General Info

URL

http://www.notepage.net/download/pgsetup.exe

Full analysis
https://app.any.run/tasks/457708bf-6087-414f-8dae-13f07e7e4176
Verdict
Malicious activity
Analysis date
8/13/2019, 15:08:14
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • regsvr32.exe (PID: 3188)
  • regsvr32.exe (PID: 2316)
  • regsvr32.exe (PID: 2848)
  • pgc.exe (PID: 4088)
  • pgsetup.exe (PID: 2784)
  • regsvr32.exe (PID: 3460)
Application was dropped or rewritten from another process
  • pgc.exe (PID: 4088)
  • pgsetup.exe (PID: 3720)
  • pgcsetup.exe (PID: 3028)
  • pgsetup.exe (PID: 2784)
  • PGSetup.exe (PID: 3756)
Registers / Runs the DLL via REGSVR32.EXE
  • pgcsetup.tmp (PID: 3300)
Creates COM task schedule object
  • regsvr32.exe (PID: 3188)
Executable content was dropped or overwritten
  • chrome.exe (PID: 2084)
  • pgsetup.exe (PID: 2784)
  • pgcsetup.exe (PID: 3028)
  • chrome.exe (PID: 2568)
  • pgcsetup.tmp (PID: 3300)
Creates files in the Windows directory
  • pgcsetup.tmp (PID: 3300)
Reads the Windows organization settings
  • pgcsetup.tmp (PID: 3300)
Modifies files in Chrome extension folder
  • chrome.exe (PID: 2568)
Reads Windows owner or organization settings
  • pgcsetup.tmp (PID: 3300)
Manual execution by user
  • pgc.exe (PID: 4088)
Creates a software uninstall entry
  • pgcsetup.tmp (PID: 3300)
Creates files in the program directory
  • pgcsetup.tmp (PID: 3300)
Application was dropped or rewritten from another process
  • pgcsetup.tmp (PID: 3300)
Reads Internet Cache Settings
  • chrome.exe (PID: 2568)
Loads dropped or rewritten executable
  • pgcsetup.tmp (PID: 3300)
Application launched itself
  • chrome.exe (PID: 2568)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
82
Monitored processes
43
Malicious processes
5
Suspicious processes
1

Behavior graph

+
drop and start drop and start start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs pgsetup.exe no specs pgsetup.exe pgsetup.exe no specs chrome.exe no specs pgcsetup.exe pgcsetup.tmp chrome.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regini.exe no specs pgc.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2568
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.notepage.net/download/pgsetup.exe"
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wpc.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\samlib.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\wbem\wmiperfinst.dll
c:\windows\system32\pdh.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\bcryptprimitives.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\imagehlp.dll
c:\program files\microsoft office\office14\olkfstub.dll
c:\progra~1\micros~1\office14\mlshext.dll
c:\program files\microsoft office\office14\onfilter.dll
c:\program files\microsoft office\office14\visshe.dll
c:\program files\common files\microsoft shared\office14\msoshext.dll
c:\program files\microsoft office\office14\msohevi.dll
c:\windows\system32\mf.dll
c:\windows\system32\shdocvw.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\syncui.dll
c:\program files\notepad++\nppshell_06.dll
c:\program files\windows sidebar\sbdrop.dll
c:\windows\system32\stobject.dll
c:\windows\system32\cryptext.dll
c:\windows\system32\colorui.dll
c:\windows\system32\winspool.drv
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\dbghelp.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\users\admin\downloads\pgsetup.exe
c:\users\admin\downloads\pgsetup (1).exe
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
1952
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x70fea9d0,0x70fea9e0,0x70fea9ec
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
284
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3416 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_watcher.dll

PID
4080
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=9101459320347645530 --mojo-platform-channel-handle=980 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libegl.dll

PID
2084
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=1571359393802502100 --mojo-platform-channel-handle=1588 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll

PID
316
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14843042858670936694 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2220 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3128
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=18414073662107266542 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2208 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2180
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=291410123461054636 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2408 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3764
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=758677089661867216 --mojo-platform-channel-handle=3376 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
2956
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=162054120216647648 --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2852 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3664
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=568121106550315888 --renderer-client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2660 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3904
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14828682393655193267 --mojo-platform-channel-handle=3436 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1748
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=17538990731541283935 --mojo-platform-channel-handle=3560 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1080
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9469290797315900626 --mojo-platform-channel-handle=3552 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3144
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=3604289522811901964 --mojo-platform-channel-handle=3620 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3988
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=13555014929158099812 --mojo-platform-channel-handle=3632 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1920
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=15972788306871840872 --mojo-platform-channel-handle=3648 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2856
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4971480674419701433 --mojo-platform-channel-handle=3664 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2560
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=13500204378821985481 --mojo-platform-channel-handle=3600 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2984
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=6773224857018722774 --mojo-platform-channel-handle=3812 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2612
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13957502092233862801 --renderer-client-id=19 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1944 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3524
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17455754266278383133 --renderer-client-id=20 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4156 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3720
CMD
"C:\Users\admin\Downloads\pgsetup.exe"
Path
C:\Users\admin\Downloads\pgsetup.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
NotePage, Inc.
Description
Installation Package for PageGate v8.4
Version
8.4.0.0
Modules
Image
c:\users\admin\downloads\pgsetup.exe
c:\systemroot\system32\ntdll.dll

PID
2784
CMD
"C:\Users\admin\Downloads\pgsetup.exe"
Path
C:\Users\admin\Downloads\pgsetup.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
NotePage, Inc.
Description
Installation Package for PageGate v8.4
Version
8.4.0.0
Modules
Image
c:\users\admin\downloads\pgsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\temp\pb791cdae0\pbcore.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\pgsetup\pgsetup.exe

PID
3756
CMD
"C:\Users\admin\AppData\Local\Temp\PGSetup\PGSetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\PGSetup\PGSetup.exe
Indicators
No indicators
Parent process
pgsetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
NotePage, Inc.
Description
PageGate Installer
Version
8.3.0.0
Modules
Image
c:\users\admin\appdata\local\temp\pgsetup\pgsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\pgsetup\pgcsetup.exe

PID
3340
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=12359180004185092137 --mojo-platform-channel-handle=3376 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netutils.dll

PID
3028
CMD
"C:\Users\admin\AppData\Local\Temp\PGSetup\pgcsetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\PGSetup\pgcsetup.exe
Indicators
Parent process
PGSetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
NotePage, Inc.
Description
PageGate Client
Version
PageGate Client
Modules
Image
c:\users\admin\appdata\local\temp\pgsetup\pgcsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\users\admin\appdata\local\temp\is-8i48i.tmp\pgcsetup.tmp

PID
3300
CMD
"C:\Users\admin\AppData\Local\Temp\is-8I48I.tmp\pgcsetup.tmp" /SL5="$D0204,121344,121344,C:\Users\admin\AppData\Local\Temp\PGSetup\pgcsetup.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-8I48I.tmp\pgcsetup.tmp
Indicators
Parent process
pgcsetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-8i48i.tmp\pgcsetup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\pgsetup\psvince.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\devrtl.dll
c:\users\admin\appdata\local\temp\pgsetup\dao360.dll
c:\program files\common files\microsoft shared\dao\dao360.dll
c:\users\admin\appdata\local\temp\pgsetup\msjet40.dll
c:\windows\system32\msjet40.dll
c:\users\admin\appdata\local\temp\pgsetup\msjint40.dll
c:\windows\system32\msjint40.dll
c:\users\admin\appdata\local\temp\pgsetup\msjter40.dll
c:\windows\system32\msjter40.dll
c:\users\admin\appdata\local\temp\pgsetup\msjtes40.dll
c:\windows\system32\msjtes40.dll
c:\users\admin\appdata\local\temp\pgsetup\msrd3x40.dll
c:\windows\system32\msrd3x40.dll
c:\users\admin\appdata\local\temp\pgsetup\msrepl40.dll
c:\windows\system32\msrepl40.dll
c:\users\admin\appdata\local\temp\pgsetup\msvbvm60.dll
c:\windows\system32\msvbvm60.dll
c:\users\admin\appdata\local\temp\pgsetup\msvcrt.dll
c:\users\admin\appdata\local\temp\pgsetup\msvcrt40.dll
c:\windows\system32\msvcrt40.dll
c:\users\admin\appdata\local\temp\pgsetup\mswdat10.dll
c:\windows\system32\mswdat10.dll
c:\users\admin\appdata\local\temp\pgsetup\mswstr10.dll
c:\windows\system32\mswstr10.dll
c:\users\admin\appdata\local\temp\pgsetup\ole32.dll
c:\users\admin\appdata\local\temp\pgsetup\oleaut32.dll
c:\users\admin\appdata\local\temp\pgsetup\olepro32.dll
c:\windows\system32\olepro32.dll
c:\users\admin\appdata\local\temp\pgsetup\vbajet32.dll
c:\windows\system32\vbajet32.dll
c:\users\admin\appdata\local\temp\pgsetup\stdole2.tlb
c:\windows\system32\stdole2.tlb
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\notepage\pagegate client\pgc.exe
c:\windows\system32\regsvr32.exe
c:\windows\system32\regini.exe
c:\windows\system32\netutils.dll

PID
1212
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1012,6142713825839177936,10914540014701043511,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=2235318877269629200 --mojo-platform-channel-handle=2948 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3460
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\NotePage\PageGate Client\flp32x20.ocx"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\notepage\pagegate client\flp32x20.ocx
c:\windows\system32\mfc42.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\odbcint.dll

PID
2848
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\NotePage\PageGate Client\sgpview4.ocx"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\notepage\pagegate client\sgpview4.ocx
c:\windows\system32\msvbvm60.dll

PID
3188
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\NotePage\PageGate Client\vbaledit2.ocx"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\notepage\pagegate client\vbaledit2.ocx
c:\windows\system32\msvbvm60.dll

PID
2868
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Common Files\Microsoft Shared\DAO\dao360.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\common files\microsoft shared\dao\dao360.dll

PID
2316
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\comdlg32.ocx"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\comdlg32.ocx
c:\windows\system32\comdlg32.dll
c:\windows\system32\sxs.dll

PID
3112
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\msjet40.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msjet40.dll
c:\windows\system32\mswstr10.dll

PID
3116
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\msjtes40.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msjtes40.dll

PID
1648
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\msrd3x40.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msrd3x40.dll
c:\windows\system32\mswstr10.dll

PID
3188
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\msvbvm60.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\notepage\pagegate client\vbaledit2.ocx
c:\windows\system32\msctf.dll
c:\windows\system32\regsvr32.exe
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\sfc.dll
c:\windows\system32\version.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msvbvm60.dll

PID
3248
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\ole32.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
2060
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\oleaut32.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
3864
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\olepro32.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\olepro32.dll

PID
3900
CMD
"regini.exe" C:\Users\admin\AppData\Local\Temp\PGSetup\npreg.ini
Path
C:\Windows\system32\regini.exe
Indicators
No indicators
Parent process
pgcsetup.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Registry Initializer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regini.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll

PID
4088
CMD
"C:\Program Files\NotePage\PageGate Client\pgc.exe"
Path
C:\Program Files\NotePage\PageGate Client\pgc.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
NotePage, Inc.
Description
PageGate Client
Version
8.04.0003
Modules
Image
c:\program files\notepage\pagegate client\pgc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\comdlg32.ocx
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll

Registry activity

Total events
2154
Read events
1641
Write events
505
Delete events
8

Modification events

PID
Process
Operation
Key
Name
Value
2568
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2568
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
2568
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13210175310994625
2568
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307080002000D000D0009000A00EC0100000000
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aapocclcgogkmnckokdopfmhonfmgoek
788D02A3973693BB012A971EA5D6EE559C1001EE81C0063D07C9BAD03F38B898
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
15B1C3FE35F29528448F36A72A4DFBC58A8083C7190559D25865779166D220A2
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aohghmighlieiainnegkcijnfilokake
9EA82F3E301FB6254EA6CFF860205CB467C8649D33D9FCDAAA87571A7F6768C0
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
apdfllckaahabafndbhieahigkjlhalf
645FF3F2BA19D5AF04AE7A8092F328FFC2AA95F9F52ADE6F6E25E5D50F2EFF10
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
blpcfgokakmgnkcojhhkbfbldkacnbeo
373A1C3DECB61E9E2B702DCF1B567CC6C25BD398650A54167BA1F8E7111B5C66
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
felcaaldnbdncclmgdcncolpebgiejap
4AB1513A02ECC4F8F66EAFB405E259E528F58CBE4A08463E004D2C2190004BCF
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
D6B079666F209503A09486C70AC09307652A0F7F783166A999B27C99D0DA79E2
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ghbmnnjooekpmoecnnnilnnbdlolhkhi
4966437425B49BAF9530DF8E5A515A9C1726550A822A724F0B10722F33325AD5
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
00175B8120231631976CA8B862A3416996C9373BA3D289F0619DDA992973DDFA
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
63355C14E8C7DF9A075F2EDDEA6F2807DC8166B83F96F4C975B9B6554C6324D7
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
0E265BFED6F1C7D5F0A9BD790C50BB30E78E959631D51EEBB8BB0DE73E65763C
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
04A45240BDA55E8777FA04357712CA6DD942253A21323E4C7D3CCF769B34BFED
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
5D58C2FED93EFDED578B006CB02BBB8DEC329128E2D098172E1316CDD15254DC
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
FC2E6064506E4E47F35620CD7B442407FACEEF7369B83ECF6E9727A1A91A1661
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pjkljhegncpnkpknbcohdijeoejaedia
ACDE70A89E71C6E0C53169FA5D23A6E186BB39294B5290680088E4072823687B
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
4CA0924B49DB9F8C201E5FE05A41EEBB7ABBD9CA8FD8DFE7FEA914231F5D68AF
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\PTimes
C
7925056AD851D501
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C1
1C1GCEA_enUA812UA812
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C2
1C2GCEA_enUA812
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C7
1C7GCEA_enUA812
2568
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
1
284
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2568-13210175309979000
259
284
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2568-13210175309979000
0
2084
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3756
PGSetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3756
PGSetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3340
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\Common Files\Microsoft Shared\DAO\dao360.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\comdlg32.ocx
1
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msjet40.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msjint40.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msjter40.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msjtes40.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msrd3x40.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msrepl40.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvbvm60.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcrt.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcrt40.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\mswdat10.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\mswstr10.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\ole32.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\oleaut32.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\olepro32.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\vb5db.dll
1
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\vbajet32.dll
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\stdole2.tlb
2
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Inno Setup: Setup Version
5.5.9 (u)
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Inno Setup: App Path
C:\Program Files\NotePage\PageGate Client
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
InstallLocation
C:\Program Files\NotePage\PageGate Client\
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Inno Setup: Icon Group
PageGate Client
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Inno Setup: User
admin
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Inno Setup: Selected Tasks
desktopicon
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Inno Setup: Deselected Tasks
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Inno Setup: Language
english
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
DisplayName
PageGate Client
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
DisplayIcon
C:\Program Files\NotePage\PageGate Client\pgc.exe
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
UninstallString
"C:\Program Files\NotePage\PageGate Client\unins000.exe"
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
QuietUninstallString
"C:\Program Files\NotePage\PageGate Client\unins000.exe" /SILENT
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
DisplayVersion
8.4
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Publisher
NotePage, Inc.
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
URLInfoAbout
http://www.notepage.com
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
HelpLink
http://www.notepage.net/support.htm
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
URLUpdateInfo
http://www.notepage.com
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Contact
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
Comments
PageGate Client
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
NoModify
1
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
NoRepair
1
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
InstallDate
20190813
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
MajorVersion
8
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
MinorVersion
4
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
VersionMajor
8
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
VersionMinor
4
3300
pgcsetup.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE86482E-F59E-46A5-B27E-23D0F6A0EFEA}_is1
EstimatedSize
12196
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}\2.1
FarPoint ListPro Controls 2.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}\2.1\FLAGS
2
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}\2.1\0\win32
C:\Program Files\NotePage\PageGate Client\flp32x20.ocx
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}\2.1\HELPDIR
C:\Program Files\NotePage\PageGate Client
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622B-1BB0-11D0-81C3-0080C7A2EF7D}
_DfpList
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622B-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622B-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622B-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622B-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
Version
2.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622C-1BB0-11D0-81C3-0080C7A2EF7D}
_DfpListEvents
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622C-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622C-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622C-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE622C-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
Version
2.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6230-1BB0-11D0-81C3-0080C7A2EF7D}
_DfpCombo
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6230-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6230-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6230-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6230-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
Version
2.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6231-1BB0-11D0-81C3-0080C7A2EF7D}
_DfpComboEvents
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6231-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6231-1BB0-11D0-81C3-0080C7A2EF7D}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6231-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DDE6231-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
Version
2.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LP.fpListCtrl.1
FarPoint List Control
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LP.fpListCtrl.1\CLSID
{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}
FarPoint List Control
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\ProgID
LP.fpListCtrl.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\InprocServer32
C:\PROGRA~1\NotePage\PAGEGA~1\flp32x20.ocx
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\ToolboxBitmap32
C:\PROGRA~1\NotePage\PAGEGA~1\flp32x20.ocx, 1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\MiscStatus
0
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\MiscStatus\1
131473
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\Control
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\Version
2.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622A-1BB0-11D0-81C3-0080C7A2EF7D}\InprocServer32
ThreadingModel
Apartment
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LP.fpComboCtrl.1
FarPoint Combo Control
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LP.fpComboCtrl.1\CLSID
{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}
FarPoint Combo Control
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\ProgID
LP.fpComboCtrl.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\InprocServer32
C:\PROGRA~1\NotePage\PAGEGA~1\flp32x20.ocx
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\ToolboxBitmap32
C:\PROGRA~1\NotePage\PAGEGA~1\flp32x20.ocx, 2
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\MiscStatus
0
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\MiscStatus\1
131473
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\Control
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\TypeLib
{8DDE6232-1BB0-11D0-81C3-0080C7A2EF7D}
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\Version
2.1
3460
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8DDE622F-1BB0-11D0-81C3-0080C7A2EF7D}\InprocServer32
ThreadingModel
Apartment
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE137165-4EE0-11D5-80FD-525400D9E86C}\7d.0
SGPView4
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE137165-4EE0-11D5-80FD-525400D9E86C}\7d.0\FLAGS
2
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE137165-4EE0-11D5-80FD-525400D9E86C}\7d.0\0\win32
C:\Program Files\NotePage\PageGate Client\sgpview4.ocx
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EE137165-4EE0-11D5-80FD-525400D9E86C}\7d.0\HELPDIR
C:\Program Files\NotePage\PageGate Client
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44DD5CC1-1C6C-4143-988B-8BB1D4F53AAB}
_SGPrint4
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44DD5CC1-1C6C-4143-988B-8BB1D4F53AAB}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44DD5CC1-1C6C-4143-988B-8BB1D4F53AAB}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44DD5CC1-1C6C-4143-988B-8BB1D4F53AAB}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44DD5CC1-1C6C-4143-988B-8BB1D4F53AAB}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21B247A5-D300-4B79-BA74-6AEA4447B33A}
_Defaults
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21B247A5-D300-4B79-BA74-6AEA4447B33A}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21B247A5-D300-4B79-BA74-6AEA4447B33A}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21B247A5-D300-4B79-BA74-6AEA4447B33A}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{21B247A5-D300-4B79-BA74-6AEA4447B33A}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5AE08219-AA7D-43DC-B81C-5116CD3A83B9}
_Designer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5AE08219-AA7D-43DC-B81C-5116CD3A83B9}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5AE08219-AA7D-43DC-B81C-5116CD3A83B9}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5AE08219-AA7D-43DC-B81C-5116CD3A83B9}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5AE08219-AA7D-43DC-B81C-5116CD3A83B9}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{940AFDEE-4C64-4A85-9EB3-2A4EED9F35AB}
_IPAO
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{940AFDEE-4C64-4A85-9EB3-2A4EED9F35AB}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{940AFDEE-4C64-4A85-9EB3-2A4EED9F35AB}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{940AFDEE-4C64-4A85-9EB3-2A4EED9F35AB}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{940AFDEE-4C64-4A85-9EB3-2A4EED9F35AB}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9074D462-5EEB-4522-B555-FE6B8CD9143C}
_ISubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9074D462-5EEB-4522-B555-FE6B8CD9143C}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9074D462-5EEB-4522-B555-FE6B8CD9143C}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9074D462-5EEB-4522-B555-FE6B8CD9143C}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9074D462-5EEB-4522-B555-FE6B8CD9143C}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEF40F6F-08F7-4EFF-946A-2195D87138D5}
_GSubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEF40F6F-08F7-4EFF-946A-2195D87138D5}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEF40F6F-08F7-4EFF-946A-2195D87138D5}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEF40F6F-08F7-4EFF-946A-2195D87138D5}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEF40F6F-08F7-4EFF-946A-2195D87138D5}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEE65ACA-C6E0-4B9C-A4E6-EBA78EA63546}
_CTimer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEE65ACA-C6E0-4B9C-A4E6-EBA78EA63546}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEE65ACA-C6E0-4B9C-A4E6-EBA78EA63546}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEE65ACA-C6E0-4B9C-A4E6-EBA78EA63546}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEE65ACA-C6E0-4B9C-A4E6-EBA78EA63546}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1CFEF9F-BE86-483A-860E-D1A380F6A410}
_PViewDesigner
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1CFEF9F-BE86-483A-860E-D1A380F6A410}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1CFEF9F-BE86-483A-860E-D1A380F6A410}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1CFEF9F-BE86-483A-860E-D1A380F6A410}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C1CFEF9F-BE86-483A-860E-D1A380F6A410}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A8B2BFE-9C9A-4BE4-B2B3-04F109D7AFA9}
__SGPrint4
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A8B2BFE-9C9A-4BE4-B2B3-04F109D7AFA9}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A8B2BFE-9C9A-4BE4-B2B3-04F109D7AFA9}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A8B2BFE-9C9A-4BE4-B2B3-04F109D7AFA9}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A8B2BFE-9C9A-4BE4-B2B3-04F109D7AFA9}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C734CF1E-9A97-45B0-AC11-8525E3632302}
__CTimer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C734CF1E-9A97-45B0-AC11-8525E3632302}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C734CF1E-9A97-45B0-AC11-8525E3632302}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C734CF1E-9A97-45B0-AC11-8525E3632302}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C734CF1E-9A97-45B0-AC11-8525E3632302}\TypeLib
Version
7d.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5DB80FE-BC01-482E-B92C-1401E31001BE}
SGPView4.PViewDesigner
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5DB80FE-BC01-482E-B92C-1401E31001BE}\InprocServer32
C:\Program Files\NotePage\PageGate Client\sgpview4.ocx
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5DB80FE-BC01-482E-B92C-1401E31001BE}\InprocServer32
ThreadingModel
Apartment
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7870C30-0D1D-4EA7-97CB-BE6613223563}
SGPView4.CTimer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7870C30-0D1D-4EA7-97CB-BE6613223563}\ProgID
SGPView4.CTimer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7870C30-0D1D-4EA7-97CB-BE6613223563}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7870C30-0D1D-4EA7-97CB-BE6613223563}\VERSION
125.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.CTimer
SGPView4.CTimer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.CTimer\Clsid
{A7870C30-0D1D-4EA7-97CB-BE6613223563}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEE65ACA-C6E0-4B9C-A4E6-EBA78EA63546}
CTimer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C734CF1E-9A97-45B0-AC11-8525E3632302}
CTimer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F01DAF9B-9ADB-4732-A1BD-0953E87AD094}
SGPView4.GSubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F01DAF9B-9ADB-4732-A1BD-0953E87AD094}\ProgID
SGPView4.GSubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F01DAF9B-9ADB-4732-A1BD-0953E87AD094}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F01DAF9B-9ADB-4732-A1BD-0953E87AD094}\VERSION
125.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.GSubclass
SGPView4.GSubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.GSubclass\Clsid
{F01DAF9B-9ADB-4732-A1BD-0953E87AD094}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FEF40F6F-08F7-4EFF-946A-2195D87138D5}
GSubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9274E314-9F7A-46D7-87FE-DB9A21EE0DD1}
SGPView4.ISubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9274E314-9F7A-46D7-87FE-DB9A21EE0DD1}\ProgID
SGPView4.ISubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9274E314-9F7A-46D7-87FE-DB9A21EE0DD1}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9274E314-9F7A-46D7-87FE-DB9A21EE0DD1}\VERSION
125.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.ISubclass
SGPView4.ISubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.ISubclass\Clsid
{9274E314-9F7A-46D7-87FE-DB9A21EE0DD1}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9074D462-5EEB-4522-B555-FE6B8CD9143C}
ISubclass
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{562569A5-48BF-4A95-9A08-865967FD6E30}
SGPView4.IPAO
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{562569A5-48BF-4A95-9A08-865967FD6E30}\ProgID
SGPView4.IPAO
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{562569A5-48BF-4A95-9A08-865967FD6E30}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{562569A5-48BF-4A95-9A08-865967FD6E30}\VERSION
125.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.IPAO
SGPView4.IPAO
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.IPAO\Clsid
{562569A5-48BF-4A95-9A08-865967FD6E30}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{940AFDEE-4C64-4A85-9EB3-2A4EED9F35AB}
IPAO
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28F0A3B3-FB8A-11D5-8200-525400D9E86C}
SGPView4.Designer
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28F0A3B3-FB8A-11D5-8200-525400D9E86C}\InprocServer32
C:\Program Files\NotePage\PageGate Client\sgpview4.ocx
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{28F0A3B3-FB8A-11D5-8200-525400D9E86C}\InprocServer32
ThreadingModel
Apartment
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE1371D4-4EE0-11D5-80FD-525400D9E86C}
SGPView4.Defaults
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE1371D4-4EE0-11D5-80FD-525400D9E86C}\InprocServer32
C:\Program Files\NotePage\PageGate Client\sgpview4.ocx
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE1371D4-4EE0-11D5-80FD-525400D9E86C}\InprocServer32
ThreadingModel
Apartment
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}
SGPView4.SGPrint4
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\ProgID
SGPView4.SGPrint4
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\InprocServer32
C:\Program Files\NotePage\PageGate Client\sgpview4.ocx
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\InprocServer32
ThreadingModel
Apartment
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\Control
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\ToolboxBitmap32
C:\Program Files\NotePage\PageGate Client\sgpview4.ocx, 30000
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\MiscStatus
0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\MiscStatus\1
131473
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\TypeLib
{EE137165-4EE0-11D5-80FD-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F607ABA-B763-11D5-81A7-525400D9E86C}\VERSION
125.0
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.SGPrint4
SGPView4.SGPrint4
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SGPView4.SGPrint4\Clsid
{4F607ABA-B763-11D5-81A7-525400D9E86C}
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{44DD5CC1-1C6C-4143-988B-8BB1D4F53AAB}
SGPrint4
2848
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1A8B2BFE-9C9A-4BE4-B2B3-04F109D7AFA9}
SGPrint4
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0587CB79-A4F0-11D6-B60A-CA5AACFBD212}\c.1
vbAccelerator Rich Edit Control - Modified by Deb
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0587CB79-A4F0-11D6-B60A-CA5AACFBD212}\c.1\FLAGS
2
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0587CB79-A4F0-11D6-B60A-CA5AACFBD212}\c.1\0\win32
C:\Program Files\NotePage\PageGate Client\vbaledit2.ocx
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0587CB79-A4F0-11D6-B60A-CA5AACFBD212}\c.1\HELPDIR
C:\Program Files\NotePage\PageGate Client
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981703-B3C0-11D6-B60A-AB0ACB20ED77}
_vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981703-B3C0-11D6-B60A-AB0ACB20ED77}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981703-B3C0-11D6-B60A-AB0ACB20ED77}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981703-B3C0-11D6-B60A-AB0ACB20ED77}\TypeLib
{0587CB79-A4F0-11D6-B60A-CA5AACFBD212}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981703-B3C0-11D6-B60A-AB0ACB20ED77}\TypeLib
Version
c.1
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981704-B3C0-11D6-B60A-AB0ACB20ED77}
__vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981704-B3C0-11D6-B60A-AB0ACB20ED77}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981704-B3C0-11D6-B60A-AB0ACB20ED77}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981704-B3C0-11D6-B60A-AB0ACB20ED77}\TypeLib
{0587CB79-A4F0-11D6-B60A-CA5AACFBD212}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981704-B3C0-11D6-B60A-AB0ACB20ED77}\TypeLib
Version
c.1
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}
vbalEdit2.vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\ProgID
vbalEdit2.vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\InprocServer32
C:\Program Files\NotePage\PageGate Client\vbaledit2.ocx
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\InprocServer32
ThreadingModel
Apartment
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\Control
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\ToolboxBitmap32
C:\Program Files\NotePage\PageGate Client\vbaledit2.ocx, 30000
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\MiscStatus
0
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\MiscStatus\1
131473
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\TypeLib
{0587CB79-A4F0-11D6-B60A-CA5AACFBD212}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}\VERSION
12.1
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\vbalEdit2.vbalRichEdit
vbalEdit2.vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\vbalEdit2.vbalRichEdit\Clsid
{50C8A4D8-A6F6-11D6-B60A-CD3FCDE1CB12}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02D-A71E-11D6-B60A-B2A4BE4F9112}
vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02D-A71E-11D6-B60A-B2A4BE4F9112}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02D-A71E-11D6-B60A-B2A4BE4F9112}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02D-A71E-11D6-B60A-B2A4BE4F9112}\Forward
{03981703-B3C0-11D6-B60A-AB0ACB20ED77}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981703-B3C0-11D6-B60A-AB0ACB20ED77}
vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02E-A71E-11D6-B60A-B2A4BE4F9112}
vbalRichEdit
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02E-A71E-11D6-B60A-B2A4BE4F9112}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02E-A71E-11D6-B60A-B2A4BE4F9112}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D65A02E-A71E-11D6-B60A-B2A4BE4F9112}\Forward
{03981704-B3C0-11D6-B60A-AB0ACB20ED77}
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{03981704-B3C0-11D6-B60A-AB0ACB20ED77}
vbalRichEdit
2316
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
2316
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
2316
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}
2316
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}
2316
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}
2316
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
Microsoft Common Dialog Control, version 6.0
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32
C:\Windows\system32\comdlg32.ocx
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\InprocServer32
ThreadingModel
Apartment
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComDlg.CommonDialog
Microsoft Common Dialog Control, version 6.0
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComDlg.CommonDialog\CLSID
{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComDlg.CommonDialog\CurVer
MSComDlg.CommonDialog.1
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComDlg.CommonDialog.1
Microsoft Common Dialog Control, version 6.0
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComDlg.CommonDialog.1\CLSID
{F9043C85-F6F2-101A-A3C9-08002B2F49FB}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\VersionIndependentProgID
MSComDlg.CommonDialog
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\ProgID
MSComDlg.CommonDialog.1
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\TypeLib
{F9043C88-F6F2-101A-A3C9-08002B2F49FB}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\Version
1.2
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\MiscStatus
0
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\MiscStatus\1
132499
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}\ToolboxBitmap32
C:\Windows\system32\comdlg32.ocx, 1
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}
Common Dialog Open Property Page Object
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32
C:\Windows\system32\comdlg32.ocx
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}
Common Dialog Color Property Page Object
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}\InprocServer32
C:\Windows\system32\comdlg32.ocx
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}
Common Dialog Print Property Page Object
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}\InprocServer32
C:\Windows\system32\comdlg32.ocx
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}
Common Dialog Font Property Page Object
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}\InprocServer32
C:\Windows\system32\comdlg32.ocx
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}
Common Dialog Help Property Page Object
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}\InprocServer32
C:\Windows\system32\comdlg32.ocx
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2
Microsoft Common Dialog Control 6.0 (SP3)
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\FLAGS
2
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32
C:\Windows\system32\comdlg32.ocx
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\HELPDIR
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{083039C2-13F4-11D1-8B7E-0000F8754DA1}
ICommonDialog
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{083039C2-13F4-11D1-8B7E-0000F8754DA1}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{083039C2-13F4-11D1-8B7E-0000F8754DA1}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{083039C2-13F4-11D1-8B7E-0000F8754DA1}\TypeLib
{F9043C88-F6F2-101A-A3C9-08002B2F49FB}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{083039C2-13F4-11D1-8B7E-0000F8754DA1}\TypeLib
Version
1.2
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9043C87-F6F2-101A-A3C9-08002B2F49FB}
ICommonDialogEvents
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9043C87-F6F2-101A-A3C9-08002B2F49FB}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9043C87-F6F2-101A-A3C9-08002B2F49FB}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9043C87-F6F2-101A-A3C9-08002B2F49FB}\TypeLib
{F9043C88-F6F2-101A-A3C9-08002B2F49FB}
2316
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9043C87-F6F2-101A-A3C9-08002B2F49FB}\TypeLib
Version
1.2
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}
VBPropertyBag
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InProcServer32
C:\Windows\system32\msvbvm60.dll
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InProcServer32
ThreadingModel
Apartment
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A4C466B8-499F-101B-BB78-00AA00383CBB}\TypeLib
Version
6.0
3188
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A4C46780-499F-101B-BB78-00AA00383CBB}\TypeLib
Version
6.0
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000100-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000001-0000-0000-C000-000000000046}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000101-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000102-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000103-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000104-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000105-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{969DC708-5C76-11D1-8D86-0000F804B057}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000109-0000-0000-C000-000000000046}\NumMethods
8
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000000a-0000-0000-C000-000000000046}\NumMethods
10
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000010a-0000-0000-C000-000000000046}\NumMethods
10
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000000b-0000-0000-C000-000000000046}\NumMethods
18
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000010b-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000000c-0000-0000-C000-000000000046}\NumMethods
14
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000010c-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000000d-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000010d-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000000e-0000-0000-C000-000000000046}\NumMethods
13
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000010e-0000-0000-C000-000000000046}\NumMethods
12
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000000f-0000-0000-C000-000000000046}\NumMethods
23
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000010f-0000-0000-C000-000000000046}\NumMethods
8
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000150-0000-0000-C000-000000000046}\NumMethods
13
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000010-0000-0000-C000-000000000046}\NumMethods
10
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{99CAF010-415E-11CF-8814-00AA00B569F5}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000012-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000112-0000-0000-C000-000000000046}\NumMethods
24
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000113-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000114-0000-0000-C000-000000000046}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000115-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000116-0000-0000-C000-000000000046}\NumMethods
15
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000117-0000-0000-C000-000000000046}\NumMethods
10
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000118-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000119-0000-0000-C000-000000000046}\NumMethods
15
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000011a-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000011b-0000-0000-C000-000000000046}\NumMethods
6
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000011c-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000011d-0000-0000-C000-000000000046}\NumMethods
14
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000011E-0000-0000-C000-000000000046}\NumMethods
8
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000022-0000-0000-C000-000000000046}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000122-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000125-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000151-0000-0000-C000-000000000046}\NumMethods
15
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000026-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000126-0000-0000-C000-000000000046}\NumMethods
8
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000127-0000-0000-C000-000000000046}\NumMethods
10
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000128-0000-0000-C000-000000000046}\NumMethods
10
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000129-0000-0000-C000-000000000046}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000012A-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000030-0000-0000-C000-000000000046}\NumMethods
6
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0C733A30-2A1C-11CE-ADE5-00AA0044773D}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000131-0000-0000-C000-000000000046}\NumMethods
6
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{000E0131-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000132-0000-0000-C000-000000000046}\NumMethods
6
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\NumMethods
10
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{000E0134-0000-0000-C000-000000000046}\NumMethods
17
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{8D19C834-8879-11D1-83E9-00C04FC2C6D4}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000135-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000136-0000-0000-C000-000000000046}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000013C-0000-0000-C000-000000000046}\NumMethods
9
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{000B013C-0000-0000-C000-000000000046}\NumMethods
15
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000140-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000141-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000143-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{000E0143-0000-0000-C000-000000000046}\NumMethods
11
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{72380D55-8D2B-43A3-8513-2B6EF31434E9}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000160-0000-0000-C000-000000000046}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{4A8DF970-8D9A-11CF-8827-00AA00B569F5}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{30F3D47A-6447-11D1-8E3C-00C04FB9386D}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B285-BAB4-101A-B69C-00AA00341D07}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}\NumMethods
8
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B287-BAB4-101A-B69C-00AA00341D07}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0E6D4D92-6738-11CF-9608-00AA00680DB4}\NumMethods
6
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{000001A0-0000-0000-C000-000000000046}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{A9D758A0-4617-11CF-95FC-00AA00680DB4}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{BC0BF6AE-8878-11D1-83E9-00C04FC2C6D4}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{F29F6BC0-5021-11CE-AA15-00006901293F}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{DB2F3ACA-2F86-11D1-8E04-00C04FB9989A}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{DB2F3ACB-2F86-11D1-8E04-00C04FB9989A}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{DB2F3ACC-2F86-11D1-8E04-00C04FB9989A}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{DB2F3ACD-2F86-11D1-8E04-00C04FB9989A}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{DB2F3ACE-2F86-11D1-8E04-00C04FB9989A}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{DB2F3ACF-2F86-11D1-8E04-00C04FB9989A}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{DE2EACD0-9C9D-11CF-882A-00AA00B569F5}\NumMethods
5
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{947990DE-CC28-11D2-A0F7-00805F858FB1}\NumMethods
4
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000138-0000-0000-C000-000000000046}\NumMethods
15
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{00000139-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000013A-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{0000013B-0000-0000-C000-000000000046}\NumMethods
7
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{40FC6ED3-2438-11CF-A3DB-080036F12502}
409
Embeddable Objects
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
409
Controls
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
409
Automation Objects
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{40FC6ED8-2438-11CF-A3DB-080036F12502}
409
Document Objects
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{40FC6ED9-2438-11CF-A3DB-080036F12502}
409
_Printable Objects
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{d573b4b1-894e-11d2-b8b6-00c04fb9618a}
ICallIndirect
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{d573b4b0-894e-11d2-b8b6-00c04fb9618a}
ICallFrame
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60c7ca75-896d-11d2-b8b6-00c04fb9618a}
ICallInterceptor
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5333b003-2e42-11d2-b89d-00c04fb9618a}
ICallUnmarshal
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{fd5e0843-fc91-11d0-97d7-00c04fb9618a}
ICallFrameEvents
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{08b23919-392d-11d2-b8a4-00c04fb9618a}
ICallFrameWalker
3248
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{d1fb5a79-7706-11d1-adba-00c04fc2adc0}
IInterfaceRelated
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{1CF2B120-547D-101B-8E65-08002B2BD119}\NumMethods
8
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B283-BAB4-101A-B69C-00AA00341D07}\NumMethods
4
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B284-BAB4-101A-B69C-00AA00341D07}\NumMethods
5
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B285-BAB4-101A-B69C-00AA00341D07}\NumMethods
7
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B286-BAB4-101A-B69C-00AA00341D07}\NumMethods
8
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B287-BAB4-101A-B69C-00AA00341D07}\NumMethods
7
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B288-BAB4-101A-B69C-00AA00341D07}\NumMethods
7
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B289-BAB4-101A-B69C-00AA00341D07}\NumMethods
10
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B28B-BAB4-101A-B69C-00AA00341D07}\NumMethods
4
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B28C-BAB4-101A-B69C-00AA00341D07}\NumMethods
7
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B28D-BAB4-101A-B69C-00AA00341D07}\NumMethods
14
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{B196B28F-BAB4-101A-B69C-00AA00341D07}\NumMethods
8
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF24292-0C96-11CE-A0CF-00AA00600AB8}\ProxyStubClsid32
{B196B286-BAB4-101A-B69C-00AA00341D07}
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF24292-0C96-11CE-A0CF-00AA00600AB8}
IViewObjectEx
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3AF24292-0C96-11CE-A0CF-00AA00600AB8}\NumMethods
15
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{922EADA0-3424-11CF-B670-00AA004CD6D8}\ProxyStubClsid32
{B196B286-BAB4-101A-B69C-00AA00341D07}
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{922EADA0-3424-11CF-B670-00AA004CD6D8}
IOleInPlaceSiteWindowless
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{922EADA0-3424-11CF-B670-00AA004CD6D8}\NumMethods
30
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C2056CC-5EF4-101B-8BC8-00AA003E3B29}\ProxyStubClsid32
{B196B286-BAB4-101A-B69C-00AA00341D07}
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C2056CC-5EF4-101B-8BC8-00AA003E3B29}
IOleInPlaceObjectWindowless
2060
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1C2056CC-5EF4-101B-8BC8-00AA003E3B29}\NumMethods
11
4088
pgc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NotePage
Test
Test

Files activity

Executable files
115
Suspicious files
26
Text files
227
Unknown types
17

Dropped files

PID
Process
Filename
Type
2568
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 799817.crdownload
executable
MD5: 01e5c7d53db3cacfc563022b37bea411
SHA256: 80687060f3d29fc6632edd00e467fa86af076ef9e1c24fd72b829e155a1b46e3
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\psapi.dll
executable
MD5: abbc53dbdb01df277a7dd8f86da1c168
SHA256: 35261e40e0fc8229978cab1efcfd2607ae712c40ecff11430df5a78bb2a87795
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial2.exe
executable
MD5: 953d9bc0d5f096ebb93cf63e26d745db
SHA256: 2ae07be9af213a5bb678ff868545d3b38b56cc6aa063cf1338a67913a18f4b18
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\mswstr10.dll
executable
MD5: 1449dcba2a54484295cbeb3db4c11fda
SHA256: a097f6958ce39fcdd1dacdda248f120adee9e8d43ce83f8193820cf148ccc3b6
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial3.exe
executable
MD5: 96a63271013b3feb86e8e963792e16ef
SHA256: 6d9df81c39d985925cbf37566e0122610a440c5ca5859c9fa57b5dff354bedad
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\oleaut32.dll
executable
MD5: 0d303488cce054204c323c37657afa34
SHA256: b34a300b2dd2b8a2946a451549202e8f9705aa38c19a4e2d73ab684cd93736c0
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial14.exe
executable
MD5: a7cced85990d1640f29336904595506c
SHA256: 9aacb61fe4ee8de2b7775e28a075d459f526970aa2ce10a4240888815aa5401f
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\ole32.dll
executable
MD5: 81a267f80035cb3a7559be4179700931
SHA256: f1adecae0786c7bb7a320f9a42066a3e81d45395423308bda050c94e44bf48ba
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial13.exe
executable
MD5: f82ca1be31faaea671a144c84adfb2e1
SHA256: 1d46f41b12b04d15c6188f4bad7543339aee78c5abae4d6d34802def72e91457
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\wodXMPP.dll
executable
MD5: 2208f8cedcad7d5d3f21aeea55dcb22e
SHA256: a178e122e7c0a0f15527ab4901965042706adc1dc87aaa1f2d66655169c2e7d7
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\scrrun.dll
executable
MD5: fd74a10a46d7cd095376930bd99edcb4
SHA256: ac6dc3ecc8a51ef7d3b309f00dabbce9f62fe4b38bc55494f78db852e4459acf
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial11.exe
executable
MD5: f7920b4fd22ef2aec7c3c38faae27930
SHA256: a2894200b8f13053c34e34e111aa9e459b179bddcd9fe7f8059b9b953fe1f42f
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial16.exe
executable
MD5: 29029a1725ac95aeab81b7356b41908b
SHA256: bd8875112b1716dd133fcc4ed23927ed00657e07b313fa77a46323a47fe9dec1
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\comdlg32.ocx
executable
MD5: b73809a916e6d7c1ae56f182a2e8f7e2
SHA256: 64c6ee999562961d11af130254ad3ffd24bb725d3c18e7877f9fd362f4936195
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\olepro32.dll
executable
MD5: 6568cb4adca8e02088b4b5f37f9e938e
SHA256: 83338b40afdb275cc1fb20dccb1da096e03f7f718346ee22e75d864f44872d30
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial10.exe
executable
MD5: 9e8a64071056eb2a5d7ce345a1e60399
SHA256: 13a3bd3ba95b207375c04581c51cf302bf3f49b5ca363952bcafbff82522a36c
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial4.exe
executable
MD5: 631505f895180efcbe4ba998b8313634
SHA256: 29fda60adafc37c7fd0bd5fe1e0ef9671ab64653f7d8ac3866c99377038aa2f5
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\vbajet32.dll
executable
MD5: 816da5b4f98779a89f07ea9631e787a5
SHA256: cc2f451c7335ef89e9c0c8083eea382573d494799424d0319350a54d5ea8f44a
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\psvince.dll
executable
MD5: a4e5c512b047a6d9dc38549161cac4de
SHA256: c7f1e7e866834d9024f97c2b145c09d106e447e8abd65a10a1732116d178e44e
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial12.exe
executable
MD5: 5f5d13331c7c2d9a19b51fe26a396cbc
SHA256: e1d66e27b9ea8afe35a87efd39450ae97e6487a3a9ef99989faf4d2a58c939f4
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial5.exe
executable
MD5: dce9f6f913d22bd8c94e73216b480023
SHA256: f865fc3c515522abd5d8805c9be968776bbed858fe1ef17ab3f499511a8fd4e5
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\vb5db.dll
executable
MD5: 4c6f2d2ce86330335801f2982b26223e
SHA256: d7cf39e673a87fac5d5abaf81c572d422675b9f0fbe18d4eb4e7c20f3d3038cd
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\npmxr.dll
executable
MD5: 844cdeffc68b0a2e9bc886affe8c2d7d
SHA256: 24fe387fa04049bbbd703a8e761ad5e98377e335aafaa656fa265d3f001d6fff
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgcsetup.exe
executable
MD5: 78d733ec181dc0d800cc445ffd3448a8
SHA256: efd383ab9ec09ddc199110d6ff37a1583a0d0ebd45bd795e75ef7a01c6ed5f2a
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial6.exe
executable
MD5: 13e5d672802b3b591cfd44902948a43b
SHA256: b980cc4b6bcbbab2d360e1dac7168e7da7da25bf342a80a2c67fad7c837b2373
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\svcomsvc.dll
executable
MD5: 55ee14db8eb57ad5cfeef7c7c711a5b4
SHA256: b076e0ad698ecc0ce316a567b865023b4197f7ac6618b68a5c7775ccd52da687
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\msvcrt40.dll
executable
MD5: 37b3c7afd09cf8dd315c506565d776cb
SHA256: 9bcd0fe2c80a07c33eda7ff67bbb2f7b70f65de6ae5f458e6a6b9411ac5d91a2
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial1.exe
executable
MD5: 77955d69e3bdc862f43043f7f5b558ea
SHA256: ec4c99e8ac3ae981eb0aebda90a0c8c7464b83066e2dba44a5fe4178e12ea863
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial7.exe
executable
MD5: 1f5b471c3455b8120d2b23edf29532ea
SHA256: 44091029cfa38d2aefca5f4833df89f2dd4402159cad1d418d476ad84a43b5a9
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\XZip.dll
executable
MD5: 5c72ca3901d7d7e716ae45a0be8ffa1e
SHA256: 9db67ab66bb18ecf02c346e363ceb492e116a4a8f20e1abd47cc0a28dc784de6
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\msvbvm60.dll
executable
MD5: 351bc7471a9874acacf7d386fa8be227
SHA256: 20cbf8835f6fd3878acacbb7868f7b95a7aae6c2c9d5d0a926337ed31378fa7a
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgasetup.exe
executable
MD5: 60394e89acb2b3bf4380b0d955c47fd3
SHA256: 513a933c62417522e69ce4b0f868cfb6bce9de42086f5163fdb54e20f963f77d
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pggascii.exe
executable
MD5: 5fdb259798ca2a14279e406804f17607
SHA256: 29c6ed581c359a9d606b5a52c395f9f87f9d08efd3a185a5190621dc25072c2d
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\flp32x20.ocx
executable
MD5: a9413e1e3a8d92a3e9d7502246072782
SHA256: f2aee4edf2d98fb3a45b234b55e267820d56a63ff1c78b7c41c27b91912b5fac
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\mswdat10.dll
executable
MD5: 70b3085d07a425b60413bf8d4e1341f0
SHA256: 6cd761605da836ccfda0df9a4246e1a6cec5bcd5776f87feab1322777d6b33c1
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgc.exe
executable
MD5: cb66c4819ebe7c56a063bc1c793f27dc
SHA256: 9d0b119cc4965aeb98e471641a4c9e1102eb807fad67aff877964d87e23e666e
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial8.exe
executable
MD5: cc6e63928591a0d884cfddf122bd0d9d
SHA256: ef0530008c000c601461d9c054aa299fa57ea7f929dc6d7ec804e1574cfc6fa4
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\httpx.ocx
executable
MD5: 6461ecc3d76df9aff45cf1d6a0e5da63
SHA256: 271cb9328099553d70c419b7ad285c63fed756fa34fa74815b445f409e62a333
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\msrepl40.dll
executable
MD5: da277b1eb27e2938c254e178ae9dae33
SHA256: 9a17af13e1dcac39c3ee2f7a309dc8b9381fb6ce9d29f6552733a4de16f357cd
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgadmin.exe
executable
MD5: 327e2655404572c0e87d7d0016cb7440
SHA256: 5bee3914f7c4be49a0c8f355b13d5161c979169175e30e4a4c7661e063bcf786
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pgdial9.exe
executable
MD5: cb716fb01bbe5f8503ba125f663fb1be
SHA256: 65a1811803c49534e4ae88f7c78f45d082a2a8da5d096c1d469d6a12a4c61006
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\mscomm32.ocx
executable
MD5: 2c6119da3993f410e74b15112f840cb0
SHA256: 51a1d6812e445c26c71465e2709e6d1ad587f8513002d662cd160f424f48b37c
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\msvcrt.dll
executable
MD5: 4300d1a092b91e7c8dfa6f1e5e7973b2
SHA256: 887eb5ce93edb7192ca3e9220f07f9ca0f94db02af5862ebcbdfcb852db99fd1
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\jetcomp.exe
executable
MD5: cf0b15ab9fe311d3edd0228682d1da29
SHA256: 6f3edd5c980f9000613fb3cf44c763764498fa817f10c1227dee3b8bee490bb3
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pggtap.exe
executable
MD5: 8685b1812b08e6c17e1761e4c13a1623
SHA256: 328895d846aaedecea02228ecbd7ff3b7a0f8f05b7b7828b029e1601b55a7ede
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\msinet.ocx
executable
MD5: 40d81470a19269d88bf44e766be7f84a
SHA256: dd1215f01b484e7842763302d42749d516963d9ac74e2fe8825a5eaba34f6229
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\msjint40.dll
executable
MD5: 5c6bb0204054c094aedfc8a6baec6945
SHA256: ad3d0dc42ff68ddc53d201cf8225feb458db656ee21788ed6c68490d00fd748f
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pagegate.exe
executable
MD5: 811494228ddeabc24f1b61136f06e5b4
SHA256: db854b25353dcadf3c3baba940c0b216f2ee32c810af5a20e10791229d41b86f
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\pggweb.exe
executable
MD5: 3078f805f25826ff37f9d9869345f2b6
SHA256: e7c71b37d8ecb4d4bf9117285b4ae8347b756d9fcf19822a19dcbf2d954c0f47
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\mscomctl.ocx
executable
MD5: d268668751ee22997d7ef1417034cb04
SHA256: fac6736251d3c61ecbd63be0420d1c75d5cd0442181d479013330155ca37d358
2784
pgsetup.exe
C:\Users\admin\AppData\Local\Temp\PGSetup\msjtes40.dll
executable
MD5: 21687b87e07385e627dae4392a6471cc
SHA256: 4c0de9fa0c0ee5ee339d00935f07bd0896b3c266941db3f044c557dddf149a01
2784