General Info

URL

https://tryeuio.ml/zp/error/err.mp3

Full analysis
https://app.any.run/tasks/04ad6994-e7bd-40de-a519-43f8dfb7971a
Verdict
Malicious activity
Analysis date
1/10/2019, 22:44:20
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO

No malicious indicators.

Creates files in the program directory
  • unregmp2.exe (PID: 3480)
Creates files in the user directory
  • wmplayer.exe (PID: 1464)
Modifies the open verb of a shell class
  • chrome.exe (PID: 2960)
Application launched itself
  • chrome.exe (PID: 2960)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
44
Monitored processes
14
Malicious processes
0
Suspicious processes
0

Behavior graph

+
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs wmplayer.exe no specs setup_wm.exe no specs unregmp2.exe no specs unregmp2.exe no specs wmplayer.exe wmplayer.exe no specs wmpshare.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2960
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" https://tryeuio.ml/zp/error/err.mp3
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\credui.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mscms.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wpc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\imagehlp.dll

PID
3688
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=68.0.3440.106 --initial-client-data=0x78,0x7c,0x80,0x74,0x84,0x6f4300b0,0x6f4300c0,0x6f4300cc
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
1492
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2964 --on-initialized-event-handle=304 --parent-handle=308 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_watcher.dll

PID
4068
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAACAAwBAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=B2E1C1888076D473A6BDD1020AE4BD29 --mojo-platform-channel-handle=988 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\program files\google\chrome\application\68.0.3440.106\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libegl.dll

PID
2544
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --service-pipe-token=6594FA022F0CF9BA49D6BA57F21202F0 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6594FA022F0CF9BA49D6BA57F21202F0 --renderer-client-id=4 --mojo-platform-channel-handle=1896 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3252
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --service-pipe-token=9A45B09FC40F5B70804A3CCA333C02B1 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9A45B09FC40F5B70804A3CCA333C02B1 --renderer-client-id=3 --mojo-platform-channel-handle=2140 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
4052
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=992,14314600984727484759,16689743019633329455,131072 --enable-features=PasswordImport --disable-gpu-sandbox --gpu-preferences=KAAAAAAAAACAAwBAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=2FCA96162A5B2B821D46BE3A6215CFF0 --mojo-platform-channel-handle=3572 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
68.0.3440.106
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_child.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\program files\google\chrome\application\68.0.3440.106\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\68.0.3440.106\swiftshader\libegl.dll

PID
3512
CMD
"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1
Path
C:\Program Files\Windows Media Player\wmplayer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Player
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\wmplayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\program files\windows media player\setup_wm.exe

PID
2512
CMD
"C:\Program Files\Windows Media Player\setup_wm.exe" /RunOnce:"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1
Path
C:\Program Files\Windows Media Player\setup_wm.exe
Indicators
No indicators
Parent process
wmplayer.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Media Configuration Utility
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\setup_wm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\pdh.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\system32\mf.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\quartz.dll
c:\windows\system32\winmm.dll
c:\windows\system32\devenum.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\unregmp2.exe

PID
2600
CMD
C:\Windows\system32\unregmp2.exe /ShowWMP /SetShowState /CreateMediaLibrary
Path
C:\Windows\system32\unregmp2.exe
Indicators
No indicators
Parent process
setup_wm.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Media Player Setup Utility
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\unregmp2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wmdrmsdk.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\winmm.dll
c:\windows\system32\linkinfo.dll
c:\program files\windows media player\wmplayer.exe

PID
3480
CMD
"C:\Windows\system32\unregmp2.exe" /PerformIndivIfNeeded
Path
C:\Windows\system32\unregmp2.exe
Indicators
No indicators
Parent process
setup_wm.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Media Player Setup Utility
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\unregmp2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wmdrmsdk.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\avrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\drmv2clt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\blackbox.dll
c:\windows\system32\cryptbase.dll

PID
1464
CMD
"C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:1
Path
C:\Program Files\Windows Media Player\wmplayer.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Media Player
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\wmplayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\jscript.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\upnphost.dll
c:\windows\system32\ssdpapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\slc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mswmdm.dll
c:\windows\system32\cewmdm.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\upnp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\wmdmps.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\shsvcs.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\normaliz.dll
c:\program files\windows media player\wmpshare.exe
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wmpps.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\mlang.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\photometadatahandler.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\windowscodecsext.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\sbe.dll
c:\windows\ehome\ehtrace.dll
c:\program files\windows media player\wmpmediasharing.dll
c:\program files\windows media player\wmpnssci.dll
c:\windows\system32\idstore.dll

PID
3096
CMD
"C:\Program Files\Windows Media Player\wmplayer.exe" /Relaunch /prefetch:1
Path
C:\Program Files\Windows Media Player\wmplayer.exe
Indicators
No indicators
Parent process
setup_wm.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Player
Version
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\windows media player\wmplayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3836
CMD
"C:\Program Files\Windows Media Player\wmpshare.exe"
Path
C:\Program Files\Windows Media Player\wmpshare.exe
Indicators
No indicators
Parent process
wmplayer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Player Folder Sharing Executable
Version
12.0.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\program files\windows media player\wmpshare.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wmp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

Registry activity

Total events
1239
Read events
892
Write events
344
Delete events
3

Modification events

PID
Process
Operation
Key
Name
Value
2960
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
aggregate
sum()
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
S-1-5-21-1302019708-1500728564-335382590-1000
1
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
aggregate
sum()
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
S-1-5-21-1302019708-1500728564-335382590-1000
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13191630277212625
2960
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice
Progid
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.htm
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.html
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.shtml
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.xht
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\.xhtml
ChromeHTML
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp
URL Protocol
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\shell\open\ddeexec
2960
chrome.exe
write
HKEY_CLASSES_ROOT\ftp\shell
open
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http
URL Protocol
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\shell\open\ddeexec
2960
chrome.exe
write
HKEY_CLASSES_ROOT\http\shell
open
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https
URL Protocol
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\DefaultIcon
C:\Program Files\Google\Chrome\Application\chrome.exe,0
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\shell\open\command
"C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\shell\open\ddeexec
2960
chrome.exe
write
HKEY_CLASSES_ROOT\https\shell
open
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Clients\StartMenuInternet
Google Chrome
2960
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-1302019708-1500728564-335382590-1000
710D93C5B7DD2E00
2960
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
1
1492
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2960-13191630276181375
259
1492
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2960-13191630276181375
0
3512
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3512
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\UserOptions
DesktopShortcut
no
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AcceptedPrivacyStatement
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MetadataRetrieval
3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SendUserGUID
00
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SilentAcquisition
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
UsageTracking
1
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUMusic
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUPictures
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUVideo
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DisableMRUPlaylists
0
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice
Progid
WMP11.AssocFile.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice
Progid
WMP11.AssocFile.WMD
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice
Progid
WMP11.AssocFile.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice
Progid
WMP11.AssocFile.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice
Progid
WMP11.AssocFile.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice
Progid
WMP11.AssocFile.WPL
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice
Progid
WMP11.AssocFile.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice
Progid
WMP11.AssocFile.TTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice
Progid
WMP11.AssocFile.WVX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice
Progid
WMP11.AssocFile.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice
Progid
WMP11.AssocFile.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice
Progid
WMP11.AssocFile.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice
Progid
WMP11.AssocFile.WMS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice
Progid
WMP11.AssocFile.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice
Progid
WMP11.AssocFile.WMV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice
Progid
WMP11.AssocFile.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice
Progid
WMP11.AssocFile.WMZ
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice
Progid
WMP11.AssocFile.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice
Progid
WMP11.AssocFile.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice
Progid
WMP11.AssocFile.WAV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice
Progid
WMP11.AssocFile.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice
Progid
WMP11.AssocFile.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice
Progid
WMP11.AssocFile.WAX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice
Progid
WMP11.AssocFile.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice
Progid
WMP11.AssocFile.AU
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice
Progid
WMP11.AssocFile.M4A
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice
Progid
WMP11.AssocFile.CDA
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice
Progid
WMP11.AssocFile.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice
Progid
WMP11.AssocFile.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice
Progid
WMP11.AssocFile.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tts\UserChoice
Progid
WMP11.AssocFile.TTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice
Progid
WMP11.AssocFile.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice
Progid
WMP11.AssocFile.AU
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice
Progid
WMP11.AssocFile.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice
Progid
WMP11.AssocFile.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice
Progid
WMP11.AssocFile.m3u
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice
Progid
WMP11.AssocFile.M2TS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice
Progid
WMP11.AssocFile.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice
Progid
WMP11.AssocFile.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice
Progid
WMP11.AssocFile.M2TS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice
Progid
WMP11.AssocFile.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice
Progid
WMP11.AssocFile.M2TS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice
Progid
WMP11.AssocFile.WMA
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice
Progid
WMP11.AssocFile.MOV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\mms\UserChoice
Progid
WMP11.AssocProtocol.MMS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/quicktime\UserChoice
Progid
WMP11.AssocMIME.MOV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/msvideo\UserChoice
Progid
WMP11.AssocMIME.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wmx\UserChoice
Progid
WMP11.AssocMIME.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/midi\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/vnd.dlna.mpeg-tts\UserChoice
Progid
WMP11.AssocMIME.TTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/vnd.dlna.adts\UserChoice
Progid
WMP11.AssocMIME.ADTS
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/wav\UserChoice
Progid
WMP11.AssocMIME.WAV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/3gpp\UserChoice
Progid
WMP11.AssocMIME.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/3gpp\UserChoice
Progid
WMP11.AssocMIME.3GP
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-wav\UserChoice
Progid
WMP11.AssocMIME.WAV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/3gpp2\UserChoice
Progid
WMP11.AssocMIME.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-aiff\UserChoice
Progid
WMP11.AssocMIME.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mp3\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-ms-wma\UserChoice
Progid
WMP11.AssocMIME.WMA
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mpegurl\UserChoice
Progid
WMP11.AssocMIME.M3U
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mpg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/x-mplayer2\UserChoice
Progid
WMP11.AssocMIME.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/avi\UserChoice
Progid
WMP11.AssocMIME.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/mpg\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-mpeg\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/vnd.ms-wpl\UserChoice
Progid
WMP11.AssocMIME.WPL
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/3gpp2\UserChoice
Progid
WMP11.AssocMIME.3G2
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mpegurl\UserChoice
Progid
WMP11.AssocMIME.M3U
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wm\UserChoice
Progid
WMP11.AssocMIME.ASF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/x-ms-wmd\UserChoice
Progid
WMP11.AssocMIME.WMD
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/aiff\UserChoice
Progid
WMP11.AssocMIME.AIFF
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mpg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\midi/mid\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-asf-plugin\UserChoice
Progid
WMP11.AssocMIME.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mid\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-ms-wax\UserChoice
Progid
WMP11.AssocMIME.WAX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mpeg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-asf\UserChoice
Progid
WMP11.AssocMIME.ASX
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mp4\UserChoice
Progid
WMP11.AssocMIME.M4A
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-mid\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mpeg\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/mp4\UserChoice
Progid
WMP11.AssocMIME.MP4
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wmv\UserChoice
Progid
WMP11.AssocMIME.WMV
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/mpeg\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\application/x-ms-wmz\UserChoice
Progid
WMP11.AssocMIME.WMZ
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/mp3\UserChoice
Progid
WMP11.AssocMIME.MP3
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-msvideo\UserChoice
Progid
WMP11.AssocMIME.AVI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/basic\UserChoice
Progid
WMP11.AssocMIME.AU
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\audio/x-midi\UserChoice
Progid
WMP11.AssocMIME.MIDI
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-mpeg2a\UserChoice
Progid
WMP11.AssocMIME.MPEG
2512
setup_wm.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\MIMEAssociations\video/x-ms-wvx\UserChoice
Progid
WMP11.AssocMIME.WVX
2600
unregmp2.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{5BBA5351-667A-47E9-89EC-BEB3DC62103D}
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MigratedXML
1
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Migrating
1
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrentDownloadCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrent500ServerErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrent503ServerErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrentOtherServerErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataCurrentNetworkErrorCount
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AutoMetadataLastResetTime
600471901
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MediaLibraryCreateNewDatabase
0
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
LocalLibraryID
{DAC4D6EA-B3BD-49F1-AC83-5867016FCE18}
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Migrating
0
2600
unregmp2.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2600
unregmp2.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
AppName
%ProgramFiles%\Windows Media Player\wmplayer.exe
3480
unregmp2.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM
DataPath
43003A005C00500072006F006700720061006D0044006100740061005C004D006900630072006F0073006F00660074005C00570069006E0064006F00770073005C00440052004D000000
1464
wmplayer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D9D675CE-21B1-4CCE-B493-4AEE382FAEA7}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Migrating
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LaunchIndex
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SQMLaunchIndex
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
AppColorLimited
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\DMR
SerialNumber
{FB007FF1-A3C4-4D8A-858E-A1E917F2932A}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\DMR
UDN
{81352F27-CEB2-4694-BBE9-FD484DDE7167}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryBackgroundImage
6
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryHMENodesVisible
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MediaLibraryCreateNewDatabase
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
LocalLibraryID
{DAC4D6EA-B3BD-49F1-AC83-5867016FCE18}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
UserWantsRemoteSharing
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME
UserWantsRemoteBrowsing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\PREFERENCES\HME\S-1-5-21-1302019708-1500728564-335382590-1000
RemoteSharingEnabled
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryForceShowColumns
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LastContainerV12
{70C02500-7C6F-11D3-9FB6-00105AA620BB}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LastContainerMode
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins
LastViewModeVTen
2
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
EnableFileTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
EnableConsoleTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
FileTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
ConsoleTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
MaxFileSize
1048576
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASAPI32
FileDirectory
%windir%\tracing
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
EnableFileTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
EnableConsoleTracing
0
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
FileTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
ConsoleTracingMask
4294901760
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
MaxFileSize
1048576
1464
wmplayer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wmplayer_RASMANCS
FileDirectory
%windir%\tracing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
UsageLoggerRanOnce
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins\res://wmploc/RT_TEXT/player.wsz
Prefs
currentMetadataIconV11;0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins\res://wmploc/RT_TEXT/player.wsz
Prefs
currentMetadataIconV11;0;FirstRun;0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Skins
LastViewModeVTen
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
EverLoadedServices
1
1464
wmplayer.exe
write
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-wmplayer
CLSID
{cd3afa96-b84f-48f0-9393-7edc34128127}
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
SetHMEPermissionsOnDBDone
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Subscriptions
ActiveService
Service=Bing&userlocale=409&GEOID=f4&locale=409
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Subscriptions
ActiveServiceName
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
DefaultSubscriptionService
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
FriendlyName
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
Task1ButtonText
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
Task1ButtonTip
Bing
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ImageLargeUrl
http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ImageSmallUrl
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ImageMenuUrl
http://images.windowsmedia.com/svcswitch/media_guide_16x16.png
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ColorPlayer
#0063B0
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ColorPlayerText
#FFFFFF
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
ContentPartner
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Services\Bing
Type
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{C120DE80-FDE4-49F5-A713-E902EF062B8A} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
010000000000000053AF27CA2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
37
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexMusic
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MostRecentFileAddOrRemove
20B64DCA2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryHasBeenPopulated
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
38
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
39
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexMusic
2
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexMusic
3
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
40
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
41
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
42
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{A38B883C-1682-497E-97B0-0A3A9E801682} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
010000000000000079E3BDCA2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
43
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
2
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
3
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
4
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
44
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
5
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
6
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
45
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
TranscodedFilesCacheSize
26204
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
TranscodedFilesCacheDefaultSizeSet
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
46
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
47
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
7
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
8
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
9
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
10
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexList
48
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
11
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
12
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
13
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexPhoto
14
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{E37A73F8-FB01-43DC-914E-AAEE76095AB9} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
0100000000000000FBB0AECB2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
ShadowFileMaxClients
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
SwagBitsPerSecond
19922944
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileDiscontinuitiesPerSecond
20
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileGrowthQuantumSeconds
180
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileInlineGrowthQuantumSeconds
30
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
FileGrowthBudgetMs
45000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
LogInitialPageCount
16
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
LogMinJobWaitTimeMs
3000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
LogMaxJobDemoteTimeMs
5000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CommitMaxCheckPointPageCount
7
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CommitMaxCheckPoitnRateMs
10000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheLongPageCount
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheShortPageCount
64
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheHashTableSize
67
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CacheWaitForSize
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
NvpRecCount
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
NvpClientsCount
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
NvpRecWaitForCounts
32
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SBE\SAL
CriticalLowDiskSpace
0000004000000000
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexVideo
1
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
TreeQueryWatcher
2
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{AEB16279-B750-48F1-8586-97956060175A} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
0100000000000000F35BE1CD2DA9D401
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
MLSChangeIndexVideo
2
1464
wmplayer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
LibraryBasketVisible
1
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
ProcessedCount
0
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ShareFolders
Folders
0
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\ErrorFolders
Folders
0
3836
wmpshare.exe
write
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\HME\UnShareFolders
ProcessedCount
0

Files activity

Executable files
0
Suspicious files
30
Text files
86
Unknown types
4

Dropped files

PID
Process
Filename
Type
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\11_All_Pictures.wpl
html
MD5: 74294ef495559ed32731f19096d70312
SHA256: db34d82f2cd23e6e55a64e12d2a0a9c27ac2ded156483238f22a336ca6825110
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
binary
MD5: 1e9eeb0fe86517c0a18b3d5db19df398
SHA256: 29e10039708f19dfb00e2861aaf6f8e3127dc71455e767d1a9cdd94a8797e8ba
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\10_All_Music.wpl
html
MD5: 51aeed11707741118e0706c1259df22e
SHA256: ec286113e5ad77ac34063589a137a6dc4b4cab8845cd9c5386519983fa3b48f0
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Temp\wmplog00.sqm
sqm
MD5: 3d75214dc913575dbb0d2edbc1efcaaa
SHA256: 8ca9d3a180cd0acc4e414cecde3022751873c36081410a7da006fa2f317d6c55
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\09_Music_played_the_most.wpl
html
MD5: 467e71aa2fd951eb0a1af3d6bb8378e8
SHA256: a54bc2cad63ced4fd9ff2a3a094a26e264e8a5ce8139193896d13236f494e2ee
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\08_Video_rated_at_4_or_5_stars.wpl
html
MD5: a3787a42b81fce0e448976ad158edd93
SHA256: 94bc17ac59bde92fbca00fcc69aed68fcbfe2c1754dd45f4810765f5fdf774ff
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\07_TV_recorded_in_the_last_week.wpl
html
MD5: b9987b1f9df6d0afc01558b907e62a16
SHA256: 0892efdb8459d81d4c5e1085239734d9910b9c6a1debd7189cf385141f0b19d1
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\06_Pictures_rated_4_or_5_stars.wpl
html
MD5: 0a8a40ca87323dc16893194b00c7fe77
SHA256: 9aa433bed2e090cc6904f1c24d5a7b5a1ed6d8f71a997e661b886c69383fd53e
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\05_Pictures_taken_in_the_last_month.wpl
html
MD5: 821d2be672f05514127c117cef460c6e
SHA256: 3abdb6cbd88ad1557054ece3f10dd1a8494ed32f423b3cf8321b18decc489474
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\04_Music_played_in_the_last_month.wpl
html
MD5: f8d3a4cacf055f5ec5c62218ea50d290
SHA256: 201f2170812cf8041964c4d3c5ef539d96adeba6a68b69ecaed0affe3ae8e25f
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\{0ACA4199-135B-4FB0-BE53-40D083D065B8}.jpg
image
MD5: 4fc21c17fb53a92d2fca85fff1d4c869
SHA256: 516008d9059cea6401443e9287fc2cd03768ecc1f3dd0e8bdc8988598327eb98
1464
wmplayer.exe
C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg
image
MD5: 70802ddd884db2336d0ec028b0318c7a
SHA256: a3df3500170e4b05cc74f73e9dc40cdb518f6bab704ee9d865a9474b6a47948a
1464
wmplayer.exe
C:\Users\Public\Music\Sample Music\Folder.jpg
image
MD5: 4fc21c17fb53a92d2fca85fff1d4c869
SHA256: 516008d9059cea6401443e9287fc2cd03768ecc1f3dd0e8bdc8988598327eb98
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Art Cache\LocalMLS\{ACF7033E-664F-4E56-9C1B-4F044F4986B1}.jpg
image
MD5: be271899f3ac99bb0c3ed733a45eaa61
SHA256: 741771c52e75eb2f3a3d3c367d79e353a85d6c7914a716b99bb512ddca652895
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\03_Music_rated_at_4_or_5_stars.wpl
html
MD5: 6d791b697af46d6777182af7f18c2955
SHA256: 4825eb90140f6b2f4f7ed0df66b24e10ff5d0da70af53ea495fd30b3aa791870
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\02_Music_added_in_the_last_month.wpl
html
MD5: 907bfc98ce854ae312127c952d8be0f2
SHA256: c475dc7423c2ad60f25adaac754cd8b68b57ff04f26ecef78f3e5961b986a324
1464
wmplayer.exe
C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg
image
MD5: 7b6f37a9c0ccc190eeb32ab56ccd1f4b
SHA256: 51352c704d2e8ad3095cf7a90f7f00fea5f21a5f05205b9fbc865173b44ea89c
1464
wmplayer.exe
C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg
image
MD5: dbf32c96b8af1d5c04f5db7b155c0461
SHA256: bf7de8674d3d0d9982ab0ad380e9a09e47f38da244f65db0b3dd3cd23ef48d21
1464
wmplayer.exe
C:\Users\Public\Music\Sample Music\Folder.jpg
image
MD5: dbf32c96b8af1d5c04f5db7b155c0461
SHA256: bf7de8674d3d0d9982ab0ad380e9a09e47f38da244f65db0b3dd3cd23ef48d21
1464
wmplayer.exe
C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg
image
MD5: 7b6f37a9c0ccc190eeb32ab56ccd1f4b
SHA256: 51352c704d2e8ad3095cf7a90f7f00fea5f21a5f05205b9fbc865173b44ea89c
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\01_Music_auto_rated_at_5_stars.wpl
html
MD5: 159e63275630ec4c9747b664bd063938
SHA256: d54745665432625a904636e7675612c85026da07e68f4e9d8dacbe98e5dee844
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\mg4_wmp12_30x30_2[1].png
image
MD5: 2fb401b99e4b8728820a2fc6a80e89bb
SHA256: 1be5955f420df102cc84e1a7cd470ea81ded6e2a4ac13409dcdd24541522837e
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\media_guide_16x16[1].png
image
MD5: 595006285cdf63edd55a1d0c1f59cd54
SHA256: 07265d4602d9e3f6f9e9e78c0a19488a1877404850b73c8c3e39575c9674f4e3
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\bing[1].xml
text
MD5: d58da90d6dc51f97cb84dfbffe2b2300
SHA256: 93acdb79543d9248ca3fca661f3ac287e6004e4b3dafd79d4c4070794ffbf2ad
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\AllServices[1].xml
xml
MD5: df03e65b8e082f24dab09c57bc9c6241
SHA256: 155b9c588061c71832af329fafa5678835d9153b8fbb7592195ae953d0c455ba
1464
wmplayer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms
binary
MD5: 5ce63626c3fe2a6069ce4ea4c5db9da4
SHA256: 0a2679801650dba3b038c4f410b8cd07a9be2fb0df04d85b3a97721f8f4faf8c
1464
wmplayer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5S8X4I7FAVA3YQ0FKB11.temp
––
MD5:  ––
SHA256:  ––
2512
setup_wm.exe
C:\Users\admin\AppData\Local\Temp\wmsetup.log
text
MD5: 55142989e2b606c356db54e73a04e4a6
SHA256: 0bdca23825f5a1053a021029283bb2bec60ad465067e09130f8a3582ce637913
3480
unregmp2.exe
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds
binary
MD5: 988e16bbf2a5cdd9fa4ec0a3a05aa533
SHA256: c7eca4fe5000936b896e01b97a6b403d51cba3de25f4b910dc618e787c7b6e25
3480
unregmp2.exe
C:\ProgramData\Microsoft\Windows\DRM\v3ks.sec
binary
MD5: 3e7dbcb75aca05240fa8cbeaedc7908c
SHA256: e19015d93cf263c50f6ffa7b360d30fdba9f2bebe1b387a705a16fde654b2817
3480
unregmp2.exe
C:\ProgramData\Microsoft\Windows\DRM\v3ks.bla
text
MD5: 8d2eac7258de5216979b2be690106cef
SHA256: 5bb53da4cd17bec803e875a55cdab48fc403b4844da9e21de8e363c3faeb6693
3480
unregmp2.exe
C:\ProgramData\Microsoft\Windows\DRM\blackbox.bin
binary
MD5: 64d63f6463a49edd993602057438ddc9
SHA256: 2aa509e320aa570b8ea6ac237476279d8006d69dc61409c14dd82043641bfd08
2600
unregmp2.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb
binary
MD5: 71d9cd0ac4f06dfec51c47e7107b0da9
SHA256: 6c32c13f09862b4eec5b31d55c935438a180c323b1e638c0e2e2971c39791766
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
text
MD5: 848339648d3adec1ecf2b7289d17c57a
SHA256: 1dfa0ffbc289d235a0c1f515a8e0a4e2d2c37d2b0de0eb32aadaf4174739baaf
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF24b798.TMP
text
MD5: 5d8e01c598fb5602f9bc3d9f0c5d81b0
SHA256: 4a9f30c91ff1acb05c03df32f9917536b51e587ce325e920f7a1b0b2c116805e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State
text
MD5: 42f1ce4c5010e788a869636802e27b12
SHA256: 76077d2b06d8c7e6db1f258aa3c4abd3bb0a8bf83594e80295266cb98a480bf3
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF24b798.TMP
text
MD5: 42f1ce4c5010e788a869636802e27b12
SHA256: 76077d2b06d8c7e6db1f258aa3c4abd3bb0a8bf83594e80295266cb98a480bf3
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\cfb56871-1e35-42d5-94f5-425e4a0606b5.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\1e6f7ae4-2834-4fab-89b5-1c4f5dcfde0c.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 14d7890e5706e28d5e01b36f4f8ae203
SHA256: 56fede52c2ccb6dc63859228d1188fe5da0dd1d7c50fe4b6bc22c9e176d75cb7
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
binary
MD5: d932a31a0fb91833edb0325c6b434b34
SHA256: 8049465356163740d6e4c0bb56b9dcaa90149631646fa6bb56d01de223bd1f8e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF24b789.TMP
text
MD5: 14d7890e5706e28d5e01b36f4f8ae203
SHA256: 56fede52c2ccb6dc63859228d1188fe5da0dd1d7c50fe4b6bc22c9e176d75cb7
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
binary
MD5: ed3d1c71e33729de7febf8fe5e6ec916
SHA256: 69c86a85adc870f4b414d529894f622580db21bbefb5e2c4da4ba14141c7b1fc
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
binary
MD5: ada29af83e43b9f810cc5dee8e35a2bf
SHA256: 5f34d6811770368794050ddbc3fd9173bce2732a7a31afe7d0f0a5d9b2ffd570
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF24b76a.TMP
text
MD5: 5d8e01c598fb5602f9bc3d9f0c5d81b0
SHA256: 4a9f30c91ff1acb05c03df32f9917536b51e587ce325e920f7a1b0b2c116805e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\78802b2c-6ae2-42c1-97e9-c19c8819df18.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
binary
MD5: d7cba2db0526703f2a176d8f1da2e0b3
SHA256: 110384cc0fc60b2db74c7be208f535ff5b20c64371b3d3c0b19f83ce0948075f
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
binary
MD5: fd00c6fd9011ba18760509e08d2161c9
SHA256: 1f0107c2a11d3508683e9e4cd99fa720fe5779e5f903af77176823d1f40bc59e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
binary
MD5: 2a41851b55584633b126cd05b5e03e3e
SHA256: c1a3699b90671a02db57651c58ba83ed7ceb48cd43ca8a6d1b1436b0004160cb
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabs
binary
MD5: 9409bab446b7204c6235dfddd6066e89
SHA256: 68c1cb50ec24ac5a1dbdc7d9c845e94a1e9d60f312cf92a694f0791cd7ea105e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_2
binary
MD5: 0eaf170c50216ff9abdfec8cee450abe
SHA256: e25e8ae0b6e05059f7240f698325f02d4d077146d1f7514cd1c60e835b4c05aa
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 5d8e01c598fb5602f9bc3d9f0c5d81b0
SHA256: 4a9f30c91ff1acb05c03df32f9917536b51e587ce325e920f7a1b0b2c116805e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_1
binary
MD5: 5b589a6125519b1bfceb2c8a0f7f1529
SHA256: 3500a6c259cbda1e19de5506835528a508ed7049ba676acf6d38353c05e0d4e1
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\192f9509-50fd-46b8-8ee7-cf0535edec50.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_0
binary
MD5: e4e3d8d1c7e635d8698ded26b333bd7b
SHA256: be91edf0d5e05b8adb1b2344b25b8f0e4796c832362be202dc7d94132e0df360
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
text
MD5: 03ae0fa4020cf338a0b88ba88643afee
SHA256: fd0b83337a93195994337c547a2f336cc3c6041bd5ffa11dc30ac97045c16af9
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG
text
MD5: 06f0ff01ebb25d8fd8f6e919aa50734c
SHA256: b8bb737cb9c9bd518f3ca60ac8c088bcc15bbbe1ca824c9eca15732c1e58633e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
text
MD5: ac019c845fb1f6c70554f020700d48f1
SHA256: 2ec82f91e916dedf75508fb8a9ba51b81534d44fbf6753b56e20f5739adb07e0
1464
wmplayer.exe
C:\Users\admin\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\0002DBFE\12_All_Video.wpl
html
MD5: 372d0beebea5460409a6a1c53ac52a18
SHA256: 5b8b62b35e5dd8a46ccccaf3fc3743be9e0965d24cbcd20da2681065eeb37ef3
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
text
MD5: e4c96054415dee8867bf4d433e9a6ebd
SHA256: 637b7d7419ac059ab91725bd8b0f3d8e176c225d119b9fe20b00b6012207d0a7
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG
text
MD5: c694f38594adfcb2492f99738edb4f69
SHA256: 3555f0db67b7b5ac3bc18e77713c32b745519363b0b8dfb3bcee3a0274c1819e
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000016
binary
MD5: cf286cb4fd0f3dcc234806e1b865987b
SHA256: 21dc23520bba7268b53957a39981c9a85d3658edc4f5455e98cac3378a440d76
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
text
MD5: 2d3a351ef1a5c181a807ad520f0e5315
SHA256: 0c6e1da8c39686c31c13ded5d45938eb80e0be55e495c57028ca6e92e6fb7661
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
text
MD5: 5289a78b6a6072d20aea1a560f666883
SHA256: 2b177b88eab0072788e1e7bee127cf68c353cf43bfbf04f4c3cad96120f698ab
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG
text
MD5: 53ddb183dff90ca7b76d8740e51aed02
SHA256: af8b47f177b77f3d6f8c01add9aecc4842006f6155f1da0a9a2ce78368a1c2d3
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\MANIFEST-000016
binary
MD5: cf286cb4fd0f3dcc234806e1b865987b
SHA256: 21dc23520bba7268b53957a39981c9a85d3658edc4f5455e98cac3378a440d76
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Visited Links
binary
MD5: 222082a8a08724e2ae10e34ddf6c6537
SHA256: 36acc3dc1fe99d8c2beed711bc1ad3a901f0f26bfb98968b513b13a584dbc6b5
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History
sqlite
MD5: dae4a8b733befb39cc5637867aa4159e
SHA256: 760c29f4a5f17938483cad053381c160bd62092e32f0301bf00d75e89d817557
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History-journal
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data
sqlite
MD5: 54ad1e10b6b57bc9b9eed994e581dd5f
SHA256: 24d2a7516de320c3e91b1513cad94ce5ce2b964bbb8a3d1f66e8083b3205b19c
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
binary
MD5: b09c375f485772d1e57c9a1880a99ccf
SHA256: d9e4faf7b988f13252bfbcd9f616b0fcb708ae7bc60b014a2d48eec4181a6c8a
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Current Session
binary
MD5: fbab17812c755c3e83bac153a1a9b9bf
SHA256: 1dc0189582fa690259b498d6d01fae38fc2f6c49b9dd909ff2e285b4e0ce9d26
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 1cdebfdb70ee68639c6b9160f416d8e1
SHA256: fc1f926f1c958c96309933e1e2b85200283648888a11d0e46dee10fb08a53676
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF24925d.TMP
text
MD5: 1cdebfdb70ee68639c6b9160f416d8e1
SHA256: fc1f926f1c958c96309933e1e2b85200283648888a11d0e46dee10fb08a53676
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\c754465d-ba77-4341-9bb0-d4833cf58ef3.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 31e530e343ac5b8d219f31505c4c508e
SHA256: 22bd3108930bcddea6f0cd5783a9995a618179789d6fab32f1539f80f499f825
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF24920f.TMP
text
MD5: 31e530e343ac5b8d219f31505c4c508e
SHA256: 22bd3108930bcddea6f0cd5783a9995a618179789d6fab32f1539f80f499f825
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\0875bb0a-8509-4577-a30c-b9ae61e5fc32.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 144d56484d0914de423f94170708055d
SHA256: 6a8e662003e2bb9422a4e05ccabc0d46785f41f0d26e091e5be22d618cad94fb
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF2491b1.TMP
text
MD5: 144d56484d0914de423f94170708055d
SHA256: 6a8e662003e2bb9422a4e05ccabc0d46785f41f0d26e091e5be22d618cad94fb
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\514b4c5d-09a9-428c-aab3-62020b0147c8.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\f_000001
mp3
MD5: 0116152611dd51432e852781f8cc7e82
SHA256: fc59bbb18f923747b9cd3f3b23537ff09c5ad2fdfc1505a4800a3f269a234e65
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Session
binary
MD5: 02536c23edc1e418a6fea313d20b2a39
SHA256: 8e8de8689482b477d0beebe0a4ac24b9cabcbfa84848f66b4c0f55cd96dc0fe9
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old
text
MD5: 80b8c44b60f8bd20d1cf8277ec794bb1
SHA256: 6371157cf7270dd227625ddf799da6c38c60b3e2110fe540b8bc9df48aef09a6
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old~RF247281.TMP
text
MD5: 80b8c44b60f8bd20d1cf8277ec794bb1
SHA256: 6371157cf7270dd227625ddf799da6c38c60b3e2110fe540b8bc9df48aef09a6
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_3
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_2
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_1
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\data_0
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Media Cache\index
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
text
MD5: ea6d75c35eb812fdc5762d84963de026
SHA256: a4e911f2978a45872ede6742468623884a33bca6e015dfb35dd4d55034d9ab74
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF246ec8.TMP
text
MD5: ea6d75c35eb812fdc5762d84963de026
SHA256: a4e911f2978a45872ede6742468623884a33bca6e015dfb35dd4d55034d9ab74
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old
text
MD5: 84042895723ac99f9599edfc7500051c
SHA256: ac49bbf4b490c77bddf11de45ef4965c72b16b00cb2519fdb627363f760c6219
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF246e7a.TMP
text
MD5: 84042895723ac99f9599edfc7500051c
SHA256: ac49bbf4b490c77bddf11de45ef4965c72b16b00cb2519fdb627363f760c6219
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model
binary
MD5: 23aab53160c3b42dcd7748f0afdcce16
SHA256: 5439ea69aeaada1d41947a25be96a890395f404e6168abd3140bd803a5c67d86
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model~RF246ddd.TMP
binary
MD5: 23aab53160c3b42dcd7748f0afdcce16
SHA256: 5439ea69aeaada1d41947a25be96a890395f404e6168abd3140bd803a5c67d86
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\6aa7cc0f-c881-40b5-8c76-7de2ad381b92.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old
text
MD5: f727dd25cda7b2cc574098cee1f5764a
SHA256: 5f7bd6926940e400ee7faa6d620192ca299f7b5aaa92d672f8173a767b3fbbff
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old~RF246bbb.TMP
text
MD5: f727dd25cda7b2cc574098cee1f5764a
SHA256: 5f7bd6926940e400ee7faa6d620192ca299f7b5aaa92d672f8173a767b3fbbff
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF246b8c.TMP
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\CURRENT
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\CURRENT~RF246b7c.TMP
text
MD5: edd71dd3bade6cd69ff623e1ccf7012d
SHA256: befea596b4676ccf7cc37ea8048044bfa0556c8931d76fdeeb693d20264e50d6
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old~RF246b3e.TMP
text
MD5: 1aa66efdb743fb0a8dcc1cd79b0b6542
SHA256: 28d56532cced7375a2a1c7731e57c1a1c2ec1ac9827f3e5beee7f8069a5f87dd
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
text
MD5: 197882774a7ecec9046bc48f63189b66
SHA256: 27377b0d5f989997c2c3f74acf163eed44b60631ddaa768f6655d7be555742b2
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old
text
MD5: 1aa66efdb743fb0a8dcc1cd79b0b6542
SHA256: 28d56532cced7375a2a1c7731e57c1a1c2ec1ac9827f3e5beee7f8069a5f87dd
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF246b3e.TMP
text
MD5: 197882774a7ecec9046bc48f63189b66
SHA256: 27377b0d5f989997c2c3f74acf163eed44b60631ddaa768f6655d7be555742b2
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\457d2044-762c-4a72-aa94-bb3520782cc4.tmp
––
MD5:  ––
SHA256:  ––
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old
text
MD5: 92be6b127e72365885ad4c3fb6534ee2
SHA256: 54302a2573acc775720e7db0ad85873276713302b4f72596a8dcc44b01c70e51
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF246b0f.TMP
text
MD5: 92be6b127e72365885ad4c3fb6534ee2
SHA256: 54302a2573acc775720e7db0ad85873276713302b4f72596a8dcc44b01c70e51
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old
text
MD5: 8ca4ba2b95d7089861a48ed69fde6561
SHA256: aa64c14d0c68b62bbab62a6d6fa4662ff89e1fbc7b337c926ac213c191d6406c
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old~RF246b0f.TMP
text
MD5: 8ca4ba2b95d7089861a48ed69fde6561
SHA256: aa64c14d0c68b62bbab62a6d6fa4662ff89e1fbc7b337c926ac213c191d6406c
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version
text
MD5: c10ebd4db49249efc8d112b2920d5f73
SHA256: 90a1b994cafe902f22a88a22c0b6cc9cb5b974bf20f8964406dd7d6c9b8867d1
3688
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
binary
MD5: b59113c2dcd2d346f31a64f231162ada
SHA256: 1d97c69aea85d3b06787458ea47576b192ce5c5db9940e5eaa514ff977ce2dc2
2960
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
binary
MD5: 9c016064a1f864c8140915d77cf3389a
SHA256: 0e7265d4a8c16223538edd8cd620b8820611c74538e420a88e333be7f62ac787

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
5
TCP/UDP connections
11
DNS requests
9
Threats
4

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
1464 wmplayer.exe GET 302 2.16.186.41:80 http://redir.metaservices.microsoft.com/redir/allservices/?sv=5&locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 unknown
––
––
whitelisted
1464 wmplayer.exe GET 200 2.16.186.98:80 http://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 unknown
xml
whitelisted
1464 wmplayer.exe GET 200 2.16.186.98:80 http://onlinestores.metaservices.microsoft.com/bing/bing.xml?locale=409&geoid=f4&version=12.0.7601.17514&userlocale=409 unknown
text
whitelisted
1464 wmplayer.exe GET 200 2.16.186.64:80 http://images.windowsmedia.com/svcswitch/media_guide_16x16.png unknown
image
whitelisted
1464 wmplayer.exe GET 200 2.16.186.64:80 http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png unknown
image
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2960 chrome.exe 172.217.18.99:443 Google Inc. US whitelisted
2960 chrome.exe 216.58.205.227:443 Google Inc. US whitelisted
2960 chrome.exe 216.58.210.13:443 Google Inc. US whitelisted
2960 chrome.exe 144.202.49.4:443 Baltimore Technology Park, LLC US suspicious
2960 chrome.exe 172.217.21.195:443 Google Inc. US whitelisted
1464 wmplayer.exe 2.16.186.41:80 Akamai International B.V. –– whitelisted
1464 wmplayer.exe 2.16.186.98:80 Akamai International B.V. –– whitelisted
1464 wmplayer.exe 2.16.186.64:80 Akamai International B.V. –– whitelisted

DNS requests

Domain IP Reputation
clientservices.googleapis.com 172.217.18.99
whitelisted
www.gstatic.com 216.58.205.227
whitelisted
tryeuio.ml 144.202.49.4
suspicious
accounts.google.com 216.58.210.13
whitelisted
ssl.gstatic.com 172.217.21.195
whitelisted
redir.metaservices.microsoft.com 2.16.186.41
2.16.186.11
whitelisted
onlinestores.metaservices.microsoft.com 2.16.186.98
2.16.186.90
whitelisted
images.windowsmedia.com 2.16.186.64
2.16.186.99
whitelisted
sqm.msn.com No response whitelisted

Threats

PID Process Class Message
–– –– Potentially Bad Traffic ET INFO DNS Query for Suspicious .ml Domain
2960 chrome.exe Potentially Bad Traffic ET INFO Suspicious Domain (*.ml) in TLS SNI
2960 chrome.exe Potentially Bad Traffic ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.ml)
2960 chrome.exe Potentially Bad Traffic ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.ml)

Debug output strings

No debug info.