:\Windows\sysnative\drivers\en-US\http.sys.mui
C:\Windows\sysnative\drivers\hwpolicy.sys
C:\Windows\sysnative\drivers\en-US\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\en\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\tssecsrv.sys
C:\Windows\sysnative\drivers\en-US\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\en\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\pacer.sys
C:\Windows\sysnative\drivers\en-US\pacer.sys.mui
C:\Windows\sysnative\drivers\mountmgr.sys
C:\Windows\sysnative\drivers\en-US\mountmgr.sys.mui
C:\Windows\sysnative\drivers\RDPCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\volmgrx.sys
C:\Windows\sysnative\drivers\en-US\volmgrx.sys.mui
C:\Windows\sysnative\drivers\afd.sys
C:\Windows\sysnative\drivers\en-US\afd.sys.mui
C:\Windows\sysnative\FirewallAPI.dll
C:\Windows\sysnative\en-US\FirewallAPI.dll.mui
C:\Windows\sysnative\drivers\RDPENCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPENCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPENCDD.sys.mui
C:\Windows\sysnative\rascfg.dll
C:\Windows\sysnative\en-US\rascfg.dll.mui
C:\Windows\sysnative\drivers\RDPREFMP.sys
C:\Windows\sysnative\drivers\en-US\RdpRefMp.sys.mui
C:\Windows\sysnative\drivers\en\RdpRefMp.sys.mui
C:\Windows\sysnative\clfs.sys
C:\Windows\sysnative\en-US\clfs.sys.mui
C:\Windows\sysnative\wbem\Logs\
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
C:\Windows\Temp
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48
C:\Windows\sysnative\en-US\radarrs.dll.mui
C:\Windows\sysnative\radarrs.dll
C:\Windows\sysnative\en-US\MSCTF.dll.mui
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe.config
C:\Users\user\AppData\Local\Temp\DOCUMENTS-7821.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
C:\Windows\System32\MSVCR110_CLR0400.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\045c9588954c3662d542b53f4462268b\mscorlib.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\045c9588954c3662d542b53f4462268b\mscorlib.ni.dll
\Device\KsecDD
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
C:\Windows\assembly\pubpol23.dat
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\05ca0ca95b6fcc0d710b63b6200cc178\System.Windows.Forms.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c4477b3ce64d0d612d1ab0dba425b77f\System.Drawing.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\79f6324a598a7c4446a4a1168be7c4b1\System.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System\79f6324a598a7c4446a4a1168be7c4b1\System.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c4477b3ce64d0d612d1ab0dba425b77f\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\05ca0ca95b6fcc0d710b63b6200cc178\System.Windows.Forms.ni.dll
C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Windows\Fonts\segoeui.ttf
C:\Windows\Fonts\segoeuib.ttf
C:\Windows\Fonts\segoeuii.ttf
C:\Windows\Fonts\segoeuiz.ttf
C:\Windows\Fonts\staticcache.dat
C:\Windows\Fonts\tahoma.ttf
C:\Windows\Fonts\msjh.ttf
C:\Windows\Fonts\msyh.ttf
C:\Windows\Fonts\malgun.ttf
C:\Windows\Fonts\micross.ttf
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\65f7c6dcc498c7157f0ef5b72824d60a\Microsoft.VisualBasic.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\4e69f1e7d86d79012db2d7e0dadc8880\System.Core.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\4e69f1e7d86d79012db2d7e0dadc8880\System.Core.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\65f7c6dcc498c7157f0ef5b72824d60a\Microsoft.VisualBasic.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
C:\Users\user\AppData\Local\Temp\tmpDEAB.tmp
C:\Windows\SysWOW64\net1.exe
C:\Windows\SysWOW64\net.exe
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\SysWOW64\
C:\Windows\Temp\fwtsqmfile00.sqm
C:\Windows\SysWOW64\sc.exe
C:\Windows\SysWOW64\en-US\sc.exe.mui
C:\Windows\SysWOW64\reg.exe
C:\Windows\appcompat\Programs\RecentFileCache.bcf
C:\Windows\SysWOW64\en-US\reg.exe.mui
C:\Windows\sysnative\Tasks\Microsoft\Windows\WDI\ResolutionHost
\Device\LanmanDatagramReceiver
C:\Windows\System32\wbem\wbemdisp.tlb
C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\509f36ec564b9ad2bb2ffda3d4a3b5fc\CustomMarshalers.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\509f36ec564b9ad2bb2ffda3d4a3b5fc\CustomMarshalers.ni.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
C:\Windows\Microsoft.Net\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll.config
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\13f5eb7285c90c219d2be24eebb55cd9\System.Management.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\13f5eb7285c90c219d2be24eebb55cd9\System.Management.ni.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\wminet_utils.dll
C:\Windows\System32\tzres.dll
C:\Windows\System32\en-US\tzres.dll.mui
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\1f56d5786274992934de0c900431c447\System.Configuration.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\1f56d5786274992934de0c900431c447\System.Configuration.ni.dll
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d91f3556f8011a5d48e1448e3fa8df9e\System.Xml.ni.dll.aux
C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d91f3556f8011a5d48e1448e3fa8df9e\System.Xml.ni.dll
C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\user\AppData\Roaming\Mozilla\SeaMonkey\profiles.ini
C:\Users\user\AppData\Roaming\Flock\Browser\profiles.ini
C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini
C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini
C:\Users\user\AppData\Roaming\K-Meleon\profiles.ini
C:\Users\user\AppData\Roaming\Mozilla\icecat\profiles.ini
C:\Users\user\AppData\Roaming\Comodo\IceDragon\profiles.ini
C:\Users\user\AppData\Roaming\Moonchild Productions\Pale Moon\profiles.ini
C:\Users\user\AppData\Roaming\Waterfox\profiles.ini
C:\Users\user\AppData\Local\falkon\profiles\profiles.ini
C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
C:\Users\user\AppData\Roaming\Postbox\profiles.ini
C:\Users\user\AppData\Roaming\tp1lvg4l.r4q.zip
C:\Windows\sysnative\cscsvc.dll
C:\Windows\sysnative\drivers\ndis.sys
C:\Windows\sysnative\drivers\discache.sys
C:\Windows\sysnative\drivers\en-US\discache.sys.mui
C:\Windows\sysnative\drivers\en\discache.sys.mui
C:\Windows\sysnative\drivers\netbt.sys
C:\Windows\sysnative\drivers\en-US\netbt.sys.mui
C:\Windows\sysnative\drivers\en\netbt.sys.mui
C:\Windows\sysnative\vmstorfltres.dll
C:\Windows\sysnative\tcpipcfg.dll
C:\Windows\sysnative\en-US\tcpipcfg.dll.mui
C:\Windows\sysnative\drivers\fvevol.sys
C:\Windows\sysnative\drivers\en-US\fvevol.sys.mui
C:\Windows\sysnative\drivers\nsiproxy.sys
C:\Windows\sysnative\drivers\en-US\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\en\nsiproxy.sys.mui
C:\Windows\sysnative\drivers\http.sys
C:\Windows\sysnative\drivers\en-US\http.sys.mui
C:\Windows\sysnative\drivers\hwpolicy.sys
C:\Windows\sysnative\drivers\en-US\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\en\hwpolicy.sys.mui
C:\Windows\sysnative\drivers\tssecsrv.sys
C:\Windows\sysnative\drivers\en-US\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\en\tssecsrv.sys.mui
C:\Windows\sysnative\drivers\pacer.sys
C:\Windows\sysnative\drivers\en-US\pacer.sys.mui
C:\Windows\sysnative\drivers\mountmgr.sys
C:\Windows\sysnative\drivers\en-US\mountmgr.sys.mui
C:\Windows\sysnative\drivers\RDPCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPCDD.sys.mui
C:\Windows\sysnative\drivers\volmgrx.sys
C:\Windows\sysnative\drivers\en-US\volmgrx.sys.mui
C:\Windows\sysnative\drivers\afd.sys
C:\Windows\sysnative\drivers\en-US\afd.sys.mui
C:\Windows\sysnative\FirewallAPI.dll
C:\Windows\sysnative\en-US\FirewallAPI.dll.mui
C:\Windows\sysnative\drivers\RDPENCDD.sys
C:\Windows\sysnative\drivers\en-US\RDPENCDD.sys.mui
C:\Windows\sysnative\drivers\en\RDPENCDD.sys.mui
C:\Windows\sysnative\rascfg.dll
C:\Windows\sysnative\en-US\rascfg.dll.mui
C:\Windows\sysnative\drivers\RDPREFMP.sys
C:\Windows\sysnative\drivers\en-US\RdpRefMp.sys.mui
C:\Windows\sysnative\drivers\en\RdpRefMp.sys.mui
C:\Windows\sysnative\clfs.sys
C:\Windows\sysnative\en-US\clfs.sys.mui
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
C:\Windows\sysnative\en-US\radarrs.dll.mui
C:\Windows\sysnative\radarrs.dll
C:\Windows\sysnative\en-US\MSCTF.dll.mui
C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
C:\Users\user\AppData\Roaming\LIeDXmUzhdkSdI.exe
C:\Users\user\AppData\Local\Temp\tmpDEAB.tmp
C:\Windows\Temp\fwtsqmfile00.sqm
C:\Windows\appcompat\Programs\RecentFileCache.bcf
\Device\LanmanDatagramReceiver
C:\Users\user\AppData\Roaming\newapp\newapp.exe
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\user\AppData\Roaming\tp1lvg4l.r4q.zip
\??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
\??\WMIDataDevice
C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48
C:\Users\user\AppData\Local\Temp\tmpDEAB.tmp
C:\Users\user\AppData\Roaming\newapp\newapp.exe:Zone.Identifier
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DOCUMENTS-7821.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_CURRENT_USER\Software\Microsoft\Fusion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-GB
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-GB
HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000809
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
\xe8\x81\xa8\xca\xa7EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKEY_CURRENT_USER\EUDC\1252
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-120665959-548228820-2376508522-1001\Installer\Assemblies\C:|Users|user|AppData|Local|Temp|DOCUMENTS-7821.exe
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|user|AppData|Local|Temp|DOCUMENTS-7821.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|user|AppData|Local|Temp|DOCUMENTS-7821.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-120665959-548228820-2376508522-1001\Installer\Assemblies\Global
HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3abfb8f2-2ffd-11e7-a4cf-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3abfb8f2-2ffd-11e7-a4cf-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3abfb8f2-2ffd-11e7-a4cf-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cc-b5ba-11e3-a2f5-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cc-b5ba-11e3-a2f5-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cc-b5ba-11e3-a2f5-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cd-b5ba-11e3-a2f5-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cd-b5ba-11e3-a2f5-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cd-b5ba-11e3-a2f5-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\AppID\DOCUMENTS-7821.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\BBB39CA1
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
DisableUserModeCallbackFilter
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_CURRENT_USER\Software\Classes\AppID\schtasks.exe
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Control Panel\International
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updates\LIeDXmUzhdkSdI
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\svchost.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF5B78E8-1581-4B10-B0CE-1363D82E22C9}\Path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF5B78E8-1581-4B10-B0CE-1363D82E22C9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updates\LIeDXmUzhdkSdI\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updates\LIeDXmUzhdkSdI\Index
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF5B78E8-1581-4B10-B0CE-1363D82E22C9}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF5B78E8-1581-4B10-B0CE-1363D82E22C9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF5B78E8-1581-4B10-B0CE-1363D82E22C9}\DynamicInfo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\net1.exe
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PreviousServiceShutdown
HKEY_LOCAL_MACHINE\system\Setup
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\winmgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sc.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\reg.exe
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Triggers
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-120665959-548228820-2376508522-1001
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
\xe6\xa9\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_CURRENT_USER\Software\Classes\WinMgmts
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\InprocServer32
HKEY_CLASSES_ROOT\CLSID\{62E522DC-8CF3-40A8-8B2E-37D595651E40}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\409
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\9
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\InprocServer32
HKEY_CLASSES_ROOT\CLSID\{04B83D61-21AE-11D2-8B33-00600806D9B6}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\809
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.CustomMarshalers__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.CustomMarshalers__b03f5f7f11d50a3a
HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\InprocServer32
HKEY_CLASSES_ROOT\CLSID\{D6BDAFB2-9435-491F-BB87-6AA0F0BC31A2}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a
HKEY_CLASSES_ROOT\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\Dynamic DST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data.SqlXml__b77a5c561934e089
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\FileDirectory
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\EnableFileTracing
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\FileTracingMask
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\EnableConsoleTracing
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\ConsoleTracingMask
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\MaxFileSize
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\FileDirectory
HKEY_CURRENT_USER
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-0c-29-f8-d7-43
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DhcpDomain
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963}
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\newapp
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR
HKEY_CURRENT_USER\Software\Policies\Microsoft\Control Panel\International\Calendars\TwoDigitYearMax
HKEY_CURRENT_USER\Control Panel\International\Calendars\TwoDigitYearMax
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-SA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-SA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bg-BG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bg-BG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ca-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ca-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cs-CZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cs-CZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\da
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\da
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\da-DK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\da-DK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\el
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\el
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\el-GR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\el-GR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fi-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fi-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\he
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\he
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\he-IL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\he-IL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hu-HU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hu-HU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\is
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\is
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\is-IS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\is-IS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ja
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ja
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ja-JP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ja-JP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ko
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ko
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ko-KR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ko-KR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nl-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nl-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\no
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\no
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nb-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nb-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pl-PL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pl-PL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pt-BR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pt-BR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rm-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rm-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ro
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ro
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ro-RO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ro-RO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ru
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ru
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ru-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ru-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hr-HR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hr-HR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sk-SK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sk-SK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sq-AL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sq-AL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sv-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sv-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\th
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\th
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\th-TH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\th-TH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tr-TR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tr-TR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ur
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ur
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ur-PK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ur-PK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\id
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\id
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\id-ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\id-ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uk-UA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uk-UA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\be
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\be
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\be-BY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\be-BY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sl-SI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sl-SI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\et
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\et
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\et-EE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\et-EE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lv-LV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lv-LV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lt-LT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lt-LT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tg-Cyrl-TJ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tg-Cyrl-TJ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fa-IR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fa-IR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\vi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\vi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\vi-VN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\vi-VN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hy-AM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hy-AM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Latn-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Latn-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\eu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\eu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\eu-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\eu-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mk-MK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mk-MK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tn-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tn-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\xh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\xh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\xh-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\xh-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zu-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zu-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\af
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\af
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\af-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\af-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ka
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ka
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ka-GE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ka-GE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fo-FO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fo-FO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hi-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hi-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mt-MT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mt-MT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ga
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ga
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ga-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ga-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ms-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ms-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kk-KZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kk-KZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ky
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ky
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ky-KG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ky-KG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sw-KE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sw-KE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tk-TM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tk-TM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Latn-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Latn-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tt-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tt-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gu-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gu-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\or
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\or
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\or-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\or-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ta
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ta
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ta-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ta-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\te
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\te
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\te-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\te-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ml
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ml
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ml-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ml-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\as
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\as
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\as-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\as-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mr-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mr-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-MN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-MN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bo-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bo-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cy-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cy-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\km
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\km
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\km-KH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\km-KH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lo-LA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lo-LA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gl-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gl-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kok
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kok
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kok-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kok-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\syr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\syr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\syr-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\syr-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\si
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\si
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\si-LK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\si-LK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Latn-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Latn-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\am
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\am
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\am-ET
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\am-ET
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tzm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tzm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tzm-Latn-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tzm-Latn-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ne
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ne
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ne-NP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ne-NP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fy-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fy-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ps
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ps
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ps-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ps-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fil
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fil
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fil-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fil-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dv-MV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dv-MV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ha
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ha
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ha-Latn-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ha-Latn-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\yo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\yo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\yo-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\yo-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nso
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nso
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nso-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nso-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ba
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ba
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ba-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ba-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lb-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lb-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kl-GL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kl-GL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ig-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ig-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ii
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ii
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ii-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ii-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\arn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\arn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\arn-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\arn-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\moh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\moh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\moh-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\moh-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\br
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\br
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\br-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\br-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ug
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ug
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ug-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ug-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mi-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mi-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\oc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oc-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\oc-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\co
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\co
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\co-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\co-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gsw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gsw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gsw-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gsw-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sah
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sah
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sah-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sah-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qut
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qut
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qut-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qut-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rw-RW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rw-RW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wo-SN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wo-SN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\prs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\prs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\prs-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\prs-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gd-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gd-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-TW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-TW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-ES_tradnl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-ES_tradnl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Cans-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Cans-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qps-ploc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qps-ploc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000501
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts\00000501
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qps-ploca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qps-ploca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\000005FE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts\000005FE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-IQ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-IQ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-MX
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-MX
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nl-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nl-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nn-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nn-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pt-PT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pt-PT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sv-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sv-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Cyrl-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Cyrl-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ms-BN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ms-BN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Cyrl-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Cyrl-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bn-BD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bn-BD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-Mong-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-Mong-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qps-plocm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qps-plocm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\000009FF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts\000009FF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-EG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-EG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-HK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-HK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-AT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-AT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-AU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-AU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-LY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-LY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hr-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hr-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smj-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smj-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-MO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-MO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-LI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-LI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-CR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-CR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smj-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smj-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-MA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-MA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-MC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-MC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sma-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sma-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-TN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-TN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-DO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-DO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sma-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sma-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-OM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-OM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-JM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-JM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-VE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-VE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sms-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sms-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-YE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-YE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-029
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-029
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-CO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-CO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smn-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smn-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-BZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-BZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-JO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-JO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-TT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-TT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-AR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-AR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-LB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-LB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-ZW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-ZW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-KW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-KW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-AE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-AE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-UY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-UY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-BH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-BH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-QA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-QA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-SV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-SV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-HN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-HN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-NI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-NI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sma
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sma
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Cans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Cans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hant
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hant
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tg-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tg-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-Mong
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-Mong
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tzm-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tzm-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ha-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ha-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\(Default)
HKEY_CLASSES_ROOT\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\Software\Policies
HKEY_CURRENT_USER\Software\Policies
HKEY_CURRENT_USER\Software
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
\xe4\x90\x88\xca\x89EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
\xe4\x90\x88\xca\x89EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
\xe4\x90\x88\xca\x89EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions
HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002\SMTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\Email
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\IMAP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\HTTP Password
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\SMTP Password
HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1
HKEY_CURRENT_USER\Software\IncrediMail\Identities
HKEY_CURRENT_USER\Software\Qualcomm\Eudora\CommandLine
HKEY_CURRENT_USER\Software\RimArts\B2\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ServiceParameters
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RunAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ActivateAtStorage
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\ROTFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AppIDFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LaunchPermission
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\LegacyImpersonationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\AuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\RemoteServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\SRPTrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\PreferredServerBitness
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LoadUserSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVMware_Virtual_SATA_Hard_Drive__________00000001#6&158e87a7&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\#
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVMware_Virtual_SATA_Hard_Drive__________00000001#6&158e87a7&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\##?#IDE#DiskVMware_Virtual_SATA_Hard_Drive__________00000001#6&158e87a7&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\DeviceInstance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses\{53f56307-b6bf-11d0-94f2-00a0c91efb8b}\Properties
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\Class
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003\6&B77DA92&0&1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CNG\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0303\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&17\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07E0&SUBSYS_07E015AD&REV_00\4&3AD87E0A&0&2088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MSISADRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MSSMBIOS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SECDRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CSC\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT6\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_00\7&2A7D3009&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_AGILEVPNMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&18\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000000100000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_SPLDR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0800\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDIS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&5\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_1977&SUBSYS_197715AD&REV_09\4&3AD87E0A&0&2888\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_L2TPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_DISCACHE\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&19\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7110&SUBSYS_197615AD&REV_08\3&2B8E0B4B&0&38\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT7\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0003&MI_01\7&2A7D3009&0&0001\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NDPROXY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_94_-_INTEL(R)_XEON(R)_CPU_E3-1270_V5_@_3.60GHZ\_0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANBH\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A03\2&DABA3FF&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&6\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_00\8&17BE0303&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUME\{FF79F28C-2FFB-11E7-A8F3-806E6F6E6963}#0000000006500000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AA\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BA\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT8\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0A05\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{EEAB7790-C514-11D1-B42B-00805FC1270E}\ASYNCMAC\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&7\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NETBT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&20\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\ACPI0003\1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_NDISWANIPV6\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_STORFLT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\4&C5D1198&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0B00\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\VID_0E0F&PID_0003&MI_01\8&2F818F48&0&0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\FIXEDBUTTON\2&DABA3FF&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT12
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HarddiskVolumeSnapshot12\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&8\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPPOEMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT9\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_FVEVOL\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2B8E0B4B&0&78
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2b8e0b4b&0&78\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2b8e0b4b&0&78\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2b8e0b4b&0&78\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2b8e0b4b&0&78\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2b8e0b4b&0&78\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&2b8e0b4b&0&78\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&21\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AB\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\1F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BB\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_94_-_INTEL(R)_XEON(R)_CPU_E3-1270_V5_@_3.60GHZ\_1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\GenuineIntel_-_Intel64_Family_6_Model_94_-_Intel(R)_Xeon(R)_CPU_E3-1270_v5_@_3.60GHz\_1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NSIPROXY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\4&3AD87E0A&0&0888\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&39\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TCPIPREG\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0C02\4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HTTP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_PPTPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&9\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&22\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT13\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_HWPOLICY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDTCP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\MS_SSTPMINIPORT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT10\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&2B8E0B4B&0&3F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_NULL\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*6TO4MP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\VMW0003\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&23\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BC\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TDX\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECDD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&10\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDPBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7190&SUBSYS_197615AD&REV_01\3&2B8E0B4B&0&00\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\CDROMNECVMWAR_VMWARE_SATA_CD01_______________1.00____\6&2848384C&0&1.0.0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\*ISATAP\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PCW\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI_HAL\PNP0C08\0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_TSSECSRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_KBD\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_KSECPKG\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\ACPI_HAL\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT11\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&24\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PEAUTH\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&11\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\DEFAULT_MONITOR\4&10C2E2D6&0&12345678&00&0F\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\RDP_MOU\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0770&SUBSYS_077015AD&REV_00\4&3AD87E0A&0&1088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\BLBDRIVE\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_LLTDIO\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\UMB\UMB\1&841921D&0&PRINTERBUSENUMERATOR\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AD\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0001\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BD\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_PSCHED\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\SYSTEM\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&25\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_8086&DEV_7191&SUBSYS_00000000&REV_01\3&2B8E0B4B&0&08\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITEBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&12\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\UMBUS\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\COMPOSITE_BATTERY\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VGASAVE\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VDRVROOT\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&26\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MOUNTMGR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&13\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0100\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPCDD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0774&SUBSYS_197615AD&REV_00\4&3AD87E0A&0&0088\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AE\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BE\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\VOLMGR\0000\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C6\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB\5&3BB57B&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLMGRX\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_AFD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT3\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_MPSDRV\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&27\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0103\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPDR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&14\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_BEEP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_VOLSNAP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPENCDD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&28\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT4\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&15\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_0790&SUBSYS_079015AD&REV_02\3&2B8E0B4B&0&88\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\ROOT_HUB20\5&6106580&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&AF\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WANARPV6\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&BF\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&C7\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPREFMP\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0200\4&205AD762&0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HDAUDIO\FUNC_01&VEN_15AD&DEV_1975&SUBSYS_15AD1975&REV_1001\5&1D3E533D&0&0001\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&29\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USB\VID_0E0F&PID_0002\6&B77DA92&0&2\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WDF01000\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&16\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RDPWD\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_CLFS\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT5\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_WFPLWF\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&A8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\IDE\DISKVMWARE_VIRTUAL_SATA_HARD_DRIVE__________00000001\6&158E87A7&0&0.0.0\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\ForcedConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&3\LogConf\BootConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B0\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ROOT\LEGACY_RSPNDR\0000\LogConf
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\DeviceDesc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\FriendlyName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Capabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\ConfigFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCI\VEN_15AD&DEV_07A0&SUBSYS_07A015AD&REV_01\3&2B8E0B4B&0&B8\Control\AllocConfig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&0\LocationInformation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\PCIIDE\IDECHANNEL\5&12368B4A&0&1\LocationInformation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnablePrivateObjectHeap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ContextLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ObjectLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Sink Transmit Buffer Size
HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Cimom
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\DefaultRpcStackSize
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wmiprvse.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\6A7AE7C1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B7B31DF9-D515-11D3-A11C-00105A1F515A}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{07435309-D440-41B7-83F3-EB82DB6C622F}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21CD80A2-B305-4F37-9D4C-4534A8D9B568}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{06413D98-405C-4A5A-8D6F-19B8B7C6ACF7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_CURRENT_USER\Control Panel\International\LocaleName
HKEY_CURRENT_USER\Control Panel\International\sCountry
HKEY_CURRENT_USER\Control Panel\International\sList
HKEY_CURRENT_USER\Control Panel\International\sDecimal
HKEY_CURRENT_USER\Control Panel\International\sThousand
HKEY_CURRENT_USER\Control Panel\International\sGrouping
HKEY_CURRENT_USER\Control Panel\International\sNativeDigits
HKEY_CURRENT_USER\Control Panel\International\sCurrency
HKEY_CURRENT_USER\Control Panel\International\sMonDecimalSep
HKEY_CURRENT_USER\Control Panel\International\sMonThousandSep
HKEY_CURRENT_USER\Control Panel\International\sMonGrouping
HKEY_CURRENT_USER\Control Panel\International\sPositiveSign
HKEY_CURRENT_USER\Control Panel\International\sNegativeSign
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat
HKEY_CURRENT_USER\Control Panel\International\sShortTime
HKEY_CURRENT_USER\Control Panel\International\s1159
HKEY_CURRENT_USER\Control Panel\International\s2359
HKEY_CURRENT_USER\Control Panel\International\sShortDate
HKEY_CURRENT_USER\Control Panel\International\sLongDate
HKEY_CURRENT_USER\Control Panel\International\iCountry
HKEY_CURRENT_USER\Control Panel\International\iMeasure
HKEY_CURRENT_USER\Control Panel\International\iPaperSize
HKEY_CURRENT_USER\Control Panel\International\iDigits
HKEY_CURRENT_USER\Control Panel\International\iLZero
HKEY_CURRENT_USER\Control Panel\International\iNegNumber
HKEY_CURRENT_USER\Control Panel\International\NumShape
HKEY_CURRENT_USER\Control Panel\International\iCurrDigits
HKEY_CURRENT_USER\Control Panel\International\iCurrency
HKEY_CURRENT_USER\Control Panel\International\iNegCurr
HKEY_CURRENT_USER\Control Panel\International\iCalendarType
HKEY_CURRENT_USER\Control Panel\International\iFirstDayOfWeek
HKEY_CURRENT_USER\Control Panel\International\iFirstWeekOfYear
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\InProcServer32
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{d63a5850-8f16-11cf-9f47-00aa00bf345c}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D63A5850-8F16-11CF-9F47-00AA00BF345C}\AppId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SecuredHostProviders\ROOT\CIMV2:__Win32Provider.Name="CIMWin32"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F50A28CF-5C9C-4F7E-9D80-E25E16E18C59}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6B3FC272-BF37-4968-933A-6DF9222A2607}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0FC8C622-1728-4149-A57F-AD19D0970710}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEC1B0AC-5808-4033-A915-C0185934581E}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EB658B8A-7A64-4DDC-9B8D-A92610DB0206}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7C857801-7381-11CF-884D-00AA004B2E24}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Identifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009
HKEY_PERFORMANCE_TEXT\Counter
HKEY_PERFORMANCE_DATA\238
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\Component Information
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\Identifier
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\InprocHandler
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\(Default)
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\InprocServer32\Synchronization
HKEY_CLASSES_ROOT\CLSID\{D2D588B5-D081-11d0-99E0-00C04FC2F8EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}\AppId
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiSystemHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiSystemHost\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiSystemHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiSystemHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiSystemHost\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-120665959-548228820-2376508522-1001\ProfileImagePath
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Environment
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Volatile Environment
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Volatile Environment\0
HKEY_CURRENT_USER\Software\Classes\AppID\taskhost.exe
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\DiagnosticModules
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{15fba3b8-a37a-4f91-bdba-fbb98fe804bf}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{282396b2-6c46-4d66-b413-70b0445df33c}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{284ddb2f-beea-4c9d-91e8-e3670ed91517}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{3EA6B3DF-393E-41C3-9885-29EC5A701926}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{45DE1EA9-10BC-4f96-9B21-4B6B83DBF476}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{4d21da64-fd02-4b82-a0a5-783266e430ab}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{50e3b0eb-5780-49de-9eb5-8d53a51fd146}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5C85A128-86F7-41a4-B655-BEE3F2ADEF46}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{5EE64AFB-398D-4edb-AF71-3B830219ABF7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{63e0d0f7-ac2f-493b-a7f2-2f3ccdb66fca}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{67f1ec80-6c5b-43bb-860b-d47ae85242b1}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{72dbb5ac-6a91-46e6-885b-d429828bea2e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{7a54f16f-a73a-4258-ba46-a1e998a6aa74}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{85e0acd9-809a-482b-b60b-bcad1f8d0cd7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{88d4896f-f553-446a-9c75-9dec124ff8b7}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8CC29128-0B57-4a2b-A7B9-A74A70BA6FA1}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{8d39bd5b-81f8-4b94-a608-6a50bbff5d15}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{95c162b7-5b71-44f8-82e4-abfd3108f40f}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{9c5a40da-b965-4fc3-8781-88dd50a6299d}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a0d86e0d-3f06-411b-9dd5-35bc5666ff3e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{a59f0643-a6ca-48e0-a7c4-4cdd258439e2}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{abd0ea66-a840-44a9-97b1-fb74fddaa8c8}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{b171ab1c-60e9-4301-a338-beab1c70b3e9}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{bf2de437-b736-48fb-84a0-5f0c389a068e}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{C0F51D84-11B9-4e74-B083-99F11BA2DB0A}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c70949f5-bda4-4bf3-8121-af0bc174925f}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{c8544339-5be9-4f25-862e-485f1b1a6935}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{d8bcedf8-46c3-440e-bc65-dfa6a5094054}\NameResource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NeverLowerPagePriority
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\DiagnosticModules\{E4CD2E3E-3852-4952-B76B-23BB8E35D344}\NameResource
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\WDI\Config
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WDI\Config\ServerName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\CLResolutionInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\DisplayInterval
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RADAR\SkipWatson
HKEY_LOCAL_MACHINE\Software\Microsoft\RADAR\HeapLeakDetection\Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\Settings\ReflectionInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectUI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\taskhost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\EnableAnchorContext
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-GB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index23
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000809
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger
HKEY_CURRENT_USER\Software\Microsoft\GDIPlus\FontCachePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
\xe8\x81\xa8\xca\xa7EY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3abfb8f2-2ffd-11e7-a4cf-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3abfb8f2-2ffd-11e7-a4cf-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cc-b5ba-11e3-a2f5-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cc-b5ba-11e3-a2f5-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cd-b5ba-11e3-a2f5-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{5e1375cd-b5ba-11e3-a2f5-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\BBB39CA1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
DisableUserModeCallbackFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\SchedulingEngineKnob
HKEY_USERS\S-1-5-21-120665959-548228820-2376508522-1001\Control Panel\International\LocaleName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF5B78E8-1581-4B10-B0CE-1363D82E22C9}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF5B78E8-1581-4B10-B0CE-1363D82E22C9}\DynamicInfo
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\Parameters\ServiceDllUnloadOnStop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0000000C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\Parameters\ServiceDllUnloadOnStop
HKEY_USERS\.DEFAULT\Control Panel\International\LocaleName
HKEY_USERS\.DEFAULT\Control Panel\International\sCountry
HKEY_USERS\.DEFAULT\Control Panel\International\sList
HKEY_USERS\.DEFAULT\Control Panel\International\sDecimal
HKEY_USERS\.DEFAULT\Control Panel\International\sThousand
HKEY_USERS\.DEFAULT\Control Panel\International\sGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sNativeDigits
HKEY_USERS\.DEFAULT\Control Panel\International\sCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\sMonDecimalSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonThousandSep
HKEY_USERS\.DEFAULT\Control Panel\International\sMonGrouping
HKEY_USERS\.DEFAULT\Control Panel\International\sPositiveSign
HKEY_USERS\.DEFAULT\Control Panel\International\sNegativeSign
HKEY_USERS\.DEFAULT\Control Panel\International\sTimeFormat
HKEY_USERS\.DEFAULT\Control Panel\International\sShortTime
HKEY_USERS\.DEFAULT\Control Panel\International\s1159
HKEY_USERS\.DEFAULT\Control Panel\International\s2359
HKEY_USERS\.DEFAULT\Control Panel\International\sShortDate
HKEY_USERS\.DEFAULT\Control Panel\International\sYearMonth
HKEY_USERS\.DEFAULT\Control Panel\International\sLongDate
HKEY_USERS\.DEFAULT\Control Panel\International\iCountry
HKEY_USERS\.DEFAULT\Control Panel\International\iMeasure
HKEY_USERS\.DEFAULT\Control Panel\International\iPaperSize
HKEY_USERS\.DEFAULT\Control Panel\International\iDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iLZero
HKEY_USERS\.DEFAULT\Control Panel\International\iNegNumber
HKEY_USERS\.DEFAULT\Control Panel\International\NumShape
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrDigits
HKEY_USERS\.DEFAULT\Control Panel\International\iCurrency
HKEY_USERS\.DEFAULT\Control Panel\International\iNegCurr
HKEY_USERS\.DEFAULT\Control Panel\International\iCalendarType
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstDayOfWeek
HKEY_USERS\.DEFAULT\Control Panel\International\iFirstWeekOfYear
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost\Id
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Hash
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}\Triggers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
\xe6\xa9\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\Scripting\Default Namespace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{565783C6-CB41-11D1-8B02-00600806D9B6}\1.2\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\TZI
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\MUI_Display
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\MUI_Std
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time\MUI_Dlt
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallationType
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\EnableConsoleTracing
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\EnableFileTracing
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\FileTracingMask
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\EnableConsoleTracing
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\ConsoleTracingMask
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\MaxFileSize
\xe8\x89\xa0\xca\xa6EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\DOCUMENTS-7821_RASAPI32\FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\LegacyWPADSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UseDomainNameDevolution
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DomainNameDevolutionLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\PrioritizeRecordData
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\AllowUnqualifiedQuery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AppendToMultiLabelName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenBadTlds
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenBadTlds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenUnreachableServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ScreenDefaultServers
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DynamicServerQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\FilterClusterIp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\FilterClusterIp
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\WaitForNameErrorOnAll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseEdns
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseEdns
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsSecureNameQueryFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\EnableDAForAllNetworks
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DirectAccessQueryOrder
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\QueryIpMatching
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\QueryIpMatching
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UseHostsFile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseHostsFile
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AddrConfigControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AddrConfigControl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterPrimaryName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterReverseLookup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableReverseAddressRegistrations
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegisterWanAdapters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DisableWanDynamicUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationTTL
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\UpdateSecurityLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UpdateTopLevelDomainZones
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\RegistrationOverwrite
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheSize
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheSize
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxNegativeCacheTtl
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\AdapterTimeoutLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ServerPriorityTimeLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MaxCachedSockets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MaxCachedSockets
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastResponderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\MulticastSenderMaxTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsTest
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\CacheAllCompartments
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\UseNewRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\ResolverRegistrationOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\DnsQuickQueryTimeouts
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\PrimaryDomainName
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableAdapterDomainNameRegistration
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\AdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\QueryAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DisableAdapterDomainName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationEnabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegisterAdapterName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\RegistrationMaxAddressCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\MaxNumberOfAddressesToRegister
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\Domain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{6AEE89DD-BCBC-4329-B07B-C7EEC7EFD7EC}\DhcpDomain
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\SearchList
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\NodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpNodeType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\ScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\DhcpScopeId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableProxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT\Parameters\EnableDns
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\newapp
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR
HKEY_CURRENT_USER\Control Panel\International\sYearMonth
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-SA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-SA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bg-BG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bg-BG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ca-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ca-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cs-CZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cs-CZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\da
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\da
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\da-DK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\da-DK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\el
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\el
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\el-GR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\el-GR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fi-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fi-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\he
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\he
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\he-IL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\he-IL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hu-HU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hu-HU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\is
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\is
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\is-IS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\is-IS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ja
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ja
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ja-JP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ja-JP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ko
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ko
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ko-KR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ko-KR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nl-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nl-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\no
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\no
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nb-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nb-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pl-PL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pl-PL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pt-BR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pt-BR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rm-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rm-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ro
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ro
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ro-RO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ro-RO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ru
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ru
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ru-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ru-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hr-HR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hr-HR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sk-SK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sk-SK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sq
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sq-AL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sq-AL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sv-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sv-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\th
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\th
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\th-TH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\th-TH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tr-TR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tr-TR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ur
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ur
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ur-PK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ur-PK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\id
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\id
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\id-ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\id-ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uk-UA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uk-UA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\be
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\be
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\be-BY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\be-BY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sl-SI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sl-SI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\et
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\et
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\et-EE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\et-EE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lv-LV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lv-LV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lt-LT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lt-LT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tg-Cyrl-TJ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tg-Cyrl-TJ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fa-IR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fa-IR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\vi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\vi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\vi-VN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\vi-VN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hy-AM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hy-AM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Latn-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Latn-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\eu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\eu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\eu-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\eu-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mk-MK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mk-MK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tn-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tn-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\xh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\xh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\xh-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\xh-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zu-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zu-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\af
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\af
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\af-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\af-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ka
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ka
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ka-GE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ka-GE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fo-FO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fo-FO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hi-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hi-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mt-MT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mt-MT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ga
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ga
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ga-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ga-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ms-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ms-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kk-KZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kk-KZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ky
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ky
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ky-KG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ky-KG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sw-KE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sw-KE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tk
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tk-TM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tk-TM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Latn-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Latn-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tt-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tt-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gu-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gu-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\or
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\or
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\or-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\or-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ta
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ta
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ta-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ta-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\te
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\te
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\te-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\te-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kn-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ml
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ml
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ml-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ml-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\as
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\as
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\as-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\as-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mr-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mr-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sa-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-MN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-MN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bo-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bo-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\cy-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\cy-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\km
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\km
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\km-KH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\km-KH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lo-LA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lo-LA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gl-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gl-ES
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kok
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kok
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kok-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kok-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\syr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\syr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\syr-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\syr-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\si
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\si
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\si-LK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\si-LK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Latn-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Latn-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\am
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\am
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\am-ET
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\am-ET
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tzm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tzm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tzm-Latn-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tzm-Latn-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ne
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ne
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ne-NP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ne-NP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fy-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fy-NL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ps
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ps
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ps-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ps-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fil
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fil
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fil-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fil-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dv-MV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dv-MV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ha
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ha
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ha-Latn-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ha-Latn-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\yo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\yo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\yo-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\yo-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nso
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nso
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nso-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nso-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ba
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ba
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ba-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ba-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\lb-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\lb-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\kl-GL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\kl-GL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ig
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ig-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ig-NG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ii
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ii
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ii-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ii-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\arn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\arn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\arn-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\arn-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\moh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\moh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\moh-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\moh-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\br
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\br
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\br-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\br-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ug
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ug
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ug-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ug-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mi
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mi-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mi-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\oc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oc-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\oc-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\co
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\co
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\co-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\co-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gsw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gsw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gsw-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gsw-FR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sah
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sah
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sah-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sah-RU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qut
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qut
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qut-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qut-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rw
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\rw-RW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\rw-RW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wo-SN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\wo-SN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\prs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\prs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\prs-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\prs-AF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\gd-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\gd-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-TW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-TW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-ES_tradnl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-ES_tradnl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Cans-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Cans-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qps-ploc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qps-ploc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000501
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts\00000501
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qps-ploca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qps-ploca
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\000005FE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts\000005FE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-IQ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-IQ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-MX
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-MX
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nl-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nl-BE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nn-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nn-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\pt-PT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\pt-PT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sv-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sv-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Cyrl-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Cyrl-AZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dsb-DE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ms-BN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ms-BN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Cyrl-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Cyrl-UZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bn-BD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bn-BD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-Mong-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-Mong-CN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\qps-plocm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\qps-plocm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\000009FF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts\000009FF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-EG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-EG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-HK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-HK
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-AT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-AT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-AU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-AU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-CS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\se-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\se-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\quz-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\quz-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-LY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-LY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-GT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-CH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\hr-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\hr-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smj-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smj-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-DZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-MO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-MO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\de-LI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\de-LI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-NZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-CR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-CR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-LU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smj-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smj-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-MA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-MA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-IE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\fr-MC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\fr-MC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sma-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sma-NO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-TN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-TN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-ZA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-DO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-DO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sma-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sma-SE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-OM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-OM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-JM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-JM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-VE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-VE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Cyrl-BA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sms-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sms-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-YE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-YE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-029
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-029
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-CO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-CO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smn-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smn-FI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-SY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-BZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-BZ
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-RS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-JO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-JO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-TT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-TT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-AR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-AR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-LB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-LB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-ZW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-ZW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-EC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl-ME
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-KW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-KW
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-CL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-AE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-AE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-UY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-UY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-BH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-BH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ar-QA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ar-QA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-IN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-BO
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-MY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-SV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-SV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-SG
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-HN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-HN
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-NI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-NI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-PR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-PR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\es-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\es-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sms
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\bs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\bs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\az-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\az-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sma
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sma
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Cans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Cans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hant
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hant
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\nb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\nb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\sr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tg-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tg-Cyrl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\dsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\dsb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\smj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\smj
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\uz-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\uz-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\mn-Mong
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\mn-Mong
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\iu-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\iu-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\tzm-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\tzm-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ha-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\ha-Latn
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
\xe4\x90\x88\xca\x89EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
\xe4\x90\x88\xca\x89EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
\xe4\x90\x88\xca\x89EY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
\xe4\x90\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix
\xe4\xb0\x88\xca\x89EY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit