Analysis

Category Package Started Completed Duration Options Log(s)
FILE exe 2025-06-13 07:10:21 2025-06-13 07:41:11 1850 seconds Show Options Show Analysis Log
procmemdump=1
import_reconstruction=1
unpacker=2
norefer=1
no-iat=1
2024-11-25 13:37:15,006 [root] INFO: Date set to: 20250612T19:21:02, timeout set to: 1800
2025-06-12 20:21:02,726 [root] DEBUG: Starting analyzer from: C:\tmp_gell1p8
2025-06-12 20:21:02,726 [root] DEBUG: Storing results at: C:\iDarMfdE
2025-06-12 20:21:02,726 [root] DEBUG: Pipe server name: \\.\PIPE\IMPWOAOm
2025-06-12 20:21:02,726 [root] DEBUG: Python path: C:\Users\Packager\AppData\Local\Programs\Python\Python310-32
2025-06-12 20:21:02,726 [root] INFO: analysis running as an admin
2025-06-12 20:21:02,726 [root] INFO: analysis package specified: "exe"
2025-06-12 20:21:02,726 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2025-06-12 20:21:03,149 [root] DEBUG: imported analysis package "exe"
2025-06-12 20:21:03,149 [root] DEBUG: initializing analysis package "exe"...
2025-06-12 20:21:03,149 [lib.common.common] INFO: wrapping
2025-06-12 20:21:03,149 [lib.core.compound] INFO: C:\Users\Packager\AppData\Local\Temp already exists, skipping creation
2025-06-12 20:21:03,149 [root] DEBUG: New location of moved file: C:\Users\Packager\AppData\Local\Temp\InputPersonalization.exe
2025-06-12 20:21:03,149 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2025-06-12 20:21:03,149 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2025-06-12 20:21:03,149 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2025-06-12 20:21:03,149 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2025-06-12 20:21:03,383 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-06-12 20:21:03,414 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2025-06-12 20:21:03,461 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-06-12 20:21:03,477 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-06-12 20:21:03,492 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-06-12 20:21:03,492 [lib.api.screenshot] ERROR: No module named 'PIL'
2025-06-12 20:21:03,492 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-06-12 20:21:03,508 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-06-12 20:21:03,508 [root] DEBUG: Initialized auxiliary module "Browser"
2025-06-12 20:21:03,508 [root] DEBUG: attempting to configure 'Browser' from data
2025-06-12 20:21:03,508 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-06-12 20:21:03,508 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-06-12 20:21:03,508 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-06-12 20:21:03,508 [root] DEBUG: Initialized auxiliary module "DigiSig"
2025-06-12 20:21:03,508 [root] DEBUG: attempting to configure 'DigiSig' from data
2025-06-12 20:21:03,508 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2025-06-12 20:21:03,508 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2025-06-12 20:21:03,508 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2025-06-12 20:21:03,633 [modules.auxiliary.digisig] DEBUG: File is not signed
2025-06-12 20:21:03,633 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2025-06-12 20:21:03,633 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2025-06-12 20:21:03,633 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-06-12 20:21:03,633 [root] DEBUG: attempting to configure 'Disguise' from data
2025-06-12 20:21:03,633 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-06-12 20:21:03,633 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-06-12 20:21:03,633 [modules.auxiliary.disguise] INFO: Disguising GUID to ce863701-2277-4ca4-b783-294e80b72cd2
2025-06-12 20:21:03,633 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2025-06-12 20:21:03,633 [root] DEBUG: Initialized auxiliary module "Human"
2025-06-12 20:21:03,633 [root] DEBUG: attempting to configure 'Human' from data
2025-06-12 20:21:03,633 [root] DEBUG: module Human does not support data configuration, ignoring
2025-06-12 20:21:03,633 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-06-12 20:21:03,633 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-06-12 20:21:03,633 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-06-12 20:21:03,633 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-06-12 20:21:03,633 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-06-12 20:21:03,633 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-06-12 20:21:03,633 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2025-06-12 20:21:03,633 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-06-12 20:21:03,633 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-06-12 20:21:03,633 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-06-12 20:21:03,633 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-06-12 20:21:03,633 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-06-12 20:21:03,633 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 696
2025-06-12 20:21:03,664 [lib.api.process] INFO: Monitor config for <Process 696 lsass.exe>: C:\tmp_gell1p8\dll\696.ini
2025-06-12 20:21:03,664 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2025-06-12 20:21:03,664 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2025-06-12 20:21:03,664 [lib.api.process] INFO: Option 'unpacker' with value '2' sent to monitor
2025-06-12 20:21:03,664 [lib.api.process] INFO: Option 'norefer' with value '1' sent to monitor
2025-06-12 20:21:03,664 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2025-06-12 20:21:03,664 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2025-06-12 20:21:03,664 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp_gell1p8\dll\NmhMelLB.dll, loader C:\tmp_gell1p8\bin\TfDuBatI.exe
2025-06-12 20:21:03,727 [root] DEBUG: Loader: IAT patching disabled.
2025-06-12 20:21:03,727 [root] DEBUG: Loader: Injecting process 696 with C:\tmp_gell1p8\dll\NmhMelLB.dll.
2025-06-12 20:21:03,758 [root] DEBUG: 696: Python path set to 'C:\Users\Packager\AppData\Local\Programs\Python\Python310-32'.
2025-06-12 20:21:03,758 [root] INFO: Disabling sleep skipping.
2025-06-12 20:21:03,758 [root] DEBUG: 696: Full process memory dumps enabled.
2025-06-12 20:21:03,758 [root] DEBUG: 696: Import reconstruction of process dumps enabled.
2025-06-12 20:21:03,758 [root] DEBUG: 696: Active unpacking of payloads enabled
2025-06-12 20:21:03,758 [root] DEBUG: 696: CAPE debug - unrecognised key norefer.
2025-06-12 20:21:03,758 [root] DEBUG: 696: TLS secret dump mode enabled.
2025-06-12 20:21:03,758 [root] DEBUG: 696: InternalYaraScan: Scanning 0x00007FF84A790000, size 0x1f4542
2025-06-12 20:21:03,774 [root] DEBUG: 696: InternalYaraScan hit: RtlInsertInvertedFunctionTable
2025-06-12 20:21:03,774 [root] DEBUG: 696: RtlInsertInvertedFunctionTable 0x00007FF84A7A090E, LdrpInvertedFunctionTableSRWLock 0x00007FF84A8FB4F0
2025-06-12 20:21:03,774 [root] DEBUG: 696: Monitor initialised: 64-bit capemon loaded in process 696 at 0x00007FF8234D0000, thread 3696, image base 0x00007FF60D500000, stack from 0x0000008EFACF4000-0x0000008EFAD00000
2025-06-12 20:21:03,774 [root] DEBUG: 696: Commandline: C:\Windows\system32\lsass.exe
2025-06-12 20:21:03,789 [root] DEBUG: 696: Hooked 5 out of 5 functions
2025-06-12 20:21:03,789 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-06-12 20:21:03,789 [root] DEBUG: Successfully injected DLL C:\tmp_gell1p8\dll\NmhMelLB.dll.
2025-06-12 20:21:03,789 [lib.api.process] INFO: Injected into 64-bit <Process 696 lsass.exe>
2025-06-12 20:2 <truncated>

    

    

    

Machine

Name Label Manager Started On Shutdown On Route
win10-2 win10-2 KVM 2025-06-13 07:10:21 2025-06-13 07:40:52 none

File Details

File Name
InputPersonalization.exe
File Type PE32+ executable (GUI) x86-64, for MS Windows
File Size 370688 bytes
MD5 5eb61dd8247ef8bf082cdb3303c8c62e
SHA1 b1414a40a3a9bfc254a09b87b93d2ae4077e32a1
SHA256 8aa842d57512f3551adc2d0e9a75383bffd3e62ff79f5ad941c7c36e4194a236 [VT] [MWDB] [Bazaar]
SHA3-384 d71073c916f9c07048a5d37b7be226ff73dc9bbb76b5f4fc8148acd0b81bb710e9e09a2a56b7a7edad8c3ac43b1baf25
CRC32 8680CBA2
TLSH T18C743A16B7DC58E6E536923CCA97C28AF7B2B4051F6196CB1220434E3F37AE59D3A311
Ssdeep 6144:TcSu/lXdWJUbYF5dSvditPzWpFlxxbA14tHsDCfkj4jKRcmtr/rKj:luZduUbYF54vktPuvbA14tM+fKIK+m1
File BinGraph Vba2Graph VirusTotal

9D$Xt
Creating ContactHarvester registry key
l$ VWATAVAWH
@.data
fA9tM
fD9)t
INK_ITEM_TYPE_SUI_LINESCRIPTl
SVWATAVAWH
hA_A^A]A\_^[]
@8|$Vt0I
@8j8uUD
@8hAu
ReleaseMutex
GetStartupInfoW
H;\$p
tRHcW
0A^^[
<security>
APPID
f9<Ju
y8uDH
t$hH;
-both
f;D$(uYH
CoMarshalInterThreadInterfaceInStream
CreateSemaphoreExW
H;8u$A
D8X@u
$TEXT_HARVESTER_SOURCE_ID_TIP
L$XI9u(
OpenFileMappingW
RestrictImplicitTextCollection
u*9Q<|%
D;S0|
GetSecurityDescriptorLength
T$ Hc
WaitNamedPipeW
TEXT_HARVESTER_SOURCE_ID_APPOINTMENT_LOCATIONWWW
A_A^A\_^][
L$xE3
CloneWWW
CreateWindowExW
Returns or sets the midline height, or distance from the baseline to the midline, of the guide box.WWWI
A8h9u
!|$\A
WORDLIST-MS-FILEPATH
x,D8t$0t
RegSetValueExW
CreateXmlReader
D8P1t
L$HE3
GetSecurityDescriptorControl
@8j0uUD
SetPriorityClass
A8~XtEA
list<T> too long
WORDLIST-MS-GIVENNAME
\\.\pipe\SearchTextHarvester
CLSIDFromString
Failed allocating memory for data to copy from TrainedDataStore UDICT!
0A_A^A]A\_^[
D8Aat
ROAMED_DICTIONARY_LASTWW
9)viH
api-ms-win-core-string-l1-1-0.dll
VWAVH
MissingContactProperty
o\$PH
pcbWrittenWW
Microsoft Corporation
LCMapStringW
D9APt
l9pRecognitionFlagsWWW
LoadLibraryExW
fD9,Qu
D8p)u
memcmp
u)A8h-t
D!t$$H
u%A8h)t
OutputDebugStringA
_XcptFilter
_wcstoi64
_lock
f;D$~
!\$@!\$\!\$D3
y uDH
D$pH;
AtlThunk_DataToCode
00"INK_ITEM_TYPE_SUI_BOXSCRIPTWl
USVWATAUAVAWH
pwcsName
{8D9FDE44-1B8D-462F-8486-32ED9C2C294B}
Microsoft-Windows-TabletPC-InputPersonalization
@SUVWAVH
UnmapViewOfFile
fD9<ru
SECURITY
@8j,uU@
F0$hF;
L9t$P
AppID
D8O\t
_initterm
TEXT_HARVESTER_SOURCE_ID_DOCUMENT_TEXTWW
.?AVlogic_error@std@@
stdole2.tlbWWW
.idata$5
LoadLibraryW
Returns or sets the number of rows in the guide box.WW7
VersionIndependentProgID = s 'TabIps.InkItem.1'
ExH9G
RecognizerGuideW
f;D$~u
TYPELIB
yTEXT_HARVESTER_SOURCE_ID_CONTACT_CITYWWW
DefaultVersion
CancelIo
{03CC4351-BEA7-437d-8E9F-95A5592AA224}
tqH!l$hH
.pdata
wcschr
Microsoft
I9:u)A8h)t
A8h1u
D8hQu$
A8q,u
.didat$2
@UVWAVAWH
TEXT_HARVESTER_SOURCE_ID_FILE_FOR_EMAIL_BODY
L9t$@t
{4FC31517-B131-4bf2-9BAA-05A400B3FA27}
.?AVCAtlException@ATL@@
INK_ITEM_TYPE_SUI_BOX_ORIGINALWWl
L$PH9
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
.data$r$brc
H;L$(t4fA
dwLockTypeWW,
GetMessageW
Allocating CIPSContactHarvester
D8BAu
IInkRecognizerGuideW
_LARGE_INTEGERWW
e0L9a
8 OIRoamDictionaryW
SetEvent
{6D3087D7-61D2-495f-9293-5B7B1C3FCEAB}
SleepConditionVariableSRW
8Y)u"D9A
_exit
pbstrTruthCorrectedFromAlternate
8A_A^A\_^[
0A^_^
HarvestContacts
ModificationTime
GroundTruthCorrectedFromAlternateStringW
D$(f;
%hs!%p:
K SVWH
Failed getting contact state
INK_ITEM_TYPE_TIP_BOXED_SCRATCH_GESTUREWl
0A_A^A\_^
UnregServer
H{BottomWW
H9{`t)H
HKEY_PERFORMANCE_DATA
pbstrRecognitionAlts
Mscoree.dll
Failed getting contact last name
D8X0uTE
IPS_SettingsManager_GetTrainerCount
p WAVAWH
D8R1u
8p|RoamDictionaryWW
rectDrawnBox
.tls$ZZZ
CoCreateInstance
GetCommandLineW
Initializing COM
IInkRectangleWWW
IInkExplicitContributorW4
8WVDB
IPS_RECOPLUGIN_FilterWordSinkAddText
Failed enabling contact harvesting
p9ColumnsWx
GetStringTypeW
fE9.t
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_14Wl
%windir%\system32\msTextPrediction.dll
CurVer = s 'TabIps.TextContributor.1'
GetFileAttributesW
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_02Wl
~i[sO
CompareFileTime
f9,Ku
D!|$@H
+mc,y8
Software\Microsoft\InputPersonalization\InkStore\LangCounts
INK_ITEM_TYPE_TIP_BOXED_PRE_OVERWRITEWWWl
BTEXT_HARVESTER_SOURCE_ID_ADDRESS_BOOK_ALIASW
.CRT$XIA
@8j)t
D8B9u
LocalServer32 = s '%MODULE%'
NIFTE_DestroyTrainer
0vCountWWW
@A^^[
RemoveWW
WORDLIST-MS-GENERAL
D;Fhs
DispatchMessageW
hA_A^A]A\_^][
D8s)t
WORDLIST-MS-USERTYPED-FILE
Software\Microsoft\TPG\HWRCustomization
plibNewPositionW,
x UAVAWH
GetSidSubAuthority
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
@8h9u
u%A8h9t
&06(TEXT_HARVESTER_SOURCE_ID_CONTACT_STATEWW
XA_A^A]A\_^][
FileDescription
D8q!u-H
9_hv\@
\$ UVWH
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_08Wl
t{D9x
atimeWWW
\$ VWAVH
UWATAVAWH
{6DA087D7-61D2-495f-9293-5B7B1C3FCEAB}
{8D20A413-BC69-4639-805A-566DCFFA645D}
z+;xm
ntdll.dll
D$@H;C8u
bstrText
CurVer = s 'TabIps.InkStore.1'
}MSFT
10.0.17763.1
I+I H
win:Informational
InitializeCriticalSection
WakeAllConditionVariable
SetThreadPriority
A_A^A\_^
HKEY_DYN_DATA
SetWindowLongPtrW
&rgrfStatFlagW,
L$hE3
TabIps.InkStore = s 'InkStore Class'
D8X8u
RightWWW@
XDEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_00_CORRECTEDWWWl
UVWATAWH
L$DE3
fA94^u
/0EKTEXT_HARVESTER_SOURCE_ID_ADDRESS_BOOK_FULL_NAMEW
WritingBoxWW
AddExplicitWT
@8w0t
\$`9s
ITextContributor
{CC2E1031-D547-4b22-B4CF-ADF91817389A}
D$(E3
TraceEvent
CLSID
SetSecurityDescriptorGroup
INK_ITEM_TYPE_TIP_LINED_INSERTWWl
message
originatingContextName
.?AVruntime_error@std@@
0A_A^_^]
D$T9D$P
@8j@uVD
WORDLIST-MS-GENERAL-CACHE
IPS_TIPTEXTCONTRIBUTOR_HarvestText
L$(E3
memmove_s
HA_A^^[
.rdata$zETW9
TEXT_HARVESTER_SOURCE_ID_CONTACT_STREETW
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_11_CORRECTEDWWWl
D8@At
{B5264E56-B32E-4996-8D8D-AE03B7CB5665}
UVWAVAWH
L$0E3
D$HH9
L$8H3
D$ H+
WORDLIST-MS-FULLNAME
_itow_s
A_A^A\_]
L$HH98t A;q
@8j-u
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_09_CORRECTEDWWWl
ProgID = s 'TabIps.InkStore.1'
INK_ITEM_TYPE_TIP_LINED_ALTERNATEWWWl
FailedHResult
IPS_Harvest_AppDictionary
TerminateProcess
\$ UVWAVAW
2VxF;P
{D23D36FA-18CF-493d-BA07-9CCB1BC1CCFB}
d$PL9%
@8q\t
f9,Au
D$QE2
{773AEC7B-FEC3-45fc-9478-E02BDADD793C}
TEXT_HARVESTER_SOURCE_ID_NOTE_TEXTWW
Software\Microsoft\InputPersonalization
\$ A;
D$P;C
H!D$PL
A_A^A]
D8X`u
ROAMED_DICTIONARY_ID
F0$hF
{6D8087D7-61D2-495f-9293-5B7B1C3FCEAB}
D$`H+
E208CCA6-44BC-45CA-9FBF-DAE2263B9583
Creating CTextHarvesterItem
Software\Microsoft\InputPersonalization\TrainedDataStore\
WORDLIST-MS-CORRECTION
HarvesterState
.text$x
CreateMutexW
T$ E3
_wtoi
SetFileAttributesW
D9l$T~
TEXT_HARVESTER_SOURCE_ID_CONTACT_TEXTWWW
GTEXT_HARVESTER_SOURCE_ID_EMAIL_BODYW
wcstoul
fE9,Hu
.xdata$x
L$HH3
A^_^
GetModuleHandleW
%localappdata%\microsoft\InputPersonalization\TrainedDataStore
D$PI;
{B7F49499-D1C7-4f6f-B1F6-A18AF6E799A3}
TEXT_HARVESTER_SOURCE_ID_TASK_TITLEW
szDictionaryFullPath
CurrentUserLexicon
.CRT$XLZ
.giats
kernelbase.dll
VAVAWH
.rsrc
$TabIpsLibWWW
SystemTimeToFileTime
EHH9F
TimeStampInterval
0A_A^_
OriginalFilename
win:Start
PucHc
ulIndexW4
D8ExuU
D8X8uTE
~1A8~0
api-ms-win-core-interlocked-l1-1-0.dll
en-us
@8p,uTA
D8B1u
pOutInkTypeWL
pguidApplicationContextW
@8}H@
9{hv"H
D9|$`u
>ResetWWW
(libOffsetWWW
BeginEndTokens
fD94Au
%LocalAppData%\Microsoft\Ink\HWRCustomization
ForceRemove {70445657-5AB0-11d9-A4E5-00301BB132BA} = s 'InkStore Class'
D;t$(r
\$8E3
D$,9G
@8oQt
_resetstkoflw
tCfD9e
{6510E5BB-5508-49C0-B192-5BB38D0D2F14}
RemoteWriteW
UVWATAUAVAWH
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
zh-Hant
CloseHandle
L$8E3
IPS_PLUGINCLIENT_ProcessMessage
,0TrainCompleteWWW
@.reloc
E8Y@u
InkStore
Microsoft.Windows.TextInput.InputPersonalizationTraceLogging
0A_A^A]_^
D$ H9G
L$PA;
LoadResource
_purecall
H9D$Pu
hA^_^[
@8k-u
D9K(t
failureCount
GetSystemTimeAsFileTime
>SetRectanglex
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_06_CORRECTEDWWWl
RegEnumValueW
D8cItJH
AtlThunk_InitData
H9Q r H
e A_A^A]A\]
EPH;E
TrainWWW
{pTimeWWW
fD94xu
AbortTrainer
A8h1t
rt$fA
|$HE3
grfLocksSupportedWWW
0TypeMask
IPS_TIPTEXTCONTRIBUTOR_HarvestTextForType
CharNextW
H9^0t
SetUnhandledExceptionFilter
Recognized Languages
wcscmp
pstatstg
fB9,ru
w`H!E
CL$`A
"pbstrTruthCorrectedByInputWW
D$ E3
.text
INK_ITEM_TYPE_SUI_BOX_CONFUSIONWl
D8x)u
EidDictionary
<description>Tablet InputPersonalization.</description>
Recognizer Capability Flags
L$8H!\$8
.rdata$brc
MappingGetServices
f;D$hH
ppInkCollectionW
originatingContextId
L$`E3
f;L$|u
I9:u)A8h1t
TextHarvestingInstallationStatus
dwHighDateTimeWW
k(fE9.t
NumberRequired
StrRStrIW
t$8I;
.idata$4
_ULARGE_INTEGERW,
IPS_TIPTEXTCONTRIBUTOR_HarvestTextAndContext
L9d$xtxH
^pvWW
4!RectangleWWWx
.rdata$T$brc
GetTokenInformation
SubjectToken
`A_A^A]A\_^[
Component Categories
{B1445657-5A98-11d9-A4E5-00301BB132BA}
__dllonexit
fclose
D8A)t
D8X(uTE
RegEnumKeyExW
GetStringTypeExW
}HKCR
,*cbSizeWW
InitializeSecurityDescriptor
StartMatchDataToken
D9l$PtTH
IPS_SettingsManager_GetDisablePersonalization
HcD$ H
fIsRemovedWW
@8j-t
__C_specific_handler
@USVWAVAWH
f9<Au
IsInkStoreCollectionEmptyWWW
D8A1t
@8j8uVD
{84445657-1F93-11dc-981E-0019B910A13E}
0A_A^A]A\_^]
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_10Wl
tDfD93t>H
|$@E3
#9Uxu
H!|$pH!|$xH!}
%s\%s
CreateEventW
CommitWW
LoadLibraryExA
Represents access to a rectangle for Automation users.=
.text$mn$00
t$ WH
SetLastError
.rsrc$01
ITipInkHistory InterfaceWW
CallContext:[%hs]
ProgID = s 'TabIps.TextContributor.1'
DebugBreak
pbstrTruthString
{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}
Y@H9;u%L
Returns or sets access to the rectangle struct.WWWM
A_A^A]A\_^[]
RegDeleteValueW
D$pE3
OffsetRect
IPS_INKSTORE_AddTipInk
uO9T$`vIL
pulIndex
{BBC5786D-9339-4d44-A413-302825D70E02}
InitializeAcl
CoTaskMemRealloc
CoInitialize
VirtualAlloc
{CEE1F374-5E00-4e90-BE5E-102C7ADF14AD}
GetSecurityDescriptorDacl
u,D9J
D8x)ug
GetTraceEnableLevel
fD99t
_CxxThrowException
TEXT_HARVESTER_SOURCE_ID_SHAPE_COLLECTOR
t^@8=$
IPS_LAD_Create
f9<Xu
\[Initd
LeaveCriticalSection
L$ USVWAVH
D9l$(vY
App Lexicon Timestamp
H!t$HH!t$PH!t$0H
WORDLIST-MS-USERREMOVED
HcAXH
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_04_CORRECTEDWWWl
D8Bau
L$ SVWH
GetTraceLoggerHandle
ProgID = s 'TabIps.InkItem.1'
u%A8h1t
CElsLad::CElsLad/MappingGetServices
Microsoft Corporation. All rights reserved.
LocaleNameToLCID
.?AVexception@@
callContext
L$PH3
PathAddBackslashW
SHCreateStreamOnFileW
Querying HARVESTER_VALUE from registry
?{uSH
C L9s
.text$yd
fE9/t
0A_A\_^]
BEhf;
fD9{l
GetWindowLongPtrW
JVhResultW
CreateDirectoryW
WORDLIST-MS-USERADDED
PA_A^_^]
LcA<E3
*0i+TEXT_HARVESTER_SOURCE_ID_CONTACT_NICK_NAMEWW
Wadvapi32.dll
Resource0
-voseo
H WATAUAVAWH
WORDLIST-MS-APPADDED
D8R-u
AcquireSRWLockExclusive
MappingFreeServices
CJt0H
`A_A^A]A\_^]
DestroyTrainer
MsgWaitForMultipleObjects
l$ E3
pRecognizerGuide
pCountWW
fE9xl
WORDLIST-MS-USERTYPED
LegalCopyright
VersionIndependentProgID = s 'TabIps.InkStore'
CallWindowProcW
function
ATL$__a
Enabled
fA9z*v$A
fD9z*vV
%s\%s\%s
GetSystemTime
StartToken
HL$pH
version="1.0.0.0"
I9:u)A8hAt
IPS_InkStore_Initialize
Failed CoInitialization
D8XPu
fA;z*
D8Q1u
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_12Wl
D9|$P
fE9<Cu
L;l$HD
@8kJt
IPS_RECOPLUGIN_FilterWordSinkAddProperty
Failed initializing TextTrainerList or no trainers in the list
@8j(uVD
@A_A^A]A\_^]
L$0H3
GroundTruthStringWWW
SVATAUAVAWH
FlushInstructionCache
q_MergeWWW
CreateTrainer
HeapDestroy
fread
NoRemove CLSID
.rdata$zzzdbg
_vsnprintf_s
{75AA3D91-B49F-4b2b-9DA4-528505E49DD5}
ForceRemove 'Programmable'
@8h)u
WAVAWH
A__^
D:P(A;OICI;GA;;;BA)(A;OICI;GA;;;SY)(A;OICI;GA;;;OW)(A;OICI;GR;;;AC)
AtlThunk_FreeData
.rdata
realloc
|$XE3
??1type_info@@UEAA@XZ
??0exception@@QEAA@XZ
api-ms-win-core-errorhandling-l1-1-0.dll
9t$<}!
RegDeleteKeyW
A_A^_^[]
83GISequentialStreamWWW
Begin
mtimeWWW
Returns or sets the left position of the InkRectangle object.W?
L$ WH
D$$I;
Software\Microsoft\TPG\LanguageModel
L9D$P
<assemblyIdentity
L9{Pt
x AWH
pA_A^A]A\_^[
TabIps 1.0 Type LibraryWWW
@8j9u
@8kAuDH
l$HLc
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_13Wl
D9nhvDL
tnH;}
WaitForSingleObject
I9:u)A8h9t
CLSID = s '{64445657-9101-11d9-994B-00301BB132BA}'
L$ UVWATAUAVAWH
OpenProcessToken
pbstrLeftContext
GetClassInfoExW
pHistory
B0AA5481-05C1-4719-9A29-EE713099C5DF
GetModuleFileNameA
0INK_ITEM_TYPE_TIP_WORD_OKWWWl
D8p)t
D8X-u
WORDLIST-MS-EMAILSMTP
WVD|mI
@8kHt
SVWATAUAVAWH
0A_A^A\
D9|$@v"H
FindResourceExW
{01ACCE07-7D1F-4c09-BC12-A24B2036DCA5}
D9|$`H
api-ms-win-core-sysinfo-l1-1-0.dll
D$XH;D$pu
^f91u
I|$`x
memcpy
.idata$3
XA_A^A]A\_^[]
H!\$0H
RGroundTruthCorrectedByInputW
L95dV
TEXT_HARVESTER_SOURCE_ID_ADDRESS_BOOK_LAST_NAMEW
VersionIndependentProgID = s 'TabIps.TextContributor'
ForceRemove {64445657-9101-11d9-994B-00301BB132BA} = s 'InkItem Class'
@8ugt0;}
.didat$5
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_05Wl
RtlDllShutdownInProgress
DEPRECATED_INK_ITEM_TYPE_TIP_WORD_CHARACTER_DELETEWWl
Pu5Hc
{473731F7-7681-4817-BAA5-E1F1DD2DE4A6}
TabIps.TextContributor = s 'TextContributor Class'
fDoNotUseWWW
TEXT_HARVESTER_SOURCE_ID_CONTACT_FULL_NAMEWW
{815E2586-C5FB-4fea-9992-328172360483}
string too long
UnitsWWW
y0uDH
fD9uP
A8hAt
Failed getting contact first name
ExpandEnvironmentStringsW
}0L9(t
D8A1u
1DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_02_CORRECTEDWWWl
(_^][
Returns or sets the bottom position of the InkRectangle object.WWW>
LEVL@
__setusermatherr
UATAUAVAWH
HeapFree
invalid string position
WORDLIST-MS-SURNAME
@8jAu
currentContextId
GetTickCount
NIFTE_TextTrain
fE9$Ou
T$PE3
{Left
D8X0u
OptionalDataToken
DEPRECATED_INK_ITEM_TYPE_TIP_WORD_CHARACTER_INSERTWWl
L$@E3
TEXT_HARVESTER_SOURCE_ID_UNKNOWN
.CRT$XIY
f;t$(u
L$@H3
PostMessageW
-tuteo
b4WVD
D9C0~
_wfopen
D$XH;
@8|$Tt
WEVT_TEMPLATE
(0}ERECOGNITION_TRAIN_REASON_DELETE_ALL_DATA
T$`E3
TimeStamp
UWAVH
u(8Y`t
\$0H;
MultiByteToWideChar
ATL$__m
A_A^A\
GetSecurityDescriptorSacl
/fD;e
api-ms-win-core-memory-l1-1-0.dll
t'fA9u
\$PH;
InputPersonalization.pdb
EventSetInformation
Failed getting contact email
</requestedPrivileges>
tmD85
D$(9G
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_05_CORRECTEDWWWl
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_11Wl
Bs`fD
UWAUAVAWH
Software\Policies\Microsoft\InputPersonalization
OutputDebugStringW
IpsContactHarvesterState
IPS_Main
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_13_CORRECTEDWWWl
UnregisterTraceGuids
@SVWAVAWH
ReturnHr
_itow
SHELL32.dll
D8`)t
'01OTEXT_HARVESTER_SOURCE_ID_APP_DICTIONARYW
x*D8d$Lt#D
IPS_SHAPECOLLECTOR_Close
T$XE3
ctimeWWW
@HcATH
@A^_]
;Data
VpRecoGuideWWl
;\$@r
Resource
A^A\]
D9S0~RE3
!|$@3
Failed adding ContactHarvester IPS Language Model
GetOverlappedResult
pbstrOverwrittenText
L$8D;9t?A
Software\Microsoft\Speech\AppLexicons
Proxy
@8,1u
@SUVWATAVAWH
WATAUAVAWH
fD9t]
TabIps.InkStore.1 = s 'InkStore Class'
tGHcl$HH
VVZOQ2VtUklTblppYldSc1kybENhRmt5VG14ak0wMW5ZbGM1YTFwWGQyZGFiVGw1U1VVMVRWSjNQVDA9
Software\Microsoft\InputPersonalization\InkStore\ToTrainExplicit
f;D$|u
D9d$@
D8X@uTE
g-pcbReadW
TextPredictionCapabilities
A_A^A]A\_
|$ E3
.CRT$XCAA
CoGetInterfaceAndReleaseStream
A8~0u!H
Hc}oH
\$ UH
TEXT_HARVESTER_SOURCE_ID_ADDRESSBOOK_FIRST_NAMEW
ADVAPI32.dll
D$XL;G
@8h9t
@8j(uUD
L95eo
CreateThread
L9{0t#H
.00cfg
CoRevokeClassObject
AcceptedPrivacyPolicy
_wcsicmp
FreeLibrary
9\$pu9A
FailFast
TEXT_HARVESTER_SOURCE_ID
tTM;}
|$xH;
T$0E3
CInkStoreShared Message Window
L9s vmA
OpenThreadToken
D8q)t
ATAVAWH
<X-uj
CompanyName
tFD9!vA
invalid map/set<T> iterator
H!\$PH
GetCurrentThreadId
uMH!]8E
D8Xau
INK_ITEM_TYPEWWWl
kROAMED_DICTIONARY_USERTYPEDW
u%A8hAt
u HcA<H
@8j9t
@8j@uUD
{6D7087D7-61D2-495f-9293-5B7B1C3FCEAB}
calloc
CoRegisterClassObject
GetProcessHeap
@8j0uVD
t3H!|$ L
@8h-t
Sleep
HKEY_CLASSES_ROOT
trending-ngrams-en-us.hwrdict
O_InkRecoGuideWWW
pt#D9
@8nAt
TextContributorW(
'%APPID%' = s 'TabIps'
@A_A^A]A\_
SentItemsHint%d
;|$X|
@8uwv#I
t$ UWATAVAWH
H9_ s
o0H9oHueH
{6D2087D7-61D2-495f-9293-5B7B1C3FCEAB}
D8sHt
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_08_CORRECTEDWWWl
{ AVH
atlthunk.dll
uRH!\$0E
8zZIInkImplicitContributorW
oT$@f
GetKeyboardLayoutList
RegOpenKeyExW
H9_Hs<
VWATAUAVAWH
ReleaseSemaphore
(0 yTEXT_HARVESTER_SOURCE_ID_CONTACT_COMPANY
{BB8B9E01-EDA4-4fa8-A5FA-E5FA7BD6C0E9}
IPS_RECOPLUGIN_GathererDataSinkShutdown
wcsncpy_s
!C$H!C(H!C0H
\$ H9_
~ L;~(r
L$`A;
WORDLIST-MS-OUTOFDICTIONARY-CACHE
GetSidLengthRequired
FindFirstFileW
_wcsnicmp
D8hQu&D
PA_A^A]A\_^]
SetSecurityDescriptorDacl
l$ VWAVH
@8h-u
E8Y8u
?what@exception@@UEBAPEBDXZ
qLcid
{8AAFE0B6-151F-4e8a-8D98-E564FD9103E1}
A^_^][
ppstmWWW
HcK0H
fE94Au
t!Hc{
SetSecurityDescriptorOwner
|$8E3
L$ SUVWH
ResolveDelayLoadedAPI
{EB01A8B8-39E0-4781-88CF-02237485FB83}
pt(fA
D$HH;C@u
D$hH;A
AddInkWW
RegisterClassExW
OpenFileFromMemory - Failed to allocate %lu bytes!
@8nQt
@8~8t
\Required Categories
??0exception@@QEAA@AEBQEBD@Z
wcsrchr
s fD97t
]$C9"D
SettingsManager Message Window
D8X9u
WaitForMultipleObjects
FInkRecoGuide
D8s,t
BeginEndToken
D8cIt2
UATAVH
{6D4087D7-61D2-495f-9293-5B7B1C3FCEAB}
D$PE3
IIpsCollectionWW
D8@at
.didat$7
CurVer = s 'TabIps.InkItem.1'
(caller: %p)
GetRectangle
Represents the area used by the recognizer in which ink can be drawn.Wf
D8AAu
L$PH;
@8y(t
_callnewh
RPCRT4.dll
D8X u
f94Bu
x@A;A
StringFromGUID2
L9t$ u
D9eHA
__set_app_type
@8oQuGH
<UbRecognitionAltListW
IPS_SHAPECOLLECTOR_Save
RightContext
A8H;A@t
IInkRecognizerGuide InterfaceW
bstrSupplementaryTextWWW
040904B0
@8jAu@H
DestroyW
D8AQt
.rdata$zETW2
8+stagTEXT_HARVESTER_ITEMWW
T$HH;
SizeofResource
wcstol
D8P-t
CreateFileMappingW
InkItemW
Contact Display Name
@USVWAVH
LanguageSpecificInit
lstrcmpiW
swprintf_s
H;L$ u
D8X,u
HcA<H
.?AVbad_alloc@std@@
A_A^A]A\_^]
@8i-u*H
H;D$Hu
PeekMessageW
A_A^]
WORDLIST-MS-NGRAM-CACHE
D8x)H
Returns or sets the number of columns in the guide box.WWWc
fp>GuF
wlcidTrainLangWWW
SHLWAPI.dll
L$4E3
TranslateMessage
D8A9t
MaximumInkStoreSize
wcscat_s
kUpdateGeneralWithCacheWW
InitOnceComplete
ForceRemove
9D$ u
L!l$PH
K tEA
ReadFile
El`I2
INK_ITEM_TYPE_TIP_LINED_SCRATCH_GESTUREWl
GetAclInformation
f;E0uv
l$xD8~
RegQueryValueExW
t<D9|$@u5H
@SVWH
D8Q-u
VWAUAVAWH
A_A^_^[
A^_^H
t$(E3
@8pQu
VarFileInfo
_fmode
H9{`t*H
HRESULT
{E257A558-0E73-4e11-8811-1BB37B26262C}
val AppID = s '%APPID%'
</security>
E:fC;D~
fD9:t
t$`fD9t$`t2H
CoSuspendClassObjects
VWAWH
QuadPartX
_vsnwprintf
api-ms-win-core-libraryloader-l1-2-0.dll
Input Personalization Server
@8{Jt
_ui64tow_s
?,cColumnsx
0isINK_ITEM_TYPE_SUI_FREE_ORIGINALWl
CreateFileW
RegDeleteTreeW
6iTimeLastUpdateW
D8s!t
A8h-t
SWVDJQM
D8Aau
TEXT_HARVESTER_SOURCE_ID_TASK_TEXTWW
Local\SM0:%d:%d:%hs
RoamDictionary ClassWW
TEXT_HARVESTER_SOURCE_ID_CONTACT_COUNTRY
IPS_InkStore_Clear
RegGetValueW
SUVWAVH
D8w t
L$PE3
L$0t1
@8s=u
FormatMessageW
D8p!t
module
x3D8|$]t,A
onecoreuap\base\win32\winnls\els\advancedservices\handwriting\recognizer\personalization\traineddatastore\ctraineddatastore.cpp
InitializeCriticalSectionAndSpinCount
D8Ext
Returns or sets the right position of the InkRectangle object./
CoUninitialize
<!-- Copyright (c) Microsoft Corporation -->
{ UAVAWH
D8q)u-H
A_A^A]A\_
10.0.17763.1 (WinBuild.160101.0800)
NoRemove
Setting ContactHarvester registry DWORD
CLSID\
DeleteCriticalSection
RaiseException
A8h-u
Failed starting IContactHarvester
rAddW4
\$ WH
fE9(u
RtlCaptureContext
HA_A^A]A\_^
GetInkStoreCollectionWWW
INK_ITEM_TYPE_SUI_LINE_DERIVEDWWl
q +q$
9L$Xu
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_03Wl
Dw=de
x ATAVAWH
TextContributor ClassW
L$P8K5
.CRT$XLA
t$XI9t$
D$@I;
x1L9u
TabIps.InkItem = s 'InkItem Class'
LcA L
D$0L9C
9\$@u
D9l$D~
H9{`t&H
L$@L;
Failed getting contact city
` UAVAWH
CoResumeClassObjects
HeapReAlloc
L$HH;O
GetLengthSid
WORDLIST-MS-EMAILUSERNAME
@8j1u
_wtoi64
HKEY_LOCAL_MACHINE
CLSID = s '{70445657-5AB0-11d9-A4E5-00301BB132BA}'
MidlineW
WORDLIST-MS-OUTOFDICTIONARY
A_A^_
8Q$IStreamW
t^H+Y 3
Failed initializing new CTrainedDataDictionary
\$HI9\$
H9{xu
WriteFile
ShapeAdaptationSupport
VirtualFree
504zDEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_14_CORRECTEDWWW
A_A^A\
D8p!u
<Y-uKL
DestroyWindow
D85xn
D$0H;
A8h)u
{D4445657-0FBC-11dc-A692-00037AF63586}
x AUAVAWH
api-ms-win-core-processthreads-l1-1-0.dll
s$fD;{*
@USVWATAVAWH
D8`)H
InterlockedPopEntrySList
<requestedPrivileges>
GetInkWW
SVAVAWH
7fD;>u
RemoteReadWW
T$(E3
E H9K@t'H
cA8W9t
O0CreationTime
{A4AE1EBA-EA27-498d-87F4-C51D30487E6A}
timeCollectionWW
;/sdI
*0S*TEXT_HARVESTER_SOURCE_ID_CONTACT_LAST_NAMEWW
D8A9u
D9l$8
RECOGNITION_TRAIN_REASON_DELETE_DATAd
tWfA;
fD9?t)A
A_A^A]_^
__wgetmainargs
ReleaseSRWLockExclusive
pTextHarvesterItemWW(
iulTextOffsetWWW
LoadCursorW
{15AC230F-0513-443b-B64D-7129E29D2753}
u$L97t
RtlLookupFunctionEntry
internal\sdk\inc\wil\resource.h
M0L9(t
GetTraceEnableFlags
[%hs(%hs)]
QueryPerformanceCounter
Failed CreatePrivateSpellCheckerFactory
effffff
Failed creating instance of CTrainedDataDictionary
threadId
t$0E3
\cbWW
msvcrt.dll
\$ UVWATAUAVAWH
D8hQt
StringFileInfo
RegNotifyChangeKeyValue
oD$ f
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_01Wl
t$ WAVAWH
reasonWW
Software
bstrOverwriteWWW
0A_A^A]A\_
ole32.dll
D$hH;
IPS_RECOPLUGIN_GathererDataSinkOnDataChange
ppRecognizerGuideWWW
pBCollectionIsEmptyW4
_wstat64
@A_A^^
t$@;k0u H
GetSecurityDescriptorGroup
.text$mn
E8e0t
{E5AAFF1B-8376-411c-BCA1-A02E64F47703}
fUseMinimalHarvestingWWW
IInkCollectionWW
Resources
Software\Policies\Microsoft
D8AQu
TEXT_HARVESTER_SOURCE_ID_EMAIL_SUBJECTWW
failureId
DrawnBoxx
&RemoteCopyTo
grfModeW
fE9&t
0(pINK_ITEM_TYPE_INVALIDWWWl
Interface
t3fD9EPu,E
SUVWATAUAVAWH
fD;7uXfD
@8k-t
@UWAVH
|XqsT
DecodePointer
=DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_01_CORRECTEDWWWl
EventWriteTransfer
T$8H!t$8H
RemoteSeekWW
C(f98t
PathAppendW
IInkTrainerW
reserved,
oL$0f
,plcidWWW
zh-Hans
T$@E3
x]fD9
bstrGroundTruthStringWWW
L$`H3
fD9$Cu
D$@E3
|$`fD
GetFileInformationByHandle
UnlockRegion
L#EPf
ATL:%p
I9>uDH
8I+,$
xA_A^A]A\_^][
CElsLad::Detect/MappingRecognizeText
AddTipInkWWW
HA_A^A]A\^[
%localappdata%\Microsoft\InputPersonalization
.didat$6
9D$8uUH
D8XAu
zlibNewSizeWW,
E8P1t
ImmDisableIME
8A^_^[
IsDebuggerPresent
H;=wo
D$xH9D$pt
.rdata$zETW1
"0"/TEXT_HARVESTER_SOURCE_ID_INK_STOREWW
??1exception@@UEAA@XZ
Module_Raw
rBFFF9080-1DAE-43B1-96B6-738575D01524
CoCreateGuid
@8{It
RtlVirtualUnwind
D$PfD
_wcmdln
GetModuleFileNameW
@SVWATAUAVAW
!0D2INK_ITEM_TYPE_TIP_BOXED_ALTERNATEWWWl
fD;8ugH
pA_A^_^]
RaiseFailFastException
api-ms-win-core-processthreads-l1-1-1.dll
{1E494655-09CB-46db-9D7C-C5911B7B9A13}
Version0
ForceRemove {83FEFA40-6F67-4244-AA04-1E590C1CB1D9} = s 'TextContributor Class'
L$@H;
Software\Microsoft
.CRT$XCA
name="Microsoft-Windows-TabletPC-InputPersonalization"
D8A)u
KERNEL32.dll
_FILETIMEWWW
IPS_OptInDialog_Showdialog
Specifies (returns) the elements of the InkRectangle object in a single call.WJ
DataTokens
f;D$@
UuidCreateSequential
IInkStoreEventsW
'InputPersonalization.exe'
CoGetClassObject
T$8H!\$8
UnhandledExceptionFilter
grfCommitFlagsWW,
DefWindowProcW
EventUnregister
IInkRectangle InterfaceWWW6
IPS_SettingsManager_Destroy
D$PD9@
wcscpy_s
Software\Microsoft\InputPersonalization\TrainedDataStore
currentContextName
GetVersionExW
@SUVWATAUAVAWH
MapViewOfFile
%localappdata%\Microsoft\InputPersonalization\InkStore
hA_A^_^[]
EgH;E
VS_VERSION_INFO
?=u$L
MappingRecognizeText
api-ms-win-core-synch-l1-2-0.dll
{6D6087D7-61D2-495f-9293-5B7B1C3FCEAB}
@8oAt
x UATAUAVAWH
Speech
A_A^_^]
.CRT$XCZ
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_06Wl
IndexWWW
{A82AAAEB-F154-43e7-B436-60212040FCE1}
%CommonProgramFiles%\Microsoft Shared\Ink\HWRCustomization
}WOverwrittenTextW
PostQuitMessage
@8jQu@H
IPS_InkStore_Add
map/set<T> too long
currentContextMessage
Exception
Generation
TEXT_HARVESTER_SOURCE_ID_CONTACT_JOBTITLEWWW
ypuEH
SendMessageW
D8x)t
fD9|$pt
GuideDataWWW
{9207D61F-0BBC-4245-8C00-C05468F54A8C}
#INK_ITEM_TYPE_SUI_LINE_ORIGINALWl
H;|$h
ubM;}
.data
fD9lE
E8Y(u
IMM32.dll
D8B)u
\TextHarvesterRestart.sav
fD9$pu
T$$D!t$ H
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_10_CORRECTEDWWWl
vOD;x
B]WVD
M9~8u&
InitializeSid
memset
L$HH9
[%hs]
IPS_SHAPECOLLECTOR_SendInkToWatson
RegServer
cRowsWWW
H9{`t&
9A98u6A9x
CAtlException initializing new CTrainedDataDictionary
\$ UVWAVAWH
GetProcAddress
</trustInfo>
ProductName
fD; t
Lexicon Generation
TabIps.InkItem.1 = s 'InkItem Class'
SOFTWARE\Microsoft\TPG\InputPersonalization\AnalysisTokens
IPS_SettingsManager_Init
.idata$6
Dt$p3
H!}8I
api-ms-win-core-heap-l1-1-0.dll
ApppInputScopeWWW
Invalid parameter passed to C runtime function.
H90u!L
Software\Microsoft\InputMethod\en-US\DuState
9D$8u
bTEXT_HARVESTER_SOURCE_ID_CONTACT_EMAIL_ADDRESSWW
@A_A^_^]
TEXT_HARVESTER_SOURCE_ID_CONTACT_FIRST_NAMEW
D$HE3
AddAce
&0vlTEXT_HARVESTER_SOURCE_ID_EMAIL_ADDRESSWW
eWA;t$
UnregisterPowerSettingNotification
.CRT$XCC
D8@9t
t$ UWAVH
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_12_CORRECTEDWWWl
FileVersion
E8P-t
HeapSize
@8hAt
1LppClonedHistoryW
}HH;N0
.?AVlength_error@std@@
SVWAVH
DEPRECATED_INK_ITEM_TYPE_TIP_WORD_SCRATCHWWWl
p AWH
c">0:s
\$09K$t
{7767A87F-5465-4c76-9E80-D083247A9145}
t$ E3
D8BQu
{D4B5C204-22A7-443B-B6D1-FCD79342701F}
sr-Cyrl
wilResult
InputPersonalization.exe
D8@1t
2Stat
pppInkWW
D8@Qt
UAVAWH
A_A^_
memcpy_s
{799E669D-4D41-45e0-A1AA-DC5C4B5DB216}
Delete
D8AAt
TEXT_HARVESTER_SOURCE_ID_EMAIL_DISPLAY_NAMEW
Creating CTextHarvesterItemList
WORDLIST-MS-CORRECTED
@8h)t
sROAMED_DICTIONARY_NONEWW
D$`H;
0A_A^_^[
CoInitializeSecurity
fD93tjA
fD9t$ t8H
TrainAndWait
DEPRECATED_INK_ITEM_TYPE_TIP_WORD_CHARACTER_ALTERNATEWWWl
IPS_TIPTEXTCONTRIBUTOR_ProcessMessages
Error Message
fD9uPs
xA_A^A]A\_^[]
TEXT_HARVESTER_SOURCE_ID_USER_DICTIONARY
A8h)t
Software\Microsoft\TPG\System Recognizers
MakeAbsoluteSD
tagSTATSTGWW
SVAVH
D$PH;
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_09Wl
\Implemented Categories
More bytes to copy from general cache wordlist file than file size
CoTaskMemAlloc
@UVWATAUAVAWH
CreateMutexExW
{FFD5C5A6-3493-40c8-B76B-D7CEE6EF917E}
CURRENT_USER\SOFTWARE\Microsoft\Personalization\Settings
MakeSelfRelativeSD
L$XL+
EventRegister
{150898DD-0EEB-40e2-AC0C-557908B3472A}
@UVWH
A_A^_^]
DeleteFileW
CoInitializeEx
\1]1z
zINK_ITEM_TYPE_MASKWW
D85Tq
@8pQt
L$ H;
.RECOGNITION_TRAIN_REASON_APPLICATION_REQUESTd
.?AVout_of_range@std@@
Contact Harvesting disabled in registry
HeapAlloc
A_A^A\_^
E8Y0u
RegisterPowerSettingNotification
LCIDToLocaleName
TEXT_HARVESTER_SOURCE_ID_SIP_SUGGESTIONW
MappingFreePropertyBag
SVWAVAWH
D$@H9F
RestrictImplicitInkCollection
@8sIt
Recognizer dll
pInputScopeW,
.data$brc
L$pH3
Y3SetSizeW
I|$`yq
l$PfD;$i
ShapeTrain
H3E H3E
InternalName
xB8\$mt<
malloc
HKEY_CURRENT_CONFIG
D9{hI
H9oPt>
INK_ITEM_TYPE_TIP_WORD_CHARACTER_OVERWRITEWWl
IPS_RECOPLUGIN_GathererDataSinkCleanup
RECOGNITION_TRAIN_REASON_APPLICATION_REQUEST_FASTWWWd
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
{74445657-3941-11dc-89E4-00301BB132BA}
api-ms-win-core-profile-l1-1-0.dll
.rsrc$02
IPS_RECOPLUGIN_GathererDataSinkAdviseStatus
\$ UVWATAUAVAW
_unlock
`A_A^A]A\_
RegisterApplicationRestart
IPS_LAD_DetectLanguage
en-US
{8492BECE-9FE6-47ce-903E-CDF80000B66B}
FindNextFileW
%ls_%ls_%ls_%ls.isf
OLEAUT32.dll
kernel32.dll
val RunAs = s 'Interactive User'
.text$di
REGISTRY
FindClose
@8j)u
originatingContextMessage
CElsLad::Detect/MappingFreePropertyBag
A8} t@A
01]INK_ITEM_TYPE_TIP_BOXED_INSERTWWl
VWATAVAWH
InkStore Class
UnregisterClassA
tJA8~Xt
|$`E3
\$0E3
GetCurrentProcessId
L$XH3
RegCreateKeyExW
.rdata$zETW0
bstrGroundTruthCorrectedFromAlternateStringW
tuL9s
StringFromCLSID
Hardware
Policy
|yD9u
T$@fD
IInkItemx
x_H9{
DelayLoadFailureHook
0A^_^][
WaitForSingleObjectEx
RegCopyTreeW
tbH+Y 3
GetSystemMetrics
Module
@8h1t
dwLowDateTimeWWW
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_07_CORRECTEDWWWl
CharUpperW
H!}'H!}/H!}7H
@8w0u
@USWH
CoTaskMemFree
PostThreadMessageW
processorArchitecture="amd64"
.CRT$XIZ
9;v!H
EgA86u4
pbstrRightContextWWW
InterlockedPushEntrySList
CBackgroundTrainer Message Window
IPS_SHAPECOLLECTOR_Launch
9T$`A
EncodePointer
!This program cannot be run in DOS mode.
Msg:[%ws]
@A^_^
sxI9>u
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_07Wl
;Ew|IH
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_03_CORRECTEDWWWl
IPS_RECOPLUGIN_FilterWordSinkAddCompleted
OPCOT
api-ms-win-eventing-provider-l1-1-0.dll
Lct$$H
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_00Wl
dlibMove
A_A^A]A\_^[
D$HL;
ClearWWW4
TextTrain
A^_^[]
USER32.dll
GetCurrentThread
t H95h
toL9s
t"D8=
wcspbrk
INK_ITEM_TYPE_TIP_SMART_CORRECTIONWWl
{A2081B32-8CCF-4fd0-95AA-FCA63CC02794}
api-ms-win-core-synch-l1-1-0.dll
CLSID = s '{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}'
D$ fD
D9|$X~]A
_ RecognitionAlternatesWWW
L9{@u
OpenSemaphoreW
Returns or sets the box that is physically drawn on the tablet's screen, in which writing takes place.4
I(H9K
D$@H;F
StrChrW
RECOGNITION_TRAIN_REASON_NEWIMPLICIT_DATAWWWd
URowsx
TEXT_HARVESTER_SOURCE_ID_CONTACT_URL
FallbackError
HeapSetInformation
f9H\u
EnterCriticalSection
.CRT$XCU
IpsMissingContactProperty
Failed creating SingletonContactHarvester instance
RegDeleteKeyExW
fE9 u
\$ E3
ConvertStringSecurityDescriptorToSecurityDescriptorW
fC9<~u
J tEA
_errno
IsRectEmpty
sr-Latn
{13C2DF27-74F4-4EEC-8643-014BF6E3BE76}
D8`Qt
SubjectTokens
SourceId
%hs(%d) tid(%x) %08X %ws
trainerGuidW
`A_A^_^]
HKEY_CURRENT_USER
GetTrainedDataDictionary
GetCurrentProcess
pulCount
H;D$H
tX91vT
ImmDisableTextFrameService
{8F364FE1-37E3-4ce2-9D8D-044C27E00F3B}
TextAdaptationSupport
win:Stop
A8~1t
@8jAt
fileName
d$ E3
L$`!l$`E
IPS_SHAPECOLLECTOR_Next
A8hAu
LocalFree
xQfD;u
L9o@t
.?AVResultException@wil@@
L;A s
type="win32"/>
</assembly>
Software\Microsoft\InputPersonalization\InkStore\ToTrainImplicit
.didat$3
Specifies (sets) the elements of the InkRectangle object in a single call.E
rectWritingBoxWW
grfStateBits
Translation
A_A^A]A\_^]
N!LockRegionWW
Opening InputPersonalization registry
D8@)t
@8j1t
ATL$__z
ShapeTrainerImplicitUpdateCount
@8{Xt/H
tagRECTW
WilError_02
RegisterTraceGuidsW
f;EguG
IPS_LAD_AddText
t3H9o
RECOGNITION_TRAIN_REASONd
FileType
D$0H+
ProductVersion
t$ I;
FlushFileBuffers
A8v0u0H
C@!CPH!CX!C`
fD90u
t5D8i
t$PE3
fD92u1L
.didat$4
UuidHash
pstm,
WVDJQM
tInkTypeW
__CxxFrameHandler3
Creating CTrainedDataDictionary
IsValidSid
_onexit
`A_A^_^[
.CRT$XIAA
{ECDC156F-7A07-4120-9DBD-99505926A944}
PRVAt
A_A^A\_^[]
failureType
Windows
D8X!u
D8X(u
@8h1u
hresult
DisablePersInternal
D$0E3
x:D8|$\t3D9|$Xv,A
fD9$Yu
InkItem ClassW
IPS_RECOPLUGIN_FilterWordSinkTextIsCompleted
=L9o<
t+H!u@L
TabIps.TextContributor.1 = s 'TextContributor Class'
LineStartTokens
NITipInkHistoryWW
.idata$2
api-ms-win-core-debug-l1-1-0.dll
x AVH
DEPRECATED_INK_ITEM_TYPE_TIP_LINE_INSERT_04Wl
.CRT$XCL
D8XQu
u%!|$ L
|$PE3
D8X1u
SYSTEM
.tls$
elscore.dll
HKEY_USERS
ApplicationContextWW
AtlThunk_AllocateData
PathStripPathW
D$ L;
.xdata
.gfids
GetLCIDFromDictionaryPath %s
8A_A^^[
nRevertWW,
XmlLite.dll
??0exception@@QEAA@AEBV0@@Z
%hs(%d)\%hs!%p:
Operating System
fppInkItemWWW
D$$9G
Hc*E3
TypeLib
vector<T> too long
@.didat
Failed getting Display Name
GetModuleHandleExW
QRecognitionFlags
@8j,uV@
_cexit
{446DF4C1-CC4B-443C-A8BA-B5883312C5DB}
GetSecurityDescriptorOwner
IPS_Harvest_UserDictionary
IShapeConsumerWWL
WORDLIST-MS-NGRAM
|$0E3
{6D5087D7-61D2-495f-9293-5B7B1C3FCEAB}
TypeMatchWWW
TEXT_HARVESTER_SOURCE_ID_CONTACT_MIDDLE_NAME
@8q)t
t$ WATAUAVAWH
GetLastError
@USVWATAUAVAWH
UWAWH
_commode
TokenFilePath
EventWrite
LocaleID`
LogHr
_amsg_exit
NoRemove AppID
{7C74C2EC-AADA-4b67-A1E4-B1B6A3A87E47}
8\$mt
p WATAUAVAWH
dwOrigin
?terminate@@YAXXZ
TEXT_HARVESTER_SOURCE_ID_SIP
_i64tow_s
D8X)u
D$ @2
t$8Lc
u%A8h-t
ulDocIdW
LeftContextW
A8h9t
IPS_OptInDialog_Server
t<fA9u
NIFTE_AbortTrainer
H;w sz
pA_A^A]A\_^]
clsidWWW
V8fA+
f;D$(u
D8q)u#D9y
WORDLIST-MS-URL
A_A^A]A\]
A_A^A]_]
InitOnceBeginInitialize
CopySid
CHMcl
`.rdata
s(fD97t
NIFTE_CreateTrainer
Returns or sets the recognizer guide structure for Automation developers.W
D$@H;
RegQueryInfoKeyW
GetFileAttributesExW
RegCloseKey
SHCreateDirectoryExW
|$ UATAUAVAWH
lineNumber

PE Information

Image Base Entry Point Reported Checksum Actual Checksum Minimum OS Version PDB Path Compile Time Import Hash
0x140000000 0x000377a0 0x00062a55 0x00062a55 10.0 InputPersonalization.pdb 1993-08-26 21:02:39 ad22ea0afe12330c3955592971b084a2

Version Infos

CompanyName Microsoft Corporation
FileDescription Input Personalization Server
FileVersion 10.0.17763.1 (WinBuild.160101.0800)
InternalName InputPersonalization.exe
LegalCopyright ร‚ยฉ Microsoft Corporation. All rights reserved.
OriginalFilename InputPersonalization.exe
ProductName Microsoftร‚ยฎ Windowsร‚ยฎ Operating System
ProductVersion 10.0.17763.1
Translation 0x0409 0x04b0

Sections

Name RAW Address Virtual Address Virtual Size Size of Raw Data Characteristics Entropy
.text 0x00000400 0x00001000 0x0003999c 0x00039a00 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.30
.rdata 0x00039e00 0x0003b000 0x0001331c 0x00013400 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.75
.data 0x0004d200 0x0004f000 0x000026c8 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2.44
.pdata 0x0004e600 0x00052000 0x00002ac0 0x00002c00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.49
.didat 0x00051200 0x00055000 0x00000158 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2.52
.rsrc 0x00051400 0x00056000 0x00008d58 0x00008e00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.95
.reloc 0x0005a200 0x0005f000 0x000005f8 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 5.38

Name Offset Size Language Sub-language Entropy File type
MUI 0x0005ec50 0x00000108 LANG_ENGLISH SUBLANG_ENGLISH_US 2.98 None
REGISTRY 0x00056518 0x000000b5 LANG_ENGLISH SUBLANG_ENGLISH_US 4.70 None
REGISTRY 0x000565d0 0x00000218 LANG_ENGLISH SUBLANG_ENGLISH_US 5.34 None
REGISTRY 0x000567e8 0x00000212 LANG_ENGLISH SUBLANG_ENGLISH_US 5.31 None
REGISTRY 0x00056a00 0x00000250 LANG_ENGLISH SUBLANG_ENGLISH_US 5.37 None
TYPELIB 0x00056c50 0x00006134 LANG_ENGLISH SUBLANG_ENGLISH_US 5.06 None
WEVT_TEMPLATE 0x0005d168 0x00001ae2 LANG_ENGLISH SUBLANG_ENGLISH_US 3.65 None
RT_VERSION 0x0005cd88 0x000003e0 LANG_ENGLISH SUBLANG_ENGLISH_US 3.42 None
RT_MANIFEST 0x000562a0 0x00000274 LANG_ENGLISH SUBLANG_ENGLISH_US 5.08 None

Imports

Name Address
CreateSemaphoreExW 0x14003c498
HeapFree 0x14003c4a0
SetLastError 0x14003c4a8
SetPriorityClass 0x14003c4b0
EnterCriticalSection 0x14003c4b8
GetCommandLineW 0x14003c4c0
GetCurrentProcess 0x14003c4c8
ReleaseSemaphore 0x14003c4d0
GetModuleHandleExW 0x14003c4d8
GetModuleFileNameW 0x14003c4e0
LeaveCriticalSection 0x14003c4e8
InitializeCriticalSection 0x14003c4f0
CreateMutexW 0x14003c4f8
WaitForSingleObject 0x14003c500
GetCurrentThreadId 0x14003c508
GetVersionExW 0x14003c510
ReleaseMutex 0x14003c518
CreateEventW 0x14003c520
MultiByteToWideChar 0x14003c528
Sleep 0x14003c530
FormatMessageW 0x14003c538
GetLastError 0x14003c540
OutputDebugStringW 0x14003c548
SetEvent 0x14003c550
GetCurrentThread 0x14003c558
InitOnceComplete 0x14003c560
WaitForSingleObjectEx 0x14003c568
OpenSemaphoreW 0x14003c570
CloseHandle 0x14003c578
RaiseException 0x14003c580
LoadLibraryW 0x14003c588
CreateThread 0x14003c590
HeapSetInformation 0x14003c598
FindResourceExW 0x14003c5a0
LoadResource 0x14003c5a8
HeapAlloc 0x14003c5b0
GetProcAddress 0x14003c5b8
CreateMutexExW 0x14003c5c0
DeleteCriticalSection 0x14003c5c8
GetCurrentProcessId 0x14003c5d0
GetProcessHeap 0x14003c5d8
GetModuleHandleW 0x14003c5e0
FreeLibrary 0x14003c5e8
DebugBreak 0x14003c5f0
lstrcmpiW 0x14003c5f8
LoadLibraryExW 0x14003c600
IsDebuggerPresent 0x14003c608
SizeofResource 0x14003c610
DecodePointer 0x14003c618
EncodePointer 0x14003c620
DelayLoadFailureHook 0x14003c628
ResolveDelayLoadedAPI 0x14003c630
FlushFileBuffers 0x14003c638
LCMapStringW 0x14003c640
CreateDirectoryW 0x14003c648
GetSystemTime 0x14003c650
SystemTimeToFileTime 0x14003c658
OpenFileMappingW 0x14003c660
GetStringTypeW 0x14003c668
GetFileAttributesExW 0x14003c670
GetOverlappedResult 0x14003c678
CancelIo 0x14003c680
WaitNamedPipeW 0x14003c688
ReadFile 0x14003c690
LocaleNameToLCID 0x14003c698
MapViewOfFile 0x14003c6a0
CreateFileMappingW 0x14003c6a8
LocalFree 0x14003c6b0
UnmapViewOfFile 0x14003c6b8
GetFileInformationByHandle 0x14003c6c0
GetFileAttributesW 0x14003c6c8
LCIDToLocaleName 0x14003c6d0
RegDeleteTreeW 0x14003c6d8
RegCopyTreeW 0x14003c6e0
CompareFileTime 0x14003c6e8
FindClose 0x14003c6f0
FindNextFileW 0x14003c6f8
FindFirstFileW 0x14003c700
RegDeleteKeyExW 0x14003c708
DeleteFileW 0x14003c710
SetFileAttributesW 0x14003c718
CreateFileW 0x14003c720
SetThreadPriority 0x14003c728
WriteFile 0x14003c730
RegEnumValueW 0x14003c738
ExpandEnvironmentStringsW 0x14003c740
WaitForMultipleObjects 0x14003c748
RegQueryValueExW 0x14003c750
RegGetValueW 0x14003c758
RegNotifyChangeKeyValue 0x14003c760
InitializeCriticalSectionAndSpinCount 0x14003c768
InitOnceBeginInitialize 0x14003c770
GetModuleFileNameA 0x14003c778
Name Address
TranslateMessage 0x14003c888
CharUpperW 0x14003c890
GetSystemMetrics 0x14003c898
MsgWaitForMultipleObjects 0x14003c8a0
PeekMessageW 0x14003c8a8
OffsetRect 0x14003c8b0
IsRectEmpty 0x14003c8b8
GetMessageW 0x14003c8c0
CreateWindowExW 0x14003c8c8
PostQuitMessage 0x14003c8d0
UnregisterPowerSettingNotification 0x14003c8d8
RegisterPowerSettingNotification 0x14003c8e0
RegisterClassExW 0x14003c8e8
LoadCursorW 0x14003c8f0
GetClassInfoExW 0x14003c8f8
DefWindowProcW 0x14003c900
PostMessageW 0x14003c908
SendMessageW 0x14003c910
SetWindowLongPtrW 0x14003c918
UnregisterClassA 0x14003c920
CharNextW 0x14003c928
CallWindowProcW 0x14003c930
DispatchMessageW 0x14003c938
DestroyWindow 0x14003c940
GetKeyboardLayoutList 0x14003c948
PostThreadMessageW 0x14003c950
GetWindowLongPtrW 0x14003c958
Name Address
__set_app_type 0x14003cab8
_unlock 0x14003cac0
_amsg_exit 0x14003cac8
_XcptFilter 0x14003cad0
_callnewh 0x14003cad8
wcsncpy_s 0x14003cae0
malloc 0x14003cae8
memmove_s 0x14003caf0
free 0x14003caf8
_vsnprintf_s 0x14003cb00
??0exception@@QEAA@AEBV0@@Z 0x14003cb08
??0exception@@QEAA@XZ 0x14003cb10
??1exception@@UEAA@XZ 0x14003cb18
_exit 0x14003cb20
wcscat_s 0x14003cb28
wcscpy_s 0x14003cb30
memcpy_s 0x14003cb38
calloc 0x14003cb40
_vsnwprintf 0x14003cb48
_resetstkoflw 0x14003cb50
__C_specific_handler 0x14003cb58
__CxxFrameHandler3 0x14003cb60
__dllonexit 0x14003cb68
_onexit 0x14003cb70
??1type_info@@UEAA@XZ 0x14003cb78
exit 0x14003cb80
_cexit 0x14003cb88
__setusermatherr 0x14003cb90
_initterm 0x14003cb98
_purecall 0x14003cba0
_fmode 0x14003cba8
swprintf_s 0x14003cbb0
??0exception@@QEAA@AEBQEBD@Z 0x14003cbb8
?what@exception@@UEBAPEBDXZ 0x14003cbc0
wcstol 0x14003cbc8
_wtoi 0x14003cbd0
wcstoul 0x14003cbd8
_itow 0x14003cbe0
_wcstoi64 0x14003cbe8
_itow_s 0x14003cbf0
wcschr 0x14003cbf8
_ui64tow_s 0x14003cc00
_i64tow_s 0x14003cc08
_wcsicmp 0x14003cc10
_wtoi64 0x14003cc18
wcspbrk 0x14003cc20
_wcsnicmp 0x14003cc28
_wstat64 0x14003cc30
fclose 0x14003cc38
_wfopen 0x14003cc40
fread 0x14003cc48
wcsrchr 0x14003cc50
_CxxThrowException 0x14003cc58
memcmp 0x14003cc60
memcpy 0x14003cc68
memset 0x14003cc70
_wcmdln 0x14003cc78
_commode 0x14003cc80
realloc 0x14003cc88
_errno 0x14003cc90
?terminate@@YAXXZ 0x14003cc98
_lock 0x14003cca0
__wgetmainargs 0x14003cca8
wcscmp 0x14003ccb0
Name Address
RtlCaptureContext 0x14003ccc0
RtlLookupFunctionEntry 0x14003ccc8
RtlVirtualUnwind 0x14003ccd0
Name Address
OutputDebugStringA 0x14003c978
Name Address
SetUnhandledExceptionFilter 0x14003c988
UnhandledExceptionFilter 0x14003c990
Name Address
HeapSize 0x14003c9a0
HeapDestroy 0x14003c9a8
HeapReAlloc 0x14003c9b0
Name Address
TerminateProcess 0x14003ca00
GetStartupInfoW 0x14003ca08
Name Address
QueryPerformanceCounter 0x14003ca28
Name Address
GetStringTypeExW 0x14003ca38
Name Address
AcquireSRWLockExclusive 0x14003ca48
ReleaseSRWLockExclusive 0x14003ca50
Name Address
WakeAllConditionVariable 0x14003ca60
SleepConditionVariableSRW 0x14003ca68
Name Address
GetTickCount 0x14003ca78
GetSystemTimeAsFileTime 0x14003ca80
Name Address
ImmDisableIME 0x14003c480
ImmDisableTextFrameService 0x14003c488
Name Address
CoInitialize 0x14003cce0
CoGetClassObject 0x14003cce8
StringFromCLSID 0x14003ccf0
CoCreateGuid 0x14003ccf8
CoTaskMemRealloc 0x14003cd00
CoMarshalInterThreadInterfaceInStream 0x14003cd08
CLSIDFromString 0x14003cd10
CoRevokeClassObject 0x14003cd18
CoInitializeEx 0x14003cd20
CoGetInterfaceAndReleaseStream 0x14003cd28
CoSuspendClassObjects 0x14003cd30
CoInitializeSecurity 0x14003cd38
CoResumeClassObjects 0x14003cd40
CoRegisterClassObject 0x14003cd48
CoTaskMemFree 0x14003cd50
CoCreateInstance 0x14003cd58
CoUninitialize 0x14003cd60
StringFromGUID2 0x14003cd68
CoTaskMemAlloc 0x14003cd70
Name Address
VarBstrCmp 0x14003c788
SafeArrayUnaccessData 0x14003c790
VarBstrCat 0x14003c798
VariantInit 0x14003c7a0
SysStringByteLen 0x14003c7a8
SysAllocStringByteLen 0x14003c7b0
SafeArrayAccessData 0x14003c7b8
VarBstrFromI8 0x14003c7c0
VariantClear 0x14003c7c8
SysAllocStringLen 0x14003c7d0
UnRegisterTypeLib 0x14003c7d8
LoadTypeLib 0x14003c7e0
SysFreeString 0x14003c7e8
RegisterTypeLib 0x14003c7f0
SysAllocString 0x14003c7f8
SysStringLen 0x14003c800
VarUI4FromStr 0x14003c808
SafeArrayDestroy 0x14003c810
SafeArrayCreateVector 0x14003c818
Name Address
SHCreateDirectoryExW 0x14003c840
Name Address
PathStripPathW 0x14003c850
PathAddBackslashW 0x14003c858
PathAppendW 0x14003c860
StrRStrIW 0x14003c868
SHCreateStreamOnFileW 0x14003c870
StrChrW 0x14003c878
Name Address
UuidCreateSequential 0x14003c828
UuidHash 0x14003c830
Name Address
CreateXmlReader 0x14003c968
Name Address
MappingFreeServices 0x14003ca90
MappingRecognizeText 0x14003ca98
MappingFreePropertyBag 0x14003caa0
MappingGetServices 0x14003caa8
Name Address
InterlockedPopEntrySList 0x14003c9c0
InterlockedPushEntrySList 0x14003c9c8
Name Address
LoadLibraryExA 0x14003c9d8
Name Address
VirtualAlloc 0x14003c9e8
VirtualFree 0x14003c9f0
Name Address
FlushInstructionCache 0x14003ca18


Reports: JSON

Usage


Processing ( 12.64 seconds )

  • 11.208 ProcessMemory
  • 0.778 BehaviorAnalysis
  • 0.646 CAPE
  • 0.008 AnalysisInfo
  • 0.001 Debug

Signatures ( 0.08 seconds )

  • 0.012 antiav_detectreg
  • 0.008 ransomware_files
  • 0.005 antianalysis_detectfile
  • 0.005 infostealer_ftp
  • 0.005 ransomware_extensions
  • 0.005 territorial_disputes_sigs
  • 0.003 antianalysis_detectreg
  • 0.003 antiav_detectfile
  • 0.003 infostealer_im
  • 0.003 ursnif_behavior
  • 0.002 infostealer_bitcoin
  • 0.002 infostealer_mail
  • 0.002 poullight_files
  • 0.001 antivm_generic_diskreg
  • 0.001 antivm_parallels_keys
  • 0.001 antivm_vbox_files
  • 0.001 antivm_vbox_keys
  • 0.001 antivm_vmware_keys
  • 0.001 antivm_xen_keys
  • 0.001 ketrican_regkeys
  • 0.001 geodo_banking_trojan
  • 0.001 browser_security
  • 0.001 darkcomet_regkeys
  • 0.001 disables_backups
  • 0.001 disables_browser_warn
  • 0.001 disables_power_options
  • 0.001 azorult_mutexes
  • 0.001 cryptbot_files
  • 0.001 echelon_files
  • 0.001 masquerade_process_name
  • 0.001 revil_mutexes
  • 0.001 modirat_behavior
  • 0.001 recon_fingerprint

Reporting ( 0.45 seconds )

  • 0.413 CAPASummary
  • 0.039 JsonDump

Signatures

Checks available memory
Queries the keyboard layout
The PE file contains a PDB path
pdbpath: InputPersonalization.pdb
SetUnhandledExceptionFilter detected (possible anti-debug)
The binary contains an unknown PE section name indicative of packing
unknown section: {'name': '.didat', 'raw_address': '0x00051200', 'virtual_address': '0x00055000', 'virtual_size': '0x00000158', 'size_of_data': '0x00000200', 'characteristics': 'IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE', 'characteristics_raw': '0xc0000040', 'entropy': '2.52'}
Yara detections observed in process dumps, payloads or dropped files
Hit: PID 1896 triggered the Yara rule 'shellcode_get_eip' with data '['{ E8 00 00 00 00 59 }']'
Anomalous binary characteristics
anomaly: Entrypoint of binary is located outside of any mapped sections

Screenshots

No screenshots available.

Hosts

No hosts contacted.

DNS

No domains contacted.

Summary

C:\Windows\System32\kernel.appcore.dll
\Device\CNG
C:\Users\Packager\AppData\Local\Microsoft\InputPersonalization
C:\Users\Packager\AppData\Local\Microsoft\InputPersonalization\TextHarvesterRestart.sav
C:\Users\Packager\AppData\Local\microsoft\InputPersonalization\TrainedDataStore
C:\Users\Packager\AppData\Local\microsoft\InputPersonalization\TrainedDataStore\*.*
C:\Windows\System32\ELSCore.dll
C:\Windows\System32\en-US\elscore.dll.mui
C:\Windows\System32\elslad.dll
C:\Windows\System32\elsTrans.dll
C:\Windows\System32\ElsCore.Config
C:\Windows\Globalization\ELS\Transliteration\Hans-To-Hant.nlt
C:\Windows\Globalization\ELS\Transliteration\cyrl-to-latin.nlt
C:\Windows\Globalization\ELS\Transliteration\decompose-hangul.nlt
C:\Windows\Globalization\ELS\Transliteration\Hant-To-Hans.nlt
C:\Windows\Globalization\ELS\Transliteration\devanagari-to-latin.nlt
C:\Windows\Globalization\ELS\Transliteration\malayalam-to-latin.nlt
C:\Windows\Globalization\ELS\Transliteration\bengali-to-latin.nlt
C:\DosDevices\pipe\
\??\pipe\SearchTextHarvester
C:\Windows\Globalization\ELS\SpellDictionaries\*.lex
C:\Users\Packager\AppData\Roaming\Microsoft\Spelling
C:\Windows\System32\Unistore.dll
C:\Windows\System32\esent.dll
C:\Windows\System32\twinapi.appcore.dll
C:\Users\Packager\AppData\Local\Microsoft\InputPersonalization\TextHarvesterRestart.sav
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\STE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\StateSeparation\RedirectionMap\Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseActivationAuthenticationLevel
HKEY_LOCAL_MACHINE\Software\Classes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\InputPersonalization.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\InputPersonalization.exe\AppId
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Microsoft\InputPersonalization
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint4
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint5
HKEY_LOCAL_MACHINE\Software\Microsoft\TPG\LanguageModel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-LR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-LR\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-LR\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-PH
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-PH\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-PH\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\Resource0
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en\Proxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-AU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\TextPredictionCapabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\TextPredictionCapabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-GB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\TextPredictionCapabilities
HKEY_CURRENT_USER\Control Panel\International\User Profile
HKEY_CURRENT_USER\Control Panel\International\User Profile\en-US
HKEY_CURRENT_USER\Control Panel\International\User Profile\en-US\TransientLangId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-LR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-LR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-LR\Proxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-PH
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-PH\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\TextPredictionCapabilities
HKEY_LOCAL_MACHINE\Software\Microsoft\TPG\System Recognizers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\Recognizer Capability Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\ShapeTrainerImplicitUpdateCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\ShapeAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\TextAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\Recognized Languages
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\Recognizer dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{BED9A940-7D48-48e3-9A68-F4887A5A1B2E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{BED9A940-7D48-48e3-9A68-F4887A5A1B2E}\Recognizer Capability Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\Recognizer Capability Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\ShapeTrainerImplicitUpdateCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\ShapeAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\TextAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\Recognized Languages
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\Recognizer dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Personalization\Settings
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Personalization\Settings\AcceptedPrivacyPolicy
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\RestrictImplicitTextCollection
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TextHarvestingInstallationStatus
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\RestrictImplicitInkCollection
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\InputPersonalization
HKEY_CURRENT_USER\Software\Policies\Microsoft\InputPersonalization
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\DisablePersInternal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\MaximumInkStoreSize
HKEY_CURRENT_USER\Software\Microsoft\InputPersonalization\TrainedDataStore
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore\HarvestContacts
HKEY_CURRENT_USER\Software\Microsoft\InputPersonalization\TrainedDataStore\
HKEY_CURRENT_USER\Software\Microsoft
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech\CurrentUserLexicon
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\Category
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\Description
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E
HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages\en-US
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\App Lexicon Timestamp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\ServiceType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\MinorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\BuildVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\OutputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\InputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\OutputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\Component
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Category
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\IsOneToOneLanguageMapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\HasSubservices
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OnlineOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\ServiceType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\MajorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\MinorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\BuildVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\StepVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\PrivateData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\InputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OutputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\InputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OutputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Component
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\Lexicon Generation
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech\CurrentUserLexicon\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11D9-A4E5-00301BB132BA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11D9-994B-00301BB132BA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\Elevation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\TreatAs
HKEY_CURRENT_USER\Software\Microsoft\InputPersonalization\InkStore\ToTrainExplicit
HKEY_CURRENT_USER\Software\Microsoft\InputPersonalization\InkStore\ToTrainImplicit
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ELS\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Category
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\IsOneToOneLanguageMapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\HasSubservices
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OnlineOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\ServiceType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\MajorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\MinorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\BuildVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\StepVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\PrivateData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\InputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OutputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\InputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OutputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Component
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B196B28F-BAB4-101A-B69C-00AA00341D07}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B196B28F-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B196B28F-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\LocalServer
HKEY_LOCAL_MACHINE\Software\Microsoft\OleAut
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsRuntime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\CustomAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\Diagnosis
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableATLEnumClassLock
HKEY_CURRENT_USER\Software\Microsoft\Spelling\Spellers
HKEY_LOCAL_MACHINE\Software\Microsoft\Spelling\Spellers
HKEY_USERS\S-1-5-21-64934406-199802361-3218922526-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-64934406-199802361-3218922526-1001
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-64934406-199802361-3218922526-1001\ProfileImagePath
HKEY_CURRENT_USER\Software\Microsoft\Spelling
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E018A9D-2415-4677-BF08-794EA61F94BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E018A9D-2415-4677-BF08-794EA61F94BB}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E018A9D-2415-4677-BF08-794EA61F94BB}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InprocHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\LocalServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\LocalServer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\Elevation
HKEY_LOCAL_MACHINE\Software\Microsoft\SecurityManager\TransientObjects\%5C%5C.%5CRpc%5CUnistoreServiceOneCore%5CServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\TransientObjects\%5C%5C.%5CRpc%5CUnistoreServiceOneCore%5CServer\SecurityDescriptor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\STE
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock\AllowDevelopmentWithoutDevLicense
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\RaiseActivationAuthenticationLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\InputPersonalization.exe\AppId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint4
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\SentItemsHint5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-LR\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-LR\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-PH\Resource0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-PH\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\Resource0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en\Proxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-AU
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-AU\TextPredictionCapabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-CA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-CA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-CA\TextPredictionCapabilities
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-GB
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-GB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-GB\TextPredictionCapabilities
HKEY_CURRENT_USER\Control Panel\International\User Profile\en-US\TransientLangId
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-LR
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-LR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-LR\Proxy
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-PH
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-PH
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-PH\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\Proxy
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\DefaultVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\LanguageModel\en-US\TextPredictionCapabilities
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\Recognizer Capability Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\ShapeTrainerImplicitUpdateCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\ShapeAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\TextAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\Recognized Languages
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{6D1087D7-61D2-495f-9293-5B7B1C3FCEAB}\Recognizer dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{BED9A940-7D48-48e3-9A68-F4887A5A1B2E}\Recognizer Capability Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\Recognizer Capability Flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\ShapeTrainerImplicitUpdateCount
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\ShapeAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\TextAdaptationSupport
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\Recognized Languages
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TPG\System Recognizers\{CC2E1031-D547-4b22-B4CF-ADF91817389A}\Recognizer dll
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Personalization\Settings\AcceptedPrivacyPolicy
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\DisablePersInternal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\MaximumInkStoreSize
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TextHarvestingInstallationStatus
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore\HarvestContacts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\Category
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\ServiceType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\MinorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\BuildVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\OutputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\InputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\OutputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{2D64B439-6CAF-4f6b-B688-E5D0F4FAA7D7}\Component
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Category
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-5
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\IsOneToOneLanguageMapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\HasSubservices
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OnlineOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\ServiceType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\MajorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\MinorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\BuildVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\StepVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\PrivateData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\InputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OutputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\InputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OutputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Component
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\Lexicon Generation
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech\CurrentUserLexicon\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70445657-5AB0-11d9-A4E5-00301BB132BA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FEFA40-6F67-4244-AA04-1E590C1CB1D9}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01171F65-249E-4EEB-81BD-03E1B0FA1873}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64445657-9101-11d9-994B-00301BB132BA}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB36653-1796-484B-BDFA-E74F1DB7C1DC}\AppID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3CACCDC8-5590-42dc-9A7B-B5A6B5B3B63B}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-6
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{3DD12A98-5AFD-4903-A13F-E17E6C0BFE01}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-10
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{4BA2A721-E43D-41B7-B330-536AE1E48863}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{A3A8333B-F4FC-42f6-A0C4-0462FE7317CB}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-7
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{C4A4DCFE-2661-4d02-9835-F48187109803}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-8
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{D8B983B1-F8BF-4a2b-BCD5-5B5EA20613E1}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{A22D52C1-DBFD-40cb-AE78-E3BA9EE1D88F}\Subservices\{F4DFD825-91A4-489f-855E-9AD9BEE55727}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Category
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Description
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Copyright
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\IsOneToOneLanguageMapping
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\HasSubservices
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OnlineOnly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\ServiceType
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\MajorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\MinorVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\BuildVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\StepVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\PrivateData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\InputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OutputContentTypes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\InputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OutputLanguages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\InputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\OutputScripts
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Els\Services\{CF7E00B1-909B-4d95-A8F4-611F7C377702}\Component
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B196B28F-BAB4-101A-B69C-00AA00341D07}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivationType
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\Server
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\DllPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\Threading
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\TrustLevel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\RemoteServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateAsUser
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateInSharedBroker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateInBrokerForMediumILContainer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\Permissions
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Globalization.Spelling.Internal.Facility\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableATLEnumClassLock
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-64934406-199802361-3218922526-1001\ProfileImagePath
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E018A9D-2415-4677-BF08-794EA61F94BB}\ProxyStubClsid32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\ActivateOnHostFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32\ThreadingModel
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\AppID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\TransientObjects\%5C%5C.%5CRpc%5CUnistoreServiceOneCore%5CServer\SecurityDescriptor
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\RestrictImplicitTextCollection
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TextHarvestingInstallationStatus
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\RestrictImplicitInkCollection
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\DisablePersInternal
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\MaximumInkStoreSize
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\App Lexicon Timestamp
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-5
HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\Lexicon Generation
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-4
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-6
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-10
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-3
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-7
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-8
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-9
HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\2\52C64B7E\C:\Windows\system32,@elscore.dll,-1
{D4445657-0FBC-11dc-A692-00037AF63586}
Local\SM0:1896:304:WilStaging_02
UnistoreSvc_1d7e26
No results
Sorry! No behavior.
Sorry! No strace.
Sorry! No tracee.

No hosts contacted.

No TCP connections recorded.

No UDP connections recorded.

No domains contacted.

HTTP Requests

No HTTP(s) requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No Suricata Extracted files.
Sorry! No dropped files.
Sorry! No process dumps.
Sorry! No process dumps.