What's new

Dissecting the new Mark 8 E-Meter updater software

CommunicatorIC

@IndieScieNews on Twitter
Be sure to see the WWP thread:

Dissecting the new Mark 8 E-Meter updater software
https://whyweprotest.net/community/...e-new-mark-8-e-meter-updater-software.115310/

It has vital and updating information.


Code:
https://www.hubbarde-meter.org/download.html
So... Who wants to download the Mark 8 updater software and stick it under a microscope? (Downloading the exe is safe, but for the love of Xenu, don't run it! Only run it inside a secure virtual box or a clean stand-alone box that you scrub afterward.

The update installer is 23.4M. I'm surprised (and very suspicious) that they let you download it without logging in on their site first.

I think Admiral Ackbar said it best...

The main question is: What else does it install besides E-meter updater? 50-ish MB expanded seem damned big for updating their new toaster.

More Clam Nanny filtering software? A rootkit for a Scienobotnet?
Watch it... When you run the program, it will send some shit:



grmwalp-png.215921

oimiwh7-png.215923


The chrome.pak file has copyright from Apple software? This is some crazy shit


img-png.215924

First part of the chrome.pak file. Seems like it's a HTML file?


http://pastebin.com/1Kz7Sz57
That's a very good observation! Before using the Mark VIII, it needs registering first (like you implied):


fraiklk-png.215979






It indeed checks if the IAS number is active (IAS membership starts at $500 a year). If not:


3rbn3uu-png.215980






How great would it be if the Virus companies mark this as a virus, and everyone gets an Virus popup when they are trying to register the E-meter. That would be epic!

This one is also interesting:


Detects if Device Softwar is installed



1,6MB!!!


1ipak9p-png.215981




Anubis report:
http://anubis.iseclab.org/?action=r...21bdd65059c34d1e8febfaf944443&format=html


It reports all kind of shit. Creating Internet Explorer keys, Deleting Internet explorer keys and more.

u4wglq2-png.215984




Detects if software is installed


Yet it uses the Winsock libraries to connect to the internet and send data. Someone really needs to run Wireshark on this mofo.
 

CommunicatorIC

@IndieScieNews on Twitter
https://whyweprotest.net/community/...r-updater-software.115310/page-2#post-2390181
DeathHamster said:
The patent schematics are over here, plus info on when they were built (2004):
https://whyweprotest.net/community/...years-in-storage-patent-diagrams-2012.111248/

It's a shame it's in rubbish little diagrams. I want the whole thing up on the wall to see it.​
Based around a flashable Renesas part:



http://www.digikey.co.uk/product-detail/en/M30624FGAFP#U3/M30624FGAFP#U3-ND/1090605



Overkill for a glorified wheatstone bridge, I would say - 100pin QFP package!


There's a Maxim serial level shifter part, as one would expect.


Utterly trivial circuit. I could knock that up in an afternoon.
 

Techless

Patron Meritorious
Would be very interesting to find out what all the 'abundant' code is.

The damn thing certainly didn't really 'need' to be fitted with a microprocessor/internet hookup...unless there's something a lot more sinister going on.

I'd bet money on it.
 

freethinker

Sponsor
So basicly what has been dissected over at WWP is that the meter does nothing, as is the legal claim, but enforces IAS membership and will disable the meter if IAS isn't up to date but it would probably run just fine beyond the expiration because it's not the e-meter that needs updating it's the membership.

This is religious enslavement at its finest: You don't pay, You don't play.

Oh and your tech guys discerned that it is a clusterfuck of program writing incorporating unused with latest program parameters and the program was a ripp-off and repurpose program that may still be under copyright that the CO$ probably didn'ty pay for.

The new Mark Super VIII is a Coercion Meter but wholly/holy religious as it forces parishioners to pay up and get their fix.
 

aegerprimo

Summa Cum Laude
So basicly what has been dissected over at WWP is that the meter does nothing, as is the legal claim, but enforces IAS membership and will disable the meter if IAS isn't up to date but it would probably run just fine beyond the expiration because it's not the e-meter that needs updating it's the membership.

This is religious enslavement at its finest: You don't pay, You don't play.

Oh and your tech guys discerned that it is a clusterfuck of program writing incorporating unused with latest program parameters and the program was a ripp-off and repurpose program that may still be under copyright that the CO$ probably didn'ty pay for.

The new Mark Super VIII is a Coercion Meter but wholly/holy religious as it forces parishioners to pay up and get their fix.
I read on WWP that the new e-meter makes toast with the image of Xenu! Pic proves it....
.
ezbake_toaster-jpg.215907
 

CommunicatorIC

@IndieScieNews on Twitter
So basicly what has been dissected over at WWP is that the meter does nothing, as is the legal claim, but enforces IAS membership and will disable the meter if IAS isn't up to date but it would probably run just fine beyond the expiration because it's not the e-meter that needs updating it's the membership.

This is religious enslavement at its finest: You don't pay, You don't play.

Oh and your tech guys discerned that it is a clusterfuck of program writing incorporating unused with latest program parameters and the program was a ripp-off and repurpose program that may still be under copyright that the CO$ probably didn'ty pay for.

The new Mark Super VIII is a Coercion Meter but wholly/holy religious as it forces parishioners to pay up and get their fix.
There is another important issue.

That issue is the extent to which the updater software acts as spyware. (Anyone remember the Scientology Net Nanny?) It appears nobody has an answer -- yet -- but it also appears people on WWP are working on it.

Note the below, excerpted from above.

quote_icon.png
Originally Posted by Anonymous, post: 2389734, member: 10537
Watch it... When you run the program, it will send some shit:



grmwalp-png.215921
!
quote_icon.png
Originally Posted by Anonymous, post: 2389920, member: 10537
This one is also interesting:


Detects if Device Softwar is installed



1,6MB!!!


1ipak9p-png.215981




Anubis report:
http://anubis.iseclab.org/?action=re...mp;format=html


It reports all kind of shit. Creating Internet Explorer keys, Deleting Internet explorer keys and more.
quote_icon.png
Originally Posted by Anonymous, post: 2389983, member: 10537
u4wglq2-png.215984




Detects if software is installed


Yet it uses the Winsock libraries to connect to the internet and send data. Someone really needs to run Wireshark on this mofo.
 

NoName

A Girl Has No Name
So basicly what has been dissected over at WWP is that the meter does nothing, as is the legal claim, but enforces IAS membership and will disable the meter if IAS isn't up to date but it would probably run just fine beyond the expiration because it's not the e-meter that needs updating it's the membership.

This is religious enslavement at its finest: You don't pay, You don't play.

Oh and your tech guys discerned that it is a clusterfuck of program writing incorporating unused with latest program parameters and the program was a ripp-off and repurpose program that may still be under copyright that the CO$ probably didn'ty pay for.

The new Mark Super VIII is a Coercion Meter but wholly/holy religious as it forces parishioners to pay up and get their fix.

It would be interesting to find out if this is the case. And what sort of anti-piracy award might be available for concerned citizens who report piracy.

:drama:
 

Idle Morgue

Gold Meritorious Patron
My guess of why one has to download software and connect to "source"...:whistling:Everything Scientology does is for maximum profit and maximum control of the clubbed seals!

The Cult of Scientology will be monitoring your every move with this new E-Meter - :coolwink: when you download your software - it will download a "SPY Ware" undectable by any firewalls...which will report to clubbed seals everything you look at on the internet.

Alarms will fire off at the INT BASE when you look at any "entheta" on the internet...and the local Org will be notified of your defection. E/O's will be instructed to immediately issue an SP Declare and all family and friends will be ordered to disconnect.

A letter will be sent to the defector commanding intention to the fact that "out ethics" have been reported and one must schedule an appointment at FLAG - they will not be allowed back to their local morgue!

If they ever make it to FLAG - some heavy "regging" in the MAA's office will be part of their program.

This should keep all clubbed seals...clubbed whilst maximizing the ultimate profit for the CULT of Scientology!:ohmy:
 

CommunicatorIC

@IndieScieNews on Twitter
https://whyweprotest.net/community/...e-meter-updater-software.115310/#post-2389777

When running the program it will create several files and folders in the TEMP folder:


shkziib-png.215947




Some of the content in the Data_3 temporary file:


vqauhqj-png.215948




Some of the content of the Data_2 temporary file:



a8egvpk-png.215949





Some of the content of the Data_1 temporary file:

he0zkpz-png.215954




So it seems like the GUI is on the hubbard site. So why is the installation 25MB? It also sends statistics information to the Google Analystics site (visitor information)
 

CommunicatorIC

@IndieScieNews on Twitter
https://whyweprotest.net/community/...e-meter-updater-software.115310/#post-2389760

It seems to be part of Chromiumembedded project stuff.


On native Windows apps, if you want to display HTML (and CSS, Javascript, etc, etc...) the option was that you had to use a control which is a gateway to Microsoft IE. That sucks donkey balls for a number of reasons. (Don't get me started when I'm suffering from PCS [Pre-Coffee Syndrome].)


Chromiumembedded is a framework to allow native apps to do the same with the Chrome browser.


So... This install has probably added either an embedded or full-up version of the Chrome browser to the system. Heck, that might explain the damned install size right there!
cool.png




The phone-home stuff is going to Scientology via their expensive Akamai proxying service. It would be nice to know what it sent.



LOL at the serial/USB dongle. I guess they really didn't have another option after the meters rotted in boxes for all these years.


Two suggestions:

  1. Check to see if there are any extra processes running. (I use Process Explorer by Mark Russinovich via Microsoft, but Task Manager might do in a pinch.)
  2. Were any start-up programs added?
Good stuff Anonymous!
 

CommunicatorIC

@IndieScieNews on Twitter
It seems like the program supposedly designed only to "update" one's Mark 8 E-Meter makes quite a few changes to one's computer, doesn't it?

https://whyweprotest.net/community/...e-meter-updater-software.115310/#post-2389799


http://pastebin.com/qBNcTxue



  1. [#############################################################################]
    Analysis Report for m8update.exe
    MD5: 4636c552cfeb57a03e7601c173af8f4e
    [#############################################################################]


    [=============================================================================]
    Table of Contents
    [=============================================================================]

    - General information
    - m8update.e.exe
    a) Registry Activities
    b) File Activities
    c) Process Activities
    d) Other Activities
    - DW20.EXE
    a) Registry Activities
    b) File Activities
    c) Process Activities


    [#############################################################################]
    1. General Information
    [#############################################################################]
    [=============================================================================]
    Information about Anubis' invocation
    [=============================================================================]
    Time needed: 256 s
    Report created: 11/27/13, 13:13:43 UTC
    Termination reason: Timeout
    Program version: 1.76.3886


    [#############################################################################]
    2. m8update.e.exe
    [#############################################################################]
    [=============================================================================]
    General information about this executable
    [=============================================================================]
    Analysis Reason: Primary Analysis Subject
    Filename: m8update.e.exe
    MD5: 4636c552cfeb57a03e7601c173af8f4e
    SHA-1: 49c70c460f102a07866222eb87b3997895d15eee
    File Size: 290104 Bytes
    Process-status
    at analysis end: alive
    Exit Code: 0

    [=============================================================================]
    Load-time Dlls
    [=============================================================================]
    Module Name: [ C:\WINDOWS\system32\ntdll.dll ],
    Base Address: [0x7C900000 ], Size: [0x000AF000 ]
    Module Name: [ C:\WINDOWS\system32\mscoree.dll ],
    Base Address: [0x79000000 ], Size: [0x0004A000 ]
    Module Name: [ C:\WINDOWS\system32\KERNEL32.dll ],
    Base Address: [0x7C800000 ], Size: [0x000F6000 ]
    Module Name: [ C:\WINDOWS\system32\ADVAPI32.dll ],
    Base Address: [0x77DD0000 ], Size: [0x0009B000 ]
    Module Name: [ C:\WINDOWS\system32\RPCRT4.dll ],
    Base Address: [0x77E70000 ], Size: [0x00092000 ]
    Module Name: [ C:\WINDOWS\system32\Secur32.dll ],
    Base Address: [0x77FE0000 ], Size: [0x00011000 ]
    Module Name: [ C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll ],
    Base Address: [0x603B0000 ], Size: [0x00066000 ]
    Module Name: [ C:\WINDOWS\system32\SHLWAPI.dll ],
    Base Address: [0x77F60000 ], Size: [0x00076000 ]
    Module Name: [ C:\WINDOWS\system32\GDI32.dll ],
    Base Address: [0x77F10000 ], Size: [0x00049000 ]
    Module Name: [ C:\WINDOWS\system32\USER32.dll ],
    Base Address: [0x7E410000 ], Size: [0x00091000 ]
    Module Name: [ C:\WINDOWS\system32\msvcrt.dll ],
    Base Address: [0x77C10000 ], Size: [0x00058000 ]
    Module Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll ],
    Base Address: [0x79E70000 ], Size: [0x0058F000 ]
    Module Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll ],
    Base Address: [0x78130000 ], Size: [0x0009B000 ]
    Module Name: [ C:\WINDOWS\system32\shell32.dll ],
    Base Address: [0x7C9C0000 ], Size: [0x00817000 ]
    Module Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll ],
    Base Address: [0x773D0000 ], Size: [0x00103000 ]
    Module Name: [ C:\WINDOWS\system32\comctl32.dll ],
    Base Address: [0x5D090000 ], Size: [0x0009A000 ]
    Module Name: [ C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\642534209e13d16e93b80a628742d2ee\mscorlib.ni.dll ],
    Base Address: [0x790C0000 ], Size: [0x00B36000 ]
    Module Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll ],
    Base Address: [0x64020000 ], Size: [0x00013000 ]
    Module Name: [ C:\WINDOWS\system32\WINTRUST.dll ],
    Base Address: [0x76C30000 ], Size: [0x0002E000 ]
    Module Name: [ C:\WINDOWS\system32\CRYPT32.dll ],
    Base Address: [0x77A80000 ], Size: [0x00095000 ]
    Module Name: [ C:\WINDOWS\system32\MSASN1.dll ],
    Base Address: [0x77B20000 ], Size: [0x00012000 ]
    Module Name: [ C:\WINDOWS\system32\IMAGEHLP.dll ],
    Base Address: [0x76C90000 ], Size: [0x00028000 ]
    Module Name: [ C:\WINDOWS\system32\RichEd20.dll ],
    Base Address: [0x74E30000 ], Size: [0x0006D000 ]
    Module Name: [ C:\WINDOWS\system32\rsaenh.dll ],
    Base Address: [0x68000000 ], Size: [0x00036000 ]
    Module Name: [ C:\WINDOWS\system32\xpsp2res.dll ],
    Base Address: [0x00EE0000 ], Size: [0x002C5000 ]
    Module Name: [ C:\WINDOWS\system32\userenv.dll ],
    Base Address: [0x769C0000 ], Size: [0x000B4000 ]
    Module Name: [ C:\WINDOWS\system32\VERSION.dll ],
    Base Address: [0x77C00000 ], Size: [0x00008000 ]
    Module Name: [ C:\WINDOWS\system32\netapi32.dll ],
    Base Address: [0x5B860000 ], Size: [0x00055000 ]
    Module Name: [ C:\WINDOWS\system32\cryptnet.dll ],
    Base Address: [0x75E60000 ], Size: [0x00013000 ]
    Module Name: [ C:\WINDOWS\system32\PSAPI.DLL ],
    Base Address: [0x76BF0000 ], Size: [0x0000B000 ]
    Module Name: [ C:\WINDOWS\system32\SensApi.dll ],
    Base Address: [0x722B0000 ], Size: [0x00005000 ]
    Module Name: [ C:\WINDOWS\system32\WINHTTP.dll ],
    Base Address: [0x4D4F0000 ], Size: [0x00059000 ]
    Module Name: [ C:\WINDOWS\system32\WLDAP32.dll ],
    Base Address: [0x76F60000 ], Size: [0x0002C000 ]
    Module Name: [ C:\WINDOWS\system32\ole32.dll ],
    Base Address: [0x774E0000 ], Size: [0x0013D000 ]
    Module Name: [ C:\WINDOWS\system32\MSCTF.dll ],
    Base Address: [0x74720000 ], Size: [0x0004C000 ]
    Module Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll ],
    Base Address: [0x79060000 ], Size: [0x00056000 ]
    Module Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\culture.dll ],
    Base Address: [0x60340000 ], Size: [0x00008000 ]
    Module Name: [ C:\WINDOWS\system32\Apphelp.dll ],
    Base Address: [0x77B40000 ], Size: [0x00022000 ]

    [=============================================================================]
    2.a) m8update.e.exe - Registry Activities
    [=============================================================================]
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Registry Values Modified:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders ],
    Value Name: [ AppData ], New Value: [ C:\Documents and Settings\Administrator\Application Data ]
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders ],
    Value Name: [ Cache ], New Value: [ C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Registry Values Read:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Accessibility,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ CustomMarshalers,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ IEExecRemote,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ IEHost,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ IIEHost,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.0.5000.0" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ ISymWrapper,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Build.Conversion.v3.5,version="3.5.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Build.Engine,version="3.5.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Build.Framework,version="3.5.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Build.Tasks.v3.5,version="3.5.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Build.Utilities.v3.5,version="3.5.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.JScript,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Transactions.Bridge,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b03f5f7f11d50a3a",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Transactions.Bridge.Dtc,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b03f5f7f11d50a3a",ProcessorArchitecture="x86",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.VisualBasic,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.VisualBasic.Vsa,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.VisualC,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.VisualC.STLCLR,version="1.0.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="9.0.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Vsa,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft.Vsa.Vb.CodeDOMProcessor,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Microsoft_VsaVb,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationBuildTasks,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationBuildTasks,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationCFFRasterizer,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationCFFRasterizer,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationCore,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="x86",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationCore,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="x86",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Aero,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Aero,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Classic,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Classic,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Luna,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Luna,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Royale,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationFramework.Royale,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationUI,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ PresentationUI,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ ReachFramework,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ ReachFramework,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ Regcode,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ SMDiagnostics,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b77a5c561934e089",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System,Version="1.0.5000.0",PublicKeyToken="b77a5c561934e089",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.AddIn,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.AddIn.Contract,version="2.0.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Configuration.Install,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Core,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Data,Version="1.0.5000.0",PublicKeyToken="b77a5c561934e089",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Data.DataSetExtensions,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Data.Linq,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Data.OracleClient,Version="1.0.5000.0",PublicKeyToken="b77a5c561934e089",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Design,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.DirectoryServices,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.DirectoryServices.AccountManagement,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Drawing,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Drawing.Design,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.EnterpriseServices,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.IO.Log,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b03f5f7f11d50a3a",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.IdentityModel,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b77a5c561934e089",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.IdentityModel.Selectors,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b77a5c561934e089",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Management,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Management.Instrumentation,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Messaging,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Net,version="3.5.0.0",publicKeyToken="b03f5f7f11d50a3a",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Printing,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="x86",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Printing,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="x86",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Runtime.Remoting,Version="1.0.5000.0",PublicKeyToken="b77a5c561934e089",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Runtime.Serialization,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b77a5c561934e089",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Runtime.Serialization.Formatters.Soap,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Security,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.ServiceModel,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b77a5c561934e089",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.ServiceModel.Install,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b77a5c561934e089",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.ServiceModel.WasHosting,Version="3.0.0.0",Culture="neutral",PublicKeyToken="b77a5c561934e089",ProcessorArchitecture="MSIL",FileVersion="3.0.4506.648" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.ServiceModel.Web,version="3.5.0.0",publicKeyToken="31bf3856ad364e35",processorArchitecture="MSIL",fileVersion="3.5.594.0",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.ServiceProcess,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Speech,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Speech,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Web,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Web.Extensions,version="3.5.0.0",publicKeyToken="31bf3856ad364e35",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Web.Extensions.Design,version="3.5.0.0",publicKeyToken="31bf3856ad364e35",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Web.Mobile,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Web.RegularExpressions,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Web.Services,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Windows.Forms,Version="1.0.5000.0",PublicKeyToken="b77a5c561934e089",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Windows.Presentation,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Workflow.Activities,processorArchitecture="MSIL",publicKeyToken="31BF3856AD364E35",culture="neutral",version="3.0.0.000000",fileVersion="3.0.4203.835" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Workflow.ComponentModel,processorArchitecture="MSIL",publicKeyToken="31BF3856AD364E35",culture="neutral",version="3.0.0.000000",fileVersion="3.0.4203.835" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Workflow.Runtime,processorArchitecture="MSIL",publicKeyToken="31BF3856AD364E35",culture="neutral",version="3.0.0.000000",fileVersion="3.0.4203.835" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.WorkflowServices,version="3.5.0.0",publicKeyToken="31bf3856ad364e35",processorArchitecture="MSIL",fileVersion="3.5.594.0",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Xml,Version="1.0.5000.0",PublicKeyToken="b77a5c561934e089",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ System.Xml.Linq,version="3.5.0.0",publicKeyToken="b77a5c561934e089",processorArchitecture="MSIL",fileVersion="3.5.21022.8",culture="neutral" ], Value: [ 0x70002100560045003300360030004b00630034004b006a00540044003400 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationClient,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationClient,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationClientsideProviders,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationClientsideProviders,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationProvider,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationProvider,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationTypes,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ UIAutomationTypes,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ WindowsBase,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ WindowsBase,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ WindowsFormsIntegration,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.0" ], Value: [ 0x29006d0066002a0065005d0061006b007b0040004f0069006c0024005700 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ WindowsFormsIntegration,Version="3.0.0.0",Culture="neutral",PublicKeyToken="31bf3856ad364e35",ProcessorArchitecture="MSIL",FileVersion="3.0.6920.1109" ], Value: [ 0x6a0025006c0024003200790062006300690035004b00290075006a005100 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ cscompmgd,Version="7.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="7.10.3052.4" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Classes\Installer\Assemblies\Global ],
    Value Name: [ mscorcfg,Version="1.0.5000.0",PublicKeyToken="b03f5f7f11d50a3a",Culture="neutral",FileVersion="1.1.4322.573" ], Value: [ 0x250045006d0041006a003f00430025006b0039005700370063004e004200 ], 1 time
    Key: [ HKLM\SOFTWARE\Microsoft\CTF\SystemShared\ ],
    Value Name: [ CUAS ], Value: [ 0 ], 1 time
    Key: [ HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001 ],
    Value Name: [ Name ], Value: [ Microsoft Strong Cryptographic Provider ], 4 times
    Key: [ HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider ],
    Value Name: [ Image Path ], Value: [ rsaenh.dll ], 4 times
    Key: [ HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider ],
    Value Name: [ Type ], Value: [ 1 ], 1 time
    Key: [ HKLM\SOFTWARE\Microsoft\PCHealth\ErrorReporting ],
    Value Name: [ AllOrNone ], Value: [ 1 ], 1 time
    Key: [ HKLM\SOFTWARE\Microsoft\PCHealth\ErrorReporting ],
    Value Name: [ DoReport ], Value: [ 1 ], 1 time
    Key: [ HKLM\SOFTWARE\Microsoft\PCHealth\ErrorReporting ],
    Value Name: [ ShowUI ], Value: [ 1 ], 1 time
    Key: [ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager ],
    Value Name: [ CriticalSectionTimeout ], Value: [ 2592000 ], 1 time
    Key: [ HKLM\SYSTEM\Setup ],
    Value Name: [ SystemSetupInProgress ], Value: [ 0 ], 1 time
    Key: [ HKLM\SYSTEM\WPA\MediaCenter ],
    Value Name: [ Installed ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Microsoft\.NETFramework ],
    Value Name: [ InstallRoot ], Value: [ C:\WINDOWS\Microsoft.NET\Framework\ ], 9 times
    Key: [ HKLM\Software\Microsoft\.NETFramework\Policy\\v4.0 ],
    Value Name: [ 30319 ], Value: [ 30319-30319 ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography ],
    Value Name: [ MachineGuid ], Value: [ 4604e8cc-5b9c-4ffb-a374-a62e6d0494fc ], 4 times
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 ],
    Value Name: [ Dll ], Value: [ cryptnet.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 ],
    Value Name: [ FuncName ], Value: [ LdapProvOpenStore ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap ],
    Value Name: [ Dll ], Value: [ cryptnet.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap ],
    Value Name: [ FuncName ], Value: [ LdapProvOpenStore ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046} ],
    Value Name: [ Dll ], Value: [ MSISIP.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{000C10F1-0000-0000-C000-000000000046} ],
    Value Name: [ FuncName ], Value: [ MsiSIPGetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ FuncName ], Value: [ GetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB} ],
    Value Name: [ FuncName ], Value: [ GetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ FuncName ], Value: [ GetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPGetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPGetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPGetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPGetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPGetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPGetSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046} ],
    Value Name: [ Dll ], Value: [ MSISIP.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{000C10F1-0000-0000-C000-000000000046} ],
    Value Name: [ FuncName ], Value: [ MsiSIPPutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{06C9E010-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ FuncName ], Value: [ PutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB} ],
    Value Name: [ FuncName ], Value: [ PutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{1A610570-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ FuncName ], Value: [ PutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPPutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB8-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPPutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AAB9-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPPutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{C689AABA-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPPutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A42-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPPutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{DE351A43-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPPutSignedDataMsg ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046} ],
    Value Name: [ Dll ], Value: [ MSISIP.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{000C10F1-0000-0000-C000-000000000046} ],
    Value Name: [ FuncName ], Value: [ MsiSIPVerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{06C9E010-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ FuncName ], Value: [ VerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB} ],
    Value Name: [ FuncName ], Value: [ VerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ Dll ], Value: [ C:\WINDOWS\system32\wshext.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{1A610570-38CE-11D4-A2A3-00104BD35090} ],
    Value Name: [ FuncName ], Value: [ VerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPVerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB8-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPVerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB9-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AAB9-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPVerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{C689AABA-8E78-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPVerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A42-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPVerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{DE351A43-8E59-11D0-8C47-00C04FC295EE} ],
    Value Name: [ FuncName ], Value: [ CryptSIPVerifyIndirectData ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyRevocation\DEFAULT ],
    Value Name: [ Dll ], Value: [ 0x630072007900700074006e00650074002e0064006c006c0000000000 ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 ],
    Value Name: [ FuncName ], Value: [ EssReceiptDecodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 ],
    Value Name: [ FuncName ], Value: [ EssReceiptRequestDecodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 ],
    Value Name: [ FuncName ], Value: [ EssKeyExchPreferenceDecodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 ],
    Value Name: [ FuncName ], Value: [ EssSignCertificateDecodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 ],
    Value Name: [ FuncName ], Value: [ EssSecurityLabelDecodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 ],
    Value Name: [ FuncName ], Value: [ EssMLHistoryDecodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 ],
    Value Name: [ FuncName ], Value: [ EssContentHintDecodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2000 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpAgencyInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2001 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcMinimalCriteriaInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2002 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcFinancialCriteriaInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2003 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcIndirectDataContentDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2004 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcPeImageDataDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2005 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2006 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcStatementTypeDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2007 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpOpusInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2008 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2009 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2130 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSigInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2221 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatNameValueDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\#2222 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatMemberInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.1 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatNameValueDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.12.2.2 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatMemberInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1 ],
    Value Name: [ Dll ], Value: [ cryptdlg.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.1.1 ],
    Value Name: [ FuncName ], Value: [ DecodeAttrSequence ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4 ],
    Value Name: [ Dll ], Value: [ cryptdlg.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.16.4 ],
    Value Name: [ FuncName ], Value: [ DecodeRecipientID ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.10 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpAgencyInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.11 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcStatementTypeDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.12 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpOpusInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.15 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcPeImageDataDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.20 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.25 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.26 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcMinimalCriteriaInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.27 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcFinancialCriteriaInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.28 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.30 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSigInfoDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObject\1.3.6.1.4.1.311.2.1.4 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcIndirectDataContentDecode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 ],
    Value Name: [ FuncName ], Value: [ EssReceiptEncodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 ],
    Value Name: [ FuncName ], Value: [ EssReceiptRequestEncodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 ],
    Value Name: [ FuncName ], Value: [ EssKeyExchPreferenceEncodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 ],
    Value Name: [ FuncName ], Value: [ EssSignCertificateEncodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 ],
    Value Name: [ FuncName ], Value: [ EssSecurityLabelEncodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 ],
    Value Name: [ FuncName ], Value: [ EssMLHistoryEncodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 ],
    Value Name: [ Dll ], Value: [ inetcomm.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 ],
    Value Name: [ FuncName ], Value: [ EssContentHintEncodeEx ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2000 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2000 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpAgencyInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2001 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2001 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcMinimalCriteriaInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2002 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2002 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcFinancialCriteriaInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2003 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2003 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcIndirectDataContentEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2004 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2004 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcPeImageDataEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2005 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2005 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2006 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2006 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcStatementTypeEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2007 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2007 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpOpusInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2008 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2008 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2009 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2009 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2130 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2130 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSigInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2221 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2221 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatNameValueEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2222 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\#2222 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatMemberInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.12.2.1 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.12.2.1 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatNameValueEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.12.2.2 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.12.2.2 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1CatMemberInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1 ],
    Value Name: [ Dll ], Value: [ cryptdlg.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.1.1 ],
    Value Name: [ FuncName ], Value: [ EncodeAttrSequence ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.4 ],
    Value Name: [ Dll ], Value: [ cryptdlg.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.16.4 ],
    Value Name: [ FuncName ], Value: [ EncodeRecipientID ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.10 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.10 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpAgencyInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.11 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.11 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcStatementTypeEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.12 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.12 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSpOpusInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.15 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcPeImageDataEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.20 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.20 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.25 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.25 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.26 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.26 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcMinimalCriteriaInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.27 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.27 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcFinancialCriteriaInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.28 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.28 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcLinkEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.30 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.30 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcSigInfoEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.4 ],
    Value Name: [ Dll ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObject\1.3.6.1.4.1.311.2.1.4 ],
    Value Name: [ FuncName ], Value: [ WVTAsn1SpcIndirectDataContentEncode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $Function ], Value: [ SoftpubCheckCert ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $Function ], Value: [ SoftpubCheckCert ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $Function ], Value: [ WintrustCertificateTrust ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $Function ], Value: [ WintrustCertificateTrust ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $Function ], Value: [ SoftpubCleanup ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $Function ], Value: [ SoftpubAuthenticode ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $DLL ], Value: [ mscorsec.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $Function ], Value: [ CORPolicyEE ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $Function ], Value: [ SoftpubInitialize ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Initialization\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Initialization\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $Function ], Value: [ SoftpubInitialize ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $Function ], Value: [ SoftpubLoadMessage ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Message\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Message\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $Function ], Value: [ SoftpubLoadMessage ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE} ],
    Value Name: [ $Function ], Value: [ SoftpubLoadSignature ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Signature\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $DLL ], Value: [ WINTRUST.DLL ], 1 time
    Key: [ HKLM\Software\Microsoft\Cryptography\Providers\Trust\Signature\{31D1ADC1-D329-11D1-8ED8-0080C76516C6} ],
    Value Name: [ $Function ], Value: [ SoftpubLoadSignature ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\GACChangeNotification\Default ],
    Value Name: [ mscorlib,2.0.0.0,,b77a5c561934e089,x86 ], Value: [ 0xa8ce1d9f20cfcb01 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32 ],
    Value Name: [ LatestIndex ], Value: [ 117 ], 3 times
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\319545b3\8 ],
    Value Name: [ DisplayName ], Value: [ mscorlib,2.0.0.0,,b77a5c561934e089 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\319545b3\8 ],
    Value Name: [ LastModTime ], Value: [ 0xa8ce1d9f20cfcb01 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\319545b3\8 ],
    Value Name: [ Modules ], Value: [ sortkey.nlp|sorttbls.nlp|big5.nlp|bopomofo.nlp|ksc.nlp|prc.nlp|prcp.nlp|xjis.nlp|normidna.nlp|normnfc.nlp|normnfd.nlp|normnfkc.nlp|normnfkd.nlp ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\319545b3\8 ],
    Value Name: [ SIG ], Value: [ 0x61498a5bb093b143a337bdf5962ece99bd6c58fc8f03105a020331f4a600 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\IL\7950e2c5\319545b3\8 ],
    Value Name: [ Status ], Value: [ 8198 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\3c74e9a9\8 ],
    Value Name: [ ConfigMask ], Value: [ 4361 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\3c74e9a9\8 ],
    Value Name: [ ConfigString ], Value: [ ZAP--0000-0000 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\3c74e9a9\8 ],
    Value Name: [ DisplayName ], Value: [ mscorlib,2.0.0.0,,b77a5c561934e089 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\3c74e9a9\8 ],
    Value Name: [ ILDependencies ], Value: [ 0xc5e25079b3459531080000000200000000000000 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\3c74e9a9\8 ],
    Value Name: [ MVID ], Value: [ 0x642534209e13d16e93b80a628742d2ee ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\181938c6\3c74e9a9\8 ],
    Value Name: [ Status ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index75 ],
    Value Name: [ ILUsageMask ], Value: [ 0xffffffffffffffffff01 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index75 ],
    Value Name: [ NIUsageMask ], Value: [ 0xfffffffffffffffff1 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\PublisherPolicy\Default ],
    Value Name: [ Latest ], Value: [ 1 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\PublisherPolicy\Default ],
    Value Name: [ LegacyPolicyTimeStamp ], Value: [ 0x0000000000000000 ], 1 time
    Key: [ HKLM\Software\Microsoft\Fusion\PublisherPolicy\Default ],
    Value Name: [ index1 ], Value: [ 0x00 ], 1 time
    Key: [ HKLM\Software\Microsoft\PCHealth\ErrorReporting\DW\Installed ],
    Value Name: [ DW0200 ], Value: [ C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE ], 1 time
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\0048F8D37B153F6EA2798C323EF4F318A5624A9E ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000015b298a354704048703a375582c45afa1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\00EA522C8A9C06AA3ECCE0B4FA6CDC21D92E8099 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000003e80175badd77c104bf941b0cf1642b01400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\0483ED3399AC3608058722EDBC5E4600E3BEF9D7 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000004c5641e50dbb2be8caa3ed1808ad43391400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\049811056AFE9FD0F5BE01685AACE6A5D1C4454C ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000f27de954e4a3220d769fe70bbbb3242b1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\0B77BEBBCB7AA24705DECC0FBD6A02FC7ABD9B52 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000266d2c1998b6706838505419ec9034601400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\1331F48A5DA8E01DAACA1BB0C17044ACFEF755BB ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000050e1419d59738b46732d7f7fcf5c44f11400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\1F55E8839BAC30728BE7108EDE7B0BB0D3298224 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000008cd79febc7b8144c5478a7903ba935671400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\209900B63D955728140CD13622D8C687A4EB0085 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000001e74c3863c0c35c53ec27fef3caa3cd91400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\216B2A29E62A00CE820146D8244141B92511B279 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000e14b5273d71bdb9330e5bde4096ebefb1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\23E594945195F2414803B4D564D2A3A3F5D88B8C ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000c570c4a2ed53780cc810538164cbd01d1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\24A40A1F573643A67F0A4B0749F6A22BF28ABB6B ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000dd753f56bfbbc5a17a1553c690f9fbcc1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\24BA6D6C8A5B5837A48DB5FAE919EA675C94D217 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000007bb508999a8c18bf85277d0eaedab2ab1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\273EE12457FDC4F90C55E82B56167F62F532E547 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000db233df969fa4bb9958044735e7d41831400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\284F55C41A1A7A3F8328D4C262FB376ED6096F24 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000011a3f4db5f814c56848ad083eb9c8c21400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\2F173F7DE99667AFA57AF80AA2D1B12FAC830338 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000abbfeae36b29a6cca6783599efad2b801400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000a923759bba49366e31c2dbf2e766ba871400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\36863563FD5128C7BEA6F005CFE9B43668086CCE ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000003ab2de229a209349f9edc8d28ae7680d1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\394FF6850B06BE52E51856CC10E180E882B385CC ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000aabfbf6497da981d6fc6083a957033ca1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000002a5d003739469475397b11a6f29341e11400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4072BA31FEC351438480F62E6CB95508461EAB2F ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000070b57c4881953e80dc289bbaef1ee4851400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000e60bd2c9ca2d88db1a710e4b78eb02411400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\43DDB1FFF3B49B73831407F6BC8B975023D07C50 ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000000531d1d7201d423c820d00b6088c5d11400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\43F9B110D5BAFD48225231B0D0082B372FEF9A54 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000259dcf5eb3259d95b93f00865f47943d1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4463C531D7CCC1006794612BB656D3BF8257846F ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000747b820343f0009e6bb3ec47bf85a5931400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\47AFB915CDA26D82467B97FA42914468726138DD ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000050193e2fe8b6f4055449f3aec98b3e191400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4B421F7515F6AE8A6ECEF97F6982A400A4D9224E ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000005a11b922850289e1c3f22ce14ec101841400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4BA7B9DDD68788E12FF852E1A024204BF286A8F6 ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000018ae695d15cab917673267d597b260c01400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4C95A9902ABE0777CED18D6ACCC3372D2748381E ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000004b1c568ca0e8c79e1ef5ee32939965fe1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000cb17e431673ee209fe455793f30afa1c0300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000034287d7c1167d18afa4703cb8312c3e1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000852ff4764cd5426ccb5e7df717e835bd1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000782a02dfdb2e14d5a75f0adfb68e9c5d1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\54F9C163759F19045121A319F64C2D0555B7E073 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000004b798dd41d0392aa51ee04e5906f47491400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\58119F0E128287EA50FDD987456F4F78DCFAD6D4 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000b3a53e77216dac4ac0c9fbd5413dca061400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5B4E0EC28EBD8292A51782241281AD9FEEDD4E4C ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000b774cd487c5f9a0d3bf3fe66f41b3dfa1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5D989CDB159611365165641B560FDBEA2AC23EF1 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000bf6059a35bbaf6a77642da6f1a7b50cf1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5E5A168867BFFF00987D0B1DC2AB466C4264F956 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000343339fc6d033a8fa25385443270dec41400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5E997CA5945AAB75FFD14804A974BF2AE1DFE7E1 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000009aaef722f533fb4eec0a249dc63d7d251400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000069f6979166690021b8c8ca2c3076f3a1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\6372C49DA9FFF051B8B5C7D4E5AAE30384024B9C ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000008956aa4d441e59d805a1886deac828b21400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\6782AAE0EDEEE21A5839D3C0CD14680A4F60142A ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000b39c25b1c32e32538015309d4d02773e1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\67EB337B684CEB0EC2B0760AB488278CDD9597DD ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000cd3b3d625b09b80936879e122f7164ba1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\687EC17E0602E3CD3F7DFBD7E28D57A0199A3F44 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000824ad493004d66b6a32ca77b3536cf0b1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\688B6EB807E8EDA5C7B17C4393D0795F0FAE155F ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000e8cc9fb09b40c51f4fba7421f952857a1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\68ED18B309CD5291C0D3357C1D1141BF883866B1 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000008212f789e10b9160a4b6229f946811921400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\69BD8CF49CD300FB592E1793CA556AF3ECAA35FB ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000a26f53b7ee40db4a68e7fa18d9104b721400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\6A174570A916FBE84453EED3D070A1D8DA442829 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000002124a681c1d8f219af4998e39dfe0bf41400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\720FC15DDC27D456D098FABF3CDD78D31EF5A8DA ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000008d26ff2f316d5929dde636a7e2ce64251400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\74207441729CDD92EC7931D823108DC28192E2BB ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000882c8c52b8a23cf3f7bb03eaaeac420b1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000010fc635df6263e0df325be5f79cd67671400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7639C71847E151B5C7EA01C758FBF12ABA298F7A ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000a8eddeeb938866d82fc3bd1dbe45be4d1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\78E9DD0650624DB9CB36B50767F209B843BE15B3 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000005186e81fbcb1c371b51810db5fdcf6201400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7A74410FB0CD5C972A364B71BF031D88A6510E9E ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000041b807f7a8d109eeb49a8e704dfc1b781400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7AC5FFF8DCBC5583176877073BF751735E9BD358 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000004b6771be33b90db64b3a400187f08b1f1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7CA04FD8064C1CAA32A37AA94375038E8DF8DDC0 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000005b6f532cbb8188fa6c042c325da56b961400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7E784A101C8265CC2DE1F16D47B440CAD90A1945 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000008f5d770627c4983c5b9378e7d77d9bcc1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\81968B3AEF1CDC70F5FA3269C292A3635BD123D3 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000257aba832eb6a20bdafef5020f08d7ad1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\838E30F77FDD14AA385ED145009C0E2236494FAA ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000b816334c4c4cf2d8d34d06b4a65b40031400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000a2339b4c747873d46ce7c1f38dcb5ce91400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\85A408C09C193E5D51587DCDD61330FD8CDE37BF ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000074014a91b108c458ce47cdf0dd1153081400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\879F4BEE05DF98583BE360D633E70D3FFE9871AF ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000003916aab96a41e11469df9e6c3b72dcb61400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\8EB03FC3CF7BB292866268B751223DB5103405CB ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000008bca525f7553d02c6f630d8f882e1cd71400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9078C5A28F9A4325C2A7C73813CDFE13C20F934E ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000f20598e5964bbe5d55181b55b388e3921400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\90AEA26985FF14804C434952ECE9608477AF556F ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000009760e8575fd35047e5430c94368ab0621400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\90DEDE9E4C4E9F6FD88617579DD391BC65A68964 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000c4d7f0b2a3c57d6167f004cd43d3ba581400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\96974CD6B663A7184526B1D648AD815CF51E801A ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000711f0e21e7aaea323a6623d3ab50d6691400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\97817950D81C9670CC34D809CF794431367EF474 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000ca3dd368f1035cd032fab82b59e85adb1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000c463ab44201c36e437c05f279d0f6f6e1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\99A69BE61AFE886B4D2B82007CB854FC317E1539 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000dff28073ccf1e66173fcf542e9c57cee1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9BACF3B664EAC5A17BED08437C72E4ACDA12F7E7 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000e2d52023eceeb872e12b5d296ffa43da1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9E6CEB179185A29EC6060CA53E1974AF94AF59D4 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000009b340d1a315b97462698bca6136a71961400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9FC796E8F8524F863AE1496D381242105F1B78F5 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000005f944a7322b8f7d131ec5939f78efe6e1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\A399F76F0CBF4C9DA55E4AC24E8960984B2905B6 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000370971c4afeb7501ae636c3016bfd1e51400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\A3E31E20B2E46A328520472D0CDE9523E7260C6D ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000a33d88fe161bddf95c9f1a7fd8c890081400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\A5EC73D48C34FCBEF1005AEB85843524BBFAB727 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000ec407d2b765267052ceaf23a4f65f0d81400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\AB48F333DB04ABB9C072DA5B0CC1D057F0369B46 ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000093c28e117bd4f30319bd2875134a454a1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\ACED5F6553FD25CE015F1F7A483B6A749F6178C6 ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000086386d5e49636c855cdb6ddc94b7d0f71400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B172B1A56D95F91FE50287E14D37EA6A4463768A ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000d7343def1d270928e131025b132bddf71400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B19DD096DCD4E3E0FD676885505A672C438D4E9C ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000002b508718392d3bffc3917f2d7dc08a971400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B3EAC44776C9C81CEAF29D95B6CCA0081B67EC9D ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000002dbbe525d3d165823ab70efae6ebe2e11400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B5D303BF8682E152919D83F184ED05F1DCE5370C ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000978fc66b3b3e40857724750b76bb55f81400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B6AF5BE5F878A00114C3D7FEF8C775C34CCD17B6 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000a37d2c27e4a7f3aa5f75d4c49264026a1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B72FFF92D2CE43DE0A8D4C548C503726A81E2B93 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000006cc9a76e47f10ce3533b784c4dc26ac51400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\BC9219DDC98E14BF1A781F6E280B04C27F902712 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000b465220a7caddf41b7d544d5adfa9a751400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000007f667a71d3eb6978209a51149d83da201400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CABB51672400588E6419F1D40878D0403AA20264 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000bdd6f58a7c3cc4a6f934ccc38961f6b21400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CFDEFE102FDA05BBE4C78D2E4423589005B2571D ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000ad8e0f9e016ba0c574d50cd368654f1e1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CFF360F524CB20F1FEAD89006F7F586A285B2D5B ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000074a82c81432b35609b78056b58f365821400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CFF810FB2C4FFC0156BFE1E1FABCB418C68D31C5 ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000071e265fbcd7b0b845be3bcd76320c5981400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\D23209AD23D314232174E40D7F9D62139786633A ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000067cb9dc013248a829bb2171ed11becd41400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\D29F6C98BEFC6D986521543EE8BE56CEBC288CF3 ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000000efa4bf7d760cd65f7a70688579862391400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\D2EDF88B41B6FE01461D6E2834EC7C8F6C77721E ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000bd8ace34a8ae6148e85ec87a1ce8ccbf1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\DA40188B9189A3EDEEAEDA97FE2F9DF5B7D18A41 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000649cef2e44fcc68f5207d051738fcb3d1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\DBAC3C7AA4254DA1AA5CAAD68468CB88EEDDEEA8 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000df168a83ea83845db96501c6a65d193e1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000a7f2e41606411150306b9ce3b49cb0c91400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E392512F0ACFF505DFF6DE067F7537E165EA574B ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000004febf1f070c280635d589fda123ca9c41400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E4554333CA390E128B8BF81D90B70F4002D1D6E9 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000bfb5e77d3dea6f1df08a50bc8c1cfa1d1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E5DF743CB601C49B9843DCAB8CE86A81109FE48E ],
    Value Name: [ Blob ], Value: [ 0x0400000001000000100000006558ab15ad576c1ea8a7b569acbfffeb1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\EBBC0E2D020CA69B222C2BFFD203CB8BF5A82766 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000b2407992461a19c4180fec34ec68afd51400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\EC0C3716EA9EDFADD35DFBD55608E60A05D3CBF3 ],
    Value Name: [ Blob ], Value: [ 0x04000000010000001000000078a5fb104be4632ed26bfbf2b6c24b8e1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\EF2DACCBEABB682D32CE4ABD6CB90025236C07BC ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000c69f6d5cb379b00389cbf03fa4c09f8a1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\F44095C238AC73FC4F77BF8F98DF70F8F091BC52 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000f4ff97428070fe66168bbed35315819b1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\F88015D3F98479E1DA553D24FD42BA3F43886AEF ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000160a1613c17ff01d887ee3d9e71261cc1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\Disallowed\\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 ],
    Value Name: [ Blob ], Value: [ 0x0f000000010000001000000033592925e547604fd98c09f1fa44c2790b00 ], 4 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\Disallowed\\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 ],
    Value Name: [ Blob ], Value: [ 0x0f00000001000000100000008cdb18e99a266c9be818e94229cf0fca0b00 ], 4 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB ],
    Value Name: [ Blob ], Value: [ 0x030000000100000014000000a377d1b1c0538833035211f4083d00fecc41 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\063DA67748F0ECCC690D319BCDCD0E72AC8D48D5 ],
    Value Name: [ Blob ], Value: [ 0x19000000010000001000000012fabd58acd5fc77cd7608b3d3378c3d0300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C ],
    Value Name: [ Blob ], Value: [ 0x030000000100000014000000109f1caed645bb78b3ea2b94c0697c740733 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\12519AE9CD777A560184F1FBD54215222E95E71F ],
    Value Name: [ Blob ], Value: [ 0x190000000100000010000000a889c4496403d2619e040ad282ffc1590300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\189271E573FED295A8C130EAF357A20C4A9F115E ],
    Value Name: [ Blob ], Value: [ 0x19000000010000001000000099c03958d4138c59ae87672beb67432a0300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\2D69A20EC4F0CD19037FD6D6246B1EE0EC41BA22 ],
    Value Name: [ Blob ], Value: [ 0x1900000001000000100000004187d1f7d569d7cab129111df89991810300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\7B02312BACC59EC388FEAE12FD277F6A9FB4FAC1 ],
    Value Name: [ Blob ], Value: [ 0x190000000100000010000000c4f1f90b2787ece21c32340df76cc67c0300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\8B24CD8D8B58C6DA72ACE097C7B1E3CEA4DC3DC6 ],
    Value Name: [ Blob ], Value: [ 0x1900000001000000100000006ed6ed7df52fc19bdc9e5fe9e2be21fb0300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\9F025D9F58711A605EB0694B0E8BC0CA4F25FD6F ],
    Value Name: [ Blob ], Value: [ 0x190000000100000010000000fe4d945be7ca1f62953a5c89cd07a9960300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\BA9E3C32562A67128CAABD4AB0C500BEE1D0C256 ],
    Value Name: [ Blob ], Value: [ 0x19000000010000001000000083b65318664e6fa245e0d7609fb958200300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\E5215D3460C2C20BBE2D9FE5FB665DAA2C0E225C ],
    Value Name: [ Blob ], Value: [ 0x190000000100000010000000a823b4a20180beb460cab955c24d7e210300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\F6357239B7C39725BD8000646E4A0D18EBCE4CFA ],
    Value Name: [ Blob ], Value: [ 0x1900000001000000100000008d1180a8ac4f2b186c7da5fffd8b86e10300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\FE622EA7B33CA46519AB39736A66B8F6E41FF157 ],
    Value Name: [ Blob ], Value: [ 0x1900000001000000100000005dc45e2cd1845791bdde7600050af5100300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4 ],
    Value Name: [ Blob ], Value: [ 0x190000000100000010000000edbccdd5106a071c5d8b4690918e48aa0300 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\disallowed\\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 ],
    Value Name: [ Blob ], Value: [ 0x0f000000010000001000000033592925e547604fd98c09f1fa44c2790b00 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\disallowed\\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 ],
    Value Name: [ Blob ], Value: [ 0x0f00000001000000100000008cdb18e99a266c9be818e94229cf0fca0b00 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\root\\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000ebb04f1d3a2e372f1dda6e27d6b680fa1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\root\\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000556ebef54c1d7c0360c43418bc9649c11400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\root\\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247 ],
    Value Name: [ Blob ], Value: [ 0x040000000100000010000000dc6d6faf897cdd17332fb5ba9035e9ce1400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\root\\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 ],
    Value Name: [ Blob ], Value: [ 0x1900000001000000100000003fc8cb0bc05241e58d65e9448b2d07c21400 ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\root\\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072 ],
    Value Name: [ Blob ], Value: [ 0x190000000100000010000000983b132635b7e91deef54a6780c092691400 ], 2 times
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscoree.dll ],
    Value Name: [ CheckAppHelp ], Value: [ 1 ], 1 time
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorwks.dll ],
    Value Name: [ CheckAppHelp ], Value: [ 1 ], 1 time
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList ],
    Value Name: [ AllUsersProfile ], Value: [ All Users ], 3 times
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList ],
    Value Name: [ DefaultUserProfile ], Value: [ Default User ], 3 times
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList ],
    Value Name: [ ProfilesDirectory ], Value: [ %SystemDrive%\Documents and Settings ], 6 times
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-842925246-1425521274-308236825-500 ],
    Value Name: [ ProfileImagePath ], Value: [ %SystemDrive%\Documents and Settings\Administrator ], 3 times
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows ],
    Value Name: [ AppInit_DLLs ], Value: [ ], 1 time
    Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion ],
    Value Name: [ CommonFilesDir ], Value: [ C:\Program Files\Common Files ], 3 times
    Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion ],
    Value Name: [ ProgramFilesDir ], Value: [ C:\Program Files ], 3 times
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers ],
    Value Name: [ AuthenticodeEnabled ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers ],
    Value Name: [ DefaultLevel ], Value: [ 262144 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers ],
    Value Name: [ PolicyScope ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers ],
    Value Name: [ TransparentEnabled ], Value: [ 1 ], 2 times
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328} ],
    Value Name: [ HashAlg ], Value: [ 32771 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328} ],
    Value Name: [ ItemData ], Value: [ 0x5eab304f957a49896a006c1c31154015 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328} ],
    Value Name: [ ItemSize ], Value: [ 779 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328} ],
    Value Name: [ SaferFlags ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91} ],
    Value Name: [ HashAlg ], Value: [ 32771 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91} ],
    Value Name: [ ItemData ], Value: [ 0x67b0d48b343a3fd3bce9dc646704f394 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91} ],
    Value Name: [ ItemSize ], Value: [ 517 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91} ],
    Value Name: [ SaferFlags ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f} ],
    Value Name: [ HashAlg ], Value: [ 32771 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f} ],
    Value Name: [ ItemData ], Value: [ 0x327802dcfef8c893dc8ab006dd847d1d ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f} ],
    Value Name: [ ItemSize ], Value: [ 918 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f} ],
    Value Name: [ SaferFlags ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d} ],
    Value Name: [ HashAlg ], Value: [ 32771 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d} ],
    Value Name: [ ItemData ], Value: [ 0xbd9a2adb42ebd8560e250e4df8162f67 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d} ],
    Value Name: [ ItemSize ], Value: [ 229 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d} ],
    Value Name: [ SaferFlags ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc} ],
    Value Name: [ HashAlg ], Value: [ 32771 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc} ],
    Value Name: [ ItemData ], Value: [ 0x386b085f84ecf669d36b956a22c01e80 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc} ],
    Value Name: [ ItemSize ], Value: [ 370 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc} ],
    Value Name: [ SaferFlags ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33} ],
    Value Name: [ ItemData ], Value: [ %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK* ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33} ],
    Value Name: [ SaferFlags ], Value: [ 0 ], 1 time
    Key: [ HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName ],
    Value Name: [ ComputerName ], Value: [ PC ], 4 times
    Key: [ HKLM\System\CurrentControlSet\Control\ProductOptions ],
    Value Name: [ ProductType ], Value: [ WinNT ], 1 time
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ ComSpec ], Value: [ %SystemRoot%\system32\cmd.exe ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ FP_NO_HOST_CHECK ], Value: [ NO ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ NUMBER_OF_PROCESSORS ], Value: [ 1 ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ OS ], Value: [ Windows_NT ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ PATHEXT ], Value: [ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ PROCESSOR_ARCHITECTURE ], Value: [ x86 ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ PROCESSOR_IDENTIFIER ], Value: [ x86 Family 6 Model 3 Stepping 3, GenuineIntel ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ PROCESSOR_LEVEL ], Value: [ 6 ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ PROCESSOR_REVISION ], Value: [ 0303 ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ Path ], Value: [ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ TEMP ], Value: [ %SystemRoot%\TEMP ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ TMP ], Value: [ %SystemRoot%\TEMP ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Session Manager\Environment ],
    Value Name: [ windir ], Value: [ %SystemRoot% ], 6 times
    Key: [ HKLM\System\CurrentControlSet\Control\Terminal Server ],
    Value Name: [ TSAppCompat ], Value: [ 0 ], 3 times
    Key: [ HKLM\System\CurrentControlSet\Control\Terminal Server ],
    Value Name: [ TSUserEnabled ], Value: [ 0 ], 1 time
    Key: [ HKLM\System\CurrentControlSet\Services\LDAP ],
    Value Name: [ LdapClientIntegrity ], Value: [ 1 ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment ],
    Value Name: [ TEMP ], Value: [ %USERPROFILE%\Local Settings\Temp ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment ],
    Value Name: [ TMP ], Value: [ %USERPROFILE%\Local Settings\Temp ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle ],
    Value Name: [ Language Hotkey ], Value: [ 1 ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle ],
    Value Name: [ Layout Hotkey ], Value: [ 2 ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Security ],
    Value Name: [ Safety Warning Level ], Value: [ Query ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\SystemCertificates\Root\ProtectedRoots ],
    Value Name: [ Certificates ], Value: [ 0x180000000100000050a5c0c5adc5c8010000000018000000 ], 4 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\SystemCertificates\ca\\Certificates\F77A3F82B7C4B3A9D869A93E3335CF1F78BC441E ],
    Value Name: [ Blob ], Value: [ 0x030000000100000014000000f77a3f82b7c4b3a9d869a93e3335cf1f78bc ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows NT\CurrentVersion\Winlogon ],
    Value Name: [ ParseAutoexec ], Value: [ 1 ], 3 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders ],
    Value Name: [ Cache ], Value: [ C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders ],
    Value Name: [ AppData ], Value: [ %USERPROFILE%\Application Data ], 4 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders ],
    Value Name: [ Cache ], Value: [ %USERPROFILE%\Local Settings\Temporary Internet Files ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders ],
    Value Name: [ Local Settings ], Value: [ %USERPROFILE%\Local Settings ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders ],
    Value Name: [ Personal ], Value: [ %USERPROFILE%\My Documents ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing ],
    Value Name: [ State ], Value: [ 146432 ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment ],
    Value Name: [ APPDATA ], Value: [ C:\Documents and Settings\Administrator\Application Data ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment ],
    Value Name: [ CLIENTNAME ], Value: [ Console ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment ],
    Value Name: [ HOMEDRIVE ], Value: [ C: ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment ],
    Value Name: [ HOMEPATH ], Value: [ \Documents and Settings\Administrator ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment ],
    Value Name: [ HOMESHARE ], Value: [ ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment ],
    Value Name: [ LOGONSERVER ], Value: [ \\PC ], 6 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment ],
    Value Name: [ SESSIONNAME ], Value: [ Console ], 6 times

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Monitored Registry Keys:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Key: [ HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 2 times
    Key: [ HKLM\Software\Microsoft\EnterpriseCertificates\ca\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\EnterpriseCertificates\disallowed\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\EnterpriseCertificates\root\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\EnterpriseCertificates\trust\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\SystemCertificates\AuthRoot\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\SystemCertificates\Disallowed\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 2 times
    Key: [ HKLM\Software\Microsoft\SystemCertificates\ca\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\SystemCertificates\disallowed\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\SystemCertificates\root\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Microsoft\SystemCertificates\trust\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\SystemCertificates ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\SystemCertificates\Disallowed\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\SystemCertificates\ca\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\SystemCertificates\disallowed\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\SystemCertificates\root\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\SystemCertificates\trust\ ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\\Software\Policies\Microsoft\SystemCertificates ],
    Watch subtree: [ 1 ], Notify Filter: [ Key Change,Value Change ], 5 times


    [=============================================================================]
    2.b) m8update.e.exe - File Activities
    [=============================================================================]
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Files Read:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File Name: [ C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 ]
    File Name: [ C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F ]
    File Name: [ C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 ]
    File Name: [ C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\config\machine.config ]
    File Name: [ C:\WINDOWS\system32\rsaenh.dll ]
    File Name: [ PIPE\lsarpc ]
    File Name: [ c:\autoexec.bat ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Files Modified:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File Name: [ PIPE\lsarpc ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File System Control Communication:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File: [ C:\Program Files\Common Files\ ], Control Code: [ 0x00090028 ], 1 time
    File: [ PIPE\lsarpc ], Control Code: [ 0x0011C017 ], 1 time

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Device Control Communication:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File: [ \Device\KsecDD ], Control Code: [ 0x00390008 ], 8 times

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Memory Mapped Files:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File Name: [ C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\culture.dll ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll ]
    File Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll ]
    File Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll ]
    File Name: [ C:\WINDOWS\WindowsShell.Manifest ]
    File Name: [ C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\642534209e13d16e93b80a628742d2ee\mscorlib.ni.dll ]
    File Name: [ C:\WINDOWS\system32\Apphelp.dll ]
    File Name: [ C:\WINDOWS\system32\MSCTF.dll ]
    File Name: [ C:\WINDOWS\system32\PSAPI.DLL ]
    File Name: [ C:\WINDOWS\system32\RichEd20.dll ]
    File Name: [ C:\WINDOWS\system32\SensApi.dll ]
    File Name: [ C:\WINDOWS\system32\WINHTTP.dll ]
    File Name: [ C:\WINDOWS\system32\comctl32.dll ]
    File Name: [ C:\WINDOWS\system32\cryptnet.dll ]
    File Name: [ C:\WINDOWS\system32\imm32.dll ]
    File Name: [ C:\WINDOWS\system32\l_intl.nls ]
    File Name: [ C:\WINDOWS\system32\mscoree.dll ]
    File Name: [ C:\WINDOWS\system32\rpcss.dll ]
    File Name: [ C:\WINDOWS\system32\rsaenh.dll ]
    File Name: [ C:\WINDOWS\system32\shell32.dll ]
    File Name: [ C:\WINDOWS\system32\xpsp2res.dll ]
    File Name: [ C:\Windows\AppPatch\sysmain.sdb ]
    File Name: [ C:\m8update.e.exe ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Directories Monitored:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Directory: [ C:\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My ], Watch subtree: [ 1 ], Notify FilterFile Name Change,Directory Name Change,Name Change,Size Change,Last Write Change ], 1 time

    [=============================================================================]
    2.c) m8update.e.exe - Process Activities
    [=============================================================================]
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Processes Created:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Executable: [ C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE ], Command Line: [ ]
    Executable: [ C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE ], Command Line: [ dw20.exe -x -s 716 ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Remote Threads Created:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Affected Process: [ C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Foreign Memory Regions Read:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Process: [ C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Foreign Memory Regions Written:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Process: [ C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE ]


    [=============================================================================]
    2.d) m8update.e.exe - Other Activities
    [=============================================================================]
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Mutexes Created:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Mutex: [ CTF.Asm.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500 ]
    Mutex: [ CTF.Compart.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500 ]
    Mutex: [ CTF.LBES.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500 ]
    Mutex: [ CTF.Layouts.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500 ]
    Mutex: [ CTF.TMD.MutexDefaultS-1-5-21-842925246-1425521274-308236825-500 ]
    Mutex: [ CTF.TimListCache.FMPDefaultS-1-5-21-842925246-1425521274-308236825-500MUTEX.DefaultS-1-5-21-842925246-1425521274-308236825-500 ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Windows SEH exceptions:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Description: [ Exception 0xe06d7363 at 0x7c812aeb ], 4 times

    Description: [ Exception 0xe0434f4d at 0x7c812aeb ], 1 time




    [#############################################################################]
    3. DW20.EXE
    [#############################################################################]
    [=============================================================================]
    General information about this executable
    [=============================================================================]
    Analysis Reason: Started by m8update.e.exe
    Filename: DW20.EXE
    MD5: a981419c39cc02259b8f2da3974000d9
    SHA-1: 905d359e2c5e8330d39b746132fa9779f52c0b93
    File Size: 637272 Bytes
    Command Line: dw20.exe -x -s 716
    Process-status
    at analysis end: alive
    Exit Code: 0

    [=============================================================================]
    Load-time Dlls
    [=============================================================================]
    Module Name: [ C:\WINDOWS\system32\ntdll.dll ],
    Base Address: [0x7C900000 ], Size: [0x000AF000 ]
    Module Name: [ C:\WINDOWS\system32\kernel32.dll ],
    Base Address: [0x7C800000 ], Size: [0x000F6000 ]
    Module Name: [ C:\WINDOWS\system32\ADVAPI32.dll ],
    Base Address: [0x77DD0000 ], Size: [0x0009B000 ]
    Module Name: [ C:\WINDOWS\system32\RPCRT4.dll ],
    Base Address: [0x77E70000 ], Size: [0x00092000 ]
    Module Name: [ C:\WINDOWS\system32\Secur32.dll ],
    Base Address: [0x77FE0000 ], Size: [0x00011000 ]
    Module Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll ],
    Base Address: [0x773D0000 ], Size: [0x00103000 ]
    Module Name: [ C:\WINDOWS\system32\msvcrt.dll ],
    Base Address: [0x77C10000 ], Size: [0x00058000 ]
    Module Name: [ C:\WINDOWS\system32\GDI32.dll ],
    Base Address: [0x77F10000 ], Size: [0x00049000 ]
    Module Name: [ C:\WINDOWS\system32\USER32.dll ],
    Base Address: [0x7E410000 ], Size: [0x00091000 ]
    Module Name: [ C:\WINDOWS\system32\SHLWAPI.dll ],
    Base Address: [0x77F60000 ], Size: [0x00076000 ]
    Module Name: [ C:\WINDOWS\system32\OLEACC.dll ],
    Base Address: [0x74C80000 ], Size: [0x0002C000 ]
    Module Name: [ C:\WINDOWS\system32\MSVCP60.dll ],
    Base Address: [0x76080000 ], Size: [0x00065000 ]
    Module Name: [ C:\WINDOWS\system32\ole32.dll ],
    Base Address: [0x774E0000 ], Size: [0x0013D000 ]
    Module Name: [ C:\WINDOWS\system32\OLEAUT32.dll ],
    Base Address: [0x77120000 ], Size: [0x0008B000 ]
    Module Name: [ C:\WINDOWS\system32\SHELL32.dll ],
    Base Address: [0x7C9C0000 ], Size: [0x00817000 ]
    Module Name: [ C:\WINDOWS\system32\urlmon.dll ],
    Base Address: [0x7E1E0000 ], Size: [0x000A2000 ]
    Module Name: [ C:\WINDOWS\system32\VERSION.dll ],
    Base Address: [0x77C00000 ], Size: [0x00008000 ]
    Module Name: [ C:\WINDOWS\system32\WININET.dll ],
    Base Address: [0x771B0000 ], Size: [0x000AA000 ]
    Module Name: [ C:\WINDOWS\system32\CRYPT32.dll ],
    Base Address: [0x77A80000 ], Size: [0x00095000 ]
    Module Name: [ C:\WINDOWS\system32\MSASN1.dll ],
    Base Address: [0x77B20000 ], Size: [0x00012000 ]

    [=============================================================================]
    Run-time Dlls
    [=============================================================================]
    Module Name: [ C:\WINDOWS\system32\MSCTF.dll ],
    Base Address: [0x74720000 ], Size: [0x0004C000 ]
    Module Name: [ C:\WINDOWS\system32\riched20.dll ],
    Base Address: [0x74E30000 ], Size: [0x0006D000 ]
    Module Name: [ C:\WINDOWS\system32\imm32.dll ],
    Base Address: [0x76390000 ], Size: [0x0001D000 ]
    Module Name: [ C:\WINDOWS\system32\shfolder.dll ],
    Base Address: [0x76780000 ], Size: [0x00009000 ]
    Module Name: [ C:\WINDOWS\system32\psapi.dll ],
    Base Address: [0x76BF0000 ], Size: [0x0000B000 ]

    [=============================================================================]
    3.a) DW20.EXE - Registry Activities
    [=============================================================================]
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Registry Values Modified:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders ],
    Value Name: [ AppData ], New Value: [ C:\Documents and Settings\Administrator\Application Data ]
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders ],
    Value Name: [ Personal ], New Value: [ C:\Documents and Settings\Administrator\My Documents ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Registry Values Read:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Key: [ HKLM\SOFTWARE\Microsoft\CTF\SystemShared\ ],
    Value Name: [ CUAS ], Value: [ 0 ], 1 time
    Key: [ HKLM\SYSTEM\CurrentControlSet\Control\Session Manager ],
    Value Name: [ CriticalSectionTimeout ], Value: [ 2592000 ], 1 time
    Key: [ HKLM\SYSTEM\Setup ],
    Value Name: [ SystemSetupInProgress ], Value: [ 0 ], 1 time
    Key: [ HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS ],
    Value Name: [ * ], Value: [ 1 ], 1 time
    Key: [ HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL ],
    Value Name: [ * ], Value: [ 1 ], 1 time
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\MiniDumpAuxiliaryDlls ],
    Value Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll ], Value: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll ], 1 time
    Key: [ HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows ],
    Value Name: [ AppInit_DLLs ], Value: [ ], 1 time
    Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion ],
    Value Name: [ CommonFilesDir ], Value: [ C:\Program Files\Common Files ], 1 time
    Key: [ HKLM\Software\Microsoft\Windows\CurrentVersion ],
    Value Name: [ ProgramFilesDir ], Value: [ C:\Program Files ], 1 time
    Key: [ HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers ],
    Value Name: [ TransparentEnabled ], Value: [ 1 ], 1 time
    Key: [ HKLM\System\CurrentControlSet\Control\Terminal Server ],
    Value Name: [ TSAppCompat ], Value: [ 0 ], 3 times
    Key: [ HKLM\System\CurrentControlSet\Control\Terminal Server ],
    Value Name: [ TSUserEnabled ], Value: [ 0 ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle ],
    Value Name: [ Language Hotkey ], Value: [ 1 ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle ],
    Value Name: [ Layout Hotkey ], Value: [ 2 ], 2 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Settings ],
    Value Name: [ Anchor Color ], Value: [ 0,0,255 ], 4 times
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders ],
    Value Name: [ AppData ], Value: [ %USERPROFILE%\Application Data ], 1 time
    Key: [ HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders ],
    Value Name: [ Personal ], Value: [ %USERPROFILE%\My Documents ], 1 time


    [=============================================================================]
    3.b) DW20.EXE - File Activities
    [=============================================================================]
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Files Created:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\73E3F.dmp ]
    File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dw.log ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Files Read:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File Name: [ C:\m8update.e.exe ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Files Modified:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File Name: [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dw.log ]

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Device Control Communication:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File: [ \Device\KsecDD ], Control Code: [ 0x00390008 ], 1 time

    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Memory Mapped Files:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll ]
    File Name: [ C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll ]
    File Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll ]
    File Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll ]
    File Name: [ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll ]
    File Name: [ C:\WINDOWS\WindowsShell.Manifest ]
    File Name: [ C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\642534209e13d16e93b80a628742d2ee\mscorlib.ni.dll ]
    File Name: [ C:\WINDOWS\system32\ADVAPI32.dll ]
    File Name: [ C:\WINDOWS\system32\CRYPT32.dll ]
    File Name: [ C:\WINDOWS\system32\GDI32.dll ]
    File Name: [ C:\WINDOWS\system32\IMAGEHLP.dll ]
    File Name: [ C:\WINDOWS\system32\KERNEL32.dll ]
    File Name: [ C:\WINDOWS\system32\MSASN1.dll ]
    File Name: [ C:\WINDOWS\system32\MSCTF.dll ]
    File Name: [ C:\WINDOWS\system32\MSVCP60.dll ]
    File Name: [ C:\WINDOWS\system32\OLEACC.dll ]
    File Name: [ C:\WINDOWS\system32\OLEACCRC.DLL ]
    File Name: [ C:\WINDOWS\system32\PSAPI.DLL ]
    File Name: [ C:\WINDOWS\system32\RPCRT4.dll ]
    File Name: [ C:\WINDOWS\system32\SHELL32.dll ]
    File Name: [ C:\WINDOWS\system32\SHLWAPI.dll ]
    File Name: [ C:\WINDOWS\system32\Secur32.dll ]
    File Name: [ C:\WINDOWS\system32\SensApi.dll ]
    File Name: [ C:\WINDOWS\system32\USER32.dll ]
    File Name: [ C:\WINDOWS\system32\VERSION.dll ]
    File Name: [ C:\WINDOWS\system32\WINHTTP.dll ]
    File Name: [ C:\WINDOWS\system32\WININET.dll ]
    File Name: [ C:\WINDOWS\system32\WINTRUST.dll ]
    File Name: [ C:\WINDOWS\system32\WLDAP32.dll ]
    File Name: [ C:\WINDOWS\system32\comctl32.dll ]
    File Name: [ C:\WINDOWS\system32\cryptnet.dll ]
    File Name: [ C:\WINDOWS\system32\imm32.dll ]
    File Name: [ C:\WINDOWS\system32\mscoree.dll ]
    File Name: [ C:\WINDOWS\system32\msvcrt.dll ]
    File Name: [ C:\WINDOWS\system32\netapi32.dll ]
    File Name: [ C:\WINDOWS\system32\ntdll.dll ]
    File Name: [ C:\WINDOWS\system32\psapi.dll ]
    File Name: [ C:\WINDOWS\system32\riched20.dll ]
    File Name: [ C:\WINDOWS\system32\rsaenh.dll ]
    File Name: [ C:\WINDOWS\system32\shell32.dll ]
    File Name: [ C:\WINDOWS\system32\shfolder.dll ]
    File Name: [ C:\WINDOWS\system32\urlmon.dll ]
    File Name: [ C:\WINDOWS\system32\userenv.dll ]
    File Name: [ C:\WINDOWS\system32\xpsp2res.dll ]
    File Name: [ C:\m8update.e.exe ]

    [=============================================================================]
    3.c) DW20.EXE - Process Activities
    [=============================================================================]
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Foreign Memory Regions Read:
    [=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
    Process: [ C:\m8update.e.exe ]




    [#############################################################################]
    International Secure Systems Lab
    http://www.iseclab.org

    Vienna University of Technology Eurecom France UC Santa Barbara
    http://www.tuwien.ac.at http://www.eurecom.fr http://www.cs.ucsb.edu

    Contact: [email protected]
 
It seems like the program supposedly designed only to "update" one's Mark 8 E-Meter makes quite a few changes to one's computer, doesn't it?


Everyone will circumvent that by having a dedicated computer just for the meter. That way, "like all good minions," they can read the turbulating shit that they can lie about during their next sec check.
 

CommunicatorIC

@IndieScieNews on Twitter
It seems like the program supposedly designed only to "update" one's Mark 8 E-Meter makes quite a few changes to one's computer, doesn't it?


Everyone will circumvent that by having a dedicated computer just for the meter. That way, "like all good minions," they can read the turbulating shit that they can lie about during their next sec check.
So, to the $10,000 for two meters and the $500 for a yearly IAS membership, or $5,000 for a lifetime IAS membership, auditors can now add the cost of a new, otherwise unnecessary computer just for the e-meter -- so they can maintain their privacy and possibly the privacy of their PCs.

Nothing wrong with that picture.
 
Apologies if this has been addressed somewhere (I can't find a clear answer), but is this strictly "update" software or does one have to install it when they initially get their meter as well? As in, the meter will not work out of the box, until this software is uploaded into it, rendering the meter useless unless one is an IAS member? I am also ve interested about the possible monitoring software and if it reports member's complete internet history (or even possibly keystrokes too?), AND, if so, the potential OSA staff members added whose sole job it is to sift through it all, analyze it and report on it. The sheer scope of man hours and resources dedicated to this is a colossal waste from an organization that has nothing left to waste. I mean, just think about if this is the case: instead of spending time, hours and money on making auditors and all that techy bridgey stuff (I'm not a scientologist or an ex and am not necissarily condoning the practice of scientology, but I respect everyone's right to their beliefs and if they don't hurt anyone and it makes them happy, then that's fine with me, and if bridgey techy audity stuff makes people happy, go for it) the few members and resources they have left are being spent on aggressively monitoring their members a la 1984 and creating the most insular virtual prison, putting their members on the defensive and focusing solely on crime and punishment instead of growth and advancement. It is like a police state. It IS a police state.
 

freethinker

Sponsor
I beleive when you get it fully dissected that you will find that ...



It follows you around the net.

It checks everything on your computer (entheta sniffer software)

It reads your emails whether on your computer or at your ISP.

It checks credit ratings.

It checks CC acct. balances when you do online payments.

It checks your bank balance.

It finds out who all your friends are on facebook.

It toggles the e-meter to off or gives it a virus if membership is not up to date.

It lets them know if you are home or not.

It has GPS.

Add any dirty thing you can think of, they have no respect.

There is another important issue.

That issue is the extent to which the updater software acts as spyware. (Anyone remember the Scientology Net Nanny?) It appears nobody has an answer -- yet -- but it also appears people on WWP are working on it.

Note the below, excerpted from above.
 
Top