General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

Stongion's Hacking Accounts Archive.rar

Verdict
Malicious activity
Analysis date
2/10/2019, 18:35:58
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
njrat
bladabindi
Indicators:

MIME:
application/x-rar
File info:
RAR archive data, v5
MD5

1e966d167f753e74d1773f0ab2ca4927

SHA1

7ba632e43f121d12bac9871381d9ad01c3b90ac0

SHA256

2d759acb2c12c03bbd0213e6f837dc18f9c432a6812cc1138ab6fbcc08f9554c

SSDEEP

98304:Z+0be8lAG6PNUTvONXz46ynT9m5AfOJwW+kP28OxVHcgl9t2wtMiUl5q:ZHzlAG6PNmYKAA2/+kPEV8gh2wtMnq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
NJRAT was detected
  • wsc.exe (PID: 3212)
Writes to a start menu file
  • wsc.exe (PID: 3212)
Connects to CnC server
  • wsc.exe (PID: 3212)
Application was dropped or rewritten from another process
  • AAPBuilder V2.3.exe (PID: 3856)
  • AAPBuilderV2.3.exe (PID: 3668)
  • wsc.exe (PID: 3212)
  • AAPBuilder V2.3.exe (PID: 2204)
Changes the autorun value in the registry
  • wsc.exe (PID: 3212)
Creates files in the user directory
  • wsc.exe (PID: 3212)
Connects to unusual port
  • wsc.exe (PID: 3212)
Executable content was dropped or overwritten
  • AAPBuilderV2.3.exe (PID: 3668)
  • wsc.exe (PID: 3212)
  • WinRAR.exe (PID: 3104)
  • AAPBuilder V2.3.exe (PID: 2204)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.rar
|   RAR compressed archive (v5.0) (61.5%)
.rar
|   RAR compressed archive (gen) (38.4%)

Screenshots

Processes

Total processes
44
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

+
drop and start drop and start start drop and start drop and start winrar.exe aapbuilder v2.3.exe no specs aapbuilder v2.3.exe aapbuilderv2.3.exe #NJRAT wsc.exe notepad.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3104
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Stongion's Hacking Accounts Archive.rar"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\users\admin\appdata\local\temp\rar$exa3104.20589\aapbuilder v2.3.exe
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll

PID
3856
CMD
"C:\Users\admin\AppData\Local\Temp\Rar$EXa3104.20589\AAPBuilder V2.3.exe"
Path
C:\Users\admin\AppData\Local\Temp\Rar$EXa3104.20589\AAPBuilder V2.3.exe
Indicators
No indicators
Parent process
WinRAR.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\rar$exa3104.20589\aapbuilder v2.3.exe
c:\systemroot\system32\ntdll.dll

PID
2204
CMD
"C:\Users\admin\AppData\Local\Temp\Rar$EXa3104.20589\AAPBuilder V2.3.exe"
Path
C:\Users\admin\AppData\Local\Temp\Rar$EXa3104.20589\AAPBuilder V2.3.exe
Indicators
Parent process
WinRAR.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\rar$exa3104.20589\aapbuilder v2.3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\aapbuilderv2.3.exe
c:\users\admin\appdata\local\temp\wsc.exe

PID
3668
CMD
"C:\Users\admin\AppData\Local\Temp\AAPBuilderV2.3.exe"
Path
C:\Users\admin\AppData\Local\Temp\AAPBuilderV2.3.exe
Indicators
Parent process
AAPBuilder V2.3.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
1.0.0.0
Modules
Image
c:\users\admin\appdata\local\temp\aapbuilderv2.3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\kernelbase.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\032f5fa875be86b577722ddeeee2e51c\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.transactions\e7044d177c8e852b85908d2702898ec8\system.transactions.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.transactions\v4.0_4.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\system32\bcrypt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\actxprxy.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\psapi.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\linkinfo.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\sc_reader.ico

PID
3212
CMD
"C:\Users\admin\AppData\Local\Temp\wsc.exe"
Path
C:\Users\admin\AppData\Local\Temp\wsc.exe
Indicators
Parent process
AAPBuilder V2.3.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\wsc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.visualbas#\08d608378aa405adc844f3cf36974b8c\microsoft.visualbasic.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\system32\shfolder.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\microsoft.net\framework\v2.0.50727\wminet_utils.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\sxs.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\custommarshalers\bf7e7494e75e32979c7824a07570a8a9\custommarshalers.ni.dll
c:\windows\assembly\gac_32\custommarshalers\2.0.0.0__b03f5f7f11d50a3a\custommarshalers.dll

PID
2756
CMD
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\New Text Document.txt
Path
C:\Windows\system32\NOTEPAD.EXE
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Notepad
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll

Registry activity

Total events
3539
Read events
1377
Write events
2162
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3104
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\Stongion's Hacking Accounts Archive.rar
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\AppData\Local\Temp
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C800000000000000000000000000320101000000000039000000B40200000000000001000000
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000003401010000000000160000002A0000000000000002000000
3104
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C800000000000000000000000000180102000000000016000000640000000000000003000000
2204
AAPBuilder V2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2204
AAPBuilder V2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\AAPBuilder\DisclaimerApproval
DontShowAgain
True
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
4100410050004200750069006C00640065007200560032002E0033002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0100000000000000020000000700000006000000030000000500000004000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0000000001000000020000000400000003000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
1
7A003100000000004A4E898C11004465736B746F7000640008000400EFBE454B814A4A4E898C2A0000007B0100000000020000000000000000003A00000000004400650073006B0074006F007000000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370036003900000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
MRUListEx
0100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\1
NodeSlot
95
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\1
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
SniffedFolderType
Generic
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CIDSave\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
9C000000980000003153505305D5CDD59C2E1B10939708002B2CF9AE3B0000002A000000004E0061007600500061006E0065005F004300460044005F0046006900720073007400520075006E0000000B000000000000004100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
2
4100410050004200750069006C00640065007200560032002E0033002E0065007800650000000000
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
MRUListEx
020000000100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
0
52003200000000000000000080003132332E657865003C0008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000003100320033002E00650078006500000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
1
52003200000000000000000080003132332E657865003C0008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000003100320033002E00650078006500000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
MRUListEx
0100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
4100410050004200750069006C00640065007200560032002E0033002E00650078006500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000BD010000870000003D04000067020000000000000000000000000000000000000100000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
4100410050004200750069006C00640065007200560032002E0033002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000BA01000071000000450300004202000000000000000000000000000000000000BD010000870000003D04000067020000000000000000000000000000000000000100000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
MRUListEx
020000000100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A000000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000A66A63283D95D211B5D600C04FD918D00B0000007800000030F125B7EF471A10A5F102608C9EEBAC0E00000078000000
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3668
AAPBuilderV2.3.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\82\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500\Software\AAPBuilder\DisclaimerApproval
DontShowAgain
True
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
1
14001F50E04FD020EA3A6910A2D808002B30309D0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
2
14001F4225481E03947BC34DB131E946B44C8DD50000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
3
14001F6880531C87A0426910A2EA08002B30309D0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
4
4C00310000000000454BB94D1000746F6F6C7300380008000400EFBE454BB94D454BB94D2A000000A844000000000200000000000000000000000000000074006F006F006C007300000014000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
5
9400310000000000000000001000303030312D363330355F56697374615F57696E375F504735333728312900680008000400EFBE00000000000000002A0000000000000000000000000000000000000000000000000030003000300031002D0036003300300035005F00560069007300740061005F00570069006E0037005F005000470035003300370028003100290000002C000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
7
14001F44471A0359723FA74489C55595FE6B30EE0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlot
82
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
1
0C0001008421DE39050000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
NodeSlot
5
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
2
0C0001008421DE39000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
3
0C0001008421DE39030000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
4
0C0001008421DE39020000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
5
0C0001008421DE39090000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0
1
1E007180000000000000000000008B4355C5233C6947A71FB6D3D9B6053A0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\0
NodeSlot
1
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1
0
F7000000F10000EEEBBEE300040000000000510000003153505330F125B7EF471A10A5F102608C9EEBAC350000000A000000001F00000012000000530063007200650065006E0020005200650073006F006C007500740069006F006E000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F00000044006900730070006C00610079002E0064006C006C002C002D00310000000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1\0
NodeSlot
2
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
0
1E00718000000000000000000000E4C006BB93D2754F8A90CB05B6477EEE0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
MRUListEx
0100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
NodeSlot
6
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
1
1E007180000000000000000000002F492640692FB846B9BF5654FC07E4230000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\0
NodeSlot
4
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
NodeSlot
7
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
0
2B010000250100EEEBBE1701040000000000550000003153505330F125B7EF471A10A5F102608C9EEBAC390000000A000000001F0000001300000043007500730074006F006D0069007A0065002000530065007400740069006E006700730000000000000000005900000031535053537DEF0C64FAD111A2030000F81FEDEE3D00000005000000001F00000016000000500061006700650043006F006E00660069006700750072006500530065007400740069006E006700730000000000000065000000315350538727BF5CCF480842B90EEE5E5D4202944900000019000000001F0000001C0000004600690072006500770061006C006C0043006F006E00740072006F006C00500061006E0065006C002E0064006C006C002C002D0031000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1\0
NodeSlot
8
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
NodeSlot
9
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
MRUListEx
02000000090000000100000008000000070000000600000005000000040000000300000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
0
1E00718000000000000000000000DBF7EE36AD88814EAD490E313F0C35F80000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
1
1E00718000000000000000000000C98F908ECCBEF640915BF4CA0E70D03D0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
2
1E00718000000000000000000000E4C006BB93D2754F8A90CB05B6477EEE0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
3
1E00718000000000000000000000D64E83ED5A4BFE4B8F11A626DCB6A9210000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
4
1E007180000000000000000000008B4355C5233C6947A71FB6D3D9B6053A0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
5
1E007180000000000000000000005076CA67E696DD4FBB43A8E774F73A570000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
6
1E00718000000000000000000000E5F5739CE77A324EA8E88D23B85255BF0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
7
1E007180000000000000000000006ABE817B2BCE7646A29EEB907A5126C50000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
8
1E00718000000000000000000000A7F864BBE7BE1A4EAB8D7D8273F7FDB60000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
9
1E007180000000000000000000002F492640692FB846B9BF5654FC07E4230000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
NodeSlot
10
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
0
FB000000F50000EEEBBEE7000400010000004D0000003153505330F125B7EF471A10A5F102608C9EEBAC310000000A000000001F000000100000004300680061006E00670065002000730065007400740069006E00670073000000000000004900000031535053537DEF0C64FAD111A2030000F81FEDEE2D00000005000000001F0000000D0000007000610067006500530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F0000007700750063006C007400750078002E0064006C006C002C002D00310000000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0\0
NodeSlot
11
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
NodeSlot
22
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
0
0F010000090100EEEBBEFB00040000000000610000003153505330F125B7EF471A10A5F102608C9EEBAC450000000A000000001F0000001A00000041006400760061006E006300650064002000730068006100720069006E0067002000730065007400740069006E00670073000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F0000000900000041006400760061006E00630065006400000000000000000055000000315350538727BF5CCF480842B90EEE5E5D4202943900000019000000001F0000001300000069006D006100670065007200650073002E0064006C006C002C002D00310030003100330000000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1\0
NodeSlot
44
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\2
NodeSlot
25
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\2
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\3
NodeSlot
28
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\3
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4
0
F7000000F10000EEEBBEE300040000000000510000003153505330F125B7EF471A10A5F102608C9EEBAC350000000A000000001F00000012000000530063007200650065006E0020005200650073006F006C007500740069006F006E000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F00000044006900730070006C00610079002E0064006C006C002C002D00310000000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4\0
NodeSlot
29
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\5
NodeSlot
45
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\5
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\6
NodeSlot
46
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\6
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\7
NodeSlot
52
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\7
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
NodeSlot
57
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
0
1F010000190100EEEBBE0B01040000000000690000003153505330F125B7EF471A10A5F102608C9EEBAC4D0000000A000000001F0000001E0000004300680061006E0067006500200041006300740069006F006E002000430065006E007400650072002000730065007400740069006E00670073000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000005D000000315350538727BF5CCF480842B90EEE5E5D4202944100000019000000001F0000001700000041006300740069006F006E00430065006E00740065007200430050004C002E0064006C006C002C002D00310000000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8\0
NodeSlot
58
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
NodeSlot
93
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
0
2B010000250100EEEBBE1701040000000000550000003153505330F125B7EF471A10A5F102608C9EEBAC390000000A000000001F0000001300000043007500730074006F006D0069007A0065002000530065007400740069006E006700730000000000000000005900000031535053537DEF0C64FAD111A2030000F81FEDEE3D00000005000000001F00000016000000500061006700650043006F006E00660069006700750072006500530065007400740069006E006700730000000000000065000000315350538727BF5CCF480842B90EEE5E5D4202944900000019000000001F0000001C0000004600690072006500770061006C006C0043006F006E00740072006F006C00500061006E0065006C002E0064006C006C002C002D0031000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9\0
NodeSlot
94
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3
0
1E00718000000000000000000000C7AC07700232D111AAD200805FC1270E0000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3\0
NodeSlot
23
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\4
NodeSlot
42
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\4
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
NodeSlot
55
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
0
1E00718000000000000000000000F1F5061269052C418FEC3204630DFB700000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5\0
NodeSlot
56
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
0
19002F433A5C000000000000000000000000000000000000000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
NodeSlot
27
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
0
7400310000000000454B804A1100557365727300600008000400EFBEEE3AA314454B804A2A0000005A01000000000100000000000000000036000000000055007300650072007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100380031003300000014000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0000000001000000020000000400000003000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
NodeSlot
34
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
1
8800310000000000464BDD51110050524F4752417E310000700008000400EFBEEE3AA314464BDD512A0000003C000000000001000000000000000000460000000000500072006F006700720061006D002000460069006C0065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003100000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
2
5200310000000000464BEA51100057696E646F7773003C0008000400EFBEEE3AA314464BEA512A000000FA010000000001000000000000000000000000000000570069006E0064006F0077007300000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
3
5000310000000000464B9D511000414E5952554E00003A0008000400EFBE454BFD4D464B9D512A0000005545000000000200000000000000000000000000000041004E005900520055004E00000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
4
5E0031000000000000000000100050726F6772616D4461746100440008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000500072006F006700720061006D00440061007400610000001A000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
0
4C00310000000000454B854A100061646D696E00380008000400EFBE454B804A454B854A2A0000002D000000000004000000000000000000000000000000610064006D0069006E00000014000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
NodeSlot
54
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
0
5200310000000000454B814A122041707044617461003C0008000400EFBE454B814A454B814A2A0000007C0100000000020000000000000000000000000000004100700070004400610074006100000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
MRUListEx
0100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
1
7A003100000000004A4E898C11004465736B746F7000640008000400EFBE454B814A4A4E898C2A0000007B0100000000020000000000000000003A00000000004400650073006B0074006F007000000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370036003900000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
0
5200310000000000454B834A1020526F616D696E67003C0008000400EFBE454B814A454B834A2A0000007D01000000000200000000000000000000000000000052006F0061006D0069006E006700000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
MRUListEx
0000000001000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
1
4C00310000000000454B645310204C6F63616C00380008000400EFBE454B814A454B64532A0000008F0100000000020000000000000000000000000000004C006F00630061006C00000014000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
NodeSlot
73
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
0
5800310000000000454B834A14204D4943524F537E310000400008000400EFBE454B814A454B834A2A0000007E0100000000020000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
MRUListEx
0100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
NodeSlot
72
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
1
4C003100000000001E4DC56E102041646F626500380008000400EFBE1C4DC45E1E4DC56E2A00000020C40000000002000000000000000000000000000000410064006F0062006500000014000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0
0
5200310000000000454B854A102057696E646F7773003C0008000400EFBE454B814A454B854A2A0000007F010000000002000000000000000000000000000000570069006E0064006F0077007300000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0
0
8200310000000000454B854A110053544152544D7E3100006A0008000400EFBE454B814A454B854A2A000000810100000000020000000000000000004000000000005300740061007200740020004D0065006E007500000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003600000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0\0
NodeSlot
3
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
NodeSlot
86
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
0
52003100000000001E4DC16E10204163726F626174003C0008000400EFBE1E4DC16E1E4DC16E2A000000D73D00000000160000000000000000000000000000004100630072006F00620061007400000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
NodeSlot
87
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
0
4400310000000000294D747C102044430000320008000400EFBE1E4DC16E294D747C2A0000000D3E000000001000000000000000000000000000000044004300000012000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
NodeSlot
88
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
0
5600310000000000294D747C1020536563757269747900003E0008000400EFBE294D747C294D747C2A00000033DA000000000400000000000000000000000000000053006500630075007200690074007900000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
NodeSlot
89
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
0
5600310000000000294D747C102043524C436163686500003E0008000400EFBE294D747C294D747C2A00000034DA0000000003000000000000000000000000000000430052004C0043006100630068006500000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0\0
NodeSlot
90
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
0
4A00310000000000464B2D52102054656D700000360008000400EFBE454B814A464B2D522A00000090010000000002000000000000000000000000000000540065006D007000000014000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
MRUListEx
03000000020000000100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
NodeSlot
74
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
1
50003100000000001D4D1D691020476F6F676C6500003A0008000400EFBE1C4D7C591D4D1D692A000000E9A1000000000A00000000000000000000000000000047006F006F0067006C006500000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
2
58003100000000001C4D8265102046494C455A497E310000400008000400EFBE1C4D43621C4D82652A000000A6C80000000003000000000000000000000000000000460069006C0065005A0069006C006C006100000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
3
58003100000000001D4DB67D10204D4943524F537E310000400008000400EFBE454B814A1D4DB67D2A000000910100000000020000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\0
NodeSlot
39
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
NodeSlot
75
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
MRUListEx
0100000000000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
0
72003100000000001D4D1D691020534F465457417E3100005A0008000400EFBE1D4D1D691D4D1D692A0000004BFC000000000100000000000000000000000000000053006F0066007400770061007200650020005200650070006F007200740065007200200054006F006F006C00000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
1
50003100000000001C4D7C5910204368726F6D6500003A0008000400EFBE1C4D7C591C4D7C592A000000ECA100000000070000000000000000000000000000004300680072006F006D006500000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
NodeSlot
76
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
0
52003100000000001D4D1D6910207265706F727473003C0008000400EFBE1D4D1D691D4D1D692A0000004EFC00000000010000000000000000000000000000007200650070006F00720074007300000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0\0
NodeSlot
77
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
NodeSlot
78
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
0
5800310000000000294DE58210205553455244417E310000400008000400EFBE1C4D7C59294DE5822A000000EEA10000000005000000000000000000000000000000550073006500720020004400610074006100000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
NodeSlot
79
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
0
5A003100000000001D4D1D69102053575245504F7E310000420008000400EFBE1C4D7D591D4D1D692A00000092BC0000000003000000000000000000000000000000530077005200650070006F007200740065007200000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
NodeSlot
80
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
0
5C003100000000001D4D1D69102033333137307E312E32303100420008000400EFBE1D4D1D691D4D1D692A000000BBFB0000000002000000000000000000000000000000330033002E003100370030002E0032003000310000001A000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0\0
NodeSlot
81
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\2
NodeSlot
83
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\2
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
NodeSlot
84
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
0
5200310000000000294DE38310204F75746C6F6F6B003C0008000400EFBE1B4D1560294DE3832A000000A61B00000000030000000000000000000000000000004F00750074006C006F006F006B00000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3\0
NodeSlot
85
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\1
NodeSlot
95
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\1
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
NodeSlot
35
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
MRUListEx
010000000000000002000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
0
50003100000000001C4D54591000476F6F676C6500003A0008000400EFBE1C4D4F591C4D54592A000000FCB0000000000200000000000000000000000000000047006F006F0067006C006500000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
1
5E003100000000001C4DA6691000434F4D4D4F4E7E310000460008000400EFBEEE3AA3141C4DA6692A0000003D00000000000100000000000000000000000000000043006F006D006D006F006E002000460069006C0065007300000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
2
56003100000000001C4D7C60100043436C65616E657200003E0008000400EFBE1C4D7B601C4D7C602A00000069C40000000003000000000000000000000000000000430043006C00650061006E0065007200000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
NodeSlot
59
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
MRUListEx
000000000200000001000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
0
50003100000000001C4D595910004368726F6D6500003A0008000400EFBE1C4D54591C4D59592A0000007AB500000000020000000000000000000000000000004300680072006F006D006500000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
1
50003100000000001C4D5259100055706461746500003A0008000400EFBE1C4D4F591C4D52592A00000011B10000000002000000000000000000000000000000550070006400610074006500000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
2
5E003100000000001C4D4F5910004352415348527E310000460008000400EFBE1C4D4F591C4D4F592A000000FFB00000000002000000000000000000000000000000430072006100730068005200650070006F00720074007300000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
NodeSlot
60
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
0
5C003100000000001C4D595910004150504C49437E310000440008000400EFBE1C4D59591C4D59592A00000001BB00000000020000000000000000000000000000004100700070006C00690063006100740069006F006E00000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0\0
NodeSlot
71
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\1
NodeSlot
61
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\1
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\2
NodeSlot
70
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\2
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
NodeSlot
62
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
0
4C003100000000001C4D5866100041646F626500380008000400EFBE1C4D4A661C4D58662A000000E9D90000000003000000000000000000000000000000410064006F0062006500000014000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
NodeSlot
63
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
MRUListEx
000000000100000002000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
0
46003100000000001C4D4A66100041524D00340008000400EFBE1C4D4A661C4D4A662A000000F6D90000000003000000000000000000000000000000410052004D00000012000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
1
52003100000000001C4D4A6610004163726F626174003C0008000400EFBE1C4D4A661C4D4A662A000000EAD900000000030000000000000000000000000000004100630072006F00620061007400000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
2
50003100000000001C4D4B66100052656164657200003A0008000400EFBE1C4D4B661C4D4B662A0000009DDA0000000002000000000000000000000000000000520065006100640065007200000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0
NodeSlot
64
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0
0
4600310000000000294D7A791000312E3000340008000400EFBE1C4D4A66294D7A792A000000F7D9000000000300000000000000000000000000000031002E003000000012000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0\0
NodeSlot
65
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\1
NodeSlot
91
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\1
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\2
NodeSlot
92
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\2
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\2
NodeSlot
69
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\2
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
NodeSlot
36
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
0
5200310000000000464BDD511000437572736F7273003C0008000400EFBEEE3AA414464BDD512A0000001305000000000100000000000000000000000000000043007500720073006F0072007300000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\0
NodeSlot
37
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\3
NodeSlot
38
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\3
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4
0
58003100000000000000000010004D6963726F736F667400400008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0
0
520031000000000000000000100057696E646F7773003C0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000570069006E0064006F0077007300000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0
0
5C003100000000000000000010005374617274204D656E750000420008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000005300740061007200740020004D0065006E00750000001A000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0
0
560031000000000000000000100050726F6772616D7300003E0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000500072006F006700720061006D007300000018000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
0
500031000000000000000000100057696E52415200003A0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000570069006E00520041005200000016000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\0
NodeSlot
51
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2
NodeSlot
12
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2
MRUListEx
00000000FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2
0
9E0000001A00EEBBFE23000010007DB10D7BD29C934A973346CC89022E7C00002A0000000000EFBE000000200000000000000000000000000000000000000000000000000100000020002A0000000000EFBE7E47B3FBE4C93B4BA2BAD3F5D3CD46F98207BA827A5B6945B5D7EC83085F08CC20002A0000000000EFBE000000200000000000000000000000000000000000000000000000000100000020000000
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2\0
NodeSlot
50
3668
AAPBuilderV2.3.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2\0
MRUListEx
FFFFFFFF
3668
AAPBuilderV2.3.exe
write
HKEY_