- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
- C:\Users\user\AppData\Local\Temp\54f7533b1a92b258e7cd1a93f4fcb1a654d121b1.exe
- C:\Users
- C:\Users\user
- C:\Users\user\AppData
-
- C:\Users\user\AppData\Local
- C:\Users\user\AppData\Local\Temp
- C:\Users\user\AppData\Local\Temp\54f7533b1a92b258e7cd1a93f4fcb1a654d121b1.exe:tmp
- C:\Users\user\AppData\Local\Temp\54f7533b1a92b258e7cd1a93f4fcb1a654d121b1.exe.tmp
- C:\Users\user\AppData\Local\Temp\54f7533b1a92b258e7cd1a93f4fcb1a654d121b1.exe:Zone.Identifier
- C:\Windows\System32\en-US\wuapi.dll.mui
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\System32
- C:\Windows\System32\
- C:\Windows
- C:\Windows\
- C:
- \??\MountPointManager
- C:\
- C:\Users\user\AppData\Local\Temp\comres.DLL
- C:\Windows\System32\comres.dll
- C:\Windows\System32\en-US\comres.DLL.mui
- C:\Windows\Fonts\staticcache.dat
- C:\Users\user\AppData\Local\Temp\imageres.dll
- C:\Windows\System32\imageres.dll
- \??\PIPE\samr
- C:\Windows\sysnative\wbem\repository
- C:\Windows\sysnative\wbem\Logs
- C:\Windows\sysnative\wbem\AutoRecover
- C:\Windows\sysnative\wbem\MOF
- C:\Windows\sysnative\wbem\repository\INDEX.BTR
- C:\Windows\sysnative\wbem\repository\WRITABLE.TST
- C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
- C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
- C:\Windows\sysnative\wbem\repository\WBEM9xUpgd.dat
- \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
- \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
- Show More 34
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
-
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
- Show More 154
- \??\PIPE\samr
- C:\Windows\sysnative\wbem\repository\WRITABLE.TST
- C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
-
- C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
- C:\Windows\sysnative\wbem\repository\INDEX.BTR
- \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
- \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
- Show More 4
- kernel32.dll.FlsAlloc
- kernel32.dll.FlsGetValue
- kernel32.dll.FlsSetValue
- kernel32.dll.FlsFree
- kernel32.dll.InitializeCriticalSectionAndSpinCount
-
- kernel32.dll.IsProcessorFeaturePresent
- kernel32.dll.VirtualAlloc
- kernel32.dll.GetModuleHandleA
- kernel32.dll.LoadLibraryA
- kernel32.dll.VirtualProtect
- kernel32.dll.ExitProcess
- kernel32.dll.Sleep
- kernel32.dll.GetTickCount
- kernel32.dll.GetProcessHeap
- winscard.dll.SCardIntroduceCardTypeA
- kernel32.dll.OpenProcess
- kernel32.dll.SetLastError
- kernel32.dll.CreateProcessW
- kernel32.dll.lstrlenW
- kernel32.dll.LocalAlloc
- kernel32.dll.GetTempPathW
- kernel32.dll.QueryDosDeviceW
- kernel32.dll.GetFullPathNameW
- kernel32.dll.GetLongPathNameW
- kernel32.dll.GetModuleFileNameW
- kernel32.dll.MoveFileExW
- kernel32.dll.ExpandEnvironmentStringsW
- kernel32.dll.WideCharToMultiByte
- kernel32.dll.MultiByteToWideChar
- kernel32.dll.GetFileAttributesW
- kernel32.dll.GetVersion
- kernel32.dll.GetFileInformationByHandle
- kernel32.dll.CopyFileW
- kernel32.dll.DeleteFileW
- kernel32.dll.IsBadWritePtr
- kernel32.dll.SetFilePointer
- kernel32.dll.CreateToolhelp32Snapshot
- kernel32.dll.Process32FirstW
- kernel32.dll.GetProcessTimes
- kernel32.dll.Process32NextW
- kernel32.dll.GetCurrentProcessId
- kernel32.dll.LoadLibraryExW
- kernel32.dll.FreeLibrary
- kernel32.dll.SetProcessShutdownParameters
- kernel32.dll.TlsAlloc
- kernel32.dll.TlsGetValue
- kernel32.dll.TlsSetValue
- kernel32.dll.GlobalAlloc
- kernel32.dll.GlobalLock
- kernel32.dll.GlobalUnlock
- kernel32.dll.GlobalFree
- kernel32.dll.GetEnvironmentVariableW
- kernel32.dll.GetLocaleInfoW
- kernel32.dll.GetComputerNameW
- kernel32.dll.ReadProcessMemory
- kernel32.dll.FileTimeToLocalFileTime
- kernel32.dll.FileTimeToSystemTime
- kernel32.dll.TerminateProcess
- kernel32.dll.GetCurrentProcess
- kernel32.dll.LoadLibraryW
- kernel32.dll.TryEnterCriticalSection
- kernel32.dll.SetEnvironmentVariableA
- kernel32.dll.CompareStringW
- kernel32.dll.CompareStringA
- kernel32.dll.WriteConsoleW
- kernel32.dll.GetConsoleOutputCP
- kernel32.dll.WriteConsoleA
- kernel32.dll.SetStdHandle
- kernel32.dll.GetConsoleMode
- kernel32.dll.GetConsoleCP
- kernel32.dll.GetStringTypeW
- kernel32.dll.GetStringTypeA
- kernel32.dll.ReadFile
- kernel32.dll.GetLocaleInfoA
- kernel32.dll.GetTimeZoneInformation
- kernel32.dll.GetStartupInfoA
- kernel32.dll.GetFileType
- kernel32.dll.SetHandleCount
- kernel32.dll.GetEnvironmentStringsW
- kernel32.dll.FreeEnvironmentStringsW
- kernel32.dll.IsValidCodePage
- kernel32.dll.GetOEMCP
- kernel32.dll.GetACP
- kernel32.dll.GetModuleFileNameA
- kernel32.dll.GetStdHandle
- kernel32.dll.TlsFree
- kernel32.dll.GetCPInfo
- kernel32.dll.LCMapStringW
- kernel32.dll.LCMapStringA
- kernel32.dll.RtlUnwind
- kernel32.dll.RaiseException
- kernel32.dll.GetStartupInfoW
- kernel32.dll.IsDebuggerPresent
- kernel32.dll.UnhandledExceptionFilter
- kernel32.dll.InterlockedExchange
- kernel32.dll.InterlockedIncrement
- kernel32.dll.DeleteFileA
- kernel32.dll.AreFileApisANSI
- kernel32.dll.GetSystemTime
- kernel32.dll.GetTempPathA
- kernel32.dll.GetVersionExA
- kernel32.dll.OutputDebugStringA
- kernel32.dll.DeleteCriticalSection
- kernel32.dll.GetFileSize
- kernel32.dll.CreateFileW
- kernel32.dll.ExitThread
- kernel32.dll.RemoveVectoredExceptionHandler
- kernel32.dll.GetProcAddress
- kernel32.dll.HeapCreate
- kernel32.dll.GetExitCodeThread
- kernel32.dll.HeapAlloc
- kernel32.dll.WaitForMultipleObjects
- kernel32.dll.SetUnhandledExceptionFilter
- kernel32.dll.SetErrorMode
- kernel32.dll.UnmapViewOfFile
- kernel32.dll.MapViewOfFile
- kernel32.dll.GetFileAttributesExW
- kernel32.dll.GetDiskFreeSpaceA
- kernel32.dll.CreateFileMappingA
- kernel32.dll.GetDiskFreeSpaceW
- kernel32.dll.LockFileEx
- kernel32.dll.HeapSize
- kernel32.dll.FlushFileBuffers
- kernel32.dll.HeapValidate
- kernel32.dll.GetFileAttributesA
- kernel32.dll.HeapDestroy
- kernel32.dll.FormatMessageW
- kernel32.dll.FormatMessageA
- kernel32.dll.UnlockFileEx
- kernel32.dll.OutputDebugStringW
- kernel32.dll.CreateFileMappingW
- kernel32.dll.WaitForSingleObjectEx
- kernel32.dll.LockFile
- kernel32.dll.FlushViewOfFile
- kernel32.dll.GetCurrentThreadId
- kernel32.dll.CreateMutexW
- kernel32.dll.GetCommandLineW
- kernel32.dll.LeaveCriticalSection
- kernel32.dll.EnterCriticalSection
- kernel32.dll.ResetEvent
- kernel32.dll.SetEvent
- kernel32.dll.CreateThread
- kernel32.dll.GetFileSizeEx
- kernel32.dll.GetModuleHandleW
- kernel32.dll.EnumResourceNamesW
- kernel32.dll.CreateEventW
- kernel32.dll.InitializeCriticalSection
- kernel32.dll.GetExitCodeProcess
- kernel32.dll.SetFileAttributesW
- kernel32.dll.WriteFile
- kernel32.dll.WaitForSingleObject
- kernel32.dll.GetLastError
- kernel32.dll.AddVectoredExceptionHandler
- kernel32.dll.VirtualQuery
- kernel32.dll.DeviceIoControl
- kernel32.dll.LocalFree
- kernel32.dll.GetSystemInfo
- kernel32.dll.GetDiskFreeSpaceExW
- kernel32.dll.GetDriveTypeW
- kernel32.dll.GetLogicalDriveStringsW
- kernel32.dll.GlobalMemoryStatusEx
- kernel32.dll.GetSystemTimeAsFileTime
- kernel32.dll.CloseHandle
- kernel32.dll.UnlockFile
- kernel32.dll.HeapFree
- kernel32.dll.QueryPerformanceCounter
- kernel32.dll.SystemTimeToFileTime
- kernel32.dll.SetEndOfFile
- kernel32.dll.HeapCompact
- kernel32.dll.CreateFileA
- kernel32.dll.HeapReAlloc
- kernel32.dll.GetFullPathNameA
- kernel32.dll.ResumeThread
- kernel32.dll.FlushInstructionCache
- kernel32.dll.VirtualFree
- kernel32.dll.InterlockedCompareExchange
- kernel32.dll.SetThreadContext
- kernel32.dll.GetThreadContext
- kernel32.dll.GetFileTime
- kernel32.dll.GetVersionExW
- kernel32.dll.GetVolumeInformationW
- kernel32.dll.GetVolumePathNameW
- kernel32.dll.GetSystemDirectoryW
- kernel32.dll.InterlockedDecrement
- user32.dll.GetSystemMetrics
- user32.dll.LoadCursorW
- user32.dll.MessageBoxW
- user32.dll.KillTimer
- user32.dll.GetCursorPos
- user32.dll.GetParent
- user32.dll.SendDlgItemMessageW
- user32.dll.TranslateMessage
- user32.dll.GetWindowLongW
- user32.dll.SetWindowLongW
- user32.dll.PostQuitMessage
- user32.dll.ReleaseDC
- user32.dll.EndDialog
- user32.dll.SendMessageW
- user32.dll.GetDlgItem
- user32.dll.GetWindowRect
- user32.dll.GetClientRect
- user32.dll.ScreenToClient
- user32.dll.SetWindowPos
- user32.dll.SetParent
- user32.dll.SetWindowTextW
- user32.dll.IsWindowVisible
- user32.dll.ShowWindow
- user32.dll.SetCursor
- user32.dll.TrackMouseEvent
- user32.dll.PostMessageW
- user32.dll.DestroyWindow
- user32.dll.GetDC
- user32.dll.SetRect
- user32.dll.IsDialogMessageW
- user32.dll.AdjustWindowRectEx
- user32.dll.UnregisterClassW
- user32.dll.DispatchMessageW
- user32.dll.GetMessageW
- user32.dll.CreateWindowExW
- user32.dll.RegisterClassExW
- user32.dll.LoadStringW
- user32.dll.CharLowerW
- user32.dll.RedrawWindow
- user32.dll.DefWindowProcW
- user32.dll.BeginPaint
- user32.dll.DrawIconEx
- user32.dll.EndPaint
- user32.dll.GetSysColor
- user32.dll.SetFocus
- user32.dll.LoadImageW
- user32.dll.SetTimer
- user32.dll.EnableWindow
- user32.dll.SetClassLongW
- user32.dll.GetForegroundWindow
- user32.dll.FlashWindow
- user32.dll.AttachThreadInput
- gdi32.dll.StretchDIBits
- gdi32.dll.SetDIBitsToDevice
- gdi32.dll.StretchBlt
- gdi32.dll.BitBlt
- gdi32.dll.SetTextColor
- gdi32.dll.SetBkMode
- gdi32.dll.CreateFontIndirectW
- gdi32.dll.GetStockObject
- gdi32.dll.GetObjectW
- gdi32.dll.DeleteObject
- gdi32.dll.CreateSolidBrush
- gdi32.dll.SelectObject
- gdi32.dll.CreateBitmap
- gdi32.dll.CreateCompatibleDC
- gdi32.dll.GetDeviceCaps
- gdiplus.dll.GdipCreateSolidFill
- gdiplus.dll.GdipDisposeImage
- gdiplus.dll.GdipDeleteGraphics
- gdiplus.dll.GdipDeleteBrush
- gdiplus.dll.GdipDrawImageRectI
- gdiplus.dll.GdipCreateFromHDC
- gdiplus.dll.GdipGetImageHeight
- gdiplus.dll.GdipGetImageWidth
- gdiplus.dll.GdipLoadImageFromStream
- gdiplus.dll.GdipFillRectangleI
- gdiplus.dll.GdiplusShutdown
- gdiplus.dll.GdiplusStartup
- shlwapi.dll.#487
- shlwapi.dll.StrCpyW
- shlwapi.dll.PathCreateFromUrlW
- shlwapi.dll.AssocQueryStringW
- comctl32.dll.InitCommonControlsEx
- comdlg32.dll.GetSaveFileNameW
- advapi32.dll.CryptHashData
- advapi32.dll.ConvertSidToStringSidW
- advapi32.dll.OpenProcessToken
- advapi32.dll.CreateProcessAsUserW
- advapi32.dll.CryptAcquireContextW
- advapi32.dll.CryptCreateHash
- advapi32.dll.CryptReleaseContext
- advapi32.dll.GetUserNameW
- advapi32.dll.SetNamedSecurityInfoW
- advapi32.dll.SetEntriesInAclW
- advapi32.dll.CreateWellKnownSid
- advapi32.dll.AdjustTokenPrivileges
- advapi32.dll.LookupPrivilegeValueW
- advapi32.dll.CopySid
- advapi32.dll.GetLengthSid
- advapi32.dll.GetTokenInformation
- advapi32.dll.RegEnumValueW
- advapi32.dll.RegEnumKeyExW
- advapi32.dll.RegQueryInfoKeyW
- advapi32.dll.RegSetValueExW
- advapi32.dll.RegCreateKeyExW
- advapi32.dll.RegCloseKey
- advapi32.dll.RegQueryValueExW
- advapi32.dll.RegOpenKeyExW
- advapi32.dll.CryptGenRandom
- advapi32.dll.CryptGetHashParam
- advapi32.dll.CryptDestroyHash
- shell32.dll.ShellExecuteW
- shell32.dll.#680
- shell32.dll.CommandLineToArgvW
- shell32.dll.#155
- shell32.dll.SHGetFolderPathW
- shell32.dll.#190
- shell32.dll.SHOpenFolderAndSelectItems
- ole32.dll.CreateStreamOnHGlobal
- ole32.dll.GetHGlobalFromStream
- ole32.dll.CoInitializeSecurity
- ole32.dll.OleSetContainedObject
- ole32.dll.CoSetProxyBlanket
- ole32.dll.CoUninitialize
- ole32.dll.CoCreateInstance
- ole32.dll.CoInitializeEx
- ole32.dll.OleLockRunning
- ole32.dll.OleCreate
- ole32.dll.CoTaskMemFree
- oleaut32.dll.#8
- oleaut32.dll.#6
- oleaut32.dll.#2
- oleaut32.dll.#9
- wininet.dll.InternetCloseHandle
- wininet.dll.InternetQueryOptionW
- wininet.dll.HttpQueryInfoA
- wininet.dll.InternetConnectW
- wininet.dll.InternetSetOptionW
- wininet.dll.InternetOpenW
- wininet.dll.HttpSendRequestW
- wininet.dll.HttpOpenRequestW
- wininet.dll.InternetReadFile
- wininet.dll.HttpQueryInfoW
- powrprof.dll.CallNtPowerInformation
- version.dll.GetFileVersionInfoW
- version.dll.VerQueryValueW
- version.dll.GetFileVersionInfoSizeW
- psapi.dll.GetProcessImageFileNameW
- iphlpapi.dll.GetAdaptersAddresses
- iphlpapi.dll.GetAdaptersInfo
- ws2_32.dll.#57
- ws2_32.dll.#115
- wintrust.dll.CryptCATAdminReleaseCatalogContext
- wintrust.dll.CryptCATCatalogInfoFromContext
- wintrust.dll.CryptCATAdminEnumCatalogFromHash
- wintrust.dll.CryptCATAdminCalcHashFromFileHandle
- wintrust.dll.CryptCATAdminAcquireContext
- wintrust.dll.CryptCATAdminReleaseContext
- crypt32.dll.CertGetNameStringW
- crypt32.dll.CertCloseStore
- crypt32.dll.CryptMsgClose
- crypt32.dll.CertFindCertificateInStore
- crypt32.dll.CertFreeCertificateContext
- crypt32.dll.CryptMsgGetParam
- crypt32.dll.CryptQueryObject
- urlmon.dll.CoInternetParseUrl
- cryptbase.dll.SystemFunction036
- user32.dll.GetWindowInfo
- user32.dll.GetAncestor
- user32.dll.GetMonitorInfoA
- user32.dll.EnumDisplayMonitors
- user32.dll.EnumDisplayDevicesA
- kernel32.dll.SortGetHandle
- kernel32.dll.SortCloseHandle
- dwmapi.dll.DwmIsCompositionEnabled
- gdi32.dll.ExtTextOutW
- gdi32.dll.GdiIsMetaPrintDC
- ntdll.dll.NtQueryInformationProcess
- ntdll.dll.NtCreateUserProcess
- cryptsp.dll.CryptAcquireContextW
- cryptsp.dll.CryptCreateHash
- cryptsp.dll.CryptHashData
- cryptsp.dll.CryptGetHashParam
- cryptsp.dll.CryptDestroyHash
- cryptsp.dll.CryptReleaseContext
- kernel32.dll.GetThreadPreferredUILanguages
- kernel32.dll.SetThreadPreferredUILanguages
- kernel32.dll.LocaleNameToLCID
- kernel32.dll.GetLocaleInfoEx
- kernel32.dll.LCIDToLocaleName
- kernel32.dll.GetSystemDefaultLocaleName
- oleaut32.dll.#283
- oleaut32.dll.#284
- rasapi32.dll.RasConnectionNotificationW
- sechost.dll.NotifyServiceStatusChangeA
- advapi32.dll.RegDeleteTreeA
- advapi32.dll.RegDeleteTreeW
- oleaut32.dll.#500
- gdi32.dll.GetLayout
- gdi32.dll.GdiRealizationInfo
- gdi32.dll.FontIsLinked
- gdi32.dll.GetTextFaceAliasW
- gdi32.dll.GetFontAssocStatus
- advapi32.dll.RegQueryValueExA
- comctl32.dll.RegisterClassNameW
- uxtheme.dll.EnableThemeDialogTexture
- uxtheme.dll.OpenThemeData
- uxtheme.dll.GetThemeBool
- uxtheme.dll.BufferedPaintInit
- uxtheme.dll.BufferedPaintRenderAnimation
- uxtheme.dll.BeginBufferedAnimation
- uxtheme.dll.IsThemeBackgroundPartiallyTransparent
- uxtheme.dll.DrawThemeParentBackground
- uxtheme.dll.DrawThemeBackground
- uxtheme.dll.GetThemeBackgroundContentRect
- uxtheme.dll.DrawThemeText
- uxtheme.dll.EndBufferedAnimation
- uxtheme.dll.CloseThemeData
- uxtheme.dll.BufferedPaintStopAllAnimations
- uxtheme.dll.BufferedPaintUnInit
- ole32.dll.CoGetClassObject
- ole32.dll.CoGetMarshalSizeMax
- ole32.dll.CoMarshalInterface
- ole32.dll.CoUnmarshalInterface
- ole32.dll.StringFromIID
- ole32.dll.CoGetPSClsid
- ole32.dll.CoTaskMemAlloc
- ole32.dll.CoReleaseMarshalData
- ole32.dll.DcomChannelSetHResult
- vssapi.dll.CreateWriter
- advapi32.dll.LookupAccountNameW
- sechost.dll.LookupAccountNameLocalW
- advapi32.dll.LookupAccountSidW
- samcli.dll.NetLocalGroupGetMembers
- samlib.dll.SamConnect
- rpcrt4.dll.NdrClientCall3
- rpcrt4.dll.RpcStringBindingComposeW
- rpcrt4.dll.RpcBindingFromStringBindingW
- rpcrt4.dll.RpcStringFreeW
- rpcrt4.dll.RpcBindingFree
- samlib.dll.SamOpenDomain
- samlib.dll.SamLookupNamesInDomain
- samlib.dll.SamOpenAlias
- samlib.dll.SamFreeMemory
- samlib.dll.SamCloseHandle
- samlib.dll.SamGetMembersInAlias
- netutils.dll.NetApiBufferFree
- samlib.dll.SamEnumerateDomainsInSamServer
- samlib.dll.SamLookupDomainInSamServer
- ole32.dll.CoCreateGuid
- ole32.dll.StringFromCLSID
- oleaut32.dll.#4
- oleaut32.dll.#7
- propsys.dll.VariantToPropVariant
- wbemcore.dll.Reinitialize
- wbemsvc.dll.DllGetClassObject
- wbemsvc.dll.DllCanUnloadNow
- authz.dll.AuthzInitializeContextFromToken
- authz.dll.AuthzInitializeObjectAccessAuditEvent2
- authz.dll.AuthzAccessCheck
- authz.dll.AuthzFreeAuditEvent
- authz.dll.AuthzFreeContext
- authz.dll.AuthzInitializeResourceManager
- authz.dll.AuthzFreeResourceManager
- rpcrt4.dll.RpcBindingCreateW
- rpcrt4.dll.RpcBindingBind
- rpcrt4.dll.I_RpcMapWin32Status
- advapi32.dll.EventRegister
- advapi32.dll.EventUnregister
- advapi32.dll.EventWrite
- kernel32.dll.RegCloseKey
- kernel32.dll.RegSetValueExW
- kernel32.dll.RegOpenKeyExW
- kernel32.dll.RegQueryValueExW
- wmisvc.dll.IsImproperShutdownDetected
- wevtapi.dll.EvtRender
- wevtapi.dll.EvtNext
- wevtapi.dll.EvtClose
- wevtapi.dll.EvtQuery
- wevtapi.dll.EvtCreateRenderContext
- rpcrt4.dll.RpcBindingSetAuthInfoExW
- rpcrt4.dll.RpcBindingSetOption
- ole32.dll.CoCreateFreeThreadedMarshaler
- cryptsp.dll.CryptGenRandom
- kernelbase.dll.InitializeAcl
- kernelbase.dll.AddAce
- sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW
- kernel32.dll.IsThreadAFiber
- sechost.dll.LookupAccountSidLocalW
- kernel32.dll.OpenProcessToken
- kernelbase.dll.GetTokenInformation
- kernelbase.dll.DuplicateTokenEx
- kernelbase.dll.AdjustTokenPrivileges
- kernelbase.dll.AllocateAndInitializeSid
- kernelbase.dll.CheckTokenMembership
- kernel32.dll.SetThreadToken
- oleaut32.dll.#285
- advapi32.dll.RegOpenKeyW
- oleaut32.dll.#12
- oleaut32.dll.#286
- ole32.dll.CLSIDFromString
- oleaut32.dll.#17
- oleaut32.dll.#20
- oleaut32.dll.#19
- oleaut32.dll.#25
- authz.dll.AuthzInitializeContextFromSid
- ole32.dll.CoGetCallContext
- ole32.dll.CoImpersonateClient
- advapi32.dll.OpenThreadToken
- ole32.dll.CoRevertToSelf
- ole32.dll.CoSwitchCallContext
- Show More 491
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
- HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
- HKEY_CURRENT_USER\Software\Classes
-
- HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
- HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
- HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
- HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\____________________________________________
- HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
- HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\Tracing\WMI
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\SessionEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Level
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AreaFlags
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\Session
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\BufferSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MinimumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumBuffers
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\MaximumFileSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\LogFileMode
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\FlushTimer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Tracing\WMI\AgeLimit
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable
- HKEY_LOCAL_MACHINE\SYSTEM\Setup
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeInProgress
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
- HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Settings
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\ActiveWriterStateTimeout
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\WMI Writer
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Settings\TornComponentsMax
- HKEY_LOCAL_MACHINE\Software\Classes
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9555-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{609B9557-4FB6-11D1-9971-00C04FBBB345}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\QueryLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\PathLimit
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbThrottlingEnabled
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighMaxLimitFactor
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbTaskMaxSleep
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold1Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold2Mult
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ArbSystemHighThreshold3Mult
- HKEY_LOCAL_MACHINE\system\Setup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Unchecked Task Count
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Working Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Build
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Logging Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\MOF Self-Install Directory
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Default Repository Driver
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueCoreFsrepVersion
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Repository Cache Spill Ratio
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckPointValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SnapShotValue
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\CheckRepositoryOnNextStartup
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NumWriteIdCheck
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Size
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Class Cache Item Age (ms)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\NextAutoRecoverFile
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Enable Provider Subsystem
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{07B00B8A-8D78-444F-9EF6-F5BA82100A47}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{386BAD19-A129-470E-A6DB-5FE177FEE62D}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{94426C32-71C4-410A-A095-79082150EAC0}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\Provider
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\Scope
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\Locale
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\User
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Client\{B7849844-D1EB-4894-8831-991E426E120D}\ProcessIdentifier
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\EnableEvents
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssToBeInitialized
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Low Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\High Threshold On Events (B)
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Wait On Events (ms)
- HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\ESS
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Merger Query Arbitration Enabled
- HKEY_LOCAL_MACHINE\software\microsoft\wbem\cimom
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\SetupDate
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Async Result Queue Size
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/subscription
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\SecurityCenter2
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\CIMOM
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerBatchSize
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ClientCallbackTimeout
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\FinalizerQueueThreshold
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\Max Tasks
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
- HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
- HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InProcServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\(Default)
- HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\LocalServer32
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\ThreadingModel
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\InprocServer32\Synchronization
- HKEY_CLASSES_ROOT\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\(Default)
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{661FF7F6-F4D1-4593-B59D-4C54C1ECE68B}\AppId
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
- HKEY_LOCAL_MACHINE\system\currentcontrolset\control\minint
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\Root
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\Root
- Show More 264
- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
- C:\Users\user\AppData\Local\Temp\54f7533b1a92b258e7cd1a93f4fcb1a654d121b1.exe
- C:\Windows\System32\en-US\wuapi.dll.mui
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Windows\System32\comres.dll
-
- C:\Windows\System32\en-US\comres.DLL.mui
- C:\Windows\Fonts\staticcache.dat
- C:\Windows\System32\imageres.dll
- \??\PIPE\samr
- C:\Windows\sysnative\wbem\repository\MAPPING1.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING2.MAP
- C:\Windows\sysnative\wbem\repository\MAPPING3.MAP
- C:\Windows\sysnative\wbem\repository\OBJECTS.DATA
- C:\Windows\sysnative\wbem\repository\INDEX.BTR
- \??\pipe\PIPE_EVENTROOT\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER
- \??\pipe\PIPE_EVENTROOT\CIMV2PROVIDERSUBSYSTEM
- Show More 11
- IESQMMUTEX_0_208
- CicLoadWinStaWinSta0
- Local\MSCTF.CtfMonitorInstMutexDefault1
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\LastServiceStart
- HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Transports\Decoupled\Server
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\CreationTime
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\MarshaledProxy
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Transports\Decoupled\Server\ProcessIdentifier
-
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM\List of event-active namespaces
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ESS\//./root/CIMV2\SCM Event Provider
- Show More 3