General Info Watch the FULL Interactive Analysis at ANY.RUN!

URL

https://tryeuio.ml/zp/error/err.mp3

Verdict
Malicious activity
Analysis date
1/10/2019, 22:44:20
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO

No malicious indicators.

Creates files in the program directory
  • unregmp2.exe (PID: 3480)
Creates files in the user directory
  • wmplayer.exe (PID: 1464)
Modifies the open verb of a shell class
  • chrome.exe (PID: 2960)
Application launched itself
  • chrome.exe (PID: 2960)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
44
Monitored processes
14
Malicious processes
0
Suspicious processes
0

Behavior graph

+
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs wmplayer.exe no specs setup_wm.exe no specs unregmp2.exe no specs unregmp2.exe no specs wmplayer.exe wmplayer.exe no specs wmpshare.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2960
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" https://tryeuio.ml/zp/error/err.mp3
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\credui.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wpc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\imagehlp.dll

PID
3688
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=68.0.3440.106 --initial-client-data=0x78,0x7c,0x80,0x74,0x84,0x6f4300b0,0x6f4300c0,0x6f4300cc
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
1492
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2964 --on-initialized-event-handle=304 --parent-handle=308 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_watcher.dll

PID
4068
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAACAAwBAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=B2E1C1888076D473A6BDD1020AE4BD29 --mojo-platform-channel-handle=988 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\program files\google\chrome\application\68.0.3440.106\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libegl.dll

PID
2544
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --service-pipe-token=6594FA022F0CF9BA49D6BA57F21202F0 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6594FA022F0CF9BA49D6BA57F21202F0 --renderer-client-id=4 --mojo-platform-channel-handle=1896 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3252
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --service-pipe-token=9A45B09FC40F5B70804A3CCA333C02B1 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9A45B09FC40F5B70804A3CCA333C02B1 --renderer-client-id=3 --mojo-platform-channel-handle=2140 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
4052
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --disable-gpu-sandbox --gpu-preferences=KAAAAAAAAACAAwBAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=2FCA96162A5B2B821D46BE3A6215CFF0 --mojo-platform-channel-handle=3572 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\program files\google\chrome\application\68.0.3440.106\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libegl.dll

PID
3512
CMD
"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1
Path
C:\Program Files\Windows Media Player\wmplayer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Player
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\wmplayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\program files\windows media player\setup_wm.exe

PID
2512
CMD
"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1
Path
C:\Program Files\Windows Media Player\setup_wm.exe
Indicators
No indicators
Parent process
wmplayer.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Media Configuration Utility
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\setup_wm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\pdh.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\system32\mf.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\quartz.dll
c:\windows\system32\winmm.dll
c:\windows\system32\devenum.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\unregmp2.exe

PID
2600
CMD
C:\Windows\system32\unregmp2.exe /ShowWMP /SetShowState /CreateMediaLibrary
Path
C:\Windows\system32\unregmp2.exe
Indicators
No indicators
Parent process
setup_wm.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Media Player Setup Utility
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\unregmp2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wmdrmsdk.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\winmm.dll
c:\windows\system32\linkinfo.dll
c:\program files\windows media player\wmplayer.exe

PID
3480
CMD
"C:\Windows\system32\unregmp2.exe" /PerformIndivIfNeeded
Path
C:\Windows\system32\unregmp2.exe
Indicators
No indicators
Parent process
setup_wm.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Media Player Setup Utility
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\unregmp2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wmdrmsdk.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\drmv2clt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\blackbox.dll
c:\windows\system32\cryptbase.dll

PID
1464
CMD
"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1
Path
C:\Program Files\Windows Media Player\wmplayer.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Media Player
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\wmplayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\jscript.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\upnphost.dll
c:\windows\system32\ssdpapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\slc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mswmdm.dll
c:\windows\system32\cewmdm.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\upnp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\wmdmps.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\shsvcs.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\normaliz.dll
c:\program files\windows media player\wmpshare.exe
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wmpps.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\mlang.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\photometadatahandler.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\windowscodecsext.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\sbe.dll
c:\windows\ehome\ehtrace.dll
c:\program files\windows media player\wmpmediasharing.dll
c:\program files\windows media player\wmpnssci.dll
c:\windows\system32\idstore.dll

PID
3096
CMD
"C:\Program Files\Windows Media Player\wmplayer.exe" /Relaunch /prefetch:1
Path
C:\Program Files\Windows Media Player\wmplayer.exe
Indicators
No indicators
Parent process
setup_wm.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Player
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\wmplayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3836
CMD
"C:\Program Files\Windows Media Player\wmpshare.exe"
Path
C:\Program Files\Windows Media Player\wmpshare.exe
Indicators
No indicators
Parent process
wmplayer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Player Folder Sharing Executable
Version
12.0.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\program files\windows media player\wmpshare.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

Registry activity

Total events
1239
Read events
892
Write events
344
Delete events
3

Modification events

PID
Process
Operation
Key
Name
Value
1492
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2960-13191630276181375
259
1492
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2960-13191630276181375
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
2960
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
aggregate
sum()
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
S-1-5-21-1302019708-1500728564-335382590-1000
1
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
aggregate
sum()
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
S-1-5-21-1302019708-1500728564-335382590-1000
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13191630277212625
2960
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.htm
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.html
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.shtml
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.xht
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.xhtml
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp
URL Protocol
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\ddeexec
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\shell
open
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http
URL Protocol
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\shell\open\ddeexec
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\shell
open
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https
URL Protocol
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\shell\open\ddeexec
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\shell
open
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Clients\StartMenuInternet
Google Chrome
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-1302019708-1500728564-335382590-1000
710D93C5B7DD2E00
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
1
3512
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3512
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\UserOptions
DesktopShortcut
no
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AcceptedPrivacyStatement
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MetadataRetrieval
3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SendUserGUID
00
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SilentAcquisition
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
UsageTracking
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUMusic
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUPictures
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUVideo
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUPlaylists
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice
Progid
WMP11.AssocFile.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice
Progid
WMP11.AssocFile.WMD
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice
Progid
WMP11.AssocFile.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice
Progid
WMP11.AssocFile.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice
Progid
WMP11.AssocFile.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice
Progid
WMP11.AssocFile.WPL
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice
Progid
WMP11.AssocFile.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice
Progid
WMP11.AssocFile.TTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice
Progid
WMP11.AssocFile.WVX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice
Progid
WMP11.AssocFile.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice
Progid
WMP11.AssocFile.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice
Progid
WMP11.AssocFile.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice
Progid
WMP11.AssocFile.WMS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice
Progid
WMP11.AssocFile.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice
Progid
WMP11.AssocFile.WMV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice
Progid
WMP11.AssocFile.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice
Progid
WMP11.AssocFile.WMZ
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice
Progid
WMP11.AssocFile.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice
Progid
WMP11.AssocFile.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice
Progid
WMP11.AssocFile.WAV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice
Progid
WMP11.AssocFile.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice
Progid
WMP11.AssocFile.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice
Progid
WMP11.AssocFile.WAX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice
Progid
WMP11.AssocFile.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice
Progid
WMP11.AssocFile.AU
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice
Progid
WMP11.AssocFile.M4A
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice
Progid
WMP11.AssocFile.CDA
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice
Progid
WMP11.AssocFile.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice
Progid
WMP11.AssocFile.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice
Progid
WMP11.AssocFile.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tts\UserChoice
Progid
WMP11.AssocFile.TTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice
Progid
WMP11.AssocFile.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice
Progid
WMP11.AssocFile.AU
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice
Progid
WMP11.AssocFile.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice
Progid
WMP11.AssocFile.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice
Progid
WMP11.AssocFile.m3u
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice
Progid
WMP11.AssocFile.M2TS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice
Progid
WMP11.AssocFile.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice
Progid
WMP11.AssocFile.M2TS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice
Progid
WMP11.AssocFile.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice
Progid
WMP11.AssocFile.M2TS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice
Progid
WMP11.AssocFile.WMA
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice
Progid
WMP11.AssocFile.MOV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\mms\UserChoice
Progid
WMP11.AssocProtocol.MMS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/quicktime\UserChoice
Progid
WMP11.AssocMIME.MOV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/msvideo\UserChoice
Progid
WMP11.AssocMIME.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wmx\UserChoice
Progid
WMP11.AssocMIME.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/midi\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/vnd.dlna.mpeg-tts\UserChoice
Progid
WMP11.AssocMIME.TTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/vnd.dlna.adts\UserChoice
Progid
WMP11.AssocMIME.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/wav\UserChoice
Progid
WMP11.AssocMIME.WAV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/3gpp\UserChoice
Progid
WMP11.AssocMIME.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/3gpp\UserChoice
Progid
WMP11.AssocMIME.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-wav\UserChoice
Progid
WMP11.AssocMIME.WAV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/3gpp2\UserChoice
Progid
WMP11.AssocMIME.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-aiff\UserChoice
Progid
WMP11.AssocMIME.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mp3\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-ms-wma\UserChoice
Progid
WMP11.AssocMIME.WMA
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mpegurl\UserChoice
Progid
WMP11.AssocMIME.M3U
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mpg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/x-mplayer2\UserChoice
Progid
WMP11.AssocMIME.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/avi\UserChoice
Progid
WMP11.AssocMIME.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/mpg\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-mpeg\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/vnd.ms-wpl\UserChoice
Progid
WMP11.AssocMIME.WPL
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/3gpp2\UserChoice
Progid
WMP11.AssocMIME.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mpegurl\UserChoice
Progid
WMP11.AssocMIME.M3U
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wm\UserChoice
Progid
WMP11.AssocMIME.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/x-ms-wmd\UserChoice
Progid
WMP11.AssocMIME.WMD
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/aiff\UserChoice
Progid
WMP11.AssocMIME.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mpg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\midi/mid\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-asf-plugin\UserChoice
Progid
WMP11.AssocMIME.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mid\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-ms-wax\UserChoice
Progid
WMP11.AssocMIME.WAX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mpeg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-asf\UserChoice
Progid
WMP11.AssocMIME.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mp4\UserChoice
Progid
WMP11.AssocMIME.M4A
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mid\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mpeg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/mp4\UserChoice
Progid
WMP11.AssocMIME.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wmv\UserChoice
Progid
WMP11.AssocMIME.WMV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/mpeg\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/x-ms-wmz\UserChoice
Progid
WMP11.AssocMIME.WMZ
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mp3\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-msvideo\UserChoice
Progid
WMP11.AssocMIME.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/basic\UserChoice
Progid
WMP11.AssocMIME.AU
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-midi\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-mpeg2a\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wvx\UserChoice
Progid
WMP11.AssocMIME.WVX
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MigratedXML
1
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Migrating
1
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrentDownloadCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrent500ServerErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrent503ServerErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrentOtherServerErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrentNetworkErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataLastResetTime
600471901
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MediaLibraryCreateNewDatabase
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
LocalLibraryID
{DAC4D6EA-B3BD-49F1-AC83-5867016FCE18}
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Migrating
0
2600
unregmp2.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{5BBA5351-667A-47E9-89EC-BEB3DC62103D}
2600
unregmp2.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
AppName
%ProgramFiles%\Windows Media Player\wmplayer.exe
3480
unregmp2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM
DataPath
43003A005C00500072006F006700720061006D0044006100740061005C004D006900630072006F0073006F00660074005C00570069006E0064006F00770073005C00440052004D000000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Migrating
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LaunchIndex
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SQMLaunchIndex
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AppColorLimited
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\DMR
SerialNumber
{FB007FF1-A3C4-4D8A-858E-A1E917F2932A}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\DMR
UDN
{81352F27-CEB2-4694-BBE9-FD484DDE7167}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryBackgroundImage
6
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryHMENodesVisible
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MediaLibraryCreateNewDatabase
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
LocalLibraryID
{DAC4D6EA-B3BD-49F1-AC83-5867016FCE18}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
UserWantsRemoteSharing
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
UserWantsRemoteBrowsing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-1302019708-1500728564-335382590-1000
RemoteSharingEnabled
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryForceShowColumns
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LastContainerV12
{70C02500-7C6F-11D3-9FB6-00105AA620BB}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LastContainerMode
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins
LastViewModeVTen
2
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
EnableFileTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
EnableConsoleTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
FileTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
ConsoleTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
MaxFileSize
1048576
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
FileDirectory
%windir%\tracing
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
EnableFileTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
EnableConsoleTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
FileTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
ConsoleTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
MaxFileSize
1048576
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
FileDirectory
%windir%\tracing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
UsageLoggerRanOnce
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins\res://wmploc/RT_TEXT/player.wsz
Prefs
currentMetadataIconV11;0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins\res://wmploc/RT_TEXT/player.wsz
Prefs
currentMetadataIconV11;0;FirstRun;0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins
LastViewModeVTen
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
EverLoadedServices
1
1464
wmplayer.exe
write
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-wmplayer
CLSID
{cd3afa96-b84f-48f0-9393-7edc34128127}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SetHMEPermissionsOnDBDone
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Subscriptions
ActiveService
Service=Bing&userlocale=409&GEOID=f4&locale=409
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Subscriptions
ActiveServiceName
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DefaultSubscriptionService
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
FriendlyName
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
Task1ButtonText
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
Task1ButtonTip
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ImageLargeUrl
http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ImageSmallUrl
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ImageMenuUrl
http://images.windowsmedia.com/svcswitch/media_guide_16x16.png
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ColorPlayer
#0063B0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ColorPlayerText
#FFFFFF
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ContentPartner
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
Type
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{C120DE80-FDE4-49F5-A713-E902EF062B8A} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
010000000000000053AF27CA2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
37
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexMusic
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MostRecentFileAddOrRemove
20B64DCA2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryHasBeenPopulated
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
38
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
39
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexMusic
2
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexMusic
3
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
40
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
41
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
42
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{A38B883C-1682-497E-97B0-0A3A9E801682} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
010000000000000079E3BDCA2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
43
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
2
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
3
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
4
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
44
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
5
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
6
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
45
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
TranscodedFilesCacheSize
26204
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
TranscodedFilesCacheDefaultSizeSet
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
46
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
47
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
7
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
8
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
9
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
10
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
48
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
11
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
12
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
13
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
14
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{E37A73F8-FB01-43DC-914E-AAEE76095AB9} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
0100000000000000FBB0AECB2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
ShadowFileMaxClients
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
SwagBitsPerSecond
19922944
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileDiscontinuitiesPerSecond
20
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileGrowthQuantumSeconds
180
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileInlineGrowthQuantumSeconds
30
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileGrowthBudgetMs
45000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
LogInitialPageCount
16
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
LogMinJobWaitTimeMs
3000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
LogMaxJobDemoteTimeMs
5000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CommitMaxCheckPointPageCount
7
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CommitMaxCheckPoitnRateMs
10000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheLongPageCount
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheShortPageCount
64
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheHashTableSize
67
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheWaitForSize
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
NvpRecCount
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
NvpClientsCount
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
NvpRecWaitForCounts
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CriticalLowDiskSpace
0000004000000000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexVideo
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
TreeQueryWatcher
2
1464
wmplayer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D9D675CE-21B1-4CCE-B493-4AEE382FAEA7}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{AEB16279-B750-48F1-8586-97956060175A} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
0100000000000000F35BE1CD2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexVideo
2
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryBasketVisible
1
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
ProcessedCount
0
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
Folders
0
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ErrorFolders
Folders
0
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\UnShareFolders
ProcessedCount
0

Files activity

Executable files
0
Suspicious files
30
Text files
86
Unknown types
4

Dropped files

PID Process Filename Type
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\11_All_Pictures.wpl html
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG text
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\10_All_Music.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Temp\wmplog00.sqm sqm
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\09_Music_played_the_most.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\08_Video_rated_at_4_or_5_stars.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\07_TV_recorded_in_the_last_week.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\06_Pictures_rated_4_or_5_stars.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\05_Pictures_taken_in_the_last_month.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\04_Music_played_in_the_last_month.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\{0ACA4199-135B-4FB0-BE53-40D083D065B8}.jpg image
1464 wmplayer.exe C:\Users\Public\Music\Sample Music\Folder.jpg image
1464 wmplayer.exe C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg image
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\{ACF7033E-664F-4E56-9C1B-4F044F4986B1}.jpg image
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\03_Music_rated_at_4_or_5_stars.wpl html
1464 wmplayer.exe C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg image
1464 wmplayer.exe C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg image
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\02_Music_added_in_the_last_month.wpl html
1464 wmplayer.exe C:\Users\Public\Music\Sample Music\Folder.jpg image
1464 wmplayer.exe C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg image
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\01_Music_auto_rated_at_5_stars.wpl html
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\mg4_wmp12_30x30_2[1].png image
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\media_guide_16x16[1].png image
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\bing[1].xml text
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\AllServices[1].xml xml
1464 wmplayer.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms binary
1464 wmplayer.exe C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5S8X4I7FAVA3YQ0FKB11.temp ––
2512 setup_wm.exe C:\Users\admin\AppData\Local\Temp\wmsetup.log text
3480 unregmp2.exe C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds binary
3480 unregmp2.exe C:\ProgramData\Microsoft\Windows\DRM\v3ks.sec binary
3480 unregmp2.exe C:\ProgramData\Microsoft\Windows\DRM\v3ks.bla text
3480 unregmp2.exe C:\ProgramData\Microsoft\Windows\DRM\blackbox.bin binary
2600 unregmp2.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF24b798.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF24b798.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\cfb56871-1e35-42d5-94f5-425e4a0606b5.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\1e6f7ae4-2834-4fab-89b5-1c4f5dcfde0c.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF24b789.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Tabs binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF24b76a.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\78802b2c-6ae2-42c1-97e9-c19c8819df18.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabs binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_2 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_1 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\192f9509-50fd-46b8-8ee7-cf0535edec50.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_0 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG text
1464 wmplayer.exe C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\12_All_Video.wpl html
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000016 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\MANIFEST-000016 binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Visited Links binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History sqlite
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History-journal ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data sqlite
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Session binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF24925d.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\c754465d-ba77-4341-9bb0-d4833cf58ef3.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF24920f.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\0875bb0a-8509-4577-a30c-b9ae61e5fc32.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF2491b1.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\514b4c5d-09a9-428c-aab3-62020b0147c8.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\f_000001 mp3
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Session binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old~RF247281.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_3 ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\index ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF246ec8.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF246e7a.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model~RF246ddd.TMP binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6aa7cc0f-c881-40b5-8c76-7de2ad381b92.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old~RF246bbb.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF246b8c.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\CURRENT text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\CURRENT~RF246b7c.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old~RF246b3e.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF246b3e.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\457d2044-762c-4a72-aa94-bb3520782cc4.tmp ––
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF246b0f.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old~RF246b0f.TMP text
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version text
3688 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma binary
2960 chrome.exe C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat binary

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
5
TCP/UDP connections
11
DNS requests
9
Threats
4

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
1464 wmplayer.exe GET 302 2.16.186.41:80 http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 unknown
––
––
whitelisted
1464 wmplayer.exe GET 200 2.16.186.98:80 http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 unknown
xml
whitelisted
1464 wmplayer.exe GET 200 2.16.186.98:80 http://onlinestores.metaservices.microsoft.com/bing/bing.xml?locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 unknown
text
whitelisted
1464 wmplayer.exe GET 200 2.16.186.64:80 http://images.windowsmedia.com/svcswitch/media_guide_16x16.png unknown
image
malicious
1464 wmplayer.exe GET 200 2.16.186.64:80 http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png unknown
image
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2960 chrome.exe 172.217.18.99:443 Google Inc. US whitelisted
2960 chrome.exe 216.58.205.227:443 Google Inc. US whitelisted
2960 chrome.exe 216.58.210.13:443 Google Inc. US whitelisted