General Info

File name

Dexpot v1614 r2439.exe

Full analysis
https://app.any.run/tasks/e27919a8-e1cf-4846-8899-38b4ce1baf85
Verdict
Malicious activity
Analysis date
12/6/2018, 17:14:58
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

installer

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

77d59e8affcdc1355883da895cd32b35

SHA1

b37be0aab31a8ee5b370333f08a76c50a3dec31e

SHA256

34de9036d0d16ef10129962be5ebb4f6d001d1ff6677c0aec6ff530322ea099c

SSDEEP

98304:LUeOU72+G79pndMEvVp89qzk900Oz+k6+OVCXOmPnaOoIcQvLThoc0sJ:1OU7U7j+EvVcqzk900W6BsXPaOoULThL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • dexpot.exe (PID: 3740)
  • SevenDex.exe (PID: 3188)
  • dexpot.exe (PID: 2212)
Loads dropped or rewritten executable
  • SevenDex.exe (PID: 3188)
  • dwm.exe (PID: 1968)
  • WINWORD.EXE (PID: 1520)
  • DllHost.exe (PID: 2412)
  • Dexpot v1614 r2439.exe (PID: 2976)
  • DllHost.exe (PID: 3092)
  • dexpot.exe (PID: 3740)
  • explorer.exe (PID: 2028)
  • dexpot.exe (PID: 2212)
  • Dexpot v1614 r2439.exe (PID: 3156)
  • RunDll32.exe (PID: 3128)
Creates files in the user directory
  • Dexpot v1614 r2439.exe (PID: 3156)
  • SevenDex.exe (PID: 3188)
  • dexpot.exe (PID: 2212)
  • explorer.exe (PID: 2028)
Modifies the open verb of a shell class
  • Dexpot v1614 r2439.exe (PID: 2976)
Executable content was dropped or overwritten
  • Dexpot v1614 r2439.exe (PID: 3156)
  • Dexpot v1614 r2439.exe (PID: 2976)
Application launched itself
  • Dexpot v1614 r2439.exe (PID: 3156)
Reads Internet Cache Settings
  • explorer.exe (PID: 2028)
Uses RUNDLL32.EXE to load library
  • Dexpot v1614 r2439.exe (PID: 2976)
Creates a software uninstall entry
  • Dexpot v1614 r2439.exe (PID: 3156)
Creates files in the program directory
  • Dexpot v1614 r2439.exe (PID: 2976)
Reads Microsoft Office registry keys
  • WINWORD.EXE (PID: 1520)
Creates files in the user directory
  • WINWORD.EXE (PID: 1520)
Starts Microsoft Office Application
  • explorer.exe (PID: 2028)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   NSIS - Nullsoft Scriptable Install System (94.8%)
.exe
|   Win32 Executable MS Visual C++ (generic) (3.4%)
.dll
|   Win32 Dynamic Link Library (generic) (0.7%)
.exe
|   Win32 Executable (generic) (0.5%)
.exe
|   Generic Win/DOS Executable (0.2%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2009:12:05 23:50:52+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
24064
InitializedDataSize:
164864
UninitializedDataSize:
1024
EntryPoint:
0x30fa
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
1.6.14.0
ProductVersionNumber:
1.6.14.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Windows, Latin1
CompanyName:
Dexpot GbR
FileDescription:
Installer for Dexpot 1.6
FileVersion:
1.6.14
LegalCopyright:
© 2001-2014 Dexpot GbR
ProductName:
Dexpot 1.6 Setup
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
05-Dec-2009 22:50:52
Detected languages
English - United States
CompanyName:
Dexpot GbR
FileDescription:
Installer for Dexpot 1.6
FileVersion:
1.6.14
LegalCopyright:
© 2001-2014 Dexpot GbR
ProductName:
Dexpot 1.6 Setup
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
05-Dec-2009 22:50:52
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00005C4C 0x00005E00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.44011
.rdata 0x00007000 0x0000129C 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.04684
.data 0x00009000 0x00025C58 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.801
.ndata 0x0002F000 0x0001D000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x0004C000 0x0000F9B0 0x0000FA00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.91124
Resources
1

2

3

4

102

103

105

106

107

111

202

203

205

206

207

211

302

303

305

306

307

311

402

403

405

406

407

411

502

503

505

506

507

511

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

    VERSION.dll

Exports

    No exports.

Screenshots

Processes

Total processes
44
Monitored processes
13
Malicious processes
6
Suspicious processes
0

Behavior graph

+
start dexpot v1614 r2439.exe dexpot v1614 r2439.exe rundll32.exe no specs explorer.exe no specs explorer.exe no specs dexpot.exe no specs explorer.exe no specs dwm.exe no specs sevendex.exe no specs Thumbnail Cache Out of Proc Server no specs dexpot.exe no specs winword.exe no specs Thumbnail Cache Out of Proc Server no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
1968
CMD
"C:\Windows\system32\Dwm.exe"
Path
C:\Windows\System32\dwm.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Desktop Window Manager
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dwm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dwmredir.dll
c:\windows\system32\dwmcore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d10_1.dll
c:\windows\system32\d3d10_1core.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\dexpot\hooxpot.dll

PID
2028
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\dexpot v1614 r2439.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\dexpot\dexpot.exe
c:\program files\dexpot\updexer.exe
c:\program files\dexpot\hooxpot.dll
c:\program files\dexpot\plugins\sevendex.exe
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\mlang.dll
c:\windows\installer\{90140000-003d-0000-0000-0000000ff1ce}\wordicon.exe

PID
3156
CMD
"C:\Users\admin\AppData\Local\Temp\Dexpot v1614 r2439.exe"
Path
C:\Users\admin\AppData\Local\Temp\Dexpot v1614 r2439.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Dexpot GbR
Description
Installer for Dexpot 1.6
Version
1.6.14
Modules
Image
c:\users\admin\appdata\local\temp\dexpot v1614 r2439.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsb5d06.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
2976
CMD
"C:\Users\admin\AppData\Local\Temp\Dexpot v1614 r2439.exe" /UAC:30110 /NCRC
Path
C:\Users\admin\AppData\Local\Temp\Dexpot v1614 r2439.exe
Indicators
Parent process
Dexpot v1614 r2439.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Dexpot GbR
Description
Installer for Dexpot 1.6
Version
1.6.14
Modules
Image
c:\users\admin\appdata\local\temp\dexpot v1614 r2439.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nss5fd5.tmp\uac.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nss5fd5.tmp\langdll.dll
c:\windows\system32\uxtheme.dll
c:\users\admin\appdata\local\temp\nss5fd5.tmp\system.dll
c:\users\admin\appdata\local\temp\nss5fd5.tmp\ocsetuphlp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nss5fd5.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\users\admin\appdata\local\temp\nss5fd5.tmp\installoptions.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\mscomctl.ocx
c:\windows\system32\sxs.dll

PID
3128
CMD
RunDll32.exe "C:\Users\admin\AppData\Local\Temp\nss5FD5.tmp\OCSetupHlp.dll",[email protected] 2976,F14DFEE9D07947E9988C799538752553,1912D08838694A9E913296095A98FCF7,B3A1A77598C2401BA889E0AC4B2874CF
Path
C:\Windows\system32\RunDll32.exe
Indicators
No indicators
Parent process
Dexpot v1614 r2439.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\temp\nss5fd5.tmp\ocsetuphlp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\riched20.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\asycfilt.dll

PID
2412
CMD
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Path
C:\Windows\system32\DllHost.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
COM Surrogate
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\propsys.dll
c:\program files\dexpot\hooxpot.dll

PID
3100
CMD
"C:\Windows\explorer.exe" "C:\Program Files\Dexpot\dexpot.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
Dexpot v1614 r2439.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
3044
CMD
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\dexpot\dexpot.exe
c:\windows\system32\mpr.dll

PID
2212
CMD
"C:\Program Files\Dexpot\dexpot.exe"
Path
C:\Program Files\Dexpot\dexpot.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Dexpot GbR
Description
Dexpot - Virtual desktops for Windows
Version
1.06.0014
Modules
Image
c:\program files\dexpot\dexpot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\asycfilt.dll
c:\program files\dexpot\dexpot.dll
c:\windows\system32\winmm.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\mscomctl.ocx
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\psapi.dll
c:\program files\dexpot\hooxpot.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\dexpot\plugins\sevendex.exe
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll

PID
3188
CMD
"C:\Program Files\Dexpot\plugins\SevenDex.exe"
Path
C:\Program Files\Dexpot\plugins\SevenDex.exe
Indicators
No indicators
Parent process
dexpot.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Dexpot GbR
Description
Dexpot - Virtual Desktops for Windows
Version
1.1.5.0
Modules
Image
c:\program files\dexpot\plugins\sevendex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\dexpot\hooxpot.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
3740
CMD
"C:\Program Files\Dexpot\dexpot.exe"
Path
C:\Program Files\Dexpot\dexpot.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Dexpot GbR
Description
Dexpot - Virtual desktops for Windows
Version
1.06.0014
Modules
Image
c:\program files\dexpot\dexpot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\dexpot\hooxpot.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\asycfilt.dll

PID
1520
CMD
"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\mondayretail.rtf"
Path
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Word
Version
14.0.6024.1000
Modules
Image
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\program files\microsoft office\office14\1033\wwintl.dll
c:\program files\dexpot\hooxpot.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwmapi.dll
c:\program files\common files\microsoft shared\office14\msptls.dll
c:\windows\system32\uxtheme.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
c:\windows\system32\spool\drivers\w32x86\3\sendtoonenoteui.dll
c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
c:\windows\system32\fontsub.dll
c:\windows\system32\prntvpt.dll
c:\program files\common files\microsoft shared\office14\usp10.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\program files\microsoft office\office14\gkword.dll
c:\windows\system32\oleacc.dll
c:\program files\common files\system\ado\msadox.dll
c:\windows\system32\netutils.dll

PID
3092
CMD
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Path
C:\Windows\system32\DllHost.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
COM Surrogate
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\dexpot\hooxpot.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\propsys.dll

Registry activity

Total events
6964
Read events
6156
Write events
724
Delete events
84

Modification events

PID
Process
Operation
Key
Name
Value
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Dexpot
FirstStart
1
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Dexpot
C:\Program Files\Dexpot
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Dexpot
Dexpot-Home
C:\Program Files\Dexpot
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Dexpot
Sprache
C:\Program Files\Dexpot\sprache\english.dxs
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Dexpot
DexpotVersion
1.6.14.2439
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
DisplayName
Dexpot
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
NoModify
1
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
NoRepair
1
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
EstimatedSize
7611
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
Publisher
Dexpot GbR
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
DisplayIcon
C:\Program Files\Dexpot\dexpot.exe
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
DisplayVersion
1.6.14
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
URLInfoAbout
"http://www.dexpot.de"
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
URLUpdateInfo
"http://www.dexpot.de"
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
UninstallString
"C:\Program Files\Dexpot\uninstall.exe"
3156
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dexpot
QuietUninstallString
"C:\Program Files\Dexpot\uninstall.exe" /S
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\Qrkcbg i1614 e2439.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002D0000003D000000B34B1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\Qrkcbg i1614 e2439.rkr
000000000000000000000000DA2F0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002D0000003D0000008D7B1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Dexpot.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Dexpot-Updater.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\About.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Apply rules.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Assign applications.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Configure Desktops.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Debug.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktop Manager.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktop Preview.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktop Rules.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktop Windows.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Exit.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Full-screen preview.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Restore default settings.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Settings.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Window catalog.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Add desktop.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Desktop 1.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Desktop 2.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Desktop 3.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Desktop 4.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Desktop back.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Next desktop.lnk
1
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dexpot\Main menu\Desktops\Previous desktop.lnk
1
2028
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Qrkcbg\qrkcbg.rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF9074E1F07E8DD40100000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D0000008D7B1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
P:\Hfref\nqzva\Qrfxgbc\Qrkcbg.yax
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF9074E1F07E8DD40100000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
HRZR_PGYFRFFVBA
0000000025000000000000002400000009000000000000000900000043003A005C00550073006500720073005C005000750062006C00690063005C004400650073006B0074006F0070005C004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000006C006E006B000000630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000001D020000000085F990758C52F402BCD51D0294D51D028852F402C8D51D02546F9D76BC66AC760000000068DA1D026C31917568DA1D02553E9175337AD50628DD1D0200000000813E917590DA1D0294DA1D028852F402CD78D50656DD1D0200000000337AD506740A91750000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000091768106A77681069176810600000000000000000000000000000000000000000000000000000000000000009D240000C0ED9D0388D61D0233AB4777C019F5EFFC0B00001027000008000000ED530200BCD61D02F8AA4777ED530200C0ED9D03DCD61D02E8DED4035CD71D0200000000A20100001CD700001360DF7ACCD61D02829191751CD71D02D0D61D02279591750000000074E3D403F8D61D02CD94917574E3D403A4D71D02E8DED403E194917500000000E8DED403A4D71D0200D71D0209000000000000000900000043003A005C00550073006500720073005C005000750062006C00690063005C004400650073006B0074006F0070005C004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000006C006E006B000000630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000001D020000000085F990758C52F402BCD51D0294D51D028852F402C8D51D02546F9D76BC66AC760000000068DA1D026C31917568DA1D02553E9175337AD50628DD1D0200000000813E917590DA1D0294DA1D028852F402CD78D50656DD1D0200000000337AD506740A91750000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000091768106A77681069176810600000000000000000000000000000000000000000000000000000000000000009D240000C0ED9D0388D61D0233AB4777C019F5EFFC0B00001027000008000000ED530200BCD61D02F8AA4777ED530200C0ED9D03DCD61D02E8DED4035CD71D0200000000A20100001CD700001360DF7ACCD61D02829191751CD71D02D0D61D02279591750000000074E3D403F8D61D02CD94917574E3D403A4D71D02E8DED403E194917500000000E8DED403A4D71D0200D71D0209000000000000000900000043003A005C00550073006500720073005C005000750062006C00690063005C004400650073006B0074006F0070005C004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000006C006E006B000000630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000001D020000000085F990758C52F402BCD51D0294D51D028852F402C8D51D02546F9D76BC66AC760000000068DA1D026C31917568DA1D02553E9175337AD50628DD1D0200000000813E917590DA1D0294DA1D028852F402CD78D50656DD1D0200000000337AD506740A91750000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000091768106A77681069176810600000000000000000000000000000000000000000000000000000000000000009D240000C0ED9D0388D61D0233AB4777C019F5EFFC0B00001027000008000000ED530200BCD61D02F8AA4777ED530200C0ED9D03DCD61D02E8DED4035CD71D0200000000A20100001CD700001360DF7ACCD61D02829191751CD71D02D0D61D02279591750000000074E3D403F8D61D02CD94917574E3D403A4D71D02E8DED403E194917500000000E8DED403A4D71D0200D71D02
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
P:\Hfref\nqzva\Qrfxgbc\Qrkcbg.yax
00000000010000000000000001000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF9074E1F07E8DD40100000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{F4E57C4B-2036-45F0-A9AB-443BCFE33D9F}\Count
HRZR_PGYFRFFVBA
0000000025000000000000002500000009000000000000000900000043003A005C00550073006500720073005C005000750062006C00690063005C004400650073006B0074006F0070005C004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000006C006E006B000000630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000001D020000000085F990758C52F402BCD51D0294D51D028852F402C8D51D02546F9D76BC66AC760000000068DA1D026C31917568DA1D02553E9175337AD50628DD1D0200000000813E917590DA1D0294DA1D028852F402CD78D50656DD1D0200000000337AD506740A91750000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000091768106A77681069176810600000000000000000000000000000000000000000000000000000000000000009D240000C0ED9D0388D61D0233AB4777C019F5EFFC0B00001027000008000000ED530200BCD61D02F8AA4777ED530200C0ED9D03DCD61D02E8DED4035CD71D0200000000A20100001CD700001360DF7ACCD61D02829191751CD71D02D0D61D02279591750000000074E3D403F8D61D02CD94917574E3D403A4D71D02E8DED403E194917500000000E8DED403A4D71D0200D71D0209000000000000000900000043003A005C00550073006500720073005C005000750062006C00690063005C004400650073006B0074006F0070005C004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000006C006E006B000000630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000001D020000000085F990758C52F402BCD51D0294D51D028852F402C8D51D02546F9D76BC66AC760000000068DA1D026C31917568DA1D02553E9175337AD50628DD1D0200000000813E917590DA1D0294DA1D028852F402CD78D50656DD1D0200000000337AD506740A91750000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000091768106A77681069176810600000000000000000000000000000000000000000000000000000000000000009D240000C0ED9D0388D61D0233AB4777C019F5EFFC0B00001027000008000000ED530200BCD61D02F8AA4777ED530200C0ED9D03DCD61D02E8DED4035CD71D0200000000A20100001CD700001360DF7ACCD61D02829191751CD71D02D0D61D02279591750000000074E3D403F8D61D02CD94917574E3D403A4D71D02E8DED403E194917500000000E8DED403A4D71D0200D71D0209000000000000000900000043003A005C00550073006500720073005C005000750062006C00690063005C004400650073006B0074006F0070005C004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000006C006E006B000000630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000001D020000000085F990758C52F402BCD51D0294D51D028852F402C8D51D02546F9D76BC66AC760000000068DA1D026C31917568DA1D02553E9175337AD50628DD1D0200000000813E917590DA1D0294DA1D028852F402CD78D50656DD1D0200000000337AD506740A91750000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000091768106A77681069176810600000000000000000000000000000000000000000000000000000000000000009D240000C0ED9D0388D61D0233AB4777C019F5EFFC0B00001027000008000000ED530200BCD61D02F8AA4777ED530200C0ED9D03DCD61D02E8DED4035CD71D0200000000A20100001CD700001360DF7ACCD61D02829191751CD71D02D0D61D02279591750000000074E3D403F8D61D02CD94917574E3D403A4D71D02E8DED403E194917500000000E8DED403A4D71D0200D71D02
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
00000000000000000100000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003E0000008D7B1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
000000000000000001000000920C0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003E0000001F881500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
000000000000000002000000920C0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003F0000001F881500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
0000000000000000020000000A130000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003F000000978E1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
00000000000000000200000068130000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003F000000F58E1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
00000000000000000300000068130000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E00000040000000F58E1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
000000000000000003000000451E0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E00000040000000D2991500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
WORDFiles
1300627477
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Zvpebfbsg Bssvpr\Bssvpr14\JVAJBEQ.RKR
0000000005000000040000005F2C0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF0090D4F97E8DD40100000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000040000000D2991500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithList
a
WINWORD.EXE
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithList
MRUList
a
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithProgids
Word.RTF.8
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
3
6D006F006E00640061007900720065007400610069006C002E00720074006600000086003200000000000000000000006D6F6E64617972657461696C2E727466202832292E6C6E6B00005E0008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000006D006F006E00640061007900720065007400610069006C002E0072007400660020002800320029002E006C006E006B00000028000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.rtf
0
6D006F006E00640061007900720065007400610069006C002E00720074006600000086003200000000000000000000006D6F6E64617972657461696C2E727466202832292E6C6E6B00005E0008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000006D006F006E00640061007900720065007400610069006C002E0072007400660020002800320029002E006C006E006B00000028000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.rtf
MRUListEx
00000000FFFFFFFF
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018120620181207
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CachePrefix
:2018120620181207:
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheLimit
8192
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheOptions
11
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018120620181207
CacheRepair
0
2028
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
2028
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
MRUListEx
03000000000000000200000001000000FFFFFFFF
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Zvpebfbsg Bssvpr\Bssvpr14\JVAJBEQ.RKR
0000000005000000050000005F2C0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF0090D4F97E8DD40100000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000041000000D2991500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Zvpebfbsg Bssvpr\Bssvpr14\JVAJBEQ.RKR
000000000500000005000000E73F0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF0090D4F97E8DD40100000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F000000410000005AAD1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Qrkcbg/FriraQrk
000000000000000004000000451E0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2028
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F000000420000005AAD1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000F000000E21705007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E006500780065000000D201B0E536027CE43602A532DC75BCE4360294E5360200000000B432DC75F4E536020145DC756A00CA028C00CA02B8ACCA0278E336020001000101000000000100000000000028FCA802C8E53602E0E2BF02A4E53602CAFEBF02A0E33602D4E536026000CA022B0000006A00CA0228FCA802000000008C00CA025CE536020A00CA020000000005000500A823D3016601CA022B0000000F000000F4E53602BCE5360228FCA8021000000074FFA802050017004E1ED301BCE436021600000002000000B8ACCA020400360228FCA80203000000000000000909090009090909000911110000000011000000B8452700B04527000000000000000000000000000000000000000000000000001CE400005A743083D0E336028291F5751CE43602CCB700002E743083E4E33602B69CF575D0B7DD024C060000FCE3360240B3DD0208E43602789CF57511000000B8452700B045270060B3DD026CE40000E67330831CE436028291F5756CE4360220E436022795F57500000000CCB7DD0248E43602CD94F575CCB7DD02F4E4360240B3DD02E194F5750000000040B3DD02F4E4360250E43602090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}
Microsoft ListView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl
Microsoft ListView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CLSID
{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CurVer
MSComctlLib.ListViewCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2
Microsoft ListView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2\CLSID
{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\VersionIndependentProgID
MSComctlLib.ListViewCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\ProgID
MSComctlLib.ListViewCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 4
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}
Microsoft ListView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CLSID
{979127D3-7D01-4FDE-AF65-A698091468AF}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2\CLSID
{979127D3-7D01-4FDE-AF65-A698091468AF}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\VersionIndependentProgID
MSComctlLib.ListViewCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\ProgID
MSComctlLib.ListViewCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 4
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}
Microsoft ListView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CLSID
{996BF5E0-8044-4650-ADEB-0B013914E99C}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2\CLSID
{996BF5E0-8044-4650-ADEB-0B013914E99C}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\VersionIndependentProgID
MSComctlLib.ListViewCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\ProgID
MSComctlLib.ListViewCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 4
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}
Microsoft ListView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl\CLSID
{BDD1F04B-858B-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ListViewCtrl.2\CLSID
{BDD1F04B-858B-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.ListViewCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.ListViewCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD1F04B-858B-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 4
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}
Microsoft TreeView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl
Microsoft TreeView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CLSID
{95F0B3BE-E8AC-4995-9DCA-419849E06410}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CurVer
MSComctlLib.TreeCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl.2
Microsoft TreeView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl.2\CLSID
{95F0B3BE-E8AC-4995-9DCA-419849E06410}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\VersionIndependentProgID
MSComctlLib.TreeCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\ProgID
MSComctlLib.TreeCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}
Microsoft TreeView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CLSID
{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl.2\CLSID
{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\VersionIndependentProgID
MSComctlLib.TreeCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\ProgID
MSComctlLib.TreeCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}
Microsoft TreeView Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl\CLSID
{C74190B6-8589-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TreeCtrl.2\CLSID
{C74190B6-8589-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.TreeCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.TreeCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C74190B6-8589-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 2
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}
Microsoft TabStrip Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip
Microsoft TabStrip Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip\CLSID
{9A948063-66C3-4F63-AB46-582EDAA35047}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip\CurVer
MSComctlLib.TabStrip.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip.2
Microsoft TabStrip Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip.2\CLSID
{9A948063-66C3-4F63-AB46-582EDAA35047}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\VersionIndependentProgID
MSComctlLib.TabStrip
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\ProgID
MSComctlLib.TabStrip.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 10
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}
Microsoft TabStrip Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip\CLSID
{24B224E0-9545-4A2F-ABD5-86AA8A849385}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip.2\CLSID
{24B224E0-9545-4A2F-ABD5-86AA8A849385}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\VersionIndependentProgID
MSComctlLib.TabStrip
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\ProgID
MSComctlLib.TabStrip.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 10
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}
Microsoft TabStrip Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip\CLSID
{1EFB6596-857C-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.TabStrip.2\CLSID
{1EFB6596-857C-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.TabStrip
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.TabStrip.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 10
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}
Microsoft Toolbar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar
Microsoft Toolbar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar\CLSID
{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar\CurVer
MSComctlLib.Toolbar.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar.2
Microsoft Toolbar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar.2\CLSID
{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\VersionIndependentProgID
MSComctlLib.Toolbar
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\ProgID
MSComctlLib.Toolbar.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\MiscStatus\1
237969
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 12
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}
Microsoft Toolbar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar\CLSID
{7DC6F291-BF55-4E50-B619-EF672D9DCC58}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar.2\CLSID
{7DC6F291-BF55-4E50-B619-EF672D9DCC58}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\VersionIndependentProgID
MSComctlLib.Toolbar
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\ProgID
MSComctlLib.Toolbar.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\MiscStatus\1
237969
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 12
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}
Microsoft Toolbar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar\CLSID
{66833FE6-8583-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Toolbar.2\CLSID
{66833FE6-8583-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.Toolbar
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.Toolbar.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\MiscStatus\1
237969
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 12
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}
Microsoft ImageList Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl
Microsoft ImageList Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CLSID
{556C2772-F1AD-4DE1-8456-BD6E8F66113B}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CurVer
MSComctlLib.ImageListCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl.2
Microsoft ImageList Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl.2\CLSID
{556C2772-F1AD-4DE1-8456-BD6E8F66113B}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\VersionIndependentProgID
MSComctlLib.ImageListCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\ProgID
MSComctlLib.ImageListCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\MiscStatus\1
165265
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 3
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}
Microsoft ImageList Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CLSID
{F91CAF91-225B-43A7-BB9E-472F991FC402}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl.2\CLSID
{F91CAF91-225B-43A7-BB9E-472F991FC402}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\VersionIndependentProgID
MSComctlLib.ImageListCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\ProgID
MSComctlLib.ImageListCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\MiscStatus\1
165265
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 3
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}
Microsoft ImageList Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl\CLSID
{2C247F23-8591-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageListCtrl.2\CLSID
{2C247F23-8591-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.ImageListCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.ImageListCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\MiscStatus\1
165265
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C247F23-8591-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 3
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}
Microsoft StatusBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl
Microsoft StatusBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CLSID
{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CurVer
MSComctlLib.SBarCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl.2
Microsoft StatusBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl.2\CLSID
{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\VersionIndependentProgID
MSComctlLib.SBarCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\ProgID
MSComctlLib.SBarCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\MiscStatus\1
172433
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}
Microsoft StatusBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CLSID
{627C8B79-918A-4C5C-9E19-20F66BF30B86}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl.2\CLSID
{627C8B79-918A-4C5C-9E19-20F66BF30B86}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\VersionIndependentProgID
MSComctlLib.SBarCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\ProgID
MSComctlLib.SBarCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\MiscStatus\1
172433
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}
Microsoft StatusBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl\CLSID
{8E3867A3-8586-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.SBarCtrl.2\CLSID
{8E3867A3-8586-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.SBarCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.SBarCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\MiscStatus\1
172433
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E3867A3-8586-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}
Microsoft Slider Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Slider
Microsoft Slider Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Slider\CLSID
{0B314611-2C19-4AB4-8513-A6EEA569D3C4}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Slider\CurVer
MSComctlLib.Slider.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Slider.2
Microsoft Slider Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Slider.2\CLSID
{0B314611-2C19-4AB4-8513-A6EEA569D3C4}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\VersionIndependentProgID
MSComctlLib.Slider
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\ProgID
MSComctlLib.Slider.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 16
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}
Microsoft Slider Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Slider\CLSID
{F08DF954-8592-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.Slider.2\CLSID
{F08DF954-8592-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.Slider
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.Slider.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F08DF954-8592-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 16
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}
Microsoft ProgressBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ProgCtrl
Microsoft ProgressBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ProgCtrl\CLSID
{A0E7BF67-8D30-4620-8825-7111714C7CAB}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ProgCtrl\CurVer
MSComctlLib.ProgCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ProgCtrl.2
Microsoft ProgressBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ProgCtrl.2\CLSID
{A0E7BF67-8D30-4620-8825-7111714C7CAB}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\VersionIndependentProgID
MSComctlLib.ProgCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\ProgID
MSComctlLib.ProgCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\MiscStatus\1
172433
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 17
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}
Microsoft ProgressBar Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ProgCtrl\CLSID
{35053A22-8589-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ProgCtrl.2\CLSID
{35053A22-8589-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.ProgCtrl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.ProgCtrl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\MiscStatus\1
172433
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35053A22-8589-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 17
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}
Microsoft ImageComboBox Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageComboCtl
Microsoft ImageComboBox Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageComboCtl\CLSID
{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageComboCtl\CurVer
MSComctlLib.ImageComboCtl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageComboCtl.2
Microsoft ImageComboBox Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageComboCtl.2\CLSID
{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\VersionIndependentProgID
MSComctlLib.ImageComboCtl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\ProgID
MSComctlLib.ImageComboCtl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 1916
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}
Microsoft ImageComboBox Control 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\InprocServer32
ThreadingModel
Apartment
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageComboCtl\CLSID
{DD9DA666-8594-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSComctlLib.ImageComboCtl.2\CLSID
{DD9DA666-8594-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\VersionIndependentProgID
MSComctlLib.ImageComboCtl
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\ProgID
MSComctlLib.ImageComboCtl.2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\TypeLib
{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\MiscStatus
0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\MiscStatus\1
131473
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DD9DA666-8594-11D1-B16A-00C0F0283628}\ToolboxBitmap32
C:\Windows\system32\mscomctl.ocx, 1916
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}
TreeView General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE32-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}
TabStrip General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE33-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}
Tab Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE34-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}
Toolbar General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE37-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}
Button Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}
ImageList General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE35-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}
Image Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE36-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}
StatusBar General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE39-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}
Panel Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3A-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}
Slider General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3C-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}
Slider Appearance Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3D-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}
Progress Bar General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3B-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}
ListView General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3E-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}
ListView Sort Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE3F-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}
ListView Images Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE40-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}
ListView Columns Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE41-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}\InprocServer32
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}
ImageComboBox General Property Page Object
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE42-8596-11D1-B16A-00C0F0283628}\InprocServer32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}\2.1
Microsoft Windows Common Controls 6.0 (SP6)
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}\2.1\FLAGS
2
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}\2.1\0\win32
C:\Windows\system32\mscomctl.ocx
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{831FDD16-0C5C-11D2-A9FC-0000F8754DA1}\2.1\HELPDIR
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2334D2B1-713E-11CF-8AE5-00AA00C00905}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2334D2B3-713E-11CF-8AE5-00AA00C00905}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EFB6594-857C-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EFB6595-857C-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EFB6597-857C-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1EFB6599-857C-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66833FE4-8583-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66833FE5-8583-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66833FE7-8583-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66833FE9-8583-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66833FEB-8583-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66833FED-8583-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E3867A1-8586-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E3867A2-8586-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E3867A4-8586-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8E3867AA-8586-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{35053A20-8589-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{35053A21-8589-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C74190B4-8589-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C74190B5-8589-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C74190B7-8589-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C74190B8-8589-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F049-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F04A-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F04C-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F04E-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F050-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F051-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F053-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDD1F055-858B-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2C247F21-8591-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2C247F22-8591-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2C247F24-8591-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2C247F26-8591-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08DF952-8592-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08DF953-8592-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C8A3DC00-8593-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD9DA660-8594-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD9DA662-8594-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD9DA664-8594-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD9DA665-8594-11D1-B16A-00C0F0283628}\TypeLib
Version
2.1
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66833FE6-8583-11D1-B16A-00C0F0283628}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD9DA666-8594-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DD9DA666-8594-11D1-B16A-00C0F0283628}
AlternateCLSID
{87DACC48-F1C5-4AF3-84BA-A2A72C2AB959}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{556C2772-F1AD-4DE1-8456-BD6E8F66113B}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2C247F23-8591-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2C247F23-8591-11D1-B16A-00C0F0283628}
AlternateCLSID
{556C2772-F1AD-4DE1-8456-BD6E8F66113B}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F91CAF91-225B-43A7-BB9E-472F991FC402}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F91CAF91-225B-43A7-BB9E-472F991FC402}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F91CAF91-225B-43A7-BB9E-472F991FC402}
AlternateCLSID
{556C2772-F1AD-4DE1-8456-BD6E8F66113B}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BDD1F04B-858B-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BDD1F04B-858B-11D1-B16A-00C0F0283628}
AlternateCLSID
{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{996BF5E0-8044-4650-ADEB-0B013914E99C}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{996BF5E0-8044-4650-ADEB-0B013914E99C}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{996BF5E0-8044-4650-ADEB-0B013914E99C}
AlternateCLSID
{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{979127D3-7D01-4FDE-AF65-A698091468AF}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{979127D3-7D01-4FDE-AF65-A698091468AF}
AlternateCLSID
{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0E7BF67-8D30-4620-8825-7111714C7CAB}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{35053A22-8589-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{35053A22-8589-11D1-B16A-00C0F0283628}
AlternateCLSID
{A0E7BF67-8D30-4620-8825-7111714C7CAB}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B314611-2C19-4AB4-8513-A6EEA569D3C4}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F08DF954-8592-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F08DF954-8592-11D1-B16A-00C0F0283628}
AlternateCLSID
{0B314611-2C19-4AB4-8513-A6EEA569D3C4}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8E3867A3-8586-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8E3867A3-8586-11D1-B16A-00C0F0283628}
AlternateCLSID
{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{627C8B79-918A-4C5C-9E19-20F66BF30B86}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{627C8B79-918A-4C5C-9E19-20F66BF30B86}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{627C8B79-918A-4C5C-9E19-20F66BF30B86}
AlternateCLSID
{585AA280-ED8B-46B2-93AE-132ECFA1DAFC}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9A948063-66C3-4F63-AB46-582EDAA35047}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1EFB6596-857C-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1EFB6596-857C-11D1-B16A-00C0F0283628}
AlternateCLSID
{9A948063-66C3-4F63-AB46-582EDAA35047}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{24B224E0-9545-4A2F-ABD5-86AA8A849385}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{24B224E0-9545-4A2F-ABD5-86AA8A849385}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{24B224E0-9545-4A2F-ABD5-86AA8A849385}
AlternateCLSID
{9A948063-66C3-4F63-AB46-582EDAA35047}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{66833FE6-8583-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{66833FE6-8583-11D1-B16A-00C0F0283628}
AlternateCLSID
{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7DC6F291-BF55-4E50-B619-EF672D9DCC58}
AlternateCLSID
{8B2ADD10-33B7-4506-9569-0A1E1DBBEBAE}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95F0B3BE-E8AC-4995-9DCA-419849E06410}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C74190B6-8589-11D1-B16A-00C0F0283628}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C74190B6-8589-11D1-B16A-00C0F0283628}
AlternateCLSID
{95F0B3BE-E8AC-4995-9DCA-419849E06410}
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\Control
2976
Dexpot v1614 r2439.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}\Implemented Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}
Compatibility Flags
1024
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E}
AlternateCLSID
{95F0B3BE-E8AC-4995-9DCA-419849E06410}
2976
Dexpot v1614 r2439.exe
write
HKEY_CURRENT_USER\Software\Dexpot
Uninstaller Sprache
1033
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dxp
Dexpot Profile File
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dexpot Profile File
Dexpot Profile File
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dexpot Profile File\shell
open
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dexpot Profile File\DefaultIcon
C:\Program Files\Dexpot\dexpot.exe,0
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dexpot Profile File\shell\open\command
"C:\Program Files\Dexpot\dexpot.exe" "%1"
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dexpot Profile File\shell\edit
Edit Dexpot Profile File
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Dexpot Profile File\shell\edit\command
"C:\Program Files\Dexpot\dexpot.exe" "%1"
2976
Dexpot v1614 r2439.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Users\admin\AppData\Local\Temp\nss5FD5.tmp\OCSetupHlp.dll
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASAPI32
EnableFileTracing
0
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASAPI32
EnableConsoleTracing
0
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASAPI32
FileTracingMask
4294901760
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASAPI32
ConsoleTracingMask
4294901760
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASAPI32
MaxFileSize
1048576
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASAPI32
FileDirectory
%windir%\tracing
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASMANCS
EnableFileTracing
0
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASMANCS
EnableConsoleTracing
0
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASMANCS
FileTracingMask
4294901760
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASMANCS
ConsoleTracingMask
4294901760
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASMANCS
MaxFileSize
1048576
3128
RunDll32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RunDll32_RASMANCS
FileDirectory
%windir%\tracing
3128
RunDll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3128
RunDll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3044
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3044
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2212
dexpot.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductNonBootFiles
1300627457
2212
dexpot.exe
write
HKEY_CURRENT_USER\Software\Dexpot\Regeln
RegelZahl
0
2212
dexpot.exe
write
HKEY_CURRENT_USER\Software\Dexpot\Regeln
RegelZahlAktiviert
0
2212
dexpot.exe
write
HKEY_CURRENT_USER\Software\Dexpot
DexpotVersion
1.6.14.2439
2212
dexpot.exe
write
HKEY_CURRENT_USER\Software\Dexpot
ForegroundLockTimeout
200000
2212
dexpot.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2212
dexpot.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2212
dexpot.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductNonBootFiles
1300627458
2212
dexpot.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductNonBootFiles
1300627459
2212
dexpot.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductNonBootFiles
1300627460
2212
dexpot.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductNonBootFiles
1300627461
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
k '
6B202700F0050000010000000000000000000000
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
1520
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
WORDFiles
1300627478
1520
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627596
1520
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627597
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTT
F0050000021FCBF97E8DD40100000000
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
d!'
64212700F005000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
n"'
6E222700F005000006000000010000006000000002000000500000000400000063003A005C00750073006500720073005C00610064006D0069006E005C006400650073006B0074006F0070005C006D006F006E00640061007900720065007400610069006C002E00720074006600000000000000
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\ReviewCycle
ReviewToken
{5D6EE527-174F-42F1-B29A-8541088D29FB}
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Max Display
25
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Place MRU
Item 1
[F00000000][T01D48D7EFA63B0A0][O00000000]*C:\Users\admin\Desktop\
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Max Display
25
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\File MRU
Item 1
[F00000000][T01D48D7EFA63B0A0][O00000000]*C:\Users\admin\Desktop\mondayretail.rtf
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\251FBA
251FBA
04000000F00500002700000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C006D006F006E00640061007900720065007400610069006C002E00720074006600100000006D006F006E00640061007900720065007400610069006C002E007200740066000000000001000000000000000065C6E2AD48D401BA1F2500BA1F250000000000DB040000000000000000000000000000000000000000000000000000FFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF
1520
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Licensing
019C826E445A4649A5B00BF08FCC4EEE
01000000270000007B39303134303030302D303033442D303030302D303030302D3030303030303046463143457D005A0000004F00660066006900630065002000310034002C0020004F0066006600690063006500500072006F00660065007300730069006F006E0061006C002D00520065007400610069006C002000650064006900740069006F006E000000
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Toolbars\Settings
Microsoft Word
0101000000000000000006000000
1520
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery\251FBA
1520
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\DocumentRecovery
1520
WINWORD.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Data
Settings
C00010033001000034010000040000001E0000001E0000001E0000001E0000001E0000001E000000220000001E0000001E0000001E000000060000000600000006000000060000000600000000000000060000000600000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000C00000002000000020000000200000002000000000000000000000000000000480000000600000006000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004000000DC000000E25024A1100A00633090060006000A002D001600000016000000C0030000F501000004060300000000000000000000000000040087010C000600C80009000180FFFF000006000000040000000C0100000502000000000000A004020000001200000000603090000064000000000000FF0000FF000000000000FF01000000010000005C08E0100000000000010000E40400001D000100000000000000020050000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000D000000000000000000000000D4944600D49446010000002F91010000080A000600000003333296040000000A050C0C0302040600000300000101010606060000000000000000000000000000000000000063631900000001000000000000000000000000000000030000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002100190000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000E01000004B0000004B0000002000640000006301190000008C0A00000000B01300004B0000004B000000640000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000002000640000006363190000008C0A00000000E01000004B0000004B0000009002000002000001010101010101000101010101010001010100010001000101010101010101000100020003010301030103000301020003010301030103010000230101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010101020101010101010101010101010101010101010101010101010101010101010101010101010101010101010101010301010101010101010101010101FFFFCFFFFFFF00008602FFFF00008602FFFF00000C00FFFF00000100FFFF00000100FFFF0000010061000000610064006D0069006E000000000000000000000087FFFF0300003E00020200000600090034000000000090009000000000000F000000FFFFFF000000000000001400140000000000000002637800C80000000000140000000000900090008000FFFF00000800FFFF00000800FFFF0B00040001002000018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E0065007700018014000B0043006F007500720069006500720020004E00650077000180140001002000018014000B0043006F007500720069006500720020004E00650077000180140009004D005300200047006F0074006800690063000180150007004D0069006E0067004C0069005500018018000600530069006D00530075006E0001801500050044006F00740075006D00018014000100200001801C0000000000
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Options
BackgroundOpen
0
1520
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627598
1520
WINWORD.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1300627599
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTF
84
1520
WINWORD.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word
MTTA
84

Files activity

Executable files
32
Suspicious files
5
Text files
214
Unknown types
35

Dropped files

PID
Process
Filename
Type
3156
Dexpot v1614 r2439.exe
C:\Users\admin\AppData\Local\Temp\nsb5D06.tmp\UAC.dll
executable
MD5: 88ad3fd90fc52ac3ee0441a38400a384
SHA256: e58884695378cf02715373928bb8ade270baf03144369463f505c3b3808cbc42
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\plugins\Taskbar Pager.exe
executable
MD5: 05f4c8e185bd8b468ed1913aa646eb1b
SHA256: 5b23bfda25056fff426cd08ecb754f0787e62c2ebc9fb60a3c0803809c7112b4
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\dexpot.exe
executable
MD5: 4761a3614a47bd22027bba49b38a2bf7
SHA256: 75a61e8bfa2344248b145c2144e160c82b2086c3531007cb2e627113190a21bf
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\plugins\Dexcube.exe
executable
MD5: 9718964ef5ab229150342b04c94baeae
SHA256: e3ac9423841b0823592e8debd8a28a5e1a38f2ded2d83070eb658bdc5b0bfc90
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\hooxpot.dll
executable
MD5: eb81e29ad929527f4459d2f7a025b7f5
SHA256: 1617eeb2d6e393444971726e036bd590ebfa13d55c5b74d375cc79cd8eb174f0
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\Dexpot.dll
executable
MD5: 4ee55e6086cd327f2c9dc38d7286902b
SHA256: 52ff0ce721481dc27be5ae81804708b133ff2d944e67f5ee5927dc4ffb7f6f0a
2976
Dexpot v1614 r2439.exe
C:\Windows\system32\mscomctl.ocx
executable
MD5: e52859fcb7a827cacfce7963184c7d24
SHA256: 45b6eef5bbf223cf8ff78f5014b68a72f0bc2cceaed030dece0a1abacf88f1f8
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\plugins\zlibwapi.dll
executable
MD5: 54789344b07bed58e43851eca47e2b12
SHA256: 9f8729ac49e0ccea86fe3b1a9b2c3fae9986ecd09db92853e7a588dbda85bf90
2976
Dexpot v1614 r2439.exe
C:\Users\admin\AppData\Local\Temp\nss5FD5.tmp\InstallOptions.dll
executable
MD5: 325b008aec81e5aaa57096f05d4212b5
SHA256: c9cd5c9609e70005926ae5171726a4142ffbcccc771d307efcd195dafc1e6b4b
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\plugins\d3dx9_43.dll
executable
MD5: 86e39e9161c3d930d93822f1563c280d
SHA256: 0b28546be22c71834501f7d7185ede5d79742457331c7ee09efc14490dd64f5f
2976
Dexpot v1614 r2439.exe
C:\Users\admin\AppData\Local\Temp\nss5FD5.tmp\nsDialogs.dll
executable
MD5: c10e04dd4ad4277d5adc951bb331c777
SHA256: e31ad6c6e82e603378cb6b80e67d0e0dcd9cf384e1199ac5a65cb4935680021a
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\plugins\MouseEvents.exe
executable
MD5: ceed044fb50983acdb320257407deded
SHA256: 5fe68d48dceb9bc04a0cd887090cd2d7affbfa763d20bfabfb4ee82e2a54b702
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\plugins\Leap.dll
executable
MD5: fcf71eb3367b39ede69f60c6297ba6d3
SHA256: e31bf7eed93a17ed9c48cbfa7323e522758f2ce60b09c71354fe2342cb9bf89e
2976
Dexpot v1614 r2439.exe
C:\Program Files\Dexpot\zlibwapi.dll
executable
MD5: 54789344b07bed58e43851eca47e2b12