魔盾安全分析报告

分析类型 开始时间 结束时间 持续时间 分析引擎版本
FILE 2022-09-24 20:18:11 2022-09-24 20:20:31 140 秒 1.4-Maldun
虚拟机机器名 标签 虚拟机管理 开机时间 关机时间
win7-sp1-x64-shaapp03-1 win7-sp1-x64-shaapp03-1 KVM 2022-09-24 20:18:12 2022-09-24 20:20:32
魔盾分数

10.0

恶意的

文件详细信息

文件名 sun java version 5.0.exe
文件大小 16433280 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows
CRC32 CE6CE4AB
MD5 a3c725416dda678a967032db070f0718
SHA1 67164f87b50a6e75cff9b941f18cd662317db436
SHA256 b60ee5985c7b0c72ff752dfbca2ada0debcb7ee88f72ce16b6cc78cc7e67b879
SHA512 be386dc8844995f19c359c29ba490446db418c9f6e037c78f0b39e2856e51a811f177198ea9276668b6513fc9566b8ff69e684d093f207bd28bbbd73e5171da4
Ssdeep 393216:uuMkqE5u+rkip/YWDYiSqCuPD4l6Qfg7QQdAr4rh:NMkPJrpYXiSpuPD4ledlt
PEiD 无匹配
Yara
  • CRC32_poly_Constant (Look for CRC32 [poly])
  • with_images (Detected the presence of an or several images)
  • with_urls (Detected the presence of an or several urls)
  • IsPE32 (Detected a 32bit PE sample)
  • IsWindowsGUI (Detected a Windows GUI sample)
  • IsPacked (Detected Entropy signature)
  • HasOverlay (Detected Overlay signature)
  • HasDigitalSignature (Detected Digital Signature)
  • HasRichSignature (Detected Rich Signature)
  • DebuggerTiming__PerformanceCounter ()
  • DebuggerTiming__Ticks (Detected timing ticks function)
  • disable_antivirus (Disable AntiVirus)
  • network_http (Detected communications function over HTTP)
  • screenshot (Detected take screenshot function)
  • create_process (Detection function for creating a new process)
  • persistence (Detected function for installing itself for autorun at Windows startup)
  • escalate_priv (Detected escalate priviledges function)
  • win_registry (Detected system registries modification function)
  • change_win_registry (Change registries to affect system)
  • win_token (Affect system token)
  • win_files_operation (Affect private profile)
  • win_private_profile (Detected private profile access function)
  • Maldun_Anomoly_Combined_Activities_7 (Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files)
VirusTotal VirusTotal查询失败

特征

样本的签名证书合法
创建RWX内存
通过进程尝试延迟分析任务
Process: msiexec.exe tried to sleep 120 seconds, actually delayed analysis time by 0 seconds
魔盾安全Yara检测结果 - 普通
Warning: Detected function for installing itself for autorun at Windows startup
Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
二进制文件可能包含加密或压缩数据
section: name: .rsrc, entropy: 7.24, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0000b000, virtual_size: 0x0000a2e0
可能是恶意的样本写入可疑的执行文件并混淆扩展名
Suspicious: c:\users\test\appdata\local\temp\msi3a41.tmp
Suspicious: c:\users\test\appdata\local\temp\msi3acf.tmp
Suspicious: c:\users\test\appdata\local\temp\msi3b5c.tmp
检查注册表中的CPU名信息,可能被用来实现反虚拟机
检测到样本尝试模糊或欺骗文件类型

运行截图

网络分析

TCP连接

IP地址 端口
23.223.199.151 80

UDP连接

IP地址 端口
192.168.122.1 53

HTTP请求

URL HTTP数据
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache

静态分析

PE 信息

初始地址 0x00400000
入口地址 0x004189fc
声明校验值 0x00fb1d5e
实际校验值 0x00fb1d5e
最低操作系统版本要求 4.0
编译时间 2004-02-05 00:43:10
载入哈希 73e98760f4aa967c6600848826ef44b1
图标
图标精确哈希值 fcbcfdcf647e677fa8cf852162062ab0
图标相似性哈希值 8724951dc1936ac7d8b2e508a33cb6bc

版本信息

LegalCopyright: Copyright (C) 2003 InstallShield Software Corp.
InternalName: setup.exe
FileVersion: 1.5.0.50
CompanyName: Sun Microsystems, Inc.
Comments:
ProductName: J2SE Runtime Environment 5.0 Update 5
ProductVersion: 1.5.0.50
FileDescription: Setup Launcher
OriginalFilename: setup.exe
Translation: 0x0409 0x04e4

PE数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x0002132e 0x00022000 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.49
.rdata 0x00023000 0x00003de8 0x00004000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.19
.data 0x00027000 0x00009218 0x00005000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3.12
.rsrc 0x00031000 0x0000a2e0 0x0000b000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7.24

覆盖

偏移量: 0x00037000
大小: 0x00f75080

资源

名称 偏移量 大小 语言 子语言 熵(Entropy) 文件类型
GIF 0x00033640 0x00007aea LANG_ENGLISH SUBLANG_ENGLISH_US 7.97 GIF image data, version 89a, 219 x 373
RT_CURSOR 0x000334f0 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US 2.49 Hitachi SH big-endian COFF object, not stripped
RT_ICON 0x00032628 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US 6.76 data
RT_ICON 0x00032628 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US 6.76 data
RT_ICON 0x00032628 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US 6.76 data
RT_ICON 0x00032628 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US 6.76 data
RT_DIALOG 0x00033110 0x000000f2 LANG_ENGLISH SUBLANG_ENGLISH_US 3.31 data
RT_DIALOG 0x00033110 0x000000f2 LANG_ENGLISH SUBLANG_ENGLISH_US 3.31 data
RT_DIALOG 0x00033110 0x000000f2 LANG_ENGLISH SUBLANG_ENGLISH_US 3.31 data
RT_DIALOG 0x00033110 0x000000f2 LANG_ENGLISH SUBLANG_ENGLISH_US 3.31 data
RT_DIALOG 0x00033110 0x000000f2 LANG_ENGLISH SUBLANG_ENGLISH_US 3.31 data
RT_STRING 0x0003b210 0x000000cc LANG_ENGLISH SUBLANG_ENGLISH_US 2.77 data
RT_STRING 0x0003b210 0x000000cc LANG_ENGLISH SUBLANG_ENGLISH_US 2.77 data
RT_STRING 0x0003b210 0x000000cc LANG_ENGLISH SUBLANG_ENGLISH_US 2.77 data
RT_GROUP_CURSOR 0x00033628 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US 2.02 MS Windows cursor resource - 1 icon, 32x256, hotspot @1x1
RT_GROUP_ICON 0x00032ed0 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US 2.65 MS Windows icon resource - 4 icons, 16x16, 16 colors
RT_VERSION 0x00031710 0x000005a0 LANG_ENGLISH SUBLANG_ENGLISH_US 2.87 data
RT_MANIFEST 0x00031470 0x0000029a LANG_NEUTRAL SUBLANG_NEUTRAL 4.88 XML 1.0 document, ASCII text, with CRLF line terminators

导入

库 VERSION.dll:
0x4233fc - VerLanguageNameA
0x423400 - GetFileVersionInfoA
0x423404 - GetFileVersionInfoSizeA
0x423408 - VerQueryValueA
库 SHELL32.dll:
0x4232dc - SHBrowseForFolderA
0x4232e0 - SHGetMalloc
0x4232e4 - SHGetPathFromIDListA
库 COMCTL32.dll:
0x42304c - None
库 KERNEL32.dll:
0x4230a4 - WideCharToMultiByte
0x4230a8 - DeleteFileA
0x4230ac - lstrlenW
0x4230b0 - WriteFile
0x4230b4 - InterlockedIncrement
0x4230b8 - InterlockedDecrement
0x4230bc - QueryPerformanceFrequency
0x4230c0 - CreateEventA
0x4230c4 - Sleep
0x4230c8 - lstrcatA
0x4230cc - CompareStringA
0x4230d0 - CompareStringW
0x4230d4 - GetVersionExA
0x4230d8 - SetFilePointer
0x4230dc - SetFileAttributesA
0x4230e0 - SetFileTime
0x4230e4 - LocalFileTimeToFileTime
0x4230e8 - DosDateTimeToFileTime
0x4230ec - FreeLibrary
0x4230f0 - GetProcAddress
0x4230f4 - LoadLibraryA
0x4230f8 - LockResource
0x4230fc - LoadResource
0x423100 - SizeofResource
0x423104 - FindResourceA
0x423108 - CreateProcessA
0x42310c - GetSystemDefaultLCID
0x423110 - GlobalHandle
0x423114 - SetCurrentDirectoryA
0x423118 - GetPrivateProfileSectionA
0x42311c - WaitForSingleObject
0x423120 - GetSystemInfo
0x423124 - GetModuleFileNameA
0x423128 - IsValidCodePage
0x42312c - GetVersion
0x423130 - FlushFileBuffers
0x423134 - LocalFree
0x423138 - FormatMessageA
0x42313c - GetDiskFreeSpaceA
0x423140 - _lclose
0x423144 - OpenFile
0x423148 - GetDriveTypeA
0x42314c - lstrcpynA
0x423150 - CreateDirectoryA
0x423154 - GetFileAttributesA
0x423158 - RemoveDirectoryA
0x42315c - GetExitCodeProcess
0x423160 - GetCurrentProcess
0x423164 - GetCurrentThread
0x423168 - GetLocaleInfoA
0x42316c - CreateFileA
0x423170 - FreeEnvironmentStringsA
0x423174 - UnhandledExceptionFilter
0x423178 - GetOEMCP
0x42317c - GetACP
0x423180 - GetCPInfo
0x423184 - SetUnhandledExceptionFilter
0x423188 - GetLastError
0x42318c - VirtualAlloc
0x423190 - VirtualFree
0x423194 - HeapCreate
0x423198 - HeapDestroy
0x42319c - GetEnvironmentVariableA
0x4231a0 - DeleteCriticalSection
0x4231a4 - InitializeCriticalSection
0x4231a8 - TlsGetValue
0x4231ac - TlsAlloc
0x4231b0 - TlsSetValue
0x4231b4 - GetCurrentThreadId
0x4231b8 - HeapSize
0x4231bc - HeapReAlloc
0x4231c0 - LeaveCriticalSection
0x4231c4 - EnterCriticalSection
0x4231c8 - GetCommandLineA
0x4231cc - GetStartupInfoA
0x4231d0 - GetModuleHandleA
0x4231d4 - TerminateProcess
0x4231d8 - ExitProcess
0x4231dc - RaiseException
0x4231e0 - HeapFree
0x4231e4 - HeapAlloc
0x4231e8 - RtlUnwind
0x4231ec - SystemTimeToFileTime
0x4231f0 - QueryPerformanceCounter
0x4231f4 - ResetEvent
0x4231f8 - SetEvent
0x4231fc - SearchPathA
0x423200 - FindFirstFileA
0x423204 - GetFileType
0x423208 - VirtualProtect
0x42320c - VirtualQuery
0x423210 - FindClose
0x423214 - GetStringTypeA
0x423218 - GetStringTypeW
0x42321c - IsBadReadPtr
0x423220 - IsBadCodePtr
0x423224 - LCMapStringA
0x423228 - LCMapStringW
0x42322c - SetStdHandle
0x423230 - GetFileSize
0x423234 - GlobalAlloc
0x423238 - CloseHandle
0x42323c - GlobalLock
0x423240 - ReadFile
0x423244 - GlobalUnlock
0x423248 - GlobalFree
0x42324c - SetLastError
0x423250 - CopyFileA
0x423254 - FreeEnvironmentStringsW
0x423258 - GetEnvironmentStrings
0x42325c - GetEnvironmentStringsW
0x423260 - MultiByteToWideChar
0x423264 - CreateThread
0x423268 - GetExitCodeThread
0x42326c - GetTickCount
0x423270 - lstrcmpiA
0x423274 - lstrcmpA
0x423278 - ExpandEnvironmentStringsA
0x42327c - GetPrivateProfileIntA
0x423280 - GetTempPathA
0x423284 - SetErrorMode
0x423288 - GetWindowsDirectoryA
0x42328c - GetTempFileNameA
0x423290 - WritePrivateProfileStringA
0x423294 - lstrcpyA
0x423298 - GetPrivateProfileStringA
0x42329c - CreateFileMappingA
0x4232a0 - MapViewOfFile
0x4232a4 - UnmapViewOfFile
0x4232a8 - IsBadWritePtr
0x4232ac - lstrlenA
0x4232b0 - SetHandleCount
0x4232b4 - GetStdHandle
库 USER32.dll:
0x4232ec - GetWindowTextLengthA
0x4232f0 - GetWindowTextA
0x4232f4 - MoveWindow
0x4232f8 - GetWindowPlacement
0x4232fc - DrawIcon
0x423300 - DestroyIcon
0x423304 - GetDlgCtrlID
0x423308 - SetWindowTextA
0x42330c - FillRect
0x423310 - GetSysColor
0x423314 - GetSysColorBrush
0x423318 - IsDialogMessageA
0x42331c - GetParent
0x423320 - EnableWindow
0x423324 - GetDlgItemTextA
0x423328 - SetCursor
0x42332c - UpdateWindow
0x423330 - GetClassInfoA
0x423334 - wvsprintfA
0x423338 - LoadStringA
0x42333c - SendMessageA
0x423340 - GetWindowRect
0x423344 - GetSystemMetrics
0x423348 - FindWindowA
0x42334c - IntersectRect
0x423350 - SubtractRect
0x423354 - CharPrevA
0x423358 - DestroyWindow
0x42335c - CreateDialogParamA
0x423360 - CharNextA
0x423364 - MessageBoxA
0x423368 - WaitForInputIdle
0x42336c - GetWindowLongA
0x423370 - BeginPaint
0x423374 - EndPaint
0x423378 - SetWindowLongA
0x42337c - GetClientRect
0x423380 - ClientToScreen
0x423384 - SetWindowPos
0x423388 - GetWindowDC
0x42338c - EndDialog
0x423390 - GetDlgItem
0x423394 - ShowWindow
0x423398 - DialogBoxParamA
0x42339c - GetDesktopWindow
0x4233a0 - wsprintfA
0x4233a4 - MsgWaitForMultipleObjects
0x4233a8 - PeekMessageA
0x4233ac - DefWindowProcA
0x4233b0 - PostMessageA
0x4233b4 - KillTimer
0x4233b8 - PostQuitMessage
0x4233bc - SetTimer
0x4233c0 - LoadIconA
0x4233c4 - LoadCursorA
0x4233c8 - RegisterClassA
0x4233cc - CreateWindowExA
0x4233d0 - GetMessageA
0x4233d4 - TranslateMessage
0x4233d8 - DispatchMessageA
0x4233dc - GetDC
0x4233e0 - ReleaseDC
0x4233e4 - ExitWindowsEx
0x4233e8 - SendDlgItemMessageA
0x4233ec - IsWindow
0x4233f0 - CharLowerBuffA
0x4233f4 - SetRect
库 GDI32.dll:
0x423054 - SetBkMode
0x423058 - SetTextColor
0x42305c - GetObjectA
0x423060 - CreateFontIndirectA
0x423064 - CreateSolidBrush
0x423068 - CreateCompatibleDC
0x42306c - SelectObject
0x423070 - BitBlt
0x423074 - GetTextExtentPointA
0x423078 - DeleteObject
0x42307c - GetStockObject
0x423080 - GetSystemPaletteEntries
0x423084 - CreatePalette
0x423088 - GetDeviceCaps
0x42308c - SelectPalette
0x423090 - RealizePalette
0x423094 - CreateDIBitmap
0x423098 - DeleteDC
0x42309c - TranslateCharsetInfo
库 ADVAPI32.dll:
0x423000 - RegQueryValueA
0x423004 - RegOpenKeyA
0x423008 - RegDeleteValueA
0x42300c - RegOpenKeyExA
0x423010 - RegQueryValueExA
0x423014 - RegCloseKey
0x423018 - RegCreateKeyExA
0x42301c - RegEnumValueA
0x423020 - RegDeleteKeyA
0x423024 - AdjustTokenPrivileges
0x423028 - LookupPrivilegeValueA
0x42302c - OpenProcessToken
0x423030 - FreeSid
0x423034 - EqualSid
0x423038 - AllocateAndInitializeSid
0x42303c - GetTokenInformation
0x423040 - OpenThreadToken
0x423044 - RegSetValueExA
库 ole32.dll:
0x423410 - CoTaskMemFree
0x423414 - CoCreateGuid
0x423418 - CreateItemMoniker
0x42341c - StringFromCLSID
0x423420 - StgIsStorageFile
0x423424 - StgOpenStorage
0x423428 - CoCreateInstance
0x42342c - CoUninitialize
0x423430 - CoInitialize
0x423434 - GetRunningObjectTable
库 OLEAUT32.dll:
0x4232bc - VariantChangeType
0x4232c0 - SysAllocString
0x4232c4 - SysAllocStringLen
0x4232c8 - SysStringLen
0x4232cc - SysReAllocStringLen
0x4232d0 - SysFreeString
0x4232d4 - VariantClear

投放文件

无信息

行为分析

互斥量(Mutexes)
  • Local\MSCTF.Asm.MutexDefault1
执行的命令
  • MSIEXEC.EXE /i "C:\Users\test\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150050}\J2SE Runtime Environment 5.0 Update 5.msi" TRANSFORMS="C:\Users\test\AppData\Local\Temp\_is982\2052.MST" SETUPEXEDIR="C:\Users\test\AppData\Local\Temp"
创建的服务 无信息
启动的服务 无信息

进程

sun java version 5.0.exe PID: 2696, 上一级进程 PID: 2344

msiexec.exe PID: 2864, 上一级进程 PID: 2696

访问的文件
  • C:\Users\test\AppData\Local\Temp\RPAWINET.DLL
  • C:\Windows\System32\RPAWINET.DLL
  • C:\Windows\system\RPAWINET.DLL
  • C:\Windows\RPAWINET.DLL
  • C:\ProgramData\Oracle\Java\javapath\RPAWINET.DLL
  • C:\Windows\System32\wbem\RPAWINET.DLL
  • C:\Windows\System32\WindowsPowerShell\v1.0\RPAWINET.DLL
  • C:\Program Files (x86)\WinRAR\RPAWINET.DLL
  • C:\Users\test\AppData\Local\Temp\sun java version 5.0.exe
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\test\AppData\Local\Temp
  • C:\Users\test\AppData\Local\Temp\~952.tmp
  • C:\Users\test\AppData\Local\Temp\
  • C:\Users\test\AppData\Local\Temp\_MSI5166._IS
  • C:\Users\test\AppData\Local\Temp\_is982.tmp
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Local
  • C:\Users\test\AppData\Local\Temp\_is982
  • C:
  • C:\Users\test\AppData\Local\Temp\_is982\Setup.INI
  • C:\Users\test\AppData\Local\Temp\_is982\_ISMSIDEL.INI
  • C:\Users\test\AppData\Local\Temp\_is982\0x0804.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0404.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0409.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x040c.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0407.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0410.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0411.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0412.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x040a.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x041d.ini
  • C:\Users\test\AppData\Local\Temp\_is982\setup.bmp
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\_is982\2052.MST
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Local\Temp\_is982\J2SE Runtime Environment 5.0 Update 5.msi
  • C:\Users\test\AppData\Local\Temp\CABINET.DLL
  • C:\Windows\System32\cabinet.dll
  • C:\Users\test\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150050}
  • C:\Users\test\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150050}\J2SE Runtime Environment 5.0 Update 5.msi
  • C:\Users\test\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150050}\2052.MST
  • C:\Users\test\AppData\Local\Temp\MSIEXEC.EXE
  • C:\Windows\System32\msiexec.exe
  • C:\Windows\SysWOW64\MSIEXEC.EXE.Local\
  • C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
  • C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
  • C:\Windows\WindowsShell.Manifest
  • C:\Windows\SysWOW64\msimsg.dll
  • A:
  • B:
  • D:
  • E:
  • F:
  • G:
  • H:
  • I:
  • J:
  • K:
  • L:
  • M:
  • N:
  • O:
  • P:
  • Q:
  • R:
  • S:
  • T:
  • U:
  • V:
  • W:
  • X:
  • Y:
  • Z:
  • C:\
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\Windows\AppPatch\msimain.sdb
  • C:\Windows\SysWOW64\sxs.dll
  • C:\Windows\SysWOW64\*
  • C:\Windows\SysWOW64\ar-SA\sxs.DLL.mui
  • C:\Windows\SysWOW64\bg-BG\sxs.DLL.mui
  • C:\Windows\SysWOW64\cs-CZ\sxs.DLL.mui
  • C:\Windows\SysWOW64\da-DK\sxs.DLL.mui
  • C:\Windows\SysWOW64\de-DE\sxs.DLL.mui
  • C:\Windows\SysWOW64\el-GR\sxs.DLL.mui
  • C:\Windows\SysWOW64\en\sxs.DLL.mui
  • C:\Windows\SysWOW64\en-US\sxs.DLL.mui
  • C:\Windows\SysWOW64\es-ES\sxs.DLL.mui
  • C:\Windows\SysWOW64\et-EE\sxs.DLL.mui
  • C:\Windows\SysWOW64\fi-FI\sxs.DLL.mui
  • C:\Windows\SysWOW64\fr-FR\sxs.DLL.mui
  • C:\Windows\SysWOW64\he-IL\sxs.DLL.mui
  • C:\Windows\SysWOW64\hr-HR\sxs.DLL.mui
  • C:\Windows\SysWOW64\hu-HU\sxs.DLL.mui
  • C:\Windows\SysWOW64\it-IT\sxs.DLL.mui
  • C:\Windows\SysWOW64\ja-JP\sxs.DLL.mui
  • C:\Windows\SysWOW64\ko-KR\sxs.DLL.mui
  • C:\Windows\SysWOW64\lt-LT\sxs.DLL.mui
  • C:\Windows\SysWOW64\lv-LV\sxs.DLL.mui
  • C:\Windows\SysWOW64\nb-NO\sxs.DLL.mui
  • C:\Windows\SysWOW64\nl-NL\sxs.DLL.mui
  • C:\Windows\SysWOW64\pl-PL\sxs.DLL.mui
  • C:\Windows\SysWOW64\pt-BR\sxs.DLL.mui
  • C:\Windows\SysWOW64\pt-PT\sxs.DLL.mui
  • C:\Windows\SysWOW64\ro-RO\sxs.DLL.mui
  • C:\Windows\SysWOW64\ru-RU\sxs.DLL.mui
  • C:\Windows\SysWOW64\sk-SK\sxs.DLL.mui
  • C:\Windows\SysWOW64\sl-SI\sxs.DLL.mui
  • C:\Windows\SysWOW64\sr-Latn-CS\sxs.DLL.mui
  • C:\Windows\SysWOW64\sv-SE\sxs.DLL.mui
  • C:\Windows\SysWOW64\th-TH\sxs.DLL.mui
  • C:\Windows\SysWOW64\tr-TR\sxs.DLL.mui
  • C:\Windows\SysWOW64\uk-UA\sxs.DLL.mui
  • C:\Windows\SysWOW64\zh-HK\sxs.DLL.mui
  • C:\Windows\SysWOW64\zh-TW\sxs.DLL.mui
  • C:\Windows\SysWOW64\MSCOREE.DLL.local
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319
  • C:\Windows\Microsoft.NET\Framework\*
  • C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
  • C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
  • C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
  • C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
  • C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll
  • C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
  • C:\Windows\SysWOW64\MSIEXEC.EXE.config
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll
  • C:\Windows\SysWOW64\zh-Hans\MsiMsg.dll.mui
  • C:\Windows\SysWOW64\zh\MsiMsg.dll.mui
  • C:\Windows\SysWOW64\en-US\MsiMsg.dll.mui
  • C:\Users\test\AppData\Local\Temp\MSI3A41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3ACF.tmp
  • C:\Windows\SysWOW64
  • C:\Windows\SysWOW64\msvcrt.dll
  • C:\Windows\Installer\$PatchCache$\Managed\8A0F842331866D117AB7000B0D510005
  • C:\MSI69d8b.tmp
  • C:\Program Files (x86)\Java\jre1.5.0_05\COPYRIGHT
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\other.zip
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\javaws\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\javaws\*
  • C:\Users\test\AppData\Local\Temp\MSI3B5C.tmp
  • C:\Windows\win.ini
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_05.b05\RegUtils.dll
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_05.b05\patchjre.exe
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_05.b05\zipper.exe
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_05.b05\FontChecker.jar
  • C:\Program Files (x86)\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_05.b05\launcher.exe
  • C:\Program Files (x86)\Java\jre1.5.0_05\
  • C:\Program Files (x86)\Java\jre1.5.0_05\PATCH.ERR
  • C:\Program Files (x86)\Java\jre1.5.0_05\CHANGES
  • C:\Program Files (x86)\Java\jre1.5.0_05\COPYRIG*
  • C:\Program Files (x86)\Java\jre1.5.0_05\LICENSE*
  • C:\Program Files (x86)\Java\jre1.5.0_05\README.*
  • C:\Program Files (x86)\Java\jre1.5.0_05\THIRDPA*
  • C:\Program Files (x86)\Java\jre1.5.0_05\Welcome*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Africa\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Africa\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Antarctica\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Antarctica\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\Argentina\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\Argentina\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Asia\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Asia\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Atlantic\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Atlantic\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Australia\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Australia\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Etc\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Etc\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Europe\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Europe\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Indian\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Indian\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\Indiana\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\Indiana\*
  • C:\Program Files (x86)\Java\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\Kentucky\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\Kentucky\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\North_Dakota\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\America\North_Dakota\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Pacific\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\zi\Pacific\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\applet\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\applet\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\classli*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\audio\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\audio\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\bin\
  • C:\Program Files (x86)\Java\jre1.5.0_05\bin\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\bin\client\
  • C:\Program Files (x86)\Java\jre1.5.0_05\bin\client\classes.jsa
  • C:\Program Files (x86)\Java\jre1.5.0_05\bin\client\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\cmm\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\cmm\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\images\cursors\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\images\cursors\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\images\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\images\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\ext\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\ext\dnsns.j*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\ext\localed*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\ext\sunjce_*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\ext\sunpkcs*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\fonts\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\fonts\badfonts.txt
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\fonts\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\i386\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\i386\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\im\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\im\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\management\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\management\*
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\security\
  • C:\Program Files (x86)\Java\jre1.5.0_05\lib\security\*
  • C:\Windows\SysWOW64\java.exe
  • C:\Windows\SysWOW64\javaw.exe
  • C:\Windows\SysWOW64\javaws.exe
  • C:\Program Files (x86)\Java\jre1.5.0_05\bin\RegUtils.dll
读取的文件
  • C:\Users\test\AppData\Local\Temp\sun java version 5.0.exe
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\test\AppData\Local\Temp\~952.tmp
  • C:\Users\test\AppData\Local\Temp\_MSI5166._IS
  • C:\Users\test\AppData\Local\Temp\_is982.tmp
  • C:\Users\test\AppData\Local\Temp\_is982\Setup.INI
  • C:\Users\test\AppData\Local\Temp\_is982\_ISMSIDEL.INI
  • C:\Users\test\AppData\Local\Temp\_is982\0x0804.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0404.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0409.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x040c.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0407.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0410.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0411.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0412.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x040a.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x041d.ini
  • C:\Users\test\AppData\Local\Temp\_is982\setup.bmp
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\_is982\2052.MST
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Local\Temp\_is982\J2SE Runtime Environment 5.0 Update 5.msi
  • C:\Windows\System32\cabinet.dll
  • C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
  • C:\Windows\WindowsShell.Manifest
  • C:\Users\test\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150050}\J2SE Runtime Environment 5.0 Update 5.msi
  • C:\Windows\SysWOW64\msimsg.dll
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\Windows\AppPatch\msimain.sdb
  • C:\Windows\SysWOW64\sxs.dll
  • C:\Windows\SysWOW64\ar-SA\sxs.DLL.mui
  • C:\Windows\SysWOW64\bg-BG\sxs.DLL.mui
  • C:\Windows\SysWOW64\cs-CZ\sxs.DLL.mui
  • C:\Windows\SysWOW64\da-DK\sxs.DLL.mui
  • C:\Windows\SysWOW64\de-DE\sxs.DLL.mui
  • C:\Windows\SysWOW64\el-GR\sxs.DLL.mui
  • C:\Windows\SysWOW64\en\sxs.DLL.mui
  • C:\Windows\SysWOW64\en-US\sxs.DLL.mui
  • C:\Windows\SysWOW64\es-ES\sxs.DLL.mui
  • C:\Windows\SysWOW64\et-EE\sxs.DLL.mui
  • C:\Windows\SysWOW64\fi-FI\sxs.DLL.mui
  • C:\Windows\SysWOW64\fr-FR\sxs.DLL.mui
  • C:\Windows\SysWOW64\he-IL\sxs.DLL.mui
  • C:\Windows\SysWOW64\hr-HR\sxs.DLL.mui
  • C:\Windows\SysWOW64\hu-HU\sxs.DLL.mui
  • C:\Windows\SysWOW64\it-IT\sxs.DLL.mui
  • C:\Windows\SysWOW64\ja-JP\sxs.DLL.mui
  • C:\Windows\SysWOW64\ko-KR\sxs.DLL.mui
  • C:\Windows\SysWOW64\lt-LT\sxs.DLL.mui
  • C:\Windows\SysWOW64\lv-LV\sxs.DLL.mui
  • C:\Windows\SysWOW64\nb-NO\sxs.DLL.mui
  • C:\Windows\SysWOW64\nl-NL\sxs.DLL.mui
  • C:\Windows\SysWOW64\pl-PL\sxs.DLL.mui
  • C:\Windows\SysWOW64\pt-BR\sxs.DLL.mui
  • C:\Windows\SysWOW64\pt-PT\sxs.DLL.mui
  • C:\Windows\SysWOW64\ro-RO\sxs.DLL.mui
  • C:\Windows\SysWOW64\ru-RU\sxs.DLL.mui
  • C:\Windows\SysWOW64\sk-SK\sxs.DLL.mui
  • C:\Windows\SysWOW64\sl-SI\sxs.DLL.mui
  • C:\Windows\SysWOW64\sr-Latn-CS\sxs.DLL.mui
  • C:\Windows\SysWOW64\sv-SE\sxs.DLL.mui
  • C:\Windows\SysWOW64\th-TH\sxs.DLL.mui
  • C:\Windows\SysWOW64\tr-TR\sxs.DLL.mui
  • C:\Windows\SysWOW64\uk-UA\sxs.DLL.mui
  • C:\Windows\SysWOW64\zh-HK\sxs.DLL.mui
  • C:\Windows\SysWOW64\zh-TW\sxs.DLL.mui
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
  • C:\Windows\SysWOW64\MSIEXEC.EXE.config
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll
  • C:\Windows\SysWOW64\zh-Hans\MsiMsg.dll.mui
  • C:\Windows\SysWOW64\zh\MsiMsg.dll.mui
  • C:\Windows\SysWOW64\en-US\MsiMsg.dll.mui
  • C:\Users\test\AppData\Local\Temp\MSI3A41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3ACF.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3B5C.tmp
  • C:\Windows\win.ini
修改的文件
  • C:\Users\test\AppData\Local\Temp\~952.tmp
  • C:\Users\test\AppData\Local\Temp\_MSI5166._IS
  • C:\Users\test\AppData\Local\Temp\_is982\Setup.INI
  • C:\Users\test\AppData\Local\Temp\_is982\_ISMSIDEL.INI
  • C:\Users\test\AppData\Local\Temp\_is982\0x0804.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0404.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0409.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x040c.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0407.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0410.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0411.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x0412.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x040a.ini
  • C:\Users\test\AppData\Local\Temp\_is982\0x041d.ini
  • C:\Users\test\AppData\Local\Temp\_is982\setup.bmp
  • C:\Users\test\AppData\Local\Temp\_is982\2052.MST
  • C:\Users\test\AppData\Local\Temp\_is982\J2SE Runtime Environment 5.0 Update 5.msi
  • C:\Users\test\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150050}\J2SE Runtime Environment 5.0 Update 5.msi
  • C:\Users\test\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150050}\2052.MST
  • C:\Users\test\AppData\Local\Temp\MSI3A41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3ACF.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3B5C.tmp
删除的文件
  • C:\Users\test\AppData\Local\Temp\~952.tmp
  • C:\Users\test\AppData\Local\Temp\_MSI5166._IS
  • C:\Users\test\AppData\Local\Temp\_is982.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3A41.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3ACF.tmp
  • C:\Users\test\AppData\Local\Temp\MSI3B5C.tmp
注册表键
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_CURRENT_USER\Software\InstallShield\ISWI\7.0\SetupExeLog
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\8A0F842331866D117AB7000B0D510005
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\8A0F842331866D117AB7000B0D510005
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\8A0F842331866D117AB7000B0D510005
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\sun java version 5.0.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_CURRENT_USER
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\MSIEXEC.EXE
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109110000000000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109110000000000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109110000000000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\000041091A0040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\000041091A0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\000041091A0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109440040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109440040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109440040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109510040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109510040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109510040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109610040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109610040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109610040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109810040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109810040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109810040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109820040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109820040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109820040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109820040800100000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109820040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109820040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109910040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109910040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109910040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109A10040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109A10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109A10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109A20000000100000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109A20000000100000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109A20000000100000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109A20040800100000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109A20040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109A20040800100000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109AB0040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109AB0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109AB0040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109B10040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109B10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109B10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109C20040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109C20040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109C20040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109E60040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109E60040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109E60040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109F10040800000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109F10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109F10040800000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\00004109F10090400000000000F01FEC
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\00004109F10090400000000000F01FEC
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\00004109F10090400000000000F01FEC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\0547300BD62584433A07ACBC8D77960A
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\0547300BD62584433A07ACBC8D77960A
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\4EA42A62D9304AC4784BF2238110120F
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\4EA42A62D9304AC4784BF2238110120F
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\62DBF9290209B993A9A757D1160F9B24
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\62DBF9290209B993A9A757D1160F9B24
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\68AB67CA7DA7035200000A0000000094
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\68AB67CA7DA7035200000A0000000094
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\68AB67CA7DA7035200000A0000000094
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA7035200000A0000000094\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA7035200000A0000000094\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\68AB67CA7DA72502B744BA0000000010
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\68AB67CA7DA72502B744BA0000000010
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\7C9F8B73BF303523781852719CD9C700
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\7C9F8B73BF303523781852719CD9C700
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\91915B2EA702BE34EA8737F3C976792C
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\91915B2EA702BE34EA8737F3C976792C
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\InstanceType
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2280033686-3172497658-3481507381-1000\Installer\Products\F60730A4A66673047777F5728467D401
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Microsoft\Installer\Products\F60730A4A66673047777F5728467D401
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\F60730A4A66673047777F5728467D401
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\InstanceType
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\LayoutIcon\0804\00000804
  • HKEY_CURRENT_USER\Software\Classes
  • HKEY_CURRENT_USER\Software\Classes\Interface\{000C101C-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C101C-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C101C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\TreatAs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\TreatAs
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C103E-0000-0000-C000-000000000046}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\ThreadingModel
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InprocHandler
  • HKEY_CLASSES_ROOT\CLSID\{000C101D-0000-0000-C000-000000000046}\DllVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}\DllVersion\(Default)
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510005\InstallProperties
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\{3248f0a8-6813-11d6-a77b-00b0d0150050}
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\.
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\..
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\0409
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\AdvancedInstallers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot2
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\com
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Dism
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\drivers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\DriverStore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\FxsTmp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicyUsers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\icsxml
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\IME
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\inetsrv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\InstallShield
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\itruscert
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\LogFiles
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Macromed
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\manifeststore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migwiz
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Msdtc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\MUI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NDF
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NetworkList
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oobe
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Printing_Admin_Scripts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ras
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Recovery
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\restore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\slmgr
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Speech
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\spp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sppui
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sysprep
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Tasks
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wbem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WCN
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wdi
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WindowsPowerShell
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\winrm
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\XPSViewer
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-CHS
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\AppPatch
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Registry Keys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Relative Files
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Target Version
  • HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
  • HKEY_USERS\S-1-5-21-2280033686-3172497658-3481507381-1000\Software\Policies\Microsoft\Windows\Installer
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\PendingFileRenameOperations
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_CURRENT_USER\Software\Microsoft\MS Setup (ACME)\User Info
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOrganization
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress
  • HKEY_CURRENT_USER\Control Panel\International
  • HKEY_CURRENT_USER\Control Panel\International\LocaleName
  • HKEY_CURRENT_USER\Software\Classes\Interface\{000C1033-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C1033-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C1033-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{000C1025-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C1025-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C1025-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
  • HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Tahoma
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\David Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixed Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Rod Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\FangSong_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\KaiTi_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
读取的注册表键
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109110000000000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\000041091A0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109440040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109510040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109610040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109810040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109820040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109910040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20000000100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109A20040800100000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109AB0040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109B10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109C20040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109E60040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10040800000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\00004109F10090400000000000F01FEC\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0547300BD62584433A07ACBC8D77960A\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\11E3B31B5551F3536AA39833EE01F4DB\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\40244AC97CCCA7330B93A3FB99A88B9A\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4EA42A62D9304AC4784BF2238110120F\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\62DBF9290209B993A9A757D1160F9B24\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA7035200000A0000000094\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA7035200000A0000000094\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\68AB67CA7DA72502B744BA0000000010\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6E8D947A316B3EB3F8F540C548BE2AB9\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\7C9F8B73BF303523781852719CD9C700\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\91915B2EA702BE34EA8737F3C976792C\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B4C5FD36FB3E64330A335CB7224FC4E9\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\C3AEB2FCAE628F23AAB933F1E743AB79\InstanceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\PackageCode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401\InstanceType
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C101C-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000C101D-0000-0000-C000-000000000046}\DllVersion\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\.
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\..
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\0409
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\AdvancedInstallers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\catroot2
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\com
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Dism
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\drivers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\DriverStore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\FxsTmp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\GroupPolicyUsers
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\icsxml
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\IME
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\inetsrv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\InstallShield
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\itruscert
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\LogFiles
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Macromed
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\manifeststore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migration
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\migwiz
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Msdtc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\MUI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NDF
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\NetworkList
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\oobe
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Printing_Admin_Scripts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\ras
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Recovery
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\restore
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\slmgr
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Speech
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\spp
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sppui
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\sysprep
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Tasks
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wbem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WCN
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\wdi
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\WindowsPowerShell
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\winrm
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\XPSViewer
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-CHS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\msi.dll\{462EF42B-ABA4-4eac-9843-9EED260F54D0}\Target Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\PendingFileRenameOperations
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOwner
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOrganization
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RegisteredOrganization
  • HKEY_CURRENT_USER\Control Panel\International\LocaleName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C1033-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{000C1025-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\David Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixed Miriam Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Rod Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\FangSong_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\KaiTi_GB2312
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
修改的注册表键 无信息
删除的注册表键 无信息
API解析
  • kernel32.dll.IsProcessorFeaturePresent
  • wininet.dll.InternetOpenA
  • wininet.dll.InternetOpenUrlA
  • wininet.dll.InternetConnectA
  • wininet.dll.InternetCrackUrlA
  • wininet.dll.InternetCreateUrlA
  • wininet.dll.InternetCloseHandle
  • wininet.dll.InternetReadFile
  • wininet.dll.HttpQueryInfoA
  • wininet.dll.FtpFindFirstFileA
  • wininet.dll.InternetGetLastResponseInfoA
  • wininet.dll.InternetSetOptionA
  • wininet.dll.InternetGetConnectedState
  • wininet.dll.InternetAutodial
  • wininet.dll.InternetErrorDlg
  • wininet.dll.HttpOpenRequestA
  • wininet.dll.HttpSendRequestA
  • wininet.dll.HttpSendRequestExA
  • wininet.dll.HttpEndRequestA
  • wininet.dll.InternetQueryOptionA
  • wininet.dll.InternetQueryDataAvailable
  • wininet.dll.InternetCanonicalizeUrlA
  • wininet.dll.InternetGetCookieA
  • wininet.dll.InternetSetCookieA
  • wininet.dll.InternetSetStatusCallbackA
  • comctl32.dll.InitCommonControlsEx
  • kernel32.dll.SortGetHandle
  • kernel32.dll.SortCloseHandle
  • kernel32.dll.GetDiskFreeSpaceExA
  • msi.dll.MsiGetProductInfoA
  • kernel32.dll.GetNativeSystemInfo
  • ole32.dll.CoInitializeEx
  • ole32.dll.CoUninitialize
  • cryptbase.dll.SystemFunction036
  • ole32.dll.CoRegisterInitializeSpy
  • ole32.dll.CoRevokeInitializeSpy
  • comctl32.dll.RegisterClassNameW
  • uxtheme.dll.EnableThemeDialogTexture
  • uxtheme.dll.OpenThemeData
  • gdi32.dll.GetLayout
  • gdi32.dll.GdiRealizationInfo
  • gdi32.dll.FontIsLinked
  • advapi32.dll.RegOpenKeyExW
  • advapi32.dll.RegQueryInfoKeyW
  • gdi32.dll.GetTextFaceAliasW
  • advapi32.dll.RegEnumValueW
  • advapi32.dll.RegCloseKey
  • advapi32.dll.RegQueryValueExW
  • advapi32.dll.RegQueryValueExA
  • advapi32.dll.RegEnumKeyExW
  • gdi32.dll.GetTextExtentExPointWPri
  • cabinet.dll.FDICreate
  • cabinet.dll.FDIIsCabinet
  • cabinet.dll.FDICopy
  • cabinet.dll.FDIDestroy
  • shfolder.dll.SHGetFolderPathA
  • msi.dll.MsiOpenDatabaseA
  • kernel32.dll.GetSystemWow64DirectoryW
  • ole32.dll.StgOpenStorage
  • cryptsp.dll.CryptAcquireContextW
  • cryptsp.dll.CryptGenRandom
  • ole32.dll.CoGetMalloc
  • msi.dll.MsiGetSummaryInformationA
  • msi.dll.MsiCloseHandle
  • msi.dll.MsiSummaryInfoGetPropertyA
  • oleaut32.dll.#500
  • lpk.dll.LpkEditControl
  • kernel32.dll.HeapSetInformation
  • ntdll.dll.WinSqmIsOptedIn
  • shlwapi.dll.UrlIsW
  • kernel32.dll.GetThreadPreferredUILanguages
  • shell32.dll.SHGetPropertyStoreForWindow
  • ole32.dll.CoTaskMemAlloc
  • propsys.dll.PSStringFromPropertyKey
  • propsys.dll.PropVariantToString
  • oleaut32.dll.#6
  • oleaut32.dll.SysAllocString
  • oleaut32.dll.SysStringLen
  • oleaut32.dll.SysFreeString
  • ole32.dll.CoInitialize
  • netapi32.dll.NetGetJoinInformation
  • netapi32.dll.NetApiBufferFree
  • kernel32.dll.GetFileAttributesExW
  • advapi32.dll.CreateWellKnownSid
  • advapi32.dll.CheckTokenMembership
  • advapi32.dll.SaferiChangeRegistryScope
  • advapi32.dll.SaferIdentifyLevel
  • advapi32.dll.SaferGetLevelInformation
  • advapi32.dll.SaferCloseLevel
  • ole32.dll.CoCreateInstance
  • ole32.dll.CoQueryProxyBlanket
  • msi.dll.DllGetClassObject
  • msi.dll.DllCanUnloadNow
  • ole32.dll.CoSetProxyBlanket
  • apphelp.dll.ApphelpGetMsiProperties
  • apphelp.dll.SdbInitDatabase
  • apphelp.dll.SdbFindFirstMsiPackage_Str
  • apphelp.dll.SdbReleaseDatabase
  • version.dll.GetFileVersionInfoSizeW
  • version.dll.GetFileVersionInfoW
  • version.dll.VerQueryValueW
  • mscoree.dll.GetCORSystemDirectory
  • kernel32.dll.FlsAlloc
  • kernel32.dll.FlsFree
  • kernel32.dll.FlsGetValue
  • kernel32.dll.FlsSetValue
  • kernel32.dll.InitializeCriticalSectionEx
  • kernel32.dll.CreateEventExW
  • kernel32.dll.CreateSemaphoreExW
  • kernel32.dll.SetThreadStackGuarantee
  • kernel32.dll.CreateThreadpoolTimer
  • kernel32.dll.SetThreadpoolTimer
  • kernel32.dll.WaitForThreadpoolTimerCallbacks
  • kernel32.dll.CloseThreadpoolTimer
  • kernel32.dll.CreateThreadpoolWait
  • kernel32.dll.SetThreadpoolWait
  • kernel32.dll.CloseThreadpoolWait
  • kernel32.dll.FlushProcessWriteBuffers
  • kernel32.dll.FreeLibraryWhenCallbackReturns
  • kernel32.dll.GetCurrentProcessorNumber
  • kernel32.dll.GetLogicalProcessorInformation
  • kernel32.dll.CreateSymbolicLinkW
  • kernel32.dll.EnumSystemLocalesEx
  • kernel32.dll.CompareStringEx
  • kernel32.dll.GetDateFormatEx
  • kernel32.dll.GetLocaleInfoEx
  • kernel32.dll.GetTimeFormatEx
  • kernel32.dll.GetUserDefaultLocaleName
  • kernel32.dll.IsValidLocaleName
  • kernel32.dll.LCMapStringEx
  • kernel32.dll.GetTickCount64
  • kernel32.dll.AcquireSRWLockExclusive
  • kernel32.dll.ReleaseSRWLockExclusive
  • advapi32.dll.EventRegister
  • mscoree.dll.#142
  • mscoreei.dll.RegisterShimImplCallback
  • mscoreei.dll.OnShimDllMainCalled
  • mscoreei.dll.GetCORSystemDirectory_RetAddr
  • kernel32.dll.GetSystemWindowsDirectoryW
  • shell32.dll.SHGetFolderPathW
  • shell32.dll.DllGetVersion
  • ntdll.dll.NtQuerySystemInformation
  • kernel32.dll.GlobalMemoryStatusEx
  • kernel32.dll.CheckElevationEnabled
  • msihnd.dll.DllGetClassObject
  • kernel32.dll.GetUserDefaultUILanguage
  • ntdll.dll.NtMapViewOfSection
  • ntdll.dll.RtlImageNtHeaderEx
  • kernel32.dll.GetEnvironmentStringsW
  • ole32.dll.CoIsHandlerConnected
  • kernel32.dll.FreeEnvironmentStringsW
  • user32.dll.AllowSetForegroundWindow
  • rpcrt4.dll.I_RpcBindingInqLocalClientPID
  • user32.dll.ChangeWindowMessageFilterEx
  • gdi32.dll.GdiIsMetaPrintDC
  • gdi32.dll.GetFontAssocStatus