分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-shaapp03-1 2020-09-25 20:51:37 2020-09-25 20:53:43 126 秒

魔盾分数

10.0

危险的

文件详细信息

文件名 XP.exe
文件大小 203264 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 9d6754d2d1357d31024affaf81e1eea3
SHA1 f52ad00f106f0d73ce9d0e044d26ec5a163648dd
SHA256 699cbd27ee8aab789823ee073c1d231075c7465f45af7f0c1be5a9905a8b137d
SHA512 3261b5c526eabe537f1b4bb66911870636ae60c7ac498f9e68ea5c28c8441c5f970a75795dd3e8e2914a1b7485b2c0a7171f39afb35db5e0624fabb126949fd2
CRC32 D73F72E7
Ssdeep 6144:ybZWaqUZQtQne3l1D0+TMDWNnzyDVqUrb:cEa1e33HNgq
Yara
  • Detected UPX. Commonly used by RAT!
样本下载 提交误报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
acroipm.adobe.com A 23.198.99.176
CNAME acroipm.adobe.com.edgesuite.net
CNAME a1983.dscd.akamai.net
A 23.198.99.183

摘要

C:\Users\test\AppData\Local\Temp
C:\Program Files (x86)
C:\Users\test\AppData\Local\Temp\XP.exe
C:\Program Files (x86)\Systds.pif
C:\Windows\System32\22878157.bak
C:\Windows\Temp
C:\Windows\LastGood.Tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
C:\Windows\ServiceProfiles
C:\Windows\ServiceProfiles\LocalService
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp
C:\Windows\ServiceProfiles\NetworkService
B:
C:\
D:
E:
F:
G:
H:
I:
J:
K:
L:
M:
N:
O:
P:
Q:
R:
S:
T:
U:
V:
W:
X:
Y:
Z:
[:
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\IA32.api
C:\Windows\System32\spool\drivers\color\D65.camp
C:\Windows\System32\spool\drivers\color\Photo.gmmp
C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\Updater.api
C:\Users\test\AppData\Local\Adobe
C:\Users\test\AppData\Local\Adobe\Acrobat
C:\Users\test\AppData\Local\Adobe\Acrobat\11.0
C:\Users\test\AppData\Local\Adobe\Acrobat\11.0\Cache
C:\Users\test\AppData\Local\Adobe\Acrobat\11.0\Cache\RdLang_Updater.CHS
C:\program files (x86)\Adobe\reader 11.0\Reader\Locale\zh_CN\updater.CHS
C:\Users\test\AppData\Local\Temp\A9RF1FC.tmp
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages-journal
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages-wal
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ndpsetup.bat
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ndpsetup.bat
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat
C:\Users\test\AppData\Local\Temp\XP.exe
C:\Windows\System32\22878157.bak
C:\Windows\LastGood.Tmp
C:\Program Files (x86)\Systds.pif
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\IA32.api
C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\Updater.api
C:\Users\test\AppData\Local\Adobe\Acrobat\11.0\Cache\RdLang_Updater.CHS
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages-journal
C:\Program Files (x86)\Systds.pif
C:\Windows\System32\22878157.bak
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages-journal
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat
C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat
C:\Windows\LastGood.Tmp
C:\Users\test\AppData\Local\Temp\A9RF1FC.tmp
C:\Users\test\AppData\LocalLow\Adobe\Acrobat\11.0\ReaderMessages-journal
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rspkbm zpifhsbt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\InstallTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Environment
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\NoInteractiveServices
HKEY_LOCAL_MACHINE\system
HKEY_LOCAL_MACHINE\SYSTEM\select
HKEY_LOCAL_MACHINE\SYSTEM\Select\Current
HKEY_LOCAL_MACHINE\SYSTEM\Select\Default
HKEY_LOCAL_MACHINE\SYSTEM\Select\LastKnownGood
HKEY_LOCAL_MACHINE\SYSTEM\Select\Failed
HKEY_LOCAL_MACHINE\System\LastKnownGoodRecovery\LastGood.Tmp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Tracing\SCM\Regular
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\SCM\Regular\TracingDisabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\Order\ProviderOrder
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\NetworkProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder\ProviderOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
HKEY_USERS\S-1-5-19
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-19\Environment
HKEY_USERS\S-1-5-19\Volatile Environment
HKEY_USERS\S-1-5-19\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
HKEY_USERS\S-1-5-20
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-20\Environment
HKEY_USERS\S-1-5-20\Volatile Environment
HKEY_USERS\S-1-5-20\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Remark
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum\{860BB310-5D01-11D0-BD3B-00A0C911CE86}
HKEY_CLASSES_ROOT\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{860BB310-5D01-11D0-BD3B-00A0C911CE86}\Instance
HKEY_CLASSES_ROOT\DirectShow\MediaObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\DirectShow\MediaObjects\Categories\860bb310-5d01-11d0-bd3b-00a0c911ce86
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClusSvc
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\ri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ProfileEnumMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ICMProfile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\sRGB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\camp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\rip
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\AVPrivate
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\Updater
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\11.0\Updater
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe ARM\1.0\ARM\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe\Adobe ARM\1.0\ARM\iCheckReader
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\11.0\ARMUser
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\11.0\ARMUser
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\11.0\Installer
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\11.0\Installer\bUpdateModeSet
HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenServiceDebugLog
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\Install
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\ZapSet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NetFramework\v2.0.50727\NGenService\Roots
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NetFramework\v2.0.50727\NGENService\State
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueue\WIN32\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueueMSI\WIN32\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenServiceDebugLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client\Install
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\ZapSet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueue\WIN64\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueueMSI\WIN64\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\NoInteractiveServices
HKEY_LOCAL_MACHINE\SYSTEM\Select\Current
HKEY_LOCAL_MACHINE\SYSTEM\Select\Default
HKEY_LOCAL_MACHINE\SYSTEM\Select\LastKnownGood
HKEY_LOCAL_MACHINE\SYSTEM\Select\Failed
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\SCM\Regular\TracingDisabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\Order\ProviderOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder\ProviderOrder
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Remark
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\InstallTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\ri
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ProfileEnumMode
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CLASS\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000\ICMProfile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\sRGB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\camp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles\rip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe\Adobe ARM\1.0\ARM\iCheckReader
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Adobe\Acrobat Reader\11.0\Installer\bUpdateModeSet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenServiceDebugLog
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\Install
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\ZapSet
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenServiceDebugLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NicPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\RegistryRoot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client\Install
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\ZapSet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\InstallTime
kernel32.dll.FormatMessageA
kernel32.dll.RtlUnwind
kernel32.dll.RaiseException
kernel32.dll.GetStartupInfoA
kernel32.dll.GetCommandLineA
kernel32.dll.ExitProcess
kernel32.dll.TerminateProcess
kernel32.dll.HeapReAlloc
kernel32.dll.HeapSize
kernel32.dll.GetACP
kernel32.dll.GetTimeZoneInformation
kernel32.dll.SetUnhandledExceptionFilter
kernel32.dll.UnhandledExceptionFilter
kernel32.dll.FreeEnvironmentStringsA
kernel32.dll.FreeEnvironmentStringsW
kernel32.dll.GetEnvironmentStrings
kernel32.dll.GetEnvironmentStringsW
kernel32.dll.GetStdHandle
kernel32.dll.GetFileType
kernel32.dll.GetEnvironmentVariableA
kernel32.dll.GetVersionExA
kernel32.dll.HeapDestroy
kernel32.dll.HeapCreate
kernel32.dll.IsBadWritePtr
kernel32.dll.LCMapStringA
kernel32.dll.LCMapStringW
kernel32.dll.GetStringTypeA
kernel32.dll.GetStringTypeW
kernel32.dll.IsBadReadPtr
kernel32.dll.IsBadCodePtr
kernel32.dll.SetStdHandle
kernel32.dll.CompareStringA
kernel32.dll.CompareStringW
kernel32.dll.SetEnvironmentVariableA
kernel32.dll.GetFileTime
kernel32.dll.GetFileSize
kernel32.dll.GetFileAttributesA
kernel32.dll.GetTickCount
kernel32.dll.FileTimeToLocalFileTime
kernel32.dll.FileTimeToSystemTime
kernel32.dll.GetFullPathNameA
kernel32.dll.GetVolumeInformationA
kernel32.dll.FindFirstFileA
kernel32.dll.FindClose
kernel32.dll.SetEndOfFile
kernel32.dll.UnlockFile
kernel32.dll.LockFile
kernel32.dll.FlushFileBuffers
kernel32.dll.SetFilePointer
kernel32.dll.WriteFile
kernel32.dll.ReadFile
kernel32.dll.CreateFileA
kernel32.dll.GetCurrentProcess
kernel32.dll.DuplicateHandle
kernel32.dll.SetErrorMode
kernel32.dll.GetOEMCP
kernel32.dll.GetCPInfo
kernel32.dll.GetThreadLocale
kernel32.dll.GetProcessVersion
kernel32.dll.GetLastError
kernel32.dll.WritePrivateProfileStringA
kernel32.dll.GlobalFlags
kernel32.dll.lstrcpynA
kernel32.dll.TlsGetValue
kernel32.dll.LocalReAlloc
kernel32.dll.TlsSetValue
kernel32.dll.EnterCriticalSection
kernel32.dll.GlobalReAlloc
kernel32.dll.LeaveCriticalSection
kernel32.dll.TlsFree
kernel32.dll.GlobalHandle
kernel32.dll.DeleteCriticalSection
kernel32.dll.TlsAlloc
kernel32.dll.InitializeCriticalSection
kernel32.dll.LocalFree
kernel32.dll.LocalAlloc
kernel32.dll.MulDiv
kernel32.dll.SetLastError
kernel32.dll.MultiByteToWideChar
kernel32.dll.WideCharToMultiByte
kernel32.dll.lstrlenA
kernel32.dll.InterlockedIncrement
kernel32.dll.GetVersion
kernel32.dll.lstrcatA
kernel32.dll.GlobalGetAtomNameA
kernel32.dll.GlobalAddAtomA
kernel32.dll.GlobalFindAtomA
kernel32.dll.lstrcpyA
kernel32.dll.GetModuleHandleA
kernel32.dll.GlobalUnlock
kernel32.dll.InterlockedDecrement
kernel32.dll.FindResourceA
kernel32.dll.LoadResource
kernel32.dll.LockResource
kernel32.dll.GlobalFree
kernel32.dll.CloseHandle
kernel32.dll.GetModuleFileNameA
kernel32.dll.GlobalLock
kernel32.dll.GlobalAlloc
kernel32.dll.GlobalDeleteAtom
kernel32.dll.lstrcmpA
kernel32.dll.lstrcmpiA
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
kernel32.dll.FreeLibrary
kernel32.dll.VirtualFree
kernel32.dll.HeapFree
kernel32.dll.VirtualAlloc
kernel32.dll.GetProcessHeap
kernel32.dll.HeapAlloc
kernel32.dll.LoadLibraryA
kernel32.dll.SetHandleCount
kernel32.dll.GetProcAddress
advapi32.dll.RegCloseKey
advapi32.dll.RegSetValueExA
advapi32.dll.RegOpenKeyExA
advapi32.dll.RegCreateKeyExA
comctl32.dll.#17
comdlg32.dll.GetFileTitleA
gdi32.dll.GetWindowExtEx
gdi32.dll.PtVisible
gdi32.dll.RectVisible
gdi32.dll.TextOutA
gdi32.dll.ExtTextOutA
gdi32.dll.Escape
gdi32.dll.GetTextColor
gdi32.dll.GetBkColor
gdi32.dll.DPtoLP
gdi32.dll.LPtoDP
gdi32.dll.GetViewportExtEx
gdi32.dll.GetMapMode
gdi32.dll.GetDeviceCaps
gdi32.dll.DeleteObject
gdi32.dll.CreateBitmap
gdi32.dll.ScaleWindowExtEx
gdi32.dll.SetWindowExtEx
gdi32.dll.ScaleViewportExtEx
gdi32.dll.SetViewportExtEx
gdi32.dll.OffsetViewportOrgEx
gdi32.dll.SetViewportOrgEx
gdi32.dll.SetMapMode
gdi32.dll.GetStockObject
gdi32.dll.SelectObject
gdi32.dll.RestoreDC
gdi32.dll.SaveDC
gdi32.dll.DeleteDC
gdi32.dll.GetObjectA
gdi32.dll.SetBkColor
gdi32.dll.SetTextColor
gdi32.dll.GetClipBox
ole32.dll.CoFreeUnusedLibraries
ole32.dll.OleInitialize
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CreateILockBytesOnHGlobal
ole32.dll.StgCreateDocfileOnILockBytes
ole32.dll.StgOpenStorageOnILockBytes
ole32.dll.CoGetClassObject
ole32.dll.CLSIDFromString
ole32.dll.CLSIDFromProgID
ole32.dll.CoRegisterMessageFilter
ole32.dll.CoRevokeClassObject
ole32.dll.OleIsCurrentClipboard
ole32.dll.OleFlushClipboard
ole32.dll.OleUninitialize
oleaut32.dll.#7
oleaut32.dll.#150
oleaut32.dll.#2
oleaut32.dll.#12
oleaut32.dll.#10
oleaut32.dll.#185
oleaut32.dll.#9
oleaut32.dll.#4
oleaut32.dll.#6
oledlg.dll.#8
olepro32.dll.#253
user32.dll.GetSysColorBrush
user32.dll.CharNextA
user32.dll.CopyAcceleratorTableA
user32.dll.SetRect
user32.dll.GetNextDlgGroupItem
user32.dll.MessageBeep
user32.dll.CharUpperA
user32.dll.RegisterClipboardFormatA
user32.dll.LoadCursorA
user32.dll.GrayStringA
user32.dll.DrawTextA
user32.dll.TabbedTextOutA
user32.dll.EndPaint
user32.dll.BeginPaint
user32.dll.GetWindowDC
user32.dll.ReleaseDC
user32.dll.GetDC
user32.dll.ClientToScreen
user32.dll.DestroyMenu
user32.dll.LoadStringA
user32.dll.ShowWindow
user32.dll.MoveWindow
user32.dll.SetWindowTextA
user32.dll.IsDialogMessageA
user32.dll.UpdateWindow
user32.dll.SendDlgItemMessageA
user32.dll.MapWindowPoints
user32.dll.GetSysColor
user32.dll.SetFocus
user32.dll.AdjustWindowRectEx
user32.dll.CopyRect
user32.dll.GetTopWindow
user32.dll.IsChild
user32.dll.GetCapture
user32.dll.WinHelpA
user32.dll.wsprintfA
user32.dll.GetClassInfoA
user32.dll.GetMenu
user32.dll.GetMenuItemCount
user32.dll.GetSubMenu
user32.dll.GetMenuItemID
user32.dll.GetWindowTextA
user32.dll.GetDlgCtrlID
user32.dll.CreateWindowExA
user32.dll.GetClassLongA
user32.dll.SetPropA
user32.dll.GetPropA
user32.dll.CallWindowProcA
user32.dll.RemovePropA
user32.dll.DefWindowProcA
user32.dll.GetMessageTime
user32.dll.GetMessagePos
user32.dll.GetForegroundWindow
user32.dll.SetForegroundWindow
user32.dll.SetWindowLongA
user32.dll.RegisterWindowMessageA
user32.dll.OffsetRect
user32.dll.SystemParametersInfoA
user32.dll.GetWindowPlacement
user32.dll.GetWindowRect
user32.dll.EndDialog
user32.dll.SetActiveWindow
user32.dll.IsWindow
user32.dll.CreateDialogIndirectParamA
user32.dll.DestroyWindow
user32.dll.GetDlgItem
user32.dll.UnhookWindowsHookEx
user32.dll.MapDialogRect
user32.dll.SetWindowPos
user32.dll.GetWindow
user32.dll.SetWindowContextHelpId
user32.dll.GetMenuCheckMarkDimensions
user32.dll.LoadBitmapA
user32.dll.GetMenuState
user32.dll.ModifyMenuA
user32.dll.SetMenuItemBitmaps
user32.dll.CheckMenuItem
user32.dll.EnableMenuItem
user32.dll.GetFocus
user32.dll.GetNextDlgTabItem
user32.dll.PtInRect
user32.dll.GetClassNameA
user32.dll.GetDesktopWindow
user32.dll.TranslateMessage
user32.dll.DispatchMessageA
user32.dll.GetActiveWindow
user32.dll.GetKeyState
user32.dll.CallNextHookEx
user32.dll.ValidateRect
user32.dll.IsWindowVisible
user32.dll.PeekMessageA
user32.dll.GetCursorPos
user32.dll.SetWindowsHookExA
user32.dll.GetParent
user32.dll.GetLastActivePopup
user32.dll.IsWindowEnabled
user32.dll.GetWindowLongA
user32.dll.MessageBoxA
user32.dll.SetCursor
user32.dll.PostQuitMessage
user32.dll.PostMessageA
user32.dll.EnableWindow
user32.dll.IsIconic
user32.dll.GetSystemMetrics
user32.dll.GetClientRect
user32.dll.DrawIcon
user32.dll.SendMessageA
user32.dll.LoadIconA
user32.dll.PostThreadMessageA
user32.dll.GetInputState
user32.dll.GetMessageA
user32.dll.RegisterClassA
user32.dll.UnregisterClassA
winspool.drv.ClosePrinter
winspool.drv.DocumentPropertiesA
winspool.drv.OpenPrinterA
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._adjust_fdiv
msvcrt.dll.malloc
msvcrt.dll._initterm
msvcrt.dll._onexit
msvcrt.dll.__dllonexit
msvcrt.dll.??1type_info@@UAE@XZ
msvcrt.dll.strchr
msvcrt.dll._beginthreadex
msvcrt.dll.??3@YAXPAX@Z
msvcrt.dll.realloc
msvcrt.dll.strcmp
msvcrt.dll._access
msvcrt.dll.strcat
msvcrt.dll.strrchr
msvcrt.dll.strncpy
msvcrt.dll._iob
msvcrt.dll.fprintf
msvcrt.dll.sprintf
msvcrt.dll.printf
msvcrt.dll.strcpy
msvcrt.dll.time
msvcrt.dll.srand
msvcrt.dll.rand
msvcrt.dll.atoi
msvcrt.dll._local_unwind2
msvcrt.dll._except_handler3
msvcrt.dll._strcmpi
msvcrt.dll._strupr
msvcrt.dll._CxxThrowException
msvcrt.dll.memcmp
msvcrt.dll.??2@YAPAXI@Z
msvcrt.dll.strstr
msvcrt.dll.memset
msvcrt.dll.strlen
msvcrt.dll.__CxxFrameHandler
msvcrt.dll._ftol
msvcrt.dll.ceil
msvcrt.dll.memcpy
msvcrt.dll.free
msvcrt.dll._stricmp
mfc42.dll.#6648
mfc42.dll.#2764
mfc42.dll.#4129
mfc42.dll.#926
mfc42.dll.#924
mfc42.dll.#922
mfc42.dll.#858
mfc42.dll.#6663
mfc42.dll.#860
mfc42.dll.#4278
mfc42.dll.#939
mfc42.dll.#6877
mfc42.dll.#537
mfc42.dll.#540
mfc42.dll.#2818
mfc42.dll.#2915
mfc42.dll.#535
mfc42.dll.#800
kernel32.dll.DisableThreadLibraryCalls
kernel32.dll.VirtualProtect
kernel32.dll.GetDriveTypeA
kernel32.dll.GetDiskFreeSpaceExA
kernel32.dll.DefineDosDeviceA
kernel32.dll.MoveFileExA
kernel32.dll.ExpandEnvironmentStringsA
kernel32.dll.CopyFileA
kernel32.dll.SetFileAttributesA
kernel32.dll.CreateDirectoryA
kernel32.dll.GetLocalTime
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Process32First
kernel32.dll.OpenProcess
kernel32.dll.Process32Next
kernel32.dll.GetCurrentProcessId
kernel32.dll.ExitThread
kernel32.dll.CreateThread
kernel32.dll.CancelIo
kernel32.dll.InterlockedExchange
kernel32.dll.SetEvent
kernel32.dll.Sleep
kernel32.dll.OutputDebugStringA
kernel32.dll.ResetEvent
kernel32.dll.CreateEventA
kernel32.dll.WaitForSingleObject
user32.dll.FindWindowA
advapi32.dll.OpenEventLogA
advapi32.dll.ClearEventLogA
advapi32.dll.CloseEventLog
advapi32.dll.ChangeServiceConfig2A
advapi32.dll.SetServiceStatus
advapi32.dll.RegisterServiceCtrlHandlerA
advapi32.dll.AdjustTokenPrivileges
advapi32.dll.LookupPrivilegeValueA
advapi32.dll.OpenProcessToken
advapi32.dll.StartServiceCtrlDispatcherA
shell32.dll.SHGetSpecialFolderPathA
shell32.dll.ShellExecuteA
shell32.dll.ShellExecuteExA
wininet.dll.InternetOpenUrlA
wininet.dll.InternetGetConnectedState
ws2_32.dll.#116
ws2_32.dll.#9
ws2_32.dll.#23
ws2_32.dll.#16
ws2_32.dll.#18
ws2_32.dll.#3
ws2_32.dll.#19
ws2_32.dll.#21
ws2_32.dll.#11
ws2_32.dll.#20
ws2_32.dll.#12
ws2_32.dll.WSASocketA
ws2_32.dll.#8
ws2_32.dll.#57
ws2_32.dll.#115
ws2_32.dll.WSAIoctl
ws2_32.dll.#111
ws2_32.dll.#52
ws2_32.dll.#4
shlwapi.dll.PathRemoveFileSpecA
kernel32.dll.CreateProcessA
kernel32.dll.CreateMutexA
kernel32.dll.ReleaseMutex
kernel32.dll.TerminateThread
kernel32.dll.GetExitCodeProcess
kernel32.dll.GetSystemInfo
kernel32.dll.GetSystemDirectoryA
kernel32.dll.MoveFileA
kernel32.dll.WTSGetActiveConsoleSessionId
user32.dll.ExitWindowsEx
user32.dll.EnumWindows
ws2_32.dll.WSAStartup
ws2_32.dll.WSACleanup
ws2_32.dll.socket
ws2_32.dll.gethostbyname
ws2_32.dll.htons
ws2_32.dll.connect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.closesocket
ws2_32.dll.setsockopt
ws2_32.dll.select
ws2_32.dll.getsockname
ws2_32.dll.gethostname
advapi32.dll.OpenSCManagerA
advapi32.dll.OpenServiceA
advapi32.dll.StartServiceA
advapi32.dll.CloseServiceHandle
advapi32.dll.QueryServiceStatus
advapi32.dll.ControlService
advapi32.dll.CreateServiceA
advapi32.dll.DeleteService
advapi32.dll.DuplicateTokenEx
advapi32.dll.SetTokenInformation
advapi32.dll.CreateProcessAsUserA
user32.dll.OpenInputDesktop
user32.dll.OpenDesktopA
user32.dll.CloseDesktop
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationA
user32.dll.SetThreadDesktop
advapi32.dll.RegDeleteKeyA
advapi32.dll.RegDeleteValueA
userenv.dll.CreateEnvironmentBlock
sechost.dll.ConvertSidToStringSidW
sspicli.dll.GetUserNameExW
advapi32.dll.RegQueryValueExA
advapi32.dll.RegEnumValueA
advapi32.dll.RegEnumKeyExA
rasapi32.dll.RasConnectionNotificationW
sechost.dll.NotifyServiceStatusChangeA
cryptbase.dll.SystemFunction036
ntdll.dll.RtlGetNtVersionNumbers
kernel32.dll.IsWow64Process
ole32.dll.CoInitialize
ole32.dll.CoUninitialize
ole32.dll.CoCreateInstance
oleaut32.dll.SysFreeString
wintrust.dll.WinVerifyTrust
msdmo.dll.DMOEnum
msdmo.dll.DMOGetTypes
msdmo.dll.DMOGetName
avicap32.dll.capGetDriverDescriptionW
mscms.dll.CloseColorProfile
mscms.dll.DeleteColorTransform
mscms.dll.TranslateBitmapBits
mscms.dll.TranslateColors
mscms.dll.CheckBitmapBits
mscms.dll.InstallColorProfileW
mscms.dll.UninstallColorProfileW
mscms.dll.EnumColorProfilesW
mscms.dll.GetStandardColorSpaceProfileW
mscms.dll.GetColorProfileHeader
mscms.dll.GetColorDirectoryW
mscms.dll.CreateProfileFromLogColorSpaceW
mscms.dll.CreateMultiProfileTransform
mscms.dll.InternalGetDeviceConfig
mscms.dll.WcsOpenColorProfileW
mscms.dll.WcsGetDefaultColorProfileSize
mscms.dll.WcsGetDefaultColorProfile
mscms.dll.WcsGetDefaultRenderingIntent
mscms.dll.WcsCreateIccProfile
mscms.dll.GetColorProfileFromHandle
mscms.dll.WcsGetUsePerUserProfiles
updater.api.PlugInMain
wininet.dll.InternetCloseHandle
advapi32.dll.StartServiceCtrlDispatcherW
advapi32.dll.RegisterServiceCtrlHandlerExW
C:\Program Files (x86)\Systds.pif
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\sppsvc.exe
C:\Program Files (x86)\Systds.pif Win7
103.42.29.55:9090:Rspkbm zpifhsbt
Rspkbm zpifhsbt
Rspkbm zpifhsbt

PE 信息

初始地址 0x00400000
入口地址 0x00488350
声明校验值 0x00000000
实际校验值 0x00037fa5
最低操作系统版本要求 4.0
编译时间 2018-04-10 22:00:35
载入哈希 b22c3df0049f8a255e1f7a57de0600db
图标
图标精确哈希值 766e132c6dae7e31968369ccc28f67ca
图标相似性哈希值 61ce2d42baa48670094bd80787dfc156

版本信息

LegalCopyright
InternalName
FileVersion
CompanyName
LegalTrademarks
ProductName
ProductVersion
FileDescription
OriginalFilename
Debugger
Translation

PEiD 规则

[u'UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser']

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
UPX0 0x00001000 0x0005a000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
UPX1 0x0005b000 0x0002e000 0x0002d600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7.93
.rsrc 0x00089000 0x00004000 0x00004000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4.02

资源

名称 偏移量 大小 语言 子语言 熵(Entropy) 文件类型
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0004de4c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0004de4c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0004de4c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_ICON 0x0006b088 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 7.71 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_MENU 0x0006e8a4 0x0000003c LANG_SPANISH SUBLANG_SPANISH_MODERN 5.67 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_DIALOG 0x00075204 0x000000e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 6.82 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_STRING 0x000844f8 0x00000042 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.74 data
RT_ACCELERATOR 0x0008453c 0x00000088 LANG_ENGLISH SUBLANG_ENGLISH_US 6.54 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_CURSOR 0x00084748 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.32 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_GROUP_ICON 0x00084a48 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US 6.36 data
RT_VERSION 0x0008c4d0 0x000005ac LANG_ENGLISH SUBLANG_ENGLISH_US 3.47 data
RT_MANIFEST 0x0008ca80 0x000001d6 LANG_ENGLISH SUBLANG_ENGLISH_US 5.05 XML 1.0 document, ASCII text

导入

库: KERNEL32.DLL:
0x48cd48 LoadLibraryA
0x48cd4c GetProcAddress
0x48cd50 ExitProcess
库: ADVAPI32.dll:
0x48cd58 RegCloseKey
库: COMCTL32.dll:
0x48cd60 None
库: comdlg32.dll:
0x48cd68 GetFileTitleA
库: GDI32.dll:
0x48cd70 Escape
库: ole32.dll:
0x48cd78 OleInitialize
库: OLEAUT32.dll:
0x48cd80 SysFreeString
库: oledlg.dll:
0x48cd88 None
库: OLEPRO32.DLL:
0x48cd90 None
库: USER32.dll:
0x48cd98 GetDC
库: WINSPOOL.DRV:
0x48cda0 ClosePrinter

.rsrc
+8@<(P
nE{'!@l=B
aDPLAY
5}\vKb\0
?H:mm:ss
k<f>f-
S/f24
i333&
FUjyA
^G/UN
yF_vC
Om:wi5
X&/W$
=x@wly
|p<|uv^
9YV*=!J@
没有防病毒引擎扫描信息!

进程树


XP.exe, PID: 2312, 上一级进程 PID: 2156
services.exe, PID: 432, 上一级进程 PID: 344
Systds.pif, PID: 2540, 上一级进程 PID: 432
Systds.pif, PID: 2628, 上一级进程 PID: 2540
AcroRd32.exe, PID: 816, 上一级进程 PID: 304
mscorsvw.exe, PID: 3048, 上一级进程 PID: 432
mscorsvw.exe, PID: 2288, 上一级进程 PID: 432

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49163 103.42.29.55 9090

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 59401 192.168.122.1 53

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
acroipm.adobe.com A 23.198.99.176
CNAME acroipm.adobe.com.edgesuite.net
CNAME a1983.dscd.akamai.net
A 23.198.99.183

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49163 103.42.29.55 9090

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 59401 192.168.122.1 53

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 15.217 seconds )

  • 10.551 Suricata
  • 1.622 BehaviorAnalysis
  • 1.051 VirusTotal
  • 0.744 NetworkAnalysis
  • 0.693 Static
  • 0.284 peid
  • 0.248 TargetInfo
  • 0.011 AnalysisInfo
  • 0.011 Strings
  • 0.002 Memory

Signatures ( 0.681 seconds )

  • 0.109 api_spamming
  • 0.089 stealth_decoy_document
  • 0.082 stealth_timeout
  • 0.04 antiav_detectreg
  • 0.022 kovter_behavior
  • 0.02 antiemu_wine_func
  • 0.019 infostealer_browser_password
  • 0.018 stealth_file
  • 0.015 injection_createremotethread
  • 0.015 process_interest
  • 0.015 antisandbox_sleep
  • 0.015 infostealer_ftp
  • 0.011 mimics_filetime
  • 0.011 reads_self
  • 0.01 injection_runpe
  • 0.01 md_url_bl
  • 0.009 shifu_behavior
  • 0.009 vawtrak_behavior
  • 0.009 infostealer_im
  • 0.009 md_domain_bl
  • 0.008 bootkit
  • 0.008 virus
  • 0.008 antianalysis_detectreg
  • 0.007 antivm_generic_disk
  • 0.007 antiav_detectfile
  • 0.006 antivm_vbox_libs
  • 0.006 process_needed
  • 0.006 hancitor_behavior
  • 0.005 anomaly_persistence_autorun
  • 0.005 infostealer_bitcoin
  • 0.005 infostealer_mail
  • 0.004 antivm_generic_scsi
  • 0.004 ransomware_extensions
  • 0.004 ransomware_files
  • 0.003 infostealer_browser
  • 0.003 exec_crash
  • 0.003 antivm_parallels_keys
  • 0.003 antivm_vbox_files
  • 0.003 geodo_banking_trojan
  • 0.002 tinba_behavior
  • 0.002 antiav_avast_libs
  • 0.002 antivm_vmware_libs
  • 0.002 antivm_generic_services
  • 0.002 betabot_behavior
  • 0.002 antisandbox_sunbelt_libs
  • 0.002 antisandbox_sboxie_libs
  • 0.002 kibex_behavior
  • 0.002 anormaly_invoke_kills
  • 0.002 antivm_xen_keys
  • 0.002 browser_security
  • 0.002 disables_browser_warn
  • 0.002 network_torgateway
  • 0.001 network_tor
  • 0.001 rat_nanocore
  • 0.001 sets_autoconfig_url
  • 0.001 ipc_namedpipe
  • 0.001 antiav_bitdefender_libs
  • 0.001 cerber_behavior
  • 0.001 antidbg_devices
  • 0.001 antisandbox_productid
  • 0.001 antivm_generic_diskreg
  • 0.001 antivm_xen_keys
  • 0.001 antivm_hyperv_keys
  • 0.001 antivm_vbox_acpi
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_addon
  • 0.001 modify_proxy
  • 0.001 darkcomet_regkeys
  • 0.001 maldun_malicious_drop_executable_file_to_temp_folder
  • 0.001 md_bad_drop
  • 0.001 recon_fingerprint

Reporting ( 0.721 seconds )

  • 0.616 ReportHTMLSummary
  • 0.105 Malheur
Task ID 577690
Mongo ID 5f6de8707e769a53cfc2228a
Cuckoo release 1.4-Maldun