General Info

URL

https://rammichael.com/wp-content/uploads/downloads/2019/06/7tt_setup.exe

Full analysis
https://app.any.run/tasks/1242edc2-62fa-4324-bfef-3583933bb323
Verdict
Malicious activity
Analysis date
8/13/2019, 23:27:59
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Connects to CnC server
  • 7+ Taskbar Tweaker.exe (PID: 2816)
Loads dropped or rewritten executable
  • 7tt_setup.exe (PID: 2232)
  • explorer.exe (PID: 128)
Runs injected code in another process
  • 7+ Taskbar Tweaker.exe (PID: 2816)
Application was dropped or rewritten from another process
  • 7+ Taskbar Tweaker.exe (PID: 2816)
  • 7tt_setup.exe (PID: 2232)
Changes the autorun value in the registry
  • 7tt_setup.exe (PID: 2232)
Application was injected by another process
  • explorer.exe (PID: 128)
Executable content was dropped or overwritten
  • 7tt_setup.exe (PID: 2232)
  • chrome.exe (PID: 2436)
  • chrome.exe (PID: 2176)
Creates files in the user directory
  • 7+ Taskbar Tweaker.exe (PID: 2816)
  • 7tt_setup.exe (PID: 2232)
Creates a software uninstall entry
  • 7tt_setup.exe (PID: 2232)
Manual execution by user
  • 7+ Taskbar Tweaker.exe (PID: 2816)
Reads Internet Cache Settings
  • chrome.exe (PID: 2176)
Application launched itself
  • chrome.exe (PID: 2176)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
47
Monitored processes
14
Malicious processes
4
Suspicious processes
0

Behavior graph

+
drop and start start inject chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs 7tt_setup.exe chrome.exe no specs 7+ taskbar tweaker.exe explorer.exe chrome.exe no specs chrome.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
128
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\msutb.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\mpr.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\naturallanguage6.dll
c:\windows\system32\nlsdata0009.dll
c:\windows\system32\nlslexicons0009.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\van.dll
c:\windows\system32\rasmm.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\wwanmm.dll
c:\windows\system32\wlanmm.dll
c:\windows\system32\wlanhlp.dll
c:\windows\system32\onex.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\eappcfg.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\rasdlg.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\netcfgx.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\comsvcs.dll
c:\windows\system32\shacct.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\twext.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\ehstorapi.dll
c:\program files\windows sidebar\sbdrop.dll
c:\program files\google\chrome\application\chrome.exe
c:\users\admin\downloads\7tt_setup.exe
c:\users\admin\appdata\roaming\7+ taskbar tweaker\7+ taskbar tweaker.exe
c:\users\admin\appdata\roaming\7+ taskbar tweaker\inject.dll

PID
2176
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rammichael.com/wp-content/uploads/downloads/2019/06/7tt_setup.exe"
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\wpc.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\samlib.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\rasadhlp.dll
c:\users\admin\downloads\7tt_setup.exe
c:\windows\system32\wbem\wmiperfinst.dll
c:\windows\system32\pdh.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\windows\system32\audioses.dll

PID
3076
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x70fea9d0,0x70fea9e0,0x70fea9ec
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
2184
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=4056 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_watcher.dll

PID
1128
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=10618810543064553895 --mojo-platform-channel-handle=1004 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\windows\system32\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\75.0.3770.100\swiftshader\libegl.dll

PID
2436
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=16890795938517776266 --mojo-platform-channel-handle=1496 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll

PID
3768
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5443410142108995286 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2212 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3220
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1925357730475801754 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2224 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2884
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11595956222218328965 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2328 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2232
CMD
"C:\Users\admin\Downloads\7tt_setup.exe"
Path
C:\Users\admin\Downloads\7tt_setup.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
RaMMicHaeL
Description
7+ Taskbar Tweaker
Version
5.7
Modules
Image
c:\users\admin\downloads\7tt_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\nse1766.tmp\system.dll
c:\users\admin\appdata\local\temp\nse1766.tmp\stdutils.dll
c:\users\admin\appdata\local\temp\nse1766.tmp\langdll.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\users\admin\appdata\roaming\7+ taskbar tweaker\uninstall.exe
c:\users\admin\appdata\roaming\7+ taskbar tweaker\7+ taskbar tweaker.exe
c:\users\admin\appdata\local\temp\nse1766.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\netutils.dll

PID
2544
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=13107799399838191293 --mojo-platform-channel-handle=3728 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
2816
CMD
"C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe"
Path
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
RaMMicHaeL
Description
7+ Taskbar Tweaker
Version
5.7
Modules
Image
c:\users\admin\appdata\roaming\7+ taskbar tweaker\7+ taskbar tweaker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll

PID
1996
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=5359700975823473596 --mojo-platform-channel-handle=1276 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\twext.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\msi.dll
c:\windows\system32\wer.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netutils.dll

PID
2672
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,7542531819750187282,2747733045872467602,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=6726457389240254206 --mojo-platform-channel-handle=488 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google LLC
Description
Google Chrome
Version
75.0.3770.100
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

Registry activity

Total events
2224
Read events
2084
Write events
138
Delete events
2

Modification events

PID
Process
Operation
Key
Name
Value
128
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
000000000000000001000000BA370000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000250000008FBA0C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
00000000000000000100000059420000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000250000002EC50C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
00000000000000000200000059420000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000260000002EC50C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
00000000000000000200000080460000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C0000002600000055C90C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qbjaybnqf\7gg_frghc.rkr
0000000000000000000000003D080000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C0000002600000092D10C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
00000000000000000300000080460000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C0000002700000092D10C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
0000000000000000030000009F460000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C00000027000000B1D10C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7+ Taskbar Tweaker\7+ Taskbar Tweaker.lnk
1
128
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qbjaybnqf\7gg_frghc.rkr
000000000000000000000000BB560000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000270000002F200D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
0000000000000000040000009F460000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000280000002F200D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
drag_towards_desktop
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
nocheck_minimize
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
nocheck_maximize
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
nocheck_close
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
pinned_ungrouped_animate_launch
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
sndvol_tooltip
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
tray_clock_fix_width
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
fix_hang_reposition
1
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
w7_tasklist_htclient
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
always_show_thumb_labels
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
scroll_reverse_cycle
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
scroll_reverse_minimize
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
multipage_wheel_scroll
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
show_desktop_button_size
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
tray_icons_padding
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
no_width_limit
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
w7_show_desktop_classic_corner
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
list_reverse_order
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
disable_topmost
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
multirow_equal_width
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
scroll_maximize_restore
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
always_show_tooltip
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
disable_taskbar_transparency
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
no_start_btn_spacing
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
right_drag_toggle_labels
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
show_desktop_on_hover
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
disable_items_drag
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
disable_tray_icons_drag
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
w10_large_icons
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
cycle_same_virtual_desktop
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
virtual_desktop_order_fix
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
scroll_no_wrap
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
show_labels
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker\OptionsEx
sndvol_classic
0
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Puebzr
0000000000000000040000006A470000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C00000028000000FA200D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
2176
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
2176
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13210205296114000
2176
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307080002000D0015001C001600C50100000000
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307080002000D0015001C001600C90100000000
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\PTimes
C
79AA8A3A1E52D501
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C1
1C1GCEA_enUA812UA812
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C2
1C2GCEA_enUA812
2176
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C7
1C7GCEA_enUA812
2184
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2176-13210205294864000
259
2436
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker
install_dir
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker
language
1033
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
DisplayName
7+ Taskbar Tweaker v5.7
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
UninstallString
"C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\uninstall.exe"
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
InstallLocation
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
Publisher
RaMMicHaeL
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
DisplayIcon
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
DisplayVersion
5.7
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
URLInfoAbout
http://rammichael.com/
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
NoModify
1
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\7 Taskbar Tweaker
NoRepair
1
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
7 Taskbar Tweaker
"C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe" -hidewnd
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker
MementoSectionUsed
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker
MementoSection_StartMenuLnk
1
2232
7tt_setup.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker
MementoSection_DesktopLnk
0
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASAPI32
EnableFileTracing
0
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASAPI32
EnableConsoleTracing
0
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASAPI32
FileTracingMask
4294901760
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASAPI32
ConsoleTracingMask
4294901760
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASAPI32
MaxFileSize
1048576
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASAPI32
FileDirectory
%windir%\tracing
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASMANCS
EnableFileTracing
0
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASMANCS
EnableConsoleTracing
0
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASMANCS
FileTracingMask
4294901760
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASMANCS
ConsoleTracingMask
4294901760
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASMANCS
MaxFileSize
1048576
2816
7+ Taskbar Tweaker.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\7+ Taskbar Tweaker_RASMANCS
FileDirectory
%windir%\tracing
2816
7+ Taskbar Tweaker.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2816
7+ Taskbar Tweaker.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000093000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2816
7+ Taskbar Tweaker.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2816
7+ Taskbar Tweaker.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2816
7+ Taskbar Tweaker.exe
write
HKEY_CURRENT_USER\Software\7 Taskbar Tweaker
updchecktime
61514812
1996
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US

Files activity

Executable files
12
Suspicious files
11
Text files
169
Unknown types
12

Dropped files

PID
Process
Filename
Type
2176
chrome.exe
C:\Users\admin\Downloads\3effccfb-8590-4a30-9b44-75e61377ec27.tmp
executable
MD5: 90f6758e4be87ee76744b59a70aba4fb
SHA256: 9c14957500fba0374a30a11986640fd800b40e6305cb7e6e8cd8bdbba9c30794
2232
7tt_setup.exe
C:\Users\admin\AppData\Local\Temp\nse1766.tmp\LangDLL.dll
executable
MD5: f1e9eed02db3a822a7ddef0c724e5f1f
SHA256: 6dff504c6759c418c6635c9b25b8c91d0d9ef7787a3a93610d7670bb563c09df
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\uninstall.exe
executable
MD5: b0a8906bbc19c9fd4773d5abc29c8f88
SHA256: b2b3e0206c1d17851eb4f187d637f29d8391b7e071d008893aec57407b22e397
2232
7tt_setup.exe
C:\Users\admin\AppData\Local\Temp\nse1766.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
2176
chrome.exe
C:\Users\admin\Downloads\7tt_setup.exe
executable
MD5: b39827f62c62798b1916d97bc6dc2a44
SHA256: e0759eed51d2d1b801bd2fa4a7bd47e163f88e425ac1aec467c5c0ef6668323d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\7+ Taskbar Tweaker.exe
executable
MD5: 395b42c06304cf0ec2687b5212b51d44
SHA256: ca4ba725248ee83ad0f863ed142af48bc879aa49f739ee45e5914bed1eaa3f7a
2436
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000001
executable
MD5: b39827f62c62798b1916d97bc6dc2a44
SHA256: e0759eed51d2d1b801bd2fa4a7bd47e163f88e425ac1aec467c5c0ef6668323d
2176
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 530305.crdownload
executable
MD5: 4da6ddef4dcdeb43f10b8a77514023e9
SHA256: 731449cedd01056b6b3255e9f955d09b1ae28f000ce4fd346efaf0960e2047b7
2232
7tt_setup.exe
C:\Users\admin\AppData\Local\Temp\nse1766.tmp\nsDialogs.dll
executable
MD5: 42b064366f780c1f298fa3cb3aeae260
SHA256: c13104552b8b553159f50f6e2ca45114493397a6fa4bf2cbb960c4a2bbd349ab
2232
7tt_setup.exe
C:\Users\admin\AppData\Local\Temp\nse1766.tmp\StdUtils.dll
executable
MD5: 9da8c0d0d94eb7ec4428e3135e2c91fa
SHA256: d94deb73938b716c37898cd2b31a019fdcfe5ddb63d0dbadcf0145bd0fc1a95a
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\inject.dll
executable
MD5: cc34dca5dfacae7b179d8b0f03899140
SHA256: 4e2b1c0b36fb528f8fa6319866ef36ecef75402bdb4f83bb6f59cefec5245b3d
2176
chrome.exe
C:\Users\admin\Downloads\Unconfirmed 530305.crdownload
executable
MD5: b39827f62c62798b1916d97bc6dc2a44
SHA256: e0759eed51d2d1b801bd2fa4a7bd47e163f88e425ac1aec467c5c0ef6668323d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-3-3_2-1.png
image
MD5: 85561bfadfc48441373f5199f124ec06
SHA256: ca8bc071f5dd6487e59496e6a9786abbcf4497984b19e94c9d56cd415063de63
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF37ac90.TMP
text
MD5: 62ead691ebc81279cd672bf4641c80e1
SHA256: d6d6238bc7f60c73e99718571246125a800c1fe487d7d39e746d595ebc260de2
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\650273f2-3218-4eb8-a6e0-626e3dbf16ae.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF378570.TMP
text
MD5: 585457e96fe6dcf1fe0e032294f989d3
SHA256: b2aa3da56cbf845e736e36339edd85291a355b305ffd65f84af885f475d9ad10
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 585457e96fe6dcf1fe0e032294f989d3
SHA256: b2aa3da56cbf845e736e36339edd85291a355b305ffd65f84af885f475d9ad10
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\115a805c-3737-44a3-ad43-de402ebb5c70.tmp
––
MD5:  ––
SHA256:  ––
2816
7+ Taskbar Tweaker.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 4ed352b5cf64aa6013a8c5e614e5d31c
SHA256: df077780b740f17067ce7170ffbef67191538b45246ebd7960c0d1e1f02c52c1
2232
7tt_setup.exe
C:\Users\admin\AppData\Local\Temp\nsu1736.tmp
––
MD5:  ––
SHA256:  ––
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7+ Taskbar Tweaker\7+ Taskbar Tweaker.lnk
lnk
MD5: 6a6bbdfa01eec082f2f6a8df3e02ea74
SHA256: 670e07b53c805f953c697bc55397a36ffa8656a4e94940926b3f6aa724c0d2fb
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma
––
MD5:  ––
SHA256:  ––
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7+ Taskbar Tweaker\Uninstall.lnk
lnk
MD5: b6e67d0469ea81a3e609d1e9bb8da419
SHA256: 904aec52c90dc8de66a095a482790a1201d9fe048b2a76f3740eedafa5375573
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\d41e5088-1459-41b7-a532-340f5dd37b76.tmp
––
MD5:  ––
SHA256:  ––
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\zh-CN\2-3-3_1-2a.png
image
MD5: f185ec96a538c2a0fb37e90af2d9c830
SHA256: 60ef10a19ffd2fd60b4ba9d92d6b7c2fcd6cfdbb15b6e2246799332a85920e6f
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\zh-CN\2-1-0_1a.png
image
MD5: f4baadc9b9628d627831c082dd600a8d
SHA256: ffbaa1d6ff9ded4bd05b974474cf4133b774f06f5b639634a6a2f7d42a8a0b63
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\zh-CN\2-2-0_1a.png
image
MD5: 19d7a2fb58d4b45a7581bd3b54043cf5
SHA256: 54e9907fadc152e17b126e9316ac2e2585069ad83e675d2beaa27431c05ce932
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\vi-VN\2-1-0_1d.png
image
MD5: df00085e247423b44128e50ffac88cab
SHA256: a4f676a9db37f794d5a6c1b9b4334b69f650804536e673d9b31e3ba54181a906
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\zh-CN\2-1-0_1d.png
image
MD5: 75249bf9fa10037811a7c3198d4b4b52
SHA256: c378d6179a4d5b0e3b6d4cc292352fb01fcca50adbd3550b74801b214dca9e04
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\zh-CN\2-2-0_1c.png
image
MD5: f6cc5c5d1f3a30d02a693562edfc9726
SHA256: c03925a147a82b026e1651fb8c371bce47ca392d3a8080cbdde3fff3507f62ec
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\vi-VN\2-2-0_1a.png
image
MD5: eeacc253ec258c7a47f4566d3e160c1b
SHA256: 80f65496432d731dfbdf6a0d3b07ff1f6c0a20b2acc9f9d6239a0f1b28d5d3a8
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\vi-VN\2-2-0_1c.png
image
MD5: ad3bacde728f6c79342219c880503241
SHA256: de5fe99bbe966a01a09d978311cb4404b294e8a5e7c3d4f33719a07460226f0f
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\vi-VN\2-3-3_1-2a.png
image
MD5: a026329523a960c7874620b5b99161c3
SHA256: 69af8f64f74083bc6eeae7bbd194a6aa54658c0936deb902d0806fcf028254be
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\vi-VN\2-3-2_1a.png
image
MD5: e4d9337643f068c56b50bf0106e20dad
SHA256: 5f68332951149cb37d52afb4cb3f6afc766de6c39d4f6a886f16dc9a199fcb44
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\zh-CN\2-3-2_1a.png
image
MD5: 645789e4c0994f2dff2a88995a310d40
SHA256: 700599d5105e57fc1c86999e4110de3637eabc6212a1c90b2b889d86cc746d49
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\tr-TR\2-2-0_1c.png
image
MD5: 8a2960af1e5ef405e2cc2f773f429583
SHA256: 310dedaf8c121471ddea1144e9b745f9f64fe56959f21bc3ae4a8a3e84514610
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\pl-PL\2-3-3_1-2a.png
image
MD5: ec4f1100b5a15b8b90cfc8249cfbe229
SHA256: bf09c8e761d3740c828082814b95b37e40cf27ffbc8f41a58d9ac9392ede187b
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\tr-TR\2-1-0_1a.png
image
MD5: 0fef2ca4a3c5a0fa01677b1753b1701c
SHA256: 4f2f784b8682bdd02774a990f1f0c5f801d6177076e35f87b3b975f2ecefc0a6
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\tr-TR\2-3-2_1a.png
image
MD5: 1239923f759e03877b4df0f7cce5af09
SHA256: 6edcd1fcf546a2c68bbe8968bbc99e7fb1d0bdba72e6d2978164ac87e64a2373
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\tr-TR\2-1-0_1d.png
image
MD5: 33f6b6ae037ca18d2a248610d6e2e074
SHA256: cefba86a1040278d4ed10cba14d29b9f7fbec81e25f580d61d08d09628fea791
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\vi-VN\2-1-0_1a.png
image
MD5: a2c375aa373a960232c65d6675d9a1cd
SHA256: 53f9e9a26269a3f2d6e314a2e17d498b72d42150a1b092d5df175b50a4abe8d6
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\tr-TR\2-3-3_1-2a.png
image
MD5: 6a6b7c45ff7ccb36d0dd4d1fd6371ec6
SHA256: 96eb701543f82984a05de19aa08e6794d616ac2f40c8bc9b6ea9ec067d06f44b
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\tr-TR\2-2-0_1a.png
image
MD5: f298ad820e1f93ae1bd75785f10a7eb7
SHA256: c9664c217ed855e9e024e0f97bc50fec74cce1403d11d2eec34be7253921b0b2
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\pl-PL\2-2-0_1c.png
image
MD5: 7f0d54351ea551a91972485e4e6f98df
SHA256: 26612ef52f5cbf1338cbad91d4b3c541b838317b5e33d333cef22612f984ba3b
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\pl-PL\2-2-0_1a.png
image
MD5: be5f0921e16d13caef1b2f5b7aa3ca0e
SHA256: 7d443ecb333d1891e1e9c5a0e8ceaa6bd568514477fca96adb76a63fe475b415
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\pl-PL\2-3-2_1a.png
image
MD5: c0761f38d3c0f0987c69fa0260c13bfb
SHA256: 1647f7de8ff725331b4c66ffd414e7765246230255c7b68df7029083f1b40a6a
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\pl-PL\2-1-0_1d.png
image
MD5: 23cdf2b4d29b65f1c0e8765a8c003a1d
SHA256: fd46f63b6bc9624c8ec2e291c6bcae2bcf2c7668a3f87788ebedab074b987fdf
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\nl-NL\2-3-3_1-2a.png
image
MD5: 025d42c01a6f3d43e5e1fd4b33a24b2b
SHA256: 77c4ca6236967ccf0b015bf0b128cbfd18673d3bd8b6bf67adab1d7ad1e0d8c8
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\pl-PL\2-1-0_1a.png
image
MD5: 98907bc4a8a88e1e8a7be0c979f747f0
SHA256: c7f19ea904e66138e180c65893a15257165ee8d3a7fb41b7b119d1f7c32836db
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\nl-NL\2-3-2_1a.png
image
MD5: fe6caa61f18dff1ab069eb32c34a8687
SHA256: 155a05bf8f9ff3eec45e95f7fe5599dffc4869e3d40d1bb07dc2e815789d16d7
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fr-FR\2-3-3_1-2a.png
image
MD5: f15cd82149351e4a57c9d835819d5d0d
SHA256: 86971ec4455a59f22f78a356a6a7122c94cc608799c7579725f03232c60ee86b
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fr-FR\2-2-0_1c.png
image
MD5: d51dcad06893063cd9cd7a95aa9d9f09
SHA256: 90ca9cf9cba8fb6a298ceedbe55fabdebb1e9deaf28a825156dfb98e493ae876
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\nl-NL\2-2-0_1a.png
image
MD5: b6b386a546bb115be4e78e76fa036685
SHA256: 0e91f5eaa4a4e1409e6785b6f4deac3987dfb7fc3551a0ea5e5a64472920cd20
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fr-FR\2-3-2_1a.png
image
MD5: 4a71bacb7c59b20762474bb41de64a1b
SHA256: 6e60502c1c351fc633c3f830572f1578c91b97e28330086664aa97476b94ee0f
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\nl-NL\2-1-0_1a.png
image
MD5: e50fb1cc981eb6d9b365372e5aed4a43
SHA256: f296ec278252d6244b1b2b162fc1489d31fa481842cbcd587ea0af1db0b215dd
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fr-FR\2-1-0_1d.png
image
MD5: 5172078b8701802b0beb6b6daa7993d8
SHA256: c085de45dbce7b2ff63ddc188feed3b384f268fd337acd3b9970bfdaef2831b6
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\nl-NL\2-1-0_1d.png
image
MD5: b8c0695165f3d73e2b67ace647f00880
SHA256: c7533f493c355e87442966b422259baea2bc0bf0aae556dbee225c2f733b8fec
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\nl-NL\2-2-0_1c.png
image
MD5: 6b3217ee2a57548253323331f33c6819
SHA256: 6ed9a1b1dfc7f1712b71e89e7723349399d4af6a6cf62162e324de3840b7ecb9
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fr-FR\2-1-0_1a.png
image
MD5: ab2823625aa7d111d2c15ef54128119d
SHA256: c20987a9b086c25e5f63d6f4f6a6dfb8acc1dcf31eff41373c3cc6b7f5a6cd15
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fr-FR\2-2-0_1a.png
image
MD5: 42b3b4a8129da4147b86cd749c8ac393
SHA256: 3497088a52ea2a913d34851dfe3c9576e331253b662d21005f7cb5ead046082d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fi-FI\2-2-0_1a.png
image
MD5: dd3763b01c1e686ac7d51c6311af4d36
SHA256: cdabde357ea1145ff3e9ed3577385e1aecec759b49a16569931a324eea08b6f9
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fi-FI\2-2-0_1c.png
image
MD5: 73a2504c54bdbda3e9c96a26f6b06aa3
SHA256: 476efb909e3fa040bfbacd422fc13d0302740fe2ec5ef80bbdcf1e56fa72fe36
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\es-VE\2-1-0_1d.png
image
MD5: dbdfca18d5356a99cfdd8ba556214ea1
SHA256: 3406da86ba6fd45ad8e22d61b2001ed871256ba16fa12ec80cbd89c2f9ded28e
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fi-FI\2-1-0_1d.png
image
MD5: faf4945ca3dfdc88f46ea3ee0854d72f
SHA256: 0583f87c61187c5ad32ec500d8353d2b3ced08f01955e92f3af7237a24df8a65
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fi-FI\2-3-2_1a.png
image
MD5: 50e3bc07eb9880959c6428e0da9f9b19
SHA256: c40b2f79729224a417e862757a4919d77eb513e8f67058f87e35ab5a606088da
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\es-VE\2-2-0_1c.png
image
MD5: 6df5046edb759b498840abd5a4a5a973
SHA256: 6f8eee2f97a6a6aa8e8a17b5bfb9d92424df138578cc12b001a2cab94ccc4966
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\es-VE\2-3-2_1a.png
image
MD5: 3bf27e95dde380f5d094f494c065a6bd
SHA256: 0b23548a5c0c233eb7c600bd4c3847dce23ebb55eb615b36de70e32e807f9275
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fi-FI\2-3-3_1-2a.png
image
MD5: 335239f1f917fc1a63a993e90b54111a
SHA256: cfac91224859d9ce93dca45b1d5c96f6dc9bbfcff559b0825e5167d2d41141df
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\fi-FI\2-1-0_1a.png
image
MD5: 2f60b3edf8175809b228380028de18ff
SHA256: caefb1c4f0ab8a7b8fea30642322023e0379bb3b5e524cda446c50c8e3bc69f7
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\es-VE\2-2-0_1a.png
image
MD5: 1d7120c5276390a7ca0a1d715e166c5a
SHA256: 0525b0cdc365ceae61ec82224b014e24dc680ac14a289349c5798205780f1992
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\es-VE\2-3-3_1-2a.png
image
MD5: e2d8110aad7a5e9487784ce51c603fa2
SHA256: ff52f289688c4d65bab6a84b95ec92fb351b41dda379a31dee15ceae0d3e73f0
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\en-US\2-1-0_1a.png
image
MD5: 56e12a0e4a3de2036c6e9a09be8b22e4
SHA256: b49f0933d707c6bcaa319490b57db782a1c1835c7178add1c27808d23fb98550
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\en-US\2-2-0_1a.png
image
MD5: a887e923fb5d2d27468980d0f2116c5c
SHA256: 764f552789b21d7c6c49e6e5d19f956d1e1722f03da6abb90a4f1481833bcb23
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\en-US\2-3-3_1-2a.png
image
MD5: 16432e7dfeffe97fb183ba6bde3c6072
SHA256: 0f6193cdd3406438b6a3d3212e573030cd9ca30fa303b48219dac89d1e73d6d8
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\de-DE\2-3-3_1-2a.png
image
MD5: 62e32f06100bcc7ba45b191b9c95314d
SHA256: c9e3abd64ecf53d8f35206eac424fe642cd5a262f70a95e4acda5ef0dccf1389
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\en-US\2-1-0_1d.png
image
MD5: 099b80219f7454d56120db6d90898657
SHA256: 9240ff2efaf767994938438ed3e8ef6b591a052453a791b5d070ddc29d517cc5
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\en-US\2-2-0_1c.png
image
MD5: 8fe52a47c72b853dcdfef0b72a136a02
SHA256: a2f7580fe0753e2ee0cbd4cda43a9b1bf4eda7d40780903527db80d99a557d17
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\en-US\2-3-2_1a.png
image
MD5: a4e629d887082799d3d787a128f97a65
SHA256: a2e4ad471b4a6982716dd70d4e4c24ee3ab4b106bfdddfc2d2e515e94f4e5140
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\es-VE\2-1-0_1a.png
image
MD5: bb4c7676a17106ce4e4464af206c0235
SHA256: e0ce7838dc80b402babefe7355f27b559ac832199c814e5d430b463701e816bf
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\de-DE\2-1-0_1a.png
image
MD5: e3cae98994cd810715c257a029f32999
SHA256: e11a6370cb46f9c90d8fc85e7867101642640c834d8c7762a23d774ba1126da6
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\de-DE\2-3-2_1a.png
image
MD5: 221289186d377413701cbd7b904dfa53
SHA256: 12810018617f30e872f9ea4ad89aaa539205082d88791b94c3278969b2770208
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\3_1.png
image
MD5: 66140e9ad74d65be0a006fc5e738512c
SHA256: be2fe351c06f0a4a3a9c8c1d92b20886a297fc40feca8ef6eba95f4a5ce4f407
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\de-DE\2-2-0_1a.png
image
MD5: e6ae5ffffeca6fd5b644fd34639860cc
SHA256: 04fcf9b00722ea86eb475b664dc10363a28ef5af19117c76f4df2bba51135f03
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\de-DE\2-1-0_1d.png
image
MD5: 64532d96ca531cc7a7a1cae65f194ba0
SHA256: feaad93bfc70ff29372f08df9f45bf07161712038a0c2b5d5da95947b700d0d0
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\de-DE\2-2-0_1c.png
image
MD5: 8ca2f9ff6759cfa34aea1441290022f4
SHA256: 32be3e75fae4a9ea46b4a0b234f6e0539edf9097559c5dc381f6c31e55d51da2
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\3_2.png
image
MD5: 94096dc82bd4b378d2809fbd0d530205
SHA256: 0e10f52a61829aa94b1ffbee08031ea30520f29f92cbda8d267219355ce95955
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\5-2_4.png
image
MD5: adf9fd82fd247b5a59259170da764e5a
SHA256: 27ae02ceaf7e69716435a48caff5f45a030d14ea7c75445d9dfa310b5aab5de9
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-3-3_2-2.png
image
MD5: b74ce03cdb45a85a1b11c64f13359ef0
SHA256: f2d274f137fdbc524e7f1b13c6f93bddeaea3836c35e35c82244c4694d415cb6
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\4_2-2.png
image
MD5: 649eda49e17f05a98005f1bb814a4859
SHA256: c1f1eec09889a82828ccb636f9dfdc37c73222939530639395c4a8e7e036df50
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\5-3_4.png
image
MD5: 24057cbd69ababa030865da762c870ab
SHA256: afe0156d8f3f457b7ce920aa0eba9d2c0e766fbbefead399e5bdf09ab1704a9f
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-3-3_3-2.png
image
MD5: aea6f76dbc251643f82f70eb2d93d124
SHA256: cbf4d58eba134e28b2f8bfc43fe0bfaf808fb3f00b7d9178a89f7ee75a6d513d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\4_2-1.png
image
MD5: 779e4c75c08813e49d28d134253afe6c
SHA256: c01949c10ce0bd06c8a969b8b4aafd905f61ce803559bc373ba8dca482408d2a
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-3-3_3-1.png
image
MD5: d12d770f770754d47cb66d8607630faa
SHA256: b926eb91cdc7f0afee53ca794632ff51103ef34b89d3ac396205a85e90ca5469
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_2-2.png
image
MD5: c137e93b22017ba4850bf5d0ce85e0db
SHA256: 372ff1a73ed51dc48a8fd6da713f33a1cee93ca2014137e567f4f404a678e5fd
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_1-2.png
image
MD5: 78ddcecee26381db8fa9de1ba9a664a9
SHA256: 5b3aa6df5d3775527a8ba67824ad33026d67cfa778a8134bf44057b470d5e2d1
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_2-1.png
image
MD5: 0b96fe8963bbe32ea8e15c350f828496
SHA256: 86f26d563d0318d8e05e820506c3f1722e5bb1858e8483e4487ee78a8167e640
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-2_0-1.png
image
MD5: 19c2fde2b75caa7c6eb1925fc6b8b1a1
SHA256: 739d68a66a48a6152607a5087ac280addfd786d3893e1a14ff8a3fb5783c88d3
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-3-3_1-2b.png
image
MD5: ab134ae75b27ed527cf2223d55195220
SHA256: 39f954a1a5b6f447a43600bec33f7a0f3577ca5ed2349a795d0bcb469563222b
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-2_0-4.png
image
MD5: e3f5957f37321df269964afbae4f29f2
SHA256: a6d00d68ecc31a2b88b2d78540c98802286f353e28db30063c96c2ee64074ae9
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-3-2_1b.png
image
MD5: 4fc5468731267ac877ed264fbcd015fa
SHA256: 1b845274199ec82889a2828bfb10bd97ff2989af20ac86a8d82e269dfa3ebd1d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_1-3.png
image
MD5: ff6628abeb1a43f69d6f852e1f695039
SHA256: 850dafad641992a020e4f39f00b7d28365942f16f1498211e01ffb3a6181f612
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_2-3.png
image
MD5: 4d91f6efc1e0cc3181db7b6aa565b9da
SHA256: e09be7be89d8cfeb3e7bd3869a2424e437ff9a415e3cd7b38ddb41e5f6629105
3076
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
binary
MD5: b59113c2dcd2d346f31a64f231162ada
SHA256: 1d97c69aea85d3b06787458ea47576b192ce5c5db9940e5eaa514ff977ce2dc2
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-3-3_1-1.png
image
MD5: 41f20605f7b05d2bb681f47f04f46785
SHA256: 5e6990ef03263232f6d0641ed5f8ae4fc080caa02dcdfaba52011aa96924500b
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-2_0-3.png
image
MD5: 42ff3990a3e569e59b8a3e7f304d93d3
SHA256: 1314291560c61a60844e92893274c77edcc630dc4468008ffba41c609dfdc3c1
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-2_0-2.png
image
MD5: 22ad05894c3cd085d87f82ed50fa3d38
SHA256: f02e87783e26fb917005f0fbafc95d13600d2901dc9dcbb86764456be8d3bf63
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_0-1.png
image
MD5: 8e941e33fe569dad90b061df54beea50
SHA256: 443bbcdbb389766057aee28ced49c679e0232f6664dc8648398a6d96d71c71de
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-1_1.png
image
MD5: fb4c09a633efba37526aff10c97309de
SHA256: 8839653546bbb94c3a3ce1bd9ba9c51129c85597488c107786d3cfcd14f63973
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\1-0_1.png
image
MD5: 24a2dc107ee224da959fa6fde1b410be
SHA256: 4b55d02a8bf044d19f2ae99ea34c08afe9ce180d4b1c533c1946aee077610772
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-4_3.png
image
MD5: 7ae109a1c9fc1cbcc2cccd33116e08a0
SHA256: 0e1978f9c28ab987534b25761483ed4eff045c3c12dd53f5272dab7c09c0c64d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-4_1.png
image
MD5: 42b240dd2be6ea958807b58bbdc30253
SHA256: 9c7992d5ced8faa8980d4eb2be91193b26a35d6d5f4a3b5c0c215fd4ddd28a74
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-4_2.png
image
MD5: dc55c0a4e1967346421f12572c489da1
SHA256: fca56b946e33fe24dccf920c9a1373b8dd0bbf810b45a08812c0216402bae1ac
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-0_1b.png
image
MD5: 0e88cbbdc0b8adc2c04043503875cedf
SHA256: 68817d37210a419bb1f02642ec84abb1305cb8de33d482f14fe3e01f1fb4b95b
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-6_1-2.png
image
MD5: a8360b5373e30021383e9d069d353fea
SHA256: cdf4d2cc3c76b9f1275a44a7c2d45751995885909eda4c2b4ce8841bff056915
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-0_1b.png
image
MD5: 7716f92e0707f4478c08ec21cff4135e
SHA256: c4421a884c846938d87fe4174c80bab068f82018978d2a51fd2057d4caff444a
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_0-2.png
image
MD5: 60a7045ad2ecc1b18e4b44122308bf1a
SHA256: ab1ad4adcffe3b0b58c93b205984bf97125e6aee21a9a46284700ce8c6bec1fc
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-2-1_1-1.png
image
MD5: 4a6c4df5c9f9af59f72ad08b9e7d9a72
SHA256: f7301a9e3bf4050f3deb33e990c54d2523ed2e567a76e9bca4d436ac8515fcb9
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-1_2.png
image
MD5: 71f538b7c78cd54a4a706fea9ac915db
SHA256: 6aa6f803032bb488730fd8b3f18415ee3d80d501aa22feb8b84c0a4d7ace1ca0
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-3_2.png
image
MD5: 6be8ca192139a9a9d7c806cfac2b6f7c
SHA256: fc7e6091a5124f01dba17594195817a479262d8add36037d5f92a941fd6e6537
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-3_1.png
image
MD5: 4f56da8db302826720313b3e40d07c80
SHA256: 6e55ca588f7d6e47c88ac97d073ca989a0cdb446fe113e549c5b5d03506d153d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-6_1-1.png
image
MD5: c0d399a2f783a0e7639132cdf877e66c
SHA256: 5bcfdfe7f26d825645a6be18de80ad42edca94756f3a7e7243a56e0819fcec4d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\images\2-1-0_1c.png
image
MD5: ffb666b8e5c6ab272160bf2fab1f5775
SHA256: e73b9ee6427d775b8f4f97162682a3b73f5e71812ee17711475899b67ddbd2c2
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\zh-CN.chm
chm
MD5: d2453057dfcb5b89ed5918015f4ea43b
SHA256: a20a6d90da91fe8cd4528016dccfbaf01694fe25073d120147a4e9a9c93fa4c7
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\vi-VN.chm
chm
MD5: 75a126f999d79fe9f3342aaea640cdfc
SHA256: 02259fb0155fb11faab7fa778c13a8a74cc43b8997d21c19c8abf39a7889eeaf
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\de-DE.chm
chm
MD5: 1ba6120cbcd14401bfcd27f5f0394a3b
SHA256: d4bf6cb2c1a26085ade5a8995797f76fa98a408899228b7388e84d3fd98acb22
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\fi-FI.chm
chm
MD5: 3cb11c7a84941e01a7556d4b703516fc
SHA256: e3036472f8708de3b6a9dc0fc0f258fe9a1922c72cbce30742e0f551b1e6f2f4
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\fr-FR.chm
chm
MD5: 941ac6292541fe04f571dc1836dc92ae
SHA256: ab190299dac4380e8817cf5e08a64319ba5469aba66b9194efe7a59d5dc1a5c2
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\tr-TR.chm
chm
MD5: 2ff77865916baeff743ccd184fc17ef6
SHA256: 3ab7ea16414bc752ab299b9310a6b9c6b526ce4772c355360e95de71c8ede90c
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\pl-PL.chm
chm
MD5: 6c743dc054c9be8f2434facc63fc0139
SHA256: 8950f33e69d49ba12dff74c7bafd5966c81bbddbc394593415186c6a3c3dcb5c
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\en-US.chm
chm
MD5: bf10729be0fe24109cf88508dcb396a5
SHA256: f43fdd9d95c9bf380dd0a3b44b527154576e4ae72b7fe0090a26a2b49cfef44c
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\es-VE.chm
chm
MD5: 355ef2cf6b6fe734ddd4a1b7a16e9e9d
SHA256: b06775dadd67022e95cd8d2da1bca51516d2664428f9f3f2057287bc51d69b3d
2232
7tt_setup.exe
C:\Users\admin\AppData\Roaming\7+ Taskbar Tweaker\help\nl-NL.chm
chm
MD5: e5b052df560a9b9b35d1727417dfa9f1
SHA256: 3c920178b86788690d74a288967bcb5c58d5599c082d46b0323d812297c1c2a2
2436
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State
text
MD5: 50d4a1912902c2f52c89ff17ed8dad80
SHA256: 62792aef6c33f6641baf0b688524ef3e2e7ed04951117ae77990362eb6cc056d
2436
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State~RF37ffb1.TMP
text
MD5: 50d4a1912902c2f52c89ff17ed8dad80
SHA256: 62792aef6c33f6641baf0b688524ef3e2e7ed04951117ae77990362eb6cc056d
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 02e54a48b661f849af346ab24bd22e56
SHA256: ff6cff5d96d13a59272fd8c2b4e9f6705eae3d9124710eb3d27fae51e0e00b57
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF374d68.TMP
text
MD5: 02e54a48b661f849af346ab24bd22e56
SHA256: ff6cff5d96d13a59272fd8c2b4e9f6705eae3d9124710eb3d27fae51e0e00b57
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\743af69a-4a4b-4e40-bc0f-9afbe1ab7fcb.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 799c1150ef75f5f8fba493399f1102d6
SHA256: 09b97f945ccec96eb5085046e9f22955a66eaa975693d8b0bb224530400a86fb
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF373f5f.TMP
text
MD5: 799c1150ef75f5f8fba493399f1102d6
SHA256: 09b97f945ccec96eb5085046e9f22955a66eaa975693d8b0bb224530400a86fb
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\aeca6e80-e43d-4ada-a23f-ce241e93223e.tmp
––
MD5:  ––
SHA256:  ––
2232
7tt_setup.exe
C:\Users\admin\AppData\Local\Temp\nse1766.tmp\modern-wizard.bmp
image
MD5: 9e4cd80a60db6947642677bf31a10906
SHA256: a7b2f12e01cbea88d4f645f797f2ca6107d76ae13cd1be6dc532b759bfe0d925
2232
7tt_setup.exe
C:\Users\admin\AppData\Local\Temp\nse1766.tmp\modern-header.bmp
image
MD5: 583c38fb0f5af5fe584d9a9b01d6a3e7
SHA256: 4c9e804ce1a391f8e603b7b9c732a6529c1e81be4d12f125c8562ea9d49095c2
2436
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ae7ac608-540f-4ee6-983d-21f090c07515.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF37fca4.TMP
text
MD5: 486c8d30d957986169c1a9c9ad131cbe
SHA256: 4f177b089b5ea8f1f306d01ba8d7b91fb6dbda8ed58ed081ac3f849584ee97cf
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 486c8d30d957986169c1a9c9ad131cbe
SHA256: 4f177b089b5ea8f1f306d01ba8d7b91fb6dbda8ed58ed081ac3f849584ee97cf
2436
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 8be1d8e447f3ad1b2e53a83e58d5748b
SHA256: e74a50aa8b3a07f5b618083c05f37845ea1c3941c2c79d45c55b1e23a1ddbcc2
2436
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF371580.TMP
text
MD5: 8be1d8e447f3ad1b2e53a83e58d5748b
SHA256: e74a50aa8b3a07f5b618083c05f37845ea1c3941c2c79d45c55b1e23a1ddbcc2
2436
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\3b9eac2e-4087-462c-913b-c70321684264.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 4800e8ea8626363ba24d7e40a56e6bf0
SHA256: 19c2b16506cc09cbac9f003baf01e17bda9f208085e20cb5210d3bd0f4d3460d
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF370fd3.TMP
text
MD5: 4800e8ea8626363ba24d7e40a56e6bf0
SHA256: 19c2b16506cc09cbac9f003baf01e17bda9f208085e20cb5210d3bd0f4d3460d
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\3d2fc049-bd00-4c4b-954e-094c0c285938.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF370f17.TMP
text
MD5: 2ad11f16e31756680f4140247ebc2b74
SHA256: 2cc31533e168302a1f91c46ec1a7db9680165117aeb2d2233449e53fd16a12ae
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 2ad11f16e31756680f4140247ebc2b74
SHA256: 2cc31533e168302a1f91c46ec1a7db9680165117aeb2d2233449e53fd16a12ae
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\2bbfa00c-9d93-4a68-99a8-cc8dc5499016.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata~RF37092c.TMP
binary
MD5: c8770ca7ffac17ec14e90d36f36312b4
SHA256: 5474ce44d4b94d76efa2968c85a2aaca997fb397aa5db6c11f7e8fd661072915
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata
binary
MD5: c8770ca7ffac17ec14e90d36f36312b4
SHA256: 5474ce44d4b94d76efa2968c85a2aaca997fb397aa5db6c11f7e8fd661072915
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\4f384060-bffc-4047-b24a-afc754f40c1c.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\DownloadMetadata
binary
MD5: bacdfbefd4c3e65b55a2f96a2204ecba
SHA256: 59c7e8e37b24e854086d5aeef09678107719123344fc2b397a90a27a6b636fe7
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\9fb44cd4-6fb9-433e-9b69-74fb894ddbfe.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\Downloads\7tt_setup.exe:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\21f4d400-2957-4a6b-867a-7a1e65c7485b.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old
text
MD5: 97aa7678fb9d338d08c371711b54a104
SHA256: 4657635b66fa68ae1550b7bff4e54016f8874b4df43a004c9a7244c8465c6ca8
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Session
binary
MD5: 92eb31d830454841999ecdb4a714d301
SHA256: 63f01870e03b0329f3ae859435ef5610661a45085390af36275ae7d6808c8ffb
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF37faa0.TMP
text
MD5: c586f3ca9cb7133e445ac3693c11aaeb
SHA256: a4ade6f981dc9bbd3bdeb5b6a0c42509e1a95b3f91e94d88bff0d243350353f9
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: c586f3ca9cb7133e445ac3693c11aaeb
SHA256: a4ade6f981dc9bbd3bdeb5b6a0c42509e1a95b3f91e94d88bff0d243350353f9
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\65f930bb-93db-4450-a59b-540aacdf497a.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF36eefd.TMP
text
MD5: 1276f7de036cb69ffbc104fa79f1d060
SHA256: 3044aa641bd2fed097ee25a5ad052d276eea8ec75a807a244102d75af9ac94f1
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
text
MD5: 1276f7de036cb69ffbc104fa79f1d060
SHA256: 3044aa641bd2fed097ee25a5ad052d276eea8ec75a807a244102d75af9ac94f1
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 62ead691ebc81279cd672bf4641c80e1
SHA256: d6d6238bc7f60c73e99718571246125a800c1fe487d7d39e746d595ebc260de2
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\CURRENT
text
MD5: 206702161f94c5cd39fadd03f4014d98
SHA256: 1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\CURRENT~RF36eeae.TMP
text
MD5: 206702161f94c5cd39fadd03f4014d98
SHA256: 1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old
text
MD5: 370df9c4af340d044e2946d87d515fd8
SHA256: f4761a6412fee517fddf04004ddcb13b935994fba8550318534705c979a29343
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF36ee9f.TMP
text
MD5: 370df9c4af340d044e2946d87d515fd8
SHA256: f4761a6412fee517fddf04004ddcb13b935994fba8550318534705c979a29343
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000002.dbtmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\000001.dbtmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
binary
MD5: f50f89a0a91564d0b8a211f8921aa7de
SHA256: b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
binary
MD5: 891a884b9fa2bff4519f5f56d2a25d62
SHA256: e2610960c3757d1757f206c7b84378efa22d86dcf161a98096a5f0e56e1a367e
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
text
MD5: c292c29e256bfac8628cf0853ebbf3ae
SHA256: 695661ca458a24357989989693bc924a555ff17cea51bd87ba0e1e0aa6043663
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old
text
MD5: 722d616be0caaf9ed585c9aea7f3742c
SHA256: f86c514fa380332be463670b3b334c8feedc2f6cb9b4118ea367729b056de0fb
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old
text
MD5: 454106ccf080f3e3795c229fc73350d4
SHA256: 9974dc611be9e20bdfa7b8d939cb913ad23859dea5f52ebb8d10cead9ab5b4fa
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old~RF36ea3a.TMP
text
MD5: 454106ccf080f3e3795c229fc73350d4
SHA256: 9974dc611be9e20bdfa7b8d939cb913ad23859dea5f52ebb8d10cead9ab5b4fa
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old
text
MD5: 911b244e4a362b56f2478647d2d61a40
SHA256: 3a5aec1ea537d8841e604d0aa4cd5f9241c805a3d4eb4e372cfb7eeb3678a361
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old
text
MD5: 0acecca4cf9ade756da7cc9dcdf02d50
SHA256: 18f910775132b4fee014ea0fab836d857f367e76232fab4ae6a86a92e4c3ebee
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF36e9ad.TMP
text
MD5: a874f3e3462932a0c15ed8f780124fc5
SHA256: 01bd196d6a114691ec642082ebf6591765c0168d4098a0cd834869bd11c8b87d
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT
text
MD5: a874f3e3462932a0c15ed8f780124fc5
SHA256: 01bd196d6a114691ec642082ebf6591765c0168d4098a0cd834869bd11c8b87d
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old
text
MD5: 3d551b6e929cf62f7aa66091e718704b
SHA256: 1698a1b1bc3e86676392fb8bd4c712438302a5a2220503c08f290ed4b1790404
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old~RF36e98e.TMP
text
MD5: 3d551b6e929cf62f7aa66091e718704b
SHA256: 1698a1b1bc3e86676392fb8bd4c712438302a5a2220503c08f290ed4b1790404
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\cdef9f9a-a636-4d5a-9ea7-64d72b57201c.tmp
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Last Tabs
binary
MD5: 0686d6159557e1162d04c44240103333
SHA256: 3303d5eed881951b0bb52cf1c6bfa758770034d0120c197f9f7a3520b92a86fb
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF36e94f.TMP
text
MD5: a519780ed0a2f4336db4f5651d79c369
SHA256: da5b71bd0075b55757bf757bf5f4d4a1dcbcf0762cda5b31b28680963e068c75
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old
text
MD5: a519780ed0a2f4336db4f5651d79c369
SHA256: da5b71bd0075b55757bf757bf5f4d4a1dcbcf0762cda5b31b28680963e068c75
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old
––
MD5:  ––
SHA256:  ––
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old
text
MD5: 213ae3da120d7862d60b5763b6c9d466
SHA256: 5736534d6ee654c1bf1a8e79e73330af58f622e8657285330d2c7189a55604f4
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old
text
MD5: c4d6cbb269c626168a5d6d0d8cce6c30
SHA256: b62cdbb758278a0c2e50593357390119441d8de09428eb29027f3dfd1332e348
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF36e8f2.TMP
text
MD5: c4d6cbb269c626168a5d6d0d8cce6c30
SHA256: b62cdbb758278a0c2e50593357390119441d8de09428eb29027f3dfd1332e348
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
text
MD5: dc32343f45b01764b6267ad36548102a
SHA256: a250f5ad57d4bd58aae92810d50278e3be2dbf869f126a3a3519691bcdfc2075
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF36e8e2.TMP
text
MD5: 213ae3da120d7862d60b5763b6c9d466
SHA256: 5736534d6ee654c1bf1a8e79e73330af58f622e8657285330d2c7189a55604f4
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF36e8e2.TMP
text
MD5: dc32343f45b01764b6267ad36548102a
SHA256: a250f5ad57d4bd58aae92810d50278e3be2dbf869f126a3a3519691bcdfc2075
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
binary
MD5: 9c016064a1f864c8140915d77cf3389a
SHA256: 0e7265d4a8c16223538edd8cd620b8820611c74538e420a88e333be7f62ac787
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version
text
MD5: 1a89a1bebe6c843c4ff582e7ed33ca1f
SHA256: 65099ca087b66aa8ca420ab121daad713e1db5a61c5a574d9b1c0df24f012520
2176
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF3839eb.TMP
text
MD5: 486c8d30d957986169c1a9c9ad131cbe
SHA256: 4f177b089b5ea8f1f306d01ba8d7b91fb6dbda8ed58ed081ac3f849584ee97cf

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
9
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2816 7+ Taskbar Tweaker.exe POST 200 104.31.93.187:80 http://rammichael.com/downloads/7tt_setup.exe?version&changelog=5.7 US
binary
text
suspicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2436 chrome.exe 104.31.92.187:443 Cloudflare Inc US shared
2436 chrome.exe 172.217.22.35:443 Google Inc. US whitelisted
2436 chrome.exe 172.217.23.173:443 Google Inc. US whitelisted
–– –– 172.217.22.35:443 Google Inc. US whitelisted
2436 chrome.exe 172.217.16.174:443 Google Inc. US whitelisted
2436 chrome.exe 172.217.16.164:443 Google Inc. US whitelisted
2436 chrome.exe 216.58.206.3:443 Google Inc. US whitelisted
2816 7+ Taskbar Tweaker.exe 104.31.93.187:80 Cloudflare Inc US shared
2436 chrome.exe 172.217.18.163:443 Google Inc. US whitelisted
2436 chrome.exe 216.58.210.14:443 Google Inc. US whitelisted

DNS requests

Domain IP Reputation
clientservices.googleapis.com 172.217.22.35
whitelisted
rammichael.com 104.31.92.187
104.31.93.187
suspicious
accounts.google.com 172.217.23.173
shared
sb-ssl.google.com 172.217.16.174
whitelisted
www.google.com 172.217.16.164
whitelisted
ssl.gstatic.com 216.58.206.3
whitelisted
www.gstatic.com 172.217.18.163
whitelisted
clients1.google.com 216.58.210.14
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.