分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-hpdapp01-1 2020-09-25 19:28:45 2020-09-25 19:31:22 157 秒

魔盾分数

10.0

危险的

文件详细信息

文件名 初音未来.exe
文件大小 11112448 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows
MD5 69b600483ef2bb1e9ceb5205ada22f20
SHA1 e471f5b7f819f3bdd4c5753778c03b01ff9b9208
SHA256 e61945e5f6c10cfeae902d6b5f95f96e1e342d19a2bc5edccae544cd7665d026
SHA512 d7352cced657424b667a91686cb46bcf56af7efdcdf3862f56a528090e67c3fe4bb378bb2f4f535f8ec6de1d070420144e7779c4a4ef983e065b77f9fce3aff8
CRC32 4A793D71
Ssdeep 196608:S7JZDqNOoyxDqvIhzLJ3GZcodJqzGx+Mlnj9Y2+aM5x5w:S7LqNOoGDRLJ3mcGwTMlj97Uxa
Yara
  • Possibly employs anti-virtualization techniques
  • Bypass DEP
  • Create or check mutex
  • Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
  • Detected UPX. Commonly used by RAT!
样本下载 提交误报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
acroipm.adobe.com CNAME acroipm.adobe.com.edgesuite.net
CNAME a1983.dscd.akamai.net.0.1.cn.akamaitech.net
CNAME a1983.dscd.akamai.net
A 23.35.98.32
A 23.35.98.25
29.o533.net A 221.229.162.40

摘要

C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Fonts\staticcache.dat
C:\Users\test\AppData\Local\Temp\xxc.dll
C:\
C:\Users\test\AppData\Local\Temp\DmReg.dll
C:\Users\test\AppData\Local\Temp\MFC42u.DLL
C:\Windows\System32\mfc42u.dll
C:\Users\test\AppData\Local\Temp\ODBC32.dll
C:\Windows\System32\odbc32.dll
C:\Users\test\AppData\Local\Temp\MSVCP60.dll
C:\Windows\System32\msvcp60.dll
C:\Windows\System32\MFC42LOC.DLL
C:\Windows\System32\MFC42LOC.DLL.DLL
C:\Windows\sysnative\MFC42LOC.DLL
C:\Windows\sysnative\MFC42LOC.DLL.DLL
\??\az1025
\??\az369
\??\az79
\??\az24786
\??\az9946
\??\az89346
\??\az7944
\??\az73925
\??\az92835
\??\az923876
\??\az237493
\??\az792385
\??\az79236
\??\az235
\??\az9726
\??\az2835
\??\az896
\??\az1027
\??\az37
\??\az8
\??\az2479
\??\az995
\??\az8935
\??\az795
\??\az7393
\??\az9284
\??\az92388
\??\az23750
\??\az79239
\??\az7924
\??\az24
\??\az973
\??\az284
\??\az90
\??\by1025
\??\by369
\??\by79
\??\by24786
\??\by9946
\??\by89346
\??\by7944
\??\by73925
\??\by92835
\??\by923876
\??\by237493
\??\by792385
\??\by79236
\??\by235
\??\by9726
\??\by2835
\??\by896
\??\by1027
\??\by37
\??\by8
\??\by2479
\??\by995
\??\by8935
\??\by795
\??\by7393
\??\by9284
\??\by92388
\??\by23750
\??\by79239
\??\by7924
\??\by24
\??\by973
\??\by284
\??\by90
\??\cx1025
\??\cx369
\??\cx79
\??\cx24786
\??\cx9946
\??\cx89346
\??\cx7944
\??\cx73925
\??\cx92835
\??\cx923876
\??\cx237493
\??\cx792385
\??\cx79236
\??\cx235
\??\cx9726
\??\cx2835
\??\cx896
\??\cx1027
\??\cx37
\??\cx8
\??\cx2479
\??\cx995
\??\cx8935
\??\cx795
\??\cx7393
\??\cx9284
\??\cx92388
\??\cx23750
\??\cx79239
\??\cx7924
\??\cx24
\??\cx973
\??\cx284
\??\cx90
\??\dw1025
\??\dw369
\??\dw79
\??\dw24786
\??\dw9946
\??\dw89346
\??\dw7944
\??\dw73925
\??\dw92835
\??\dw923876
\??\dw237493
\??\dw792385
\??\dw79236
\??\dw235
\??\dw9726
\??\dw2835
\??\dw896
\??\dw1027
\??\dw37
\??\dw8
\??\dw2479
\??\dw995
\??\dw8935
\??\dw795
\??\dw7393
\??\dw9284
\??\dw92388
\??\dw23750
\??\dw79239
\??\dw7924
\??\dw24
\??\dw973
\??\dw284
\??\dw90
\??\ev1025
\??\ev369
\??\ev79
\??\ev24786
\??\ev9946
\??\ev89346
\??\ev7944
\??\ev73925
\??\ev92835
\??\ev923876
\??\ev237493
\??\ev792385
\??\ev79236
\??\ev235
\??\ev9726
\??\ev2835
\??\ev896
\??\ev1027
\??\ev37
\??\ev8
\??\ev2479
\??\ev995
\??\ev8935
\??\ev795
\??\ev7393
\??\ev9284
\??\ev92388
\??\ev23750
\??\ev79239
\??\ev7924
\??\ev24
\??\ev973
\??\ev284
\??\ev90
\??\fu1025
\??\fu369
\??\fu79
\??\fu24786
\??\fu9946
\??\fu89346
\??\fu7944
\??\fu73925
\??\fu92835
\??\fu923876
\??\fu237493
\??\fu792385
\??\fu79236
\??\fu235
\??\fu9726
\??\fu2835
\??\fu896
\??\fu1027
\??\fu37
\??\fu8
\??\fu2479
\??\fu995
\??\fu8935
\??\fu795
\??\fu7393
\??\fu9284
\??\fu92388
\??\fu23750
\??\fu79239
\??\fu7924
\??\fu24
\??\fu973
\??\fu284
\??\fu90
\??\gt1025
\??\gt369
\??\gt79
\??\gt24786
\??\gt9946
\??\gt89346
\??\gt7944
\??\gt73925
\??\gt92835
\??\gt923876
\??\gt237493
\??\gt792385
\??\gt79236
\??\gt235
\??\gt9726
\??\gt2835
\??\gt896
\??\gt1027
\??\gt37
\??\gt8
\??\gt2479
\??\gt995
\??\gt8935
\??\gt795
\??\gt7393
\??\gt9284
\??\gt92388
\??\gt23750
\??\gt79239
\??\gt7924
\??\gt24
\??\gt973
\??\gt284
\??\gt90
\??\hs1025
\??\hs369
\??\hs79
\??\hs24786
\??\hs9946
\??\hs89346
\??\hs7944
\??\hs73925
\??\hs92835
\??\hs923876
\??\hs237493
\??\hs792385
\??\hs79236
\??\hs235
\??\hs9726
\??\hs2835
\??\hs896
\??\hs1027
\??\hs37
\??\hs8
\??\hs2479
\??\hs995
\??\hs8935
\??\hs795
\??\hs7393
\??\hs9284
\??\hs92388
\??\hs23750
\??\hs79239
\??\hs7924
\??\hs24
\??\hs973
\??\hs284
\??\hs90
\??\ir1025
\??\ir369
\??\ir79
\??\ir24786
\??\ir9946
\??\ir89346
\??\ir7944
\??\ir73925
\??\ir92835
\??\ir923876
\??\ir237493
\??\ir792385
\??\ir79236
\??\ir235
\??\ir9726
\??\ir2835
\??\ir896
\??\ir1027
\??\ir37
\??\ir8
\??\ir2479
\??\ir995
\??\ir8935
\??\ir795
\??\ir7393
\??\ir9284
\??\ir92388
\??\ir23750
\??\ir79239
\??\ir7924
\??\ir24
\??\ir973
\??\ir284
\??\ir90
\??\jq1025
\??\jq369
\??\jq79
\??\jq24786
\??\jq9946
\??\jq89346
\??\jq7944
\??\jq73925
\??\jq92835
\??\jq923876
\??\jq237493
\??\jq792385
\??\jq79236
\??\jq235
\??\jq9726
\??\jq2835
\??\jq896
\??\jq1027
\??\jq37
\??\jq8
\??\jq2479
\??\jq995
\??\jq8935
\??\jq795
\??\jq7393
\??\jq9284
\??\jq92388
\??\jq23750
\??\jq79239
\??\jq7924
\??\jq24
\??\jq973
\??\jq284
\??\jq90
\??\kp1025
\??\kp369
\??\kp79
\??\kp24786
\??\kp9946
\??\kp89346
\??\kp7944
\??\kp73925
\??\kp92835
\??\kp923876
\??\kp237493
\??\kp792385
\??\kp79236
\??\kp235
\??\kp9726
\??\kp2835
\??\kp896
\??\kp1027
\??\kp37
\??\kp8
\??\kp2479
\??\kp995
\??\kp8935
\??\kp795
\??\kp7393
\??\kp9284
\??\kp92388
\??\kp23750
\??\kp79239
\??\kp7924
\??\kp24
\??\kp973
\??\kp284
\??\kp90
\??\lo1025
\??\lo369
\??\lo79
\??\lo24786
\??\lo9946
\??\lo89346
\??\lo7944
\??\lo73925
\??\lo92835
\??\lo923876
\??\lo237493
\??\lo792385
\??\lo79236
\??\lo235
\??\lo9726
\??\lo2835
\??\lo896
\??\lo1027
\??\lo37
\??\lo8
\??\lo2479
\??\lo995
\??\lo8935
\??\lo795
\??\lo7393
\??\lo9284
\??\lo92388
\??\lo23750
\??\lo79239
\??\lo7924
\??\lo24
\??\lo973
\??\lo284
\??\lo90
\??\mn1025
\??\mn369
\??\mn79
\??\mn24786
\??\mn9946
\??\mn89346
\??\mn7944
\??\mn73925
\??\mn92835
\??\mn923876
\??\mn237493
\??\mn792385
\??\mn79236
\??\mn235
\??\mn9726
\??\mn2835
\??\mn896
\??\mn1027
\??\mn37
\??\mn8
\??\mn2479
\??\mn995
\??\mn8935
\??\mn795
\??\mn7393
\??\mn9284
\??\mn92388
\??\mn23750
\??\mn79239
\??\mn7924
\??\mn24
\??\mn973
\??\mn284
\??\mn90
\??\nm1025
\??\nm369
\??\nm79
\??\nm24786
\??\nm9946
\??\nm89346
\??\nm7944
\??\nm73925
\??\nm92835
\??\nm923876
\??\nm237493
\??\nm792385
\??\nm79236
\??\nm235
\??\nm9726
\??\nm2835
\??\nm896
\??\nm1027
\??\nm37
\??\nm8
\??\nm2479
\??\nm995
\??\nm8935
\??\nm795
\??\nm7393
\??\nm9284
\??\nm92388
\??\nm23750
\??\nm79239
\??\nm7924
\??\nm24
\??\nm973
\??\nm284
\??\nm90
\??\ol1025
\??\ol369
\??\ol79
\??\ol24786
\??\ol9946
\??\ol89346
\??\ol7944
\??\ol73925
\??\ol92835
\??\ol923876
\??\ol237493
\??\ol792385
\??\ol79236
\??\ol235
\??\ol9726
\??\ol2835
\??\ol896
\??\ol1027
\??\ol37
\??\ol8
\??\ol2479
\??\ol995
\??\ol8935
\??\ol795
\??\ol7393
\??\ol9284
\??\ol92388
\??\ol23750
\??\ol79239
\??\ol7924
\??\ol24
\??\ol973
\??\ol284
\??\ol90
\??\pk1025
\??\pk369
\??\pk79
\??\pk24786
\??\pk9946
\??\pk89346
\??\pk7944
\??\pk73925
\??\pk92835
\??\pk923876
\??\pk237493
\??\pk792385
\??\pk79236
\??\pk235
\??\pk9726
\??\pk2835
\??\pk896
\??\pk1027
\??\pk37
\??\pk8
\??\pk2479
\??\pk995
\??\pk8935
\??\pk795
\??\pk7393
\??\pk9284
\??\pk92388
\??\pk23750
\??\pk79239
\??\pk7924
\??\pk24
\??\pk973
\??\pk284
\??\pk90
\??\qj1025
\??\qj369
\??\qj79
\??\qj24786
\??\qj9946
\??\qj89346
\??\qj7944
\??\qj73925
\??\qj92835
\??\qj923876
\??\qj237493
\??\qj792385
\??\qj79236
\??\qj235
\??\qj9726
\??\qj2835
\??\qj896
\??\qj1027
\??\qj37
\??\qj8
\??\qj2479
\??\qj995
\??\qj8935
\??\qj795
\??\qj7393
\??\qj9284
\??\qj92388
\??\qj23750
\??\qj79239
\??\qj7924
\??\qj24
\??\qj973
\??\qj284
\??\qj90
\??\ri1025
\??\ri369
\??\ri79
\??\ri24786
\??\ri9946
\??\ri89346
\??\ri7944
\??\ri73925
\??\ri92835
\??\ri923876
\??\ri237493
\??\ri792385
\??\ri79236
\??\ri235
\??\ri9726
\??\ri2835
\??\ri896
\??\ri1027
\??\ri37
\??\ri8
\??\ri2479
\??\ri995
\??\ri8935
\??\ri795
\??\ri7393
\??\ri9284
\??\ri92388
\??\ri23750
\??\ri79239
\??\ri7924
\??\ri24
\??\ri973
\??\ri284
\??\ri90
\??\sh1025
\??\sh369
\??\sh79
\??\sh24786
\??\sh9946
\??\sh89346
\??\sh7944
\??\sh73925
\??\sh92835
\??\sh923876
\??\sh237493
\??\sh792385
\??\sh79236
\??\sh235
\??\sh9726
\??\sh2835
\??\sh896
\??\sh1027
\??\sh37
\??\sh8
\??\sh2479
\??\sh995
\??\sh8935
\??\sh795
\??\sh7393
\??\sh9284
\??\sh92388
\??\sh23750
\??\sh79239
\??\sh7924
\??\sh24
\??\sh973
\??\sh284
\??\sh90
\??\tg1025
\??\tg369
\??\tg79
\??\tg24786
\??\tg9946
\??\tg89346
\??\tg7944
\??\tg73925
\??\tg92835
\??\tg923876
\??\tg237493
\??\tg792385
\??\tg79236
\??\tg235
\??\tg9726
\??\tg2835
\??\tg896
\??\tg1027
\??\tg37
\??\tg8
\??\tg2479
\??\tg995
\??\tg8935
\??\tg795
\??\tg7393
\??\tg9284
\??\tg92388
\??\tg23750
\??\tg79239
\??\tg7924
\??\tg24
\??\tg973
\??\tg284
\??\tg90
\??\uf1025
\??\uf369
\??\uf79
\??\uf24786
\??\uf9946
\??\uf89346
\??\uf7944
\??\uf73925
\??\uf92835
\??\uf923876
\??\uf237493
\??\uf792385
\??\uf79236
\??\uf235
\??\uf9726
\??\uf2835
\??\uf896
\??\uf1027
\??\uf37
\??\uf8
\??\uf2479
\??\uf995
\??\uf8935
\??\uf795
\??\uf7393
\??\uf9284
\??\uf92388
\??\uf23750
\??\uf79239
\??\uf7924
\??\uf24
\??\uf973
\??\uf284
\??\uf90
\??\ve1025
\??\ve369
\??\ve79
\??\ve24786
\??\ve9946
\??\ve89346
\??\ve7944
\??\ve73925
\??\ve92835
\??\ve923876
\??\ve237493
\??\ve792385
\??\ve79236
\??\ve235
\??\ve9726
\??\ve2835
\??\ve896
\??\ve1027
\??\ve37
\??\ve8
\??\ve2479
\??\ve995
\??\ve8935
\??\ve795
\??\ve7393
\??\ve9284
\??\ve92388
\??\ve23750
\??\ve79239
\??\ve7924
\??\ve24
\??\ve973
\??\ve284
\??\ve90
\??\wd1025
\??\wd369
\??\wd79
\??\wd24786
\??\wd9946
\??\wd89346
\??\wd7944
\??\wd73925
\??\wd92835
\??\wd923876
\??\wd237493
\??\wd792385
\??\wd79236
\??\wd235
\??\wd9726
\??\wd2835
\??\wd896
\??\wd1027
\??\wd37
\??\wd8
\??\wd2479
\??\wd995
\??\wd8935
\??\wd795
\??\wd7393
\??\wd9284
\??\wd92388
\??\wd23750
\??\wd79239
\??\wd7924
\??\wd24
\??\wd973
\??\wd284
\??\wd90
\??\xc1025
\??\xc369
\??\xc79
\??\xc24786
\??\xc9946
\??\xc89346
\??\xc7944
\??\xc73925
\??\xc92835
\??\xc923876
\??\xc237493
\??\xc792385
\??\xc79236
\??\xc235
\??\xc9726
\??\xc2835
\??\xc896
\??\xc1027
\??\xc37
\??\xc8
\??\xc2479
\??\xc995
\??\xc8935
\??\xc795
\??\xc7393
\??\xc9284
\??\xc92388
\??\xc23750
\??\xc79239
\??\xc7924
\??\xc24
\??\xc973
\??\xc284
\??\xc90
\??\yb1025
\??\yb369
\??\yb79
\??\yb24786
\??\yb9946
\??\yb89346
\??\yb7944
\??\yb73925
\??\yb92835
\??\yb923876
\??\yb237493
\??\yb792385
\??\yb79236
\??\yb235
\??\yb9726
\??\yb2835
\??\yb896
\??\yb1027
\??\yb37
\??\yb8
\??\yb2479
\??\yb995
\??\yb8935
\??\yb795
\??\yb7393
\??\yb9284
\??\yb92388
\??\yb23750
\??\yb79239
\??\yb7924
\??\yb24
\??\yb973
\??\yb284
\??\yb90
C:\Windows\System32\ntdll.dll
C:\Users\test\AppData\Local\Temp\QQbrowserQQbrowserQQbrowser.bat
C:\Users\test\AppData\Local\Temp\xxc.dll.2.Manifest
C:\Users\test\AppData\Local\Temp\xxc.dll.3.Manifest
C:\Users\test\AppData\Local\Temp\xxc.dll.Manifest
C:\Windows\SysWOW64\stdole2.tlb
\??\PhysicalDrive0
C:\Users\test\AppData\Local\Temp\
C:\Users
C:\Users\test
C:\Users\test\AppData
C:\Users\test\AppData\Local
C:\Users\test\AppData\Local\Temp
\??\a10284132
\??\a368173
\??\a78714
\??\a24785531
\??\a994451
\??\a89534451
\??\a7954431
\??\a73964241
\??\a92648341
\??\a923843751
\??\a239744912
\??\a792038441
\??\a79233051
\??\a232401
\??\a9017215
\??\a2083114
\??\a181950
\??\a1028361
\??\a376871
\??\a7771
\??\a2478851
\??\a999441
\??\a8093441
\??\a279441
\??\a7334921
\??\a9204831
\??\a92348071
\??\a23074491
\??\a79203481
\??\a7903231
\??\a23301
\??\a972201
\??\a280113
\??\a81109
\??\b10284132
\??\b368173
\??\b78714
\??\b24785531
\??\b994451
\??\b89534451
\??\b7954431
\??\b73964241
\??\b92648341
\??\b923843751
\??\b239744912
\??\b792038441
\??\b79233051
\??\b232401
\??\b9017215
\??\b2083114
\??\b181950
\??\b1028361
\??\b376871
\??\b7771
\??\b2478851
\??\b999441
\??\b8093441
\??\b279441
\??\b7334921
\??\b9204831
\??\b92348071
\??\b23074491
\??\b79203481
\??\b7903231
\??\b23301
\??\b972201
\??\b280113
\??\b81109
\??\c10284132
\??\c368173
\??\c78714
\??\c24785531
\??\c994451
\??\c89534451
\??\c7954431
\??\c73964241
\??\c92648341
\??\c923843751
\??\c239744912
\??\c792038441
\??\c79233051
\??\c232401
\??\c9017215
\??\c2083114
\??\c181950
\??\c1028361
\??\c376871
\??\c7771
\??\c2478851
\??\c999441
\??\c8093441
\??\c279441
\??\c7334921
\??\c9204831
\??\c92348071
\??\c23074491
\??\c79203481
\??\c7903231
\??\c23301
\??\c972201
\??\c280113
\??\c81109
\??\d10284132
\??\d368173
\??\d78714
\??\d24785531
\??\d994451
\??\d89534451
\??\d7954431
\??\d73964241
\??\d92648341
\??\d923843751
\??\d239744912
\??\d792038441
\??\d79233051
\??\d232401
\??\d9017215
\??\d2083114
\??\d181950
\??\d1028361
\??\d376871
\??\d7771
\??\d2478851
\??\d999441
\??\d8093441
\??\d279441
\??\d7334921
\??\d9204831
\??\d92348071
\??\d23074491
\??\d79203481
\??\d7903231
\??\d23301
\??\d972201
\??\d280113
\??\d81109
\??\e10284132
\??\e368173
\??\e78714
\??\e24785531
\??\e994451
\??\e89534451
\??\e7954431
\??\e73964241
\??\e92648341
\??\e923843751
\??\e239744912
\??\e792038441
\??\e79233051
\??\e232401
\??\e9017215
\??\e2083114
\??\e181950
\??\e1028361
\??\e376871
\??\e7771
\??\e2478851
\??\e999441
\??\e8093441
\??\e279441
\??\e7334921
\??\e9204831
\??\e92348071
\??\e23074491
\??\e79203481
\??\e7903231
\??\e23301
\??\e972201
\??\e280113
\??\e81109
\??\f10284132
\??\f368173
\??\f78714
\??\f24785531
\??\f994451
\??\f89534451
\??\f7954431
\??\f73964241
\??\f92648341
\??\f923843751
\??\f239744912
\??\f792038441
\??\f79233051
\??\f232401
\??\f9017215
\??\f2083114
\??\f181950
\??\f1028361
\??\f376871
\??\f7771
\??\f2478851
\??\f999441
\??\f8093441
\??\f279441
\??\f7334921
\??\f9204831
\??\f92348071
\??\f23074491
\??\f79203481
\??\f7903231
\??\f23301
\??\f972201
\??\f280113
\??\f81109
\??\g10284132
\??\g368173
\??\g78714
\??\g24785531
\??\g994451
\??\g89534451
\??\g7954431
\??\g73964241
\??\g92648341
\??\g923843751
\??\g239744912
\??\g792038441
\??\g79233051
\??\g232401
\??\g9017215
\??\g2083114
\??\g181950
\??\g1028361
\??\g376871
\??\g7771
\??\g2478851
\??\g999441
\??\g8093441
\??\g279441
\??\g7334921
\??\g9204831
\??\g92348071
\??\g23074491
\??\g79203481
\??\g7903231
\??\g23301
\??\g972201
\??\g280113
\??\g81109
\??\h10284132
\??\h368173
\??\h78714
\??\h24785531
\??\h994451
\??\h89534451
\??\h7954431
\??\h73964241
\??\h92648341
\??\h923843751
\??\h239744912
\??\h792038441
\??\h79233051
\??\h232401
\??\h9017215
\??\h2083114
\??\h181950
\??\h1028361
\??\h376871
\??\h7771
\??\h2478851
\??\h999441
\??\h8093441
\??\h279441
\??\h7334921
\??\h9204831
\??\h92348071
\??\h23074491
\??\h79203481
\??\h7903231
\??\h23301
\??\h972201
\??\h280113
\??\h81109
\??\i10284132
\??\i368173
\??\i78714
\??\i24785531
\??\i994451
\??\i89534451
\??\i7954431
\??\i73964241
\??\i92648341
\??\i923843751
\??\i239744912
\??\i792038441
\??\i79233051
\??\i232401
\??\i9017215
\??\i2083114
\??\i181950
\??\i1028361
\??\i376871
\??\i7771
\??\i2478851
\??\i999441
\??\i8093441
\??\i279441
\??\i7334921
\??\i9204831
\??\i92348071
\??\i23074491
\??\i79203481
\??\i7903231
\??\i23301
\??\i972201
\??\i280113
\??\i81109
\??\j10284132
\??\j368173
\??\j78714
\??\j24785531
\??\j994451
\??\j89534451
\??\j7954431
\??\j73964241
\??\j92648341
\??\j923843751
\??\j239744912
\??\j792038441
\??\j79233051
\??\j232401
\??\j9017215
\??\j2083114
\??\j181950
\??\j1028361
\??\j376871
\??\j7771
\??\j2478851
\??\j999441
\??\j8093441
\??\j279441
\??\j7334921
\??\j9204831
\??\j92348071
\??\j23074491
\??\j79203481
\??\j7903231
\??\j23301
\??\j972201
\??\j280113
\??\j81109
\??\k10284132
\??\k368173
\??\k78714
\??\k24785531
\??\k994451
\??\k89534451
\??\k7954431
\??\k73964241
\??\k92648341
\??\k923843751
\??\k239744912
\??\k792038441
\??\k79233051
\??\k232401
\??\k9017215
\??\k2083114
\??\k181950
\??\k1028361
\??\k376871
\??\k7771
\??\k2478851
\??\k999441
\??\k8093441
\??\k279441
\??\k7334921
\??\k9204831
\??\k92348071
\??\k23074491
\??\k79203481
\??\k7903231
\??\k23301
\??\k972201
\??\k280113
\??\k81109
\??\l10284132
\??\l368173
\??\l78714
\??\l24785531
\??\l994451
\??\l89534451
\??\l7954431
\??\l73964241
\??\l92648341
\??\l923843751
\??\l239744912
\??\l792038441
\??\l79233051
\??\l232401
\??\l9017215
\??\l2083114
\??\l181950
\??\l1028361
\??\l376871
\??\l7771
\??\l2478851
\??\l999441
\??\l8093441
\??\l279441
\??\l7334921
\??\l9204831
\??\l92348071
\??\l23074491
\??\l79203481
\??\l7903231
\??\l23301
\??\l972201
\??\l280113
\??\l81109
\??\m10284132
\??\m368173
\??\m78714
\??\m24785531
\??\m994451
\??\m89534451
\??\m7954431
\??\m73964241
\??\m92648341
\??\m923843751
\??\m239744912
\??\m792038441
\??\m79233051
\??\m232401
\??\m9017215
\??\m2083114
\??\m181950
\??\m1028361
\??\m376871
\??\m7771
\??\m2478851
\??\m999441
\??\m8093441
\??\m279441
\??\m7334921
\??\m9204831
\??\m92348071
\??\m23074491
\??\m79203481
\??\m7903231
\??\m23301
\??\m972201
\??\m280113
\??\m81109
\??\n10284132
\??\n368173
\??\n78714
\??\n24785531
\??\n994451
\??\n89534451
\??\n7954431
\??\n73964241
\??\n92648341
\??\n923843751
\??\n239744912
\??\n792038441
\??\n79233051
\??\n232401
\??\n9017215
\??\n2083114
\??\n181950
\??\n1028361
\??\n376871
\??\n7771
\??\n2478851
\??\n999441
\??\n8093441
\??\n279441
\??\n7334921
\??\n9204831
\??\n92348071
\??\n23074491
\??\n79203481
\??\n7903231
\??\n23301
\??\n972201
\??\n280113
\??\n81109
\??\o10284132
\??\o368173
\??\o78714
\??\o24785531
\??\o994451
\??\o89534451
\??\o7954431
\??\o73964241
\??\o92648341
\??\o923843751
\??\o239744912
\??\o792038441
\??\o79233051
\??\o232401
\??\o9017215
\??\o2083114
\??\o181950
\??\o1028361
\??\o376871
\??\o7771
\??\o2478851
\??\o999441
\??\o8093441
\??\o279441
\??\o7334921
\??\o9204831
\??\o92348071
\??\o23074491
\??\o79203481
\??\o7903231
\??\o23301
\??\o972201
\??\o280113
\??\o81109
\??\p10284132
\??\p368173
\??\p78714
\??\p24785531
\??\p994451
\??\p89534451
\??\p7954431
\??\p73964241
\??\p92648341
\??\p923843751
\??\p239744912
\??\p792038441
\??\p79233051
\??\p232401
\??\p9017215
\??\p2083114
\??\p181950
\??\p1028361
\??\p376871
\??\p7771
\??\p2478851
\??\p999441
\??\p8093441
\??\p279441
\??\p7334921
\??\p9204831
\??\p92348071
\??\p23074491
\??\p79203481
\??\p7903231
\??\p23301
\??\p972201
\??\p280113
\??\p81109
\??\q10284132
\??\q368173
\??\q78714
\??\q24785531
\??\q994451
\??\q89534451
\??\q7954431
\??\q73964241
\??\q92648341
\??\q923843751
\??\q239744912
\??\q792038441
\??\q79233051
\??\q232401
\??\q9017215
\??\q2083114
\??\q181950
\??\q1028361
\??\q376871
\??\q7771
\??\q2478851
\??\q999441
\??\q8093441
\??\q279441
\??\q7334921
\??\q9204831
\??\q92348071
\??\q23074491
\??\q79203481
\??\q7903231
\??\q23301
\??\q972201
\??\q280113
\??\q81109
\??\r10284132
\??\r368173
\??\r78714
\??\r24785531
\??\r994451
\??\r89534451
\??\r7954431
\??\r73964241
\??\r92648341
\??\r923843751
\??\r239744912
\??\r792038441
\??\r79233051
\??\r232401
\??\r9017215
\??\r2083114
\??\r181950
\??\r1028361
\??\r376871
\??\r7771
\??\r2478851
\??\r999441
\??\r8093441
\??\r279441
\??\r7334921
\??\r9204831
\??\r92348071
\??\r23074491
\??\r79203481
\??\r7903231
\??\r23301
\??\r972201
\??\r280113
\??\r81109
\??\s10284132
\??\s368173
\??\s78714
\??\s24785531
\??\s994451
\??\s89534451
\??\s7954431
\??\s73964241
\??\s92648341
\??\s923843751
\??\s239744912
\??\s792038441
\??\s79233051
\??\s232401
\??\s9017215
\??\s2083114
\??\s181950
\??\s1028361
\??\s376871
\??\s7771
\??\s2478851
\??\s999441
\??\s8093441
\??\s279441
\??\s7334921
\??\s9204831
\??\s92348071
\??\s23074491
\??\s79203481
\??\s7903231
\??\s23301
\??\s972201
\??\s280113
\??\s81109
\??\t10284132
\??\t368173
\??\t78714
\??\t24785531
\??\t994451
\??\t89534451
\??\t7954431
\??\t73964241
\??\t92648341
\??\t923843751
\??\t239744912
\??\t792038441
\??\t79233051
\??\t232401
\??\t9017215
\??\t2083114
\??\t181950
\??\t1028361
\??\t376871
\??\t7771
\??\t2478851
\??\t999441
\??\t8093441
\??\t279441
\??\t7334921
\??\t9204831
\??\t92348071
\??\t23074491
\??\t79203481
\??\t7903231
\??\t23301
\??\t972201
\??\t280113
\??\t81109
\??\u10284132
\??\u368173
\??\u78714
\??\u24785531
\??\u994451
\??\u89534451
\??\u7954431
\??\u73964241
\??\u92648341
\??\u923843751
\??\u239744912
\??\u792038441
\??\u79233051
\??\u232401
\??\u9017215
\??\u2083114
\??\u181950
\??\u1028361
\??\u376871
\??\u7771
\??\u2478851
\??\u999441
\??\u8093441
\??\u279441
\??\u7334921
\??\u9204831
\??\u92348071
\??\u23074491
\??\u79203481
\??\u7903231
\??\u23301
\??\u972201
\??\u280113
\??\u81109
\??\v10284132
\??\v368173
\??\v78714
\??\v24785531
\??\v994451
\??\v89534451
\??\v7954431
\??\v73964241
\??\v92648341
\??\v923843751
\??\v239744912
\??\v792038441
\??\v79233051
\??\v232401
\??\v9017215
\??\v2083114
\??\v181950
\??\v1028361
\??\v376871
\??\v7771
\??\v2478851
\??\v999441
\??\v8093441
\??\v279441
\??\v7334921
\??\v9204831
\??\v92348071
\??\v23074491
\??\v79203481
\??\v7903231
\??\v23301
\??\v972201
\??\v280113
\??\v81109
\??\w10284132
\??\w368173
\??\w78714
\??\w24785531
\??\w994451
\??\w89534451
\??\w7954431
\??\w73964241
\??\w92648341
\??\w923843751
\??\w239744912
\??\w792038441
\??\w79233051
\??\w232401
\??\w9017215
\??\w2083114
\??\w181950
\??\w1028361
\??\w376871
\??\w7771
\??\w2478851
\??\w999441
\??\w8093441
\??\w279441
\??\w7334921
\??\w9204831
\??\w92348071
\??\w23074491
\??\w79203481
\??\w7903231
\??\w23301
\??\w972201
\??\w280113
\??\w81109
\??\x10284132
\??\x368173
\??\x78714
\??\x24785531
\??\x994451
\??\x89534451
\??\x7954431
\??\x73964241
\??\x92648341
\??\x923843751
\??\x239744912
\??\x792038441
\??\x79233051
\??\x232401
\??\x9017215
\??\x2083114
\??\x181950
\??\x1028361
\??\x376871
\??\x7771
\??\x2478851
\??\x999441
\??\x8093441
\??\x279441
\??\x7334921
\??\x9204831
\??\x92348071
\??\x23074491
\??\x79203481
\??\x7903231
\??\x23301
\??\x972201
\??\x280113
\??\x81109
\??\y10284132
\??\y368173
\??\y78714
\??\y24785531
\??\y994451
\??\y89534451
\??\y7954431
\??\y73964241
\??\y92648341
\??\y923843751
\??\y239744912
\??\y792038441
\??\y79233051
\??\y232401
\??\y9017215
\??\y2083114
\??\y181950
\??\y1028361
\??\y376871
\??\y7771
\??\y2478851
\??\y999441
\??\y8093441
\??\y279441
\??\y7334921
\??\y9204831
\??\y92348071
\??\y23074491
\??\y79203481
\??\y7903231
\??\y23301
\??\y972201
\??\y280113
\??\y81109
\??\z10284132
\??\z368173
\??\z78714
\??\z24785531
\??\z994451
\??\z89534451
\??\z7954431
\??\z73964241
\??\z92648341
\??\z923843751
\??\z239744912
\??\z792038441
\??\z79233051
\??\z232401
\??\z9017215
\??\z2083114
\??\z181950
\??\z1028361
\??\z376871
\??\z7771
\??\z2478851
\??\z999441
\??\z8093441
\??\z279441
\??\z7334921
\??\z9204831
\??\z92348071
\??\z23074491
\??\z79203481
\??\z7903231
\??\z23301
\??\z972201
\??\z280113
\??\z81109
C:\Users\test\AppData\Local\Temp\c1396.sys
C:\Windows\SysWOW64\ntdll.dll
C:\Windows\SysWOW64\KernelBase.dll
C:\Windows\SysWOW64\kernel32.dll
C:\Windows\SysWOW64\user32.dll
C:\Windows\SysWOW64\advapi32.dll
C:\Windows\SysWOW64\IPHLPAPI.DLL
B:
D:
E:
F:
G:
H:
I:
J:
K:
L:
M:
N:
O:
P:
Q:
R:
S:
T:
U:
V:
W:
X:
Y:
Z:
[:
C:\Windows\QQbrowserQQbrowserQQbrowser.dat
\??\MountPointManager
C:\\*.*
C:\Users\*.*
C:\Users\All Users\*.*
C:\Users\All Users\Desktop\*.*
C:\Users\test\*.*
C:\Users\test\Desktop\*.*
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Windows\Fonts\staticcache.dat
C:\Users\test\AppData\Local\Temp\DmReg.dll
C:\Windows\System32\mfc42u.dll
C:\Windows\System32\odbc32.dll
C:\Windows\System32\msvcp60.dll
C:\Users\test\AppData\Local\Temp\xxc.dll
\??\az1025
\??\az369
\??\az79
\??\az24786
\??\az9946
\??\az89346
\??\az7944
\??\az73925
\??\az92835
\??\az923876
\??\az237493
\??\az792385
\??\az79236
\??\az235
\??\az9726
\??\az2835
\??\az896
\??\az1027
\??\az37
\??\az8
\??\az2479
\??\az995
\??\az8935
\??\az795
\??\az7393
\??\az9284
\??\az92388
\??\az23750
\??\az79239
\??\az7924
\??\az24
\??\az973
\??\az284
\??\az90
\??\by1025
\??\by369
\??\by79
\??\by24786
\??\by9946
\??\by89346
\??\by7944
\??\by73925
\??\by92835
\??\by923876
\??\by237493
\??\by792385
\??\by79236
\??\by235
\??\by9726
\??\by2835
\??\by896
\??\by1027
\??\by37
\??\by8
\??\by2479
\??\by995
\??\by8935
\??\by795
\??\by7393
\??\by9284
\??\by92388
\??\by23750
\??\by79239
\??\by7924
\??\by24
\??\by973
\??\by284
\??\by90
\??\cx1025
\??\cx369
\??\cx79
\??\cx24786
\??\cx9946
\??\cx89346
\??\cx7944
\??\cx73925
\??\cx92835
\??\cx923876
\??\cx237493
\??\cx792385
\??\cx79236
\??\cx235
\??\cx9726
\??\cx2835
\??\cx896
\??\cx1027
\??\cx37
\??\cx8
\??\cx2479
\??\cx995
\??\cx8935
\??\cx795
\??\cx7393
\??\cx9284
\??\cx92388
\??\cx23750
\??\cx79239
\??\cx7924
\??\cx24
\??\cx973
\??\cx284
\??\cx90
\??\dw1025
\??\dw369
\??\dw79
\??\dw24786
\??\dw9946
\??\dw89346
\??\dw7944
\??\dw73925
\??\dw92835
\??\dw923876
\??\dw237493
\??\dw792385
\??\dw79236
\??\dw235
\??\dw9726
\??\dw2835
\??\dw896
\??\dw1027
\??\dw37
\??\dw8
\??\dw2479
\??\dw995
\??\dw8935
\??\dw795
\??\dw7393
\??\dw9284
\??\dw92388
\??\dw23750
\??\dw79239
\??\dw7924
\??\dw24
\??\dw973
\??\dw284
\??\dw90
\??\ev1025
\??\ev369
\??\ev79
\??\ev24786
\??\ev9946
\??\ev89346
\??\ev7944
\??\ev73925
\??\ev92835
\??\ev923876
\??\ev237493
\??\ev792385
\??\ev79236
\??\ev235
\??\ev9726
\??\ev2835
\??\ev896
\??\ev1027
\??\ev37
\??\ev8
\??\ev2479
\??\ev995
\??\ev8935
\??\ev795
\??\ev7393
\??\ev9284
\??\ev92388
\??\ev23750
\??\ev79239
\??\ev7924
\??\ev24
\??\ev973
\??\ev284
\??\ev90
\??\fu1025
\??\fu369
\??\fu79
\??\fu24786
\??\fu9946
\??\fu89346
\??\fu7944
\??\fu73925
\??\fu92835
\??\fu923876
\??\fu237493
\??\fu792385
\??\fu79236
\??\fu235
\??\fu9726
\??\fu2835
\??\fu896
\??\fu1027
\??\fu37
\??\fu8
\??\fu2479
\??\fu995
\??\fu8935
\??\fu795
\??\fu7393
\??\fu9284
\??\fu92388
\??\fu23750
\??\fu79239
\??\fu7924
\??\fu24
\??\fu973
\??\fu284
\??\fu90
\??\gt1025
\??\gt369
\??\gt79
\??\gt24786
\??\gt9946
\??\gt89346
\??\gt7944
\??\gt73925
\??\gt92835
\??\gt923876
\??\gt237493
\??\gt792385
\??\gt79236
\??\gt235
\??\gt9726
\??\gt2835
\??\gt896
\??\gt1027
\??\gt37
\??\gt8
\??\gt2479
\??\gt995
\??\gt8935
\??\gt795
\??\gt7393
\??\gt9284
\??\gt92388
\??\gt23750
\??\gt79239
\??\gt7924
\??\gt24
\??\gt973
\??\gt284
\??\gt90
\??\hs1025
\??\hs369
\??\hs79
\??\hs24786
\??\hs9946
\??\hs89346
\??\hs7944
\??\hs73925
\??\hs92835
\??\hs923876
\??\hs237493
\??\hs792385
\??\hs79236
\??\hs235
\??\hs9726
\??\hs2835
\??\hs896
\??\hs1027
\??\hs37
\??\hs8
\??\hs2479
\??\hs995
\??\hs8935
\??\hs795
\??\hs7393
\??\hs9284
\??\hs92388
\??\hs23750
\??\hs79239
\??\hs7924
\??\hs24
\??\hs973
\??\hs284
\??\hs90
\??\ir1025
\??\ir369
\??\ir79
\??\ir24786
\??\ir9946
\??\ir89346
\??\ir7944
\??\ir73925
\??\ir92835
\??\ir923876
\??\ir237493
\??\ir792385
\??\ir79236
\??\ir235
\??\ir9726
\??\ir2835
\??\ir896
\??\ir1027
\??\ir37
\??\ir8
\??\ir2479
\??\ir995
\??\ir8935
\??\ir795
\??\ir7393
\??\ir9284
\??\ir92388
\??\ir23750
\??\ir79239
\??\ir7924
\??\ir24
\??\ir973
\??\ir284
\??\ir90
\??\jq1025
\??\jq369
\??\jq79
\??\jq24786
\??\jq9946
\??\jq89346
\??\jq7944
\??\jq73925
\??\jq92835
\??\jq923876
\??\jq237493
\??\jq792385
\??\jq79236
\??\jq235
\??\jq9726
\??\jq2835
\??\jq896
\??\jq1027
\??\jq37
\??\jq8
\??\jq2479
\??\jq995
\??\jq8935
\??\jq795
\??\jq7393
\??\jq9284
\??\jq92388
\??\jq23750
\??\jq79239
\??\jq7924
\??\jq24
\??\jq973
\??\jq284
\??\jq90
\??\kp1025
\??\kp369
\??\kp79
\??\kp24786
\??\kp9946
\??\kp89346
\??\kp7944
\??\kp73925
\??\kp92835
\??\kp923876
\??\kp237493
\??\kp792385
\??\kp79236
\??\kp235
\??\kp9726
\??\kp2835
\??\kp896
\??\kp1027
\??\kp37
\??\kp8
\??\kp2479
\??\kp995
\??\kp8935
\??\kp795
\??\kp7393
\??\kp9284
\??\kp92388
\??\kp23750
\??\kp79239
\??\kp7924
\??\kp24
\??\kp973
\??\kp284
\??\kp90
\??\lo1025
\??\lo369
\??\lo79
\??\lo24786
\??\lo9946
\??\lo89346
\??\lo7944
\??\lo73925
\??\lo92835
\??\lo923876
\??\lo237493
\??\lo792385
\??\lo79236
\??\lo235
\??\lo9726
\??\lo2835
\??\lo896
\??\lo1027
\??\lo37
\??\lo8
\??\lo2479
\??\lo995
\??\lo8935
\??\lo795
\??\lo7393
\??\lo9284
\??\lo92388
\??\lo23750
\??\lo79239
\??\lo7924
\??\lo24
\??\lo973
\??\lo284
\??\lo90
\??\mn1025
\??\mn369
\??\mn79
\??\mn24786
\??\mn9946
\??\mn89346
\??\mn7944
\??\mn73925
\??\mn92835
\??\mn923876
\??\mn237493
\??\mn792385
\??\mn79236
\??\mn235
\??\mn9726
\??\mn2835
\??\mn896
\??\mn1027
\??\mn37
\??\mn8
\??\mn2479
\??\mn995
\??\mn8935
\??\mn795
\??\mn7393
\??\mn9284
\??\mn92388
\??\mn23750
\??\mn79239
\??\mn7924
\??\mn24
\??\mn973
\??\mn284
\??\mn90
\??\nm1025
\??\nm369
\??\nm79
\??\nm24786
\??\nm9946
\??\nm89346
\??\nm7944
\??\nm73925
\??\nm92835
\??\nm923876
\??\nm237493
\??\nm792385
\??\nm79236
\??\nm235
\??\nm9726
\??\nm2835
\??\nm896
\??\nm1027
\??\nm37
\??\nm8
\??\nm2479
\??\nm995
\??\nm8935
\??\nm795
\??\nm7393
\??\nm9284
\??\nm92388
\??\nm23750
\??\nm79239
\??\nm7924
\??\nm24
\??\nm973
\??\nm284
\??\nm90
\??\ol1025
\??\ol369
\??\ol79
\??\ol24786
\??\ol9946
\??\ol89346
\??\ol7944
\??\ol73925
\??\ol92835
\??\ol923876
\??\ol237493
\??\ol792385
\??\ol79236
\??\ol235
\??\ol9726
\??\ol2835
\??\ol896
\??\ol1027
\??\ol37
\??\ol8
\??\ol2479
\??\ol995
\??\ol8935
\??\ol795
\??\ol7393
\??\ol9284
\??\ol92388
\??\ol23750
\??\ol79239
\??\ol7924
\??\ol24
\??\ol973
\??\ol284
\??\ol90
\??\pk1025
\??\pk369
\??\pk79
\??\pk24786
\??\pk9946
\??\pk89346
\??\pk7944
\??\pk73925
\??\pk92835
\??\pk923876
\??\pk237493
\??\pk792385
\??\pk79236
\??\pk235
\??\pk9726
\??\pk2835
\??\pk896
\??\pk1027
\??\pk37
\??\pk8
\??\pk2479
\??\pk995
\??\pk8935
\??\pk795
\??\pk7393
\??\pk9284
\??\pk92388
\??\pk23750
\??\pk79239
\??\pk7924
\??\pk24
\??\pk973
\??\pk284
\??\pk90
\??\qj1025
\??\qj369
\??\qj79
\??\qj24786
\??\qj9946
\??\qj89346
\??\qj7944
\??\qj73925
\??\qj92835
\??\qj923876
\??\qj237493
\??\qj792385
\??\qj79236
\??\qj235
\??\qj9726
\??\qj2835
\??\qj896
\??\qj1027
\??\qj37
\??\qj8
\??\qj2479
\??\qj995
\??\qj8935
\??\qj795
\??\qj7393
\??\qj9284
\??\qj92388
\??\qj23750
\??\qj79239
\??\qj7924
\??\qj24
\??\qj973
\??\qj284
\??\qj90
\??\ri1025
\??\ri369
\??\ri79
\??\ri24786
\??\ri9946
\??\ri89346
\??\ri7944
\??\ri73925
\??\ri92835
\??\ri923876
\??\ri237493
\??\ri792385
\??\ri79236
\??\ri235
\??\ri9726
\??\ri2835
\??\ri896
\??\ri1027
\??\ri37
\??\ri8
\??\ri2479
\??\ri995
\??\ri8935
\??\ri795
\??\ri7393
\??\ri9284
\??\ri92388
\??\ri23750
\??\ri79239
\??\ri7924
\??\ri24
\??\ri973
\??\ri284
\??\ri90
\??\sh1025
\??\sh369
\??\sh79
\??\sh24786
\??\sh9946
\??\sh89346
\??\sh7944
\??\sh73925
\??\sh92835
\??\sh923876
\??\sh237493
\??\sh792385
\??\sh79236
\??\sh235
\??\sh9726
\??\sh2835
\??\sh896
\??\sh1027
\??\sh37
\??\sh8
\??\sh2479
\??\sh995
\??\sh8935
\??\sh795
\??\sh7393
\??\sh9284
\??\sh92388
\??\sh23750
\??\sh79239
\??\sh7924
\??\sh24
\??\sh973
\??\sh284
\??\sh90
\??\tg1025
\??\tg369
\??\tg79
\??\tg24786
\??\tg9946
\??\tg89346
\??\tg7944
\??\tg73925
\??\tg92835
\??\tg923876
\??\tg237493
\??\tg792385
\??\tg79236
\??\tg235
\??\tg9726
\??\tg2835
\??\tg896
\??\tg1027
\??\tg37
\??\tg8
\??\tg2479
\??\tg995
\??\tg8935
\??\tg795
\??\tg7393
\??\tg9284
\??\tg92388
\??\tg23750
\??\tg79239
\??\tg7924
\??\tg24
\??\tg973
\??\tg284
\??\tg90
\??\uf1025
\??\uf369
\??\uf79
\??\uf24786
\??\uf9946
\??\uf89346
\??\uf7944
\??\uf73925
\??\uf92835
\??\uf923876
\??\uf237493
\??\uf792385
\??\uf79236
\??\uf235
\??\uf9726
\??\uf2835
\??\uf896
\??\uf1027
\??\uf37
\??\uf8
\??\uf2479
\??\uf995
\??\uf8935
\??\uf795
\??\uf7393
\??\uf9284
\??\uf92388
\??\uf23750
\??\uf79239
\??\uf7924
\??\uf24
\??\uf973
\??\uf284
\??\uf90
\??\ve1025
\??\ve369
\??\ve79
\??\ve24786
\??\ve9946
\??\ve89346
\??\ve7944
\??\ve73925
\??\ve92835
\??\ve923876
\??\ve237493
\??\ve792385
\??\ve79236
\??\ve235
\??\ve9726
\??\ve2835
\??\ve896
\??\ve1027
\??\ve37
\??\ve8
\??\ve2479
\??\ve995
\??\ve8935
\??\ve795
\??\ve7393
\??\ve9284
\??\ve92388
\??\ve23750
\??\ve79239
\??\ve7924
\??\ve24
\??\ve973
\??\ve284
\??\ve90
\??\wd1025
\??\wd369
\??\wd79
\??\wd24786
\??\wd9946
\??\wd89346
\??\wd7944
\??\wd73925
\??\wd92835
\??\wd923876
\??\wd237493
\??\wd792385
\??\wd79236
\??\wd235
\??\wd9726
\??\wd2835
\??\wd896
\??\wd1027
\??\wd37
\??\wd8
\??\wd2479
\??\wd995
\??\wd8935
\??\wd795
\??\wd7393
\??\wd9284
\??\wd92388
\??\wd23750
\??\wd79239
\??\wd7924
\??\wd24
\??\wd973
\??\wd284
\??\wd90
\??\xc1025
\??\xc369
\??\xc79
\??\xc24786
\??\xc9946
\??\xc89346
\??\xc7944
\??\xc73925
\??\xc92835
\??\xc923876
\??\xc237493
\??\xc792385
\??\xc79236
\??\xc235
\??\xc9726
\??\xc2835
\??\xc896
\??\xc1027
\??\xc37
\??\xc8
\??\xc2479
\??\xc995
\??\xc8935
\??\xc795
\??\xc7393
\??\xc9284
\??\xc92388
\??\xc23750
\??\xc79239
\??\xc7924
\??\xc24
\??\xc973
\??\xc284
\??\xc90
\??\yb1025
\??\yb369
\??\yb79
\??\yb24786
\??\yb9946
\??\yb89346
\??\yb7944
\??\yb73925
\??\yb92835
\??\yb923876
\??\yb237493
\??\yb792385
\??\yb79236
\??\yb235
\??\yb9726
\??\yb2835
\??\yb896
\??\yb1027
\??\yb37
\??\yb8
\??\yb2479
\??\yb995
\??\yb8935
\??\yb795
\??\yb7393
\??\yb9284
\??\yb92388
\??\yb23750
\??\yb79239
\??\yb7924
\??\yb24
\??\yb973
\??\yb284
\??\yb90
C:\Windows\System32\ntdll.dll
C:\Users\test\AppData\Local\Temp\xxc.dll.2.Manifest
C:\Users\test\AppData\Local\Temp\xxc.dll.3.Manifest
C:\Users\test\AppData\Local\Temp\xxc.dll.Manifest
C:\Windows\SysWOW64\stdole2.tlb
\??\PhysicalDrive0
\??\a10284132
\??\a368173
\??\a78714
\??\a24785531
\??\a994451
\??\a89534451
\??\a7954431
\??\a73964241
\??\a92648341
\??\a923843751
\??\a239744912
\??\a792038441
\??\a79233051
\??\a232401
\??\a9017215
\??\a2083114
\??\a181950
\??\a1028361
\??\a376871
\??\a7771
\??\a2478851
\??\a999441
\??\a8093441
\??\a279441
\??\a7334921
\??\a9204831
\??\a92348071
\??\a23074491
\??\a79203481
\??\a7903231
\??\a23301
\??\a972201
\??\a280113
\??\a81109
\??\b10284132
\??\b368173
\??\b78714
\??\b24785531
\??\b994451
\??\b89534451
\??\b7954431
\??\b73964241
\??\b92648341
\??\b923843751
\??\b239744912
\??\b792038441
\??\b79233051
\??\b232401
\??\b9017215
\??\b2083114
\??\b181950
\??\b1028361
\??\b376871
\??\b7771
\??\b2478851
\??\b999441
\??\b8093441
\??\b279441
\??\b7334921
\??\b9204831
\??\b92348071
\??\b23074491
\??\b79203481
\??\b7903231
\??\b23301
\??\b972201
\??\b280113
\??\b81109
\??\c10284132
\??\c368173
\??\c78714
\??\c24785531
\??\c994451
\??\c89534451
\??\c7954431
\??\c73964241
\??\c92648341
\??\c923843751
\??\c239744912
\??\c792038441
\??\c79233051
\??\c232401
\??\c9017215
\??\c2083114
\??\c181950
\??\c1028361
\??\c376871
\??\c7771
\??\c2478851
\??\c999441
\??\c8093441
\??\c279441
\??\c7334921
\??\c9204831
\??\c92348071
\??\c23074491
\??\c79203481
\??\c7903231
\??\c23301
\??\c972201
\??\c280113
\??\c81109
\??\d10284132
\??\d368173
\??\d78714
\??\d24785531
\??\d994451
\??\d89534451
\??\d7954431
\??\d73964241
\??\d92648341
\??\d923843751
\??\d239744912
\??\d792038441
\??\d79233051
\??\d232401
\??\d9017215
\??\d2083114
\??\d181950
\??\d1028361
\??\d376871
\??\d7771
\??\d2478851
\??\d999441
\??\d8093441
\??\d279441
\??\d7334921
\??\d9204831
\??\d92348071
\??\d23074491
\??\d79203481
\??\d7903231
\??\d23301
\??\d972201
\??\d280113
\??\d81109
\??\e10284132
\??\e368173
\??\e78714
\??\e24785531
\??\e994451
\??\e89534451
\??\e7954431
\??\e73964241
\??\e92648341
\??\e923843751
\??\e239744912
\??\e792038441
\??\e79233051
\??\e232401
\??\e9017215
\??\e2083114
\??\e181950
\??\e1028361
\??\e376871
\??\e7771
\??\e2478851
\??\e999441
\??\e8093441
\??\e279441
\??\e7334921
\??\e9204831
\??\e92348071
\??\e23074491
\??\e79203481
\??\e7903231
\??\e23301
\??\e972201
\??\e280113
\??\e81109
\??\f10284132
\??\f368173
\??\f78714
\??\f24785531
\??\f994451
\??\f89534451
\??\f7954431
\??\f73964241
\??\f92648341
\??\f923843751
\??\f239744912
\??\f792038441
\??\f79233051
\??\f232401
\??\f9017215
\??\f2083114
\??\f181950
\??\f1028361
\??\f376871
\??\f7771
\??\f2478851
\??\f999441
\??\f8093441
\??\f279441
\??\f7334921
\??\f9204831
\??\f92348071
\??\f23074491
\??\f79203481
\??\f7903231
\??\f23301
\??\f972201
\??\f280113
\??\f81109
\??\g10284132
\??\g368173
\??\g78714
\??\g24785531
\??\g994451
\??\g89534451
\??\g7954431
\??\g73964241
\??\g92648341
\??\g923843751
\??\g239744912
\??\g792038441
\??\g79233051
\??\g232401
\??\g9017215
\??\g2083114
\??\g181950
\??\g1028361
\??\g376871
\??\g7771
\??\g2478851
\??\g999441
\??\g8093441
\??\g279441
\??\g7334921
\??\g9204831
\??\g92348071
\??\g23074491
\??\g79203481
\??\g7903231
\??\g23301
\??\g972201
\??\g280113
\??\g81109
\??\h10284132
\??\h368173
\??\h78714
\??\h24785531
\??\h994451
\??\h89534451
\??\h7954431
\??\h73964241
\??\h92648341
\??\h923843751
\??\h239744912
\??\h792038441
\??\h79233051
\??\h232401
\??\h9017215
\??\h2083114
\??\h181950
\??\h1028361
\??\h376871
\??\h7771
\??\h2478851
\??\h999441
\??\h8093441
\??\h279441
\??\h7334921
\??\h9204831
\??\h92348071
\??\h23074491
\??\h79203481
\??\h7903231
\??\h23301
\??\h972201
\??\h280113
\??\h81109
\??\i10284132
\??\i368173
\??\i78714
\??\i24785531
\??\i994451
\??\i89534451
\??\i7954431
\??\i73964241
\??\i92648341
\??\i923843751
\??\i239744912
\??\i792038441
\??\i79233051
\??\i232401
\??\i9017215
\??\i2083114
\??\i181950
\??\i1028361
\??\i376871
\??\i7771
\??\i2478851
\??\i999441
\??\i8093441
\??\i279441
\??\i7334921
\??\i9204831
\??\i92348071
\??\i23074491
\??\i79203481
\??\i7903231
\??\i23301
\??\i972201
\??\i280113
\??\i81109
\??\j10284132
\??\j368173
\??\j78714
\??\j24785531
\??\j994451
\??\j89534451
\??\j7954431
\??\j73964241
\??\j92648341
\??\j923843751
\??\j239744912
\??\j792038441
\??\j79233051
\??\j232401
\??\j9017215
\??\j2083114
\??\j181950
\??\j1028361
\??\j376871
\??\j7771
\??\j2478851
\??\j999441
\??\j8093441
\??\j279441
\??\j7334921
\??\j9204831
\??\j92348071
\??\j23074491
\??\j79203481
\??\j7903231
\??\j23301
\??\j972201
\??\j280113
\??\j81109
\??\k10284132
\??\k368173
\??\k78714
\??\k24785531
\??\k994451
\??\k89534451
\??\k7954431
\??\k73964241
\??\k92648341
\??\k923843751
\??\k239744912
\??\k792038441
\??\k79233051
\??\k232401
\??\k9017215
\??\k2083114
\??\k181950
\??\k1028361
\??\k376871
\??\k7771
\??\k2478851
\??\k999441
\??\k8093441
\??\k279441
\??\k7334921
\??\k9204831
\??\k92348071
\??\k23074491
\??\k79203481
\??\k7903231
\??\k23301
\??\k972201
\??\k280113
\??\k81109
\??\l10284132
\??\l368173
\??\l78714
\??\l24785531
\??\l994451
\??\l89534451
\??\l7954431
\??\l73964241
\??\l92648341
\??\l923843751
\??\l239744912
\??\l792038441
\??\l79233051
\??\l232401
\??\l9017215
\??\l2083114
\??\l181950
\??\l1028361
\??\l376871
\??\l7771
\??\l2478851
\??\l999441
\??\l8093441
\??\l279441
\??\l7334921
\??\l9204831
\??\l92348071
\??\l23074491
\??\l79203481
\??\l7903231
\??\l23301
\??\l972201
\??\l280113
\??\l81109
\??\m10284132
\??\m368173
\??\m78714
\??\m24785531
\??\m994451
\??\m89534451
\??\m7954431
\??\m73964241
\??\m92648341
\??\m923843751
\??\m239744912
\??\m792038441
\??\m79233051
\??\m232401
\??\m9017215
\??\m2083114
\??\m181950
\??\m1028361
\??\m376871
\??\m7771
\??\m2478851
\??\m999441
\??\m8093441
\??\m279441
\??\m7334921
\??\m9204831
\??\m92348071
\??\m23074491
\??\m79203481
\??\m7903231
\??\m23301
\??\m972201
\??\m280113
\??\m81109
\??\n10284132
\??\n368173
\??\n78714
\??\n24785531
\??\n994451
\??\n89534451
\??\n7954431
\??\n73964241
\??\n92648341
\??\n923843751
\??\n239744912
\??\n792038441
\??\n79233051
\??\n232401
\??\n9017215
\??\n2083114
\??\n181950
\??\n1028361
\??\n376871
\??\n7771
\??\n2478851
\??\n999441
\??\n8093441
\??\n279441
\??\n7334921
\??\n9204831
\??\n92348071
\??\n23074491
\??\n79203481
\??\n7903231
\??\n23301
\??\n972201
\??\n280113
\??\n81109
\??\o10284132
\??\o368173
\??\o78714
\??\o24785531
\??\o994451
\??\o89534451
\??\o7954431
\??\o73964241
\??\o92648341
\??\o923843751
\??\o239744912
\??\o792038441
\??\o79233051
\??\o232401
\??\o9017215
\??\o2083114
\??\o181950
\??\o1028361
\??\o376871
\??\o7771
\??\o2478851
\??\o999441
\??\o8093441
\??\o279441
\??\o7334921
\??\o9204831
\??\o92348071
\??\o23074491
\??\o79203481
\??\o7903231
\??\o23301
\??\o972201
\??\o280113
\??\o81109
\??\p10284132
\??\p368173
\??\p78714
\??\p24785531
\??\p994451
\??\p89534451
\??\p7954431
\??\p73964241
\??\p92648341
\??\p923843751
\??\p239744912
\??\p792038441
\??\p79233051
\??\p232401
\??\p9017215
\??\p2083114
\??\p181950
\??\p1028361
\??\p376871
\??\p7771
\??\p2478851
\??\p999441
\??\p8093441
\??\p279441
\??\p7334921
\??\p9204831
\??\p92348071
\??\p23074491
\??\p79203481
\??\p7903231
\??\p23301
\??\p972201
\??\p280113
\??\p81109
\??\q10284132
\??\q368173
\??\q78714
\??\q24785531
\??\q994451
\??\q89534451
\??\q7954431
\??\q73964241
\??\q92648341
\??\q923843751
\??\q239744912
\??\q792038441
\??\q79233051
\??\q232401
\??\q9017215
\??\q2083114
\??\q181950
\??\q1028361
\??\q376871
\??\q7771
\??\q2478851
\??\q999441
\??\q8093441
\??\q279441
\??\q7334921
\??\q9204831
\??\q92348071
\??\q23074491
\??\q79203481
\??\q7903231
\??\q23301
\??\q972201
\??\q280113
\??\q81109
\??\r10284132
\??\r368173
\??\r78714
\??\r24785531
\??\r994451
\??\r89534451
\??\r7954431
\??\r73964241
\??\r92648341
\??\r923843751
\??\r239744912
\??\r792038441
\??\r79233051
\??\r232401
\??\r9017215
\??\r2083114
\??\r181950
\??\r1028361
\??\r376871
\??\r7771
\??\r2478851
\??\r999441
\??\r8093441
\??\r279441
\??\r7334921
\??\r9204831
\??\r92348071
\??\r23074491
\??\r79203481
\??\r7903231
\??\r23301
\??\r972201
\??\r280113
\??\r81109
\??\s10284132
\??\s368173
\??\s78714
\??\s24785531
\??\s994451
\??\s89534451
\??\s7954431
\??\s73964241
\??\s92648341
\??\s923843751
\??\s239744912
\??\s792038441
\??\s79233051
\??\s232401
\??\s9017215
\??\s2083114
\??\s181950
\??\s1028361
\??\s376871
\??\s7771
\??\s2478851
\??\s999441
\??\s8093441
\??\s279441
\??\s7334921
\??\s9204831
\??\s92348071
\??\s23074491
\??\s79203481
\??\s7903231
\??\s23301
\??\s972201
\??\s280113
\??\s81109
\??\t10284132
\??\t368173
\??\t78714
\??\t24785531
\??\t994451
\??\t89534451
\??\t7954431
\??\t73964241
\??\t92648341
\??\t923843751
\??\t239744912
\??\t792038441
\??\t79233051
\??\t232401
\??\t9017215
\??\t2083114
\??\t181950
\??\t1028361
\??\t376871
\??\t7771
\??\t2478851
\??\t999441
\??\t8093441
\??\t279441
\??\t7334921
\??\t9204831
\??\t92348071
\??\t23074491
\??\t79203481
\??\t7903231
\??\t23301
\??\t972201
\??\t280113
\??\t81109
\??\u10284132
\??\u368173
\??\u78714
\??\u24785531
\??\u994451
\??\u89534451
\??\u7954431
\??\u73964241
\??\u92648341
\??\u923843751
\??\u239744912
\??\u792038441
\??\u79233051
\??\u232401
\??\u9017215
\??\u2083114
\??\u181950
\??\u1028361
\??\u376871
\??\u7771
\??\u2478851
\??\u999441
\??\u8093441
\??\u279441
\??\u7334921
\??\u9204831
\??\u92348071
\??\u23074491
\??\u79203481
\??\u7903231
\??\u23301
\??\u972201
\??\u280113
\??\u81109
\??\v10284132
\??\v368173
\??\v78714
\??\v24785531
\??\v994451
\??\v89534451
\??\v7954431
\??\v73964241
\??\v92648341
\??\v923843751
\??\v239744912
\??\v792038441
\??\v79233051
\??\v232401
\??\v9017215
\??\v2083114
\??\v181950
\??\v1028361
\??\v376871
\??\v7771
\??\v2478851
\??\v999441
\??\v8093441
\??\v279441
\??\v7334921
\??\v9204831
\??\v92348071
\??\v23074491
\??\v79203481
\??\v7903231
\??\v23301
\??\v972201
\??\v280113
\??\v81109
\??\w10284132
\??\w368173
\??\w78714
\??\w24785531
\??\w994451
\??\w89534451
\??\w7954431
\??\w73964241
\??\w92648341
\??\w923843751
\??\w239744912
\??\w792038441
\??\w79233051
\??\w232401
\??\w9017215
\??\w2083114
\??\w181950
\??\w1028361
\??\w376871
\??\w7771
\??\w2478851
\??\w999441
\??\w8093441
\??\w279441
\??\w7334921
\??\w9204831
\??\w92348071
\??\w23074491
\??\w79203481
\??\w7903231
\??\w23301
\??\w972201
\??\w280113
\??\w81109
\??\x10284132
\??\x368173
\??\x78714
\??\x24785531
\??\x994451
\??\x89534451
\??\x7954431
\??\x73964241
\??\x92648341
\??\x923843751
\??\x239744912
\??\x792038441
\??\x79233051
\??\x232401
\??\x9017215
\??\x2083114
\??\x181950
\??\x1028361
\??\x376871
\??\x7771
\??\x2478851
\??\x999441
\??\x8093441
\??\x279441
\??\x7334921
\??\x9204831
\??\x92348071
\??\x23074491
\??\x79203481
\??\x7903231
\??\x23301
\??\x972201
\??\x280113
\??\x81109
\??\y10284132
\??\y368173
\??\y78714
\??\y24785531
\??\y994451
\??\y89534451
\??\y7954431
\??\y73964241
\??\y92648341
\??\y923843751
\??\y239744912
\??\y792038441
\??\y79233051
\??\y232401
\??\y9017215
\??\y2083114
\??\y181950
\??\y1028361
\??\y376871
\??\y7771
\??\y2478851
\??\y999441
\??\y8093441
\??\y279441
\??\y7334921
\??\y9204831
\??\y92348071
\??\y23074491
\??\y79203481
\??\y7903231
\??\y23301
\??\y972201
\??\y280113
\??\y81109
\??\z10284132
\??\z368173
\??\z78714
\??\z24785531
\??\z994451
\??\z89534451
\??\z7954431
\??\z73964241
\??\z92648341
\??\z923843751
\??\z239744912
\??\z792038441
\??\z79233051
\??\z232401
\??\z9017215
\??\z2083114
\??\z181950
\??\z1028361
\??\z376871
\??\z7771
\??\z2478851
\??\z999441
\??\z8093441
\??\z279441
\??\z7334921
\??\z9204831
\??\z92348071
\??\z23074491
\??\z79203481
\??\z7903231
\??\z23301
\??\z972201
\??\z280113
\??\z81109
C:\Users\test\AppData\Local\Temp\c1396.sys
C:\Windows\SysWOW64\ntdll.dll
C:\Windows\SysWOW64\KernelBase.dll
C:\Windows\SysWOW64\kernel32.dll
C:\Windows\SysWOW64\user32.dll
C:\Windows\SysWOW64\advapi32.dll
C:\Windows\SysWOW64\IPHLPAPI.DLL
C:\Users\test\AppData\Local\Temp\xxc.dll
C:\Users\test\AppData\Local\Temp\DmReg.dll
\??\az1025
\??\az369
\??\az79
\??\az24786
\??\az9946
\??\az89346
\??\az7944
\??\az73925
\??\az92835
\??\az923876
\??\az237493
\??\az792385
\??\az79236
\??\az235
\??\az9726
\??\az2835
\??\az896
\??\az1027
\??\az37
\??\az8
\??\az2479
\??\az995
\??\az8935
\??\az795
\??\az7393
\??\az9284
\??\az92388
\??\az23750
\??\az79239
\??\az7924
\??\az24
\??\az973
\??\az284
\??\az90
\??\by1025
\??\by369
\??\by79
\??\by24786
\??\by9946
\??\by89346
\??\by7944
\??\by73925
\??\by92835
\??\by923876
\??\by237493
\??\by792385
\??\by79236
\??\by235
\??\by9726
\??\by2835
\??\by896
\??\by1027
\??\by37
\??\by8
\??\by2479
\??\by995
\??\by8935
\??\by795
\??\by7393
\??\by9284
\??\by92388
\??\by23750
\??\by79239
\??\by7924
\??\by24
\??\by973
\??\by284
\??\by90
\??\cx1025
\??\cx369
\??\cx79
\??\cx24786
\??\cx9946
\??\cx89346
\??\cx7944
\??\cx73925
\??\cx92835
\??\cx923876
\??\cx237493
\??\cx792385
\??\cx79236
\??\cx235
\??\cx9726
\??\cx2835
\??\cx896
\??\cx1027
\??\cx37
\??\cx8
\??\cx2479
\??\cx995
\??\cx8935
\??\cx795
\??\cx7393
\??\cx9284
\??\cx92388
\??\cx23750
\??\cx79239
\??\cx7924
\??\cx24
\??\cx973
\??\cx284
\??\cx90
\??\dw1025
\??\dw369
\??\dw79
\??\dw24786
\??\dw9946
\??\dw89346
\??\dw7944
\??\dw73925
\??\dw92835
\??\dw923876
\??\dw237493
\??\dw792385
\??\dw79236
\??\dw235
\??\dw9726
\??\dw2835
\??\dw896
\??\dw1027
\??\dw37
\??\dw8
\??\dw2479
\??\dw995
\??\dw8935
\??\dw795
\??\dw7393
\??\dw9284
\??\dw92388
\??\dw23750
\??\dw79239
\??\dw7924
\??\dw24
\??\dw973
\??\dw284
\??\dw90
\??\ev1025
\??\ev369
\??\ev79
\??\ev24786
\??\ev9946
\??\ev89346
\??\ev7944
\??\ev73925
\??\ev92835
\??\ev923876
\??\ev237493
\??\ev792385
\??\ev79236
\??\ev235
\??\ev9726
\??\ev2835
\??\ev896
\??\ev1027
\??\ev37
\??\ev8
\??\ev2479
\??\ev995
\??\ev8935
\??\ev795
\??\ev7393
\??\ev9284
\??\ev92388
\??\ev23750
\??\ev79239
\??\ev7924
\??\ev24
\??\ev973
\??\ev284
\??\ev90
\??\fu1025
\??\fu369
\??\fu79
\??\fu24786
\??\fu9946
\??\fu89346
\??\fu7944
\??\fu73925
\??\fu92835
\??\fu923876
\??\fu237493
\??\fu792385
\??\fu79236
\??\fu235
\??\fu9726
\??\fu2835
\??\fu896
\??\fu1027
\??\fu37
\??\fu8
\??\fu2479
\??\fu995
\??\fu8935
\??\fu795
\??\fu7393
\??\fu9284
\??\fu92388
\??\fu23750
\??\fu79239
\??\fu7924
\??\fu24
\??\fu973
\??\fu284
\??\fu90
\??\gt1025
\??\gt369
\??\gt79
\??\gt24786
\??\gt9946
\??\gt89346
\??\gt7944
\??\gt73925
\??\gt92835
\??\gt923876
\??\gt237493
\??\gt792385
\??\gt79236
\??\gt235
\??\gt9726
\??\gt2835
\??\gt896
\??\gt1027
\??\gt37
\??\gt8
\??\gt2479
\??\gt995
\??\gt8935
\??\gt795
\??\gt7393
\??\gt9284
\??\gt92388
\??\gt23750
\??\gt79239
\??\gt7924
\??\gt24
\??\gt973
\??\gt284
\??\gt90
\??\hs1025
\??\hs369
\??\hs79
\??\hs24786
\??\hs9946
\??\hs89346
\??\hs7944
\??\hs73925
\??\hs92835
\??\hs923876
\??\hs237493
\??\hs792385
\??\hs79236
\??\hs235
\??\hs9726
\??\hs2835
\??\hs896
\??\hs1027
\??\hs37
\??\hs8
\??\hs2479
\??\hs995
\??\hs8935
\??\hs795
\??\hs7393
\??\hs9284
\??\hs92388
\??\hs23750
\??\hs79239
\??\hs7924
\??\hs24
\??\hs973
\??\hs284
\??\hs90
\??\ir1025
\??\ir369
\??\ir79
\??\ir24786
\??\ir9946
\??\ir89346
\??\ir7944
\??\ir73925
\??\ir92835
\??\ir923876
\??\ir237493
\??\ir792385
\??\ir79236
\??\ir235
\??\ir9726
\??\ir2835
\??\ir896
\??\ir1027
\??\ir37
\??\ir8
\??\ir2479
\??\ir995
\??\ir8935
\??\ir795
\??\ir7393
\??\ir9284
\??\ir92388
\??\ir23750
\??\ir79239
\??\ir7924
\??\ir24
\??\ir973
\??\ir284
\??\ir90
\??\jq1025
\??\jq369
\??\jq79
\??\jq24786
\??\jq9946
\??\jq89346
\??\jq7944
\??\jq73925
\??\jq92835
\??\jq923876
\??\jq237493
\??\jq792385
\??\jq79236
\??\jq235
\??\jq9726
\??\jq2835
\??\jq896
\??\jq1027
\??\jq37
\??\jq8
\??\jq2479
\??\jq995
\??\jq8935
\??\jq795
\??\jq7393
\??\jq9284
\??\jq92388
\??\jq23750
\??\jq79239
\??\jq7924
\??\jq24
\??\jq973
\??\jq284
\??\jq90
\??\kp1025
\??\kp369
\??\kp79
\??\kp24786
\??\kp9946
\??\kp89346
\??\kp7944
\??\kp73925
\??\kp92835
\??\kp923876
\??\kp237493
\??\kp792385
\??\kp79236
\??\kp235
\??\kp9726
\??\kp2835
\??\kp896
\??\kp1027
\??\kp37
\??\kp8
\??\kp2479
\??\kp995
\??\kp8935
\??\kp795
\??\kp7393
\??\kp9284
\??\kp92388
\??\kp23750
\??\kp79239
\??\kp7924
\??\kp24
\??\kp973
\??\kp284
\??\kp90
\??\lo1025
\??\lo369
\??\lo79
\??\lo24786
\??\lo9946
\??\lo89346
\??\lo7944
\??\lo73925
\??\lo92835
\??\lo923876
\??\lo237493
\??\lo792385
\??\lo79236
\??\lo235
\??\lo9726
\??\lo2835
\??\lo896
\??\lo1027
\??\lo37
\??\lo8
\??\lo2479
\??\lo995
\??\lo8935
\??\lo795
\??\lo7393
\??\lo9284
\??\lo92388
\??\lo23750
\??\lo79239
\??\lo7924
\??\lo24
\??\lo973
\??\lo284
\??\lo90
\??\mn1025
\??\mn369
\??\mn79
\??\mn24786
\??\mn9946
\??\mn89346
\??\mn7944
\??\mn73925
\??\mn92835
\??\mn923876
\??\mn237493
\??\mn792385
\??\mn79236
\??\mn235
\??\mn9726
\??\mn2835
\??\mn896
\??\mn1027
\??\mn37
\??\mn8
\??\mn2479
\??\mn995
\??\mn8935
\??\mn795
\??\mn7393
\??\mn9284
\??\mn92388
\??\mn23750
\??\mn79239
\??\mn7924
\??\mn24
\??\mn973
\??\mn284
\??\mn90
\??\nm1025
\??\nm369
\??\nm79
\??\nm24786
\??\nm9946
\??\nm89346
\??\nm7944
\??\nm73925
\??\nm92835
\??\nm923876
\??\nm237493
\??\nm792385
\??\nm79236
\??\nm235
\??\nm9726
\??\nm2835
\??\nm896
\??\nm1027
\??\nm37
\??\nm8
\??\nm2479
\??\nm995
\??\nm8935
\??\nm795
\??\nm7393
\??\nm9284
\??\nm92388
\??\nm23750
\??\nm79239
\??\nm7924
\??\nm24
\??\nm973
\??\nm284
\??\nm90
\??\ol1025
\??\ol369
\??\ol79
\??\ol24786
\??\ol9946
\??\ol89346
\??\ol7944
\??\ol73925
\??\ol92835
\??\ol923876
\??\ol237493
\??\ol792385
\??\ol79236
\??\ol235
\??\ol9726
\??\ol2835
\??\ol896
\??\ol1027
\??\ol37
\??\ol8
\??\ol2479
\??\ol995
\??\ol8935
\??\ol795
\??\ol7393
\??\ol9284
\??\ol92388
\??\ol23750
\??\ol79239
\??\ol7924
\??\ol24
\??\ol973
\??\ol284
\??\ol90
\??\pk1025
\??\pk369
\??\pk79
\??\pk24786
\??\pk9946
\??\pk89346
\??\pk7944
\??\pk73925
\??\pk92835
\??\pk923876
\??\pk237493
\??\pk792385
\??\pk79236
\??\pk235
\??\pk9726
\??\pk2835
\??\pk896
\??\pk1027
\??\pk37
\??\pk8
\??\pk2479
\??\pk995
\??\pk8935
\??\pk795
\??\pk7393
\??\pk9284
\??\pk92388
\??\pk23750
\??\pk79239
\??\pk7924
\??\pk24
\??\pk973
\??\pk284
\??\pk90
\??\qj1025
\??\qj369
\??\qj79
\??\qj24786
\??\qj9946
\??\qj89346
\??\qj7944
\??\qj73925
\??\qj92835
\??\qj923876
\??\qj237493
\??\qj792385
\??\qj79236
\??\qj235
\??\qj9726
\??\qj2835
\??\qj896
\??\qj1027
\??\qj37
\??\qj8
\??\qj2479
\??\qj995
\??\qj8935
\??\qj795
\??\qj7393
\??\qj9284
\??\qj92388
\??\qj23750
\??\qj79239
\??\qj7924
\??\qj24
\??\qj973
\??\qj284
\??\qj90
\??\ri1025
\??\ri369
\??\ri79
\??\ri24786
\??\ri9946
\??\ri89346
\??\ri7944
\??\ri73925
\??\ri92835
\??\ri923876
\??\ri237493
\??\ri792385
\??\ri79236
\??\ri235
\??\ri9726
\??\ri2835
\??\ri896
\??\ri1027
\??\ri37
\??\ri8
\??\ri2479
\??\ri995
\??\ri8935
\??\ri795
\??\ri7393
\??\ri9284
\??\ri92388
\??\ri23750
\??\ri79239
\??\ri7924
\??\ri24
\??\ri973
\??\ri284
\??\ri90
\??\sh1025
\??\sh369
\??\sh79
\??\sh24786
\??\sh9946
\??\sh89346
\??\sh7944
\??\sh73925
\??\sh92835
\??\sh923876
\??\sh237493
\??\sh792385
\??\sh79236
\??\sh235
\??\sh9726
\??\sh2835
\??\sh896
\??\sh1027
\??\sh37
\??\sh8
\??\sh2479
\??\sh995
\??\sh8935
\??\sh795
\??\sh7393
\??\sh9284
\??\sh92388
\??\sh23750
\??\sh79239
\??\sh7924
\??\sh24
\??\sh973
\??\sh284
\??\sh90
\??\tg1025
\??\tg369
\??\tg79
\??\tg24786
\??\tg9946
\??\tg89346
\??\tg7944
\??\tg73925
\??\tg92835
\??\tg923876
\??\tg237493
\??\tg792385
\??\tg79236
\??\tg235
\??\tg9726
\??\tg2835
\??\tg896
\??\tg1027
\??\tg37
\??\tg8
\??\tg2479
\??\tg995
\??\tg8935
\??\tg795
\??\tg7393
\??\tg9284
\??\tg92388
\??\tg23750
\??\tg79239
\??\tg7924
\??\tg24
\??\tg973
\??\tg284
\??\tg90
\??\uf1025
\??\uf369
\??\uf79
\??\uf24786
\??\uf9946
\??\uf89346
\??\uf7944
\??\uf73925
\??\uf92835
\??\uf923876
\??\uf237493
\??\uf792385
\??\uf79236
\??\uf235
\??\uf9726
\??\uf2835
\??\uf896
\??\uf1027
\??\uf37
\??\uf8
\??\uf2479
\??\uf995
\??\uf8935
\??\uf795
\??\uf7393
\??\uf9284
\??\uf92388
\??\uf23750
\??\uf79239
\??\uf7924
\??\uf24
\??\uf973
\??\uf284
\??\uf90
\??\ve1025
\??\ve369
\??\ve79
\??\ve24786
\??\ve9946
\??\ve89346
\??\ve7944
\??\ve73925
\??\ve92835
\??\ve923876
\??\ve237493
\??\ve792385
\??\ve79236
\??\ve235
\??\ve9726
\??\ve2835
\??\ve896
\??\ve1027
\??\ve37
\??\ve8
\??\ve2479
\??\ve995
\??\ve8935
\??\ve795
\??\ve7393
\??\ve9284
\??\ve92388
\??\ve23750
\??\ve79239
\??\ve7924
\??\ve24
\??\ve973
\??\ve284
\??\ve90
\??\wd1025
\??\wd369
\??\wd79
\??\wd24786
\??\wd9946
\??\wd89346
\??\wd7944
\??\wd73925
\??\wd92835
\??\wd923876
\??\wd237493
\??\wd792385
\??\wd79236
\??\wd235
\??\wd9726
\??\wd2835
\??\wd896
\??\wd1027
\??\wd37
\??\wd8
\??\wd2479
\??\wd995
\??\wd8935
\??\wd795
\??\wd7393
\??\wd9284
\??\wd92388
\??\wd23750
\??\wd79239
\??\wd7924
\??\wd24
\??\wd973
\??\wd284
\??\wd90
\??\xc1025
\??\xc369
\??\xc79
\??\xc24786
\??\xc9946
\??\xc89346
\??\xc7944
\??\xc73925
\??\xc92835
\??\xc923876
\??\xc237493
\??\xc792385
\??\xc79236
\??\xc235
\??\xc9726
\??\xc2835
\??\xc896
\??\xc1027
\??\xc37
\??\xc8
\??\xc2479
\??\xc995
\??\xc8935
\??\xc795
\??\xc7393
\??\xc9284
\??\xc92388
\??\xc23750
\??\xc79239
\??\xc7924
\??\xc24
\??\xc973
\??\xc284
\??\xc90
\??\yb1025
\??\yb369
\??\yb79
\??\yb24786
\??\yb9946
\??\yb89346
\??\yb7944
\??\yb73925
\??\yb92835
\??\yb923876
\??\yb237493
\??\yb792385
\??\yb79236
\??\yb235
\??\yb9726
\??\yb2835
\??\yb896
\??\yb1027
\??\yb37
\??\yb8
\??\yb2479
\??\yb995
\??\yb8935
\??\yb795
\??\yb7393
\??\yb9284
\??\yb92388
\??\yb23750
\??\yb79239
\??\yb7924
\??\yb24
\??\yb973
\??\yb284
\??\yb90
C:\Users\test\AppData\Local\Temp\QQbrowserQQbrowserQQbrowser.bat
\??\PhysicalDrive0
\??\a10284132
\??\a368173
\??\a78714
\??\a24785531
\??\a994451
\??\a89534451
\??\a7954431
\??\a73964241
\??\a92648341
\??\a923843751
\??\a239744912
\??\a792038441
\??\a79233051
\??\a232401
\??\a9017215
\??\a2083114
\??\a181950
\??\a1028361
\??\a376871
\??\a7771
\??\a2478851
\??\a999441
\??\a8093441
\??\a279441
\??\a7334921
\??\a9204831
\??\a92348071
\??\a23074491
\??\a79203481
\??\a7903231
\??\a23301
\??\a972201
\??\a280113
\??\a81109
\??\b10284132
\??\b368173
\??\b78714
\??\b24785531
\??\b994451
\??\b89534451
\??\b7954431
\??\b73964241
\??\b92648341
\??\b923843751
\??\b239744912
\??\b792038441
\??\b79233051
\??\b232401
\??\b9017215
\??\b2083114
\??\b181950
\??\b1028361
\??\b376871
\??\b7771
\??\b2478851
\??\b999441
\??\b8093441
\??\b279441
\??\b7334921
\??\b9204831
\??\b92348071
\??\b23074491
\??\b79203481
\??\b7903231
\??\b23301
\??\b972201
\??\b280113
\??\b81109
\??\c10284132
\??\c368173
\??\c78714
\??\c24785531
\??\c994451
\??\c89534451
\??\c7954431
\??\c73964241
\??\c92648341
\??\c923843751
\??\c239744912
\??\c792038441
\??\c79233051
\??\c232401
\??\c9017215
\??\c2083114
\??\c181950
\??\c1028361
\??\c376871
\??\c7771
\??\c2478851
\??\c999441
\??\c8093441
\??\c279441
\??\c7334921
\??\c9204831
\??\c92348071
\??\c23074491
\??\c79203481
\??\c7903231
\??\c23301
\??\c972201
\??\c280113
\??\c81109
\??\d10284132
\??\d368173
\??\d78714
\??\d24785531
\??\d994451
\??\d89534451
\??\d7954431
\??\d73964241
\??\d92648341
\??\d923843751
\??\d239744912
\??\d792038441
\??\d79233051
\??\d232401
\??\d9017215
\??\d2083114
\??\d181950
\??\d1028361
\??\d376871
\??\d7771
\??\d2478851
\??\d999441
\??\d8093441
\??\d279441
\??\d7334921
\??\d9204831
\??\d92348071
\??\d23074491
\??\d79203481
\??\d7903231
\??\d23301
\??\d972201
\??\d280113
\??\d81109
\??\e10284132
\??\e368173
\??\e78714
\??\e24785531
\??\e994451
\??\e89534451
\??\e7954431
\??\e73964241
\??\e92648341
\??\e923843751
\??\e239744912
\??\e792038441
\??\e79233051
\??\e232401
\??\e9017215
\??\e2083114
\??\e181950
\??\e1028361
\??\e376871
\??\e7771
\??\e2478851
\??\e999441
\??\e8093441
\??\e279441
\??\e7334921
\??\e9204831
\??\e92348071
\??\e23074491
\??\e79203481
\??\e7903231
\??\e23301
\??\e972201
\??\e280113
\??\e81109
\??\f10284132
\??\f368173
\??\f78714
\??\f24785531
\??\f994451
\??\f89534451
\??\f7954431
\??\f73964241
\??\f92648341
\??\f923843751
\??\f239744912
\??\f792038441
\??\f79233051
\??\f232401
\??\f9017215
\??\f2083114
\??\f181950
\??\f1028361
\??\f376871
\??\f7771
\??\f2478851
\??\f999441
\??\f8093441
\??\f279441
\??\f7334921
\??\f9204831
\??\f92348071
\??\f23074491
\??\f79203481
\??\f7903231
\??\f23301
\??\f972201
\??\f280113
\??\f81109
\??\g10284132
\??\g368173
\??\g78714
\??\g24785531
\??\g994451
\??\g89534451
\??\g7954431
\??\g73964241
\??\g92648341
\??\g923843751
\??\g239744912
\??\g792038441
\??\g79233051
\??\g232401
\??\g9017215
\??\g2083114
\??\g181950
\??\g1028361
\??\g376871
\??\g7771
\??\g2478851
\??\g999441
\??\g8093441
\??\g279441
\??\g7334921
\??\g9204831
\??\g92348071
\??\g23074491
\??\g79203481
\??\g7903231
\??\g23301
\??\g972201
\??\g280113
\??\g81109
\??\h10284132
\??\h368173
\??\h78714
\??\h24785531
\??\h994451
\??\h89534451
\??\h7954431
\??\h73964241
\??\h92648341
\??\h923843751
\??\h239744912
\??\h792038441
\??\h79233051
\??\h232401
\??\h9017215
\??\h2083114
\??\h181950
\??\h1028361
\??\h376871
\??\h7771
\??\h2478851
\??\h999441
\??\h8093441
\??\h279441
\??\h7334921
\??\h9204831
\??\h92348071
\??\h23074491
\??\h79203481
\??\h7903231
\??\h23301
\??\h972201
\??\h280113
\??\h81109
\??\i10284132
\??\i368173
\??\i78714
\??\i24785531
\??\i994451
\??\i89534451
\??\i7954431
\??\i73964241
\??\i92648341
\??\i923843751
\??\i239744912
\??\i792038441
\??\i79233051
\??\i232401
\??\i9017215
\??\i2083114
\??\i181950
\??\i1028361
\??\i376871
\??\i7771
\??\i2478851
\??\i999441
\??\i8093441
\??\i279441
\??\i7334921
\??\i9204831
\??\i92348071
\??\i23074491
\??\i79203481
\??\i7903231
\??\i23301
\??\i972201
\??\i280113
\??\i81109
\??\j10284132
\??\j368173
\??\j78714
\??\j24785531
\??\j994451
\??\j89534451
\??\j7954431
\??\j73964241
\??\j92648341
\??\j923843751
\??\j239744912
\??\j792038441
\??\j79233051
\??\j232401
\??\j9017215
\??\j2083114
\??\j181950
\??\j1028361
\??\j376871
\??\j7771
\??\j2478851
\??\j999441
\??\j8093441
\??\j279441
\??\j7334921
\??\j9204831
\??\j92348071
\??\j23074491
\??\j79203481
\??\j7903231
\??\j23301
\??\j972201
\??\j280113
\??\j81109
\??\k10284132
\??\k368173
\??\k78714
\??\k24785531
\??\k994451
\??\k89534451
\??\k7954431
\??\k73964241
\??\k92648341
\??\k923843751
\??\k239744912
\??\k792038441
\??\k79233051
\??\k232401
\??\k9017215
\??\k2083114
\??\k181950
\??\k1028361
\??\k376871
\??\k7771
\??\k2478851
\??\k999441
\??\k8093441
\??\k279441
\??\k7334921
\??\k9204831
\??\k92348071
\??\k23074491
\??\k79203481
\??\k7903231
\??\k23301
\??\k972201
\??\k280113
\??\k81109
\??\l10284132
\??\l368173
\??\l78714
\??\l24785531
\??\l994451
\??\l89534451
\??\l7954431
\??\l73964241
\??\l92648341
\??\l923843751
\??\l239744912
\??\l792038441
\??\l79233051
\??\l232401
\??\l9017215
\??\l2083114
\??\l181950
\??\l1028361
\??\l376871
\??\l7771
\??\l2478851
\??\l999441
\??\l8093441
\??\l279441
\??\l7334921
\??\l9204831
\??\l92348071
\??\l23074491
\??\l79203481
\??\l7903231
\??\l23301
\??\l972201
\??\l280113
\??\l81109
\??\m10284132
\??\m368173
\??\m78714
\??\m24785531
\??\m994451
\??\m89534451
\??\m7954431
\??\m73964241
\??\m92648341
\??\m923843751
\??\m239744912
\??\m792038441
\??\m79233051
\??\m232401
\??\m9017215
\??\m2083114
\??\m181950
\??\m1028361
\??\m376871
\??\m7771
\??\m2478851
\??\m999441
\??\m8093441
\??\m279441
\??\m7334921
\??\m9204831
\??\m92348071
\??\m23074491
\??\m79203481
\??\m7903231
\??\m23301
\??\m972201
\??\m280113
\??\m81109
\??\n10284132
\??\n368173
\??\n78714
\??\n24785531
\??\n994451
\??\n89534451
\??\n7954431
\??\n73964241
\??\n92648341
\??\n923843751
\??\n239744912
\??\n792038441
\??\n79233051
\??\n232401
\??\n9017215
\??\n2083114
\??\n181950
\??\n1028361
\??\n376871
\??\n7771
\??\n2478851
\??\n999441
\??\n8093441
\??\n279441
\??\n7334921
\??\n9204831
\??\n92348071
\??\n23074491
\??\n79203481
\??\n7903231
\??\n23301
\??\n972201
\??\n280113
\??\n81109
\??\o10284132
\??\o368173
\??\o78714
\??\o24785531
\??\o994451
\??\o89534451
\??\o7954431
\??\o73964241
\??\o92648341
\??\o923843751
\??\o239744912
\??\o792038441
\??\o79233051
\??\o232401
\??\o9017215
\??\o2083114
\??\o181950
\??\o1028361
\??\o376871
\??\o7771
\??\o2478851
\??\o999441
\??\o8093441
\??\o279441
\??\o7334921
\??\o9204831
\??\o92348071
\??\o23074491
\??\o79203481
\??\o7903231
\??\o23301
\??\o972201
\??\o280113
\??\o81109
\??\p10284132
\??\p368173
\??\p78714
\??\p24785531
\??\p994451
\??\p89534451
\??\p7954431
\??\p73964241
\??\p92648341
\??\p923843751
\??\p239744912
\??\p792038441
\??\p79233051
\??\p232401
\??\p9017215
\??\p2083114
\??\p181950
\??\p1028361
\??\p376871
\??\p7771
\??\p2478851
\??\p999441
\??\p8093441
\??\p279441
\??\p7334921
\??\p9204831
\??\p92348071
\??\p23074491
\??\p79203481
\??\p7903231
\??\p23301
\??\p972201
\??\p280113
\??\p81109
\??\q10284132
\??\q368173
\??\q78714
\??\q24785531
\??\q994451
\??\q89534451
\??\q7954431
\??\q73964241
\??\q92648341
\??\q923843751
\??\q239744912
\??\q792038441
\??\q79233051
\??\q232401
\??\q9017215
\??\q2083114
\??\q181950
\??\q1028361
\??\q376871
\??\q7771
\??\q2478851
\??\q999441
\??\q8093441
\??\q279441
\??\q7334921
\??\q9204831
\??\q92348071
\??\q23074491
\??\q79203481
\??\q7903231
\??\q23301
\??\q972201
\??\q280113
\??\q81109
\??\r10284132
\??\r368173
\??\r78714
\??\r24785531
\??\r994451
\??\r89534451
\??\r7954431
\??\r73964241
\??\r92648341
\??\r923843751
\??\r239744912
\??\r792038441
\??\r79233051
\??\r232401
\??\r9017215
\??\r2083114
\??\r181950
\??\r1028361
\??\r376871
\??\r7771
\??\r2478851
\??\r999441
\??\r8093441
\??\r279441
\??\r7334921
\??\r9204831
\??\r92348071
\??\r23074491
\??\r79203481
\??\r7903231
\??\r23301
\??\r972201
\??\r280113
\??\r81109
\??\s10284132
\??\s368173
\??\s78714
\??\s24785531
\??\s994451
\??\s89534451
\??\s7954431
\??\s73964241
\??\s92648341
\??\s923843751
\??\s239744912
\??\s792038441
\??\s79233051
\??\s232401
\??\s9017215
\??\s2083114
\??\s181950
\??\s1028361
\??\s376871
\??\s7771
\??\s2478851
\??\s999441
\??\s8093441
\??\s279441
\??\s7334921
\??\s9204831
\??\s92348071
\??\s23074491
\??\s79203481
\??\s7903231
\??\s23301
\??\s972201
\??\s280113
\??\s81109
\??\t10284132
\??\t368173
\??\t78714
\??\t24785531
\??\t994451
\??\t89534451
\??\t7954431
\??\t73964241
\??\t92648341
\??\t923843751
\??\t239744912
\??\t792038441
\??\t79233051
\??\t232401
\??\t9017215
\??\t2083114
\??\t181950
\??\t1028361
\??\t376871
\??\t7771
\??\t2478851
\??\t999441
\??\t8093441
\??\t279441
\??\t7334921
\??\t9204831
\??\t92348071
\??\t23074491
\??\t79203481
\??\t7903231
\??\t23301
\??\t972201
\??\t280113
\??\t81109
\??\u10284132
\??\u368173
\??\u78714
\??\u24785531
\??\u994451
\??\u89534451
\??\u7954431
\??\u73964241
\??\u92648341
\??\u923843751
\??\u239744912
\??\u792038441
\??\u79233051
\??\u232401
\??\u9017215
\??\u2083114
\??\u181950
\??\u1028361
\??\u376871
\??\u7771
\??\u2478851
\??\u999441
\??\u8093441
\??\u279441
\??\u7334921
\??\u9204831
\??\u92348071
\??\u23074491
\??\u79203481
\??\u7903231
\??\u23301
\??\u972201
\??\u280113
\??\u81109
\??\v10284132
\??\v368173
\??\v78714
\??\v24785531
\??\v994451
\??\v89534451
\??\v7954431
\??\v73964241
\??\v92648341
\??\v923843751
\??\v239744912
\??\v792038441
\??\v79233051
\??\v232401
\??\v9017215
\??\v2083114
\??\v181950
\??\v1028361
\??\v376871
\??\v7771
\??\v2478851
\??\v999441
\??\v8093441
\??\v279441
\??\v7334921
\??\v9204831
\??\v92348071
\??\v23074491
\??\v79203481
\??\v7903231
\??\v23301
\??\v972201
\??\v280113
\??\v81109
\??\w10284132
\??\w368173
\??\w78714
\??\w24785531
\??\w994451
\??\w89534451
\??\w7954431
\??\w73964241
\??\w92648341
\??\w923843751
\??\w239744912
\??\w792038441
\??\w79233051
\??\w232401
\??\w9017215
\??\w2083114
\??\w181950
\??\w1028361
\??\w376871
\??\w7771
\??\w2478851
\??\w999441
\??\w8093441
\??\w279441
\??\w7334921
\??\w9204831
\??\w92348071
\??\w23074491
\??\w79203481
\??\w7903231
\??\w23301
\??\w972201
\??\w280113
\??\w81109
\??\x10284132
\??\x368173
\??\x78714
\??\x24785531
\??\x994451
\??\x89534451
\??\x7954431
\??\x73964241
\??\x92648341
\??\x923843751
\??\x239744912
\??\x792038441
\??\x79233051
\??\x232401
\??\x9017215
\??\x2083114
\??\x181950
\??\x1028361
\??\x376871
\??\x7771
\??\x2478851
\??\x999441
\??\x8093441
\??\x279441
\??\x7334921
\??\x9204831
\??\x92348071
\??\x23074491
\??\x79203481
\??\x7903231
\??\x23301
\??\x972201
\??\x280113
\??\x81109
\??\y10284132
\??\y368173
\??\y78714
\??\y24785531
\??\y994451
\??\y89534451
\??\y7954431
\??\y73964241
\??\y92648341
\??\y923843751
\??\y239744912
\??\y792038441
\??\y79233051
\??\y232401
\??\y9017215
\??\y2083114
\??\y181950
\??\y1028361
\??\y376871
\??\y7771
\??\y2478851
\??\y999441
\??\y8093441
\??\y279441
\??\y7334921
\??\y9204831
\??\y92348071
\??\y23074491
\??\y79203481
\??\y7903231
\??\y23301
\??\y972201
\??\y280113
\??\y81109
\??\z10284132
\??\z368173
\??\z78714
\??\z24785531
\??\z994451
\??\z89534451
\??\z7954431
\??\z73964241
\??\z92648341
\??\z923843751
\??\z239744912
\??\z792038441
\??\z79233051
\??\z232401
\??\z9017215
\??\z2083114
\??\z181950
\??\z1028361
\??\z376871
\??\z7771
\??\z2478851
\??\z999441
\??\z8093441
\??\z279441
\??\z7334921
\??\z9204831
\??\z92348071
\??\z23074491
\??\z79203481
\??\z7903231
\??\z23301
\??\z972201
\??\z280113
\??\z81109
C:\Users\test\AppData\Local\Temp\c1396.sys
C:\Users\test\AppData\Local\Temp\DmReg.dll
C:\Users\test\AppData\Local\Temp\c1396.sys
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\____________.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\BidInterface\Loader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_CURRENT_USER\SOFTWARE\ODBC\ODBC.INI\ODBC
HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBC.INI\ODBC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\DmReg.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DisableLocalOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\FileSystem\Win31FileSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableImprovedZoneCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\xxc.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
HKEY_CURRENT_USER\Software\Classes
HKEY_CURRENT_USER\Software\Classes\TypeLib
HKEY_CURRENT_USER\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}\1.0
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}\1.0\804
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}\1.0\4
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}\1.0\0
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}\1.0\0\win32
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}\1.0\0\win32\(Default)
HKEY_CURRENT_USER\Software\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{33E35B0A-D1F6-4AB1-A1AE-56B8A256B787}\EnableDhcp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Linkage\Bind
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Direct3D HAL\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Direct3D HAL\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Ramp Emulation\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Ramp Emulation\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\RGB Emulation\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\RGB Emulation\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\LoadDebugRuntime
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\ForceDriverFlagsOff
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\GammaCalibrator
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\SoftwareOnly
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Video\{3A7BC9EC-2E2A-4F66-906C-5C7B51408F78}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3A7BC9EC-2E2A-4F66-906C-5C7B51408F78}\0000\InstalledDisplayDrivers
HKEY_CURRENT_USER\Software\Classes\AppID\____________.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\DE32C1F6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnablePrivateObjectHeap
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\ContextLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\ObjectLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Callout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Ws2_32NumHandleBuckets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Ws2_32SpinCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\AutodialDLL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winsock\Parameters\Transports
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\Winsock\Mapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\Mapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winsock\Setup Migration\Providers\Tcpip\WinSock 2.0 Provider ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\MinSockaddrLength
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\MaxSockaddrLength
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\UseDelayedAcceptance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\HelperDllName
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\c1396
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\ImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SuperProServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\ConnectGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\MarkTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\DeleteFiles
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\2
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum\{860BB310-5D01-11D0-BD3B-00A0C911CE86}
HKEY_CLASSES_ROOT\CLSID
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{860BB310-5D01-11D0-BD3B-00A0C911CE86}\Instance
HKEY_CLASSES_ROOT\DirectShow\MediaObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\DirectShow\MediaObjects\Categories\860bb310-5d01-11d0-bd3b-00a0c911ce86
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\Host
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\DmReg.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DisableLocalOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\Com+Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\FileSystem\Win31FileSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaxSxSHashCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableImprovedZoneCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\xxc.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{1284123C-296A-62E5-DEFA-FA81B03EA9E2}\1.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{33E35B0A-D1F6-4AB1-A1AE-56B8A256B787}\EnableDhcp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Linkage\Bind
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\DX6TextureEnumInclusionList\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Direct3D HAL\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Direct3D HAL\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Ramp Emulation\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\Ramp Emulation\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\RGB Emulation\Size
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\RGB Emulation\Name
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\LoadDebugRuntime
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\ForceDriverFlagsOff
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Direct3D\Drivers\SoftwareOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3A7BC9EC-2E2A-4F66-906C-5C7B51408F78}\0000\InstalledDisplayDrivers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Log File Max Size
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\DE32C1F6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\ProcessID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnablePrivateObjectHeap
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\ContextLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\ObjectLimit
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\IdentifierLimit
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hans
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\WinSock_Registry_Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Callout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\LibraryPath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\DisplayString
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\AddressFamily
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\SupportedNameSpace
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\Version
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\StoresServiceClassInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000006\ProviderInfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Ws2_32NumHandleBuckets
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\Ws2_32SpinCount
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2\Parameters\AutodialDLL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winsock\Parameters\Transports
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\Winsock\Mapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\Mapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winsock\Setup Migration\Providers\Tcpip\WinSock 2.0 Provider ID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\MinSockaddrLength
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\MaxSockaddrLength
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\UseDelayedAcceptance
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Winsock\HelperDllName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\Parameters\RpcCacheTimeout
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\MarkTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\DeleteFiles
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\ProcessorNameString
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\Host
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\ConnectGroup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\c1396
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\c1396\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SuperProServer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\ConnectGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SuperProServer\MarkTime
kernel32.dll.IsProcessorFeaturePresent
cryptbase.dll.SystemFunction036
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
comctl32.dll.RegisterClassNameW
uxtheme.dll.EnableThemeDialogTexture
uxtheme.dll.OpenThemeData
imm32.dll.ImmIsIME
gdi32.dll.GetLayout
gdi32.dll.GdiRealizationInfo
gdi32.dll.FontIsLinked
advapi32.dll.RegOpenKeyExW
advapi32.dll.RegQueryInfoKeyW
gdi32.dll.GetTextFaceAliasW
advapi32.dll.RegEnumValueW
advapi32.dll.RegCloseKey
advapi32.dll.RegQueryValueExW
advapi32.dll.RegQueryValueExA
advapi32.dll.RegEnumKeyExW
gdi32.dll.GetTextExtentExPointWPri
comctl32.dll.InitCommonControlsEx
imm32.dll.ImmAssociateContext
uxtheme.dll.SetWindowTheme
user32.dll.SetTimer
kernel32.dll.TryEnterCriticalSection
kernel32.dll.SetCriticalSectionSpinCount
kernel32.dll.IsWow64Process
ntdll.dll.ZwOpenKey
ntdll.dll.ZwOpenKeyEx
ntdll.dll.ZwQueryKey
ntdll.dll.ZwQueryValueKey
ntdll.dll.ZwClose
dmreg.dll.SetDllPathA
ntdll.dll.ZwProtectVirtualMemory
kernel32.dll.RemoveDirectoryA
kernel32.dll.GetWindowsDirectoryA
kernel32.dll.GetCurrentDirectoryA
kernel32.dll.GetLocalTime
kernel32.dll.GetSystemTime
kernel32.dll.FileTimeToSystemTime
kernel32.dll.GetProcessTimes
kernel32.dll.GetThreadTimes
kernel32.dll.GetSystemTimeAsFileTime
kernel32.dll.GlobalReAlloc
kernel32.dll.GetHandleInformation
kernel32.dll.GetLogicalDriveStringsA
kernel32.dll.ReleaseMutex
kernel32.dll.OpenMutexA
kernel32.dll.LoadLibraryExW
kernel32.dll.GetDiskFreeSpaceExA
kernel32.dll.CreateMutexA
kernel32.dll.ExitThread
kernel32.dll.SetProcessAffinityMask
kernel32.dll.GetProcessAffinityMask
kernel32.dll.VirtualProtect
kernel32.dll.GetPrivateProfileStringA
kernel32.dll.WritePrivateProfileStringA
kernel32.dll.GetPrivateProfileSectionNamesA
kernel32.dll.GetPrivateProfileSectionA
kernel32.dll.SuspendThread
kernel32.dll.GetModuleFileNameW
kernel32.dll.lstrcmpA
kernel32.dll.EnumResourceLanguagesA
kernel32.dll.ConvertDefaultLocale
kernel32.dll.GlobalDeleteAtom
kernel32.dll.GlobalAddAtomA
kernel32.dll.FileTimeToLocalFileTime
kernel32.dll.LocalAlloc
kernel32.dll.FindClose
kernel32.dll.FindFirstFileA
kernel32.dll.GetFileTime
kernel32.dll.FindNextFileA
kernel32.dll.GetVersionExA
kernel32.dll.GetThreadLocale
kernel32.dll.TlsGetValue
kernel32.dll.GlobalHandle
kernel32.dll.TlsAlloc
kernel32.dll.TlsSetValue
kernel32.dll.LocalReAlloc
kernel32.dll.SetFileAttributesA
kernel32.dll.GlobalFlags
kernel32.dll.lstrcmpW
kernel32.dll.GlobalFindAtomA
kernel32.dll.GlobalGetAtomNameA
kernel32.dll.FreeResource
kernel32.dll.FlushFileBuffers
kernel32.dll.LockFile
kernel32.dll.UnlockFile
kernel32.dll.SetEndOfFile
kernel32.dll.DuplicateHandle
kernel32.dll.GetVolumeInformationA
kernel32.dll.GetFullPathNameA
kernel32.dll.SetErrorMode
kernel32.dll.GetCPInfo
kernel32.dll.GetOEMCP
kernel32.dll.HeapAlloc
kernel32.dll.HeapFree
kernel32.dll.RtlUnwind
kernel32.dll.HeapReAlloc
kernel32.dll.UnhandledExceptionFilter
kernel32.dll.SetUnhandledExceptionFilter
kernel32.dll.IsDebuggerPresent
kernel32.dll.GetCommandLineA
kernel32.dll.GetProcessHeap
kernel32.dll.ExitProcess
kernel32.dll.HeapSize
kernel32.dll.SetStdHandle
kernel32.dll.HeapDestroy
kernel32.dll.HeapCreate
kernel32.dll.GetStdHandle
kernel32.dll.GetACP
kernel32.dll.IsValidCodePage
kernel32.dll.LCMapStringA
kernel32.dll.LCMapStringW
kernel32.dll.SetHandleCount
kernel32.dll.GetStartupInfoA
kernel32.dll.GetStringTypeA
kernel32.dll.GetStringTypeW
kernel32.dll.GetConsoleCP
kernel32.dll.GetConsoleMode
kernel32.dll.GetTimeZoneInformation
kernel32.dll.GetUserDefaultLCID
kernel32.dll.EnumSystemLocalesA
kernel32.dll.IsValidLocale
kernel32.dll.FreeEnvironmentStringsA
kernel32.dll.GetEnvironmentStrings
kernel32.dll.FreeEnvironmentStringsW
kernel32.dll.GetEnvironmentStringsW
kernel32.dll.GetDriveTypeA
kernel32.dll.GetLocaleInfoW
kernel32.dll.WriteConsoleA
kernel32.dll.GetConsoleOutputCP
kernel32.dll.WriteConsoleW
kernel32.dll.SetEnvironmentVariableA
kernel32.dll.CreateDirectoryA
kernel32.dll.GetProcessId
kernel32.dll.VirtualFreeEx
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.GetSystemTimes
kernel32.dll.GetSystemDirectoryA
kernel32.dll.GetLocaleInfoA
kernel32.dll.SetThreadExecutionState
kernel32.dll.MoveFileA
kernel32.dll.CopyFileA
kernel32.dll.InterlockedCompareExchange
kernel32.dll.Beep
kernel32.dll.MulDiv
kernel32.dll.SetLastError
kernel32.dll.GlobalAlloc
kernel32.dll.GlobalLock
kernel32.dll.GlobalUnlock
kernel32.dll.GlobalFree
kernel32.dll.FormatMessageA
kernel32.dll.LocalFree
kernel32.dll.GetSystemInfo
kernel32.dll.IsBadReadPtr
kernel32.dll.SetProcessWorkingSetSize
kernel32.dll.LockResource
kernel32.dll.WriteFile
kernel32.dll.GetModuleHandleW
kernel32.dll.GetSystemDirectoryW
kernel32.dll.SetFilePointer
kernel32.dll.GetFileSize
kernel32.dll.VirtualProtectEx
kernel32.dll.SetThreadContext
kernel32.dll.GetThreadContext
kernel32.dll.ReadProcessMemory
kernel32.dll.VirtualQueryEx
kernel32.dll.GetCurrentThread
kernel32.dll.GetFileType
kernel32.dll.CreateFileW
kernel32.dll.DeviceIoControl
kernel32.dll.CreatePipe
kernel32.dll.CreateProcessA
kernel32.dll.ReadFile
kernel32.dll.Process32First
kernel32.dll.Process32Next
kernel32.dll.DeleteFileA
kernel32.dll.CreateFileA
kernel32.dll.GetTempPathA
kernel32.dll.GetLongPathNameA
kernel32.dll.WaitForMultipleObjects
kernel32.dll.ResumeThread
kernel32.dll.GetCurrentThreadId
kernel32.dll.TerminateProcess
kernel32.dll.QueryPerformanceFrequency
kernel32.dll.QueryPerformanceCounter
kernel32.dll.lstrcpyA
kernel32.dll.lstrcatA
kernel32.dll.CreateThread
kernel32.dll.WaitForSingleObjectEx
kernel32.dll.SetEvent
kernel32.dll.TerminateThread
kernel32.dll.CreateEventA
kernel32.dll.LoadLibraryA
kernel32.dll.CreateFileMappingA
kernel32.dll.Sleep
kernel32.dll.MapViewOfFile
kernel32.dll.VirtualAlloc
kernel32.dll.UnmapViewOfFile
kernel32.dll.VirtualFree
kernel32.dll.FlushInstructionCache
kernel32.dll.WaitForSingleObject
kernel32.dll.GetExitCodeThread
kernel32.dll.GetCurrentProcess
kernel32.dll.GetProcAddress
kernel32.dll.OpenEventA
kernel32.dll.GetModuleHandleA
kernel32.dll.LoadLibraryExA
kernel32.dll.FindResourceA
kernel32.dll.LoadResource
kernel32.dll.SizeofResource
kernel32.dll.FreeLibrary
kernel32.dll.IsDBCSLeadByte
kernel32.dll.GetModuleFileNameA
kernel32.dll.VirtualQuery
kernel32.dll.GetCurrentProcessId
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Module32First
kernel32.dll.Module32Next
kernel32.dll.CloseHandle
kernel32.dll.GetFileAttributesA
kernel32.dll.GetTickCount
kernel32.dll.InterlockedDecrement
kernel32.dll.InterlockedIncrement
kernel32.dll.DeleteCriticalSection
kernel32.dll.InitializeCriticalSection
kernel32.dll.LeaveCriticalSection
kernel32.dll.EnterCriticalSection
kernel32.dll.RaiseException
kernel32.dll.lstrlenA
kernel32.dll.lstrcmpiA
kernel32.dll.CompareStringW
kernel32.dll.CompareStringA
kernel32.dll.lstrlenW
kernel32.dll.GetVersion
kernel32.dll.GetLastError
kernel32.dll.WideCharToMultiByte
kernel32.dll.MultiByteToWideChar
kernel32.dll.TlsFree
kernel32.dll.InterlockedExchange
advapi32.dll.RegQueryValueA
advapi32.dll.RegEnumKeyA
advapi32.dll.RegEnumValueA
advapi32.dll.RegOpenKeyA
advapi32.dll.GetTokenInformation
advapi32.dll.OpenProcessToken
advapi32.dll.LookupPrivilegeValueA
advapi32.dll.AdjustTokenPrivileges
advapi32.dll.RegEnumKeyExA
advapi32.dll.RegQueryInfoKeyA
advapi32.dll.RegSetValueExA
advapi32.dll.RegOpenKeyExA
advapi32.dll.RegCreateKeyExA
advapi32.dll.RegDeleteValueA
advapi32.dll.RegDeleteKeyA
comdlg32.dll.GetFileTitleA
gdi32.dll.Escape
gdi32.dll.SetViewportOrgEx
gdi32.dll.OffsetViewportOrgEx
gdi32.dll.SetViewportExtEx
gdi32.dll.ScaleViewportExtEx
gdi32.dll.SetWindowExtEx
gdi32.dll.ScaleWindowExtEx
gdi32.dll.TextOutA
gdi32.dll.ExtSelectClipRgn
gdi32.dll.RectVisible
gdi32.dll.PtVisible
gdi32.dll.DeleteObject
gdi32.dll.SetStretchBltMode
gdi32.dll.RestoreDC
gdi32.dll.SaveDC
gdi32.dll.CreateRectRgnIndirect
gdi32.dll.ExtTextOutA
gdi32.dll.GetClipBox
gdi32.dll.CreateRoundRectRgn
gdi32.dll.CreateEllipticRgn
gdi32.dll.CreateSolidBrush
gdi32.dll.CreatePen
gdi32.dll.MoveToEx
gdi32.dll.LineTo
gdi32.dll.SetBkMode
gdi32.dll.DPtoLP
gdi32.dll.CreateBitmap
gdi32.dll.GetMapMode
gdi32.dll.SetMapMode
gdi32.dll.SetBkColor
gdi32.dll.CreateDIBSection
gdi32.dll.ExtCreateRegion
gdi32.dll.GetPixel
gdi32.dll.SetDIBits
gdi32.dll.EnumFontFamiliesExA
gdi32.dll.CreateFontIndirectA
gdi32.dll.SetTextColor
gdi32.dll.BitBlt
gdi32.dll.CreateCompatibleDC
gdi32.dll.CreateCompatibleBitmap
gdi32.dll.SelectObject
gdi32.dll.DeleteDC
gdi32.dll.GetObjectA
gdi32.dll.GetStockObject
gdi32.dll.SelectPalette
gdi32.dll.RealizePalette
gdi32.dll.GetDIBits
gdi32.dll.GetDeviceCaps
gdi32.dll.SetDIBitsToDevice
gdi32.dll.CreateRectRgn
gdi32.dll.CombineRgn
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemRealloc
ole32.dll.CoTaskMemFree
ole32.dll.CoCreateInstance
ole32.dll.StringFromGUID2
ole32.dll.CoUninitialize
ole32.dll.CoInitialize
ole32.dll.CoSetProxyBlanket
ole32.dll.CoInitializeSecurity
ole32.dll.CoRevokeClassObject
ole32.dll.OleUninitialize
ole32.dll.CoFreeUnusedLibraries
ole32.dll.OleInitialize
ole32.dll.OleIsCurrentClipboard
ole32.dll.OleFlushClipboard
ole32.dll.CoRegisterMessageFilter
oleaut32.dll.#7
oleaut32.dll.#2
oleaut32.dll.#161
oleaut32.dll.#186
oleaut32.dll.#163
oleaut32.dll.#277
oleaut32.dll.#162
oleaut32.dll.#4
oleaut32.dll.#9
oleaut32.dll.#8
oleaut32.dll.#184
oleaut32.dll.#12
oleaut32.dll.#6
oledlg.dll.#8
shlwapi.dll.PathFindExtensionA
shlwapi.dll.PathFindFileNameA
shlwapi.dll.PathStripToRootA
shlwapi.dll.PathIsUNCA
shlwapi.dll.UrlUnescapeA
user32.dll.SetActiveWindow
user32.dll.GetCapture
user32.dll.WinHelpA
user32.dll.SendDlgItemMessageA
user32.dll.LoadIconA
user32.dll.RegisterWindowMessageA
user32.dll.IsDialogMessageA
user32.dll.PostThreadMessageA
user32.dll.EndDialog
user32.dll.GetNextDlgTabItem
user32.dll.CreateDialogIndirectParamA
user32.dll.DestroyMenu
user32.dll.GetClassInfoExA
user32.dll.GetClassInfoA
user32.dll.RegisterClassA
user32.dll.GetSysColorBrush
user32.dll.GetSysColor
user32.dll.GrayStringA
user32.dll.TabbedTextOutA
user32.dll.CopyRect
user32.dll.RegisterClipboardFormatA
user32.dll.GetLastActivePopup
user32.dll.SetCursor
user32.dll.ValidateRect
user32.dll.SetMenuItemBitmaps
user32.dll.GetMenuCheckMarkDimensions
user32.dll.LoadBitmapA
user32.dll.ModifyMenuA
user32.dll.EnableMenuItem
user32.dll.CheckMenuItem
user32.dll.GetMenuState
user32.dll.GetMenuItemID
user32.dll.GetMenuItemCount
user32.dll.GetSubMenu
user32.dll.SetWindowsHookExW
user32.dll.GetMessageW
user32.dll.DestroyWindow
user32.dll.TranslateAcceleratorA
user32.dll.GetWindowThreadProcessId
user32.dll.CopyIcon
user32.dll.GetKeyState
user32.dll.GetActiveWindow
user32.dll.GetCursorPos
user32.dll.SetCursorPos
user32.dll.CallNextHookEx
user32.dll.SetWindowLongW
user32.dll.ReleaseCapture
user32.dll.DestroyCursor
user32.dll.CallWindowProcA
user32.dll.GetMessageTime
user32.dll.UnhookWindowsHookEx
user32.dll.SetWindowsHookExA
user32.dll.UnloadKeyboardLayout
user32.dll.BeginPaint
user32.dll.EndPaint
user32.dll.FillRect
user32.dll.DrawTextA
user32.dll.IsZoomed
user32.dll.GetFocus
user32.dll.GetClassNameW
user32.dll.DrawTextExA
user32.dll.SendMessageA
user32.dll.SetRect
user32.dll.SetForegroundWindow
user32.dll.AttachThreadInput
user32.dll.EnableWindow
user32.dll.SetFocus
user32.dll.GetClipboardData
user32.dll.GetDoubleClickTime
user32.dll.GetClassNameA
user32.dll.IsWindowEnabled
user32.dll.GetWindowLongW
user32.dll.SetPropA
user32.dll.ScreenToClient
user32.dll.FindWindowW
user32.dll.FindWindowExA
user32.dll.SetWindowTextW
user32.dll.GetDlgCtrlID
user32.dll.GetKeyboardLayout
user32.dll.RedrawWindow
user32.dll.RemovePropA
user32.dll.GetMenu
user32.dll.GetPropA
user32.dll.MapVirtualKeyA
user32.dll.GetMessageExtraInfo
user32.dll.SendInput
user32.dll.CharUpperA
user32.dll.CharNextA
user32.dll.MessageBoxA
user32.dll.GetDC
user32.dll.MonitorFromPoint
user32.dll.EnumWindows
user32.dll.GetWindow
user32.dll.WindowFromPoint
user32.dll.SetWindowPos
user32.dll.ShowWindow
user32.dll.MoveWindow
user32.dll.FindWindowA
user32.dll.GetWindowTextA
user32.dll.OpenClipboard
user32.dll.EmptyClipboard
user32.dll.SetClipboardData
user32.dll.CloseClipboard
user32.dll.MsgWaitForMultipleObjects
user32.dll.PeekMessageA
user32.dll.ClipCursor
user32.dll.ExitWindowsEx
user32.dll.ChangeDisplaySettingsA
user32.dll.SystemParametersInfoA
user32.dll.GetDlgItem
user32.dll.GetTopWindow
user32.dll.GetMessagePos
user32.dll.MapWindowPoints
user32.dll.GetWindowPlacement
user32.dll.CloseDesktop
user32.dll.SetThreadDesktop
user32.dll.OpenInputDesktop
user32.dll.InvalidateRect
user32.dll.SetWindowRgn
user32.dll.GetWindowRect
user32.dll.ClientToScreen
user32.dll.GetClientRect
user32.dll.GetWindowLongA
user32.dll.IsWindow
user32.dll.GetForegroundWindow
user32.dll.IsWindowVisible
user32.dll.SetWindowTextA
user32.dll.PtInRect
user32.dll.PostQuitMessage
user32.dll.SetWindowLongA
user32.dll.KillTimer
user32.dll.IsIconic
user32.dll.DefWindowProcA
user32.dll.RegisterClassExA
user32.dll.LoadCursorA
user32.dll.UnregisterClassA
user32.dll.DispatchMessageA
user32.dll.TranslateMessage
user32.dll.GetMessageA
user32.dll.UpdateWindow
user32.dll.SetClassLongA
user32.dll.GetClassLongA
user32.dll.GetClassLongW
user32.dll.IsWindowUnicode
user32.dll.CreateWindowExA
user32.dll.AdjustWindowRectEx
user32.dll.MessageBoxW
user32.dll.ReleaseDC
user32.dll.GetWindowDC
user32.dll.GetDesktopWindow
user32.dll.GetParent
user32.dll.GetAsyncKeyState
user32.dll.GetCaretPos
user32.dll.DrawTextW
user32.dll.GetSystemMetrics
user32.dll.GetIconInfo
user32.dll.DrawIcon
user32.dll.PostMessageA
wininet.dll.InternetOpenUrlA
wininet.dll.InternetReadFile
wininet.dll.InternetWriteFile
wininet.dll.InternetSetFilePointer
wininet.dll.InternetQueryOptionA
wininet.dll.InternetOpenA
wininet.dll.InternetGetLastResponseInfoA
wininet.dll.InternetCloseHandle
wininet.dll.HttpQueryInfoA
wininet.dll.InternetSetOptionExA
wininet.dll.InternetSetStatusCallback
wininet.dll.InternetCanonicalizeUrlA
wininet.dll.InternetCrackUrlA
wininet.dll.InternetQueryDataAvailable
winspool.drv.DocumentPropertiesA
winspool.drv.OpenPrinterA
winspool.drv.ClosePrinter
ws2_32.dll.#116
ws2_32.dll.#115
ws2_32.dll.#14
ws2_32.dll.#17
ws2_32.dll.#20
ws2_32.dll.#21
ws2_32.dll.#8
ws2_32.dll.#19
ws2_32.dll.#16
ws2_32.dll.#3
ws2_32.dll.#7
ws2_32.dll.#11
ws2_32.dll.#52
ws2_32.dll.#23
ws2_32.dll.#9
ws2_32.dll.#4
ws2_32.dll.#111
kernel32.dll.CreateActCtxW
kernel32.dll.ReleaseActCtx
kernel32.dll.ActivateActCtx
kernel32.dll.DeactivateActCtx
ntdll.dll.ZwAllocateVirtualMemory
sxs.dll.SxsOleAut32RedirectTypeLibrary
advapi32.dll.RegOpenKeyW
advapi32.dll.RegQueryValueW
sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid
iphlpapi.dll.GetAdaptersInfo
d3d9.dll.Direct3DCreate9
kernel32.dll.Wow64EnableWow64FsRedirection
sechost.dll.LookupAccountNameLocalW
advapi32.dll.LookupAccountSidW
sechost.dll.LookupAccountSidLocalW
kernel32.dll.GetThreadPreferredUILanguages
kernel32.dll.SetThreadPreferredUILanguages
kernel32.dll.LocaleNameToLCID
kernel32.dll.GetLocaleInfoEx
kernel32.dll.LCIDToLocaleName
kernel32.dll.GetSystemDefaultLocaleName
oleaut32.dll.#283
oleaut32.dll.#284
oleaut32.dll.#500
dnsapi.dll.DnsApiFree
advapi32.dll.RegCreateKeyA
ntdll.dll.NtLoadDriver
ntdll.dll.NtUnloadDriver
ntdll.dll.RtlAnsiStringToUnicodeString
ntdll.dll.RtlInitAnsiString
ntdll.dll.RtlFreeUnicodeString
kernel32.dll.Wow64DisableWow64FsRedirection
kernel32.dll.Wow64RevertWow64FsRedirection
ntdll.dll.RtlUnicodeStringToAnsiString
ntdll.dll._vsnwprintf
ntdll.dll.memset
ntdll.dll.RtlFreeAnsiString
ntdll.dll.RtlFreeHeap
ntdll.dll.RtlDeleteCriticalSection
ntdll.dll.RtlInitializeCriticalSection
ntdll.dll.RtlAllocateHeap
ntdll.dll.CsrVerifyRegion
ntdll.dll.RtlGetNativeSystemInformation
ntdll.dll.NtQuerySystemInformation
ntdll.dll.RtlCreateTagHeap
ntdll.dll.NtQueryInformationProcess
ntdll.dll.NtSetInformationProcess
ntdll.dll.NtClose
ntdll.dll.NtSetInformationFile
ntdll.dll.NtCreateIoCompletion
ntdll.dll.NtSetIoCompletion
ntdll.dll.RtlSetLastWin32Error
ntdll.dll.SbSelectProcedure
ntdll.dll.NtRemoveIoCompletion
ntdll.dll.RtlDeactivateActivationContextUnsafeFast
ntdll.dll.NtRemoveIoCompletionEx
ntdll.dll.RtlActivateActivationContextUnsafeFast
ntdll.dll.NtCreateNamedPipeFile
ntdll.dll.NtOpenFile
ntdll.dll.NtWaitForSingleObject
ntdll.dll.NtFsControlFile
ntdll.dll.NtCreateEvent
ntdll.dll.NtQueryInformationFile
ntdll.dll._allmul
ntdll.dll.RtlSetDaclSecurityDescriptor
ntdll.dll.RtlCreateSecurityDescriptor
ntdll.dll.RtlDefaultNpAcl
ntdll.dll.RtlDosPathNameToNtPathName_U
ntdll.dll.RtlAppendUnicodeStringToString
ntdll.dll._wcsnicmp
ntdll.dll.RtlPrefixString
ntdll.dll.RtlInitUnicodeString
ntdll.dll.RtlDetermineDosPathNameType_U
ntdll.dll.RtlCreateUnicodeString
ntdll.dll.memcpy
ntdll.dll.NtDeviceIoControlFile
ntdll.dll.NtCreateFile
ntdll.dll.RtlTimeToTimeFields
ntdll.dll.RtlTimeFieldsToTime
ntdll.dll.RtlAcquirePrivilege
ntdll.dll.RtlInitializeSRWLock
ntdll.dll.RtlReleaseSRWLockExclusive
ntdll.dll.RtlAcquireSRWLockExclusive
ntdll.dll.RtlCutoverTimeToSystemTime
ntdll.dll.RtlReleaseSRWLockShared
ntdll.dll.RtlAcquireSRWLockShared
ntdll.dll.RtlReleasePrivilege
ntdll.dll.NtSetSystemTime
ntdll.dll.RtlUnicodeStringToInteger
ntdll.dll.wcschr
ntdll.dll.wcscpy_s
ntdll.dll.RtlpCheckDynamicTimeZoneInformation
ntdll.dll._stricmp
ntdll.dll._wcsicmp
ntdll.dll.RtlDeregisterWaitEx
ntdll.dll.RtlCreateTimerQueue
ntdll.dll.NtDelayExecution
ntdll.dll.RtlCreateTimer
ntdll.dll.RtlUpdateTimer
ntdll.dll.RtlDeleteTimer
ntdll.dll.RtlDeleteTimerQueueEx
ntdll.dll.RtlRegisterWait
ntdll.dll.wcsrchr
ntdll.dll.NtQueryValueKey
ntdll.dll.NtOpenKey
ntdll.dll.RtlxAnsiStringToUnicodeSize
ntdll.dll.NlsMbCodePageTag
ntdll.dll.RtlxOemStringToUnicodeSize
ntdll.dll.NlsMbOemCodePageTag
ntdll.dll.RtlxUnicodeStringToOemSize
ntdll.dll.RtlxUnicodeStringToAnsiSize
ntdll.dll.LdrEnumerateLoadedModules
ntdll.dll.NtAllocateVirtualMemory
ntdll.dll._alloca_probe
ntdll.dll.RtlReleasePebLock
ntdll.dll.RtlQueryEnvironmentVariable
ntdll.dll.RtlAcquirePebLock
ntdll.dll.RtlLeaveCriticalSection
ntdll.dll.RtlEnterCriticalSection
ntdll.dll.wcsncmp
ntdll.dll.RtlUnicodeStringToOemString
ntdll.dll.RtlOemStringToUnicodeString
ntdll.dll.RtlRaiseException
ntdll.dll.NtDuplicateObject
ntdll.dll.NtQueryObject
ntdll.dll.NtSetInformationObject
ntdll.dll.NtQueryVolumeInformationFile
ntdll.dll.NtLockFile
ntdll.dll.NtUnlockFile
ntdll.dll.RtlNtStatusToDosError
ntdll.dll.NtReadFile
ntdll.dll.NtWriteFile
ntdll.dll.NtCancelIoFileEx
ntdll.dll.NtReadFileScatter
ntdll.dll.NtWriteFileGather
ntdll.dll.RtlWow64EnableFsRedirectionEx
ntdll.dll.memmove
ntdll.dll.NtFlushBuffersFile
ntdll.dll.NtCreateSection
ntdll.dll.NtOpenSection
ntdll.dll.NtMapViewOfSection
ntdll.dll.NtFlushVirtualMemory
ntdll.dll.RtlFlushSecureMemoryCache
ntdll.dll.NtUnmapViewOfSection
ntdll.dll.NtReadVirtualMemory
ntdll.dll.NtFlushInstructionCache
ntdll.dll.NtWriteVirtualMemory
ntdll.dll.NtProtectVirtualMemory
ntdll.dll.NtFreeVirtualMemory
ntdll.dll.NtQueryVirtualMemory
ntdll.dll.NtQuerySystemInformationEx
ntdll.dll.RtlGetCurrentProcessorNumberEx
ntdll.dll.NtOpenProcess
ntdll.dll.RtlExitUserProcess
ntdll.dll.NtTerminateProcess
ntdll.dll.RtlReportSilentProcessExit
ntdll.dll.NtRaiseHardError
ntdll.dll.RtlRaiseStatus
ntdll.dll.RtlInitUnicodeStringEx
ntdll.dll.RtlQueryEnvironmentVariable_U
ntdll.dll.strchr
ntdll.dll.RtlInitAnsiStringEx
ntdll.dll.RtlUpcaseUnicodeChar
ntdll.dll.RtlEqualUnicodeString
ntdll.dll.RtlCompareMemory
ntdll.dll.NtQueryDirectoryObject
ntdll.dll.NtQuerySymbolicLinkObject
ntdll.dll.NtOpenSymbolicLinkObject
ntdll.dll.NtOpenDirectoryObject
ntdll.dll.RtlSetEnvironmentStrings
ntdll.dll.RtlSetEnvironmentVariable
ntdll.dll.RtlSetEnvironmentVar
ntdll.dll.RtlExpandEnvironmentStrings
ntdll.dll.RtlUnicodeToOemN
ntdll.dll.RtlUnicodeToMultiByteSize
ntdll.dll.RtlExpandEnvironmentStrings_U
ntdll.dll.RtlInitializeCriticalSectionAndSpinCount
ntdll.dll.RtlInitializeCriticalSectionEx
ntdll.dll.NtSetEvent
ntdll.dll.NtClearEvent
ntdll.dll.NtPulseEvent
ntdll.dll.NtCreateSemaphore
ntdll.dll.NtReleaseSemaphore
ntdll.dll.NtCreateMutant
ntdll.dll.NtReleaseMutant
ntdll.dll.NtCreateTimer
ntdll.dll.NtSetTimerEx
ntdll.dll.NtCancelTimer
ntdll.dll.NtOpenEvent
ntdll.dll.NtOpenSemaphore
ntdll.dll.NtOpenMutant
ntdll.dll.NtWaitForMultipleObjects
ntdll.dll.NtOpenTimer
ntdll.dll.RtlExitUserThread
ntdll.dll.LdrUnloadAlternateResourceModule
ntdll.dll.LdrRemoveLoadAsDataTable
ntdll.dll.RtlImageNtHeader
ntdll.dll.LdrUnloadDll
ntdll.dll.LdrDisableThreadCalloutsForDll
ntdll.dll.LdrUnlockLoaderLock
ntdll.dll.LdrLockLoaderLock
ntdll.dll.LdrGetDllHandle
ntdll.dll.LdrAddRefDll
ntdll.dll.RtlComputePrivatizedDllName_U
ntdll.dll.RtlPcToFileHeader
ntdll.dll.LdrGetProcedureAddress
ntdll.dll.RtlInitString
ntdll.dll.RtlGetVersion
ntdll.dll.LdrAccessResource
ntdll.dll.RtlReAllocateHeap
ntdll.dll.LdrAddLoadAsDataTable
ntdll.dll.RtlGetActiveActivationContext
ntdll.dll.LdrWx86FormatVirtualImage
ntdll.dll.NtQuerySection
ntdll.dll.LdrGetDllHandleByMapping
ntdll.dll.RtlImageNtHeaderEx
ntdll.dll.RtlDosSearchPath_Ustr
ntdll.dll.LdrGetDllHandleByName
ntdll.dll.RtlDosApplyFileIsolationRedirection_Ustr
ntdll.dll.LdrLoadDll
ntdll.dll.LdrFindResource_U
ntdll.dll.RtlFreeSid
ntdll.dll.RtlSetSaclSecurityDescriptor
ntdll.dll.RtlAddMandatoryAce
ntdll.dll.RtlAddAccessAllowedAce
ntdll.dll.RtlCreateAcl
ntdll.dll.RtlLengthSid
ntdll.dll.RtlAllocateAndInitializeSid
ntdll.dll.DbgPrint
ntdll.dll.NtOpenThread
ntdll.dll.NtSetInformationThread
ntdll.dll.NtQueryInformationThread
ntdll.dll.NtTerminateThread
ntdll.dll.TpCheckTerminateWorker
ntdll.dll.RtlCaptureStackBackTrace
ntdll.dll.NtSuspendThread
ntdll.dll.NtResumeThread
ntdll.dll.RtlClearBits
ntdll.dll.RtlAreBitsSet
ntdll.dll.NtQueueApcThread
ntdll.dll.#8
ntdll.dll.RtlQueryInformationActivationContext
ntdll.dll.RtlFlsAlloc
ntdll.dll.RtlProcessFlsData
ntdll.dll.RtlFlsFree
ntdll.dll.NtYieldExecution
ntdll.dll.RtlFreeActivationContextStack
ntdll.dll.RtlReleaseActivationContext
ntdll.dll.RtlActivateActivationContextEx
ntdll.dll.RtlAllocateActivationContextStack
ntdll.dll.NtCreateThreadEx
ntdll.dll.TpCaptureCaller
ntdll.dll.RtlFindClearBitsAndSet
ntdll.dll.RtlFormatMessageEx
ntdll.dll.RtlFindMessage
ntdll.dll.RtlLoadString
ntdll.dll.RtlUnicodeToMultiByteN
ntdll.dll.RtlUnlockHeap
ntdll.dll.RtlFreeHandle
ntdll.dll.RtlIsValidHandle
ntdll.dll.RtlLockHeap
ntdll.dll.RtlSetUserValueHeap
ntdll.dll.RtlAllocateHandle
ntdll.dll._aulldiv
ntdll.dll.RtlCreateHeap
ntdll.dll.RtlDestroyHeap
ntdll.dll.RtlQueryHeapInformation
ntdll.dll.RtlValidateHeap
ntdll.dll.RtlGetProcessHeaps
ntdll.dll.RtlCompactHeap
ntdll.dll.RtlWalkHeap
ntdll.dll.RtlSetHeapInformation
ntdll.dll.RtlInitializeHandleTable
ntdll.dll.RtlIsDosDeviceName_U
ntdll.dll.RtlAnsiCharToUnicodeChar
ntdll.dll.RtlIntegerToChar
ntdll.dll.wcsncpy_s
ntdll.dll.RtlGetCurrentDirectory_U
ntdll.dll.RtlSetThreadErrorMode
ntdll.dll.toupper
ntdll.dll.RtlReleaseRelativeName
ntdll.dll.RtlDosPathNameToRelativeNtPathName_U
ntdll.dll.RtlDosPathNameToRelativeNtPathName_U_WithStatus
ntdll.dll.NtQueryAttributesFile
ntdll.dll.RtlDosPathNameToNtPathName_U_WithStatus
ntdll.dll.NtQueryFullAttributesFile
ntdll.dll.NtNotifyChangeDirectoryFile
ntdll.dll.NtQueryDirectoryFile
ntdll.dll.RtlGetFullPathName_UEx
ntdll.dll.RtlSetCurrentDirectory_U
ntdll.dll.#1
ntdll.dll.NtQueryEaFile
ntdll.dll.NtIsProcessInJob
ntdll.dll.NtDuplicateToken
ntdll.dll.NtAllocateLocallyUniqueId
ntdll.dll.NtAccessCheck
ntdll.dll.NtAccessCheckByType
ntdll.dll.NtAccessCheckByTypeResultList
ntdll.dll.NtOpenProcessToken
ntdll.dll.NtOpenThreadToken
ntdll.dll.NtQueryInformationToken
ntdll.dll.NtSetInformationToken
ntdll.dll.NtAdjustPrivilegesToken
ntdll.dll.NtAdjustGroupsToken
ntdll.dll.NtPrivilegeCheck
ntdll.dll.NtAccessCheckAndAuditAlarm
ntdll.dll.NtAccessCheckByTypeAndAuditAlarm
ntdll.dll.NtAccessCheckByTypeResultListAndAuditAlarm
ntdll.dll.NtAccessCheckByTypeResultListAndAuditAlarmByHandle
ntdll.dll.NtOpenObjectAuditAlarm
ntdll.dll.NtPrivilegeObjectAuditAlarm
ntdll.dll.NtCloseObjectAuditAlarm
ntdll.dll.NtDeleteObjectAuditAlarm
ntdll.dll.NtPrivilegedServiceAuditAlarm
ntdll.dll.RtlValidSid
ntdll.dll.RtlEqualSid
ntdll.dll.RtlEqualPrefixSid
ntdll.dll.RtlLengthRequiredSid
ntdll.dll.RtlInitializeSid
ntdll.dll.RtlIdentifierAuthoritySid
ntdll.dll.RtlSubAuthoritySid
ntdll.dll.RtlSubAuthorityCountSid
ntdll.dll.RtlCopySid
ntdll.dll.RtlAreAllAccessesGranted
ntdll.dll.RtlAreAnyAccessesGranted
ntdll.dll.RtlMapGenericMask
ntdll.dll.RtlValidAcl
ntdll.dll.RtlQueryInformationAcl
ntdll.dll.RtlSetInformationAcl
ntdll.dll.RtlAddAce
ntdll.dll.RtlDeleteAce
ntdll.dll.RtlGetAce
ntdll.dll.RtlAddAccessAllowedAceEx
ntdll.dll.RtlAddAccessDeniedAce
ntdll.dll.RtlAddAccessDeniedAceEx
ntdll.dll.RtlAddAuditAccessAce
ntdll.dll.RtlAddAuditAccessAceEx
ntdll.dll.RtlAddAccessAllowedObjectAce
ntdll.dll.RtlAddAccessDeniedObjectAce
ntdll.dll.RtlAddAuditAccessObjectAce
ntdll.dll.RtlFirstFreeAce
ntdll.dll.RtlValidSecurityDescriptor
ntdll.dll.RtlValidRelativeSecurityDescriptor
ntdll.dll.RtlLengthSecurityDescriptor
ntdll.dll.RtlGetControlSecurityDescriptor
ntdll.dll.RtlSetControlSecurityDescriptor
ntdll.dll.RtlGetDaclSecurityDescriptor
ntdll.dll.RtlGetSaclSecurityDescriptor
ntdll.dll.RtlSetOwnerSecurityDescriptor
ntdll.dll.RtlGetOwnerSecurityDescriptor
ntdll.dll.RtlSetGroupSecurityDescriptor
ntdll.dll.RtlGetGroupSecurityDescriptor
ntdll.dll.RtlNewSecurityObject
ntdll.dll.RtlConvertToAutoInheritSecurityObject
ntdll.dll.RtlNewSecurityObjectEx
ntdll.dll.RtlNewSecurityObjectWithMultipleInheritance
ntdll.dll.RtlSetSecurityObject
ntdll.dll.RtlSetSecurityObjectEx
ntdll.dll.RtlQuerySecurityObject
ntdll.dll.RtlDeleteSecurityObject
ntdll.dll.RtlAbsoluteToSelfRelativeSD
ntdll.dll.RtlSelfRelativeToAbsoluteSD
ntdll.dll.NtSetSecurityObject
ntdll.dll.NtQuerySecurityObject
ntdll.dll.RtlImpersonateSelf
ntdll.dll.NtImpersonateAnonymousToken
ntdll.dll.NtFilterToken
ntdll.dll.RtlSelfRelativeToAbsoluteSD2
ntdll.dll.RtlGetSecurityDescriptorRMControl
ntdll.dll.RtlSetSecurityDescriptorRMControl
ntdll.dll.CsrClientConnectToServer
ntdll.dll.RtlUnhandledExceptionFilter
ntdll.dll.RtlGetLocaleFileMappingAddress
ntdll.dll.NtGetNlsSectionPtr
ntdll.dll.RtlNormalizeString
ntdll.dll.wcspbrk
ntdll.dll.RtlLcidToLocaleName
ntdll.dll.EtwEventUnregister
ntdll.dll.EtwEventEnabled
ntdll.dll.EtwEventRegister
ntdll.dll.NtSetDefaultLocale
ntdll.dll.RtlLocaleNameToLcid
ntdll.dll.NtEnumerateValueKey
ntdll.dll.RtlpMuiFreeLangRegistryInfo
ntdll.dll.RtlCultureNameToLCID
ntdll.dll.qsort
ntdll.dll.RtlpIsQualifiedLanguage
ntdll.dll.RtlpGetLCIDFromLangInfoNode
ntdll.dll.RtlpGetNameFromLangInfoNode
ntdll.dll.NtQueryInstallUILanguage
ntdll.dll.RtlLCIDToCultureName
ntdll.dll.RtlpLoadUserUIByPolicy
ntdll.dll.RtlpLoadMachineUIByPolicy
ntdll.dll.RtlpCreateProcessRegistryInfo
ntdll.dll.RtlpInitializeLangRegistryInfo
ntdll.dll.LdrFindResourceEx_U
ntdll.dll.RtlGetFileMUIPath
ntdll.dll.RtlGetUILanguageInfo
ntdll.dll.RtlpGetSystemDefaultUILanguage
ntdll.dll.RtlGetThreadPreferredUILanguages
ntdll.dll.RtlGetProcessPreferredUILanguages
ntdll.dll.RtlpQueryDefaultUILanguage
ntdll.dll.RtlGetSystemPreferredUILanguages
ntdll.dll.RtlGetUserPreferredUILanguages
ntdll.dll.NtCreateKey
ntdll.dll.NtSetValueKey
ntdll.dll.NtDeleteKey
ntdll.dll.NtEnumerateKey
ntdll.dll.RtlIntegerToUnicodeString
ntdll.dll.RtlAppendUnicodeToString
ntdll.dll.RtlCopyUnicodeString
ntdll.dll.EtwEventWrite
ntdll.dll.RtlOpenCurrentUser
ntdll.dll.NtQueryDefaultLocale
ntdll.dll.NtNotifyChangeKey
ntdll.dll.swprintf_s
ntdll.dll.RtlUTF8ToUnicodeN
ntdll.dll.RtlUnicodeToUTF8N
ntdll.dll.NtDeleteValueKey
ntdll.dll.RtlUnwind
ntdll.dll.DbgPrintEx
ntdll.dll.RtlSetLastWin32ErrorAndNtStatusFromNtStatus
ntdll.dll.TpAllocPool
ntdll.dll.TpSetPoolMinThreads
ntdll.dll.TpSetPoolStackInformation
ntdll.dll.TpQueryPoolStackInformation
ntdll.dll.TpAllocCleanupGroup
ntdll.dll.TpSimpleTryPost
ntdll.dll.TpAllocWork
ntdll.dll.TpAllocTimer
ntdll.dll.TpAllocWait
ntdll.dll.TpAllocIoCompletion
ntdll.dll.TpCallbackMayRunLong
ntdll.dll.NtQueryMultipleValueKey
ntdll.dll.RtlCaptureContext
ntdll.dll.RtlConvertSidToUnicodeString
ntdll.dll.RtlRunOnceInitialize
ntdll.dll.NtResetEvent
ntdll.dll.strncat
ntdll.dll._strlwr
ntdll.dll.RtlpConvertCultureNamesToLCIDs
ntdll.dll.RtlpConvertLCIDsToCultureNames
ntdll.dll.RtlSetProcessPreferredUILanguages
ntdll.dll.RtlIdnToUnicode
ntdll.dll.RtlIdnToNameprepUnicode
ntdll.dll.RtlIdnToAscii
ntdll.dll.RtlIsNormalizedString
ntdll.dll._ui64tow
ntdll.dll._wtol
ntdll.dll._wcslwr
ntdll.dll.wcsncpy
ntdll.dll.RtlReadThreadProfilingData
ntdll.dll.RtlQueryThreadProfiling
ntdll.dll.RtlDisableThreadProfiling
ntdll.dll.RtlEnableThreadProfiling
ntdll.dll.RtlSetExtendedFeaturesMask
ntdll.dll.RtlGetExtendedFeaturesMask
ntdll.dll.RtlLocateExtendedFeature
ntdll.dll.RtlCopyContext
ntdll.dll.RtlGetEnabledExtendedFeatures
ntdll.dll.RtlGetExtendedContextLength
ntdll.dll.RtlInitializeExtendedContext
ntdll.dll.RtlLocateLegacyContext
ntdll.dll.NtRaiseException
ntdll.dll.EtwEventWriteNoRegistration
ntdll.dll.RtlSetIoCompletionCallback
ntdll.dll.RtlQueueWorkItem
ntdll.dll.RtlDeregisterWait
ntdll.dll.NtResetWriteWatch
ntdll.dll.NtGetWriteWatch
ntdll.dll.NtMapUserPhysicalPagesScatter
ntdll.dll.NtMapUserPhysicalPages
ntdll.dll.NtFreeUserPhysicalPages
ntdll.dll.NtAllocateUserPhysicalPages
ntdll.dll.NtUnlockVirtualMemory
ntdll.dll.NtLockVirtualMemory
ntdll.dll.RtlComputeImportTableHash
ntdll.dll.bsearch
ntdll.dll.RtlEncodeSystemPointer
ntdll.dll.RtlFindCharInUnicodeString
ntdll.dll.RtlNtPathNameToDosPathName
ntdll.dll.NtApphelpCacheControl
ntdll.dll.RtlRandom
ntdll.dll.RtlFindActivationContextSectionGuid
ntdll.dll.RtlFindActivationContextSectionString
ntdll.dll.RtlDoesFileExists_U
ntdll.dll.RtlCreateActivationContext
ntdll.dll.RtlSetThreadPreferredUILanguages
ntdll.dll.RtlQueryActivationContextApplicationSettings
ntdll.dll.RtlMultiAppendUnicodeStringBuffer
ntdll.dll.RtlpEnsureBufferSize
ntdll.dll.RtlGetLengthWithoutLastFullDosOrNtPathElement
ntdll.dll.RtlpApplyLengthFunction
ntdll.dll.RtlDeactivateActivationContext
ntdll.dll.RtlActivateActivationContext
ntdll.dll.RtlZombifyActivationContext
ntdll.dll.RtlAddRefActivationContext
ntdll.dll.NtSetInformationJobObject
ntdll.dll.NtCreateJobSet
ntdll.dll.NtQueryInformationJobObject
ntdll.dll.NtTerminateJobObject
ntdll.dll.NtAssignProcessToJobObject
ntdll.dll.NtOpenJobObject
ntdll.dll.NtCreateJobObject
ntdll.dll.tolower
ntdll.dll.atol
ntdll.dll.isdigit
ntdll.dll.RtlCopyLuid
ntdll.dll.RtlFreeOemString
ntdll.dll.RtlCreateEnvironment
ntdll.dll.RtlCreateEnvironmentEx
ntdll.dll.RtlDestroyEnvironment
ntdll.dll.NtQueryEvent
ntdll.dll.CsrClientCallServer
ntdll.dll.CsrAllocateCaptureBuffer
ntdll.dll.CsrAllocateMessagePointer
ntdll.dll.CsrFreeCaptureBuffer
ntdll.dll.RtlCreateQueryDebugBuffer
ntdll.dll.RtlQueryProcessDebugInformation
ntdll.dll.RtlDestroyQueryDebugBuffer
ntdll.dll.RtlFreeUserStack
ntdll.dll.RtlCreateUserStack
ntdll.dll.NtSetContextThread
ntdll.dll.NtGetContextThread
ntdll.dll.NtSignalAndWaitForSingleObject
ntdll.dll.RtlRunOnceComplete
ntdll.dll.RtlRunOnceBeginInitialize
ntdll.dll.RtlRunOnceExecuteOnce
ntdll.dll.RtlSleepConditionVariableSRW
ntdll.dll.RtlSleepConditionVariableCS
ntdll.dll.NtOpenPrivateNamespace
ntdll.dll.NtCreatePrivateNamespace
ntdll.dll.NtDeletePrivateNamespace
ntdll.dll.RtlAddIntegrityLabelToBoundaryDescriptor
ntdll.dll.RtlAddSIDToBoundaryDescriptor
ntdll.dll.RtlCreateBoundaryDescriptor
ntdll.dll.strcpy_s
ntdll.dll.NtReplacePartitionUnit
ntdll.dll.RtlCompareUnicodeString
ntdll.dll.RtlQueryRegistryValues
ntdll.dll.RtlDecodeSystemPointer
ntdll.dll.RtlWow64LogMessageInEventLogger
ntdll.dll.NtIsSystemResumeAutomatic
ntdll.dll.NtGetDevicePowerState
ntdll.dll.NtSetThreadExecutionState
ntdll.dll.NtInitiatePowerAction
ntdll.dll.NtPowerInformation
ntdll.dll.NtSetVolumeInformationFile
ntdll.dll.RtlGetFullPathName_U
ntdll.dll.RtlIsNameLegalDOS8Dot3
ntdll.dll._allshl
ntdll.dll.LdrLoadAlternateResourceModuleEx
ntdll.dll.LdrLoadAlternateResourceModule
ntdll.dll.LdrpResGetMappingSize
ntdll.dll.LdrRscIsTypeExist
ntdll.dll._strcmpi
ntdll.dll.strncat_s
ntdll.dll.wcstoul
ntdll.dll.LdrGetFileNameFromLoadAsDataTable
ntdll.dll.LdrResFindResourceDirectory
ntdll.dll.LdrResFindResource
ntdll.dll.LdrpResGetResourceDirectory
ntdll.dll.RtlImageDirectoryEntryToData
ntdll.dll.LdrResGetRCConfig
ntdll.dll.RtlVerifyVersionInfo
ntdll.dll.RtlGetProductInfo
ntdll.dll.NtCreateMailslotFile
ntdll.dll.RtlExtendedLargeIntegerDivide
ntdll.dll.RtlCleanUpTEBLangLists
ntdll.dll.RtlSetThreadPoolStartFunc
ntdll.dll.LdrSetDllManifestProber
ntdll.dll.RtlSetUserCallbackExceptionFilter
ntdll.dll.RtlSetUnhandledExceptionFilter
ntdll.dll.RtlEncodePointer
ntdll.dll.LdrQueryImageFileExecutionOptions
ntdll.dll.RtlDeregisterSecureMemoryCacheCallback
ntdll.dll.RtlRegisterSecureMemoryCacheCallback
ntdll.dll.RtlSizeHeap
ntdll.dll.RtlGetUserInfoHeap
ntdll.dll.NtSetSystemEnvironmentValueEx
ntdll.dll.RtlGUIDFromString
ntdll.dll.NtQuerySystemEnvironmentValueEx
ntdll.dll._alldiv
ntdll.dll.RtlGetLastNtStatus
ntdll.dll.NtCreateKeyTransacted
ntdll.dll.RtlWow64EnableFsRedirection
ntdll.dll.NtCancelIoFile
ntdll.dll.NtCancelSynchronousIoFile
ntdll.dll.RtlGetThreadErrorMode
ntdll.dll.RtlNtStatusToDosErrorNoTeb
ntdll.dll.RtlQueryElevationFlags
ntdll.dll.RtlCharToInteger
ntdll.dll.strncpy_s
ntdll.dll.RtlGetLongestNtPathLength
ntdll.dll.RtlEqualString
ntdll.dll.RtlIsTextUnicode
ntdll.dll.RtlFormatCurrentUserKeyPath
ntdll.dll.RtlPrefixUnicodeString
ntdll.dll.RtlMultiByteToUnicodeSize
ntdll.dll.RtlMultiByteToUnicodeN
ntdll.dll.RtlQueryAtomInAtomTable
ntdll.dll.NtQueryInformationAtom
ntdll.dll.RtlDeleteAtomFromAtomTable
ntdll.dll.NtDeleteAtom
ntdll.dll.RtlLookupAtomInAtomTable
ntdll.dll.NtFindAtom
ntdll.dll.RtlAddAtomToAtomTable
ntdll.dll.NtAddAtom
ntdll.dll.RtlCreateAtomTable
ntdll.dll.RtlDestroyAtomTable
ntdll.dll.DbgUiStopDebugging
ntdll.dll.DbgUiContinue
ntdll.dll.DbgUiWaitStateChange
ntdll.dll.DbgUiConvertStateChangeStructure
ntdll.dll.DbgUiGetThreadDebugObject
ntdll.dll.NtSetInformationDebugObject
ntdll.dll.DbgUiIssueRemoteBreakin
ntdll.dll.DbgUiConnectToDbg
ntdll.dll.DbgUiDebugActiveProcess
ntdll.dll.CsrGetProcessId
ntdll.dll.NtSetSystemInformation
ntdll.dll.RtlGetCurrentTransaction
ntdll.dll.RtlSetCurrentTransaction
ntdll.dll.wcscat_s
ntdll.dll.wcsstr
ntdll.dll.RtlCreateUnicodeStringFromAsciiz
ntdll.dll.RtlDnsHostNameToComputerName
ntdll.dll.wcscspn
ntdll.dll._memicmp
ntdll.dll.NtFlushKey
ntdll.dll.NtSetEaFile
ntdll.dll.RtlInitializeExceptionChain
ntdll.dll.NtWow64WriteVirtualMemory64
ntdll.dll.RtlDestroyProcessParameters
ntdll.dll.RtlCreateProcessParametersEx
ntdll.dll.NtRemoveProcessDebug
ntdll.dll.LdrQueryImageFileKeyOption
ntdll.dll.NtCreateUserProcess
ntdll.dll.RtlGetFullPathName_UstrEx
ntdll.dll.RtlDecodePointer
ntdll.dll.RtlKnownExceptionFilter
ntdll.dll.NtRequestWaitReplyPort
ntdll.dll.NtOpenKeyTransacted
ntdll.dll.NtQueryKey
ntdll.dll.NtOpenKeyEx
ntdll.dll.NtOpenKeyTransactedEx
ntdll.dll.NtLoadKey
ntdll.dll.NtUnloadKey
ntdll.dll.NtNotifyChangeMultipleKeys
ntdll.dll.NtRestoreKey
ntdll.dll.NtSaveKeyEx
ntdll.dll.RtlMakeSelfRelativeSD
ntdll.dll._strnicmp
ntdll.dll.strncmp
ntdll.dll.RtlTryAcquirePebLock
ntdll.dll._vsnprintf
ntdll.dll.RtlWerpReportException
ntdll.dll.LdrResSearchResource
ntdll.dll.NtWow64ReadVirtualMemory64
ntdll.dll.NtWow64QueryInformationProcess64
ntdll.dll.WerReportSQMEvent
ntdll.dll.VerSetConditionMask
ntdll.dll.WinSqmIsOptedIn
ntdll.dll.strcat_s
ntdll.dll._aullrem
kernelbase.dll.BaseReleaseProcessDllPath
kernelbase.dll.BaseGetProcessExePath
kernelbase.dll.BaseGetProcessDllPath
kernelbase.dll.LoadStringByReference
kernelbase.dll.InternalLcidToName
kernelbase.dll.NlsIsUserDefaultLocale
kernelbase.dll.GetUserInfo
kernelbase.dll.GetPtrCalDataArray
kernelbase.dll.GetPtrCalData
kernelbase.dll.GetStringTableEntry
kernelbase.dll.CheckGroupPolicyEnabled
kernelbase.dll.OpenRegKey
kernelbase.dll.GetCPHashNode
kernelbase.dll.Internal_EnumSystemCodePages
kernelbase.dll.Internal_EnumUILanguages
kernelbase.dll.Internal_EnumLanguageGroupLocales
kernelbase.dll.Internal_EnumSystemLanguageGroups
kernelbase.dll.Internal_EnumDateFormats
kernelbase.dll.Internal_EnumTimeFormats
kernelbase.dll.KernelBaseGetGlobalData
kernelbase.dll.InvalidateTzSpecificCache
kernelbase.dll.IsDBCSLeadByte
kernelbase.dll.CreateFileMappingNumaW
kernelbase.dll.CompareStringA
kernelbase.dll.LoadStringBaseExW
kernelbase.dll.BaseInvalidateDllSearchPathCache
kernelbase.dll.BaseInvalidateProcessSearchPathCache
kernelbase.dll.BaseDllFreeResourceId
kernelbase.dll.BaseDllMapResourceIdW
kernelbase.dll.GetUserDefaultUILanguage
kernelbase.dll.EnumUILanguagesW
kernelbase.dll.AreFileApisANSI
kernelbase.dll.EnumCalendarInfoExW
kernelbase.dll.EnumCalendarInfoW
kernelbase.dll.EnumDateFormatsExW
kernelbase.dll.EnumDateFormatsW
kernelbase.dll.EnumLanguageGroupLocalesW
kernelbase.dll.EnumSystemCodePagesW
kernelbase.dll.EnumSystemLanguageGroupsW
kernelbase.dll.EnumSystemLocalesEx
kernelbase.dll.EnumSystemLocalesW
kernelbase.dll.EnumTimeFormatsW
kernelbase.dll.GetLocaleInfoA
kernelbase.dll.GetStringTypeA
kernelbase.dll.GetSystemDefaultUILanguage
kernelbase.dll.IsDBCSLeadByteEx
kernelbase.dll.MapViewOfFileExNuma
kernelbase.dll.SetFileApisToANSI
kernelbase.dll.SetFileApisToOEM
kernelbase.dll.VirtualAllocExNuma
kernelbase.dll.EnumCalendarInfoExEx
kernelbase.dll.EnumDateFormatsExEx
kernelbase.dll.EnumTimeFormatsEx
kernelbase.dll.GetCurrencyFormatEx
kernelbase.dll.GetEraNameCountedString
kernelbase.dll.GetNumberFormatEx
kernelbase.dll.GetSystemDefaultLocaleName
kernelbase.dll.GetUserDefaultLocaleName
kernelbase.dll.LCIDToLocaleName
kernelbase.dll.GetNamedLocaleHashNode
kernelbase.dll.GetLocaleInfoHelper
kernelbase.dll.GetUserInfoWord
kernelbase.dll.GetCalendar
kernelbase.dll.SpecialMBToWC
kernelbase.dll.Internal_EnumCalendarInfo
kernelbase.dll.NlsValidateLocale
kernelbase.dll.BaseReleaseProcessExePath
kernelbase.dll.TlsGetValue
kernelbase.dll.SetThreadPriority
kernelbase.dll.SetProcessShutdownParameters
kernelbase.dll.SetPriorityClass
kernelbase.dll.ResumeThread
kernelbase.dll.QueueUserAPC
kernelbase.dll.ProcessIdToSessionId
kernelbase.dll.OpenThread
kernelbase.dll.GetThreadPriorityBoost
kernelbase.dll.GetThreadPriority
kernelbase.dll.GetStartupInfoW
kernelbase.dll.GetProcessTimes
kernelbase.dll.GetPriorityClass
kernelbase.dll.GetExitCodeThread
kernelbase.dll.GetCurrentThreadId
kernelbase.dll.GetCurrentThread
kernelbase.dll.GetProcessId
kernelbase.dll.GetProcessIdOfThread
kernelbase.dll.GetThreadId
kernelbase.dll.GetCurrentProcessId
kernelbase.dll.CreateRemoteThreadEx
kernelbase.dll.GetExitCodeProcess
kernelbase.dll.TlsFree
kernelbase.dll.TlsAlloc
kernelbase.dll.TerminateThread
kernelbase.dll.TerminateProcess
kernelbase.dll.SwitchToThread
kernelbase.dll.SuspendThread
kernelbase.dll.SetThreadStackGuarantee
kernelbase.dll.SetThreadPriorityBoost
kernelbase.dll.OpenProcessToken
kernelbase.dll.TlsSetValue
kernelbase.dll.SetProcessAffinityUpdateMode
kernelbase.dll.QueryProcessAffinityUpdateMode
kernelbase.dll.GetProcessVersion
kernelbase.dll.CreateRemoteThread
kernelbase.dll.InitializeProcThreadAttributeList
kernelbase.dll.UpdateProcThreadAttribute
kernelbase.dll.DeleteProcThreadAttributeList
kernelbase.dll.GetCurrentProcess
kernelbase.dll.HeapCreate
kernelbase.dll.HeapSetInformation
kernelbase.dll.HeapQueryInformation
kernelbase.dll.HeapLock
kernelbase.dll.HeapDestroy
kernelbase.dll.GetProcessHeap
kernelbase.dll.GetProcessHeaps
kernelbase.dll.HeapWalk
kernelbase.dll.HeapValidate
kernelbase.dll.HeapUnlock
kernelbase.dll.HeapCompact
kernelbase.dll.HeapSummary
kernelbase.dll.MapViewOfFileEx
kernelbase.dll.ReadProcessMemory
kernelbase.dll.UnmapViewOfFile
kernelbase.dll.VirtualAlloc
kernelbase.dll.VirtualAllocEx
kernelbase.dll.VirtualFree
kernelbase.dll.VirtualFreeEx
kernelbase.dll.VirtualProtect
kernelbase.dll.WriteProcessMemory
kernelbase.dll.VirtualQueryEx
kernelbase.dll.VirtualQuery
kernelbase.dll.VirtualProtectEx
kernelbase.dll.FlushViewOfFile
kernelbase.dll.CreateFileMappingW
kernelbase.dll.OpenFileMappingW
kernelbase.dll.MapViewOfFile
kernelbase.dll.DuplicateHandle
kernelbase.dll.GetHandleInformation
kernelbase.dll.SetHandleInformation
kernelbase.dll.CloseHandle
kernelbase.dll.OpenProcess
kernelbase.dll.OpenSemaphoreW
kernelbase.dll.OpenWaitableTimerW
kernelbase.dll.ReleaseMutex
kernelbase.dll.ReleaseSemaphore
kernelbase.dll.OpenMutexW
kernelbase.dll.SetEvent
kernelbase.dll.SetWaitableTimer
kernelbase.dll.SleepEx
kernelbase.dll.WaitForMultipleObjectsEx
kernelbase.dll.WaitForSingleObjectEx
kernelbase.dll.OpenEventW
kernelbase.dll.OpenEventA
kernelbase.dll.InitializeCriticalSectionEx
kernelbase.dll.InitializeCriticalSectionAndSpinCount
kernelbase.dll.CreateWaitableTimerExW
kernelbase.dll.CreateSemaphoreExW
kernelbase.dll.CreateEventA
kernelbase.dll.CreateEventW
kernelbase.dll.CancelWaitableTimer
kernelbase.dll.CreateEventExA
kernelbase.dll.CreateEventExW
kernelbase.dll.CreateMutexA
kernelbase.dll.CreateMutexExA
kernelbase.dll.CreateMutexExW
kernelbase.dll.ResetEvent
kernelbase.dll.CreateMutexW
kernelbase.dll.GetFullPathNameW
kernelbase.dll.GetFullPathNameA
kernelbase.dll.SetFileTime
kernelbase.dll.QueryDosDeviceW
kernelbase.dll.CreateFileW
kernelbase.dll.LockFile
kernelbase.dll.GetFileSize
kernelbase.dll.SetEndOfFile
kernelbase.dll.WriteFile
kernelbase.dll.SetFilePointer
kernelbase.dll.ReadFile
kernelbase.dll.WriteFileEx
kernelbase.dll.WriteFileGather
kernelbase.dll.GetFinalPathNameByHandleA
kernelbase.dll.GetFinalPathNameByHandleW
kernelbase.dll.RemoveDirectoryW
kernelbase.dll.GetDiskFreeSpaceW
kernelbase.dll.CreateDirectoryW
kernelbase.dll.DefineDosDeviceW
kernelbase.dll.FindFirstFileExA
kernelbase.dll.FindFirstFileExW
kernelbase.dll.FindClose
kernelbase.dll.GetFileType
kernelbase.dll.FlushFileBuffers
kernelbase.dll.SetFileAttributesW
kernelbase.dll.GetFileAttributesExW
kernelbase.dll.DeleteFileW
kernelbase.dll.GetFileTime
kernelbase.dll.DeleteFileA
kernelbase.dll.GetFileAttributesA
kernelbase.dll.FindNextFileW
kernelbase.dll.FindFirstFileW
kernelbase.dll.GetLogicalDriveStringsW
kernelbase.dll.GetTempFileNameW
kernelbase.dll.GetVolumeInformationW
kernelbase.dll.CompareFileTime
kernelbase.dll.CreateDirectoryA
kernelbase.dll.FileTimeToLocalFileTime
kernelbase.dll.FileTimeToSystemTime
kernelbase.dll.FindCloseChangeNotification
kernelbase.dll.FindFirstFileA
kernelbase.dll.FindFirstChangeNotificationA
kernelbase.dll.FindFirstChangeNotificationW
kernelbase.dll.FindNextChangeNotification
kernelbase.dll.FindNextFileA
kernelbase.dll.GetDiskFreeSpaceA
kernelbase.dll.GetDiskFreeSpaceExA
kernelbase.dll.GetDiskFreeSpaceExW
kernelbase.dll.UnlockFileEx
kernelbase.dll.GetDriveTypeA
kernelbase.dll.GetDriveTypeW
kernelbase.dll.GetFileAttributesExA
kernelbase.dll.GetFileAttributesW
kernelbase.dll.GetFileInformationByHandle
kernelbase.dll.GetFileSizeEx
kernelbase.dll.GetVolumeInformationByHandleW
kernelbase.dll.LocalFileTimeToFileTime
kernelbase.dll.LockFileEx
kernelbase.dll.ReadFileScatter
kernelbase.dll.ReadFileEx
kernelbase.dll.RemoveDirectoryA
kernelbase.dll.SetFileAttributesA
kernelbase.dll.SetFileInformationByHandle
kernelbase.dll.SetFilePointerEx
kernelbase.dll.SetFileValidData
kernelbase.dll.UnlockFile
kernelbase.dll.PostQueuedCompletionStatus
kernelbase.dll.GetQueuedCompletionStatusEx
kernelbase.dll.GetQueuedCompletionStatus
kernelbase.dll.CreateIoCompletionPort
kernelbase.dll.CancelIoEx
kernelbase.dll.GetOverlappedResult
kernelbase.dll.DeviceIoControl
kernelbase.dll.ChangeTimerQueueTimer
kernelbase.dll.CreateTimerQueue
kernelbase.dll.UnregisterWaitEx
kernelbase.dll.DeleteTimerQueueTimer
kernelbase.dll.DeleteTimerQueueEx
kernelbase.dll.CreateTimerQueueTimer
kernelbase.dll.GetModuleHandleA
kernelbase.dll.GetModuleHandleW
kernelbase.dll.GetModuleHandleExA
kernelbase.dll.GetModuleHandleExW
kernelbase.dll.LoadResource
kernelbase.dll.LockResource
kernelbase.dll.SizeofResource
kernelbase.dll.GetProcAddress
kernelbase.dll.GetModuleFileNameA
kernelbase.dll.FreeLibraryAndExitThread
kernelbase.dll.FindStringOrdinal
kernelbase.dll.DisableThreadLibraryCalls
kernelbase.dll.LoadLibraryExA
kernelbase.dll.GetModuleFileNameW
kernelbase.dll.FindResourceExW
kernelbase.dll.FreeLibrary
kernelbase.dll.LoadLibraryExW
kernelbase.dll.FreeResource
kernelbase.dll.PeekNamedPipe
kernelbase.dll.DisconnectNamedPipe
kernelbase.dll.CreatePipe
kernelbase.dll.ConnectNamedPipe
kernelbase.dll.GetNamedPipeAttribute
kernelbase.dll.GetNamedPipeClientComputerNameW
kernelbase.dll.WaitNamedPipeW
kernelbase.dll.SetNamedPipeHandleState
kernelbase.dll.CreateNamedPipeW
kernelbase.dll.TransactNamedPipe
kernelbase.dll.IsWow64Process
kernelbase.dll.LCMapStringA
kernelbase.dll.LocalLock
kernelbase.dll.LocalReAlloc
kernelbase.dll.LocalUnlock
kernelbase.dll.GlobalAlloc
kernelbase.dll.FormatMessageW
kernelbase.dll.FormatMessageA
kernelbase.dll.NeedCurrentDirectoryForExePathA
kernelbase.dll.EnumSystemLocalesA
kernelbase.dll.PulseEvent
kernelbase.dll.Sleep
kernelbase.dll.Wow64DisableWow64FsRedirection
kernelbase.dll.Wow64RevertWow64FsRedirection
kernelbase.dll.lstrcmpW
kernelbase.dll.lstrcmpiW
kernelbase.dll.lstrcpynA
kernelbase.dll.lstrcpynW
kernelbase.dll.lstrlenA
kernelbase.dll.FatalAppExitA
kernelbase.dll.NeedCurrentDirectoryForExePathW
kernelbase.dll.FatalAppExitW
kernelbase.dll.LocalAlloc
kernelbase.dll.GlobalFree
kernelbase.dll.lstrlenW
kernelbase.dll.LocalFree
kernelbase.dll.IsProcessInJob
kernelbase.dll.GetLocalTime
kernelbase.dll.GetSystemTimeAdjustment
kernelbase.dll.GetSystemTimeAsFileTime
kernelbase.dll.GetTickCount64
kernelbase.dll.GetTimeZoneInformation
kernelbase.dll.GetTimeZoneInformationForYear
kernelbase.dll.GetVersion
kernelbase.dll.GetVersionExA
kernelbase.dll.GetVersionExW
kernelbase.dll.GetWindowsDirectoryW
kernelbase.dll.SetLocalTime
kernelbase.dll.SystemTimeToTzSpecificLocalTime
kernelbase.dll.TzSpecificLocalTimeToSystemTime
kernelbase.dll.GetDynamicTimeZoneInformation
kernelbase.dll.GetLogicalProcessorInformation
kernelbase.dll.GetSystemInfo
kernelbase.dll.GetLogicalProcessorInformationEx
kernelbase.dll.GetWindowsDirectoryA
kernelbase.dll.GlobalMemoryStatusEx
kernelbase.dll.GetTickCount
kernelbase.dll.GetSystemTime
kernelbase.dll.SystemTimeToFileTime
kernelbase.dll.GetComputerNameExW
kernelbase.dll.GetComputerNameExA
kernelbase.dll.VerLanguageNameA
kernelbase.dll.FindNLSStringEx
kernelbase.dll.SetThreadLocale
kernelbase.dll.NlsWriteEtwEvent
kernelbase.dll.NlsEventDataDescCreate
kernelbase.dll.ConvertDefaultLocale
kernelbase.dll.VerLanguageNameW
kernelbase.dll.SetLocaleInfoW
kernelbase.dll.SetCalendarInfoW
kernelbase.dll.LCMapStringW
kernelbase.dll.IsValidLocale
kernelbase.dll.IsValidLanguageGroup
kernelbase.dll.IsValidCodePage
kernelbase.dll.IsNLSDefinedString
kernelbase.dll.GetUserDefaultLCID
kernelbase.dll.GetUserDefaultLangID
kernelbase.dll.GetThreadLocale
kernelbase.dll.GetSystemDefaultLCID
kernelbase.dll.GetSystemDefaultLangID
kernelbase.dll.GetProcessPreferredUILanguages
kernelbase.dll.GetOEMCP
kernelbase.dll.GetLocaleInfoW
kernelbase.dll.GetCPInfoExW
kernelbase.dll.GetCPInfo
kernelbase.dll.GetACP
kernelbase.dll.GetFileMUIPath
kernelbase.dll.FindNLSString
kernelbase.dll.NlsUpdateSystemLocale
kernelbase.dll.NlsUpdateLocale
kernelbase.dll.NlsGetCacheUpdateCount
kernelbase.dll.NlsCheckPolicy
kernelbase.dll.GetCalendarInfoW
kernelbase.dll.GetCalendarInfoEx
kernelbase.dll.GetLocaleInfoEx
kernelbase.dll.GetSystemPreferredUILanguages
kernelbase.dll.GetThreadPreferredUILanguages
kernelbase.dll.GetThreadUILanguage
kernelbase.dll.GetUILanguageInfo
kernelbase.dll.GetUserPreferredUILanguages
kernelbase.dll.IsValidLocaleName
kernelbase.dll.LCMapStringEx
kernelbase.dll.LocaleNameToLCID
kernelbase.dll.ResolveLocaleName
kernelbase.dll.GetFileMUIInfo
kernelbase.dll.GetEnvironmentStrings
kernelbase.dll.GetEnvironmentVariableW
kernelbase.dll.SearchPathW
kernelbase.dll.SetStdHandleEx
kernelbase.dll.ExpandEnvironmentStringsA
kernelbase.dll.ExpandEnvironmentStringsW
kernelbase.dll.FreeEnvironmentStringsA
kernelbase.dll.FreeEnvironmentStringsW
kernelbase.dll.GetCommandLineA
kernelbase.dll.GetCommandLineW
kernelbase.dll.GetCurrentDirectoryA
kernelbase.dll.GetCurrentDirectoryW
kernelbase.dll.GetEnvironmentStringsW
kernelbase.dll.SetEnvironmentStringsW
kernelbase.dll.GetEnvironmentVariableA
kernelbase.dll.GetStdHandle
kernelbase.dll.SetCurrentDirectoryA
kernelbase.dll.SetCurrentDirectoryW
kernelbase.dll.SetEnvironmentVariableA
kernelbase.dll.SetEnvironmentVariableW
kernelbase.dll.SetStdHandle
kernelbase.dll.GetStringTypeW
kernelbase.dll.GetStringTypeExW
kernelbase.dll.FoldStringW
kernelbase.dll.CompareStringW
kernelbase.dll.WideCharToMultiByte
kernelbase.dll.CompareStringOrdinal
kernelbase.dll.CompareStringEx
kernelbase.dll.MultiByteToWideChar
kernelbase.dll.DebugBreak
kernelbase.dll.OutputDebugStringA
kernelbase.dll.OutputDebugStringW
kernelbase.dll.IsDebuggerPresent
kernelbase.dll.GetLastError
kernelbase.dll.GetErrorMode
kernelbase.dll.RaiseException
kernelbase.dll.SetErrorMode
kernelbase.dll.SetLastError
kernelbase.dll.FlsAlloc
kernelbase.dll.FlsFree
kernelbase.dll.FlsGetValue
kernelbase.dll.FlsSetValue
kernelbase.dll.Beep
kernelbase.dll.QueryPerformanceFrequency
kernelbase.dll.QueryPerformanceCounter
kernelbase.dll.AllocateAndInitializeSid
kernelbase.dll.FreeSid
kernelbase.dll.DuplicateToken
kernelbase.dll.AccessCheck
ntdll.dll.wcstol
ntdll.dll.RtlQueryInformationActiveActivationContext
ntdll.dll.NtVdmControl
ntdll.dll.RtlIsThreadWithinLoaderCallout
ntdll.dll.RtlGetIntegerAtom
ntdll.dll.RtlRetrieveNtUserPfn
ntdll.dll.RtlInitializeNtUserPfn
ntdll.dll._allshr
ntdll.dll.NtCallbackReturn
ntdll.dll._chkstk
ntdll.dll.CsrCaptureMessageBuffer
ntdll.dll.RtlRunDecodeUnicodeString
ntdll.dll.RtlRunEncodeUnicodeString
ntdll.dll.RtlGetThreadLangIdByIndex
ntdll.dll.sscanf_s
ntdll.dll.strrchr
ntdll.dll.wcsncat_s
ntdll.dll.RtlCheckRegistryKey
ntdll.dll.LdrFlushAlternateResourceModules
ntdll.dll.iswspace
ntdll.dll._wtoi
ntdll.dll._aulldvrm
ntdll.dll.NlsAnsiCodePage
gdi32.dll.GetClipRgn
gdi32.dll.GetHFONT
gdi32.dll.SetGraphicsMode
gdi32.dll.SetLayout
gdi32.dll.GetBoundsRect
gdi32.dll.ExcludeClipRect
gdi32.dll.PlayEnhMetaFile
gdi32.dll.Ellipse
gdi32.dll.GdiFixUpHandle
gdi32.dll.Rectangle
gdi32.dll.GetTextCharacterExtra
gdi32.dll.SetTextCharacterExtra
gdi32.dll.GetCurrentObject
gdi32.dll.GetViewportOrgEx
gdi32.dll.PolyPatBlt
gdi32.dll.CreateBrushIndirect
gdi32.dll.SetBoundsRect
gdi32.dll.CopyEnhMetaFileW
gdi32.dll.CopyMetaFileW
gdi32.dll.GetPaletteEntries
gdi32.dll.CreatePalette
gdi32.dll.SetPaletteEntries
gdi32.dll.GetTextCharsetInfo
gdi32.dll.QueryFontAssocStatus
gdi32.dll.GetCharWidthInfo
gdi32.dll.GetCharWidthA
gdi32.dll.GetTextFaceW
gdi32.dll.GetCharABCWidthsA
gdi32.dll.GetCharABCWidthsW
gdi32.dll.SetBrushOrgEx
gdi32.dll.CreateFontIndirectW
gdi32.dll.EnumFontsW
gdi32.dll.GetTextMetricsW
gdi32.dll.GetTextColor
gdi32.dll.GdiGetCodePage
gdi32.dll.GetTextCharset
gdi32.dll.GetBkMode
gdi32.dll.GetViewportExtEx
gdi32.dll.GetWindowExtEx
gdi32.dll.GdiGetCharDimensions
gdi32.dll.GdiPrinterThunk
gdi32.dll.GdiLoadType1Fonts
gdi32.dll.GdiAddFontResourceW
gdi32.dll.TranslateCharsetInfo
gdi32.dll.OffsetWindowOrgEx
gdi32.dll.ExtTextOutW
gdi32.dll.CreateDCW
gdi32.dll.CreateDIBitmap
gdi32.dll.SetBitmapBits
gdi32.dll.GdiValidateHandle
gdi32.dll.GdiDllInitialize
gdi32.dll.GdiProcessSetup
gdi32.dll.GdiConvertBitmapV5
gdi32.dll.GdiCreateLocalEnhMetaFile
gdi32.dll.GdiCreateLocalMetaFilePict
gdi32.dll.GetRgnBox
gdi32.dll.OffsetRgn
gdi32.dll.MirrorRgn
gdi32.dll.EnableEUDC
gdi32.dll.GdiConvertToDevmodeW
gdi32.dll.GetTextExtentPointA
gdi32.dll.GetTextExtentPointW
gdi32.dll.SetTextAlign
gdi32.dll.GetTextAlign
gdi32.dll.IntersectClipRect
gdi32.dll.GetBkColor
gdi32.dll.GetObjectW
gdi32.dll.StretchDIBits
gdi32.dll.GetDIBColorTable
gdi32.dll.GdiGetBitmapBitsSize
gdi32.dll.DeleteMetaFile
gdi32.dll.DeleteEnhMetaFile
gdi32.dll.GdiConvertMetaFilePict
gdi32.dll.GdiConvertEnhMetaFile
gdi32.dll.GdiReleaseDC
gdi32.dll.StretchBlt
gdi32.dll.GetObjectType
gdi32.dll.GdiConvertAndCheckDC
gdi32.dll.SetRectRgn
gdi32.dll.TextOutW
gdi32.dll.PatBlt
gdi32.dll.SetLayoutWidth
kernel32.dll.DelayLoadFailureHook
kernel32.dll.CreateFileMappingW
kernel32.dll.WerpNotifyLoadStringResource
kernel32.dll.GetSystemDefaultLangID
kernel32.dll.RegQueryInfoKeyW
kernel32.dll.RegEnumValueW
kernel32.dll.RegOpenKeyExW
kernel32.dll.RegQueryValueExW
kernel32.dll.GetVersionExW
kernel32.dll.WerpNotifyUseStringResource
kernel32.dll.ProcessIdToSessionId
kernel32.dll.FindFirstFileW
kernel32.dll.FindNextFileW
kernel32.dll.GetLogicalDrives
kernel32.dll.SetCurrentDirectoryW
kernel32.dll.GetCurrentDirectoryW
kernel32.dll.GetAtomNameW
kernel32.dll.GetAtomNameA
kernel32.dll.AddAtomW
kernel32.dll.AddAtomA
kernel32.dll.GetSystemWindowsDirectoryW
kernel32.dll.CreateProcessW
kernel32.dll.EnumResourceNamesExW
kernel32.dll.SetFileTime
kernel32.dll.FindResourceW
kernel32.dll.FoldStringW
kernel32.dll.GlobalAddAtomW
kernel32.dll.ExpandEnvironmentStringsW
kernel32.dll.SearchPathW
kernel32.dll.IsDBCSLeadByteEx
kernel32.dll.DisableThreadLibraryCalls
kernel32.dll.FindResourceExA
kernel32.dll.FindResourceExW
kernel32.dll.LoadStringBaseExW
kernel32.dll.RegisterWaitForInputIdle
kernel32.dll.QueryActCtxSettingsW
kernel32.dll.LoadAppInitDlls
kernel32.dll.LocalSize
kernel32.dll.LocalUnlock
kernel32.dll.LocalLock
kernel32.dll.GetPrivateProfileStringW
kernel32.dll.RegSetValueExW
kernel32.dll.RegCloseKey
kernel32.dll.RegCreateKeyExW
kernel32.dll.RegDeleteKeyExW
kernel32.dll.GlobalSize
kernel32.dll.DeleteAtom
kernel32.dll.LoadLibraryW
kernel32.dll.GlobalGetAtomNameW
kernel32.dll.WaitForMultipleObjectsEx
kernel32.dll.lstrcmpiW
kernel32.dll.WritePrivateProfileStringW
kernel32.dll.GlobalFindAtomW
advapi32.dll.CheckTokenMembership
msvcrt.dll.iswctype
msvcrt.dll._wcstoui64
msvcrt.dll._ftol2
msvcrt.dll.tolower
msvcrt.dll._ultow
msvcrt.dll.wcstok
msvcrt.dll.isalnum
msvcrt.dll.isspace
msvcrt.dll._errno
msvcrt.dll.mbstowcs
msvcrt.dll._except_handler4_common
msvcrt.dll.wcschr
msvcrt.dll.wcsrchr
msvcrt.dll.memset
msvcrt.dll.memmove
msvcrt.dll._wcsicmp
msvcrt.dll._vsnwprintf
msvcrt.dll.memcpy
msvcrt.dll.wcscpy_s
msvcrt.dll._stricmp
msvcrt.dll.strchr
msvcrt.dll.strrchr
msvcrt.dll.strstr
msvcrt.dll._vsnprintf
msvcrt.dll.wcstombs
msvcrt.dll.wcsstr
msvcrt.dll.swprintf_s
msvcrt.dll.wcsncpy_s
msvcrt.dll.wcsncmp
msvcrt.dll.swscanf_s
msvcrt.dll._wcsnicmp
msvcrt.dll.wcstoul
msvcrt.dll.wcscat_s
ntdll.dll.EtwEventWriteEx
ntdll.dll.NtQuerySystemTime
ntdll.dll.RtlGetNtProductType
ntdll.dll.RtlIsValidIndexHandle
ntdll.dll.NtCompareTokens
ntdll.dll.RtlEnumerateGenericTableWithoutSplaying
ntdll.dll.RtlIsGenericTableEmpty
ntdll.dll.RtlDuplicateUnicodeString
ntdll.dll.RtlDeleteElementGenericTable
ntdll.dll.RtlInsertElementGenericTable
ntdll.dll.RtlDestroyHandleTable
ntdll.dll.RtlStringFromGUID
ntdll.dll.RtlInitializeGenericTable
ntdll.dll.RtlLookupElementGenericTable
ntdll.dll.RtlNumberGenericTableElements
ntdll.dll.RtlDllShutdownInProgress
ntdll.dll.RtlRegisterThreadWithCsrss
ntdll.dll.NtTraceControl
ntdll.dll.EtwSendNotification
ntdll.dll.EtwDeliverDataBlock
ntdll.dll.EtwEnumerateProcessRegGuids
ntdll.dll.RtlQueryTimeZoneInformation
ntdll.dll.RtlQueryPerformanceFrequency
ntdll.dll.EtwpGetCpuSpeed
ntdll.dll.NtQueryPerformanceCounter
ntdll.dll.RtlInitializeBitMap
ntdll.dll.RtlInterlockedClearBitRun
ntdll.dll.NtTraceEvent
ntdll.dll.RtlAdjustPrivilege
ntdll.dll.EtwProcessPrivateLoggerRequest
ntdll.dll.RtlIpv4AddressToStringW
ntdll.dll.RtlIpv6AddressToStringW
ntdll.dll.NtRenameKey
ntdll.dll.NtLoadKeyEx
ntdll.dll.RtlCopyString
ntdll.dll.RtlTimeToSecondsSince1970
ntdll.dll.NtQueryMutant
ntdll.dll.NtAlpcQueryInformation
ntdll.dll.NtReplaceKey
ntdll.dll.NtSaveKey
ntdll.dll.NtSaveMergedKeys
ntdll.dll.EtwLogTraceEvent
sechost.dll.RegisterServiceCtrlHandlerExW
sechost.dll.StartServiceCtrlDispatcherW
sechost.dll.SetServiceStatus
sechost.dll.I_ScRpcBindW
sechost.dll.StartServiceCtrlDispatcherA
sechost.dll.StartServiceA
sechost.dll.RegisterServiceCtrlHandlerW
sechost.dll.RegisterServiceCtrlHandlerExA
sechost.dll.RegisterServiceCtrlHandlerA
sechost.dll.QueryServiceStatus
sechost.dll.QueryServiceConfigA
sechost.dll.QueryServiceConfig2A
sechost.dll.OpenServiceA
sechost.dll.OpenSCManagerA
sechost.dll.NotifyServiceStatusChangeA
sechost.dll.CreateServiceA
sechost.dll.ControlServiceExA
sechost.dll.ControlService
sechost.dll.ChangeServiceConfigA
sechost.dll.ChangeServiceConfig2A
sechost.dll.I_ScRpcBindA
sechost.dll.ControlServiceExW
sechost.dll.OpenSCManagerW
sechost.dll.OpenServiceW
sechost.dll.CreateServiceW
sechost.dll.DeleteService
sechost.dll.CloseServiceHandle
sechost.dll.StartServiceW
sechost.dll.QueryServiceConfig2W
sechost.dll.NotifyServiceStatusChangeW
sechost.dll.ChangeServiceConfig2W
sechost.dll.ChangeServiceConfigW
sechost.dll.QueryServiceConfigW
sechost.dll.QueryServiceObjectSecurity
sechost.dll.QueryServiceStatusEx
sechost.dll.SetServiceObjectSecurity
kernel32.dll.RegSaveKeyExW
kernel32.dll.RegNotifyChangeKeyValue
kernel32.dll.RegQueryInfoKeyA
kernel32.dll.RegQueryValueExA
kernel32.dll.RegLoadMUIStringA
kernel32.dll.RegSaveKeyExA
kernel32.dll.RegGetKeySecurity
kernel32.dll.RegSetKeySecurity
kernel32.dll.RegRestoreKeyA
kernel32.dll.RegRestoreKeyW
kernel32.dll.RegLoadKeyA
kernel32.dll.RegLoadKeyW
kernel32.dll.RegDeleteKeyExA
kernel32.dll.RegDeleteValueA
kernel32.dll.RegDeleteValueW
kernel32.dll.RegEnumKeyExA
kernel32.dll.RegEnumKeyExW
kernel32.dll.RegEnumValueA
kernel32.dll.RegGetValueA
kernel32.dll.RegGetValueW
kernel32.dll.RegCreateKeyExA
kernel32.dll.RegFlushKey
kernel32.dll.RegOpenCurrentUser
kernel32.dll.RegOpenKeyExA
kernel32.dll.RegDisablePredefinedCacheEx
kernel32.dll.RegLoadMUIStringW
kernel32.dll.RegOpenUserClassesRoot
kernel32.dll.RegSetValueExA
kernel32.dll.RegUnLoadKeyA
kernel32.dll.RegUnLoadKeyW
kernel32.dll.RegDeleteTreeW
kernel32.dll.RegDeleteTreeA
kernelbase.dll.ImpersonateNamedPipeClient
kernel32.dll.GetPriorityClass
kernel32.dll.OpenThread
kernel32.dll.SetThreadToken
kernel32.dll.OpenThreadToken
kernel32.dll.OpenProcessToken
kernel32.dll.CreateProcessAsUserW
kernelbase.dll.GetSidLengthRequired
kernelbase.dll.GetSidSubAuthority
kernelbase.dll.GetSidSubAuthorityCount
kernelbase.dll.GetWindowsAccountDomainSid
kernelbase.dll.ImpersonateAnonymousToken
kernelbase.dll.ImpersonateLoggedOnUser
kernelbase.dll.ImpersonateSelf
kernelbase.dll.InitializeAcl
kernelbase.dll.InitializeSecurityDescriptor
kernelbase.dll.InitializeSid
kernelbase.dll.IsTokenRestricted
kernelbase.dll.IsValidAcl
kernelbase.dll.IsValidRelativeSecurityDescriptor
kernelbase.dll.IsValidSecurityDescriptor
kernelbase.dll.IsWellKnownSid
kernelbase.dll.MakeAbsoluteSD
kernelbase.dll.MakeAbsoluteSD2
kernelbase.dll.GetSidIdentifierAuthority
kernelbase.dll.MapGenericMask
kernelbase.dll.PrivilegeCheck
kernelbase.dll.QuerySecurityAccessMask
kernelbase.dll.RevertToSelf
kernelbase.dll.SetAclInformation
kernelbase.dll.SetKernelObjectSecurity
kernelbase.dll.SetPrivateObjectSecurity
kernelbase.dll.SetPrivateObjectSecurityEx
kernelbase.dll.EqualDomainSid
kernelbase.dll.SetSecurityAccessMask
kernelbase.dll.SetSecurityDescriptorControl
kernelbase.dll.SetSecurityDescriptorDacl
kernelbase.dll.SetSecurityDescriptorGroup
kernelbase.dll.SetSecurityDescriptorOwner
kernelbase.dll.SetSecurityDescriptorRMControl
kernelbase.dll.SetSecurityDescriptorSacl
kernelbase.dll.SetTokenInformation
kernelbase.dll.GetSecurityDescriptorSacl
kernelbase.dll.GetSecurityDescriptorRMControl
kernelbase.dll.GetSecurityDescriptorOwner
kernelbase.dll.GetSecurityDescriptorLength
kernelbase.dll.GetSecurityDescriptorGroup
kernelbase.dll.GetSecurityDescriptorDacl
kernelbase.dll.GetSecurityDescriptorControl
kernelbase.dll.GetPrivateObjectSecurity
kernelbase.dll.GetLengthSid
kernelbase.dll.GetKernelObjectSecurity
kernelbase.dll.GetAclInformation
kernelbase.dll.GetAce
kernelbase.dll.FindFirstFreeAce
kernelbase.dll.MakeSelfRelativeSD
kernelbase.dll.EqualSid
kernelbase.dll.IsValidSid
kernelbase.dll.AccessCheckAndAuditAlarmW
kernelbase.dll.AccessCheckByTypeAndAuditAlarmW
kernelbase.dll.AccessCheckByTypeResultListAndAuditAlarmW
kernelbase.dll.AccessCheckByTypeResultListAndAuditAlarmByHandleW
kernelbase.dll.ObjectOpenAuditAlarmW
kernelbase.dll.ObjectPrivilegeAuditAlarmW
kernelbase.dll.ObjectCloseAuditAlarmW
kernelbase.dll.ObjectDeleteAuditAlarmW
kernelbase.dll.PrivilegedServiceAuditAlarmW
kernelbase.dll.SetFileSecurityW
kernelbase.dll.GetFileSecurityW
kernelbase.dll.CopySid
kernelbase.dll.GetTokenInformation
kernelbase.dll.AccessCheckByType
kernelbase.dll.AccessCheckByTypeResultList
kernelbase.dll.AddAccessAllowedAce
kernelbase.dll.AddAccessAllowedAceEx
kernelbase.dll.AddAccessAllowedObjectAce
kernelbase.dll.AddAccessDeniedAce
kernelbase.dll.AddAccessDeniedAceEx
kernelbase.dll.AddAccessDeniedObjectAce
kernelbase.dll.AddAce
kernelbase.dll.AddAuditAccessAce
kernelbase.dll.AddAuditAccessAceEx
kernelbase.dll.AddAuditAccessObjectAce
kernelbase.dll.AdjustTokenGroups
kernelbase.dll.AdjustTokenPrivileges
kernelbase.dll.AllocateLocallyUniqueId
kernelbase.dll.AreAllAccessesGranted
kernelbase.dll.AreAnyAccessesGranted
kernelbase.dll.CheckTokenMembership
kernelbase.dll.ConvertToAutoInheritPrivateObjectSecurity
kernelbase.dll.CreatePrivateObjectSecurity
kernelbase.dll.CreatePrivateObjectSecurityEx
kernelbase.dll.CreatePrivateObjectSecurityWithMultipleInheritance
kernelbase.dll.CreateRestrictedToken
kernelbase.dll.CreateWellKnownSid
kernelbase.dll.DeleteAce
kernelbase.dll.DestroyPrivateObjectSecurity
kernelbase.dll.DuplicateTokenEx
kernelbase.dll.EqualPrefixSid
kernel32.dll.VirtualAllocEx
kernel32.dll.OpenProcess
kernel32.dll.GetActiveProcessorCount
kernel32.dll.GetVolumeInformationW
kernel32.dll.GetDriveTypeW
kernel32.dll.GetLogicalDriveStringsW
kernel32.dll.GetComputerNameW
kernel32.dll.ExpandEnvironmentStringsA
kernel32.dll.RegKrnInitialize
kernel32.dll.GetComputerNameA
kernel32.dll.CreateMutexW
kernel32.dll.FreeLibraryAndExitThread
kernel32.dll.GetPrivateProfileIntW
kernel32.dll.ResetEvent
kernel32.dll.DosDateTimeToFileTime
kernel32.dll.FileTimeToDosDateTime
kernel32.dll.FindFirstFileExW
kernel32.dll.SetFileInformationByHandle
kernel32.dll.CopyFileW
kernel32.dll.GetFileSizeEx
kernel32.dll.GetComputerNameExW
kernel32.dll.CreateProcessInternalA
kernel32.dll.RegKrnGetGlobalState
kernel32.dll.SleepEx
kernel32.dll.GetFullPathNameW
kernel32.dll.GetFileAttributesW
kernel32.dll.CreateEventW
kernel32.dll.GetThreadUILanguage
kernel32.dll.GetCommandLineW
kernel32.dll.GetModuleHandleExW
kernel32.dll.MoveFileW
kernel32.dll.DeleteFileW
kernel32.dll.GetFileAttributesExW
kernel32.dll.OutputDebugStringW
kernel32.dll.FormatMessageW
kernel32.dll.CompareFileTime
kernel32.dll.GetLongPathNameW
kernel32.dll.GetVolumePathNameW
kernel32.dll.GetFileMUIPath
kernel32.dll.GetDiskFreeSpaceExW
kernel32.dll.GetOverlappedResult
rpcrt4.dll.RpcBindingCreateW
rpcrt4.dll.UuidCreate
rpcrt4.dll.RpcBindingSetAuthInfoA
rpcrt4.dll.RpcEpResolveBinding
rpcrt4.dll.I_RpcSNCHOption
rpcrt4.dll.UuidFromStringW
rpcrt4.dll.UuidToStringW
rpcrt4.dll.RpcExceptionFilter
rpcrt4.dll.RpcBindingSetAuthInfoW
rpcrt4.dll.RpcSsDestroyClientContext
rpcrt4.dll.I_RpcMapWin32Status
rpcrt4.dll.I_RpcExceptionFilter
rpcrt4.dll.NdrClientCall2
rpcrt4.dll.RpcBindingSetAuthInfoExW
rpcrt4.dll.RpcStringBindingComposeW
rpcrt4.dll.RpcBindingFromStringBindingW
rpcrt4.dll.RpcStringFreeW
rpcrt4.dll.RpcBindingFree
rpcrt4.dll.RpcBindingSetAuthInfoExA
rpcrt4.dll.RpcRaiseException
rpcrt4.dll.RpcBindingBind
msvcrt.dll.qsort
msvcrt.dll.gmtime
msvcrt.dll.iswdigit
msvcrt.dll.free
msvcrt.dll.malloc
msvcrt.dll._wtoi
msvcrt.dll._XcptFilter
msvcrt.dll._initterm
msvcrt.dll._amsg_exit
ntdll.dll.RtlIpv4AddressToStringA
ntdll.dll.RtlIpv6StringToAddressA
ntdll.dll.RtlIpv4StringToAddressA
ntdll.dll.RtlIpv6StringToAddressExW
ntdll.dll.RtlIpv4StringToAddressExW
nsi.dll.NsiSetAllPersistentParametersWithMask
nsi.dll.NsiCancelChangeNotification
nsi.dll.NsiRequestChangeNotification
nsi.dll.NsiSetAllParameters
nsi.dll.NsiGetParameter
nsi.dll.NsiSetParameter
nsi.dll.NsiEnumerateObjectsAllParameters
nsi.dll.NsiAllocateAndGetTable
nsi.dll.NsiGetAllParameters
nsi.dll.NsiFreeTable
winnsi.dll.NsiConnectToServer
winnsi.dll.NsiRpcRegisterChangeNotification
winnsi.dll.NsiRpcDeregisterChangeNotification
winnsi.dll.NsiRpcGetParameter
winnsi.dll.NsiDisconnectFromServer
rpcrt4.dll.NdrAsyncServerCall
rpcrt4.dll.RpcServerUnregisterIf
rpcrt4.dll.RpcServerUseProtseqEpW
rpcrt4.dll.RpcServerRegisterIf2
rpcrt4.dll.RpcServerInqCallAttributesW
rpcrt4.dll.RpcBindingUnbind
rpcrt4.dll.RpcAsyncCompleteCall
kernelbase.dll.HeapFree
kernelbase.dll.HeapReAlloc
kernelbase.dll.HeapAlloc
kernelbase.dll.InterlockedIncrement
kernelbase.dll.InterlockedCompareExchange
kernelbase.dll.InterlockedExchangeAdd
kernelbase.dll.InterlockedExchange
kernelbase.dll.InterlockedDecrement
kernel32.dll.QueueUserAPC
kernelbase.dll.GetSystemDirectoryW
kernel32.dll.GetEnvironmentVariableA
msvcrt.dll.strncpy
iphlpapi.dll.GetInterfaceInfo
psapi.dll.GetMappedFileNameW
shell32.dll.SHGetFolderPathW
kernel32.dll.PeekNamedPipe
kernel32.dll.DisconnectNamedPipe
kernel32.dll.WinExec
kernel32.dll.GetFileInformationByHandle
kernel32.dll.GetExitCodeProcess
kernel32.dll.WTSGetActiveConsoleSessionId
advapi32.dll.LsaOpenPolicy
advapi32.dll.LsaRetrievePrivateData
advapi32.dll.LsaClose
advapi32.dll.LookupAccountNameA
advapi32.dll.IsValidSid
advapi32.dll.GetSidIdentifierAuthority
advapi32.dll.GetSidSubAuthorityCount
advapi32.dll.GetSidSubAuthority
advapi32.dll.EnumServicesStatusA
advapi32.dll.QueryServiceConfigA
advapi32.dll.ControlService
advapi32.dll.DeleteService
advapi32.dll.QueryServiceStatus
advapi32.dll.ChangeServiceConfigA
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.AllocateAndInitializeSid
advapi32.dll.GetLengthSid
advapi32.dll.InitializeAcl
advapi32.dll.AddAccessAllowedAce
advapi32.dll.SetSecurityDescriptorDacl
advapi32.dll.FreeSid
advapi32.dll.OpenSCManagerA
advapi32.dll.CreateServiceA
advapi32.dll.LockServiceDatabase
advapi32.dll.ChangeServiceConfig2A
advapi32.dll.UnlockServiceDatabase
advapi32.dll.StartServiceA
advapi32.dll.OpenServiceA
advapi32.dll.CloseServiceHandle
advapi32.dll.StartServiceCtrlDispatcherA
advapi32.dll.DuplicateTokenEx
advapi32.dll.SetTokenInformation
advapi32.dll.CreateProcessAsUserA
advapi32.dll.ClearEventLogA
advapi32.dll.OpenEventLogA
advapi32.dll.ReadEventLogA
advapi32.dll.LookupAccountSidA
advapi32.dll.CloseEventLog
imagehlp.dll.MakeSureDirectoryPathExists
iphlpapi.dll.GetIfTable
mfc42.dll.#539
mfc42.dll.#6394
mfc42.dll.#5450
mfc42.dll.#6383
mfc42.dll.#5440
mfc42.dll.#6283
mfc42.dll.#2784
mfc42.dll.#6662
mfc42.dll.#4278
mfc42.dll.#2763
mfc42.dll.#6282
mfc42.dll.#6876
mfc42.dll.#6874
mfc42.dll.#3663
mfc42.dll.#6930
mfc42.dll.#3010
mfc42.dll.#533
mfc42.dll.#5194
mfc42.dll.#5778
mfc42.dll.#5465
mfc42.dll.#798
mfc42.dll.#940
mfc42.dll.#547
mfc42.dll.#2820
mfc42.dll.#536
mfc42.dll.#6648
mfc42.dll.#2824
mfc42.dll.#6143
mfc42.dll.#356
mfc42.dll.#922
mfc42.dll.#2770
mfc42.dll.#2781
mfc42.dll.#4058
mfc42.dll.#3178
mfc42.dll.#1980
mfc42.dll.#4215
mfc42.dll.#3181
mfc42.dll.#6883
mfc42.dll.#668
mfc42.dll.#2614
mfc42.dll.#3811
mfc42.dll.#801
mfc42.dll.#541
mfc42.dll.#941
mfc42.dll.#924
mfc42.dll.#2915
mfc42.dll.#2818
mfc42.dll.#5710
mfc42.dll.#939
mfc42.dll.#537
mfc42.dll.#800
mfc42.dll.#535
mfc42.dll.#858
mfc42.dll.#540
mfc42.dll.#4129
mfc42.dll.#2764
mfc42.dll.#6877
mfc42.dll.#5572
mfc42.dll.#860
mfc42.dll.#2919
mprapi.dll.MprConfigServerConnect
mprapi.dll.MprConfigGetFriendlyName
msvcp60.dll.??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
msvcp60.dll.?_C@?1??_Nullstr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@CAPBDXZ@4DB
msvcp60.dll.?_Eos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEXI@Z
msvcp60.dll.?_Grow@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAE_NI_N@Z
msvcp60.dll.?_Xlen@std@@YAXXZ
msvcp60.dll.?append@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z
msvcp60.dll.?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB
msvcp60.dll.?append@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBDI@Z
msvcp60.dll.?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBDI@Z
msvcp60.dll.?_Tidy@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEX_N@Z
msvcp60.dll.?_Refcnt@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEAAEPBD@Z
msvcp60.dll.?_Split@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEXXZ
msvcp60.dll.?_Xran@std@@YAXXZ
msvcp60.dll.?erase@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@II@Z
msvcp60.dll.?_Nullstr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@CAPBDXZ
msvcp60.dll.?assign@?$char_traits@D@std@@SAXAADABD@Z
msvcp60.dll.?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z
msvcp60.dll.??1_Winit@std@@QAE@XZ
msvcp60.dll.??0_Winit@std@@QAE@XZ
msvcp60.dll.??1Init@ios_base@std@@QAE@XZ
msvcp60.dll.??0Init@ios_base@std@@QAE@XZ
msvcrt.dll._splitpath
msvcrt.dll.??3@YAXPAX@Z
msvcrt.dll.??2@YAPAXI@Z
msvcrt.dll.__CxxFrameHandler
msvcrt.dll.ceil
msvcrt.dll._ftol
msvcrt.dll._purecall
msvcrt.dll.sprintf
msvcrt.dll.sscanf
msvcrt.dll.realloc
msvcrt.dll.toupper
msvcrt.dll.atoi
msvcrt.dll.rand
msvcrt.dll.strncmp
msvcrt.dll._except_handler3
msvcrt.dll._mbscmp
msvcrt.dll.vsprintf
msvcrt.dll._CIacos
msvcrt.dll.printf
msvcrt.dll._CIpow
msvcrt.dll._wcsupr
msvcrt.dll._strnicmp
msvcrt.dll._adjust_fdiv
msvcrt.dll._onexit
msvcrt.dll.__dllonexit
msvcrt.dll.calloc
msvcrt.dll._beginthreadex
msvcrt.dll.localtime
msvcrt.dll.wcscpy
msvcrt.dll.fwrite
msvcrt.dll._local_unwind2
msvcrt.dll._mbsstr
msvcrt.dll._mbslwr
msvcrt.dll.wcscmp
msvcrt.dll.fopen
msvcrt.dll.fseek
msvcrt.dll.ftell
msvcrt.dll.fread
msvcrt.dll.fclose
netapi32.dll.NetUserAdd
netapi32.dll.NetUserSetInfo
netapi32.dll.NetUserGetInfo
netapi32.dll.NetUserDel
netapi32.dll.NetUserGetLocalGroups
netapi32.dll.NetLocalGroupAddMembers
netapi32.dll.NetApiBufferFree
netapi32.dll.NetUserEnum
psapi.dll.GetModuleFileNameExA
psapi.dll.EnumProcessModules
psapi.dll.GetProcessImageFileNameA
shell32.dll.SHGetFileInfoA
shell32.dll.SHGetSpecialFolderPathA
shell32.dll.ShellExecuteA
shlwapi.dll.PathGetArgsA
shlwapi.dll.PathRemoveArgsA
shlwapi.dll.PathUnquoteSpacesA
shlwapi.dll.PathIsDirectoryA
user32.dll.OpenDesktopA
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationA
user32.dll.GetCursorInfo
user32.dll.mouse_event
user32.dll.SetCapture
user32.dll.keybd_event
user32.dll.BlockInput
user32.dll.SetDlgItemTextA
user32.dll.GetDlgItemTextA
user32.dll.CreateDialogParamA
user32.dll.SwapMouseButton
user32.dll.wsprintfA
user32.dll.GetInputState
userenv.dll.CreateEnvironmentBlock
userenv.dll.GetProfilesDirectoryA
version.dll.GetFileVersionInfoA
version.dll.GetFileVersionInfoSizeA
version.dll.VerQueryValueA
winmm.dll.mixerOpen
winmm.dll.mixerGetDevCapsA
winmm.dll.mixerGetNumDevs
winmm.dll.waveInGetDevCapsA
winmm.dll.mixerSetControlDetails
winmm.dll.mixerGetLineInfoA
winmm.dll.waveOutOpen
winmm.dll.waveOutClose
winmm.dll.waveOutWrite
winmm.dll.waveOutPrepareHeader
winmm.dll.mixerGetLineControlsA
winmm.dll.mixerGetControlDetailsA
winmm.dll.mixerClose
winmm.dll.PlaySoundA
winmm.dll.waveInReset
winmm.dll.waveInOpen
winmm.dll.waveInClose
winmm.dll.waveInAddBuffer
winmm.dll.waveInPrepareHeader
winmm.dll.waveInUnprepareHeader
winmm.dll.waveOutUnprepareHeader
winmm.dll.mciSendStringA
winmm.dll.waveInGetNumDevs
winmm.dll.waveInStart
ws2_32.dll.#6
ws2_32.dll.#15
ws2_32.dll.WSASocketA
ws2_32.dll.WSAIoctl
ws2_32.dll.#57
ws2_32.dll.#18
ws2_32.dll.#12
wtsapi32.dll.WTSQueryUserToken
wtsapi32.dll.WTSFreeMemory
wtsapi32.dll.WTSEnumerateSessionsA
wtsapi32.dll.WTSQuerySessionInformationA
wintrust.dll.WinVerifyTrust
msdmo.dll.DMOEnum
msdmo.dll.DMOGetTypes
msdmo.dll.DMOGetName
avicap32.dll.capGetDriverDescriptionW
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
comctl32.dll.#332
comctl32.dll.#386
C:\Users\test\AppData\Local\Temp\QQbrowserQQbrowserQQbrowser.bat
Local\__DDrawExclMode__
Local\__DDrawCheckExclMode__

PE 信息

初始地址 0x00400000
入口地址 0x0049607d
声明校验值 0x00000000
实际校验值 0x00aa3be1
最低操作系统版本要求 4.0
编译时间 2020-09-25 19:25:26
载入哈希 c562e5c0b310365e3e08b0ac583da40f

版本信息

LegalCopyright
FileVersion
CompanyName
Comments
ProductName
ProductVersion
FileDescription
Translation

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x000b5b6a 0x000b6000 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.55
.rdata 0x000b7000 0x009c3012 0x009c4000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7.91
.data 0x00a7b000 0x00049fa8 0x00018000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5.01
.rsrc 0x00ac5000 0x000054f8 0x00006000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.05

导入

库: KERNEL32.dll:
0x4b7170 GetLocalTime
0x4b7174 GetSystemTime
0x4b717c RtlUnwind
0x4b7180 GetStartupInfoA
0x4b7184 GetOEMCP
0x4b7188 GetCPInfo
0x4b718c GetProcessVersion
0x4b7190 SetErrorMode
0x4b7194 GlobalFlags
0x4b7198 GetCurrentThread
0x4b719c GetFileTime
0x4b71a0 RaiseException
0x4b71a4 TlsGetValue
0x4b71a8 LocalReAlloc
0x4b71ac TlsSetValue
0x4b71b0 TlsFree
0x4b71b4 GlobalHandle
0x4b71b8 TlsAlloc
0x4b71bc LocalAlloc
0x4b71c0 lstrcmpA
0x4b71c4 GetVersion
0x4b71c8 GlobalGetAtomNameA
0x4b71cc GlobalAddAtomA
0x4b71d0 GlobalFindAtomA
0x4b71d4 GlobalDeleteAtom
0x4b71d8 lstrcmpiA
0x4b71dc SetEndOfFile
0x4b71e0 UnlockFile
0x4b71e4 LockFile
0x4b71e8 FlushFileBuffers
0x4b71ec SetFilePointer
0x4b71f0 GetCurrentProcess
0x4b71f4 DuplicateHandle
0x4b71f8 lstrcpynA
0x4b71fc SetLastError
0x4b7208 LocalFree
0x4b7214 TerminateProcess
0x4b7218 HeapSize
0x4b721c GetACP
0x4b7234 SetHandleCount
0x4b7238 GetStdHandle
0x4b723c GetFileType
0x4b7244 HeapDestroy
0x4b7248 HeapCreate
0x4b724c VirtualFree
0x4b7254 LCMapStringA
0x4b7258 LCMapStringW
0x4b725c VirtualAlloc
0x4b7260 IsBadWritePtr
0x4b7264 GetStringTypeA
0x4b7268 GetStringTypeW
0x4b7270 CompareStringA
0x4b7274 CompareStringW
0x4b7278 IsBadReadPtr
0x4b727c IsBadCodePtr
0x4b7280 SetStdHandle
0x4b7284 SuspendThread
0x4b7288 ReleaseMutex
0x4b728c CreateMutexA
0x4b7290 TerminateThread
0x4b7294 CreateSemaphoreA
0x4b7298 ResumeThread
0x4b729c ReleaseSemaphore
0x4b72a8 GetProfileStringA
0x4b72ac WriteFile
0x4b72b4 CreateFileA
0x4b72b8 SetEvent
0x4b72bc FindResourceA
0x4b72c0 LoadResource
0x4b72c4 LockResource
0x4b72c8 ReadFile
0x4b72cc lstrlenW
0x4b72d0 GetModuleFileNameA
0x4b72d4 WideCharToMultiByte
0x4b72d8 MultiByteToWideChar
0x4b72dc GetCurrentThreadId
0x4b72e0 ExitProcess
0x4b72e4 GlobalSize
0x4b72e8 GlobalFree
0x4b72f4 lstrcatA
0x4b72f8 lstrlenA
0x4b72fc CloseHandle
0x4b7300 WinExec
0x4b7304 lstrcpyA
0x4b7308 FindNextFileA
0x4b730c GlobalReAlloc
0x4b7310 HeapFree
0x4b7314 HeapReAlloc
0x4b7318 GetProcessHeap
0x4b731c HeapAlloc
0x4b7320 GetUserDefaultLCID
0x4b7324 GetFullPathNameA
0x4b7328 FreeLibrary
0x4b732c LoadLibraryA
0x4b7330 GetLastError
0x4b7334 GetVersionExA
0x4b733c CreateThread
0x4b7340 CreateEventA
0x4b7344 Sleep
0x4b7348 GlobalAlloc
0x4b734c GlobalLock
0x4b7350 GlobalUnlock
0x4b7354 FindFirstFileA
0x4b7358 FindClose
0x4b735c SetFileAttributesA
0x4b7360 GetFileAttributesA
0x4b7364 DeleteFileA
0x4b7370 GetModuleHandleA
0x4b7374 GetProcAddress
0x4b7378 MulDiv
0x4b737c GetCommandLineA
0x4b7380 GetTickCount
0x4b7384 CreateProcessA
0x4b7388 WaitForSingleObject
0x4b738c GetFileSize
库: USER32.dll:
0x4b73c8 LoadIconA
0x4b73cc TranslateMessage
0x4b73d0 DrawFrameControl
0x4b73d4 DrawEdge
0x4b73d8 DrawFocusRect
0x4b73dc WindowFromPoint
0x4b73e0 GetMessageA
0x4b73e4 DispatchMessageA
0x4b73e8 SetRectEmpty
0x4b73f8 DrawIconEx
0x4b73fc CreatePopupMenu
0x4b7400 AppendMenuA
0x4b7404 ModifyMenuA
0x4b7408 CreateMenu
0x4b7410 GetDlgCtrlID
0x4b7414 GetSubMenu
0x4b7418 EnableMenuItem
0x4b741c ClientToScreen
0x4b7424 LoadImageA
0x4b742c ShowWindow
0x4b7430 IsWindowEnabled
0x4b7438 GetKeyState
0x4b7440 PostQuitMessage
0x4b7444 IsZoomed
0x4b7448 GetClassInfoA
0x4b744c DefWindowProcA
0x4b7450 GetSystemMenu
0x4b7454 DeleteMenu
0x4b7458 GetMenu
0x4b745c SetMenu
0x4b7460 PeekMessageA
0x4b7464 IsIconic
0x4b7468 SetFocus
0x4b746c GetActiveWindow
0x4b7470 GetWindow
0x4b7478 SetWindowRgn
0x4b747c GetMessagePos
0x4b7480 ScreenToClient
0x4b7488 CopyRect
0x4b748c LoadBitmapA
0x4b7490 WinHelpA
0x4b7494 KillTimer
0x4b7498 SetTimer
0x4b749c ReleaseCapture
0x4b74a0 GetCapture
0x4b74a4 SetCapture
0x4b74a8 GetScrollRange
0x4b74ac SetScrollRange
0x4b74b0 SetScrollPos
0x4b74b4 SetRect
0x4b74b8 InflateRect
0x4b74bc IntersectRect
0x4b74c0 DestroyIcon
0x4b74c4 PtInRect
0x4b74c8 OffsetRect
0x4b74cc IsWindowVisible
0x4b74d0 EnableWindow
0x4b74d4 UnregisterClassA
0x4b74d8 GetWindowLongA
0x4b74dc SetWindowLongA
0x4b74e0 GetSysColor
0x4b74e4 SetActiveWindow
0x4b74e8 SetCursorPos
0x4b74ec LoadCursorA
0x4b74f0 SetCursor
0x4b74f4 GetDC
0x4b74f8 FillRect
0x4b74fc IsRectEmpty
0x4b7500 ReleaseDC
0x4b7504 IsChild
0x4b7508 DestroyMenu
0x4b750c SetForegroundWindow
0x4b7510 GetWindowRect
0x4b7514 EqualRect
0x4b7518 UpdateWindow
0x4b751c ValidateRect
0x4b7520 InvalidateRect
0x4b7524 GetClientRect
0x4b7528 GetFocus
0x4b752c GetParent
0x4b7530 GetTopWindow
0x4b7534 PostMessageA
0x4b7538 IsWindow
0x4b753c SetParent
0x4b7540 DestroyCursor
0x4b7544 SendMessageA
0x4b7548 SetWindowPos
0x4b754c GetWindowTextA
0x4b7554 CharUpperA
0x4b7558 GetWindowDC
0x4b755c BeginPaint
0x4b7560 EndPaint
0x4b7564 TabbedTextOutA
0x4b7568 DrawTextA
0x4b756c GrayStringA
0x4b7570 GetDlgItem
0x4b7574 DestroyWindow
0x4b757c EndDialog
0x4b7580 GetNextDlgTabItem
0x4b7584 GetWindowPlacement
0x4b758c GetForegroundWindow
0x4b7590 GetLastActivePopup
0x4b7594 GetMessageTime
0x4b7598 RemovePropA
0x4b759c CallWindowProcA
0x4b75a0 GetPropA
0x4b75a4 UnhookWindowsHookEx
0x4b75a8 SetPropA
0x4b75ac GetClassLongA
0x4b75b0 CallNextHookEx
0x4b75b4 SetWindowsHookExA
0x4b75b8 CreateWindowExA
0x4b75bc GetMenuItemID
0x4b75c0 GetMenuItemCount
0x4b75c4 RegisterClassA
0x4b75c8 GetScrollPos
0x4b75cc AdjustWindowRectEx
0x4b75d0 MapWindowPoints
0x4b75d4 SendDlgItemMessageA
0x4b75d8 ScrollWindowEx
0x4b75dc IsDialogMessageA
0x4b75e0 SetWindowTextA
0x4b75e4 MoveWindow
0x4b75e8 CheckMenuItem
0x4b75ec SetMenuItemBitmaps
0x4b75f0 GetMenuState
0x4b75f8 GetClassNameA
0x4b75fc GetDesktopWindow
0x4b7600 LoadStringA
0x4b7604 GetSysColorBrush
0x4b7608 MessageBoxA
0x4b760c GetCursorPos
0x4b7610 GetSystemMetrics
0x4b7614 EmptyClipboard
0x4b7618 SetClipboardData
0x4b761c OpenClipboard
0x4b7620 GetClipboardData
0x4b7624 CloseClipboard
0x4b7628 wsprintfA
0x4b762c WaitForInputIdle
0x4b7630 RedrawWindow
库: GDI32.dll:
0x4b7024 GetTextMetricsA
0x4b7028 ExtTextOutA
0x4b702c TextOutA
0x4b7030 RectVisible
0x4b7034 PtVisible
0x4b7038 GetViewportExtEx
0x4b703c Escape
0x4b7040 ExtSelectClipRgn
0x4b7044 SetBkColor
0x4b704c SetStretchBltMode
0x4b7050 GetClipRgn
0x4b7054 CreatePolygonRgn
0x4b7058 SelectClipRgn
0x4b705c DeleteObject
0x4b7060 CreateDIBitmap
0x4b7068 CreatePalette
0x4b706c StretchBlt
0x4b7070 SelectPalette
0x4b7074 RealizePalette
0x4b7078 GetDIBits
0x4b707c GetWindowExtEx
0x4b7080 GetViewportOrgEx
0x4b7084 GetWindowOrgEx
0x4b7088 BeginPath
0x4b708c EndPath
0x4b7090 PathToRegion
0x4b7094 CreateEllipticRgn
0x4b7098 CreateRoundRectRgn
0x4b709c GetTextColor
0x4b70a0 GetBkMode
0x4b70a4 GetBkColor
0x4b70a8 GetROP2
0x4b70ac GetStretchBltMode
0x4b70b0 GetPolyFillMode
0x4b70b8 CreateDCA
0x4b70bc CreateBitmap
0x4b70c0 SelectObject
0x4b70c4 CreatePen
0x4b70c8 PatBlt
0x4b70cc ScaleViewportExtEx
0x4b70d0 SetViewportExtEx
0x4b70d4 OffsetViewportOrgEx
0x4b70d8 SetViewportOrgEx
0x4b70dc SetMapMode
0x4b70e0 SetTextColor
0x4b70e4 SetROP2
0x4b70e8 SetPolyFillMode
0x4b70ec SetBkMode
0x4b70f0 RestoreDC
0x4b70f4 SaveDC
0x4b70f8 CombineRgn
0x4b70fc CreateRectRgn
0x4b7100 FillRgn
0x4b7104 CreateSolidBrush
0x4b7108 CreateFontIndirectA
0x4b710c GetStockObject
0x4b7110 GetObjectA
0x4b7114 EndPage
0x4b7118 EndDoc
0x4b711c DeleteDC
0x4b7120 StartDocA
0x4b7124 StartPage
0x4b7128 BitBlt
0x4b712c CreateCompatibleDC
0x4b7130 Ellipse
0x4b7134 Rectangle
0x4b7138 LPtoDP
0x4b713c DPtoLP
0x4b7140 GetCurrentObject
0x4b7144 RoundRect
0x4b714c GetDeviceCaps
0x4b7150 LineTo
0x4b7154 MoveToEx
0x4b7158 ExcludeClipRect
0x4b715c GetClipBox
0x4b7160 ScaleWindowExtEx
0x4b7164 SetWindowExtEx
0x4b7168 SetWindowOrgEx
库: WINMM.dll:
0x4b7640 waveOutWrite
0x4b7644 waveOutPause
0x4b7648 waveOutReset
0x4b764c waveOutClose
0x4b7650 waveOutGetNumDevs
0x4b7654 waveOutOpen
0x4b765c midiStreamOpen
0x4b7660 midiStreamProperty
0x4b7668 midiStreamOut
0x4b766c waveOutRestart
0x4b7670 midiStreamStop
0x4b7674 midiOutReset
0x4b7678 midiStreamClose
0x4b767c midiStreamRestart
库: WINSPOOL.DRV:
0x4b7684 OpenPrinterA
0x4b7688 DocumentPropertiesA
0x4b768c ClosePrinter
库: ADVAPI32.dll:
0x4b7000 RegCloseKey
0x4b7004 RegOpenKeyExA
0x4b7008 RegSetValueExA
0x4b700c RegQueryValueA
0x4b7010 RegCreateKeyExA
库: SHELL32.dll:
0x4b73bc ShellExecuteA
0x4b73c0 Shell_NotifyIconA
库: ole32.dll:
0x4b76d4 CLSIDFromProgID
0x4b76d8 OleRun
0x4b76dc CoCreateInstance
0x4b76e0 CLSIDFromString
0x4b76e4 OleUninitialize
0x4b76e8 OleInitialize
库: OLEAUT32.dll:
0x4b7394 VariantCopyInd
0x4b7398 VariantInit
0x4b739c SysAllocString
0x4b73a0 RegisterTypeLib
0x4b73a4 LHashValOfNameSys
0x4b73a8 LoadTypeLib
0x4b73ac UnRegisterTypeLib
0x4b73b0 VariantChangeType
0x4b73b4 VariantClear
库: COMCTL32.dll:
0x4b7018 ImageList_Destroy
0x4b701c None
库: WS2_32.dll:
0x4b7694 inet_ntoa
0x4b7698 WSACleanup
0x4b769c ntohl
0x4b76a0 accept
0x4b76a4 getpeername
0x4b76a8 recv
0x4b76ac ioctlsocket
0x4b76b0 recvfrom
0x4b76b4 closesocket
0x4b76b8 WSAAsyncSelect
库: comdlg32.dll:
0x4b76c0 ChooseColorA
0x4b76c4 GetOpenFileNameA
0x4b76c8 GetSaveFileNameA
0x4b76cc GetFileTitleA

.text
`.rdata
@.data
.rsrc
8`}<j
T$hVj
DRQPj
T$|Vj
T$th
|$TVj
jjjjh
没有防病毒引擎扫描信息!

进程树


____________.exe, PID: 2504, 上一级进程 PID: 2224
QQbrowserQQbrowserQQbrowser.bat, PID: 2568, 上一级进程 PID: 2504

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49162 103.45.183.154 9090
192.168.122.201 49165 103.45.183.154 9090
192.168.122.201 49168 103.45.183.154 9090
192.168.122.201 49163 221.229.162.40 29.o533.net 8088
192.168.122.201 49158 23.35.98.32 acroipm.adobe.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 61084 192.168.122.1 53
192.168.122.201 63282 192.168.122.1 53

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
acroipm.adobe.com CNAME acroipm.adobe.com.edgesuite.net
CNAME a1983.dscd.akamai.net.0.1.cn.akamaitech.net
CNAME a1983.dscd.akamai.net
A 23.35.98.32
A 23.35.98.25
29.o533.net A 221.229.162.40

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49162 103.45.183.154 9090
192.168.122.201 49165 103.45.183.154 9090
192.168.122.201 49168 103.45.183.154 9090
192.168.122.201 49163 221.229.162.40 29.o533.net 8088
192.168.122.201 49158 23.35.98.32 acroipm.adobe.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 61084 192.168.122.1 53
192.168.122.201 63282 192.168.122.1 53

HTTP 请求

URI HTTP数据
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache

URL专业沙箱检测 -> http://29.o533.net:8088/m.asp?code=fgBIBBgGDBOBBBBBKNSb9HKelOzhkyrU0vks4OGIsgRHt6m8DPC4gLym6Am7lV6knNlFVOG8ngFhsTBHmvlwJeLiqca5b0RbhkeNSKoWIvPo9nYZ91A%%2bUEXG%%2bTE5yAP2HU2rDqCXWxQjkqgeR03/i3QbyW4u6CrYHoWRextvJD14VbKmJxfz2cH0edNrRLTgxzT7t2j1ZPHWEnaPSApjYqx0ZVJPHXy%%2b5pTK9tO90o4PfOAdJnmZwFHIUX%%2bMu/HEmVW%%2bnjXo8MTRzILW--23143
GET /m.asp?code=fgBIBBgGDBOBBBBBKNSb9HKelOzhkyrU0vks4OGIsgRHt6m8DPC4gLym6Am7lV6knNlFVOG8ngFhsTBHmvlwJeLiqca5b0RbhkeNSKoWIvPo9nYZ91A%%2bUEXG%%2bTE5yAP2HU2rDqCXWxQjkqgeR03/i3QbyW4u6CrYHoWRextvJD14VbKmJxfz2cH0edNrRLTgxzT7t2j1ZPHWEnaPSApjYqx0ZVJPHXy%%2b5pTK9tO90o4PfOAdJnmZwFHIUX%%2bMu/HEmVW%%2bnjXo8MTRzILW--23143 HTTP/1.0
Host: 29.o533.net

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

源地址 目标地址 ICMP类型 数据
192.168.1.1 192.168.122.201 3
192.168.1.1 192.168.122.201 3

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 61.246 seconds )

  • 29.286 Static
  • 16.048 Suricata
  • 7.06 BehaviorAnalysis
  • 2.996 TargetInfo
  • 2.75 VirusTotal
  • 2.494 NetworkAnalysis
  • 0.447 peid
  • 0.111 AnalysisInfo
  • 0.035 config_decoder
  • 0.016 Strings
  • 0.003 Memory

Signatures ( 44.135 seconds )

  • 39.116 network_http
  • 1.916 md_url_bl
  • 0.321 api_spamming
  • 0.305 maldun_anomaly_massive_file_ops
  • 0.257 stealth_timeout
  • 0.217 stealth_decoy_document
  • 0.129 stealth_file
  • 0.126 virus
  • 0.124 reads_self
  • 0.123 antivm_generic_disk
  • 0.109 mimics_filetime
  • 0.108 bootkit
  • 0.103 rat_luminosity
  • 0.093 maldun_malicious_write_executeable_under_temp_to_regrun
  • 0.087 maldun_anomaly_write_exe_and_dll_under_winroot_run
  • 0.083 maldun_anomaly_write_exe_and_obsfucate_extension
  • 0.082 ransomware_extensions
  • 0.056 antiav_detectfile
  • 0.056 antiav_detectreg
  • 0.051 kovter_behavior
  • 0.045 antiemu_wine_func
  • 0.043 infostealer_browser_password
  • 0.043 infostealer_bitcoin
  • 0.037 infostealer_ftp
  • 0.03 hawkeye_behavior
  • 0.028 dridex_behavior
  • 0.028 ransomware_files
  • 0.026 md_domain_bl
  • 0.022 infostealer_im
  • 0.021 antivm_vbox_files
  • 0.017 antisandbox_sleep
  • 0.016 kazybot_behavior
  • 0.015 stealth_network
  • 0.014 infostealer_mail
  • 0.013 antivm_vbox_libs
  • 0.013 shifu_behavior
  • 0.012 anomaly_persistence_autorun
  • 0.012 antidbg_windows
  • 0.012 antianalysis_detectreg
  • 0.012 antidbg_devices
  • 0.011 dead_connect
  • 0.008 tinba_behavior
  • 0.008 betabot_behavior
  • 0.008 geodo_banking_trojan
  • 0.007 network_tor
  • 0.007 exec_crash
  • 0.006 antisandbox_sunbelt_libs
  • 0.006 ispy_behavior
  • 0.006 network_torgateway
  • 0.005 rat_nanocore
  • 0.005 antiav_avast_libs
  • 0.005 kibex_behavior
  • 0.005 hancitor_behavior
  • 0.005 antianalysis_detectfile
  • 0.005 maldun_malicious_drop_executable_file_to_temp_folder
  • 0.005 rat_pcclient
  • 0.004 antisandbox_sboxie_libs
  • 0.004 antiav_bitdefender_libs
  • 0.003 andromeda_behavior
  • 0.003 antivm_vmware_libs
  • 0.003 injection_createremotethread
  • 0.003 vawtrak_behavior
  • 0.003 cerber_behavior
  • 0.003 sniffer_winpcap
  • 0.003 antivm_parallels_keys
  • 0.003 antivm_vmware_files
  • 0.003 antivm_xen_keys
  • 0.003 disables_browser_warn
  • 0.003 codelux_behavior
  • 0.003 network_tor_service
  • 0.002 antivm_generic_services
  • 0.002 antivm_vbox_window
  • 0.002 antivm_generic_scsi
  • 0.002 antivm_vmware_events
  • 0.002 anormaly_invoke_kills
  • 0.002 injection_runpe
  • 0.002 antisandbox_fortinet_files
  • 0.002 antisandbox_threattrack_files
  • 0.002 antivm_generic_diskreg
  • 0.002 browser_security
  • 0.002 modify_proxy
  • 0.002 darkcomet_regkeys
  • 0.002 malicous_targeted_flame
  • 0.002 md_bad_drop
  • 0.002 network_cnc_http
  • 0.002 recon_fingerprint
  • 0.001 infostealer_browser
  • 0.001 Locky_behavior
  • 0.001 ursnif_behavior
  • 0.001 antisandbox_script_timer
  • 0.001 cryptowall_behavior
  • 0.001 bypass_firewall
  • 0.001 spreading_autoruninf
  • 0.001 modifies_hostfile
  • 0.001 antisandbox_cuckoo_files
  • 0.001 antisandbox_productid
  • 0.001 antisandbox_joe_anubis_files
  • 0.001 antisandbox_sunbelt_files
  • 0.001 antivm_generic_system
  • 0.001 antivm_xen_keys
  • 0.001 antivm_hyperv_keys
  • 0.001 antivm_vbox_acpi
  • 0.001 antivm_vbox_devices
  • 0.001 antivm_vbox_keys
  • 0.001 antivm_vmware_keys
  • 0.001 antivm_vpc_files
  • 0.001 antivm_vpc_keys
  • 0.001 banker_cridex
  • 0.001 banker_zeus_mutex
  • 0.001 bitcoin_opencl
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_addon
  • 0.001 disables_system_restore
  • 0.001 disables_windows_defender
  • 0.001 maldun_anomaly_invoke_vb_vba
  • 0.001 maldun_network_blacklist
  • 0.001 office_security
  • 0.001 packer_armadillo_regkey
  • 0.001 ransomware_radamant
  • 0.001 rat_spynet
  • 0.001 stealth_modify_uac_prompt

Reporting ( 1.74 seconds )

  • 1.12 ReportHTMLSummary
  • 0.62 Malheur
Task ID 577684
Mongo ID 5f6dd5af2f8f2e0ab852d05a
Cuckoo release 1.4-Maldun