-
\Device\KsecDD
-
C:\Windows\System32\WSHTCPIP.DLL
-
C:\Windows\System32\wship6.dll
-
C:\Windows\System32\wshqos.dll
-
C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
-
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
-
kernel32.dll.WriteFile
-
kernel32.dll.WriteConsoleW
-
kernel32.dll.WaitForSingleObject
-
kernel32.dll.VirtualQuery
-
kernel32.dll.VirtualFree
-
-
kernel32.dll.VirtualAlloc
-
kernel32.dll.SwitchToThread
-
kernel32.dll.SetWaitableTimer
-
kernel32.dll.SetUnhandledExceptionFilter
-
kernel32.dll.SetProcessPriorityBoost
-
kernel32.dll.SetEvent
-
kernel32.dll.SetErrorMode
-
kernel32.dll.SetConsoleCtrlHandler
-
kernel32.dll.LoadLibraryA
-
kernel32.dll.LoadLibraryW
-
kernel32.dll.GetSystemInfo
-
kernel32.dll.GetSystemDirectoryA
-
kernel32.dll.GetStdHandle
-
kernel32.dll.GetQueuedCompletionStatus
-
kernel32.dll.GetProcessAffinityMask
-
kernel32.dll.GetProcAddress
-
kernel32.dll.GetEnvironmentStringsW
-
kernel32.dll.GetConsoleMode
-
kernel32.dll.FreeEnvironmentStringsW
-
kernel32.dll.ExitProcess
-
kernel32.dll.DuplicateHandle
-
kernel32.dll.CreateThread
-
kernel32.dll.CreateIoCompletionPort
-
kernel32.dll.CreateEventA
-
kernel32.dll.CloseHandle
-
kernel32.dll.AddVectoredExceptionHandler
-
kernel32.dll.AddVectoredContinueHandler
-
kernel32.dll.GetQueuedCompletionStatusEx
-
kernel32.dll.LoadLibraryExA
-
kernel32.dll.LoadLibraryExW
-
advapi32.dll.SystemFunction036
-
ntdll.dll.NtWaitForSingleObject
-
winmm.dll.timeBeginPeriod
-
winmm.dll.timeEndPeriod
-
ws2_32.dll.WSAGetOverlappedResult
-
cryptbase.dll.SystemFunction001
-
cryptbase.dll.SystemFunction002
-
cryptbase.dll.SystemFunction003
-
cryptbase.dll.SystemFunction004
-
cryptbase.dll.SystemFunction005
-
cryptbase.dll.SystemFunction028
-
cryptbase.dll.SystemFunction029
-
cryptbase.dll.SystemFunction034
-
cryptbase.dll.SystemFunction036
-
cryptbase.dll.SystemFunction040
-
cryptbase.dll.SystemFunction041
-
kernel32.dll.SetHandleInformation
-
kernel32.dll.GetSystemDirectoryW
-
ws2_32.dll.WSAStartup
-
kernel32.dll.CancelIoEx
-
kernel32.dll.SetFileCompletionNotificationModes
-
ws2_32.dll.WSAEnumProtocolsW
-
kernel32.dll.GetCommandLineW
-
kernel32.dll.GetEnvironmentVariableW
-
kernel32.dll.WTSGetActiveConsoleSessionId
-
kernel32.dll.FormatMessageW
-
wtsapi32.dll.WTSQuerySessionInformationW
-
winsta.dll.WinStationQueryInformationW
-
advapi32.dll.LookupAccountSidW
-
sechost.dll.LookupAccountSidLocalW
-
advapi32.dll.CreateWellKnownSid
-
rpcrt4.dll.RpcStringBindingComposeW
-
rpcrt4.dll.RpcBindingFromStringBindingW
-
rpcrt4.dll.RpcStringFreeW
-
rpcrt4.dll.RpcBindingSetAuthInfoExW
-
sechost.dll.LookupAccountNameLocalW
-
rpcrt4.dll.NdrClientCall2
-
rpcrt4.dll.RpcBindingFree
-
advapi32.dll.LookupAccountNameW
-
advapi32.dll.ConvertSidToStringSidW
-
kernel32.dll.LocalFree
-
advapi32.dll.RegOpenKeyExW
-
kernel32.dll.GetTimeZoneInformation
-
Show More 73
-
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
-
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
-
HKEY_USERS\S-1-5-21-2298303332-66077612-2598613238-1000\Software\Microsoft\TestApp
-
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
-
\Device\KsecDD
-
C:\Windows\System32\WSHTCPIP.DLL
-
C:\Windows\System32\wship6.dll
-
C:\Windows\System32\wshqos.dll
-
C:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
49b7a7484c716ac86421602641bbab7b66a56d52