C:\Users\test\AppData\Local\Temp\version.dll
C:\Users\test\AppData\Local\Temp\version.dll.123.Manifest
C:\Users\test\AppData\Local\Temp\version.dll.124.Manifest
C:\Users\test\AppData\Local\Temp\version.dll.2.Manifest
C:\Windows\SysWOW64\rundll32.exe
C:\Users\test\AppData\Local\Temp\RASAPI32.dll
C:\Windows\System32\rasapi32.dll
C:\Users\test\AppData\Local\Temp\rasman.dll
C:\Windows\System32\rasman.dll
C:\Users\test\AppData\Local\Temp\WINMM.dll
C:\Windows\System32\winmm.dll
C:\Windows\SysWOW64\rundll32.exe.Local\
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
C:\Windows\SysWOW64
C:\Users\test\AppData\Local\Temp\4a19dd.tmp
C:\Windows\System32\ntdll.dll
C:\
C:\Users\test\AppData\Local\Temp\4a1a1c.tmp
C:\Windows\System32\user32.dll
C:\Users\test\AppData\Local\Temp\4a1a4c.tmp
C:\Windows\System32\gdi32.dll
C:\Users\test\AppData\Local\Temp\version.dll
C:\Users\test\AppData\Local\Temp\version.dll.123.Manifest
C:\Users\test\AppData\Local\Temp\version.dll.124.Manifest
C:\Users\test\AppData\Local\Temp\version.dll.2.Manifest
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\System32\rasapi32.dll
C:\Windows\System32\rasman.dll
C:\Windows\System32\winmm.dll
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
C:\Windows\System32\ntdll.dll
C:\Users\test\AppData\Local\Temp\4a19dd.tmp
C:\Windows\System32\user32.dll
C:\Users\test\AppData\Local\Temp\4a1a1c.tmp
C:\Windows\System32\gdi32.dll
C:\Users\test\AppData\Local\Temp\4a1a4c.tmp
C:\Users\test\AppData\Local\Temp\4a19dd.tmp
C:\Users\test\AppData\Local\Temp\4a1a1c.tmp
C:\Users\test\AppData\Local\Temp\4a1a4c.tmp
C:\Users\test\AppData\Local\Temp\4a19dd.tmp
C:\Users\test\AppData\Local\Temp\4a1a1c.tmp
C:\Users\test\AppData\Local\Temp\4a1a4c.tmp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableImprovedZoneCheck
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\version.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\DisableImprovedZoneCheck
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\version.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
kernel32.dll.IsProcessorFeaturePresent
cryptbase.dll.SystemFunction036
kernel32.dll.GetVersionExA
kernel32.dll.GetModuleHandleA
kernel32.dll.GetProcAddress
kernel32.dll.IsWow64Process
kernel32.dll.GetCurrentProcess
kernel32.dll.WideCharToMultiByte
kernel32.dll.GetSystemDirectoryA
kernel32.dll.CopyFileA
ntdll.dll.RtlMoveMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.VirtualFreeEx
kernel32.dll.GetLogicalDriveStringsA
kernel32.dll.QueryDosDeviceA
kernel32.dll.GetShortPathNameA
kernel32.dll.GetCurrentProcessId
ntdll.dll.RtlAdjustPrivilege
kernel32.dll.OpenProcess
advapi32.dll.OpenProcessToken
advapi32.dll.LookupPrivilegeValueA
advapi32.dll.AdjustTokenPrivileges
kernel32.dll.CloseHandle
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Module32First
kernel32.dll.Module32Next
kernel32.dll.ReadProcessMemory
kernel32.dll.WriteProcessMemory
kernel32.dll.LoadLibraryExA
kernel32.dll.FreeLibrary
kernel32.dll.CreateRemoteThread
kernel32.dll.WaitForSingleObject
kernel32.dll.LoadLibraryA
version.dll.GetFileVersionInfoA
version.dll.GetFileVersionInfoByHandle
version.dll.GetFileVersionInfoExW
version.dll.GetFileVersionInfoSizeA
version.dll.GetFileVersionInfoSizeExW
version.dll.GetFileVersionInfoSizeW
version.dll.GetFileVersionInfoW
version.dll.VerFindFileA
version.dll.VerFindFileW
version.dll.VerInstallFileA
version.dll.VerInstallFileW
version.dll.VerLanguageNameA
version.dll.VerLanguageNameW
version.dll.VerQueryValueA
version.dll.VerQueryValueW
version.dll.#1
oleaut32.dll.#500