File: 609e618f198c6b871e141bf89c20a63000097a48899c6b35324c8595e5eb0297

Metadata
File name:baglosnot32tritony.png
File type:PE32 executable (GUI) Intel 80386, for MS Windows
File size:445952 bytes
Analysis date:2017-06-29 09:31:57
MD5:bc1b3e08f207a4418d913c130e6fbeff
SHA1:6948244bec2289f81d315c1cd8bc4f078b460e9c
SHA256:609e618f198c6b871e141bf89c20a63000097a48899c6b35324c8595e5eb0297
SHA512:dbe21c13f9af20b85893664f73257985685e7ed2c9abe74ac52553fc1449e3c9b1d9de5fe51349ac0083ddc7cedf4fa52703ef5afeeca0f345e9f0deb51fd66a
SSDEEP:6144:qnUrm7jw40GG8O6WqHvKwVRuB8M7ROY/eZXdb4mrtF2I8+gAHmkYNQnu:qmm7XS0QB8AUYmZNRpt8+TGP7
IMPHASH:2e68d8327eb91a58e1388cff5df0cf19
Authentihash:N/A
Related resources
APTNotes
Cyber threat intelligence reports associated with 609e618f198c6b871e141bf89c20a63000097a48899c6b35324c8595e5eb0297.
Loading...
Domains
Domains the malware sample communicates with.
Hosts
Hosts the malware sample communicates with.
HTTP Requests
HTTP requests the malware sample makes.
HostURLUser-Agent
icanhazip.com/Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36
www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabMicrosoft-CryptoAPI/5.131.2600.5512
www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtMicrosoft-CryptoAPI/5.131.2600.5512
Mutants
Mutants created by the malware sample.
Registry keys
Registry keys created by the malware sample.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IMM
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\SystemShared
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ComputerName
ActiveComputerName
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004_Classes
HKEY_LOCAL_MACHINE\Software\Classes
\REGISTRY\USER
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}
CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\TreatAs
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocServer32
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocServerX86
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\LocalServer32
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocHandler32
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocHandlerX86
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\LocalServer
HKEY_CLASSES_ROOT\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}
HKEY_CLASSES_ROOT\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\TreatAs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\UnsafeSslApps
CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}
CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\TreatAs
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocServer32
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocServerX86
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\LocalServer32
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocHandler32
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocHandlerX86
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\LocalServer
HKEY_CLASSES_ROOT\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}
HKEY_CLASSES_ROOT\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\TreatAs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\SOFTWARE\Microsoft\Cryptography\Providers\Type 024
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider (Prototype)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Offload
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\DESHashSessionKeyBackward
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B83AF3AB-4FED-45D1-A8B8-9E66F3411813}
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\digest.dll
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\SOFTWARE\Microsoft\Cryptography\Providers\Type 012
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft RSA SChannel Cryptographic Provider
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\SOFTWARE\Microsoft\Cryptography\Providers\Type 018
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft DH SChannel Cryptographic Provider
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Certificate\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Initialization\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Message\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Signature\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\CertCheck\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\DiagnosticPolicy\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Providers\Trust\Cleanup\{573E31F8-AABA-11D0-8CCB-00C04FC295EE}
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\SOFTWARE\Microsoft\Cryptography\Providers\Type 001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Internet Explorer\Security
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\root\PhysicalStores
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\root
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\Root\ProtectedRoots
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\root\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\root\\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\root\\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\root\\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\root\\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\0048F8D37B153F6EA2798C323EF4F318A5624A9E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\00EA522C8A9C06AA3ECCE0B4FA6CDC21D92E8099
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\0483ED3399AC3608058722EDBC5E4600E3BEF9D7
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\049811056AFE9FD0F5BE01685AACE6A5D1C4454C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\0B77BEBBCB7AA24705DECC0FBD6A02FC7ABD9B52
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\1331F48A5DA8E01DAACA1BB0C17044ACFEF755BB
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\1F55E8839BAC30728BE7108EDE7B0BB0D3298224
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\209900B63D955728140CD13622D8C687A4EB0085
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\216B2A29E62A00CE820146D8244141B92511B279
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\23E594945195F2414803B4D564D2A3A3F5D88B8C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\24A40A1F573643A67F0A4B0749F6A22BF28ABB6B
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\24BA6D6C8A5B5837A48DB5FAE919EA675C94D217
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\273EE12457FDC4F90C55E82B56167F62F532E547
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\284F55C41A1A7A3F8328D4C262FB376ED6096F24
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\2F173F7DE99667AFA57AF80AA2D1B12FAC830338
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\36863563FD5128C7BEA6F005CFE9B43668086CCE
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\394FF6850B06BE52E51856CC10E180E882B385CC
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4072BA31FEC351438480F62E6CB95508461EAB2F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\43DDB1FFF3B49B73831407F6BC8B975023D07C50
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\43F9B110D5BAFD48225231B0D0082B372FEF9A54
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4463C531D7CCC1006794612BB656D3BF8257846F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\47AFB915CDA26D82467B97FA42914468726138DD
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4B421F7515F6AE8A6ECEF97F6982A400A4D9224E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4BA7B9DDD68788E12FF852E1A024204BF286A8F6
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4C95A9902ABE0777CED18D6ACCC3372D2748381E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\4F65566336DB6598581D584A596C87934D5F2AB4
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\54F9C163759F19045121A319F64C2D0555B7E073
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\58119F0E128287EA50FDD987456F4F78DCFAD6D4
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5B4E0EC28EBD8292A51782241281AD9FEEDD4E4C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5D989CDB159611365165641B560FDBEA2AC23EF1
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5E5A168867BFFF00987D0B1DC2AB466C4264F956
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\5E997CA5945AAB75FFD14804A974BF2AE1DFE7E1
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\627F8D7827656399D27D7F9044C9FEB3F33EFA9A
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\6372C49DA9FFF051B8B5C7D4E5AAE30384024B9C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\6782AAE0EDEEE21A5839D3C0CD14680A4F60142A
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\67EB337B684CEB0EC2B0760AB488278CDD9597DD
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\687EC17E0602E3CD3F7DFBD7E28D57A0199A3F44
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\688B6EB807E8EDA5C7B17C4393D0795F0FAE155F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\68ED18B309CD5291C0D3357C1D1141BF883866B1
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\69BD8CF49CD300FB592E1793CA556AF3ECAA35FB
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\6A174570A916FBE84453EED3D070A1D8DA442829
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\720FC15DDC27D456D098FABF3CDD78D31EF5A8DA
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\74207441729CDD92EC7931D823108DC28192E2BB
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7639C71847E151B5C7EA01C758FBF12ABA298F7A
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\78E9DD0650624DB9CB36B50767F209B843BE15B3
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7A74410FB0CD5C972A364B71BF031D88A6510E9E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7AC5FFF8DCBC5583176877073BF751735E9BD358
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7CA04FD8064C1CAA32A37AA94375038E8DF8DDC0
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\7E784A101C8265CC2DE1F16D47B440CAD90A1945
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\81968B3AEF1CDC70F5FA3269C292A3635BD123D3
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\838E30F77FDD14AA385ED145009C0E2236494FAA
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\85371CA6E550143DCE2803471BDE3A09E8F8770F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\85A408C09C193E5D51587DCDD61330FD8CDE37BF
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\879F4BEE05DF98583BE360D633E70D3FFE9871AF
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\8EB03FC3CF7BB292866268B751223DB5103405CB
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9078C5A28F9A4325C2A7C73813CDFE13C20F934E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\90AEA26985FF14804C434952ECE9608477AF556F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\90DEDE9E4C4E9F6FD88617579DD391BC65A68964
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\96974CD6B663A7184526B1D648AD815CF51E801A
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\97817950D81C9670CC34D809CF794431367EF474
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\97E2E99636A547554F838FBA38B82E74F89A830A
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\99A69BE61AFE886B4D2B82007CB854FC317E1539
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9BACF3B664EAC5A17BED08437C72E4ACDA12F7E7
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9E6CEB179185A29EC6060CA53E1974AF94AF59D4
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\9FC796E8F8524F863AE1496D381242105F1B78F5
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\A399F76F0CBF4C9DA55E4AC24E8960984B2905B6
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\A3E31E20B2E46A328520472D0CDE9523E7260C6D
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\A5EC73D48C34FCBEF1005AEB85843524BBFAB727
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\AB48F333DB04ABB9C072DA5B0CC1D057F0369B46
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\ACED5F6553FD25CE015F1F7A483B6A749F6178C6
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B172B1A56D95F91FE50287E14D37EA6A4463768A
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B19DD096DCD4E3E0FD676885505A672C438D4E9C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B3EAC44776C9C81CEAF29D95B6CCA0081B67EC9D
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B5D303BF8682E152919D83F184ED05F1DCE5370C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B6AF5BE5F878A00114C3D7FEF8C775C34CCD17B6
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\B72FFF92D2CE43DE0A8D4C548C503726A81E2B93
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\BC9219DDC98E14BF1A781F6E280B04C27F902712
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CABB51672400588E6419F1D40878D0403AA20264
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CFDEFE102FDA05BBE4C78D2E4423589005B2571D
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CFF360F524CB20F1FEAD89006F7F586A285B2D5B
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\CFF810FB2C4FFC0156BFE1E1FABCB418C68D31C5
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\D23209AD23D314232174E40D7F9D62139786633A
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\D29F6C98BEFC6D986521543EE8BE56CEBC288CF3
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\D2EDF88B41B6FE01461D6E2834EC7C8F6C77721E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\DA40188B9189A3EDEEAEDA97FE2F9DF5B7D18A41
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\DBAC3C7AA4254DA1AA5CAAD68468CB88EEDDEEA8
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E392512F0ACFF505DFF6DE067F7537E165EA574B
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E4554333CA390E128B8BF81D90B70F4002D1D6E9
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\E5DF743CB601C49B9843DCAB8CE86A81109FE48E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\EBBC0E2D020CA69B222C2BFFD203CB8BF5A82766
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\EC0C3716EA9EDFADD35DFBD55608E60A05D3CBF3
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\EF2DACCBEABB682D32CE4ABD6CB90025236C07BC
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\F44095C238AC73FC4F77BF8F98DF70F8F091BC52
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\Certificates\F88015D3F98479E1DA553D24FD42BA3F43886AEF
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\root
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\root\Certificates
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\root\CRLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\root\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\root\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\root
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\root\
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\root\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\root\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\root\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\ca\PhysicalStores
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\ca
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\ca\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\ca\\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\ca\\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\ca\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\ca
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\ca\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\ca\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\ca\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\063DA67748F0ECCC690D319BCDCD0E72AC8D48D5
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\12519AE9CD777A560184F1FBD54215222E95E71F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\189271E573FED295A8C130EAF357A20C4A9F115E
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\2D69A20EC4F0CD19037FD6D6246B1EE0EC41BA22
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\7B02312BACC59EC388FEAE12FD277F6A9FB4FAC1
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\8B24CD8D8B58C6DA72ACE097C7B1E3CEA4DC3DC6
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\9F025D9F58711A605EB0694B0E8BC0CA4F25FD6F
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\BA9E3C32562A67128CAABD4AB0C500BEE1D0C256
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\E5215D3460C2C20BBE2D9FE5FB665DAA2C0E225C
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\F6357239B7C39725BD8000646E4A0D18EBCE4CFA
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\FE622EA7B33CA46519AB39736A66B8F6E41FF157
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\ca\\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ca
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ca\Certificates
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ca\CRLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\ca\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\ca\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\ca
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\ca\
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\ca\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\ca\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\ca\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\disallowed\PhysicalStores
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\disallowed
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\disallowed\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\disallowed\\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\disallowed\\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\disallowed\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\disallowed
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed\
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed\\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed\\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\disallowed\\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\disallowed
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\disallowed\Certificates
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\disallowed\CRLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\disallowed\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\disallowed\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\disallowed
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\disallowed\
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\disallowed\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\disallowed\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\disallowed\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\trust
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\trust\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\trust\\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\trust\\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\trust\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\trust\\CTLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust\Certificates
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust\CRLs
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\trust\CTLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\\Certificates
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\\CRLs
HKEY_LOCAL_MACHINE\Software\Microsoft\EnterpriseCertificates\trust\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\my\PhysicalStores
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\my
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1547161642-507921405-839522115-1004
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Environment
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Volatile Environment
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\my\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\my\\Certificates
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\my\\CRLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\my\\CTLs
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\SystemCertificates\my\\Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllConvertPublicKeyInfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllConvertPublicKeyInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SystemCertificates\AuthRoot
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\SchemeDllRetrieveEncodedObjectW
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\SchemeDllRetrieveEncodedObjectW
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllEncodeObjectEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4
Comments
User comments about 609e618f198c6b871e141bf89c20a63000097a48899c6b35324c8595e5eb0297.
NOTICE: We have updated our privacy terms and conditions in accordance to GDPR. By using our site, you acknowledge that you have read and understand our Privacy Policy. Your use of ThreatMiner’s Products and Services is subject to these policies and terms.